Get tomorrow's brief in your inbox
Today: The Supreme Court rejects billion-dollar copyright liability for ISPs while establishing a narrow standard for contributory infringement, finding Cox Communications cannot be held responsible for customer piracy. FCC Chairman Brendan Carr faces formal legal pushback as 80+ legal scholars document First Amendment violations in his threats against broadcasters. EU regulators launch child safety crackdown, investigating Snapchat for age verification failures and warning four pornography sites of potential penalties for inadequate protections.
Supreme Court Reverses $1 Billion Cox Communications Judgment (Cox v. Sony)
The Supreme Court unanimously reversed a billion-dollar judgment against Cox Communications for contributory copyright infringement, establishing that ISPs cannot be held liable for customer piracy simply for providing internet access. Justice Clarence Thomas wrote that contributory liability requires either active inducement of infringement or providing a service tailored to infringement with no substantial non-infringing uses. The Court found no evidence Cox encouraged infringement and emphasized that general-purpose internet connectivity is capable of substantial lawful uses. The decision clarifies that mere knowledge that customers may infringe is insufficient to establish liability. Sony and other content providers failed to show Cox actively promoted infringement, and the record showed Cox implemented warning systems, suspended service, and terminated accounts to discourage unlawful activity.
French DPA Closes KASPR Enforcement Without Penalty (SAN-2026-004)
France's CNIL determined that lead generation company KASPR complied with all requirements of a December 2024 injunction and declined to enforce the daily penalty payment. The December 2024 decision (SAN-2024-020) had ordered KASPR to bring its LinkedIn data collection practices into compliance with GDPR Articles 6, 5(1)(e), 12, 14, and 15, addressing unlawful data collection, excessive retention, lack of transparency, and access request failures. By May 2025, KASPR deleted its database, ceased data collection from LinkedIn, ended automatic renewal of retention periods, provided multilingual transparency notices, and responded to outstanding access requests. The CNIL's March 4, 2026 decision confirms that the controller met all injunction requirements within the prescribed period.
Luxembourg Administrative Tribunal Annuls Minister's Data Disclosure Refusal (N°46014)
The Luxembourg Administrative Tribunal annulled the Minister of Consumer Protection's refusal to provide Ryanair with passenger contact information, ruling that invoking Article 6(1)(a) GDPR consent requirement alone was insufficient. The Minister had issued seven decisions ordering Ryanair to pay €250 compensation to each of 37 passengers for canceled flights under EU Regulation 261/2004, then refused to provide full names and addresses when Ryanair sought to notify passengers of its annulment action. The Tribunal held that public authorities have multiple legal bases available under Article 6(1) GDPR, including Article 6(1)(e) for public interest tasks and Article 6(1)(c) for legal obligations. The court emphasized that the Minister's enforcement role under Regulation 261/2004 required collecting passenger data for its public mission, and compatibility with original purpose should have been assessed under Article 5(1)(b) and Article 6(4) GDPR.
RedLine Malware Developer Extradited, Faces 30 Years
Armenian national Hambardzum Minasyan appeared in Austin federal court Tuesday following his Monday extradition on charges of conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. The Justice Department alleges Minasyan maintained digital infrastructure for RedLine infostealer malware, including administrative panels and servers enabling affiliates to deploy the malware. Prosecutors allege he collected payments from affiliates, provided customer service to hackers, coordinated theft of financial information, and laundered earnings through cryptocurrency exchanges. The extradition follows an October 2024 takedown of RedLine infrastructure by DOJ and law enforcement in the Netherlands and Belgium. RedLine has been deployed in thousands of attacks across 150+ countries since March 2020, extracting credentials from browsers, FTP clients, email apps, and VPNs.
Oura Ring Faces Class Action Over California Automatic Renewal Law (Lekhadia v. Oura Health)
Three consumers filed a class action in California federal court (Case No. 3:25-cv-10997, N.D. Cal.) alleging Oura Health Oy and Ouraring Inc. violated California's Automatic Renewal Law by failing to clearly disclose renewal terms and provide easy cancellation mechanisms. Plaintiffs Kunal Lekhadia, Neel Patel, and Gaurav Agrawal claim their one-month and one-year prepaid memberships ($5.99-$69.99) automatically renewed without knowledge or consent. The complaint alleges violations of California's ARL, Consumers Legal Remedies Act, and Unfair Competition Law for lack of clear conspicuous disclosures in visual proximity to "Place Order" prompts and failure to provide cost-effective, timely, easy-to-use cancellation methods. Plaintiffs seek certification of a nationwide class for all U.S. consumers who purchased Oura Ring products with automatic renewal plans within the last four years.
Lenovo Sued for TCPA Violations in Marketing Text Messages (Reyes v. Lenovo, Case No. 3:26-cv-01546)
Plaintiff Peejay Reyes filed a class action in California federal court alleging Lenovo United States Inc. sent marketing text messages at unlawful hours in violation of the Telephone Consumer Protection Act. Reyes claims he received two marketing texts on November 28 and December 1, 2025 at 6:48 AM and 8:58 AM, before the TCPA's 8 AM restriction. The complaint seeks to represent a nationwide class of consumers who received more than one marketing text from Lenovo before 8 AM or after 9 PM within any 12-month period. Reyes argues the TCPA prohibits telephone solicitations to residential subscribers before 8 AM and after 9 PM, and the messages constituted intrusion into privacy by advertising Lenovo's property, goods, and services. The plaintiff demands declaratory and injunctive relief and statutory damages.
Federal Court Dismisses Cookie Tracking as CIPA Trap-and-Trace Device (Travis Rounds v. DDI, 2026 WL 746291)
The Central District of California dismissed without leave to amend plaintiff Travis Rounds's claim that Development Dimensions International's use of 6Sense data-broker SDK constituted an illegal trap-and-trace device under California Penal Code § 638.51. Judge David O. Carter found that allegations of cookie use do not suffice as a statutory violation of § 638.51. California Penal Code § 638.50(c) defines trap-and-trace devices as capturing incoming impulses identifying originating numbers or routing information, not contents. The court found DDI's use of cookies to track geolocation, device information, browser cookies, and other browser data for user deanonymization and profile building did not plausibly establish a § 638.51 violation. The dismissal was based on lack of personal jurisdiction, with the court concluding that cookie use was insufficient to establish jurisdiction over the Pennsylvania-based defendant.
Supreme Court Holds Supervised Release Terms Expire Despite Flight (Rico v. United States)
The Supreme Court ruled 8-1 that a defendant's term of supervised release expires at its scheduled end date even if the defendant absconds, and new crimes committed after expiration cannot independently authorize revocation. Isabel Rico pleaded guilty to drug trafficking and received four years of supervised release. She violated terms multiple times, then absconded near the end of her term and committed new crimes while a fugitive. Justice Neil Gorsuch's opinion reasoned that statutory extension and tolling rules (18 U.S.C. §§ 3582(e)(2), 3582(i), 3624(e)) do not address fugitive status, undercutting any unstated extension. Section 3583(i) allows courts to adjudicate pre-expiration violations after expiration if a warrant or summons was issued, but does not extend the term itself. The Court accepted that post-expiration crimes while a fugitive may be considered in sentencing for identified violations, but do not independently justify revocation or factor into guideline calculations.
April 2026 Class Action Settlements Closing
Ten class action settlements are accepting claims in April 2026 across privacy, data breach, consumer protection, and TCPA violations:
Inova Health agreed to pay $3.1 million for allegations it used pixel tracking technology to collect and share patient information with Facebook and Google without consent (claim deadline April 6). Capital Health agreed to $4.5 million for a 2023 data breach exposing Social Security numbers and clinical information (April 6 deadline, up to $5,000 documented losses or $100 cash). Panda Restaurant Group agreed to $2.45 million for a March 2023 data breach (April 10 deadline, up to $5,000 documented losses, $100 alternative payment, $125 for California residents). Pacific Life agreed to $58.3 million for misleading indexed universal life insurance policy illustrations in California (April 10 deadline). Gen Digital agreed to $9.95 million for unsolicited TCPA robocalls using artificial or prerecorded voices.
Supreme Court Debates Arbitration Exemption for Last-Mile Drivers (Flowers Foods v. Brock)
The Supreme Court heard arguments on whether the Federal Arbitration Act's interstate transportation worker exemption applies to "last-mile" drivers who do not cross state lines. Justices Sotomayor, Jackson, Alito, and Kagan appeared skeptical of the employer's position that only drivers who physically cross state borders qualify for the exemption. Justice Jackson noted it would be "ludicrous" that a driver crossing a border for one minute qualifies as interstate but workers on ten-hour shifts delivering the same cargo do not. Justice Kagan emphasized that "everybody who's involved in making the goods [get there] ought to fall into the same category." The argument focused on hypotheticals about whether the interstate movement of goods themselves is sufficient, rather than requiring the worker to cross borders. The justices appeared inclined to give last-mile drivers the benefit of the exemption, allowing them to choose court over forced arbitration.
EU Opens Snapchat Investigation and Warns Pornography Platforms
The European Commission launched an investigation into Snapchat and issued warnings to four pornographic platforms (Pornhub, Stripchat, XNXX, XVideos) for failing to comply with Digital Services Act child safety requirements. The Commission stated it is "not convinced of the measures that Snapchat has taken to ensure that under-13s are not getting on the platform" and expressed concerns about Snapchat's AI-based age estimation failing to reliably identify users. The investigation examines whether minors can circumvent age protections to access banned goods (alcohol, vaping products) and whether reporting tools meet EU standards. For pornography sites, the Commission found that self-declaration systems allowing users to confirm age with a single click are inadequate. Companies face fines up to 6% of global annual turnover for non-compliance. The Commission is testing a privacy-focused "mini wallet" in France, Denmark, Italy, Greece, and Spain to allow age verification without disclosing personal data.
Apple Implements UK Age Verification Requirements
Apple launched age verification for UK users with iOS 26.4, requiring customers to prove they are at least 18 to use certain features. Age filters are turned on by default, requiring all users including adults to verify age via credit card, payment methods on file, or ID submission. The policy responds to UK regulatory pressure from the Information Commissioner's Office and Ofcom, which gave platforms weeks to report child safety plans and threatened "further regulatory action" if platforms do not increase efforts to keep children under 13 off platforms. The UK is weighing a social media ban for children aged 15 and younger and announced pilot programs to test regulation approaches. Ofcom published a statement supporting the policy as bolstering efforts to "keep young people away from harmful content."
EFF Warns of License Plate Reader Mission Creep
A 404 Media report revealed Georgia State Patrol ticketed a motorcyclist in December 2025 for holding a cell phone based on Flock Safety ALPR camera footage, despite Flock's public statements that its systems "are not used to enforce traffic violations." The ticket read "CAPTURED ON FLOCK CAMERA 31 MM 1 HOLDING PHONE IN LEFT HAND." Flock now lists six traffic enforcement technology companies on its "Partner program" site, and public records show speed enforcement cameras connected to Flock's ALPR network. EFF emphasized this demonstrates the mission creep privacy advocates have warned about, where surveillance infrastructure approved for serious crimes gets expanded to petty violations and protest monitoring. EFF urged cities, states, and companies to end relationships with Flock Safety due to incompatibility between mass surveillance and civil liberties protection.
FCC Chairman Brendan Carr Receives Formal Legal Challenge
A coalition of 80+ legal scholars, former FCC officials, and civil society organizations sent a formal letter to FCC Chairman Brendan Carr documenting First Amendment violations in his threats against broadcasters. The letter, organized by TechFreedom and signed by ACLU, EFF, Knight First Amendment Institute, Institute for Free Speech, and Copia Institute, directly addresses Carr's assertion that broadcasters "are running hoaxes and news distortions" and threats that they would "lose their licenses" if they do not "correct course before their license renewals come up." The letter responds to Carr's retweet of President Trump's complaint about Wall Street Journal and New York Times headlines, followed by Trump's threat of "Charges for TREASON for the dissemination of false information." The coalition explains that Carr's reliance on the dormant "news distortion" policy is legally bankrupt and deliberately blurs the distinction between protected editorial decisions and fabricated content.
Trump Executive Order Targets College Football Scheduling
President Trump issued an executive order directing FCC Chairman Brendan Carr to consider whether broadcast licensees' public interest obligations require the Army-Navy Game remain a "national service event" and prevent competing college football playoff games from airing simultaneously. The order claims expansion of College Football Playoffs threatens to "encroach upon the second Saturday in December" traditionally reserved for the Army-Navy game. CBS Sports, owned by Trump ally David Ellison, holds exclusive broadcast rights to the Army-Navy game. ESPN/Disney/ABC owns broadcast rights to competing playoff games. The order tasks the FCC to "consider reviewing the public interest obligations of broadcast licensees" but has no legal enforcement mechanism and Trump has no authority to influence private scheduling organizations. The order raises concerns about abuse of public interest standards to benefit political allies' business interests.
Trump AI Executive Order Blocks State Regulation
In December 2025, the Trump administration signed an executive order neutering states' ability to regulate AI by ordering his administration to sue and withhold funds from states attempting regulation. The action supports industry lobbyists seeking to avoid constraints while undermining consumers, advocates, and industry associations concerned about AI harms who spent years pushing for state regulation. A May 2025 survey found 70%+ of likely voters favor state and federal regulators having a role in AI policy. A December 2025 Navigator Research poll found net +48% favorability for more AI regulation. Despite overwhelming voter preference and Congressional consensus (Congress was essentially unanimous in defeating a previous state AI regulation moratorium), Trump delivered on industry priorities. The order explicitly challenges voter will across blue and red states from California to South Dakota, setting up a wedge issue for upcoming midterm elections.
Implement age verification for EU and UK services: Organizations serving EU or UK users must deploy robust age verification beyond self-declaration by April 2026, particularly for age-restricted content. Evaluate document verification, biometric estimation, or privacy-preserving attestation systems meeting DSA and UK Online Safety Act standards.
Audit third-party tracking pixels and SDKs: Healthcare providers and businesses must review all third-party pixels, tracking scripts, and analytics integrations to ensure no unauthorized sharing of personal or protected health information occurs. Pixel tracking settlements (Inova Health $3.1M) demonstrate enforcement priority for health data sharing without consent.
Document anti-infringement measures for ISPs and platforms: Following Cox v. Sony, service providers should maintain records of warning systems, account suspensions, policy enforcement, and active discouragement of infringement to defend against contributory liability claims based on customer actions.
Establish ALPR use restrictions before deployment: Municipalities procuring automated license plate readers must implement binding use policies prohibiting mission creep, require vendor contractual limits on data access, and establish independent oversight before installation. Georgia's Flock camera traffic enforcement demonstrates scope expansion from serious crimes to petty violations.
Review subscription renewal disclosures for ARL compliance: California-based subscription services and services targeting California residents must ensure automatic renewal terms are clearly and conspicuously disclosed in visual proximity to purchase buttons, obtain affirmative consent, and provide easy cancellation mechanisms. Oura Ring class action demonstrates continued enforcement of California Automatic Renewal Law requirements.