← Carolina Clear Tech

Legal & Privacy Brief

2026-03-28

Listen to this brief (18:32)

Download MP3
Show Notes

Show Notes - 2026-03-28

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 28, 2026

Today: The Supreme Court takes up the birthright citizenship case on April 1 with lower courts unanimous that Trump's executive order is unconstitutional. A federal court in Texas dismissed X Corp's antitrust lawsuit against advertisers with prejudice, ruling that companies declining to advertise do not constitute antitrust injury. Meta and Google face major litigation exposure after California and New Mexico juries awarded millions in damages for social media addiction and failure to protect minors.

Enforcement Actions

Dutch Court Orders xAI to Stop Nonconsensual Nude Image Generation

A Dutch judge ordered xAI's Grok AI assistant to immediately stop creating nude images without subjects' consent, threatening fines of €100,000 ($115,000) per day for noncompliance, with damages capping at €10 million ($11.5 million). The court found that while X implemented some controls in January after global backlash, evidence from plaintiff nonprofit Offlimits suggests the changes may not be working. The court banned xAI from producing, distributing, offering, publicly displaying, or possessing sexual imagery in the Netherlands involving AI-generated child pornography. The ruling applies worldwide because Grok does not consider victim location when generating images.

Romanian DPA Fines Renault €125,000 for Data Breach Security Failures

The Romanian Data Protection Authority (ANSPDCP) fined Renault Commercial Roumanie SRL RON 637,262.50 (€125,000) for failing to implement appropriate technical and organizational security measures following a cyberattack on an application administered by a data processor. The breach resulted in unauthorized access and public disclosure of personal data including names, telephone numbers, home addresses, driver's license numbers, email addresses, personal identification codes, chassis numbers, birth dates, identity card details, and employment information affecting a very large number of data subjects. The DPA found violations of Article 32(1)(b), Article 32(1)(d), Article 32(2), and Article 28(1) GDPR for failure to ensure security measures and failure to vet processor security guarantees.

Romanian DPA Sanctions Company €3,000 for Body-Cam Use and Data Disclosure

The Romanian DPA (ANSPDCP) fined Domeniul Public și Privat SA RON 15,285 (€3,000) for multiple GDPR violations: RON 10,190 (€2,000) for unlawful use of body-cams and failure to inform employees about video/audio recordings in breach of Article 5(1)(a), Article 5(1)(c), Article 12, and Article 13 GDPR; and RON 5,095 (€1,000) for unlawfully disclosing an employee's personal data to their general health practitioner. The DPA found the body-cam processing was excessive given that less intrusive means of checking health and safety compliance were available. The company also received a warning for incomplete information regarding audio-video recording of disciplinary investigation meetings.

Belgian DPA Orders Travel Blogger to Erase Photos Following GDPR Complaint

The Belgian DPA (APD) issued a prima facie decision ordering a travel blogger to comply with a data subject's erasure request for photos depicting her on his travel blog, finding potential violations of Article 6, Article 12, and Article 17(1) GDPR. The controller had previously informed the complainant that hardly any photos remained but could not identify their locations. The DPA dismissed the complaint regarding erasure of the blogger's children's personal data, ruling that issue falls within parental authority disputes that must be resolved by competent courts. The controller has 30 days to submit a reconsideration request or the case proceeds to a hearing on the merits.

Litigation Updates

California and New Mexico Juries Award Millions Against Meta and Google for Social Media Addiction

A Los Angeles jury awarded $6 million in damages ($3 million compensatory, $3 million punitive) finding Meta and Google liable for the mental health struggles of plaintiff Kaley G.M., who became addicted to Instagram and YouTube as a child. The jury found both companies acted with "malice, fraud or oppression," apportioning liability at 70% Instagram and 30% YouTube. Meta must pay $2.1 million in punitive damages and Google $900,000. One day earlier, a New Mexico jury ordered Meta to pay $375 million ($187.5 million for unfair practices, $187.5 million for unconscionable acts) over claims brought by New Mexico Attorney General Raul Torrez that Meta hid the full scope of mental health harm to underage users. The verdict was based on 37,500 violations for each claim at $5,000 per violation. The state alleged Meta failed to protect teens from sexual predation and bullying, ignored internal warnings about harmful suicide and self-injury content, and took no meaningful action to keep users under 13 off its platforms. These bellwether trials are expected to provide settlement benchmarks as Meta and Google face thousands of similar lawsuits nationwide consolidated in Case No. 22STCV21355, Los Angeles County Superior Court.

Federal Judge Dismisses X Corp Antitrust Lawsuit Against Advertisers With Prejudice

Judge Jane Boyle of the Northern District of Texas dismissed X Corp's antitrust lawsuit against advertisers who declined to advertise on the platform, ruling that companies choosing not to buy from a competitor because they dislike the product does not constitute antitrust injury. The court held that antitrust law protects competition, not competitors, and that loss from customers choosing competitors' goods and services over the plaintiff's does not constitute antitrust injury. X had alleged that advertisers conspired to boycott the platform, but failed to allege that advertisers chose competing platforms as part of an agreement not to do business with X. The court found X suffered no antitrust injury because consumers, not competitors, must be harmed. The lawsuit was filed in August 2024 after Elon Musk told advertisers to "go fuck" themselves.

Federal Court Enjoins Trump Administration Actions Against Anthropic for Constitutional Violations

A federal court issued a preliminary injunction restraining the Trump administration's retaliatory actions against Anthropic following the AI company's public disagreement with the Department of Defense over contract use. The court found likely violations of due process (Fifth Amendment) for designating Anthropic a "supply chain risk" without notice or opportunity to respond, a designation previously reserved for foreign intelligence agencies, terrorists, and hostile actors. The government issued three challenged measures: a presidential directive banning all federal agencies from contracting with Anthropic, a Department of Defense directive requiring all defense contractors to sever commercial relationships with Anthropic, and the supply chain risk designation. The court clarified the injunction does not require DOD to use Anthropic's products or prevent DOD from transitioning to other AI providers, but restrains unlawful punitive measures. The injunction is stayed for seven days.

Grammarly Faces Class Action Over AI Tool Using Writers' Identities Without Consent

Journalist Julia Angwin filed a class action lawsuit (Case No. 1:26-cv-02005, S.D.N.Y.) against Grammarly's operator Superhuman Platform Inc., alleging the company misappropriated the names and identities of hundreds of journalists, authors, writers, and editors to profit from its Expert Review tool. Angwin claims Grammarly launched the tool in August 2025 enabling users to receive real-time feedback on their writing from well-known journalists like herself and authors like Stephen King for $12 per month, without obtaining consent from the experts. The complaint alleges Grammarly analyzes experts' publicly available work to generate advice these experts did not actually give. Angwin asserts violations of California's common law right of publicity, California Civil Code, New York Civil Rights Law, and unjust enrichment. She demands declaratory and injunctive relief plus compensatory damages and restitution.

EFF Urges Supreme Court to Hold Cisco Liable for Building Surveillance System That Enabled Torture Abroad

The Electronic Frontier Foundation filed an amicus brief in Cisco Systems, Inc., et al., v. Doe I, et al. (No. 24-856, scheduled for argument April 28) urging the Supreme Court to uphold the Ninth Circuit's ruling that U.S. corporations can be held liable under the Alien Tort Statute (ATS) for taking actions in the U.S. that aided and abetted persecution and torture abroad. The case involves Cisco's "Golden Shield" system custom-built for the Chinese government that was essential to persecution of the Falun Gong religious group, including online spying, tracking, detention, and torture. Victims reported intercepted communications were used during torture sessions. The Ninth Circuit held in 2023 that companies need only have "knowledge" that their assistance helped in human rights abuses, not "purpose" to facilitate them, and that legitimate uses of technology do not shield companies from liability when international law standards are met. The district court dismissed the case in 2014; Falun Gong victims originally sued in 2011.

Mississippi Death Row Inmate Challenges Racial Discrimination in Jury Selection

The Supreme Court will hear oral argument Tuesday in Pitchford v. Cain, where Terry Pitchford contends he was sentenced to death in violation of Batson v. Kentucky (1986) when prosecutor Doug Evans eliminated four potential Black jurors using peremptory challenges. Evans' conduct during jury selection previously led the Supreme Court to throw out another conviction in 2019 (Curtis Flowers case). Pitchford was tried before a jury with one Black juror in Grenada County, Mississippi (40% Black). The Mississippi Supreme Court held Pitchford forfeited his Batson claim by not rebutting the prosecutor's race-neutral explanations at trial. U.S. District Judge Michael Mills ruled the strikes violated Batson and ordered retrial or release, but the Fifth Circuit reversed, holding the state court decision was not "objectively unreasonable" under the Antiterrorism and Effective Death Penalty Act (AEDPA). Pitchford argues Evans used strikes to remove 80% of eligible Black jurors but only 8.3% of eligible white jurors without credible explanations. The case is Connell v. Eye Physicians of Central Florida PLC, Case No. 2023-CA-017660-O, Circuit Court for Orange County, Florida.

Roku Faces Class Action for Removing Camera Feature Without Subscription

Plaintiff Louis Moses filed a class action lawsuit (Case No. 3:26-cv-01422, S.D. Cal.) against Roku Inc. alleging the company removed the Motion Snapshots feature from its Smart Home Cameras in July 2025, forcing customers to pay for a subscription to access still images of detected motion or sound. The lawsuit alleges Roku marketed the cameras in October 2022 as providing motion alerts and access to still images without a subscription, but quietly eliminated this functionality, leaving users unable to review what triggered alerts unless they purchase a subscription. Moses argues Roku's conduct constitutes "software tethering" where manufacturers use software updates to render devices less functional, forcing consumers to buy new products or subscriptions. He seeks certification of a class including anyone worldwide who purchased Roku Smart Home Cameras before July 16, 2025 and still owned the device on or after that date, asserting breach of contract, breach of implied warranties, Computer Fraud and Abuse Act violations, breach of quasi-contract, unjust enrichment, and trespass to chattels.

Regulatory Guidance

European Parliament Rejects Extension of CSAM Scanning Rules

The European Parliament voted 311 against extending rules that exempt tech platforms from strict privacy rules to scan for child sexual abuse material (CSAM), effective next Friday. The law allowed platforms to use scanning tools to detect CSAM and report it to law enforcement. Critics argued scanning enables mass surveillance and violates privacy rights, citing false positives that led to innocent people being accused. Digital rights nonprofit eDRI stated the scanning targets everyone, not just suspects, without credible effectiveness statistics. Europol Executive Director Catherine De Bolle expressed alarm, noting Europol processed 1.1 million CyberTips from scanning in the prior year and predicting a "serious reduction" in investigative leads. Tech companies including Google, Snapchat, Microsoft, TikTok, and Meta released a joint statement expressing deep concern, stating the vote reduces legal clarity that enabled voluntary CSAM detection for nearly 20 years. The companies stated their hash matching systems create digital fingerprints identifying known CSAM with high precision while adhering to privacy principles. The vote followed weeks of infighting between Parliament, national governments, and European commissioners. Parliament has negotiated a permanent CSAM detection framework since November 2023 without reaching agreement.

Supreme Court to Hear Birthright Citizenship Challenge April 1

The Supreme Court will hear oral arguments April 1 in Trump v. Barbara, a challenge to President Trump's January 2025 executive order ending birthright citizenship for babies born in the United States if their parents are in the country illegally or temporarily. The Citizenship Clause of the 14th Amendment confers citizenship on anyone "born in the United States, and subject to the jurisdiction thereof." All lower courts that have weighed in ruled the order is unconstitutional. The administration argues the clause was intended to overrule Dred Scott and give citizenship to formerly enslaved people and their children, not children of aliens temporarily present or illegal aliens. Challengers counter the administration "is asking for nothing less than a remaking of our Nation's constitutional foundations" that "would cast a shadow over the citizenship of millions upon millions of Americans, going back generations." The executive order was temporarily blocked by multiple federal judges and has never gone into effect. U.S. District Judge Joseph Laplante issued a preliminary injunction July 10 barring the administration from enforcing the order against babies born after February 20, 2025 who would be denied citizenship, concluding the order "contradicts the text of the Fourteenth Amendment and the century-old untouched precedent that interprets it."

Supreme Court Schedules Temporary Protected Status Arguments for April 29

The Supreme Court announced it will hear arguments April 29 on the Trump administration's efforts to end the Temporary Protected Status (TPS) program for several thousand Syrians and roughly 350,000 Haitians living in the United States. The Court will hear Mullin v. Doe (Syrian nationals) combined with Trump v. Miot (Haitian nationals). Federal judges in New York and Washington, D.C. postponed termination of the TPS program, which allows nationals of designated countries to remain in the United States and work because of adverse conditions in their home countries. The April 29 arguments are the final day of regularly scheduled oral arguments for the April session.

Privacy Developments

FBI Confirms Continued Warrantless Purchase of Americans' Location Data

FBI Director Kash Patel testified to the Senate that the FBI purchases commercially available location data of Americans, stating the agency "uses all tools to do our mission" and that such purchases are "consistent with the Constitution and the laws under the Electronic Communications Privacy Act." When Senator Ron Wyden asked if the FBI would commit to not buying Americans' location data, Patel declined and claimed the purchases have led to valuable intelligence. The practice exploits a perceived loophole in the Supreme Court's 2018 Carpenter v. United States ruling, which required warrants for cell site location information (CSLI) obtained from cell service providers for 127 days of tracking. Federal agencies argue location data purchased from data brokers and ad networks, including real-time bidding (RTB) data that ties location to specific devices, differs from CSLI and can be obtained without warrants. In 2023, then-FBI Director Christopher Wray admitted to Congress that the FBI was buying location data like CBP, ICE, Secret Service, IRS, and federal prisons, claiming the process was "court-authorized" but failing to produce supporting court documents.

Iran-Linked Hackers Breach FBI Director Kash Patel's Personal Email

The FBI confirmed that Iran-linked hacking group Handala stole and leaked photographs and emails from FBI Director Kash Patel's personal email account, stating the information is "historical in nature and involves no government information." The Justice Department confirmed to Reuters the documents appear authentic. The group published photos and mundane emails from 2010 and 2019 in a blog post claiming the leak was retaliation for FBI actions last week involving takedown of several Handala websites and a $10 million bounty on group members. The Justice Department seized four domains (Justicehomeland.org, Handala-Hack.to, Karmabelow80.org, and Handala-Redwanted.to) allegedly used by Iran's Ministry of Intelligence and Security (MOIS) since 2022. Handala created new websites and issued threats to U.S. and Israeli officials throughout the week. The FBI stated Handala "has frequently targeted U.S. government officials" and the $10 million reward remains active. Handala previously claimed responsibility for a cyberattack on a Michigan medical device firm and leaked alleged personal information of Lockheed Martin officials.

Policy Changes

UK Government Prepares Limits on Political Donations Following Foreign Interference Warnings

The British government is preparing to tighten rules on political donations after two major reports warned that foreign interference in U.K. democracy is becoming more complex and harder to counter. The Rycroft Review on foreign financial interference and a cross-party parliamentary Foreign Affairs Committee report on foreign information manipulation and interference (FIMI) warn that hostile actors conduct sustained and sophisticated campaigns to interfere in democratic processes by exploiting divisive issues. The parliamentary report states that government sanctions against dozens of organizations and individuals responsible for Russian information warfare are "dwarfed by the global scale of the problem," citing Moldova where Russian disinformation reached tens of millions of views during elections. The reports raise concerns about wealthy individuals with significant global reach, specifically citing Professor Vera Tolz-Zilitinkevic's assessment that Elon Musk's influence in the U.K. may exceed Russia's. The government plans to impose a temporary ban on cryptocurrency donations and cap contributions from overseas voters at £100,000 annually to limit disproportionate financial influence from individuals with limited day-to-day ties to the U.K. However, the temporary ban would not address cases where cryptocurrency donations are converted through permissible donors into regular currency before contribution, as The Observer reported Reform UK did.

Compliance Takeaways