← Carolina Clear Tech

Legal & Privacy Brief

2026-03-31

Listen to this brief (24:27)

Download MP3
Show Notes

Show Notes - 2026-03-31

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 31, 2026

Today: Spanish telecom Orange fined €230,000 for failing to prevent unauthorized eSIM duplication. Italian banking giant Intesa Sanpaolo faces €31.8 million penalty for employee accessing 3,573 customer accounts without authorization for over two years. Dutch court orders X to ban Grok from generating non-consensual intimate images and CSAM under GDPR violations.

Enforcement Actions

Italian Banking Giant Fined €31.8 Million for Unauthorized Account Access

Italy's Data Protection Authority fined Intesa Sanpaolo SpA €31.8 million ($36 million) for security failures that allowed an employee to access the banking information of 3,573 customers between February 2022 and April 2024 without proper authorization. The regulator found serious shortcomings in personal data security due to inadequate technical and organizational measures. The bank's operating model allowed operators to query the entire customer base without adequate controls to prevent or identify unauthorized access. The affected customers were considered "high-risk" and included well-known public figures. The bank also failed to notify customers within legally required deadlines and the notifications sent were incomplete.

Spanish DPA Fines Orange €230,000 for eSIM Duplication Failure (Case EXP202305035)

Spain's data protection authority fined Orange Espagne S.A.U. €230,000 for violating Article 32 GDPR after the telecom company issued a duplicate eSIM card to a third party without the data subject's consent. Despite issuing an internal warning after detecting identity theft attempts, Orange employees later issued a duplicate eSIM that was successfully activated. The third party used a manipulated copy of the data subject's ID and changed the email address associated with the account. The data subject only became aware of the breach after receiving notifications about fraudulent bank transactions and losing phone coverage. The DPA found this was not an isolated incident but a general weakness in Orange's security policy, and ordered the company to ensure its processing activities comply with Article 32 GDPR requirements.

State Department Reissues $10 Million Reward for Iranian Hackers

The State Department reissued a $10 million reward for information on Iranian hackers, specifically naming two entities: Handala and Parsian Afzar Rayan Borna. The notice followed FBI confirmation that Iranian hackers gained access to FBI Director Kash Patel's personal Gmail account. Handala, which operates under Iran's Ministry of Intelligence and Security (MOIS), has claimed responsibility for recent cyberattacks on U.S. and Israeli companies including medical device firm Stryker. The FBI has repeatedly taken down Handala websites, including several over the weekend hosting information stolen from Patel's account. Parsian Afzar Rayan Borna is an Iranian IT company with ties to MOIS that allegedly assisted state hackers in targeting Albania's government in 2022 and engages in domestic surveillance.

Trump DOJ Settles Flynn Malicious Prosecution Lawsuit for $1.2 Million

The Justice Department reached an agreement to pay President Trump's former national security adviser Michael Flynn $1.2 million to settle his malicious prosecution lawsuit. Flynn's lawsuit had been dismissed by a federal judge in 2024 after Biden's DOJ responded to it. Flynn previously pleaded guilty to charges brought by special counsel Robert Mueller for lying to FBI agents about contacts with Russia's ambassador, and the Trump Justice Department under Attorney General William Barr moved to drop the case in 2020. Trump later pardoned Flynn. Critics argue the settlement amounts to a political payout from public funds for a lawsuit that was no longer viable, as defendants typically cannot both plead guilty and successfully claim malicious prosecution.

Russian Court Sentences Card Fraud Ringleader 'Flint' and 25 Associates

A Russian military court sentenced 26 members of the cybercrime group Flint24 to prison terms up to 15 years for forming an organized criminal group and illegally trafficking payment card data. Alexei Stroganov, known as "Flint," received one of the longest sentences. The group operated between 2014 and March 2020, stealing payment card data from victims in Russia, post-Soviet countries, the EU, and the United States, distributing the data through approximately 90 online stores. Law enforcement seized about $432,000 in cash during March 2020 raids at 60 locations. Stroganov is separately wanted by U.S. authorities on wire fraud, bank fraud, and aggravated identity theft charges for a conspiracy that allegedly harvested data linked to hundreds of millions of payment cards, generating losses exceeding $35 million for financial institutions.

Litigation Updates

Louis Vuitton Faces Second Class Action Over Salesforce Data Breach (Case 1:26-cv-00702)

Plaintiff Adriana Winkler filed a class action in the Southern District of New York alleging Louis Vuitton North America failed to protect consumers' personally identifiable information from a data breach involving its Salesforce database. The lawsuit claims Louis Vuitton failed to implement basic security measures such as restricting network access, enabling multi-factor authentication, and using security tools available in Salesforce Shield despite warnings from Salesforce and Google's Threat Intelligence Group that ShinyHunters was using voice phishing to gain unauthorized access. The compromised data includes names, addresses, dates of birth, driver's license numbers, and partial Social Security numbers. Winkler argues the breach resulted from Louis Vuitton ignoring extensive and express warnings. The lawsuit seeks certification of a nationwide class, declaratory and injunctive relief, and damages. This is the second wave of Louis Vuitton data breach litigation, following lawsuits filed in August after the breach allegedly impacted over 400,000 people worldwide.

GlaxoSmithKline Boostrix Class Action Settlement (Case 2:21-cv-04869)

GlaxoSmithKline agreed to settle class action claims in the Eastern District of New York that its "Big Bad Cough" advertising campaign misled viewers about Boostrix's ability to prevent whooping cough. The settlement benefits adults who viewed the campaign and either lived in New York or were vaccinated with Boostrix in New York between May 20, 2016 and May 20, 2020. Class members providing proof of vaccination can receive $50; those submitting attestation without proof can receive $10. The exclusion and objection deadline is May 11, 2026. Final approval hearing is scheduled for July 2, 2026. Claim forms must be submitted by June 8, 2026. GSK has not admitted wrongdoing.

SlimQuick Class Action Claims Weight-Loss Supplements Unsafe (Case 3:26-cv-00696)

Plaintiffs Maria Nelson and Michelle Garza filed a class action in the Southern District of California against Platinum US Distribution, WellNX Life Sciences, and WellNX Life Sciences DR on February 4, alleging false advertising of SlimQuick weight-loss supplements. The complaint alleges the companies falsely claim SlimQuick increases metabolism, reduces appetite, and is made with safe and natural ingredients. Plaintiffs allege SlimQuick contains a dangerous amount of green tea extract that can cause liver injury and liver failure, and that no ingredients in SlimQuick individually or in combination safely and effectively increase weight loss. The lawsuit seeks to represent California purchasers and alleges violations of California's Consumers Legal Remedies Act, Unfair Competition Law, and False Advertising Law. Plaintiffs seek class certification, at least $5 million in damages, and fees and costs.

Supreme Court to Hear Pregnancy Discrimination Affirmative Defense Case (Younge v. Fulton Judicial Circuit DA)

The Supreme Court granted review in Younge v. Fulton Judicial Circuit District Attorney's Office, a procedural question arising from a pregnancy discrimination case. The case examines whether a defendant can raise an affirmative defense later in proceedings when it did not raise that defense in the answer to the plaintiff's complaint. Jasmine Younge filed a federal civil rights suit claiming pregnancy discrimination against the Fulton County District Attorney's Office, where she was deputy chief of staff. The Civil Rights Act of 1964 carves out an exemption for elected officials and their "personal staff." The DA's office did not raise the exemption when responding to Younge's complaint, but sought to rely on it when filing for summary judgment. The district court allowed the defense and ruled for the DA's office. The 11th Circuit affirmed. The Supreme Court's decision will affect procedural standards for when affirmative defenses must be raised.

Supreme Court Dissent: Jarkesy Decision and Jury Trial Rights in SEC Cases

A Supreme Court dissent examined the Jarkesy case, in which the Court held that George Jarkesy was entitled to a jury trial for SEC fraud charges. The case took nearly a decade to reach a real court after Jarkesy was prosecuted in an SEC administrative tribunal. In 2013, the SEC declined to bring its case in federal court and instead routed the prosecution to an in-house administrative law judge. The proceedings took seven years, with no jury, looser rules of evidence, and a judge embedded within the prosecuting agency. The Supreme Court ultimately affirmed Jarkesy's right to a jury trial under the Seventh Amendment. The majority worried about expanding the administrative state at the expense of constitutional rights. Dissenters warned that requiring jury trials would impair efficient regulation. Post-Dodd-Frank, the SEC could pursue harsh penalties including large financial penalties and industry exclusion through in-house tribunals rather than federal court. Studies showed the SEC won approximately 90% of in-house proceedings compared to 69% in federal court.

Regulatory Guidance

Dutch Court Bans X from Generating Non-Consensual Intimate Images via Grok (Case C/13/783613 / KG ZA 26-120)

The Amsterdam District Court banned X Internet Unlimited Company from generating and distributing non-consensual intimate imagery and child sexual abuse material (CSAM) through its Grok AI chatbot, and prohibited X from offering Grok functionalities as long as violations occur. Stichting Offlimits estimated Grok generated approximately 3 million sexualized images between December 29, 2025 and January 9, 2026, of which approximately 23,000 depicted children. The court held that X processed personal data in its image generating feature and failed to verify whether consent had been obtained from data subjects. The court found X had not implemented sufficient safeguards and questioned the effectiveness of measures it claimed to have implemented. The court rejected X's argument that users, not X, generated the images and that Grok was merely a tool. The EU Commission launched a Digital Services Act investigation in January 2026 into whether X met its obligations relating to dissemination of illegal content.

European Commission Downplays ShinyHunters Attack on Europa.eu Portal

The European Commission confirmed a cyberattack on its Europa.eu web portal but downplayed the impact, stating no evidence showed internal systems were compromised. ShinyHunters claimed responsibility and alleged it stole over 350 gigabytes of data including databases, emails, and internal documents. The Commission spokesperson confirmed parts of the Europa platform are hosted on Amazon cloud infrastructure and said defense systems immediately detected malicious activities and implemented risk mitigation measures. The Commission stated affected domains were limited to Europa.eu public websites and described potentially compromised data as "potentially already in the public domain." The Commission declined to specify what data was accessed, how many users were affected, or whether personal data was involved.

Healthcare Software Firm CareCloud Reports Potential Patient Data Leak to SEC

Electronic health records provider CareCloud notified the SEC that a network disruption on March 16 affected one of its six EHR environments for eight hours after a hacker temporarily accessed the system. By March 24, CareCloud determined the incident was material given the sensitivity of potentially affected information. The company is still assessing whether and to what extent patient information or other data was accessed or exfiltrated. Potential consequences include remediation and response costs, legal and regulatory matters, notification obligations, and effects on patients, customers, reputation, and operations. CareCloud serves over 45,000 healthcare providers and reported $120.5 million in revenue last fiscal year. No hacking group has claimed responsibility.

Privacy Developments

White House App Strips Privacy Consent Dialogs and Tracks GPS Location

Security researchers discovered the official White House mobile app silently injects JavaScript and CSS into third-party websites viewed through its built-in browser to strip away cookie consent dialogs, GDPR banners, login gates, and paywalls. The app hides OneTrust popups, privacy banners, consent management platform boxes, and forces body overflow to re-enable scrolling. A MutationObserver continuously removes consent elements that get dynamically added. The app also contains OneSignal's full GPS tracking pipeline that captures latitude, longitude, accuracy, timestamp, foreground/background status, and whether tracking is fine (GPS) or coarse (network). A background service continues capturing location even when the app is not active. The tracking requires user permission grants and a flag called _isShared to be set to true, but the entire pipeline including permission strings and background location service code is compiled into the app.

FBI Director Kash Patel's Personal Email Breached by Iranian Hackers

Iran-linked hacking group Handala breached FBI Director Kash Patel's personal Gmail account and published photographs and over 300 emails dating between 2010 and 2019. The FBI confirmed the breach involves historical communications. Email verification tools confirmed several emails are authentic, including some Patel sent from his Justice Department email address to his Gmail account in 2014, meaning the breach includes government information despite FBI statements to the contrary. The breach demonstrates poor operational security practices by a senior law enforcement official who routed DOJ email to a personal account.

Apple Camera Indicator Lights Provide Strong Privacy Protection

A security analysis found Apple's on-display camera indicator system is well-designed to alert users when the camera is active. While hardware indicator lights are generally more secure than software indicators because they are harder to tamper with, Apple's implementation goes beyond simplistic software rendering. The system is designed such that malicious software cannot draw over the pixels where the camera indicator is rendered to disguise camera use. The implementation provides effective protection against malware surreptitiously starting camera recording.

Policy Changes

Democrats Urge FCC to Investigate Foreign Funding of Ellison's Warner Bros Acquisition

Seven Democratic lawmakers urged the FCC to investigate Saudi and Chinese backing of Larry Ellison's $111 billion acquisition of Warner Brothers, citing national security concerns. The letter highlighted that China's Tencent has a relationship with the Chinese Communist Party and Chinese law requires domestic technology companies to cooperate with state intelligence services. The lawmakers expressed concern that Tencent's stake in the parent company of CBS News and CNN creates avenues for potential foreign influence over American broadcast journalism. The deal involves $25 billion in Saudi, Chinese, and other foreign funding. Three Middle Eastern sovereign wealth funds (Saudi Arabia's Public Investment Fund, Qatar Investment Authority, and Abu Dhabi Investment Authority) agreed to forgo governance rights including board representation. FCC Chairman Brendan Carr, who previously criticized China's relationship with TikTok, has been silent on this transaction.

Pentagon Restricts Press Credentials and Reporter Access Under Hegseth

Defense Secretary Pete Hegseth ordered major news organizations to give up their Pentagon press room desks to MAGA-aligned outlets, with NPR's desk going to Breitbart News. Reporters were prohibited from roaming Pentagon hallways and restricted to a single corridor outside the press room. Hegseth conditioned issuance of press credentials on reporters effectively giving military brass the right to censor or sanitize reports. Almost the entire Pentagon press corps, including AP, New York Times, Fox News, and USNI News, moved out of the building in October 2025. The Pentagon abruptly banned photographers from press briefings after Hegseth's staff found images of him unflattering. The restrictions limit reporters' ability to develop relationships with sources and obtain information that deviates from official statements.

Supreme Court to Hear Birthright Citizenship Challenge (Trump v. Barbara)

The Supreme Court will hear oral arguments on April 1 in Trump v. Barbara, a challenge to President Trump's January 2025 executive order seeking to end birthright citizenship. The case involves profound constitutional questions about the 14th Amendment and whether children born in the United States to parents who are not citizens or legal permanent residents are entitled to citizenship. The executive order invokes concepts of "mother," "father," "parents," and "domicile" despite none of these words appearing in the text of the 14th Amendment or Section 1401(a) of the Immigration and Nationality Act. The case raises questions about whether the executive order's parent-based rules are supported by constitutional text or represent extra-textual interpretation similar to the trimester rules in Roe v. Wade.

EFF Executive Director Discusses Privacy Book on The Daily Show

EFF Executive Director Cindy Cohn appeared on The Daily Show on March 30 to discuss her book "Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance." The book details her role representing technology users, innovators, whistleblowers, and researchers during the Crypto Wars of the 1990s, battles over NSA dragnet internet spying in the 2000s, and fights against FBI gag orders. EFF has defended civil liberties in the digital world for over 35 years, with lawyers, activists, and technologists working on issues including age verification, AI, and government surveillance. The organization is supported by over 30,000 members.

Compliance Takeaways