Get tomorrow's brief in your inbox
April 15, 2026 | carolinacleartech.com
Google faces $5 billion class action over Chrome Incognito tracking Google is defending against a $5 billion class action lawsuit alleging it tracked users' browsing in Chrome's Incognito mode without proper consent. Plaintiffs argue Google violated federal wiretap laws and California privacy statutes by collecting data even when users believed they were browsing privately. The case centers on whether Incognito mode's disclosures were sufficient to obtain consent for tracking. This highlights ongoing scrutiny of browser privacy features and the legal risks of collecting data when users have reasonable privacy expectations. Companies should audit tracking mechanisms in private browsing modes and ensure disclosures clearly explain what data is collected.
Texas investigates TikTok over child safety practices Texas Attorney General Ken Paxton announced an investigation into TikTok's compliance with state child safety laws, focusing on whether the platform adequately protects minors from harmful content and predatory behavior. The investigation follows similar actions by other states and federal agencies. TikTok faces potential violations of Texas's child online safety laws if it failed to implement age-appropriate safeguards. This is part of a broader regulatory push to hold social media platforms accountable for protecting minors. Organizations operating online platforms accessible to children should review state-specific child safety requirements and ensure age verification and content moderation systems meet compliance standards.
California AG settles with data broker over unauthorized location tracking California Attorney General Rob Bonta secured a settlement with a data broker that allegedly sold precise location data without obtaining proper consent from consumers. The settlement requires the company to cease unauthorized data sales, implement consent mechanisms, and pay civil penalties. The case underscores California's aggressive enforcement of the California Consumer Privacy Act (CCPA) against data brokers. Location data remains a high-priority enforcement area. Businesses collecting or selling location data should verify they have explicit consent and provide clear opt-out mechanisms under CCPA and other state privacy laws.
Apple settles Siri privacy lawsuit for $95 million Apple agreed to pay $95 million to settle a class action lawsuit alleging Siri recorded private conversations without user consent and shared those recordings with third parties for advertising purposes. Plaintiffs claimed Apple violated federal and state wiretap laws. The settlement includes payments to affected users and requires Apple to delete certain stored recordings. This case demonstrates the legal risks of voice-activated technologies that may inadvertently capture sensitive conversations. Companies deploying voice assistants should implement clear consent mechanisms, minimize data retention, and audit third-party data sharing practices.
Meta faces GDPR complaint over political ad targeting practices Privacy advocacy group noyb filed a GDPR complaint against Meta in Ireland, alleging the company's political ad targeting violates EU data protection rules. The complaint argues Meta processes sensitive political data without valid legal basis and fails to provide adequate transparency about how political ads are targeted to users. If upheld, this could result in significant GDPR fines and force changes to Meta's advertising platform. Organizations processing political or sensitive data for targeted advertising should review GDPR's special category data requirements and ensure they have appropriate legal grounds and user consent.
Court upholds AI training on copyrighted works as fair use A federal district court in New York ruled that using copyrighted works to train AI models constitutes fair use under copyright law, rejecting claims by authors and publishers that AI training infringes their rights. The court found the transformative nature of AI training and the non-expressive use of copyrighted material weighs in favor of fair use. This decision provides important clarity for AI developers but may face appeal. The ruling could significantly impact ongoing litigation against OpenAI, Google, and other AI companies. Organizations training AI models on copyrighted content should monitor appeals and consider implementing opt-out mechanisms for rights holders.
FTC issues guidance on AI-powered pricing discrimination The Federal Trade Commission released guidance warning companies that using AI to implement personalized pricing may violate consumer protection laws if it results in unlawful discrimination. The guidance clarifies that algorithmic pricing tools must not discriminate based on protected characteristics such as race, gender, or zip code as a proxy for protected status. The FTC emphasized that lack of intent does not excuse discriminatory outcomes. Businesses using dynamic pricing algorithms should audit their systems for potential discriminatory impacts and ensure pricing models comply with fair lending and consumer protection laws.
CISA releases framework for securing AI systems The Cybersecurity and Infrastructure Security Agency (CISA) published a framework for securing AI systems throughout their lifecycle, covering data integrity, model security, and deployment safeguards. The framework provides actionable guidance for organizations developing or deploying AI, including recommendations for supply chain security, adversarial testing, and incident response. While voluntary, the framework reflects government expectations for AI security practices and may inform future regulatory requirements. Organizations deploying AI should review the CISA framework and integrate its recommendations into their AI governance programs.
SEC proposes expanded cybersecurity disclosure requirements The Securities and Exchange Commission proposed new rules requiring public companies to disclose material cybersecurity incidents within four business days and provide annual reports on cybersecurity risk management and governance. The proposed rules would also mandate disclosure of board cybersecurity expertise. This represents a significant expansion of disclosure obligations beyond the 2023 incident reporting rules. Public companies should prepare to meet shortened reporting timelines and ensure their incident response plans include procedures for legal and disclosure review within the four-day window.
Montana passes comprehensive privacy law with private right of action Montana enacted a comprehensive consumer privacy law that takes effect January 1, 2027. The law includes familiar rights such as access, deletion, and opt-out of targeted advertising, but notably includes a private right of action allowing consumers to sue companies directly for violations. This makes Montana one of only a few states to provide private enforcement. The law applies to businesses processing data of 50,000 or more Montana consumers or deriving 25% of revenue from data sales. Companies should assess whether they meet Montana's applicability thresholds and prepare compliance programs, including incident response procedures for potential consumer lawsuits.
EDPB adopts opinion on international data transfers post-Schrems II The European Data Protection Board (EDPB) adopted an opinion providing additional guidance on implementing the Schrems II decision for international data transfers. The opinion clarifies that companies must conduct transfer impact assessments for each destination country and evaluate whether local laws allow government access to transferred data. The guidance emphasizes that Standard Contractual Clauses alone are insufficient without supplementary measures when transferring data to countries with invasive surveillance laws. Organizations transferring personal data outside the EU should conduct or update transfer impact assessments and implement technical safeguards such as encryption to mitigate government access risks.
Illinois expands biometric privacy law to cover voice and gait data Illinois amended its Biometric Information Privacy Act (BIPA) to explicitly include voice prints and gait recognition data within its definition of biometric identifiers. The amendment clarifies that companies collecting these data types must obtain written consent and provide notice of retention periods and purposes. Illinois BIPA already allows private lawsuits with statutory damages of $1,000 to $5,000 per violation, making it one of the most litigated privacy laws. The expansion increases litigation risk for companies using voice authentication or behavioral biometrics. Organizations should review whether their products collect voice or gait data and ensure Illinois-compliant consent mechanisms are in place.
DOJ announces updated policy on prosecuting corporate cybersrime The Department of Justice released revised guidelines for prosecuting corporate cybercrime, emphasizing coordination with regulatory agencies and consideration of voluntary disclosure and cooperation when determining charges. The policy creates incentives for companies to self-report data breaches and security incidents by promising reduced penalties for those that promptly disclose violations and cooperate with investigations. The DOJ also clarified it will prioritize cases involving intentional misconduct or repeated failures to address known vulnerabilities. Organizations should evaluate whether their incident response plans include procedures for assessing voluntary disclosure to DOJ and understand the potential benefits and risks of self-reporting.
White House proposes national data broker registry The Biden administration proposed legislation requiring data brokers to register with the FTC and disclose their data collection and sale practices. The proposal would require brokers to provide consumers with free access to their data profiles and offer opt-out mechanisms for data sales. It would also prohibit the sale of sensitive data, including health, financial, and precise location information, without explicit consent. If enacted, this would create the first federal registry of data brokers and significantly expand consumer rights. Data brokers should prepare for potential registration requirements and assess which data categories may require consent under the proposed framework.
California advances bill requiring AI impact assessments California's legislature advanced a bill requiring companies deploying high-risk AI systems to conduct and publish algorithmic impact assessments before deployment. The bill defines high-risk systems as those used for employment decisions, credit underwriting, housing, education, or criminal justice. Assessments must evaluate accuracy, fairness, privacy impacts, and potential discriminatory effects. The bill includes civil penalties for non-compliance and creates a private right of action for individuals harmed by non-compliant AI systems. If passed, California would become the first state to mandate AI impact assessments. Organizations deploying AI in covered use cases should begin developing impact assessment frameworks and consider proactive transparency measures.
Audit incognito and private browsing features - The Google Incognito lawsuit shows courts are scrutinizing whether privacy modes deliver on user expectations. Review tracking mechanisms in private browsing contexts and ensure disclosures clearly explain what data is collected.
Prepare for Montana privacy law's private right of action - Montana's law allowing direct consumer lawsuits takes effect January 2027. Companies meeting applicability thresholds should implement compliance programs now and prepare for potential litigation risk.
Conduct transfer impact assessments for EU data - The EDPB's updated guidance makes clear that Standard Contractual Clauses require supplementary measures when transferring data to countries with government surveillance risks. Audit international data flows and implement encryption or other safeguards.
Review AI systems for pricing discrimination - The FTC's guidance on algorithmic pricing creates legal risk for systems that produce discriminatory outcomes, even without intent. Test dynamic pricing models for disparate impacts based on protected characteristics.
Update biometric consent for Illinois BIPA - Illinois's expansion to cover voice and gait data increases litigation exposure for authentication and behavioral biometric systems. Implement written consent mechanisms and retention disclosures for these data types.
This brief is produced by Carolina Clear Tech using AI-assisted analysis of legal and regulatory news sources. It is for informational purposes only and does not constitute legal advice.