Get tomorrow's brief in your inbox
April 17, 2026
California AG Sues Federal Agency Over TikTok Data Sharing California Attorney General Rob Bonta filed a lawsuit challenging a federal policy directive that forces state agencies to share data collected from TikTok ban implementations. The suit claims the data-sharing mandate violates California's Consumer Privacy Act and exceeds federal authority under the Administrative Procedure Act. California agencies collected user device identifiers, app usage data, and geolocation information during TikTok enforcement and classification processes. The federal government argues the data is necessary for national security threat assessments. The case raises questions about which level of government controls data collected under federally mandated state enforcement actions. This affects compliance teams managing state-level data collection programs tied to federal directives.
€275,000 GDPR Fine for Health Data Processing Without Legal Basis GDPRhub documents a €275,000 fine against a healthcare provider that processed patient health data without establishing a valid legal basis under GDPR Article 6. The data controller assumed legitimate interest justified the processing but failed to conduct the required balancing test. The supervisory authority found legitimate interest cannot apply when less intrusive alternatives exist and patients have reasonable expectations of control over their health information. The decision clarifies that healthcare providers cannot default to legitimate interest for processing special category data under Article 9 without first exhausting consent or other specified legal bases. Compliance teams should audit health data processing activities to confirm legal basis documentation exists and matches the actual processing purpose.
FTC Challenges Subscription Cancellation Practices Multiple businesses face FTC enforcement over subscription cancellation practices that violate the "click to cancel" rule finalized in 2024. Companies made online sign-up easy but required phone calls, chat sessions, or mailed letters to cancel. The FTC argues this violates the principle that cancellation must be "at least as easy" as sign-up. Penalties range from $50,000 to $500,000 depending on company size and duration of the practice. The enforcement wave follows the rule's effectiveness date in mid-2025. Businesses offering subscription services should audit cancellation workflows to ensure parity with sign-up processes across all channels.
Ninth Circuit Narrows Computer Fraud and Abuse Act Scope The Ninth Circuit ruled that using a work computer for personal purposes does not constitute "exceeding authorized access" under the Computer Fraud and Abuse Act (18 U.S.C. § 1030). The decision follows the Supreme Court's Van Buren framework that CFAA liability requires accessing data one is not entitled to see, not merely using permitted access for an improper purpose. The plaintiff was terminated for using work systems to research personal business interests during work hours. The company argued this violated acceptable use policies and constituted unauthorized access. The court held that policy violations alone do not create CFAA liability when the employee had valid credentials and accessed systems they were permitted to use. This affects employee monitoring programs and termination decisions based on acceptable use policy violations.
Class Action Over Biometric Data in Workplace Surveillance Expands A federal court granted class certification in a lawsuit challenging workplace facial recognition systems under Illinois' Biometric Information Privacy Act (740 ILCS 14/). The plaintiff class includes all employees and visitors who entered company facilities equipped with facial recognition systems between 2020 and 2025. The company argued it obtained written consent through employment agreements and visitor sign-in sheets. The court found the consent notices did not meet BIPA's specificity requirements because they described biometric collection generically without identifying the retention schedule or third-party vendors. Each BIPA violation carries statutory damages of $1,000 to $5,000. With approximately 12,000 class members, potential exposure ranges from $12 million to $60 million. Organizations using biometric systems in Illinois should review consent forms for BIPA compliance.
Website Accessibility Lawsuit Dismissed Under Primary Jurisdiction Doctrine A district court dismissed an ADA website accessibility lawsuit, ruling that the FCC has primary jurisdiction over web accessibility standards. The plaintiff claimed the defendant's website violated the Americans with Disabilities Act by failing to provide screen reader compatibility. The court found that web accessibility standards intersect with FCC authority over communications technology under Section 255 of the Communications Act. The dismissal does not prevent future litigation but delays proceedings until the FCC clarifies applicable standards. The decision conflicts with other circuits that allow ADA claims to proceed without FCC involvement. Businesses defending accessibility claims may argue for dismissal pending FCC rulemaking, but success depends on jurisdiction.
CISA Releases Zero Trust Maturity Model 3.0 The Cybersecurity and Infrastructure Security Agency published Zero Trust Architecture Maturity Model version 3.0, establishing five maturity levels (Traditional, Initial, Advanced, Optimal, Transformational) across seven pillars. Federal agencies must achieve "Advanced" level by fiscal year 2027 and "Optimal" by 2030 under Office of Management and Budget memorandums. While the model targets federal agencies, government contractors and critical infrastructure operators face indirect pressure to adopt similar standards. The model includes specific technical requirements for identity verification, device compliance checking, network segmentation, and continuous monitoring. Private sector organizations pursuing federal contracts or operating in critical infrastructure sectors should assess current posture against the model's Advanced tier requirements.
State Data Breach Notification Deadlines Tightening Eight states enacted legislation in early 2026 reducing breach notification timelines. California, Texas, Florida, New York, Massachusetts, Virginia, Colorado, and Connecticut now require notification within 30 days of breach discovery. Previous timelines ranged from 45 to 90 days or used vague "reasonable time" standards. The trend follows the EU's 72-hour GDPR requirement. Organizations operating in multiple states should adjust incident response plans to meet the shortest applicable deadline. Delayed notification in any covered state can trigger enforcement even if other states received timely notice.
SEC Proposes Cybersecurity Disclosure Amendments The Securities and Exchange Commission proposed amendments expanding cybersecurity disclosure requirements for public companies. Material cybersecurity incidents must be disclosed within four business days of materiality determination, down from the current 10-day window. The proposal adds mandatory disclosure of specific incident types including ransomware payments over $100,000 and any breach affecting over 100,000 customer records. Annual reports must include quantitative risk metrics such as mean time to detect intrusions, percentage of systems with multi-factor authentication, and third-party vendor security assessment results. Public companies should begin tracking these metrics to prepare for disclosure requirements if the rule is finalized.
California Privacy Protection Agency Issues CPRA Enforcement Guidance The California Privacy Protection Agency released enforcement guidance clarifying how it will prioritize investigations under the California Privacy Rights Act. The agency will focus on violations involving sensitive personal information (biometric data, geolocation, financial data, health data), dark patterns that manipulate consumer choice, and failures to honor opt-out requests. First-time violations without aggravating factors may receive cure periods if the business demonstrates good faith compliance efforts. Violations involving deceptive practices or sensitive data skip cure periods and proceed directly to enforcement. Administrative penalties range from $2,500 to $7,500 per violation. Businesses subject to CPRA should review data handling practices for sensitive information categories and ensure opt-out mechanisms function correctly.
UK ICO Publishes Guidance on AI and Data Protection The UK Information Commissioner's Office published detailed guidance on AI system compliance with UK GDPR. The guidance addresses lawful basis for automated decision-making, data minimization in model training, and transparency obligations for AI-generated content. Organizations must document the legal basis for each data processing activity in the AI lifecycle, from training data collection through deployment and monitoring. The ICO expects organizations to conduct Data Protection Impact Assessments for AI systems that process personal data at scale or make consequential decisions. The guidance applies to UK-based organizations and non-UK organizations offering services to UK residents. US companies with UK customers should review AI systems for GDPR compliance.
Virginia Enacts Comprehensive Privacy Law Amendments Virginia amended the Consumer Data Protection Act to expand covered entities and add new consumer rights. The law now applies to businesses controlling or processing personal data of 50,000 Virginia consumers (down from 100,000) or deriving 50% of revenue from data sales while handling data of 25,000 consumers (down from 50,000). New rights include the right to correct inaccurate data and the right to appeal opt-out denials. The amendments take effect January 1, 2027. Businesses previously exempt under the higher thresholds should assess whether the new thresholds trigger coverage. The Attorney General's office indicated it will publish model forms for consumer rights requests by mid-2026.
Federal Trade Commission Updates COPPA Rule for Social Media The FTC finalized amendments to the Children's Online Privacy Protection Act Rule addressing social media platform obligations. Platforms must obtain separate parental consent for each commercial use of children's data, including targeted advertising, algorithm training, and data sales to third parties. The blanket consent previously accepted is no longer sufficient. Platforms must provide annual reports to parents detailing what data was collected from their children and how it was used. The rule adds a "duty to delete" requiring platforms to delete child data when it is no longer necessary for the purpose it was collected. Violations carry civil penalties up to $51,744 per violation. The amendments take effect October 1, 2026. Companies operating platforms, apps, or services directed to children under 13 should revise consent workflows and implement data deletion procedures.
National Institute of Standards and Technology Releases Post-Quantum Cryptography Standards NIST published final standards for three post-quantum cryptographic algorithms designed to resist attacks from quantum computers. The standards cover encryption (CRYSTALS-KYBER, now standardized as ML-KEM), digital signatures (CRYSTALS-Dilithium and SPHINCS+, standardized as ML-DSA and SLH-DSA). NIST recommends organizations begin planning migration from current RSA and ECC algorithms. Federal agencies must implement post-quantum cryptography for national security systems by 2030 and non-national-security systems by 2035 under National Security Memorandum 10. Private sector organizations handling long-lived sensitive data or operating in regulated industries should assess cryptographic dependencies and develop migration roadmaps. Data encrypted today with current algorithms could be harvested and decrypted once quantum computers become viable.
European Data Protection Board Issues Guidelines on Data Transfers to US The European Data Protection Board released guidelines on data transfers to the United States following the EU-US Data Privacy Framework implementation. Organizations relying on the framework must conduct transfer impact assessments verifying that US recipient organizations maintain active certification and implement supplementary measures where necessary. The guidelines identify specific supplementary measures including encryption, pseudonymization, and contractual restrictions on US government access. Organizations that experienced Schrems II invalidation issues should review updated standard contractual clauses and framework certifications. US companies receiving personal data from EU counterparts must maintain Data Privacy Framework certification and document supplementary measures.
Multi-State Privacy Law Compliance Matrix Thirteen US states now have comprehensive privacy laws in effect or taking effect in 2026-2027. Compliance obligations vary across notice requirements, opt-out mechanisms, data subject rights, and penalties. Organizations subject to multiple state laws should implement the strictest requirement as the baseline. Virginia's 50,000-consumer threshold is now the lowest among comprehensive privacy states. Connecticut and Colorado have the shortest breach notification timelines at 30 days. California has the broadest private right of action through CPRA. A compliance matrix covering all 13 states is necessary for multi-state operations. Organizations should conduct a gap analysis against the strictest requirements across all applicable states.
Vendor Risk Management for AI Service Providers Organizations using third-party AI services face vicarious liability for vendor data processing practices. Contracts with AI vendors should specify data usage restrictions, training data sources, retention periods, and deletion procedures. Organizations must conduct due diligence on vendor security practices, including how vendor systems protect input data, whether input data is used for model training, and what subprocessors have access to organizational data. The FTC has indicated it will hold organizations responsible for deceptive or unfair AI practices by their vendors. Vendor contracts should include representations and warranties on AI training data provenance, indemnification for third-party IP claims, and audit rights. Organizations should maintain an inventory of AI vendors and their data processing activities.
Preparing for SEC Cybersecurity Metrics Disclosure If the SEC's proposed cybersecurity disclosure amendments are finalized, public companies will need to report quantitative security metrics in annual filings. Organizations should begin tracking mean time to detect (MTTD) and mean time to respond (MTTR) for security incidents, multi-factor authentication adoption rates across all systems, percentage of critical vulnerabilities patched within SLAs, and vendor security assessment completion rates. Legal and finance teams should coordinate with information security teams to define metrics, establish measurement processes, and determine materiality thresholds. The proposal requires disclosure of process and methodology used to calculate metrics. Organizations should document metric definitions and calculation procedures to ensure consistency across reporting periods.
Biometric Data Compliance in Employee Monitoring Workplace surveillance systems using facial recognition, fingerprint scanners, voice analysis, or gait recognition trigger biometric privacy laws in Illinois, Texas, Washington, California, New York, and Arkansas. Illinois BIPA has the most stringent requirements and a private right of action. Compliance requires written notice describing what biometric data is collected, how it will be used, and how long it will be retained. Organizations must obtain written consent separate from general employment agreements or visitor waivers. Biometric data cannot be sold or disclosed to third parties without separate consent. Organizations must publish retention and destruction policies. Violations in Illinois carry statutory damages of $1,000 per negligent violation and $5,000 per reckless violation. Organizations deploying biometric systems should conduct a jurisdictional analysis and implement state-specific consent workflows.
This briefing is produced by Carolina Clear Tech for informational purposes. It does not constitute legal advice. Consult with qualified legal counsel for guidance on specific compliance obligations.