← Carolina Clear Tech

Legal & Privacy Brief

2026-04-18

Listen to this brief (18:51)

Download MP3
Show Notes

Show Notes - 2026-04-18

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 18, 2026

Today: Comcast settles a 2023 data breach class action for $117.5 million with claims due August 14. The House passed a 10-day extension of Section 702 surveillance authority after rejecting Trump's push for a clean reauthorization, keeping warrant requirement debates alive. The Supreme Court ruled 8-0 that oil companies can move Louisiana coastal damage lawsuits to federal court under the federal officer removal statute.

Enforcement Actions

$8.75M Metropolis Parking Practices Settlement (Tennessee AG)

Tennessee Attorney General reached an $8.75 million settlement with Metropolis Technologies Inc. over deceptive parking practices at lots in Nashville, Knoxville, and Memphis. The settlement follows an October 2023 investigation that found Metropolis misled consumers through unclear pricing, inadequate signage, and misleading communications about parking fees and violation notices. The company made it difficult for consumers to obtain refunds and failed to clearly disclose pricing and parking terms. Under the settlement, Metropolis will provide $2.25 million in parking credits to eligible Tennessee drivers (up to two $15 credits per driver) and pay $6.5 million to the state for consumer restitution, legal costs, and administrative expenses. Metropolis denied wrongdoing but agreed to implement business practice changes including clearer signage, accurate rate disclosures, a 15-minute grace period at certain lots, and improved refund procedures. Case: State of Tennessee ex rel. Jonathan Skrmetti v. Metropolis Technologies Inc., Case No. 26-0028-III, Chancery Court of Davidson County, Tennessee.

Litigation Updates

$117.5M Comcast Data Breach Class Action Settlement

Comcast agreed to a $117.5 million class action settlement to resolve claims it failed to protect consumer information from a data breach that occurred October 16-19, 2023, publicly disclosed in December 2023. Plaintiffs argued Comcast could have prevented the breach through reasonable cybersecurity measures. Class members can claim up to $10,000 in compensation for documented out-of-pocket losses (identity theft, fraud, credit expenses, communication charges, credit monitoring costs) plus up to five hours of lost time at $30 per hour, or an alternative $50 cash payment if not claiming expenses. The settlement provides three years of identity defense services through CyEx Financial Shield Complete, including one-bureau credit monitoring, dark web monitoring, real-time authentication alerts, high-risk transaction monitoring, lost wallet protection, $1 million identity theft insurance, and monthly credit score tracking. Exclusion and objection deadline is June 1, 2026. Final approval hearing is July 7, 2026. Case: Hasson v. Comcast Cable Communications LLC, Case No. 2:23-cv-05039-JMY, U.S. District Court for the Eastern District of Pennsylvania.

Vivint Class Action Over Spam Emails and Website Tracking

Plaintiff Kenia Gonzalez filed a class action against Vivint Smart Home LLC on April 2 in California federal court alleging violations of California's Business & Professions Code and Trap and Trace Law. Gonzalez claims Vivint, through affiliate marketers, sent spam emails with misleading headers, spoofed domains, and deceptive subject lines that tricked her into visiting Vivint's website, where she was subjected to illegal digital surveillance through tracking pixels. The email was sent from an address that appeared to be from a friend in Atlanta. The email's metadata and embedded code showed multiple signs of spam evasion and deceptive marketing practices, transmitted through a third-party bulk mailing service with a sending IP that failed authentication checks, indicating spoofing. Gonzalez claims Vivint is responsible for sending more than 100,000 spam emails to individuals with California email addresses each year. She is seeking class certification, $1,000 in damages for each email sent, plus attorney's fees and costs. Case: Gonzalez v. Vivint Smart Home LLC, Case No. 3:26-cv-02103-JLS-BJW, U.S. District Court for the Southern District of California.

Kate Spade Outlet "Comparable Value" Pricing Class Action

Plaintiff Amanda Curry filed a class action on March 5 in Oregon federal court against Tapestry Inc. and Coach Services Inc., claiming Kate Spade outlets falsely advertise discounts by using inflated "comparable value" prices. Curry argues nearly all products sold at Kate Spade outlets bear a "comparable value" price that is always higher than the actual sale price, with discounts of 50% to 70% or more creating the impression of substantial savings. Oregon law prohibits retail price comparisons unless sellers identify the source of the compared price and can show it reflects a bona fide offering by a competitor in the same geographic market for substantially similar goods. Curry argues Kate Spade's "comparable value" prices do not satisfy these requirements and bear no meaningful relationship to actual transaction prices at which identifiable competitors offer substantially similar goods at outlet malls in the same geographic area. She seeks actual or statutory damages, injunctive relief, and declaratory relief under the Oregon Unlawful Trade Practices Act. Case: Curry v. Tapestry Inc., et al., Case No. 6:26-cv-00429, U.S. District Court for the District of Oregon.

Ameriprise Data Breach Class Action

Plaintiff Betty Lackey filed a class action in Minnesota federal court alleging Ameriprise Financial failed to protect client personally identifiable information from a data breach by the ShinyHunters ransomware group in March 2026. Lackey claims Ameriprise has not notified victims that their PII (names, addresses, dates of birth, account information, payment card information, authentication information, financial transaction information, contact information, Social Security numbers) was compromised and that they are at significant risk of identity theft. She argues Ameriprise failed to adequately enhance data security practices despite knowing companies in the financial industry were susceptible targets. Lackey seeks declaratory and injunctive relief and actual, statutory, and punitive damages for a nationwide class. Case: Lackey v. Ameriprise Financial Inc., Case No. 0:26-cv-02128, U.S. District Court for the District of Minnesota.

Supreme Court Rules for Oil Companies in Louisiana Coastal Damage Suit

The Supreme Court ruled 8-0 in Chevron USA Inc. v. Plaquemines Parish, Louisiana, sending a lawsuit seeking to hold oil and gas companies liable for damage to the Louisiana coast back to federal courts. Louisiana parishes had filed the lawsuit in state court arguing companies violated state environmental laws by failing to obtain proper permits or violating permit terms for crude oil production during World War II. The companies sought to transfer the case to federal court citing the federal officer removal statute, which gives federal courts power to hear state court cases filed against federal officers or persons acting under federal officers for acts under color of office. The 5th Circuit agreed companies were "acting under" a federal officer but concluded the lawsuit was not "for or relating to" its acts. Justice Clarence Thomas wrote that the phrase "relating to" requires a connection that is not "tenuous, remote, or peripheral," and concluded Chevron's case fits within that range because the lawsuit "implicates acts by Chevron that are closely connected to the performance of its federal duties."

Supreme Court to Consider Rights of Lawful Permanent Residents Accused of Crimes

Oral argument on Wednesday in Blanche v. Lau will consider the rights of lawful permanent residents accused of committing crimes that put them at risk of removal. Muk Choi Lau, a lawful permanent resident, was arrested in May 2012 for allegedly selling nearly $300,000 worth of counterfeit Coogi shorts. While awaiting trial, he left the U.S. and returned in June 2012 at JFK Airport. Immigration officers determined Lau was subject to the "moral turpitude" exception (dishonest or immoral acts) based on his pending counterfeiting charge and paroled him temporarily rather than admitting him. In June 2013, Lau pleaded guilty to trademark counterfeiting and was sentenced to two years' probation. In March 2014, DHS began removal proceedings on the ground that he was ineligible for admission, treating him as if he was not a lawful permanent resident and requiring him to prove eligibility for admission rather than requiring the government to prove he could be deported. The 2nd Circuit held that immigration officers could not invoke the exception without "clear and convincing evidence" that Lau had committed a disqualifying offense and that officers improperly classified him.

Regulatory Guidance

House Extends Section 702 Surveillance for 10 Days

The House passed stopgap legislation early Friday to extend Section 702 of the Foreign Intelligence Surveillance Act (FISA) for 10 days, following a failed lobbying campaign by the Trump administration. The outcome is a defeat for President Trump and House GOP leaders, who pushed for a clean 18-month reauthorization despite divisions among Republicans. Section 702 allows the intelligence community to collect communications of foreign targets without a warrant, but also picks up personal data of an unknown number of Americans. After days of talks with hardline conservatives over additional privacy protections and imposing a warrant requirement, House Speaker Mike Johnson attempted to put a five-year extension with minor tweaks on the floor, which was rejected, and 20 Republicans blocked an 18-month extension in a separate vote. The legislation was approved by voice vote in the Senate late Friday morning. Privacy advocates in both parties considered the House debate as the best chance to get a warrant requirement added. The administration informed Congress last month that the intelligence court renewed the surveillance program to operate for another year through March 2027, even if lawmakers ultimately fail to reauthorize the statute.

Privacy Developments

FBI Abuse of Section 702 Revealed in Senate Letter

Senator Ron Wyden sent a "Dear Colleague" letter to fellow Senators about FBI abuse of Section 702, revealing a "secret interpretation" of the law that enables surveillance of Americans. Wyden stated that "law-abiding Americans having perfectly legitimate, often sensitive, conversations" could include journalists, foreign aid workers, people with family members overseas, and women trying to get abortion medication from overseas providers. Under current practice, the FBI can query and read the U.S. side of communications without a warrant, treating collected data with a "finders keepers" approach. The NSA collects full conversations being conducted by and with targets overseas (including Americans in the U.S.) and stores them in massive databases, allowing FBI access to untold amounts of information. Victims of this surveillance will not know and have few ways of finding out their communications have been surveilled.

APT28 Campaign Targeting Ukrainian Prosecutors Confirmed

Ukraine confirmed that several local government agencies were targeted in a long-running cyber-espionage campaign attributed to Russian state-linked APT28 (Fancy Bear, BlueDelta, Forest Blizzard). Ukrainian authorities have been tracking the campaign since 2023, with CERT-UA identifying three waves of attacks. The intrusions exploited vulnerabilities in the open-source Roundcube webmail platform that allow attackers to execute malicious code when a victim simply opens an email without clicking links or downloading attachments. More than 170 email accounts belonging to prosecutors and investigators were compromised. Affected institutions included the Specialized Anti-Corruption Prosecutor's Office (SAP) and the Asset Recovery and Management Agency (ARMA). ARMA confirmed employees were targeted but hackers failed to access internal systems. SAP found no evidence of data theft though review is ongoing.

Policy Changes

FCC Chair Carr Pursues Investigations of Late-Night TV Host

FCC Chairman Brendan Carr is revisiting conflict-of-interest rules for broadcasters in what observers describe as an effort to target late-night TV host Jimmy Kimmel. Carr stated he is looking at "conflict-of-interest rules that apply to broadcasters, both personal financial, but also personal political," referencing a pending FCC complaint against Kimmel over a $23,000 payment to Democrat Adam Schiff's campaign a year before Schiff appeared on Jimmy Kimmel Live. First Amendment lawyer Bob Corn-Revere, who served as Chief Counsel to former FCC Chairman James Quello, published an open letter warning Carr that his threats violate the First Amendment and citing Pam Bondi's firing as Attorney General as a cautionary lesson about officials who over-promise to curry favor but under-perform due to limits of their authority. A right-wing activism group, the Center for American Rights (CAR), had direct access to Carr and helped shape complaints against Kimmel and ABC. Stephen Colbert was recently fired by CBS after pressure from Trump associate Larry Ellison.

Trump Administration Designates Far-Left Groups as Terrorist Organizations

The Trump administration is pushing Western governments to combat "antifa and far-left terrorism," with State Department official Monica A. Jacobsen defining far-left terrorism to include threats from communists, Marxists, anarchists, anticapitalists, and those with "eco-extremist" and "other self-identified antifascist ideologies." In November, the State Department designated four leftist groups in Europe (two in Greece, one in Germany, one in Italy) as terrorist organizations, though none have been known to plot attacks on Americans in the past decade, which is usually a criterion for such designation. The administration has not provided hard evidence of violent threats posed by far-left activists. Over the past decade, right-wing extremists have killed 112 people in the United States.

Trump Lawsuit Against IRS Seeks $10 Billion for Tax Return Leak

Trump is suing his own IRS and Treasury Department for $10 billion over the 2019-2020 leak of his tax returns by IRS contractor Charles Littlejohn, who is serving a five-year prison sentence. The DOJ defending the IRS is staffed with Trump's former personal attorneys including acting AG Todd Blanche. The parties filed a consent motion for a 90-day extension to "engage in discussions designed to resolve this matter and to avoid protracted litigation." No scheduling order has issued and the government has not yet answered or responded on the merits. The plaintiff is the sitting President, the defendants are executive branch agencies the President runs, and the lawyers representing defendants report through a chain of command to Trump's former personal lawyers.

Compliance Takeaways