← Carolina Clear Tech

Legal & Privacy Brief

2026-04-21

Listen to this brief (29:37)

Download MP3
Show Notes

Show Notes - 2026-04-21

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief

April 21, 2026

Today: The DOJ unsealed a 10-count indictment against two AI technology company executives for allegedly defrauding investors by fabricating hundreds of millions in revenues. A federal judge ruled that Uber owes passengers a non-delegable duty of care for safety, potentially opening liability for driver misconduct despite independent contractor status. Attorney General Pam Bondi's public demands that tech platforms remove ICE-critical content led to a preliminary injunction, with a federal court finding likely First Amendment violations through government coercion.

Enforcement Actions

iLearningEngines Executives Indicted for AI Investment Fraud

The U.S. Attorney's Office for the Eastern District of New York unsealed a 10-count indictment on April 17, 2026, against Harish Chidambaran (former CEO) and Farhan Naqvi (former CFO) of iLearningEngines, Inc., an AI-driven digital education company. Prosecutors allege the defendants operated a multi-year scheme to defraud investors and lenders through false financial statements, dramatically inflating revenues by hundreds of millions of dollars annually, representing more than 90% of reported revenues. The indictment alleges the defendants created fake contractual arrangements with shell entities controlled by employees, associates, friends, and family members, conducting repeated round-trip transfers of investor funds to create the appearance of legitimate customer activity. During the company's SPAC transaction process and after its April 2024 Nasdaq listing under ticker "AILE," the defendants allegedly made materially false representations in financial statements filed with the SEC and provided to auditors. The DOJ framed the case as exploiting investor excitement over the AI boom, stating the defendants pitched iLearningEngines as revolutionary AI-driven training when the artificial part was the fabricated customers and revenues.

Italian Data Protection Authority Fines Postal Service €12.5 Million

Italy's data protection regulator announced on April 20, 2026, fines totaling €12.5 million ($14.7 million) against Poste Italiane SpA (€6.6 million) and its digital payments subsidiary Postepay SpA (€5.9 million) for illegally processing millions of users' personal data. The investigation focused on the Postepay app and BancoPosta app, which required users to authorize monitoring of data on mobile devices, including installed and running applications, allegedly to identify malicious software for fraud prevention. The regulator determined the monitoring methods were excessively invasive and not necessary for fraud prevention or compliance with payment services rules. Additional violations included failing to provide users with adequate information about data processing, not implementing sufficient security safeguards, and retaining data for excessive periods.

Federal Court Issues Preliminary Injunction Against DOJ and DHS for Platform Coercion

Judge Jorge L. Alonso of the Northern District of Illinois granted a preliminary injunction on April 19, 2026, against the DOJ and DHS, finding plaintiffs are likely to succeed on First Amendment claims that the government coerced Facebook and Apple into suppressing protected speech. The case involves Kassandra Rosado, who ran the 100,000-member Facebook group "ICE Sightings - Chicagoland," and Kreisau Group, which created the "Eyes Up" app for documenting ICE enforcement activity. Both services had been reviewed by the platforms and found compliant with policies. After Laura Loomer tagged Attorney General Pam Bondi and Kristi Noem demanding action, Facebook disabled the group two days later. Bondi posted on X that "following outreach from DOJ, Facebook removed a large group that was being used to dox and target ICE agents in Chicago." Noem added that "platforms like Facebook must be PROACTIVE in stopping the doxxing" and threatened prosecution. Bondi also told Fox News about demanding Apple remove the app. The court found this public bragging about demanding platform censorship constituted likely government coercion violating the First Amendment.

Litigation Updates

Federal Judge Rules Uber Owes Non-Delegable Duty to Passenger Safety (MDL No. 3:23-md-03084)

U.S. District Judge Charles R. Breyer ruled that Uber can be held liable for alleged sexual assault by one of its drivers, finding the company qualifies as a common carrier that owes passengers a heightened, non-delegable duty of care. The lawsuit was brought by a passenger identified as WHB 823, who alleges she was sexually assaulted by an Uber driver during a March 2019 ride. The court rejected Uber's argument that it merely connects riders with independent drivers and should not be treated as a transportation provider, finding Uber holds itself out as a transportation service through advertising and exercises control over fares, ride matching, payments, and safety measures. The ruling states Uber's duty to ensure passenger safety is non-delegable, meaning the company remains responsible even if drivers are classified as independent contractors rather than employees. The case is part of multidistrict litigation involving thousands of similar claims alleging passengers were sexually assaulted by Uber drivers.

John Deere $99 Million Right to Repair Settlement (MDL No. 3030, Case No. 3:22-cv-50188)

Deere & Co. reached a $99 million class action settlement with farmers who accused the company of monopolizing the repair market for tractors and heavy equipment, filed in Illinois federal court on April 6, 2026. The farmers alleged Deere engaged in an anticompetitive scheme to withhold vital repair tools from farmers and independent repair providers, forcing them to use authorized Deere dealers for repair services. The settlement provides $99 million to class members who paid authorized dealers for repairs to large agricultural equipment between January 10, 2018, and the date of preliminary approval. In addition to monetary relief, Deere agreed to provide injunctive relief by making repair resources widely available, including access to digital tools required for maintenance, diagnosis, and repair of large agricultural equipment. The injunctive relief remains in effect for 10 years, during which the court retains continued jurisdiction to enforce the settlement terms. The settlement follows Deere's 2023 agreement with the American Farm Bureau Federation committing to similar changes.

Farmers Insurance $1.2 Million New Mexico Underinsured Motorist Settlement (Case No. 1:22-CV-616-JB-SCY)

Farmers Direct Property & Casualty Insurance Co. agreed to a $1.2 million settlement resolving claims it violated New Mexico law by misrepresenting uninsured/underinsured motorist (UM/UIM) coverage. The settlement benefits individuals who had an underinsured motorist claim reduced or offset by the amount paid by the at-fault driver between October 1, 2010, and January 31, 2022, or who purchased a New Mexico automobile insurance policy containing UM/UIM coverage during that period. The lawsuit claimed Farmers violated New Mexico law by misrepresenting underinsured motorist coverage or failing to disclose that the company applied an offset due to insurance coverage limits of third parties responsible for injuries or property damage. Under the settlement, class members who had claims reduced or offset can receive up to $25,000. Class members who paid premiums but are not eligible for claim readjustment can receive a refund of a portion of premiums paid during the class period. The claim form deadline is May 26, 2026, with final approval hearing scheduled for July 1, 2026.

Blood Pressure Medication Contamination Settlements Total $15.2 Million (In re: Valsartan, Losartan and Irbesartan Products Liability Litigation)

Pharmaceutical manufacturers Aurobindo, Hetero, and Vivimed agreed to class action settlements totaling more than $15.2 million to resolve claims their blood pressure medications were contaminated with cancer-causing nitrosamine impurities (NDEA, NDMA, and NMBA). The Aurobindo settlement ($2 million) benefits consumers who paid for irbesartan medications manufactured with Aurobindo API since January 1, 2016. The Hetero settlement ($11,365,489.80) benefits consumers who paid for valsartan medications manufactured using Hetero Process III API sold between May 1, 2018, and July 31, 2018. The Vivimed settlement ($1,899,000) benefits consumers who paid for Vivimed losartan finished drug formulations sold under specific impacted National Drug Codes. Class members can receive cash payments based on amounts paid for contaminated medications. For Aurobindo and Hetero settlements, the deadline for exclusion, objection, and claim submission is June 2, 2026, with final approval hearing scheduled for June 30, 2026.

Abercrombie & Fitch Sued Over Hidden Handling Fees (Case No. 3:26-cv-02224-SK)

Plaintiff Naomi Heilman filed a class action lawsuit in California federal court alleging Abercrombie & Fitch Co. violates California's Consumer Legal Remedies Act by using drip pricing, failing to disclose mandatory handling fees until the end of the checkout process on Abercrombie & Fitch and Hollister websites. The complaint alleges consumers are quoted artificially low prices, then charged a mandatory handling fee at checkout, a practice known as drip pricing and a form of bait-and-switch illegal under California law. The lawsuit seeks to represent California consumers who purchased items and paid a handling fee during the past three years (and after July 1, 2024, for Hollister). Heilman alleges she purchased a dress on April 21, 2025, and had to pay a required $7.00 shipping and handling fee because the website requires a fee for all shipping orders totaling less than $99.

Regulatory Guidance

Supreme Court to Review Birthright Citizenship Executive Order (Trump v. Barbara)

The Supreme Court will hear oral arguments in Trump v. Barbara, reviewing President Trump's January 20, 2025, executive order attempting to limit access to birthright citizenship based on parents' citizenship or immigration status. The executive order claims the 14th Amendment grants U.S. citizenship to children born in the United States depending on whether their parents are "subject to the jurisdiction thereof," which the administration interprets to require the mother to be domiciled in the United States with legal permission to live in the country indefinitely as a permanent resident. During oral arguments, several justices signaled skepticism of U.S. Solicitor General D. John Sauer's interpretation that domicile requires lawful presence with intent to remain permanently. Justice Samuel Alito stated domicile is "the place where he or she intends to make a permanent home" without mentioning lawful presence. Justice Neil Gorsuch suggested legality of presence is irrelevant to domicile because in 1868, when the 14th Amendment was adopted, immigration restrictions did not exist in the way they do today.

Supreme Court to Hear Religious Liberty Case on Universal Preschool (St. Mary Catholic Parish v. Roy)

The Supreme Court granted review in St. Mary Catholic Parish v. Roy, a case involving a Catholic preschool in Littleton, Colorado, challenging its exclusion from Colorado's universal preschool program. The preschool argues its exclusion from the program constitutes religious discrimination in violation of the First Amendment because Colorado will not provide an exemption from rules requiring it to admit everyone, including LGBTQ children and children with LGBTQ parents. The U.S. Court of Appeals for the 10th Circuit rejected the preschool's argument, holding the state's conditions were neutral and generally applied to every preschool regardless of religion, the kind of government actions that normally do not violate the Constitution under Employment Division v. Smith (1990). The Supreme Court declined to reconsider Employment Division v. Smith but will hear oral arguments on the religious exemption question.

House Defeats Clean Section 702 FISA Reauthorization Twice in One Night

House Speaker Mike Johnson's efforts to reauthorize Section 702 of the Foreign Intelligence Surveillance Act (FISA) by five years failed on April 19, 2026, after 20 Republicans joined Democrats in striking down the bill in a 200-220 vote at 1:22 AM. A second vote on a rule to consider a clean 18-month extension also failed at 2:07 AM in a 197-228 vote. The failed bills would have codified existing law allowing warrantless access to Section 702-acquired communications by IC agencies and made it easier to use Section 702 data against Americans in criminal proceedings. The FISA court recently approved an extension of NSA collection provided the government fixed problematic backdoor searches of US persons' communications. Congress has until the end of April 2026 to pass reauthorization before the surveillance power lapses. Senator Ron Wyden stated the House backing down from an 18-month extension "buying us time to negotiate on real reforms."

Privacy Developments

French Identity Document Agency Cyberattack Exposes Personal Data

A cyberattack targeting the French government's National Agency for Secure Documents (ANTS) website detected on April 15, 2026, may have exposed personal data from individual and professional accounts used to manage passports, national identity cards, residence permits, and driver's licenses. Initial analysis indicates several types of personal information linked to individual user accounts may have been exposed, including login credentials, names, email addresses, dates of birth, account unique identifiers, postal addresses, places of birth, and phone numbers. The Interior Ministry stated leaked information does not include documents uploaded during administrative procedures and cannot be used to gain unauthorized access to ANTS portal accounts. The government has not disclosed the number of users affected or the origin of the attack. The incident follows a series of cybersecurity breaches affecting French public institutions, including an Education Ministry breach in late 2025 affecting student account data and a February 2026 breach of France's National Bank Accounts File exposing information linked to roughly 1.2 million accounts.

Elon Musk Fails to Appear for French Police Questioning Over AI-Generated Sexual Images on X

Elon Musk and X CEO Linda Yaccarino failed to appear for voluntary police interviews on April 20, 2026, in Paris as part of a French criminal investigation into X over allegations the platform was producing and distributing child sexual abuse material. The summons were issued after French gendarmes and Europol raided X's Paris offices in February 2026. Paris prosecutors said the investigation is being conducted "in a constructive manner" with the aim of bringing X into compliance with French law rather than simply pursuing punishment. The voluntary hearings were designed to let Musk and Yaccarino present their positions and outline compliance steps. Prosecutors confirmed materials from the French case have been shared with the DOJ and state-level prosecutors in California and New York, as well as with European prosecutors' offices. Officials in the United States, United Kingdom, and European Union have criticized X after the platform's AI tool Grok was used to create sexual images of non-consenting people, including children, in response to user requests.

North Korean Hackers Blamed for $290 Million Cryptocurrency Theft from Kelp

A cryptocurrency theft on April 19, 2026, of approximately $290 million from platform Kelp has been attributed to North Korea's TraderTraitor group, part of the Lazarus operation, according to a post-mortem published by LayerZero, a cryptocurrency infrastructure developer. LayerZero operates Decentralized Verifier Networks (DVNs) that verify messages sent across blockchains. The attack exploited Kelp's configuration using LayerZero's DVN as the sole entity verifying messages for rsETH, a token allowing users to deposit Ether and earn yields. The attackers breached LayerZero and created large amounts of rsETH without providing real Ether as collateral, then used the fictitious rsETH as collateral on other platforms to borrow real Ether and stablecoins. LayerZero blamed Kelp for using a single-point-of-failure configuration that "directly contradicts the multi-DVN redundancy model that LayerZero has consistently recommended." The attackers also launched a DDoS attack on backup systems and used self-destructing tools. A Kelp source disputed LayerZero's assessment, noting about 40% of LayerZero customers use the single DVN setup and the company had never raised issues about it.

Bluesky Attributes Outage to Sophisticated DDoS Attack

Bluesky reported that a widespread outage affecting its social media platform on April 15, 2026, was caused by a sophisticated distributed denial-of-service (DDoS) attack disrupting feeds, notifications, threads, and search functions. The company said its engineers worked overnight to mitigate the attack, which intensified throughout the day. The application has remained stable since April 16, 2026, despite ongoing DDoS attacks. Bluesky said it found no evidence of unauthorized access to private user data. An Iran-linked hacker group calling itself 313 Team claimed responsibility for the attack in a Telegram message, saying it launched a massive cyberattack targeting Bluesky's API. Cybersecurity researchers have previously linked 313 Team to retaliatory cyber operations aligned with Iran-backed Shiite militias, typically targeting organizations or platforms associated with countries supporting the United States or Israel. Bluesky stated it is "not in a position to speculate about attribution."

Policy Changes

EFF and Human Rights Groups Question Palantir's ICE Work Against Its Own Human Rights Commitments

The Electronic Frontier Foundation sent a detailed letter to Palantir Technologies asking how the company's publicly stated human rights framework extends to its work providing tools to Immigration and Customs Enforcement (ICE). EFF asked what human rights due diligence Palantir conducted when it first contracted with ICE and DHS, whether it performed proactive risk scoping, how it reviews work over time, what it has done in response to reports of misuse, and whether it has used contract provisions, third-party oversight, or termination to prevent or mitigate harms. Palantir largely did not answer EFF's accountability questions. The company denied building a mega database for ICE or creating a database of protesters, but EFF noted this sidesteps the central issue of what capabilities Palantir's tools actually provide to ICE. According to sworn testimony in Oregon, ICE agents use Palantir's ELITE tool to determine where to conduct deportation sweeps, pulling from all kinds of databases through a unified interface. Palantir says it performs comprehensive human rights analysis and has publicly embraced the UN Guiding Principles on Business and Human Rights, the Universal Declaration of Human Rights, and the OECD Guidelines for Multinational Enterprises.

ProPublica Investigation Finds Federal Prosecutors Dismissing Anti-ICE Protest Charges

A ProPublica and FRONTLINE investigation identified more than 300 protesters and bystanders arrested by federal agents during immigration sweeps between June 2025 and April 2026 and accused of crimes such as assaulting or interfering with law enforcement. Court records show that in more than one-third of cases, prosecutors quickly dismissed charges that couldn't be substantiated, refused to file charges at all, or lost at trial. Reviews of court files found statements made by arresting officers were repeatedly debunked by video footage. The investigation highlighted the case of Alejandro Orellana, a Marine Corps veteran arrested on June 2025 in a raid involving National Guard soldiers and federal agents, charged with conspiracy and aiding and abetting civil disorder. Within weeks, prosecutors moved to have charges dismissed after agents searching his home found little incriminating evidence and no one else was charged as part of the supposed conspiracy. Chief federal defender Cuauhtémoc Ortega for the Central District of California stated "we've never had a situation where it seems like you arrest first and then try to justify the reasons for the arrests later."

Reddit CLO Defends Section 230 as Protecting User Moderation, Not Just Platforms

Reddit Chief Legal Officer Ben Lee, in an interview with EFF, emphasized that Section 230 protects people, not platforms, shielding millions of volunteer moderators and everyday users from lawsuits for participating in community moderation activities like voting on posts, enforcing community rules, or moderating discussions. Lee stated that weakening or eliminating Section 230 would undermine community self-governance and discourage people from moderating or speaking at all due to litigation risk from powerful entities. Reddit's decentralized model allows thousands of independent subreddits to create and enforce their own rules, with the vast majority of content moderation decisions made by volunteer moderators rather than Reddit itself. Lee explained Section 230 is fundamental to protecting moderators from frivolous lawsuits and gives Reddit the freedom to experiment with community-based moderation approaches where users shape interest-based spaces through voting and rule enforcement.

Compliance Takeaways