← Carolina Clear Tech

Legal & Privacy Brief

2026-04-23

Listen to this brief (20:28)

Download MP3
Show Notes

Show Notes - 2026-04-23

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 23, 2026

Today: EPIC and civil rights groups sue Alaska for sharing unredacted voter registration lists with DOJ in violation of constitutional privacy protections. EFF sues DHS and ICE demanding disclosure of policies behind administrative subpoenas used to unmask online critics without judicial approval. Arkansas's second attempt at social media age verification legislation struck down on First Amendment and vagueness grounds.

Enforcement Actions

MUBI Auto-Renewal Settlement - $1.6 Million (Case No. 5:25-cv-03652-BLF)

MUBI agreed to a $1.6 million class action settlement resolving California automatic renewal law violations. The streaming service failed to provide adequate notice that subscriptions automatically renewed and failed to obtain sufficient consent for renewals between April 1, 2021 and May 31, 2025. California residents who signed up for MUBI subscriptions on or after April 1, 2021 that were renewed during the class period and did not receive refunds are eligible. Class members can receive an equal share of the net settlement fund as a check or electronic payment. The settlement requires claims by June 9, 2026, with final approval hearing scheduled for July 16, 2026 in the U.S. District Court for the Northern District of California.

ICE Admits Use of Graphite Spyware

Immigration and Customs Enforcement admitted it uses spyware from Israeli company Graphite as part of its Homeland Security Investigations mission. ICE claims the zero-click surveillance tool is used to "disrupt and dismantle foreign terrorist organizations, particularly those involved in the trafficking of fentanyl." The admission raises concerns about warrantless surveillance capabilities deployed against domestic targets under the guise of counter-terrorism and drug enforcement operations.

Litigation Updates

Supreme Court to Hear Geofence Warrant Case (Chatrie v. United States)

The Supreme Court will hear oral argument on whether law enforcement violated the Fourth Amendment by obtaining location data through a geofence warrant. Okello Chatrie was convicted of a 2019 Virginia bank robbery after police served Google with a warrant creating a 150-meter geofence around the bank for 30 minutes before and after the robbery. Law enforcement obtained data in three steps: an initial anonymous list of devices in the area, a narrowed list for a two-hour period, and finally names and information for three accounts including Chatrie's. The second and third steps occurred without warrants. The district court found the warrant lacked probable cause but allowed the evidence under good-faith exception. The Fourth Circuit affirmed in a deeply splintered decision, holding no Fourth Amendment "search" occurred because Chatrie had no reasonable expectation of privacy in two hours of location data voluntarily shared with Google.

Arkansas Social Media Age Verification Law Struck Down (Act 900)

Federal Judge Timothy Brooks preliminarily enjoined Arkansas Act 900, the state's second attempt at social media age verification legislation after the first law was permanently enjoined earlier this year. Act 900 imposed four requirements: prohibition on "addictive practices," default settings for minors including nighttime notification blackout, privacy default settings at maximum protection, and parental dashboard requirements. The court found the "addictive practices" provision unconstitutionally vague, relying on undefined "contemporary understanding of addiction" with no clinical consensus that social media constitutes addiction. The law imposed strict liability based on a single child's response and could hold platforms liable for practices that evoke addiction to off-platform activities. The ruling demonstrates continued First Amendment barriers to state-level social media regulation targeting minors.

Paul Mitchell Class Action - Cruelty-Free Claims (Case No. 2:26-cv-01986)

More than 20 plaintiffs filed a class action against John Paul Mitchell Systems in California federal court alleging the company falsely advertised products as cruelty-free despite allowing animal testing to access the Chinese market where such testing was mandatory. The complaint alleges Paul Mitchell has promoted its cruelty-free stance since 1980 through website claims, social media, and product labels stating "Never Animal Tested" and "A Pioneer in Cruelty-Free Hair Care." Plaintiffs claim the company prioritized profits over principles by selling in China during the class period when animal testing was required, causing consumers to overpay for products they believed were cruelty-free. The lawsuit alleges violations of state consumer protection laws and breach of express warranties.

General Motors Cadillac Lyriq Defects (Case No. 3:26-cv-05329)

Two consumers filed a class action in Washington federal court alleging Cadillac Lyriq electric vehicles contain defects in electrical architecture, software systems, battery management modules, and vehicle control networks that can render vehicles completely inoperable or "bricked." Plaintiffs Wendy J. Cochran and Charlene Riddle claim the vehicles can become nonfunctional due to software failures, control module communication errors, battery management system failures, and charging system faults requiring towing and prolonged dealer service. The complaint alleges GM knew about the defects through pre-release testing, internal engineering reports, warranty claims, NHTSA complaints, and consumer reports but continued marketing the Lyriq as a reliable luxury electric vehicle. Plaintiffs claim dealerships cannot repair vehicles promptly, leaving them inoperable for weeks or months.

Empire Hotel Group Drip Pricing (Case No. 1:26-cv-00884)

Plaintiff Miguel Frias filed a class action in New York federal court alleging Empire Hotel Group uses "drip pricing" to mislead consumers about hotel room costs. The complaint alleges Empire Hotels advertises lower room prices on search pages while hiding mandatory taxes and fees until checkout, violating New York's General Business Law and FTC rules on deceptive fees. The FTC passed a rule in May 2025 prohibiting businesses from advertising prices without clearly disclosing all mandatory fees. Frias booked a room at The Belvedere Hotel and discovered the total price exceeded the advertised rate due to undisclosed taxes and fees only visible after clicking through multiple pages.

Parking Lot Arbitration Clause Enforced (Brant v. Parking Revenue Recovery Services, No. 1:25-cv-01771)

A Colorado federal court held that conspicuous arbitration clause signage on parking lot entrances, exits, and pay stations binds customers even without affirmative express consent. The plaintiff sought to bring nationwide class claims alleging overcharges due to confusing payment systems and predatory pricing. The court analogized the physical signs to clickwrap agreements, finding drivers who park without reading the posted terms are bound similarly to online users who click "Accept" without reading terms of use. The decision confirms that prominent arbitration clause displays can preclude class actions based on mutual assent analysis, even when consumers do not actively acknowledge the terms.

Regulatory Guidance

FTC Click-to-Cancel Protections

EPIC joined 15 civil society organizations in a comment supporting the FTC's efforts to modernize the Negative Option Rule and urging swift action against harmful subscription practices. The coalition supports restoration of click-to-cancel protections requiring businesses to make cancellation as easy as subscription sign-up.

EPIC Statement on House GOP Privacy Bills - SECURE Data Act and GUARD Financial Data Act

EPIC criticized two House Republican privacy bills as playing "directly into the hands of Big Tech" and failing to protect Americans' personal data. EPIC's statement condemns both the SECURE Data Act and GUARD Financial Data Act as inadequate privacy legislation that does not meet the standards needed for comprehensive federal privacy protection.

FTC Strategic Plan 2026-2030 Falls Short

EPIC criticized the FTC's new Strategic Plan for Fiscal Years 2026-2030 as falling "far short of what is needed to effectively protect consumers." The plan, published April 3, represents a significant reduction in ambition compared to previous strategic plans. The assessment suggests weakened consumer protection enforcement over the next five years.

Privacy Developments

EPIC and Civil Rights Groups Sue Alaska Over Voter Registration List Sharing

EPIC, ACLU of Alaska, and ACLU Voting Rights Project filed a lawsuit challenging the Alaska Division of Elections' unconstitutional sharing of Alaska's unredacted Voter Registration List with the U.S. Department of Justice in December 2025. The lawsuit alleges the disclosure violated voter privacy protections by providing DOJ with sensitive personal information without adequate legal authority or privacy safeguards.

EPIC Urges Sixth Circuit to Block DOJ Voter Roll Demand

EPIC filed an amicus brief in United States v. Benson urging the Sixth Circuit to refuse enforcement of the Department of Justice's demand for Michigan's voter rolls. The brief argues the demand violates voter privacy protections and lacks adequate legal authority. EPIC was represented by pro bono counsel from Wilmer Hale.

EFF Sues DHS and ICE Over Administrative Subpoenas Targeting Online Critics

The Electronic Frontier Foundation sued the Department of Homeland Security and Immigration and Customs Enforcement in U.S. District Court for the District of Columbia demanding public records about their use of administrative subpoenas to unmask online critics. Court records and news reports show DHS used administrative subpoenas in the past year to identify internet users who documented ICE activities, criticized the government, or attended protests. The subpoenas are sent to technology companies demanding information about users engaged in protected First Amendment activity without requiring judicial approval. When challenged in court with ACLU assistance, DHS withdrew subpoenas rather than waiting for judicial decisions. DHS and ICE have ignored EFF's public records requests filed in March seeking policies, procedures, legal analyses, approval processes, issuance statistics, and communications regarding the subpoena program.

Google Broke Promise to Users - ICE Data Sharing

EFF's latest newsletter reports on an EFF client whose data was given to ICE after Google broke its promise to notify users before sharing data with law enforcement. The case involves a doctoral student targeted with an ICE administrative subpoena after briefly attending a pro-Palestine protest. EFF asked California and New York attorneys general to investigate Google for deceptive trade practices for failing to protect users targeted by the government.

EPIC Files Fourth Circuit Brief on Flock ALPR Surveillance (Schmidt v. City of Norfolk)

EPIC filed an amicus brief to the Fourth Circuit on April 20 supporting plaintiffs in Schmidt v. City of Norfolk, who allege that Norfolk, Virginia's use of Flock's Automated License Plate Reader system creates a warrantless mass surveillance program constituting an unreasonable search under the Fourth Amendment. Plaintiffs appealed after the district court dismissed the case in January. The brief details how ALPR systems expose the "privacies of life" by tracking vehicle movements and creating comprehensive location histories without warrants.

Policy Changes

Supreme Court Shadow Docket Origins - 2016 Clean Power Plan

Internal Supreme Court memoranda from February 2016 reveal the origins of the court's modern "shadow docket" when five conservative justices blocked President Obama's Clean Power Plan in a 5-4 partisan vote before any briefings, oral arguments, or lower court rulings on the merits. Chief Justice John Roberts pushed for the emergency ruling claiming immediate irreparable harm despite Justice Stephen Breyer noting the first compliance deadline was six years away and full compliance was not required until 2030. The court never heard the case on its merits, issuing only legal boilerplate without reasoning. SCOTUSblog analysis challenges the narrative that this marked the birth of emergency relief on national policies, citing earlier examples including a Justice Sonia Sotomayor order blocking executive regulatory programs more than two years prior.

Global Internet Shutdowns Reach Record High

Authorities imposed 304 internet shutdowns across 54 countries in 2024, the highest number ever recorded. Governments increasingly weaponize connectivity by cutting, slowing, or selectively restoring internet access to control information flow during protests and unrest. Egypt's 2011 internet shutdown marked a turning point when five ISPs shut down networks at government direction, leveraging the country's consolidated telecommunications sector where all providers operate by government license. The Telecommunications Industry Dialogue formalized in 2013 to develop human rights principles, but voluntary approaches have done little to constrain legal and political pressures driving shutdowns.

UK Handles Four Major Cyber Incidents Weekly - Nation-State Attacks Surge

UK National Cyber Security Centre chief Richard Horne warned at the CYBERUK conference that Britain handles four nationally significant cyber incidents every week, with the majority now traced to hostile foreign governments rather than criminal hackers. China's military and intelligence agencies display an "eye-watering level of sophistication," making Beijing a "peer competitor in cyberspace." Russia is exporting tactics developed in Ukraine and directing them at states it considers hostile. Iran is using cyber operations to target British individuals on UK soil seen as regime threats. The UK announced a £90 million investment package and new Cyber Resilience Pledge requiring major organizations to treat cybersecurity as a board-level responsibility. Security Minister Dan Jarvis cited testing of Anthropic's Mythos Preview model that autonomously identified thousands of previously unknown software flaws overlooked for more than two decades.

Compliance Takeaways