← Carolina Clear Tech

Legal & Privacy Brief

2026-04-25

Listen to this brief (19:53)

Download MP3
Show Notes

Show Notes - 2026-04-25

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 25, 2026

Today: The Supreme Court hears arguments Monday on geofence warrants in Chatrie v. United States, the most significant digital privacy case in years. A federal jury found Live Nation monopolized concert ticketing markets across 33 states, with remedies potentially including Ticketmaster divestiture. California lawmakers fast-track A.B. 1709, requiring biometric age verification for all social media users and banning access for anyone under 16.

Enforcement Actions

$50M Google Discrimination Class Action Settlement

Google agreed to a $50 million settlement to resolve claims it discriminated against Black employees in California and New York through hiring, promotion, pay, and job level assignments from 2017-2023. The settlement in Curley v. Google LLC (Case No. 4:22-cv-01735-KAW, N.D. Cal.) covers individuals identified as Black or Black+ who worked in job levels 3-6 in California from March 18, 2018 through December 31, 2023, and in New York from October 15, 2017 through December 31, 2023. Google denied wrongdoing but agreed to non-monetary relief including continued pay equity analysis, robust leveling policies, and employee reporting mechanisms.

$7.4M Trader Joe's FACTA Class Action Settlement

Trader Joe's agreed to a $7.4 million settlement for printing the first six and last four digits of credit card numbers on customer receipts from March 5, 2019 through July 19, 2019, violating the Fair and Accurate Credit Transactions Act. The settlement in Keim v. Trader Joe's Company (Case No. 19STCV36790, Los Angeles County Superior Court) provides an estimated $102.45 per claimant. FACTA prohibits displaying more than the last five digits of card numbers on receipts to prevent identity theft.

ADT Data Breach Affects Customer Records

ADT disclosed a cyberattack on April 21 that resulted in the theft of customer and prospective customer information including names, phone numbers, addresses, dates of birth, and the last four digits of Social Security numbers and tax IDs. The ShinyHunters cybercriminal group claimed to have stolen 10 million records and threatened to leak the data without ransom payment. ADT reported the incident to the SEC and stated that customer security systems were not compromised. This is the latest in multiple cybersecurity breaches ADT has reported to the SEC over the last two years.

Litigation Updates

Live Nation Monopoly Verdict Across 33 States

A federal jury found Live Nation and Ticketmaster unlawfully monopolized the concert ticketing market and engaged in anticompetitive tying practices across 33 states and Washington D.C. in the case U.S. v. Live Nation (Case No. 1:24-cv-03973, S.D.N.Y.). Jurors determined Live Nation acquired monopoly power in ticketing services for major concert venues, tied artists' access to large amphitheaters to the use of its promotional services, and overcharged consumers by approximately $1.72 per ticket. The verdict follows claims that Live Nation leveraged its ownership of Ticketmaster to require venues and artists to use its services, preventing competitors from entering the ticketing market.

Capital One Customers Seek Class Certification Over Meta and Google Data Sharing

Capital One customers moved for class certification in Shah v. Capital One Financial Corp. (Case No. 3:24-cv-05985, N.D. Cal.) over claims the financial institution installed third-party tracking tools that shared personal and financial information with Meta Platforms, Google, and other third parties without adequate disclosure or consent. Plaintiffs Gary Ingraham and Deia Williams seek to represent two nationwide classes under the Electronic Communications Privacy Act and two California subclasses under the California Consumer Privacy Act and California Invasion of Privacy Act. Judge Trina L. Thompson heard arguments on April 21 but did not rule from the bench. Plaintiffs claim the tracking tools collect account information, employment data, browsing activity, credit card application details, and approval data, which Capital One shares in real time for marketing purposes.

Pacifica Beauty Sued Over False Urgency Email Claims Under Washington CEMA

Plaintiff Jace Hoag filed a class action in Washington state court (Hoag v. Pacifica Beauty LLC, Case No. 26-2-00983-34, Thurston County Superior Court) alleging Pacifica Beauty sends marketing emails with deliberately false urgency claims in subject lines, violating the Washington Commercial Electronic Mail Act. The complaint cites emails with subject lines like "Last Day! 20% OFF SITEWIDE" and "ENDS TOMORROW" that were extended after the stated deadline. CEMA prohibits commercial emails to Washington residents containing false or misleading information in subject lines. A CEMA violation constitutes a per se violation of the Washington Consumer Protection Act, allowing for actual or liquidated damages trebled and attorneys' fees.

Kash Patel Defamation Case Dismissed, Second Case Filed

U.S. District Judge George C. Hanks Jr. dismissed FBI Director Kash Patel's defamation lawsuit against MSNBC's Frank Figliuzzi, ruling that Figliuzzi's statement that Patel "has been visible at nightclubs far more than he has been on the seventh floor of the Hoover building" constituted rhetorical hyperbole that cannot be defamatory. The court found a person of reasonable intelligence would not have taken the statement literally. The dismissal came one day after Patel filed a separate defamation lawsuit against The Atlantic over reporting on drinking concerns, in which Patel's lawyers cited the Figliuzzi lawsuit as evidence the reporting was false.

Regulatory Guidance

Supreme Court to Hear Geofence Warrant Case Monday

The Supreme Court hears arguments April 27 in Chatrie v. United States, addressing whether police need a warrant before accessing geofence data and whether geofence warrants constitute permissible Fourth Amendment searches. Geofence warrants allow law enforcement to obtain location data from service providers like Google or Apple within specific geographic boundaries and time periods to identify potential suspects. The case follows the Court's 2017 decision in Carpenter v. United States, which held police must obtain a warrant before reviewing seven or more days of cell-site location information. Lower courts have spent years contending with Carpenter's boundaries, and Chatrie presents the Court's opportunity to clarify Fourth Amendment protections for digital location data in the modern investigative landscape.

Supreme Court to Consider Trump Administration TPS Revocations

On April 29, the Supreme Court will hear arguments in Mullin v. Doe over the Trump administration's efforts to end Temporary Protected Status designations for Haiti and Syria. Federal judges in Washington D.C. and New York blocked the terminations, finding DHS Secretary Kristi Noem likely ended Haiti's TPS designation "because of hostility to nonwhite immigrants" and violated the Administrative Procedure Act by failing to consult with other federal agencies. The TPS program, enacted in 1990, allows DHS to designate countries' citizens as eligible to remain and work in the U.S. when they cannot return safely due to natural disasters, armed conflict, or extraordinary conditions. Syria was designated in 2012 following Assad's crackdown; Haiti was designated after the 2010 earthquake.

Fifth Circuit Upholds Texas Ten Commandments Law

The Fifth Circuit en banc reversed its earlier panel decision and upheld a Texas law mandating Ten Commandments displays in public school classrooms. The majority concluded the law does not violate the Establishment Clause or Free Exercise Clause, declaring that the Supreme Court's Lemon v. Kurtzman test has been "jettisoned" despite the Supreme Court never formally overturning the precedent. The court distinguished Stone v. Graham (1980), which invalidated a similar Kentucky law under the Lemon test, by claiming Lemon is no longer valid following Kennedy v. Bremerton School District (2022). The decision follows the Fifth Circuit's similar June 2025 ruling lifting an injunction against Louisiana's Ten Commandments mandate.

Pentagon Addresses AI Security for Autonomous Weapons

Chairman of the Joint Chiefs of Staff Gen. Caine stated autonomous weapons will be a "key and essential part of everything we do," while acknowledging significant cybersecurity challenges for AI systems in military applications. Speaking at Vanderbilt University's Asness Summit, Caine highlighted the Defense Department's growing dependence on privately-developed software systems not originally designed for military use, raising concerns about vulnerabilities, supply chain risks, and adversarial exploitation. The remarks followed the ongoing dispute with Anthropic over the Mythos Preview model, which the Pentagon designated a "supply chain risk" after Anthropic declined to ease restrictions on domestic surveillance and fully autonomous weapons use. A federal judge temporarily blocked the White House's order to phase out Anthropic tools in March.

Norwegian Prime Minister Proposes Social Media Ban for Under-16

Norwegian Prime Minister Jonas Gahr Støre announced plans to introduce legislation by year-end that would ban children under 16 from using social media and hold technology companies accountable for using age verification tools. The bill proposes allowing children to begin using social media on January 1 of the year they turn 16. Støre's Labour party does not hold a majority in parliament, leaving the bill's passage uncertain. The proposal follows similar initiatives across Europe, including France's Senate vote to ban social media for children under 15, Spain's announced ban for under-15, and the Netherlands' proposed 15-year minimum age.

Privacy Developments

California A.B. 1709 Mandates Biometric Age Verification for All Social Media Users

California lawmakers are fast-tracking A.B. 1709, which would ban anyone under 16 from using social media and require all users to verify their identity through government-issued ID or biometric information before accessing social platforms. The bill passed the Assembly Privacy and Judiciary Committees with nearly unanimous support and moves next to the Assembly Appropriations Committee, followed by a floor vote likely within the next week. EFF opposes the bill as unconstitutional, arguing it violates First Amendment protections for minors' speech, destroys online anonymity for all users, and creates massive security risks by forcing users to hand sensitive biometric data to private companies. The bill's age-verification mandate disproportionately impacts marginalized communities, including those whose IDs don't match their presentation, people with disabilities, and trans and gender non-conforming individuals.

CBP Seeks San Clemente Approval for AI Surveillance Tower

Customs and Border Protection is seeking permission from San Clemente, California to install an Anduril Industries Autonomous Surveillance Tower on a coastal cliff 1.5 miles inland that would monitor the entire 62,000-resident city. The Sentry tower combines video, radar, and computer vision to constantly scan for movement, autonomously detecting, identifying, and tracking humans, animals, and vehicles using AI algorithms. CBP claims the system will primarily monitor the coastline for migrant boats, but the long-range maritime model could see up to nine miles, covering San Clemente and potentially neighboring Dana Point. CBP rejected the city's proposed lease restriction prohibiting residential surveillance, stating the system would be "configured to avoid" scanning residential areas but must retain the capability to track smuggling events that traverse neighborhoods. The system retains imagery for 30 days and maintains learning training data indefinitely to train algorithms.

CareCloud Data Breach Exposes EHR Environment for Eight Hours

Healthcare IT company CareCloud disclosed to the SEC that an unauthorized third party breached one of its six electronic health record environments on March 16, exposing patient information for approximately eight hours. The breach affected CareCloud's CareCloud Health division and was contained the same day it was discovered. CareCloud stated the incident did not affect other platforms, divisions, or systems. The company is working with outside cybersecurity experts and continues to investigate whether patient information was accessed or exfiltrated, including the categories and volume of any compromised data.

Toronto Police Make First SMS Blaster Arrests in Canada

Toronto police arrested three men in Canada's first known criminal case involving mobile SMS blasters, devices that impersonate cellular towers to send mass phishing messages and disrupt networks. The investigation began in November after authorities detected a suspicious device operating in downtown Toronto. Police seized multiple SMS blasters and recorded more than 13 million network disruptions linked to the devices. Tens of thousands of mobile phones connected to the rogue system, which sent phishing messages appearing to originate from banks and government agencies. The devices temporarily prevented phones from connecting to legitimate cellular networks, potentially limiting 911 access for seconds to minutes. Similar attacks have been reported in Greece, Thailand, Indonesia, Qatar, and the United Kingdom.

Policy Changes

Virginia Strips Tax-Exempt Status from Confederate Organizations

Virginia Governor Abigail Spanberger signed legislation stripping tax-exempt status from Confederate-affiliated organizations including the United Daughters of the Confederacy and Sons of the Confederacy. The law represents part of a years-long effort to address Virginia's role as the capital of the Confederate states. Spanberger also signed a bill ending production of specialty license plates featuring Robert E. Lee. The changes follow the 2020 removal of Confederate monuments and symbols from public spaces across Virginia.

Compliance Takeaways