← Carolina Clear Tech

Legal & Privacy Brief

2026-04-30

Listen to this brief (21:12)

Download MP3
Show Notes

Show Notes - 2026-04-30

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 30, 2026

Today: The Supreme Court struck down Louisiana's congressional map for racial gerrymandering while hearing critical arguments on geofence surveillance and Temporary Protected Status. Maryland became the first state to ban surveillance pricing in grocery stores. The House renewed Section 702 warrantless surveillance powers for three years.

Enforcement Actions

European Commission Charges Meta with Child Safety Violations

The European Commission formally accused Meta of violating the Digital Services Act by failing to prevent children under 13 from accessing Instagram and Facebook. The commission found that Meta relies solely on self-declared age with no verification mechanism and does not adequately identify or remove underage users. Evidence across the EU shows 10-12% of children under 13 are using these platforms. Meta contradicted its own statements in the inquiry by claiming enforcement was adequate despite readily available scientific evidence showing younger children face heightened vulnerability to platform harms. Meta could face fines up to 6% of annual revenue plus periodic penalty payments to force compliance.

DOJ, China Coordinate on Dubai Scam Center Raids

The Justice Department announced charges against four individuals running pig-butchering scam centers in Dubai following coordinated raids with Chinese authorities that led to 276 arrests. Federal prosecutors charged Thet Min Nyi (Burmese national) and Indonesian nationals Wiliang Awang, Andreas Chandra, and Lisa Mariam with fraud and money laundering. The defendants allegedly ran front companies Ko Thet Company, Sanduo Group, and Giant Company to conduct cryptocurrency investment scams that defrauded US victims of millions. The coordination with Chinese law enforcement represents a shift in international cooperation on cybercrime enforcement, though the DOJ did not address the status of the 276 people arrested or the human trafficking conditions typically present in these facilities.

Swiss Police Arrest Black Axe Regional Leader

Swiss and German authorities arrested 10 suspected members of the Nigerian criminal network Black Axe, including a regional leader overseeing Southern Europe operations. The suspects, aged 32-54, face charges for romance scams causing millions in losses and international money laundering. Europol estimates Black Axe has 30,000 registered members worldwide organized into 60 zones in Nigeria and 35 abroad, generating billions annually through cybercrime, drug trafficking, and human trafficking. The arrests follow a 2023 international crackdown that seized over 200 bank accounts and a 2026 Spanish operation detaining 34 members.

Litigation Updates

Supreme Court Strikes Down Louisiana Redistricting Map (Louisiana v. Callais)

The Supreme Court ruled 6-3 that Louisiana's 2024 congressional map creating a second majority-Black district violated the Constitution's equal protection clause through unconstitutional racial gerrymandering. Justice Alito's majority opinion held that no compelling interest justified the state's use of race in redistricting, even when attempting to comply with Section 2 of the Voting Rights Act. Justice Kagan's 14-minute dissent argued the decision completes "this court's effort to dismantle and, indeed, destroy the Voting Rights Act," rendering Section 2 protections "all but a dead letter." The map had created a second majority-Black district following a lower court ruling that the prior 2022 map (with one majority-Black district for a state with one-third Black population) likely violated the VRA. The decision leaves Louisiana barred from using the 2024 map in future elections while preserving the current Congress member elected under it.

Fourth Circuit Blocks ERISA Mandatory Class Certification (Trauernicht v. Genworth Financial)

The Fourth Circuit reversed a district court's certification of a mandatory class under Rule 23(b)(1) in an ERISA fiduciary breach case involving a defined contribution plan. The court held that ERISA Section 502(a)(2) claims seeking monetary relief for alleged fiduciary breaches in defined contribution plans cannot be certified as mandatory classes because they are individual monetary damages claims, not derivative plan-wide relief. The court rejected the district court's reasoning that ERISA fiduciary duty claims "inherently" satisfy Rule 23's commonality requirement, emphasizing that commonality requires proof that class members suffered the same injury capable of resolution "in one stroke." The ruling stressed that in defined contribution plans, assets are held in individual accounts and participants may be affected differently by alleged breaches depending on investment timing and withdrawal dates.

CSC ServiceWorks Data Breach Settlement Available

A class action settlement is now open for consumers whose information was compromised in the 2024 CSC ServiceWorks data breach. CSC ServiceWorks operates laundry payment systems in apartment buildings and laundromats. Settlement details including compensation amounts and claim deadlines were not disclosed in the public notice.

Hims & Hers Face Dual Data Breach Class Actions

Two class action lawsuits accuse telehealth companies Hims and Hims & Hers of failing to adequately protect patient information in data breaches that exposed consumers to identity theft and fraud. The complaints allege inadequate security controls for sensitive medical and personal information. The lawsuits follow a pattern of healthcare data breach litigation targeting telehealth platforms that store prescription records, payment information, and health conditions.

ByHeart Infant Formula Litigation Consolidated in MDL

The Judicial Panel on Multidistrict Litigation consolidated 19 class action lawsuits against infant formula manufacturer ByHeart into a new MDL in New York federal court. The consolidation will streamline discovery and pretrial proceedings. MDL assignment typically indicates significant common factual questions across multiple cases filed in different jurisdictions.

Regulatory Guidance

House Renews Section 702 Surveillance Authority for Three Years

The House voted 235-191 to renew Section 702 of the Foreign Intelligence Surveillance Act, allowing warrantless surveillance of foreigners for three years. The bill now heads to the Senate one day before the authority expires. GOP leaders added Fourth Amendment safeguards and tougher penalties for privacy violations to win conservative support, but the final bill contains no warrant requirement for querying Americans' messages. A permanent ban on Federal Reserve digital currency was attached to secure ultra-right conservative votes, leading Senate GOP leaders to indicate they will not support the House version. The Senate may pass its own renewal and send it back to the House hours before the deadline.

Ninth Circuit Upholds Federal Officer Mask Ban Block

The Ninth Circuit upheld a lower court ruling blocking California's law banning federal immigration officers from wearing masks during enforcement operations. The appeals court held that the No Vigilantes Act Section 10 directly regulates the United States in its performance of governmental functions, violating the Supremacy Clause. The district court had blocked the mask ban while allowing an ID display requirement to stand, ruling the mask ban discriminated against the federal government because it exempted state troopers. The Ninth Circuit rejected California's argument that the law could survive by applying to all law enforcement officers, stating the correct standard applies to direct regulation of governmental activities. The court did not address public safety concerns raised by the FBI regarding masked criminals posing as law enforcement officers.

EPIC Challenges GLBA Amendment Draft

EPIC, the National Consumer Law Center, UnidosUS, and 42 civil society organizations sent a letter to the House Financial Services Committee opposing a draft bill to amend the Gramm-Leach-Bliley Act. The coalition argues the discussion draft expands GLBA's ineffective notice-and-choice framework, includes a weak data minimization standard, lacks a private right of action, and would preempt stronger state financial privacy provisions. EPIC submitted a separate statement for the record to the committee's March 17 hearing on financial privacy frameworks.

Privacy Developments

Maryland Bans Surveillance Pricing in Grocery Stores

Maryland became the first state to ban surveillance pricing in grocery stores, prohibiting retailers from using personal data to set varying prices for different buyers. The law follows an FTC investigation and report published in January showing companies use expansive personal data ranges in dynamic pricing. Anti-surveillance advocates noted the law contains industry carveouts that may allow companies to achieve similar outcomes through harder-to-detect methods. Colorado, California, Massachusetts, Illinois, and New Jersey are considering similar bills. EPIC counsel Tom McBrien said the exemptions allow "other ways of arriving at the same outcome that are just harder for consumers to detect."

Supreme Court Hears Geofence Warrant Case (Chatrie v. United States)

The Supreme Court heard arguments on whether geofence warrants violate the Fourth Amendment by allowing police to request location data from Google and other providers to identify all devices in a geographic area during a specific time period. EPIC executive director Alan Butler argued in a statement that geofence searches are "an incredibly invasive investigative technique that threatens the Fourth Amendment rights of hundreds of millions of individuals." The Court should hold that the Constitution protects digital data stored by app or cloud providers and ensure highly sensitive phone-generated records cannot be obtained without particularized suspicion and close judicial oversight. Google has since transferred location data from its servers to individual phones, preventing the company from complying with geofence warrants in the same way, though the government is increasingly seeking data directly from cellphone providers and other companies.

EPIC Challenges Illegal SAVE System Overhaul (League of Women Voters v. DHS)

EPIC and the League of Women Voters renewed their call for a federal court to block DHS's conversion of the SAVE system (Systematic Alien Verification for Entitlements) into an illegal mass voter verification and benefits eligibility tool. The plaintiffs' combined reply and opposition brief argues DHS has subjected members to widespread privacy violations, false identification as "potential non-citizen voters," forced citizenship proof demands, voter roll purges, and disenfranchisement. The brief highlighted a recent executive order directing DHS and SSA to create "State Citizenship Lists" of every voting-age American citizen. The case is part of EPIC's broader effort to fight the administration's illegal collection of state voter information and attempted creation of national data banks.

EPIC Testifies for Vermont Privacy Expansion

EPIC Deputy Director Caitriona Fitzgerald testified before the Vermont House Committee on Commerce and Economic Development supporting S.71 v.2.3, which would expand consumer data privacy protections. The bill includes strong data minimization provisions, heightened minor protections, and a ban on sensitive data sales. EPIC noted the removal of the private right of action (present in last session's vetoed version) was a significant concession but still supports the legislation. Fitzgerald testified that "privacy is a fundamental right, and it is time for business practices to reflect that reality" as self-regulation has failed and Congress remains unable to enact comprehensive protections.

Texas License Plate Reader Expansion Faces Pushback

Texas municipalities are pushing back against rapid adoption of Flock automated license plate reader systems as privacy advocates highlight the unregulated nature of the technology. EPIC fellow Kabbas Azhar told the Texas Observer that "the use of Flock currently is completely unregulated" and even when regulations exist, the system operates on the honor system with no meaningful oversight. The cameras capture location data on vehicles and store it for extended periods, creating mass surveillance databases accessible to law enforcement.

GAO Report Reveals DOGE Treasury Access Security Failures

A GAO report found the Treasury Department flouted basic security safeguards when granting the Department of Government Efficiency access to sensitive payment systems. EPIC deputy director John Davisson said Treasury concluded one DOGE employee would be in a position to cause "inestimable damage" to security interests but failed to obtain a signed access agreement or comply with baseline safeguards. The employee subsequently broke the law by disclosing sensitive, unencrypted personal data related to USAID operations.

Policy Changes

Supreme Court Considers Temporary Protected Status Termination (Mullin v. Doe)

The Supreme Court heard arguments on whether the Trump administration properly terminated Temporary Protected Status designations for Haitian and Syrian nationals. Then-Secretary Kristi Noem ended both designations in 2025, stating Syria's new government was moving toward stable governance and finding no extraordinary and temporary conditions in Haiti preventing safe return. Noem also stated continuation would be "contrary to the national interest." Federal judges in Washington and New York blocked the terminations. Solicitor General D. John Sauer argued courts cannot review DHS determinations on TPS designation or termination. UCLA professor Ahilan Arulanantham countered that DHS "must turn square corners" and follow statutory procedures. Justice Amy Coney Barrett's personal connection to Haiti (she adopted two children from there including after the 2010 earthquake that led to Haiti's TPS designation) drew media attention as potentially relevant to her approach.

DOJ Indicts James Comey for Seashell Instagram Post

The Department of Justice charged former FBI Director James Comey with two federal felonies (threatening the President under 18 U.S.C. § 871 and transmitting a threat in interstate commerce under 18 U.S.C. § 875(c)) for posting an Instagram photo of seashells arranged to spell "8647" with the caption "Cool shell formation on my beach walk." First Amendment attorney Ken White called the charge "preposterous" and stated "no competent or honest prosecutor would bring it," representing "a betrayal of the professional and ethical obligations of every U.S. Department of Justice attorney involved." The indictment was filed by W. Ellis Boyle, U.S. Attorney for the Eastern District of North Carolina, after a prior indictment was dismissed because it was filed by Lindsey Halligan, who was not legally appointed as a U.S. Attorney.

ICE Courthouse Arrest Policy Remains Unclear

Two unnamed DHS officials told NBC News that ICE field offices received verbal instructions to no longer arrest individuals inside courthouses without judicial warrants and to stop entering homes without warrants. However, a DHS spokesperson immediately contradicted the statement, saying "no change in policy" and "we will continue to arrest illegal aliens at immigration courts following their proceedings in compliance with the law." The conflicting statements follow DOJ court admissions that ICE officers committed illegal arrests by detaining migrants attending immigration hearings. The verbal-only nature of any policy change suggests DHS is avoiding creating a paper trail.

Compliance Takeaways