← Carolina Clear Tech

Legal & Privacy Brief

2026-05-06

Listen to this brief (17:59)

Download MP3
Show Notes

Show Notes - 2026-05-06

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - May 6, 2026

Today: The FTC settled with data broker Kochava, banning the sale of sensitive location data without consent. Germany advanced legislation permitting law enforcement to use automated facial recognition against public internet data. The Supreme Court rushed Louisiana redistricting while simultaneously blocking Texas map changes in December, raising consistency concerns.

Enforcement Actions

FTC bans data broker Kochava from selling sensitive location info

The Federal Trade Commission reached a settlement with data broker Kochava and its subsidiary Collective Data Solutions, blocking them from selling, sharing, or disclosing sensitive location data without consumers' explicit consent. The FTC's 2023 complaint alleged Kochava illegally obtained and sold consumers' yearly incomes, mobile device IDs, app usage, and nearly real-time geolocation data within 10 meters. The company sold precise geolocation data showing consumers visiting houses of worship and health care clinics without their consent. The proposed order does not impose a fine on Kochava but requires the company to create a sensitive location data program cataloging sensitive locations, establish a supplier assessment program to confirm consumer consent, alert the FTC if third parties violate the settlement terms, and create a data retention schedule mandating predetermined deletion timeframes.

Conti, Akira ransomware affiliate sentenced to 8 years

Latvian ransomware affiliate Deniss Zolotarjovs was sentenced to more than eight years in prison for conducting attacks on behalf of Conti, Akira, and other ransomware operations. Zolotarjovs pleaded guilty to money laundering and wire fraud charges after extradition from Georgia. He specialized in escalating pressure tactics during ransom negotiations, analyzing stolen data and researching victims to force payment. In one incident, he became enraged when a pediatric healthcare company refused to pay and urged his group to leak or sell children's health information, escalating to sending samples of stolen pediatric data to hundreds of patients as a threat. Prosecutors said the organization he worked for operated from St. Petersburg, included multiple former Russian law enforcement officers, and caused $56 million in losses across 53 companies during Zolotarjovs's participation from June 2021 to March 2023. The organization remains active and was the second most observed malware family in 2025.

Litigation Updates

Sony PlayStation Store settles antitrust class action for $7.85M

Sony Interactive Entertainment agreed to a $7.85 million class action settlement resolving claims it violated federal antitrust laws by monopolizing the PlayStation digital game market. The settlement addresses allegations that Sony's exclusive control over digital game distribution on PlayStation consoles constituted anticompetitive conduct.

Eighth Circuit affirms dismissal of agricultural antitrust case for impermissible group pleading

In In re: Crop Inputs Antitrust Litigation, No. 24-3104, the Eighth Circuit affirmed dismissal with prejudice of an antitrust class action alleging suppliers of seeds, pesticides, and agricultural inputs conspired to refuse to sell to direct-to-consumer e-commerce platforms. The court determined the complaint failed for two reasons: many factual allegations referred to "Manufacturer," "Wholesaler," or "Retailer Defendants" collectively without identifying who did what, to whom, where, and when, constituting impermissible group pleading. Second, the remaining allegations failed to plead parallel conduct, as the complaint did not allege more than one defendant engaged in similar conduct around the same time. The decision establishes that plaintiffs alleging antitrust conspiracy must specify relevant acts by each defendant individually and connect each defendant's behavior to allegedly parallel actions of other defendants to plausibly plead an unlawful agreement under the Sherman Act.

DocketWise class action alleges data breach from inadequate security

A class action lawsuit alleges DocketWise, an immigration and case management solution company, failed to properly safeguard and secure the personally identifiable information of more than 116,000 consumers during a recent data breach. The complaint claims DocketWise's "utter failure" to protect information led to the breach.

Regulatory Guidance

Germany advances legislation expanding law enforcement surveillance technology

Germany's federal cabinet advanced a legislative package allowing law enforcement to use automated biometric image matching against publicly available internet data. The bills would legalize automated data analysis and artificial intelligence tools that let police upload a photo of a face and scour the internet for more images depicting the same person. Officers currently must perform manual searches of social networks and other internet sites. The German government defended the move, stating the bills would not create a state-controlled database of images stored indefinitely, and surveillance images collected in real time by public cameras will not be included. A coalition of more than a dozen civil society organizations opposed the package, stating it will fuel digital dragnets and create a mass surveillance state, violating fundamental constitutional and human rights grounds. On the same day, privacy advocacy group noyb filed a lawsuit against the Hamburg data protection authority for allegedly not enforcing European laws making the facial recognition search engine PimEyes illegal.

Trump administration plans AI model pre-vetting system

The Trump administration is discussing an executive order to create an AI working group bringing together tech executives and government officials to examine potential oversight procedures. Among the potential plans is a formal government review process for new AI models. The administration previously revoked Biden's policy on AI safety reviews on Day 1. The planned approach would be more stringent than Biden's voluntary setup, which involved the U.S. Artificial Intelligence Safety Institute (USAISI) within NIST conducting basic standardized testing. The Trump version would require AI companies to provide the government with "first access" to models with significant cyber capabilities before deployment.

Australia establishes Cyber Incident Review Board

Australia announced the establishment of a Cyber Incident Review Board to conduct independent reviews following major cyberattacks. The board will carry out no-fault, post-incident reviews of significant cyberattacks on Australian government and industry, focusing on systemic lessons rather than individual or corporate culpability. It is modeled on the Cyber Safety Review Board established by the Biden administration in 2022, which produced three reports before being disbanded by the Trump administration. Unlike its U.S. counterpart, which relied entirely on voluntary cooperation, Australia's board can compel information from entities that decline to participate.

Privacy Developments

EFF and 18 organizations urge UK to address root causes of online harm

EFF and 18 organizations wrote to UK policymakers urging them to address the root causes of online harm rather than undermining the open web through blunt restrictions. The coalition warned that proposed measures following passage of the Children's Wellbeing and Schools Bill risk fundamentally reshaping the internet. Chief among these proposals are sweeping age-gating requirements and access restrictions that would apply not only to young people but effectively to all users. The signatories argue these measures threaten the core architecture of the open internet. Age-gating at scale could fragment the web into a patchwork of restricted jurisdictions, limit access to information, and entrench the dominance of powerful gatekeepers. The coalition calls on UK policymakers to hold companies accountable for systemic practices and prioritize user rights by design rather than imposing access bans.

Policy Changes

Supreme Court rushes Louisiana redistricting certification while blocking Texas map changes

The Supreme Court agreed to rush making last week's Louisiana v. Callais ruling official, allowing Louisiana to speed up redistricting plans even though some voting has already started. Justice Alito agreed to compress the normal 32-day waiting period. In his response to Justice Jackson's dissent, Alito argued the 2026 congressional elections in Louisiana should not be held under a map held to be unconstitutional. However, in December, Alito blocked changes to Texas's unconstitutional gerrymander, stating Texas needed "certainty" on which map would govern the 2026 midterm elections and that December was too late to interfere with the election map. The Louisiana ruling allows the state to potentially claim a state of emergency to halt in-progress voting and redraw districts.

Supreme Court declines to revisit Employment Division v. Smith in religious exemption case

The Supreme Court agreed to hear argument next term in St. Mary Catholic Parish v. Roy, in which a Catholic preschool is challenging its exclusion from Colorado's universal preschool program by arguing Colorado must allow it to deny admission to LGBTQ children and children with LGBTQ parents. The justices declined to revisit or potentially overrule 1990's Employment Division v. Smith, which limits the reach of the First Amendment's free exercise clause. The court made the same move four years ago in 303 Creative LLC v. Elenis, taking up the free speech claim but not the free exercise claim or the question of whether Smith should be overruled. Five current justices indicated in 2021 they are considering overruling Smith, but the precedent continues to be acknowledged and applied.

Compliance Takeaways