← Carolina Clear Tech

Legal & Privacy Brief

2026-05-26

Listen to this brief (6:32)

Download MP3
Show Notes

Show Notes - 2026-05-26

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - May 26, 2026

Today: Texas filed suit against Netflix alleging the streaming platform secretly tracked and sold users' viewing data while marketing itself as privacy-focused. Carnival faces a class action for allegedly failing to notify customers of a data breach that exposed personally identifiable information. Teva, Granules, and Heritage Pharmaceuticals agreed to pay $5.55 million to settle claims their metformin products contained NDMA contamination.

Litigation Updates

$5.55M Teva, Granules and Heritage metformin class action settlement

Teva, Granules, and Heritage Pharmaceuticals agreed to pay $5.55 million to settle class action claims that their metformin products were contaminated with N-Nitrosodimethylamine (NDMA), a probable human carcinogen. The settlement resolves allegations that consumers purchased and ingested contaminated diabetes medication without adequate warning. Class members include purchasers of the affected metformin products during the relevant period.

Texas lawsuit claims Netflix secretly tracked, sold users' viewing data

The State of Texas filed a lawsuit against Netflix alleging the streaming platform secretly tracked users' personal viewing data and sold it to third parties, despite publicly marketing itself as an ad-free, privacy-focused alternative to other technology companies. The complaint challenges Netflix's data collection and monetization practices as deceptive and in violation of state consumer protection laws. The case centers on alleged discrepancies between Netflix's privacy representations to consumers and its actual data handling practices.

Carnival class action claims cruise line failed to notify customers of data breach

A class action lawsuit alleges Carnival Corp., which operates Carnival Cruise Line, failed to notify customers that their personally identifiable information was stolen in a data breach. The complaint asserts Carnival violated data breach notification requirements by not informing affected individuals of the compromise in a timely manner. Class members include customers whose PII was accessed in the breach but who did not receive required notifications.

Costco faces class action over Kirkland tortelloni's 'preservative free' labeling

A class action lawsuit accuses Costco of falsely advertising its Kirkland Signature Five Cheese Tortelloni with Parmigiano Reggiano frozen pasta as containing "no preservatives" when the product allegedly contains citric acid and other preservative compounds. The complaint alleges deceptive labeling practices under state consumer protection statutes. The case highlights ongoing litigation over food labeling accuracy and the definition of "preservative-free" claims.

Mercedes-Benz recalls 144K vehicles due to instrument panel display failure

Mercedes-Benz USA LLC issued a recall affecting more than 144,000 vehicles across multiple model lines due to a software defect that can cause the digital instrument panel to go dark while the vehicle is in operation. The recall addresses a safety hazard where drivers lose access to critical vehicle information including speed, fuel level, and warning indicators. The software flaw represents a failure in vehicle safety systems that could result in litigation if accidents occur before remediation.

Policy Changes

Kremlin appoints cyber executive with alleged GRU ties to Security Council role

Russian President Vladimir Putin appointed Andrei Kozlov, former head of a cybersecurity center within state-owned defense conglomerate Rostec, as an aide to Security Council Secretary Sergei Shoigu. According to leaked data published by The Insider, Kozlov held a classified security clearance under Military Unit 26165, the 85th Main Special Service Center, which Western governments and cybersecurity firms have linked to the APT28 hacking group (also tracked as Fancy Bear, BlueDelta, and Forest Blizzard). The group has conducted cyber espionage, credential theft, and influence operations targeting governments, defense contractors, logistics companies, and policy organizations across Europe and the United States. Kozlov previously served as acting general director of RT-Information Security (RT-IB), a Rostec subsidiary sanctioned by the U.S., EU, and other Western states. His predecessor in the Security Council role, Pavel Konovalchik, was also reportedly linked to the same GRU unit.

Compliance Takeaways