← Carolina Clear Tech

Legal & Privacy Brief

2026-06-06

Listen to this brief (13:03)

Download MP3
Show Notes

Show Notes - 2026-06-06

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 6, 2026

Today: The Supreme Court issued three unanimous decisions including validation of SEC disgorgement powers without requiring proof of investor monetary loss and rejection of generic pharmaceutical liability for pharmacist prescribing decisions. Data breach litigation in the Eastern District of Michigan shows plaintiffs clearing Article III standing hurdles but failing on negligence claims due to insufficient causation pleading. Multiple class action settlements reached for data breach ($1.54M Deanco Healthcare) and website tracking violations ($1.9M Barefoot Dreams).

Litigation Updates

A-Line Staffing Solutions Data Breach (Case No. 24-cv-11917, E.D. Mich.)

The Eastern District of Michigan dismissed negligence and related claims in a consolidated data breach putative class action following a ransomware attack that compromised employee PII and published it on the dark web. The court found plaintiffs satisfied Article III standing requirements under Galaria v. Nationwide Mutual Insurance by plausibly alleging that bad actors stole their PII and that defendant's lax security enabled the theft, requiring "more than speculative but less than but-for" causation at the pleading stage. However, the court granted dismissal under Rule 12(b)(6), holding that plaintiffs failed to establish "but-for" causal link between the breach and alleged injuries, relying instead on "temporal proximity and correlation" deemed too speculative. The court also dismissed breach of implied contract (PII provision too incidental to establish consideration), unjust enrichment (no independent benefit shown), breach of fiduciary duty (no special relationship), breach of confidence (no disclosure by defendant), and declaratory relief claims (cannot prevent already-occurred breach).

Hikma Pharmaceuticals v. Amarin Pharma (Supreme Court)

The Supreme Court unanimously rejected holding generic pharmaceutical manufacturers liable for patent infringement based on pharmacist and physician prescribing decisions. Justice Ketanji Brown Jackson's opinion held that generic manufacturer Hikma could not be liable for "active inducement" of infringement for the patented cardiovascular indication of Vascepa when its product label, press releases, and website statements had "obvious alternative explanations" of complying with law and industry standards rather than encouraging infringement. The Court rejected Amarin's argument that describing Hikma's product as "generic Vascepa" and using broad therapeutic category descriptions constituted inducement, noting that federal statute requires generic labels to be identical to brand labels except for carved-out patented uses, and that conforming to normal industry practice should not create liability.

Deanco Healthcare Data Breach Settlement

Class action settlement provides up to $5,000 for documented losses plus two years of medical monitoring following data breach. Settlement amount totals $1.54 million.

Barefoot Dreams Website Tracking Settlement

Class action settlement offers cash payments to consumers who purchased products online between October 14, 2023, and June 1, 2026. Settlement amount totals $1.9 million for alleged violations related to website tracking technologies.

Smucker Sugar-Free Product Labeling

New class action lawsuit accuses Smucker of misleading consumers by marketing sugar-free hot fudge topping as sweetened with Splenda despite primary sweetening from other ingredients. Lawsuit alleges violations of state consumer protection and false advertising statutes.

Honda Odyssey Airbag Defect

Class action alleges Honda sold Odyssey minivans with defects causing spontaneous airbag deployment without warning or crash. Lawsuit seeks damages for vehicle owners and safety-related repairs.

Regulatory Guidance

Sripetch v. SEC (Supreme Court)

The Supreme Court unanimously validated the SEC's use of disgorgement to recover wrongdoer profits without proving specific pecuniary loss to investors. Justice Neil Gorsuch's opinion resolved tension following Kokesh v. SEC (2017) and Liu v. SEC (2020) by holding that traditional equitable principles support disgorgement conditioned only on showing defendant interfered with plaintiff's legally protected rights, not investor monetary harm. The case involved classic pump-and-dump operations with penny stocks. The decision clarifies that SEC must quantify defendant's net profits (not gross revenues) and amounts recovered must be awarded to victims rather than Treasury, but specific investor loss calculations are not required for disgorgement orders.

Federal Communications Commission v. AT&T (Supreme Court)

The Supreme Court held 8-1 that the FCC does not violate the Seventh Amendment right to jury trial when issuing forfeiture orders without jury involvement. Chief Justice John Roberts wrote the majority opinion with Justice Clarence Thomas dissenting. The decision preserves FCC administrative enforcement authority for telecommunications regulatory violations.

EU Tech Sovereignty Package

The European Commission proposed comprehensive legislation to reduce EU reliance on foreign technology suppliers, including Chips Act 2.0, Cloud and AI Development Act (CADA), Open Source Strategy, and energy digitalization roadmap. The package addresses EU dependence on foreign suppliers for over 80% of key digital products and establishes requirements for national governments to expedite planning and regulatory approvals for semiconductor facilities. The strategy includes scaled-up European open-source alternatives for cybersecurity, funding for long-term maintenance and security of critical open-source infrastructure, and procurement guidance pushing public administrations toward open-source tools.

Privacy Developments

Global Age Verification Expansion

Multiple jurisdictions have implemented or expanded age verification and social media access restrictions for minors. Australia banned users under 16 from social media accounts with penalties up to $32 million USD for non-compliance, affecting Instagram, Facebook, Threads, Snapchat, YouTube, TikTok, Kick, Reddit, Twitch, and X. UK Online Safety Act requires services to assess harmful content risks and implement age checks, with algorithm and moderation system changes to prevent exposure to violent imagery. Indonesia deactivated accounts for users under 16 on YouTube, TikTok, Facebook, Instagram, Threads, X, Bigo Live, and Roblox as of March 28, 2026. Malaysia announced plans to ban users under 16 from platforms with 8+ million Malaysian users, requiring data downloads within one month before restrictions apply, with penalties up to $2.5 million USD. Brazil's 2025 law requires age assurance for products and services offering risks to minors, with full compliance expected early 2027 under Brazilian National Data Protection Agency enforcement.

Apple Removes Russian State Messaging App

Apple removed Russia's state-backed messaging app Max from its App Store citing compliance with sanctions regulations, affecting approximately 20 million Russian users. The app, developed by VK and promoted as domestic alternative to Telegram and WhatsApp, combines messaging with government services access, digital identification, electronic signatures, and payment functions. Russian authorities have required smartphone manufacturers to preinstall Max on devices sold in Russia since September 2025. Digital rights advocates criticized Max for close government infrastructure integration and lack of end-to-end encryption enabling potential communications monitoring. Cloudflare briefly classified Max as spyware in April before removing the designation.

Policy Changes

Internet Archive Blocking by News Publishers

Over 340 local news sites across the United States now limit Internet Archive's ability to access and preserve their content, up from approximately six cases in February. Many blocking sites are owned by major publishers including USA Today Co., McClatchy, Advance Local, MediaNews Group, and Tribune Publishing (subsidiaries of Alden Global Capital). Publishers cite concerns about AI companies scraping archived content for training data without compensation. The blocking prevents preservation of local news reporting and limits historical research access. Internet Archive has implemented restrictions on bulk downloading and collaborates with Cloudflare to monitor bot activity in response to publisher concerns.

Trump Administration Anti-Weaponization Fund

Despite Trump administration abandonment of formal "Anti-Weaponization Fund" following congressional pressure, existing legal tools including the Judgment Fund and Federal Tort Claims Act allow similar taxpayer-funded payments to beneficiaries with limited congressional or judicial oversight. The settlement agreement between the government and the Trumps establishing the fund remains legally binding and can only be modified with written party agreement. Attorney General Todd Blanche refused to issue written rescission order during congressional hearing.

Schedule Policy/Career Implementation

President Trump's Schedule Policy/Career executive order recategorized approximately 8,000 federal employees in "confidential, policy-determining, policy-making, or policy-advocating" positions with reduced civil service protections. The order authorizes removal of employees who fail to "faithfully implement administration policies to the best of their ability," expanding presidential control over career civil servants and threatening political independence of federal workforce.

Compliance Takeaways