← Carolina Clear Tech

Legal & Privacy Brief

2026-06-10

Listen to this brief (16:37)

Download MP3
Show Notes

Show Notes - 2026-06-10

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 10, 2026

Today: Google agrees to pay $68 million to settle privacy claims over Google Assistant recordings. The Supreme Court continues narrowing criminal justice reform legislation while expanding Second Amendment protections. Trump administration strips AI safety guardrails from national security deployments through new presidential memorandum. FTC finalizes stronger data minimization requirements for educational technology providers following a breach affecting 10 million students.

Enforcement Actions

FTC Settlement with Illuminate Education Strengthens Data Minimization

The FTC finalized a revised consent order with Illuminate Education following a major data breach that exposed the personal information of 10 million students. The complaint alleged insufficient security measures led to the breach. The final order incorporates strengthened data minimization requirements, including enforceable limits on the collection, processing, and retention of student personal data. The settlement reflects the FTC's position that data minimization is an essential pillar of data security and that preventing data collection is more effective than securing data after it has been collected.

Litigation Updates

$68 Million Google Assistant Privacy Class Action Settlement

Consumers who purchased Google-made devices or had communications recorded by Google Assistant may be eligible for settlement benefits under a $68 million class action settlement. The settlement addresses privacy claims related to Google's collection and storage of voice recordings through its Assistant technology.

Trump Seeks Supreme Court Review of $475 Million CNN Defamation Suit

President Donald Trump filed a notice with the Supreme Court requesting a 60-day extension to August 15 to petition for review of a lower court's dismissal of his $475 million defamation lawsuit against CNN. The lawsuit, dating from 2022, accused the network of using the term "Big Lie" to describe his claims that the 2020 election was rigged, which Trump argues constitutes defamation.

Federal Court Blocks Trump's $100,000 Visa Fee as Unauthorized Tax

U.S. District Judge Leo Sorokin blocked President Donald Trump's attempt to impose a $100,000 fee on employers seeking to hire foreign workers for specialized roles, ruling the policy constitutes an unauthorized tax requiring congressional approval. The decision relied on Supreme Court precedents establishing that the president can only exercise taxing authority when given unambiguous approval by Congress.

Federal Court Restores Immigration Benefits to Travel Ban Countries

A Rhode Island federal court blocked the Trump administration's policy of denying work permits and green cards to individuals from countries designated as "high risk," including Iran, Nigeria, and Venezuela, even when those individuals were already present in the United States. Chief Judge John McConnell Jr. found evidence of pretextual reasoning and anti-immigrant animus behind the policies, including derogatory statements about immigrants by administration officials. The court noted the policy was implemented retroactively through executive order without congressional authorization, stripping protections previously awarded by prior administrations.

Omni Hotels Class Action Alleges TCPA Violations for Unwanted Text Messages

A new class action lawsuit filed in Florida accuses Omni Hotels Corporation of sending unwanted text messages to consumers who had opted out of receiving them. Plaintiff Joe Biscaha claims the company violated the Telephone Consumer Protection Act by continuing to send marketing messages after consumers withdrew consent.

Supreme Court Narrows First Step Act in Compassionate Release Cases (Rutherford v. United States, Fernandez v. United States)

The Supreme Court issued two decisions limiting the scope of compassionate release under the First Step Act. In Rutherford v. United States and the companion case Carter v. United States, the court held that prisoners serving sentences under the old mandatory minimum "stacking" regime cannot cite changes in sentencing law as grounds for compassionate release, even when their sentences would be 14 to 21 years shorter under current law. The majority reasoned this would constitute an improper retroactive application of the First Step Act. In Fernandez v. United States, the court held that serious doubt about a conviction's integrity cannot qualify as an "extraordinary and compelling" ground for compassionate release, reasoning that federal prisoners must use habeas corpus procedures to challenge convictions. Justice Sotomayor dissented in both cases, arguing the majority "conjured categorical limitations" not imposed by Congress or the Sentencing Commission.

Regulatory Guidance

CISA Announces Overhaul of Vulnerability Assessment and Risk Prioritization

The Cybersecurity and Infrastructure Security Agency (CISA) announced it will transform how it assesses cyber vulnerabilities and threats, with a new binding operational directive being released on June 11. Acting Director Nick Andersen stated CISA will move away from the historical "apply this patch as quickly as you can" approach toward risk-based prioritization that considers whether assets are internet-exposed, align with known exploited vulnerabilities, and support critical infrastructure functions. The directive will address whether patching windows need to be shortened and will direct federal agencies to change their vulnerability management protocols overall. CISA will prioritize specific critical functions over broad system protection, such as focusing on a bank's bulk payment system rather than individual branch operations.

White House Removes AI Safety Guardrails from National Security Deployments (NSPM 11)

The Trump administration issued National Security Presidential Memorandum 11 on June 5, instructing heads of agencies working on national security, military operations, intelligence, and government data processing to accelerate adoption and deployment of AI systems. The memorandum rescinds and replaces the Biden administration's NSM 25, which emphasized protection of human rights, civil rights, civil liberties, and privacy when using AI. While NSPM 11 states AI deployment should be "consistent with" constitutional rights and privacy laws protecting Americans, it provides no framework or concrete steps to accomplish this goal. The Biden-era framework had prohibited certain uses, identified high-impact uses requiring additional scrutiny, and outlined minimal risk management practices. The new memorandum's reference to protections for "American citizens" rather than "U.S. persons" raises concerns, as constitutional rights and privacy protections legally apply to all U.S. persons, including noncitizens.

Privacy Developments

Meta Confirms AI Chatbot Helped Hackers Compromise 20,000 Instagram Accounts

Meta filed a data breach notice with Maine's Attorney General confirming that a vulnerability in an AI-assisted account recovery system for Instagram allowed hackers to perform password resets and compromise at least 20,225 Instagram accounts. The breach occurred over a three-week period. Hackers exploited the AI support assistant by using VPNs to match account holders' regions, then simply asked the chatbot for access. The compromises allowed hackers to obtain contact information, dates of birth, profile information, posts, direct messages, and account activity. Accounts with two-factor authentication enabled were not affected. Meta stated it is "unaware" of the full scope of information compromised, suggesting the impact could be worse than currently known.

Policy Changes

House Considers Bills Formalizing Treasury Data Collection and Fraud Prevention Authority (H.R. 8312, 8463, 8464)

The House of Representatives is voting this week on three bills that would expand the Treasury Department's authority to collect and analyze personal information for fraud prevention. H.R. 8312 (Fraud Prevention and Accountability Act) would create a national databank at Treasury and direct the agency to continuously analyze information without individualized suspicion of wrongdoing. H.R. 8464 (Stopping Fraudulent Payments Act) would grant Treasury authority to stop or segment payments based on "fraud-risk indicators," a broad and undefined metric. H.R. 8363 (Pre-Payments Fraud Prevention and Treasury Data Access Act) would expand the Treasury's Do Not Pay system and authorize the agency to gather taxpayer and Social Security information. H.R. 8463 has already passed the House. Critics argue these bills formalize practices used during the DOGE operation at Treasury, which involved illegal disclosure of sensitive personal data. According to a U.S. Government Accountability Office report, Treasury's data security has not fully recovered from DOGE access and remains at risk of improper access and abuse.

EFF Campaigns Against Social Media Age Verification and Ban Legislation

Multiple states including Massachusetts, Idaho, Minnesota, North Carolina, South Carolina, Illinois, and California are advancing legislation to ban or restrict young people from accessing social media platforms. California's AB 1709 would require operating systems to collect age bracket information and block anyone under 16 from social media apps starting January 2027. Florida's HB 3 takes a more aggressive approach by forcing platforms to directly verify user identities through third-party companies. Minnesota's HF 1438 and South Carolina's H 4591 use behavioral age estimation, requiring platforms to analyze user behavior and activity to estimate age. EFF argues these bills create mass surveillance infrastructure, entrench exploitative data collection practices used for behavioral advertising, and will inevitably expand to censor broader categories of lawful speech once the government establishes authority to collect and verify user data.

Senate Judiciary Committee to Consider NO FAKES Act

The Senate Judiciary Committee is set to vote on the Nurture Originals, Foster Art, and Keep Entertainment Safe Act (NO FAKES), which would create a broad property right in a person's look, voice, and general style to address AI-generated replicas. Critics argue the bill would censor First Amendment-protected expression including parody, news, and criticism. The bill creates a property right rather than a privacy right, allowing studios and record labels to require artists to sign away their image rights in contracts. The bill would require platforms to implement filters that identify potential digital replicas, not just exact copyrighted matches, and provides minimal redress for bad faith takedowns.

Section 702 Reauthorization Deadline June 12

Congress faces a Friday, June 12 deadline to reauthorize Section 702 of the Foreign Intelligence Surveillance Act. Section 702 allows the NSA to collect communications from targets overseas, including communications with Americans in the U.S., and store them in databases accessible to the FBI and other agencies. Under current practice, the FBI can query and read the U.S. side of communications without a warrant. The appointment of Bill Pulte as acting Director of National Intelligence has raised concerns about abuse of Section 702 data, as Pulte has a history of using private government data for political purposes during his tenure at the Federal Housing Finance Agency, where he accused political opponents of mortgage fraud. Pulte lacks intelligence, military, or congressional experience but is not subject to Senate confirmation under the Vacancies Act.

UK Weakens Telecoms Cybersecurity Protections After Industry Lobbying

Britain weakened proposed cybersecurity protections for telecommunications networks that were developed in response to the Salt Typhoon espionage campaign, after telecom companies lobbied against cost and practicality. The Department for Science, Innovation and Technology proposed the measures in August as an updated code of practice following state-linked attacks on U.S. telecoms. BT, VMO2, VodafoneThree, Sky, Ericsson, and Amazon Web Services submitted responses opposing the measures. Among the protections dropped is a requirement for providers to deploy an independent signaling intrusion detection system separate from existing controls to monitor for bypassed security controls. The weakened code will take effect in mid-July unless Parliament resolves against it. Providers could face fines up to 10 percent of turnover for failing to meet the statutory duty to take appropriate and proportionate security measures.

Compliance Takeaways