← Carolina Clear Tech

Legal & Privacy Brief

2026-06-13

Listen to this brief (19:08)

Download MP3
Show Notes

Show Notes - 2026-06-13

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 13, 2026

Today: Section 702 of FISA expired at midnight on June 12, halting new warrantless surveillance orders while existing orders continue. South Korea imposed a record $409 million fine on Coupang for a data breach affecting 33.2 million customers and 4.3 million non-members whose information was stored without consent. The Supreme Court rejected investor suits to enforce the Investment Company Act, restricting enforcement to the SEC. Congress introduced the Right to Record Act to codify protections for filming federal law enforcement. 23andMe bankruptcy administrators approved a $47 million settlement fund for 7 million data breach victims.

Enforcement Actions

South Korea Record Fine for Coupang Data Breach

South Korea's Personal Information Protection Commission imposed a record 624.7 billion won ($409 million) fine on Coupang and its subsidiary Coupang Fulfillment Services following a data breach that compromised 33,222,472 registered members and 4,338,368 non-members whose contact information was stored as delivery recipients without their knowledge. A former Chinese national employee stole authentication signing keys before leaving in late 2024, then systematically harvested customer data through 148 million hits to delivery address pages and 35 million access attempts to account edit pages between January and October 2025. The company failed to detect traffic spikes many times above normal levels or millions of requests using non-existent member IDs. When regulators ordered log preservation on November 21, Coupang manually deleted six months of web access logs six days later and failed to pause automatic deletion policies, destroying 13% of attack period records. The regulator referred Coupang for criminal prosecution over evidence destruction and urged notification of non-member victims four times, which the company ignored each time. The penalty surpasses the previous record $88.8 million SK Telecom fine.

23andMe Bankruptcy Settlement Approved ($47 Million)

A Missouri bankruptcy court administrator approved a $46.8 million settlement fund for approximately 7 million victims of the 2023 23andMe data breach, with $32.5 million allocated to victims and $14.3 million to Kroll as claims administrator. The breach, which began in April 2023, exposed DNA Relatives profiles for 5.5 million customers and Family Tree data for 14.1 million customers. Nearly 256,000 claims have been resolved with awards ranging from $50 for minor claims to $10,000 for the most serious individual harms. Plaintiffs originally sought $48 billion in damages, but the administrator approved the lower amount after finding that protracted litigation would cost millions in professional fees and deplete resources better preserved for stakeholders, given the company's dire financial condition even before the breach. 23andMe, now named Chrome Holding Co., filed for bankruptcy in March 2025 and liquidated most assets before founder Anne Wojcicki bought back the company.

Litigation Updates

Spectrum Data Breach Class Action (40+ Million Records)

Charter Communications faces a new class action alleging failure to properly secure personally identifiable information of Spectrum customers and employees, with over 40 million customer records allegedly exposed in a data breach. The lawsuit accuses the telecommunications provider of inadequate security measures and failure to safeguard PII. No breach notification date or specific attack vector details are available in public filings.

Microsoft Antitrust Class Action Over PC Game Price-Fixing with Steam

Microsoft is facing a class action lawsuit alleging conspiracy with Valve to fix prices for personal computer games. The complaint claims the companies coordinated pricing strategies to maintain artificially high game prices on their respective platforms. No specific damages amount or case docket number is available in public reporting.

Walmart Tariff Refund Class Action

Walmart faces a class action alleging unjust enrichment by retaining money collected from customers to offset tariffs that were later deemed illegal. The lawsuit claims Walmart collected tariff-related price increases from consumers but kept the funds as profits after receiving refunds when the tariffs were invalidated. No settlement or damages amount has been disclosed.

Supreme Court Rejects Judicial Estoppel Rigidity in Bankruptcy (Keathley v. Buddy Ayers Construction)

In a unanimous opinion by Justice Ketanji Brown Jackson, the Supreme Court rejected a rigid application of judicial estoppel that would automatically punish bankrupt debtors for failing to disclose potential post-filing assets to bankruptcy courts. The court held that lower courts must examine the totality of circumstances when determining whether a debtor's omission was inadvertent or a deliberate attempt to conceal assets, rather than applying a conclusive presumption based solely on whether the debtor had a potential motive to conceal. The ruling emphasized that equity "eschews mechanical rules" and requires case-by-case analysis. Justice Clarence Thomas wrote a concurrence joined by Justice Neil Gorsuch, and Justice Sonia Sotomayor wrote a separate concurrence. The decision reverses a lower court ruling that dismissed a personal injury lawsuit by a bankrupt debtor who failed to notify the bankruptcy court of a car accident that occurred after filing.

Supreme Court Rejects Private Enforcement of Investment Company Act (FS Credit Opportunities Corp. v. Saba Capital Master Fund)

In a 6-3 decision, the Supreme Court held that Section 47(b) of the Investment Company Act does not implicitly authorize private parties to sue for rescission of contracts that allegedly violate the Act. Justice Amy Coney Barrett's majority opinion emphasized that "Congress, not the Judiciary, decides who may enforce the law" and refused to imply a private right of action not expressly written into federal law. The court distinguished between remedies and causes of action, finding that Section 47(b)'s language ("a court may not deny rescission at the instance of any party") is "a mandate directed to courts" regarding remedial authority rather than a grant of individual rights. Justice Elena Kagan wrote a dissenting opinion, joined in full by Justice Sonia Sotomayor and in part by Justice Kagan, arguing for implied private enforcement. The ruling restricts Investment Company Act enforcement to the SEC.

Supreme Court Venue Ruling for Document Falsification (Abouammo v. United States)

In a unanimous opinion by Justice Elena Kagan, the Supreme Court held that a defendant charged with knowingly falsifying a document with intent to obstruct a federal investigation must be tried in the district where the falsification occurred, not where the investigation was located. The ruling establishes venue requirements for obstruction of justice prosecutions involving document falsification.

Regulatory Guidance

Section 702 FISA Surveillance Authority Expired

Section 702 of the Foreign Intelligence Surveillance Act expired at midnight on June 12, 2026, marking the first lapse of the warrantless surveillance program since its passage in 2008. The program authorizes U.S. intelligence agencies to collect digital communications of foreigners overseas without a warrant, routinely sweeping in Americans' emails, messages, and calls. The expiration followed failed legislative efforts in both the House and Senate after President Trump's appointment of Bill Pulte (director of Federal Housing Finance Agency, with no military or intelligence experience) as acting Director of National Intelligence enraged Democrats and blindsided Republicans. Trump subsequently nominated Jay Clayton (federal district judge and former SEC chair) for permanent DNI, with Senate Intelligence Committee confirmation hearing scheduled for next week. An intelligence court approved continuation of the FISA program for another year in March, likely meaning existing Section 702 orders continue but the government cannot seek new ones. Key uncertainty remains whether major U.S. communications providers will continue complying with existing court orders without statutory indemnification. In 2024, two service providers informed NSA they would opt out if the program expired. Senator Mark Warner warned that loss of indemnification could cause telecoms to cease participation, potentially triggering court battles similar to the 2008 Yahoo litigation.

Texas Age Verification Law for App Stores (Emergency Supreme Court Appeal)

The Computer & Communications Industry Association filed an emergency request with the Supreme Court to block Texas Senate Bill 2420, which requires app stores to verify users' ages. The appeal follows a U.S. 5th Circuit Court of Appeals ruling that overturned a district court's temporary injunction blocking the law. Texas officials claim the law protects children from harmful content. The emergency application seeks Supreme Court intervention before enforcement begins.

FCC Foreign Router Ban Supply Chain Disruptions

NCTA (The Internet & Television Association), the cable industry's primary lobbying organization, filed a petition with the FCC requesting an expedited waiver from the Trump administration's ban on foreign-manufactured routers, citing unavoidable supply chain shortages and impossibility of onshoring manufacturing. The ban, announced in March under FCC Chairman Brendan Carr, requires router manufacturers to obtain conditional waivers (with undisclosed fees or conditions) to continue U.S. operations. Amazon's Eero and Netgear received exemptions through a non-transparent process with no public disclosure of agreed terms. NCTA's filing notes that AI demand, tariffs, and supply chain constraints make compliance expensive or impossible, and that immediate onshoring of substrate materials and memory modules is not realistic. AT&T suppliers face the same constraints. The petition warns that failure to grant waivers will disrupt broadband availability for large numbers of U.S. consumers and businesses. The policy lacks transparency on what manufacturers must provide in exchange for waivers (financial payments, surveillance backdoors, or other concessions).

Privacy Developments

South Korea Coupang Breach (See Enforcement Actions)

The $409 million Coupang fine establishes precedent for data protection enforcement against companies that store non-customer information without consent and fail to implement basic traffic monitoring. The breach highlights risks of insider threats from former employees with system access and signing key custody.

23andMe Genetic Data Settlement (See Enforcement Actions)

The $47 million settlement for 7 million breach victims establishes a damages baseline of approximately $6.70 per affected individual for genetic data breaches in bankruptcy contexts, significantly below the $48 billion originally sought.

Spectrum 40+ Million Record Breach Lawsuit (See Litigation Updates)

The alleged exposure of over 40 million Spectrum customer and employee records represents one of the larger telecommunications data breaches under litigation in 2026.

Policy Changes

Right to Record Act of 2026 Introduced

Senator Richard Blumenthal (D-Conn.) and Representative Maxwell Frost (D-Fla.) introduced the Right to Record Act of 2026, which would create a federal cause of action allowing individuals to sue federal law enforcement or immigration officers who violate First Amendment rights to document and record police activities. The legislation creates liability for officers who threaten or harass videographers, conduct surveillance on them, or seize and destroy recording equipment. The bill addresses only federal officers (not state or local police) due to recent allegations of Department of Homeland Security officials targeting videographers in New Jersey, Memphis, and other locations, particularly during immigration enforcement operations. DHS officials have suggested that recording officers constitutes doxing and obstruction of justice. The bill eliminates qualified immunity defenses for violations and creates liability for both individual officers and the federal government. The legislation responds to the Supreme Court's refusal to establish the right to record in multiple cert denials despite most lower courts recognizing this right, and to the court's narrowing of Bivens civil rights actions.

Michigan Legislation to Ban Chinese-Tagged Vehicles

Michigan lawmakers introduced the Protecting America From Chinese Cars Act and Connected Vehicle Security Act, which would ban not only sales of Chinese-made vehicles but also prohibit Chinese-tagged vehicles from entering Michigan, including for day trips. Senator Elissa Slotkin and Representative Haley Stevens claim the legislation protects Michigan jobs and national security, characterizing Chinese vehicles as "traveling surveillance packages" that collect data sent to Beijing. The bills do not address the broader vehicle data privacy problem affecting all connected cars regardless of manufacturer origin. U.S. and foreign automakers selling vehicles in the U.S. routinely collect biometric, location, and phone data from drivers and sell this information to unregulated data brokers, who resell access to domestic and foreign intelligence services. The legislation represents protectionism for U.S. automakers facing Chinese EV price competition rather than comprehensive vehicle privacy reform.

Compliance Takeaways