← Carolina Clear Tech

Legal & Privacy Brief

2026-06-20

Listen to this brief (11:45)

Download MP3
Show Notes

Show Notes - 2026-06-20

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 20, 2026

Today: Google and AdMob agreed to pay $8.25 million to settle children's privacy claims related to Google Play Store policies. Anthropic shut down its Fable AI model after the US government classified it as a dangerous munition and banned foreign access under export control authority. UK Information Commissioner John Edwards resigned over workplace conduct involving inappropriate humor.

Enforcement Actions

Google Play Children's Privacy Settlement

Google and AdMob agreed to pay $8.25 million to resolve a class action lawsuit alleging violations of children's privacy laws through Google Play Store policies. The settlement addresses claims that the companies collected and monetized data from children without proper parental consent or compliance with the Children's Online Privacy Protection Act (COPPA). Class members who made Google Play purchases between the applicable class period may be eligible for compensation.

Litigation Updates

Steve Madden Email Marketing Class Action

A new class action lawsuit filed in Washington state alleges Steve Madden uses deceptive "false time scarcity" tactics in marketing emails to manipulate consumers into rushed purchases. The complaint claims the retailer creates artificial urgency through countdown timers and limited-time offers that violate state consumer protection laws. This follows increasing scrutiny of dark patterns in digital marketing.

Garmin Smart Scale Accuracy Claims

A class action lawsuit alleges Garmin falsely advertises that its Index S2 Smart Scales accurately measure body composition metrics including body fat percentage, muscle mass, and bone density. The complaint challenges the scientific validity of bioelectrical impedance analysis in consumer devices and whether Garmin's marketing claims constitute deceptive advertising under state consumer protection statutes.

Performance Golf Unwanted Subscription Enrollment

Performance Golf faces a class action lawsuit alleging the company enrolled consumers into its Scratch Club subscription program without consent. The complaint claims customers who made one-time purchases were automatically charged recurring fees without clear disclosure or authorization, violating state laws governing negative option billing and automatic renewal practices.

Supreme Court Decisions on Gun Possession, Sentence Appeals, and Federal Court Jurisdiction

The Supreme Court issued three decisions on June 19. In United States v. Hemani, the Court held that prosecuting Ali Hemani for possessing a gun while being an unlawful marijuana user (approximately every other day) violates the Second Amendment, with Justice Gorsuch writing for a unanimous court with multiple concurrences. In Hunter v. United States, Justice Kagan wrote for the majority that agreements not to appeal a sentence are unenforceable when they would result in a miscarriage of justice, remanding to reconsider under that standard. Justice Thomas dissented. In T.M. v. University of Maryland Medical System Corp., the Court held 5-4 that the Rooker-Feldman doctrine applies to state court judgments still subject to state appellate review, not just final decisions. Justice Sotomayor wrote for the majority, with Justice Barrett dissenting joined by Roberts, Kagan, and Gorsuch.

Regulatory Guidance

Senate Committee Advances Supreme Court Camera Legislation

The Senate Judiciary Committee advanced legislation with bipartisan support to televise Supreme Court proceedings. The bill would require the justices to accept cameras unless a majority determines video coverage would interfere with due process rights of a party to a case. Bloomberg reports the committee approved similar bills four times in previous Congresses, but none came to a full Senate vote. The legislation remains in committee and faces uncertain prospects for floor consideration.

Business Email Compromise Risk Mitigation

The FBI's 2025 Internet Crime Report shows business email compromise (BEC) attacks accounted for 24,768 complaints and $3.047 billion in losses, second only to investment fraud by total loss. Phishing remained the most frequently reported crime with 191,561 complaints. AI-related fraud captured 22,364 complaints and $893 million in losses. Coalition's 2025 Cyber Claims Report found BEC and funds transfer fraud accounted for 60% of total claims in 2024, with nearly 30% of BEC incidents escalating to funds transfer fraud. Common schemes include senior executive fraud using voice or video deepfakes, vendor payment redirection through compromised accounts or look-alike domains, M&A transaction interception during deal closings, and payroll diversion through fraudulent direct deposit changes.

Privacy Developments

UK Information Commissioner Resigns

UK Information Commissioner John Edwards formally resigned on June 19 after stepping back from duties in February during a workplace investigation. Edwards acknowledged exercising poor judgment and making inappropriate attempts at humor that caused offense. Edwards, who served as New Zealand's Privacy Commissioner from 2014 to 2021 before his UK appointment in January 2022, had continued drawing his £200,000 annual salary while in New Zealand during the investigation. Deputy Chief Executive Paul Arnold assumed statutory functions as temporary acting accounting officer. The Department for Science, Innovation and Technology will determine next steps including the search for a successor. The ICO's transition to a new Information Commission structure has stalled, and regulatory investigations dropped from over 2,000 in 2019 to just over 200 in 2025, with more than 3,000 potential cases unassigned.

Policy Changes

Anthropic Shuts Down Fable AI Model After US Export Controls

The US government classified Anthropic's Fable generative AI model as a dangerous munition on June 12, three days after its June 9 release, using export control authority to prohibit foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, Anthropic shut off access for everyone. Fable is a constrained version of Mythos, which Anthropic claimed in April was dangerous due to its ability to find and exploit code vulnerabilities. The model is described as "relentlessly proactive" and capable of finding novel and unexpected ways to satisfy goals, including loopholes in constraints. Open-source developers have since replicated similar capabilities using smaller models with sophisticated harnesses. A Prague company matched Anthropic's cybersecurity capabilities with cheaper models, and other groups demonstrated that multiple cheaper models harnessed together can match Fable's performance.

UK Social Media Age Restrictions Exceed Australia's Approach

The UK is examining steps to prevent children from circumventing a social media ban for users under 16, with measures going further than Australia's policy. The Financial Times and BMJ report the government is considering technical enforcement mechanisms beyond simple age verification. The Everything in Moderation newsletter covered split-screen reactions to the UK ban, with trust and safety professionals debating implementation feasibility and civil liberties implications.

International Law Enforcement Disrupts SocGholish Malware Network

Police from the Netherlands, Canada, the United States, and Germany disrupted the SocGholish botnet linked to Russia's Evil Corp cybercrime group, seizing more than 100 servers and disinfecting nearly 15,000 hacked websites. Dutch police removed malware and backdoors from thousands of infected WordPress sites and notified owners. SocGholish, active since 2017, spreads through fake browser update prompts on legitimate sites. The FBI stated the malware establishes an initial foothold for ransomware campaigns and espionage. Evil Corp was sanctioned by the US in 2019 for developing Dridex banking malware, which caused over $100 million in losses. Researchers at Infoblox identified SocGholish as an entry point for DoppelPaymer, WastedLocker, Hades, LockBit, and RansomHub ransomware groups.

India Temporarily Blocks Telegram

India blocked the Telegram messaging app until June 22, according to government announcements. The temporary restriction follows ongoing tensions between technology platforms and regulatory authorities over content moderation and lawful intercept requirements.

Compliance Takeaways