← Carolina Clear Tech

Legal & Privacy Brief

2026-06-30

Listen to this brief (17:12)

Download MP3
Show Notes

Show Notes - 2026-06-30

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief -- 2026-06-30

Today: The Supreme Court's ruling in Trump v. Slaughter eliminates FTC independence and has structurally destabilized the EU-US Data Privacy Framework, putting transatlantic data transfers by thousands of companies into immediate legal jeopardy. In Chatrie v. United States, the Court held 6-3 that geofence warrants constitute Fourth Amendment searches, extending digital privacy protections to app-generated location data held by third-party tech companies and dealing a significant blow to the third-party doctrine. A $12.67M Delta Dental web tracking settlement and a new DentaQuest class action tied to the ShinyHunters breach add to continuing enforcement pressure on healthcare data privacy.


Enforcement Actions

$12.67M Delta Dental Web Tracking Class Action Settlement

Wyssta Services agreed to a $12.67M settlement resolving claims that web tracking tools deployed on Delta Dental plan member websites collected and transmitted sensitive health information to third parties without consent. Class members may claim up to $16.50. The case follows the same pattern as prior pixel-tracking enforcement actions against hospital and insurance systems, where analytics and advertising tools embedded in member portals were treated as HIPAA-adjacent unauthorized disclosures regardless of whether a formal enforcement proceeding was initiated by OCR.

Lands' End Data Breach Class Action Settlement

A class action settlement is open for consumers whose personal information was compromised in a December 2024 Lands' End data breach. The settlement benefits affected consumers through cash payments and credit monitoring. This case follows the standard post-breach litigation timeline: breach, notification, class certification, and settlement roughly 18 months out.


Litigation Updates

Chatrie v. United States -- Geofence Warrants Are Fourth Amendment Searches

The Supreme Court held 6-3 that law enforcement's use of a geofence warrant directing Google to produce location data for devices near a 2019 Virginia bank robbery constituted a Fourth Amendment "search," requiring probable cause and particularity. Justice Kagan, writing for the majority joined by Roberts, Sotomayor, Kavanaugh, and Jackson, held that individuals retain a reasonable expectation of privacy in cellphone location records even when those records are held by third-party app providers, extending the Carpenter v. United States (2018) framework to shorter-duration surveillance. The Court rejected the government's third-party doctrine argument -- that users forfeit privacy rights by voluntarily sharing location data with Google -- because location history functions as a personal journal of movements revealing "familial, political, professional, religious, and sexual associations." The case was remanded to the Fourth Circuit to assess whether the specific warrant was sufficiently particularized and reasonable. Google's 2023 architectural changes have already made it impossible for the company to respond to new geofence demands, but the ruling applies broadly to any company holding granular location histories, including Uber, Lyft, and Apple.

Trump v. Slaughter -- FTC Independence Eliminated, EU-US Data Privacy Framework in Jeopardy

The Supreme Court ruled 6-3 in Trump v. Slaughter that the FTC's for-cause removal protection violates the constitutional separation of powers, overruling the 91-year-old Humphrey's Executor v. United States (1935) precedent. Chief Justice Roberts held that the President must have full at-will removal authority over FTC commissioners. The ruling broadly covers approximately two dozen multi-member agencies Congress intended to operate independently of executive control. Justice Sotomayor dissented, joined by Kagan and Jackson, warning that the ruling gives the President "far greater power than ever before." Privacy organization noyb immediately called on the European Commission to withdraw the EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision EU 2023/1795), noting that the Framework cites the "independent" FTC 259 times as the required privacy oversight authority. EU treaty law (Article 16(2) TFEU; Article 8(3), Charter of Fundamental Rights) requires independent oversight as a structural condition for adequacy. With the FTC now subject to at-will presidential removal, that condition fails. The Biden-era Data Protection Review Court, the U.S.'s redress mechanism for EU data subjects, is also vulnerable to executive modification without legislation.

DentaQuest Data Breach Class Action -- ShinyHunters Cyberattack

A class action was filed against DentaQuest Group alleging the company failed to protect personal information of thousands of consumers following an attack by the ShinyHunters threat group. ShinyHunters has been attributed to multiple large-scale breaches across healthcare, insurance, and retail sectors, typically exploiting cloud storage misconfigurations and credential theft. The suit alleges inadequate security controls left plan member data -- sufficient for identity theft -- exposed.

Cisco Systems, Inc. v. Doe -- ATS and TVPA Aiding-and-Abetting Claims Eliminated

The Supreme Court held that federal courts cannot create new causes of action under the Alien Tort Statute (ATS) beyond the three categories recognized at the statute's founding (safe conducts, ambassador rights, piracy), and that the Torture Victim Protection Act (TVPA) does not extend to aiding-and-abetting liability because Congress did not include such language in the text. Justice Barrett wrote for the six-Justice majority. The ruling forecloses the primary legal theories plaintiffs have used to hold U.S. technology companies liable in federal court for complicity in international human rights violations, including claims that network equipment, surveillance software, or AI tools were sold to authoritarian governments and used against dissidents or religious minorities.

Evereden Auto-Renewal Class Action -- California Automatic Renewal Law

A class action was filed against Evereden alleging the company automatically renewed subscriptions for its children's bath products without complying with California's Automatic Renewal Law (Business and Professions Code Section 17600 et seq.), which requires clear and conspicuous pre-transaction disclosure of renewal terms and affirmative consumer consent before any recurring charge.


Regulatory Guidance

EU-US Data Privacy Framework: Adequacy at Immediate Risk

Following Trump v. Slaughter, noyb has written formally to the European Commission demanding withdrawal of the adequacy decision underpinning the EU-US Data Privacy Framework (EU 2023/1795). The Commission's decision rests on FTC independence as the structural equivalent of an EU supervisory authority, a requirement of EU treaty law that is now constitutionally impossible for the U.S. to satisfy under the unitary executive framework the Supreme Court has endorsed. European data protection authorities may issue preliminary opinions or begin enforcement proceedings against DPF-reliant transfers before the Commission acts formally. Two prior adequacy decisions were annulled by the CJEU in Schrems I (2015) and Schrems II (2020) with limited transition windows; companies caught without alternative mechanisms in place faced abrupt compliance obligations.


Privacy Developments

UK Age Verification: Third-Party Data Risks for Compliance Teams

As of July 2025, UK platforms hosting content deemed harmful by Ofcom are required to verify user ages under the Online Safety Act. EFF's analysis of the Ofcom-approved verification methods identifies distinct privacy risk profiles across facial age estimation, photo-ID matching, and credit card verification. Third-party verification providers -- including Yoti, Incode, and Persona -- may retain biometric images, government ID scans, or behavioral data beyond the verification event. The EFF guidance recommends auditing whether the vendor's stated claims about retention and third-party sharing are backed by specialized security audits (NCC Group, Trail of Bits class), not merely certification adherence audits, and confirming whether the platform being verified for learns anything beyond a pass/fail age result.


Policy Changes

KIDS Act Passes House 267-117, Senate Passage Uncertain

The Kids Internet and Digital Safety (KIDS) Act passed the House with a two-thirds majority (267-117). Key provisions include: mandatory disclosure by AI chatbots that they are not human, age verification requirements for users seeking to access pornographic content, data broker obligations covering minors' personal information, prohibitions on addictive design features and geolocation sharing with unknown adults, and a ban on ad targeting to minors. The bill does not include a duty of care provision and does not preempt stronger state laws. Senate opposition is substantive: Senators Blumenthal and Blackburn, lead sponsors of the competing Kids Online Safety Act (KOSA) with three-fourths Senate co-sponsorship, have pledged to block the House bill. KOSA includes a duty of care provision absent from the KIDS Act.

Illinois HB 5511 -- Device-Level Age-Gating Pending Governor Action

The Illinois legislature passed HB 5511, which would impose device-level age-gating across nearly all internet-enabled hardware, operating systems, and online services operating in Illinois. Platforms would be required to collect and share user age data and obtain verifiable parental consent before minors can access personalized content feeds or overnight notifications. EFF has formally urged Governor Pritzker to veto the bill, citing privacy and free speech concerns, including that the bill effectively mandates online de-anonymization for all users. The bill mirrors contested California AB 1043 and New York's SAFE for Kids Act frameworks, neither of which has taken effect, been tested in court, or proven technically viable.

AI Lab Coordination Pause -- Antitrust Exposure

Lawfare published an analysis arguing that calls for AI labs to formally pause or slow frontier AI development introduce material antitrust liability. A formal coordination agreement among competing labs to restrict AI output would likely face per se horizontal output restriction treatment under the Sherman Act. Intermediate structures using a mutual auditor to trigger pauses reduce but do not eliminate exposure, because cross-commitments among firms function as coordinated restraints on supply. The features that make a pause effective -- commitment, notification obligations, verification, defection consequences -- are the same features that establish an anticompetitive agreement's existence.


Compliance Takeaways