Get tomorrow's brief in your inbox
Today: The Supreme Court's ruling in Trump v. Slaughter eliminates FTC independence and has structurally destabilized the EU-US Data Privacy Framework, putting transatlantic data transfers by thousands of companies into immediate legal jeopardy. In Chatrie v. United States, the Court held 6-3 that geofence warrants constitute Fourth Amendment searches, extending digital privacy protections to app-generated location data held by third-party tech companies and dealing a significant blow to the third-party doctrine. A $12.67M Delta Dental web tracking settlement and a new DentaQuest class action tied to the ShinyHunters breach add to continuing enforcement pressure on healthcare data privacy.
$12.67M Delta Dental Web Tracking Class Action Settlement
Wyssta Services agreed to a $12.67M settlement resolving claims that web tracking tools deployed on Delta Dental plan member websites collected and transmitted sensitive health information to third parties without consent. Class members may claim up to $16.50. The case follows the same pattern as prior pixel-tracking enforcement actions against hospital and insurance systems, where analytics and advertising tools embedded in member portals were treated as HIPAA-adjacent unauthorized disclosures regardless of whether a formal enforcement proceeding was initiated by OCR.
Lands' End Data Breach Class Action Settlement
A class action settlement is open for consumers whose personal information was compromised in a December 2024 Lands' End data breach. The settlement benefits affected consumers through cash payments and credit monitoring. This case follows the standard post-breach litigation timeline: breach, notification, class certification, and settlement roughly 18 months out.
Chatrie v. United States -- Geofence Warrants Are Fourth Amendment Searches
The Supreme Court held 6-3 that law enforcement's use of a geofence warrant directing Google to produce location data for devices near a 2019 Virginia bank robbery constituted a Fourth Amendment "search," requiring probable cause and particularity. Justice Kagan, writing for the majority joined by Roberts, Sotomayor, Kavanaugh, and Jackson, held that individuals retain a reasonable expectation of privacy in cellphone location records even when those records are held by third-party app providers, extending the Carpenter v. United States (2018) framework to shorter-duration surveillance. The Court rejected the government's third-party doctrine argument -- that users forfeit privacy rights by voluntarily sharing location data with Google -- because location history functions as a personal journal of movements revealing "familial, political, professional, religious, and sexual associations." The case was remanded to the Fourth Circuit to assess whether the specific warrant was sufficiently particularized and reasonable. Google's 2023 architectural changes have already made it impossible for the company to respond to new geofence demands, but the ruling applies broadly to any company holding granular location histories, including Uber, Lyft, and Apple.
Trump v. Slaughter -- FTC Independence Eliminated, EU-US Data Privacy Framework in Jeopardy
The Supreme Court ruled 6-3 in Trump v. Slaughter that the FTC's for-cause removal protection violates the constitutional separation of powers, overruling the 91-year-old Humphrey's Executor v. United States (1935) precedent. Chief Justice Roberts held that the President must have full at-will removal authority over FTC commissioners. The ruling broadly covers approximately two dozen multi-member agencies Congress intended to operate independently of executive control. Justice Sotomayor dissented, joined by Kagan and Jackson, warning that the ruling gives the President "far greater power than ever before." Privacy organization noyb immediately called on the European Commission to withdraw the EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision EU 2023/1795), noting that the Framework cites the "independent" FTC 259 times as the required privacy oversight authority. EU treaty law (Article 16(2) TFEU; Article 8(3), Charter of Fundamental Rights) requires independent oversight as a structural condition for adequacy. With the FTC now subject to at-will presidential removal, that condition fails. The Biden-era Data Protection Review Court, the U.S.'s redress mechanism for EU data subjects, is also vulnerable to executive modification without legislation.
DentaQuest Data Breach Class Action -- ShinyHunters Cyberattack
A class action was filed against DentaQuest Group alleging the company failed to protect personal information of thousands of consumers following an attack by the ShinyHunters threat group. ShinyHunters has been attributed to multiple large-scale breaches across healthcare, insurance, and retail sectors, typically exploiting cloud storage misconfigurations and credential theft. The suit alleges inadequate security controls left plan member data -- sufficient for identity theft -- exposed.
Cisco Systems, Inc. v. Doe -- ATS and TVPA Aiding-and-Abetting Claims Eliminated
The Supreme Court held that federal courts cannot create new causes of action under the Alien Tort Statute (ATS) beyond the three categories recognized at the statute's founding (safe conducts, ambassador rights, piracy), and that the Torture Victim Protection Act (TVPA) does not extend to aiding-and-abetting liability because Congress did not include such language in the text. Justice Barrett wrote for the six-Justice majority. The ruling forecloses the primary legal theories plaintiffs have used to hold U.S. technology companies liable in federal court for complicity in international human rights violations, including claims that network equipment, surveillance software, or AI tools were sold to authoritarian governments and used against dissidents or religious minorities.
Evereden Auto-Renewal Class Action -- California Automatic Renewal Law
A class action was filed against Evereden alleging the company automatically renewed subscriptions for its children's bath products without complying with California's Automatic Renewal Law (Business and Professions Code Section 17600 et seq.), which requires clear and conspicuous pre-transaction disclosure of renewal terms and affirmative consumer consent before any recurring charge.
EU-US Data Privacy Framework: Adequacy at Immediate Risk
Following Trump v. Slaughter, noyb has written formally to the European Commission demanding withdrawal of the adequacy decision underpinning the EU-US Data Privacy Framework (EU 2023/1795). The Commission's decision rests on FTC independence as the structural equivalent of an EU supervisory authority, a requirement of EU treaty law that is now constitutionally impossible for the U.S. to satisfy under the unitary executive framework the Supreme Court has endorsed. European data protection authorities may issue preliminary opinions or begin enforcement proceedings against DPF-reliant transfers before the Commission acts formally. Two prior adequacy decisions were annulled by the CJEU in Schrems I (2015) and Schrems II (2020) with limited transition windows; companies caught without alternative mechanisms in place faced abrupt compliance obligations.
UK Age Verification: Third-Party Data Risks for Compliance Teams
As of July 2025, UK platforms hosting content deemed harmful by Ofcom are required to verify user ages under the Online Safety Act. EFF's analysis of the Ofcom-approved verification methods identifies distinct privacy risk profiles across facial age estimation, photo-ID matching, and credit card verification. Third-party verification providers -- including Yoti, Incode, and Persona -- may retain biometric images, government ID scans, or behavioral data beyond the verification event. The EFF guidance recommends auditing whether the vendor's stated claims about retention and third-party sharing are backed by specialized security audits (NCC Group, Trail of Bits class), not merely certification adherence audits, and confirming whether the platform being verified for learns anything beyond a pass/fail age result.
KIDS Act Passes House 267-117, Senate Passage Uncertain
The Kids Internet and Digital Safety (KIDS) Act passed the House with a two-thirds majority (267-117). Key provisions include: mandatory disclosure by AI chatbots that they are not human, age verification requirements for users seeking to access pornographic content, data broker obligations covering minors' personal information, prohibitions on addictive design features and geolocation sharing with unknown adults, and a ban on ad targeting to minors. The bill does not include a duty of care provision and does not preempt stronger state laws. Senate opposition is substantive: Senators Blumenthal and Blackburn, lead sponsors of the competing Kids Online Safety Act (KOSA) with three-fourths Senate co-sponsorship, have pledged to block the House bill. KOSA includes a duty of care provision absent from the KIDS Act.
Illinois HB 5511 -- Device-Level Age-Gating Pending Governor Action
The Illinois legislature passed HB 5511, which would impose device-level age-gating across nearly all internet-enabled hardware, operating systems, and online services operating in Illinois. Platforms would be required to collect and share user age data and obtain verifiable parental consent before minors can access personalized content feeds or overnight notifications. EFF has formally urged Governor Pritzker to veto the bill, citing privacy and free speech concerns, including that the bill effectively mandates online de-anonymization for all users. The bill mirrors contested California AB 1043 and New York's SAFE for Kids Act frameworks, neither of which has taken effect, been tested in court, or proven technically viable.
AI Lab Coordination Pause -- Antitrust Exposure
Lawfare published an analysis arguing that calls for AI labs to formally pause or slow frontier AI development introduce material antitrust liability. A formal coordination agreement among competing labs to restrict AI output would likely face per se horizontal output restriction treatment under the Sherman Act. Intermediate structures using a mutual auditor to trigger pauses reduce but do not eliminate exposure, because cross-commitments among firms function as coordinated restraints on supply. The features that make a pause effective -- commitment, notification obligations, verification, defection consequences -- are the same features that establish an anticompetitive agreement's existence.
Activate SCCs for EU-US transfers immediately. Trump v. Slaughter has eliminated the structural basis for the EU-US Data Privacy Framework. Execute Standard Contractual Clauses (Commission Decision 2021/914) for all EU-to-US data export relationships and complete transfer impact assessments before any formal Commission action or CJEU referral. Both prior adequacy decisions were annulled with limited transition time.
Location data and third-party doctrine: update law enforcement response policies. Chatrie v. United States requires probable cause warrants for geofence searches and has significantly weakened the third-party doctrine for app-generated data. Any geofence, reverse-keyword, or broad location data demand should be routed to legal counsel before response. Audit whether your product retains granular location histories subject to future compelled disclosure.
Healthcare portals: remove or gate unauthorized web trackers. The $12.67M Delta Dental settlement confirms that analytics and advertising pixels on member or patient portals generate class action liability even absent OCR enforcement. Conduct a full third-party script inventory and confirm legal basis for each data flow. Execute BAAs with vendors processing PHI-adjacent data.
Assess ShinyHunters exposure in dental and insurance sectors. The DentaQuest class action extends a pattern of ShinyHunters-linked breaches across healthcare adjacent sectors. Prioritize cloud storage access control audits, credential exposure monitoring, and third-party vendor access reviews. Confirm that breach litigation defense costs are covered separately from first-party incident costs in your cyber policy.
Kids online safety: build for state law, not federal. The KIDS Act faces a Senate block. California AB 1043 (effective January 2027), New York's SAFE for Kids Act, and Illinois HB 5511 (pending veto) create binding state-level obligations for platforms serving minors. Begin compliance infrastructure assessments for the California and New York laws now; they take effect first and carry the broadest geographic reach.