Get tomorrow's brief in your inbox
TP-Link faces UK consumer protection probe over privacy practices The UK's Competition and Markets Authority (CMA) opened an investigation into TP-Link's smart security cameras after finding products failed to properly disclose AI surveillance features and marketed products differently than their actual capabilities. The CMA is evaluating whether TP-Link violated consumer protection law by collecting and using customer video data without adequate notice or control. This follows similar enforcement patterns where regulators scrutinize IoT manufacturers for unclear privacy practices around AI-powered features.
Halliburton cyber incident costs reach $35 million Halliburton disclosed in SEC filings that a ransomware attack earlier this year cost the company $35 million in direct response and recovery costs. The oil services giant suffered business disruptions across multiple facilities when attackers gained access to internal systems. While the filing does not specify regulatory penalties, companies in critical infrastructure face heightened scrutiny from CISA and sector regulators following material cyber incidents. Organizations should budget for both technical remediation and potential regulatory investigation costs when calculating cyber incident reserves.
FTC cracks down on TurboTax for deceptive free filing claims The Federal Trade Commission finalized a $141 million settlement with Intuit over deceptive advertising in its TurboTax "free" filing campaigns. The FTC found Intuit advertised free tax preparation but then charged most customers after they had already invested time entering data. The agency determined this constituted unfair and deceptive practices under Section 5 of the FTC Act. The settlement requires direct payments to affected consumers and prohibits future misleading advertising about free services. This enforcement demonstrates the FTC's continued focus on dark patterns and bait-and-switch tactics in consumer software.
California AG targets data brokers under new CCPA provisions California Attorney General Rob Bonta announced enforcement actions against data brokers who failed to register under California's data broker registry requirement. The CCPA amendments enacted in 2023 require businesses that sell California resident data to register annually and pay fees. The AG's office identified multiple companies selling consumer profiles, location data, and behavioral analytics who never registered. Penalties include $200 per day per violation. Organizations that monetize consumer data, including through advertising partnerships or lead generation, should audit whether they meet California's data broker definition.
Plaintiff wins $8.3 million in biometric privacy class action An Illinois court approved an $8.3 million settlement in a class action against a retail employer accused of collecting employee fingerprints for timekeeping without proper BIPA consent. The Biometric Information Privacy Act requires written notice and consent before collecting biometric identifiers. The settlement provides per-person damages averaging $1,200 for approximately 6,900 class members. Illinois courts have consistently held that BIPA violations allow statutory damages even without proof of actual harm, creating significant financial exposure for employers using biometric timekeeping, access control, or authentication systems.
Wiretap claims survive dismissal in website tracking lawsuit A federal district court refused to dismiss wiretap claims against a healthcare provider that used Meta Pixel tracking on patient portal login pages. The court found that intercepting communications between the user and the website in real time could constitute wiretapping under both federal and state law, even if the interception happens via JavaScript rather than network-level capture. The decision creates risk for organizations using third-party analytics and advertising pixels on pages where users enter sensitive information, particularly in healthcare, finance, and legal services sectors.
Data breach notification lawsuit advances on adequacy grounds A Texas appeals court allowed a class action to proceed against a company that sent data breach notifications by postcard rather than sealed envelope. Plaintiffs argued the notification method itself created additional privacy harm by exposing breach details to mail carriers and household members. The court found these allegations sufficient to establish standing and move past motion to dismiss. Organizations should review notification methods to ensure they do not inadvertently create additional exposure beyond the underlying breach.
Airline sued over wheelchair damage disclosure practices Southwest Airlines faces a proposed class action alleging the carrier violated disability rights laws by failing to properly track and disclose wheelchair damage incidents. Plaintiffs claim Southwest's internal reporting systems undercounted damaged wheelchairs, preventing passengers from making informed decisions about checking mobility devices. While the case centers on the Air Carrier Access Act rather than data privacy statutes, it illustrates growing litigation around disclosure obligations when companies maintain customer safety or incident data.
CISA releases secure software attestation framework The Cybersecurity and Infrastructure Security Agency published final guidance for software suppliers to attest their products meet secure development practices. The framework implements requirements from OMB M-22-18, which mandates federal agencies only procure software with vendor-signed attestations covering secure coding, vulnerability management, and supply chain security. While the requirement currently applies only to federal procurement, CISA indicated the framework will likely influence state and private sector contracting. Software vendors serving government customers or critical infrastructure should begin documenting development security controls to support attestation requirements.
FCC proposes caller ID authentication enforcement The Federal Communications Commission proposed rules to require voice service providers to block calls that lack proper STIR/SHAKEN authentication. The proposal would mandate blocking within six months and establish penalties for providers who fail to implement authentication or continue carrying verified spoofed traffic. The rulemaking follows years of voluntary adoption that reduced but did not eliminate robocalls using forged caller ID. Organizations that place legitimate outbound calls, particularly for authentication or fraud alerts, should verify their providers support STIR/SHAKEN to avoid future blocking.
DOJ updates corporate criminal enforcement policy The Department of Justice revised its corporate criminal enforcement policy to clarify how cooperation credit is evaluated when companies report misconduct. The updated policy emphasizes timely disclosure, full remediation, and compensation of victims as key factors in declination or reduced penalty decisions. DOJ clarified that companies cannot receive full cooperation credit if they delay reporting until after government inquiry begins. General counsel should review incident response plans to ensure legal holds and voluntary disclosure protocols align with DOJ's cooperation expectations.
European Data Protection Board issues AI training guidance The EDPB adopted formal guidance on using personal data to train artificial intelligence models under GDPR. The opinion addresses lawful basis requirements, transparency obligations, and data subject rights in AI training contexts. Key findings include that legitimate interest is rarely an appropriate basis for training on scraped personal data, consent must be specific to the AI use case, and individuals retain rights to access and deletion even after model training. Organizations training models on European user data should audit legal basis documentation and implement technical measures to support data subject rights.
Montana passes comprehensive privacy law Montana enacted comprehensive consumer privacy legislation requiring businesses to honor opt-out requests, conduct data protection assessments for high-risk processing, and provide detailed privacy notices. The law follows the structure of Connecticut and Colorado's frameworks rather than California's CCPA model. Effective January 2025, it applies to businesses that control data of at least 50,000 Montana residents or derive over 25% of revenue from data sales. Unlike some state laws, Montana's version does not include a private right of action and relies solely on attorney general enforcement.
Brazil updates LGPD consent requirements Brazil's data protection authority (ANPD) published binding guidance requiring consent requests to use plain language, avoid bundled consent for unrelated purposes, and provide granular controls for different data uses. The guidance prohibits consent walls that block service access for users who decline optional data collection. Organizations operating in Brazil should review consent forms and update denial-of-service logic to ensure basic functionality remains available when users opt out of non-essential processing.
UK finalizes adequacy decision for international transfers The UK government finalized an adequacy decision covering data transfers to South Korea under UK GDPR. The decision allows personal data to flow from the UK to Korean recipients without additional safeguards like standard contractual clauses. The determination followed the UK's review of Korean privacy law and found it provides essentially equivalent protections. Organizations with UK and Korean operations can simplify cross-border transfer mechanisms for employee, customer, and business partner data.
California advances genetic privacy protections California lawmakers advanced legislation to extend CCPA protections specifically to genetic information collected by direct-to-consumer DNA testing companies. The bill would prohibit selling genetic data without explicit opt-in consent, require destruction upon request, and mandate annual transparency reports disclosing law enforcement requests. The legislation responds to concerns about genealogy databases used in criminal investigations and insurance underwriters accessing genetic risk data. Companies that collect biological samples or genetic markers should monitor the bill's progress and prepare for stricter consent and deletion obligations.
White House issues AI safety executive order The administration issued an executive order establishing AI safety and security standards for federal agencies and federally-funded research. Key provisions include mandatory safety testing for models above defined compute thresholds, watermarking requirements for AI-generated content, and restrictions on using AI systems for certain high-risk decisions without human review. While the order directly applies only to government use and procurement, industry observers expect it to influence voluntary frameworks and potential future legislation. Organizations developing or deploying AI should review the order's risk management principles and testing protocols as likely previews of broader regulatory expectations.
State legislatures push back on federal privacy preemption The National Association of Attorneys General submitted comments opposing federal privacy legislation that would preempt existing state laws like CCPA and GDPR-equivalent frameworks. The letter argues state laws drive innovation in privacy protections and federal preemption would weaken existing consumer rights in states with comprehensive frameworks. This signals continued tension between state-level privacy enforcement and efforts to establish a uniform federal standard. Organizations should plan for continued state-by-state compliance rather than assuming federal legislation will create a single national framework.
Congress advances kids' online safety bills The Senate Commerce Committee advanced legislation requiring social media platforms to disable addictive features by default for users under 18, provide parental controls, and conduct annual independent audits of child safety practices. The bill includes provisions requiring age verification but allows platforms flexibility in implementation methods. Privacy advocates have raised concerns about age verification creating new data collection and surveillance risks. Platforms and age verification vendors should monitor the bill's progress and prepare for significant changes to default settings and verification requirements if enacted.
FTC explores commercial surveillance rulemaking The Federal Trade Commission held a public hearing on potential rules governing commercial surveillance and lax data security practices. Commissioners heard testimony on topics including data minimization requirements, algorithmic discrimination, and mandatory security standards. Chair Khan indicated the FTC is considering whether to use its rulemaking authority under Section 5 to establish baseline privacy and security requirements beyond case-by-case enforcement. Organizations should monitor the FTC's advanced notice of proposed rulemaking, expected later this year, and prepare comments on how broad privacy rules would interact with existing state laws and sector-specific regulations.
Audit third-party tracking on authenticated pages The website tracking wiretap decision creates immediate risk for organizations using analytics, advertising, or chat tools on pages where users enter credentials or sensitive information. In-house counsel should work with IT and marketing teams to inventory all third-party scripts on login pages, account portals, checkout flows, and forms collecting health, financial, or legal data. Consider moving analytics to first-party collection or implementing consent gates before loading third-party trackers. The risk is highest in healthcare, financial services, and legal sectors where courts have found enhanced privacy expectations.
Review data broker registration obligations California's enforcement against unregistered data brokers demonstrates the AG's office is actively identifying violators rather than waiting for complaints. Organizations should evaluate whether they meet the data broker definition, which includes not only traditional data aggregators but also companies that share customer data with advertising platforms, sell leads to third parties, or monetize user analytics. Registration costs $400 annually but non-compliance carries $200 per day penalties. Legal teams should document the analysis even if concluding registration is not required, as AG investigators may inquire during unrelated matters.
Prepare for STIR/SHAKEN blocking Organizations that use outbound calling for customer authentication, fraud alerts, or service notifications should verify their voice providers support caller ID authentication. Once the FCC's proposed blocking rules take effect, unauthenticated calls face higher risk of being blocked by carriers as spam. Contact your voice service provider to confirm STIR/SHAKEN implementation status and ask whether your calling numbers are properly registered and attested. Consider alternative channels like SMS or app notifications for critical communications to reduce dependence on voice calls.
Budget for biometric consent and breach exposure The $8.3 million BIPA settlement demonstrates ongoing financial risk for employers and service providers using biometric authentication without proper consent protocols. Organizations using fingerprint readers, facial recognition, or voice authentication should audit notice and consent procedures, particularly for systems deployed before 2023. Illinois BIPA claims allow statutory damages of up to $5,000 per violation, creating massive exposure in class actions covering thousands of employees or customers. Budget for both remediation costs and potential litigation reserves if you operate in Illinois or other states considering similar biometric privacy laws.
Document AI training data sources The EDPB's guidance on AI training clarifies that legitimate interest cannot justify training models on personal data scraped from the web or obtained without clear notice. Organizations training models on customer data, user-generated content, or third-party datasets should document lawful basis for each data source and implement processes to honor deletion requests. This may require maintaining metadata linking training examples to source users, even if the production model does not store raw data. Companies without documented legal basis for training data face enforcement risk in Europe and likely similar scrutiny from US state attorneys general under consumer protection statutes.
Published July 2, 2026 Carolina Clear Tech | carolinacleartech.com/legal-brief