Get tomorrow's brief in your inbox
Today: A Supreme Court ruling threatens the EU-US Data Privacy Framework by undermining FTC independence, the same court greenlit presidential removal of FTC commissioners without cause. X Corp petitions to escape its 2022 privacy consent decree, while Roku settles Florida children's privacy claims. EFF and allies urge the FTC to reject X's petition, arguing corporate restructuring doesn't dissolve privacy obligations.
Farmers Insurance Telemarketing Settlement ($2.87M)
Farmers Insurance agreed to pay $2.87 million to resolve a class action alleging violations of the federal Telephone Consumer Protection Act (TCPA) through unsolicited telemarketing calls and texts. The settlement resolves claims that the company contacted consumers without prior consent, violating federal restrictions on automated dialing systems and prerecorded messages.
Roku Settles Florida Children's Privacy Claims
Roku reached a settlement with the Florida Attorney General's Office over allegations that the streaming platform unlawfully collected and sold children's personal information in violation of state privacy laws. The settlement follows enforcement action targeting the company's data collection practices related to minors.
FirstBank Class Action Alleges Facilitation of Epstein Sex Trafficking
A class action lawsuit accuses FirstBank Puerto Rico and parent company First BanCorp of facilitating Jeffrey Epstein's sex trafficking operation by providing banking services to Epstein and his associates for more than two decades. The lawsuit alleges the banks failed to identify and report suspicious transactions despite red flags indicating criminal activity.
ButcherBox Faces California Automatic Renewal Law Violation
A class action lawsuit alleges ButcherBox violated California's Automatic Renewal Law by failing to make clear and conspicuous disclosures about its subscription service. The complaint targets the company's cancellation policy and subscription renewal practices, claiming consumers were not adequately informed about automatic renewals.
Supreme Court Qualified Immunity Ruling (Sotomayor Dissent)
The Supreme Court granted qualified immunity to Wisconsin jail officers who confined a prisoner naked in a freezing cell (25-57°F) for 23 hours, despite the Seventh Circuit finding an Eighth Amendment violation. Justice Sotomayor's dissent criticized the majority for cherry-picking qualified immunity cases to reverse, creating what she characterized as a "get-out-of-lawsuit-free card" for government employees. The case involved Antonio Smith, who was pepper-sprayed, stripped, and confined during a hunger strike wellness check dispute.
Palantir Loses Swiss "Right of Reply" Lawsuit
Zurich's commercial court rejected 22 of 23 claims in Palantir's lawsuit against Swiss magazine Republik. Palantir sued to force publication of company rebuttals to critical reporting on its attempts to sell surveillance technology to the Swiss government. The court ruled only one passage in one article warranted a limited published reply, and ordered Palantir to pay 95% of court costs (9,000 Swiss francs) plus 9,900 francs in Republik's legal expenses.
DC Settles First Amendment Lawsuit Over "Imperial March" Arrest
The District of Columbia reached an undisclosed settlement with Sam O'Hara, a resident arrested for playing Darth Vader's theme music while following National Guard troops during a federal law enforcement surge. O'Hara was arrested for alleged harassment despite engaging in clearly protected First Amendment activity. The lawsuit, filed by the ACLU, alleged unlawful detention and violation of free speech rights.
Supreme Court Ruling Threatens EU-US Data Privacy Framework
A Supreme Court decision allowing presidents to remove members of independent agencies at will threatens the EU-US Data Privacy Framework (DPF), which facilitates €1.7 trillion in annual transatlantic trade. Privacy advocate Max Schrems announced plans to sue to invalidate the DPF, arguing the ruling undermines the FTC's independence, which the European Commission cited 259 times as justification for allowing data transfers to US companies. The FTC's independence is central to the DPF's legitimacy. If invalidated, Meta and Google have indicated they will pull out of Europe.
FTC Independence Decision (Trump v. Slaughter and Trump v. Cook)
The Supreme Court held that the FTC's powers are "executive through and through," allowing presidents to remove FTC commissioners without cause. The decision overturns 91 years of precedent from Humphrey's Executor v. United States. Chief Justice Roberts wrote that the FTC's rulemaking, enforcement, and litigation powers are quintessentially executive functions. The companion case, Trump v. Cook, preserved the Federal Reserve's independence by allowing Congress to protect Federal Reserve governors from at-will removal.
X Corp Petitions FTC to Escape Privacy Consent Decree
X Corp filed a petition with the FTC to set aside or modify a 2022 consent decree requiring the company to report regularly to the FTC for privacy violations. The order, which runs until 2042, fined Twitter (now X) $150 million for using phone numbers and email addresses collected for account security to instead target advertising to 140 million users. EFF and allies (Demand Progress Education Fund, National Consumers League, EPIC) filed comments urging the FTC to reject the petition. X argues corporate restructuring and new leadership justify terminating oversight, but civil society groups counter that FTC orders bind the corporate entity regardless of personnel changes. The groups also note X's recent privacy failures, including training its Grok AI model on user data without meaningful consent and a 2025 data breach.
European Parliament Member Infected with Pegasus Spyware
Citizen Lab researchers found that former European Parliament member Stelios Kouloglou's phone was infected with NSO Group's Pegasus spyware in October 2022 and March 2023 while he served on the PEGA Committee investigating commercial spyware abuse. The infections occurred during sensitive committee work preparing recommendations for tackling spyware misuse in Europe. The European Commission has largely ignored the committee's May 2023 recommendations. Citizen Lab linked the Kouloglou attacks to the same Pegasus customer responsible for targeting seven Russian and Belarusian journalists and opposition figures between 2020 and 2023.
EFF Guide: Wiping Online Data Pointing to Queer Identity
EFF published guidance for removing personal data online that could identify LGBTQ individuals. The guide covers two primary data sources: sites where users voluntarily posted data (social media, forums, reviews) and data brokers who collect, repackage, and sell personal information. Recommended actions include removing advertising IDs from phones, using Privacy Badger to block trackers, requesting deletion from data brokers via California Privacy Protection Agency tools or services like EasyOptOuts and Optery, and using Google's "Results about you" page to suppress personal information from search results (though not from the internet itself).
UK National Cyber Action Plan Delayed Amid Labour Leadership Crisis
The UK's National Cyber Action Plan, the government's strategy for defending the economy against state-backed and criminal hacking, was delayed following Prime Minister Keir Starmer's resignation. The plan was due for publication July 1 but has been postponed amid the Labour Party's leadership contest, which opens July 9. A voluntary Cyber Resilience Pledge signing by FTSE 350 companies is still expected to proceed July 2. The delay adds to concerns that cybersecurity remains a low political priority in Westminster, following similar delays to the Cyber Security and Resilience Bill (now not expected to be enforced until 2028, a decade after the regulations it replaces) and ransomware proposals that were scuppered by the 2024 election.
Cybersecurity Mission Creep Analysis
A new academic paper titled "Cybersecurity Mission Creep" analyzes how policymakers increasingly reframe diverse policy issues (misinformation, child social media safety, antitrust, journalist misconduct, anti-sex trafficking) as cybersecurity threats to access "the politics and law of urgency and exceptionalism." The paper argues this "cybersecuritization" oversimplifies problems, invites unidimensional solutions, defers to specialists, and erodes public trust through opacity. The author contends that framing issues as cybersecurity threats grants them "normative power to override countervailing considerations" and invites First Amendment trump cards.
Prepare for DPF invalidation. Companies using the EU-US Data Privacy Framework for transatlantic data transfers should immediately assess Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs) as alternative legal mechanisms. Monitor EDPB guidance and Max Schrems' pending litigation.
Audit TCPA compliance after $2.87M Farmers Insurance settlement. Review all telemarketing practices and consent documentation. Verify express written consent exists for all automated or prerecorded calls. Update procedures to prevent TCPA violations.
Review California Automatic Renewal Law compliance. Ensure subscription service disclosures are clear and conspicuous at the point of sale. Make cancellation procedures prominent and easily accessible. Do not bury auto-renewal terms in general terms of service.
Understand consent decree obligations survive corporate restructuring. The X Corp petition demonstrates that FTC consent decrees bind the corporate entity, not specific personnel. Leadership changes and corporate restructuring do not provide grounds for modification or termination.
Children's privacy enforcement continues. The Roku settlement signals ongoing state AG enforcement of children's data protection laws. Platforms serving minors must maintain COPPA compliance, verify parental consent mechanisms, and audit third-party data sharing to ensure no monetization of children's data without authorization.