← Carolina Clear Tech

Legal & Privacy Brief

2026-07-10

Listen to this brief (14:56)

Download MP3
Show Notes

Show Notes - 2026-07-10

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - July 10, 2026

Today: The House passed the KIDS Act mandating age verification online, drawing privacy concerns over collection of sensitive identity data. EU enforcement action targets four member states over 20-month delays implementing the NIS2 cybersecurity directive for critical infrastructure. Madison Square Garden faces class action over a cyberattack exposing 26 million records including biometric data.

Enforcement Actions

xAI Memphis Data Center Pollution Lawsuit

Civil rights groups including the Southern Environmental Law Center, Earthjustice, and the NAACP filed suit against Elon Musk's xAI data centers in Memphis for operating 57 gas turbines without required permits under the Clean Air Act. The facility emits over 1,700 tons of nitrogen oxides annually, making it the largest industrial source in the Memphis area, which already fails national smog standards. The turbines also emit 180 tons of fine particulate matter, 500 tons of carbon monoxide, and 19 tons of formaldehyde annually into minority neighborhoods with disproportionately high pollution-caused childhood illnesses. Musk failed to build a promised water filtration system. The DOJ is attempting dismissal on national security grounds.

Litigation Updates

Madison Square Garden Biometric Data Breach Class Action

A class action alleges Madison Square Garden Sports failed to secure personal information of millions of customers, resulting in a cyberattack that compromised more than 26 million records including biometric data. The lawsuit claims inadequate security controls left customer information vulnerable to unauthorized access.

Gas Station Price-Fixing Algorithm Class Action

A California class action accuses Marathon Petroleum, 7-Eleven, and BP Products of conspiring to use artificial intelligence-based algorithms to inflate fuel prices. The lawsuit alleges coordinated use of pricing software constituted unlawful collusion.

AmazonFresh Assistant Manager Misclassification

A collective action alleges AmazonFresh misclassifies assistant store managers to avoid paying overtime wages under the Fair Labor Standards Act. The lawsuit claims ASMs perform non-exempt duties but are classified as exempt from overtime requirements.

Bayer Roundup Federal Litigation Post-Supreme Court

Bayer is seeking dismissal of federal litigation consolidating 4,000 Roundup cancer lawsuits following the Supreme Court's June 25 ruling that plaintiffs cannot sue over warning label failures. Plaintiffs' attorneys argue the ruling was limited to label claims and does not affect design defect and negligence claims.

E. Jean Carroll Payment Order

U.S. District Judge Lewis Kaplan rejected President Trump's request to delay payment of $5.8 million to E. Jean Carroll until after Supreme Court review of the sexual abuse and defamation verdict. Kaplan ordered release of funds from escrow. Trump's attorneys appealed within an hour.

Renaissance Faire Hidden Fees Settlement

Renaissance Entertainment Productions agreed to a $1.9 million class action settlement over claims it failed to disclose service fees for New York Renaissance Faire tickets. The settlement resolves allegations of deceptive fee disclosures.

Regulatory Guidance

EU NIS2 Directive Enforcement Action

The European Commission filed legal referrals at the Court of Justice of the European Union against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive more than 20 months past the October 2024 deadline. The Commission is seeking lump sum and daily financial penalties until each country transposes the directive into domestic law. NIS2 sets minimum security standards for 18 critical sectors including hospitals, energy networks, transport operators, and public administrations. As of January 2025, only six of 27 EU member states had transposed the directive. The directive adds risk management and incident reporting requirements not included in the original 2016 NIS directive.

Latvia Ransomware Attack System Restoration

Latvia's state-owned forestry company LVM continues restoring IT systems weeks after a ransomware attack disrupted mapping platforms, hunting applications, and contractor information exchange systems. The attackers exploited a vulnerability in a system not updated for two years and accessed the network for over a week before detection. Attackers leaked 44 gigabytes of data including internal documents, email correspondence, software code repositories, digital certificates, cryptographic keys, and user credentials. CERT.LV attributed the attack to a foreign financially motivated ransomware group targeting NATO and EU entities. Two-thirds of customers with service contracts still lack system access.

Privacy Developments

World Cup Surveillance Infrastructure Expansion

The U.S. government invested over $1 billion in 2026 FIFA World Cup security surveillance, deploying facial recognition cameras, AI-driven autonomous drones, robot dogs with cameras, and expanded CCTV networks across host cities. Over 120 civil society groups including Amnesty International and the ACLU issued travel advisories warning of invasive social media screening, electronic device searches, racial profiling, arrest, detention, and deportation risks. Facial recognition cameras in stadiums collect and analyze biometric data that can be retained for unknown future uses. States like New York used federal World Cup funding to expand law enforcement drone capabilities with AI-supported monitoring, tracking, and intelligence gathering. Seattle's mayor reactivated a previously shut down CCTV system despite prior biometric privacy concerns. Drones can read text from 60,000 feet and function as cell tower simulators to intercept communications.

Texas Abortion Surveillance Billboards

Mayday Health launched billboard campaigns in Houston warning drivers that Texas law enforcement uses automated license plate readers (ALPRs), location tracking tools like Locate X, and search history data to investigate abortion-related activities. A Texas sheriff's office used data from 83,000 ALPR cameras to track a woman suspected of self-managing an abortion. The billboards reached over 1 million drivers during a four-week campaign. Mayday Health operates a website providing abortion information without collecting cookies or identifying information, and directs visitors to the Digital Defense Fund for privacy and security resources.

Policy Changes

House Passes KIDS Act with Age Verification Mandates

The House passed the KIDS Act 267-117, combining a revised Kids Online Safety Act (KOSA) with multiple internet bills imposing age-gating schemes on online services. The bill now moves to the Senate. The legislation requires platforms to determine which users are under 18, creating mandatory age verification systems. EFF warns no age verification method is both privacy-protective and accurate. Systems may require government-issued ID, biometric scans, or algorithmic age estimation from facial images or online behavior, all of which link offline identity to online activity and create breach risks. The revised KOSA language pressures platforms to police lawful speech by establishing and enforcing policies addressing gambling, alcohol, and cannabis content, encouraging broad deletion of speech on these topics including teens seeking help for parental gambling problems or substance abuse recovery resources.

NSA Restores Tailored Access Operations Designation

The National Security Agency rebranded its Office of Computer Network Operations back to Tailored Access Operations (TAO), the name used before the 2016 NSA21 reorganization. Deputy Director Tim Kosiba spearheaded the change to reunite developers and operators previously separated under NSA21. TAO creates custom software implants and tools to penetrate foreign computer networks for espionage, including the Stuxnet weapon used against Iran's nuclear program. The Shadow Brokers leak of TAO tools in 2017 led to the WannaCry ransomware attack using the EternalBlue exploit, which infected 200,000 organizations across 150 countries. TAO is expected to open a dedicated building at Fort Meade next month.

ICE Office of Professional Responsibility Investigating Critics

ICE's Office of Professional Responsibility has shifted from investigating ICE employee misconduct to investigating external critics and online speech. OPR investigated 131 cases of "doxing and threats directed towards ICE employees nationwide" between January 2025 and March 2026. OPR issued administrative subpoenas to tech companies to unmask online critics and visited a New York poll worker during voting to demand she sign a warning notice and remove an Instagram post crediting news reporting that identified an ICE agent involved in a shooting. The form characterized the post as threatening to assault, kidnap, or murder federal officials. The poll worker refused to sign, viewing it as an admission of guilt.

European Commission Declines Social Media Interoperability Enforcement

The European Commission announced in its first Digital Markets Act review that it will not extend the DMA's interoperability mandate to social networking platforms and provided no enforcement timeline. The Commission stated there is "no clear demand" from users and businesses for social networking interoperability and the technical complexity is too great. The DMA requires interoperability for messaging services despite technical and privacy challenges. ActivityPub and the Fediverse demonstrate existing decentralized networking protocols. The Commission will "continue to monitor and assess how these services evolve" rather than mandate interoperability.

Compliance Takeaways