← Carolina Clear Tech

Legal & Privacy Brief

2026-07-16

Listen to this brief (22:11)

Download MP3
Show Notes

Show Notes - 2026-07-16

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - July 16, 2026

Today: 23andMe settles with 42 states for $18 million over a 2023 data breach exposing 6.9 million users' genetic data. Block Inc. pays $45 million to 46 states for misleading Cash App users about fraud protections. California steps back from expanding its age-gating law to browsers and websites, reducing threats to online anonymity.

Enforcement Actions

23andMe Reaches $18 Million Settlement for Cybersecurity Failures

A coalition of 42 state attorneys general secured an $18 million settlement with 23andMe for cybersecurity failings that led to an October 2023 data breach exposing 6.9 million users' genetic ancestry data. The company had no protections against credential stuffing attacks, insufficient intrusion prevention measures, failed to log or monitor for breaches, and did not fix known vulnerabilities. 23andMe initially denied the breach occurred and later blamed consumers for password reuse. The settlement requires the 23andMe Research Institute (which acquired the company's assets in July 2025 for $305 million) to undertake risk assessments, appoint a special board for data security oversight, and maintain users' right to delete genetic samples and personal data indefinitely.

Block Inc. Pays $45 Million Over Cash App Fraud Protection Claims

Block Inc. agreed to pay $45 million to resolve allegations by 46 state attorneys general that it misled consumers about Cash App's safety and fraud protections while failing to adequately protect users from fraud. The multistate investigation found Block made representations about refund protections and customer support while allegedly failing to deliver promised fraud protections and dispute resolution. The consent judgment addresses allegations related to account locks, account suspensions, fraud communications, and compliance with the Electronic Fund Transfer Act and Regulation E. Block must maintain 24-hour telephone support for fraud complaints and educate consumers about common fraud schemes. Block denies wrongdoing and states the agreement resolves a legacy matter primarily relating to historical aspects of its business.

Litigation Updates

Temu Faces California Class Action Over Deceptive Spam Emails and Tracking Pixels (Case No. 2:26-cv-05657)

Dallas Pottish filed a class action complaint against Whaleco Inc. (doing business as Temu) in California federal court alleging violations of California's anti-spam law and Trap and Trace Law. The complaint claims Temu sends spam emails with misleading subject lines (such as "$0.01 False Nails - Ends Soon"), forged headers, and spoofed domains (including privaterelay.appleid.com) to obscure sender identity. After recipients click links and visit Temu's website, the company allegedly installs tracking pixels that monitor online activity and collect personal data without consent. California's Trap and Trace Law requires companies to obtain a court order before installing devices that capture routing or signaling information from electronic communications. Pottish seeks statutory damages of $1,000 per spam email plus punitive damages and injunctive relief on behalf of all California citizens who received spam emails from Temu or had their data collected without consent.

STIIIZY Data Breach Class Action Settlement Reaches $2.95 Million

A $2.95 million class action settlement has been reached for individuals affected by the STIIIZY data breach. Class members who were affected by the breach may be eligible for cash payments from the settlement fund.

Popflex and Redo Tech Sued Over Hidden Return Fee Dark Patterns (Case No. 8:26-cv-00597)

Madison Beikirch and Crystle Caigoy filed a class action in California federal court against oGorgeous Inc. (Popflex) and Redo Tech Inc. alleging violations of state consumer protection laws. The complaint claims Popflex automatically adds a $2.18 "Checkout+ Unlimited Returns or Exchanges" fee without knowledge or consent, displaying it in small text below the subtotal rather than as a cart item. Customers must click a faint link reading "continue without checkout+" to remove the fee, which plaintiffs allege is designed to make shoppers think they would abandon checkout entirely. In Popflex's mobile app, a toggle next to "Unlimited Returns or Exchanges" defaults to "on," but switching it off does not remove the fee, which reappears at checkout. The FTC defines these design practices as "dark patterns" that trick or manipulate users into choices they would not otherwise make. Plaintiffs seek damages, restitution, and injunctive relief for a nationwide class and subclasses in California, New York, and Utah.

Cove USA Accused of Running Perpetual Fake Sales (Case No. 8:26-cv-00789)

Rustle Laich filed a class action against Cove Surf Co. Inc. in California federal court alleging violations of California's False Advertising Law, Consumers Legal Remedies Act, and Unfair Competition Law. The complaint claims Cove runs perpetual sales with fabricated urgency, including a "LIMITED 24HR FLASH SALE" that reset nightly and continued for nearly four weeks. Wayback Machine archives confirmed fake sales ran for more than three months. California's False Advertising Law bars advertising former prices not prevailing in the three preceding months. The complaint also alleges Cove rebranded the same discount as multiple separate sales (December 2025 Holiday Sale became January 2026 New Year's Sale, then March 2026 Spring Sale). Plaintiff seeks damages, restitution, and injunctive relief for all U.S. consumers who purchased products advertised at a discount on Cove's website within the applicable statute of limitations.

Supreme Court Ruling on Bruen Test Survives in United States v. Hemani

The Supreme Court unanimously sustained Ali Hemani's challenge to his indictment under 18 U.S.C. § 922(g)(3) for possessing firearms while being an unlawful user of a controlled substance. Justice Neil Gorsuch's opinion subjects the government's historical evidence to exacting scrutiny, rejecting claims that the law is consistent with founding-era vagrancy laws. The decision confirms the Bruen test from New York State Rifle and Pistol Association v. Bruen (2022) remains the standard for Second Amendment challenges: challengers must show conduct falls within the plain text of the Second Amendment, then government must prove the law is consistent with the nation's historical tradition of firearm regulation. The court dissected the "how" and "why" of founding-era regulations, finding they targeted individuals who did not meet societal expectations of work, not categorically violent persons. Section 922(g)(3) remains on the books but cannot be applied without proper historical analogues.

Fifth Circuit Vacates Due Process Ruling for Migrants, Reheard En Banc

The Fifth Circuit vacated its July 2, 2026 panel opinion recognizing due process rights for migrants detained longer than 90 days and ordered the case reheard en banc. The original panel decision found that migrants arrested long after crossing the border have access to due process rights, but only after 90 days in custody. The majority of circuit judges voted to rehear the case, likely signaling an intent to eliminate even the 90-day delay before due process protections apply. The administration has been relocating detained migrants to Fifth Circuit jurisdictions (Texas, Louisiana, Mississippi) to prevent constitutional challenges during the 90-day window.

Federal Judge Rules Rubio State Department Engaged in Censorship by Denying Visas to Disinformation Researchers

A federal court ruled that the State Department's policy of denying visas to people who work in misinformation/disinformation research, content moderation, fact-checking, or trust and safety roles constitutes unconstitutional viewpoint discrimination. Judge Boasberg held that the policy punishes researchers for their own speech and association regarding disinformation research. The court noted that only government officials or those working directly at the behest of government can engage in censorship of protected expression, while private parties use their own rights of association to determine what content they wish to associate with. The plaintiff organization's (CITR) work depends on researchers who study how platforms structure public debate, report on misinformation, advocate for platform data access, and collaborate to set standards. The policy impairs CITR's ability to determine who will contribute to its reports, what reports can say, who will attach their names, and whether researchers will participate in convenings.

Supreme Court Shadow Docket Decisions Now Outnumber Merits Docket

ProPublica analysis of over two decades of Supreme Court rulings found that when the last term ended, justices issued 63 orders on the shadow docket versus 56 orders on the merits docket where oral arguments are scheduled months in advance and justices issue signed opinions. This marks the first time in modern history that so many consequential decisions were made by secret ballot with few signed opinions. These emergency decisions have thrown lower courts' processes into turmoil and sometimes directly contradicted longstanding legal precedent. The court has used the shadow docket to limit federal courts from issuing nationwide injunctions, diminish Congress' authority over federal agencies, and allow detention of American citizens by immigration agents. Legal scholars state the patterns show a court enabling Trump administration policies that lower courts have blocked, with little to no explanation.

Regulatory Guidance

Trump Administration Announces Gold Eagle Cyber Vulnerability Clearinghouse

The Trump administration announced Gold Eagle, an operative federal clearinghouse housed in the Treasury Department allowing industry, critical infrastructure operators, and government to use artificial intelligence to rapidly detect, prioritize, and patch cybersecurity vulnerabilities. The clearinghouse uses AI (including Anthropic's Mythos model) to detect and fix vulnerabilities at unprecedented speed and scale, enabling vulnerability discovery at levels not seen before. Gold Eagle deconflicts resources, validates vulnerabilities, and coordinates triage among industry and government engineers. The effort is made possible by the CISA 2015 Act, which expires in September 2026. Administration officials stated that without Congressional reauthorization, the effort is fundamentally challenged. Carnegie Mellon University's Software Engineering Institute built the intake platform. The clearinghouse also facilitates a Vulnerability Information and Coordination Environment (VINTS) for processing, secure sharing, validation, prioritization, and disclosure of vulnerabilities.

NYC Implements Click to Cancel Rules and Junk Fee Ban

New York City Mayor Zohran Mamaani announced Executive Orders 9 and 10, which ban all hidden junk fees and implement a "click to cancel" rule guaranteeing consumers can cancel subscriptions as easily as they sign up. The rules follow the Biden FTC's 2024 "click to cancel" rules (which were blocked by the 8th Circuit Court of Appeals before taking effect) and are advised by former FTC Chair Lina Khan. The orders require that if a service can be signed up with one click, it can be cancelled with one click. Enforcement will be critical, as states and municipalities often announce such rules but fail to engage in costly and time-consuming enforcement against deep-pocketed companies.

Privacy Developments

California Legislature Removes Browser and Website Age-Gating Expansion from A.B. 1856

The California legislature stepped back from expanding its age-gating law (A.B. 1043) to browsers and websites, removing the most problematic language from A.B. 1856. The underlying law A.B. 1043 (signed in 2025, effective January 2027) requires operating systems and app stores to collect users' ages, place them in age brackets, and block young people from lawful speech and services based on age. The law fines operating systems up to $7,500 per affected child for violations, creating liability that will likely push services to verify users' ages through ID checks, biometric scanning, and invasive data collection. A.B. 1856 amendments exempted open-source operating systems and removed the expansion to browsers and websites. EFF removed its opposition to A.B. 1856 following these changes but maintains that A.B. 1043 remains unconstitutional as it threatens online anonymity, privacy, and security by encouraging age verification systems that link offline identity to online activity.

Most Wearable Health Devices Lack Transparency Reports and End-to-End Encryption

EFF research found that only two of ten major wearable health device companies (Apple and Google/Fitbit) publish transparency reports on law enforcement data requests. Only these two companies plus Whoop promise to notify users of law enforcement requests. Oura updated its privacy policy in June 2026 to notify users of requests and stated it is actively evaluating transparency reports. Surveys suggest around 40 percent of people in the United States own wearable health devices that collect abundant data with no special health-related privacy protections. Companies share data with third-parties for marketing or to influence insurance rates, or use it to train artificial intelligence models. Wearable data has been critical in law enforcement cases, with surveillance company Penlink calling fitness trackers an "overlooked source" showing movement patterns and heart rate changes. Law enforcement accesses this data through subpoenas or warrants. Few companies offer end-to-end encryption preventing the company itself from accessing health data.

Sony Deletes 551 Purchased Movies and TV Shows from PlayStation Store Accounts

Sony removed 551 films and TV series from PlayStation Store customer accounts on September 1 due to licensing agreement fallout with StudioCanal. This marks the third major content deletion incident (2022 German and Austrian users lost hundreds of movies; 2023 American users lost hundreds of TV episodes after Warner Bros.-Discovery merger). No refunds are provided. Sony's terms and conditions state purchases are temporary licenses for an undetermined time period, but the company does not prominently disclose this limitation, and most customers believe they are buying permanent ownership. The announcements treat content deletion as routine with no apology or compensation.

Policy Changes

Congress Advances KIDS Act Age-Gating Package

The House of Representatives passed the KIDS Act, a package of proposals to control what users can see and say online. Supporters claim the act is needed to protect minors, but the legislation encourages more surveillance instead of protecting privacy. EFF warns that if the KIDS Act becomes law, it will threaten the open internet by mandating age verification and content restrictions. The act represents Congressional efforts to age-gate the internet following state-level initiatives.

Trump Administration Asks Supreme Court to Reconsider Temporary Protected Status for Venezuelan and Haitian Nationals

U.S. Solicitor General D. John Sauer urged the Supreme Court to order the 9th Circuit to reconsider its ruling blocking then-DHS Secretary Kristi Noem's decisions to end Temporary Protected Status (TPS) designations for Venezuela (designated 2021, redesignated 2023, extended through October 2026) and Haiti (designated 2010 after earthquake). The 9th Circuit upheld U.S. District Judge Edward Chen's order setting aside the termination decisions. The Supreme Court's ruling in Mullin v. Doe held that courts generally cannot review the Secretary of Homeland Security's decision to designate or terminate a country under the TPS program, barring review of non-constitutional claims. Sauer argues the 9th Circuit should reconsider based on Mullin and presumably reverse its relief for Venezuelan and Haitian TPS beneficiaries. Challengers' response is due August 12, 2026.

Compliance Takeaways