← Carolina Clear Tech

Legal & Privacy Brief

2026-07-28

Listen to this brief (13:36)

Download MP3
Show Notes

Show Notes - 2026-07-28

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: The Trump administration asked the Supreme Court to enforce new mail-in voting restrictions before November elections despite a federal injunction. The Energy Department admitted in court filings that it canceled $7.5 billion in clean energy grants based solely on political criteria, targeting Democratic states. A UK court ruled Bahrain cannot claim state immunity to block a lawsuit over FinSpy spyware targeting dissidents.

Enforcement Actions

$450,000 Stanford Federal Credit Union NSF Fee Settlement

Stanford Federal Credit Union agreed to pay $450,000 to settle class action claims challenging its overdraft and non-sufficient funds (NSF) fee policies. The settlement resolves allegations that the credit union's fee assessment practices violated consumer protection standards.

$1.5 Billion Anthropic AI Training Settlement Approved

A federal judge granted final approval to a $1.5 billion class action settlement resolving claims that Anthropic PBC used pirated books without authorization to train Claude, its AI chatbot. The settlement represents one of the largest copyright infringement resolutions in the AI training litigation wave and establishes precedent for how AI companies must compensate rights holders for training data.

Energy Department Admits Political Termination of $7.5 Billion in Grants

The Department of Energy acknowledged in court documents that it terminated $7.5 billion in Biden-era clean energy grants based solely on political criteria, targeting projects in states that voted for Kamala Harris in 2024 and have two Democratic senators. The DOE stipulated that the differential treatment between Blue State and non-Blue State grants was not based on any rational connection to agency priorities. This admission contradicts the administration's public claims that the cancellations were necessary to prevent waste.

Litigation Updates

UK Supreme Court Rejects Bahrain State Immunity in Spyware Case

The United Kingdom's Supreme Court ruled 3-2 that Bahrain cannot invoke state immunity to block a lawsuit filed by dissidents Saeed Shehabi and Moosa Mohammed, who allege the government infected their devices with FinSpy spyware around 2011. The court found that because the alleged hacking occurred in the UK, state immunity does not apply. The plaintiffs claim Bahraini officials used the spyware to monitor their work with political prisoners, journalists and torture victims by accessing laptop data, intercepting communications, and using device microphones and cameras for surveillance. FinSpy, also known as FinFisher, was sold exclusively to governments for intelligence purposes before the company declared insolvency in 2022.

Meta Pump-and-Dump Class Actions Dismissed

A California federal judge dismissed two class action lawsuits alleging Meta Platforms used its AI tools to enable pump-and-dump schemes that caused nearly $30 million in investor losses. The dismissal suggests plaintiffs failed to establish sufficient causal connection between Meta's advertising platform and the alleged securities fraud.

Google DMCA Scraping Lawsuit Dismissed

A judge dismissed Google's DMCA Section 1201 anti-circumvention lawsuit against SerpAPI, which scrapes Google search results to create an unauthorized API. The court rejected Google's argument that bypassing SearchGuard (essentially a CAPTCHA challenge) to scrape publicly available search results constitutes copyright infringement under DMCA 1201. The ruling reinforces that scraping open websites does not violate anti-circumvention provisions, even when the site deploys technological measures to block automated access. The court left the door open for Google to refile.

Taylor Farms Faces Cyclospora Outbreak Class Action

Consumers filed a class action lawsuit alleging Taylor Farms sold lettuce and leafy greens contaminated with cyclospora during a summer outbreak that sickened consumers across multiple states. The lawsuit follows Taylor Farms de Mexico's July 17 recall of all iceberg lettuce grown in central Mexico after health officials linked the product to a multistate outbreak tied to Taco Bell restaurants.

Regulatory Guidance

Senator Demands Federal VPN Purge

Sen. Ron Wyden (D-OR) called on CISA, OMB and NIST to lead an effort removing public internet-facing and insecure virtual private networks from federal systems, citing multiple recent hacking campaigns by Russian and Chinese adversaries targeting VPN products from Cisco, Fortinet, Ivanti and Check Point. Wyden urged CISA to set a two-year deadline for civilian agencies to eliminate public-facing remote access systems and replace them with zero-trust architecture. He directed the NSA to order a similar purge across military, intelligence and national security networks, and asked NIST to create implementation standards for zero-trust migration.

Trump Administration Seeks Supreme Court Intervention on Mail-in Voting

The Trump administration asked the Supreme Court to lift a federal injunction blocking implementation of an executive order imposing restrictions on mail-in voting. The March 31 executive order directs USPS to propose rules requiring that mail-in ballots only be sent to voters appearing on DHS-compiled state citizenship lists. U.S. District Judge Indira Talwani prohibited implementation of the order for November 2026 elections in 23 states and the District of Columbia, finding it conflicts with constitutional provisions giving states authority over voter eligibility and election procedures. The 1st Circuit upheld the injunction on Saturday. U.S. Solicitor General D. John Sauer argued the injunction causes irreparable harm by preventing agencies from implementing plans before the November election.

Small Businesses Challenge Trump Tariffs

Small businesses and Learning Resources (the Illinois toymaker that won a Supreme Court ruling against 2025 tariffs) filed separate lawsuits in the Court of International Trade challenging the Trump administration's latest wave of tariffs on 60 trade partners enacted under Section 301 of the Trade Act of 1974. The complaints allege the U.S. Trade Representative acted arbitrarily and capriciously by imposing near-uniform tariffs across 60 materially different economies without a reasoned, record-based explanation.

Privacy Developments

Federal Judge Blocks End to TPS Despite Supreme Court Precedent

U.S. District Judge Patti Saris issued a temporary administrative stay preserving Temporary Protected Status (TPS) protections for South Sudanese nationals while considering whether plaintiffs may amend their lawsuit and seek renewed relief on constitutional grounds. The order came despite a recent Supreme Court decision that significantly narrowed lower courts' authority to intervene in immigration matters. DHS General Counsel James Percival accused the judge of "open defiance" of the Supreme Court.

Protester Charged After Providing GrapheneOS Duress Passcode

Federal prosecutors charged Cop City protester Sam Tunick with property destruction after he provided CBP agents with a duress passcode to his GrapheneOS phone during an airport interrogation on January 24, 2025. When Tunick entered the duress code, the phone's screen went blank, flashed, and restarted, wiping data. CBP officers interrogated Tunick without Miranda warnings, ignored multiple requests for an attorney, and told him they had authority to search his phone without a warrant under immigration and customs exceptions. The prosecution appears to treat use of a legitimate privacy-protecting operating system feature as evidence of criminal intent.

Telegram Phishing Campaign Targets Activists

Researchers at Resident NGO uncovered a personalized Telegram phishing campaign targeting at least one Belarusian activist in Lithuania and users in Russia and Kazakhstan since October 2024. The operation used end-to-end encrypted secret chats to send fake security alerts claiming rule violations and account blocking threats. Each phishing link was individualized with the target's phone number and deployed infrastructure that fingerprinted visitors, redirecting security tools to legitimate sites while showing targets fake login pages. The campaign collected device details, timestamps and ISP information to send follow-up messages that appeared legitimate.

Policy Changes

State Department Redirects Human Rights Funding to Conservative Groups

Trump administration officials proposed bypassing the State Department's normal open bidding process to direct human rights aid to at least a dozen organizations aligned with conservative and anti-immigration movements in Europe and white South African advocacy groups. Proposals included a British free-speech organization that fought bans on gay conversion therapy, an Afrikaner self-governance group, and a $4.9 million program for "civilizational self-confidence in Europe" focused on research, conferences and civil society support in wealthy democracies. After congressional pushback, the State Department abandoned plans to fund a British American think tank dedicated to "renewing our Judeo-Christian culture and civilisational mission."

Compliance Takeaways