← Carolina Clear Tech

Legal & Privacy Brief

2026-07-29

Listen to this brief (13:49)

Download MP3
Show Notes

Show Notes - 2026-07-29

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: A federal magistrate denied a 30-day cell-site simulator warrant in Ohio, rejecting the government's attempt at blanket surveillance of thousands of Akron residents. California's SB 690 advances to eliminate private lawsuits over website pen register claims under CIPA, with retroactive effect on pending cases. Walmart faces two BIPA class actions over voiceprint collection at Illinois stores. Google is sued for allegedly sharing user data with Chinese companies Temu and Baidu in violation of federal data security rules.


Enforcement Actions

FTC Policy Statement on AI Accuracy Draws Scrutiny

The FTC's open comment period on its "Policy Statement Addressing AI Accuracy" closes this week. The statement asserts Section 5 authority to pursue AI companies whose outputs are deemed inaccurate or ideologically biased, claiming consumers have a "reasonable expectation" of truthful, undistorted outputs. Critics, including a former FTC lawyer, argue the policy stretches deception authority beyond its statutory basis by allowing the Commission to unilaterally define what consumers "reasonably expect" from AI systems.

FCC Escalates Action Against Chinese Drone Front Companies

The FCC proposed $25,000 fines against eight companies marketing relabeled Chinese drones and cameras in violation of its ban, and is now pursuing broader retroactive bans on those companies' ability to import, distribute, and sell existing inventory. The enforcement targets companies that changed labels on Chinese-manufactured products to circumvent the ban on DJI and similar manufacturers.


Litigation Updates

Court Denies 30-Day Cell-Site Simulator Warrant in Ohio

A U.S. magistrate judge denied a federal warrant application seeking to deploy a cell-site simulator 24 hours a day for 30 consecutive days across the Akron, Ohio area. The June 15, 2026 application sought to identify cellular devices used by a suspect, but the court found it would grant "unbridled discretion to examine the movements of private citizens at all times for thirty days" and expose data from thousands of uninvolved individuals. The ruling cited Fourth Amendment particularity requirements. The federal agency involved was not identified, and the rest of the docket remains sealed.

Walmart Faces Two BIPA Lawsuits Over Voiceprint Collection

Two proposed class actions accuse Walmart of collecting voiceprints from Illinois customers who called local stores without providing the written disclosures or obtaining the consent required by the Illinois Biometric Information Privacy Act (BIPA). The lawsuits allege Walmart's phone systems captured biometric identifiers without complying with BIPA's informed-consent framework.

Google Sued Over Data Sharing with Temu and Baidu

A proposed class action alleges Google unlawfully shared Americans' sensitive personal information with Chinese companies, including Temu and Baidu, through its online advertising infrastructure. The complaint cites violations of a federal data security rule designed to protect U.S. national security.

Intuit/Credit Karma Class Action Over Account Security

A class action alleges Intuit and Credit Karma failed to maintain reasonable security and customer protection for Credit Karma Money checking and savings accounts, resulting in unauthorized withdrawals from customer accounts.

$750K Strides Testosterone Gel Settlement

Strides Pharma agreed to a $750,000 class action settlement over claims that its testosterone gel products were contaminated with benzene. The settlement is currently open for claims.


Regulatory Guidance

California SB 690 Advances to Eliminate Private CIPA Pen Register Lawsuits

On July 1, 2026, a California Assembly committee advanced amendments to SB 690 that would eliminate private lawsuits asserting website-based "pen register" claims under the California Invasion of Privacy Act (CIPA), leaving enforcement exclusively to the Attorney General. The bill passed the California Senate 35-0 in June 2025. The amended version applies retroactively to claims filed within two years before the operative date, potentially affecting a substantial volume of pending lawsuits and demand letters. The committee described pen register claims as a "poster child for abusive lawsuits." The bill leaves CIPA wiretapping (Section 631) and confidential recording (Section 632) private rights of action intact. If enacted, it would become operative January 1, 2027.


Privacy Developments

ICE Surveillance Toolkit Detailed in Leaked Document

A leaked 2024 document obtained by 404 Media catalogs the surveillance and investigative tools available to ICE and CBP officers. The inventory includes: cell phone location data from commercial brokers, Clearview AI facial recognition (access controlled by CIEU under unspecified circumstances), Vigilant Solutions license plate/location database, ISO Claimsearch insurance claims data, FTC consumer complaint data (with unclear redaction practices for personal information), and "Insight," a tool combining WHOIS-like capabilities with geolocation data and the ability to bypass privacy registrars. The document predates newer tools like ELITE and ImmigrationOS.

EFF Opposes Surveillance Pricing, Backs California A.B. 2654

EFF is supporting California A.B. 2654, which would ban "surveillance pricing," the practice of offering different prices to different consumers based on personal information collected through electronic surveillance. The FTC has documented cases of companies using personal profiles to show higher-priced products to consumers. The San Francisco Board of Supervisors stalled a resolution supporting the bill after the San Francisco Chamber of Commerce raised objections. The bill includes carveouts for cost-based price differences, loyalty programs, and volume discounts.

Gay Bars Using PatronScan Raise Privacy Concerns Under California ID Law

PatronScan, an ID-scanning and patron-tracking system deployed at multiple LGBTQ+ bars in San Francisco's Castro neighborhood, is drawing scrutiny under California's ID privacy law. The system scans government-issued IDs, retains personal information (name, date of birth, photo, gender, zip code, and venue entry timestamps) for 21 days (five years for flagged patrons), and shares data across participating venues. A 2018 California Senate Judiciary Committee analysis found PatronScan had collected data on 561,087 customers in Sacramento in five months and maintained bans averaging over 19 years. California law restricts businesses from retaining or using information from scanned IDs except for limited purposes such as age verification.

License Plate Surveillance: Axon Replacing Flock with Similar Capabilities

Municipalities switching from Flock Safety to Axon license plate readers are not meaningfully reducing surveillance capabilities. Axon cameras capture personal details beyond license plate numbers, and the privacy impact for residents remains comparable regardless of vendor. Denver, Colorado is among cities making this switch.

Bank of Baroda Confirms Cyber Incident

India's Bank of Baroda confirmed an employee email account was compromised, allowing unauthorized access to "certain data." A threat actor operating as "leak-king-F" claimed to have leaked customer information, corporate banking records, internal emails, loan documents, and audit files on a darknet forum. The bank states core banking systems were not affected.


Policy Changes

Section 702 FISA Lapses Amid DNI Confirmation Battle

The Senate confirmed Jay Clayton as Director of National Intelligence by a 51-47 party-line vote. Section 702 of the Foreign Intelligence Surveillance Act has lapsed after Democrats objected to interim DNI Bill Pulte's appointment. Pulte announced a 30% personnel cut at ODNI before leaving, which, combined with former DNI Gabbard's 40% cut, likely leaves the organization with fewer than 1,000 staff. Senate Intelligence Committee Chairman Cotton said any supplemental or reconciliation spending bill must include approximately $40 billion for intelligence agencies.

Birthright Citizenship Executive Order: Rehearing Deadline Passes

The Trump administration did not file a petition for rehearing in Trump v. Barbara before the July 27 deadline, making the Supreme Court's June 30 ruling striking down the birthright citizenship executive order final. The 6-3 decision held the order violated the 14th Amendment's citizenship clause. A rehearing petition would have required five votes, including at least one from the majority.

International Law and AI Infrastructure Sovereignty

A Lawfare analysis argues that customary international law is being pushed toward treating unauthorized access to a state's AI infrastructure as a sovereignty violation. The analysis identifies a gap in U.S. legal positions: the same thresholds designed to preserve space for intelligence operations deny legal remedies when U.S. AI infrastructure (including under AUKUS Pillar II) is the target of exfiltration or data poisoning.


Compliance Takeaways