← Carolina Clear Tech

Legal & Privacy Brief

2026-08-28

Listen to this brief (12:09)

Download MP3
Show Notes

Show Notes - 2026-08-28

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - August 28, 2026

Today: HireVue settles Illinois BIPA lawsuit for $3.75 million over biometric data collection from job applicants. TikTok agrees to $400 million penalty for illegally collecting children's data under age 13. The Trump administration bans foreign-made power infrastructure equipment over cyber backdoor concerns, while ICE expands administrative subpoenas targeting tech companies for user data in immigration enforcement investigations.

Enforcement Actions

HireVue Illinois BIPA class action settlement

HireVue agreed to pay $3.75 million to settle claims that it violated Illinois' Biometric Information Privacy Act (BIPA) by collecting and storing biometric data from job applicants during video interviews without proper consent. The settlement resolves claims that the company's AI-powered video interview platform analyzed facial features, eye movements, and other biometric identifiers from candidates without meeting BIPA's strict notice and consent requirements.

TikTok $400M settlement over children's data privacy

TikTok agreed to pay $400 million to resolve a U.S. Department of Justice lawsuit alleging the social media platform illegally collected personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). The enforcement action addresses TikTok's failure to obtain verifiable parental consent before collecting, using, or disclosing personal information from children, despite knowing a significant portion of its user base was under the age threshold.

Regulatory Guidance

White House bans foreign-made power infrastructure over cyber threats

The Trump administration issued an executive order banning the acquisition of foreign-made technology used to manage electricity and power generation, citing vulnerabilities that foreign actors could exploit through digital backdoors. The order covers bulk-power systems rated at 69,000 volts or higher, including substations, control rooms, power generating stations, and associated software that could be remotely accessed by foreign governments. The Defense, Commerce, and Energy Departments must create pre-qualified equipment and vendor lists within 120 days, check transactions involving bulk-power equipment, and develop rules identifying countries warranting scrutiny.

Privacy Developments

ICE administrative subpoenas target tech companies for user data

Immigration and Customs Enforcement has sent hundreds of administrative subpoenas to technology companies requesting basic subscriber data as part of investigations into individuals who documented ICE activities, social media users who criticized the government, and international students who attended protests. From 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter. In the second half of 2025 alone, DHS sent 21 administrative subpoenas to Reddit. Multiple subpoenas have been withdrawn after users challenged them in court or companies pushed back, with courts finding the subpoenas exceeded statutory authority and violated First Amendment rights.

Manchester Airports Group data breach affects 8.7 million customers

Manchester Airports Group disclosed that an unauthorized third party accessed customer data belonging to approximately 8.7 million customers associated with car park, lounge, Fast Track bookings, and in-airport Wi-Fi sign-ups at Manchester, London Stansted, and East Midlands airports. Compromised information includes email addresses, phone numbers, vehicle registrations, and postcodes. The company detected the intrusion on Tuesday, with evidence suggesting attackers first accessed customer data a few days prior. No payment card or banking information was exposed as the affected system does not store financial data.

Litigation Updates

Finland appeals court revives Eagle S cable damage prosecution

A Finnish appeals court revived the prosecution of three senior officers from the Eagle S, a Russia-linked oil tanker that severed multiple subsea cables in the Baltic Sea on Christmas Day 2024. The Helsinki Court of Appeal ruled that Finland has jurisdiction despite the officers' argument that the case could only be heard by courts in the ship's flag state (Cook Islands) or crew members' home countries (Georgia and India). The court held that the alleged crimes were committed in Finland because damage to the country's power and telecommunications infrastructure occurred there, and that events did not constitute a "maritime accident" under the UN Convention on the Law of the Sea after the crew falsely told Finnish authorities both anchors were secured, then continued dragging an anchor for 90 kilometers, severing four additional cables.

Federal judge lifts final block on Trump mail-in voting order

U.S. District Judge Indira Talwani vacated her nationwide injunction blocking enforcement of President Trump's executive order on mail-in voting, citing the Supreme Court's Monday decision that it was premature for courts to consider challenges to the order. The ruling clears the way for USPS to enforce a new rule requiring states to provide lists of mail voters and use federally reviewed ballot envelopes with unique barcodes. A fresh wave of litigation followed, with 23 states, Washington D.C., and Pennsylvania Governor Josh Shapiro filing a new lawsuit contending USPS lacks authority to impose the rule and that it violates the Voting Rights Act and intrudes on states' constitutional power to administer elections.

Fed Governor Lisa Cook responds to removal consideration

Federal Reserve Governor Lisa Cook's attorney Abbe Lowell responded to the White House's August 5 letter stating President Trump was "considering" her removal based on mortgage fraud allegations. Lowell stated that allegations Cook committed fraud by signing mortgage agreements for both a Michigan home and Atlanta condominium as "primary" residences were "unfounded and untrue," characterizing the Atlanta mortgage designation as "entirely inadvertent oversight" without intent to defraud. The response included an expert opinion from Suffolk University Law Professor Kathleen Engel concluding that no banking professional can reliably determine Cook received more favorable terms or acted with intent to deceive. The White House letter came after FHFA head William Pulte sent criminal referrals to DOJ and approximately two months after the Supreme Court ruled 5-4 that Cook was entitled to notice and opportunity to respond before termination.

Australia charges two TeamPCP members for supply-chain attacks

Australian Federal Police charged Perth residents Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, with a combined 14 offenses related to their alleged membership in TeamPCP, the cybercrime group responsible for major supply-chain attacks since March 2025. Authorities allege both were principal participants in attacks targeting developer tools including TanStack, Trivy, and LiteLLM, with downstream victims including the European Commission and GitHub. Investigators estimate the campaign compromised over 1,000 organizations worldwide, exposed more than 500,000 credentials, stole at least 300 gigabytes of data, and caused hundreds of millions of dollars in remediation costs. Thomson faces eight charges including unauthorized data modification and dealing with proceeds of crime over $100,000. If convicted on all counts, Thomson faces up to 56 years and Gaebler 26 years, though sentences are typically served concurrently.

Policy Changes

Oracle shifts Section 230 strategy after TikTok investment

Oracle, which spent years funding anti-Section 230 advocacy groups primarily to target Google, now holds a 15% stake in TikTok and faces exposure to Section 230 litigation affecting both its cloud services business and TikTok investment. Oracle's top lobbying executive Ken Glueck, who architected the company's dark money campaign against Section 230, now sits on TikTok's board. The company's recent political activity reports show it no longer funds the Internet Accountability Project and Free and Fair Markets Initiative, two prominent anti-tech groups that stopped updating their websites in 2024 and 2023 respectively. Oracle continues funding only the Copyright Alliance, whose remit extends beyond attacking tech companies. TikTok already faces Section 230 challenges, including the Anderson v. TikTok ruling that bizarrely concluded TikTok didn't qualify for Section 230 protections.

Compliance Takeaways