← Carolina Clear Tech

Legal & Privacy Brief

2026-09-11

Listen to this brief (14:37)

Download MP3
Show Notes

Show Notes - 2026-09-11

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - September 11, 2026

Today: California bans social media for users under 16 despite civil liberties concerns. The Supreme Court blocks Missouri's Republican-favored congressional map after the secretary of state's delay created election chaos. Identity verification firm IDScan confirms a breach exposing 153 million driver's license scans after hackers listed the database for sale on a Russian dark web marketplace.


Enforcement Actions

California Enacts Social Media Ban for Users Under 16 (AB 1709)

California Gov. Gavin Newsom signed AB 1709 into law, functionally banning social media use for anyone under 16. The Electronic Frontier Foundation and allied civil liberties groups condemned the law as a poorly designed restriction that cuts young people off from essential information, supportive communities, and free expression. The law forces all users to submit more personal data for age verification, concentrating power in the hands of companies rather than protecting privacy. Research shows social media bans are ineffective while denying minors opportunities to develop their own voices, share art, practice religion, and engage politically. LGBTQ+ youth advocacy group COLAGE noted the law strips people with LGBTQ+ parents of the ability to meet and build community online during a period of increasing stigma and marginalization.


Litigation Updates

Supreme Court Blocks Missouri Congressional Map After Secretary of State's Delay

The Supreme Court granted an emergency request to prevent Missouri from using a new congressional map (HB 1) expected to give Republicans an additional House seat. The dispute began when Missouri Secretary of State Denny Hoskins rejected a referendum petition with over 300,000 signatures on Aug. 4, the last day to do so. The Missouri Supreme Court unanimously reversed Hoskins on Sept. 3, ruling the referendum petition was legal and timely, and that HB 1 never took effect. When Hoskins appealed to SCOTUS, Justice Brett Kavanaugh denied the stay on Sept. 8. Hours later, federal district judge Stephen Clark issued a temporary restraining order allowing use of HB 1, which the 8th Circuit left intact. The Supreme Court reversed Clark's order on Sept. 10, effectively blocking the new map. Legal experts criticized the 8th Circuit for ignoring its own jurisdiction limits and the district court for violating the Purcell principle (federal courts should not interfere with state elections shortly before voting), the Rooker-Feldman doctrine (federal district courts cannot review state supreme court rulings), and Kavanaugh's prior denial.

Trump Administration Challenges 9th Circuit Ruling on Acting U.S. Attorney Appointments

U.S. Solicitor General D. John Sauer asked the Supreme Court to reverse a 9th Circuit ruling that Trump ally Sigal Chattah was unlawfully serving as acting U.S. attorney for Nevada. Chattah was appointed as first assistant U.S. attorney and then designated acting U.S. attorney after her initial 120-day interim appointment under the Federal Vacancies Reform Act (FVRA) expired. The 9th Circuit held the FVRA does not permit filling an existing vacancy by designating a new first assistant after the vacancy arises. Judge Eric Miller wrote that automatic succession applies only to first assistants who served under a validly appointed official. Sauer argued the text of FVRA does not restrict automatic succession to pre-existing first assistants and that both Republican and Democratic administrations have used this practice for decades, including in the solicitor general's office. The 9th Circuit disqualified Chattah from three criminal cases but declined to dismiss the indictments. Two other circuits have issued similar rulings, creating what Sauer called "mass confusion" affecting over 8,000 civil and criminal cases across five U.S. attorney offices in the 9th Circuit.

Ninth Circuit Requires Class-Wide Proof of Deception in False Advertising Claims (Rusoff v. The Happy Group)

The 9th Circuit held that when plaintiffs allege a marketing claim is deceptive because it violates industry standards, they must offer common, class-wide proof that reasonable consumers would associate the representation with that standard. In Rusoff v. The Happy Group, No. 24-7706 (9th Cir. Aug. 17, 2026), plaintiffs alleged "pasture raised on over 8 acres" on egg cartons was deceptive because it did not comply with standards set by the American Humane Association and Humane Farm Animal Care. The district court excluded plaintiffs' expert who opined on industry standards, finding his methodology (photographing egg cartons near his home) did not meet expert witness standards. Without that expert, plaintiffs lacked proof connecting a reasonable consumer's understanding of "pasture raised" to the alleged industry standard. The 9th Circuit affirmed denial of class certification, holding plaintiffs failed to show common proof of deception.

Costa Del Mar Sunglasses Repair Class Action Settlement ($23.9M)

Costa Del Mar agreed to a $23.9 million settlement to resolve claims that high, undisclosed repair fees blindsided consumers.

Globe Life Data Breach Class Action Settlement ($3.4M)

Globe Life and American Income Life Insurance agreed to a $3.4 million settlement for individuals affected by a data breach.

GoFundMe Accused of Deceptive Default Tips

A new class action alleges GoFundMe uses deceptive website design to trick donors into paying optional tips that go directly to the company.

FedEx Delivery Driver Wage and Hour Lawsuits

Seven delivery drivers filed lawsuits alleging FedEx denied them overtime pay despite treating them as direct employees.


Privacy Developments

IDScan Data Breach Exposes 153 Million Driver's License Scans

Identity verification firm IDScan confirmed hackers accessed customer data from its cloud platform, exposing scans of approximately 153 million driver's licenses, 10 million identification cards, 3 million travel documents, and 579,000 medical cards belonging to U.S. and Canadian citizens. IDScan became aware of the breach on or around Sept. 1, the same day journalist Brian Krebs reported that Russian dark web marketplace Nexus was offering the database for sale. IDScan's Sept. 4 security notice said "an unauthorized third party may have accessed and/or copied certain customer information" including full names and driver's license or government-issued ID numbers. The company directed search engines not to index the notice, making it difficult to find. IDScan downplayed the incident by noting hackers weren't making the data freely available, though they were selling access. The FBI launched an inquiry. Businesses across cannabis retail, gun stores, and banks rely on IDScan to authenticate government IDs, raising concerns about age verification mandates as lawmakers push social media platforms to verify user ages with government ID.

DHS Feeds Bank Records to Predictive Policing Units for Traffic Stops

Border Patrol's secretive Predictive Intelligence Targeting Teams (PITT) analyze Americans' financial activity and feed intelligence to local police, who then pull over individuals not suspected of any specific crime. In one Montana case, a PITT agent reviewed "law enforcement-sensitive databases" showing "financial activity patterns commonly associated with illicit narcotics activity" and provided intelligence to local authorities, who stopped the driver for an obstructed license plate and charged him with DUI. The DHS document describing the program was disclosed during discovery. Border Patrol Agent Matthew Phelps, assigned to the Spokane Sector PITT, wrote he reviews financial databases to develop intelligence before handing information to local law enforcement. The program appears to manufacture suspicion by feeding bulk financial data to a system designed to generate pretextual traffic stops. Border Patrol and CBP defended the practice as smart criminal hunting, though the "financial activity patterns" resembled normal transactions rather than clear money laundering indicators.


Policy Changes

FCC Censorship Pressure Blocks Political Interview on ABC

Jimmy Kimmel's planned interview with Texas Senate candidate James Talarico did not air on ABC broadcast TV due to network lawyers' concerns about FCC reprisal. The interview will instead air on YouTube. FCC Chair Brendan Carr launched a sham investigation of ABC's broadcast licenses, falsely claiming Talarico's Feb. 2026 appearance on The View violated the FCC's "equal time" rule. The View has been exempt from the equal time rule since 2002 under clear FCC agreements. Carr worked with right-wing affiliates to claim ABC's Houston affiliate violated the law. ABC sued the FCC for First Amendment violations, but while litigation proceeds, network lawyers are avoiding any content that could fuel Carr's investigation. The View stopped hosting politicians entirely. Kimmel noted he interviewed political candidates for over 20 years, including Donald Trump in 2015 and 2016, with no FCC interference until Trump became president again.

Automakers Lobby Congress to Ban Chinese EVs Under Privacy Pretense

The Alliance for Automotive Innovation, representing U.S. automakers, pressured Congress to ban Chinese electric vehicles, software, and hardware, citing privacy and national security concerns. CEO John Bozzella claimed "Chinese automakers are dumping subsidized vehicles with connected software and hardware around the world" and urged lawmakers to "enact a Chinese vehicle, software and hardware ban before adjourning this year." The U.S. auto industry has some of the worst privacy practices of any American industry, selling comprehensive driving, personal, and behavioral data to data brokers in a country with no federal privacy law. The failure to regulate data brokers means Chinese entities can simply purchase the same data U.S. automakers claim to be protecting. Critics noted the protectionist effort ignores the auto industry's own extensive subsidies and poor security practices, calling it "incompetent rank protectionism."

Lawmakers Urge Commerce Secretary to Blacklist Appin Hack-for-Hire Firm

Senators Ron Wyden (D-OR) and Sheldon Whitehouse (D-RI) and Rep. Pat Harrigan (R-NC) sent a bipartisan letter to Commerce Secretary Howard Lutnick requesting that Appin and related companies (CyberRoot, BellTroX, Adaptive Control Security Global Corporate, ABP Holdings, and "Sunkissed Organic Farms") be added to the Bureau of Industry and Security Entity List. The designation would cut these firms off from American technology and business partners, similar to the 2021 action against NSO Group. Appin is an Indian hack-for-hire firm that Reuters investigation detailed as a "leading cyberespionage firm" that "stole secrets from executives, politicians, military officials and wealthy elites around the globe." Appin and founder Rajat Khare have aggressively threatened journalists and media outlets reporting on their activities, convincing an Indian court to force Reuters to temporarily remove its investigation and pressuring numerous publications to redact coverage.


Compliance Takeaways