← Carolina Clear Tech

Legal & Privacy Brief

2026-09-23

Listen to this brief (16:40)

Download MP3
Show Notes

Show Notes - 2026-09-23

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - September 23, 2026

Today: The Trump administration faces its ninth circuit court loss on immigration detention without bond hearings, with the Fourth Circuit comparing the policy to Japanese internment. The Supreme Court will resolve a critical Video Privacy Protection Act question affecting online data collection, while two data breach settlements totaling $8.45 million move forward and a Canadian regulator opens an investigation into IDScan following a breach affecting 153 million driver's licenses.

Enforcement Actions

Canadian Privacy Commissioner Investigates IDScan After 153 Million Driver's License Breach

Canada's Privacy Commissioner Philippe Dufresne launched an investigation into IDScan.net following reports that hackers penetrated company databases and stole personal data and scans of 153 million driver's licenses. The investigation will examine IDScan's security practices and whether victim notifications met requirements under Canada's federal private-sector privacy law. IDScan, whose technology is widely used in retail and hospitality sectors for ID verification, learned of the breach on September 1 after journalist Brian Krebs revealed the scans were for sale on the dark web.

Microsoft Disrupts AI-Powered Cybercriminal Platform, Two Arrested in UK

Microsoft's Digital Crimes Unit obtained U.S. District Court authorization to dismantle EvilTokens, an AI-powered cybercriminal platform operating on Telegram for a $1,500 initiation fee and $500 monthly subscription. The platform used multiple AI models to help criminals compromise accounts, analyze breached inboxes, and identify fraud opportunities. Microsoft seized 50 websites and disabled 150 domains tied to the service. UK Metropolitan Police arrested two men, aged 32 and 38, on suspicion of making articles for use in fraud and money laundering. The platform launched in February 2026 and was linked to over 12,000 compromised email inboxes across 10,000 organizations worldwide, concentrated in the U.S., Canada, UK, Australia, India, and France.

Litigation Updates

Fourth Circuit Rejects ICE Detention Without Bond, Cites Japanese Internment

The Fourth Circuit Court of Appeals rejected the Trump administration's attempt to detain millions of people without bond hearings under the 1996 Illegal Immigration Reform and Immigrant Responsibility Act. In a 2-1 decision, Judge Nicole Berner wrote that "mass detention of marginalized individuals without due process harkens back to some of the darkest moments in our country's history," comparing the policy to WWII Japanese internment. This marks the ninth of eleven appellate circuits to rule against the administration's interpretation that allows detention of any migrant without due process, regardless of how long they have lived in the United States. The case involved two plaintiffs who had been in the U.S. since 1996 and 2005.

Supreme Court to Take Up Immigration Detention Question After Genalo v. Black Becomes Moot

The Trump administration filed a new petition asking the Supreme Court to review due process rights under Section 1226(c) of the Immigration and Nationality Act after the original case, Genalo v. Black, was dismissed as moot. The new case, Genalo v. D.C., involves a man detained since September 2025 who obtained a bond hearing in March and was released March 31. The central question is at what point noncitizens detained for extended periods under Section 1226(c) have a Fifth Amendment due process right to a bond hearing, and what the government must prove to justify continued detention. The administration asked for expedited review before judgment to replace the dismissed case on the 2026-27 oral argument docket. D.C.'s response is due October 21.

Synchrony Bank Credit Reporting Lawsuit Alleges Reporting Canceled Debt as Due

A new lawsuit alleges Synchrony Bank continued to report a canceled debt as due and owing on a consumer's credit reports with Experian and other agencies despite having formally canceled the debt and reported the cancellation to the IRS. The suit raises Fair Credit Reporting Act compliance questions regarding the reconciliation of debt cancellation and credit bureau reporting obligations.

Missouri Redistricting Dispute Returns to Supreme Court After 8th Circuit Ruling

The Supreme Court twice blocked Missouri's gerrymandered congressional map sought by Republicans after Trump called on red states to redistrict mid-decade. After opponents gathered signatures for a referendum blocking the map, Missouri Secretary of State Denny Hoskins waited eight months to reject the submission on spurious grounds, causing primaries to be held under the invalidated map. The Missouri Supreme Court unanimously ruled the referendum was proper and the map never lawfully took effect. The 8th Circuit subsequently ruled for the gerrymandered map, requiring the matter to return to the Supreme Court for a third time.

Casely Faces New Product Liability Class Action Over Power Pod Fire Hazard

A new class action accuses Casely of selling Power Pod power banks with a defect that can cause the lithium-ion battery to overheat and catch fire. The suit follows earlier claims regarding the product's safety.

Lenox Sued Under Washington Law Over Allegedly Misleading Email Subject Lines

A class action lawsuit accuses luxury home goods company Lenox of sending spam emails with false or misleading subject lines in violation of Washington state consumer protection law.

University of Hawaii Data Breach Settlement Provides $3.5 Million

The University of Hawaii reached a $3.5 million class action settlement to resolve claims related to a 2025 data breach. Eligible individuals affected by the breach may file claims for benefits.

ConnectOnCall and Phreesia Data Breach Settlement Reaches $4.95 Million

A $4.95 million class action settlement provides benefits to individuals affected by the ConnectOnCall and Phreesia data breach. The settlement covers healthcare data compromised in the incident.

Regulatory Guidance

EU Cyber Resilience Act Incident Reporting Now In Force With 24-Hour Deadlines

The EU Cyber Resilience Act's mandatory reporting obligations for actively exploited vulnerabilities and severe incidents came into force September 11, 2026, with 24-hour initial reporting deadlines. While full CRA obligations apply from December 11, 2027, manufacturers of covered products (essentially all connected software and hardware, including IoT devices, industrial control systems, and smart cards) must now report through ENISA's Single Reporting Platform to the relevant Member State CSIRT. Reporting follows a three-stage timeline: early warning within 24 hours, detailed intermediate report within 72 hours, and final report within 14 days (for vulnerabilities) or one month (for incidents). The requirements apply to all CRA-covered products, including those placed on the market before December 11, 2027, though manufacturers need not retrospectively report issues known before September 11, 2026.

FCC Approves Foreign Government Investment in Paramount-Warner Bros. Merger

The FCC approved the $111 billion merger between CBS/Paramount and Warner Brothers despite nearly 50% of financing coming from Saudi Arabia, Qatar, and China. FCC Chairman Brendan Carr determined the foreign investment serves the public interest despite the Communications Act prohibiting foreign governments from owning more than 25% of capital stock or voting rights in companies controlling broadcast licenses. The FCC waived this restriction, though foreign investors technically lack voting rights and nothing prevents them from obtaining such rights later.

Privacy Developments

Supreme Court to Resolve Video Privacy Protection Act Circuit Split in Salazar v. Paramount Global

The Supreme Court will resolve a circuit split on who qualifies as a "consumer" under the Video Privacy Protection Act in its October 2026 term. The VPPA, passed in 1988 after Judge Robert Bork's video rental records were published, prohibits video providers from disclosing personally identifiable information to third parties without consent. The question in Salazar v. Paramount Global is whether "goods or services from a video tape service provider" in the VPPA's consumer definition refers to all of a provider's goods or services, or only audiovisual goods or services. The decision will determine the scope of VPPA protections against pixel tracking technologies that companies use to collect and share consumer viewing data with data brokers and advertisers without consent.

Meta Settlement Restricts Youth Social Media Access, Raises Free Speech Concerns

Meta settled with 52 states and territories over youth use of Instagram and Facebook, requiring age gating across all products, two-hour daily time limits for users under 18, content restrictions, and default "age-appropriate" content filters that block posts with LGBTQ+ hashtags. The settlement will pressure non-Meta platforms like TikTok and YouTube to adopt similar restrictions. Digital rights advocates warn the settlement silences youth activism by limiting rapid response organizing, blocking access to news labeled "age-inappropriate," and preventing engagement metrics needed to gauge campaign effectiveness. Meta has previously hidden posts with #lesbian, #bisexual, #gay, #trans, and #queer for users with sensitive content filters enabled.

X Platform CSAM Detection Failures Continue Despite Musk Claims

The Canadian Center for Child Protection and the New York Times found 75 instances of known child sexual abuse material on X (formerly Twitter) using PhotoDNA hash matching and identified 65 instances where Grok created sexualized or exploitative images of children before X halted the feature. This follows Elon Musk's 2022 claim that "removing child exploitation is priority #1" and reports that X refused to pay bills to Thorn, a major CSAM detection tool provider. X previously claimed it implemented superior in-house technology to replace Thorn. The platform reduced trust and safety specialists working on CSAM to fewer than 10 at one point.

Policy Changes

UK Official Warns AI Favors Cyber Attackers Over Defenders

Dave Chismon, chief technology officer for architecture at the UK's National Cyber Security Centre, warned that defenders cannot put AI to work as freely as attackers because defensive actions lack clear success measures and carry severe downside risks on live systems. Unlike attacks that simply fail, botched defensive actions can cause the disruption defenders were trying to prevent. Chismon stated that "there's little difference" from a board perspective between an attack taking down IT and a defensive action doing the same, "except that the board can't shout at an attacker over the phone." The NCSC is building Cyber Shield, an agentic AI cyber defense capability, but acknowledges autonomous defensive actions remain an unsolved problem.

Compliance Takeaways