❌

Reading view

There are new articles available, click to refresh the page.

Canadian regulator opens probe of IDScan for allegedly violating data privacy laws

Suzanne Smalley reports: Privacy Commissioner of Canada Philippe Dufresne has launched a probe of IDScan.net in the wake of reports that a bad actor penetrated company databases to steal personal data and scans of 153 million people’s drivers’ licenses. IDScan.net’s technology is widely used by industry — particularly in the retail and hospitality sectors —...

Source

Google fined €403m by Irish data watchdog over location data

Brian O’Donovan reports: Tech giant Google has been fined €403m by the Data Protection Commission (DPC) over the processing of location data. Under data protection rules, such information must be processed in a lawful, fair and transparent manner. The DPC said that its investigation into Google found failures in this regard meaning that people could...

Source

Companies Make It Hard to Access Your Personal Data Under State Privacy Laws, CR Finds

Derek Kravitz reports: Nearly every time you buy something online or sign up for a loyalty program, you leave behind personal information that can be collected, shared, and sold among companies including advertisers, retailers, and data brokers. This kind of information is sometimes used to charge consumers more for a range of products and services,...

Source

Epstein had huge cache of child sex pics; victims sue to find out who’s in them

Ashley Belanger reports: On Tuesday, two survivors of child sex abuse accused the Justice Department of failing to notify dozens of victims found in Jeffrey Epstein’s massive collection of child sex images. In a proposed class action, survivors explained that Epstein apparently started collecting child sex images in the 1990s, many of which the DOJ...

Source

Manhattan D.A.’s Office Seizes Domains Of 12 Illegal Websites Selling AI-Generated “Deep Fakes”

September 14, 2026 Marks Largest Known Seizure of AI-Generated Celebrity Deepfake Websites To Date Manhattan District Attorney Alvin L. Bragg, Jr., today announced the Office’s seizure of 12 domain names of illegal websites used for unlawfully disseminating, publishing, and selling non-consensual celebrity “deepfake” videos. Individuals under investigation allegedly used artificial-intelligence (“AI”) image and video creation...

Source

NZ Privacy Act notification clock starts as offshore edtech breach lands

Roxanne Libatique reports: A data breach affecting more than one million students, parents, and teachers across Australia and New Zealand has produced one of the clearest test cases the Australian cyber insurance market has seen for how patch-management obligations in policy wordings translate into real claims consequences. Online mathematics platform Mathspace confirmed on September 6,...

Source

Lawyers get $147M from Google data tracking suit; Class members get $5

Jonathan Bilyk reports:  A federal judge will allow lawyers who led a privacy class action lawsuit against Google to claim nearly $147 million in legal fees, nearly a third of the $425 million a jury had ordered the tech giant to pay for allegedly tracking more than 100 million people’s data after the Google users...

Source

Privacy advocates call on Maryland to investigate data brokers

Jude Joffe-Block reports: Maryland has passed some of the strictest data privacy provisions in the country. But privacy and civil rights advocates say commercial data brokers are violating state law by collecting and selling Marylanders’ geolocation data, as well as selling information to federal immigration authorities. A coalition of privacy and civil rights groups filed a consumer...

Mental health provider accused of sharing data with Meta, Google settles lawsuit for $3M

Chad Van Alstin reports: Mental health provider chain LifeStance Health has agreed to a $3 million settlement to put to rest a 2023 class action lawsuit, stemming from its use of third-party tracking technologies on its website. According to the complaint, between March 2020 and April 2023 the publicly traded, for-profit mental health services company...

CA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related Breaches

VOCM reports: The province’s Privacy Commissioner is recommending that public bodies consider providing the name of anyone involved in snooping-related privacy breaches to affected individuals. The recommendation comes after an employee of NL Health Services had a peek at a person’s health record. NLHS was notified. The Privacy Commissioner says the health authority took the appropriate steps...

FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

The Federal Trade Commission, joined by Utah and California, by and through Los Angeles County Counsel, today sued Hims & Hers alleging that the telehealth provider shared consumers’ sensitive health information about medical conditions with third-party advertising platforms despite claiming its services maintain consumers’ privacy and deceives users about its billing and cancellation practices. In...

Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features

I think I missed this one, but you shouldn’t miss it, too. Thorin Klosowski of EFF writes: Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our...

Iowa, 41 other states to receive money from 23andMe settlement

Emery Glover reports: Iowa is now among 42 states that have reached a settlement with the genetics and biotech company, 23andMe. A lawsuit against 23andMe was filed in 2023 after a massive data breach that impacted nearly 7 million people, according to the Iowa Attorney General’s office. The breach reportedly exposed customers’ genetic ancestry information, personal information...

Plaintiffs’ Bar Revs Up Claims Under the Driver’s Privacy Protection Act

“License plate numbers themselves generally are not understood to be “personal information from a motor vehicle record” subject to the DPPA, but private companies using ALPR data may match license plates with DMV records to identify vehicle owners for parking, tolling, collection or enforcement-related notices, creating another use case in which DPPA risk may arise.”...

Memorial Healthcare Services Settles Pixel Litigation

Steve Alder writes: Memorial Healthcare Services, a nonprofit healthcare provider serving patients in Southern California, has agreed to settle a class action lawsuit over its use of pixels and other tracking, web analytics, and advertising technologies on its website. The tools are alleged to have been added to the website without the knowledge or consent...

Veradigm Loses Bid to Toss Suit Over Data Sharing With Google

Christopher Brown reports: Health-technology provider Veradigm Inc. must face a proposed class action alleging it shared patients’ health information with Google LLC without consent in violation of state and federal privacy law. The plaintiffs plausibly alleged that Veradigm disclosed their personal health information, and adequately pleaded claims under the Electronic Communications Privacy Act, the California Invasion of...
❌