HeadFlash

Privacy

Privacy Digest: EU Kids Ban, Palantir Blacklist & More

Spain blacklists Palantir, EU eyes social media ban for kids, New Jersey targets surveillance pricing, and Signal tip line breach.

Listen

Spain Orders State-Owned Companies to Blacklist Palantir

The Spanish government has directed state-controlled entities to cease future contracting with U.S. data analytics firm Palantir Technologies, citing national security concerns over potential misuse of classified information. The prime minister’s office instructed companies overseen by the State Society of Industrial Participations (SEPI) to halt dealings, affecting major firms such as Telefónica, Indra, and military shipbuilder Navantia. The intervention blocked a near-finalized project with Navantia and a collaboration agreement with the Guardia Civil that was vetoed by Interior Minister Fernando Grande-Marlaska.

Spain Orders Blacklist of US Tech Giant Palantir From Public and Private Companies →

EU Commission Expected to Propose Social Media Ban for Children in September

European Commission President Ursula von der Leyen is expected to announce proposals for an EU-wide social media ban for children during her State of the Union address on 16 September, according to multiple EU officials. The initiative would represent the bloc’s clearest political commitment to introducing age restrictions, though the legal framework and minimum age remain undecided. An advisory panel is set to report on 13 July, and momentum has built as France, Spain, Germany, Denmark, and Greece pursue national measures, while Australia and the UK have already enacted similar bans. Ireland, holding the rotating EU presidency, is pushing for an EU-wide approach to age verification.

Just a moment… →

New Jersey Passes Law Banning Surveillance Pricing in Grocery Stores

New Jersey has passed the Fair Price Protection Act, banning the use of AI or algorithms to adjust grocery prices based on customer personal data. The bipartisan law also imposes a one-year moratorium on electronic shelf labels (ESLs). It awaits Governor Mikie Sherrill’s signature, who has expressed support. Exemptions exist for loyalty programs, military discounts, and senior discounts, provided they are uniformly applied. The United Food and Commercial Workers union praised the law, while Walmart, which has already installed ESLs in all New Jersey stores, denies using the technology for harmful price changes.

New Jersey Becomes Latest State to Pass Law Against Surveillance Pricing →

Gay Dating App Goose Accused of Using AI-Generated Profiles to Promote App

Goose, a gay dating app founded by actor Derek Chadwick, markets itself as an ‘anti-algorithm’ membership-only platform. A Wired investigation alleges that the app may be using AI-generated men to promote itself via unsolicited direct messages on Instagram. Investigators identified over two dozen Instagram accounts created in May or June 2026 that posted only a few times, and AI detectors flagged the images as likely synthetic. The Federal Trade Commission requires disclosure for paid social ads; Goose did not respond to requests for comment. The allegations raise concerns about deceptive marketing and privacy in dating apps.

Gay dating app Goose accused of using AI models to drum up interest →

The Intercept’s Signal Tip Line Breached by Unauthorized Third Party

The Intercept’s official Signal tip line was taken over by an unknown actor who has been communicating with prospective sources since at least February 2026. The publication switched to a new Signal account on June 30 after becoming aware of the breach. A fraudulent X account posing as ‘Investigative Intake’ for The Intercept has been soliciting tips, making roughly 100 posts between February and May. David Bralow, The Intercept’s chief legal officer, stated that no source compromise has been confirmed, but the breach highlights risks of dormant Signal accounts being recycled. The compromised account remains active, and the fraudulent X account was still active as of July 2.

Shared Message — A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers →

Hacker Recovers Missing Tesla Crash Data That Tesla Said Was Corrupted

In a 2019 fatal crash involving a Tesla Model S on Autopilot, Tesla claimed critical collision snapshot data was missing or corrupted. A Miami jury awarded $243 million in August 2025, the largest verdict against Tesla at the time. A hacker later recovered the snapshot from the vehicle’s computer, showing Autopilot had detected road boundaries, a stop sign, a blinking red light, a parked SUV, and pedestrians but failed to brake or warn. The jury accepted claims that Tesla lacked safeguards for unsafe road operation, had insufficient driver monitoring, and misled consumers about self-driving capabilities. Tesla maintains the driver was solely responsible and denies intentional data suppression; an appeal is pending.

Tesla Said the Crash Data Was Missing. A Hacker Found It Anyway. →