HeadFlash

Privacy

EU Revives Mass Surveillance, EDPB Cracks Down on Blockchain, and More

EU parliament approves suspicionless message scanning until 2028; EDPB issues strict blockchain guidelines; Puerto Rico exposes 1M SSNs; Meta pauses keystroke tracking; artists confront AI data scraping.

Listen

EU Parliament Passes Suspicionless Mass Scanning Until 2028

The European Parliament allowed suspicionless mass scanning of private communications, known as Chat Control 1.0, to pass despite a majority of voting MEPs opposing it. The motion to reject the interim regulation failed to secure the required absolute majority of 361 votes, with 314 against, 276 in favor, and 17 abstentions. The measure permits US tech companies like Meta, Google, and Apple to scan direct messages on platforms such as Instagram, Discord, Snapchat, Skype, Xbox, Gmail, and iCloud without a warrant or suspicion. A symbolic exemption for end-to-end encrypted chats like WhatsApp was included, but service providers do not scan those anyway. Civil rights activist and former MEP Dr. Patrick Breyer called the vote ‘a farce that damages democracy,’ noting that children lose out. The interim regulation will remain in effect until 2028 or until a permanent law is agreed. Critics highlight that mass scanning has not led to increased convictions or rescued children; EU Commission figures show it accounted for only 36 percent of abuse reports in 2024, and 48 percent of incoming alerts are not criminally relevant. Negotiations for a permanent Chat Control 2.0 resume in September, with the core dispute over indiscriminate versus targeted scanning. Survivors of sexual violence condemned the approach, emphasizing that privacy is essential for reporting abuse. Breyer argued that resistance in Parliament was so strong that a permanent suspicionless scanning law is a pipe dream.

EU Parliament greenlights Chat Control 1.0 – Breyer: “Our children lose out” – Patrick Breyer →

EDPB Finalizes GDPR Blockchain Guidelines, Rejects Anonymisation Workaround

The European Data Protection Board finalized its guidelines on processing personal data through blockchain technologies on July 8, 2026, alongside stricter anonymisation standards that close the industry’s primary compliance loophole. The guidelines apply GDPR concepts to public, private, and consortium chains, stating that only private and consortium chains can realistically satisfy controller-accountability requirements. On public permissionless blockchains, identifying a data controller is nearly impossible, and all node operators may be treated as joint controllers. The EDPB maintains that encrypted or hashed on-chain data remains personal data because it can potentially be re-identified. The new anonymisation guidelines codify a three-criteria test requiring no record isolation, no linkage, and no inference possible. The board explicitly notes that technical impossibility does not justify non-compliance; if an architecture cannot support data subjects’ rights like erasure, it cannot be used with personal data. Recommended approaches include storing no personal data on-chain, using off-chain databases with cryptographic proofs, or employing encryption with off-chain key management. The guidelines also highlight compliance challenges for international data transfers on public blockchains, where nodes are distributed globally without vetted recipients. Smart contract execution may trigger GDPR Article 22 restrictions on automated decision-making. The EDPB’s position has drawn criticism from industry lawyers who argue it is not fully grounded in the GDPR’s text. Public consultation on the new anonymisation guidelines is open until October 30, 2026.

EU Finalizes GDPR Blockchain Rules: Encrypted Data Is Still Personal Data →

Puerto Rico Agency Exposes 1 Million Social Security Numbers via Property Map

The Municipal Revenue Collection Center (CRIM) in Puerto Rico inadvertently exposed the Social Security numbers of approximately 1 million people through a loophole in its Catastro Digital interactive property map. The vulnerability was discovered by Centro de Periodismo Investigativo and ProPublica, who notified CRIM in mid-June. While a basic search only reveals property details, anyone who understood how websites request data could download unprotected SSNs without authentication. CRIM Executive Director Javier García Cintrón repeatedly denied any breach, stating that a review found no exposure of confidential information. After the news organizations verified the hole and provided detailed technical information, the security gaps were patched, but García claimed no fix was needed. CRIM did not notify the Puerto Rico Innovation & Technology Service as required by government cybersecurity protocol. PRITS declined to comment. At least three property listing companies that obtain data from Catastro Digital said they were unaware of the vulnerability and did not access the sensitive data.

A Puerto Rico government agency exposed 1M Social Security numbers →

Meta CTO Confirms Internal Data Leak in Keystroke Logging Program

Meta’s chief technology officer Andrew Bosworth confirmed that a researcher moved sensitive employee data from the company’s keystroke-logging program to an internal location where it was not supposed to go. He said there was no outside intrusion and the data remained accessible only to a handful of people. The program, called the Model Capability Initiative, recorded keystrokes and mouse movements of most US employees for AI training. Meta paused the initiative in June after screenshots showed the data was readable across the organization. Bosworth told The Atlantic’s CEO that the data had ‘landed someplace it shouldn’t have internally’ and that Meta was locking everything down until it could establish what happened. He also said the project was gathering too much of the same type of data, and that variance is more important for AI models. This realization prompted Meta to expand opt-outs, reversing its original no-opt-out policy. Over 1,600 employees had signed a petition against the tracking. The keystroke logging remains dormant as the investigation continues; Meta has not decided what to do with the data already collected.

Meta CTO says employee-tracking data landed ‘where it wasn’t supposed to go’ →

In mid-June, The Atlantic published searchable databases compiled from datasets used across the AI music development community, allowing artists to check if their work was included. The largest database came from a 12-million-track collection scraped from YouTube. Musicians of all levels found their names on the list, but since AI company Suno does not disclose its training data, it is unclear if their music was actually used. Berlin-based composer Robot Koch, who found over 200 of his songs in the datasets, said music was ripped from Spotify and that opt-out systems are burdensome. He described major-label settlements with AI companies as ‘murky’ and did not feel the labels defended independent artists. Boston composer Mike Sempert, who found over a dozen of his songs, called it ‘probably the greatest copyright heist of all time’ and joined a class-action lawsuit. Hagens Berman attorneys said major-label settlements appear to have forfeited artists’ copyright claims and gave no compensation for past conduct. The American Federation of Musicians has filed a lawsuit attacking the settlements as unfair. Even a favorable court ruling would not undo the training, since data cannot be extracted from AI models.

Their music may have trained AI. No one asked them either way →