Privacy
Privacy Pulse: Settlement, AI Consent, Encryption, and a Nuclear Breach
23andMe settles for $18M, Samsung clarifies health data consent, OpenAI encrypts agent chats, and Indian nuclear plant data leaked.
23andMe Reaches $18 Million Settlement with State Attorneys General
Genetic testing company 23andMe has agreed to a multimillion-dollar settlement with a coalition of state attorneys general, according to a report from The San Diego Union-Tribune. The settlement is valued at $18 million, though further details about the terms or specific allegations remain behind a paywall. The agreement marks a significant regulatory action against a major player in the direct-to-consumer genetic testing industry, which has long faced scrutiny over how it handles sensitive biometric and health data. The settlement underscores growing pressure from state-level authorities to enforce stricter privacy protections for genetic information, a category of data that is uniquely personal and irreversible if exposed.
States reach $18 million settlement with 23andMe →
Samsung Clarifies Health Data Policy After Consent Confusion
Samsung Health recently began prompting users to allow their health information to be used for AI training and modeling. The permission was described as optional, but users who declined or withdrew consent were warned that Samsung Cloud syncing would stop and stored health data would be permanently deleted – a statement that sparked widespread concern. Following inquiries from SamMobile, Samsung issued a new in-app notice clarifying that data gathered for AI development is collected and managed separately from the health records required to run Samsung Health services. Withdrawing permission now only removes the data collected specifically for AI training, leaving users’ existing health history intact and accessible. Samsung acknowledged that the original warning was unclear and said it is revising the notice to make the policy easier to understand. SamMobile tested the app after withdrawing consent and confirmed that Samsung Health continued syncing and that the Cloud sync setting remained active.
Refusing Samsung Health AI training will not wipe your health history after all →
OpenAI Codex Now Encrypts Agent-to-Agent Instructions, Limiting Developer Visibility
Since early June, OpenAI’s coding tool Codex has been encrypting the instructions that a main agent passes to its subagents, replacing readable task descriptions with unreadable strings in the session history. This change leaves developers unable to inspect what their agent delegates to each subagent. A bug report on GitHub has asked OpenAI to store a readable copy locally alongside the encrypted version. For a time, GPT-5.5 would not allow developers to turn off encryption using the dedicated toggle, cutting off visibility entirely; OpenAI has since reverted GPT-5.5 to the readable path. However, forced encryption now applies to the larger GPT-5.6 variants, Sol and Terra, while only the smallest variant, Luna, still uses the open path. The new system has proven unreliable – several developers report that encrypted handoffs to subagents fail because the content cannot be decrypted, sometimes even when the main and subagent use the same model. OpenAI has not explained why it encrypts agent communication. Community members suspect the company is trying to prevent rivals from training on these prompts, following the recent suspicion that Zhipu AI’s open GLM-5.2 model was distilled from GPT-5.5 and Opus 4.8. Alternatively, the encryption may simply be a privacy measure, as OpenAI’s API already encrypts intermediate states for forwarding requests. OpenAI has not confirmed whether the change is about distillation protection, data privacy, or both.
Kudankulam Nuclear Plant Data Breached; NPCIL Says Core Systems Unaffected
Nuclear Power Corporation of India Ltd (NPCIL) has stated that core systems at the Kudankulam nuclear plant were not affected by a cyber security incident, after ransomware group World Leaks published a large cache of files on the dark web and claimed a data breach. NPCIL and Russia’s Rosatom are jointly developing the 6,000-MW plant in Tamil Nadu; units 1 and 2 are operational, while units 3 through 6 are under construction. Reliance Infrastructure Ltd (Reliance Infra), part of Anil Ambani’s Reliance Group, was involved in designing and building infrastructure for units 3 and 4 in 2018. A Reliance Group spokesperson said that Yotta Data Services Private Limited, its third-party data centre service provider, reported a cybersecurity incident involving an attempted ransomware attack that resulted in a partial breach of data hosted on one of Yotta’s servers. Yotta stated that the suspicious process was identified and terminated immediately, the incident was contained, no ransomware execution or data loss occurred, and services were restored. Yotta has since implemented enhanced security monitoring and preventive controls; Reliance Group has directed Yotta to conduct a detailed investigation and submit a report. The incident was reported to CERT-In, and disclosure was made to stock exchanges. NPCIL executive director Prateek Agrawal said the files are not related to nuclear safety or nuclear security systems, comparing them to common service tenders in thermal power plants. NPCIL later reiterated that the information in the public domain pertains only to conventional balance of plant common service facilities and does not relate to any nuclear safety or nuclear security systems or information.
Kudankulam nuclear plant data breached, NPCIL says core systems untouched →