HeadFlash

Privacy

Surveillance Pricing Banned, Geofence Warrants Curbed, and a Duress Password Case

New Jersey bans grocery surveillance pricing; Supreme Court requires warrants for geofence data; first US duress password prosecution.

Listen

New Jersey Bans Grocery Stores From Using Personal Data for Surveillance Pricing

Governor Mikie Sherrill signed the Fair Price Protection Act on Thursday, making New Jersey one of the first states to ban surveillance pricing in grocery stores. The law, effective August 1, 2027, prohibits stores from using shoppers’ digital history, biometric information, or genetic data to tailor prices based on what algorithms predict each customer is willing to pay. It does not ban dynamic pricing based on demand, such as ride-hailing surge pricing. The law allows the state attorney general or consumers to sue violators, with fines up to $10,000 for a first offense and $20,000 for subsequent violations, plus potential refunds and permit losses. The legislation also imposes a one-year pause on electronic shelf labels while the state studies their potential for unfair pricing. Opponents, including the New Jersey Business & Industry Association, argued the law could interfere with loyalty programs, though the law explicitly exempts discounts, promotions, and loyalty programs. New Jersey is the third state to enact such a ban, following Maryland and Connecticut; similar legislation has passed the New York Legislature and awaits the governor’s signature, while California lawmakers consider a comparable bill.

New Jersey bans grocery stores from using shoppers’ personal data to set prices • Jersey Vindicator →

Attorneys Seek Non-Users for Class Action Over Meta Pixel Health Data Collection

Attorneys are preparing a class action lawsuit against Meta, alleging the company used its Meta pixel tracking code on telehealth websites to collect sensitive health information about patients, including those without a Facebook account. The pixel, embedded on sites of companies like Monument, Cerebral, and Brightside Health, can record every action a visitor takes, including button clicks, searches, and information provided through the website. Attorneys believe Meta compiles this data for advertising without consent, potentially violating the California Invasion of Privacy Act, which allows recovery of up to $5,000 per violation. For non-users, Meta may be compiling data into a ‘shadow profile’ — a collection of information about a person they never chose to share. The Federal Trade Commission and the U.S. Department of Health and Human Services sent a letter on July 20 to roughly 130 hospital systems and telehealth providers warning about risks from tracking technologies like the Meta pixel, citing a December 2020 investigation that found 13 of 50 telehealth websites tracked and shared patients’ medical intake answers.

Facebook Shadow Profiles Lawsuits | Non-User Health Data Collection? →

18 Georgia Law Enforcement Officers Arrested for Misusing Flock License Plate Data

In Georgia, 18 law enforcement officers have been arrested in recent months for misusing Flock Safety license plate reader data. The most recent arrest was DeKalb County Sheriff’s Office Sgt. Kabiru Salawu, a 17-year veteran, who faces up to one year in prison for a misdemeanor and one to five years for a felony charge of violating his oath. On Wednesday, Conyers Police Department supervisor Paige Forte was arrested for allegedly misusing the Flock system over 30 times between April and July to search for her domestic partner’s car. Flock Safety, the Atlanta-based company behind the automatic license plate reader networks that log over 20 billion data points monthly, credited its Audit Assistance tool, announced in April, for enabling at least some of these arrests. Privacy advocates argued that more is needed to protect privacy, noting that officers with access can track vehicles without a warrant. Michael Soyfer, an attorney at the Institute for Justice, said the lack of a warrant requirement predictably allows officers to abuse access for stalking romantic partners.

Georgia cops keep getting arrested for misusing Flock surveillance data →

EU Accuses TikTok of Failing to Protect Minors, Risks 6% Fine

The European Commission issued preliminary findings under the Digital Services Act accusing TikTok of failing to shield young users from serious online dangers, including predators, cyberbullying, and unwanted contact. Regulators found that minors can flip their profiles to public, allowing anyone to view their videos, and that even private accounts remain discoverable through following and follower lists visible to people without an account. The Commission wants TikTok to change default settings so content stays visible only to users a young person has approved. This is the fourth formal allegation TikTok has faced in two years. TikTok said it would examine the findings and cooperate, pointing to existing protections including private-by-default profiles for anyone under 18 and direct messaging blocked for the youngest teens. If the case holds, the penalty could reach 6% of TikTok’s global annual turnover, translating into hundreds of millions of dollars.

TikTok risks a 6% fine as EU targets child safety failures →

Supreme Court Rules Geofence Warrants Require a Warrant for Location Data

On June 29, 2026, the U.S. Supreme Court decided Chatrie v. United States, ruling that the Fourth Amendment requires a warrant for law enforcement to obtain granular location history data from Google. The case involved a geofence warrant, a tool that asks a technology company for records of which devices were in a specific area around a time of a crime. The Court held that Americans have a reasonable expectation of privacy in granular location data stored in their Google accounts, regardless of whether the data covers several days (as in the 2018 Carpenter decision) or one to two hours (as in Chatrie). That expectation persists despite users consenting to data collection, storing data in the cloud, and allowing the collecting company to use it for limited purposes. The Court did not decide whether the specific geofence warrant in Chatrie was constitutional, leaving open questions about whether geofence warrants can ever satisfy the Fourth Amendment. The ruling leaves intact a circuit split, with the Fifth Circuit holding that reverse warrants are unconstitutional general warrants, while the Colorado Supreme Court rejects that categorical analysis.

Geofence Warrant Ruling Is a Big Victory for Personal Privacy →

US Prosecutes American for Using Duress Password to Wipe Phone at Border

The U.S. Justice Department is prosecuting American citizen Samuel Tunick for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, in what is thought to be the first known case in the United States of federal prosecutors charging someone for the alleged destruction of data using a ‘duress’ password built into a phone’s software. Tunick’s attorneys said it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year and that any evidence should be thrown out. The case centers on a feature in GrapheneOS, a custom Android operating system, that allows the device owner to set a passcode that deliberately wipes the device’s contents if entered instead of the user’s unlock passcode. Tunick’s attorneys filed a motion to suppress the evidence, claiming the detention and seizure were unlawful, and that border authorities took Tunick into secondary inspection at Atlanta’s Hartsfield-Jackson airport on January 24, 2025, but repeatedly denied him access to an attorney. The motion argued the government was investigating him over his association with the environmental movement Defend the Atlanta Forest, which opposes the development of a training campus for law enforcement in Atlanta called ‘Cop City.’ Prosecutors charged Tunick under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it; Tunick has pleaded not guilty. Security experts from the Electronic Frontier Foundation and Granitt said they had not seen similar cases involving duress passwords.

US accuses American of allegedly wiping his phone using a ‘duress’ password during border search | TechCrunch →

Vanderbilt Health Employee Click Sparks Patient Data Exposure in Nashville

A Vanderbilt Health employee clicked a malicious link in a phishing email, potentially exposing a limited number of patients’ personal health information. The intrusion was discovered on March 27, 2026, after an unauthorized user gained access to the employee’s email account, with signs of mailbox activity on March 23 when the intruder viewed certain documents. Vanderbilt Health stated it has no evidence the information has been misused and that its electronic medical record system was not accessed. The potentially viewed files included patient names, medical record numbers, admission and discharge dates, diagnosis or procedure details, and provider or facility names; Social Security numbers and financial account information were not involved. Vanderbilt Health is notifying affected patients, offering complimentary credit monitoring, and tightening email and digital security while expanding cybersecurity training for staff.

Vanderbilt Health Worker’s One Bad Click Sparks Patient Data Scare In Nashville →

Indonesia’s Biometric SIM Registration Hits 10 Million, May Expand to 291 Million Existing Users

Indonesia’s biometric SIM registration program, SEMANTIK, has surpassed 10 million facial-recognition verifications since its mandate took effect on July 1, and the government is signaling that the face-scan requirement may extend to the country’s roughly 291 million active mobile subscribers who registered under the old system. At a ceremony on July 23, Minister of Communication and Digital Affairs Meutya Hafid set a new target of 20 million total registrations within the next month, specifying that the next 10 million should include existing subscribers. The previous SIM registration system, in place since 2017, was exploited through borrowed identity cards and stolen credentials; the government estimates roughly 300 million scam calls occur annually, with digital fraud losses of approximately IDR 9.5 trillion (about $530 million USD) from more than 548,000 complaints through April 2026. Under Ministerial Regulation No. 7/2026, facial recognition adds a Know Your Customer layer that matches a live face against the national ID database, with operators prohibited from retaining raw facial images on private servers. A real-world failure mode has emerged: retailers registering SIM cards using the seller’s own face rather than the customer’s. Privacy International concludes that mandatory SIM registration laws have not proven effective at curbing crime, citing Pakistan’s black markets for unregistered SIM cards after biometric registration and Mexico’s 2009 enactment and 2012 repeal after no measurable improvement. Indonesian cybersecurity experts noted that biometric registration cannot prevent many common forms of online fraud relying on social engineering, and recommended establishing an independent Personal Data Protection supervisory agency before expanding biometric data collection.

Indonesia’s Biometric SIM Drive Hits 10 Million, Targets 291 Million Existing Subscribers →

Sam Altman’s Eye-Scanning ID Startup World Raises $52.5 Million

World, the online identity-verification venture co-founded by OpenAI CEO Sam Altman, raised $52.5 million through a token sale of Worldcoin (WLD) on Friday. Pantera Capital led the round, joined by Eightco Holdings, Bain Capital Crypto, Susquehanna Crypto, and Selini Capital, with tokens under a 12-month lockup. World, operated by Tools for Humanity and led by CEO Alex Blania, verifies users through Orb devices that scan irises to issue a World ID, designed to distinguish real people from bots online. The Orbs rely on Nvidia chips, which Chief Business Officer Trevor Traina has called limited in supply despite rapid production efforts, constraining scale. In April, World partnered with Zoom Communications, rolling out ‘Deep Face’ verification to flag AI-generated meeting imposters, alongside a Tinder integration. Adoption has lagged, prompting Tools for Humanity to conduct layoffs in June. The token sale follows Grayscale Investments’ July filing for a spot Worldcoin ETF under ticker ‘GWLD.’

Sam Altman’s Eye-Scanning ID Startup World Just Raised $52.5 Million, Even as Nvidia Chip Shortages Slow Its Rollout →

Pope’s Official Prayer App Leaks Data of Over 700,000 Users

The official prayer app of the Pope’s Worldwide Prayer Network, Click To Pray, leaked the names and email addresses of over 700,000 users for at least six months. The vulnerability, an Insecure Direct Object Reference (IDOR) bug, was discovered and reported by an ethical hacker using the alias BobDaHacker on January 3, 2026. The app assigns users sequential numeric user IDs upon signup, and the API endpoint returns user data for any account without performing authorization or ownership validation. The exposed data includes email addresses, first and last names, country, dates of birth, and whether the account has been deleted. Because user IDs are sequential and there is no rate limiting, an attacker could enumerate all 719,517 accounts. The hacker noted that the vulnerability was still live as of her Friday blog post and that nobody from the Pope’s Worldwide Prayer Network had responded to her disclosure. The Register contacted the network and received no response.

Pope’s official prayer app commits cardinal sin, leaks 700K+ users’ info →

In autumn 2025, as part of a larger legal reform called the Digital Omnibus, the EU Commission proposed a solution to cookie banners: automated signals that would communicate a user’s privacy preferences between their device and websites or apps, allowing a user to choose whether to accept, refuse, or limit tracking. The proposal would let users set privacy preferences in the browser once and never see another banner. The tracking industry, spearheaded by Google, is pushing back against the proposal, leading several Member States to block it. Industry groups are also lobbying the European Parliament to reject the proposal. The source states that up to 90% of people say ‘YES’ to cookie banners, even though only around 3% actually want to be tracked online. The Member States and the European Parliament have not yet decided on their position.

Kill the Cookie Banner! →

Japan’s Official Pokemon Card Stores to Require Facial Recognition for Entry

The Pokemon Company has announced that Japan’s official Pokemon Card Store locations will begin using a facial recognition system to enforce store entry and purchase limits. Customers who wish to enter the stores must consent to facial recognition and will receive a numbered entry ticket; the system will verify that each customer only receives one entry ticket per day, and if it detects the same person attempting to receive multiple tickets or enter the store more than once in a day, staff will deny entry. The new measures are intended to prevent scalpers from circumventing entry and purchase limits. Preschoolers are exempt from the facial recognition and may only enter with an adult. The Pokemon Company says facial image data and visit counts will be stored securely for a certain amount of time in accordance with its privacy policy. It is unclear if these measures could expand to Pokemon Center stores; earlier this year, Pokemon also announced that select TCG purchases at Pokemon Centers will require a government-issued photo ID starting in August.

Japan’s Official Pokemon Card Stores to Require Facial Recognition for Entry and TCG Purchases - PokeBeach | PokéBeach →

CJEU Blocks Sweden’s GDPR Exemption for Criminal Convictions Database

The Court of Justice of the European Union ruled on 9 July 2026 in Case C-199/24 that Article 85(1) of the GDPR does not authorize member states to legislate beyond what Article 85(2) permits, and that national measures cannot introduce derogations from the regulation for processing carried out for purposes other than journalistic, academic, artistic or literary expression. The case involved ND v Legal Newsdesk Sweden AB, the operator of Lexbase, a commercial database of Swedish criminal convictions. The court ruled that member states may not reduce a convicted person’s legal remedies to defamation proceedings alone; where personal data about criminal convictions are made available online for payment, the affected individual retains the remedies granted directly by the regulation. The court also held that making public documents consisting of criminal convictions available online in return for payment cannot be treated as processing for journalistic purposes unless the activity meets defined conditions: disclosure to the public of information, opinions or ideas, in compliance with the ethical rules and codes of conduct of the journalistic profession, following editing or adaptation or at least an editorial policy, and after verification of the factual allegations concerned. The CJEU press release stated that the act of placing criminal convictions online for payment ‘does not appear’ to satisfy those conditions, subject to verification by the national court. The judgment revives a claim for damages of 300,000 Swedish kronor (roughly 26,000 euros) plus interest.

CJEU blocks Sweden’s GDPR exemption, reviving SEK 300,000 damages claim →

Vint Cerf: Privacy May Be an Anomaly in Human History

Vint Cerf, a former Google chief internet evangelist from October 2005 through July 2026, made remarks about privacy during a media Q&A session at a Federal Trade Commission workshop on the Internet of Things. The Verge reconstructed his words, with Cerf stating that throughout human existence, the desire for privacy is a relatively modern blip. Cerf argued that humans are naturally inclined to live in small communities, such as villages, where only a few thousand people would interact and everyone would know what everyone else was doing, and the postmaster would know who everyone was getting their mail from. He noted that since the Industrial Revolution, there has been massive growth in larger population centers like cities and a global population explosion.

Quote of the day by ex-Google evangelist Vint Cerf: ‘Privacy may actually be an anomaly’ — putting our rights into perspective →