HeadFlash

Privacy

Chat Control, Data Breaches, and Privacy Rights: July 28, 2026

Claude chats leak, UK age checks under fire, EU chat control advances, and a major Australian data breach.

Listen

Hundreds of Claude AI Chats Exposed in Search Results

The exposed conversations included users seeking help with CVs, including names and contact information, and users conducting what appeared to be proprietary research, including transcripts of private conversations. An Anthropic spokeswoman stated that Claude users maintain control over if and when to share conversations, and that links to conversations are not guessable or discoverable unless people choose to share them. The share option within Claude tells a user that anyone with the link may view the contents, but does not explicitly state the link may appear in search results. A Google spokesman stated the company does not control what pages are made public on the web, and that action comes from websites.

Some people’s chats with Claude AI found publicly available online →

Lords Inquiry Opens as UK Age Checks Strip Adult Privacy

The law requires platforms to implement highly effective age verification for content harmful to children, but does not specify what data may be collected, how long vendors may retain it, or whether privacy-preserving alternatives must be offered. The market’s default has been government-ID upload to third-party vendors, forcing users to submit passport photographs or driving licenses. A privacy-preserving alternative exists and is Ofcom-endorsed: zero-knowledge proofs (ZKP), a cryptographic method that allows a platform to confirm a user is over 18 without learning the user’s identity. Baroness Keeley, Chair of the committee, said it is now clear that the Act is not working as well as it should. The committee will examine enforcement and whether problems in the statute itself require Parliament to act.

Lords Open Online Safety Act Inquiry as Breach-Prone Age Checks Strip Adult Privacy →

California Court Rules License Plate Data Collection Alone Is Not Harm

The question before the court was whether a person who alleges harm under the state law but identifies no resulting harm other than a subjective belief that privacy has been invaded has standing to sue. The unanimous opinion, written by Associate Justice Truc Do, concluded the answer is no. The appellate court found that standing to sue requires a showing of actual harm, such as unauthorized access to or use of the data or a security breach. Several civil rights groups filed briefings in support of Mata, including the Electronic Frontier Foundation and two California chapters of the ACLU. EFF Privacy Litigation Director Adam Schwartz said the organization is disappointed that the court turned away this challenge on the incorrect claim that privacy harm is not sufficient harm to have standing.

California appeals court finds that license plate data collection alone is not harm →

EU Governments Confirm Interim Chat Control Regime, Excluding Encrypted Apps

Under the proposal, providers would first assess risk and implement mitigation measures; if a national authority identifies significant risk, it may request a court or independent body to issue a targeted, time-limited, and proportionate detection order. For encrypted apps, the most debated requirement is client-side scanning, which inspects content on the device before encryption. Digital rights groups argue that a targeted order effectively becomes mass surveillance once scanning infrastructure is implemented across a platform. EU privacy watchdogs warn the proposal could enable broad, indiscriminate scanning of ordinary communications, conflicting with the EU Charter’s privacy protections. Critics argue client-side scanning undermines true end-to-end encryption and could be repurposed, posing risks to journalists and whistleblowers and prompting services like Signal to leave the market.

Why is Chat Control one of the EU’s biggest digital rights fights? →

Origin Energy Breach Exposes 900,000 Customers’ Data

Origin has 4.8 million customer accounts in Australia and provides electricity, natural gas, LPG, and internet services. The company warned customers to be alert to a heightened risk of scams, advising them to be wary of unexpected calls, emails, or texts referring to their account. Griffith University expert Graeme Hughes said the breach was unlikely to cause payment fraud but marked a social engineering problem, as the last four digits of a card, a date of birth, and authentic billing history are trust signals businesses use to verify themselves over the phone.

Origin reveals 900,000 customers had their data breached in hack →