Privacy
California DROP Portal Draws 300,000 Deletion Requests
California's new DROP platform sees 300,000 requests as 600+ data brokers face mandatory erasure; ALPR data flows to police; AI chatbot age checks criticized.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
California DROP Portal Lets 300,000 Users Demand Data Deletion From Brokers
Starting August 1, more than 600 companies registered as data brokers in California became legally required to erase personal information of any Californian who asked. About 300,000 people have already submitted requests through DROP, the Delete Request and Opt-out Platform, available at privacy.ca.gov and run free of charge by the California Privacy Protection Agency.
Repo Agents Scan Low-Income Areas With ALPRs, Feeding Police Databases
As car repossessions rise, agents are increasingly using automatic license plate readers to locate vehicles, with Digital Recognition Network supplying the technology to over 1,000 private clients. Repo men mount ALPRs on tow trucks and in ordinary cars for stealth scanning, driving through areas where they expect to find targeted vehicles, including low-income neighborhoods, which they admitted favoring because residents there are more likely to face financial issues. All scanned plates go into DRN’s master database with time, date, and location data, and nearly every car scanned is not on a repossession list, yet the data can be used for police investigations without a warrant. DRN is a sister company to Vigilant Solutions, now known as Motorola Solutions, which supplies ALPRs to ICE, meaning data generated by repo men cruising low-income neighborhoods is available for immigration enforcement.
As Repossessions Rise, License Plate Readers Aren’t Just For Cops Anymore →
SignalTrace Links Devices to Vehicles, Raising Fourth Amendment Questions
SignalTrace, a surveillance system marketed by Leonardo, works alongside license plate readers to recognize groups of consumer devices that regularly move together and associate them with plate records, allowing searches even without a plate number. The system collects electronic signatures from Bluetooth or RFID signals already being broadcast, stores fingerprints for later queries, and can recognize a vehicle without seeing its license plate, with several devices reportedly installed in Oxon Hill, Maryland. The patent describes targets that may be people or vehicles, and the system is designed to develop leads, influencing which records officers request and whose movements receive further scrutiny. The Supreme Court’s June 2026 decision in Chatrie v. United States held that obtaining location data constituted a Fourth Amendment search, but the ruling does not determine whether SignalTrace collection would also count as a search, since it detects signals broadcast from nearby devices rather than location records. A recurring cluster of devices may reflect a family routine, shared commute, or passengers who happen to travel together, and a correct match between a device and a vehicle does not establish who carried it on a particular day.
A new surveillance tool can trace people through the devices they carry →
Russia’s State-Backed Max Messenger AI Tells Users to Switch to Telegram or Signal
Alisa, the AI assistant built into Russia’s state-backed Max messenger, has been telling users in chat conversations to install other apps instead, including Telegram, Signal, or WhatsApp. The AI, developed by Yandex, cites several vulnerabilities in Max: it lacks end-to-end encryption and routes user data to servers owned by VK, collecting IP addresses, activity times, contacts, device and browser type, and other metadata that may be shared with third parties, including government agencies, upon a lawful request. Alisa recommends keeping Max on a separate device rather than installing it on a phone used for banking apps and private chats, and suggests using the browser version and denying the app permanent access to location, contacts, microphone, and camera if it must be used on a personal phone.
ITIF Report: Age Verification Bills for AI Chatbots Harm Adult Privacy
A new ITIF report finds that the most common state approach to protecting children from AI chatbots, requiring platforms to verify user ages via identity documents or biometric scans, imposes a structural privacy cost on all adults without achieving its goal. As of August 2026, almost 100 state chatbot-specific bills have been introduced across 34 states plus three federal proposals, and the report argues that forcing chatbots to collect additional personally identifiable information is a backwards approach. Three age verification vendors have experienced major security incidents: AU10TIX exposed users’ driver’s licenses in 2024, a Zendesk system used by Discord exposed approximately 70,000 users’ ID photos in 2025, and Persona faced a breach in 2026. The report proposes that Congress require device operating systems to create an opt-in child flag that parents set once per device, generating a signal that apps can query without the chatbot developer ever receiving the child’s identity, birth date, or biometric data, moving the compliance burden from individual app developers to the operating system layer where Apple and Google already manage device-level account systems.
ITIF Report Warns 98 AI Chatbot Bills Collect Adult ID Data Without Protecting Children →