HeadFlash

Privacy

Google Pays $10M for Spirit Airlines Data, Picks Anonymizer

Google's $10M Spirit Airlines data deal faces court review; France warns taxpayers after major hack; Russia expands travel surveillance.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Google’s $10M Spirit Airlines Data Deal Nears Court Approval

Google has agreed to pay $10 million for Spirit Airlines’ data, with the sale set for a bankruptcy court hearing on Wednesday morning. The agreement, filed on 14 August, gives Google sole control over selecting the third-party agent that will deidentify the data, and Google will cover all associated costs. The chosen agent must certify the work meets the California Consumer Privacy Act standard, with health-related material handled under federal health privacy rules.

Google picked and paid for the firm anonymising the Spirit Airlines data →

Supreme Court Rejects Verizon’s Bid to Recover $47M FCC Fine

The US Supreme Court declined on 17 August to modify its 4 June ruling, blocking Verizon’s attempt to recoup a $46.9 million penalty paid to the FCC over location-data privacy violations. The June ruling found telecoms cannot demand a jury trial upon receiving an FCC forfeiture order, but a footnote left open whether Verizon was misled into paying. AT&T, facing a $57 million fine, remains unaffected as its case follows a different procedural path through the Fifth Circuit, preserving its ability to seek reimbursement.

US court rejects Verizon bid to recoup $47M FCC fine →

France Warns Taxpayers After Major Personal Data Hack

French taxpayers were warned after personal data was stolen in a major hack. The warning was issued in France on 17/08/2026. No further details on the breach or its scope were provided in the source material.

French taxpayers warned after personal data stolen in major hack →

German Asylum Card’s Lawyer-Naming Rule Ruled Illegal by DPA

Germany’s state-issued prepaid Visa card for asylum seekers, the Bezahlkarte, now operates across all 16 federal states, with approximately 200,000 users. The card restricts cash withdrawals to €50 per month in 13 states, blocks bank transfers, and disables online purchases. Brandenburg’s data protection commissioner ruled the whitelist mechanism, which requires cardholders to name specific recipients like lawyers for manual approval, is not lawful under the GDPR, as public authorities cannot invoke legitimate interests for such processing.

Germany Asylum Payment Card Requires Cardholders to Name Lawyers to State; DPA Rules Illegal →

Russia Proposes Near Real-Time Travel Data Sharing for Security Services

Russia’s Transport Ministry is proposing to expand the data carriers must transmit to the state, adding actual trip data alongside planned trip data. Airlines and railways would have 15 minutes after a passenger’s arrival to enter the data, while road, sea, and river transport would have 30 minutes. Each trip would receive a unique identifier linking all passenger actions, with air travel data also including connecting flights and baggage information. Experts believe authorities will use the new rules for investigative operations, tracking individuals named in criminal cases in real time.

Russia moves to give security services near real-time access to citizens’ travel data — Meduza →