HeadFlash

Privacy

Uber hit with $964M Dutch fine over automated driver bans

Dutch regulators fine Uber $964M for automated account suspensions; CBP database abuse exposed; Maryland coalition targets data brokers.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Uber fined $964 million by Dutch regulator over automated driver account suspensions

Dutch data protection authorities fined Uber 825 million euros ($964 million) on Friday for using automated software to suspend driver accounts, sometimes permanently, without human review. The Dutch Data Protection Authority determined Uber violated the EU’s General Data Protection Regulation, which prohibits fully automated decision-making, and also failed to inform drivers about its automatic processes. The violations took place from 2018 to 2022.

Uber said it disagrees with the decision and will appeal, arguing the authority examined historic policies that were discontinued years ago and that the company takes decisions affecting drivers seriously, including through human reviews and appeal opportunities. This is the fourth time the Dutch authority has fined Uber; its largest previous penalty was in 2024, when Uber was fined 290 million euros ($324 million) for transferring European drivers’ personal details to the US without adequate protection.

Uber fined nearly $1 billion by Dutch regulators over automated suspensions of driver accounts →

CBP and DHS employees allegedly stalked exes and leaked data via government databases

Internal records obtained by WIRED through Freedom of Information Act requests contain hundreds of allegations of database misuse by U.S. Customs and Border Protection employees and contractors spanning more than a decade. The alleged abuses include federal agents querying data to look up romantic interests, monitor family members, expose personal information, and, in some cases, provide intelligence to suspected smugglers or drug-trafficking organizations. In one case, an officer allegedly used government databases to contact a flight attendant; another was accused of pulling information from trusted-traveler applications to ask people out.

A DHS employee allegedly used ad-tech-derived location data to track several coworkers’ cell phones, which appears to be the first known internal abuse case involving DHS use of such data. According to the documents, most officers are allowed to resign rather than face discipline or criminal charges, and contractors who abuse access can move on to other jobs in the same field.

CBP Officers And Contractors Abused Government Databases To Stalk Their Exes →

Coalition files complaint against seven companies under Maryland’s new data privacy law

A coalition of civil rights and privacy organizations in Maryland filed a 29-page complaint on Wednesday, August 20, 2026, accusing seven companies of violating the Maryland Data Privacy Act. The complaint alleges the companies’ products improperly collected, shared, and sold personal data, including cellphone and vehicle location data, and that in some cases the data was sold to agencies like U.S. Immigrant and Customs Enforcement (ICE). The seven companies named are Penlink, Motorola, Thomson Reuters, Insight LPR, LexisNexis, Flock Safety, and ThunderCat Technology.

The coalition is calling on the Maryland attorney general to enforce the law, which took effect in July. The AG’s office confirmed it received the complaint and is reviewing it. Only Penlink and Thomson Reuters responded to inquiries, both saying they are compliant with Maryland’s privacy laws. The Maryland Data Privacy Act was signed into law in May and aims to strengthen restrictions on data brokers regarding Marylanders’ personal data. Howard County Sen. Clarence Lam, a sponsor of the law, said the growth of A.I. and the Trump administration’s immigration strategy made the law necessary, citing concerns about the administration pulling information from state databases to track people down.

Coalition alleges companies are violating Maryland’s new data privacy law →

Free Atlas of Surveillance tool maps Flock camera deployments near you

The Atlas of Surveillance, created by the Electronic Frontier Foundation and the University of Nevada, Reno’s Reynolds School of Journalism, is a free tool that collects public information about surveillance technology used by law enforcement across the US. Its database covers thousands of agencies and surveillance deployments, including Flock Safety cameras, which are automated license plate readers that photograph passing vehicles and record plate information for police investigations.

Users can search by city, county, state, or local police agency, then filter results to “Automated License Plate Readers” or sort by “Flock Safety” as the vendor. Each entry shows which agency uses the cameras, when they were adopted, and sometimes how many are in service, with links to sources such as government records and news reports. The Atlas tracks deployments by police agencies, not the exact location of every camera pole.

This free tool shows whether police near you use Flock cameras →

Zero-knowledge proofs fail as age verification solution, researchers warn

Age verification laws are widespread: about half of US states have such laws, and federal proposals like the KIDS Act and the Kids Online Safety Act (KOSA) have advanced. EU member states are moving toward age verification in a centralized app by the end of this year, and Australia has a broad restriction in place. Zero-Knowledge Proofs (ZKPs) are promoted by some as a solution, but recent examples show ZKP-focused age verification schemes are gameable and hackable.

The mechanism requires a user to be issued a “token” vouching for their age at each login, creating a constant link back to the verifying entity. That issuer could track every use of the credential, creating a metadata trail, and could be pressured by authoritarian governments to remove a user’s access to a service. A security researcher bypassed the EU’s mini-wallet app using a Chrome extension that tricked the app into repeatedly accepting the same “over-18” token without fresh verification. Over 400 security researchers signed an open letter stating that age assurance checkpoints would cause more harm than good, citing the single point of failure vulnerable to cyberattack and authoritarian overreach.

Zero Knowledge Proofs Aren’t Age Verification Silver Bullets →

TikTok agrees to $400 million settlement over child privacy claims

TikTok agreed to pay a $400 million settlement over claims it failed to protect children’s online privacy. The social media site and its parent company were sued by the US Department of Justice in 2024. Lawyers argued that the firm collected “vast amounts of data” on millions of young children aged under 13.

TikTok to pay US government $400 million in child privacy settlement →

On 29 July 2026, a Federal Capital Territory High Court ordered Stanbic IBTC Bank to pay N15 million in general damages to two former customers, David Ogundipe and Salami Tolulope Ibrahim. The bank continued to retain and process their personal data and sent them marketing messages after they had closed their accounts and withdrawn consent. Justice Kayode Agunloye ruled that consent and lawful basis are not permanent once granted and expire when the purpose for which they were given ends.

The court found the continued processing a breach of the NDPA 2023, an infringement of the constitutional right to privacy under Section 37, and an unfair trade practice under the FCCPA 2018. The court did not order blanket deletion of the claimants’ records, recognising banks’ independent statutory retention obligations under AML and banking regulation. The order was to “delete what you have no legal basis to keep, and stop using what remains for marketing.” The case originated from two individuals represented by private counsel using the courts directly, not from the Nigeria Data Protection Commission.

Stanbic IBTC’s privacy judgment is a warning to every brand holding customer data →

Flock Safety CEO says privacy focus is ‘wrong thing’ in license plate reader debate

Flock Safety CEO Garrett Langley said people are prioritizing the “wrong thing” in the debate over automated license plate readers, arguing the focus should be on safety rather than privacy. Langley stated that the “privacy or safety” framing is a false choice and that communities are “prioritizing the wrong thing” when they focus on privacy concerns. He said the technology is designed to solve crimes and that the data collected is used only for law enforcement purposes.

Langley added that Flock Safety’s systems are not used for mass surveillance and that the company has safeguards in place to prevent misuse. He emphasized that the cameras help police recover stolen vehicles and solve violent crimes, and that the public should weigh the benefits of crime-solving against privacy worries.

‘PRIVACY OR SAFETY’: Flock Safety CEO says people are prioritizing the ‘wrong thing’ →

Swedish police probe online communities after sword attack kills one at school

Swedish police are investigating whether an 18-year-old man who attacked students at a high school with a sword on Friday, killing one, was involved in online communities promoting school violence, a police source said. The attack occurred at a school in the central Swedish town of Fagersta, severely injuring two teenage boys before the suspect was arrested. The parents of a 17-year-old girl told local newspaper Fagersta-Posten that their daughter was killed in the attack.

Police are investigating whether a TikTok account that posted a picture of a sword 20 minutes before the assault belonged to the suspect. According to the Dagens Nyheter newspaper, the image appeared to have been taken in a restroom at the school. Before it was taken down on Friday, the month-old account contained videos that referred to two episodes of mass violence in Sweden and to Norwegian far-right mass murderer Anders Behring Breivik. “The investigators are looking into various online communities which might have egged on the suspect to carry out the attack,” the police source said. Prosecutors ordered the man’s detention on suspicion of murder and several counts of attempted murder.

Sword attack in Sweden that killed 1 prompts probe into social media →

Privacy in AI era demands identity-centric Zero Trust and confidential computing

Privacy is no longer only a compliance issue for legal or IT departments but a strategic necessity at the core of digital trust, national security, and corporate resilience. AI systems require massive datasets containing private, financial, health, and proprietary data. Generative and agentic AI enables voice cloning, automated spying, convincing deepfakes, hyper-targeted phishing, and machine-speed polymorphic malware. The attack cycle is now a few hours or minutes instead of weeks. Quantum computing poses a danger to current encryption paradigms through “harvest now, decrypt later” techniques.

Every significant security issue pertaining to agentic AI comes down to identity: who or what is acting, with what authority, under which ongoing controls, and when access is revocable. Recommended fundamentals include making privacy a leadership and board-level obligation, strict cyber hygiene with phishing-resistant multi-factor authentication, and extending hygiene to AI systems by securing training data and preventing model poisoning. Confidential computing should be used to safeguard data: hardware-rooted Trusted Execution Environments, or secure enclaves, decrypt data only for approved processing and then re-encrypt or isolate it. Organizations should prepare for the quantum horizon and plan migration to post-quantum cryptography.

Protecting Digital Privacy In The Artificial Intelligence Era →

Anthropic adds watermarks to AI text, citing EU AI Act transparency rules

Anthropic has introduced watermarks for AI-generated text, a change driven by the European Union’s Artificial Intelligence Act rather than market demands or innovation. The EU rules prohibit AI systems from deploying subliminal, manipulative, or deceptive techniques that distort behavior and impair informed decision-making. The EU AI Act imposes fines of up to 7% of global revenue for violations. Anthropic is rolling out watermarks in all countries, citing the law’s transparency requirements.

The watermarking method was developed and already used by Google. It involves how the AI model selects specific words and word fragments, using a key with two lists of words; generated text must include enough words from one list to be statistically significant. The method does not work well on shorter passages and only reveals the likelihood that text was written by AI. The move is expected to increase pushback from the Trump administration over concerns about thwarting tech innovation and harming U.S. tech giants. President Trump said last month the administration will conduct a formal review to retaliate against the EU’s “discriminatory” digital practices.

Hidden Watermarks Will Track AI-Generated Text →

World ID comes to robots, letting delivery machines verify humans without identity data

World and peaq made World ID available to robots and machines running peaqOS, through robotic.sh. A machine can now request and verify a World ID proof, confirming it is dealing with a real and unique human, and, where needed, that the person completing an action is the same person who started it. The machine receives a proof, not a name, face, or other identity data. The mechanism is a zero-knowledge proof presented through World App, a wallet built by project contributor Tools for Humanity. Machines running peaqOS can perform the check natively, without an API key and without a per-verification charge.

Automated traffic overtook human traffic for the first time on record in 2024 and reached 53% of all web requests in 2025, with malicious automation alone accounting for 40%. World spent three years building a way for a person to prove humanness without disclosing identity, reaching nearly 18 million people verified at an Orb across 160 countries. peaq built an economic identity layer for machines, and by March 2026 had onboarded more than 3.3 million machines, robots, devices, vehicles, and agents with verified machine identities across more than 60 applications in 22 industries. In the medication scenario, a patient verifies through World App before the order is accepted, the pharmacist verifies before the medication is loaded, and the patient verifies again when the robot arrives, establishing the recipient is the same human associated with the order before unlocking. At no point does the robot learn the patient’s name or condition.

World ID Comes to Robots, Letting a Delivery Machine Check Whether You Are a Human | HackerNoon →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches