Privacy
FTC Bans GM From Selling Driver Data for Five Years
California curbs AI in schools, Florida confirms DMV breach, and Oregon cities drop Flock cameras as privacy fights sharpen.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
FTC Imposes Five-Year Ban on GM Selling Driver Data to Brokers
The Federal Trade Commission issued a five-year ban preventing General Motors from selling customer data to consumer reporting agencies and third-party data brokers. GM collected detailed driving information, including how often customers sped and whether they drove at night, then sold it to brokers who used it to generate risk profiles for insurance companies. Many drivers were unaware of the extent of the collection, and many unknowingly consented by signing up for an OnStar connected services plan that activated a feature called Smart Driver.
GM shared the data with two brokers, LexisNexis and Verisk, both of which work with the insurance industry. A 2024 New York Times investigation found that some drivers saw their insurance rates rise as a result, and that the enrollment process was confusing enough that many vehicle owners did not realize their data was being shared. Under the settlement, GM must make it easier for drivers to turn off location tracking and must let them access and delete the data the automaker collected.
Your car is selling your data →
California Law Bars Ed-Tech From Using Student Data to Train AI
California Gov. Gavin Newsom signed Assembly Bill 1159, imposing stricter student privacy rules on education technology providers including Canvas and DuoLingo starting next year. The law prohibits technology companies from using student data to train or develop AI models, at a time when California’s K-12 schools, community colleges and universities increasingly rely on AI for learning, grading and navigating bureaucratic issues.
The measure, by Assemblymember Dawn Addis, a San Luis Obispo Democrat, expands on California’s landmark education technology law, which limits how companies can use data from students in prekindergarten, preschool and K-12. The new law applies the same rules to college students’ data and broadens the scope of companies subject to the regulations. Addis said in a press release that ensuring data privacy and protection is vital to children’s well-being, dignity and right to learn, and that no child should be put at risk of big tech taking advantage of their personal data for financial or any other kind of gain. The law was supported by unions representing California teachers, nurses and college professors, while TechNet and the California Chamber of Commerce opposed the bill.
California became the first state in the country to regulate education technology companies’ use of student data in 2014. That law applies to companies that primarily serve students and that are designed and marketed for them, excluding popular products such as Google or YouTube, which can argue they are not primarily for students and were not originally designed and marketed for them. The new law says any company that knows its products are used in schools and whose products are designed or marketed to students is prohibited from selling the data it collects or using that information for anything beyond that student’s education. Newsom said at a press conference before signing the law along with 12 others related to kids and technology, including those limiting children’s access to chatbots, that it was a good day for the state’s children and for California’s leadership. The bill is unlikely to cover all of children’s data, especially for apps and websites used outside the classroom or not specifically endorsed by the school.
Tech companies are selling kids’ data. A new California law aims to protect their privacy →
Florida Confirms DMV Database Breach via Stolen Police Credentials
The Florida Department of Highway Safety and Motor Vehicles confirmed its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. FLHSMV said that on September 4, 2026, it learned of a data breach conducted by an international cybercriminal organization, that the breach was quickly mitigated, and that no further breach has occurred or is ongoing. The agency’s investigation determined the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device.
FLHSMV notified the Florida Office of the Attorney General and is working with the Florida Digital Service and Florida Department of Law Enforcement as part of its response. It said further information will be released at an appropriate time because the criminal investigation is ongoing. ShinyHunters claimed a different access method than FLHSMV’s findings. The hackers said they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent, then began iterating through DAVID record IDs and downloading associated HTML pages and images beginning on September 3. As proof, the threat actors shared a screenshot of a DAVID record belonging to Jeffrey Epstein containing sensitive personal and vehicle information.
ShinyHunters later told BleepingComputer it had lost access to the system and believed the flaw was being patched. The gang claimed it stole more than 200,000 driver records; FLHSMV has not disclosed how many records were accessed or stolen and has not confirmed that figure.
Florida confirms DMV database breached via stolen police account →
Revolut Disclosed Customer Data After Fake Government Requests
Revolut confirmed that sensitive customer information was disclosed to an unauthorised third party after it received fraudulent requests sent from a legitimate government agency email domain, a company spokesperson told Reuters on Saturday. Upon detection, Revolut immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection and financial regulators, the spokesperson said. Revolut systems and customer funds are unaffected, the spokesperson said, without disclosing the exact number of individuals affected.
The compromised data included customers’ birth dates, postal and email addresses, and phone numbers, as well as copies of identity documents including passports and driver’s licences. Revolut is planning for a potential public listing and aiming for a valuation of up to $200 billion. It is one of the most successful European fintech companies, with no physical bank branches.
Revolut confirms sensitive customer data breach, falling for fake government requests →
Six Oregon Cities and Two Counties Cut Ties With Flock Cameras
At least six Oregon cities and two counties have canceled or curtailed contracts with Flock, the surveillance technology company, over the past year, spanning red and blue parts of the state. Republican and Democratic state lawmakers have vowed to introduce legislation to ban the AI-powered camera network, which captures license plate numbers at more than 500 locations in Oregon. Critics including the American Civil Liberties Union and the sheriff of Josephine County, where Republicans outnumber Democrats nearly 2 to 1, say the cameras invade privacy because they can track any motorist’s car even when the person is not suspected of a violation or crime.
In testimony to the Oregon Legislature, ACLU representative Ethan Krow wrote that the result is an ever-growing volume of highly sensitive data about Oregonians’ daily lives. The exact number of Oregon license-plate readers and Flock cameras cannot be determined because Flock does not release their locations. The $8.4 billion company has said it has 120,000 cameras nationwide that capture and store images of plate numbers, including date, time and location, and vehicle details such as dents, decals and bumper stickers. Motorola, Axon and other companies also operate camera networks in Oregon and elsewhere. Activists have compiled Flock locations in a crowdsourced database called Open Street Map, which shows Oregon has at least 529 license plate readers, almost certainly a vast undercount.
License-plate reader technology has existed for decades, but the AI-powered Flock network is a comprehensive, vehicle-profiling ecosystem with a central database available to more than 5,000 police departments, according to the company. Flock has been accused of lax data security and has misidentified suspects and stolen cars. In Los Angeles, police reported a 32% inaccuracy rate in the technology identifying stolen cars over two recent months. During a trial run in Woodburn, Oregon’s most Latino city, officials found the data they collected was being accessed by federal immigration agencies, which Oregon law explicitly prohibits. The cities of Bend, Eugene, Springfield, Talent, Winston and Woodburn signed contracts with Flock but in the past several months canceled or suspended them, citing safety and privacy concerns. The readers have led to false arrests and detainments across the country, according to the ACLU. This past spring, Oregon lawmakers passed legislation to curtail the reach of AI-powered camera networks, mandating that images be stored for only 30 days unless the driver of a photographed vehicle is suspected of traffic offenses or other more serious crimes. Two lawmakers believe the change did not go far enough and want to ban automatic license-plate reader cameras entirely.
In Oregon, left and right find common ground in opposition to Flock cameras →
Ring’s New TAKE Encryption Falls Short of End-to-End Privacy
Amazon introduced Throw Away the Key Encryption (TAKE) for its Ring cameras, a key-management scheme intended to reduce the video content available to the company and potentially to law enforcement. Under TAKE, the user’s device holds its key while Ring temporarily holds encryption keys within its own cloud infrastructure. Ring’s servers receive the keys temporarily so the company can provide features it says it cannot offer under end-to-end encryption, including video descriptions, smart alerts and video search, then deletes the key after 24 hours. This differs from the existing setup, in which footage is encrypted in transit and at rest and then decrypted by Ring, which always has access to the footage to process those features.
Many Ring camera features require cloud processing, so Ring must decrypt footage stored on its cloud servers to provide them. Under TAKE, Ring gets access to cloud-stored footage for 24 hours to decrypt it for these features. TAKE adds small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. After cloud processing delivers the requested feature, the key is deleted 24 hours later, until the user wants to watch an old video or use other smart features, at which point the keys are sent back to the server. In practice, the system as a whole is barely different from encryption at rest where the server holds the keys; the client device essentially takes the place of a hardware security module, including making keys available to the server whenever needed.
The result is an improvement over the status quo but still not close to the privacy protections of end-to-end encryption. Ring says it does not keep backups of the keys and that no Ring employee can access footage, and it claims any decrypted content is deleted from its servers. Account recovery keys are stored in the camera itself by default, and indices of video contents are currently available to the company, so TAKE is not a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest, decrypting account backups and using that information to decrypt encrypted videos. Ring told EFF that by design under TAKE it will not be able to provide encryption keys or decrypted content, and that it will only preserve and provide encrypted video files in response to valid legal process. EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears technically possible, but the company did not address it. Ring already offers an option for end-to-end encryption, and turning that on by default would offer the real privacy improvements sought from video doorbells.
Cold TAKE: Amazon’s New Encryption Method Still Doesn’t Deliver Real Privacy →
Census Bureau Staffers Question Independence After DSEP Charter Rewrite
Current and former Census Bureau staffers say governance changes to a key agency committee have opened the door for Trump administration interference and removed accountability mechanisms from Bureau decision-making. The Data Stewardship Executive Policy Committee, known as DSEP, is a leadership body that aids director-level Bureau staff with internal policy and decisions, focusing especially on Title 13, the law requiring the Census Bureau to protect respondent confidentiality. Since the committee was created in 2001, political appointees have not traditionally held permanent positions.
A late July update to the DSEP charter makes the Bureau’s deputy director for data, policy and science — a newly created, politically appointed position — a co-chair. That role is held by Michael Lachanski, a two-time fellow at the Claremont Institute, a conservative think tank that has funneled personnel to key positions throughout the Trump federal government. Lachanski was also a senior advisor at the Department of Commerce’s Office of the Under Secretary for Economic Affairs when that department rolled out a ban on a Census privacy-protection method called differential privacy, which scientists found to be safe and effective. Right-wing influencers and Republican politicians attacked differential privacy, claiming falsely that it helped Democrats accrue political power. The ban alarmed experts because it did not appear to have undergone the normal review process, which would have included an analysis from career staff at DSEP.
Other charter changes include removal of the requirement that the Bureau reject political influence and elimination of the Bureau’s commitment to equitable uses of federal data. The charter also adds additional politically appointed staffers to the DSEP committee. Simson Garfinkel, a former Census Bureau scientist, said the change is consistent with the administration’s view that executive branch activities should align with its goals and policies, and that the policy changes also go against the Bureau’s previous statistical standards. A former longtime staffer said the changes may actually have the opposite effect of actively politicizing the committee: they have cut DSEP out of crucial initiatives it would otherwise have analyzed and advised on. The charter changes were enacted just under one month after the Commerce Department banned disclosure avoidance, a suite of highly scientific and rigorously studied privacy techniques that include differential privacy. That policy did not go through DSEP, which experts called unprecedented for such a significant policy shift. The DSEP charter changes also came just before the Census Bureau published an unusual report using unreliable private data, with help from the right-wing America First Policy Institute, purporting to show very limited evidence of non-U.S. citizens voting in federal elections. That report also does not appear to have been presented before DSEP, though it should have been, two former Census staffers said. Wired reported that Lachanski was a co-author on the report, which was published without attribution. A current Census Bureau employee said Lachanski specifically requested an employee be assigned to review data used in that report.
GDPR Compliance Gaps Widen as AI Agents Enter Enterprise Workflows
GDPR came into force before generative AI was embedded in everyday business applications, before AI agents executed multi-step tasks across corporate databases, and before prompt injection was a mainstream vector for data exfiltration. The regulation was designed around a different data environment, while AI has introduced new ways for data to be processed, inferred, retrieved and exposed, creating compliance risks that could not have been anticipated. Prompt injection illustrates the gap. An organisation may have strong access controls around a database of sensitive customer information, a documented lawful basis for processing, and policies on retention and deletion, but if it gives an AI assistant access to that database, an attacker could manipulate the AI into retrieving information it legitimately has access to. The underlying data controls may work, but the vulnerability sits in the layer between the user, the AI and the systems it can access.
The risk escalates as enterprises deploy agentic workflows. An AI agent may search internal documents, send emails, update records, access customer systems or interact with other applications, and each additional capability creates another potential route to personal data if the agent can be manipulated. GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data, but in an AI environment those measures cannot be assessed merely by whether they exist. Organisations need to understand how they perform under adversarial conditions, which means testing for prompt injection and data leakage, examining what an AI system can reveal through carefully constructed interactions, determining whether an agent can be manipulated into accessing or transmitting information outside its intended purpose, and testing the permissions given to AI systems and what happens when those permissions are abused. AI needs to be treated as part of the attack surface rather than as an application assessed once and then considered secure.
AI systems behave differently from conventional applications, with outputs influenced by inputs, context and interactions, and a system that appears secure under normal conditions may behave differently under an adversarial interaction. A compliance assessment carried out at deployment cannot necessarily show how a system will behave months later after the underlying model has changed, new data sources have been connected or permissions have expanded, so GDPR compliance in an AI environment needs to be continuous rather than static. A capability challenge accompanies this. Developers need to understand the security implications of the AI systems they build, security professionals need hands-on experience defending against adversarial AI techniques, and organisations must evaluate human-AI readiness by proving that human operators have the technical dexterity to direct, validate and override autonomous agents when they hallucinate or fall under attack. Future GDPR compliance will require evidence that organisations have actively tested their AI systems, challenged their assumptions and assessed how those systems behave under attack, and evidence that the people responsible for building and defending them have the practical capabilities to identify and respond to emerging threats.
GDPR wasn’t designed for AI and that’s a security problem | Computer Weekly →
Europe Weighs Action on Smart Glasses After Covert Filming
Calls are growing in Europe for action against smart glasses after secretly filmed footage of girls and women appeared online. A petition in Britain is demanding a ban on their sale. The push follows the circulation of covertly captured material, putting pressure on regulators and retailers to respond to privacy concerns around the wearable devices.
Europe eyes battle over ‘pervert’ AI glasses →
Explaining eTLD+1: The Boundary That Defines a Web Site
An eTLD+1 is the shortest part of a domain name that an independent party could have registered for itself: an effective top-level domain plus the single label immediately to its left. In www.example.com the effective top-level domain is com and the eTLD+1 is example.com. In project.github.io it is github.io, because GitHub lets anyone claim a name beneath it, so the eTLD+1 is project.github.io. Browsers call the result a site; advertising systems call it a domain, a root domain or a property, and use it as the unit against which inventory is authorised, counted and blocked.
The term exists because the line between one organisation’s web space and another’s cannot be read off the shape of a hostname: counting dots fails, since co.uk looks structurally identical to example.com but is a registry, not a website, and nothing in the Domain Name System marks where registration control passes to the public. The boundary is calculated from the Public Suffix List, maintained by the Mozilla Foundation as a community resource and published as a plain text file at publicsuffix.org. A public suffix is a name under which anyone can register; entries are also called effective top-level domains, or eTLDs. Its specification states that the registrable domain is the public suffix plus one additional label. As of September 12, 2026 it carried 10,325 rules, 6,951 in the ICANN section and 3,376 in the private one. The private entries matter most in advertising because that is where hosting and publishing platforms declare that their subdomains belong to unrelated parties: blogspot.com, github.io, myshopify.com, netlify.app, pages.dev and vercel.app all appear there.
Browsers add the scheme. Google’s Privacy Sandbox glossary defines a site as an eTLD+1 together with a protocol, and Chrome’s documentation calls websites sharing both same-site and everything else cross-site. Cookie scope follows the same boundary: RFC 6265 treats the public suffix check as what stops a hostile site setting a cookie with a Domain attribute of com. In advertising the clearest use is authorisation. The IAB Tech Lab ads.txt specification defines the root domain on which publishers must post the file as the public suffix plus one string in the name, and tells crawlers to use the Public Suffix List to derive it. Domain spoofing works by misrepresenting the boundary: the Financial Times found its display inventory offered on ten exchanges and its video on fifteen, at an estimated loss of around one million pounds a month, because a declared domain is asserted rather than proven. The list is static, so consumers holding an outdated copy misclassify newer suffixes until their software updates, and ownership remains the deeper gap: an eTLD+1 marks a registration boundary, not a corporate one.
Explaining Unlinkability: Why Privacy Hinges on Broken Joins
Unlinkability is the property of a system in which an observer cannot determine whether two pieces of information relate to the same person. Two ad requests, two logins, two purchases: where the property holds, nothing in the data reveals that one individual produced both. Most privacy harm in digital advertising comes not from any single observation but from the joins between them; one page view is close to worthless, but the same page view attached to four hundred earlier ones is a profile. The reference definition comes from a terminology paper by Andreas Pfitzmann of TU Dresden and Marit Hansen of the Schleswig-Holstein data protection authority, circulated in numbered versions through the 2000s and last released as version 0.34 on 10 August 2010. RFC 6973, published by the Internet Architecture Board in July 2013, defines unlinkability as the inability of an observer or attacker, within a particular set of information, to distinguish whether two items of interest are related, at a probability useful to that observer.
Three conditions sit inside that definition: the property is defined against a named adversary, so a dataset can be unlinkable to one recipient and fully linkable to another holding different side knowledge; it is probabilistic, a matter of degree rather than a binary state; and it is scoped to a set, the pool of candidates among which a record must stay indistinguishable. In advertising the joining happens at four layers. At the storage layer, a cookie gives one domain a stable handle on a visitor, and third-party cookies extended that handle across every site carrying the same tag; cookie syncing reconciles two vendors’ separate handles into one. At the network layer an IP address does the same job with no stored state at all. At the transport layer the links are explicit fields: bid requests carry an exchange cookie identifier, a buyeruid produced by syncing and an eids array of third-party identifiers, plus source.tid, which names the auction opportunity itself. At the data layer, identity graphs and clean rooms resolve scattered identifiers to a person-level token. LiveRamp’s RampID is the best-documented case; a February 2024 Cracked Labs report for the Open Rights Group put the system at 250 million identity records in the United States, 45 million in the United Kingdom and 25 million in France, queried more than 60 billion times a day.
Five families of mechanism recur to prevent linking. Partitioning keys state to the top-level site rather than the embedder; rotation shortens identifier lifetimes or issues a distinct identifier per recipient; network masking removes the address; blind tokens separate the moment a client is vouched for from the moment it spends the voucher; and anonymous credentials apply the same separation to identity documents. Linkage is the revenue: addressable reach, frequency capping, deduplicated reach and multi-touch attribution all assume two observations can be recognised as one person. Unlinkability is therefore a cost line before it is a compliance line. The regulatory weight arrived later and is heavier. The European Data Protection Board adopted Guidelines 02/2026 on Anonymisation on 7 July 2026, replacing the Article 29 Working Party test of 2014 with three criteria a dataset must satisfy: No Record Isolation, No Linkage and No Inference. The second asks whether a record could be matched, with certainty or high likelihood, to a record about the same person in a separate dataset — unlinkability under another name — and failing it means a controller has been processing personal data, retroactively, for the whole period it believed otherwise.