Last Update: 08/01/2026 at 1:00 PM EST

Morning Briefing: Privacy

Wednesday, July 22, 2026

July 22, 2026

23andMe Settlement Tests Privacy Accountability After Bankruptcy

Yesterday did not bring a new privacy regime. It brought a sharper test of the mechanisms already being used to claim accountability: settlement terms, deletion rights, audit logs and public dashboards.

The contrast was revealing. The 23andMe resolution carries security duties into the hands of a successor data holder even as bankruptcy sharply limits recovery, while local Flock reporting showed that an audit can range from recurring public review to scrutiny of just three searches. The question is no longer simply whether safeguards exist, but whether they are built to discover failure.

Legal Newsline and TechTarget detailed the multistate resolution of claims arising from 23andMe's 2023 breach, which affected nearly 7 million customers worldwide. Investigators alleged that the company lacked reasonable defenses against credential stuffing, including multifactor authentication, effective rate limits and monitoring for unusual login activity. States had $150 million in allowed claims, but bankruptcy limits their recovery to $18 million. More consequential over time, security reviews, an advisory board and continued deletion rights are obligations of the successor holder of the genetic data.

Local reporting exposed a wide gap between surveillance transparency and meaningful scrutiny. GV Wire reported that Fresno recorded 8,318 Flock ALPR searches during a one-month audit period, with more than 21 million plates scanned and 506 active users; although 100 searches were selected for analysis, only three were randomly reviewed. In Georgia, Chatham County launched a portal showing camera totals, recent scans and data-sharing partners, while Bluffton, South Carolina, described quarterly civilian oversight. These are all accountability measures, but they provide very different levels of assurance.

The New York Times reported that the New York Liquor Authority withdrew charges connecting Madison Square Garden's facial-recognition exclusions to state rules requiring licensed establishments to admit the general public, although fines remained against three venues. The withdrawal narrows one attempted route for challenging MSG's biometric practices. It does not establish that the underlying surveillance or exclusion policy is broadly lawful.

SecurityWeek reported that a social-engineering attack compromised three Clover Health employee accounts with access to PII and PHI. The company said corporate financial and claims systems were not reached, but the affected population and full scope remained unknown. The incident is smaller and less developed than the 23andMe case, yet it reinforces the continuing privacy exposure created by ordinary employee accounts with access to sensitive workflows.

Key Points

  • In the 23andMe case, state authorities treated the sale of consumer data during bankruptcy as a transfer of responsibility rather than a reset. That is an important distinction for distressed data businesses: a new owner may acquire the asset, but it can also inherit deletion, security and governance duties attached to it.
  • Police departments are responding to ALPR controversy with portals, retention statements, documented search purposes and civilian review. Yesterday's reporting made clear, however, that the existence of an audit says little by itself. Sample size, reviewer independence, access coverage and the ability to investigate cross-agency searches determine whether oversight can actually find misuse.
  • The MSG episode illustrates the fragility of regulating a biometric practice through an adjacent licensing rule. When enforcement depends on connecting facial recognition to public-admission or alcohol rules, the legal challenge may turn on the fit of that particular statute rather than the privacy consequences of the technology.

Implications

Organizations holding genetic, health or identity-rich data should treat account-takeover defenses as privacy controls, not generic security hygiene. The 23andMe allegations and Clover disclosure point to the same operational priorities: phishing resistance, multifactor authentication, breached-password screening, rate limits, anomaly detection and tightly limited employee access.

Buyers of distressed or data-intensive businesses need privacy diligence that extends beyond the purchase agreement. Successor obligations must be translated into working deletion processes, risk reviews, oversight structures and records showing that inherited commitments are being honored.

Public agencies operating ALPR networks should be prepared to demonstrate more than policy compliance. Reviews need enough depth to test high-volume users, unusual query patterns, external sharing and searches involving sensitive purposes. A dashboard can improve visibility, but it cannot substitute for an audit designed to uncover misconduct.

For biometric operators, the withdrawal of the New York charges removes one immediate regulatory pressure without resolving the wider legal and reputational exposure. Companies should not read the failure of one enforcement theory as general approval of facial-recognition-based exclusion.

Watchpoints

Watch

Whether TTAM Research Institute establishes the required data security advisory board, completes formal risk analyses and provides a usable process for customers seeking deletion of genetic data.

Watch

California's separate 23andMe lawsuit and the practical distribution of the bankruptcy-limited recovery, including whether further disputes arise over the successor holder's obligations.

Watch

Fresno's contract decision, any expansion of its audit beyond the three reviewed searches, and developments in the lawsuit alleging that Flock's National Lookup enabled access by unauthorized federal or out-of-state agencies.

Watch

Clover Health's final breach scope, affected-person count, notification filings and findings about how the three employee accounts were socially engineered.

Fallout

Meaningful movement concentrated in three long-running subjects: accountability for genetic data after corporate failure, the uneven quality of local ALPR oversight, and the difficulty of constraining facial recognition through laws written for other purposes. None amounted to a broad policy turn, but each clarified where existing protections are strongest and where they remain procedural or incomplete.

Genetic Data After Bankruptcy

Genetic information creates an unusually durable privacy obligation because it cannot be replaced like a password and may reveal information about relatives as well as the customer. The 23andMe bankruptcy has therefore become a test of whether consumer protections can survive the failure and sale of the company that collected the data.

Fresh developments

The multistate resolution gave the financial and operational consequences greater definition. States with $150 million in allowed claims are limited to an $18 million recovery from available bankruptcy funds, illustrating how insolvency can reduce monetary accountability even after investigators identify alleged security failures. At the same time, the successor data holder must maintain deletion rights, conduct risk analyses and establish security oversight.

Why we noticed

The most important outcome may not be the payment. It is the effort to make privacy obligations follow the data after ownership changes. For companies acquiring sensitive datasets, that turns privacy commitments into liabilities and operating requirements that can survive the original business.

Watch for:

  • Public details about the successor's advisory board and security reviews.
  • Evidence that deletion requests remain accessible and are completed after the transfer.
  • The progress of California's separate lawsuit and any additional bankruptcy disputes.

Networked License Plate Surveillance

ALPR disputes increasingly concern the network around the camera rather than the image alone: who can search plate histories, which agencies can obtain access, how long records remain available and whether audits can detect improper use.

Fresh developments

Fresno's audit provided the clearest stress test. Thousands of searches, millions of plate scans and hundreds of users were covered by a process that ultimately reviewed only three searches at random. Elsewhere, Chatham County launched a public portal with camera, scan and sharing information, while Bluffton pointed to documented searches and quarterly civilian audits. The comparison showed that local governance is becoming more visible but remains highly inconsistent.

Why we noticed

The practical question is shifting from whether an agency has an ALPR policy to whether its controls can withstand the scale and interoperability of the system. Sparse sampling can validate paperwork without detecting patterns of misuse, while public reporting is most useful when paired with access logs, meaningful review and consequences.

Watch for:

  • Whether Fresno expands its audit before deciding the future of its Flock contract.
  • Whether transparency portals disclose enough information to test sharing and retention claims.
  • Court developments concerning alleged federal access through National Lookup.

Facial Recognition and Indirect Regulation

Biometric surveillance is often challenged through laws governing public access, licensing, employment or consumer protection rather than through a single comprehensive rule. That can create pressure on operators, but it can also make enforcement vulnerable to narrow statutory disputes.

Fresh developments

New York's liquor regulator withdrew charges that connected MSG's facial-recognition-based exclusions to rules requiring licensed venues to admit the general public. The authority still assessed fines against Madison Square Garden, the Beacon Theater and Radio City Music Hall, but the biometric component of the case receded.

Why we noticed

The development clarifies the limits of using an adjacent regulatory power to govern a surveillance practice. A failed licensing theory can reduce immediate pressure without settling questions about biometric collection, exclusion, fairness or other potential legal claims.

Watch for:

  • Whether MSG changes its facial-recognition or exclusion practices despite the withdrawal.
  • Any further court or regulatory action based on a more direct biometric, privacy or civil-rights theory.

Final Thought

Data often lasts longer than companies, contracts and political assurances. Yesterday's reporting showed that privacy protection has to be designed for that longer life: obligations must follow transferred data, and oversight must continue after surveillance systems become routine.