UK Court Opens a Path for Spyware Accountability
Yesterday was a fragmented but legally consequential day. The clearest developments concerned the procedural gates that determine whether privacy objections can be heard at all: state immunity in a UK spyware case, standing in a California license-plate surveillance suit, and notice-and-comment requirements around a proposed federal collection of identifiable hospital records.
That distinction matters because concern about surveillance or sensitive-data use does not automatically produce a remedy. The UK Supreme Court allowed dissidents’ claims against Bahrain to proceed, while a California appeals court rejected an ALPR challenge for lack of demonstrated harm. Meanwhile, hospitals are questioning whether the CPSC followed the required process before seeking a much larger flow of identifiable ER data. Privacy governance is often decided at these thresholds before a court or regulator reaches the underlying practice.
The UK Supreme Court ruled 3–2 that Bahrain could not use state immunity to block a lawsuit alleging that dissidents were hacked with FinSpy in the UK. The Record reported that the location of the alleged hacking was central to the ruling. This does not establish that Bahrain conducted the surveillance, but it removes a major barrier to testing the allegations in court and creates a meaningful route for accountability when foreign-state hacking reaches people inside the UK.
KFF Health News documented a CPSC plan to obtain identifiable ER records from at least 100 hospitals by the end of 2026, with Konza Health collecting information that could include names, addresses and diagnoses. The proposed dataset covers more than 10,000 diagnostic conditions, including some not clearly related to consumer products. More significant, however, is the unresolved legal basis: hospital lawyers dispute whether the records can be required or disclosed, and the CPSC acknowledged that it had not completed the notice-and-comment process required for requests involving 10 or more entities.
Pressure on Flock Safety’s ALPR network widened without producing a coordinated rollback. A proposed federal funding bill would penalize local governments and police departments that use the cameras; several cities have paused or reconsidered contracts; and Costa Mesa retained 46 devices while planning to revisit data-sharing terms. Estimates of the network’s size vary, but the reporting consistently describes tens of thousands of cameras and thousands of agencies. The practical fight remains over who may search the records, how long they are retained and whether local data can be reached by federal authorities.
A California appeals court underscored the difficulty of challenging large surveillance databases without evidence of individual injury. FindLaw reported that the court rejected Guillermo Mata’s case against Digital Recognition Network because he had not shown actual harm from its ALPR collection. Coming shortly after stronger constitutional protection for granular Google location history, the decision is a reminder that location-privacy doctrine does not automatically give every person captured in a database standing to sue.
The EDPB published draft anonymisation guidance built around relative identifiability. As Sidley explained, the same dataset may be personal data for one recipient but anonymous for another, depending on the means available to identify people. Although the guidance remains a draft, it points toward a more contextual compliance test for data sharing, research and vendor relationships rather than a single permanent label attached to a dataset.
Key Points
- For opponents of persistent vehicle surveillance, procurement rules and legislation may prove more immediately consequential than broad privacy lawsuits. The California standing decision shows why: a system can generate widespread discomfort and political resistance while remaining difficult to challenge without proof that a particular person suffered legally recognizable harm.
- The CPSC proposal illustrates how technology modernization can increase privacy exposure rather than simply improve administration. The existing injury-surveillance system generally relied on non-identifying reports; the planned approach would route identifiable medical records through a private contractor before filtering. Konza says it will remove unnecessary details and will not market or sell the data, but the proposed collection still creates a new custody, retention and security boundary.
- Changes in corporate ownership are becoming operational privacy events. The 23andMe settlement preserves deletion and research-consent controls after its data assets moved to TTAM Research Institute, while The Guardian reported that the UK government approved TPG’s acquisition of Optum UK, whose EMIS software serves more than half of England’s GP practices. In both cases, the enduring question is not merely who owns the company, but whether access limits and consumer rights continue to function after the transaction.
- Bystander privacy is beginning to constrain where camera-equipped eyewear can be deployed. New York’s court system has banned camera- and microphone-equipped glasses from all 1,240 courthouses, concluding that indicator lights were insufficient protection. Separately, PCMag reported that Apple may have delayed its N50 smart-glasses reveal over privacy concerns, though Apple has not confirmed that account. Institutions are not waiting for a comprehensive wearable-privacy law before setting their own boundaries.
Implications
Hospitals approached by the CPSC will need to examine legal authority, HIPAA obligations, data minimization and contractor retention rather than treating the request as routine public-health reporting. The agency’s previous disclosure of health information involving roughly 30,000 people makes documented safeguards and clear accountability especially important.
Police departments and municipalities using ALPR systems should expect scrutiny of authorized users, search purposes, retention periods, audit logs and external sharing. The absence of successful litigation should not be mistaken for validation of a program’s governance; the California case turned on standing, not a definitive approval of mass vehicle-data collection.
Organizations acquiring data-rich businesses need to test whether deletion requests, consent withdrawals and purpose limitations remain technically operable after the sale. The 23andMe matter shows that privacy duties can survive financial distress even when bankruptcy sharply limits monetary recovery.
Companies relying on anonymised information in the EU should assess identifiability separately for each recipient and use case. If the EDPB’s approach is finalized, contractual restrictions, access to auxiliary datasets and a recipient’s technical capabilities may determine whether information remains subject to data-protection law.
The Bahrain ruling increases litigation exposure for foreign governments and spyware operators when alleged intrusion activity occurs in the UK. Its practical reach will depend on what the claimants can establish as the case proceeds; the court opened the door without deciding the merits.
Watchpoints
Watch
Whether the CPSC begins a formal notice-and-comment process, narrows the requested fields or diagnostic scope, and clarifies whether hospital participation is compulsory.
Watch
Whether hospitals decline participation or challenge the CPSC’s authority, and what security, deletion and audit terms apply to Konza Health’s handling of patient records.
Watch
The next stage of the Bahrain spyware case, including discovery and judicial findings about the alleged FinSpy deployment.
Watch
Whether the proposed federal restriction on Flock funding gains committee movement or bipartisan support, and whether Costa Mesa’s planned renegotiation produces enforceable limits on sharing and access.
Watch
How the EDPB revises its draft anonymisation guidance and whether the final version clarifies the role of contracts, recipient capabilities and access to supplementary information.
Watch
Implementation of 23andMe’s post-sale security commitments, deletion controls and research-use revocation rights under TTAM Research Institute.
Fallout
Three longer-running subjects moved meaningfully yesterday: courts clarified who can pursue surveillance claims, a federal agency’s proposed health-data expansion drew concrete legal objections, and regulators further complicated the assumption that data can be classified as anonymous without considering who receives it.
Surveillance, Standing and Accountability
Persistent surveillance systems can reconstruct movement, identify people and support searches across jurisdictions. The continuing legal question is not only whether those capabilities invade privacy, but who has standing to challenge them and which governments can claim immunity.
Fresh developments
The UK Supreme Court allowed dissidents’ spyware claims against Bahrain to proceed despite the state-immunity defense, while a California appeals court rejected an ALPR lawsuit because the plaintiff had not shown actual harm. At the same time, political resistance to Flock expanded through a proposed federal funding restriction and renewed local disputes over contracts, retention and federal access.
Why we noticed
The contrasting rulings explain why surveillance governance is likely to remain fragmented. A targeted hacking victim may be able to identify a concrete intrusion and pursue a foreign state, while a person included in a vast location database may struggle to prove individualized harm. That makes procurement conditions, retention rules, access controls and legislative limits especially important for systems whose effects are distributed across entire communities.
Watch for:
- Merits and discovery developments in the Bahrain spyware case.
- Whether courts apply recent location-privacy rulings to ALPR databases.
- Federal or local movement on Flock funding, retention and data-sharing restrictions.
Sensitive Health and Genetic Data
Health and genetic records combine enduring personal facts with information useful for identity fraud, discrimination and intimate inference. The central governance challenge is limiting collection and preserving individual control across agencies, contractors, breaches and ownership changes.
Fresh developments
KFF Health News reported that the CPSC wants at least 100 hospitals to send identifiable ER records through Konza Health, materially expanding a system that generally used non-identifying injury reports. Separately, the $18 million multistate 23andMe settlement continued moving through state implementation, with security, deletion and research-consent obligations following the company’s data into new ownership.
Why we noticed
The two developments show privacy governance at opposite ends of the data lifecycle. The CPSC plan would create a larger identifiable dataset before the legal authority and safeguards are settled; the 23andMe resolution imposes controls after millions of genetic records were already exposed. Preventive scrutiny is especially consequential because monetary remedies may become limited once a data-rich company enters bankruptcy.
Watch for:
- Hospital participation, legal challenges and any narrowing of the CPSC request.
- Konza Health’s retention, filtering, access and deletion practices.
- Whether TTAM keeps consumer deletion and research-revocation controls fully operational.
Anonymisation and Control of Data-Rich Assets
Privacy obligations increasingly depend on context: who holds a dataset, what other information that party can access and whether rights survive transfers to a new owner. This complicates both anonymisation claims and transactions involving sensitive infrastructure.
Fresh developments
The EDPB’s draft Guidelines 02/2026 set out a relative identifiability approach under which one party may hold anonymous information while another holds personal data. In the UK, the government approved TPG’s acquisition of Optum UK under the National Security and Investment Act 2021; the deal includes EMIS, whose software stores millions of NHS patient records and serves more than half of England’s GP practices.
Why we noticed
Taken together, the developments reinforce that privacy risk cannot be assessed from the dataset alone. A recipient’s capabilities, auxiliary information, contractual permissions and ownership structure all affect what can be learned and who can exercise control. For compliance teams, that means data classification and transaction review must examine real access and technical capability rather than relying solely on labels or assurances.
Watch for:
- The final EDPB standard and its treatment of contractual and technical barriers to identification.
- Post-acquisition governance, access and security arrangements for EMIS-held NHS records.
- Whether regulators impose more explicit privacy conditions on future acquisitions of sensitive-data infrastructure.
Final Thought
Yesterday’s developments suggest that data practices can expand faster than substantive privacy law, leaving procedure—who may sue, what process an agency followed and what a contract permits—as the first line of governance.
