Last Update: 09/29/2026 at 3:33 PM EST

Morning Briefing: Privacy

Sunday, September 20, 2026

September 20, 2026

Privacy Governance Is Finding Leverage in Courts and Procurement

Yesterday’s clearest privacy actions came not through a sweeping new rule, but through two points of practical control. A federal judge signaled resistance to ending TikTok’s 2019 FTC consent decree as part of a proposed Justice Department settlement, while five English police forces ended their participation in Palantir’s Project Nectar data-integration pilot.

Those interventions stand beside a less reassuring operational reality. Revolut confirmed that a fraudulent request made through a legitimate government domain led to disclosure of sensitive customer data. Taken together, the day showed that courts and procurement choices can constrain particular systems, even as trusted access channels and compliance-driven product designs keep creating new exposure.

CNBC reported that a judge may refuse to let TikTok’s proposed $400 million settlement end its 2019 FTC decree over children’s data. The signal is not a final order, but it would preserve a continuing compliance mechanism rather than treat a payment and revised controls as a full resolution.

Five East Midlands police forces are leaving Palantir’s Project Nectar pilot after the regional special-operations unit decided the two-year trial should not continue. Democracy for Sale reported that the system was meant to connect police-held information and support advanced analytics. This is a localized withdrawal, not a UK-wide reversal, but it stops one surveillance deployment from moving automatically from pilot to permanence.

Revolut confirmed that an impersonator using an address on a legitimate government domain obtained sensitive customer information, including identity and financial records. The company says its systems and customer funds were unaffected, but the incident demonstrates how a trusted-request workflow can expose highly consequential data without a core-system intrusion.

Two smaller developments sharpened the compliance picture. Talking Tilly required global users to undergo age estimation while recording, transcribing, and analyzing calls for emotional state; meanwhile, Suno faces a proposed class action over an alleged historical breach affecting roughly 55 million accounts. The first is a concrete product-design trade-off, while the second moves alleged data-security failures into litigation.

Key Points

  • Privacy constraints are proving most tangible where an institution can withhold approval: a court can preserve an existing decree, and a public customer can end a pilot. Recent briefings have also pointed to rising scrutiny of networked police surveillance; yesterday added an operational pullback rather than another call for oversight.
  • The Revolut disclosure reinforces a pattern visible in recent reporting: sensitive data often escapes through authorization and verification failures, not only through attacks on core databases. The relevant control is therefore not simply technical security, but rigorous authentication and escalation for supposedly official requests.
  • Age assurance is becoming a broader data-governance question. Talking Tilly illustrates how a requirement framed around age can combine biometric estimation, identity-document requests, behavioral inference, third-party processing, and retention choices for users well beyond the jurisdiction driving the requirement.

Implications

For platforms under existing privacy orders, negotiated settlements may not eliminate ongoing oversight. TikTok’s ultimate obligations will depend on the court’s formal decision and the final settlement terms, but the judge’s stance makes compliance architecture more consequential than the headline payment alone.

Public-sector surveillance vendors face a practical adoption risk when pilots fail to secure continued institutional backing. The Project Nectar outcome does not establish a wider market shift, yet it shows that integration ambitions can be interrupted before they become embedded operations.

Organizations holding identity, financial, or verification data should treat trusted-request handling, retention, vendor processing, and automated-inference disclosures as connected privacy controls. Revolut and Talking Tilly show different failure modes: one exposes data through requester authentication, the other through product design.

Watchpoints

Watch

Whether the TikTok court formally keeps the 2019 FTC decree in force, and which obligations remain alongside any settlement.

Watch

Whether the five-force withdrawal from Project Nectar prompts a wider reassessment of police data-integration deployments or remains confined to this pilot.

Watch

Revolut’s final affected-customer count, geographic scope, any regulator action, and whether alleged publication of customer data is confirmed.

Watch

Suno’s response to the proposed class action and how the court treats challenges to arbitration, class-waiver, and liability-limit provisions.

Watch

Whether other age-assurance services adopt similarly expansive combinations of biometric estimation, behavioral analysis, and call-data retention.

Fallout

Yesterday’s most consequential privacy developments centered on enforceable constraints and the operational weak points those constraints do not automatically solve.

Children’s Data Enforcement at TikTok

The proposed settlement may not end TikTok’s earlier FTC obligations, leaving continuing oversight as a live compliance question.

Fresh developments

A federal judge signaled that TikTok and ByteDance may need more justification to terminate the 2019 FTC consent decree within their proposed $400 million Justice Department settlement.

Why we noticed

A preserved decree would retain a standing compliance mechanism around children’s data rather than relying solely on a monetary resolution and proposed product changes.

Watch for:

  • A formal court order on the decree’s status.
  • The final settlement terms and any continuing compliance requirements.
  • How TikTok’s proposed age and moderation controls are reflected in the resolution.

Police Data-Integration Deployments

Five English police forces are ending a Palantir pilot intended to connect police-held data and support advanced analytics.

Fresh developments

The East Midlands special-operations unit concluded that Project Nectar’s two-year pilot should not continue, ending participation by five forces.

Why we noticed

The decision is a concrete interruption to a surveillance deployment’s path from trial to continued use, following recent scrutiny of networked law-enforcement systems.

Watch for:

  • Whether participating forces adopt substitute systems.
  • Whether other police deployments reassess integrated-data projects.
  • Any fuller public account of why the pilot was ended.

Trusted Requests and Sensitive Financial Data

Revolut’s confirmed disclosure shows how impersonation of an official requester can bypass ordinary assumptions about secure data custody.

Fresh developments

Revolut said a fraudulent request sent from an address on a legitimate government domain caused disclosure of identity documents, verification selfies, contact details, IBANs, statements, and transaction histories.

Why we noticed

The event did not compromise Revolut’s core systems or customer funds, but the exposed data could enable targeted phishing, impersonation, identity theft, and fraud.

Watch for:

  • Revolut’s confirmed customer count and geographic scope.
  • Any regulator response or additional verified disclosure details.
  • Changes to verification and escalation procedures for government-style requests.

Age Assurance and AI Interaction Data

Talking Tilly offers a narrow but vivid example of privacy exposure created by age-assurance product design.

Fresh developments

The service required automated age verification through a video selfie, could request identity documents, inferred emotional state from camera and voice inputs, and retained recordings and transcripts for defined periods.

Why we noticed

The service illustrates how age checks can expand into biometric processing, behavioral inference, third-party processing, and automated moderation. Xicoia says it does not retain verification images or create faceprints, but those safeguards were not independently verified in the available reporting.

Watch for:

  • Whether similar practices appear in other age-assurance implementations.
  • Whether users receive meaningful choices around emotion analysis and retention.
  • The service’s planned September 27 shutdown.

Breach Litigation at Suno

A proposed class action has added legal consequences to allegations of a large historical Suno breach.

Fresh developments

A plaintiff filed suit in Massachusetts federal court over an alleged November 2025 exposure involving approximately 55 million accounts and purported delayed acknowledgement.

Why we noticed

The complaint is unproven, but it puts arbitration, class-waiver, and liability-limit provisions at the center of customers’ ability to seek collective redress.

Watch for:

  • Suno’s response to the allegations.
  • Court treatment of the contractual provisions challenged in the complaint.
  • Any substantiated account of the breach’s scope and customer impact.

Final Thought

The day’s lesson is not that privacy governance has become coherent. It is that existing legal obligations and procurement decisions can still impose real limits—while the most sensitive data remains vulnerable wherever trust is granted too easily or compliance is built too broadly.