Key developments
ACLU sues Florida agencies over facial-recognition arrest
WebProNews' Victoria Mossi reported that the ACLU filed a June 10, 2026 lawsuit for Robert Dillon, a Fort Myers crabber arrested in August 2024 after Jacksonville Beach police used a 93% FACES/FACESNXT facial-recognition match from low-quality McDonald's security footage. The complaint alleges officers photographed a security screen with a cellphone, ignored Dillon's alibi and license-plate reader data, and treated the match as probable cause. Charges were later dropped; the suit seeks damages and reforms including image-quality standards and corroboration requirements.
Why it matters
The case directly challenges police use of facial-recognition leads as near-certain identification in criminal investigations.
Sources & driving stories
WEBPRONEWS · Victoria Mossi
WebProNews coverageWEBPRONEWS · Ava Callegari
Webpronews coverageRebound data-breach settlement receives final approval
The Columbian reported that Clark County Superior Court Judge Gregory Gonzales approved Rebound Orthopedics & Neurosurgery's $2.5 million class-action settlement over a February 2024 cyberattack. Court records said accessed files included names, dates of birth, Social Security numbers, driver's license numbers, medical information, health insurance data and financial account data. Plaintiffs may receive cash payments and two years of credit and medical data monitoring services.
Why it matters
The settlement is a concrete patient-data privacy outcome that also spotlights delayed breach notification and healthcare cybersecurity controls.
Sources & driving stories
COLUMBIAN
Columbian coverageEDPB adopts draft EU breach-notification template
Lexology reported that the European Data Protection Board adopted a draft common data breach notification template on June 10, 2026, with public consultation open until August 5. The template is designed to harmonize GDPR Article 33 reporting across EU data protection authorities, covering breach facts, affected people and data, likely consequences, mitigation and communications with affected individuals. A related Digital Omnibus proposal could let the European Commission adopt the template by implementing act, potentially making it mandatory EU-wide.
Why it matters
A common template could materially change how organizations prepare, standardize and submit breach notifications across EU jurisdictions.
Sources & driving stories
LEXOLOGY
Lexology coverageWorth noting
WORTH NOTING
Novo discloses clinical-trial data breach
SC World reported unauthorized access to Novo Nordisk internal IT systems exposed pseudonymized clinical-trial data and healthcare professional details including names, registration numbers, contact information, WhatsApp details and office locations.
WORTH NOTING
Section 702 deadline remains unresolved
The Killeen Daily Herald reported that Section 702 is set to expire after Congress failed to pass temporary extensions, though a March court order allows surveillance powers to continue for another year.
WORTH NOTING
Maui approves AI police surveillance
Hawaii News Now's Daryl Huff reported Maui council approval of $1.7 million for fixed cameras, drones and a real-time operations center using AI-assisted anomaly detection, drawing ACLU Hawaii privacy objections.
Still unclear
OPEN QUESTION
Will facial-recognition matches require independent corroboration?
The Dillon lawsuit squarely targets the evidentiary gap between an algorithmic lead and probable cause for arrest.
OPEN QUESTION
Will the EU breach template become mandatory?
The consultation is voluntary for now, but the Digital Omnibus route could turn a harmonized form into a binding reporting standard.
