Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Saturday, June 13, 2026 · 11:50 AM EDT

Key developments

WEBPRONEWS

ACLU sues Florida agencies over facial-recognition arrest

WebProNews' Victoria Mossi reported that the ACLU filed a June 10, 2026 lawsuit for Robert Dillon, a Fort Myers crabber arrested in August 2024 after Jacksonville Beach police used a 93% FACES/FACESNXT facial-recognition match from low-quality McDonald's security footage. The complaint alleges officers photographed a security screen with a cellphone, ignored Dillon's alibi and license-plate reader data, and treated the match as probable cause. Charges were later dropped; the suit seeks damages and reforms including image-quality standards and corroboration requirements.

Why it matters

The case directly challenges police use of facial-recognition leads as near-certain identification in criminal investigations.

Sources & driving stories

WEBPRONEWS · Victoria Mossi

WebProNews coverage

WEBPRONEWS · Ava Callegari

Webpronews coverage
COLUMBIAN

Rebound data-breach settlement receives final approval

The Columbian reported that Clark County Superior Court Judge Gregory Gonzales approved Rebound Orthopedics & Neurosurgery's $2.5 million class-action settlement over a February 2024 cyberattack. Court records said accessed files included names, dates of birth, Social Security numbers, driver's license numbers, medical information, health insurance data and financial account data. Plaintiffs may receive cash payments and two years of credit and medical data monitoring services.

Why it matters

The settlement is a concrete patient-data privacy outcome that also spotlights delayed breach notification and healthcare cybersecurity controls.

Sources & driving stories

LEXOLOGY

EDPB adopts draft EU breach-notification template

Lexology reported that the European Data Protection Board adopted a draft common data breach notification template on June 10, 2026, with public consultation open until August 5. The template is designed to harmonize GDPR Article 33 reporting across EU data protection authorities, covering breach facts, affected people and data, likely consequences, mitigation and communications with affected individuals. A related Digital Omnibus proposal could let the European Commission adopt the template by implementing act, potentially making it mandatory EU-wide.

Why it matters

A common template could materially change how organizations prepare, standardize and submit breach notifications across EU jurisdictions.

Sources & driving stories

Worth noting

WORTH NOTING

Novo discloses clinical-trial data breach

SC World reported unauthorized access to Novo Nordisk internal IT systems exposed pseudonymized clinical-trial data and healthcare professional details including names, registration numbers, contact information, WhatsApp details and office locations.

WORTH NOTING

Section 702 deadline remains unresolved

The Killeen Daily Herald reported that Section 702 is set to expire after Congress failed to pass temporary extensions, though a March court order allows surveillance powers to continue for another year.

WORTH NOTING

Maui approves AI police surveillance

Hawaii News Now's Daryl Huff reported Maui council approval of $1.7 million for fixed cameras, drones and a real-time operations center using AI-assisted anomaly detection, drawing ACLU Hawaii privacy objections.

Still unclear

OPEN QUESTION

Will facial-recognition matches require independent corroboration?

The Dillon lawsuit squarely targets the evidentiary gap between an algorithmic lead and probable cause for arrest.

OPEN QUESTION

Will the EU breach template become mandatory?

The consultation is voluntary for now, but the Digital Omnibus route could turn a harmonized form into a binding reporting standard.