Key developments
Vermont enacts 23rd state privacy law
IAPP's Alex LaCasse reported that Vermont Gov. Phil Scott signed Senate Bill 71, the Vermont Data Privacy and Online Surveillance Act, on 16 June, making Vermont the 23rd U.S. state with a comprehensive privacy law. The law takes effect 1 Jan. 2028, gives enforcement exclusively to the attorney general, excludes a private right of action, and includes a 60-day cure period expiring 30 June 2029. It applies at thresholds including processing data for more than 35,000 Vermont residents, requires honoring opt-out preference signals, and requires privacy notices to say whether personal data is used to train large language models.
Why it matters
Vermont adds another low-threshold state regime and introduces AI-training disclosure into mainstream U.S. state privacy compliance.
Sources & driving stories
IAPP · Alex LaCasse
IAPP coverageEDPB proposes common EU breach notification template
DLA Piper's Privacy Matters reported that the European Data Protection Board published a proposed common template for GDPR personal data breach notifications, with consultation open until 5 Aug. 2026. The draft would standardize Article 33 reporting fields across EU data protection authorities, including incident classifications, affected data types, security measures, cross-border reporting, attachments, and phased reporting statuses. The template may go beyond Article 33 minimums and its interaction with the proposed Digital Omnibus single EU breach-reporting portal remains unresolved.
Why it matters
A common EU template could reduce fragmented breach reporting but may also increase the amount of information controllers must gather quickly after incidents.
Sources & driving stories
PRIVACY MATTERS
Privacy Matters coverageShinyHunters claims widen across enterprise platforms
Tech Jacks Solutions reported that ShinyHunters, also tracked as UNC6395, claimed a Kodak breach involving 2.2 million records of customer PII and internal corporate data, with Kodak confirming a breach but not the access vector or data volume. PR Newswire reported that Edelson Lechtzin opened an investigation after ShinyHunters claimed theft from JCPenney and Catalyst Brands; the companies confirmed potentially impacted information may include Social Security numbers, dates of birth, W-2 forms, payroll records, driver's licenses, and government ID scans. Technadu's Lore Apostol also reported that One Medical disclosed unauthorized access to a third-party file storage system for legacy Iora Health/One Medical Seniors archived patient records, while ShinyHunters claimed 8.8 TB of data.
Why it matters
The reports point to a widening privacy-risk pattern around SaaS integrations, third-party storage, and legacy systems, with actor claims often broader than confirmed facts.
Sources & driving stories
TECH JACKS SOLUTIONS SECURITY COMMAND CENTER · Tech Jacks Solutions
Tech Jacks Solutions Security Command Center coveragePR NEWSWIRE
PR Newswire coverageTECHNADU · Lore Apostol
Technadu coverageWorth noting
WORTH NOTING
California breach pleading bar lowered
CooleyED reported that the California Supreme Court's J.M. v. Illuminate Education ruling allows claims based on significant risk of unauthorized access even without actual access or misuse, likely increasing breach litigation exposure.
WORTH NOTING
Novo confirms clinical-trial data copying
Penligent Security Blog reported Novo Nordisk confirmed unauthorized access and copying from limited internal systems, including some pseudonymized clinical-trial patient data, while Reuters reported unverified FulcrumSec claims of more than 1 TB stolen and a $25 million demand.
WORTH NOTING
Kansas City bus face-recognition pilot
TribLive reported Kansas City is pursuing a public-bus facial recognition pilot despite Missouri declining funding over facial-recognition concerns, with a larger pilot of up to 30 buses expected later this year.
Still unclear
OPEN QUESTION
How wide is the SaaS breach blast radius?
Multiple incidents involve Salesforce environments, third-party file storage, or enterprise integrations, but companies have confirmed narrower facts than threat actors are claiming.
OPEN QUESTION
Will EU breach reporting become simpler or heavier?
The EDPB template could harmonize reporting, but its extra fields and possible overlap with the proposed Digital Omnibus portal may add operational complexity during the first 72 hours.
