Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Thursday, June 18, 2026 · 11:50 AM EDT

Key developments

IAPP

Vermont enacts 23rd state privacy law

IAPP's Alex LaCasse reported that Vermont Gov. Phil Scott signed Senate Bill 71, the Vermont Data Privacy and Online Surveillance Act, on 16 June, making Vermont the 23rd U.S. state with a comprehensive privacy law. The law takes effect 1 Jan. 2028, gives enforcement exclusively to the attorney general, excludes a private right of action, and includes a 60-day cure period expiring 30 June 2029. It applies at thresholds including processing data for more than 35,000 Vermont residents, requires honoring opt-out preference signals, and requires privacy notices to say whether personal data is used to train large language models.

Why it matters

Vermont adds another low-threshold state regime and introduces AI-training disclosure into mainstream U.S. state privacy compliance.

Sources & driving stories

IAPP · Alex LaCasse

IAPP coverage
PRIVACY MATTERS

EDPB proposes common EU breach notification template

DLA Piper's Privacy Matters reported that the European Data Protection Board published a proposed common template for GDPR personal data breach notifications, with consultation open until 5 Aug. 2026. The draft would standardize Article 33 reporting fields across EU data protection authorities, including incident classifications, affected data types, security measures, cross-border reporting, attachments, and phased reporting statuses. The template may go beyond Article 33 minimums and its interaction with the proposed Digital Omnibus single EU breach-reporting portal remains unresolved.

Why it matters

A common EU template could reduce fragmented breach reporting but may also increase the amount of information controllers must gather quickly after incidents.

Sources & driving stories

TECH JACKS SOLUTIONS SECURITY COMMAND CENTER

ShinyHunters claims widen across enterprise platforms

Tech Jacks Solutions reported that ShinyHunters, also tracked as UNC6395, claimed a Kodak breach involving 2.2 million records of customer PII and internal corporate data, with Kodak confirming a breach but not the access vector or data volume. PR Newswire reported that Edelson Lechtzin opened an investigation after ShinyHunters claimed theft from JCPenney and Catalyst Brands; the companies confirmed potentially impacted information may include Social Security numbers, dates of birth, W-2 forms, payroll records, driver's licenses, and government ID scans. Technadu's Lore Apostol also reported that One Medical disclosed unauthorized access to a third-party file storage system for legacy Iora Health/One Medical Seniors archived patient records, while ShinyHunters claimed 8.8 TB of data.

Why it matters

The reports point to a widening privacy-risk pattern around SaaS integrations, third-party storage, and legacy systems, with actor claims often broader than confirmed facts.

Sources & driving stories

TECH JACKS SOLUTIONS SECURITY COMMAND CENTER · Tech Jacks Solutions

Tech Jacks Solutions Security Command Center coverage

TECHNADU · Lore Apostol

Technadu coverage

Worth noting

WORTH NOTING

California breach pleading bar lowered

CooleyED reported that the California Supreme Court's J.M. v. Illuminate Education ruling allows claims based on significant risk of unauthorized access even without actual access or misuse, likely increasing breach litigation exposure.

WORTH NOTING

Novo confirms clinical-trial data copying

Penligent Security Blog reported Novo Nordisk confirmed unauthorized access and copying from limited internal systems, including some pseudonymized clinical-trial patient data, while Reuters reported unverified FulcrumSec claims of more than 1 TB stolen and a $25 million demand.

WORTH NOTING

Kansas City bus face-recognition pilot

TribLive reported Kansas City is pursuing a public-bus facial recognition pilot despite Missouri declining funding over facial-recognition concerns, with a larger pilot of up to 30 buses expected later this year.

Still unclear

OPEN QUESTION

How wide is the SaaS breach blast radius?

Multiple incidents involve Salesforce environments, third-party file storage, or enterprise integrations, but companies have confirmed narrower facts than threat actors are claiming.

OPEN QUESTION

Will EU breach reporting become simpler or heavier?

The EDPB template could harmonize reporting, but its extra fields and possible overlap with the proposed Digital Omnibus portal may add operational complexity during the first 72 hours.