Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Thursday, June 18, 2026 · 6:49 PM EDT

Key developments

IAPP

Vermont enacts comprehensive privacy law

IAPP's Alex LaCasse reported that Vermont Gov. Phil Scott signed Senate Bill 71, the Vermont Data Privacy and Online Surveillance Act, on 16 June, making Vermont the 23rd U.S. state with a comprehensive consumer privacy law. The law takes effect 1 Jan. 2028, gives exclusive enforcement authority to the attorney general, includes no private right of action, and requires opt-out preference signals plus notice disclosures on whether personal data is used to train large language models. Scott also signed data broker and edtech registration legislation and a Genetic Information Privacy Act restricting genetic-data sharing without explicit consent.

Why it matters

Vermont adds another state regime with low applicability thresholds and AI-training notice obligations, increasing compliance fragmentation for privacy programs.

Sources & driving stories

IAPP · Alex LaCasse

IAPP coverage

HUNTON PRIVACY AND CYBERSECURITY LAW BLOG

Hunton Privacy and Cybersecurity Law Blog coverage
TECHCRUNCH

Texas agency breach exposes license data

TechCrunch reported that a Texas Parks and Wildlife Department breach allowed hackers to steal driver license information and passport numbers for more than 3 million people. The department said Texas' cybersecurity unit recently detected an incident involving access to a license system vendor used for hunting and fishing license sales, but did not identify the vendor, incident timing, or attack method. Claim Depot reported state breach data listing 3,087,721 affected Texas residents and additional exposed identifiers including Social Security numbers, government ID numbers, names, addresses and dates of birth.

Why it matters

The breach combines government identity documents, contact data and an unnamed third-party licensing vendor, creating high identity-theft and public-sector vendor-risk implications.

Sources & driving stories

PRIVACY MATTERS

EDPB proposes EU breach notification template

Privacy Matters reported that the European Data Protection Board published a proposed common template for GDPR personal data breach notifications, with consultation open until 5 Aug. 2026. The draft is intended for DPA implementation through an IT tool and would standardize incident categories, breached data types, security measures, cross-border authority fields, attachments and phased Article 33(4) reporting. The proposal may overlap with the EU Digital Omnibus concept for a single breach reporting portal covering GDPR, NIS2, DORA and related frameworks.

Why it matters

A common template could reduce national reporting divergence, but may also expand the practical detail organizations must produce within GDPR's 72-hour breach-notification window.

Sources & driving stories

Worth noting

WORTH NOTING

Popa linked to NetNut

Brian Krebs reported that multiple researchers link the Android TV-box Popa botnet to NetNut/Alarum infrastructure, raising privacy issues around residential proxy networks, AI scraping, account takeovers and weak user consent disclosures.

WORTH NOTING

California breach claims broaden

CooleyED reported that the California Supreme Court's J.M. v. Illuminate Education decision permits data breach claims based on significant risk of unauthorized access even without actual access or misuse.

WORTH NOTING

Bulgaria surveillance exports alleged

The Record's Suzanne Smalley reported Human Rights Watch findings that Bulgarian licensing records from 2018-2023 show Circles surveillance products supplied to law enforcement and intelligence agencies in countries with repression or spyware-abuse concerns.

Still unclear

OPEN QUESTION

Will EU breach reporting actually converge?

The EDPB template is optional for national DPAs and may need to coexist with a future Digital Omnibus single-portal model.

OPEN QUESTION

Who was the Texas vendor?

Texas Parks and Wildlife has not named the license-system vendor or disclosed the incident timeline, limiting assessment of downstream risk and accountability.