Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Monday, June 22, 2026 · 6:50 PM EDT

Key developments

TEXAS ATTORNEY GENERAL

Texas investigates Carnival over massive breach

Texas Attorney General Ken Paxton announced an ongoing investigation into Carnival Corporation after an April 14, 2026 breach compromised personal information for an estimated 6 million people, including 800,060 Texans. Carnival told the Texas OAG that unauthorized activity involved an employee account accessed through social-engineering techniques. Exposed categories included names, contact details, dates of birth, payment information, passport information, driver's license information and health information; Carnival submitted its breach notification 44 days after the breach.

Why it matters

The investigation tests Texas enforcement expectations for breach response, notification timing and reasonable safeguards at a major travel company holding highly sensitive identity and health data.

Sources & driving stories

TEXAS ATTORNEY GENERAL

Texas Attorney General coverage
ABC NEWS

Judge blocks federal voter-screening database

ABC News reported that U.S. District Judge Sparkle Sooknanan blocked the Trump administration's use of the Systematic Alien Verification for Entitlement database for purging non-citizens from voter rolls. The court found that the government unlawfully consolidated personal information of millions of Americans and violated the Social Security Act, the Privacy Act and the Administrative Procedure Act. Plaintiffs including the League of Women Voters had sued DHS in March, alleging illegal voter surveillance and comprehensive citizen data collection.

Why it matters

The ruling curbs a government identity-screening system that plaintiffs said created large-scale voter surveillance and led states to remove U.S. citizens based on inaccurate information.

Sources & driving stories

BIOMETRICUPDATE.COM

MSG sued after biometric surveillance breach

BiometricUpdate.com reported that Madison Square Garden Entertainment faces a federal class action, Avalo v. MSG Entertainment, after hacker group ShinyHunters claimed it stole 45GB of data spanning 26 million visits to MSG venues. The data allegedly came from facial-recognition-powered surveillance systems and included biometric tracking logs, background check information, internet threat assessment data and customer emails from people who had criticized MSG's facial-recognition practices. Plaintiffs filed after an alleged June 15 ransom deadline passed and seek at least $5 million in initial damages.

Why it matters

The case ties biometric surveillance, ransomware extortion and venue security practices into a concrete privacy liability dispute.

Sources & driving stories

BIOMETRICUPDATE.COM

BiometricUpdate.com coverage

Worth noting

WORTH NOTING

Meta glasses face-recognition code surfaced

Northeastern Global News' Hannah Morse reported on WIRED's finding that Meta had quietly added, then removed after reporting, dormant smart-glasses face-recognition code in the Meta AI app that could create phone-stored biometric faceprints and alert wearers when recognized people appeared.

WORTH NOTING

Peregrine funds public-safety AI expansion

Fortune's Lily Mae Lazarus reported that Peregrine raised $250 million at a $6.8 billion valuation while serving up to 400 agencies and running security fusion centers for eight of 11 2026 World Cup host cities, amid civil-liberties concerns over AI-powered public-safety data integration.

WORTH NOTING

Texas license breach exceeds three million

Spectrum News 1 South Texas and FRPA reported that a Texas Parks and Wildlife Department vendor breach may have exposed driver license information, passport numbers and contact details for more than 3 million hunting and fishing license holders, while Social Security numbers, birth dates and financial data were not affected.

Still unclear

OPEN QUESTION

Will regulators punish slow or partial breach notices?

Carnival's 44-day Texas notification, Cherry Health's preliminary notice without affected-person counts and London Hydro's limited disclosure all leave open questions about timeliness, scope and transparency.

OPEN QUESTION

What consent standard fits wearable recognition?

The Meta smart-glasses reporting and MSG biometric lawsuit both show that indicator lights, audit trails or post-hoc policies may not address bystanders whose biometric data is captured without opt-in consent.