Key developments
House compromise revives federal children’s privacy push
Biometric Update’s Anthony Kimery reported that House Energy and Commerce Chair Brett Guthrie and Ranking Member Frank Pallone announced a bipartisan agreement on the Kids Internet and Digital Safety Act, potentially moving in the House next week. The package combines KOSA-style provisions with child privacy rules: default protective settings for users known to be under 17, limits on messaging, location sharing and personalized recommendations, annual audits, 10-day responses to harm reports, age verification for commercial pornography sites, COPPA advertising restrictions, and an FTC registry for data brokers selling minors’ data. Senate backers Richard Blumenthal and Marsha Blackburn criticized the House version for lacking a duty of care, while CDT warned age verification could put all users’ privacy at risk.
Why it matters
The bill would reshape platform obligations for minors while reopening the unresolved tradeoff between child safety mandates and broader identity or age-verification data collection.
Sources & driving stories
BIOMETRIC UPDATE · Anthony Kimery
Biometric Update coverageVermont and Louisiana add privacy statutes
Mondaq’s Josh Hansen reported that Vermont’s new Data Privacy and Online Surveillance Act takes effect January 1, 2028, with low applicability thresholds: 35,000 residents’ personal data, 3,000 residents’ sensitive data, or sale of data for 3,000 residents. Vermont adds notable obligations covering teen targeted advertising and data sales, consumer health data, geofencing near healthcare facilities, profiling rights, and disclosure of whether personal data is used or sold for training large language models. DWT reported that Louisiana enacted SB 386, the Louisiana Data Privacy Act, effective January 1, 2027, with access, correction, deletion, portability, opt-outs for targeted advertising and sale, sensitive-data opt-in consent, processor contract duties, and a temporary cure process.
Why it matters
The state privacy patchwork is expanding beyond baseline consumer rights into AI-training transparency, health-data limits, biometric-data notices, and more granular compliance triggers.
Sources & driving stories
MONDAQ · Josh Hansen
Mondaq coverageDWT
DWT coverageJudge blocks DOJ access to trans-youth records
The ACLU reported that a Southern District of New York judge granted a temporary restraining order blocking disclosure of medical information sought through Trump administration subpoenas to New York City hospitals. The ACLU, NYCLU and Lambda Legal filed the case for three families with transgender youth and two transgender young adults, challenging DOJ efforts to obtain identifying and sensitive health information about gender-dysphoria treatment begun while patients were minors. The subpoena to NYU Langone was issued in May 2026 under a federal grand jury in Fort Worth, Texas; the plaintiffs argue the demands violate Fourth and Fifth Amendment privacy rights and New York doctor-patient privilege.
Why it matters
The order reinforces judicial limits on government access to highly sensitive medical records amid a broader national fight over transgender healthcare privacy.
Sources & driving stories
ACLU
ACLU coverageWorth noting
WORTH NOTING
Illinois shields reproductive health records
Wifr reported that Gov. JB Pritzker signed the Reproductive Health Records Privacy Act, effective July 1, 2027, requiring abortion-related information and gender-dysphoria diagnoses to be separated from digital medical records and restricting out-of-state access.
WORTH NOTING
Russia-linked messaging phishing targets officials
The Record’s Daryna Antoniuk reported that Ukraine’s SBU, with FBI involvement, uncovered a long-running Russian campaign using support impersonation and one-time-code theft to compromise messaging accounts of officials, military personnel, politicians and activists in Ukraine, Europe and the United States.
WORTH NOTING
23andMe lawsuit alleges earlier breach timeline
Bizjournals reported that a California attorney general lawsuit alleges unauthorized access to 23andMe systems began as early as April 2023, that the company mishandled the investigation by August, and that disclosure did not occur until October 2023.
Still unclear
OPEN QUESTION
Can child-safety law avoid privacy-invasive age checks?
The House KIDS Act depends on platforms knowing when users are under 17 and separately mandates pornography-site age verification, raising the risk of broader identity collection for both minors and adults.
OPEN QUESTION
Will AI-training disclosure become a state-law baseline?
Vermont’s requirement to say whether personal data is used or sold to train large language models could become a model for other states before a federal privacy law emerges.
