Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Friday, June 26, 2026 · 6:49 PM EDT

Key developments

BIOMETRIC UPDATE

House compromise revives federal children’s privacy push

Biometric Update’s Anthony Kimery reported that House Energy and Commerce Chair Brett Guthrie and Ranking Member Frank Pallone announced a bipartisan agreement on the Kids Internet and Digital Safety Act, potentially moving in the House next week. The package combines KOSA-style provisions with child privacy rules: default protective settings for users known to be under 17, limits on messaging, location sharing and personalized recommendations, annual audits, 10-day responses to harm reports, age verification for commercial pornography sites, COPPA advertising restrictions, and an FTC registry for data brokers selling minors’ data. Senate backers Richard Blumenthal and Marsha Blackburn criticized the House version for lacking a duty of care, while CDT warned age verification could put all users’ privacy at risk.

Why it matters

The bill would reshape platform obligations for minors while reopening the unresolved tradeoff between child safety mandates and broader identity or age-verification data collection.

Sources & driving stories

BIOMETRIC UPDATE · Anthony Kimery

Biometric Update coverage
MONDAQ

Vermont and Louisiana add privacy statutes

Mondaq’s Josh Hansen reported that Vermont’s new Data Privacy and Online Surveillance Act takes effect January 1, 2028, with low applicability thresholds: 35,000 residents’ personal data, 3,000 residents’ sensitive data, or sale of data for 3,000 residents. Vermont adds notable obligations covering teen targeted advertising and data sales, consumer health data, geofencing near healthcare facilities, profiling rights, and disclosure of whether personal data is used or sold for training large language models. DWT reported that Louisiana enacted SB 386, the Louisiana Data Privacy Act, effective January 1, 2027, with access, correction, deletion, portability, opt-outs for targeted advertising and sale, sensitive-data opt-in consent, processor contract duties, and a temporary cure process.

Why it matters

The state privacy patchwork is expanding beyond baseline consumer rights into AI-training transparency, health-data limits, biometric-data notices, and more granular compliance triggers.

Sources & driving stories

MONDAQ · Josh Hansen

Mondaq coverage
ACLU

Judge blocks DOJ access to trans-youth records

The ACLU reported that a Southern District of New York judge granted a temporary restraining order blocking disclosure of medical information sought through Trump administration subpoenas to New York City hospitals. The ACLU, NYCLU and Lambda Legal filed the case for three families with transgender youth and two transgender young adults, challenging DOJ efforts to obtain identifying and sensitive health information about gender-dysphoria treatment begun while patients were minors. The subpoena to NYU Langone was issued in May 2026 under a federal grand jury in Fort Worth, Texas; the plaintiffs argue the demands violate Fourth and Fifth Amendment privacy rights and New York doctor-patient privilege.

Why it matters

The order reinforces judicial limits on government access to highly sensitive medical records amid a broader national fight over transgender healthcare privacy.

Sources & driving stories

Worth noting

WORTH NOTING

Illinois shields reproductive health records

Wifr reported that Gov. JB Pritzker signed the Reproductive Health Records Privacy Act, effective July 1, 2027, requiring abortion-related information and gender-dysphoria diagnoses to be separated from digital medical records and restricting out-of-state access.

WORTH NOTING

Russia-linked messaging phishing targets officials

The Record’s Daryna Antoniuk reported that Ukraine’s SBU, with FBI involvement, uncovered a long-running Russian campaign using support impersonation and one-time-code theft to compromise messaging accounts of officials, military personnel, politicians and activists in Ukraine, Europe and the United States.

WORTH NOTING

23andMe lawsuit alleges earlier breach timeline

Bizjournals reported that a California attorney general lawsuit alleges unauthorized access to 23andMe systems began as early as April 2023, that the company mishandled the investigation by August, and that disclosure did not occur until October 2023.

Still unclear

OPEN QUESTION

Can child-safety law avoid privacy-invasive age checks?

The House KIDS Act depends on platforms knowing when users are under 17 and separately mandates pornography-site age verification, raising the risk of broader identity collection for both minors and adults.

OPEN QUESTION

Will AI-training disclosure become a state-law baseline?

Vermont’s requirement to say whether personal data is used or sold to train large language models could become a model for other states before a federal privacy law emerges.