Key developments
Supreme Court limits geofence location searches
The U.S. Supreme Court ruled 6-3 in Chatrie v. United States that police conducted a Fourth Amendment search when they obtained Google Location History through a geofence warrant. The case involved a 150-meter-radius request around a credit union during the hour around a robbery, and the Court remanded the case for lower-court review of the warrant’s validity. The majority rejected the government’s argument that opting into Google Location History eliminated privacy protections.
Why it matters
The ruling raises constitutional barriers for law enforcement use of geofence warrants and short-term phone-location surveillance.
Sources & driving stories
THE REGISTER · Thomas Claburn
The Register coverageARS TECHNICA
Ars Technica coverageNissan discloses PeopleSoft zero-day employee breach
Nissan disclosed in California Attorney General breach notifications that current and former employee data was accessed after attackers exploited Oracle PeopleSoft PeopleTools CVE-2026-35273. The company said affected data may include contact details, banking information, Social Security or national ID numbers, financial and tax data, and dependent or beneficiary information for employees in the U.S., Canada, Mexico, and Brazil. TechNadu’s Lore Apostol reported that Mandiant confirmed zero-day exploitation between May 27 and June 9, and that ShinyHunters claimed more than 300 PeopleSoft instances across 100 organizations were breached.
Why it matters
A payroll and personnel-system zero-day creates high-risk identity, financial, and employee privacy exposure across potentially many organizations.
Sources & driving stories
TECHNADU · Lore Apostol
TechNadu coverageVermont passes privacy law effective 2028
Vermont passed Senate Bill 71, a comprehensive privacy law scheduled to take effect January 1, 2028. Mondaq’s Joseph Lazzarotti reported that the law applies to covered businesses meeting thresholds tied to processing 35,000 consumers’ data, 3,000 consumers’ sensitive data, or selling data of at least 3,000 consumers. The law adds consumer health data provisions, heightened protections for children, opt-out preference signal requirements, data minimization duties, data protection assessments, and Vermont Attorney General enforcement without a private right of action.
Why it matters
The law adds another state privacy regime with specific health, child-data, and opt-out-signal obligations for compliance teams to track.
Sources & driving stories
MONDAQ · Joseph Lazzarotti
Mondaq coverageWorth noting
WORTH NOTING
EY trainees charged over Albanese bank data
Yahoo News’ Shweta Sharma reported that Australian Federal Police charged two EY graduate trainees assigned to Commonwealth Bank with allegedly accessing restricted banking data tied by local reports to Prime Minister Anthony Albanese.
WORTH NOTING
KCATA weighs bus facial recognition pilot
The Kansas City Star reported that KCATA is considering SafeSpace Global facial-recognition cameras on about nine buses, with possible expansion to 30, despite concerns about rider privacy, false matches, and public trust.
WORTH NOTING
Breach notices span insurers, utilities, clinics
New reports described AssuranceAmerica customer data exposure, a London Hydro breach affecting about 170,000 customers, and Texas Hearing Institute exposure involving Social Security numbers and medical records.
Still unclear
OPEN QUESTION
How far will Chatrie constrain geofence warrants?
The Court held that accessing Google Location History is a search but did not ban geofence warrants, leaving particularity and probable-cause limits for lower courts.
OPEN QUESTION
How many PeopleSoft victims will surface?
Oracle told Nissan that personnel records of hundreds of companies may have been obtained, while ShinyHunters claims more than 300 PeopleSoft instances across 100 organizations were breached.
