Key developments
Supreme Court brings geofence warrants under Fourth Amendment
The U.S. Supreme Court held that law enforcement geofence warrants seeking Google Location History data constitute a Fourth Amendment search. In the Chatrie case, police used a warrant tied to a 2019 Virginia credit union robbery to identify devices within roughly 150 meters during a one-hour window; the Court vacated the lower-court ruling and remanded for a reasonableness analysis. Justice Neil Gorsuch separately argued that Location History can function as a user’s personal “effects,” even when stored on Google servers.
Why it matters
The ruling imposes constitutional scrutiny on a major digital-location investigative tool while leaving unresolved how narrow or justified geofence warrants must be.
Sources & driving stories
WASHINGTON EXAMINER · Kaelan Deese
Washington Examiner coverageREASON · Jacob Sullum
Reason coverageSECURITYWEEK
SecurityWeek coverageHouse passes KIDS Act despite Senate resistance
The U.S. House passed the Kids Internet and Digital Safety Act on a Monday night 267-117 vote using a fast-track process. The bill includes age-verification requirements, AI chatbot disclosure rules, data broker obligations for children’s information, and restrictions involving targeted ads, geolocation sharing, and contact from unknown adults. The Record reported that Senate approval is unlikely, with senators including Richard Blumenthal and Marsha Blackburn backing a competing duty-of-care model.
Why it matters
The bill advances federal youth-safety regulation but raises privacy concerns that age checks could normalize collection of IDs, biometrics, or other sensitive data from all users.
Sources & driving stories
THE RECORD · Suzanne Smalley
The Record coverageWEBPRONEWS · Ava Callegari
WebProNews coveragePeopleSoft zero-day exposes Nissan and NAIC data
Nissan and the National Association of Insurance Commissioners confirmed unauthorized access linked to exploitation of Oracle PeopleSoft, with ShinyHunters tied to the campaign. Nissan warned current and former employees in the U.S., Canada, Mexico, and Brazil that contact details, bank account information, Social Security or government identifiers, and financial or tax data may have been stolen. NAIC disclosed PeopleSoft access on June 17 and confirmed by June 25 that stolen data had been published online, while stating PII, payment, credit card, and banking data were not accessed.
Why it matters
The campaign shows how a single enterprise software flaw can cascade into sensitive employee, payroll, regulatory, and financial-data exposure across multiple organizations.
Sources & driving stories
DATABREACHTODAY
Databreachtoday coverageTHE NATIONAL CIO REVIEW · Elizabeth Rigsby
The National CIO Review coverageMITCHELL WILLIAMS
Mitchell Williams coverageWorth noting
WORTH NOTING
Vermont privacy law takes effect 2028
Senate Bill 71 adds a comprehensive state privacy regime covering personal data, sensitive data, consumer health data, children’s protections, opt-out signals, and attorney-general enforcement without a private right of action.
WORTH NOTING
EDPB breach template enters consultation
The European Data Protection Board adopted a common GDPR Article 33 breach-notification template, now open for public consultation until August 5, to harmonize reporting across EU data protection authorities.
WORTH NOTING
Camera surveillance programs draw local resistance
KCATA’s AI facial-recognition bus pilot is delayed amid privacy objections, while Flock license-plate-reader deployments face pauses, lawsuits, immigration-use concerns, and roughly 50 local cancellations or deactivations nationally.
Still unclear
OPEN QUESTION
How narrow must geofence warrants become?
The Supreme Court classified geofence access as a search but remanded the reasonableness question, leaving police, courts, and platforms to determine acceptable scope, duration, and particularity.
OPEN QUESTION
Can age assurance avoid identity infrastructure?
The House bill and UK age-verification debates both point toward ID, facial, banking, or phone-based checks that could create durable privacy risks beyond child-safety use cases.
