Key developments
Supreme Court recognizes Location History privacy search
Yuanchung Lee of the Federal Defenders of New York Second Circuit Blog reported that the Supreme Court’s Chatrie decision held, 6-3 with Justice Gorsuch concurring in the judgment, that individuals have a reasonable expectation of privacy in cell phone Location History records held by Google. The Court said police conduct a Fourth Amendment search when they gain access to Location History, even for a limited time and from a third-party technology company. The ruling leaves reasonableness, warrant compliance, probable cause, particularity, and the Leon good-faith exception for remand to the Fourth Circuit.
Why it matters
The decision strengthens constitutional privacy protection for digital location records and could reshape geofence warrant practices.
Sources & driving stories
FEDERAL DEFENDERS OF NEW YORK SECOND CIRCUIT BLOG · Yuanchung Lee
Federal Defenders of New York Second Circuit Blog coverageSouth Korea rejects U.S. Coupang discrimination report
AP reporting published by The Gazette said South Korea’s Foreign Ministry disputed a U.S. House Judiciary Committee report accusing Seoul of discriminating against U.S.-listed Coupang. South Korea’s Personal Information Protection Commission fined Coupang 625 billion won, about $403 million, in June after a breach exposed personal information of more than 37 million people, including 33 million Coupang customers, and after Coupang missed the 72-hour breach reporting deadline. Yahoo’s summary of the House report said the committee framed South Korea’s raids, audits, and inquiries as discriminatory treatment of American-owned firms, while Seoul said the enforcement was lawful and consumer-protection focused.
Why it matters
A major privacy enforcement action is now entangled with U.S.-South Korea trade and discrimination claims.
Sources & driving stories
THE GAZETTE
The Gazette coverageYAHOO
Yahoo coverageMedtronic notifies customers after ShinyHunters breach
Bill Toulas of BleepingComputer reported that Medtronic is notifying affected customers after unusual activity detected April 15 led investigators to find unauthorized access to certain corporate IT systems from April 13 to April 19, 2026. ShinyHunters claimed responsibility and alleged possession of about nine million Medtronic records containing personally identifiable information and internal corporate data. Medtronic said stolen data was not exposed online, medical devices remain safe to use, and affected people should use 24 months of credit monitoring and identity theft protection while watching for phishing and social engineering.
Why it matters
Healthcare-sector breaches combine identity-risk exposure with high-value patient and corporate data targeted by extortion groups.
Sources & driving stories
BLEEPINGCOMPUTER · Bill Toulas
BleepingComputer coverageWorth noting
WORTH NOTING
Apple Hide My Email bug reported
Tyler Lacoma of CNET reported that Easy Opt Out co-founder Tyler Murphy found Apple’s Hide My Email aliases could be used to uncover real email addresses through identity search sites, even after Apple said in March 2026 that it had fixed the issue.
WORTH NOTING
DPF faces FTC-independence challenge
Shumaker noted that noyb and Max Schrems argue the Supreme Court’s Trump v. Slaughter decision may undermine FTC independence assumptions in the EU-U.S. Data Privacy Framework, though the DPF remains legally valid for now.
WORTH NOTING
Flock cameras draw county scrutiny
Mike Nolting of WV MetroNews reported that Monongalia County residents questioned data storage, security, and sharing for Flock Safety license plate reader cameras, while officials said local use excludes facial recognition and is limited to alerts, warrants, and criminal complaints.
Still unclear
OPEN QUESTION
How far will Chatrie constrain geofence warrants?
The Supreme Court found a search occurred, but the remand will determine how reasonableness, particularity, probable cause, and good faith apply to this investigative technique.
OPEN QUESTION
Can the DPF absorb FTC-independence challenges?
Companies can still rely on the EU-U.S. Data Privacy Framework today, but noyb’s withdrawal request and threatened litigation create a concrete path toward renewed transfer uncertainty.
