Key developments
EU revives ePrivacy derogation for CSA scanning
The European Parliament said it will vote on using urgent procedure to reactivate an ePrivacy Directive derogation allowing internet services to voluntarily detect child sexual abuse in private communications. The Council adopted the Commission proposal as its position on July 2, triggering Parliament’s second reading after the prior interim law expired on April 3 and Parliament rejected an extension on March 26. Parliament now has three months to reject or amend the Council position, with amendments requiring an absolute majority of 360 MEPs.
Why it matters
The file directly tests how far EU lawmakers will let platforms scan private communications for child-safety purposes despite ePrivacy protections.
Sources & driving stories
EUROPEAN PARLIAMENT
European Parliament coverageSeoul rejects U.S. claims over Coupang fine
The Gazette, carrying AP reporting, said South Korea disputed a U.S. House Judiciary Committee report accusing Seoul of discriminating against U.S.-listed Coupang. South Korea’s Personal Information Protection Commission fined Coupang 625 billion won, about $403 million, in June after a breach exposed personal information of more than 37 million people, including 33 million customers, and after the company missed the 72-hour breach reporting deadline. Officials attributed the access to a former employee using a stolen security key; Coupang apologized and plans to challenge the fine in administrative court.
Why it matters
A major privacy enforcement action has become a U.S.–South Korea trade and regulatory dispute over whether data-protection penalties are consumer protection or discriminatory treatment.
Sources & driving stories
THE GAZETTE
The Gazette coverageYAHOO
Yahoo coverageMedtronic notifies customers after ShinyHunters breach
BleepingComputer’s Bill Toulas reported that Medtronic began notifying customers affected by unauthorized access to specific corporate IT systems from April 13 to April 19, after unusual activity was detected on April 15. ShinyHunters claimed it held about 9 million Medtronic records containing personally identifiable information and internal corporate data, listed the company on an extortion portal on April 18, and threatened release by April 21. Medtronic said the data was not exposed online, medical devices remain safe to use, and affected people are being offered 24 months of credit monitoring and identity-theft protection.
Why it matters
The breach adds a large healthcare-technology data exposure to the ShinyHunters extortion pattern while raising customer phishing and identity-risk concerns.
Sources & driving stories
BLEEPINGCOMPUTER · Bill Toulas
BleepingComputer coverageWorth noting
WORTH NOTING
Supreme Court strengthens location-history privacy
Yuanchung Lee wrote that in Chatrie the Court held 6–3 that police access to Google Location History is a Fourth Amendment search, while remanding reasonableness, warrant, particularity, probable-cause, and good-faith questions.
WORTH NOTING
Apple email masking bug persists
CNET’s Tyler Lacoma reported that a Hide My Email vulnerability could reveal users’ real addresses, was reported to Apple in June 2025, and allegedly persisted after Apple said it had fixed the issue in March 2026.
WORTH NOTING
X seeks to loosen FTC oversight
EFF’s Bill Budington said EFF and allies urged the FTC to reject X Corp.’s May 15 petition to set aside or modify a 2022 privacy consent decree tied to misuse of phone numbers and email addresses for targeted advertising.
Still unclear
OPEN QUESTION
Will Parliament add safeguards before adoption?
If MEPs cannot assemble an absolute majority to amend or reject the Council’s ePrivacy derogation position, the original Commission proposal could move forward with fewer limits than Parliament previously sought.
OPEN QUESTION
Can child-safety rules avoid identity surveillance?
The EU CSA-scanning debate and U.S. age-verification proposals both show privacy pressure points around protecting minors without normalizing broad identity checks or private-message monitoring.
