Key developments
EU to assess FTC ruling’s DPF impact
Hunton reported that the European Commission will assess whether the U.S. Supreme Court’s Trump v. Slaughter ruling, concerning presidential removal authority over FTC commissioners, affects the EU-U.S. Data Privacy Framework. The 2023 DPF adequacy decision relied partly on the FTC as an independent enforcement authority, and NOYB has asked the Commission to withdraw the adequacy decision while planning further CJEU litigation. The DPF remains valid for now, so certified U.S. companies can continue receiving covered EU personal data transfers.
Why it matters
Any serious EU doubts about FTC independence could destabilize a major legal basis for EU-to-U.S. data transfers.
Sources & driving stories
HUNTON
Hunton coverageCalifornia panel advances CIPA cookie-litigation reform
Mondaq authors Gregory Szewczyk and Hayley Steele reported that the California Assembly Committee on Privacy and Consumer Protection passed SB 690 on July 1, 2026. The amended bill would remove conduct on websites, online applications, and mobile apps from CIPA’s private right of action, shifting enforcement to the California Attorney General. The committee also added retroactive application for certain pending claims filed within two years before the bill’s operative date, if enacted.
Why it matters
SB 690 could sharply reduce the wave of CIPA wiretap and pen-register lawsuits targeting cookies, pixels, and online tracking.
Sources & driving stories
MONDAQ · Gregory Szewczyk and Hayley Steele
Mondaq coverageSeoul rejects U.S. Coupang breach-bias report
Asianews author No Kyung-min and The Korea Herald author Ji Da-gyum reported that South Korea rejected a U.S. House Judiciary Committee interim staff report alleging discriminatory treatment of U.S.-owned Coupang after a massive data breach. Seoul said investigations and regulatory actions followed Korean law and were not based on nationality. The Korea Herald reported a dispute over breach scope, with authorities alleging more than 33 million exposed personal records while Coupang and a suspect alleged about 3,000 extracted and stored records.
Why it matters
The dispute turns a major privacy investigation into a cross-border enforcement and market-access controversy.
Sources & driving stories
ASIANEWS · No Kyung-min
Asianews coverageTHE KOREA HERALD · Ji Da-gyum
The Korea Herald coverageSAHM
Sahm coverageWorth noting
WORTH NOTING
Vermont privacy law adds LLM disclosures
Privado AI author Robert Bateman reported that Vermont’s new S.71, signed June 16 and effective January 1, 2028, requires disclosures on personal data used for large language model training, opt-out preference signal support, sensitive-data consent, and health-facility geofencing limits.
WORTH NOTING
Flock vehicle fingerprints identify plateless cars
Bruce Schneier highlighted a 2024 Flock presentation describing searches based on decals, bumper stickers, racks, temporary tags, and “multi geo search” for vehicles believed to travel together even without full plate information.
WORTH NOTING
New breach notices expose health data
Recent notices and reporting cite Medtronic patient data exposure, a St. Paul incident affecting 12,484 people and 43 GB of data, and an AssuranceAmerica incident potentially affecting more than 1.1 million people.
Still unclear
OPEN QUESTION
Will EU regulators accept FTC independence after Slaughter?
The DPF remains in force, but renewed Commission review and NOYB litigation plans create uncertainty for transfer-risk assessments.
OPEN QUESTION
Can SB 690’s retroactivity survive opposition?
The retroactive carveout is the bill’s most consequential feature for pending CIPA claims and likely the focal point for lobbying and legal challenges.
