Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Saturday, July 4, 2026 · 6:49 PM EDT

Key developments

MONDAQ

California committee advances CIPA private-action rollback

Mondaq’s Gregory Szewczyk and Hayley Steele report that the California Assembly Committee on Privacy and Consumer Protection passed SB 690 amendments on July 1, 2026. The bill would remove conduct on websites, online applications, and mobile applications from CIPA’s private right of action, shift enforcement to the California Attorney General, and apply the commercial-purpose exception retroactively to some pending claims filed within two years before the bill’s operative date. The measure is expected to move to the Appropriations Committee after the legislature’s summer recess in August.

Why it matters

If enacted, SB 690 could sharply reduce cookie, pixel, wiretap, and pen-register litigation risk for businesses operating online in California.

Sources & driving stories

MONDAQ · Gregory Szewczyk and Hayley Steele

Mondaq coverage
THE RECORD

Pegasus infected former MEP probing spyware misuse

The Record’s Suzanne Smalley reports that Citizen Lab found Pegasus spyware infections on former European Parliament member Stelios Kouloglou’s phone in October 2022 and March 2023, while he served on the PEGA Committee investigating commercial spyware abuse. Kouloglou alleged Greek government responsibility, but Citizen Lab said it had no evidence confirming that claim. Citizen Lab also linked the same Pegasus customer and email to earlier infections involving journalists and opposition figures.

Why it matters

The report suggests lawmakers investigating spyware abuses may themselves be surveillance targets, with implications for democratic oversight and legislative confidentiality.

Sources & driving stories

THE RECORD · Suzanne Smalley

The Record coverage
COMPUTER WEEKLY

IBM-managed SLA environment exposed 70,000 records

Computer Weekly reports that Singapore Land Authority disclosed unauthorized access to a cloud environment managed by IBM for development and systems integration testing. The dataset was meant to contain mock or anonymized information but instead included names, NRIC numbers, and property addresses for about 70,000 people. SLA said live property ownership and lodgement systems were unaffected, while IBM revoked access and SLA notified affected individuals, police, the Personal Data Protection Commission, GovTech, and the Cyber Security Agency of Singapore.

Why it matters

The breach highlights a recurring privacy failure: real personal data left in third-party development and test environments that are supposed to be anonymized.

Sources & driving stories

Worth noting

WORTH NOTING

Lemonade settlement covers 190,000 people

CNBC’s Brian Sloan reports Lemonade agreed to a $10.5 million class settlement over an alleged quote-platform vulnerability that exposed driver’s license numbers and other data, with claims offering up to $10,000 for documented losses and three years of credit monitoring.

WORTH NOTING

Union County paid Kairos $1 million

Security Affairs’ Pierluigi Paganini reports a Ransom-ISAC case study saying a U.S. government organization later identified as Union County, Ohio paid about $1 million after Kairos threatened to publish 1.6 million files and 2 TB of data, including Social Security numbers, fingerprints, and passport numbers.

WORTH NOTING

AI agents draw privacy scrutiny

Biometric Update’s Anthony Kimery reports Sen. Mark Warner released draft legislation limiting consumer AI agents’ data access and secondary uses, while BleepingComputer’s Bill Toulas reports Sysdig identified JadePuffer as a ransomware operation allegedly conducted entirely by an autonomous LLM agent.

Still unclear

OPEN QUESTION

Will SB 690 survive retroactivity fights?

The bill’s retroactive effect on pending CIPA claims is one of its most consequential provisions and could trigger intense lobbying or legal challenges before final passage.

OPEN QUESTION

Can deletion promises ever be verified?

The Kairos case shows public-sector victims may pay for alleged deletion of stolen data even when the proof of deletion is not technically verifiable.