Key developments
California committee advances CIPA private-action rollback
Mondaq’s Gregory Szewczyk and Hayley Steele report that the California Assembly Committee on Privacy and Consumer Protection passed SB 690 amendments on July 1, 2026. The bill would remove conduct on websites, online applications, and mobile applications from CIPA’s private right of action, shift enforcement to the California Attorney General, and apply the commercial-purpose exception retroactively to some pending claims filed within two years before the bill’s operative date. The measure is expected to move to the Appropriations Committee after the legislature’s summer recess in August.
Why it matters
If enacted, SB 690 could sharply reduce cookie, pixel, wiretap, and pen-register litigation risk for businesses operating online in California.
Sources & driving stories
MONDAQ · Gregory Szewczyk and Hayley Steele
Mondaq coveragePegasus infected former MEP probing spyware misuse
The Record’s Suzanne Smalley reports that Citizen Lab found Pegasus spyware infections on former European Parliament member Stelios Kouloglou’s phone in October 2022 and March 2023, while he served on the PEGA Committee investigating commercial spyware abuse. Kouloglou alleged Greek government responsibility, but Citizen Lab said it had no evidence confirming that claim. Citizen Lab also linked the same Pegasus customer and email to earlier infections involving journalists and opposition figures.
Why it matters
The report suggests lawmakers investigating spyware abuses may themselves be surveillance targets, with implications for democratic oversight and legislative confidentiality.
Sources & driving stories
THE RECORD · Suzanne Smalley
The Record coverageIBM-managed SLA environment exposed 70,000 records
Computer Weekly reports that Singapore Land Authority disclosed unauthorized access to a cloud environment managed by IBM for development and systems integration testing. The dataset was meant to contain mock or anonymized information but instead included names, NRIC numbers, and property addresses for about 70,000 people. SLA said live property ownership and lodgement systems were unaffected, while IBM revoked access and SLA notified affected individuals, police, the Personal Data Protection Commission, GovTech, and the Cyber Security Agency of Singapore.
Why it matters
The breach highlights a recurring privacy failure: real personal data left in third-party development and test environments that are supposed to be anonymized.
Sources & driving stories
COMPUTER WEEKLY
Computer Weekly coverageDATA TRUST CADENCE
Data Trust Cadence coverageWorth noting
WORTH NOTING
Lemonade settlement covers 190,000 people
CNBC’s Brian Sloan reports Lemonade agreed to a $10.5 million class settlement over an alleged quote-platform vulnerability that exposed driver’s license numbers and other data, with claims offering up to $10,000 for documented losses and three years of credit monitoring.
WORTH NOTING
Union County paid Kairos $1 million
Security Affairs’ Pierluigi Paganini reports a Ransom-ISAC case study saying a U.S. government organization later identified as Union County, Ohio paid about $1 million after Kairos threatened to publish 1.6 million files and 2 TB of data, including Social Security numbers, fingerprints, and passport numbers.
WORTH NOTING
AI agents draw privacy scrutiny
Biometric Update’s Anthony Kimery reports Sen. Mark Warner released draft legislation limiting consumer AI agents’ data access and secondary uses, while BleepingComputer’s Bill Toulas reports Sysdig identified JadePuffer as a ransomware operation allegedly conducted entirely by an autonomous LLM agent.
Still unclear
OPEN QUESTION
Will SB 690 survive retroactivity fights?
The bill’s retroactive effect on pending CIPA claims is one of its most consequential provisions and could trigger intense lobbying or legal challenges before final passage.
OPEN QUESTION
Can deletion promises ever be verified?
The Kairos case shows public-sector victims may pay for alleged deletion of stolen data even when the proof of deletion is not technically verifiable.
