Key developments
Noyb presses EU to unwind US data framework
MrWeb reported that Noyb, the Austrian privacy group led by Max Schrems, called on the European Commission to begin an “orderly withdrawal” of the EU-US data transfer framework. Noyb argues a June 29, 2026 U.S. Supreme Court ruling in Trump v. Slaughter undermines the FTC independence cited more than 250 times in the Commission’s 2023 adequacy decision. The framework remains in force, but Noyb says it will sue within weeks if the Commission does not act.
Why it matters
A new Schrems-linked challenge could again destabilize transatlantic personal-data transfers, even if litigation would likely take years.
Sources & driving stories
MRWEB
MrWeb coverageComcast agrees to $117.5 million breach settlement
The Sun Herald reported that Comcast agreed to pay $117.5 million to settle class-action claims tied to an October 2023 cybersecurity breach affecting Xfinity customers. Comcast said exposed data included usernames, passwords, contact information, dates of birth and the last four digits of Social Security numbers. Eligible notified customers can claim up to $10,000 for documented losses or lost time, or seek a $50 alternative cash payment, with online and paper claim deadlines on Sept. 14.
Why it matters
The settlement is a large consumer breach payout and sets concrete near-term claims deadlines for affected Xfinity customers.
Sources & driving stories
SUN HERALD · Gabe Hauari
Sun Herald coverageJudge closes Bayview’s $26 million breach case
National Mortgage News reported that U.S. District Judge Darrin P. Gayles entered final judgment approving Bayview Asset Management’s $26 million settlement over a late-2021 hack at mortgage servicing subsidiaries. The deal covers 5,774,688 class members and includes an $8.6 million attorneys’ fee award, $1.7 million in litigation expenses, reimbursements up to $5,000 per person, pro rata cash payments and one year of identity theft monitoring. The case followed Lakeview Loan Servicing’s disclosure that an unauthorized actor remained in systems for 41 days.
Why it matters
The approval ends one of the largest recent data breach settlements involving a nonbank mortgage lender.
Sources & driving stories
NATIONAL MORTGAGE NEWS · Andrew Martinez
National Mortgage News coverageWorth noting
WORTH NOTING
California DROP deletions begin soon
Newsweek reported that 332,292 Californians had enrolled as of July 1, with registered data brokers required to begin processing centralized deletion requests after Aug. 1 and facing penalties of $200 per day per affected person for failures.
WORTH NOTING
BIPA eyewear suit revived
Law.com reported that the Seventh Circuit reversed dismissal of a class action against GUNNAR Optiks, finding more proceedings are needed before its virtual glasses try-on tool can qualify for BIPA’s healthcare exception.
WORTH NOTING
Lifeline breach data appears doctored
Insurance Business reported that Lifeline Australia is notifying affected staff and volunteers after accessed information appeared in a dark web post, while the charity says help seeker data and financial information were not compromised.
Still unclear
OPEN QUESTION
Will the EU act before Noyb sues?
A Commission-led withdrawal could give businesses transition time, while another court-driven invalidation could recreate a sudden compliance cliff for EU-US transfers.
OPEN QUESTION
How will courts define biometric healthcare exceptions?
The GUNNAR Optiks remand leaves unresolved how far BIPA exceptions extend when consumer-facing biometric tools are marketed around health or fit benefits.
