Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Thursday, July 16, 2026 · 6:50 PM EDT

Key developments

AL.COM

23andMe state settlement shrinks to $18 million

A coalition of 42 states and the District of Columbia will receive about $18 million from 23andMe’s bankruptcy estate to resolve claims tied to the 2023 breach affecting roughly 6.9 million customers. The states had $150 million in allowed claims, but 23andMe’s 2025 bankruptcy reduced available recovery; Texas is expected to receive about $1.27 million, Florida $1.11 million, Indiana $979,424, Alabama $260,817, and Oklahoma $276,435. The agreement adds cybersecurity, risk-assessment, advisory-board, privacy-law compliance, and consumer deletion-right obligations that also apply to the successor 23andMe Research Institute.

Why it matters

The settlement turns a major genetic-data breach into enforceable post-bankruptcy privacy obligations, but with sharply reduced public recovery.

Sources & driving stories

AL.COM · Claudia Dimuro

AL.com coverage
THE RECORD

Ofcom opens TikTok age-verification investigation

The U.K. communications regulator Ofcom opened an investigation into whether TikTok is failing to effectively verify users’ ages under the Online Safety Act. Ofcom said TikTok’s age-inference models may have misidentified a significant proportion of children, increasing exposure risk to content involving pornography, suicide, and eating disorders. TikTok said it enforces age-appropriate experiences and will demonstrate compliance; Ofcom said possible penalties include fines up to £18 million or 10% of qualifying worldwide revenue.

Why it matters

The probe tests whether algorithmic age inference is sufficient for children’s privacy and safety compliance under the U.K.’s new online-safety regime.

Sources & driving stories

THE RECORD · Suzanne Smalley

The Record coverage
EAGLE-TRIBUNE

Fiesta Insurance breach notifications follow yearlong review

Fiesta Insurance Franchise Corporation began mailing breach notices around July 13, 2026, after determining in late June that files potentially accessed or acquired by an unauthorized party contained personal information. The company learned on June 9, 2025 that systems had been affected, then conducted a forensic investigation that reportedly took about a year. More than 160,000 people were reportedly affected, with potentially exposed data including names, addresses, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account information, payment-card details, and health-related financial information.

Why it matters

The delayed notice and breadth of exposed identifiers create heightened identity-theft and regulatory-risk questions for an insurance and tax-services franchisor.

Sources & driving stories

Worth noting

WORTH NOTING

GSA floats AI data safeguards

GSA’s revised draft GSAR clause would restrict contractor use of government data in large language model systems, require encryption and audit logging, and limit transmission outside approved premises or FedRAMP-authorized services.

WORTH NOTING

Qantas breach traced to vishing

Bitdefender reported that the Qantas breach began with a fake IT-support call that connected a legitimate CRM session to an attacker-controlled extraction tool, compromising about 5.67 million records.

WORTH NOTING

Vehicle impairment mandate faces privacy delay

A House amendment would delay federally mandated in-car impairment-detection technology while lawmakers study accuracy, data ownership, retention, transfer, and potential surveillance risks.

Still unclear

OPEN QUESTION

Will 23andMe obligations survive the data sale?

The settlement’s privacy protections depend on continued enforcement against the successor 23andMe Research Institute after consumer genetic data moved through bankruptcy.

OPEN QUESTION

Can age inference satisfy UK regulators?

Ofcom’s TikTok investigation directly challenges a common platform approach that the regulator says is not listed among highly effective age-verification methods.