Key developments
23andMe state settlement shrinks to $18 million
A coalition of 42 states and the District of Columbia will receive about $18 million from 23andMe’s bankruptcy estate to resolve claims tied to the 2023 breach affecting roughly 6.9 million customers. The states had $150 million in allowed claims, but 23andMe’s 2025 bankruptcy reduced available recovery; Texas is expected to receive about $1.27 million, Florida $1.11 million, Indiana $979,424, Alabama $260,817, and Oklahoma $276,435. The agreement adds cybersecurity, risk-assessment, advisory-board, privacy-law compliance, and consumer deletion-right obligations that also apply to the successor 23andMe Research Institute.
Why it matters
The settlement turns a major genetic-data breach into enforceable post-bankruptcy privacy obligations, but with sharply reduced public recovery.
Sources & driving stories
Ofcom opens TikTok age-verification investigation
The U.K. communications regulator Ofcom opened an investigation into whether TikTok is failing to effectively verify users’ ages under the Online Safety Act. Ofcom said TikTok’s age-inference models may have misidentified a significant proportion of children, increasing exposure risk to content involving pornography, suicide, and eating disorders. TikTok said it enforces age-appropriate experiences and will demonstrate compliance; Ofcom said possible penalties include fines up to £18 million or 10% of qualifying worldwide revenue.
Why it matters
The probe tests whether algorithmic age inference is sufficient for children’s privacy and safety compliance under the U.K.’s new online-safety regime.
Sources & driving stories
THE RECORD · Suzanne Smalley
The Record coverageFiesta Insurance breach notifications follow yearlong review
Fiesta Insurance Franchise Corporation began mailing breach notices around July 13, 2026, after determining in late June that files potentially accessed or acquired by an unauthorized party contained personal information. The company learned on June 9, 2025 that systems had been affected, then conducted a forensic investigation that reportedly took about a year. More than 160,000 people were reportedly affected, with potentially exposed data including names, addresses, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account information, payment-card details, and health-related financial information.
Why it matters
The delayed notice and breadth of exposed identifiers create heightened identity-theft and regulatory-risk questions for an insurance and tax-services franchisor.
Sources & driving stories
EAGLE-TRIBUNE
Eagle-Tribune coverageWorth noting
WORTH NOTING
GSA floats AI data safeguards
GSA’s revised draft GSAR clause would restrict contractor use of government data in large language model systems, require encryption and audit logging, and limit transmission outside approved premises or FedRAMP-authorized services.
WORTH NOTING
Qantas breach traced to vishing
Bitdefender reported that the Qantas breach began with a fake IT-support call that connected a legitimate CRM session to an attacker-controlled extraction tool, compromising about 5.67 million records.
WORTH NOTING
Vehicle impairment mandate faces privacy delay
A House amendment would delay federally mandated in-car impairment-detection technology while lawmakers study accuracy, data ownership, retention, transfer, and potential surveillance risks.
Still unclear
OPEN QUESTION
Will 23andMe obligations survive the data sale?
The settlement’s privacy protections depend on continued enforcement against the successor 23andMe Research Institute after consumer genetic data moved through bankruptcy.
OPEN QUESTION
Can age inference satisfy UK regulators?
Ofcom’s TikTok investigation directly challenges a common platform approach that the regulator says is not listed among highly effective age-verification methods.
