Lucid Privacy Group @lucidprivacygroup.bsky.social · 28/08/2026Gov't argued you turned on Location History, so you forfeited privacy in it. SCOTUS said no. Acquiring that data is a Fourth Amendment search. Kagan compares it to your email, photos and calendar on Google's servers. That's the part to watch. supremecourt.gov/opinions/25p… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 26/08/2026The UK could order Apple to build a backdoor into encrypted iCloud data, gag Apple from confirming it exists, as well as reaching US citizens' data too. LINK therecord.media/apple-uk-tcn-… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 24/08/2026NJ just made it illegal for grocers to price your food based on data pulled from cameras and sensors watching you shop. Following NY, CT, and MD. "Personalized pricing" was always just a surveillance overstep. insideprivacy.com/state-priva… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 21/08/2026Same question, three opposite answers: who should verify a kid's age and hold the data? New York says the platform. Illinois says the phone. Congress can't decide. Out money is on the one that scares us most 🧵 Full breakdown linkedin.com/pulse/hot-potato… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 20/08/2026In this issue: 👉 Three kids'-safety laws playing hot potato with who verifies a minor's age. 👉 CalPrivacy's all-California fortnight: a double broker fine, a fee hike, a deletion platform going live. 👉 Four fights over who holds the data and who can reach in. www.linkedin.com/pulse/hot-po...linkedin.com🥔 Hot PotatoesLucid folks, There's an accidental theme this issue, and it's a question: who's holding the data, and who gets to reach into it? Our feature finds three children's-safety laws quietly arguing over who... 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 17/08/2026Blaming the algorithm won't save employers anymore - under CTs new CART Act, companies using AI in hiring can no longer escape discrimination liability by blaming third-party vendor software. knowledge.dlapiper.com/dlapip… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 15/08/2026NJ signed a design code covering services where 2%+ of users might be minors — lowest threshold of any state. Effective Sept 2027. Dark patterns, recommendation algorithms, safety defaults all in scope .. with private right of action. fpf.org/blog/a-new-design-code-takes-root-in-the-garden-state/ 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 15/08/2026The FTC, CA, & UT are suing Hims & Hers for allegedly leaking sensitive health data to Meta & Snap via tracking pixels while also tacking on subscription-trap claims. This suit could set legal precedent on background ad-tracking. therecord.media/hims-hers-pri… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 13/08/2026Meta’s Flo app verdict is escalating into a $6 billion nightmare - if your app or website uses pixels and SDKs to track health-adjacent data, consider this a wake-up call to audit your ad tech now mlex.com/mlex/data-privacy-se… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 12/08/2026CalPrivac launched its first formal sectoral audit. Moving from complaints to proactive audits signals an enforcement shift. Starting with gig platforms, it tests if workers can access geolocation, biometric & algorithmic data employers use. privacy.ca.gov/2026/07/califo… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 11/08/2026Major wearable makers offer no basic safeguards like default end-to-end encryption. Meaning if a company can read your data, they can be subpoenaed for it. eff.org/deeplinks/2026/07/mos… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 10/08/2026Illinois became the first to mandate annual, independent third-party compliance audits for large frontier developers, with summaries published for the public. Will we see more states force Frontier AI regulation? dlapiper.com/en-us/insights/p… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 07/08/2026Vermont just became the 12th member of the Consortium of Privacy Regulators. By pooling expertise and resources, states are creating a powerful "force multiplier" for smarter, coordinated consumer protection. ago.vermont.gov/blog/2026/08/… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 05/08/2026In this issue: 🪝 Brussels moves the AI Act deadline and quietly swaps its target 🪝 Meta's year-old Flo verdict turns into a multibillion-dollar bill 🪝 Illinois makes AI bring its own auditor www.linkedin.com/pulse/off-cl...linkedin.com⏱️ Off the Clock, On the HookLucid folks, There's a comforting story regulators like to tell: the deadline is coming, so get your house in order before it lands. This week complicates it. 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 31/07/2026IAB wants tiered consent for teen ad targeting. Parental consent under 13, opt-in w/ parental notice for 13-15, self-consent at 16-17. Clearer age bands, but still doesn't solve the core problem: verifying age without collecting more data. mediapost.com/publications/ar… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 29/07/2026The EU wants a bloc-wide "start date" for social media ban for under-13s - unless supervised or proven teen-safe. The hard part remains: age checks without verification & a new trove of ID data. therecord.media/eu-proposed-s… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 27/07/2026IAB EU has appointed a Governance Board to oversee compliance with TCF, following a 2025 Belgian ruling on IAB's role as joint controller. The board includes Google, Amazon, Criteo, WPP, Publicis & Samsung. Industry stands by to see if firmer self regs change anything! iabeurope.eu/iab-europe-annou… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 22/07/2026In this issue: ✔️ What happens when AI governance lands in the DPO’s inbox ✔️ Europe starts drawing lines around social media ✔️ Adtech’s teen-targeting rules run into the age-check problem www.linkedin.com/pulse/loose-...linkedin.com🌞 Loose EndsLucid folks, This week’s stories all land in the messy middle between deciding what should happen and figuring out who has to make it happen. DPOs are being pulled into AI governance before many organ... 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 21/07/2026House passed a kids' online safety bill, but Senate path looks shaky. By omitting the Senate's "duty-of-care" rule while adding AI & age verification, the bill proves everyone wants to protect kids, but no one agrees on how. Link here: us.list-manage.com/mo0iZJ35lw… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 20/07/2026A judge ruled Veradigm must face class action alleging its patient portals sent health data to Google without consent. Patient portals & 3Ps face rising legal scrutiny. Link Here: us.list-manage.com/188RjxGkxv… 001
Lucid Privacy Group @lucidprivacygroup.bsky.social · 17/07/2026New Jersey has added a costly law to privacy patchwork. Banning sensitive data sales & a new data broker registration with $$$ fees. Link here us.list-manage.com/3DRd7PK2Dt… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 16/07/2026The SC’s ruling in Trump v. Slaughter has reopened questions about FTC’s independence, giving noyb a new basis to challenge the DPF. Companies relying on the DPF should be watching closely. Link Here noyb.eu/en/us-supreme-court-j… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 15/07/2026Spain’s AEPD fined Amadeus after finding records were reused without proper notice. This matters for adtech and data-platform vendors whose contracts still treat infrastructure roles as safely behind the scenes. Link: here dataprotectionreport.com/2026… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 14/07/2026Hearing alot about CA Deletion Act & DROP but don’t know where to start. Here’s a useful FAQ to get you started. Drop us a note if you need more help in getting operational. us.list-manage.com/TfMs26Ra_M… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 13/07/2026Updated Lucid Pan-US Readiness Record now includes 2026 rollouts for IA, DE, NE, NH, NJ, TN, MN, MD, IN, KY & RI. Built to turn state regulations into a simple, practical compliance process. OK, AL & LA are next. Simplify compliance: us.list-manage.com/ZTDf0vVFGi… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 13/07/2026In this issue: 👉 DROP brings broker backends into the light 👉 The DPF gets dragged back into the FTC independence fight 👉 New Jersey gives data brokers one more reason to stay up at night www.linkedin.com/pulse/button...linkedin.com🗳️ ButtonpushersLucid folks, There is a strange asymmetry in privacy law: companies can collect, enrich, sell, append, and resell personal information at scale, but the person trying to undo that chain is often sent ... 020
Lucid Privacy Group @lucidprivacygroup.bsky.social · 30/06/2026Siri AI is delayed for EU iPhones. Apple claims the DMA's rules threaten security by forcing open private data and app functions to competing assistants. There’s a battle brewing over who controls ecosystem-wide agents. us.list-manage.com/9zTWybNpyd… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 29/06/2026Privacy group noyb is launching a class action against credit agency CRIF over a secret "shadow registry." CRIF allegedly tracked nearly all adults in Austria, scoring them on location, age, and gender rather than financial history. us.list-manage.com/JC9G_zMK43… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 26/06/2026The UK gives Apple/Google 3 months to build device-level controls blocking minors from sharing nude images. This shifts child safety from apps straight into the OS, leading to privacy and age verification by default? us.list-manage.com/Oxbps9OIf5… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 24/06/2026Can you delegate Amazon shopping to an AI agent? Amazon says no. It won an injunction against Perplexity’s Comet bot. The real threat isn't privacy or security—it's AI completely bypassing Amazon's highly profitable ad funnel. Link: us.list-manage.com/EE9IWwn51g… 021
Lucid Privacy Group @lucidprivacygroup.bsky.social · 24/06/2026CA's Delete Act gets a copycat! Connecticut passed a data broker law requiring state registration by 2027 and a universal "one-click" deletion button. With audits and $200/day penalties, deletion infrastructure is expanding. Full dive: linkedin.com/pulse/infrastruc… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 22/06/2026We’ve updated the Lucid Pan-US Readiness Record! We added 11 new state laws (including NJ, NH, MN, & MD). Evaluate compliance easily with our new questionnaire & legal reference sheet. Link: lucidprivacy.io/references/pa… 022
Lucid Privacy Group @lucidprivacygroup.bsky.social · 17/06/2026In this issue: ➡️ Connecticut gives California’s Delete Act a sequel ➡️ AI agents and device controls hit the same wall: system access ➡️ Hidden data machinery keeps drawing legal fire www.linkedin.com/pulse/infras...linkedin.com🌞 Infrastructure WeekLucid folks, A lot of privacy fights used to be about what companies collected. This week, the more interesting question is where control gets built in. 010
Lucid Privacy Group @lucidprivacygroup.bsky.social · 12/06/2026The proposal gives pubs something useful, but it doesn’t make the implementation simple. The ICO’s ask leans heavily on 1P control: storage & processing should stay close to the pub’s own domain, while broad 3P sharing stays on a short leash. linkedin.com/pulse/end-easy-l… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 10/06/2026insideprivacy.com/artificial-… If you give AI agents access to APIs, files, & databases, a single prompt can completely wreck. Autonomy is cool until your AI deletes or shortcuts barriers to reach the goal. We will see some major agentic screw-ups in the near future. 011
Lucid Privacy Group @lucidprivacygroup.bsky.social · 08/06/2026keanmiller.com/insights/blog/… Louisiana is joining the state-by-state data privacy circus. It’s different enough from CA and TX to add unwanted complexity to compliance. We are reaching a point where you’ll need 50 lawyers just to launch a website in the US. 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 05/06/2026insideprivacy.com/united-stat… Shutterstock got hit with a $35M FTC fine for hiding subscription terms & turning cancellation into a hostage negotiation. Regs are sending a message: recurring revenue is not a license to scam. If your business model relies on dark patterns, your product just sucks. 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 04/06/2026therecord.media/why-supreme-c… Can the police search everyone first and then find a suspect? The SC is reviewing the Chatrie case on "reverse" geofence warrants. If approved, cops could sweep your searches, AI chats, and geodata just because you were near a crime scene. 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 03/06/2026In this issue: 📌 The ICO proposes a new path for a lower-risk online ad ecosystem 📌 Louisiana moves closer to a comprehensive privacy law. 📌 The Supreme Court weighs privacy limits on geofence warrants www.linkedin.com/pulse/end-ea...linkedin.com🌞 The End of EasyLucid folks, This week is about the hidden costs of making everything feel easy. For a long time, the internet made a simple promise: the machinery could get more complicated as long as the experience... 021
Lucid Privacy Group @lucidprivacygroup.bsky.social · 01/06/2026The EU has fast-tracked a ban on AI “nudifier” tools. It’s a clear moral line, but also smart positioning: even as Brussels softens parts of the AI Act, banning synthetic abuse tools by end of 2026 helps preserve its ethical high ground. therecord.media/european-lead… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 29/05/2026Vibe-coding is creating real corporate liability. If you don't establish security standards, your corporate data & IP is essentially public property. Contact your friendly Lucid Rep today to secure your AI AUP strategy! wired.com/story/thousands-of-… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 26/05/2026Google’s upcoming “simplification” of data controls may create a cleaner flow, but it also creates real liability for publishers. The era of “set & forget” Consent Mode is over. Publishers: audit your implementations now (or ask Lucid to do it for you). searchengineland.com/google-simpl...searchengineland.comGoogle simplifies Analytics and Ads consent rulesGoogle’s June consent update will make consent setup more critical by making user permission the main control for how Ads collects/uses data. 011
Lucid Privacy Group @lucidprivacygroup.bsky.social · 21/05/2026CA’s Delete Request & Opt-Out Platform (DROP) is where that fantasy starts meeting production infrastructure. It’s not a magic delete button. It’s handing brokers recurring lists of consumer instructions and expecting their databases to obey them. (1/2) 121
Lucid Privacy Group @lucidprivacygroup.bsky.social · 20/05/2026In this issue: ☑️ What CA’s DROP API means for data brokers, identity graphs, and deletion ☑️ Google’s Analytics “simplification” shifts more consent risk onto publishers ☑️ Forbes’ $10M tracker settlement shows CIPA pixel claims are no longer theoretical www.linkedin.com/pulse/so-muc...linkedin.com🌞 So Much for “Set It and ForgetLucid folks, For years, privacy compliance has had a comforting little fantasy at its center: someone asks for their data to be deleted, the company finds the data, and the data disappears. Very neat. 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 20/05/2026EU negotiators just pushed high-risk AI compliance from Aug 2026 to Dec 2027. Privacy teams still need updated AI governance roadmaps. www.insideprivacy.com/artificial-in… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 13/05/2026GM's $12.75M settlement isn't just about the money. CA now requires documented privacy programs with regular risk assessments reported to regulators. therecord.media/gm-to-pay-12-millio… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 07/05/2026In this issue: ✦ Google leans on timing in ad tech cases, but plaintiffs say the conduct continues ✦ The UK ICO sharpens tracking rules as exemption questions remain ✦ Car data cases diverge as data flows shape what sticks www.linkedin.com/pulse/mind-g...linkedin.com🌞 Mind the GapLucid folks, For a long time, compliance left room for storytelling: describe a system cleanly enough, and the reality of how personal data was handled could stay in the background, undisturbed, and u... 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 07/05/2026Forbes agreed to pay $10M for tracking users without consent via LinkedIn/Microsoft pixels. California wiretapping law treats IP addresses + identifiers as protected communication interception. therecord.media/forbes-agrees-10-mi… 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 23/04/2026In this issue: ☞ Meta’s “Name Tag” idea runs into a very public line in the sand ☞ AI rules are piling onto an already crowded privacy map ☞ Federal privacy resurfaces, unresolved as ever www.linkedin.com/pulse/seams-...linkedin.com🌞 At the SeamsLucid folks, Most things work fine right up until someone actually asks how they work. That’s sort of where we are right now. 000
Lucid Privacy Group @lucidprivacygroup.bsky.social · 14/04/2026When does “data sharing” stop being just processing? FTC alleges OkCupid shared user data + photos with an AI company despite limiting disclosures. Are standard disclosure declarations fit for purpose? 100