Right To Know - September 2026, Vol. 45
Cyber, Privacy, and Technology Report
Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed.
View previous issues and sign up to receive future newsletters by email here.
Litigation & Enforcement:
- CalPrivacy Targets Data Broker Opt-Out Practices in First-of-Its-Kind Enforcement Action: On Aug. 11th, the California Privacy Protection Agency Board (CalPrivacy) settled its first enforcement action alleging violations of both the California Consumer Privacy Act (CCPA) and the Delete Act, against data broker LocateSmarter, LLC. CalPrivacy found that LocateSmarter failed to register as a data broker by the Jan. 31st, 2026 deadline, despite selling personal information obtained from third parties, including names, contact information, dates of birth, Social Security numbers, and other sensitive data. Cal Privacy also found that LocateSmarter violated the CCPA by requiring consumers to provide the last four digits of their Social Security number to opt out of the sale or sharing of personal information—an unnecessary verification requirement inconsistent with data minimization principles. The company agreed to pay $110,490 in administrative fines—$30,600 for Delete Act violations and $79,890 for CCPA violations—and to register as a data broker, comply with the Delete Act, streamline its opt-out process, eliminate Social Security number requirements, and provide updated CCPA training. The action signals CalPrivacy’s continued focus on data broker registration and accessible consumer rights. Businesses should avoid unnecessary verification steps and collect only the information reasonably necessary to process privacy requests
- Second Data Broker Action in One-Week Signals Sustained California Enforcement: On Aug. 13th, the California Privacy Protection Agency (CalPrivacy) announced a stipulated order imposing a $52,400 administrative fine on marketing technology company Cybba, Inc. for failing to register as a data broker by the Jan. 31st, 2025, deadline, as required under the Delete Act. CalPrivacy found that Cybba qualified as a data broker because it sold personal information—including geolocation data, internet activity, identifiers, commercial information, and consumer inferences—about consumers with whom it had no direct relationship. Cybba registered after CalPrivacy contacted the company and timely registered in 2026 for its 2025 activities. In addition to the fine, Cybba agreed to maintain timely registration, process deletion requests through the Delete Request and Opt-out Platform (DROP) and publish required consumer-request metrics in its privacy policy. As CalPrivacy’s second data broker enforcement action in August 2026, the settlement signals sustained scrutiny of Delete Act compliance. Organizations that collect and sell data without a direct consumer relationship should assess data broker status and ensure timely registration, DROP participation, and transparent reporting.
- TikTok and ByteDance to Pay DOJ $400M: The Department of Justice (“DOJ”) has reached a $400 million settlement with TikTok and ByteDance resolving allegations that the companies violated the Children’s Online Privacy Protection Act (“COPPA”). The DOJ alleged that TikTok collected personal information from children under 13 without obtaining the parental consent required by law and failed to honor certain parental deletion requests. Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree involving TikTok’s predecessor, Musical.ly, making it one of the largest settlements in a COPPA enforcement action. The settlement serves as a reminder that regulators continue to closely scrutinize children’s privacy practices and the collection of minors’ personal information online.
- Los Angeles County Reaches Settlement Over Tracking Pixels Disclosing Health-Related Purchase Information (PS): Los Angeles County announced a settlement with Walmart and Sam’s Club resolving allegations that tracking technologies embedded on their websites disclosed consumers’ confidential health-related purchase information to third-party advertising platforms without notice or consent. According to the County’s complaint, Meta and Google tracking pixels transmitted information concerning consumers who purchased products including emergency contraception, HIV testing kits, drug testing kits, and prenatal vitamins. The settlement requires Walmart to pay $908,817 in restitution, civil penalties, attorneys’ fees, and costs, and includes permanent injunctive relief restricting the sharing of customers’ personal information and requiring compliance with applicable privacy laws. The action highlights regulators’ continued scrutiny of website tracking technologies where seemingly ordinary browsing or purchase information can reveal sensitive health information. Organizations offering health-related products or services should carefully assess what information their websites transmit to advertising and analytics platforms and whether appropriate notice, consent, and contractual restrictions are in place.
- FTC Sues Hims & Hers Over Privacy Practices: The Federal Trade Commission (FTC), joined by Utah and California, sued Hims & Hers, alleging that the telehealth company engaged in deceptive billing, cancellation, and health-privacy practices. The FTC alleges that Hims charged many consumers and enrolled them in recurring prescription subscriptions shortly after they submitted an intake form, despite representations that consumers would first consult with a medical provider and would not be charged until medication was prescribed. The agency also claims Hims made subscription cancellations unnecessarily difficult, including by obscuring the online cancellation option and failing to clearly disclose refill timing. Most significantly, the FTC alleges that Hims shared sensitive consumer health information with third-party advertising platforms, including Meta and Snap, despite promising consumers that their health information would remain private. The complaint alleges violations of federal and state consumer-protection laws, but because it is a lawsuit rather than a final judgment, the allegations will ultimately be decided by the court.
- Meta Settles Litigation over Child Addiction for $17B: Meta Platforms, Inc. agreed to settle its litigation with a coalition of state attorneys general resolving allegations that Meta used Facebook and Instagram to engage and retain young users while misleading the public about the platforms’ risks and violating the federal Children’s Online Privacy Protection Act (COPPA). Without admitting liability or wrongdoing, Meta agrees to extensive changes intended to protect children and teenagers, including stronger age-assurance systems, enhanced protections for users under 13, and limits on the collection and use of age-related data. The settlement also requires Meta to impose controls on teen usage, including daily time limits, nighttime restrictions, school-hour protections, and “productive pauses,” while giving parents or guardians greater ability to supervise and modify their teenagers’ settings. Meta must also undergo independent auditing and comply with specified monetary-payment obligations to the settling states, with the agreement generally remaining in effect for ten years. Upon court approval, the consent judgment would fully and finally resolve the participating states’ claims against Meta in this action, while expressly stating that the settlement is not an admission of liability and does not establish precedent for other jurisdictions or cases.
Industry Updates:
- China Continues Relentless Hacking of US Federal Government: The United States Department of Justice and the Federal Bureau of Investigation announced that they were seizing domains used by a Chinese based organization known as QTFY. QFTY is sponsored by the Peoples Republic of China (PRC) and used the domains to make two hacking tools- QScan and QTRouter- available to PRC linked groups targeting the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. QScan is used to scan for and infect vulnerable IoT devices and QTRouter was used to as command and control for the infected devices. The DOJ release notes that the seized domains were hardcoded into both tools, the seizure rendered the tools inoperable.
- ATF Hit with Ransomware- Declared a “Major Incident”: On Aug. 26th, the US Bureau of Alcohol, Tobacco and Firearms (“ATF”) declared that it was responding to a cybersecurity incident and that it was a “major incident.” The ransomware group Qilin has taken responsibility for the incident. The impact of the incident and the potential data at risk may be limited as the ATF claimed that the “impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.”
- Maine Attorney General Takes Down Data Breach Portal After Hoax Filings: The Office of the Maine Attorney General disabled its public-facing data breach database after discovering that reported breaches involving VRChat and Discord were hoaxes submitted by an unknown entity. Maine is one of several states that publish information on data breaches reported to their office. VRChat publicly stated it had no reason to believe its systems were compromised and that the notice was submitted on fake letterhead using the name of a person who does not exist. A separate hoax filing claimed a Discord breach affecting 10 million users. After conversations with VRChat, the AG’s office confirmed the notices were false, removed them, and said it had no knowledge of any recent legitimate breach reports from either company. The office said it is reviewing its procedures to make such abuse less likely while preserving public access, and that the public database will remain offline in the interim; organizations that need to file a report can still do so through the AG’s online reporting service.
- AI Booking Agent Exploits Gym Software, Bumps Another Member Off the Waitlist: In another example of AI going rogue, Australian news outlet ABC reported that an Australian man asked his AI assistant to book a morning gym class, and the agent exploited a vulnerability in the booking software to reserve classes months in advance, something the gym does not even allow. According to the news story, the agent also reported that the booking API had zero authorization checks on cancelling other people’s reservations, tested this against the person in the first waitlist position, and moved its user up the queue.
- CISA Publishes Insights From Two Red Team Assessments: On Aug. 25th, the Cybersecurity and Infrastructure Security Agency (CISA) published “A Tale of Two SOCs: Insights from Two Red Team Assessments,” reporting on red team assessments that it performed on two different critical infrastructure organizations. In both assessments, the red team was able to achieve full domain compromise and access sensitive business systems and cloud resources. In one target, the red team remained undetected after gaining initial access to multiple workstations, elevating privileges over the domain, and moving laterally to other systems and resources. In the second target, the red team’s access was detected and quarantined. The advisory provides details about the red team’s activities and the defensive actions by each of the targets. It also explores lessons learned from the simulated attacks and responses and mitigation measures to strengthen protection, detection, and response.
Regulatory:
- New Update to California’s Deletion Act: As of Aug. 1st, data brokers are required to access the Delete Request and Opt-Out Platform (“DROP”) and process deletion requests. DROP allows consumers to submit one deletion request rather than submitting to individual brokers. As of Aug. 25th, over 500,000 California residents have signed up.
- CalPrivacy Announces Audit Division: This August, the California Privacy Protection Agency (“CPPA”) announced the formation of an Audits Division that will proactively “look under the hood” of businesses’ privacy and cybersecurity practices. The division will employ technologists who can translate complex technical information into terms auditors can evaluate. The initiative is designed to function much like a health inspector’s review of restaurant safety, allowing the CPPA to assess practices before problems arise.
- HHS Releases Cybersecurity Assessment Tool for Healthcare Facilities: HHS’s Administration for Strategic Preparedness and Response (ASPR) has released a 2026 Health Care Facility-Level Cybersecurity Assessment intended to help hospitals and other health care facilities evaluate their cybersecurity posture and preparedness for cyber disruptions. The voluntary assessment addresses core controls such as network segmentation, multifactor authentication, access management, vulnerability testing, third-party risks, backups, incident response planning, downtime communications, system restoration priorities, and cyber insurance. It also emphasizes that information generated through the assessment may itself be highly sensitive and should be de-identified before being shared with health care coalitions or other outside parties. Although the tool is not intended for regulatory oversight or scoring, it provides health care organizations with a practical framework for identifying gaps and documenting preparedness. Health care entities may want to use the assessment as part of periodic security risk reviews, tabletop exercises, vendor oversight, and business continuity planning.
International Updates:
- Brazil’s ANPD Fines ByteDance $30 Million for Unlawful Processing of Minors’ Personal Data: Brazil’s National Data Protection Authority (“ANPD”) recently fined ByteDance, TikTok’s parent company, approximately BRL 153.7 million (nearly $30 million) for alleged violations of Brazil’s General Data Protection Law (“LGPD”) involving the processing of children’s and adolescents’ personal data. ANPD found that TikTok processed data belonging to minors without an adequate legal basis and failed to implement sufficient safeguards to prevent such processing, including through both registered accounts and guest-access features. In addition to the monetary penalty, ByteDance was ordered to delete certain unlawfully collected data and implement a compliance plan designed to strengthen protections for children and adolescents on the platform, including enhanced privacy controls and parental oversight measures. The enforcement action reflects increasing global regulatory scrutiny of online platforms’ collection and use of minors’ personal information and serves as a reminder that organizations must ensure they have an appropriate legal basis for processing personal data, particularly where children and adolescents are involved.
- EU AI Act – New Obligations Now in Effect: The EU AI Act became broadly applicable on Aug. 2nd, and the Article 50 transparency obligations took effect on schedule, imposing direct duties on providers and deployers of chatbots, synthetic-media generators, emotion-recognition systems, and deepfake tools, regardless of whether the system is “high-risk”. From the same date, the EU AI Office’s enforcement powers over general-purpose AI providers became operational. National market surveillance authorities can enforce the core Article 50 transparency and disclosure duties from that date. The Article 50 transparency obligations essentially require that any AI systems interacting with natural persons are clear and upfront such that those natural persons are aware what they are interacting with (unless it is abundantly obvious). Similarly, the generation of synthetic audio, image, video or text content shall carry a requirement to disclose that it has been artificially generated or manipulated.
- Scams Cost €760m in Ireland During 2025: Recently released research has indicated that the Irish public lost a total of circa €760m to scams in 2025 with the average scam loss per person being €890. The findings, announced by Ekco cybersecurity, were based on findings from 1,000 people surveyed. Top of the list of scams was fake customs charges (nearly 50%). Next in line was “payment verification” scams followed by motorway toll charges. 96% of those survyed were targeted by a scam or phishing attempt within the last year.
- NHS England Clarifies When Healthcare Personnel May Access Patient Records: NHS England updated its guidance concerning unlawful access to health and care records, providing additional detail regarding when healthcare personnel may appropriately access patient information for purposes beyond direct patient care. The revised guidance explains that authorized access may extend to activities such as resolving complaints, conducting patient-safety investigations, responding to legal actions, morbidity and mortality reviews, clinical audits and quality-improvement activities, education and training, and operational support for care. At the same time, NHS England emphasizes that accessing records based solely on personal curiosity or for other non-work purposes is unlawful and may result in employment, professional, and criminal consequences. The guidance also stresses role-based access, limiting access to information reasonably necessary for the applicable purpose, and monitoring electronic access logs for unusual activity. Although directed to healthcare organizations in England, the guidance reflects broader privacy principles relevant to healthcare organizations globally, particularly with respect to workforce access controls, auditing, and minimum-necessary access to patient information.
This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author only and are not necessarily the views of Clark Hill PLC. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.