Legal & Privacy Brief · 2026-06-18 · 16 min
Key moments - from our scoring
Substance score
29 / 100
Five dimensions, 20 points each
Section 702 surveillance authority lapsed on June 13, 2026, marking the first FISA expiration since Snowden's 2013 revelations - triggered by President Trump's refusal to support renewal unless Congress passed his Save America Act voting bill. Democrats blocked reauthorization after Trump nominated Bill Polt as acting Director of National Intelligence, fearing weaponization against political opponents. Meanwhile, the Third Circuit tightened class action fee awards in BMW defect litigation, vacating a $3.7 million counsel fee for the second time and restricting Lodestar multipliers. The EFF warned that IETF cryptographic authentication standards for web crawlers threaten researchers, archivists, and journalists by enabling sites to block automated access. Additional developments include Willow TV's $850,000 privacy settlement, Amazon Ring biometric data litigation, 7-Eleven data breach class actions, and expanding federal AI use cases (up 70% under Trump). Legal departments, tech companies, and platforms should monitor 702 renewal negotiations, prepare for heightened fee petition scrutiny, implement explicit biometric consent mechanisms, and engage IETF processes on web scraping standards.
President Trump tied Section 702 renewal to passage of his Save America Act voting bill, which lacked sufficient congressional votes. Democrats blocked reauthorization after Trump nominated Bill Polt as acting Director of National Intelligence, citing concerns he would weaponize 702 powers against political opponents. Trump refused to support renewal without the Save America Act, causing the authority to lapse on June 13, 2026.
The Third Circuit vacated a $3.7 million fee award, holding that Lodestar multiplier enhancements cannot be justified by risk of non-payment, case complexity, or counsel skill - factors already reflected in baseline Lodestar calculations or available only in rare circumstances. The court also found over 80% of 2,877 claimed hours billed at partner rates 'startling and inadequately justified.'
The EFF warns that IETF proposals for cryptographic bot authentication would enable websites to restrict crawling to pre-approved lists, effectively closing the open Internet to researchers, journalists, archivists, and investigators while potentially allowing sites to require licensing payments for automated access.
Companies must obtain explicit written consent under state biometric privacy statutes like Illinois BIPA and Texas CUBI before collecting facial scans or fingerprints. Compliance requires clear disclosure in device documentation and privacy policies, and opt-in mechanisms rather than buried terms of service provisions.
Australia banned users under 16 with fines up to $32 million USD; the UK requires age checks under the Online Safety Act; Indonesia deactivated under-16 accounts starting March 28, 2026; Malaysia plans to ban under-16 users with penalties up to $2.5 million USD; and Brazil approved age verification requirements for risky products and services.
Our reviewer’s read on each dimension, with quotes from the episode.
The briefing packs a high number of stories into 16 minutes but each topic gets only 2-3 sentences of substance before pivoting to generic compliance bullets. A few items - the 702 political mechanics and the lodestar multiplier ruling - offer real practitioner value, but most compliance actions are boilerplate and non-obvious insight per minute is diluted by repetitive templated structure.
The court also found that over 80% of 2,877 claimed hours were billed at partner rates, a uh proportion the court described as startling and inadequately justified
the Office of Management and budget disclosed 3,611 active or planned AI use cases across the federal government, a 70% increase from the Biden Administration's final year
This is a pure news digest format with zero original analysis, no contrarian framing, and no first-principles reasoning. Every compliance recommendation follows an identical templated pattern across all 10+ stories, and there is no editorial voice distinguishing the host's synthesis from simple paraphrasing of source articles.
Review subscription service privacy policies and data collection practices. Ensure explicit consent mechanisms are in place before collecting or sharing user data with third parties
Compliance companies deploying facial recognition or biometric technologies must obtain explicit written consent under statutes like Illinois bepa, the Biometric Information Privacy Act, Texas cubi, and similar state laws
There are no guests whatsoever - this is a single narrator reading a structured newsletter aloud. No practitioner expertise is demonstrated through dialogue, no seniority is established, and there is no evidence of anyone having actually done anything at scale being interviewed.
That concludes today's legal and privacy brief from Carolina Cleartech for informational purposes only, not legal advice
Specificity is the format's clear strength: the episode is dense with case numbers, citation strings, dollar figures, named statutes, specific dates, and named companies, giving a practitioner real reference points. The weakness is that these specifics are sourced wholesale from the underlying articles rather than analysed or contextualised.
The district court improperly enhanced the lodestar based on risk of non payment case complexity and counsel skill factors already subsumed in the baseline lodestar or available only in rare and exceptional circumstances
Australia banned users under 16 from social media accounts with platforms facing fines up to $32 million USD for non compliance
There is no conversation in this episode - it is a solo monologue structured as a read-aloud newsletter. There are no questions, no guests, no follow-ups, no pushback, and no dialogue of any kind, making this dimension essentially inapplicable.
Legal and Privacy Brief for June 18, 2026 Section 702 surveillance authority expired after Trump tied renewal to his election bill
Computed from the transcript - who did the talking, and the words that came up most.
Show Notes - 2026-06-18 Stories Covered: - Today: - Willow TV $850,000 Privacy Settlement ( - Third Circuit Vacates $3.7 Million Class Counsel Fee (Gelis v. BMW of N. Am., LLC, No. 24-2721) ( - 7-Eleven Data Breach Class Actions ( - Amazon Ring Biometric Data Class Action ( - Roy Moore Emergency Application on $8.2 Million Defamation Award ( - Supreme Court Immigration Detention Attorneys' Fees Case (Montoya Palacios v. Liggins) ( - FISA Section 702 Surveillance Authority Expires ( - EFF Warns IETF Proposals Threaten Open Web Access ( - Global Age Verification Mandates Expand ( - Figma AI Training Data Investigation ( - NO FAKES Act Threatens Satire and Commentary ( - FCC Chairman Carr Targets ABC Over Equal Time Rule ( - Federal AI Use Cases Expand 70% Under Trump Administration ( Full brief:
Transcribed and scored by The B2B Podcast Index.
Speaker A: Legal and Privacy Brief for June 18, 2026 Section 702 surveillance authority expired after Trump tied renewal to his election bill, creating the first FISA lapse since Snowden exposed the program in 2013. The 3rd Circuit vacated a $3.7 million class council fee for the second time in a BMW defect case, tightening limits on Lodestar multipliers. EFF warned that IETF proposals to cryptographically authenticate Web crawlers could close off the open Internet to researchers and archivists. Here's the full breakdown of today's top legal and privacy stories. Legal and Privacy Brief 2026 0618Next Section Enforcement Actions Willow TV $850,000 Privacy Settlement Willow TV agreed to pay $850,000 to settle a class action alleging privacy violations. Settlement provides compensation to users whose data was allegedly collected or shared without proper consent. Class members who purchased or used Willow TV services during the class period may qualify for payment from the settlement fund. Review subscription service privacy policies and data collection practices. Ensure explicit consent mechanisms are in place before collecting or sharing user data with third parties. Top Class Actions Next Section Litigation Updates 3rd Circuit vacates $3.7M class council fee BMW of N M M LLC no. 24 2,721 the 3rd Circuit vacated a $3.7 million fee award to class council for the second time in a consumer class action alleging defective BMW timing chains. The court held that limits from Purdue v. Kenny A xrel win559U.S.542, 2010On fee enhancements apply equally to contractual fee shifting cases and common fund cases. The district court improperly enhanced the lodestar based on risk of non payment case complexity and counsel skill factors already subsumed in the baseline lodestar or available only in rare and exceptional circumstances. The court also found that over 80% of 2,877 claimed hours were billed at partner rates, a uh proportion the court described as startling and inadequately justified. Compliance action Legal departments negotiating class action settlement agreements should expect closer judicial scrutiny of fee petitions, ensure billing records, provide granular detail, and justify staffing allocations. Budget for multiple fee review rounds if District court approves multipliers based on factors perdue deems already reflected in lodestar calculations. Source Inside Class Actions 711 Data Breach Class Actions Two separate class actions accuse 711 of failing to adequately protect customer personally identifiable information during an April 2026 data breach. Lawsuits allege that the convenience store chain's inadequate security measures allowed unauthorized access to customer PII, violating state data protection statutes and creating risk of identity theft and fraud for affected consumers. Retail organizations should audit point of sale systems and customer databases for security gaps, implement multi factor authentication, encrypt customer data at rest and in transit, and review incident response plans to ensure rapid breach notification compliance Sources Top Class Actions Amazon Ring Biometric Data Class Action A class action accuses Amazon's ring security cameras of violating privacy rights by collecting facial recognition data without user consent. The lawsuit alleges that ring cameras capture and process biometric identifiers in violation of state biometric privacy statutes, which require express written consent before collecting fingerprints, facial scans, or other biometric data. Compliance companies deploying facial recognition or biometric technologies must obtain explicit written consent under statutes like Illinois bepa, the Biometric Information Privacy Act, Texas cubi, and similar state laws. Review device documentation and privacy policies to ensure clear disclosure of biometric data collection. Implement opt in mechanisms rather than relying on buried terms of service provisions. Source Top Class Actions Roy Moore Emergency application on $8.2 million Defamation award Former Alabama Chief Justice Roy Moore filed an emergency application with the Supreme Court, asking the justices to block the 11th Circuit's ruling reversing his $8.2 million jury award from going into effect. Moore sued Senate Majority PC for a 2017 campaign advertisement he claims falsely portrayed him as soliciting sex from a 14 year old girl. Uh, a jury found the PAC published the statement with actual malice under New York Times v. Sullivan, but the 11th Circuit threw out the verdict. Moore argues that if the mandate issues and the bond is released before the Supreme Court can review the case, he will lose the jury award. As a practical matter, Justice Clarence Thomas has not yet instructed the PAC to respond. Sources BLAG Supreme Court Immigration Detention Attorney's Fees Case Montoya Palacios v. Ligons the Supreme Court is considering whether attorneys who successfully challenge immigration detention through habeas corpus petitions can recover fees under the Equal Access to Justice Act. Circuits are split the 4th and 5th circuits hold that habeas is a hybrid criminal civil proceeding not covered by EJA, while the second, third and 10th circuits consider habeas a civil lawsuit eligible for attorney's fees. Kevin Isaac Montoya Palacios, an El Salvadoran citizen granted withholding from removal, was detained by ICE in December 2025 and and quickly won a habeas petition securing his release. The district court denied attorneys fees under the 4th Circuit's precedent. A Solicitor General also asked the justices to resolve the circuit split compliance action. Immigration Legal services organizations should monitor this case closely. If the court holds that EJA does not cover habeas immigration cases, expect a dramatic reduction in attorneys willing to take detention challenges on a contingency basis, potentially leaving detained migrants without representation. Skatu? S Blog Next Section Regulatory guidance visa section 702 surveillance authority expires the government section 702 surveillance authority lapsed on June 13, 2026, after President Trump tied renewal to his Save America act voting bill. Section 702 allows the NSA to collect communications to and from foreign targets, including communications, bio and to Americans. The FBI has historically used backdoor searches to query these communications, effectively spying on Americans without a warrant. Democrats blocked renewal after Trump nominated Bill Polt as acting director of National Intelligence, fearing Polt would weaponize 702 powers against political opponents. Trump then refused to support renewal unless Congress passed his Save America act, which lacks sufficient votes. The lapse marks the first time the surveillance authority has expired since Edward Snowden exposed the program in 2013. Compliance technology companies subject to FISA orders should consult legal counsel on whether existing 702 collection obligations remain in force during the lapse, monitor congressional negotiations on renewal and prepare for potential emergency reauthorization with or without reforms. Tech Dirt Next Section Privacy Developments EFF Warns IETF Proposals Threaten Open Web Access the Electronic Frontier foundation warned that Internet Engineering Task Force proposals to control web crawling and scraping threaten to close off the open Internet to researchers, journalists and archivists. The AI Preferences Working Group is developing preference signals that would allow websites to block crawling for AI related purposes through robots. Txt Potentially with legal force in some jurisdictions, the Web Bot Auth Working Group is pursuing standards that would enable sites to cryptographically identify bots and restrict crawling to a pre approved list of authenticated entities. EFF argues these proposals would give website operators veto power over accessibility tools, investigative journalism, archival preservation and research efforts. Sites could require licensing payments for automated access, effectively monetizing Internet access and locking out startups and nonprofits. Organizations relying on web scraping for competitive intelligence, price monitoring, accessibility tools or research should engage in the IETF Comment process, document legitimate use cases for automated access, and prepare alternative data collection strategies if cryptographic authentication requirements are adopted. EFF Deep Links Global Age Verification Mandates Expand Governments in Australia, the United Kingdom, Indonesia, Malaysia and Brazil have implemented or proposed age verification mandates requiring platforms to verify user ages before allowing access to social media. Australia banned users under 16 from social media accounts with platforms facing fines up to $32 million USD for non compliance. The UK's Online Safety act requires platforms to assess harmful content and implement age checks. Indonesia deactivated accounts of users under 16 on high risk platforms starting March 28, 2026. Malaysia plans to ban users under 16 from platforms with at least 8 million users in Malaysia, with penalties up to $2.5 million. USD Brazil approved a UH law requiring age checks for products and services offering risks to underage users. Compliance Action Platforms operating in multiple jurisdictions must implement age verification systems compliant with each country's requirements. Consider privacy preserving age verification technologies that minimize data collection. Document age assurance methodologies to demonstrate reasonable steps in jurisdictions with safe harbor provisions. Budget for legal challenges to unconstitutional mandates Source Tech Dirt FIGMA AI Training Data Investigation A lawsuit investigation is underway for FIGMA users whose account data or content may have been used for AI training without consent. The investigation examines whether figma's use of customer designs and files to train generative AI models violates user agreements, privacy policies, or state laws requiring consent for commercial use of personal data compliance. SaaS, providers and cloud platforms should review terms of service and privacy policies to ensure explicit disclosure of AI training data use. Implement opt in consent mechanisms for using customer content to train models. Provide clear data retention and deletion policies that apply equally to training datasets. Source Top Class Actions Next section Policy changes no Fakes Act Threatens Satire and Commentary the Electronic Frontier foundation and a coalition of civil society groups urged the Senate Judiciary Committee not to advance the no Fakes act, which would create a new federal likeness right ostensibly targeting AI generated impersonations. The bill imports the worst features of the DMCA notice and takedown system into a broader range of online expression. Platforms face penalties up to $750,000 per work for failing to remove content after receiving complaints. With no safe harbor for judgment calls about whether content is satire, parody, commentary or news, the bill allows individuals to license or transfer their likeness rights to others, meaning background actors or ordinary platform users who sign releases or click through terms of service could lose control of their own face and voice for years with federal enforcement behind it. Compliance action Content platforms should prepare for DMCA style takedown procedures for likeness claims if no Fakes advances. Review moderation policies to account for subjective determinations about satire and parity. Legal departments should assess exposure to $750,000 per work penalties for hosting user generated content featuring recognizable voices or faces. EFF Deep Links FCC Chairman Carr Targets ABC over Equal Time Rule FCC Chairman Brendan Carr launched an investigation into ABC's the View for alleged equal time rule violations after the show hosted Texas Senate candidate James Talarico. Carr claims Disney owned affiliates failed to file required equal time paperwork. Though the FCC granted the View, uh, a bona fide news exemption in 2002, Disney filed a petition for declaratory ruling that the View did nothing wrong hiring Paul Clement and Jennifer Tatel to represent the company. The equal time rule applies only to broadcast license holders and requires equal airtime for competing political candidates, but exempts bona fide newscasts and news interviews. Public comments on the investigation are due within one week. Broadcast affiliates should review equal time exemption policies and consult FCC guidance on bona fide news programs. File public comments opposing cars Investigation by the deadline to establish a record that the public opposes retaliatory enforcement actions against protected speech. Tech Dirt Federal AI use cases expand 70% under Trump administration the Office of Management and budget disclosed 3,611 active or planned AI use cases across the federal government, a 70% increase from the Biden Administration's final year. Uses include HHS hiring Palantir to scan grant applications for ideological alignment the Federal Bureau of Prisons developing AI to assess inmate misconduct potential before any wrongdoing occurs the Department of Veterans affairs using AI to assess suicide risk on crisis line calls the Department of Energy testing to autonomously control nuclear reactors. The State Department ended a program using AI to forecast mass civilian killings. The disclosures carry minimal information and lack context necessary to understand purpose and approach. Only one of the cited use cases proposes public consultation compliance action. Federal contractors developing AI systems for government agencies should document validation methodologies, bias testing, and safety certifications. Prepare for public scrutiny of high risk use cases involving detention, benefits, adjudication, and life safety systems. Monitor OMB's GitHub account for new disclosures and common opportunities. Schneier on security compliance takeaways FISA 702 laps monitor congressional negotiations on section 702 renewal technology companies should consult legal counsel on whether existing FISA collection obligations remain in force during the lapse and prepare for potential emergency reauthorization. Class Action Fee Scrutiny Legal departments should expect closer judicial review of class counsel fee petitions following the Third Circuit's Geli's ROMAN II decision. Ensure billing records provide granular detail and justify staffing allocations, particularly partner heavy billing. Biometric Privacy Companies deploying facial recognition or biometric technologies must obtain explicit written consent under state biometric privacy statutes Review device documentation and privacy policies to ensure clear disclosure and implement opt in mechanisms. Age Verification Mandates Platforms operating in Australia, uk, Indonesia, Malaysia, or Brazil must implement jurisdiction specific age verification systems. Consider privacy preserving age verification technologies and document age assurance methodologies to demonstrate reasonable steps. Web scraping standards organizations relying on Web scraping for legitimate purposes should engage in IETF comment processes on the AI preferences and Web bot auth proposals. Prepare alternative data collection strategies if cryptographic authentication requirements are adopted. Generated 20260618 sources 29 articles from 13 legal and regulatory feeds. That concludes today's legal and privacy brief from Carolina Cleartech for informational purposes only, not legal advice.