<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.eff.org/rss/updates.xml" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Deeplinks</title>
    <link>https://www.eff.org/rss/updates.xml</link>
    <description>EFF&#039;s Deeplinks Blog: Noteworthy news from around the internet</description>
    <language>en</language>
     <atom:link href="https://www.eff.org/rss/updates.xml" rel="self" type="application/rss+xml" />
      <item>
    <title>📍 The Sneaky Code Tracking App Users | EFFector 38.15</title>
    <link>https://www.eff.org/deeplinks/2026/08/sneaky-code-tracking-app-users-effector-3815</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Your location isn&#039;t just a pin on a map—it can expose some of the most intimate details about your life. The value of this information to advertisers and others has turned the location data business into a multi-billion dollar industry. In &lt;a href=&quot;https://eff.org/effector/38/14&quot;&gt;our latest EFFector newsletter&lt;/a&gt;, we&#039;re covering a new EFF report on how ad libraries encourage apps to leak user location data—potentially without app developers themselves even realizing it.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.eff.org/effector/&quot;&gt;JOIN OUR NEWSLETTER&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For over 35 years, &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFFector&lt;/a&gt; has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers what &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/too-little-too-late-flock-admits-their-technology-needs-reforms&quot;&gt;recently announced Flock reforms&lt;/a&gt; actually do, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/senate-should-reject-kosas-privacy-risks&quot;&gt;privacy-invasive legislation&lt;/a&gt; advancing in the Senate, and &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy&quot;&gt;an EFF investigation into mobile ad software&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Prefer to listen in? EFFector is now available on all major podcast platforms. This time, we&#039;re covering EFF&#039;s new report on mobile ad libraries and chatting with EFF Executive Director Nicole Ozer about how digital rights have become fundamental to our lives. You can find the episode and subscribe&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://effector.simplecast.com/&quot;&gt;on your podcast platform of choice&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: 70px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2Fbaf87477-9c26-4b51-8f00-b0465a2606d1%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/baf87477-9c26-4b51-8f00-b0465a2606d1?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/6Q48ICplENdQ4ZarUIgfLZ&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effector/id1882562931&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.com/podcasts/83be1062-f511-47b3-bd2b-fc44e831c3ad&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feeds.eff.org/effector&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Want to protect your right to digital privacy? Sign up for &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFF&#039;s EFFector newsletter&lt;/a&gt; for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you &lt;a href=&quot;https://eff.org/join&quot;&gt;support EFF today&lt;/a&gt;!&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 19 Aug 2026 16:35:30 +0000</pubDate>
 <guid isPermaLink="false">112267 at https://www.eff.org</guid>
 <dc:creator>Hudson Hongo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/effector-green-web.png" alt="" type="image/png" length="78242" />
  </item>
  <item>
    <title>Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230</title>
    <link>https://www.eff.org/deeplinks/2026/08/ninth-circuit-ruling-will-force-online-platforms-host-user-speech-fight-lengthy</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;A federal appeals court just made it harder for online services, big and small, to get lawsuits over user speech dismissed early. In &lt;a href=&quot;https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/10/24-7032.pdf&quot;&gt;&lt;em&gt;California v. Meta&lt;/em&gt;&lt;/a&gt;, a Ninth Circuit three-judge panel held that the lower court’s denial of Section 230 immunity to Meta is not immediately appealable. The misguided ruling has the potential to have widespread impact and to threaten the free speech of all internet users.&lt;/p&gt;
&lt;p&gt;The ruling is bigger than a loss for Meta, which has the resources to defend itself against these lawsuits. The court’s ruling signals that all online services (and internet users) that host others’ speech—including those without Meta’s deep pockets—must bear the burden and expense of fighting lawsuits that Section 230 ultimately precludes. This will have real consequences, incentivizing online services to take down users’ speech in response to spurious legal threats, filter speech preemptively, or simply stop offering a place for people to speak online. So even though some may think that Meta is not a sympathetic company, the ruling should raise concerns for anyone who cares about an open and free internet.&lt;/p&gt;
&lt;h4&gt;Immunities from Suit Advance Important Public Interests&lt;/h4&gt;
&lt;p&gt;A little procedural background is necessary to understand the implications of the Ninth Circuit’s ruling.&lt;/p&gt;
&lt;p&gt;Meta had moved to dismiss a group of social media addiction cases brought by state attorneys general, school districts, and local governments. Meta argued that &lt;a href=&quot;https://www.law.cornell.edu/uscode/text/47/230&quot;&gt;Section 230(c)(1)&lt;/a&gt; immunity applies because the plaintiffs’ claims, framed as seeking to hold Meta liable for allegedly harmful &lt;em&gt;platform features&lt;/em&gt;, really seek to hold the company liable for publishing decisions related to &lt;em&gt;third-party content&lt;/em&gt;. Section 230 is one of the &lt;a href=&quot;https://www.eff.org/issues/cda230&quot;&gt;most important laws&lt;/a&gt; supporting online free speech, because its protections for online services enable them to distribute users’ speech at an unprecedented scale.&lt;/p&gt;
&lt;p&gt;The district court ruled that Section 230 does not apply to certain features (and does apply to others) and so denied the motion to dismiss on the claims related to those features. Meta immediately appealed invoking appellate jurisdiction under &lt;a href=&quot;https://www.law.cornell.edu/uscode/text/28/1291&quot;&gt;28 U.S.C. § 1291&lt;/a&gt;, but the question before the Ninth Circuit was whether the appeal was legally appropriate.&lt;/p&gt;
&lt;p&gt;Under Section 1291, U.S. circuit courts generally only have jurisdiction to hear appeals of “final decisions” from the district courts. Final decisions are trial court orders ending a case, or come after a trial on the merits. &lt;span&gt;Section 230 appellate cases often arise from a district court’s &lt;em&gt;grant&lt;/em&gt; of a defendant platform’s motion to dismiss the plaintiff’s case based on Section 230. T&lt;/span&gt;ypically, a district court’s &lt;em&gt;denial&lt;/em&gt; of a defendant’s motion to dismiss is not a final order—it simply means that the case may continue to discovery and summary judgment or trial, after which time an appeal would be appropriate.&lt;/p&gt;
&lt;p&gt;However, federal law allows for “interlocutory appeals,” which are appeals of orders that do not end a case but nonetheless are allowed because they involve important legal issues. For example, &lt;span&gt;there is an exception to Section 1291 called the “collateral order doctrine”—at issue in this case—allowing for immediate appeal if, as the Ninth Circuit explained here, “&lt;/span&gt;holding a trial would &lt;span&gt;imperil a substantial public interest.” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Inherent in the collateral order doctrine is the consideration of whether an immunity like Section 230 provides mere “immunity from liability” or a more robust “immunity from suit.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;An &lt;/span&gt;&lt;span&gt;i&lt;/span&gt;&lt;span&gt;mmunity from liability does not require an immediate appeal and so demands that Section 1291’s final order rule be followed. That’s because waiting until the end of a case before an appellate court can consider the trial court’s denial of immunity does not prejudice the defendant. The appellate court may overturn the trial court and grant the immunity, and thus the defendant’s right to be immune from liability would be vindicated on appeal.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Immunity from suit is different. It means that the public interest demands that a defendant be able to get out of a case as early as possible and avoid having to litigate the case to the end. The U.S. Supreme Court has held, for example, that &lt;/span&gt;&lt;a href=&quot;https://supreme.justia.com/cases/federal/us/472/511/#opinions&quot;&gt;qualified immunity&lt;/a&gt;&lt;span&gt; is such an immunity, and that a district court’s denial of qualified immunity for a government official is immediately appealable under Section 1291, notwithstanding the lack of a final order. The idea is that the public interest is served when government officials are free to act without fear of consequences when &lt;/span&gt;&lt;a href=&quot;https://www.law.cornell.edu/wex/qualified_immunity&quot;&gt;established rights are not implicated&lt;/a&gt;&lt;span&gt;, and so determining as soon as possible whether their acts are immune serves that public interest. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Here, the Ninth Circuit held that the district court’s denial of Section 230 immunity for Meta was not immediately appealable under Section 1291’s collateral order doctrine because the immunity is &lt;em&gt;not from suit&lt;/em&gt;, but rather from &lt;em&gt;ultimate liability&lt;/em&gt;. The panel’s absurd result contravenes the text of Section 230, the statute’s policy goals, and the court’s own prior rulings.&lt;/p&gt;
&lt;h4&gt;Treating Section 230 as an Immunity from Suit Protects Online Free Speech&lt;/h4&gt;
&lt;p&gt;Meta rightly argued that Section 230(e)(3) plainly states, “No &lt;strong&gt;cause of action may be brought&lt;/strong&gt; &lt;strong&gt;and no liability may be imposed&lt;/strong&gt; under any State or local law that is inconsistent with this section.” The panel dismissed this argument, stating that this language likely amounts to “redundancy” reflecting &lt;em&gt;only&lt;/em&gt; immunity from liability. The court failed to side with the more reasonable position that statutory language should generally not be interpreted as &lt;a href=&quot;https://www.congress.gov/crs-product/IF12992&quot;&gt;superfluous&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Meta also reminded the panel that the Ninth Circuit has many times over the past two decades framed Section 230 as &lt;em&gt;both&lt;/em&gt; an immunity from liability and an immunity from suit. The panel also dismissed this argument, stating, “It is true that we have &lt;span&gt;used the phrase ‘immunity’ somewhat loosely in our section 230 jurisprudence.” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;But “loosely” is a gross mischaracterization—the panel did not discuss a seminal prior ruling, &lt;a href=&quot;https://scholar.google.com/scholar_case?case=7987071093240934335&quot;&gt;&lt;em&gt;Fair Housing Council of San Fernando Valley v. Roommates.com&lt;/em&gt;&lt;/a&gt; (2008), in which the entire Ninth Circuit, not just a three-judge panel, explicitly ruled that Section 230 is also an immunity from suit. That court rightly explained that Section 230 “must be interpreted to protect websites not merely from ultimate liability, but from having to fight costly and protracted legal battles.”&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Why is it important that social media platforms and other internet intermediaries (and their users) have immunity from suit for engaging in publishing activities related to third-party content—and thus a right to immediately appeal when Section 230 immunity is denied?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The Ninth Circuit panel here, using their own words, failed to “&lt;span&gt;evaluate the interests that would be lost through rigorous application of a final judgment requirement” and failed to consider the “substantial public interest” served by treating Section 230 as an immunity from suit.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Section 230 immunity, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2020/12/section-230-good-actually&quot;&gt;contrary to what some argue&lt;/a&gt;&lt;span&gt;, is not a gift to Big Tech—it applies to all internet intermediaries, big and small, from the large social media companies to smaller entities like community message boards and local ISPs. It even protects internet users who forward others’ emails or host comments on their blogs. In turn, the law supports the free speech of all internet users.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;While it is helpful when an internet intermediary can ultimately benefit from Section 230 immunity, if a trial court’s early denial is not immediately appealable, that means the intermediary must bear the extended logistical and financial burdens of defending itself. Under the Ninth Circuit’s logic, anyone hosting others’ speech online would have to endure the pain and expense of discovery, summary judgment, or trial, before they ultimately can be protected by Section 230.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Congress crafted Section 230 to give internet intermediaries legal breathing room, so that they will be incentivized to facilitate online communication and commerce, allowing the rest of us to go online with minimal barriers to entry, without needing to have lo&lt;/span&gt;&lt;span&gt;ads of money or to know how to code. Congress acknowledged in Section 230 itself, “&lt;/span&gt;Increasingly Americans are relying on interactive media for a variety of political, educational, cultural, and entertainment services.”&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Yet if platforms, especially smaller platforms, know that they will have to defend themselves for years in court before they can ultimately benefit from Section 230 immunity, this alone will create a perverse incentive, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/cda230&quot;&gt;as we have explained&lt;/a&gt;&lt;span&gt;, to &lt;/span&gt;censor user speech, in order to reduce the platforms’ legal exposure.&lt;span&gt; And this incentive is only exacerbated at scale, where the sheer volume of user-generated content hosted by modern platforms makes legal risk astronomical.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Unfortunately, this opinion seems to be part of larger trend reflecting the Ninth Circuit’s increasing &lt;/span&gt;&lt;a href=&quot;https://scholar.google.com/scholar_case?case=9670009706659914865&quot;&gt;disdain&lt;/a&gt;&lt;span&gt; for Section 230, and apparently for free speech rights more broadly. The court similarly held last year in &lt;/span&gt;&lt;a href=&quot;https://scholar.google.com/scholar_case?case=9014395445447849844&quot;&gt;&lt;em&gt;Gopher Media v. Melone&lt;/em&gt;&lt;/a&gt;&lt;span&gt; (2025)—overruling itself—that a trial court’s denial of a defendant’s &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/tags/anti-slapp&quot;&gt;anti-SLAPP&lt;/a&gt;&lt;span&gt; motion also is not immediately appealable under the collateral order doctrine. This is despite the fact that, similar to Section 230, California’s &lt;/span&gt;&lt;a href=&quot;https://www.casp.net/california-anti-slapp-first-amendment-law-resources/statutes/&quot;&gt;anti-SLAPP law&lt;/a&gt;&lt;span&gt; is intended to allow defendants to get harassing lawsuits meant to silence them dismissed early, lest they be chilled from engaging in lawful speech on public issues due to the risk of being mired in litigation, even if they ultimately win a delayed appeal.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 18 Aug 2026 23:23:50 +0000</pubDate>
 <guid isPermaLink="false">112264 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/cda230">Section 230</category>
 <category domain="https://www.eff.org/taxonomy/term/72">Legal Analysis</category>
 <dc:creator>Sophia Cope</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/section-230-2d.png" alt="One person holds a megaphone for another, with rainbow stripes" type="image/png" length="323424" />
  </item>
  <item>
    <title>Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets</title>
    <link>https://www.eff.org/deeplinks/2026/08/zkps-arent-age-verification-silver-bullets</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;a href=&quot;http://www.eff.org/age&quot;&gt;&lt;span&gt;Age verification&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (laws and regulations requiring platforms and websites to assure or estimate that a user seeking to use an online service is of a certain age) is everywhere. At the time of writing, about &lt;/span&gt;&lt;a href=&quot;https://action.freespeechcoalition.com/age-verification-resources/state-avs-laws/&quot;&gt;&lt;span&gt;half the states&lt;/span&gt;&lt;/a&gt;&lt;span&gt; in the US have some internet age verification law in place, and dangerous proposals, from the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online&quot;&gt;&lt;span&gt;KIDS Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/senate-should-reject-kosas-privacy-risks&quot;&gt;&lt;span&gt;Kids Online Safety Act (KOSA),&lt;/span&gt;&lt;/a&gt;&lt;span&gt; have been advancing at the federal level. European Union member states are moving toward having age verification &lt;/span&gt;&lt;a href=&quot;https://commission.europa.eu/news-and-media/news/commission-urges-fast-rollout-age-verification-app-2026-04-29_en&quot;&gt;&lt;span&gt;in a centralized app&lt;/span&gt;&lt;/a&gt;&lt;span&gt; by the end of this year. &lt;/span&gt;&lt;a href=&quot;https://www.legislation.gov.au/C2024A00127/asmade/text&quot;&gt;&lt;span&gt;Australia famously now has one extremely broad restriction in place&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Most age verification laws &lt;/span&gt;&lt;a href=&quot;https://www.reuters.com/world/australias-teen-social-media-ban-fails-clear-first-hurdle-age-checks-says-study-2026-07-07/&quot;&gt;&lt;span&gt;tend to fail&lt;/span&gt;&lt;/a&gt;&lt;span&gt; at &lt;/span&gt;&lt;a href=&quot;https://www.theguardian.com/media/2026/jun/24/australia-under-16-social-media-ban-no-substantial-effects-study&quot;&gt;&lt;span&gt;their primary goal&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of barring kids from being online or from entering only specially designated zones, not to mention they pose a significant threat to everyone’s privacy. Some proponents of these age-based internet restrictions think they&#039;ve found the silver bullet: Zero-Knowledge Proofs (ZKPs). &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/07/zero-knowledge-proofs-alone-are-not-digital-id-solution-protecting-user-privacy&quot;&gt;&lt;span&gt;We wrote about ZKP’s&lt;/span&gt;&lt;/a&gt;&lt;span&gt; when they were first rolled out in the age verification context last year. However, more recent examples show our concerns weren’t just conjecture; ZKP-focused AV schemes are &lt;/span&gt;&lt;a href=&quot;https://www.wired.com/story/vpns-and-age-verification-laws/&quot;&gt;&lt;span&gt;gameable&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, hackable, and not the cure-all some may claim.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;ZKPs in Age Verification Would Only Centralize Power and Create More Harms&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Before we jump into how these systems work, it must be said: creating a single point of failure for internet access contradicts the very idea of a free and open internet. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The mechanisms underlying ZKPs pose an existential threat to everyone’s digital rights, not just kids. The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user&#039;s access to a service, essentially removing that person’s access to the internet entirely. Without oversight of who has authority to implement and operate these systems, this approach centralizes critical internet infrastructure in the hands of very few actors. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;How ZKPs Work&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;ZKPs are mathematically impressive cryptographic tools—but they weren’t developed with age verification in mind. Essentially, they let a computer quickly attest to the validity of a given question asked by another computer without divulging any underlying private data. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Computer A (such as the device operated by a person trying to access a website) is able to prove to Computer B (such as the server for the website that person is trying to access) that something is true without actually sharing the contents of that information itself. Computer A locks in a &quot;commitment&quot; to the information it needs to convey. Computer B, which wants to verify that information, generates mathematical &quot;challenges&quot; that can be answered correctly only if the information is true. Traditionally, this happens over many different “challenges&quot; until there is no room for doubt that Computer A’s &quot;commitment&quot; is true.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Since that kind of lengthy back-and-forth process would drastically slow things down over the internet, there&#039;s a shortened version of this exchange that&#039;s &quot;non-interactive.” In that case, the ZKP is verified instantly. The answer itself is hashed (mathematically converted into a fixed, shorter string of characters), and the resulting hash is theoretically unpredictable and tamper-resistant. This shortened version of the ZKP exchange is called &quot;zk-SNARK,&quot; which is the current preferred method for age verification.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In the ideal scenario, this means that ZKP’s are able to attest to a person’s status as an adult or a child without actually giving away any other private information about that person. In other words, only one entity would collect that private information, typically on the user’s device, instead of every website or app that needs the user’s age attested to. Unfortunately, recent real-world testing of these systems prove that ZKP’s aren’t the silver bullet that proponents of AV laws were hoping for.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;EU’s AV Rollout Reveals How Broken It Is&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;By the end of 2026, the 27 states within the European Union are expected to have infrastructure in place to do age verification within a &quot;mini-wallet&quot; app that will live inside the EUDI (European Digital Identity) Wallet. &lt;/span&gt;&lt;a href=&quot;https://citizens-initiative.europa.eu/initiatives/details/2026/000011_en&quot;&gt;&lt;span&gt;This is being met with plenty of warranted criticism from digital rights experts&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. The &quot;mini-wallet&quot; version is already being rolled out, with promises that the ZKPs are in working order. &lt;/span&gt;&lt;a href=&quot;https://docs.yivi.app/blog/eu-age-verification-security-analysis/&quot;&gt;&lt;span&gt;But recent insights show &lt;/span&gt;&lt;/a&gt;&lt;span&gt;that the ZKP features aren&#039;t yet turned on except for the closed demo/prototype build (not the version of the app people are using “out of the box”), which the vast majority of everyday users can’t access. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Worse still, a &lt;/span&gt;&lt;a href=&quot;https://xident.io/blog/eu-age-verification-blueprint-security-lessons-platform-operators/&quot;&gt;&lt;span&gt;security researcher found they could bypass the app&#039;s system&lt;/span&gt;&lt;/a&gt;&lt;span&gt; using a quickly built Chrome extension that tricked the app into repeatedly accepting the same &quot;over-18&quot; token. It did so without ever asking for fresh verification. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Over &lt;/span&gt;&lt;a href=&quot;https://csa-scientist-open-letter.org/ageverif-Feb2026&quot;&gt;&lt;span&gt;400 security researchers signed an open letter&lt;/span&gt;&lt;/a&gt;&lt;span&gt; stating that age assurance checkpoints, even if implemented with privacy in mind, would cause more harm than good. A primary focus of their concern, which we share, is the fact that a centralized identity verification system creates a single point of failure that is extremely vulnerable to both cyberattack and authoritarian overreach.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Once the &quot;mini-wallet&quot; version of this is fully integrated into the EUDI Wallet, it will replicate these same failures, perhaps more, but at a much larger scale. At that point, the failures will involve many more pieces of sensitive information that the EUDI Wallet contains: passports, driver&#039;s licenses, travel information, financial information, to name a few.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;ZKP’s Aren’t The Magic Bullet&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;As we’ve said &lt;/span&gt;&lt;span&gt;&lt;a href=&quot;https://www.eff.org/document/age-verification-harms-users-all-ages-0&quot;&gt;time and time again&lt;/a&gt;,&lt;/span&gt;&lt;span&gt; no method of online age verification is privacy-protective, fully accurate, and capable of guaranteeing universal coverage without introducing severe security risks. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Lawmakers concerned about the privacy failures of age verification mandates must understand that ZKPs are not a magic bullet. They do not solve the age verification paradox; they simply push the burden of trust down the road, relying on technical ignorance and magical thinking about how the internet actually functions.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Mandatory online age verification of any kind is a dangerously flawed idea. &lt;/span&gt;&lt;a href=&quot;https://acteff.org/&quot;&gt;&lt;span&gt;Tell your lawmakers we said so.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 18 Aug 2026 22:39:03 +0000</pubDate>
 <guid isPermaLink="false">112263 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>Daly Barnett</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  <item>
    <title>Too Little, Too Late: Flock Admits Their Technology Needs Reforms  </title>
    <link>https://www.eff.org/deeplinks/2026/08/too-little-too-late-flock-admits-their-technology-needs-reforms</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Flock Safety, the embattled vendor of mass surveillance technology, has rolled out a handful of new reforms intended to appease the justified nationwide anger that has seen &lt;/span&gt;&lt;a href=&quot;https://www.newsnationnow.com/business/tech/flock-camera-contracts-canceled-23-states/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;scores of towns&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.kare11.com/article/news/local/breaking-the-news/multiple-cities-minnesota-cancel-contracts-flock/89-bfd002b1-6830-4139-8287-cea513e602a0&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cancel or suspend&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; their contracts with the company for &lt;/span&gt;&lt;a href=&quot;https://sls.eff.org/technologies/automated-license-plate-readers-alprs&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;automated license plate readers&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; (ALPRs). The reforms are a combination of long overdue changes along with some cosmetic fixes that fail to address the fundamental dangers of this technology. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;We should not be letting companies decide how much privacy we deserve. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;So, what do these reforms actually do? &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The most consequential is Flock’s default setting of an optional 7-day retention period for ALPR data, down from its original default optional 30-day retention period. This means if police want to retain data beyond the duration of their retention setting, they need to access “Evidence Mode,” i.e., when the desired data is associated with an active investigation and not just a fishing expedition. This is significant because, in at least some circumstances, Flock has &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/flock-contract&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;previously charged&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; its customers to extend their retention period. So, while towns can likely easily flip the switch to longer retention periods, it might come with a price tag some cities will be unwilling to pay. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Flock also has two other, likely easier-to-bypass reforms. The first is offense filtering so that cities can enable other departments to access their ALPR data only if they are investigating certain crimes, e.g., murder or robbery but not immigration-related investigations. The second is supposedly beefing up their audit feature and proactively locking out officers who file suspicious requests for data. The major problem here is the fact that Flock’s enhanced audit and transparency tools help to address a problem that Flock itself has created—an abusable mass surveillance system that tracks all cars all the time. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In addition to these reforms, there is also a tone shift coming from Flock’s CEO, Garrett Langley. Langley went from calling the &lt;/span&gt;&lt;a href=&quot;https://deflock.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;DeFlock movement&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; “terrorists” (&lt;/span&gt;&lt;a href=&quot;https://ipvm.com/reports/flock-trump&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;which he has since apologized for&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;) and saying that the wave of anti-surveillance anger was &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;more about the current federal administration than it was specifically about his company&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, to a more conciliatory tone that acknowledges some of the problems of &lt;/span&gt;&lt;a href=&quot;https://www.yahoo.com/news/us/articles/wrong-person-wrong-car-innocent-165054399.html&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;dangerous surveillance&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-school-residency-verification-background&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;mission creep&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.nytimes.com/2026/08/12/us/georgia-sheriffs-flock-cameras-stalking.html&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;police abuse&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.  Just look at this &lt;/span&gt;&lt;a href=&quot;https://www.bbc.com/news/articles/crrv1rjwgl9o&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;report from the BBC&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;: &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;“Historically, my point of view as a chief executive of a private company was, I don&#039;t know if I should be making these decisions. I don&#039;t know if it&#039;s my job to say how long data should be retained,” Langley said.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;He added that he has come to agree with groups like the American Civil Liberties Union and the Electronic Frontier Foundation that police should need an active case number to search Flock&#039;s data.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;“They&#039;re right. I think it should be required.”&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;To be clear, our position has long been that police, at a minimum, &lt;/span&gt;&lt;/b&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-school-residency-verification-background&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;need to get a warrant&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, signed by a judge, in order to search for historic ALPR data regarding specific vehicles.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; For us, it’s common sense: if police want to dip into historic ALPR data like they were going back in time to retroactively follow your comings and goings, they need a warrant. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Fundamentally, these reforms leave us wondering: what is stopping Flock from reversing course on them if their law enforcement customers respond by defecting to another ALPR vendor? Nothing. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This all leads to the bigger and more important issue: We should not be letting companies decide how much privacy we deserve. If our privacy is determined by how much surveillance technology vendors decide is &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;too much surveillance&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, then we’re really out of luck. It shouldn’t be up to Flock or any other ALPR vendor to decide how long police can collect and retain data on millions, if not hundreds of millions, of innocent people. We need lawmakers to step up and pass laws that restrict police’s use of surveillance technology. After all, the surveillance business model is the problem, and a few company-imposed slapdash reforms aren’t going to change that.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-related-cases field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Related Cases:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;/cases/siren-v-san-jose&quot;&gt;SIREN and CAIR-CA v. San Jose&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 13 Aug 2026 20:52:35 +0000</pubDate>
 <guid isPermaLink="false">112260 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/mass-surveillance-technologies">Surveillance Technologies</category>
 <dc:creator>Matthew Guariglia</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/flockbanner2_davemaass_ccby.png" alt="Photograph of an automated license plate reader " type="image/png" length="161449" />
  </item>
  <item>
    <title>Who (or What) Generates Images for EFF?</title>
    <link>https://www.eff.org/deeplinks/2026/08/who-or-what-generates-images-eff</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;We’ve had a few questions from EFF supporters lately, asking whether the images we use on our blog posts, or on &lt;a href=&quot;https://supporters.eff.org/donate/join-4--wsid&quot; title=&quot;Donate to EFF&quot;&gt;donation&lt;/a&gt; and &lt;a href=&quot;https://shopeff.org/&quot; title=&quot;EFF shop&quot;&gt;shop&lt;/a&gt; items, have been created with AI image generators. We’d like to answer these questions and clarify our internal policy regarding image creation.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;EFF images are all made by human beings, not by automated image generators, with very rare exceptions. This is an internal decision made by our small design team, for the following reasons:&lt;/span&gt;&lt;span&gt; &lt;br /&gt;&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt; &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Helvetica&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Our designers bring knowledge and expertise to the images we create, informed by years of consultation with EFF’s lawyers, technologists and activists. We find that this informed perspective helps make the issues we cover more clear, and more engaging, for our supporters.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Helvetica&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;The content on our sites is written by human beings, not by bots, and we feel that the images illustrating these posts should be human&lt;/span&gt;&lt;span&gt;-&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;made as well. Our supporters come to EFF for honest, trustworthy information from expert human beings, and we want our images to communicate that authenticity as well.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Helvetica&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Aesthetic preference: our designers prefer the look, as well as the process, of images made “by hand.” It also gives us &lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;more control over the images, including producing multiple versions for different posts. While it&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt; can sometimes take a bit longer, we feel the results are more satisfactory and long-lasting. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Helvetica&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;While it is rare, it is possible for image generators to create images that are under copyright, or understood by some to be under copyright. This could conflict with our use of a Creative Commons Attribution license for all our images. By generating our own images, we avoid&lt;/span&gt;&lt;span&gt; any risk&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt; of a dispute about copyright infringement, so that we can continue our work promoting digital rights (including the right to fair use of copyrighted materials) without fear of a lawsuit.&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/08/03/eff-shirt-sketch-2.png&quot; width=&quot;1215&quot; height=&quot;634&quot; alt=&quot;EFF pencil sketch and final artwork&quot; title=&quot;EFF pencil sketch and final artwork&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;An example of EFF artwork process: sketch and final art&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;To be as clear as possible, we are now adding a small credit in the lower righthand area of each banner image that will read “Image created by EFF.” As mentioned earlier, there may be rare exceptions, when an EFF designer uses an automatically generated image as a small element in a larger illustration. In these cases, we will indicate that use with additional text, specifying the elements involved, and naming the image generator used.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;We hope that by describing our internal design thinking, we are answering the questions we are getting without confusing anyone about EFF&#039;s various and nuanced positions on the issues raised by image generators. As with past technological developments, we continue to defend the rights of technologists to develop these powerful tools, as well as the &lt;a href=&quot;https://www.eff.org/pages/ai-and-fair-use#main-content&quot; title=&quot;EFF page on AI and Fair Use&quot;&gt;right of the public&lt;/a&gt; to make legal and legitimate use of them.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; Ultimately, EFF&#039;s design team has made a choice we feel is consistent with EFF&#039;s brand and look, and it&#039;s a decision we think every user gets to make for themselves. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;And don&#039;t forget: because all of our images are &lt;a href=&quot;https://creativecommons.org/licenses/by/4.0/deed.en&quot; title=&quot;Creative Commons CC-By page&quot;&gt;CC-By&lt;/a&gt;, you are free to use, share or remix any image we create (we ask that you include a credit to EFF). If you need hi-res versions, you can find some on our &lt;a href=&quot;https://www.flickr.com/photos/electronicfrontierfoundation/&quot; title=&quot;EFF Flickr page&quot;&gt;Flickr page&lt;/a&gt;, or you can email us directly with any requests. And you can enjoy some of the art we create on gifts you receive when you donate to EFF!&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/join-4--wsid&quot; title=&quot;Donate to EFF&quot;&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Donate to EFF&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Get awesome human-generated art as a thank you gift!&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 11 Aug 2026 20:24:25 +0000</pubDate>
 <guid isPermaLink="false">112240 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <dc:creator>Hugh D&amp;#039;Andrade</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-brain-surgery-banner.jpg" alt="robot doing brain surgery on itself" type="image/jpeg" length="673377" />
  </item>
  <item>
    <title>Dismiss Church’s Trademark Lawsuit Against “Mormon Stories” Podcast, EFF Urges Court</title>
    <link>https://www.eff.org/deeplinks/2026/08/dismiss-churchs-trademark-lawsuit-against-mormon-stories-podcast-eff-urges-court</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Imagine if McDonald’s could use trademark law to control how you use the term “fast food.” Or if the Canadian government could stop you from using the word “Canada” in the title of a book about the country and its people. That wouldn’t just be absurd; it would be an unacceptable obstacle to criticism of and commentary about those institutions. Yet the Church of Jesus Christ of Latter-day Saints (the “LDS Church”) has a track record of claiming exactly that kind of authority over the word “Mormon,” using the threat of expensive litigation to pressure speakers into compliance.&lt;/p&gt;
&lt;p&gt;We at EFF have opposed the LDS Church’s abuse of trademark law for over a decade. In 2014, we filed an amicus brief when the church sued an online dating service for church members called &lt;a href=&quot;https://www.eff.org/press/releases/dating-site-fights-outrageous-trademark-claim-mormon-church&quot;&gt;Mormon Match&lt;/a&gt;. In 2016, it threatened legal action against our client the &lt;a href=&quot;https://www.eff.org/deeplinks/2016/02/not-mormonr-still-mormon&quot;&gt;Mormon Mental Health Association&lt;/a&gt;, a nonprofit association for mental health professionals who work with members of Mormon faiths. In 2025, the church tried to pressure our client Burke Sorenson into changing the name of his &lt;a href=&quot;http://eff.org/document/eff-letter-re-mormon-news-roundup&quot;&gt;Mormon News Roundup&lt;/a&gt; podcast. Now, the LDS Church has brought a &lt;a href=&quot;http://eff.org/document/complaint-intellectual-reserve-inc-v-open-stories-foundation&quot;&gt;lawsuit&lt;/a&gt; over a podcast called Mormon Stories that examines Mormonism and Mormon culture. With the help of attorneys at Ballard Spahr, EFF has filed an amicus brief in the case.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://eff.org/document/eff-amicus-brief-intellectual-reserve-inc-v-open-stories-foundation&quot;&gt;Our brief&lt;/a&gt; urges the district court to dismiss the case as soon as possible. Trademark is supposed to be about helping consumers identify the sources of the products they buy, not controlling criticism. That’s why our brief asks the court to use a test that’s more protective of speech than what’s applied in most trademark cases. This test, known as &lt;a href=&quot;https://www.eff.org/zh-hans/deeplinks/2023/03/eff-tells-supreme-court-trademark-law-doesnt-trump-first-amendment&quot;&gt;the &lt;em&gt;Rogers&lt;/em&gt; test&lt;/a&gt;, has been adopted by many courts (but not yet this one) for cases where someone is using a trademark as part of an expressive work, rather than just as a brand name. We explain to the court that the &lt;em&gt;Rogers&lt;/em&gt; test is an important First Amendment safeguard in part because it makes it easier to throw out meritless trademark claims before the most expensive parts of litigation, allowing more speakers to confidently stand up for their rights.&lt;/p&gt;
&lt;p&gt;Our brief goes on to explain that First Amendment safeguards are especially important in cases like this one, where a plaintiff is seeking to control the use of a common term for its common meaning. Trademark law isn’t even supposed to extend to generic terms, and for good reason. Otherwise, we risk giving trademark owners power to control discussion and debate over entire topics.&lt;/p&gt;
&lt;p&gt;It’s about time that a court shut down the LDS Church’s trademark bullying. We hope the court will do so here, while also taking the opportunity to endorse the &lt;em&gt;Rogers&lt;/em&gt; test.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 11 Aug 2026 00:00:30 +0000</pubDate>
 <guid isPermaLink="false">112255 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/trademark">Trademark</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Cara Gagliano</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/trademark-cans.png" alt="Cans on a shelf with Trademark symbols" type="image/png" length="20019" />
  </item>
  <item>
    <title>Meta Must Stop Silencing Reproductive Health Information</title>
    <link>https://www.eff.org/deeplinks/2026/08/meta-must-stop-silencing-reproductive-health-information</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Access to accurate information about reproductive and maternal health can be critical. But on Meta&#039;s platforms, simply talking about prescription medication, abortion care, or one&#039;s own medical experiences can be enough to trigger content removals and account restrictions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That&#039;s why EFF recently submitted a public comment to the Meta Oversight Board in its consideration of &lt;/span&gt;&lt;a href=&quot;https://www.oversightboard.com/pc/prescription-drugs-in-pregnancy-and-childbirth/&quot;&gt;&lt;span&gt;a case involving an Instagram post about prescription drugs during pregnancy&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and childbirth. The case touches upon a topic we’ve been documenting for some time; last year we collected stories from individuals who had experienced censorship of reproductive health information on various platforms. Meta in particular stood out: Its moderation systems routinely fail to distinguish between prohibited drug transactions and legitimate discussion of medications, including educational information and people&#039;s firsthand experiences with healthcare.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Through our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/stop-censoring-abortion&quot;&gt;&lt;span&gt;Stop Censoring Abortion&lt;/span&gt;&lt;/a&gt;&lt;span&gt; project, EFF collected nearly 100 submissions from healthcare providers, clinics, educators, advocates, researchers, and others whose reproductive health content had been removed or suppressed by social media platforms. What we found was alarming: systemic over-enforcement, confusing policies, arbitrary takedowns, sudden account bans, de-ranking, and appeals that too often went nowhere.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Talking About Medication Isn&#039;t the Same as Selling It&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;In almost every case we reviewed, the censored posts and accounts did not actually violate the platforms&#039; stated rules. Meta frequently cited its &lt;/span&gt;&lt;a href=&quot;https://transparency.meta.com/policies/community-standards/restricted-goods-services/&quot;&gt;&lt;span&gt;Restricted Goods and Services policy&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which prohibits attempts to buy, sell, trade, donate, gift, or request pharmaceutical drugs. But the content EFF documented overwhelmingly consisted of factual or educational information—not attempts to sell or distribute drugs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The consequences were significant. For example, the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/silencing-abortion-providers-meta#main-content&quot;&gt;&lt;span&gt;Miscarriage+Abortion Hotline&lt;/span&gt;&lt;/a&gt;&lt;span&gt; had its Instagram account restricted and posts removed even though it was providing information about legally obtaining medication rather than offering pharmaceuticals for sale. &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/when-knowing-someone-meta-only-way-break-out-content-jail#main-content&quot;&gt;&lt;span&gt;Red River Women&#039;s Clinic and the RISE reproductive health research center at Emory University&lt;/span&gt;&lt;/a&gt;&lt;span&gt; had accounts locked after posting about mifepristone.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Other users reported having their content quietly de-ranked or “shadowbanned,” limiting its reach without giving them meaningful notice or recourse. We believe educational content and people&#039;s experiences involving reproductive healthcare and medication should not be suppressed in this way.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And when Meta gets these decisions wrong, &lt;a href=&quot;https://www.eff.org/pages/when-knowing-someone-meta-only-way-break-out-content-jail#main-content&quot;&gt;the appeals process too often fails to fix them&lt;/a&gt;. In several cases EFF documented, accounts were restored only after journalists drew attention to the problem or someone with a personal connection inside Meta intervened. A moderation system shouldn&#039;t require knowing the right person to get an erroneous decision reversed.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Meta Can—and Must—Do Better&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Our submission calls on Meta to make five changes—&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/platforms-have-failed-us-abortion-content-heres-how-they-can-fix-it#main-content&quot;&gt;&lt;span&gt;the same five changes&lt;/span&gt;&lt;/a&gt;&lt;span&gt; we asked for last year.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;First, Meta should publish clear, understandable policies so users can know what content is permitted and what might result in removal, downranking, or account suspension. Second, those rules must be enforced consistently and fairly. Third, Meta must provide meaningful explanations for enforcement decisions, including what rule was violated and how users can appeal. Fourth, users need a functional appeals system that doesn&#039;t depend on insider access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Finally, Meta should expand human review. Reproductive healthcare is precisely the sort of nuanced and context-dependent subject that automated moderation systems struggle to understand. As our research shows, automated systems can mistake education for drug sales, misinterpret terminology, overlook cultural and political context, and even classify legitimate advocacy as dangerous content. Human moderators should therefore play a greater role when automated systems flag sensitive healthcare information or political expression.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Meta has chosen to allow discussion of reproductive healthcare, including abortion, on its platforms. That commitment means little if its moderation systems nevertheless prevent people from accessing or sharing that information.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;At a moment when reproductive rights are under attack around the world, the stakes are particularly high. Restricting access to essential healthcare information can have profound consequences, especially for people who already face barriers to reproductive care.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Users deserve a system in which rules aren&#039;t applied arbitrarily, appeals actually work, and vital health information isn&#039;t silenced because an automated system failed to understand its context. Meta can—and must—do better.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;You can read our comment in full below.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 10 Aug 2026 17:18:21 +0000</pubDate>
 <guid isPermaLink="false">112251 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/reproductive-justice">Reproductive Justice</category>
 <category domain="https://www.eff.org/issues/corporate-speech-controls">Corporate Speech Controls</category>
 <dc:creator>Jennifer Pinsof</dc:creator>
 <dc:creator>Jillian C. York</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/stopcensoringabortion-banner-2.png" alt="two hands holding a box of mifepristone tablets, with a sheet reading &amp;quot;access denied&amp;quot; pulled out" type="image/png" length="348746" />
  </item>
  <item>
    <title>Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction</title>
    <link>https://www.eff.org/deeplinks/2026/08/senate-vote-tomorrow-four-internet-bills-one-wrong-direction</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;The Senate Commerce Committee &lt;a href=&quot;https://www.commerce.senate.gov/meetings/executive-session-24-08-05-2026/&quot;&gt;will &lt;/a&gt;&lt;/span&gt;&lt;a href=&quot;https://www.commerce.senate.gov/meetings/executive-session-24-08-05-2026/&quot;&gt;&lt;span&gt;vote&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;a href=&quot;https://www.commerce.senate.gov/meetings/executive-session-24-08-05-2026/&quot;&gt; this week&lt;/a&gt; on several censorious and privacy invasive bills: &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/senate-should-reject-kosas-privacy-risks&quot;&gt;&lt;span&gt;KOSA&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/screen-act-threatens-privacy-far-beyond-adult-websites&quot;&gt;&lt;span&gt;SCREEN Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/youth-ai-privacy-acts-privacy-paradox&quot;&gt;&lt;span&gt;Youth AI Privacy Act,&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/chatbot-act-forces-one-parenting-model-every-family&quot;&gt;&lt;span&gt;CHATBOT Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. While we appreciate that the Committee is taking the time to look at these bills separately, it’s still impossible to ignore the message Congress is sending to the world: Age-gate the internet and block young people from speaking and accessing lawful speech online. Or else. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Tell Congress: don&#039;t age-gate the internet&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Each of these bills claims to be trying to protect children and teenagers from dangerous situations on and offline—certainly a worthy goal. But the proposed solutions in these bills are unlikely to make children and teenagers safer at all. Rather, they would create sweeping new privacy and data security problems, and force platforms to adopt unconstitutional restrictions on the content they host, for both adults and teenagers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There is a better way. Instead of considering these bills, the Senate Commerce Committee should be focusing on a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/wp/privacy-first-better-way-address-online-harms&quot;&gt;&lt;span&gt;national consumer privacy bill&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that would protect ALL internet users, or on &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/03/ban-online-behavioral-advertising&quot;&gt;&lt;span&gt;banning behavioral advertising &lt;/span&gt;&lt;/a&gt;&lt;span&gt;that tracks us across the web—again, for users of all ages. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;But the bills being considered this week move in the other direction—more information being collected, more surveillance, and less privacy for internet users of all ages. &lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;help eff oppose these bills&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF sent a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-letter-senate-commerce-regarding-concerns-screen-act-kosa-youth-ai-privacy-act-and&quot;&gt;&lt;span&gt;letter&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to the Committee with our concerns about these bills. We look forward to continuing to work with them to find a way forward that protects all users. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 05 Aug 2026 00:15:11 +0000</pubDate>
 <guid isPermaLink="false">112247 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>India McKinney</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/congress-action_0_0.jpg" alt="" type="image/jpeg" length="72345" />
  </item>
  <item>
    <title>Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA</title>
    <link>https://www.eff.org/deeplinks/2026/08/appeals-court-agrees-eff-building-web-browser-doesnt-violate-cfaa</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/comparison-shopping-not-computer-crime&quot;&gt;had sued&lt;/a&gt; Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistant” that can browse websites like Amazon for comparison shopping purposes, violated the CFAA because Amazon did not “authorize” Perplexity to access Amazon users’ accounts. Rejecting that theory, the Ninth Circuit &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/comparison-shopping-not-computer-crime&quot;&gt;held&lt;/a&gt; that Perplexity was unlikely to be liable because users operate the tool, not Perplexity.&lt;/p&gt;
&lt;p&gt;That’s the right conclusion, as both a legal and technical matter. As we explained to the court in &lt;a href=&quot;https://www.eff.org/document/brief-amici-curiae-electronic-frontier-foundation-alliance-responsible-data-collection&quot;&gt;our amicus brief&lt;/a&gt;, the CFAA requires unauthorized “access,” and Perplexity itself does not access Amazon’s servers—users of the Comet browser do. The court agreed, noting that EFF’s explanation “articulates the nature of the system most clearly.”&lt;/p&gt;
&lt;p&gt;The court noted that agentic AI may present novel legal issues, and there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.” Ultimately, though, thorny questions of AI “intent” were irrelevant to this case, because the Assistant “is a tool, not a person for statutory purposes.” And, the court concluded, it is a tool operated by users, not Perplexity. Even where Perplexity received information from users about their Amazon accounts and used this information to instruct the Assistant, the court found that that did not constitute the sort of control needed to find access by Perplexity. As the court noted, Amazon might have other viable claims against Perplexity, but invoking the CFAA was both legally baseless and bad policy that “could expose users themselves to criminal liability. &lt;/p&gt;
&lt;p&gt;This is a gratifying decision because all too often, big players use the CFAA to bully upstarts and innovators who offer potentially helpful user tools. When we counsel clients as part of EFF’s &lt;a href=&quot;https://www.eff.org/issues/coders&quot;&gt;Coders Rights Project&lt;/a&gt;, CFAA risk is a frequent topic of conversation, even for developers who merely create tools that allow others to access websites in new or different ways. We’ve &lt;a href=&quot;https://www.eff.org/deeplinks/2020/11/once-again-facebook-using-privacy-sword-kill-independent-innovation&quot;&gt;stood up&lt;/a&gt; for these creators before, and we’ll do it again, but it’s helpful to have back up from one of the most influential appellate courts in the country.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-related-cases field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Related Cases:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;/cases/facebook-v-power-ventures&quot;&gt;Facebook v. Power Ventures&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 04 Aug 2026 22:32:39 +0000</pubDate>
 <guid isPermaLink="false">112245 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/competition">Competition</category>
 <category domain="https://www.eff.org/issues/coders">Coders&#039; Rights Project</category>
 <dc:creator>Andrew Crocker</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/coder-cat-2.png" alt="" type="image/png" length="38507" />
  </item>
  <item>
    <title>Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds</title>
    <link>https://www.eff.org/press/releases/mobile-ad-software-encourages-location-data-sharing-eff-report-finds</link>
    <description>&lt;div class=&quot;field field--name-field-pr-subhead field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Developers Must Beware of Ad Libraries that Betray Users’ Privacy&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy&quot;&gt;report found&lt;/a&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers. The probe revealed how such SDKs can facilitate and encourage location data sharing – without users’ knowledge or meaningful consent – through privacy-invasive defaults, financial incentives, and unclear documentation.   &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;“Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information,” EFF Staff Technologist Lena Cohen said. “Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.”&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Cohen and EFF Senior Staff Technologist Bill Budington reviewed the public developer documentation of dozens of widely used advertising SDKs to identify how they handle and communicate with developers about location data. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In their analysis, they highlighted four advertising SDKs that collect and share a user&#039;s location by default for ad targeting whenever the user has given the app location permissions: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. But EFF’s focus on these four does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. In fact, advertising SDKs not discussed in this investigation have been &lt;/span&gt;&lt;a href=&quot;https://www.rainintelligence.com/blog/emerging-privacy-litigation-risks-mobile-sdks-under-legal-scrutiny&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;criticized and sued&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; for collecting location data without valid user consent. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads,” Budington said. “Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Developers have a responsibility to protect their users’ from these harms, regardless of advertising SDKs’ default settings.”&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For the EFF report: &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy&quot;&gt;https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For more on location data brokers: &lt;/span&gt;&lt;/b&gt;&lt;a href=&quot;https://www.eff.org/issues/location-data-brokers&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;https://www.eff.org/issues/location-data-brokers&lt;/span&gt;&lt;/a&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For more on SDKs: &lt;/span&gt;&lt;/b&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;  &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-contact field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Contact:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;div  class=&quot;ds-1col node node--profile view-mode-node_embed node--node-embed node--profile--node-embed clearfix&quot;&gt;

  
  &lt;div class=&quot;&quot;&gt;
    &lt;div class=&quot;field field--name-field-profile-first-name field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;William&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-last-name field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Budington&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-title field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Senior Staff Technologist&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-email field--type-email field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;mailto:bill@eff.org&quot;&gt;bill@eff.org&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;  &lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;&lt;div class=&quot;field__item odd&quot;&gt;&lt;div  class=&quot;ds-1col node node--profile view-mode-node_embed node--node-embed node--profile--node-embed clearfix&quot;&gt;

  
  &lt;div class=&quot;&quot;&gt;
    &lt;div class=&quot;field field--name-field-profile-first-name field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Lena&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-last-name field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Cohen&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-title field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Staff Technologist&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-email field--type-email field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;mailto:lcohen@eff.org&quot;&gt;lcohen@eff.org&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;  &lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 04 Aug 2026 19:30:41 +0000</pubDate>
 <guid isPermaLink="false">112231 at https://www.eff.org</guid>
 <dc:creator>Josh Richman</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/locationdata_v2.mov1_.gif" alt="An animated image showing location pins dropping onto a street map from above, tracing several paths" type="image/gif" length="2071190" />
  </item>
  <item>
    <title>Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy</title>
    <link>https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how&quot;&gt;&lt;span&gt;ad systems that location data brokers use&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/targeted-advertising-gives-your-location-government-just-ask-cbp&quot;&gt;&lt;span&gt;ICE investigations&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/&quot;&gt;&lt;span&gt;global spy tools&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.washingtonpost.com/dc-md-va/2023/03/09/catholics-gay-priests-grindr-data-bishops/&quot;&gt;&lt;span&gt;outing a gay priest&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/system/files/ftc_gov/pdf/2023196mobilewallacomplaint.pdf&quot;&gt;&lt;span&gt;tracking union organizers&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.reuters.com/business/media-telecom/pentagon-says-us-military-personnel-are-reportedly-being-targeted-using-location-2026-05-28/&quot;&gt;&lt;span&gt;tracking US military personnel&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;Defaults matter, not just for users, but for app developers as well.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location &lt;/span&gt;&lt;i&gt;&lt;span&gt;by default&lt;/span&gt;&lt;/i&gt;&lt;span&gt; when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Contents:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;#data-brokers-harvest&quot;&gt;&lt;span&gt;Data Brokers Harvest Location Information From Advertising Systems&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#how-advertising-sdks-leak&quot;&gt;&lt;span&gt;How Advertising SDKs Leak Location Data&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#eff-identified-advertising-sdks&quot;&gt;&lt;span&gt;EFF Identified Advertising SDKs That Share Location Data by Default&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;#inmobi&quot;&gt;&lt;span&gt;InMobi Encourages Keeping Location Sharing Enabled By Highlighting Financial Incentives&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#bidmachine&quot;&gt;&lt;span&gt;BidMachine Updates Previously Inaccurate Developer Documentation After EFF&#039;s Technical Analysis Observed Precise Location Data Collection&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#verve&quot;&gt;&lt;span&gt;Verve Emphasizes Consent More in its Play Store Language Than its Configuration Guide&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#huawei&quot;&gt;&lt;span&gt;Huawei Highlights Financial Incentives for Location Data Sharing Before Showing Developers How to Opt Out&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;&lt;a href=&quot;#sharing-without-knowledge&quot;&gt;&lt;span&gt;Location Data Sharing Can Happen Without Users’ Knowledge or Meaningful Consent&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#issues-beyond&quot;&gt;&lt;span&gt;Location Privacy Issues Extend Beyond These Four SDKs&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#fighting-back-against&quot;&gt;&lt;span&gt;Fighting Back Against AdTech Companies That Enable and Encourage Location Data Sharing&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;#developers&quot;&gt;&lt;span&gt;Developers&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#regulators&quot;&gt;&lt;span&gt;Regulators&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;#legislators&quot;&gt;&lt;span&gt;Legislators&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;&lt;a id=&quot;data-brokers-harvest&quot;&gt;&lt;/a&gt;Data Brokers Harvest Location Information From Advertising Systems&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/issues/location-data-brokers&quot;&gt;&lt;span&gt;Location data brokers&lt;/span&gt;&lt;/a&gt;&lt;span&gt; sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on people’s phones. Some apps partner with data brokers directly, using &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/03/apple-and-google-kicked-two-location-data-brokers-out-their-app-stores-good-now&quot;&gt;&lt;span&gt;data-broker-developed SDKs&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or &lt;/span&gt;&lt;a href=&quot;https://themarkup.org/the-breakdown/2022/02/24/who-is-policing-the-location-data-industry&quot;&gt;&lt;span&gt;server-to-server transfers&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to sell users’ location data. Other apps leak users’ location data through advertising SDKs serving behaviorally-targeted ads through “&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how&quot;&gt;&lt;span&gt;real-time bidding&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” (RTB). In the process of auctioning off ad space, ad tech companies can broadcast &lt;/span&gt;&lt;a href=&quot;https://brave.com/static-assets/files/3-bid-request-examples.pdf&quot;&gt;&lt;span&gt;user data&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to &lt;/span&gt;&lt;a href=&quot;https://www.iccl.ie/wp-content/uploads/2023/11/Americas-hidden-security-crisis.pdf&quot;&gt;&lt;span&gt;thousands&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how&quot;&gt;&lt;span&gt;collect personal information&lt;/span&gt;&lt;/a&gt;&lt;span&gt; contained in bid requests. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Indiscriminate data sharing through RTB can lead app developers to unknowingly share their users’ location with data brokers. In 2025, a hack of location data broker Gravy Analytics revealed &lt;/span&gt;&lt;a href=&quot;https://www.404media.co/candy-crush-tinder-myfitnesspal-see-the-thousands-of-apps-hijacked-to-spy-on-your-location/&quot;&gt;&lt;span&gt;thousands of apps&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that may have been sources of its data. When journalists reached out to the app developers, many &lt;/span&gt;&lt;a href=&quot;https://www.404media.co/candy-crush-tinder-myfitnesspal-see-the-thousands-of-apps-hijacked-to-spy-on-your-location/&quot;&gt;&lt;span&gt;claimed they had no relationship with or knowledge of Gravy Analytics&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. To prevent location information from being shared with data brokers through RTB, developers must understand the location-sharing practices of their advertising SDKs.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;&lt;a id=&quot;how-advertising-sdks-leak&quot;&gt;&lt;/a&gt;How Advertising SDKs Leak Location Data&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Developers don’t have to manually, or even intentionally, share location data for it to be broadcast through RTB auctions. Once a user grants an app permission to access their location, SDKs embedded in the app &lt;/span&gt;&lt;a href=&quot;https://arxiv.org/pdf/2108.03787&quot;&gt;&lt;span&gt;receive the same access&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—there are no SDK-specific location permissions. That means advertising SDKs can automatically collect users’ location data and share it in bid requests.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;While apps and SDKs can estimate a users’ approximate &lt;/span&gt;&lt;a href=&quot;https://arxiv.org/pdf/2105.13389&quot;&gt;&lt;span&gt;location from their IP address&lt;/span&gt;&lt;/a&gt;&lt;span&gt; without requesting any permissions, location permissions provide access to estimates that are &lt;/span&gt;&lt;a href=&quot;https://ipapi.is/blog/ip-geolocation-accuracy.html&quot;&gt;&lt;span&gt;more accurate&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and revealing. &lt;/span&gt;&lt;a href=&quot;https://developer.android.com/develop/sensors-and-location/location/permissions&quot;&gt;&lt;span&gt;Precise location permissions&lt;/span&gt;&lt;/a&gt;&lt;span&gt; give apps (and their embedded SDKs) access to location estimates within about 160 feet, but sometimes as accurate as 10 feet. &lt;/span&gt;&lt;a href=&quot;https://developer.android.com/develop/sensors-and-location/location/permissions&quot;&gt;&lt;span&gt;Approximate location&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a separate permissions level, gives apps access to a location estimate within about 1.2 square miles. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Developers and advertising SDKs also have a &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/12/unpacking-real-time-bidding-through-ftcs-case-mobilewalla&quot;&gt;&lt;span&gt;financial incentive&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to share location data, since it can &lt;/span&gt;&lt;a href=&quot;https://headerbidding.co/bid-request/&quot;&gt;&lt;span&gt;increase bid prices&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for an app’s ad space. While many advertising SDKs require developers to configure a setting before collecting and sharing users’ location data in ad requests, this is not always the case. EFF found several advertising SDKs who publicly acknowledge sharing users’ location data &lt;/span&gt;&lt;i&gt;&lt;span&gt;by default &lt;/span&gt;&lt;/i&gt;&lt;span&gt;when embedded in apps granted location permissions. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;&lt;a id=&quot;eff-identified-advertising-sdks&quot;&gt;&lt;/a&gt;EFF Identified Advertising SDKs That Share Location Data by Default&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;EFF reviewed the public developer documentation of dozens of &lt;/span&gt;&lt;a href=&quot;https://reports.exodus-privacy.eu.org/en/trackers/?filter=apps&quot;&gt;&lt;span&gt;widely-used advertising SDKs&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to identify how they handle and communicate with developers about location data. In the following sections, we highlight four advertising SDKs who engage in a particularly egregious practice: collecting a user&#039;s location by default for ad targeting whenever a user has given an app location permissions. &lt;/span&gt;&lt;span&gt;We reached out to each SDK company and the referenced app developers for comment. One company responded, and as detailed below, subsequently updated its documentation in response to our questions. Another company responded with clarifications to its developer documentation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We chose to focus on SDKs with this privacy-invasive default because it increases the risk of developers leaking users’ location data without realizing it. &lt;/span&gt;&lt;a href=&quot;https://www.usenix.org/system/files/soups2019-mhaidli.pdf&quot;&gt;&lt;span&gt;Several&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://petsymposium.org/popets/2025/popets-2025-0056.pdf&quot;&gt;&lt;span&gt;studies&lt;/span&gt;&lt;/a&gt;&lt;span&gt; have found that developers tend to stick to SDKs’ default settings. If an advertising SDK transmits location data by default, users&#039; precise location can end up in advertising systems without the developer intentionally enabling location sharing. These SDKs have &lt;/span&gt;&lt;a href=&quot;https://developers.verve.com/docs/hybid-android-configuration#enable-coppa-compliance&quot;&gt;&lt;span&gt;separate&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/monetize/policy4-0000001146675575#section16123552185318&quot;&gt;&lt;span&gt;documentation&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/privacy&quot;&gt;&lt;span&gt;pages that&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://support.inmobi.com/monetize/privacy/coppa#declare-the-app%E2%80%99s-audience&quot;&gt;&lt;span&gt;instruct&lt;/span&gt;&lt;/a&gt;&lt;span&gt; developers to flag users covered by privacy laws like GDPR and COPPA for restricted data processing, but these modes are not the default. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;By analyzing how these four SDKs present their location sharing practices to developers, we hope to illustrate how the design and documentation of advertising SDKs can facilitate location data sharing at scale. Although the advertising SDKs we highlight are not the &lt;a href=&quot;https://appfigures.com/top-sdks/ads/all&quot;&gt;most prevalent SDKs&lt;/a&gt; used, they are embedded in thousands of apps and reach billions of users.&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;inmobi&quot;&gt;&lt;/a&gt;InMobi Encourages Keeping Location Sharing Enabled By Highlighting Financial Incentives&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;InMobi claims to reach “&lt;/span&gt;&lt;a href=&quot;https://www.inmobi.com&quot;&gt;&lt;span&gt;2B+ users across 150+ countries&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” and is the 10th most popular advertising SDK on Android (according to &lt;/span&gt;&lt;a href=&quot;https://www.appbrain.com/stats/libraries/ad-networks&quot;&gt;&lt;span&gt;AppBrain&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://appfigures.com/top-sdks/ads/all&quot;&gt;&lt;span&gt;Appfigures&lt;/span&gt;&lt;/a&gt;&lt;span&gt; at the time of publication). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;InMobi’s “&lt;/span&gt;&lt;a href=&quot;https://support.inmobi.com/monetize/sdk-documentation/android-guidelines/overview-android-guidelines#optimization&quot;&gt;&lt;span&gt;Getting Started with Android SDK Integration&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” suggests that location sharing is enabled by default, stating “The InMobi SDK automatically forwards location signals when available.” InMobi provides developers with a setting to opt out, but explicitly recommends sharing location data. Developer documentation highlights the financial incentive for location sharing, stating “location-enriched impressions typically yield higher revenue.” &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/getting_started_with_android_sdk_integration_1.png&quot; width=&quot;688&quot; height=&quot;525&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://support.inmobi.com/monetize/sdk-documentation/android-guidelines/overview-android-guidelines#optimization&quot;&gt;Getting Started with Android SDK Integration&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Apps that use InMobi may not need location information to function or may only need access to &lt;/span&gt;&lt;i&gt;&lt;span&gt;approximate&lt;/span&gt;&lt;/i&gt;&lt;span&gt; location information, but InMobi highly recommends that developers request &lt;/span&gt;&lt;i&gt;&lt;span&gt;precise&lt;/span&gt;&lt;/i&gt;&lt;span&gt; location permissions “to enable accurate ad targeting.” They even encourage developers to request Wi-Fi network information permissions, which (&lt;/span&gt;&lt;a href=&quot;https://developer.android.com/develop/connectivity/wifi/wifi-scan&quot;&gt;&lt;span&gt;when paired with precise location permissions&lt;/span&gt;&lt;/a&gt;&lt;span&gt;) provide Wi-Fi access point identifiers that can also be used for location tracking.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/getting_started_with_android_sdk_integration_2.png&quot; width=&quot;596&quot; height=&quot;579&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://support.inmobi.com/monetize/sdk-documentation/android-guidelines/overview-android-guidelines#granting-permissions&quot;&gt;Getting Started with Android SDK Integration&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]&lt;/p&gt;
&lt;p&gt;&lt;span&gt;InMobi has been accused of misleading developers over location sharing practices in the past: In 2016, they &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2016/06/mobile-advertising-network-inmobi-settles-ftc-charges-it-tracked-hundreds-millions-consumers&quot;&gt;&lt;span&gt;settled&lt;/span&gt;&lt;/a&gt;&lt;span&gt; with the FTC over charges that they bypassed users’ location permissions for apps and tracked their precise locations through WiFi network data (Android now &lt;/span&gt;&lt;a href=&quot;https://developer.android.com/develop/connectivity/wifi/wifi-scan&quot;&gt;&lt;span&gt;requires&lt;/span&gt;&lt;/a&gt;&lt;span&gt; apps to request location permissions to access this WiFi data too).&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;bidmachine&quot;&gt;&lt;/a&gt;BidMachine Updates Previously Inaccurate Developer Documentation After EFF&#039;s Technical Analysis Observed Precise Location Data Collection&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;BidMachine claims to reach over &lt;/span&gt;&lt;a href=&quot;https://www.bidmachine.com/ad-exchange&quot;&gt;&lt;span&gt;600 million “direct SDK users.”&lt;/span&gt;&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span&gt;BidMachine reveals that it collects location data by default on the “&lt;/span&gt;&lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/advanced#location&quot;&gt;&lt;span&gt;Advanced Settings&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” page of its Android SDK Integration guide, stating that the “SDK can automatically track user device location to serve better ads” as long as developers request location permissions for their app. Before publication, EFF reached out to BidMachine for comment, notifying them of our plan to highlight their Android SDK location sharing practices.&lt;/span&gt;  &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/advanced_settings_1.png&quot; width=&quot;790&quot; height=&quot;331&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/advanced#location&quot;&gt;Advanced Settings&lt;/a&gt;&lt;span&gt;”&lt;/span&gt; on 7/31/26, before EFF asked BidMachine for comment]&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span&gt;After EFF reached out, BidMachine changed their documentation to clarify the practice, but not their default collection of location information once app-level permissions are granted. &lt;/span&gt;&lt;/span&gt;&lt;span&gt;This updated section still fails to explain how developers can opt out of BidMachine location tracking, which is critical for app developers that require location access for core features but wish to prevent user data from being shared with advertisers.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;span&gt;&lt;span&gt;&lt;img src=&quot;/files/2026/08/03/screenshot_2026-08-03_at_1.25.39_pm.png&quot; width=&quot;973&quot; height=&quot;385&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/advanced#location&quot;&gt;Advanced Settings&lt;/a&gt;” on 8/3/26, after EFF asked BidMachine for comment]&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span&gt;Before EFF reached out, BidMachine’s “&lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/app-privacy-details-on-the-google-play&quot;&gt;App Privacy Details On Google Play&lt;/a&gt;” page had stated that they only collected coarse location data and precise location data was “not collected.” However, our technical analysis of two apps, which &lt;a href=&quot;https://reports.exodus-privacy.eu.org/en/reports/com.appswing.qr.barcodescanner.barcodereader/latest/&quot;&gt;Exodus&lt;/a&gt; &lt;a href=&quot;https://reports.exodus-privacy.eu.org/en/reports/com.ktwapps.speedometer/latest/&quot;&gt;Privacy&lt;/a&gt; determined include the BidMachine SDK, contradicted this claim: Network requests from the apps &lt;a href=&quot;https://play.google.com/store/apps/details?id=com.appswing.qr.barcodescanner.barcodereader&amp;amp;hl=en-US&amp;amp;pli=1&quot;&gt;QR Scanner&lt;/a&gt; and &lt;a href=&quot;https://play.google.com/store/apps/details?id=com.ktwapps.speedometer&amp;amp;hl=en_US&amp;amp;pli=1&quot;&gt;GPS Speedometer&lt;/a&gt; to a BidMachine domain include precise location coordinates.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/app_privacy_details_on_google_play_1.png&quot; width=&quot;538&quot; height=&quot;253&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/app-privacy-details-on-the-google-play&quot;&gt;App Privacy Details On Google Play&lt;/a&gt;&lt;span&gt;”&lt;/span&gt; on 7/31/26,&lt;span&gt; before EFF asked BidMachine for comment&lt;/span&gt;]&lt;/p&gt;
&lt;p&gt;&lt;span&gt;After EFF reached out, BidMachine also corrected its documentation to make it clear precise location &lt;/span&gt;&lt;i&gt;&lt;span&gt;is&lt;/span&gt;&lt;/i&gt;&lt;span&gt; collected by the SDK whenever the app-level permission is granted:&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;span&gt;&lt;img src=&quot;/files/2026/08/03/screenshot_2026-08-03_at_1.35.55_pm.png&quot; width=&quot;954&quot; height=&quot;300&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;&lt;span&gt;[Observed on “&lt;/span&gt;&lt;a href=&quot;https://developers.bidmachine.io/sdk/general/android/app-privacy-details-on-the-google-play&quot;&gt;App Privacy Details On Google Play&lt;/a&gt;&lt;span&gt;” on 8/3/26,&lt;/span&gt; after EFF asked BidMachine for comment&lt;span&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;a href=&quot;/files/2026/08/03/com.appswing.qr_.barcodescanner.barcodereader_bidmachine.flows&quot;&gt;&lt;span&gt;com.appswing.qr.barcodescanner.barcodereader_bidmachine.flows&lt;br /&gt;&lt;img src=&quot;/files/2026/07/31/com.appswing.qr_.barcodescanner.barcodereader_bidmachine.flows_.png&quot; width=&quot;564&quot; height=&quot;358&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;a href=&quot;/files/2026/08/03/com.ktwapps.speedometer_bidmachine.flows&quot;&gt;&lt;span&gt;com.ktwapps.speedometer_bidmachine.flows&lt;br /&gt;&lt;img src=&quot;/files/2026/07/31/com.ktwapps.speedometer_bidmachine.flows_.png&quot; width=&quot;574&quot; height=&quot;358&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span&gt;In response to our request for comment, BidMachine stated that it wasn&#039;t possible for them to get location information “unless the user has granted the app the relevant permission through the operating system.” They also stated that“publishers are responsible for configuring their apps&#039; permission and consent flows.”&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;verve&quot;&gt;&lt;/a&gt;Verve Emphasizes Consent More in its Play Store Language Than its Configuration Guide &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Verve has claimed its HyBid SDK reaches “&lt;/span&gt;&lt;a href=&quot;https://press.verve.com/mgi-media-and-games-invest-se-releases-on-device-targeting-ai-atom-30-to-10000-apps&quot;&gt;&lt;span&gt;over 1.5 billion users across more than 10,000 apps worldwide&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Verve’s configuration guide for its &lt;/span&gt;&lt;a href=&quot;https://developers.verve.com/docs/hybid-android-configuration#location-tracking&quot;&gt;&lt;span&gt;HyBid Android SDK&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (formerly called Pubnative HyBid) makes clear that location tracking is “enabled by default,” stating, “If the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.” &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/hybid_android_sdk_-_hybid_configuration_1.png&quot; width=&quot;736&quot; height=&quot;247&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developers.verve.com/docs/hybid-android-configuration#location-tracking&quot;&gt;HyBid Android SDK - HyBid Configuration&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]  &lt;/p&gt;
&lt;p&gt;&lt;span&gt;Verve’s &lt;/span&gt;&lt;a href=&quot;https://developers.verve.com/docs/google-play-data-safety-guidance&quot;&gt;&lt;span&gt;guidance&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for data disclosure to the Google Play Store tells a more careful story. Despite the fact that location tracking is enabled by default, the &lt;/span&gt;&lt;a href=&quot;https://developers.verve.com/docs/google-play-data-safety-guidance&quot;&gt;&lt;span&gt;Google Play Data Safety Guidance&lt;/span&gt;&lt;/a&gt;&lt;span&gt; states that the SDK “&lt;/span&gt;does not &lt;span&gt;collect or attempt to collect [location] information independently.”&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/google_play_data_safety_guidance_1.png&quot; width=&quot;832&quot; height=&quot;285&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developers.verve.com/docs/google-play-data-safety-guidance&quot;&gt;Google Play Data Safety Guidance&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]  &lt;/p&gt;
&lt;p&gt;&lt;span&gt;It also emphasizes user consent, claiming the SDK will &lt;/span&gt;&lt;i&gt;&lt;span&gt;only&lt;/span&gt;&lt;/i&gt;&lt;span&gt; collect location data “if the publishers allows &lt;/span&gt;&lt;b&gt;&lt;i&gt;its app&lt;/i&gt;&lt;/b&gt;&lt;span&gt; to collect location data from users after obtaining user’s explicit consent to such data collection” (emphasis added). The configuration guide lacks recommendations or instructions for obtaining user consent to share location data&lt;/span&gt;&lt;i&gt;&lt;span&gt; with Verve&lt;/span&gt;&lt;/i&gt;&lt;span&gt;, beyond app-level access. Instead, the configuration guide highlights the financial incentives for developers to add location permissions to their app.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/hybid_android_sdk_-_hybid_configuration_2.png&quot; width=&quot;1482&quot; height=&quot;514&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developers.verve.com/docs/hybid-android-configuration#manifest-permissions&quot;&gt;HyBid Android SDK - HyBid Configuration&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]  &lt;/p&gt;
&lt;p&gt;&lt;span&gt;When reached for comment, Verve clarified that “in its current Android implementation, the SDK reads the cached network-provider location and does not use the GPS data of the end user&#039;s device. Furthermore, any geolocation data is coarsened prior to processing, ensuring that location is limited to an accuracy radius of no less than 1,850 feet.” It also said that it contractually requires apps to comply with data protection laws. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;To Verve’s credit, the HyBid SDK is open source, so careful developers can check the code instead of relying on documentation alone. HyBid’s open-source code shows that latitude and longitude coordinates are &lt;/span&gt;&lt;a href=&quot;https://github.com/pubnative/pubnative-hybid-android-sdk/blob/5840b89708eac7f306b443db655a69db164200b1/hybid.sdk/src/main/java/net/pubnative/lite/sdk/models/OpenRTBAdRequestFactory.java#L427..L440&quot;&gt;&lt;span&gt;rounded to two decimal places&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and that it does only collect and share &lt;/span&gt;&lt;a href=&quot;https://github.com/pubnative/pubnative-hybid-android-sdk/blob/5840b89708eac7f306b443db655a69db164200b1/hybid.sdk/src/main/java/net/pubnative/lite/sdk/location/HyBidLocationManager.java&quot;&gt;&lt;span&gt;network-derived location data&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, confirming the statement the company sent to us. If an app has precise location permissions, &lt;/span&gt;&lt;a href=&quot;https://pmc.ncbi.nlm.nih.gov/articles/PMC12694262/&quot;&gt;&lt;span&gt;networked-derived location data&lt;/span&gt;&lt;/a&gt;&lt;span&gt; rounded to two decimal places &lt;/span&gt;&lt;i&gt;&lt;span&gt;could&lt;/span&gt;&lt;/i&gt;&lt;span&gt; be accurate within &lt;/span&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Decimal_degrees#Precision&quot;&gt;&lt;span&gt;approximately 0.5 square miles&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which is still more precise than the &lt;/span&gt;&lt;a href=&quot;https://developer.android.com/develop/sensors-and-location/location/permissions&quot;&gt;&lt;span&gt;1.2 square miles&lt;/span&gt;&lt;/a&gt;&lt;span&gt; typically revealed with Android’s approximate location permission. But even coarse location data, especially when collected repeatedly over time, can reveal movements that should remain private by default.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Verve’s response also conveyed a willingness to revise their documentation: “As part of our ongoing commitment to providing clear and comprehensive developer resources, we continually review and enhance our documentation, and we will take your observations into account as part of that process.” &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;huawei&quot;&gt;&lt;/a&gt;Huawei Highlights Financial Incentives for Location Data Sharing Before Showing Developers How to Opt Out&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Huawei has claimed its Petal Ads SDK is embedded in more than &lt;/span&gt;&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/promotion/introduction-0000001051265655&quot;&gt;&lt;span&gt;85,000 apps worldwide&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Huawei’s “&lt;/span&gt;&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/monetize/androidappsdk-0000001053440624&quot;&gt;&lt;span&gt;Integrating the Petal Ads SDK into an Android App&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” guide begins with a recommendation that developers obtain location permissions to increase app revenue and an acknowledgement that location sharing will happen by default in apps with location permissions.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/integrating_the_petal_ads_sdk_into_an_android_app_1.png&quot; width=&quot;855&quot; height=&quot;173&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/monetize/androidappsdk-0000001053440624&quot;&gt;Integrating the Petal Ads SDK into an Android App&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]&lt;/p&gt;
&lt;p&gt;&lt;span&gt;A separate “&lt;/span&gt;&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/HMSCore-Guides/publisher-service-location-based-0000001163023235&quot;&gt;&lt;span&gt;Use of Location Data for Ads&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” page repeats that the Petal Ads SDK will include users’ location information in ad requests if an app has access to location information. Neither of those pages mention that developers can use the &lt;/span&gt;&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/development/HMSCore-References/adparam-builder-0000001050066829#section7194265410&quot;&gt;&lt;span&gt;setRequestLocation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; method to disable the default collection of location information (this setting is referenced in the last section of the &lt;/span&gt;&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/HMSCore-Guides/whale-hong-kinetic-sdk-compliance-user-guide-0000001658442922&quot;&gt;&lt;span&gt;Ads SDK Compliance Guide&lt;/span&gt;&lt;/a&gt;&lt;span&gt;). Huawei’s &lt;/span&gt;&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/HMSCore-Guides/whale-hong-kinetic-energy-sdk-privacy-statement-0000001658283582&quot;&gt;&lt;span&gt;Ads SDK Privacy Statement&lt;/span&gt;&lt;/a&gt;&lt;span&gt; states that “The SDK and its services will not store precise location information, and will only use it to determine the approximate device location.” However, the guide does not specify how Huawei defines approximate versus precise location data. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;img src=&quot;/files/2026/07/31/use_of_location_data_for_ads_1.png&quot; width=&quot;906&quot; height=&quot;434&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;[Observed on “&lt;a href=&quot;https://developer.huawei.com/consumer/en/doc/HMSCore-Guides/publisher-service-location-based-0000001163023235&quot;&gt;Use of Location Data for Ads&lt;/a&gt;,&lt;span&gt;”&lt;/span&gt; 7/31/26]&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;&lt;a id=&quot;sharing-without-knowledge&quot;&gt;&lt;/a&gt;Location Data Sharing Can Happen Without Users’ Knowledge or Meaningful Consent &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;In some cases, after an app itself obtains location permission, advertising SDKs can separately obtain and share users’ location information without their knowledge or meaningful consent. Neither app that EFF observed sharing precise location data with BidMachine (&lt;/span&gt;&lt;a href=&quot;https://play.google.com/store/apps/details?id=com.appswing.qr.barcodescanner.barcodereader&amp;amp;hl=en-US&amp;amp;pli=1&quot;&gt;&lt;span&gt;QR Scanner&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://play.google.com/store/apps/details?id=com.ktwapps.speedometer&amp;amp;hl=en_US&amp;amp;pli=1&quot;&gt;&lt;span&gt;GPS Speedometer&lt;/span&gt;&lt;/a&gt;&lt;span&gt;) showed a notice or requested consent before doing so. Additionally, neither apps’ Google Play Store “Data safety” section includes location data under “This app may share these data types with third parties.” The lack of transparency and control that users have over their location on mobile apps is dangerous. &lt;/span&gt;&lt;a href=&quot;https://play.google.com/store/apps/details?id=com.appswing.qr.barcodescanner.barcodereader&amp;amp;hl=en-US&amp;amp;pli=1&quot;&gt;&lt;span&gt;QR Scanner&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://play.google.com/store/apps/details?id=com.ktwapps.speedometer&amp;amp;hl=en_US&amp;amp;pli=1&quot;&gt;&lt;span&gt;GPS Speedometer&lt;/span&gt;&lt;/a&gt;&lt;span&gt; are just two examples of apps that quietly share users’ location data through advertising SDKs, but they have been downloaded more than 50 million and 10 million times, respectively. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if users’ were to grant these apps permission to obtain their location data, they would likely not expect their location data to be shared with third parties. Many users don’t know that granting location permissions to an app grants the same permissions to third-party SDKs embedded in the app, or that an app they&#039;re using contains code from outside companies. And many apps that request location permissions, like &lt;/span&gt;&lt;a href=&quot;https://play.google.com/store/apps/details?id=com.ktwapps.speedometer&amp;amp;hl=en_US&amp;amp;pli=1&quot;&gt;&lt;span&gt;GPS Speedometer&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, require it for core functionality. App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;&lt;a id=&quot;issues-beyond&quot;&gt;&lt;/a&gt;Location Privacy Issues Extend Beyond These Four SDKs&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Our initial focus on four advertising SDKs does not mean that other SDKs adequately protect location data or that developers never &lt;/span&gt;&lt;i&gt;&lt;span&gt;choose&lt;/span&gt;&lt;/i&gt;&lt;span&gt; to share location data when it’s not the default. Advertising SDKs not discussed in this report have been &lt;/span&gt;&lt;a href=&quot;https://richtfirm.com/applovin-sec-investigation-key-compliance-takeaways-for-mobile-advertising-companies/&quot;&gt;&lt;span&gt;criticized&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.rainintelligence.com/blog/emerging-privacy-litigation-risks-mobile-sdks-under-legal-scrutiny&quot;&gt;&lt;span&gt;sued&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for allegations that they collect location data without valid user consent. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The issues we’ve highlighted around privacy-invasive defaults, financial incentives, and unclear documentation extend beyond the specific SDKs we analyzed. Multiple studies have found that advertising SDKs often steer developers toward increased data collection through their design and documentation. A &lt;/span&gt;&lt;a href=&quot;https://tulipslab.org/papers/tahaei2021AdNetworkLBW.pdf&quot;&gt;&lt;span&gt;2021 study&lt;/span&gt;&lt;/a&gt;&lt;span&gt; found that popular advertising SDKs used dark patterns to nudge developers towards sharing more sensitive data. A &lt;/span&gt;&lt;a href=&quot;https://dl.acm.org/doi/pdf/10.1145/3647632.3647991&quot;&gt;&lt;span&gt;2024 study&lt;/span&gt;&lt;/a&gt;&lt;span&gt; identified discrepancies between several SDKs’ documentation and their actual data collection practices. And a &lt;/span&gt;&lt;a href=&quot;https://petsymposium.org/popets/2025/popets-2025-0042.pdf&quot;&gt;&lt;span&gt;2025 study&lt;/span&gt;&lt;/a&gt;&lt;span&gt; concluded that developers have minimal influence over SDKs’ data transmission, often leaving them with the choice of accepting SDKs&#039; invasive data collection or avoiding them entirely. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;&lt;a id=&quot;fighting-back-against&quot;&gt;&lt;/a&gt;Fighting Back Against AdTech Companies That Enable and Encourage Location Data Sharing &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;EFF’s analysis shows that advertising SDKs don’t just allow developers to share location data–they often encourage it. Default settings, financial incentives, and unclear documentation can make sharing users’ location the easiest option for developers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Users can &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/11/creators-police-location-tracking-tool-arent-vetting-buyers-heres-how-protect&quot;&gt;&lt;span&gt;take extra steps&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;developers&quot;&gt;&lt;/a&gt;Developers&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Developers should carefully evaluate all third-party SDKs they include in their apps and disable unnecessary data collection whenever possible. Regardless of advertising SDKs’ default settings, developers have a responsibility to protect their users’ location data. But protecting users’ privacy shouldn’t depend on developers reading the right piece of SDK documentation. Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;regulators&quot;&gt;&lt;/a&gt;Regulators&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Regulators should continue to hold app developers accountable when they unlawfully share personal data and include libraries which subject users to privacy harms, &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2016/03/ftc-issues-warning-letters-app-developers-using-silverpush-code&quot;&gt;&lt;span&gt;as they have in the past&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. But they should also scrutinize the companies whose SDKs encourage these practices at scale. Otherwise, companies can continue to design SDKs that make invasive data sharing the default while shifting the responsibility and consequences to developers who include their tools. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;a id=&quot;legislators&quot;&gt;&lt;/a&gt;Legislators&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The US is in dire need of a federal law to protect all Americans’ location privacy, one which doesn’t preempt stronger &lt;/span&gt;&lt;a href=&quot;https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-investigative-sweep-location-data-industry&quot;&gt;&lt;span&gt;state privacy laws&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and has a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/01/you-should-have-right-sue-companies-violate-your-privacy&quot;&gt;&lt;span&gt;private right of action&lt;/span&gt;&lt;/a&gt;&lt;span&gt; empowering individuals to sue those who violate their privacy. Countries across the globe should likewise enact legislation that protects their users’ location privacy. &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/international-privacy-standards&quot;&gt;&lt;span&gt;Everyone deserves privacy&lt;/span&gt;&lt;/a&gt;&lt;span&gt; as a universal human right.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Legislators can address the root of the problem by &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/03/ban-online-behavioral-advertising&quot;&gt;&lt;span&gt;banning online behavioral advertising&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. This would remove the primary incentive for companies to track and share your personal data. It would also prevent users&#039; precise locations from being broadcast to data brokers through RTB auctions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Until then, developers should be wary of ad libraries that betray their users’ location privacy.&lt;/span&gt;&lt;/p&gt;
&lt;table&gt;

&lt;tr&gt;
&lt;td&gt;
&lt;h4&gt;&lt;span&gt;Notes on Methodology&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;We were interested in looking at network traffic for various Android ads SDKs that send precise location by default when granted location permissions. We chose Android for this investigation because of the relative openness of and our familiarity with analysis on the platform. We’ve used publicly available resources like &lt;/span&gt;&lt;a href=&quot;https://exodus-privacy.eu.org/en/&quot;&gt;&lt;span&gt;Exodus Privacy&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.appbrain.com/&quot;&gt;&lt;span&gt;AppBrain&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to identify popular ads SDKs and the apps which include them.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In a lab setting, we set up a machine to view our own http(s) traffic using &lt;/span&gt;&lt;a href=&quot;https://www.mitmproxy.org/&quot;&gt;&lt;span&gt;mitmproxy&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from our test device, and connect the test device to that machine in order to view our real-time traffic.  Where needed, we use the dynamic instrumentation toolkit &lt;/span&gt;&lt;a href=&quot;https://frida.re/&quot;&gt;&lt;span&gt;Frida&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to ensure the traffic we generate can be analyzed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We’ve included &lt;/span&gt;&lt;i&gt;&lt;span&gt;flows&lt;/span&gt;&lt;/i&gt;&lt;span&gt; files in this post, which can be opened in mitmproxy to show the requests we’ve observed with location coordinates.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;


&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 04 Aug 2026 19:30:21 +0000</pubDate>
 <guid isPermaLink="false">112236 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/taxonomy/term/77">Technical Analysis</category>
 <dc:creator>Lena Cohen</dc:creator>
 <dc:creator>Bill Budington</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/locationdata_v2.mov1_.gif" alt="An animated image showing location pins dropping onto a street map from above, tracing several paths" type="image/gif" length="2071190" />
  </item>
  <item>
    <title>Technology&#039;s Power in the Hands of the People</title>
    <link>https://www.eff.org/deeplinks/2026/07/vv26</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;In the scorching heat of every Las Vegas summer, EFF joins thousands of hackers, makers, policy analysts, and activists for the world&#039;s largest computer security gathering. If you&#039;re there during this summer security week, be sure to say hello to us at &lt;a href=&quot;https://www.eff.org/event/eff-bsides-las-vegas-1&quot;&gt;BSides Las Vegas&lt;/a&gt;, &lt;a href=&quot;https://www.eff.org/event/eff-black-hat-usa-2&quot;&gt;Black Hat Briefings&lt;/a&gt;, and &lt;a href=&quot;https://www.eff.org/event/eff-def-con-34&quot;&gt;DEF CON 34&lt;/a&gt;. While tech companies align with governments to target the people, our community is harnessing technology to fight back. Will you lend your support this year?&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;JOIN EFF&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;EFF’s relentless work in the legal system makes a meaningful difference for privacy and free expression everywhere. But we also know that your rights won&#039;t wait while the wheels of justice turn.&lt;/p&gt;
&lt;p&gt;Sometimes hacking the system means creating tools and resources to protect your rights today. That includes EFF’s &lt;a href=&quot;https://www.eff.org/pages/privacy-badger&quot;&gt;Privacy Badger&lt;/a&gt;, &lt;a href=&quot;https://www.eff.org/pages/certbot&quot;&gt;Certbot&lt;/a&gt;, &lt;a href=&quot;https://ssd.eff.org&quot;&gt;Surveillance Self-Defense guide&lt;/a&gt;, and the countless security trainings that our team conducts for vulnerable populations—&lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;all thanks to EFF member support&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Technology is inseparable from our workplaces, schools, healthcare, the justice system, and our democratic process. If you think tech should benefit everyone and not just accumulate wealth and control for the powerful, then congratulations: &lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;We&#039;d like to welcome you to the team.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;&lt;img src=&quot;/files/2026/07/31/2026_defcon_shirt_frontback-01-150dpi.png&quot; width=&quot;1200&quot; height=&quot;600&quot; alt=&quot; Many Hands Make Light Work&quot; title=&quot;Join today to defend our privacy and free expression!&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;caption-text&quot;&gt;Hayley and Joe take a break from EFF’s Activism Team to show off EFF’s DEF CON member t-shirt.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;For a limited time only: Get EFF’s &lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;“Many Hands Make Light Work”&lt;/a&gt; t-shirt designed for the DEF CON 34 hacker conference by EFF artist Hannah Diaz. Don’t miss the link to the online puzzle incorporated into the design!&lt;span&gt; &lt;/span&gt;With the strength of community and the spirit of curiosity, we can hack anything.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Many thanks to our puzzlemasters Aaron Steimle (AKA &lt;/span&gt;&lt;a href=&quot;https://bsky.app/profile/elegin.bsky.social&quot;&gt;Elegin&lt;/a&gt;)&lt;span&gt; and Kevin Hulin (AKA &lt;a href=&quot;https://x.com/0xCryptoK&quot;&gt;CryptoK&lt;/a&gt;). Elegin is our longtime collaborator on the EFF shirt puzzle, and previously a multiyear winner of this very contest. CryptoK is a crypto puzzle enthusiast and also develops challenges for the DEF CON &lt;a href=&quot;https://defcon.org/html/defcon-34/dc-34-villages.html#orga_41430&quot;&gt;Crypto and Privacy Village&#039;s&lt;/a&gt; Gold Bug Contest.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Members can also choose from EFF’s puffy stickers, the internet tracker-obsessed Privacy Badger embroidered sweatshirt, and our ALPR-focused “Claw Back” t-shirt.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;center&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;&lt;img src=&quot;/files/2026/07/31/claw_back_many_hands_2.png&quot; width=&quot;700&quot; height=&quot;1050&quot; alt=&quot;Illustration of a cat swatting at surveillance equipment. Below a person with red glasses adjusts six mechanical arms with ASL signs. &quot; title=&quot;Choose an EFF t-shirt when you join. &quot; /&gt;&lt;/a&gt;&lt;p class=&quot;caption-text&quot;&gt;EFF member t-shirt designs: Claw Back and Many Hands Make Light Work&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&lt;/p&gt;&lt;/center&gt;
&lt;p&gt;EFF fights to protect fundamental rights for everyone, and your privacy and free expression have never been more important. &lt;a href=&quot;https://supporters.eff.org/donate/VirtualVegas--DL&quot;&gt;Support the cause today! Together we can make sure that technology supports freedom, justice, and innovation for all people.&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 04 Aug 2026 14:12:50 +0000</pubDate>
 <guid isPermaLink="false">112224 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/coders">Coders&#039; Rights Project</category>
 <category domain="https://www.eff.org/taxonomy/term/68">Announcement</category>
 <dc:creator>Aaron Jue</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/defcon-manyhands-banner-animated.gif" alt="Person with red glasses adjusting six mechanical arms with ASL signs." type="image/gif" length="162310" />
  </item>
  <item>
    <title> The Senate Should Reject KOSA&#039;s Privacy Risks</title>
    <link>https://www.eff.org/deeplinks/2026/08/senate-should-reject-kosas-privacy-risks</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt;&lt;span&gt; The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The Senate Commerce Committee is once again considering legislation that would dramatically expand age verification, and undermine privacy for everyone. Alongside the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/screen-act-threatens-privacy-far-beyond-adult-websites&quot;&gt;&lt;span&gt;SCREEN Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/chatbot-act-forces-one-parenting-model-every-family&quot;&gt;&lt;span&gt;CHATBOT Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and the Youth AI Privacy Act, the Kids Online Safety Act (KOSA) would push companies to collect more information about their users while creating new incentives to restrict lawful speech.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Tell Congress: KOSA endangers the privacy of all&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;KOSA Pushes Platforms Toward Age Verification&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The Senate version of KOSA imposes a “duty of care” on online services, including social media, to avoid exposing young people to certain material the law deems harmful. But those obligations only work if online services know which users are minors. That means more platforms will be pressured to implement age verification or age estimation systems.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;That’s not a bill that increases privacy—it’s one that creates new privacy problems. Whether companies verify ages by checking government IDs, performing facial analysis, checking your bank records, or collecting other personal information, all of these systems require the handing over of more sensitive data, simply to access lawful online speech and services. They also create new databases of personal information that can be breached, misused, or demanded by governments.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Everyone deserves privacy online. Congress could push for a bill that protects privacy for all users, but that’s not what they’re doing here. Instead, KOSA and the other bills coming up for a vote this week push online services to adopt systems that require people to identify themselves before they can speak, read, or participate online.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;KOSA Still Creates Incentives to Censor Lawful Speech&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Some online content isn’t appropriate for minors. Families, schools, and communities all have important roles to play in helping children navigate the internet. But KOSA takes those decisions away from families and the young people who have a First Amendment right to speak and access information online. It instead empowers government officials to enforce how online services handle lawful speech. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;And by empowering elected attorneys general in states across the country to enforce KOSA, the bill means those elected officials, rather than your family, deciding what’s appropriate online content for teens. Even more likely, it will lead to limits on what minors and adults are able to see at all, as companies shut down potentially controversial forums in order to avoid legal action from government bureaucrats. &lt;/p&gt;
&lt;p&gt;The latest version of KOSA once again includes a broad &quot;duty of care&quot; requiring platforms to mitigate a wide range of alleged harms to minors.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Whatever disclaimers and exceptions the bill includes, the practical effect is unchanged. When platforms face liability for content that someone later claims contributed to harms like anxiety, eating disorders, or substance use, the safest response is to remove lawful speech or shut down forums discussing those topics altogether. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;More worrisome, the potential liability KOSA creates may push online services to either remove speech well in advance of a young person seeing it, or block young people’s access so they never see it. That will likely include forums where people try to help each other, find community and recovery resources for the exact harms listed in the bill, like gambling and drug addiction. In trying to protect young people, KOSA may actually cut them off from valuable sources of support. &lt;/p&gt;
&lt;p&gt;&lt;span&gt;We&#039;ve &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/07/kosa-internet-censorship-bill-just-passed-senate-its-our-last-chance-stop-it&quot;&gt;&lt;span&gt;explained these censorship risks&lt;/span&gt;&lt;/a&gt;&lt;span&gt; in detail before, and they remain just as real in the latest version of the bill.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Congress Should Reject KOSA&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Minors deserve meaningful privacy protections online—as do adults. But KOSA moves in the opposite direction by encouraging more &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/age-verification&quot;&gt;&lt;span&gt;age verification&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, as well as more legal pressure for platforms to monitor and restrict lawful speech.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The Senate Commerce Committee should reject KOSA, along with the other bills in this legislative package, and instead pursue comprehensive privacy legislation that protects everyone—not just minors—without undermining privacy, security, or free expression.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Congress shouldn&#039;t set the rules for what we see online&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 03 Aug 2026 23:47:38 +0000</pubDate>
 <guid isPermaLink="false">112244 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>Joe Mullin</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  <item>
    <title>EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act</title>
    <link>https://www.eff.org/deeplinks/2026/08/eff-joins-18-civil-rights-organizations-calling-governor-hochul-reject-stealth</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to veto &lt;/span&gt;&lt;a href=&quot;https://www.nysenate.gov/legislation/bills/2025/S9934/amendment/A&quot;&gt;&lt;span&gt;Senate Bill 9934A, the New York Stealth Crawler Prohibition Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. The letter states:&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;&lt;span&gt;While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to the open web. By requiring all web crawlers to disclose their identity and explicit purpose, and by granting media outlets unchecked authority to obtain judicial subpoenas to unmask unidentified automated web traffic without any showing of misconduct or actual injury, this bill threatens digital privacy, compromises the foundational architecture of the internet, and will ultimately stifle the very independent journalism it seeks to protect.&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span&gt;As we’ve &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/stealth-crawlers-are-not-threat-open-web-bills-targeting-them-would-be&quot;&gt;&lt;span&gt;previously explained&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, so-called “stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf&quot;&gt; &lt;span&gt;important work&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that benefits the public, including investigative reporting, academic research, cybersecurity protection, and EFF’s own &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/10/privacy-badger-learns-block-ever-more-trackers&quot;&gt;&lt;span&gt;Privacy Badger&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. As we illustrate in the letter: &lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;&lt;span&gt;Anonymous crawling fuels important investigative journalism. For example, &lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://themarkup.org/amazons-advantage/2021/10/14/amazon-puts-its-own-brands-first-above-better-rated-products&quot;&gt;&lt;i&gt;&lt;span&gt;The Markup&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt;, a non-profit news site, used anonymous crawlers to &lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://themarkup.org/google-the-giant/2020/07/28/how-we-analyzed-google-search-results-web-assay-parsing-tool&quot;&gt;&lt;i&gt;&lt;span&gt;investigate&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt; potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which &lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://themarkup.org/amazons-advantage/2021/10/14/how-we-analyzed-amazons-treatment-of-its-brands-in-search-results&quot;&gt;&lt;i&gt;&lt;span&gt;allowed The Markup&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt; to understand how Amazon search results pages would appear to ordinary users. Similarly, &lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://www.propublica.org/article/amazon-says-it-puts-customers-first-but-its-pricing-algorithm-doesnt&quot;&gt;&lt;i&gt;&lt;span&gt;ProPublica&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt; used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives. &lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;span&gt;Anonymous web scraping is also crucial &lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://www.sans.org/blog/undercover-operations-scraping-the-cybercrime-underground&quot;&gt;&lt;i&gt;&lt;span&gt;for cybersecurity professionals&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt;, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including &lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/10/privacy-badger-learns-block-ever-more-trackers&quot;&gt;&lt;i&gt;&lt;span&gt;EFF’s Privacy Badger&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt;, also crawl sites anonymously to identify trackers without compromising user privacy.&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span&gt;Laws like S9934A sweep far beyond AI, targeting anonymity rather than the real technical issue: overaggressive crawling that can overtax technological infrastructure. Unmasking crawlers won&#039;t fix these server strains, but it will chill vital public-interest research and compromise digital privacy. Addressing the harms of web scraping requires narrow technical solutions—not policies that give publishers veto power over the open web. This is why we are calling on Governor Hochul to veto S9934A.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;You can &lt;a href=&quot;https://www.eff.org/document/ny-s9934a-stealth-crawlers-request-veto&quot;&gt;read the &lt;/a&gt;&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/ny-s9934a-stealth-crawlers-request-veto&quot;&gt;&lt;span&gt;full letter here&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. For a deeper dive into why crawlers and scrapers are vital for the open web, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/stealth-crawlers-are-not-threat-open-web-bills-targeting-them-would-be&quot;&gt;&lt;span&gt;check out this blog post&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 03 Aug 2026 23:25:40 +0000</pubDate>
 <guid isPermaLink="false">112243 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/issues/anonymity">Anonymity</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <dc:creator>Tori Noble</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-robot-warhol-2.png" alt="robot portraits Warhol-style" type="image/png" length="211803" />
  </item>
  <item>
    <title>EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal</title>
    <link>https://www.eff.org/deeplinks/2026/08/eff-joins-comments-calling-ftc-drop-its-ai-policy-proposal</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.&lt;span&gt;” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class=&quot;kY2IgmnCmOGjharHErah N56cWZpP8cNJu1dqgCxB&quot;&gt;&lt;span&gt;The new proposed policy builds on, and directly references, the Trump administration’s  &lt;a href=&quot;https://www.whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/&quot;&gt;“Preventing Woke AI in the Federal Government”&lt;/a&gt; executive order—a &lt;a href=&quot;https://www.eff.org/deeplinks/2025/08/president-trumps-war-woke-ai-civil-liberties-nightmare&quot;&gt;nightmare for civil liberties&lt;/a&gt; that seeks to strong-arm AI companies into modifying their models to conform with the its ideological agenda.&lt;/span&gt;&lt;/span&gt; In recently filed &lt;a href=&quot;https://www.eff.org/document/eff-pk-fftf-comments-ftc-re-concerning-suppression-accuracy-artificial-intelligence-systems&quot;&gt;comments&lt;/a&gt;, EFF,  &lt;a href=&quot;https://publicknowledge.org/&quot;&gt;Public Knowledge&lt;/a&gt;, and &lt;a href=&quot;https://www.fightforthefuture.org/&quot;&gt;Fight for the Future&lt;/a&gt; call for the FTC to stop its unconstitutional efforts to regulate lawful speech, override state laws, and intimidate AI developers into ideological alignment with the Trump administration.&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;The government may not install itself as the arbiter of truth.&lt;/p&gt;

&lt;p&gt;In the joint comments, we outline three critical flaws within the latest proposed policy. First, it violates the First Amendment. The policy calls for the Commission to become the judge of which AI outputs meet an undefined standard of accuracy. Installing the FTC as the authority of this sort of viewpoint-based judgment is a prior restraint on speech. Additionally, the policy&lt;span&gt;’&lt;/span&gt;s proposed solution to address speech concerns compounds, rather than properly limits, the likely harms to speech. As we say in our comments: the government may not install itself as the arbiter of truth. &lt;/p&gt;
&lt;p&gt;Second, it exceeds the FTC&lt;span&gt;’&lt;/span&gt;s legal authority by claiming that its federal regulatory rules can override, or “preempt,&lt;span&gt;”&lt;/span&gt; laws in states that have passed to regulate artificial intelligence use. This is clearly an attempt to target state laws the administration disagrees with. For example, the policy specifically criticizes &lt;a href=&quot;https://leg.colorado.gov/bills/SB26-189&quot;&gt;Colorado&#039;s automated decisionmaking law&lt;/a&gt;, which applies when automated technology is used to consider consequential decisions such as those around employment, access to housing, health care, and insurance. We noted to the FTC that characterizing this law as one that requires AI companies to “suppress accuracy,” or encourages deception, is itself inaccurate. In any case, the FTC lacks the authority to put its rules in place over state law, unless Congress directly delegates it that power. It has been given no such power here.&lt;/p&gt;
&lt;p&gt;Third, the policy is vague and sets the stage for improper &lt;a href=&quot;https://www.eff.org/deeplinks/2022/06/when-jawboning-creates-private-liability&quot;&gt;jawboning&lt;/a&gt; of AI developers and companies that use AI tools (deployers). Jawboning is a term for situations in which &lt;span class=&quot;kY2IgmnCmOGjharHErah N56cWZpP8cNJu1dqgCxB&quot;&gt;&lt;span&gt;the government urges private companies or people to censor another&#039;s speech. The proposal, as written, &lt;/span&gt;&lt;/span&gt;creates an enforcement regime that would put a thumb on the scale in favor of certain partisan speech and ideals. This will lead companies to censor only what the &lt;em&gt;administration&lt;/em&gt; interprets as biased or untruthful. Yet, in our filing, we note that the FTC itself can&#039;t define an objective standard for what “bias” means, conceding the “exact line of what constitutes bias may be difficult to draw.”&lt;/p&gt;
&lt;p&gt;There is work the FTC should be doing to protect consumers in the age of AI. In our comments, we conclude by saying:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;[We] implore the Commission to focus on its core strengths and the mission for which it is so urgently needed—promoting structural market competition and protecting consumers from real unfair and deceptive acts and practices—in both the burgeoning and critically important AI industry and across the broader technology marketplace.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;EFF and our partners have always urged the FTC to police genuine deception in technology markets. We have also consistently opposed government efforts to dictate what private speakers may say. That&lt;span&gt;’&lt;/span&gt;s why we urge the FTC to withdraw this proposal. &lt;/p&gt;
&lt;p&gt;You can read our full comments &lt;a href=&quot;https://www.eff.org/document/eff-pk-fftf-comments-ftc-re-concerning-suppression-accuracy-artificial-intelligence-systems&quot;&gt;here&lt;/a&gt;. &lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 03 Aug 2026 22:17:56 +0000</pubDate>
 <guid isPermaLink="false">112238 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Tori Noble</dc:creator>
 <dc:creator>Hayley Tsukayama</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/icon-2026-ai-robot-v2.png" alt="A human face with a bright cog inside and a colorful background" type="image/png" length="17646" />
  </item>
  <item>
    <title>The Youth AI Privacy Act’s Privacy Paradox</title>
    <link>https://www.eff.org/deeplinks/2026/08/youth-ai-privacy-acts-privacy-paradox</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;&lt;strong&gt;Update:&lt;/strong&gt; The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The Senate Commerce Committee is poised to consider the&lt;/span&gt; &lt;a href=&quot;https://www.congress.gov/119/bills/s4199/BILLS-119s4199is.pdf&quot;&gt;&lt;span&gt;Youth AI Privacy&lt;/span&gt; &lt;span&gt;Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would&lt;span&gt;—&lt;/span&gt;like &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/chatbot-act-forces-one-parenting-model-every-family&quot;&gt;three&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/screen-act-threatens-privacy-far-beyond-adult-websites&quot;&gt;other&lt;/a&gt; bills under consideration this week—require more data collection and make it harder for people to access lawful speech online. &lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;While the bill is narrower than some other proposed chatbot bills, it still has massive data &lt;/span&gt;&lt;span&gt;security implications because it protects information for only certain users. This creates a problem we’ve cited many times before: if a bill requires that online services offer protections to minor users, the services will respond &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/02/eff-court-strike-down-age-estimation-california-not-consumer-privacy&quot;&gt;&lt;span&gt;by imposing age gates&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to know which users should receive them. A better approach would be to offer the same privacy protections to all users. That way, we would avoid the services having to collect data on everyone to know a users’ age.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This bill also contains a problematic and vague provision that expressly allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing &quot;harm to users”—without being clear on what exactly that means. Either way, services will need to collect even more information from young people, who are &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/age-verification-systems-are-surveillance-systems#main-content&quot;&gt;&lt;span&gt;already targets&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of data theft and identity fraud. The Youth AI Privacy Act will give young people less privacy, not more. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The Youth AI Privacy Act does include some positive privacy provisions around prohibiting the processing of personal information, like limiting what companies can do with people’s chat logs, including training, profiling, and disclosing them to other companies for training. But a general privacy bill must set these limits for everyone, not just minors.&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Mandating Design is Regulating Speech&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The bill also requires the use of “safe design features,” which would restrict how online services providers design their systems and would deny teenagers the ability to use features like push alerts and notifications.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We have seen this same type of restriction, sometimes called “age appropriate design code” in several states, including in &lt;/span&gt;&lt;a href=&quot;https://www.courtlistener.com/docket/66636540/74/netchoice-llc-v-bonta/&quot;&gt;&lt;span&gt;California&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://cdt.org/wp-content/uploads/2023/09/FSC-v.-Colmenero-amicus-brief-.pdf&quot;&gt;&lt;span&gt;Texas&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/03/age-verification-mandates-would-undermine-anonymity-online&quot;&gt;&lt;span&gt;Arkansas&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Unfortunately, these restrictions run into constitutional problems. In fact, federal courts have largely blocked these laws from going into effect because they likely violate the First Amendment rights of all internet users and the online services they regulate. Specifically, these laws interfere with internet users’ First Amendment rights to either speak or access speech online, and they also violate the rights on online services to decide how they will present information on their sites. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Similarly, the Supreme Court has repeatedly &lt;/span&gt;&lt;a href=&quot;https://www.loc.gov/item/usrep422205/&quot;&gt;&lt;span&gt;ruled&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that “minors are entitled to a significant measure of First Amendment protection.” This does not mean that parents or guardians can’t set their own rules for their families&lt;span&gt;—&lt;/span&gt;they can and they should, based on the needs and circumstances of the individual teenagers. But it does mean that Congress cannot adopt a “one size fits all” regulation that sets a restrictive government default that affects the First Amendment rights of all internet users, including teenagers. &lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 03 Aug 2026 21:08:45 +0000</pubDate>
 <guid isPermaLink="false">112241 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Maddie Daly</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-robots-emotion.png" alt="Two robots, one smiling, one frowning (photo: Nicholas-Halodi CC-BY) " type="image/png" length="580680" />
  </item>
  <item>
    <title>EFF at BSidesLV, Black Hat, and DEF CON 👨‍💻</title>
    <link>https://www.eff.org/deeplinks/2026/07/eff-bsideslv-black-hat-and-def-con</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;It&#039;s time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: &lt;a href=&quot;https://www.eff.org/event/eff-bsides-las-vegas-1&quot;&gt;BSidesLV&lt;/a&gt;, &lt;a href=&quot;https://www.eff.org/event/eff-black-hat-usa-2&quot;&gt;Black Hat USA&lt;/a&gt;, and &lt;a href=&quot;https://www.eff.org/event/eff-def-con-34&quot;&gt;DEF CON&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;EFF&#039;s lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you&#039;re attending the conference and have any legal concerns about an upcoming talk or sensitive infosec research—during the Las Vegas conferences or anytime—don&#039;t hesitate to reach out to &lt;a href=&quot;mailto:info@eff.org&quot;&gt;info@eff.org&lt;/a&gt; where &lt;a href=&quot;https://www.eff.org/deeplinks/2020/08/digital-rights-ground-view-effs-intake-desk&quot;&gt;our intake team&lt;/a&gt; is ready to assist! Share a brief summary of the issue, and we&#039;ll do our best to connect you with the right resources. You can also learn more about our work supporting technologists on our &lt;a href=&quot;https://www.eff.org/issues/coders&quot;&gt;Coders&#039; Rights Project page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Be sure to swing by the expo areas at all three conferences to say hello to your friendly neighborhood EFF staffers! You&#039;ll probably spot us roaming the conference halls, but we&#039;d love for you to stop by our booths to catch up on our latest work, get on our action alerts, and become an EFF member! For the whole week, we&#039;ll have our limited-edition DEF CON 34 t-shirt on hand. We&#039;re excited to see them—and other EFF gear—take over each conference!&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://eff.org/join&quot;&gt;&lt;img src=&quot;/files/2026/08/03/2026_defcon_shirt_all-fronts-01-150dpi.png&quot; width=&quot;1200&quot; height=&quot;600&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;EFF Staff Presentations&lt;/h2&gt;
&lt;h4&gt;Privacy&#039;s Defenders: How Hackers Helped and Can Do So Again&lt;/h4&gt;
&lt;p&gt;Hackers have a long history standing up for justice and that history has a lot to teach and inspire the hackers of today as we face a world with 360-degree surveillance that is increasingly marshaled against us by both companies and governments. My talk will tell background and stories from my book, Privacy&#039;s Defender, that tells the story of my 30 years working with EFF to try to protect security and privacy in the digital age. Cards on the table: I&#039;m trying to recruit you to join in the fight.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;WHERE: Florentine F | BSides Las Vegas&lt;br /&gt;WHEN: Monday, August 3 @ 11:00&lt;br /&gt;WHO: Cindy Cohn - Former EFF Executive Director &lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Ask EFF at BSidesLV&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Panelists from the EFF Staff will give brief updates on key topics in their expertise before turning it over to BSides attendees to ask their burning questions about policy, advocacy and making the future of tech brighter. It&#039;s a dynamic session fostering engaging discussions on digital rights featuring an EFF staff attorney, activist, and public interest technologist.&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;WHERE: Florentine F | BSides Las Vegas&lt;em&gt;&lt;br /&gt;&lt;/em&gt;WHEN: Tuesday, August 4 @ 14:00&lt;br /&gt;WHO: EFF&#039;s Rory Mir, Kenyatta Thomas, Alexis Hancock, Haley Pederson, and Cindy Cohn&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;What Election Security Researchers Need to Know about Section 1201 of the Digital Millennium Copyright Act&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;WHERE: Voting Village | DEF CON&lt;br /&gt;WHEN: Friday, August 7, 10:30-11:00&lt;br /&gt;WHO: EFF Staff Attorney Tori Noble&lt;/p&gt;
&lt;h4&gt;Privacy&#039;s Defender: How Hackers Protected the Internet Before and Can Do It Again&lt;/h4&gt;
&lt;p&gt;EFF&#039;s Outgoing Executive Director Cindy Cohn&#039; presents her first-person stories from her recently published book, Privacy&#039;s Defender, that take you Inside the privacy battles that have shaped today&#039;s Internet. It includes the hackers who helped free up encryption technology from US governmental control, allowing us to have the still imperfect privacy and security we now have online, and the battles to stop the mass NSA spying and eternal gag orders that arose from the governments formerly secret mass spying programs in the aftermath of the 9/11 attacks. She then draws from that long career of legal activism to the fights of today and tomorrow, featuring the role that hackers can play in helping to bring about a better, more just future.&lt;br /&gt;WHERE: Creator Stage 1 | DEF CON&lt;br /&gt;WHEN: Friday, August 7, 15:00-16:30&lt;br /&gt;WHO: Former EFF Executive Director, Cindy Cohn&lt;/p&gt;
&lt;h4&gt;Why Mandatory Age Verification Keeps Us All Less Safe&lt;/h4&gt;
&lt;p&gt;WHERE: Creator Stage 7 | DEF CON&lt;br /&gt;WHEN: Saturday, August 8, 13:30-14:30&lt;br /&gt;WHO: EFF Director of Engineering Alexis Hancock &amp;amp; EFF Social Media and Video Manager Kenyatta Thomas&lt;/p&gt;
&lt;h4&gt;ESP32 As A Counter-Surveillance Platform&lt;/h4&gt;
&lt;p&gt;Privacy should be accessible to all. Historically, counter-surveillance tools have been expensive, complex, and inaccessible to most individuals, often limited to well-funded researchers and costly hardware configurations. The ESP32 offers a transformative alternative. This presentation will demonstrate how an affordable microcontroller has become the foundation for a growing suite of open-source, user-friendly anti-surveillance tools. We will discuss the technical features that make the ESP32 a compelling choice for these applications, including passive 802.11 and Bluetooth monitoring, OUI-based device fingerprinting, and robust cryptographic capabilities. Applications include detecting police body cameras in operational environments, mapping Flock Safety automatic license plate recognition (ALPR) infrastructure, identifying unauthorized drones, detecting radio frequency jamming across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous robots operating with known-vulnerable firmware. These tools are cost-effective and freely available. We will also consider future developments in accessible counter-surveillance hardware, such as the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc. Advancing anti-surveillance culture requires designing devices that individuals are motivated to use and carry.&lt;br /&gt;WHERE: Main Track 1 | DEF CON&lt;br /&gt;WHEN: Sunday, August 9, 10:00-11:00&lt;br /&gt;WHO: EFF Senior Staff Technologist Cooper Quintin&lt;/p&gt;
&lt;h4&gt;Tactical Advocacy: Panel &amp;amp; Peer Sessions with EFF&lt;/h4&gt;
&lt;p&gt;WHERE: Policy Village | DEF CON&lt;br /&gt;WHEN: Sunday, August 9, 12:30-14:00&lt;br /&gt;WHO: EFF&#039;s Thorin Klosowski, Cooper Quintin, Alexis Hancock, Tori Noble, Rory Mir &amp;amp; Cindy Cohn&lt;/p&gt;
&lt;h2&gt;EFF Contests at DEF CON 34&lt;/h2&gt;
&lt;h4&gt;EFF Benefit Poker Tournament&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;We’re going all in on internet freedom. Take a break from hacking the Gibson to&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/poker&quot;&gt;face off with your competition at the tables&lt;/a&gt;&lt;span&gt;—and benefit EFF! Your buy-in is paired with a donation to support EFF’s mission to protect online privacy and free expression for all.&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/poker&quot;&gt;Join us&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;on Friday, August 7 at 12:00 at the&lt;/span&gt;&lt;span&gt;Horseshoe&lt;/span&gt;&lt;span&gt; Poker Room. Play for glory. Play for money. Play for the future of the web.&lt;br /&gt;WHERE: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas, NV 89109&lt;/span&gt;&lt;br /&gt;&lt;span&gt;WHEN: Friday, August 7, 12:00-15:00&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span&gt;Beard and Mustache Contest&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;Yes, it&#039;s exactly what it sounds like. Join EFF at the intersection of facial hair and hacker culture. Spectate, heckle, or compete in any of four categories: Full beard, Partial Beard, Moustache  Only, or Freestyle (anything goes so create your own facial apparatus!). Prizes! Donations to EFF! Beard oil!&lt;br /&gt;WHERE: Contest Stage (near the entrance to Hall 1)&lt;br /&gt;WHEN: Friday, August 7, 13:00-15:00&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span&gt;Tech Trivia Contest&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;Join us for some &lt;a href=&quot;https://www.eff.org/event/tech-trivia-def-con-34&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;tech trivia on Saturday, August 8&lt;/a&gt;! EFF&#039;s privacy and security experts have crafted a new trivia challenge for DEF CON 34! Compete as a team in our no-holds-barred showdown to prove mastery over the obscure facts of digital security, online rights, and internet culture. The First Place team wins a set of custom Cybertiger Champion Badges and EFF swag. Second and third place teams will also win Badges and EFF gear. Invite your friends OR show up and make new friends! Did someone say BRIBES? The world is unfair! You too could influence the judges to add a point or two to your team&#039;s tally. Overall Bribe winner also wins a custom badge!&lt;br /&gt;WHERE: Contest Stage (near the entrance to Hall 1)&lt;br /&gt;WHEN: Saturday, August 8, 17:00-20:00&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Privacy&#039;s Defender Book Signing with Cindy Cohn&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Grab a copy of former EFF Executive Director Cindy Cohn&#039;s new book, &lt;a href=&quot;https://shopeff.org/products/privacys-defender-by-cindy-cohn&quot;&gt;Privacy&#039;s Defender&lt;/a&gt;—and get it signed—while at DEF CON 34!&lt;br /&gt;WHERE: Exhibit Hall West 4 (Book Signings)&lt;br /&gt;WHEN: Saturday, August 8, 11:00-12:00 AND 13:00-14:00 &lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Join the Cause!&lt;/strong&gt;&lt;/h2&gt;
&lt;p class=&quot;subhead&quot;&gt;Come find our table at BSidesLV (Middle Ground), Black Hat USA (back of the Business Hall), and DEF CON (Vendor Hall) to learn more about the latest in online rights, get on our action alert list, or&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://eff.org/join&quot;&gt;donate to become an EFF member&lt;/a&gt;. We&#039;ll also have our limited-edition DEF CON 34 shirts available starting Monday at BSidesLV! These shirts have a puzzle incorporated into the design. Snag one online for yourself starting on Tuesday, August 4 if you&#039;re not in Vegas!&lt;/p&gt;
&lt;p class=&quot;subhead take-action&quot;&gt;&lt;a href=&quot;https://eff.org/join&quot;&gt;Join EFF&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;subhead take-explainer&quot;&gt;Support Security &amp;amp; Digital Innovation&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 03 Aug 2026 14:45:00 +0000</pubDate>
 <guid isPermaLink="false">112232 at https://www.eff.org</guid>
 <dc:creator>Christian Romero</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/2026_defcon-manyhands-eff-banner.png" alt="EFF logo with a skull and crossbones wearing red glasses" type="image/png" length="32405" />
  </item>
  <item>
    <title>Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy</title>
    <link>https://www.eff.org/deeplinks/2026/07/amending-ab-1709-doesnt-fix-it-californias-social-media-ban-still-threatens-free</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;California lawmakers have amended &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1709&quot;&gt;&lt;span&gt;A.B. 1709&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, but the core problem remains: the bill is still a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/act-now-stop-californias-paternalistic-and-privacy-destroying-social-media-ban&quot;&gt;&lt;span&gt;ban on social media access for youth under 16&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and it still threatens the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/age-verification-privacy-nightmare&quot;&gt;&lt;span&gt;privacy&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/age-verification-bills-are-unconstitutional&quot;&gt;&lt;span&gt;First Amendment&lt;/span&gt;&lt;/a&gt;&lt;span&gt; rights of all Californians.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Proponents of the bill may argue that the recent amendments represent a &lt;/span&gt;&lt;a href=&quot;http://www.eff.org/deeplinks/2025/02/eff-ninth-circuit-young-people-have-first-amendment-right-use-social-media-and-all&quot;&gt;&lt;span&gt;compromise&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, but a close look at the text shows no major changes. As the bill moves forward in the Senate, we must continue to urge lawmakers to vote NO.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167034/&quot;&gt;Take Action: Tell Your Senator to OPPOSE A.B. 1709&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;A &quot;Compromise&quot; That Still Denies Access&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Under the newly amended Section 22683, platforms are prohibited from offering &quot;addictive features&quot; to users under 16. A platform can allow a minor to keep an account only if it strips away these features, which include what the bill calls &quot;addictive feeds,&quot; auto-play, and anything else the Attorney General designates in future rulemaking.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;However, the bill defines &quot;addictive feeds&quot; so broadly that it covers virtually every functional recommendation algorithm. The bill applies this label to any presentation of user-generated content recommended &quot;in whole or in part, on information provided by the user.&quot; That includes basic inputs like who a user follows, what posts they like, or their self-expressed interests. By calling these basic tools and features “addictive,&quot; the bill also makes broad conclusions about the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/science-not-settled-how-weak-evidence-fueling-national-push-ban-social-media-youth&quot;&gt;&lt;span&gt;unsettled science&lt;/span&gt;&lt;/a&gt;&lt;span&gt; behind social media use, youth, and addiction.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Because almost every major social media service uses automated feeds to deliver content, the end result of AB 1709 remains the same: young people under 16 will be denied access to major social media services as they currently exist.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if a platform attempts to comply by stripping away recommendation systems for minors, this still violates the First Amendment. Recommendation systems are the primary tools that users rely on to find speech and disseminate their own. Forcing young people onto a stripped-down, dysfunctional version of social media burdens their constitutional &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/eff-ninth-circuit-young-people-have-first-amendment-right-use-social-media-and-all&quot;&gt;&lt;span&gt;right to access information and participate in public discourse&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;AB 1709 Still Forces Invasive Age Verification&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The amendments do not eliminate the privacy threats posed by age gating. Although the bill references the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/ab-1043s-internet-age-gates-hurt-everyone&quot;&gt;&lt;span&gt;age-signaling framework in AB 1043&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, Section 22684 explicitly states that a covered platform &quot;shall verify the age of a user” and makes platforms liable every time a person under 16 makes it through an age check. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Because AB 1043 does not actually specify how verification should occur without requiring additional proof, AB 1709 will, in practice, force platforms to implement the strictest forms of age verification. To comply, platforms will likely require users to upload government-issued IDs or submit to biometric scanning. Forcing users to turn over their personal information will create massive &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/age-verification-privacy-nightmare&quot;&gt;&lt;span&gt;honeypots of sensitive personal data&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, destroying online &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/03/age-verification-mandates-would-undermine-anonymity-online&quot;&gt;&lt;span&gt;anonymity&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and exposing users of all ages to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/age-verification-systems-are-surveillance-systems&quot;&gt;&lt;span&gt;security breaches.&lt;/span&gt;&lt;/a&gt;&lt;span&gt; And relying on biometric systems to verify users’ ages is &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/face-scans-estimate-our-age-creepy-af-and-harmful&quot;&gt;&lt;span&gt;problematic&lt;/span&gt;&lt;/a&gt;&lt;span&gt; because the systems have historically had high error rates estimating ages across &lt;/span&gt;&lt;a href=&quot;https://sciencepolicy.hsites.harvard.edu/blog/racial-discrimination-face-recognition-technology&quot;&gt;&lt;span&gt;race and gender lines&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167034/&quot;&gt;Take Action: Tell Your Senator to OPPOSE A.B. 1709&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Lawmakers Must Reject AB 1709&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The amendments to AB 1709 also introduce legal confusion, creating provisions that conflict with already enacted legislation like &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/eff-ninth-circuit-young-people-have-first-amendment-right-use-social-media-and-all&quot;&gt;&lt;span&gt;SB 976&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Rather than providing clarity or protecting young people, AB 1709 creates a tangled regulatory scheme that sacrifices constitutional rights for political grandstanding.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Denying minors access to digital forums—or stripping those forums of the basic tools needed to navigate them—is censorship. California should not set a national precedent of cutting young people off from digital lifelines, communities, and speech.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We need to keep the pressure on as AB 1709 moves through the Senate. Contact your state senator today and tell them that minor tweaks to a bad bill do not make it good policy.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 31 Jul 2026 19:47:34 +0000</pubDate>
 <guid isPermaLink="false">112235 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverification-banner2-1a.png" alt="A concerned parent and child stand on a large laptop keyboard, while a shadowy hand reaches out from the screen with social media icons and a magnifying glass to scan them." type="image/png" length="1146559" />
  </item>
  <item>
    <title>The SCREEN Act Threatens Privacy Far Beyond Adult Websites </title>
    <link>https://www.eff.org/deeplinks/2026/07/screen-act-threatens-privacy-far-beyond-adult-websites</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;&lt;strong&gt;Update: &lt;/strong&gt;On August 5, 2026, The Senate Commerce Committee &lt;a href=&quot;https://www.politico.com/news/2026/08/05/senate-panels-vote-for-kids-safety-rules-throws-gauntlet-to-house-01025574&quot;&gt;voted 15-13 to advance this bill&lt;/a&gt;, but the bill did not advance because of a lack of Senators in attendance. EFF continues to oppose the bill. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The Senate Commerce Committee is set to consider &lt;/span&gt;&lt;a href=&quot;https://www.congress.gov/bill/119th-congress/senate-bill/737/text&quot;&gt;&lt;span&gt;S. 737&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.  &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;protect your right to browse the web privately&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a &lt;/span&gt;&lt;i&gt;&lt;span&gt;single&lt;/span&gt;&lt;/i&gt;&lt;span&gt; piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/online-vs-person-id-checks&quot;&gt;&lt;span&gt;dramatically different&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;The SCREEN Act Attacks Your Right To Use VPNs&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users&#039; ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server&#039;s IP address, not your actual location. It&#039;s like sending a letter through a P.O. box so the recipient doesn&#039;t know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Tell Congress to oppose the s&lt;/a&gt;creen act&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 31 Jul 2026 19:41:55 +0000</pubDate>
 <guid isPermaLink="false">112234 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>India McKinney</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  <item>
    <title>The CHATBOT Act Forces One Parenting Model On Every Family</title>
    <link>https://www.eff.org/deeplinks/2026/07/chatbot-act-forces-one-parenting-model-every-family</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;&lt;strong&gt;Update:&lt;/strong&gt; The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced &lt;/span&gt;&lt;a href=&quot;https://www.congress.gov/bill/119th-congress/senate-bill/4407/text&quot;&gt;&lt;span&gt;CHATBOT Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt; answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Tell Congress not to age-gate the internet&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;The Bill Requires AI Companies To Build Family Monitoring Systems &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Parents are &lt;/span&gt;&lt;a href=&quot;https://www.pewresearch.org/internet/2026/02/24/what-parents-say-about-their-teens-ai-use/&quot;&gt;&lt;span&gt;approaching AI in different ways&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As part of the required parental-consent process for teens, AI companies must offer parents a &quot;family account&quot; that provides access to a &quot;full record of the conversations and activity&quot; of teen users and tools to &quot;monitor, analyze, and understand, at scale&quot; those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;The CHATBOT Act Creates New Privacy Risks For Families&lt;/b&gt;&lt;b&gt; &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Parents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The vast archives of conversations created by the government-mandated family accounts won&#039;t be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Tell Congress to oppose the &lt;/a&gt;chatbot act&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;The CHATBOT Act Applies A Children’s Law To Teenagers &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The CHATBOT Act takes the basic structure of &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa&quot;&gt;&lt;span&gt;COPPA&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. &lt;/span&gt;&lt;a href=&quot;https://www.facebook.com/terms/&quot;&gt;&lt;span&gt;Facebook&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://help.instagram.com/termsofuse&quot;&gt;&lt;span&gt;Instagram&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.ucsf.edu/news/2025/01/429296/many-children-use-tiktok-against-rules&quot;&gt;&lt;span&gt;TikTok&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://help.x.com/en/rules-and-policies/information-for-parents-and-minor-users&quot;&gt;&lt;span&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://kids.youtube.com/t/terms&quot;&gt;&lt;span&gt;YouTube&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.snap.com/terms&quot;&gt;&lt;span&gt;Snapchat&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://support.discord.com/hc/en-us/community/posts/360050817374-Age-restriction&quot;&gt;&lt;span&gt;Discord&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.spotify.com/us/legal/end-user-agreement/plain/&quot;&gt;&lt;span&gt;Spotify&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and blogging platforms like &lt;/span&gt;&lt;a href=&quot;https://wordpress.com/tos/&quot;&gt;&lt;span&gt;WordPress&lt;/span&gt;&lt;/a&gt;&lt;span&gt; all keep out users under 13. &lt;/span&gt;&lt;span&gt;Children under 13 are also not allowed to use &lt;/span&gt;&lt;a href=&quot;https://support.microsoft.com/en-us/microsoft-copilot/microsoft-copilot-young-people&quot;&gt;&lt;span&gt;Microsoft Co-Pilot&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://support.google.com/gemini/answer/16275805?hl=en&quot;&gt;&lt;span&gt;Google Gemini&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, or &lt;/span&gt;&lt;a href=&quot;https://help.openai.com/en/articles/8313401-is-chatgpt-safe-for-all-ages&quot;&gt;&lt;span&gt;ChatGPT&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Anthropic &lt;/span&gt;&lt;a href=&quot;https://support.claude.com/en/articles/13117299-minimum-age-requirement-access-restriction&quot;&gt;&lt;span&gt;does not allow users under 18&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/01/congress-wants-hand-your-parenting-big-tech&quot;&gt;&lt;span&gt;creating those accounts with parental consent&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting &lt;/span&gt;&lt;i&gt;&lt;span&gt;more&lt;/span&gt;&lt;/i&gt;&lt;span&gt; information about young users. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI system&lt;span&gt;—&lt;/span&gt;the bill’s only option is to create a family account.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, &lt;/span&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Wikipedia:Guidance_for_younger_editors&quot;&gt;&lt;span&gt;uses Wikipedia&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, types search terms into Google, or &lt;/span&gt;&lt;a href=&quot;https://help.nytimes.com/115014893428-Terms-of-Service&quot;&gt;&lt;span&gt;reads a newspaper online&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;The CHATBOT Act Will Pressure AI Companies To Check Users’ Ages &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The bill says it doesn’t require &lt;a href=&quot;https://www.eff.org/issues/age-verification&quot;&gt;age verification&lt;/a&gt;. But like many &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online&quot;&gt;&lt;span&gt;recent “kids online safety” bills&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, it imposes obligations that depend on a company knowing whether a user is under 18. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification.  Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;A Better Way Forward&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Congress doesn&#039;t have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children&#039;s privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Lawmakers have &lt;/span&gt;&lt;a href=&quot;https://www.duckworth.senate.gov/imo/media/doc/260312aitoyslettertoftc1.pdf&quot;&gt;&lt;span&gt;urged the FTC to crack down&lt;/span&gt;&lt;/a&gt;&lt;span&gt; on AI-enabled toys that make unsubstantiated educational claims or illegally collect children&#039;s data. Those are regulatory actions that can be taken right now. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Finally, the FTC is &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions&quot;&gt;&lt;span&gt;currently investigating&lt;/span&gt;&lt;/a&gt;&lt;span&gt; how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/167270/&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;stop this bill&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 31 Jul 2026 19:06:43 +0000</pubDate>
 <guid isPermaLink="false">112233 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Joe Mullin</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-robots-emotion.png" alt="Two robots, one smiling, one frowning (photo: Nicholas-Halodi CC-BY) " type="image/png" length="580680" />
  </item>
  <item>
    <title>EFF Guide to Recording Law Enforcement</title>
    <link>https://www.eff.org/deeplinks/2026/07/eff-guide-recording-law-enforcement</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;em&gt;This post is available as a printable one page handout in &lt;a href=&quot;https://www.eff.org/files/2026/07/20/2026_right_to_record_one-pager.pdf&quot;&gt;English&lt;/a&gt; and &lt;a href=&quot;https://www.eff.org/files/2026/07/30/2026_right_to_record_one-pager_es.pdf&quot;&gt;Spanish&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability and can support movements for social change. But recording officers can come with risks. Below are important legal and practical considerations related to recording the police and other law enforcement officers.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Can I legally record the police or immigration officers?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Yes. All Americans have a First Amendment right to record law enforcement.&lt;/b&gt;&lt;span&gt; This includes local police and federal officers such as those from Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP). Although the Supreme Court has not squarely ruled on the issue, nine different federal appellate courts have recognized and affirmed this right, relying on decades of Supreme Court precedent.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Courts typically frame the right to record law enforcement as &lt;/b&gt;&lt;b&gt;&lt;i&gt;the right to record officers exercising their official duties in public&lt;/i&gt;&lt;/b&gt;&lt;b&gt;.&lt;/b&gt;&lt;span&gt; This right extends to bystanders as well as people &lt;a href=&quot;https://www.eff.org/fourth-circuit-right-to-record&quot;&gt;recording their own interactions&lt;/a&gt; with law enforcement, such as livestreaming their own traffic stops.&lt;/span&gt;&lt;span&gt; The right &lt;a href=&quot;https://www.eff.org/victory-court-protects-right-to-record&quot;&gt;also applies to private places where the recorder has a legal right to be&lt;/a&gt;, such as in their own home.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;You may take photos, or record video and audio. &lt;/b&gt;&lt;span&gt;Courts have held that wiretap laws, which generally protect private conversations, do not prohibit civilians from &lt;/span&gt;&lt;i&gt;&lt;span&gt;audio&lt;/span&gt;&lt;/i&gt;&lt;span&gt; recording law enforcement. That’s because &lt;/span&gt;&lt;i&gt;&lt;span&gt;officers exercising their official duties, particularly in public, do not have a reasonable expectation of privacy&lt;/span&gt;&lt;/i&gt;&lt;span&gt;. Neither do civilians in public places who speak to law enforcement in a manner audible to passersby.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;What are some limitations on the right to record law enforcement?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Courts have been clear that behavior that &lt;/b&gt;&lt;b&gt;obstructs or interferes&lt;/b&gt;&lt;b&gt; with effective law enforcement or the protection of public safety &lt;/b&gt;&lt;b&gt;&lt;i&gt;is not protected&lt;/i&gt;&lt;/b&gt;&lt;b&gt;.&lt;/b&gt;&lt;span&gt; Officers can&#039;t order you to move &lt;/span&gt;&lt;i&gt;&lt;span&gt;because&lt;/span&gt;&lt;/i&gt;&lt;span&gt; you are recording, but they may order you to move for public safety reasons &lt;/span&gt;&lt;i&gt;&lt;span&gt;even if you are recording&lt;/span&gt;&lt;/i&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If the law enforcement officer is &lt;/span&gt;&lt;b&gt;off-duty or is in a private space that you don’t also have a right to be in&lt;/b&gt;&lt;span&gt;, your right to record the officer may be limited. For example, a Los Angeles jury in 2026 found two women guilty of felony stalking after they followed an ICE agent to his home and livestreamed the pursuit.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;What are some other considerations when recording officers?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Even if you believe you are appropriately exercising your First Amendment right to record law enforcement, officers may nevertheless escalate the situation and/or retaliate against you. Below are some things to keep in mind.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Stay calm and courteous.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;If you are a bystander, stand at a &lt;/span&gt;&lt;b&gt;safe distance&lt;/b&gt;&lt;span&gt; from the scene that you are recording. But note that officers may approach and confront you, closing that distance in an effort to accuse you of interfering with and possibly also assaulting a federal officer.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Be alert and mindful of the possibility that officers may &lt;/span&gt;&lt;b&gt;illegally retaliate against you&lt;/b&gt;&lt;span&gt; in a number of ways, including arrest, destruction of your device, and bodily harm. They may also try to retaliate by harming the person being arrested. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Consider the &lt;/span&gt;&lt;b&gt;sensitive nature &lt;/b&gt;&lt;span&gt;of recording in the context of an arrest. For example, the person being arrested or their loved ones may be concerned about exposing their immigration status, so think about obtaining consent or blurring out faces in any version you publish to focus on ICE/CBP conduct (while still retaining the original video). &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Law enforcement may not search your cell phone or other device &lt;/span&gt;&lt;b&gt;&lt;a href=&quot;https://www.eff.org/riley-v-california&quot;&gt;without a warrant&lt;/a&gt; &lt;/b&gt;&lt;span&gt;based on probable cause from a judge&lt;/span&gt;&lt;span&gt;, even if you are under arrest. Thus, &lt;/span&gt;&lt;b&gt;you may refuse a request from an officer to review or delete what you recorded. You also may refuse to unlock your phone or provide your passcode.&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;What can I do to protect my footage?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;How well protected your photos or video footage are depends on both the device and the way you’re recording. If you’re uploading video to a livestreaming service, it can save that video to the cloud if you enable that setting. But what if you want to protect your recordings  stored locally?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Modern smartphones generally protect data, including videos, using encryption. This means if your phone is locked and protected by a strong passphrase, it is more difficult for an officer to delete what you’ve stored on the device. Removing biometrics such as face and fingerprint unlock can protect your device contents further. You can &lt;a href=&quot;//ssd.eff.org/module/how-to-get-to-know-android-privacy-and-security-settings&quot;&gt;check your settings&lt;/a&gt; by following the steps in our Surveillance Self-Defense guides (see below) to &lt;a href=&quot;https://ssd.eff.org/module/how-encrypt-your-iphone&quot;&gt;ensure device encryption is turned on&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Want more information?&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Read more about your right to record law enforcement: https://www.eff.org/issues/right-record&lt;/li&gt;
&lt;li&gt;Read EFF’s Surveillance Self-Defense technical guide: https://ssd.eff.org&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 31 Jul 2026 14:11:24 +0000</pubDate>
 <guid isPermaLink="false">112211 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/right-record">Right to Record</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Sophia Cope</dc:creator>
 <dc:creator>Bill Budington</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/protest-recording-bigboot.jpg" alt="Protesters record on their phones as a massive boot positions to crush." type="image/jpeg" length="267518" />
  </item>
  <item>
    <title>🏃 Fitness Tracker Privacy Fails | EFFector 38.14</title>
    <link>https://www.eff.org/deeplinks/2026/07/fitness-tracker-privacy-fails-effector-3814</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. But what are the companies that make fitness trackers doing to protect our sensitive data from prying eyes? A lot less than they could be, it turns out. We&#039;re explaining what companies can do to protect your health data, and more, with our &lt;a href=&quot;https://eff.org/effector/38/14&quot;&gt;EFFector newsletter&lt;/a&gt;. &lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.eff.org/effector/&quot;&gt;JOIN OUR NEWSLETTER&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For over 35 years, &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFFector&lt;/a&gt; has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers the rapid rise of &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/hundreds-drone-first-responder-programs-could-soon-be-launched-across-country&quot;&gt;police drone programs&lt;/a&gt;, a disappointing ruling on &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/fourth-circuit-says-border-agents-can-search-your-phone-hand-no-suspicion-required&quot;&gt;electronic device searches&lt;/a&gt; at the U.S. border, and &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy&quot;&gt;how fitness trackers are falling down&lt;/a&gt; when it comes to protecting our health data.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Prefer to listen in? EFFector is now available on all major podcast platforms. This time, we&#039;re chatting with EFF Senior Security and Privacy Activist Thorin Klosowski about the health fitness tracker landscape and your privacy. You can find the episode and subscribe&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://effector.simplecast.com/&quot;&gt;on your podcast platform of choice&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: 70px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F8cabd912-722d-436b-a498-815da45f01bf%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/8cabd912-722d-436b-a498-815da45f01bf?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;div class=&quot;mytube&quot;&gt;
&lt;div class=&quot;mytubetext&quot;&gt;&lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/4e65dc91-33af-4dd4-ae88-1c8626b39537?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;span&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/6Q48ICplENdQ4ZarUIgfLZ&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effector/id1882562931&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.com/podcasts/83be1062-f511-47b3-bd2b-fc44e831c3ad&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feeds.eff.org/effector&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Want to protect your right to digital privacy? Sign up for &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFF&#039;s EFFector newsletter&lt;/a&gt; for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you &lt;a href=&quot;https://eff.org/join&quot;&gt;support EFF today&lt;/a&gt;!&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 29 Jul 2026 16:52:58 +0000</pubDate>
 <guid isPermaLink="false">112223 at https://www.eff.org</guid>
 <dc:creator>Christian Romero</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/effector-green-web.png" alt="" type="image/png" length="78242" />
  </item>
  <item>
    <title>San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing</title>
    <link>https://www.eff.org/deeplinks/2026/07/san-francisco-dont-fall-industry-defense-surveillance-pricing</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, collate, and store as much of our personal data as possible, and then monetize it through use and sale. When it comes to surveillance pricing, that looks like corporations offering the same product to two different people at two different prices, based on harvested personal information. That&#039;s why &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/californias-bill-ban-surveillance-pricing&quot;&gt;&lt;span&gt;EFF supports A.B. 2654&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, authored by Assemblymember Chris Ward, which bans this harmful practice. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As an organization based in San Francisco, EFF was proud to learn that the San Francisco Board of Supervisors had also &lt;/span&gt;&lt;a href=&quot;https://media.api.sf.gov/documents/LI071426.pdf&quot;&gt;&lt;span&gt;introduced a resolution&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to similarly support the legislation. However,  we were disappointed to learn the San Francisco Board of Supervisors has since &lt;/span&gt;&lt;a href=&quot;https://www.sfexaminer.com/news/community/board-not-yet-ready-to-weigh-in-on-state-surveillance-pricing-ban/article_0ae4d143-cced-4988-abda-0b71bcbe524c.html&quot;&gt;&lt;span&gt;stalled a vote&lt;/span&gt;&lt;/a&gt;&lt;span&gt; on the &lt;a href=&quot;https://media.api.sf.gov/documents/LI071426.pdf&quot;&gt;resolution&lt;/a&gt; stating their own support for &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB2564&quot;&gt;&lt;span&gt;A.B. 2654&lt;/span&gt;&lt;/a&gt;&lt;span&gt; after receiving an email from the San Francisco Chamber of Commerce criticizing the bill using well-worn and debunked concerns. We’ve sent the Supervisors a &lt;a href=&quot;https://www.eff.org/document/letter-sf-bos-re-surveillance&quot;&gt;letter&lt;/a&gt; asking them to reconsider.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Banning surveillance pricing would be good for consumers. The FTC has found that companies will set higher prices based on personal information. “For instance,” &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/system/files/ftc_gov/pdf/p246202_surveillancepricing6bstudy_researchsummaries_redacted.pdf&quot;&gt;&lt;span&gt;the FTC found last year&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, “if a consumer is profiled as a new parent, the consumer may intentionally be shown higher-priced baby thermometers on the first page of their in-app search results, based on their residential zip code and time of purchase.” Let&#039;s say that again: the U.S. government has found that companies may seek to use surveillance pricing to charge parents searching for a thermometer in the middle of the night &lt;/span&gt;&lt;i&gt;&lt;span&gt;more money&lt;/span&gt;&lt;/i&gt;&lt;span&gt; in a time of need.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://btlj.org/wp-content/uploads/2025/01/39-2_Ozer.pdf&quot;&gt;&lt;span&gt;Privacy is a human right&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, not something that people should understand as a currency to give away or protect based on how it will impact the price of groceries. EFF has&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2020/10/why-getting-paid-your-data-bad-deal&quot;&gt; &lt;span&gt;long&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://www.eff.org/wp/privacy-first-better-way-address-online-harms#Legislation&quot;&gt; &lt;span&gt;opposed&lt;/span&gt;&lt;/a&gt;&lt;span&gt; pay-for-privacy schemes, in which a company charges a higher price to a customer who refuses to submit to processing of their personal data. Surveillance pricing is another version of that practice. You should never have to worry that your privacy rights depend on how much you make.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;At a time when prices for everyday goods continue to climb, some surveillance pricing defenders &lt;/span&gt;&lt;a href=&quot;https://progresschamber.org/project/more-ways-to-save/&quot;&gt;&lt;span&gt;note&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that using personal information could lead to lower prices for some consumers. Yet &lt;/span&gt;&lt;a href=&quot;https://www.cmu.edu/tepper/news/stories/researchers-decode-welfare-effects-pricing-algorithms&quot;&gt;&lt;span&gt;some&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://insights.som.yale.edu/insights/the-perils-of-personalized-pricing&quot;&gt; &lt;span&gt;recent&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://www.sciencedirect.com/science/article/abs/pii/S014829632100727X&quot;&gt; &lt;span&gt;studies&lt;/span&gt;&lt;/a&gt;&lt;span&gt; indicate there will be losers and winners  based on factors such as whether a consumer is willing or able to switch products. Who loses or wins also will turn on the accuracy of the underlying data – yet surveillance pricing is often based on&lt;/span&gt;&lt;a href=&quot;https://www.consumerreports.org/money/questionable-business-practices/kroger-secret-grocery-shopper-loyalty-profiles-unfair-a1011215563/&quot;&gt; &lt;span&gt;false information&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That said, even if surveillance pricing has the capability to lead to lower prices (which it often doesn&#039;t) we oppose it as just another way that corporations try to make customers pay for their privacy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The San Francisco Chamber of Commerce’s concerns are fully addressed in the text of A.B. 2654. The Chamber raises questions about how businesses will comply with the law. But the bill is quite clear: “a retailer shall not engage in surveillance pricing.” It also has a clear definition of what “surveillance pricing” is. The banned practice is defined as: “[i] a customized price for a good for a specific consumer or group of consumers, [ii] based, in whole or in part, on personally identifiable information collected through electronic surveillance,” including if that information is “acquired from a third party.” In other words, “surveillance pricing” is a customized price based on personal information.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The SF  Chamber’s letter also asks about the bill&#039;s “treatment of discounts and loyalty programs.” In this way, too, A.B. 2654 is quite clear. The bill includes three broad carveouts that ensure it doesn&#039;t disrupt loyalty programs and discounts:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;First, for price differences “based solely on costs associated with providing the good to different consumers.”&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Second, for a discount offered to a consumer who is taking steps to terminate a service.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Third, for a discount, conspicuously posted on a retailer’s website, that is uniformly available based on (1) criteria anyone can meet, such as signing up for a mailing list, (2) membership in a broadly defined group, such as seniors, or (3) participation in a loyalty program.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;An opt-in senior discount to the movies is not the problem. The systematic collection of all of our personal information to determine whether someone is a senior and if so whether they should pay more or less for that matinee is. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As we said in our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/californias-bill-ban-surveillance-pricing&quot;&gt;&lt;span&gt;blog post&lt;/span&gt;&lt;/a&gt;&lt;span&gt; outlining our support for this bill:&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;span&gt;Surveillance pricing is very similar to online behavioral advertising, a business practice that EFF urges governments to&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/03/ban-online-behavioral-advertising&quot;&gt; &lt;span&gt;ban&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Both practices incentivize all businesses to collect as much of our personal data as possible, in order to later monetize it. Both practices lead some businesses to collate and store our data into dossiers about us for later use. Both practices use these surveillance-based dossiers to manipulate and limit our economic choices, by altering the advertisements and prices we see online.&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span&gt;We urge the San Francisco Board of Supervisors to join&lt;/span&gt;&lt;a href=&quot;https://techequity.us/surveillance-pricing-ab-2564/&quot;&gt;&lt;span&gt; the coalition&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://cdt.org/wp-content/uploads/2026/03/Bespoke-pricing-Calif-AB2564-coalition-letter.pdf&quot;&gt;&lt;span&gt;of groups&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://advocacy.consumerreports.org/press_release/california-state-assembly-passes-key-bill-to-prohibit-surveillance-pricing/&quot;&gt;&lt;span&gt;that support&lt;/span&gt;&lt;/a&gt;&lt;span&gt; A.B. 2564, and stand against companies mining our personal information to charge us different prices for the same thing. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;You can read our letter to the Supervisors &lt;a href=&quot;https://www.eff.org/document/letter-sf-bos-re-surveillance&quot;&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 28 Jul 2026 21:55:43 +0000</pubDate>
 <guid isPermaLink="false">112228 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/mass-surveillance-technologies">Surveillance Technologies</category>
 <dc:creator>Matthew Guariglia</dc:creator>
 <dc:creator>Hayley Tsukayama</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/third_party_tracking_banner.png" alt="A woman being watched behind a one-way mirror" type="image/png" length="178751" />
  </item>
  <item>
    <title>Why Are Gay Bars Building Databases of Their Patrons?</title>
    <link>https://www.eff.org/deeplinks/2026/07/why-are-gay-bars-building-databases-their-patrons</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;&lt;strong&gt;Update 8/10/2026:&lt;/strong&gt; Two San Francisco bars that used Patronscan have said they will &lt;a class=&quot;theme markdown__link&quot; href=&quot;https://www.sfgate.com/sf-culture/article/bars-face-scanning-reverse-22382172.php&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;stop using the system&lt;/a&gt; after listening to customers’ privacy concerns. EFF applauds this change and we hope other bars follow suit by returning to ID-checking systems that respect their customers’ rights.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Update 8/18/2026:&lt;/strong&gt; A third SF bar has &lt;a href=&quot;https://www.cbsnews.com/sanfrancisco/news/three-san-francisco-bars-drop-id-verification-cameras-following-privacy-concerns/&quot;&gt;stopped using Patronscan&lt;/a&gt;.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;————————————————————&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.advocate.com/news/san-francisco-gay-bars-privacy&quot;&gt;&lt;span&gt;Recent reports&lt;/span&gt;&lt;/a&gt;&lt;span&gt; have &lt;/span&gt;&lt;a href=&quot;https://sf.gazetteer.co/why-do-these-castro-gay-bars-have-tsa-style-face-scanners&quot;&gt;&lt;span&gt;raised alarm&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether those images are used for facial recognition.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;A broader privacy concern also deserves scrutiny. For years, PatronScan has marketed itself not just as an ID-verification tool, but as a system that allows bars and clubs to identify patrons, keep records about them, and share information across venues. As one news article published in 2019 &lt;/span&gt;&lt;a href=&quot;https://onezero.medium.com/id-at-the-door-meet-the-security-company-building-an-international-database-of-banned-bar-patrons-7c6d4b236fc3&quot;&gt;&lt;span&gt;documented&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, PatronScan built a network that allowed participating bars to flag patrons and share information about them with other establishments. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And in California, it’s not at all clear how PatronScan’s business model of scanning IDs and sharing the information from those scans with other bars comports with the law. California’s &lt;/span&gt;&lt;a href=&quot;https://codes.findlaw.com/ca/civil-code/civ-sect-1798-90-1/&quot;&gt;&lt;span&gt;ID privacy law&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which was amended in 2018 to add ID “scans,” states that no businesses shall “retain or use” any information from a scanned ID card except for limited purposes such as to verify age, comply with a legal requirement, or prevent fraud. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Californians should be deeply concerned about businesses that collect information from government-issued IDs and use it to build databases about where people go, whom they associate with, and whether they should be allowed into other public gathering places. That concern is especially strong in LGBTQ+ spaces, which have long served as refuges for people to go &lt;/span&gt;&lt;i&gt;&lt;span&gt;without&lt;/span&gt;&lt;/i&gt;&lt;span&gt; being tracked, monitored, or put on lists. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;We reached out to Patronscan with questions regarding their practices and their views on California ID law. They referred us to their &lt;a href=&quot;https://patronscan.com/policies/&quot;&gt;published FAQ&lt;/a&gt; question “Is Patronscan privacy compliant in California?” which claims that the use of Patronscan kiosks is legal in California. They also said “Patronscan does not do facial recognition in North America, or any kind of automated analysis of the ID or the live photo image.” &lt;/p&gt;
&lt;h3&gt;&lt;b&gt;The California Legislature Has Investigated PatronScan’s Business Model &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;In 2018, the California Legislature published bill analyses (on that year&#039;s &lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201720180AB2769&quot;&gt;AB 2769&lt;/a&gt;) that went into detail about PatronScan’s business. Reviewing PatronScan&#039;s own materials, the California Senate Judiciary Committee &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/ca-senate-floor-analysis-ab-2769&quot;&gt;&lt;span&gt;found that the company had collected and retained information&lt;/span&gt;&lt;/a&gt;&lt;span&gt; on 561,087 customers in Sacramento alone during the first five months of 2018—a remarkable figure for a city whose population had only recently topped 500,000.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Lawmakers also found that at that time, PatronScan retained information for at least 90 days or longer in some cases, shared information among participating bars, and maintained bans that lasted an average of more than 19 years. A PatronScan “Public Safety Report” used 10,000 scans collected on a single day to report on “where customers live, how far they have traveled, and how many different venues the customers patronized.” &lt;/p&gt;
&lt;p&gt;&lt;span&gt;This was not simply checking IDs at the door. PatronScan was building a database. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;An immigrants’ rights group, the Coalition for Human Immigrant Rights (CHIRLA), &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/ca-assembly-floor-analysis-ca-2769&quot;&gt;&lt;span&gt;wrote about its concern&lt;/span&gt;&lt;/a&gt;&lt;span&gt; at the time with these growing ID databases, saying that “placing individuals on a database that labels them a &quot;threat to public safety&quot; has “significant immigration consequences that could lead to deportation, revoking of current status, or denial of future immigration relief.” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Today, Patronscan &lt;/span&gt;&lt;a href=&quot;https://patronscan.com/policies/&quot;&gt;&lt;span&gt;states&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that it retains personal information about all customers for 21 days, and about flagged customers for up to five years. This includes the customer’s name, date of birth, photograph, gender, and zip code. It also includes the dates and times that the customer entered particular bars. Such databases are a grave privacy threat. Personal data is routinely stolen by thieves, misused by a company’s employees, seized by government agencies, and diverted to new purposes by a company’s executives. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;California Law Still Bans ID-Scan Databases, And Bars Should Follow That Law&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;In 2018, California lawmakers closed what they viewed as a loophole. Existing law already prohibited businesses from retaining or using information obtained when they “swiped” a driver&#039;s license, except for the narrow purposes of legal requirements (like a judicial warrant) or “preventing fraud, abuse, or material misrepresentation.” &lt;/p&gt;
&lt;p&gt;&lt;span&gt;After reviewing companies like PatronScan, the Legislature amended the law to make clear that the same restrictions that apply to businesses that “swipe” ID cards also apply when those IDs are “scanned.” PatronScan opposed that change, arguing it wanted to preserve the ability to share information among bars so participating venues could decide whether to admit patrons.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The bill became law anyway. Yet PatronScan continues to market and sell a system that apparently retains information from scanned IDs, and allows participating venues to flag patrons and share information across its network. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;At a minimum, that raises serious questions about how those practices fit with California&#039;s existing ID privacy law. Bar and nightlife venue owners who utilize PatronScan should think twice about its effects on their customers, and consider going back to standard, visual ID checks. These physical checks have been effective at keeping underage patrons out of 21-and-over venues for decades, and don’t present the serious privacy dangers of creating a private database of bar patrons. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For venues serving vulnerable communities like immigrants or the LGBTQ+ community, the stakes of using this technology are even higher. It’s disappointing and alarming to see some of California’s more well-known LGBTQ+ nightlife spots instead lining up as PatronScan’s early adopters. A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database. These businesses should reject PatronScan, return to the standard ID checks that every other bar has been able to utilize, and prove to their customers that their privacy and security still matters. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 28 Jul 2026 16:19:13 +0000</pubDate>
 <guid isPermaLink="false">112222 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Joe Mullin</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ca-privacy-general-2.png" alt="lock icon with CA state map &amp;amp; vintage colors" type="image/png" length="486510" />
  </item>
  <item>
    <title>Missed EFF&#039;s Livestream with Adam Savage and iFixit? Listen Here!</title>
    <link>https://www.eff.org/deeplinks/2026/07/miss-last-weeks-livestream-adam-savage-and-ifixit-listen-here</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;EFF’s first &lt;a href=&quot;https://www.eff.org/pages/effecting-change&quot;&gt;EFFecting Change livestream&lt;/a&gt; was all the way back in July of 2024. Maybe you&#039;ve caught each stream, or maybe you’ve only caught a few. Or maybe you’re like me and prefer to listen to conversations like these on your daily commute! Either way, if you want to stay on top of these monthly conversations, you can now subscribe to our new podcast feed for EFFecting Change—starting with our conversation on the &lt;a href=&quot;https://www.eff.org/issues/right-to-repair&quot;&gt;Right to Repair movement&lt;/a&gt; with Adam Savage and iFixit CEO Kyle Wiens:&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: 70px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F1ffaef7d-fd63-4133-8f3e-c28a98ff9f60%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/1ffaef7d-fd63-4133-8f3e-c28a98ff9f60?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/033VcugZJe3H2KiyqCcl8N?si=3JzdDgThSdCIj-Nr9rtZjg&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effecting-change/id6794432321&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.com/podcasts/1e8fde0e-5f44-49b3-94a3-11254cb29663/effecting-change&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feedpress.me/effectingchange&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;This new feed will include the full conversations with our panelists, posted after the livestream ends. Subscribe today to get each stream straight to your podcast player of choice. You can also find other podcasts by EFF at &lt;a href=&quot;https://eff.org/podcast&quot;&gt;eff.org/podcast&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;And mark your calendar for the next EFFecting Change livestream: &lt;a href=&quot;https://www.eff.org/livestream-ai&quot;&gt;Who the Machine Serves&lt;/a&gt;. EFF Executive Director Nicole Ozer and Cory Doctorow will be having a conversation on AI, tackling what needs to happen now to ensure AI actually works for everyone, not just those in power. &lt;a href=&quot;https://www.eff.org/livestream-ai&quot;&gt;RSVP today&lt;/a&gt;!&lt;/p&gt;
&lt;p&gt;Want to ensure EFF can keep inviting expert panelists to chat about the future of technology and how it impacts you? Support our work today.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://eff.org/SupportChange&quot;&gt;Donate to EFF&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 27 Jul 2026 19:25:18 +0000</pubDate>
 <guid isPermaLink="false">112221 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/right-to-repair">Defend Your Right to Repair!</category>
 <dc:creator>Christian Romero</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/effectingchange_banner.png" alt="The words &amp;quot;EFFecting Change&amp;quot; on a black background with red, white, and grey ribbons" type="image/png" length="118140" />
  </item>
  <item>
    <title>Farmers Are Getting Control Of Their Equipment Back </title>
    <link>https://www.eff.org/deeplinks/2026/07/farmers-are-getting-control-their-equipment-back</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;For years, John Deere had actively made repairing their tractors near-impossible for anyone but itself and the few &quot;authorized&quot; repair shops—regardless of the ability of its customers to actually visit such shops. Now, in a major win for farmers and right to repair advocates, John Deere must soon provide farmers with not just the tools and resources to finally repair their own John Deere equipment, but also access to future updates for said equipment.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;In 2025, the Federal Trade Commission (FTC) brought a suit against farm equipment manufacturer John Deere, alleging John Deere used their control over equipment repair tools and resources to limit the ability of farmers and independent repair providers (IRPs) to repair John Deere equipment. Earlier this month, John Deere reached &lt;/span&gt;&lt;a href=&quot;https://www.ftc.gov/system/files/ftc_gov/pdf/Deere-JointMotion-StipOrd.pdf&quot;&gt;&lt;span&gt;a settlement &lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-states-secure-settlement-deere-company-advancing-farmers-right-repair&quot;&gt;&lt;span&gt;with the FTC&lt;/span&gt;&lt;/a&gt;&lt;span&gt; in which they will immediately make available a tranche of repair resources, then continue to make further resources available until the end of the year. Five states joined the FTC in this suit, and over the next 10 years these states will work alongside the FTC to ensure John Deere complies with this settlement. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;It is worth noting there is a second, farmer-initiated antitrust lawsuit against John Deere, also concerning a farmer’s right to repair their own equipment. In April, John Deere agreed to a&lt;/span&gt;&lt;a href=&quot;https://nationalaglawcenter.org/john-deere-agrees-to-settle-antitrust-lawsuit/&quot;&gt;&lt;span&gt; $99 million settlement &lt;/span&gt;&lt;/a&gt;&lt;span&gt;in that case, which also includes right to repair provisions.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;This fight is just one example of how, as machines become increasingly computerized, companies &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2016/12/john-deere-really-doesnt-want-you-own-tractor&quot;&gt;&lt;span&gt;like John Deere &lt;/span&gt;&lt;/a&gt;&lt;span&gt;restrict your ability to repair machines behind software&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/dmca-rulemaking&quot;&gt;&lt;span&gt; subject to legal regimes &lt;/span&gt;&lt;/a&gt;&lt;span&gt;that don’t just lock down repair, but make unauthorized repair a potential criminal offense. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;John Deere’s market dominance in farm equipment led to an extraordinary power over access to the tools and resources of repair. John Deere actively restricted who had access to repair tools, and monopolized who could do the repair. This revenue stream—and control of it—is built into the business models of a lot of the technology we buy today. It also encourages companies to move away from the kinds of devices that can be easily fixed at home to ones that offer bells and whistles no one wants but makes repair difficult—like app-enabled toasters. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;This whole saga with John Deere has been an exemplar of the greater need for right to repair laws, policy, and enforcement.  There was a time when you bought a tractor and with some know-how and a manual could fix it yourself. It is easy to envision why someone with John Deere farm equipment might find it inconvenient to wait for John Deere approved repairpeople to come and fix any broken equipment. Especially when it meant waiting for days or weeks. Especially if it meant their crop was &lt;/span&gt;&lt;a href=&quot;https://publicinterestnetwork.org/wp-content/uploads/2023/04/Out-to-Pasture.pdf&quot;&gt;&lt;span&gt;withering on the vine&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. This settlement will help ensure this is no longer the case. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But it’s not just about farm equipment; &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/right-to-repair&quot;&gt;&lt;span&gt;If you can’t fix it, you don’t own it&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. While some might feel more willing to agree they “shouldn’t” futz with laptops or smartphone, it still stands that — whether it’s farm equipment, a car, a laptop, or even your phone — if you legally cannot fix it yourself, if you must go hat in hand to an “approved provider,” you are at the mercy of a corporation. It is why EFF continues to support right to repair laws that ensure people truly own what they buy. And it is why EFF continues to fight for exemptions to the law that makes it most difficult to tinker and repair your own devices. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 24 Jul 2026 18:18:28 +0000</pubDate>
 <guid isPermaLink="false">112218 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/right-to-repair">Defend Your Right to Repair!</category>
 <dc:creator>Chao Liu</dc:creator>
 <dc:creator>Katharine Trendacosta</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/fixcopyright-graphic-banner.jpg" alt="EFF Presents &amp;quot;Fix Copyright&amp;quot;, a design featuring a cartoon mouse hacking his tractor." type="image/jpeg" length="359162" />
  </item>
  <item>
    <title>Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country</title>
    <link>https://www.eff.org/deeplinks/2026/07/hundreds-drone-first-responder-programs-could-soon-be-launched-across-country</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Police departments across the country are lining up to launch drone-as-first-responder (DFR) programs, and hundreds have cleared a necessary hurdle toward making deployment a reality, expanding aerial surveillance and data collection even in areas patrol officers typically can&#039;t reach.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;As of February 2026, &lt;/span&gt;&lt;a href=&quot;https://docs.google.com/spreadsheets/d/1FpoISaAdmQLtMKelPy1sdCOLvYVNxSXBVzASo-I-djI/edit?gid=0#gid=0&quot;&gt;&lt;span&gt;over 1,000 public safety agencies&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—including police, fire, and other emergency management agencies—had received Federal Aviation Administration (FAA) waivers needed to automate drone operations and launch a DFR program, according to a recent Freedom of Information Act (FOIA) release listing agencies that have obtained &lt;/span&gt;&lt;a href=&quot;https://www.faa.gov/uas/public_safety_gov/public_safety_toolkit/Public_Aircraft-Public_Safety_Operation_CoW-COA_FAQ.pdf&quot;&gt;&lt;span&gt;Part 91 waivers&lt;/span&gt;&lt;/a&gt;&lt;span&gt; since the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/drone-first-responder-programs-2025-review&quot;&gt;&lt;span&gt;FAA &lt;/span&gt;&lt;/a&gt;&lt;span&gt;streamlined and sped up the process in April 2025.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;The changes led to a massive increase in the number of waivers issued. Only 976 DFR waivers had been granted since the first DFR program launched in 2018 through April 2025, according to an FAA representative. The agency issued more waivers between April 2025 and February 2026 than it had in the previous seven years combined.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;a href=&quot;https://www.google.com/maps/d/u/0/viewer?mid=1cKmm6M-3ssutj7bTMi-dU-me90NDZP0&amp;amp;ll=40.447369026323244%2C-92.16257714038733&amp;amp;z=4&quot; title=&quot;Map of locations with DFR waivers&quot;&gt;&lt;img src=&quot;/files/2026/07/23/202607_dfr_map.png&quot; width=&quot;1388&quot; height=&quot;796&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;caption-text&quot;&gt;A map illustrating the locations of police departments and other public safety agencies that have received Part 91 waivers, making it possible for them to launch drone-as-first-responder programs. (This map image links to Google Maps, which is governed by Google&#039;s privacy policy)&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&lt;span&gt;The new FAA process for waivers and the rush of police departments to obtain them signifies a shift in law enforcement&#039;s use of drones: from human-operated aerial surveillance to AI-based autonomous drone use. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;Typically, a drone operator is only permitted to fly in areas that can still be seen by the pilot, and that drone pilot needs to be certified under FAA Part 107. To fly drones “Beyond Visual Line of Sight” (BVLOS) requires additional approval from the FAA, as do flights above 200 feet, due to the risk of colliding with planes and other aircrafts. Without such approval, an officer could not pilot a drone from a desk inside a building and fly it to a call across the city because they could not possibly have line of sight on the drone. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;FAA rules for police drones also required a human operator to manually fly the device to a scene, but DFR technology has become &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/beware-bundle-companies-are-banking-becoming-your-police-departments-favorite&quot;&gt;&lt;span&gt;a more common and more automated police technology&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. DFR programs increasingly rely on artificial intelligence to automate drone flights from launchpads placed around the city, often atop municipal buildings, and make it possible for one drone operator to “fly” multiple devices at once. Though not every police department that has received BVLOS has launched a DFR program yet, by going through this process, &lt;/span&gt;&lt;a href=&quot;https://docs.google.com/spreadsheets/d/1FpoISaAdmQLtMKelPy1sdCOLvYVNxSXBVzASo-I-djI/edit?gid=0#gid=0&quot;&gt;&lt;span&gt;every department on this list&lt;/span&gt;&lt;/a&gt;&lt;span&gt; has signified it has strong enough interest to clear the necessary regulatory hurdles.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;Police departments and the companies that sell DFR equipment claim that these drones make it easier for officers to establish “situational awareness” of a scene before they arrive. Early drone adoption centered on similar claims, particularly related to high-risk situations like vehicular accidents or incidents involving an armed suspect. However, these kinds of situations may make up only a small portion of deployments, which often occur in response to low-risk calls for service related to unhoused people, mental health concerns, and &lt;/span&gt;&lt;a href=&quot;https://www.aclu.org/documents/eye-in-the-sky-policing-needs-strict-limits&quot;&gt;&lt;span&gt;loud music&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, as a &lt;/span&gt;&lt;a href=&quot;https://www.govtech.com/biz/data/drone-cops-the-future-of-policing-american-cities&quot;&gt;&lt;span&gt;Government Technology analysis&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of the system in Chula Vista, California, found&lt;/span&gt;&lt;i&gt;&lt;span&gt;.&lt;/span&gt;&lt;/i&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;DFR programs have become important sources of revenue for companies like Flock Safety and Axon, the latter of which &lt;/span&gt;&lt;a href=&quot;https://www.sec.gov/Archives/edgar/data/1069183/000162828026031285/axon-20260506xex991.htm&quot;&gt;&lt;span&gt;reported that its DFR&lt;/span&gt;&lt;/a&gt;&lt;span&gt; platform has become one of the company’s fastest growing sectors. Axon is also known for products like the TASER and the Fusus camera system that lets police integrate viewing of public and private cameras. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;Footage from drone flights is streamed back to a police office, and it can be stored, shared, and analyzed like other video. Turning drone footage into fodder for automated license plate reader (ALPR) networks, for example, requires very little additional software, and Flock Safety was &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/drone-sky-could-be-tracking-your-car&quot;&gt;&lt;span&gt;quietly able to turn its drones into “flying ALPRs” last year&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;The normalization of police DFR programs jeopardizes privacy in communities across the country. As flying cameras, drones can capture footage from areas typically inaccessible to a casual patrol officer—backyards, roofs, through windows—at distances that leave subjects of surveillance completely unaware of the spy in the sky. &lt;/span&gt;&lt;a href=&quot;https://www.wired.com/story/sfpd-drone-video-leak-surveillance/&quot;&gt;&lt;span&gt;A recent leak of drone footage&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from the San Francisco Police Department illustrated the ease with which surreptitious drone flights could observe innocent individuals for minutes without them realizing it. EFF&#039;s &lt;a href=&quot;https://www.atlasofsurveillance.org/search?location=&amp;amp;technologies%5Bdrones%5D=on&amp;amp;sort=&quot;&gt;Atlas of Surveillance&lt;/a&gt; contains a list of police departments with drones, including those with DFR programs.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;While daytime DFR use grows, police departments are exploring other ways to expand overhead surveillance. In October 2024, the &lt;/span&gt;&lt;a href=&quot;https://www.campbellca.gov/m/newsflash/home/detail/976&quot;&gt;&lt;span&gt;Campbell Police Department in California announced&lt;/span&gt;&lt;/a&gt;&lt;span&gt; it had received the first FAA approval for BVLOS operations at night, claiming it was the “first to incorporate radar technology with electro-optical sensors to enhance airspace monitoring, enabling a single remote pilot to safely deploy drones both day and night.”  &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;As communities consider drone use, it’s crucial that they have a say in whether the program is acquired at all, not just how it&#039;s run once purchased. Throughout the process, police should be transparent with the community and comply with local regulations about its adoption.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;Many cities provide portals that log the flight paths and reasons for each drone flight, often in real time, an important transparency practice. In California, under &lt;/span&gt;&lt;a href=&quot;https://legiscan.com/CA/text/AB481/id/2435304&quot;&gt;&lt;span&gt;AB 481&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, police departments are required to provide advance notice of intent to acquire drones, establish policies before they’re procured, and provide annual updates on their uses—giving communities and city councils the opportunity, before any contract is signed, to weigh in or object to the acquisition itself. &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span&gt;For police departments and communities considering drone use, clear policies on appropriate use, transparency around deployment, and regular re-evaluation—including the choice to discontinue a program that isn&#039;t working—are all vital for protecting people’s privacy and security. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 23 Jul 2026 22:00:00 +0000</pubDate>
 <guid isPermaLink="false">112216 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/street-level-surveillance">Street-Level Surveillance</category>
 <dc:creator>Beryl Lipton</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/drone-police-by-shelby-criswell.png" alt="police drone on tan background" type="image/png" length="109457" />
  </item>
  <item>
    <title>The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required</title>
    <link>https://www.eff.org/deeplinks/2026/07/fourth-circuit-says-border-agents-can-search-your-phone-hand-no-suspicion-required</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;em&gt;Legal intern &lt;/em&gt;&lt;em&gt;Suzanne Castillo was the principal author of this post.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The Fourth Circuit issued a disappointing opinion in &lt;a href=&quot;https://law.justia.com/cases/federal/appellate-courts/ca4/25-4239/25-4239-2026-07-13.html&quot;&gt;&lt;em&gt;U.S. v. Belmonte Cardozo&lt;/em&gt;&lt;/a&gt;, a case in which EFF filed an &lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/eff-fourth-circuit-electronic-device-searches-border-require-warrant&quot;&gt;amicus brief&lt;/a&gt;, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the National Association of Criminal Defense Lawyers (NACDL).&lt;/p&gt;
&lt;p&gt;We argued that electronic device searches at the border should require a warrant based on probable cause, but at minimum, regardless of whether an officer searches by hand or with forensic software that plugs into a device and downloads its entire contents for search, the same Fourth Amendment standard should apply to all device searches at the border.&lt;/p&gt;
&lt;p&gt;Unfortunately, the court rejected that argument and ruled that a lower standard applies to manual searches, allowing the government to conduct extraordinarily invasive electronic device searches without any suspicion of wrongdoing, simply because the border officer chooses to search by hand rather than with a forensic tool.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;The Border Search Exception Meets Your Phone&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;The &lt;a href=&quot;https://constitution.congress.gov/constitution/amendment-4/&quot;&gt;Fourth Amendment&lt;/a&gt; requires that government searches of persons or property be reasonable, which usually means obtaining a warrant based on probable cause from a judge.&lt;/p&gt;
&lt;p&gt;But a warrantless search can still be reasonable if it falls within an exception to the warrant requirement, including the exception that allows officers to search your belongings at the border. The border search exception allows warrantless searches of persons or property crossing the U.S. border, including the functional equivalent of the border such as international airports, given the government’s interests in controlling &lt;a href=&quot;https://supreme.justia.com/cases/federal/us/431/606/&quot;&gt;who and what may enter the country&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Historically, courts have categorized border searches of luggage, vehicles, and personal effects as “routine” and thus reasonable even if conducted without any suspicion that the traveler has engaged in wrongdoing; courts have also held that more invasive “nonroutine” searches, such as certain &lt;a href=&quot;https://supreme.justia.com/cases/federal/us/473/531/&quot;&gt;body searches&lt;/a&gt; and searches that &lt;a href=&quot;https://supreme.justia.com/cases/federal/us/541/149/&quot;&gt;damage property&lt;/a&gt;, require reasonable suspicion.&lt;/p&gt;
&lt;p&gt;But a person’s privacy interests in the personal data on a phone or laptop are extraordinarily different than their limited privacy interests in the contents of their suitcase.&lt;/p&gt;
&lt;p&gt;The Supreme Court addressed cell phone privacy in &lt;a href=&quot;https://scholar.google.com/scholar_case?case=8132273445572991924&quot;&gt;&lt;em&gt;Riley v. California&lt;/em&gt; (2014)&lt;/a&gt;, holding that the search-incident-to-arrest exception to the warrant requirement did not apply to cell phones, thereby generally requiring a warrant for phone searches, at least at the interior of the country. The court recognized the unprecedented privacy interests people have in their cell phones and how even brief manual searches can reveal the “sum of an individual’s private life,” including our political affiliations, religious beliefs, sexuality, and more. Accordingly, the Supreme Court held that because electronic device searches bear “little resemblance” to searches of bags or physical containers, they should be evaluated differently.&lt;/p&gt;
&lt;p&gt;Following &lt;em&gt;Riley&lt;/em&gt;, the Fourth Circuit considered two border device search cases involving forensic searches, in which border officers used external software to extract and analyze a device’s data.&lt;/p&gt;
&lt;p&gt;In &lt;a href=&quot;https://scholar.google.com/scholar_case?case=150597407311153261&quot;&gt;&lt;em&gt;U.S. v. Kolsuz &lt;/em&gt;(2018)&lt;/a&gt;, the Fourth Circuit held that a forensic search of a cell phone at the border “must be considered a nonroutine border search, requiring some measure of individualized suspicion” of a transnational offense, but the court declined to decide whether the standard is only reasonable suspicion or instead a probable cause warrant.&lt;/p&gt;
&lt;p&gt;Then in &lt;a href=&quot;https://scholar.google.com/scholar_case?case=8486127174869807366&quot;&gt;&lt;em&gt;U.S. v. Aigbekaen &lt;/em&gt;(2019)&lt;/a&gt;, the Fourth Circuit held that a forensic device search at the border in support of a purely domestic law enforcement investigation requires a warrant. The court also reiterated the general &lt;em&gt;Kolsuz&lt;/em&gt; rule for a forensic border-related device search: the “Government must have individualized suspicion of an offense that bears some nexus to the border search exception&#039;s purposes of protecting national security, collecting duties, blocking the entry of unwanted persons, or disrupting efforts to export or import contraband.”&lt;/p&gt;
&lt;p&gt;In &lt;em&gt;Belmonte Cardozo&lt;/em&gt;, manual searches were finally before the court.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;A Disappointing Decision&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Jose Belmonte Cardozo was already on the U.S. government’s radar when he traveled from Bolivia to the U.S. and was met by a U.S. Customs and Border Protection (CBP) officer at Washington Dulles International Airport. The officer manually searched his cell phone and found child sexual abuse material (CSAM), considered “digital contraband,” leading to Belmonte Cardozo’s arrest and criminal prosecution.&lt;/p&gt;
&lt;p&gt;At issue on appeal was what standard should apply to manual device searches at the border. The Fourth Circuit held that, unlike forensic searches, manual searches are “routine” and thus reasonable under the Fourth Amendment without a warrant or individualized suspicion.&lt;/p&gt;
&lt;p&gt;The court’s holding hinged on four differences between manual and forensic searches: (1) in a manual search, a person does the searching, not a machine; (2) a manual search’s breadth depends on the officer’s time and energy, while forensic searches are comprehensive; (3) manual searches reveal only what a user can typically access, while forensic searches can uncover deleted files, cached fragments, metadata, and more; and (4) manual searches are subject to an officer’s fading memory or imperfect notes, while forensic searches create a permanent copy.&lt;/p&gt;
&lt;p&gt;But in identifying these technical differences, the court never explains &lt;em&gt;why&lt;/em&gt; they justify a lower standard for manual searches.&lt;/p&gt;
&lt;p&gt;The Fourth Circuit’s holding is problematic because, as we argued in our amicus brief, manual searches reach the &lt;em&gt;same&lt;/em&gt; categories of data as forensic searches—data that can reveal highly personal aspects of our identities and our lives. It does not matter if a search is conducted by an agent’s thumbs or by software: the end result is equally as invasive, therefore all device searches should fall under the warrant requirement, or at least the same Fourth Amendment standard.&lt;/p&gt;
&lt;p&gt;The court repeatedly emphasized that the search here lasted only two minutes, suggesting that the time-limited search was not privacy-invasive. But an individual’s privacy interests in their personal data don’t change based on &lt;em&gt;how&lt;/em&gt; their phone is searched or &lt;em&gt;how long&lt;/em&gt;. Scrolling for two minutes through someone’s personal text messages or photos is an invasion of privacy that may reveal intimate details about the person even in that short period of time.&lt;/p&gt;
&lt;p&gt;Moreover, as devices’ native search functions improve, manual searches can surface personal information in seconds through keyword searches, &lt;a href=&quot;https://support.apple.com/guide/iphone/search-for-photos-and-videos-iph392d77d5f/ios&quot;&gt;even for photos&lt;/a&gt;, where it might have taken an hour of scrolling to find the same information, further showing that a time-limited search is not necessarily less privacy-invasive. What matters is not the breadth of the search itself, but the unprecedented (and growing) breadth of data on our phones.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;A Silver Lining&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;There’s one silver lining: by relying on the fact that the search lasted two minutes, the Fourth Circuit left open the possibility that lengthier manual searches could trigger heightened suspicion requirements. But until a clear line is drawn, border officers within the &lt;a href=&quot;https://www.ca4.uscourts.gov/about-the-court&quot;&gt;Fourth Circuit’s jurisdiction&lt;/a&gt; can use manual searches to sidestep heightened Fourth Amendment standards that would otherwise apply. In the meantime, EFF will keep fighting against extraordinarily invasive warrantless, suspicionless device searches at the border, and for robust privacy standards to protect our most personal data.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 22 Jul 2026 22:30:31 +0000</pubDate>
 <guid isPermaLink="false">112217 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/border-searches">Border Searches</category>
 <category domain="https://www.eff.org/taxonomy/term/72">Legal Analysis</category>
 <dc:creator>Sophia Cope</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/og-borderagents-2_0.png" alt="" type="image/png" length="3507" />
  </item>
  <item>
    <title>New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression  </title>
    <link>https://www.eff.org/deeplinks/2026/07/new-eu-court-justice-ruling-platform-liability-could-cause-collateral-damage</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Intermediary liability laws &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/05/platform-liability-trends-around-globe-taxonomy-and-tools-intermediary-liability&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;around the world&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/03/rewriting-intermediary-liability-law-what-eff-asks-and-you-should-too&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;recognize&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate with others and participate in public debate, and foster innovation online. These laws generally shield platforms, to varying degrees, from legal liability for user content: the responsibility for unlawful speech should rest primarily with the speaker, not with those who merely host it. &lt;/span&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;These&lt;/span&gt; liability protections are &lt;a href=&quot;https://www.eff.org/deeplinks/2022/05/platform-liability-trends-around-globe-safe-harbors-increased-responsibility&quot;&gt;not a gift&lt;/a&gt; for platforms.&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;They exist so that platforms&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt; are not encouraged to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/08/general-monitoring-not-answer-problem-online-harms&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;proactively monitor and filter&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; what we say online, or to remove even lawful speech simply to avoid legal risk.&lt;/span&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This is why a recent judgment by the EU Court of Justice, &lt;/span&gt;&lt;/b&gt;&lt;a href=&quot;https://infocuria.curia.europa.eu/tabs/jurisprudence?publishedId=C-188%2F24&amp;amp;searchTerm=C%252D188%252F24&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;Coyote System&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;(Joined Cases C-188/24 and C-190/24), &lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;is concerning: it could deprive online platforms of liability protection because of how they organize and disseminate user content. The consequences for freedom of expression could be significant.&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-GB&quot; class=&quot;TextRun MacChromeBold SCXW231073070 BCX0&quot; xml:lang=&quot;EN-GB&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW231073070 BCX0&quot; data-ccp-parastyle=&quot;pdq2pg_selectionanchorcontainer&quot; data-ccp-parastyle-defn=&quot;[201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Times New Roman&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Times New Roman&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Times New Roman&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;pdq2pg_selectionanchorcontainer&amp;quot;,201340122,&amp;quot;2&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;pdq2pgselectionanchorcontainer&amp;quot;,335572020,&amp;quot;1&amp;quot;,335559705,&amp;quot;2057&amp;quot;,134233118,&amp;quot;true&amp;quot;,134233117,&amp;quot;true&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}&quot;&gt;Liability Protections in the EU&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP Selected SCXW231073070 BCX0&quot; data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The European Union has long embraced a system of limited liability for online service providers. Under the e-Commerce Directive and now the &lt;/span&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Digital_Services_Act&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Digital Services Act (DSA)&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, platforms benefit from liability exemptions for user content. To discourage censorship, they also cannot be required to generally monitor user content or actively search for illegal activity. But that liability protection comes with &lt;/span&gt;qualifications&lt;span data-contrast=&quot;auto&quot;&gt;: Platforms &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;lose this benefit if they play an &quot;active role&quot; such that they have &lt;/span&gt;knowledge of, or control over, user-provided information&lt;span data-contrast=&quot;auto&quot;&gt; (Recital 42 ECD, Recital 18 DSA, and case law, for example para. 113 in &lt;/span&gt;&lt;a href=&quot;https://eur-lex.europa.eu/legal-content/en/TXT/HTML/?uri=CELEX:62024CC0188&quot;&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;L’Oréal v eBay)&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For hosting services, providers must remove or disable content they know to be illegal. The DSA has introduced extensive due diligence obligations for platforms but left these foundational immunities intact. &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The message is clear: platforms bear responsibility for proper systems and processes, but generally not for users&#039; speech.&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Coyote System&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, however, could &lt;/span&gt;undermine this balance.&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Confronted with a case about restrictions on navigation systems that transmit information to drivers about roadside checks, the Court formulated a general test for when an intermediary ceases to be a &quot;neutral&quot; host and therefore loses the hosting liability exemption. In essence, the Court held that where an intermediary&#039;s algorithm goes beyond merely categorizing and indexing user information to determine, &quot;&lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;under what conditions, how and in which order of priority&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;&quot; (para. 122) information is disseminated, the intermediary &quot;controls&quot; that information and is deprived of protection under the e-Commerce Directive.&lt;/span&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Let&#039;s be clear: the case is &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;not about a service that ranked or recommended user-generated content in the way social media platforms do.&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt; It is about the collection and real-time relay of user alerts about roadside checks.&lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;However, &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;the Court&#039;s reasoning is not confined to navigation services. &lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Recommendation algorithms determine how and in what order user content is disseminated across virtually every major online platform. &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Should such platforms now cease to qualify as neutral intermediaries and lose the protection of the hosting liability exemption? The answer should be no.&lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-GB&quot; class=&quot;TextRun MacChromeBold SCXW169279319 BCX0&quot; xml:lang=&quot;EN-GB&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW169279319 BCX0&quot; data-ccp-parastyle=&quot;isselectedend&quot; data-ccp-parastyle-defn=&quot;[201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Times New Roman&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Times New Roman&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Times New Roman&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;isselectedend&amp;quot;,201340122,&amp;quot;2&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;isselectedend&amp;quot;,335572020,&amp;quot;1&amp;quot;,335559705,&amp;quot;2057&amp;quot;,134233118,&amp;quot;true&amp;quot;,134233117,&amp;quot;true&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}&quot;&gt;The Meaning of Control&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP Selected SCXW169279319 BCX0&quot; data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Control has never been understood this broadly. Nor should it be. Every hosting service provider, think of Facebook, Amazon or Bluesky, will have some control over users’ content. If that ability alone ruled the analysis, the liability exemption would become largely meaningless. Instead, the disqualifying “active role” must relate to the actual content itself, not merely the technical means by which that content is organised or disseminated.&lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Court’s own case law reinforces this conclusion: &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In &lt;/span&gt;&lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:62018CJ0682&quot;&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;YouTube and Cyando&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, it examined a platform that categorises, ranks and recommends user content through algorithms, yet still proceeded on the basis that it could generally benefit from the hosting liability exemption. To be sure, the Court was mainly addressing specific knowledge of illegal content rather than the separate category of control. Even so, the underlying premise is clear: &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;those features do not, by themselves, place a platform outside of protection&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Advocate General therefore &lt;/span&gt;&lt;a href=&quot;https://infocuria.curia.europa.eu/tabs/document?source=document&amp;amp;text=&amp;amp;docid=228712&amp;amp;pageIndex=0&amp;amp;doclang=en&amp;amp;mode=req&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;explained&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that what matters is the provider&#039;s &quot;intellectual control of that content&quot; (para 152). The relevant question is who controls the information itself, makes it their own, not who determines how it appears.&lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;That is precisely where &lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Coyote System&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; breaks new ground and offers a dangerous &lt;/span&gt;&lt;/b&gt;&lt;a href=&quot;https://eulawanalysis.blogspot.com/2026/06/the-end-of-immunity-for-internet.html?m=1&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;change of emphasis&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. By equating algorithmic organisation with content control, the ruling risks excluding social networks and other platforms from the liability exemption and encouraging proactive monitoring of what users say online and removal of lawful content.&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;That outcome would have terrible consequences for freedom of expression in the EU. It’s also &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;difficult to reconcile with the structure of the DSA&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, which certainly does not treat recommendation algorithms as incompatible with intermediary immunity. On the contrary, it accepts them as a defining feature of modern platforms, regulates them extensively through dedicated due diligence obligations, and still leaves the hosting liability regime untouched (it even integrated the &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;YouTube &lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;ruling in its preamble!). &lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This was no accident: During the DSA negotiations, proposals to deprive platforms of the hosting liability exemption if they optimize, classify, organize or otherwise promote online content were rejected, following successful &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/dsa-joint-letter-ep&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;advocacy by EFF and allies&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Would the Court have decided this case differently under the DSA? Probably not. It’s more plausible that the EU judges were influenced by the specific nature of the service, which could explain why the judgment says remarkably, and sadly, little about why intermediary liability exists in the first place and the fundamental rights it serves. &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Coyote System&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; did not merely transmit user reports but aggregated them into what the Advocate General &lt;/span&gt;&lt;a href=&quot;https://infocuria.curia.europa.eu/tabs/jurisprudence?publishedId=C-188%2F24&amp;amp;searchTerm=C-188%2F24&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;described&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; as a new &quot;information layer,&quot; a distinction &lt;/span&gt;&lt;a href=&quot;https://verfassungsblog.de/eugh-coyote-russmedia-haftung-plattformen/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;omitted&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; by the Court.&lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt;&lt;span class=&quot;EOP Selected SCXW169279319 BCX0&quot; data-ccp-props=&quot;true}&quot;&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-GB&quot; class=&quot;TextRun MacChromeBold SCXW233784235 BCX0&quot; xml:lang=&quot;EN-GB&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW233784235 BCX0&quot; data-ccp-parastyle=&quot;isselectedend&quot; data-ccp-parastyle-defn=&quot;[201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Times New Roman&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Times New Roman&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Times New Roman&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;isselectedend&amp;quot;,201340122,&amp;quot;2&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;isselectedend&amp;quot;,335572020,&amp;quot;1&amp;quot;,335559705,&amp;quot;2057&amp;quot;,134233118,&amp;quot;true&amp;quot;,134233117,&amp;quot;true&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}&quot;&gt;Chipping Away &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW233784235 BCX0&quot; data-ccp-parastyle=&quot;isselectedend&quot;&gt;at &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW233784235 BCX0&quot; data-ccp-parastyle=&quot;isselectedend&quot;&gt;Intermediary Liability Protections&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP Selected SCXW233784235 BCX0&quot; data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The danger is that the Court&#039;s broad language on algorithmic curation reaches well beyond that narrow category and, &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;unintentionally or not, &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;chips away at one of the most important safeguards for freedom of expression online.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Unfortunately, &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Coyote System&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; does not stand alone. It is the latest in a &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;line of judgments that have gradually narrowed intermediary liability protections&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Recently, in &lt;/span&gt;&lt;a href=&quot;https://verfassungsblog.de/cjeu-russmedia/&quot;&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;Russmedia&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, the Court privileged preventive content control in the name of data protection, paying &lt;/span&gt;&lt;a href=&quot;https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6966821&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;little regard&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to the possibility of reconciling both regimes and the privacy costs of increased monitoring of user content. And in &lt;/span&gt;&lt;a href=&quot;https://infocuria.curia.europa.eu/tabs/affair?lang=en&amp;amp;sort=AFF_NUM-DESC&amp;amp;searchTerm=%2522C%252D421%252F24%2522&amp;amp;publishedId=C-421%2F24&quot;&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;AGCOM&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, concerning Google&#039;s liability for YouTube videos uploaded by creators participating in its Partner Programme, the Court appears to leap from eligibility reviews to specific knowledge of illegal content.&lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;There is a&lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; political risk too.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;auto&quot;&gt; While the top court’s reasoning will be applied by national courts and further refined over time, the European Commission has shown little hesitation in incorporating landmark rulings into legislation. Just recently, in its digital omnibus proposal, it selectively restated part of a recent Court of Justice &lt;/span&gt;&lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62023CJ0413&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;judgment&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/eus-new-digital-package-proposal-promises-red-tape-cuts-guts-gdpr-privacy-rights&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;justify narrowing privacy rights&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; of users.&lt;/span&gt;&lt;span data-ccp-props=&quot;true}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;If these trends continue, freedom of expression online will become collateral damage in the EU.&lt;/span&gt;&lt;span data-ccp-props=&quot;259}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 22 Jul 2026 08:34:12 +0000</pubDate>
 <guid isPermaLink="false">112214 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/cda230">Section 230</category>
 <category domain="https://www.eff.org/issues/eu-policy">EU Policy</category>
 <category domain="https://www.eff.org/issues/eu-policy-principles">Digital Services Act</category>
 <dc:creator>Christoph Schmon</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/cjeu.png" alt="CJEU" type="image/png" length="80540" />
  </item>
  <item>
    <title>Protect Your Privacy with California&#039;s DROP Tool</title>
    <link>https://www.eff.org/deeplinks/2026/07/what-you-need-know-about-californias-drop-tool</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Are you a California resident? Then we&#039;ve got exciting news for you: there&#039;s a tool just for you that lets you take a single, relatively easy step to protect your privacy. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;It&#039;s called a DROP request. (That&#039;s Delete Request and Opt-out Platform, if you&#039;re fancy). This one bit of paperwork lets you tell every data broker registered in the state of California that you&#039;d like them to delete your information from their databases and request they stop selling and sharing your information. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Here are some things to know about DROP. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(Don’t want all the details and want to just learn how to file a request? &lt;a href=&quot;#Filing&quot;&gt;Skip to this section&lt;/a&gt;.)&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;What does a request do?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Filing a request on the DROP will send a request to delete and opt-out of sale to all the data brokers in California&#039;s registry. Data brokers are companies that collect information about people, repackage that information, and sell it. As of time of writing, a single DROP request reaches 614 brokers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt; After August 1, once data brokers receive a request, they will have 45 days to address the request. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;DROP officially launched on Jan. 1 of this year, but companies have until Aug. 1 to begin complying with requests. That means if you file a request now, you&#039;ll be in on the ground floor.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Didn&#039;t I hear about this before?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;If you pay attention to EFF, you sure did. With your help, we advocated for the law creating the DROP tool, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/08/californias-delete-act-protects-us-data-brokers&quot;&gt;&lt;span&gt;the Delete Act.&lt;/span&gt;&lt;/a&gt;&lt;span&gt; As we said then, we needed the DROP because Californians have&lt;/span&gt;&lt;a href=&quot;https://oag.ca.gov/privacy/ccpa#sectiond&quot;&gt; &lt;span&gt;a right to request&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that companies delete information collected about them, and a right to opt-out of having businesses sell information about them. Yet, in reality, making those requests is an incredibly time-consuming and tedious process. Filing each request is hard. Plus, because data brokers buy, sell, and exchange information with so many companies (and each other) people may not even know who to file a request with. By linking a request to California&#039;s data broker registry, DROP cuts this process down considerably.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We advocated for DROP and the Delete Act because it makes our privacy law more user-friendly, which gives us better control over our data and reduces the risks that the uncontrolled collection and sale of personal information creates in our everyday lives. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;What&#039;s in it for me?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Filing a request benefits you in a few ways. For one, data brokers are often how spammers (or companies that act like spammers) get your email address, phone number, and other ways of contacting you. Removing yourself from data broker lists could lead to a decrease in these kinds of messages. Second, reducing the number of companies that have your personal information also improves your personal cybersecurity, as it decreases the number of firms with your information who could be hacked. Third and finally, it gives you an opportunity to exert more control over how your personal information is collected and used—an important element of privacy. &lt;/span&gt;&lt;span&gt;Unless you opt out, data brokers can sell your private information to &lt;/span&gt;&lt;a href=&quot;https://www.businessinsider.com/how-marketers-use-big-data-to-prey-on-the-poor-2013-12&quot;&gt;&lt;span&gt;predatory companies&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.forbes.com/sites/steveweisman/2026/03/01/data-brokers-fuel-scams-senate-report-on-billions-of-consumer-losses/&quot;&gt;&lt;span&gt;scammers&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.lawfaremedia.org/article/people-search-data-brokers-stalking-and-publicly-available-information-carve-outs&quot;&gt;&lt;span&gt;stalkers&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.nytimes.com/2024/03/11/technology/carmakers-driver-tracking-insurance.html&quot;&gt;&lt;span&gt;insurance companies&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/04/tell-congress-support-fourth-amendment-not-sale-act&quot;&gt;&lt;span&gt;law enforcement&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;What kinds of information will (and won&#039;t) be deleted?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The California Privacy Protection Agency, which administers the DROP, has a &lt;/span&gt;&lt;a href=&quot;https://privacy.ca.gov/drop/personal-information-and-data-brokers/#yourPI&quot;&gt;&lt;span&gt;great resource&lt;/span&gt;&lt;/a&gt;&lt;span&gt; explaining what data are and are not included in a request. But in summary, a request will often deal with identifying information such as: social security number, precise geolocation, browsing history, email address, and phone numbers. It will also enter a request to delete guesses that data brokers may have made about you based on identifying information, such as political views, inferences about your health—inferences about pregnancy or chronic illness, for example, that may be based on purchases or browsing history.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Not all information will be deleted. Some information, such as vehicle or real estate ownership, contains information that is a matter of public record. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If there is a specific data broker you&#039;d like to be able to retain and continue selling your data, the system also gives you a way to remove them from the list of brokers that get any given request. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;a id=&quot;Filing&quot;&gt;&lt;/a&gt;How do I file?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Head to the California Privacy Protection Agency&#039;s &lt;/span&gt;&lt;a href=&quot;https://consumer.drop.privacy.ca.gov/&quot;&gt;&lt;span&gt;DROP website&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to start your request. Before you start, there are a few pieces of information you may want to gather for your request, such as your &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/05/how-disable-ad-id-tracking-ios-and-android-and-why-you-should-do-it-now&quot;&gt;&lt;span&gt;advertising ID&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or your VIN number, if you want this information to be deleted from data broker databases. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The agency does ask to collect some personal information—name, address, phone number, email address, etc.—in order to fulfill a request. (Yes, there is an irony to this.) This is to verify that you&#039;re the right person asking for your deletion and opt-out request in any given database, and the agency itself is bound to its terms of service that say they won&#039;t sell or share it for other purposes.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you&#039;re interested in filing a request for someone else, such as an elderly relative drowning in junk mail, you can also do that but will need to attest that you&#039;re filing for someone else who is a resident of California. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Once you&#039;ve filed, you will get a DROP ID, which you can use to check in on your request. If you lose this ID, you can contact the agency to recover it, but keep it in a safe place if you want to check in on the status of your request.  &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;If I file once, am I done forever?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Unfortunately, no. While the opt-out of sale request should last indefinitely, California&#039;s privacy law still allows companies to collect information without asking for permission first in most cases. That means data brokers are likely to continue to collect information for profiles of you—but they will will have less data and be limited in how they use it after an opt-out request. New data brokers may also register with the state after you file your request. And DROP won&#039;t stop companies who aren&#039;t registered data brokers, like Google, from collecting and sharing your personal information.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Two things can be true. DROP is a fantastic tool to help more people exercise their California privacy rights. We also still need even stronger privacy laws to make things more fair for everyday people. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That fact shouldn&#039;t undercut the power of this tool, but it does mean that you may want to make updating your request a regular part of a broader plan to &lt;a href=&quot;https://ssd.eff.org/module/how-to-manage-your-digital-footprint&quot;&gt;manage your digital footprint.&lt;/a&gt; For example, might we suggest doing it as a part of &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;&lt;span&gt;Opt-Out October&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—&lt;/span&gt;&lt;span&gt;a thing we totally made up but also totally stand behind?&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;What if I&#039;m not in California?&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Also unfortunately for those who don&#039;t live in California, this tool only works for California residents. But it&#039;s not all bad news. Versions of the Delete Act have been introduced around the country, and many regulators are monitoring how California&#039;s system works to see whether a similar system might work in their own states. &lt;/span&gt;&lt;span&gt;Residents of all states can use &lt;/span&gt;&lt;span&gt;EFF’s &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;&lt;span&gt;Opt-Out October&lt;/span&gt;&lt;/a&gt;&lt;span&gt; guide to bolster their online privacy and limit the ways that data brokers harvest their personal data&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 20 Jul 2026 21:55:28 +0000</pubDate>
 <guid isPermaLink="false">112201 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Hayley Tsukayama</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ca-privacy-general-2.png" alt="lock icon with CA state map &amp;amp; vintage colors" type="image/png" length="486510" />
  </item>
  <item>
    <title>An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion </title>
    <link>https://www.eff.org/deeplinks/2026/07/explosion-surveillance-towers-coming-us-borders-costing-over-1-billion</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;&lt;a href=&quot;https://www.documentcloud.org/documents/28483437-gao-26-108118/#document/p99&quot;&gt;A new report&lt;/a&gt;&lt;/span&gt; from the Government Accounting Office reveals that the Department of Homeland Security (DHS) plans to nearly triple the number of surveillance towers along U.S. borders, from the current 830 to 2,300 by 2034.&lt;/p&gt;
&lt;p&gt;DHS expects to expend $1 billion in taxpayer dollars for this dangerous expansion of a surveillance network indiscriminately trained on towns, school playgrounds, backyards, and vehicles—threatening the privacy and civil liberties of everyone in the border regions.&lt;/p&gt;
&lt;p&gt;The towers are planned as part of DHS component Customs and Border Protection’s (CBP) Integrated Surveillance Tower (IST) program, which captures images of people and vehicles. The IST program operates autonomous surveillance towers, consisting of autonomous surveillance towers, consisting of &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/california-coastal-community-must-reject-cbps-ai-powered-surveillance-tower&quot;&gt;AI-based systems&lt;/a&gt; using radar, thermal infrared and optical systems to track targets over long distances; integrated fixed towers, optimized for surveilling foot traffic and vehicles; and remote video surveillance systems, which can often be found very close to the border fence in Arizona, including residential neighborhoods where cameras are capable of spying on homes on both sides of the border. (For a description and photos of these technologies, see EFF’s &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/hot-press-effs-updated-guide-tech-us-mexico-border&quot;&gt;updated guide&lt;/a&gt; to surveillance at the U.S.-Mexico Border.)&lt;/p&gt;
&lt;p&gt;DHS expects to purchase more long-range autonomous towers and to upgrade existing towers with autonomous capabilities. The $1 billion comes from the so-called One Big Beautiful Act—a massive tax and spending law that President Trump signed in 2025, the report says.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.eff.org/issues/border-surveillance-technology&quot;&gt;explosive expansion of border surveillance&lt;/a&gt; is a digital dumpster fire for human rights and civil liberties. It’s not just surveillance towers; &lt;a href=&quot;https://www.eff.org/document/eff-v-dhs-cbp-supplemental-agency-list&quot;&gt;drones&lt;/a&gt;, &lt;a href=&quot;https://www.youtube.com/watch?v=nleYJgKSQrY&quot;&gt;aerostats&lt;/a&gt;, surveillance vehicles, ground sensors, game cameras, and &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/how-identify-automated-license-plate-readers-us-mexico-border&quot;&gt;license plate readers&lt;/a&gt; are also part of the vast taxpayer-funded infrastructure that threatens all those who live, work, or seek refuge in the borderlands. This technology isn’t exclusive to U.S. federal agencies: it’s also deployed by state and local law enforcement, and even by governments on the Mexican side.&lt;/p&gt;
&lt;p&gt;Since 2022, EFF has studied and &lt;a href=&quot;https://www.eff.org/document/us-mexico-border-surveillance-data&quot;&gt;mapped surveillance technology&lt;/a&gt; along the U.S.-Mexico border using public records research, open-source intelligence, and fact-finding trips, and &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/03/cbp-expanding-its-surveillance-tower-program-us-mexico-border-and-were-mapping-it&quot;&gt;created a handy interactive map&lt;/a&gt;&lt;/span&gt; to provide researchers and journalists with the tools they need to analyze the impact of U.S. border security policy. We have also documented the different types of surveillance technology in a zine, &lt;span&gt;&quot;&lt;a href=&quot;https://www.eff.org/pages/zine-surveillance-technology-us-mexico-border&quot;&gt;Surveillance Technology at the U.S.-Mexico Border&lt;/a&gt;.&quot; We updated the publication earlier this year to help people identify the machinery of homeland security by adding more models of surveillance towers, newly deployed military tech, and a gallery of disguised trail cams and automated license plate readers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF’s work includes &lt;a href=&quot;https://www.eff.org/cases/alasaad-v-duke&quot;&gt;defending the rights&lt;/a&gt; of individuals whose devices have been &lt;a href=&quot;https://www.eff.org/issues/border-searches&quot;&gt;searched&lt;/a&gt; or seized upon entering the country; &lt;a href=&quot;https://www.eff.org/cases/united-auto-workers-v-us-department-state&quot;&gt;pushing back&lt;/a&gt; on the collection of biometric and social media identifiers; and developing &lt;a href=&quot;https://www.eff.org/document/digital-privacy-us-border-one-pager-handout&quot;&gt;digital security guidance&lt;/a&gt; for people crossing borders.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;With the web of surveillance tech at the borders about to explode, EFF will continue to investigate and expose it and find ways to fight back with the communities that live in the shadow of this technological threat to human rights.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 20 Jul 2026 19:25:44 +0000</pubDate>
 <guid isPermaLink="false">112212 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/border-surveillance-technology">Border Surveillance Technology</category>
 <category domain="https://www.eff.org/issues/street-level-surveillance">Street-Level Surveillance</category>
 <dc:creator>Karen Gullo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/distant_shot_of_an_anduril_sentry_off_ca-98_in_imperial_county_ca.jpg" alt="An Anduril tower in the desert" type="image/jpeg" length="267286" />
  </item>
  <item>
    <title>“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.</title>
    <link>https://www.eff.org/deeplinks/2026/07/stealth-crawlers-are-not-threat-open-web-bills-targeting-them-would-be</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but.&lt;/p&gt;
&lt;p&gt;“Stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf&quot;&gt;important work&lt;/a&gt; that benefits the public, including investigative reporting, academic research, cybersecurity protection, and more.&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;Anonymous crawling enables some of the most publicly beneficial uses of the open web.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Many publishers want to unmask crawlers anyways—and are pushing for new legislation that would give them new powers to do so. These legislative proposals threaten the open web, user privacy, and valuable research without directly addressing the problems they’re supposedly intending to solve.&lt;/p&gt;
&lt;p&gt;Alarmingly, these harmful proposals are gaining traction. The New York state legislature has already passed such a bill, the &lt;a href=&quot;https://www.nysenate.gov/legislation/bills/2025/S9934/amendment/A&quot;&gt;NY Stealth Crawler Protection Act&lt;/a&gt;, which is now on Governor Hochul’s desk. We expect to see similar bills introduced in other states, and potentially in Congress. That’s a big problem for the open web—and the many benefits it provides.&lt;/p&gt;
&lt;h2 class=&quot;subhead&quot;&gt;&lt;strong&gt;Anonymous crawling is worth protecting&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Anonymous crawling enables some of the most publicly beneficial uses of the open web. Researchers, journalists, and other watchdog groups use unidentified automated tools to gather the information necessary to hold powerful institutions accountable and protect the public.&lt;/p&gt;
&lt;p&gt;Anonymous crawling fuels important investigative journalism. For example, &lt;em&gt;The Markup&lt;/em&gt;, a non-profit news site, used &lt;a href=&quot;https://themarkup.org/google-the-giant/2020/07/28/how-we-analyzed-google-search-results-web-assay-parsing-tool&quot;&gt;anonymous crawlers&lt;/a&gt; to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to &lt;a href=&quot;https://themarkup.org/amazons-advantage/2021/10/14/amazon-puts-its-own-brands-first-above-better-rated-products&quot;&gt;prioritize Amazon brands and Amazon-exclusive products&lt;/a&gt; over competitors with higher ratings. The crawlers identified themselves as &lt;a href=&quot;https://themarkup.org/amazons-advantage/2021/10/14/how-we-analyzed-amazons-treatment-of-its-brands-in-search-results&quot;&gt;ordinary Firefox browsers&lt;/a&gt; to web servers, which allowed &lt;em&gt;The Markup &lt;/em&gt;to understand how Amazon search results pages would appear to ordinary users. Similarly, &lt;em&gt;ProPublica &lt;/em&gt;used an automated tool designed to simulate an ordinary Amazon customer to reveal that the &lt;a href=&quot;https://www.propublica.org/article/amazon-says-it-puts-customers-first-but-its-pricing-algorithm-doesnt&quot;&gt;site steered shoppers to more expensive products&lt;/a&gt; over cheaper alternatives.&lt;/p&gt;
&lt;p&gt;Anonymous web scraping is also crucial for &lt;a href=&quot;https://www.sans.org/blog/undercover-operations-scraping-the-cybercrime-underground&quot;&gt;cybersecurity professionals&lt;/a&gt;, who use automated tools to monitor the web for information that helps them protect against malicious attackers. &lt;a href=&quot;https://themarkup.org/blacklight&quot;&gt;Privacy tools&lt;/a&gt;, including EFF’s own &lt;a href=&quot;https://www.eff.org/deeplinks/2023/10/privacy-badger-learns-block-ever-more-trackers&quot;&gt;Privacy Badger&lt;/a&gt;, also crawl sites anonymously to identify trackers without compromising user privacy.&lt;/p&gt;
&lt;p&gt;However, without the ability to scrape anonymously, these tools would likely be blocked. Sites can—and do—block crawlers operated by researchers, journalists, and activists who criticize them. For example, Facebook &lt;a href=&quot;https://www.nytimes.com/2021/08/10/opinion/facebook-misinformation.html?eafs_enabled=false&quot;&gt;shut down&lt;/a&gt; accounts belonging to researchers who used automated tools to study misinformation on the platform and demanded that they &lt;a href=&quot;https://knightcolumbia.org/content/researchers-nyu-knight-institute-condemn-facebooks-effort-to-squelch-independent-research-about-misinformation&quot;&gt;take down&lt;/a&gt; published research. Many sites block automated access by anyone who hasn’t paid to crawl public webpages.    &lt;/p&gt;
&lt;h2 class=&quot;subhead&quot;&gt;&lt;strong&gt;Unmasking crawlers threatens the open web&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;News publishers—and their allies in government—&lt;a href=&quot;https://www.newsmediaalliance.org/ny-passes-stealth-crawler-prohibition-act/&quot;&gt;say that&lt;/a&gt; unmasking crawlers is necessary to protect news organizations from technological strain caused by AI-related crawling, and fears that AI could reduce news sites’ traffic and ad revenue. These are legitimate concerns.&lt;/p&gt;
&lt;p&gt;But enacting broad, reactionary restrictions on automated access is not the answer. &lt;a href=&quot;https://news.bgov.com/bloomberg-government-news/new-york-becomes-first-state-to-ban-bots-that-scrape-news-sites&quot;&gt;Legislation targeting anonymous crawling&lt;/a&gt; threatens the open web, user privacy, and valuable research without actually addressing these technological and potential economic harms of scraping.&lt;/p&gt;
&lt;p&gt;The New York state legislature recently passed the &lt;a href=&quot;https://www.nysenate.gov/legislation/bills/2025/S9934/amendment/A&quot;&gt;NY Stealth Crawler Protection Act&lt;/a&gt;, a law that would make it illegal to crawl news websites without revealing who is operating the crawler and all possible future uses of the data collected by the crawler. The law would give websites the power to obtain court orders that unmask anyone using an unidentified crawler—without any evidence that they broke the law.&lt;/p&gt;
&lt;p&gt;Laws like the New York bill sweep far beyond AI, and do not meaningfully address the technological or potential harms of AI-related web scraping. These policies would chill beneficial crawling by allowing publishers to veto lawful public access, giving them the power to block not just bad actors, but also security professionals, researchers, dissidents, or anyone who has not paid for a license to view public text. This needlessly undermines the free and open internet.&lt;/p&gt;
&lt;p&gt;Digital news publishers—like most websites—face real technological challenges in the AI era. While web crawling has been around for decades, with the proliferation of AI, crawlers now collect far more public web data than they used to. This pushes servers closer to their maximum capacity, and if some bots collect information too aggressively, they may strain web servers to the point that it degrades site performance. The problem is not anonymity—so unmasking crawlers won’t solve it. The real problem is overaggressive crawling, which can be effectively addressed with technical measures that target harmful conduct without impeding anonymous access to information.&lt;/p&gt;
&lt;h2 class=&quot;subhead&quot;&gt;&lt;strong&gt;A better path forward&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;There are other, far less harmful ways to protect publishers from the harms these “stealth crawler” laws claim to target. Addressing the harms of AI-related crawling requires policies that narrowly target the causes of these issues–without undermining free expression and the open web. Policies that target crawlers and scrapers are anything but.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 20 Jul 2026 18:46:50 +0000</pubDate>
 <guid isPermaLink="false">112207 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/anonymity">Anonymity</category>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <dc:creator>Tori Noble</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-robot-warhol-2.png" alt="robot portraits Warhol-style" type="image/png" length="211803" />
  </item>
  <item>
    <title>Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices</title>
    <link>https://www.eff.org/deeplinks/2026/07/victory-flock-ends-rollout-audio-distress-detection-human-voices</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Reversing course, Flock Safety—the surveillance technology vendor most known for its extensive network of &lt;/span&gt;&lt;a href=&quot;https://sls.eff.org/technologies/automated-license-plate-readers-alprs&quot;&gt;&lt;span&gt;automated license plate readers&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—&lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/blog/how-flocks-audio-detection-works&quot;&gt;&lt;span&gt;has announced&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that it will end a pilot for its &lt;/span&gt;&lt;a href=&quot;https://sls.eff.org/technologies/gunshot-detection&quot;&gt;&lt;span&gt;acoustic gunshot detection devices&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to identify signs of “human distress.”&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;...public pressure can sometimes work to influence both companies and lawmakers that control a city’s purse strings to discontinue or divest from harmful products...&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In October 2025, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/flocks-gunshot-detection-microphones-will-start-listening-human-voices&quot;&gt;&lt;span&gt;EFF warned the public&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that Flock was rolling out a new feature called “Distress Detection” that would be deployed through their acoustic gunshot detection devices (formerly known as Flock Raven, now called Audio Detection). This feature purported to use high-powered microphones scattered throughout a city to search for sounds of human distress, with original advertisements from the product indicating it would search for “screaming.” (Since the publication of our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/flocks-gunshot-detection-microphones-will-start-listening-human-voices&quot;&gt;&lt;span&gt;original blog post&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, Flock quietly amended the ad on this&lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/distress-early-access&quot;&gt; &lt;span&gt;webpage&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to say “distress” instead of “screaming.”)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Now, Flock &lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/blog/how-flocks-audio-detection-works&quot;&gt;&lt;span&gt;has published&lt;/span&gt;&lt;/a&gt;&lt;span&gt; a blog post stating that “[a]fter careful consideration and community consultation, we decided to remove the feature.” Good riddance. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We said it when the product was announced and we’ll say it again: this was a misguided and dangerous feature because of the civil liberties concerns it poses, the possibility it could summon armed police to every loud interaction happening on the street, and because in several places &lt;/span&gt;&lt;a href=&quot;https://www.justia.com/50-state-surveys/recording-phone-calls-and-conversations/&quot;&gt;&lt;span&gt;this type of spying would be illegal under state eavesdropping laws&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We were &lt;/span&gt;&lt;a href=&quot;https://www.tiktok.com/@efforg/video/7632813360416918814?lang=en&quot;&gt;&lt;span&gt;not quiet&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about this potential new feature. Flock even mentioned our concern about Distress Detection in an &lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/blog/does-flock-enable-mass-surveillance&quot;&gt;&lt;span&gt;attempt&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to rebut our opposition to the mass surveillance their products enable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The suspension of Distress Detection, however, does not mean that these high-powered microphones are now magically safe or beyond our concern. Acoustic gunshot detection is still a dangerous and &lt;/span&gt;&lt;a href=&quot;https://www.cnn.com/2024/02/24/us/shotspotter-cities-choose-not-to-use&quot;&gt;&lt;span&gt;often highly inaccurate technology&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that has resulted in real world harm, as in Chicago where it resulted in &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/03/responding-shotspotter-police-shoot-child-lighting-fireworks&quot;&gt;&lt;span&gt;police shooting at children lighting fireworks&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. As Flock itself states, “No acoustic system is perfect, and we don&#039;t claim otherwise.” But police response to a situation where they believe guns are actively in use seems like a pretty high-stakes situation to be making, selling, and deploying technology known to be imperfect. Flock’s devices also listen for more than just gunshots. Their marketing materials admit to be listening for “&lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/products/gunshot-detection&quot;&gt;&lt;span&gt;community disruption&lt;/span&gt;&lt;/a&gt;&lt;span&gt;,” which includes “non-violent” threats like car sideshows and fireworks. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Flock’s failed attempt to roll out Distress Detection teaches us a few important lessons about the current state of police surveillance. First, we should not assume that just because these companies are large and well-funded, that does not ensure that they are complying with local privacy laws before floating new products to customers. Second, companies roll out and police adopt invasive technology under the justification that it will be used to address our society’s very worst crimes. However, both the companies and police will leverage deployed surveillance infrastructure to introduce new uses without necessarily seeking the consent or approval of the public. Gunshot detecting microphones eventually being used to listen for screaming is exactly the type of mission creep that we’ve seen happen with other pieces of surveillance technology, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-school-residency-verification-background&quot;&gt;&lt;span&gt;including Flock’s license plate readers&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Finally, gun violence is too serious and complex of an issue to purport to solve with one flawed piece of technology. It has become too easy for police and cities to listen to the &lt;/span&gt;&lt;a href=&quot;http://www.eff.org/document/selling-safety-journalists-guide-covering-police-technology&quot;&gt;&lt;span&gt;fancy marketing pitches of tech companies&lt;/span&gt;&lt;/a&gt;&lt;span&gt; claiming they’re going to solve all crime instead of doing the hard work of addressing the root causes of societal issues. And, in the meantime, that technology creates more problems and hazards for the communities they blanket in police surveillance. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As we’ve also seen with people across the country pushing back on Flock license plate reader contracts in their communities, public pressure can sometimes work to influence both companies and lawmakers that control a city’s purse strings to discontinue or divest from harmful products. Flock’s decision to end “Distress Detection” for human voices is a win.  &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 17 Jul 2026 17:05:57 +0000</pubDate>
 <guid isPermaLink="false">112209 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/street-level-surveillance">Street-Level Surveillance</category>
 <dc:creator>Matthew Guariglia</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/surveillance-og-2.png" alt="A cityscape with surveillance" type="image/png" length="67391" />
  </item>
  <item>
    <title>Your Vision. Your Legacy. Your Future.</title>
    <link>https://www.eff.org/deeplinks/2026/07/your-vision-your-legacy-your-future</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;This month, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/building-our-future-together&quot;&gt;we celebrate 36 years of EFF&lt;/a&gt; and a mission that is bigger than any one of us. Thanks to EFF, communities around the world are demanding that technology protects their freedom, advances justice, and opens doors to opportunity. That&#039;s not a small thing—it&#039;s a life&#039;s work worth continuing.&lt;/p&gt;
&lt;p&gt;If you are committed to staying on the cutting edge of digital rights issues, I&#039;d like to invite you to consider taking that commitment one step further by joining &lt;a href=&quot;https://www.eff.org/givingsociety/lighthouse&quot;&gt;EFF’s Lighthouse Society&lt;/a&gt;, our way to acknowledge and thank the community of supporters who are including EFF in their legacy plans.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://eff.org/lighthouse&quot;&gt;Learn About the Lighthouse Society&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;By including EFF in your will or estate plans, you can ensure that EFF’s work and values don&#039;t just live beyond you; they thrive because of you. A legacy gift is one of the most powerful ways to say: &lt;em&gt;This matters, and I want it to matter long after I&#039;m gone.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Your gift will fuel our mission for generations by protecting freedom, advancing justice, and driving innovation for communities who need it most. There is still so much more to do, so much more to fight for. With your foresight, it can go so much further.&lt;/p&gt;
&lt;p&gt;Planned giving is also more flexible than you might realize. A bequest in your will, a simple beneficiary designation, or another estate planning option can all make a profound difference, often without affecting your finances today.&lt;/p&gt;
&lt;p&gt;Get in touch and learn more about what&#039;s possible with the Lighthouse Society. Reach out to Jocelyn Wicker at &lt;a href=&quot;mailto:majorgifts@eff.org&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;majorgifts@eff.org&lt;/a&gt; or &lt;a href=&quot;https://eff.org/lighthouse&quot;&gt;fill out our online form&lt;/a&gt; to share your intention to give. Thank you for considering a legacy that will carry this work forward for years to come.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 17 Jul 2026 16:44:40 +0000</pubDate>
 <guid isPermaLink="false">112208 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/taxonomy/term/68">Announcement</category>
 <dc:creator>Jocelyn Wicker</dc:creator>
 <dc:creator>Aaron Jue</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/lighthouse-banner-1.png" alt="" type="image/png" length="15658" />
  </item>
  <item>
    <title>How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues</title>
    <link>https://www.eff.org/deeplinks/2026/07/how-watch-dogs-video-game-series-mirrored-and-predicted-real-world-digital-rights</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;When Ubisoft&#039;s &lt;/span&gt;&lt;a href=&quot;https://www.ubisoft.com/en-us/game/watch-dogs/watch-dogs-2&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Watch Dogs 2&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; was released in 2016, it was a headtrip for those of us working on digital-rights issues in the Bay Area. During the day, I&#039;d fight tech-authoritarianism from EFF&#039;s San Francisco offices and then, at night, I&#039;d fight tech-authoritarianism in an uncanny simulation of San Francisco from my home gaming console. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Watch Dogs 2 is an open-world video game that follows a hacktivist collective called Dedsec as they take on surveillance tech and discriminatory AI systems that are being controlled by tech bros, government contractors, and corrupt cops. The game&#039;s missions often felt like they were ripped from the pages of EFF&#039;s &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks?type=blog&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Deeplinks&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; blog. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;EFF’s mission is defending civil liberties in the digital world, and we do that with activists, technologists, and lawyers. If you&#039;ve ever dreamt of joining Dedsec, you should definitely join us as a member. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://supporters.eff.org/donate/conference-goer--sdcc&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Join the movement to Take Back CTRL.&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;In fact, we&#039;ve even got the &lt;/span&gt;&lt;a href=&quot;https://shopeff.org/collections/apparel-accessories&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;same merch aesthetic&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. I cosplayed as the lead character, Marcus, at Dragon Con, and no one even knew I was in costume. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/07/16/image5.png&quot; width=&quot;375&quot; height=&quot;378&quot; alt=&quot;&quot; title=&quot;&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Dave (left) as Marcus takes a selfie with a Wrench cosplayer at Dragon Con 2018.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;To commemorate Watch Dog 2&#039;s 10th anniversary, I&#039;ll be speaking on &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/event/eff-san-diego-comic-con&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;a panel at San Diego Comic-Con&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; reflecting on how the game predicted tech issues we&#039;re facing today. Organized by Mia Ginae of The Mighty Hostess and Black in Gaming, we&#039;ve got voice actors Ruffin Prentiss lll and Shawn Baichoo, cinematic producer Timmy Fisher, and music producer Hudson Mohawke, who did the soundtrack, with Mia Ginae moderating. That&#039;s at 3:15 PM on Friday, July 24 in room 6BCF.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/files/2026/07/16/image3.png&quot; width=&quot;842&quot; height=&quot;468&quot; alt=&quot;Watch Dogs 2 panel at San Diego Comic-Con&quot; title=&quot;Watch Dogs 2 panel at San Diego Comic-Con&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;But not everyone can get to Comic-Con and I certainly have more to say that can fit in. So here are a few ways where Watch Dogs 2 mirrored our work back then and foresaw what we&#039;re facing today.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;a href=&quot;https://www.eff.org/event/eff-san-diego-comic-con&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Check out our full San Diego Comic Schedule, including panels and a meet-up.&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;none&quot;&gt;Insecure Surveillance Cameras&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;One of the signature gameplay elements of the Watch Dogs series is the ability for your character to hack into nearby security cameras from your phone and use that to gain a strategic advantage over hostile adversaries.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;About a year before, that&#039;s exactly the issue that we were working on. EFF Technologist Cooper Quintin and I used the service &lt;/span&gt;&lt;a href=&quot;https://www.shodan.io/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Shodan&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2015/10/license-plate-readers-exposed-how-public-safety-agencies-responded-massive&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;identify a slew of automated license plate readers&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; (ALPRs) that Louisiana police had left unprotected on the internet. We found that the controls were open to anyone to manipulate and, just like in the game, you could watch the live video feeds.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;&lt;img src=&quot;/files/2026/07/16/image4.png&quot; width=&quot;657&quot; height=&quot;562&quot; alt=&quot;Shodan screencap of unprotected ALPR feeds&quot; title=&quot;Shodan screencap of unprotected ALPR feeds&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;We didn&#039;t use the data to acquire a skill point or collectible outfit. Instead, we forced police agencies to lock down their equipment and then used what we learned to persuade then Gov. Bobby Jindal to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2015/10/license-plate-readers-exposed-how-public-safety-agencies-responded-massive&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;veto&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; a bill that would have created a new statewide surveillance dragnet. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;This issue still persists today. Most recently, security researchers &lt;/span&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=uB0gr7Fh6lY&amp;amp;t=1387s&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Benn Jordan and Jon “GainSec” Gaines&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, and the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/press/releases/electronic-frontier-foundation-present-annual-eff-awards-carolina-botero-connecting&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;award-winning&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; journalists at &lt;/span&gt;&lt;a href=&quot;https://www.404media.co/flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;404 Media&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, uncovered how at least 60 pan-tilt-zoom cameras from the vendor Flock Safety were left exposed online.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;none&quot;&gt;Cell-Site Simulators&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;In Watch Dogs 2 there&#039;s a mission called &quot;&lt;/span&gt;&lt;a href=&quot;https://watchdogs.fandom.com/wiki/Stolen_Signals&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Stolen Signals&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;,&quot; in which Marcus and his best friend Wrench are trying to locate &quot;stingrays,&quot; police devices that gather nearby cell-phone data by masquerading as legit cellular towers. We call these &quot;&lt;/span&gt;&lt;a href=&quot;https://sls.eff.org/technologies/cell-site-simulators-imsi-catchers&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cell-site simulators&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;&quot; (CSSs) and they&#039;re are an extremely alarming mass surveillance technology that allows police to track individual users through their phone identifiers. We&#039;ve long advocated that this should require a search warrant. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Like Dedsec, we also had initiated a project to do the exact same thing. And in true Dedsec fashion, we also gave it a pop-culture name: &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2020/06/quick-and-dirty-guide-cell-phone-surveillance-protests&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Crocodile Hunter&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, an homage to wildlife expert Steve Irwin, who had famously died after a stingray attack. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;But while Marcus was running around Telegraph Hill, staff technologist Cooper Quintin and I were running around downtown San Francisco, testing out our own device for detecting suspicious cell phone towers during Salesforce&#039;s annual Dreamforce conference. And while we didn&#039;t find a CSS that day, we did find a mobile surveillance tower that a start-up had set up for the event.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/07/16/image6.jpg&quot; width=&quot;1059&quot; height=&quot;794&quot; alt=&quot;Cooper Quintin, EFF&#039;s own &amp;quot;Wrench,&amp;quot; testing out Crocodile Hunter at Dreamforce &quot; title=&quot;Cooper Quintin, EFF&#039;s own &amp;quot;Wrench,&amp;quot; testing out Crocodile Hunter at Dreamforce &quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Cooper Quintin, EFF&#039;s own &#039;Wrench,&#039; testing out Crocodile Hunter at Dreamforce&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Today, that project has evolved into &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Rayhunter&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, which allows anyone to use a cheap mobile hotspot to detect the type of cellular anomalies associated with CSSs. We&#039;re proud to say that now there&#039;s a whole international Dedsec-style network of researchers using this technology to look for surveillance &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/rayhunter-what-we-have-found-so-far&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;at protests, at the border, and in metropolitan areas&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Security Robots&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Throughout the game, Marcus encounters a number of autonomous pickle-shaped security robots wandering the city. At one point, Wrench reprograms one to become &quot;Wrench Jr,&quot; a bona fide member of the Dedsec team. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;In real life, these robots are made by a company called Knightscope, and EFF started shining light on them in &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/01/police-robots-are-not-selfie-opportunity-theyre-privacy-disaster-waiting-happen&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;2020-2021&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, when they were first being deployed by companies and government agencies.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/07/16/image1.jpg&quot; width=&quot;827&quot; height=&quot;1103&quot; alt=&quot;&quot; title=&quot;&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;A Knightscope robot patrols a casino parking lot in Reno, Nevada. &lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Today, law enforcement is &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/lawmakers-must-act-now-prevent-armed-police-drones&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;pursuing&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; weaponized robots and drones, and EFF is at the forefront to stop this dystopian reality. In fact, in December 2022, we &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/12/victory-san-francisco-bans-killer-robotsfor-now&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;successfully fought&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; for San Francisco to ban the police department from weaponizing drones. In 2024, New York Police Department also &lt;/span&gt;&lt;a href=&quot;https://www.nytimes.com/2024/02/02/nyregion/nypd-subway-robot-retires.html&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;retired&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; its subway robot.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;none&quot;&gt;A Citywide Surveillance &quot;Operating System&quot;&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;In the Watch Dog series, one of the ominous developments is CTOS 2.0 (Central Operating System 2.0). Through this system, Blume, a government contractor, tries to collect a massive amount of data through citywide sensors and infrastructure, and to combine all that data into one unified&lt;span&gt;—&lt;/span&gt;and totally insecure&lt;span&gt;—&lt;/span&gt;analytics system. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;At the time we&#039;d only just begun to see this idea floated, with a limited number of cities trying tools like Palantir&#039;s Gotham to manage data.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Today, it is a frighteningly competitive market, particularly when it comes to law enforcement surveillance. For example, both Axon and Flock Safety are trying to offer products that integrate with every function of policing that sound like CTOs. In fact, Flock Safety product is literally titled, &quot;Flock OS.&quot;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/07/16/image2.jpg&quot; width=&quot;922&quot; height=&quot;691&quot; alt=&quot;&quot; title=&quot;&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Fusus demonstrated at a police chief&#039;s conference. &lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Meanwhile, Axon&#039;s camera networking product, &quot;&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/05/neighborhood-watch-out-cops-are-incorporating-private-cameras-their-real-time&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Fusus&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;,&quot; sounds like it came straight from the Watch Dogs&#039; writers room. Fusus allows for central live-streaming of all types of surveillance cameras in a city, including body-worn cameras, which was another prediction from the Watch Dog series that came true. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;EFF has been part of many local battles to reject Flock and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/03/guardrails-wont-protect-nashville-residents-against-ai-enabled-camera-networks&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Axon&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; surveillance systems, and we&#039;ve also &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/06/dangers-consolidating-all-government-information&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;advocated&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; against recent efforts at the federal level to consolidate government data. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;none&quot;&gt;Join the Fight Against Authoritarian Tech&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Watch Dogs 2&#039;s protagonists aren&#039;t just the merry band of core hackers: It&#039;s a distributed movement spread across the region and social media. The sequel, Watch Dogs Legion, is even designed so that every single person in the city of London is a potential playable Dedsec member, ready to take on tech tyranny with whatever skills they have. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;That&#039;s also our philosophy: If you use tech, if you&#039;re affected by tech, this is your fight. And it&#039;s time to &lt;/span&gt;&lt;a href=&quot;https://takebackctrl.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;take back control.&lt;/span&gt;&lt;/a&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;There are a lot of ways to do this. You can become a member by &lt;/span&gt;&lt;a href=&quot;https://supporters.eff.org/donate/conference-goer--sdcc&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;donating&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. You can contact public officials through our &lt;/span&gt;&lt;a href=&quot;https://act.eff.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Action Center&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. You can join the thousands of volunteers who are helping gather data on surveillance through our &lt;/span&gt;&lt;a href=&quot;https://atlasofsurveillance.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Atlas of Surveillance&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; project. You can also hunt cell-site simulators with us&lt;span&gt;—&lt;/span&gt;and help improve our code&lt;span&gt;—&lt;/span&gt;through the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Rayhunter&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; project. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;And just like Watch Dogs 2, this is a game we can win if we work together.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 17 Jul 2026 15:01:22 +0000</pubDate>
 <guid isPermaLink="false">112206 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/street-level-surveillance">Street-Level Surveillance</category>
 <dc:creator>Dave Maass</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/dedsec_watch_dogs_1200x600.jpg" alt="Watch Dogs 2 Dedsec attack" type="image/jpeg" length="449288" />
  </item>
  <item>
    <title>EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines </title>
    <link>https://www.eff.org/deeplinks/2026/07/eff-and-article-19-submission-european-commission-dsa-trusted-flagger-guidelines</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;EFF and &lt;/span&gt;&lt;a href=&quot;https://www.article19.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;ARTICLE 19&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; have submitted joint comments to the European Commission on &lt;/span&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-trusted-flaggers&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;draft guidelines&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while preserving intermediary liability protections and the prohibition on general monitoring, we welcome the Commission&#039;s effort to provide practical guidance on how the trusted flagger system should operate.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The DSA’s &lt;/span&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;trusted flagger system&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; can help platforms identify illegal content more efficiently. But if implemented poorly, it could also encourage over-removal of lawful speech, weaken due process, and give government authorities disproportionate influence over online expression.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;We support the Commission&#039;s focus on good practices and illustrative examples, rather than legal interpretations that could inadvertently steer platforms toward particular enforcement outcomes—and argue that the guidelines should include stronger safeguards to protect freedom of expression, due process, and the impartiality of the trusted flagger system.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;We also support the Commission&#039;s clarification that the DSA itself does not define &quot;illegal content&quot;; that determination must come from applicable national or EU law. Trusted flaggers submit prioritized notice, but platforms remain responsible for determining whether content is actually illegal. Platforms must therefore conduct careful, informed assessments and should not assume that a trusted flagger notice necessarily warrants restricting content.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Our submission highlights several areas where the guidelines could be strengthened:&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Cross-border assessments require caution.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt; Platforms should not rely on a trusted flagger notice to assess legality across Member States, where national legal frameworks may differ.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;2&quot; data-aria-level=&quot;1&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Systemic risks extend beyond content moderation.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt; The DSA&#039;s systemic risk framework should not rely too heavily on individual moderation decisions, but should also consider broader platform design choices, including recommender systems.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;3&quot; data-aria-level=&quot;1&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Law enforcement authorities should generally not be granted trusted flagger status.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt; They already have statutory powers under Article 9 of the DSA, and combining those powers with trusted flagger status creates a risk that platforms may treat trusted flagger notices as de facto removal orders, undermining due process and the rule of law.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;4&quot; data-aria-level=&quot;1&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Civil society organizations play an essential role.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt; Civil society organizations help identify illegal content and report human rights abuses, but the guidelines should also recognize that these organizations may face retaliation for their work and should be protected from abusive campaigns that threaten their independence.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;5&quot; data-aria-level=&quot;1&quot;&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Trusted flaggers should complement—not replace—existing partnerships.&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt; The new mechanism should not sideline existing trusted partnership programs, including collaborations with civil society organizations that do not or cannot hold trusted flagger status, especially those outside of the EU with valuable regional expertise. &lt;/span&gt;&lt;span&gt; &lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;Read the full submission here:&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 16 Jul 2026 09:22:17 +0000</pubDate>
 <guid isPermaLink="false">112205 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/international">International</category>
 <category domain="https://www.eff.org/issues/eff-europe">European Union</category>
 <dc:creator>Jillian C. York</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/eu-flag-11.png" alt="EU-flag-circuits" type="image/png" length="48177" />
  </item>
  <item>
    <title>California Steps Back From Dangerous Expansion of its Age-Gating Law</title>
    <link>https://www.eff.org/deeplinks/2026/07/california-steps-back-dangerous-expansion-its-age-gating-law</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;The California legislature has stepped back from a plan that would have expanded its age-gating law, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/one-step-forward-two-steps-back-cas-ab-1856-exempts-open-source-expands-age-gating&quot;&gt;&lt;span&gt;removing language that could have compounded serious threats to users’ speech, privacy and security&lt;/span&gt;&lt;/a&gt;&lt;span&gt; just to browse the internet. &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1856&quot;&gt;&lt;span&gt;A.B. 1856&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, authored by Assemblymember Buffy Wicks, will now move forward through the legislature without its most problematic pieces.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF still believes the underlying law that A.B. 1856 amends, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/ab-1043s-internet-age-gates-hurt-everyone&quot;&gt;&lt;span&gt;A.B. 1043&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, is unconstitutional. Signed into law in 2025 (and effective January of 2027), A.B. 1043 requires all operating systems and app stores to collect users’ ages, place them in various age brackets and then block young people from lawful speech and services depending on their age. We also believe that even though A.B. 1043 does not require age verification, the liability it creates for operating systems and app stores—including fining operating systems up to $7,500 per affected child for violating the law—will push those services to verify users’ ages. In practice, that could lead to more ID checks, more biometric scanning, more invasive data collection and risk of breach, and more barriers to adults’ and young people’s lawful speech.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;However, we appreciate that the Legislature has abandoned its plan to expand this problematic age-gating  framework to browsers and websites. This would have significantly expanded this dangerous law before it even took effect. We thank the author and committee staff for recognizing these harms and not moving forward with this language. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;On top of that, EFF is pleased that an earlier amendment to A.B 1856 &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/one-step-forward-two-steps-back-cas-ab-1856-exempts-open-source-expands-age-gating&quot;&gt;&lt;span&gt;reduced the threat to the open-source community by exempting open-source operating systems&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Given these changes,&lt;a href=&quot;https://www.eff.org/document/eff-letter-re-ab-1856-removal-opposition-amended-july-1&quot;&gt; EFF has removed its opposition to A.B. 1856&lt;/a&gt;. We appreciate the author for listening to concerns from &lt;/span&gt;&lt;a href=&quot;https://www.pcgamer.com/software/operating-systems/a-new-california-law-says-all-operating-systems-including-linux-need-to-have-some-form-of-age-verification-at-account-setup/&quot;&gt;&lt;span&gt;advocates&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.opensourceforu.com/2026/03/california-age-law-puts-open-source-operating-systems-in-a-compliance-dilemma/&quot;&gt;&lt;span&gt;developers&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.tomshardware.com/software/operating-systems/california-introduces-age-verification-law&quot;&gt;&lt;span&gt;others&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about the effect it would have on open-source development and also &lt;/span&gt;&lt;a href=&quot;https://allaboutcookies.org/california-ab-1856-age-verification&quot;&gt;&lt;span&gt;around expanding this problematic framework&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;To be clear, we still believe the law passed last year threatens online anonymity, privacy, and security. A.B. 1043 is one of a &lt;/span&gt;&lt;a href=&quot;http://www.eff.org/deeplinks/2025/12/year-states-chose-surveillance-over-safety-2025-review&quot;&gt;&lt;span&gt;troubling wave of proposals&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that encourage—or, in some cases, outright require—age verification. Our position on this is clear: no one should have to provide or verify their age to access the internet. Once users’ personal data is collected, it can easily be leaked, hacked, or misused. No matter the method, every age verification system demands that people hand over their sensitive and immutable personal information to link their offline identity to their online activity. That’s a bad deal for us all.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;span&gt;Age-gating mandates are reshaping the internet in ways that are invasive, dangerous, and deeply unnecessary. But users are not powerless! We can challenge these laws, protect our digital rights, and build a safer digital world for all internet users, no matter their ages. This&lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://www.eff.org/issues/eff.org/pages/why-join-fight-overview-efforgage#main-content&quot;&gt; &lt;i&gt;&lt;span&gt;resource hub&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span&gt; can help—so explore, share, and join us in the fight for a better internet.&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 15 Jul 2026 20:50:48 +0000</pubDate>
 <guid isPermaLink="false">112203 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner.png" alt="Purple padlock with an 18+ only symbol and a combination lock requiring Day, Month, and Year. Surrounded by abstract purple dashed lines." type="image/png" length="1291379" />
  </item>
  <item>
    <title>Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features</title>
    <link>https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. It’s time they step up and start providing transparency reports and stronger encryption options.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://pmc.ncbi.nlm.nih.gov/articles/PMC12795147/&quot;&gt;&lt;span&gt;Surveys suggest that around 40 percent&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of people in the United States own some sort of commercially available wearable health device. Despite being marketed as health devices, they have no special health-related privacy protections that one might hope for. The companies who make these devices can and do collect an abundance of data, and many of them share that data with third-parties for marketing or &lt;/span&gt;&lt;a href=&quot;https://www.npr.org/sections/health-shots/2018/11/19/668266197/as-insurers-offer-discounts-for-fitness-trackers-wearers-should-step-with-cautio&quot;&gt;&lt;span&gt;to influence insurance rates&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, or use it for their own purposes, like training artificial intelligence models.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Health data is increasingly an important part of law enforcement or government investigations. Wearable data has been &lt;/span&gt;&lt;a href=&quot;https://www.law360.com/articles/2311168/the-growing-role-of-wearable-health-tech-in-criminal-probes&quot;&gt;&lt;span&gt;critical in a number of cases&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, where information about heart rate and steps was used to determine the whereabouts of individuals. And the surveillance company &lt;/span&gt;&lt;a href=&quot;https://www.penlink.com/blog/6-overlooked-sources-of-tracker-data-investigators-shouldnt-miss/&quot;&gt;&lt;span&gt;Penlink calls fitness trackers and wearables&lt;/span&gt;&lt;/a&gt;&lt;span&gt; an “overlooked source” for law enforcement since they tend to show movement patterns and changes in heart rates. Law enforcement can try to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/06/how-cops-can-get-your-private-online-data&quot;&gt;&lt;span&gt;get access to this data through&lt;/span&gt;&lt;/a&gt;&lt;span&gt; subpoenas or warrants. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There are many potential privacy issues with these sorts of devices, including whether the companies who make them share or sell information to third-parties. But here we are choosing to focus on two facets we’re concerned with around health data itself: 1) whether the company shares information with law enforcement and governments and 2) if they offer end-to-end encryption, which means the company itself can’t access that health data to begin with.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Reading through dozens of product review sites we narrowed our research in on ten companies that seem to make the majority of recommended consumer health products on the market:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Amazfit&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Apple&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Coros&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Garmin&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Google (including Fitbit)&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Hume&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Oura&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Polar&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Suunto&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Whoop &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;We reviewed each company’s public facing policies, then emailed them to confirm those findings. Here’s what we found.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Transparency Reports Are Few and Far Between&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Companies should provide transparency reports of how often they provide data to the government, including information about whether it’s an official demand or an unofficial request. We have been calling on tech companies to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/who-has-your-back-2014#transparency&quot;&gt;&lt;span&gt;publish transparency reports for a long time&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, but the practice is still rare across the industry. That’s especially true with fitness gadgets. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Only two of the companies we surveyed, &lt;/span&gt;&lt;a href=&quot;https://www.apple.com/legal/transparency/&quot;&gt;&lt;span&gt;Apple&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://transparencyreport.google.com/?hl=en&quot;&gt;&lt;span&gt;Google&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (which also owns Fitbit), currently publish transparency reports. &lt;/span&gt;&lt;a href=&quot;https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf&quot;&gt;&lt;span&gt;Apple&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://policies.google.com/terms/information-requests?hl=en-US&quot;&gt;&lt;span&gt;Google&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.whoop.com/us/en/whoop-privacy-policies/&quot;&gt;&lt;span&gt;Whoop&lt;/span&gt;&lt;/a&gt;&lt;span&gt; promise to notify users of law enforcement requests in publicly available documentation. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Oura now does too, after an &lt;/span&gt;&lt;a href=&quot;https://ouraring.com/privacy-policy&quot;&gt;&lt;span&gt;update to their privacy policy in June 2026&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that was perhaps prompted by a &lt;/span&gt;&lt;a href=&quot;https://this.weekinsecurity.com/oura-says-it-gets-government-demands-for-user-data-will-it-share-how-many/&quot;&gt;&lt;span&gt;series of requests from journalist Zack Whittaker.&lt;/span&gt;&lt;/a&gt;&lt;span&gt; In that same update and in an email to us, Oura promises that it is “actively evaluating ways to provide greater visibility into how we handle these requests, like through a transparency report.” This is promising, and we hope the company agrees that transparency reports are the best option moving forward. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;Any company that handles data that’s of interest to law enforcement and governments owes it to their users to publish transparency reports and, when legally possible, notify users when that data is requested. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Similarly, Suunto does not currently publish transparency reports, but in an email reply to our questions the company did express an openness to potentially doing so, stating, “We continuously evaluate our transparency practices and may publish additional information, such as a transparency report, in the future if we believe it would provide meaningful value for users and support our data protection efforts.” We hope they do, as these sorts of reports are a useful metric for all of us to better understand if and when our data can potentially be accessed by law enforcement.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We could not find instances where the other companies publicly state a policy around notification or transparency reports, and no others replied to our email questions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Any company that handles data that’s of interest to law enforcement and governments owes it to their users to publish transparency reports and, when legally possible, notify users when that data is requested. This is especially true of personal health data, which can reveal our movements, and be used to infer details about what we’re doing at any given moment.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;End-to-End Encrypted Data Is Far Too Rare of a Feature&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://ssd.eff.org/playlist/interested-in-encryption&quot;&gt;&lt;span&gt;End-to-end encryption is a method&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to ensure that your personal data is only accessible by you, and not the company who makes the device and manages the cloud storage. End-to-end encryption is usually used to refer to message encryption in communication apps, like Signal or WhatsApp, but can also refer to data storage. For example, many &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/choosing-the-password-manager-that-s-right-for-you#end-to-end-encrypted-backups&quot;&gt;&lt;span&gt;password managers use end-to-end encryption&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/02/amazon-rings-end-end-encryption-what-it-means?language=en&quot;&gt;&lt;span&gt;Ring implemented it for its cameras&lt;/span&gt;&lt;/a&gt;&lt;span&gt; after &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2020/02/how-ring-could-really-protect-its-users-encrypt-footage-end-end&quot;&gt;&lt;span&gt;we pushed for it&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. There’s no reason it can’t be offered for wearables too.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In the case of health data from wearable devices, it’s a way to store data in the cloud so that information can be synced and backed up between your device and an app on your phone in a way where only your devices can access it. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Support for end-to-end encryption is more rare than transparency reports. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The Apple Watch, at least with data that’s stored in the Health app, is the &lt;/span&gt;&lt;a href=&quot;https://www.apple.com/health/pdf/Health_Privacy_Overview_May_2023.pdf&quot;&gt;&lt;span&gt;only popular fitness wearable that supports end-to-end encryption&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and it’s enabled by default for all users (you are required to have two-factor authentication enabled as well, but that is also on by default for most accounts).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;However, Apple Watch owners should remember that this protection is only for data stored in the Apple Health app. If you use other apps on your watch, or choose to share data with third-parties, like Strava, or if you’re sharing data with other wearables, like an Oura ring, that data is likely &lt;/span&gt;&lt;i&gt;&lt;span&gt;not&lt;/span&gt;&lt;/i&gt;&lt;span&gt; end-to-end encrypted by the third-party company. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;Support for end-to-end encryption is more rare than transparency reports. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And that’s it. Apple is the only one. No other popular consumer health wearable offers end-to-end encryption for the data it collects and stores online. Not Google. Not Garmin. Not Oura. Most of these companies instead offer encryption in transit and at rest, but this means those companies can still see and use your data. This is the industry standard, but it doesn’t have to be.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Another option would be more robust local-storage options. Some devices we looked at, like a handful of Garmin and Polar watches, can operate on the watch itself without syncing data to the cloud, but some models are limited in capability and cannot sync to an app without storing data online. More robust options for limiting the data to just the wearable and the phone app it&#039;s synced to would be a privacy improvement. For example, the Apple Watch has the option to disable iCloud sharing in Apple Health, which will keep the data only on your phone. It’s the only wearable we found that offers this feature without using a third-party app like &lt;/span&gt;&lt;a href=&quot;https://gadgetbridge.org/&quot;&gt;&lt;span&gt;Gadgetbridge&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or by physically connecting the wearable to a computer with a USB cable and transferring activity files over manually.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The general lack of local-only options or end-to-end encryption is a major privacy oversight, especially when you consider these devices collect heart rate, track sleep, and can log your location while also calculating a variety of health metrics supposedly intuiting everything from anxiety to your fitness “age.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We understand that it’s technically more difficult to implement end-to-end encryption than other sorts of cloud storage, and comes with some limitations that may affect a user’s experience with a product. It also makes certain types of AI-related features harder to implement, since they’d typically need to work on-device (either in the app or the wearable device itself). Because of that, we believe an &lt;/span&gt;&lt;i&gt;&lt;span&gt;option&lt;/span&gt;&lt;/i&gt;&lt;span&gt; for end-to-end encryption or local-only storage of the data collected by a wearable is the least companies can do. This way, those who want to use these devices can do so with the choice to either accept some privacy risks, or choose a more locked down option.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;What’s Next&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;If you’re a user of a fitness wearable from any of the companies we’ve reached out to, or any other one, don’t be shy in asking for these sorts of features. In the rare cases a company offers a feature request page, use it—like for &lt;/span&gt;&lt;a href=&quot;https://www.garmin.com/en-US/forms/ideas/&quot;&gt;&lt;span&gt;Garmin&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://support.polar.com/en/contact-form/development-idea&quot;&gt;&lt;span&gt;Polar&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://forum.suunto.com/category/13/feature-suggestions&quot;&gt;&lt;span&gt;Suunto&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.community.whoop.com/c/product-feedback/15&quot;&gt;&lt;span&gt;Whoop&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. And when those types of outlets aren’t offered, don’t shy away from general contact pages, like those offered by &lt;/span&gt;&lt;a href=&quot;https://www.amazfit.com/pages/contact-us&quot;&gt;&lt;span&gt;Amazfit&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://partnersupport.ouraring.com/hc/en-us/requests/new?ticket_form_id=360001793194&quot;&gt;&lt;span&gt;Oura&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, or on community subreddits.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The companies that make these wearables, whether they’re designed for fitness or health, need to improve. At the bare minimum, companies need to publish transparency reports detailing how often they receive requests from law enforcement and commit to notifying users whenever that happens. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;It’s also well past the time for more companies to offer end-to-end encryption for the health data they’re storing. We acknowledge that this may be a trade-off for some features, like social networking features, but it should be up to users to decide if they’re willing to make those trade-offs. This level of privacy is an appealing feature that benefits users in myriad ways and more companies can set themselves apart by committing to this level of privacy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Health data is some of the most personal data we produce, and most wearables companies are behind the times when it comes to basic privacy practices and transparency. Now’s the time to improve those practices. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 15 Jul 2026 19:56:18 +0000</pubDate>
 <guid isPermaLink="false">112202 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/transparency">Transparency</category>
 <category domain="https://www.eff.org/issues/law-enforcement-access">Law Enforcement Access</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Thorin Klosowski</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/wearable-tech-green.jpg" alt="silhouette of running woman surrounded by digital interface" type="image/jpeg" length="235834" />
  </item>
  <item>
    <title>🚫 Don&#039;t Let Congress Age-Gate the Internet | EFFector 38.13</title>
    <link>https://www.eff.org/deeplinks/2026/07/dont-let-congress-age-gate-internet-effector-3813</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;The effort to age gate the internet is back in Washington—and now it has a new name. Recently passed by the House of Representatives, the KIDS Act is a sprawling package of proposals to control what we can see and say online. Supporters claim the KIDS Act is needed to protect minors online. But if lawmakers really want to make the internet safer, why are they encouraging more surveillance instead of protecting our privacy? We dive into this question with our &lt;a href=&quot;https://eff.org/effector/38/13&quot;&gt;EFFector newsletter&lt;/a&gt;.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.eff.org/effector/&quot;&gt;JOIN OUR NEWSLETTER&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For over 35 years, &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFFector&lt;/a&gt; has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers a &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-data?utm_source=effector&quot;&gt;victory for location privacy&lt;/a&gt; in the Supreme Court, disturbing developments in the &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/lawmakers-must-act-now-prevent-armed-police-drones?utm_source=effector&quot;&gt;militarization of domestic drones&lt;/a&gt;, and a &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/house-passed-kids-act-senate-should-reject-it?utm_source=effector&quot;&gt;controversial Congressional bill&lt;/a&gt; to control what we can see and say online.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Prefer to listen in? EFFector is now available on all major podcast platforms. This time, we&#039;re chatting with EFF Senior Policy Analyst Joe Mullin on what would happen to the open internet if the KIDS Act becomes law. You can find the episode and subscribe&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://effector.simplecast.com/&quot;&gt;on your podcast platform of choice&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: 70px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F4e65dc91-33af-4dd4-ae88-1c8626b39537%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/4e65dc91-33af-4dd4-ae88-1c8626b39537?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/6Q48ICplENdQ4ZarUIgfLZ&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effector/id1882562931&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.com/podcasts/83be1062-f511-47b3-bd2b-fc44e831c3ad&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feeds.eff.org/effector&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Want to protect your right to online anonymity and access to the open web? Sign up for &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFF&#039;s EFFector newsletter&lt;/a&gt; for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you &lt;a href=&quot;https://eff.org/join&quot;&gt;support EFF today&lt;/a&gt;!&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 15 Jul 2026 17:02:02 +0000</pubDate>
 <guid isPermaLink="false">112200 at https://www.eff.org</guid>
 <dc:creator>Christian Romero</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/effector-green-web.png" alt="" type="image/png" length="78242" />
  </item>
  <item>
    <title>European Court: Apple Can Not Shirk Off its Interoperability Requirements</title>
    <link>https://www.eff.org/deeplinks/2026/07/european-court-apple-can-not-shirk-its-interoperability-requirements</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;One of the best bulwarks against monopoly is interoperability—that is making a new product or service work with an existing product or service. Interoperability allows users, and not the manufacturers of their devices or largest player in a market, to decide what application best serves them. Unsurprisingly, companies like Apple have worked hard to resist interoperability requirements. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;On July 8, the General Court of the  European Union (General Court) &lt;/span&gt;&lt;a href=&quot;https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260096en.pdf&quot;&gt;&lt;span&gt;ruled&lt;/span&gt;&lt;/a&gt;&lt;span&gt; against Apple in several cases the company brought against the European Commission (&lt;/span&gt;&lt;a href=&quot;https://infocuria.curia.europa.eu/tabs/tout?lang=EN&amp;amp;searchTerm=%2522T%252D1080%252F23%2522&quot;&gt;&lt;span&gt;joint cases&lt;/span&gt;&lt;/a&gt;&lt;span&gt;), affirming the company’s obligations under the Digital Markets Act (DMA). Apple argued in the cases that it should be exempted from the law’s requirements &lt;/span&gt;&lt;i&gt;&lt;span&gt;especially with regards to interoperability&lt;/span&gt;&lt;/i&gt;&lt;span&gt; on multiple grounds. We applaud the General Court’s  decision, and congratulate the Free Software Foundation Europe (FSFE) as well as others who &lt;/span&gt;&lt;a href=&quot;https://fsfe.org/news/2026/news-20260708-01.en.html&quot;&gt;&lt;span&gt;intervened in support of the Commission against Apple&#039;s attempt&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to shirk off its responsibilities, thus ensuring fair competition in European markets.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;A Positive Development for Europeans&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This is a clear and substantive win for developers and users in Europe. The stranglehold Apple exerts over its ‘walled garden’ is injurious for developers, users, and researchers alike. By confirming Apple’s obligations under the DMA, the General Court has ensured that developers will be given more choice on where they can publish their apps, and users will have more options to obtain apps which, for whatever reason, Apple dislikes. And researchers will have less roadblocks and hurdles to overcome in their studies of Apple’s OSes, particularly iOS, iPadOS, and watchOS.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Apple argues that the interoperability requirements will force it to lower the security standards that have led Apple products’ users to trust their devices. While this self-serving logic is not entirely without merit, it is far from the inevitable outcome. Especially with regards to the App Store, users can be given clear, informed choice when leaving the Apple ecosystem to obtain apps elsewhere. While we urge European courts to take Apple’s security concerns seriously, we’ve &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/04/eu-digital-markets-acts-interoperability-rule-addresses-important-need-raises&quot;&gt;&lt;span&gt;previously noted&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that this should not be used as a smokescreen to protect anticompetitive behavior.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Interoperability and security are not inherently at odds. When interoperable functionality is worked into the security model of a platform from the ground-up, a proper balance can be struck between two forces that are often falsely framed as naturally conflicting. While Apple OS platforms have not been built this way from the get-go, it is still possible, but takes more time to get it right. Here, the devil is in the implementation details.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Apple’s Case Arguments and the Court’s Rebuttal&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Under the DMA, designation as a ‘gatekeeper’ is reserved for the biggest of Big Tech, companies that provide services deemed essential for businesses to reach end users. Apple is one of only &lt;/span&gt;&lt;a href=&quot;https://digital-markets-act.ec.europa.eu/gatekeepers-portal_en&quot;&gt;&lt;span&gt;seven&lt;/span&gt;&lt;/a&gt;&lt;span&gt; companies that meet this designation, along with Alphabet, Amazon, Booking, ByteDance, Meta, and Microsoft. In its case, Apple argued that Article 6(7) of the DMA, specifying interoperability requirements for gatekeepers aimed at restoring fair competition, is unlawful in light of the Charter of Fundamental Rights of the European Union (specifically the right to property), and as such its designation as a gatekeeper subject to the requirements is unlawful and should be annulled as a result. In its ruling, the General Court rejected the argument as Article 6(7) does not form the legal basis of the designation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Apple separately argues that the App Store fails to meet the requirements defining a core platform service (CPS), since the various stores (across iOS, iPadOS, watchOS, macOS) do not constitute a single platform. A company’s gatekeeper status relies on it providing a CPS that is an important gateway for business users to reach end users. Here, the implications of the argument are clear: remove service designation as CPSes, remove the gatekeeper status. The court rejected the argument on the basis that “irrespective of the device on which it was available, each of the App Stores was used for the same purpose, namely to intermediate between end users and business users in the distribution of applications and in-app digital content.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Finally, the court rejected as inadmissible Apple’s argument that iMessage should not be classified as a number-independent interpersonal communication service (NIICS) constituting a CPS. This decision rested on the fact that the “classification does not, by itself, produce binding legal effects that bring about a change in Apple’s legal position” since iMessage was not listed as an “important gateway” in the designation decision and therefore was not subject to the DMA obligations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In ruling against Apple in favor of the European Commission, the General Court has set an important precedent in ensuring competitive fairness and openness in the digital marketplace. The landmark effects of the DMA will serve to benefit all Europeans in the choice and freedom it affords them. Despite Big Tech’s legal challenges, these decisions build a strong foundation for a better digital future—a lesson which other regions should learn from and take note.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 14 Jul 2026 21:14:31 +0000</pubDate>
 <guid isPermaLink="false">112198 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/taxonomy/term/76">News Update</category>
 <dc:creator>Bill Budington</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/cjeu.png" alt="CJEU" type="image/png" length="80540" />
  </item>
  <item>
    <title>Don’t Repeat NY’s 3D Printing Blunder</title>
    <link>https://www.eff.org/deeplinks/2026/07/dont-repeat-nys-3d-printing-blunder</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect every artist, researcher, engineer, and hobbyist in the state, but there is a real risk of other states thoughtlessly following suit—prior to the New York rules even taking effect.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We, along with many &lt;/span&gt;&lt;a href=&quot;https://blog.adafruit.com/2026/02/03/new-york-wants-to-ctrlaltdelete-your-3d-printer/&quot;&gt;&lt;span&gt;other experts&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/stop-new-yorks-attack-3d-printing&quot;&gt;&lt;span&gt;already warned about this bill&lt;/span&gt;&lt;/a&gt;&lt;span&gt; buried in the state’s crowded budget process. Hundreds of our supporters and 3D printing enthusiasts in New York reached out to their representatives hoping to kill this farcical bill. While there were some welcome amendments in response to the outcry, Albany passed it anyway.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;It might be well-intentioned, but bills like these sell a fantasy that can only have an untold negative impact on the privacy, free expression, and consumer rights of anyone using these general purpose devices. Behind the banner of reducing gun violence, which is nearly always committed with commercial firearms, New York lawmakers have passed draconian legislation that will let manufacturers lock in users and collect their data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Now that the bill has passed and been signed by Governor Hochul, let’s look at two important ways &lt;/span&gt;&lt;a href=&quot;https://www.nysenate.gov/legislation/bills/2025/S9005/amendment/C&quot;&gt;&lt;span&gt;the final legislation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; changed &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/stop-new-yorks-attack-3d-printing&quot;&gt;&lt;span&gt;since we last wrote about it&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and why states like &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/3DPrintCA&quot;&gt;&lt;span&gt;California shouldn’t make the same mistake&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Reduced Risk for Lawful File Sharing &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The New York bill includes language that criminalizes access to firearm print files, a proposal correctly dropped by &lt;/span&gt;&lt;a href=&quot;https://hoodline.com/2026/03/polis-veto-scare-ends-with-scaled-back-3d-gun-ban-at-colorado-capitol/&quot;&gt;&lt;span&gt;states like Colorado&lt;/span&gt;&lt;/a&gt;&lt;span&gt; due to First Amendment concerns. While this made it through to the passed legislation, a few wins were still gained.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Originally the legislation threatened felony charges for the storing and sharing of files, potentially impacting researchers, artists, and journalists with no intention of printing a firearm component. These charges were downgraded to a Class A misdemeanor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Two provisions criminalized file sharing. The first of the two provisions criminalizing this file sharing, which pertains to the sale or distribution of files in the state, gained an important exception for when a sender has a reasonable belief that the recipient won’t illegally print these components. However the second provision, pertaining to criminalizing file possession, complicates this. &lt;a href=&quot;https://www.nysenate.gov/legislation/bills/2025/S9005/amendment/C&quot;&gt;Under 2.12&lt;/a&gt; of the subpart, people who possess the file with &lt;/span&gt;&lt;i&gt;&lt;span&gt;intent&lt;/span&gt;&lt;/i&gt;&lt;span&gt; to share the files do not clearly get this same reasonable belief exception.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In other words, if you share one of these files the actual sharing is covered by the exception, but the law makes it ambiguous whether possessing those same files is covered when you intend to share them.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;While this exception could have created some breathing room for researchers and journalists operating in good faith, this slapdash bill language leaves plenty of ambiguity and potential speech-chilling effects. However, these changes do offer a modicum of harm reduction in this unconstitutional law.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Saving Face by Preserving Online Sale&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Originally the bill had a strange requirement for all 3D printers and Computer Numerical Control, or CNC, machines to be sold and delivered face-to-face, with no exception. That would have meant a major barrier to access, particularly for people in &lt;/span&gt;&lt;a href=&quot;https://www.mdpi.com/2624-7402/8/3/104&quot;&gt;&lt;span&gt;agricultural&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.voxelmatters.com/low-cost-3d-printed-simulators-rural-medical-training/&quot;&gt;&lt;span&gt;rural areas&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of the state who uniquely benefit from in-home fabrication and repair. It also would have meant a major inconvenience for businesses using these devices. For everyone though, it meant fewer retailers to choose from and facing more stigma for using these devices. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Fortunately this was dropped from the bill entirely. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Next Step: We Find Out What Was Actually Passed&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;In addition to being buried in the complicated legislative process of the NY budget and avoiding proper scrutiny, this bill also kicked the can down the road in determining what &lt;/span&gt;&lt;i&gt;&lt;span&gt;exactly&lt;/span&gt;&lt;/i&gt;&lt;span&gt; is being mandated. In many respects, legislators passed a vibe. We’ll see how the actual law be developed over the next year by a working group with no mandated transparency to the public. Further, they have no obligation to ensure consumer safeguards in developing this state-mandated censorware.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We are still concerned by the possibility of a biased working group acting in the interest of manufacturers or facing pressure to accept consumer harms in the standards they produce. Our remaining hope is this working group convened by the Department of State and the state university system is composed of actual experts who are aware of how &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/print-blocking-wont-work-permission-print-part-2&quot;&gt;&lt;span&gt;unfeasible&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/print-blocking-anti-consumer-permission-print-part-1&quot;&gt;&lt;span&gt;harmful&lt;/span&gt;&lt;/a&gt;&lt;span&gt; this mandate is, and prevent it from being realized.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;The Fight Continues&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;New York is the first to go down this path of state-mandated censorship and surveillance software on 3D printers, but it’s far from the only one to entertain it. It is now more urgent that we fiercely oppose this trend in other states, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/we-can-still-stop-californias-3d-printer-surveillance-scheme&quot;&gt;&lt;span&gt;like California&lt;/span&gt;&lt;/a&gt;&lt;span&gt;,  as they attempt to join the bandwagon—before even seeing the real-world impacts.  &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.eff.org/3DPrintCA&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://www.eff.org/3DPrintCA&quot;&gt;Don’t Let California Repeat NY’s Mistake&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We cannot allow this to be the foundation for future restrictions on speech and design, or serve as a playbook for the state and corporations to wrest control over our tools.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 14 Jul 2026 19:52:39 +0000</pubDate>
 <guid isPermaLink="false">112196 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <category domain="https://www.eff.org/issues/competition">Competition</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Rory Mir</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/3d-ny-3-banner.jpg" alt="3D printer makes a map of NY" type="image/jpeg" length="283416" />
  </item>
  <item>
    <title>Sony Nerfs Videogame Ownership</title>
    <link>https://www.eff.org/deeplinks/2026/07/sony-nerfs-videogame-ownership</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;i&gt;&lt;span&gt;Legal intern Suzanne Castillo co-authored of this post.&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Playstation’s &lt;/span&gt;&lt;a href=&quot;https://www.ign.com/articles/sony-just-killed-discs-physical-disc-production-to-end-january-2028-for-new-games-releasing-on-playstation-consoles&quot;&gt;&lt;span&gt;decision to kill physical game discs&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and negligent lawmakers share the blame — and they can do better. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We’ve seen the same playbook used in the move to digital distribution of  film, TV, and music: draw in customers with the convenience of a digital download, then limit physical access and move the goalpost on what it actually means to “own” a piece of media. The end goal is to &lt;/span&gt;&lt;a href=&quot;https://www.digitalrightsbytes.org/topics/wait-i-don-t-own-the-digital-downloads-i-buy&quot;&gt;&lt;span&gt;turn the customer into a renter&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, stuck making regular &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/01/fragging-subscription-model-comes-gamers&quot;&gt;&lt;span&gt;subscription payments&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for access. Gamers are right to sound the alarm, and we must take this moment to fight for digital ownership before it’s too late.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Disk Space Invaders&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Depriving gamers of physical discs leads to another obvious and immediate cost: data.  Unlike other digital media like film and TV, video games require a ton of storage. Access to high speed internet is still abysmal in the US, making the high-speeds needed for digital game downloads a luxury some of us may take for granted. For many, a modern game can take days and exceed their data caps. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This made physical discs, particularly for the &lt;/span&gt;&lt;a href=&quot;https://www.bbc.com/news/articles/cjrg52egw1ro&quot;&gt;&lt;span&gt;biggest AAA titles&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a logical choice that also largely spared gamers from losing traditional ownership rights. With physical disks, the cost of storing the game was included in the purchase.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Own or Be Pwned&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Limiting customers to digital copies also pushes gamers further into &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/01/rent-only-copyright-culture-makes-us-all-worse&quot;&gt;&lt;span&gt;rent-only copyright culture&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Physical media comes with a &quot;right of first sale,&quot; which means you can lawfully share, resell, alter, or destroy your own copy of a copyrighted work. This right has also helped protect the emergence of alternative community servers, and emulator addition of online play to &lt;/span&gt;&lt;a href=&quot;https://www.timeextension.com/news/2026/05/it-was-honestly-not-that-hard-this-nintendo-64-emulator-lets-you-play-online-with-rollback-netcode&quot;&gt;&lt;span&gt;games from the dial up era&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But courts have held that digital media doesn&#039;t carry the same right, meaning no such protection is afforded to digital purchases. Your ability to freely share games with friends or pass them on to family members becomes totally subject to the whims of the distributor. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;So, for example, a digital-only approach effectively guts the second-hand market for games. Saving some money with a used game and recouping the costs by reselling are no longer an option. Even with steep discounts and holiday sales, this &lt;/span&gt;&lt;a href=&quot;https://kotaku.com/analysts-say-sonys-termination-disc-game-one-step-closer-death-physical-games-2000712106&quot;&gt;&lt;span&gt;raises the minimum cost&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of engaging with the medium at all.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The inevitable conclusion of the move to digital-only purchases is to lock gamers into  &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/01/fragging-subscription-model-comes-gamers&quot;&gt;&lt;span&gt;subscription models&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, making their access totally dependent on the distributor — or, several distributors, as we’ve seen with major TV and movie streamers. A handful of companies actually own the games, and your only option is to regularly pay for fractured libraries of games you may never play and &lt;/span&gt;&lt;a href=&quot;https://www.ign.com/articles/hideo-kojima-warns-of-frightening-digital-future-after-playstation-reveals-plan-to-end-physical-disc-production&quot;&gt;&lt;span&gt;will never truly own&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Achievement Locked&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Since digital games are easy to copy, distributors and publishers argue that they are in an arms race against piracy. The irony is that law-abiding customers consistently suffer collateral damage. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Most digital distributors lock down the content they offer with restrictive user agreements and digital rights management (DRM) software. DRM software, in particular, imposes onerous controls on the game — like &lt;/span&gt;&lt;a href=&quot;https://www.tomshardware.com/video-games/pc-gaming/denuvo-has-been-bypassed-in-all-single-player-games-it-previously-protected-2k-games-and-denuvo-reportedly-retaliate-with-mandatory-14-day-online-checks&quot;&gt;&lt;span&gt;forcing internet connection for single player games &lt;/span&gt;&lt;/a&gt;&lt;span&gt;or modifications that harm performance — and can even introduce serious privacy and security concerns. Any gamer or researcher in the US who wants to reduce this burden by removing or modifying that DRM risks a lawsuit, thanks to Section 1201 of the Digital Millennium Copyright Act (DMCA). This federal law makes it illegal to alter DRM software, and is a beloved tool for companies trying to restrict how we can lawfully use our purchases — whether it’s a copy of the newest tractor simulator or &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2016/12/john-deere-really-doesnt-want-you-own-tractor&quot;&gt;&lt;span&gt;a literal tractor&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And since much of this DRM is tied to user accounts, ownership of a game is also revocable and modifiable for any number of reasons outside of your control. Error in your subscription payment? Your account got hacked? Licensing deal falls through with a major publisher? Developers want to kill the game in an update? All of this can limit or change your ability to access the game long after your so-called “purchase.”&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Level-up Ownership&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Policymakers can and should work to restore our ownership rights for the digital age. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That starts with legal protections ensuring that the same rights that apply to physical media apply to digital media. Next up? Reform Section 1201 of the DMCA to clarify that it does not forbid fair uses.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;At the state level, we need meaningful consumer protections. Some promising models include California’s AB 1921, which would clarify what customers &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2016/05/what-do-customers-think-theyre-getting-when-they-buy-media-online&quot;&gt;&lt;span&gt;are actually paying for&lt;/span&gt;&lt;/a&gt;&lt;span&gt; on digital storefronts and ensure some protections for maintaining discontinued games. The gaming industry has done its best to kill the bill, including claiming that &lt;/span&gt;&lt;a href=&quot;https://www.yahoo.com/news/politics/articles/esa-quietly-starts-walking-back-140625401.html&quot;&gt;&lt;span&gt;private community servers are illegal&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you bought it, you should own it, and EFF will continue working to mitigate some of the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/cases/2018-dmca-rulemaking&quot;&gt;&lt;span&gt;worst harms of the DMCA 1201&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, defending modders, and fighting deceptive licensing that makes culture less free. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 13 Jul 2026 17:30:45 +0000</pubDate>
 <guid isPermaLink="false">112190 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/video-games">Video Games</category>
 <category domain="https://www.eff.org/issues/drm">DRM</category>
 <category domain="https://www.eff.org/issues/dmca-rulemaking">DMCA Rulemaking</category>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <dc:creator>Rory Mir</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/videogame.png" alt="multi-color alien sprites from videogame space invaders" type="image/png" length="6104" />
  </item>
  <item>
    <title>Building Our Future Together</title>
    <link>https://www.eff.org/deeplinks/2026/07/building-our-future-together</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;In my first weeks as Executive Director of EFF, I’ve been reminded every day how consequential this moment is in determining what kind of future we will have. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We are on the edge. What each one of us steps up to do – with our expertise, energy, and resources – will determine whether our future is one of openness, security, and fundamental rights, or one controlled through fear, surveillance, and centralized power. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I am proud to take the torch and help lead our EFF community forward at this pivotal time in history. &lt;a href=&quot;https://supporters.eff.org/donate/nicole--wsjd&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;And we need you in the fight&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;We can and must reject a false choice between innovation and civil liberties.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Right now, we are &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-data&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;celebrating an important U.S. Supreme Court win&lt;/a&gt;&lt;span&gt; in &lt;em&gt;Chatrie v. United States&lt;/em&gt; that reaffirmed our right to privacy in our location data and will help curb one flank of supercharged government surveillance. But in another case, the Court &lt;/span&gt;&lt;a href=&quot;https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;overturned 90 years of precedent limiting executive power&lt;/a&gt; and rubber-stamped the President’s firing of FTC Commissioner Rebecca Slaughter. The U.S. government also issued a chilling directive to Anthropic to &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/ai-regulation-should-be-rational-not-retaliatory&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;prohibit the company from allowing foreign nationals to access its newest technology&lt;/a&gt; – then rescinded it two weeks later. And legislation &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/how-and-why-fight-back-against-social-media-bans&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;limiting access to social media &lt;/a&gt;is advancing in many places around the world.&lt;/p&gt;
&lt;p&gt;Each headline is different, but they tell one story: Many of the threats that once seemed hypothetical are now reality, and EFF’s work to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical. Governments and large corporations possess surveillance capabilities that were unimaginable just a few years ago. Ever greater concentrations of power are shaping speech, creativity, markets, and democratic institutions. Governments are increasingly seeking to control the internet and people’s ability to access information and communicate freely. Our community’s work is fundamental to the future of our countries, our livelihoods, and literally our lives.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I am also mindful that the United States marked its 250&lt;sup&gt;th&lt;/sup&gt; anniversary last week and that this week is EFF’s 36&lt;sup&gt;th&lt;/sup&gt; birthday. Anniversaries, like leadership changes, naturally invite reflection on where we are in history and challenge us to look ahead. &lt;/span&gt;What does it mean for a democracy, founded in an analog age, to survive in the digital world?&lt;/p&gt;
&lt;p&gt;&lt;span&gt;It is also an opportunity to ask how our EFF community can be even stronger, so we can help bring more people into the work of making sure technology serves everyone. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I began my career in public-interest work in Silicon Valley at the height of the 1990s dotcom boom, working at some of the earliest nonprofit “digital divide” programs that provided community access to computers and the internet, because I have always believed in the power of technology to create greater opportunity for all, not just profit for a few. I have dedicated my career to public interest technology because I am driven to see technology’s promise realized in my lifetime, and there is no other organization in the world that can do more to meet this moment and build a future where technology truly works for people than EFF.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;These are perilous times. It is also a moment of extraordinary possibility. The &lt;/span&gt;&lt;span&gt;future of AI has not been written and we can work together to get it right. &lt;/span&gt;&lt;span&gt;We can make sure our laws reflect the needs of the modern digital age. We can build the technologies that empower rather than marginalize communities. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span&gt;The future we want and need will be built by people and movements working together to ensure technology empowers rather than oppresses.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For me, the work starts with recognizing that &lt;/span&gt;&lt;span&gt;digital rights are not a siloed policy issue. We must fight and win on the digital terrain to organize, speak freely, access healthcare, find work, receive an education, and participate fully in democracy. We can and must reject a false choice between innovation and civil liberties, and build power across movements to make sure technology truly works for people. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;This challenge is what EFF was purpose-built to tackle. &lt;span&gt;When EFF was founded in 1990, the World Wide Web did not yet exist, cell phones were the size of bricks, and EFF’s founders understood something remarkably prescient: Technology and civil liberties would become inseparable. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Now we all live digital lives, and the important digital rights issues that EFF has worked on since 1990 have become kitchen-table issues all around the world. EFF’s founders understood that how technology is built, developed, used, and controlled deeply intersects with rights, justice, freedom, and democracy. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF’s unique combination &lt;/span&gt;&lt;span&gt;of world-class lawyers, activists, and public interest technologists pursue change simultaneously in the courts, legislatures, companies, and our communities, and pierce through false choices. This integrated, intersectional approach, grounded in deep legal, policy, and technical expertise, is &lt;/span&gt;&lt;span&gt;a linchpin in fighting and winning against some of the most powerful forces in the world – both governments and trillion-dollar companies.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;We &lt;a href=&quot;https://www.eff.org/cases/american-federation-government-employees-v-us-office-personnel-management&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;defend people against unlawful government data collection&lt;/a&gt; and &lt;a href=&quot;https://sls.eff.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;challenge license plate and face surveillance&lt;/a&gt; in our communities. &lt;span&gt;We &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/ai&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;shape AI law and policy&lt;/a&gt;&lt;span&gt; to protect civil liberties and support creativity and innovation. We &lt;/span&gt;&lt;a href=&quot;https://encryptitalready.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;push companies to strengthen encryption&lt;/a&gt;, &lt;span&gt;fight to ensure you have the &lt;/span&gt;&lt;a href=&quot;https://drb.eff.org/topics/wait-i-don-t-own-the-digital-downloads-i-buy&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;right to own what you buy&lt;/a&gt;&lt;span&gt;, and build public interest technologies like &lt;/span&gt;&lt;a href=&quot;https://privacybadger.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Privacy Badger&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://certbot.eff.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Certbot&lt;/a&gt;&lt;span&gt; that millions of people rely on every day. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;This work matters because it all answers the same question: Will technology empower or control us?&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As I look ahead, there are major battles on the horizon. We must:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Challenge increasingly sophisticated government and corporate surveillance systems that endanger our rights, democracy, safety and security&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Preserve strong encryption and online anonymity&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Ensure AI is developed and used in ways that respect fundamental rights and works for those who build it, use it, and are affected by it&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Confront the concentrations of power that limit access to new creativity and defend the rights of developers to build and innovate&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To meet these challenges, we must not only utilize the powerful levers of successful litigation, smart policy interventions, and effective public interest technology tools. We must also build a broader movement that recognizes that fights on the digital terrain are integral to all our fights for rights and justice – from civil rights and immigrants’ rights to reproductive rights, disability rights, LGBTQ+ rights, workers&#039; rights, economic justice, and more. Together, our EFF community can help broaden the public conversation about technology&#039;s role in society and continue building the collective power necessary to shape the future rather than react to it.&lt;/p&gt;
&lt;p&gt;I have hit the ground running, working with EFF’s exceptional staff and Board and starting to meet many of you in the broader EFF community. Every conversation has reinforced my confidence that our community is uniquely prepared for the work ahead. I’m looking forward to meeting more of you at my first &lt;a href=&quot;https://www.eff.org/pages/effecting-change&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;EFFecting Change &lt;/a&gt;livestream on August 12 with &lt;a href=&quot;https://www.eff.org/pages/cory-doctorow&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Cory Doctorow&lt;/a&gt;, and hope this conversation is just the beginning of finding new ways to work together. Please stay tuned for additional in-person events with me around the country this fall.&lt;/p&gt;
&lt;p&gt;As we celebrate EFF&#039;s birthday, &lt;span&gt;I am energized by all the opportunities ahead for us to build on EFF’s strong foundation and make it even mightier&lt;/span&gt;. And we need you and others in the fight. Please renew your membership, &lt;a href=&quot;https://supporters.eff.org/donate/nicole--wsjd&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;become a recurring monthly supporter&lt;/a&gt;, and introduce someone new to EFF by snagging them a &lt;a href=&quot;https://shopeff.org/products/eff-gift-membership-certificate&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;gift membership&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Everything we accomplish—every lawsuit, every policy victory, every public interest technology tool, every campaign—is possible because people like you are committed to ensuring technology strengthens freedom, privacy, creativity, and opportunity for everyone.&lt;/p&gt;
&lt;p&gt;The future we want and need will be built by people and movements working together to ensure technology empowers rather than oppresses.&lt;/p&gt;
&lt;p&gt;Let’s build that future together.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 10 Jul 2026 15:00:03 +0000</pubDate>
 <guid isPermaLink="false">112181 at https://www.eff.org</guid>
 <dc:creator>Nicole Ozer</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/welcomenicky-banner.jpg" alt="EFF Executive Director Nicole Ozer" type="image/jpeg" length="369075" />
  </item>
  <item>
    <title>Automated Moderation Is Here to Stay—Accountability Must Keep Pace</title>
    <link>https://www.eff.org/deeplinks/2026/07/part-2-automated-moderation-here-stay-accountability-must-keep-pace</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;em&gt;This post is part 2 in a series about automated content moderation. Read the first post &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/part-1-automated-moderation-here-stay&quot;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;When whistleblower Frances Haugen leaked a set of documents from Meta in 2020, among the revelations was a jarring statistic: The company’s algorithms designed to detect terrorist content incorrectly &lt;a href=&quot;https://www.politico.eu/article/facebook-content-moderation-posts-wars-afghanistan-middle-east-arabic/&quot;&gt;deleted nonviolent Arabic-language content&lt;/a&gt; 77 percent of the time, while &lt;a href=&quot;https://www.isdglobal.org/media-mentions/the-facebook-papers-hate-speech-filters-through-in-middle-east-thanks-to-lack-of-arabic-language-monitoring-and-faulty-ai-tech/&quot;&gt;failing to detect hate speech&lt;/a&gt; under the company’s own policies in many instances. Meta’s own transparency report released later that year &lt;a href=&quot;https://www.eff.org/deeplinks/2020/10/facebooks-most-recent-transparency-report-demonstrates-pitfalls-automated-content&quot;&gt;demonstrated similar findings&lt;/a&gt;. Five years later, researchers in the region report that &lt;a href=&quot;https://7amleh.org/post/meta-suppression-of-palestinian-content-en&quot;&gt;overzealous moderation remains a problem&lt;/a&gt;, while paths to remedy have all but collapsed.&lt;/p&gt;
&lt;p&gt;Where these systems are faltering in Arabic, they’re positively failing in less-resourced languages. As a &lt;a href=&quot;https://cdt.org/insights/content-moderation-in-the-global-south-a-comparative-study-of-four-low-resource-languages/&quot;&gt;2025 report&lt;/a&gt; from the Center for Democracy and Technology found, labeled datasets in certain languages and dialects such as Maghrebi Arabic and Kiswahili contain inconsistencies, bias, and inaccuracies due to the limited hiring of annotators who actually speak the languages as well as shifts in the languages themselves. An &lt;a href=&quot;https://restofworld.org/2023/chatgpt-problems-global-language-testing/&quot;&gt;investigation&lt;/a&gt; into ChatGPT’s outputs in several low-resource languages demonstrates the depth of problem.&lt;/p&gt;
&lt;p&gt;But language disparities are just one of several concerns as automated moderation becomes more widespread. From the &lt;a href=&quot;https://www.hrw.org/report/2023/12/21/metas-broken-promises/systemic-censorship-palestine-content-instagram-and&quot;&gt;systemic suppression of content from Palestine&lt;/a&gt; to the repeated &lt;a href=&quot;https://www.eff.org/deeplinks/2021/08/how-lgbtq-content-censored-under-guise-sexually-explicit&quot;&gt;misclassification of LGBTQ+ content as adult or explicit material&lt;/a&gt;, these varied examples demonstrate the risks of overreliance on automated moderation—and the need for stronger safeguards.&lt;/p&gt;
&lt;h3&gt;Transparency, Cultural Competence, Appeals&lt;/h3&gt;
&lt;p&gt;As we discussed in &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/part-1-automated-moderation-here-stay&quot;&gt;Part 1&lt;/a&gt; of this series, automated systems can process content at a scale that humans never could, potentially enabling better moderation at scale and alleviating the psychological load on ill-paid moderators whose jobs require them to view incredibly disturbing content. But automated systems also reproduce existing biases, struggle to understand context, and often make mistakes that disproportionately affect journalists, activists, artists, and other vulnerable and marginalized communities.&lt;/p&gt;
&lt;p&gt;As Rachel Griffin &lt;a href=&quot;https://www.cigionline.org/articles/algorithmic-content-moderation-brings-new-opportunities-and-risks/&quot;&gt;wrote in 2023&lt;/a&gt;, “Perfectly accurate moderation is not only technically out of reach but intrinsically impossible.” Despite those intrinsic flaws, there is a great deal companies, policymakers, and civil society can do to help ensure that highly-automated systems operate in ways that respect human rights, minimize predictable harms, and provide meaningful accountability when they fail. If companies are going to continue relying on automation to moderate users’ speech—and there is little reason to believe they won’t—then accountability must evolve alongside these technologies.&lt;/p&gt;
&lt;p&gt;That evolution can start with committing to the &lt;a href=&quot;https://santaclaraprinciples.org/&quot;&gt;Santa Clara Principles 2.0&lt;/a&gt;. These principles, first outlined in 2020 and re-launched in 2021 after substantial international input, reflect the needs and expectations of the global community and specifically address automation. The first Foundational Principle states:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Companies should ensure that human rights and due process considerations are integrated at all stages of the content moderation process, and should publish information outlining how this integration is made. Companies should only use automated processes to identify or remove content or suspend accounts, whether supplemented by human review or not, when there is sufficiently high confidence in the quality and accuracy of those processes. Companies should also provide users with clear and accessible methods of obtaining support in the event of content and account action. &lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Drawing on the &lt;span&gt;&lt;a href=&quot;https://santaclaraprinciples.org/&quot;&gt;Santa Clara Principles 2.0&lt;/a&gt;&lt;/span&gt;, international human rights standards, and &lt;a href=&quot;https://www.cambridge.org/core/journals/cambridge-forum-on-ai-law-and-governance/article/platforms-on-the-hook-eu-and-human-rights-requirements-for-human-involvement-in-content-moderation/63AB46C3687985F39187F923FA9F6341&quot;&gt;years&lt;/a&gt; of &lt;span&gt;&lt;a href=&quot;https://docs.un.org/en/A/73/348&quot;&gt;research&lt;/a&gt;&lt;/span&gt; documenting the shortcomings of automated moderation, we propose eight recommendations for policymakers thinking about regulation and companies deploying AI-assisted content moderation systems.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Automated technologies should help, not replace, human moderators. For example, automated systems can help flag and prioritize content for review, while humans can interpret context, handle sensitive cases, and refine system performance.&lt;/li&gt;
&lt;li&gt;Companies must be transparent about when and how automation is used in content decisions.&lt;/li&gt;
&lt;li&gt;Companies must regularly audit their automated systems for bias, with particular attention to low-resource languages, vulnerable and marginalized communities, and conflict zones.&lt;/li&gt;
&lt;li&gt;Users must have the ability to appeal, and to provide context when they believe human or automated moderation decisions have wrongfully removed their content. Appeals should be promptly evaluated and decided by human moderators.&lt;/li&gt;
&lt;li&gt;Companies should regularly assess the human rights impact of their moderation decisions, and issue public statements of the results&lt;/li&gt;
&lt;li&gt;If they rely on third-party vendors, companies should carefully (and regularly) audit those vendors for compliance with these same principles&lt;/li&gt;
&lt;li&gt;Lawmakers should avoid promoting and passing legislation that effectively or explicitly mandates automated moderation systems&lt;/li&gt;
&lt;li&gt;Policymakers should also refrain from attempting to dictate platforms technical and design choices to favor or disfavor particular expression.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;These recommendations understand that automated content moderation isn’t just a technical problem for clever engineers and product teams to solve. Because content moderation shapes public discourse and fundamental rights, its design and oversight must respond to the concerns of policymakers, civil society, independent researchers, and the communities most affected by these systems.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This is the second post in a 2-part series on automated content moderation. Read the first post &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/part-1-automated-moderation-here-stay&quot;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 10 Jul 2026 13:19:46 +0000</pubDate>
 <guid isPermaLink="false">112189 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/corporate-speech-controls">Corporate Speech Controls</category>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/taxonomy/term/69">Call To Action</category>
 <category domain="https://www.eff.org/taxonomy/term/70">Commentary</category>
 <dc:creator>Jillian C. York</dc:creator>
 <dc:creator>Corynne McSherry</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/social-media-2026-2_1.gif" alt="" type="image/gif" length="3467306" />
  </item>
  <item>
    <title>&quot;We Want Texans to Know Their Rights&quot;: Q&amp;A with Mayday Health on the Impact of Surveillance on Abortion Care</title>
    <link>https://www.eff.org/deeplinks/2026/07/we-want-texans-know-their-rights-qa-mayday-health-impact-surveillance-abortion</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Last May, EFF &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools for keeping communities safe by finding missing persons and locating stolen vehicles, but this case showed how ALPRS can be weaponized to investigate people’s private healthcare decisions. And these aren’t the only tools in the surveillance arsenal: others include location &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/12/location-tracking-tools-endanger-abortion-access-lawmakers-must-act-now&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;tracking tools like Locate X&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, which can show a person’s visit to an abortion clinic, or &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/04/two-years-post-roe-better-understanding-digital-threats&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;search histories&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; which might be used as evidence of a person’s interest in obtaining abortion pills. Taken together, these tools create a dangerous surveillance pipeline that threatens everyone’s health privacy.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Too often, though, the public is unaware of the threat, and one nonprofit is working to change that. Following EFF and 404 Media’s report on Texas’s use of Flock cameras, eye-catching billboards popped up in Houston, warning drivers that if they’re pregnant, the state of Texas could be tracking them. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;img src=&quot;/files/2026/07/09/billboard.jpeg&quot; width=&quot;649&quot; height=&quot;865&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;Photo provided by Mayday Health&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;These billboards came from &lt;/span&gt;&lt;a href=&quot;https://www.mayday.health/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Mayday Health&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, a nonprofit dedicated to sharing information about abortion pills, birth control, and gender-affirming care. We spoke with Leo Raisner, Executive Director of Mayday Health, about the billboards to learn more about the campaign and organization and to discuss how surveillance affects reproductive freedom.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;***&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;THOMAS: Why did Mayday Health start this campaign in Texas? &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;RAISNER: Well, we read the incredible reporting coming from EFF about &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/flock-safety-and-texas-sheriff-claimed-license-plate-search-was-missing-person-it&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Texas&#039;s surveillance&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. We want Texans to know their rights, to know their options, and to know that there are organizations and people who have their back. So we decided to put up a few billboards around the Houston area to remind people that they still have options. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Digital advertising in the space, as I know you&#039;re well aware of, faces enormous platform restrictions from Meta and Google, whereas billboards reach people in the physical world without algorithmic gatekeeping and without requiring anyone to search for information. So at the very least, if a driver&#039;s passing by the billboard, we’re spreading information that they should be careful that they might be surveilled, and also there are different options. There&#039;s a website where they can come learn more about those options.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;THOMAS: And how have the billboards been received so far? Have you heard anything from folks in the Houston area yet? &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;  &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;RAISNER: Yeah, we&#039;ve heard some messages of support on social media DMs. We&#039;re just thrilled about how many drivers these messages are going to reach. They&#039;ll be up for 4 weeks, and are expected to hit over 1,000,000 drivers during that 4-week campaign period. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;  &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;THOMAS: Are there other ways that Mayday Health has seen surveillance systems impact people seeking healthcare? &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;RAISNER: You know, we go all over the country and talk to folks who are seeking reproductive healthcare options in states where clinics are banned, and we direct folks to our website where they can learn more about abortion pills. We make privacy very central to how we operate. Privacy is not just an afterthought for us. When people arrive at our website, we direct them to the &lt;/span&gt;&lt;a href=&quot;https://digitaldefensefund.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Digital Defense Fund&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, which offers people privacy and security resources as they&#039;re navigating reproductive healthcare in states where they might be being surveilled. We don&#039;t &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/do-not-track&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;collect cookies&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, we don&#039;t collect identifying information from visitors to our site. We want people to know their options, and we don&#039;t have any interest in knowing who they are. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;THOMAS: Why do you think the work of the digital rights movement is so important to the work of the reproductive health rights and justice movement? &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;RAISNER: I mean, those two movements are inextricably linked. The anti-abortion movement is using every tool in their toolbox to prevent people from getting the healthcare access they need, whether that&#039;s surveilling people online or closing down brick&lt;/span&gt;&lt;span&gt;-&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;and&lt;/span&gt;&lt;span&gt;-&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;mortar clinics, but we encourage people to visit Mayday Health and learn that they still have options no matter where they live. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;THOMAS: Is there anything else that you would like the readers of our blog to know about Mayday Health? &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;  &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;RAISNER: I&#039;d love for people to know that abortion pills are FDA approved. They&#039;re safe, they&#039;re effective, and they&#039;re available through the mail.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;***&lt;/span&gt;&lt;span data-ccp-props=&quot;2}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;EFF has said it time and time again – &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;surveillance&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/press/releases/dozens-rogue-california-police-agencies-still-sharing-driver-locations-anti-abortion&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;and&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2024/12/location-tracking-tools-endanger-abortion-access-lawmakers-must-act-now&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;reproductive&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/event/eff-livestream-series-reproductive-justice-digital-age&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;freedom&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2024/04/two-years-post-roe-better-understanding-digital-threats&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cannot&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2024/03/location-data-tracks-abortion-clinic-visits-heres-what-know&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;coexist&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Whether the tracking occurs over the internet or through license plate reader systems &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;with over 83,000 cameras,&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; it is an invasion of privacy. Protecting our digital privacy is more critical now than ever. Help EFF fight back against this digital dragnet and protect reproductive freedom for all by making a donation.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 09 Jul 2026 21:12:57 +0000</pubDate>
 <guid isPermaLink="false">112183 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/reproductive-justice">Reproductive Justice</category>
 <dc:creator>Kenyatta Thomas</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/mayday_health_banner.png" alt="Photo of a billboard with a blue background and white text that says &amp;quot;PREGNANT? TEXAS IS TRACKING YOU. LEARN MORE AT MAYDAY.HEALTH&amp;quot;" type="image/png" length="497170" />
  </item>
  <item>
    <title>The House Passed The KIDS Act—The Senate Should Reject It </title>
    <link>https://www.eff.org/deeplinks/2026/07/house-passed-kids-act-senate-should-reject-it</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Last week, the House voted on the &lt;/span&gt;&lt;a href=&quot;https://d1dth6e84htgma.cloudfront.net/H7757_SUS_xml_4b1ac8f00f.pdf&quot;&gt;&lt;span&gt;KIDS Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a disjointed package of legislation that seeks to control Americans’ web browsing and private messaging. The package combines a revised version of the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/kids-online-safety-act-will-make-internet-worse-everyone&quot;&gt;&lt;span&gt;Kids Online Safety Act&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (&lt;/span&gt;&lt;span&gt;KOSA), with several other internet bills, study bills, reporting requirements, and new regulations. Different parts of the bill &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/how-spot-age-verification-mandate#main-content&quot;&gt;&lt;span&gt;pressure&lt;/span&gt;&lt;/a&gt;&lt;span&gt; online services to impose different age-gating schemes, using different standards. EFF &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online&quot;&gt;&lt;span&gt;opposed this bill&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, along with many of our members and supporters.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://act.eff.org/action/tell-congress-don-t-force-age-checks-online&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://act.eff.org/action/tell-congress-don-t-force-age-checks-online&quot;&gt;Tell Congress: no internet age-gates&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The &lt;/span&gt;&lt;a href=&quot;https://www.congress.gov/bill/119th-congress/house-bill/7757/all-actions?overview=closed&amp;amp;q=%7B%22roll-call-vote%22%3A%22all%22%7D&quot;&gt;&lt;span&gt;bill passed&lt;/span&gt;&lt;/a&gt;&lt;span&gt; the House, 267-117. It now heads to the Senate, where its fate remains uncertain. But this fight is not over. Even if you took our earlier action to contact the House, we need you to reach out to your Senators today. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;The KIDS Act Will Lead to Mandatory Age Checks &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Many of the bills in the KIDS Act share the same premise: that children and teenagers should have different experiences online than adults. In practice, that requires websites and apps to determine who is under 18—and who isn’t. That’s where the problems with the KIDS Act start. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF certainly supports giving all users better privacy and safety tools online. But those protections should not, and do not need to, come at the expense of privacy or free expression. Unfortunately, that’s exactly the tradeoff the KIDS Act makes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There is no way to determine a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/age-verification&quot;&gt;&lt;span&gt;user’s age online&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that is both privacy protective and accurate. Some age verification processes may rely on collecting government-issued ID, while others may use biometric scans. Others will use algorithms to guess a user’s age based on facial images or online behavior. But no matter the method, every system demands users hand over sensitive personal information that links their offline identity to their online activity. And then, once that valuable data is collected, it can be leaked, hacked, or misused. In fact, we’ve &lt;a href=&quot;https://www.eff.org/deeplinks/2026/02/discord-voluntarily-pushes-mandatory-age-verification-despite-recent-data-breach&quot;&gt;already seen&lt;/a&gt; &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/06/hack-age-verification-company-shows-privacy-danger-social-media-laws&quot;&gt;&lt;span&gt;several breaches&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of age verification providers.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;The Bill Still Regulates Online Speech&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The revised KOSA language within the KIDS Act still pressures companies to police lawful speech online. Platforms must “establish, implement, maintain, and enforce” policies that address content like gambling or the use of alcohol or cannabis. This encourages platforms to broadly restrict speech on these topics, which could include a teen seeking advice on a parent’s gambling problem or searching for substance abuse recovery resources. When platforms are required to create and enforce content moderation policies that regulators can sue them over, they will often err on the side of deleting speech. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Protect Privacy For Everyone&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;There is a better way to protect young people online. Instead of encouraging a complicated system of age checks, more monitoring, and more restrictions on access to information, Congress could finally pass a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/wp/privacy-first-better-way-address-online-harms&quot;&gt;&lt;span&gt;strong, comprehensive privacy law&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that benefits all users. A great place to start would be to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/03/ban-online-behavioral-advertising&quot;&gt;&lt;span&gt;ban behavioral advertising that tracks us across the web&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—again, for users of all ages. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We urge the Senate to oppose the KIDS Act and instead focus on a strong, bipartisan privacy package for all users. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://act.eff.org/action/tell-congress-don-t-force-age-checks-online&quot;&gt;Take action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;a href=&quot;https://act.eff.org/action/tell-congress-don-t-force-age-checks-online&quot;&gt;Tell the senate to reject the kids act&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 09 Jul 2026 20:58:33 +0000</pubDate>
 <guid isPermaLink="false">112186 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>India McKinney</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverification-banner2-3a.png" alt="two kids on a huge laptop, spied on by an eye in magnifying glass" type="image/png" length="1249014" />
  </item>
  <item>
    <title>European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates </title>
    <link>https://www.eff.org/deeplinks/2026/07/european-commission-chooses-keep-eu-users-locked-behind-big-techs-gates</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has so many benefits that solve those issues. &lt;/span&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;Say you’re on multiple platforms because you have friends you follow on different networks, but you’ve decided to choose one platform with better privacy practices. With interoperability, you could switch and still interact with friends who remain on larger platforms. It could also enable independent apps with better privacy controls and more user choice. These are the untapped possibilities that could benefit users in the European Union under the 2022 Digital Markets Act (&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/adoption-dsadma-notre-analyse#main-content&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;DMA&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;). &lt;/span&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;Yet, the European Commission, in its &lt;/span&gt;&lt;a href=&quot;https://digital-markets-act.ec.europa.eu/system/files/2026-04/DMA%20Review%20Report_COM_2026_178_1_EN.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;first review&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; of the DMA, announced in April it had decided not to extend the DMA’s interoperability mandate to social networking and didn’t give a deadline or a timeline for enforcing that part of the Act. The Commission said &lt;/span&gt;&lt;a href=&quot;https://ec.europa.eu/commission/presscorner/detail/en/ip_26_914&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;“there is no clear demand”&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; from users and businesses for social networking interoperability and, in any case, it’s too technically complex at the moment. Meanwhile, the Big Tech platforms that have been slow-walking interoperability over the last two years, erecting a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/05/big-tech-eu-drop-dead&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;myriad of hurdles&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; for users seeking more freedom to choose other platforms, get a pass.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;This is a huge disappointment and a missed opportunity by the Commission. Interoperability dismantles one of the biggest barriers faced by users who want to leave the tech giants’ platforms: the choice between changing to a platform you prefer or staying behind on a platform where all your friends, communities, and customers are.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;The DMA, which went into force in 2024, aims to foster more choices for European Union users and encourage competition and innovation by forcing so-called &lt;/span&gt;&lt;a href=&quot;https://digital-markets-act.ec.europa.eu/gatekeepers-portal_en&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;gatekeeper&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; platforms like Meta, Apple, and Google, to open their ecosystems to competitors. The regulation does a great deal to foster the integration of competing services and devices with the ecosystems of very large online platforms that act as gatekeepers. It even requires interoperability for messaging services, despite the significant technical and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/04/eu-digital-markets-acts-interoperability-rule-addresses-important-need-raises&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;privacy challenges involved&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;So, it’s odd that the Commission is using complexity as a shield against taking on social networking interoperability. The internet already runs on complex interoperable systems. Approaches like &lt;/span&gt;&lt;a href=&quot;https://activitypub.rocks/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;ActivityPub&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, the decentralized networking protocol behind the “&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/11/fediverse-could-be-awesome-if-we-dont-screw-it&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Fediverse&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;,” which gave rise to decentralize&lt;/span&gt;&lt;span&gt;d&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt; networks like Mastodon, already exist. The DMA shouldn’t mandate a specific protocol, but it can require meaningful interoperability outcomes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;The argument that there’s no real demand for social networking interoperability also falls flat. Users want the ability to move across platforms, choose the content they’d like to see from platforms, and not be tied down to a single platform. But there’s no way to get there—the platforms are doing little to open their social networking ecosystems. And now you have the DMA’s enforcer saying it’s not going to make them change. Demand for alternatives won’t materialize at scale until users see real progress towards interoperability, something the Commission has the power to do.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;Having decided there’s little demand and too much complexity to proceed with mandating social networking interoperability, the &lt;/span&gt;&lt;span&gt;C&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;ommission said it “will continue to monitor and assess how these services evolve.” This wait-and-see-posture only hurts users and strengthens and further entrenches Big Tech incumbents.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;The DMA is supposed to center on the rights of technology users and be the pathway to an internet experience where you decide which software runs on your devices, where it’s easy to find the best products and services, and where you can leave a platform for a better one without forfeiting your social relationships.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;Meanwhile, Big Tech is also resisting the DMA’s openness requirements. For example, Apple is supposed to be opening up iOS devices to rival app stores. Yet, the smartphone giant’s plan for opening its App Store levies junk fees and onerous conditions on app makers and is effectively &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/10/eu-apple-let-users-choose-their-software-apple-nah&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;impossible for &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;any&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;none&quot;&gt; competitor to use&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;It’s not just Apple pushing back against DMA enforcement. Meta&#039;s response is a “pay for privacy “system, in which users who do not consent to Meta’s surveillance will have to pay to use the service, or be blocked from it. Whether their &lt;/span&gt;&lt;a href=&quot;https://about.fb.com/news/2024/11/facebook-and-instagram-to-offer-subscription-for-no-ads-in-europe/?utm_source=chatgpt.com&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;plan&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; complies with the DMA remains under review.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;Nowhere in the DMA does it say social networking companies get to install a toll booth for users seeking to benefit from privacy rights the regulation grants them. The future EU Digital Fairness Act is another &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/dos-and-donts-eus-digital-fairness-act-effs-recommendation-regulating-digital&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;opportunity&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to protect users from such practices by declaring them unfair.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt;The Commission has responded to these developments with &lt;/span&gt;&lt;a href=&quot;https://open-web-advocacy.org/blog/eu-opens-dma-investigations/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;investigations&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://thenextweb.com/news/eu-google-dma-fine-search-self-preferencing&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;preliminary rulings&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.lawsociety.ie/gazette/top-stories/2025/april/eu-imposes-first-fines-for-dma-breaches/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;fines&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Meanwhile, users are missing out on greater choice and flexibility in how they communicate and connect online. &lt;/span&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;[1,1,1,1,1,1,1,1,1,1,1,1]}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 09 Jul 2026 18:30:12 +0000</pubDate>
 <guid isPermaLink="false">112187 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/international">International</category>
 <category domain="https://www.eff.org/issues/eu-policy">EU Policy</category>
 <category domain="https://www.eff.org/issues/eff-europe">European Union</category>
 <category domain="https://www.eff.org/issues/social-networks">Social Networks</category>
 <dc:creator>Karen Gullo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/eu-flag-11.png" alt="EU-flag-circuits" type="image/png" length="48177" />
  </item>
  <item>
    <title>Google&#039;s New Remote Attestation Scheme is As Bad As Its Old One </title>
    <link>https://www.eff.org/deeplinks/2026/07/googles-new-remote-attestation-scheme-every-bit-terrible-its-old-remote</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Google owes its existence to the open web, but today, its technological “innovations” have much to do with locking users into a “walled garden.” The latest of these is “&lt;/span&gt;&lt;a href=&quot;https://support.google.com/recaptcha/answer/16609652&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;reCAPTCHA Mobile Verification&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;,” an experimental initiative that will let companies block users if they are running independent, &quot;de-googled&quot; versions of Android. These “indie Android” versions are favored by people who want to protect their privacy and their attention by blocking trackers and ads. Worse, this is just the latest in a line of similarly user-hostile measures.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Long before “agentic AI,” we had the idea that software would act as your agent on the internet. That&#039;s why the old-fashioned technical term for a browser is a “user agent.” Your browser acts on your behalf to retrieve information and then show it to you, in the format you choose. &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2013/10/lowering-your-standards&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;It&#039;s your agent&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This is a powerful and profound idea. It is because browsers are our “agents” that we expect them to accept our directives, say, by blocking pop-ups, or by turning off autoplay sound, or by &lt;/span&gt;&lt;a href=&quot;https://privacybadger.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;blocking commercial surveillance trackers&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Your browser does all that because your browser works for &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;you&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. The reason your browser &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;can&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; work for you is that the web is an open, standardized technology. In theory, anyone who follows the standards published by the World Wide Web Consortium (W3C) can make a browser, and that web browser can connect to &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;any&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; web server. Browsers and servers are &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;interoperable&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. It&#039;s the same force that means you can put anyone&#039;s gas in your gas-tank, or anyone&#039;s shoelaces in your shoes, or anyone&#039;s milk on your cereal.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;But what if manufacturers could dictate those choices to you? What if your light socket refused to use a lightbulb unless it was officially blessed by the socket&#039;s manufacturer? What if your dishwasher refused to wash your dishes unless you bought them from one of the manufacturer&#039;s “dish partners?” &lt;/span&gt;&lt;a href=&quot;https://arstechnica.com/gaming/2020/01/unauthorized-bread-a-near-future-tale-of-refugees-and-sinister-iot-appliances/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;What if your toaster refused to toast “unauthorized bread?”&lt;/span&gt;&lt;/a&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;It&#039;s hard to see how a company could win its market with this strategy. After all, if the dishes are really better than the competition&#039;s, you&#039;d buy them voluntarily, without any need for law or technology to force the matter. The only reason to make a dishwasher that refuses a rival&#039;s dishes is if the manufacturer&#039;s own dishes are ugly, expensive, and/or badly made.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;But once a company owns the market&lt;span&gt;—&lt;/span&gt;once they&#039;ve achieved dominance by buying out their rivals; by bribing potential competitors to stay out of their lane; and by engaging in deceptive conduct to trap key suppliers and customers&lt;span&gt;—&lt;/span&gt;they can cement their dominance by blocking interoperability, keeping out rival dishes, milk, gas, lightbulbs, shoelaces and bread, capturing their whole market and &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;squeezing&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; it.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Once a company owns the market, they can cement their dominance by blocking interoperability.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;That&#039;s what Google has done, and that&#039;s what Google wants to do more of Google&#039;s commercial behavior has been so unethical, deceptive and abusive that the company &lt;/span&gt;&lt;a href=&quot;https://www.bigtechontrial.com/p/google-loses-the-adtech-monopolization&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;just lost &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;three&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;none&quot;&gt; federal antitrust cases&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. This thrice-convicted monopolist &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/how-do-you-solve-problem-google-search-courts-must-enable-competition-while&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;paid Apple&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;&lt;span&gt;—&lt;/span&gt;&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;more than $20b/year&lt;span&gt;—&lt;/span&gt; to stay out of the search market: It &lt;/span&gt;&lt;a href=&quot;https://www.thebignewsletter.com/p/boom-google-loses-antitrust-case&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cheated app vendors&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, ripping them off with sky-high junk fees and onerous conditions that raised prices while lowering the share of your spending that went to the companies whose products you were paying for. It&lt;/span&gt;&lt;a href=&quot;https://www.justice.gov/opa/pr/department-justice-prevails-landmark-antitrust-case-against-google&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt; cheated advertisers&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, rigging the ad market to gouge businesses on ad prices and underinvesting to fight rampant ad-fraud, sucking hundreds of billions out of the productive economy for overpriced ads that no one saw.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Google wasn&#039;t always this way. The “don&#039;t be evil” company owes its very existence to the open web ecosystem. When the company started to index the web in 1998, it was playing on an open field, where any web server could talk to any “user agent,” even one whose user was a startup like Google, that was making a copy of every page on the server.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For years, Google thrived on the open web, and built open technologies. Android&lt;span&gt;—&lt;/span&gt;the mobile operating system that Google bought in 2005 &lt;span&gt;—&lt;/span&gt;was presented as an “open” alternative to existing mobile offerings, and as the mobile market collapsed into two companies&lt;span&gt;—&lt;/span&gt;Google and Apple&lt;span&gt;—&lt;/span&gt;Google always presented Android as the open alternative to Apple&#039;s “walled garden.” But there were always ways in which Google&#039;s “open” Android wasn&#039;t &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;exactly&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; open. &lt;/span&gt;&lt;a href=&quot;https://ec.europa.eu/commission/presscorner/detail/en/ip_18_4581&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;The company engaged in illegal “tying” arrangements&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that forced hardware vendors and carriers to lock out versions of Android that were created by Google&#039;s competitors.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In other words, even though Google offered a mobile platform that was (mostly) &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;technically&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; open, it found other ways to try to choke off the market oxygen for alternative Android versions that tried to capitalize on that technical openness.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;But life finds a way. The existence of an open, modifiable, tinkerer-friendly mobile operating system meant Android hackers could create alternatives to Google&#039;s (de facto) walled garden, which thrived in the cracks in that garden wall. Operating systems like &lt;/span&gt;&lt;a href=&quot;https://calyxos.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;CalyxOS&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://pureos.net/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;PureOS&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://grapheneos.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Graphene&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; offered a more private, more secure Android experience, one that was largely “de-Googled,” blocking Google&#039;s relentless acquisition of your private data.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;And Google&#039;s data-hunger is &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;relentless&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Android exfiltrates a chunk of your personal and behavioral data &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;every five minutes&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. &lt;/span&gt;&lt;a href=&quot;https://digitalcontentnext.org/blog/2018/08/21/google-data-collection-research/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;The “resting heartbeat” of Android surveillance pulses and pulses&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, irrespective of whether you&#039;re using your device, and the instant you unlock your screen, that heartbeat quickens, sending even more data to the company. All that data has proven irresistible to authoritarian governments. Donald Trump&#039;s enforcers have seized on Google data as a vital source of information about the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/google-broke-its-promise-me-now-ice-has-my-data&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;identity of protesters and the location of migrants hunted by ICE&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;So there are plenty of reasons why users would seek out these de-Googled alternatives to Android, finding them in spite of Google&#039;s efforts to block access to competing technologies. The worse it got, the better those alternatives looked.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Perhaps this explains Google&#039;s years-long effort to increase the &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;technical&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; barriers to using modified versions of Android, beefing these up to match the commercial restrictions that stand in the way of a de-Googled existence.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Back in 2023, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/08/your-computer-should-say-what-you-tell-it-say-1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Google floated the idea of “Web Environment Integrity” (WEI)&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, a set of modifications to web standards that would force your computer to disclose its operating environment to the web servers it connected to, &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;even if you objected to this disclosure.&lt;/span&gt;&lt;/i&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;WEI was a form of “remote attestation.” That&#039;s when your device uses a sub-processor (sometimes called a “Technical Protection Module” or “TPM”) or a walled off part of its main processor (sometimes called a “secure enclave”) to produce a cryptographically signed description of your device and its configuration: which hardware, software, plug-ins, and settings you&#039;re running.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Take away our ability to block obnoxious digital content and you &lt;i&gt;guarantee&lt;/i&gt; that we will be flooded with it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;When you connect to a server, it demands that your device send this “attestation” before it handles your request. If your device won&#039;t provide this data, or if the server doesn&#039;t like (or recognize) your device and its details, it can refuse to deal with you. And because the attestation is prepared by a TPM or a secure enclave that you can&#039;t modify or override, you don&#039;t get to decide which facts about your device it&#039;s allowed to see.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Practically speaking, this means that remote attestation lets a server refuse to deal with you until you turn off your ad-blocker and your tracker-blocker. It means that the server can discriminate against users who block auto-play sound and video, who block pop-ups, who put the tab in the background when it&#039;s playing a mandatory pre-roll ad.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;WEI was especially disturbing in light of Google&#039;s plan to kill ad-blockers and privacy blockers through updates to Chrome, &lt;/span&gt;&lt;a href=&quot;https://protonprivacy.substack.com/p/google-is-finally-killing-ublock&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;an effort that continues to this day&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;These blockers are an important part of the dynamic between web publishers and their users. In the real world, when you get an offer, you can make a &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;counter-offer&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. That&#039;s all an ad-blocker is: a way for users to respond to a server whose opening bid is, “How about you give me all your data and let me take over your computer in exchange for showing you this page?” with &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/07/adblocking-how-about-nah&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;“How about &#039;Nah?&#039;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;We didn&#039;t get rid of pop-up ads by making them illegal, or by boycotting advertisers who used them. We got rid of pop-up ads when web users installed pop-up blockers, which made pop-up ads pointless. Take away our ability to block obnoxious digital content and you &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;guarantee&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that we will be flooded with it.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;These kinds of modifications aren&#039;t just used to block ads&lt;span&gt;—&lt;/span&gt;they&#039;re also key to accessibility. People who have photosensitive epilepsy or suffer from low-contrast vision problems use add-ons to reformat pages so they can safely and legibly access them.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;WEI&#039;s creators said they were only trying to put the web on a level playing field with apps, which routinely disclose facts about your device to the companies whose servers you connect to, without asking you, and even if you don’t want them to. Apps are a source of bottomless enshittification, not least because (unlike the web), they enjoy special, dangerous legal protections that make it &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;very&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; legally risky to modify them. WEI wasn&#039;t an effort to level the playing field between apps and the web&lt;span&gt;—&lt;/span&gt;it was &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;a race to the bottom&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, an attempt to make the web as enshittification-friendly as apps.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Public outrage to WEI killed the project, but Google&#039;s commitment to augmenting its illegal commercial lockdown efforts with &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;technical&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; lockdowns never ended. Now, &lt;/span&gt;&lt;a href=&quot;https://support.google.com/recaptcha/answer/16609652&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Google has rolled out an experimental “reCAPTCHA Mobile Verification”&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that uses an app, your camera, and your device&#039;s TPM or secure enclave to produce an attestation about your Android device.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.reddit.com/r/PrivacySecurityOSINT/comments/1tbdjbj/privacy_concerns_around_googles_recaptcha_mobile/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;This will make it much easier&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; for the apps and other services you interact with to block your device if you run an Android alternative, or if you install a mod that overrides the actions of Google&#039;s stock Android.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This is a terrible idea&lt;span&gt;—&lt;/span&gt;it&#039;s every bit as bad as WEI was. In an age in which Big Tech is ever-more tied to authoritarian governments, redesigning our devices to tell strangers things we don&#039;t want them to know isn&#039;t just shortsighted, it&#039;s inexcusable.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 09 Jul 2026 09:15:49 +0000</pubDate>
 <guid isPermaLink="false">112182 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/competition">Competition</category>
 <category domain="https://www.eff.org/issues/trusted-computing">Trusted Computing</category>
 <category domain="https://www.eff.org/issues/drm">DRM</category>
 <category domain="https://www.eff.org/issues/big-tech">Big Tech</category>
 <dc:creator>Cory Doctorow</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/mobile-privacy-knight-2_0.png" alt="" type="image/png" length="46254" />
  </item>
  <item>
    <title>Automated Moderation Is Here to Stay</title>
    <link>https://www.eff.org/deeplinks/2026/07/part-1-automated-moderation-here-stay</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;em&gt;This blog post is part 1 of a 2-part series. The &lt;a href=&quot;https://eff.org/deeplinks/2026/07/part-2-automated-moderation-here-stay-accountability-must-keep-pace&quot;&gt;second part&lt;/a&gt; sets out recommendations for companies and policymakers.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Six years ago—one month into a global pandemic—we &lt;a href=&quot;https://www.eff.org/deeplinks/2020/04/automated-moderation-must-be-temporary-transparent-and-easily-appealable&quot;&gt;argued&lt;/a&gt; that the automated moderation processes many platforms were rapidly adopting should be highly transparent, easily appealable, and temporary. We warned that &quot;protocols adopted in times of crisis often persist when the crisis is over.&quot;&lt;/p&gt;
&lt;p&gt;That warning proved prescient. The use of automation and artificial intelligence (AI) to identify, flag, and moderate content has become the new norm—a permanent feature of how platforms govern speech online. In this two part series, we’re take stock of this new norm, and considering what platforms can and should do to ensure that AI serves online expression rather than stifling it.&lt;/p&gt;
&lt;h3&gt;A brief history of automated content moderation&lt;/h3&gt;
&lt;p&gt;From spam filtering and keyword blacklists to the hash-matching technologies used to identify child sexual abuse material and terrorist content, automated technologies have been used in commercial content moderation for many years. While these tools have long posed risks to freedom of expression, their use was, for quite some time, relatively limited in scope.&lt;/p&gt;
&lt;p&gt;Then, in 2017, a &lt;a href=&quot;https://about.fb.com/news/2017/06/how-we-counter-terrorism/&quot;&gt;blog post&lt;/a&gt; published by Facebook (now Meta) described the company&#039;s &quot;fairly recent&quot; use of artificial intelligence to identify, classify, and remove violent extremist content. At the same time, Facebook emphasized caution, noting that it did not want to suggest there was &quot;any easy technical fix.&quot;&lt;/p&gt;
&lt;p&gt;Just one year later, Mark Zuckerberg appeared before the U.S. Senate&#039;s Commerce and Judiciary Committees and &lt;a href=&quot;https://www.washingtonpost.com/news/the-switch/wp/2018/04/10/transcript-of-mark-zuckerbergs-senate-hearing/&quot;&gt;disclosed&lt;/a&gt; that &quot;99 percent of the ISIS and Al Qaida content&quot; removed by Facebook was flagged by AI &quot;before any human sees it.&quot; He also stated that Facebook was &quot;developing A.I. tools that can identify certain classes of bad activity proactively and flag it for our team at Facebook.&quot; At the time, we &lt;a href=&quot;https://www.eff.org/deeplinks/2018/04/despite-what-zuckerbergs-testimony-may-imply-ai-cannot-save-us&quot;&gt;raised concerns&lt;/a&gt; about the ethical implications of using AI in this manner.&lt;/p&gt;
&lt;p&gt;Then came 2020. The sudden &lt;a href=&quot;https://www.washingtonpost.com/technology/2020/03/23/facebook-moderators-coronavirus/&quot;&gt;reduction of the human moderation workforce&lt;/a&gt;, combined with a dramatic increase in social media use—and with it, a surge in misinformation—created the perfect conditions for platforms to expand their reliance on AI-driven moderation. It &lt;a href=&quot;https://www.eff.org/deeplinks/2020/10/facebooks-most-recent-transparency-report-demonstrates-pitfalls-automated-content&quot;&gt;quickly became apparent&lt;/a&gt; that companies&#039;—and particularly Meta&#039;s—approach to moderation during the pandemic represented a backslide in transparency, freedom of expression, and access to remedy. The increased reliance on automation was a significant factor.&lt;/p&gt;
&lt;h3&gt;The costs and benefits of AI content moderation&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2020/04/automated-moderation-must-be-temporary-transparent-and-easily-appealable&quot;&gt;We knew in 2020&lt;/a&gt; that the use of AI to moderate content would present problems for online freedom of expression. Today, those problems are well-documented. A 2025 &lt;a href=&quot;https://www.ohchr.org/sites/default/files/documents/issues/expression/statements/2025-10-24-joint-declaration-artificial-intelligence.pdf&quot;&gt;joint declaration&lt;/a&gt; by special rapporteurs and representatives of the United Nations (UN), Organization for Security and Co-operation in Europe (OSCE), Organization of American States (OAS), and African Commission on Human and Peoples’ Rights (ACHPR) states:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;“The use of AI content moderation can lead to over-removal, discrimination and censorship. Reliance on inherently biased datasets and opaque training processes can amplify pre-existing inequalities, risking homogenisation of expression, and erasure of linguistic and cultural diversity.”&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;EFF and many of our allies have documented these impacts. For example, our &lt;a href=&quot;https://www.eff.org/files/2019/05/30/caught_in_the_net_whitepaper_2019.pdf&quot;&gt;2019 paper &lt;/a&gt;co-authored with Witness and Syrian Archive examined the impact of extremist content regulations—and their implementation through automation and AI—on human rights documentation. A 2020 report from &lt;a href=&quot;https://www.hrw.org/report/2020/09/10/video-unavailable/social-media-platforms-remove-evidence-war-crimes&quot;&gt;Human Rights Watch&lt;/a&gt; highlighted the consequences of these removals, noting: &quot;There is no way of knowing how much potential evidence of serious crimes is disappearing without anyone&#039;s knowledge.&quot;&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;http://cdt.org/insights/content-moderation-in-the-global-south-a-comparative-study-of-four-low-resource-languages/&quot;&gt;Center for Democracy and Technology&#039;s recent series&lt;/a&gt; on content moderation in the Global South demonstrates persistent inequities in content moderation of four “low-resource” languages—so-called because the relative scarcity of training data makes it more difficult to develop equitable and accurate AI models for them. &lt;/p&gt;
&lt;p&gt;Content moderation often disproportionately impacts vulnerable and historically marginalized groups, and AI content moderation is no different. &lt;a href=&quot;https://glaad.org/2026-ai-report-build-for-everyone/lgbtq-impacts/&quot;&gt;GLAAD&lt;/a&gt; recognizes the role AI plays in scaling content moderation but notes that “when moderation systems lack nuance, transparency, and human oversight, they can fail to curb harassment and wrongly suppress legitimate LGBTQ content.”&lt;/p&gt;
&lt;p&gt;These failures are not incidental. They are a predictable consequence of deploying automated systems to make complex judgments about language, culture, context, and identity at scale.&lt;/p&gt;
&lt;p&gt;All of that said, automated content moderation can offer important benefits. The primary one: helping to spare human content moderators who must review content that varies from whimsical to horrific, often for little pay and with devastating mental health consequences. Outsourcing this work to the bots can offer some relief—though it’s worth noting that the humans hired to train the AI models face a similar dynamic.&lt;/p&gt;
&lt;p&gt;In addition, AI models could &lt;em&gt;potentially&lt;/em&gt; be trained over time to be more precise, accurate, and dynamic, helping to mitigate over-censorship and disinformation. The jury is still out on whether this potential will be realized; what we do know is that new approaches to the persistent problem of over and under-enforcement are desperately needed.&lt;/p&gt;
&lt;h3&gt;Automated moderation is no longer an experiment&lt;/h3&gt;
&lt;p&gt;Getting the balance between real costs and potential benefits depends a lot on the details: how automated systems are designed, trained, implemented, and audited.  &lt;/p&gt;
&lt;p&gt;Despite advances in the sophistication and scale of automated moderation systems, many of the transparency, accountability, and due process safeguards advocated by civil society, researchers, and human rights experts have yet to be fully realized. At the same time, automated systems have become increasingly central to how platforms enforce their rules and govern online speech.&lt;/p&gt;
&lt;p&gt;The question today is not whether companies will use AI to moderate content, but under what conditions they should do so. And now as ever, the answer is not that the public should just trust that platforms’ deployment of increasingly powerful systems will serve, rather than inhibit online expression. In fact, as automated systems become more sophisticated and more deeply embedded in platform governance, the need for transparency and accountability becomes more urgent. &lt;/p&gt;
&lt;p&gt;&lt;em&gt;This is part 1 of a 2-part series. You can read the second part &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/part-2-automated-moderation-here-stay-accountability-must-keep-pace&quot;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 07 Jul 2026 16:21:36 +0000</pubDate>
 <guid isPermaLink="false">112180 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/corporate-speech-controls">Corporate Speech Controls</category>
 <dc:creator>Jillian C. York</dc:creator>
 <dc:creator>Corynne McSherry</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/social-media-2026-2.gif" alt="" type="image/gif" length="3467306" />
  </item>
  <item>
    <title>Help EFF Cut the AI Hype</title>
    <link>https://www.eff.org/deeplinks/2026/07/help-eff-cut-ai-hype</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;In the global race to build and dominate the AI industry, it can sure seem like the interests of ordinary people sit last on the agenda. It&#039;s just the opposite for EFF. While companies furiously jam AI tools into their veins and your eyeballs, EFF’s technologists, activists, and attorneys have been meticulously cutting through the hype to ensure AI can serve your privacy and free expression. Technology has leaned into a new era, and this summer you can help EFF fight for the people.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/s26--d1&quot;&gt;JOIN EFF&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Over the next two weeks, we’re encouraging you to support the cause as &lt;a href=&quot;https://supporters.eff.org/donate/s26--d1&quot;&gt;an EFF member for as little as $10 each month&lt;/a&gt;. You can get great member swag every year like our privacy puffy stickers, Claw Back t-shirt, and Privacy Badger Crewneck.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/s26--d1&quot;&gt;&lt;img src=&quot;/files/2026/07/01/claw_f_crewb.jpg&quot; width=&quot;1667&quot; height=&quot;1200&quot; alt=&quot;A person wears an EFF Claw Back member t-shirt on the left. A person on the right wears a black sweatshirt with the Privacy Badger mascot on the chest.&quot; title=&quot;Get new EFF gear when you join!&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;caption-text&quot;&gt;Fight mass surveillance! Pictured: Claw Back member t-shirt and Privacy Badger Crewneck.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;AI tools—beyond their marketing fluff—demonstrate both incredible potential and real danger. With the support of members around the world, &lt;a href=&quot;https://eff.org/ai&quot;&gt;EFF detangles the possibilities&lt;/a&gt; from the anxieties and threats with the care and nuance it deserves. In recent months, EFF:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/congress-narrowed-guard-act-serious-problems-remain&quot;&gt;Mobilized people against the GUARD Act&lt;/a&gt;, which would require problematic age verifications systems for AI companions.&lt;/li&gt;
&lt;li&gt;Joined civil society partners to call out a General Services Administration proposal that &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/tech-nonprofits-feds-dont-weaponize-procurement-undermine-ai-trust-and-safety&quot;&gt;would make AI tools less safe and less useful&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Sued for answers under the Freedom of Information Act to uncover &lt;a href=&quot;https://www.eff.org/press/releases/eff-sues-answers-about-medicares-ai-experiment&quot;&gt;how the government is using AI to evaluate requests for medical care&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/eff-testifies-congress-protecting-americans-rights-government-ai&quot;&gt;Testified before the U.S. Congress&lt;/a&gt; Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The scope of AI, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/02/smart-ai-policy-means-understanding-its-real-harms-and-benefits&quot;&gt;both the good and the bad&lt;/a&gt;, multiplies every day. If we want the AI-powered benefits of efficiency, scientific discovery, and greater accessibility to knowledge, then we also need strong protections against surveillance, harms to creativity and innovation online, perpetuating systemic bias, and privacy violations now.&lt;/p&gt;
&lt;p&gt;With AI taking over the public consciousness, you can be assured that EFF will never stop advocating for you. Together, we can ensure that technology supports freedom, justice, and innovation for all people.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/s26--d1&quot;&gt;Join EFF&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;____________________&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW4268908 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW4268908 BCX0&quot;&gt;EFF is a member-supported U.S. 501(c)(3) organization. &lt;/span&gt;&lt;span class=&quot;NormalTextRun CommentStart CommentHighlightPipeRest CommentHighlightRest SCXW4268908 BCX0&quot;&gt;We&#039;ve&lt;/span&gt;&lt;span class=&quot;NormalTextRun CommentHighlightRest SCXW4268908 BCX0&quot;&gt; received top rati&lt;/span&gt;&lt;span class=&quot;NormalTextRun CommentHighlightRest SCXW4268908 BCX0&quot;&gt;ngs &lt;/span&gt;&lt;span class=&quot;NormalTextRun CommentHighlightRest SCXW4268908 BCX0&quot;&gt;from the nonprofit watchdog Charity Navigator since 2013!&lt;/span&gt;&lt;span class=&quot;NormalTextRun CommentHighlightPipeRest SCXW4268908 BCX0&quot;&gt; Your donation is tax-deductible as allowed by law.&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 07 Jul 2026 16:17:38 +0000</pubDate>
 <guid isPermaLink="false">112177 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <dc:creator>Aaron Jue</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/icon-2026-ai-robot-v2.png" alt="A human face with a bright cog inside and a colorful background" type="image/png" length="17646" />
  </item>
  </channel>
</rss>
