<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.eff.org/rss/updates.xml" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Deeplinks</title>
    <link>https://www.eff.org/rss/updates.xml</link>
    <description>EFF&#039;s Deeplinks Blog: Noteworthy news from around the internet</description>
    <language>en</language>
     <atom:link href="https://www.eff.org/rss/updates.xml" rel="self" type="application/rss+xml" />
      <item>
    <title>Site-Blocking Will Not Defend IP, No Matter the Bill’s Name </title>
    <link>https://www.eff.org/deeplinks/2026/10/site-blocking-will-not-defend-ip-no-matter-bills-name</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;There has been a raft of site-blocking bills in the latest Congress, and the latest is called the “Deterring Extraterritorial Foreign Exploitation of Networks Damaging Intellectual Property” aka the “&lt;/span&gt;&lt;a href=&quot;https://www.congress.gov/bill/119th-congress/house-bill/10575?hl=defend+ip&amp;amp;s=1&amp;amp;r=1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;DEFEND IP Act&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.” The problem is that instead of “defending IP,” this bill will incentivize censorship, overblocking, and bad faith attempts to block access to a website. DEFEND IP Act, and all of these site-blocking proposals, threaten the open web.&lt;/span&gt;&lt;span data-ccp-props=&quot;200}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;We keep seeing attempts to pass site-blocking legislation–from SOPA/PIPA in 2012 to &lt;/span&gt;&lt;a href=&quot;https://www.tillis.senate.gov/services/files/24A0311C-E658-4440-A259-AA8A876115E6&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Block BEARD&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.congress.gov/bill/119th-congress/house-bill/791&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;FADPA&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/10/congress-has-another-site-blocking-bill-and-one-targets-vpns&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;ACPA&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; this year. Every one of them has at its core the rotten idea that enforcing copyrights requires building a censorship machine for websites into the architecture of the internet. This is, of course, a disaster for a free and open web. There is no way to create a mechanism for blocking access to an entire website that does not invite both deliberate abuse and lots of collateral harm to free and lawful speech. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;DEFEND IP deputizes every service provider into a copyright cop, so long as a rightsholder has accused a website of copyright infringement. Let’s be clear: this isn’t about removing access to an infringing work–that already exists via the DMCA. This isn’t about getting damages from the website or the uploader. It is about making an entire website inaccessible for everyone trying to visit it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;DEFEND IP lets any rightsholder go to a court and get an order requiring service providers to block access to an entire website after alleging copyright infringement. What DEFEND IP does not have is any deterrent for someone seeking to block a website in bad faith. There are no punishments for getting a website blocked for protected speech. There are no meaningful remedies for those whose speech is vanished from the internet due to an entire website being disappeared. It creates a one-stop shop for getting an entire website–again, not an instance of infringement but an entire site hosting all sorts of user content–removed. But for those whose business, speech, or access to information is affected, there is no easy way to get the site restored.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;DEFEND IP scales up the extraordinary legal structures that already exist for copyright enforcement. In doing so, it likewise scales up the problems those regimes pose to protected speech.&lt;/span&gt;&lt;span data-ccp-props=&quot;200}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;We see this with DMCA takedowns all the time. We see it with bad faith &lt;a href=&quot;https://www.eff.org/takedowns&quot;&gt;takedowns&lt;/a&gt; used to silence criticism or commentary. We see it with the voluntary use of copyright filters by sites like YouTube, where seconds of sound matching seconds of sound in another video can prevent an entire work from reaching its audience. In these existing systems, there are at least some mechanisms of challenge available to the targeted creator. DEFEND IP has none. Instead, site owners, users, or readers will have to find a lawyer and go to court and hope to challenge the order, a slow, expensive, and daunting process&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Those existing systems are already frustrating for the targeted creators and users, but under DEFEND IP a whole class of people doing protected speech will find themselves deplatformed because of the actions of others&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This bill is not a defense of creativity or creators. It is a way to reshape the internet by building a vast new infrastructure of censorship. Congress should put aside DEFEND IP and the failed idea of site-blocking laws, for good.&lt;/span&gt;&lt;span data-ccp-props=&quot;200}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 02 Oct 2026 18:59:23 +0000</pubDate>
 <guid isPermaLink="false">112423 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <category domain="https://www.eff.org/issues/copyright-trolls">Copyright Trolls</category>
 <dc:creator>Katharine Trendacosta</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/og-copyrightbot-alt1_1_0.png" alt="" type="image/png" length="195622" />
  </item>
  <item>
    <title>Congress Has Another Site-Blocking Bill, And This One Targets VPNs</title>
    <link>https://www.eff.org/deeplinks/2026/10/congress-has-another-site-blocking-bill-and-one-targets-vpns</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Congress is taking another run at site-blocking, a deeply flawed concept that would undermine basic internet infrastructure. Rep. Darrell Issa (R-CA) has introduced the American Copyright Protection Act (ACPA), &lt;/span&gt;&lt;a href=&quot;https://www.congress.gov/bill/119th-congress/house-bill/10364/text?s=1&amp;amp;r=1&quot;&gt;&lt;span&gt;H.R. 10364&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a bill that would give copyright owners a new legal tool to block Americans’ access to foreign websites accused of copyright infringement. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The basic idea is &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/01/more-decade-later-site-blocking-still-censorship&quot;&gt;&lt;span&gt;all too&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/congress-reviving-site-blocking-and-its-just-dangerous-ever&quot;&gt;&lt;span&gt;familiar&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and it’s still dangerous. A copyright owner first asks a court to label a foreign website a “foreign piracy site.” Once that happens, the copyright owner could seek orders requiring internet service providers, DNS providers, and—new and explicit in this bill—VPN providers to take “commercially reasonable steps” to stop their users in the United States from accessing those sites. The decision to label a website as a “foreign piracy site” can happen without the accused site even showing up in court to defend itself. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;ACPA Goes Further Than Other Site-Blocking Proposals &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;In some ways, the ACPA is even worse than a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/congress-reviving-site-blocking-and-its-just-dangerous-ever&quot;&gt;&lt;span&gt;site-blocking legislation introduced last year&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the&lt;/span&gt; &lt;a href=&quot;https://lofgren.house.gov/media/press-releases/rep-lofgren-introduces-targeted-legislation-combat-foreign-online-piracy&quot;&gt;&lt;span&gt;Foreign Anti-Digital Piracy Act (FADPA)&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which EFF also opposed. That bill at least excluded companies that provide only VPN services, as well as providers that offer DNS resolution exclusively through encrypted DNS protocols. The ACPA drops those protections. In fact, the bill explicitly includes VPNs among the service providers that can be ordered to block access to a website. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The bill also broadens the definition of a “piracy site.” Last year’s &lt;/span&gt;&lt;a href=&quot;https://lofgren.house.gov/sites/evo-subsites/lofgren.house.gov/files/evo-media-document/1.29.25%20-%20Foreign%20Anti-Digital%20Piracy%20Act_Full%20Text_0.pdf&quot;&gt;&lt;span&gt;site blocking bill&lt;/span&gt;&lt;/a&gt;&lt;span&gt; covered sites with “no commercially significant purpose or use” other than infringement. ACPA changes that to sites with “only limited commercially significant purpose or use” beyond infringement. In other words, under ACPA, even a website with legitimate commerce going on could still be labeled a “foreign piracy site” and ultimately blocked for all Americans. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Better Process Still Doesn’t Fix The Problem &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The ACPA includes some procedural protections, such as requiring service providers that could be subject to a blocking order to receive legal notice and an opportunity to respond. The bill also requires courts to consider the potential harm to other websites and internet users before ordering intermediaries to block websites. It further requires the copyright owner to post a bond, in an amount determined by the court, sufficient to cover the costs and damages incurred by any service provider found to have been wrongfully enjoined. The bill also provides a mechanism for operators or users of third-party online services affected by erroneous blocking to seek compensation after the fact in certain circumstances.&lt;/span&gt; &lt;span&gt;Finally, a site operator can ask a court to rescind its designation as a “foreign piracy site.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;These safeguards are significant and positive changes, but they don’t solve the basic, and severe, due process problem. The initial decision to label a website a “foreign piracy site” can still be made without the site operator appearing to defend itself. The court can appoint a “special master,” which is an independent expert who helps the judge evaluate evidence, to review the copyright owner’s case—but that step is not required. In any case, a special master  is not a lawyer who actually represents the accused website, nor the users whose access to information and speech may be affected. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We know what site-blocking looks like when it’s put into practice. Supporters of site-blocking like to point to its use in other countries. But what we’re seeing in other countries is serious collateral damage to lawful websites. In Italy, &lt;/span&gt;&lt;a href=&quot;https://recreatecoalition.org/infographic/site-blocking-poses-a-massive-threat-to-americas-open-internet/&quot;&gt;&lt;span&gt;510 benign, non-streaming websites&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, including a Catholic convent and a telehealth platform, were blocked by the country’s “Piracy Shield” program. In Spain, &lt;/span&gt;&lt;a href=&quot;https://recreatecoalition.org/infographic/site-blocking-poses-a-massive-threat-to-americas-open-internet/&quot;&gt;&lt;span&gt;a site-blocking system blocked more than 550,000 domains&lt;/span&gt;&lt;/a&gt;&lt;span&gt; during soccer broadcasts, including sites belonging to Greenpeace and Harvard University.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Congress Should Reject Site-Blocking Proposals&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;More than a decade ago, Congress abandoned SOPA and PIPA after internet users pushed back against site-blocking and other threats to the open internet. We shouldn&#039;t start building that infrastructure now.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;ACPA adds some safeguards, but those don’t fundamentally change what Congress is being asked to create: a system for blocking Americans’ access to entire websites at the request of copyright owners. By explicitly bringing VPNs into that system, the bill also reaches into basic tools that people use to access the internet safely and privately. Adding somewhat better procedures to a bad idea doesn’t turn it into a good idea. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 02 Oct 2026 17:41:08 +0000</pubDate>
 <guid isPermaLink="false">112422 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <category domain="https://www.eff.org/issues/copyright-trolls">Copyright Trolls</category>
 <category domain="https://www.eff.org/issues/intellectual-property">Fair Use</category>
 <dc:creator>Joe Mullin</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/copyright-orange_0.png" alt="Copyright Symbol" type="image/png" length="31474" />
  </item>
  <item>
    <title>Victory! Court Rejects Government Effort to Dismiss Social Media Surveillance Lawsuit</title>
    <link>https://www.eff.org/press/releases/victory-court-rejects-government-effort-dismiss-social-media-surveillance-lawsuit</link>
    <description>&lt;div class=&quot;field field--name-field-pr-subhead field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Judge Allows Social Media Surveillance Lawsuit Against Trump Administration to Move Forward&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;NEW YORK — A lawsuit filed by three labor unions against the Departments of State and Homeland Security for their viewpoint-based surveillance and suppression of protected expression online can move forward, a federal judge ruled yesterday.&lt;/p&gt;
&lt;p&gt;On October 1, 2026, Judge Alvin K. Hellerstein of the U.S. District Court for the Southern District of New York rejected the government’s motion to dismiss the lawsuit. &lt;a href=&quot;https://www.eff.org/cases/united-auto-workers-v-us-department-state&quot;&gt;The case was filed in October 2025&lt;/a&gt; on behalf of the United Automobile Workers (UAW), Communications Workers of America (CWA), and American Federation of Teachers (AFT). The Electronic Frontier Foundation (EFF), Muslim Advocates (MA), and the Media Freedom &amp;amp; Information Access Clinic (MFIA) represent the labor unions.&lt;/p&gt;
&lt;p&gt;This decision is a victory: The Court held that claims that the government’s social media surveillance program is harming the unions’ members, as well as hampering the ability of the unions to associate with their members and potential members, can move forward.&lt;/p&gt;
&lt;p&gt;The Court ruled that: &quot;This threat of adverse immigration consequences, under a government whose harsh immigration crackdowns has been heavily publicized and reported on, is certainly enough to &#039;deter a person of ordinary firmness from the exercise of First Amendment rights.&#039; It is objectively reasonable that noncitizens would limit their expression of disfavored viewpoints under the [Challenged Surveillance Program] given the credible threat of adverse immigration action from the Government.&quot;&lt;/p&gt;
&lt;p&gt;&quot;The freedom of Plaintiffs&#039; members to speak, associate, and appear publicly is not incidental to union work, but rather is the mechanism through which unions recruit, organize, communicate, and bargain,&quot; the Court further explained. &quot;A program alleged to silence members and drive them from the unions&#039; rolls therefore strikes at the unions&#039; representational function itself, which is the &#039;grounds that bring [their] membership together.&#039;&quot;&lt;/p&gt;
&lt;p&gt;Since taking power, the Trump administration has created a mass surveillance program to monitor constitutionally protected speech by noncitizens lawfully present in the U.S. Using AI and other automated technologies, the program surveils the social media accounts of visa and green card holders with the goal of identifying and punishing those who express viewpoints the government disfavors. The surveillance program has been paired with a public intimidation campaign—silencing not just noncitizens with immigration status, but also the families, coworkers, and friends with whom their lives are integrated.&lt;/p&gt;
&lt;p&gt;In October 2025, UAW, CWA, and AFT sued the Departments of State and Homeland Security, alleging that this viewpoint-based surveillance program violates the First Amendment and the Administrative Procedure Act.&lt;/p&gt;
&lt;p&gt;&quot;No one should have to fear government surveillance or retaliation against their immigration status for expressing their views or participating in their union. We&#039;re pleased the Court has allowed this challenge to move forward and will continue fighting to protect the rights of everyone to speak, organize, and advocate without fear,&quot; said &lt;strong&gt;UAW President Shawn Fain&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&quot;This is a victory for working people, for the labor movement, and for our democracy,&quot; said &lt;strong&gt;CWA President Claude Cummings Jr&lt;/strong&gt;. &quot;Our very freedom is under attack by the Trump administration&#039;s online surveillance program, and today&#039;s decision is a critical first step toward affirming our freedom to speak, to protest, to organize without fear of government retaliation. These essential freedoms underpin our union rights to join together and fight to improve our working conditions. CWA is a fighting union, and our members remain ready to stand together to protect our rights and our freedoms.&quot;&lt;/p&gt;
&lt;p&gt;&quot;Today’s decision is a critical step toward vindicating our Constitutional right to freedom of speech and rejecting the Trump Administration’s cynical attempts to criminalize and punish those who disagree with them,&quot; said &lt;strong&gt;AFT President Randi Weingarten&lt;/strong&gt;. &quot;Government surveillance to monitor the &#039;opposition&#039; is a tool of dictators that erodes the democratic principles this country was founded on. We will continue to remain vigilant in defending our 250-year-old rights—not just for our members, but for all Americans.&quot;&lt;/p&gt;
&lt;p&gt;&quot;Our plaintiff-unions have members that have wholly changed the way they interact with social media—including limiting their engagement with union content—because of the government&#039;s social media surveillance program,&quot; said &lt;strong&gt;EFF Senior Staff Attorney Lisa Femia&lt;/strong&gt;. &quot;Many have stopped posting online together, and have even stopped engaging in offline activities, for fear of being scrutinized or targeted related to immigration benefits. We are pleased that the Court has agreed to let the case proceed, and allow unions and their members to seek justice for infringement of their rights.&quot;&lt;/p&gt;
&lt;p&gt;&quot;Today’s ruling is an important step forward in holding the government accountable for its ever-expansive online surveillance program that silenced non-citizens, stoking fear that exercise of their protected First Amendment rights could result in unfavorable treatment on their immigration applications or worse.&quot; said &lt;strong&gt;Sadaf Hasan, Staff Attorney at Muslim Advocates&lt;/strong&gt;. &quot;We will keep fighting until all non-citizens are able to freely associate, organize, and speak out without the looming threat of visa revocation and immigration enforcement simply because the government dislikes their views.&quot;&lt;/p&gt;
&lt;p&gt;&quot;Defendants&#039; attempt to evade accountability on specious jurisdictional grounds was rightly rejected by the Court,&quot; said &lt;strong&gt;Nick Jones&lt;/strong&gt;, a student in the &lt;strong&gt;Media Freedom &amp;amp; Information Access Clinic&lt;/strong&gt;. &quot;We are excited to see the case now proceed to the merits, where we expect to prevail as well.”&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For the ruling: &lt;/strong&gt;&lt;a href=&quot;https://www.eff.org/document/uaw-v-dos-opinion-order-denying-motion-dismiss&quot;&gt;https://www.eff.org/document/uaw-v-dos-opinion-order-denying-motion-dismiss&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For more about the litigation: &lt;/strong&gt;&lt;a href=&quot;https://eff.org/cases/united-auto-workers-v-us-department-state&quot;&gt;https://eff.org/cases/united-auto-workers-v-us-department-state&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Contacts:&lt;/strong&gt;&lt;br /&gt;Electronic Frontier Foundation: &lt;a href=&quot;mailto:press@eff.org&quot;&gt;press@eff.org&lt;/a&gt;&lt;br /&gt;Muslim Advocates: &lt;a href=&quot;mailto:melissa@muslimadvocates.org&quot;&gt;melissa@muslimadvocates.org&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 02 Oct 2026 15:54:42 +0000</pubDate>
 <guid isPermaLink="false">112421 at https://www.eff.org</guid>
 <dc:creator>Hudson Hongo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/social-media-surveillance-2026.jpg" alt="Security camera screens display logos for Facebook, YouTube, X, TikTok, and Reddit " type="image/jpeg" length="142559" />
  </item>
  <item>
    <title>Ola Bini Ordered to Leave Ecuador Under Obscure Accusations</title>
    <link>https://www.eff.org/deeplinks/2026/10/ola-bini-ordered-leave-ecuador-under-obscure-accusations</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;In a new blow to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/six-years-dangerous-misconceptions-targeting-ola-bini-and-digital-rights-ecuador&quot;&gt;&lt;span&gt;Ola Bini’s&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; legal guarantees, Ecuadorean authorities retained the free software developer and security expert yesterday in Quito and ordered his immediate deportation from the country. He is barred from returning to Ecuador for 10 years.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;According to &lt;/span&gt;&lt;a href=&quot;https://x.com/calilo84/status/2105759848210248146&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;information released&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; by his lawyer, Bini was intercepted by a car with four people who identified themselves as immigration agents. He was then taken to an immigration office without further information or a formal order from a competent authority. There, officials told Bini that his visa had been revoked but didn’t show any supporting document. &lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Bini&#039;s defense &lt;/span&gt;&lt;a href=&quot;https://x.com/MinutoJusticia/status/2105783319019258264&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;filed&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; a &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;habeas corpus&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;none&quot;&gt; to safeguard his freedom and prevent his deportation. Yet, Ecuadorian authorities affirmed that the developer represents a threat or risk to public security and the state structure, and must leave the country. The ground for deportation is &lt;/span&gt;&lt;a href=&quot;https://x.com/ecuainm_oficial/status/2105805585929130311&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;a secret report&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; which allegedly asserts that Bini committed acts against the security of Ecuador. The defense could not access its contents. &lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The deportation hearing started yesterday at 5pm Quito time. Human rights organizations tried to attend the hearing but were &lt;/span&gt;&lt;a href=&quot;https://x.com/DDHH_Alianza/status/2105790314237628874&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;denied entry&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. The hearing was suspended but later reconvened establishing his immediate deportation. Ola Bini was relocated to Quito&#039;s airport and must stay there until he flies back to Sweden.&lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The case that led to Bini&#039;s &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/six-years-dangerous-misconceptions-targeting-ola-bini-and-digital-rights-ecuador&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;unfounded criminal conviction&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; has expired (the statute of limitations ran out) and the court had already formally lifted all precautionary measures against him&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;. Yesterday&#039;s e&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;vents open a new chapter in the nefarious persecution of Ola Bini by Ecuadorean authorities. &lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Since Bini’s arbitrary arrest in 2019, EFF &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/tags/ola-bini&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;has reported&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; about his criminal prosecution fraught with misconceptions and rights violations. The script of what happened yesterday follows the same patterns we saw in the entire case, from its outset with unjustified allegations that Bini was a national security risk. The Observation Mission of Ola Bini’s case, joined by EFF and other digital and human rights organizations, has published &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/05/eff-and-other-civil-society-organizations-issue-report-danger-digital-rights-what&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;reports&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/11/observation-mission-stresses-key-elements-ola-binis-case-upholding-digital-rights&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;raised international awarenness&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; about the perils of this case to the protection of rights online and the beneficial work of security experts. &lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;In a case surrounded by &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/08/ecuador-political-actors-must-step-away-ola-binis-case&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;political interests&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, Ola Bini’s &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/03/aftermath-ola-binis-unanimous-acquittal-ecuadorian-court&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;unanimous acquittal&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; by the lower court in 2023 was overturned after the prosecution’s appeal. The majority of the appeals court convicted Bini&lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt; &lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt;for&lt;/span&gt; &lt;span data-contrast=&quot;none&quot;&gt;attempted unauthorized access of a telecommunications system without &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/08/telnet-not-crime-unconvincing-prosecution-screenshot-leaked-ola-bini-case&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;actual evidence&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; to corroborate the accusation claims. &lt;/span&gt;&lt;span data-ccp-props=&quot;276}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Now, once again we must sound the alarm.&lt;/span&gt; &lt;span&gt;Ecuadorean authorities must explain&lt;/span&gt;&lt;span&gt; the accusations against the sec&lt;/span&gt;&lt;span&gt;urity expert&lt;/span&gt;&lt;span&gt;. We will remain vigilant &lt;/span&gt;&lt;span&gt;and&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;ensure that at least this time his &lt;/span&gt;&lt;span&gt;rights are respected.&lt;/span&gt; &lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 02 Oct 2026 13:34:01 +0000</pubDate>
 <guid isPermaLink="false">112420 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/international">International</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/coders">Coders&#039; Rights Project</category>
 <dc:creator>Veridiana Alimonti</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/offline-general.png" alt="Offline General" type="image/png" length="18239" />
  </item>
  <item>
    <title>We Demand More Information on How Marin Cops Illegally Shared Flock ALPR Data </title>
    <link>https://www.eff.org/deeplinks/2026/10/we-demand-more-information-how-marin-cops-illegally-shared-flock-alpr-data</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;The Marin County Sheriff’s Office is the latest California law enforcement agency to get caught sharing automated license plate reader (ALPR) data from their Flock Safety system with out-of-state and federal agencies. EFF and the ACLU of Northern California are calling them out for this direct violation of California law, which has put every driver in the county at risk and is especially dangerous for immigrants, abortion seekers, and other targets of the federal government.&lt;/p&gt;
&lt;p&gt;Today, we sent the Marin County Sheriff’s Office (MCSO) a demand letter and request for records under the California Public Records Act following the &lt;a href=&quot;https://www.ptreyeslight.com/news/marins-flock-data-breached/&quot;&gt;Point Reyes Light’s recent report&lt;/a&gt; that MCSO provided non-California agencies access to its ALPR database. This directly violates California law and the terms of the 2022 &lt;a href=&quot;https://www.eff.org/document/lagleva-v-doyle-settlment-agreement&quot;&gt;Settlement Agreement&lt;/a&gt; in our case &lt;a href=&quot;https://www.eff.org/cases/lagleva-v-marin&quot;&gt;&lt;em&gt;Lagleva v. Marin County Sheriff&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/pages/automated-license-plate-readers-alpr&quot;&gt;ALPRs&lt;/a&gt; are cameras that capture images of vehicles and upload their location to a searchable, shareable database. They are a mass surveillance technology that collects data indiscriminately on every vehicle on the road.&lt;/p&gt;
&lt;p&gt;Sharing ALPR data with out-of-state or federal agencies—for &lt;em&gt;any&lt;/em&gt; reason—violates California law (&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&amp;amp;division=3.&amp;amp;title=1.81.23.&amp;amp;part=4.&amp;amp;chapter=&amp;amp;article&quot;&gt;SB 34&lt;/a&gt;). If this data is shared for the purpose of assisting with immigration enforcement, agencies violate an additional California law (&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billCompareClient.xhtml?bill_id=201720180SB54&quot;&gt;SB 54&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;But network audit logs obtained by Point Reyes Light show that during the final months of 2024, &lt;span&gt;Marin County Sheriff’s Office&lt;/span&gt; shared ALPR data with multiple out-of-state and federal agencies, including &lt;em&gt;254,131 times in November 2024 alone&lt;/em&gt;. Many of these searches were conducted by law enforcement in states that impose severe restrictions on reproductive care and have a history of assisting ICE, including Alabama, Indiana, Kentucky, Florida, and Texas.&lt;/p&gt;
&lt;p&gt;This sharing violated state law and “exposed sensitive driver location information to misuse by the federal government and by states that lack California’s robust privacy protections,” the letter explains.&lt;/p&gt;
&lt;p&gt;This is not the first time MCSO has shared Marin County ALPR information with federal and out-of-state agencies in violation of California law.&lt;/p&gt;
&lt;p&gt;Back in 2021, on behalf of community activists, EFF and ACLU sued the Marin County Sheriff for illegally sharing millions of local drivers’ license plate numbers and location data with hundreds of federal and out-of-state agencies, including ICE and Border Patrol.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/press/releases/community-activists-reach-settlement-marin-county-sheriff-unlawfully-sharing-drivers&quot;&gt;The parties eventually reached a settlement&lt;/a&gt;, under which the Sheriff agreed to stop sharing license plate and location information with agencies outside of California to comply with state laws SB 34 and SB 54.&lt;/p&gt;
&lt;p&gt;“MCSO’s November 2024 audit report shows that your office has violated not only SB 34, but the terms of the &lt;em&gt;Lagleva&lt;/em&gt; Settlement Agreement as well,” the letter explains.&lt;/p&gt;
&lt;p&gt;EFF and ACLU are urging MCSO to launch a thorough audit of its ALPR database, institute new protocols for compliance, and assess penalties for any employee found to be sharing ALPR information out of state.&lt;/p&gt;
&lt;p&gt;“While your office claims that it took deliberate steps to disable nationwide data-access capabilities and ensure your system operated within strict privacy safeguards, you have not explained how outside agencies nonetheless obtained access, how you plan to prevent future violations of SB 34 and the &lt;em&gt;Lagleva&lt;/em&gt; Settlement Agreement, or why you did not take steps to inform the public and the Marin County Inspector General once you learned about the breach,” the letter explains.&lt;/p&gt;
&lt;p&gt;As we’ve demonstrated &lt;a href=&quot;https://www.eff.org/press/releases/civil-liberties-groups-demand-california-police-stop-sharing-drivers-location-data&quot;&gt;over&lt;/a&gt; and &lt;a href=&quot;https://www.eff.org/press/releases/dozens-rogue-california-police-agencies-still-sharing-driver-locations-anti-abortion&quot;&gt;over&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/cases/lagleva-v-marin&quot;&gt;again&lt;/a&gt;, many California agencies continue to ignore these laws, exposing sensitive location information to misuse and putting entire communities at risk. As federal agencies continue to carry out violent ICE raids, and many states enforce harsh, draconian restrictions on abortion, ALPR technology is already being used to target and surveil &lt;a href=&quot;https://calmatters.org/economy/technology/2025/06/california-police-sharing-license-plate-reader-data/&quot;&gt;immigrants&lt;/a&gt; and &lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down&quot;&gt;abortion seekers&lt;/a&gt;. These incidents have made it clear that having ALPR programs &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/effs-policy-position-alpr-surveillance-eliminate-it-and-reduce-its-harms&quot;&gt;are incompatible&lt;/a&gt; with the protection of residents. California agencies, including Marin County Sheriff’s Office, have an obligation to protect the rights of Californians, even when those rights are not recognized by other states or the federal government. &lt;/p&gt;
&lt;p&gt;See the full letter here: &lt;a href=&quot;https://www.eff.org/document/20261001-letter-aclu-norcal-and-eff-marin-sheriff&quot;&gt;https://www.eff.org/document/20261001-letter-aclu-norcal-and-eff-marin-sheriff&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 01 Oct 2026 21:59:08 +0000</pubDate>
 <guid isPermaLink="false">112418 at https://www.eff.org</guid>
 <dc:creator>Jennifer Pinsof</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ice-alpr-5.jpg" alt="ICE and CBP agents use ALPR surveillance on a car" type="image/jpeg" length="159758" />
  </item>
  <item>
    <title>Challengers Approach: Third Party App Stores Arrive to Google Play </title>
    <link>https://www.eff.org/deeplinks/2026/10/challengers-approach-third-party-app-stores-arrive-google-play</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;If you are an Android user, you may have noticed it already: Google has begun allowing rival, third-party app stores to be distributed through the Google Play Store. And if you are a developer, you may have noticed new options for billing and distributing your apps. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/cases/epic-games-v-google&quot;&gt;&lt;span&gt;years,&lt;/span&gt;&lt;/a&gt;&lt;span&gt; Epic Games, maker of games such as Fortnite, has been suing Google, alleging violations of antitrust law. Specifically at issue were Google&#039;s restrictions on the distribution of alternate app stores through the Play Store, restrictions on app developers who have little practical choice but to distribute their apps through the Play Store, and Google’s rules governing in-app payments and the fees associated with them. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Epic’s challenge ultimately resulted in a court order requiring significant changes to Google’s practices. Among other changes, rival, third-party Android app stores are now allowed to access the Play Store’s catalog and to be distributed through the Google Play Store. Developers also have greater freedom to direct users to alternative payment and distribution options.   &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;These changes give users and developers more choices and create new opportunities for competition in the Android ecosystem, breaking the power Google once had over many facets of the app ecosystem. This is a win for competition and antitrust enforcement. But the benefits can extend beyond competition itself—more meaningful choice can also create opportunities for greater freedom of online expression, privacy, and security. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;With alternate app stores able to compete for Android users, Google no longer has the first and last say on what apps can reach users and on what terms. Developers have more options for reaching their audiences, rather than having a single company’s rules determine the terms of access. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;More importantly, Android users are no longer trapped in an arrangement of &lt;/span&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2012/12/feudal_sec.html&quot;&gt;&lt;span&gt;feudal security &lt;/span&gt;&lt;/a&gt;&lt;span&gt;with Google, where users must depend on the goodwill of a monopolist to protect them and guarantee their safety. If Google does not adequately protect their data or security, Android users can now switch to a competitor that does a better job. And if that competitor fails them, they can choose another. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Competition in the app store market therefore means competition not only over which apps are offered, the user experience, and developer fees, but also over privacy and security. Users and developers gain something fundamental in the process: the ability to choose. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As we’ve&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/why-ftc-v-meta-trial-matters-competition-gaps-and-civil-liberties-opportunities&quot;&gt;&lt;span&gt; previously written&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, antitrust has never been just about prices—&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/08/party-its-1979-og-antitrust-back-baby&quot;&gt;&lt;span&gt;it’s also about power&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. It is about who gets to control and shape the future of the internet. A world in which a handful of dominant platforms can dictate how users access apps or programs, how developers reach them, and what rules govern those interactions is one in which users have fewer meaningful choices. Without Epic’s successful antitrust challenge and the changes that followed, users would have remained in a world of &lt;/span&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2012/12/feudal_sec.html&quot;&gt;&lt;span&gt;feudal security&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, where they would have been left begging their feudal tech lord for more. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The arrival of competitor app stores on Google Play does not solve every problem with the Android ecosystem. But it opens the door to something that dominant platforms have spent years trying to keep out: meaningful competition. And each new competitor gives users another opportunity to choose something better. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-related-cases field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Related Cases:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;/cases/epic-games-v-google&quot;&gt;Epic Games v. Google&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 01 Oct 2026 21:25:19 +0000</pubDate>
 <guid isPermaLink="false">112417 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/competition">Competition</category>
 <dc:creator>Chao Liu</dc:creator>
 <dc:creator>Betty Gedlu</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/competition_robot.png" alt="A large robot hand steals a tool from an alarmed person" type="image/png" length="207242" />
  </item>
  <item>
    <title>Court Agrees with EFF: Utah’s VPN Law Demands a Technical Impossibility</title>
    <link>https://www.eff.org/deeplinks/2026/10/court-agrees-eff-utahs-vpn-law-demands-technical-impossibility</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;When state lawmakers attempt to rewrite how the internet works, users rely on courts to recognize that laws can’t make technical impossibilities a reality. That’s why we were happy to see that a court has blocked Utah’s attempt to outlaw the privacy protections of Virtual Private Networks (VPNs).&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In a win for digital rights, a federal judge has &lt;/span&gt;&lt;a href=&quot;https://www.courthousenews.com/wp-content/uploads/2026/09/aylo-freesites-utah-division-consumer-protection-opinion.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;issued a preliminary injunction&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; blocking Utah’s SB 73, the state’s draconian &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;anti-VPN age verification law&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. The decision comes as EFF &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-response-utah-department-commerce-notice-proposed-rulemaking-r152-78b&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;submitted our comments&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to the Utah Department of Commerce, detailing how forcing platforms to detect and block privacy-preserving tools undermines user privacy and security worldwide while demanding the impossible. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;What SB 73 Does&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Signed &lt;/span&gt;&lt;a href=&quot;https://governor.utah.gov/news-advisory/gov-cox-signs-74-bills-in-the-2026-general-legislative-session/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;into law earlier this year&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, SB 73 attempted to regulate adult websites by requiring them to block VPN users or to identify the physical location of visitors using them or similar tools that mask their network traffic. It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks. This made Utah, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Utah federal court &lt;/span&gt;&lt;a href=&quot;https://www.yahoo.com/news/politics/articles/utah-federal-judge-blocks-vpn-152715799.html&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;halted enforcement&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; of the law&#039;s VPN provisions last week, &lt;/span&gt;&lt;a href=&quot;https://www.courthousenews.com/wp-content/uploads/2026/09/aylo-freesites-utah-division-consumer-protection-opinion.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;r&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;uling that the law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah. The law’s “actual-location provision in practice requires an entity to perform age verification services for every user visiting its site from any location because the entity would violate the law if even one of those users happened to be obfuscating,” the court wrote. The court essentially ruled that Utah has less-burdensome ways to prevent Utah minors from accessing adult websites than requiring all users in the world to comply with SB 73.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Aylo’s lawsuit does not challenge SB 73’s provision prohibiting the websites covered by the law from sharing information about VPNs.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Legal Challenge&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This court order follows months of legal maneuvering. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Initially set to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;go into effect in May 2026&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, SB 73 sparked an &lt;/span&gt;&lt;a href=&quot;https://utahnewsdispatch.com/wp-content/uploads/2026/09/Porhub-lawsuit-complaint.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;immediate constitutional challenge from Aylo&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, the parent company of major online adult platforms like Pornhub. In response to the lawsuit, Utah and Aylo &lt;/span&gt;&lt;a href=&quot;https://www.newsfromthestates.com/article/utah-wont-enforce-new-vpn-rules-pornhubs-parent-company-litigation-continues&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;initially agreed&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that the state would pause enforcement while the court considered the preliminary injunction request &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;or &lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;until administrative rules setting specific compliance terms were finalized. Those proposed compliance rules (R152-78B, see &lt;/span&gt;&lt;a href=&quot;https://rules.utah.gov/wp-content/uploads/b20260901.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Utah State Bulletin, page 6&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;) were published by the Utah Department of Commerce’s Division of Consumer Protection on September 1&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;st&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and EFF &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-response-utah-department-commerce-notice-proposed-rulemaking-r152-78b&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;submitted formal comments&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to the Department in opposition. According to the notice, the proposed rules could be effective as soon as October 8, 2026. However, Judge Barlow’s decision means that it cannot be enforced pending further action by the court.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Ruling&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;EFF welcomes Judge Barlow’s ruling, which recognizes the fundamental disconnect between state legislation of the internet and how technology works. In his ruling, Judge Barlow noted that the statute requires a technical impossibility on pain of legal liability. “Aylo is correct that the statute, as amended, now essentially imposes strict liability for entities like it when it comes to determining the location of its websites’ users.”&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The court recognized that the problem is that SB 73 “requires entities like Aylo to geolocate its website users with perfection to avoid liability.” But, at the same time, the court acknowledged “that geolocation perfection is not presently possible.”&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;EFF explained this technical impossibility in &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-response-utah-department-commerce-notice-proposed-rulemaking-r152-78b&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;our comment to the Department of Commerce.&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; VPNs protect user privacy by routing web traffic through intermediary servers. Because destination websites only see the IP address of the VPN server, they have no reliable mechanism to tell whether a connection originates from Salt Lake City, Seattle, or Shanghai. So, under Utah&#039;s current statutory framework, platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely. Judge Barlow agreed, asserting: &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Because the law requires perfection in the absence of perfect geolocation tools, Aylo would need to verify those 28 million users—whether located in Salt Lake City, Boston, New Orleans, Anchorage, or Honolulu—to ensure compliance and avoid liability.&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Rulemaking&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The administrative rules drafted by the state compelled commercial entities to implement &quot;commercially reasonable geolocation obfuscation detection systems&quot;, which is a directive, we argue, that demands a technical impossibility. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In our submission to the Utah Department of Commerce, EFF also detailed how these rules force an invasive data collection regime onto internet users everywhere. So, in response to internet users trying to avoid invasive data collection required by age-verification requirements, SB 73 requires even greater surveillance of internet users’ online activities. The Department’s suggested detection heuristics (like monitoring connection latency or device time zones) are notoriously unreliable and easily skewed by normal network conditions. This active surveillance inevitably leads to widespread misclassification, unwarranted access blocks, and severe impacts on users’ privacy far beyond Utah&#039;s borders. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;You can read EFF’s full comments to the Department of Commerce &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-response-utah-department-commerce-notice-proposed-rulemaking-r152-78b&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;span data-contrast=&quot;auto&quot;&gt;What Now?&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h2&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;As we’ve said &lt;a href=&quot;https://www.eff.org/pages/vpns-are-not-solution-age-gating-mandates&quot;&gt;time&lt;/a&gt; and &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/lawmakers-want-ban-vpns-and-they-have-no-idea-what-theyre-doing&quot;&gt;time again&lt;/a&gt;: the internet will always route around censorship. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Mandating invasive tracking and punishing the use of essential security tools turns genuine privacy concerns into mere compliance theater and requires more state-mandated surveillance of internet users who rely on VPNs. As is the case in heavily censored regions, VPN services and obfuscation tools will simply adapt, making this framework fundamentally unsustainable. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;As we’ve said &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/vpns-are-not-solution-age-gating-mandates&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;time&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/lawmakers-want-ban-vpns-and-they-have-no-idea-what-theyre-doing&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;time again&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;: the internet will always route around censorship.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;While Utah legislators &lt;/span&gt;&lt;a href=&quot;https://www.ksl.com/article/51628735/judge-temporarily-blocks-utahs-new-age-verification-law-in-pornhub-lawsuit&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;have indicated&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; they may attempt to revise the law during the next legislative session, the court&#039;s preliminary injunction sets an important precedent: state lawmakers should not weaponize age verification to force dragnet tracking or undermine essential security tools. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;As other states consider similar anti-VPN proposals, EFF will continue pushing back against these technically impossible mandates and defending users’ privacy and anonymity. Thus, we urge legislators and regulators to reject anti-privacy rules, prioritize real user security, and safeguard constitutional protections for all users.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 01 Oct 2026 19:57:20 +0000</pubDate>
 <guid isPermaLink="false">112416 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/cyber-security-legislation">Cyber Security Legislation</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/vpn-highway-tunnel-banner.jpg" alt="A highway sign shows the upcoming turns for different IP addresses, as cars pass a circuit tree lined road and drive into a tunnel." type="image/jpeg" length="284672" />
  </item>
  <item>
    <title>Happy Opt Out October! Let’s Find Real Alternatives to the Tech Giants</title>
    <link>https://www.eff.org/deeplinks/2026/10/happy-opt-out-october-lets-find-real-alternatives-tech-giants</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Over the years, the major tech companies have found all sorts of ways to embed themselves into our lives. We often use their software, their AI tools, their social media, and their operating systems by default without even thinking about potential alternatives. It’s time to rethink that relationship. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last year, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security#main-content&quot;&gt;&lt;span&gt;we created Opt Out October&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to help remind ourselves of the variety of ways we can take back control of our data through small steps inside apps, operating systems, and other various forms. This year, we highlight the idea that sometimes the best way to control your data is to leave a platform, app, or operating system altogether. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;To do so, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/welcome-opt-out-october-lets-take-control-our-data-and-our-devices&quot;&gt;&lt;span&gt;we’ve created a hub of resources sharing ways&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to find new software that isn’t made by the tech giants, take advantage of the growing universe of new social media options, install a whole new operating system, and better control how various popular tools and software use your data for AI training. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As an incentive, we’ve made merit badges like the one below to help you track your own wins and share them with others. Complete any of these tasks and let the world know by sharing that accomplishment on social media or changing your profile image! Better, more privacy-respecting, and less-enshittified tools are out there. We just have to find and use them.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;center-image&quot;&gt;&lt;span&gt;&lt;img src=&quot;https://www.eff.org/files/2026/09/22/ghost_badge-optout_social_media_controlled.png&quot; width=&quot;401&quot; height=&quot;398&quot; alt=&quot;image of a ghost holding a sign that says &amp;quot;i opted out of social media&amp;quot;&quot; title=&quot;image of a ghost holding a sign that says &amp;quot;i opted out of social media&amp;quot;&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Head over to our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/welcome-opt-out-october-lets-take-control-our-data-and-our-devices&quot;&gt;&lt;span&gt;Opt Out October landing page&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and start taking the first steps to regaining control of the tools and software you use. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 01 Oct 2026 19:27:29 +0000</pubDate>
 <guid isPermaLink="false">112412 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Thorin Klosowski</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/opt_out_ghosties-banner_2026.jpg" alt="ghosts holding opt out signs" type="image/jpeg" length="208202" />
  </item>
  <item>
    <title>Victory! California Appeals Court Refuses to Revive Surveillance Tech CEO’s Meritless Lawsuit Against Journalist</title>
    <link>https://www.eff.org/deeplinks/2026/09/victory-california-appeals-court-refuses-revive-surveillance-tech-ceos-meritless</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;When the rich and powerful try to use the court to silence negative reporting about themselves, it’s worth calling out that behavior for what it is: an attack on free speech. This is why EFF is happy to stand up for reporters who find themselves in that situation.&lt;/p&gt;
&lt;p&gt;The California Court of Appeals &lt;a href=&quot;https://www.eff.org/document/blackman-v-substack-opinion&quot;&gt;upheld&lt;/a&gt; a lower court’s decision to strike a former &lt;a href=&quot;https://jackpoulson.substack.com/p/premise-data-confirms-secret-military?utm_source=publication-search&quot;&gt;Premise Data&lt;/a&gt; CEO’s meritless lawsuit against a journalist who exposed the CEO’s secret arrest for felony domestic violence. Jack Poulson, the writer and publisher of &lt;a href=&quot;https://jackpoulson.substack.com/&quot;&gt;&lt;em&gt;All Source Intelligenc&lt;/em&gt;e&lt;/a&gt;, reported details from the San Francisco Police Department’s report of the arrest and posted a copy of the report after receiving the document from a confidential source. Poulson later learned the arrest record had been sealed. The CEO, Maury Blackman, &lt;a href=&quot;https://www.eff.org/cases/blackman-v-substack-et-al&quot;&gt;sued&lt;/a&gt; Poulson, Substack, AWS, and another organization for damages to try and force the removal of Poulson’s reporting from the internet.&lt;/p&gt;
&lt;p&gt;The trial court &lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/victory-eff-helps-defeat-meritless-lawsuit-against-journalist&quot;&gt;tossed the entire case&lt;/a&gt; under California’s anti-SLAPP statute—SLAPP stands for “strategic lawsuit against public participation” and describes cases where the goal isn’t vindication in court so much as it is costing someone time, money, and peace of mind fighting the lawsuit. To fight SLAPP cases, states like California have passed anti-SLAPP laws, which are invaluable tools for protecting the First Amendment. California’s law provides an avenue for early dismissals of these baseless lawsuits, which curtails their intended effect on the target. Blackman appealed the court’s decision, arguing that a court order sealing the arrest overrides Poulson’s right to report the news.&lt;/p&gt;
&lt;p&gt;The Court of Appeals correctly rejected Blackman’s appeal and affirmed the decision to throw out the case. The court held that the First Amendment protects Poulson’s publications. As the court explained in its decision, “the First Amendment protects the lawfully obtained truthful publication of the information at issue absent ‘a need to further a state interest of the highest order,’” a standard that Blackman’s privacy interests do not satisfy. The Court also found that Poulson, as the publisher of the &lt;em&gt;All Source Intelligence&lt;/em&gt; newsletter, was protected by California’s Shield Law, relying on &lt;a href=&quot;https://www.eff.org/cases/apple-v-does&quot;&gt;precedent established by EFF&lt;/a&gt; in 2006. The Court also affirmed that Substack and the other website, which had merely temporarily hosted a copy of the arrest record, were immunized from liability by Section 230.&lt;/p&gt;
&lt;p&gt;This decision is a win for free speech, for Jack Poulson, and for everybody.  &lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-related-cases field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Related Cases:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;/cases/blackman-v-substack-et-al&quot;&gt;Blackman v. Substack, et al.&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 30 Sep 2026 22:38:05 +0000</pubDate>
 <guid isPermaLink="false">112411 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/cyberslapp">CyberSLAPP</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Tori Noble</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/section-230-2-podcasts.jpg" alt="" type="image/jpeg" length="376596" />
  </item>
  <item>
    <title>📱 Hey Siri, How Do I Limit AI Data Access? | EFFector 38.17</title>
    <link>https://www.eff.org/deeplinks/2026/09/hey-siri-how-do-i-limit-ai-data-access-effector-3817</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;With the launch of iOS 27, Apple is rolling out a variety of new AI features to its familiar voice assistant, Siri. But how are AI tools like these handling our data? In &lt;a href=&quot;https://www.eff.org/effector/38/17&quot;&gt;our latest EFFector newsletter&lt;/a&gt;, we&#039;re talking about &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/how-limit-what-apples-new-siri-ai-can-access-ios-27?utm_source=effector&quot;&gt;the privacy complications&lt;/a&gt; of AI phone features.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.eff.org/effector/&quot;&gt;JOIN OUR NEWSLETTER&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For over 35 years, &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFFector&lt;/a&gt; has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/dc-circuit-must-vacate-drone-flight-restriction-criminalized-recording-immigration?utm_source=effector&quot;&gt;drones and our right to record the law enforcement&lt;/a&gt;, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/cold-take-amazons-new-encryption-method-still-doesnt-deliver-real-privacy?utm_source=effector&quot;&gt;video doorbell footage privacy&lt;/a&gt;, and &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/how-limit-what-apples-new-siri-ai-can-access-ios-27?utm_source=effector&quot;&gt;how to limit what data Apple&#039;s new Siri AI can access&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Prefer to listen in? EFFector is now available on all major podcast platforms. This time we&#039;re asking EFF&#039;s Thorin Klosowski about the difference between AI phone features that are computed on-device and ones that are computed on external servers—and what that means for data protection. You can find the episode and subscribe&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://effector.simplecast.com/&quot;&gt;on your podcast platform of choice&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: 70px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2Ff5abca72-7d82-4e94-9c0b-0d9f991891f0%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/f5abca72-7d82-4e94-9c0b-0d9f991891f0?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/6Q48ICplENdQ4ZarUIgfLZ&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effector/id1882562931&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.com/podcasts/83be1062-f511-47b3-bd2b-fc44e831c3ad&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feeds.eff.org/effector&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Want to protect your right to digital privacy? Sign up for &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFF&#039;s EFFector newsletter&lt;/a&gt; for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you &lt;a href=&quot;https://eff.org/join&quot;&gt;support EFF today&lt;/a&gt;!&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 30 Sep 2026 16:45:11 +0000</pubDate>
 <guid isPermaLink="false">112408 at https://www.eff.org</guid>
 <dc:creator>Hudson Hongo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/effector-green-web.png" alt="" type="image/png" length="78242" />
  </item>
  <item>
    <title>While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards</title>
    <link>https://www.eff.org/deeplinks/2026/09/while-country-rejects-alpr-mass-surveillance-sf-settles-weak-safeguards</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;San Francisco&#039;s &lt;a href=&quot;https://www.sf.gov/news-mayor-daniel-lurie-unveils-strong-privacy-protections-for-public-safety-cameras-building-on-work-to-drive-down-crime-in-san-francisco&quot;&gt;decision to retain its use of Automated License Plate Reader (ALPR) surveillance cameras&lt;/a&gt; belies what we know about this spying technology tool: it endangers residents and threatens the privacy and civil liberties of our community. &lt;/span&gt;Based on what&#039;s in the city&#039;s press release and announcement, this policy will do nothing to stop actual harms.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We know innocent drivers will be stopped and menaced by officers because of &lt;a href=&quot;https://www.eff.org/deeplinks/2024/11/human-toll-alpr-errors&quot;&gt;erroneous matches&lt;/a&gt;. We know officers use Flock to &lt;a href=&quot;https://www.washingtonpost.com/technology/2026/08/02/how-police-officers-used-vast-network-cameras-spy-their-exes/&quot;&gt;stalk potential and past romantic partners&lt;/a&gt;. Data will be &lt;a href=&quot;https://www.404media.co/ice-taps-into-nationwide-ai-enabled-camera-network-data-shows/&quot;&gt;accessed by Immigration and Customs Enforcement (ICE)&lt;/a&gt; and &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/are-your-local-police-using-flock-safety-alprs-scan-immigrants&quot;&gt;used to deport immigrants&lt;/a&gt;. Promising greater penalties for such abuse will not end this. These are not isolated mistakes that another policy can fix. They are consequences of building a system that records everyone’s movements and makes them searchable by police. This is also not unique to a single vendor. From Flock Safety to Motorola to Axon—San Francisco must end its use of ALPRs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We ultimately cannot rely on new protocols from city officials, and the City’s new policy is woefully inadequate. There is no warrant requirement to search stored ALPR data. An incident or computer-aided dispatch (CAD) number is not judicial authorization. Without a warrant requirement, officers can search stored location data without showing probable cause to a judge, and will. Without judicial control, officers will continue to search the data for abusive reasons. But a warrant requirement alone would not justify retaining the ALPR network: the community is demanding an end to the collection itself.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Additionally, the announced policies include no deadline to delete ALPR data, there is only a 30-day deadline to move data from the vendor’s servers to the city’s servers. City officials must understand that moving data is not deleting it. Whether Flock or SFPD stores the data, it remains a permanent record of where people drive, worship, work, organize, seek care, and spend time with others. Thus, the best practice is deletion. New Hampshire requires deletion in three minutes, and Flock itself has reduced the default retention time to seven days. San Francisco can and should do better.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Lastly, while transparency and documentation are important concepts, better audit logs are not the answer. They can expose abuse only after a search has occurred. They cannot undo the disclosure of someone’s movements or justify collecting everyone’s location data in the first place; especially when we are talking about people’s lives and civil liberties. The city&#039;s announced policy does not even require officers to state, in their own words, why they are searching the stored ALPR data—an accountability rule that &lt;a href=&quot;http://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down&quot;&gt;has&lt;/a&gt; &lt;a href=&quot;http://www.eff.org/deeplinks/2026/09/high-crime-lmao-how-cops-are-treating-mass-surveillance-joke&quot;&gt;exposed&lt;/a&gt; &lt;a href=&quot;http://www.eff.org/deeplinks/2025/11/license-plate-surveillance-logs-reveal-racist-policing-against-romani-people&quot;&gt;abusive&lt;/a&gt; &lt;a href=&quot;http://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists&quot;&gt;searches&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/effs-investigations-expose-flock-safetys-surveillance-abuses-2025-review&quot;&gt;across the country&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;San Francisco is behind many communities that have considered the tradeoffs of ALPR surveillance and made the right choice by ending their contracts. San Francisco must do the same.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 29 Sep 2026 21:30:22 +0000</pubDate>
 <guid isPermaLink="false">112405 at https://www.eff.org</guid>
 <dc:creator>Rindala Alajaji</dc:creator>
 <dc:creator>Adam Schwartz</dc:creator>
 <dc:creator>Sarah Hamid</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/flock-vector-2b.png" alt="A flock camera with spying eyes, silhouetted against a dark purple ground." type="image/png" length="10240" />
  </item>
  <item>
    <title>Privacy’s Defenders Podcast: Cowboys, Cypherpunks and Visionaries</title>
    <link>https://www.eff.org/deeplinks/2026/09/privacys-defenders-podcast-cowboys-cypherpunks-and-visionaries</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;People are increasingly concerned about the ways in which mass surveillance is tracking our every move: from Flock license plate readers to face recognition to creepy ads that – based on what we see and do online – seem to know everything we’re thinking and planning. It didn’t have to be this way, and since the early days of the internet, a dedicated band of activists, lawyers and technologists have fought for a better, more secure and private digital future – a future that’s still attainable. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Cindy Cohn, who just finished a 26-year run with the Electronic Frontier Foundation including 11 years as its executive director, has lived this fight. She says privacy isn’t just about secrecy: It&#039;s ultimately about power – who has it, and who has the ability to protect themselves from it.  &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Welcome to the first episode of “Privacy’s Defenders,” a podcast about the people – lawyers, journalists, hackers, and others – who’ve fought to secure your digital liberties since before most people even knew what the internet was.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: -4px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%2252px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F2f955342-7675-4c8c-bb40-fa364d9a569d%3Fdark%3Dtrue%26amp%3Bcolor%3D000000%22%20allow%3D%22autoplay%22%3E%C2%A0%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/2f955342-7675-4c8c-bb40-fa364d9a569d?dark=true&amp;amp;color=000000&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;279}&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/4UAplFpPDqE4hWlwsjplgt&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effs-how-to-fix-the-internet/id1539719568&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.ca/podcasts/bf81f00f-11e1-431f-918d-374ab6ad07cc/how-to-fix-the-internet?ref=dmm_art_us_HTFTI&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://www.eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feeds.eff.org/howtofixtheinternet&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;(You can also find this episode &lt;a href=&quot;https://archive.org/details/privacys-defenders-e-1-fine-cut-v-5&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;on the Internet Archive&lt;/a&gt; and &lt;a href=&quot;https://youtu.be/EWK8MtAowcM?si=1G_wjO74pD-Zlk-n&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;on YouTube&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In this episode, Cindy talks with EFF cofounder &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/about/board/john-gilmore&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;John Gilmore&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; about how he – an early employee at Sun Microsystems – came together with Lotus Development cofounder &lt;/span&gt;&lt;a href=&quot;https://www.kaporcenter.org/team/mitch-kapor/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Mitch Kapor&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; and cattle rancher, philosopher and Grateful Dead lyricist &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/john-perry-barlow&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;John Perry Barlow&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to create EFF as a bulwark against government investigation and prosecution of early internet users. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;It’s a story of the Secret Service’s “Operation Sundevil,” jet-setting tech titans, tie-dyed cypherpunks, and a fateful house party in San Francisco’s Haight-Ashbury district amid the earliest days of online communications, setting the stage for the battles that created the internet as we know it and issues we still grapple with today.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The “Privacy’s Defenders” podcast is a follow-up to Cindy’s book, “Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance,” bringing to life pivotal moments in the voices of those who fought for your rights. Sales of “Privacy’s Defender” benefit EFF, so &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/Privacys-Defender&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;pick up your copy today&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;!&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Joanne Elgart Jennings co-produced and created this podcast. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Jarod Sport co-produced, mixed, and mastered it. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Corinne Ruff is our story editor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;We had additional help from Rachel Estabrook and Alison Broverman.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The original music was composed and performed by Nat Keefe of Hot Buttered Rum with Ben Andrews on the fiddle. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;And other archival sound came from the Internet Archive&#039;s amazing collection, including the snippet of the Grateful Dead song “Cassidy” that John Perry Barlow co-wrote.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 29 Sep 2026 15:00:32 +0000</pubDate>
 <guid isPermaLink="false">112382 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/how-to-fix-the-internet-podcast">How to Fix the Internet: Podcast</category>
 <dc:creator>Josh Richman</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/pd-podcast-banner.png" alt="Privacy&amp;#039;s Defender: Stories From the Fights for Digital Rights" type="image/png" length="1062415" />
  </item>
  <item>
    <title>EFF to San Francisco Police: Drones are Powerful Surveillance Tools That Require a Robust Policy</title>
    <link>https://www.eff.org/deeplinks/2026/09/eff-san-francisco-police-drones-are-powerful-surveillance-tools-require-robust</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;The San Francisco Police Department (SFPD) began regularly deploying drones two years ago and has since expanded their use in a way that has outpaced its documented policy and evaded existing local and state oversight of these devices. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The department has a new proposed policy, which continues to be grossly inadequate in protecting privacy and civil liberties. At best, the draft policy continues the SFPD’s pattern of putting vague guardrails on a powerful surveillance tool, but at worst, if implemented, the policy could effectively usher in sweeping, non-targeted, and unspecified general surveillance over the city with few guardrails.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF has repeatedly opposed the unaccountable development of the SFPD’s drone program and recently &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-public-comment-sf-dgo-1012&quot;&gt;&lt;span&gt;sent a comment&lt;/span&gt; &lt;/a&gt;&lt;span&gt;to the Police Commission, the local civilian oversight body, about the SFPD’s new proposed policy. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The SFPD has been sidestepping oversight of its drones since 2024. In March 2024, San Francisco voters approved a &lt;/span&gt;&lt;a href=&quot;https://sfstandard.com/2024/01/22/london-breed-prop-e-san-francisco-police-fundraising/&quot;&gt;&lt;span&gt;heavily-funded, billionaire-backed measure&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/02/what-proposition-e-and-why-should-san-francisco-voters-oppose-it&quot;&gt;&lt;span&gt;Proposition E&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which sought to expand police access to surveillance technology. Among its impacts, Prop E removed drones from oversight required by the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/12/police-surveillance-san-francisco-2024-year-review&quot;&gt;&lt;span&gt;2019 Surveillance Technology Ordinance&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Nonetheless, in its haste to purchase drones after Prop E passed, the &lt;/span&gt;&lt;a href=&quot;https://sfstandard.com/2024/09/16/san-francisco-police-bought-drones-illegally-emails-warned/&quot;&gt;&lt;span&gt;SFPD knowingly violated&lt;/span&gt;&lt;/a&gt;&lt;span&gt; California’s &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202120220AB481&quot;&gt;&lt;span&gt;AB 481&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, a state statute requiring law enforcement agencies to get approval from their local elected governing body before purchasing military equipment, including drones. Eventually the SFPD &lt;/span&gt;&lt;a href=&quot;https://sfgov.legistar.com/LegislationDetail.aspx?ID=6717195&amp;amp;GUID=27A31B2E-869C-49A5-8E77-C85C3CA81DD9&quot;&gt;&lt;span&gt;sought retroactive approval&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from the Board of Supervisors and, soon after, announced that it would be &lt;/span&gt;&lt;a href=&quot;https://www.nbcbayarea.com/video/news/local/new-police-drone-program/3692648/&quot;&gt;&lt;span&gt;launching a drone-as-first-responder&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (DFR) program.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Now, San Francisco finally has an opportunity to update the SFPD’s guidance in a way that won’t quickly become stale, as has happened while the SFPD steadily increases the purposes for drone use. Though drones were initially identified as tools to use for specific actions such as &lt;/span&gt;&lt;a href=&quot;https://www.sanfranciscopolice.org/unmanned-aircraft-system-uas-proposed-law-enforcement&quot;&gt;&lt;span&gt;vehicle pursuits and active criminal investigations&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, within a year, the SFPD expanded use cases to include &lt;/span&gt;&lt;a href=&quot;https://media.api.sf.gov/documents/PoliceCommission3426_-_AB481_Annual_Report_2025_PowerPoint.pdf&quot;&gt;&lt;span&gt;patrol&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, i.e. unrelated to a specific incident. Along with this mission creep, the SFPD has also steadily and exponentially increased the number of drone flights, from roughly 350 deployments in 2024, to &lt;/span&gt;&lt;a href=&quot;https://www.sanfranciscopolice.org/sites/default/files/2026-01/SFPD_AB481MilitaryEquipmentAnnualReport_2025_20260123.pdf&quot;&gt;&lt;span&gt;over 1,100&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from January to August 2025, to &lt;/span&gt;&lt;a href=&quot;https://www.sfchronicle.com/crime/article/san-francisco-drones-22325281.php&quot;&gt;&lt;span&gt;over 3,500&lt;/span&gt;&lt;/a&gt;&lt;span&gt; in just the first five months of 2026.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The &lt;/span&gt;&lt;a href=&quot;https://media.api.sf.gov/documents/PoliceCommission9226_-_DGO_10.12_Unmanned_Aircraft_Systems_Operations_CLEAN.pdf&quot;&gt;&lt;span&gt;original draft&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of an updated policy brought by the SFPD to the local Police Commission, a civilian oversight body, earlier this month provided limited details and proposed allowing police to treat drone flights as an extension of their patrol abilities, paving the way for general surveillance, including of First Amendment-protected activity. The proposal received significant community pushback, and the San Francisco Public Defender’s Office &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/sf-public-defender-coalition-letter-dgo-1012-draft&quot;&gt;&lt;span&gt;authored a letter &lt;/span&gt;&lt;/a&gt;&lt;span&gt;describing the policy’s shortcomings. That letter was signed by over a dozen local, state, and national groups, including EFF. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Based on these concerns, the Police Commission deferred taking action until the SFPD addressed them. The SFPD then &lt;/span&gt;&lt;a href=&quot;https://media.api.sf.gov/documents/DGO_10_EyVdRcg.12_-_Public_Comment.pdf&quot;&gt;&lt;span&gt;revised its proposed policy&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, but this, too, falls short of providing practical guidance to officers and protecting civil liberties, as the Public Defender’s Office identified in a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/sf-public-defender-coalition-letter-dgo-1012-revised-draft&quot;&gt;&lt;span&gt;follow-up letter&lt;/span&gt;&lt;/a&gt;&lt;span&gt; signed by over 40 organizations, including EFF.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF’s additional comment to the Police Commission, in part, calls out the incredible gap in oversight of these ballooning drone flights and the immense data collection they facilitate:&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;span&gt;The revised policy states that “[unmanned aerial vehicles] may be used as an asset in any situation in which a member may be deployed for a public safety response or when a member onviews criminal activity” but fails to define what is meant by a “public safety response.” The revised policy also provides a definition of “Drone as First Responders,” but it fails to provide any more detail about appropriate DFR deployment. Without appropriate safeguards around deployment and use, drones could be deployed to every call for service, even in situations that are ultimately deemed nonincidents, collecting data along the way that is then stored for 30 days. This type of general patrol could effectively become general surveillance, which SFPD acknowledges is an inappropriate use of their drones and yet is still possible under the vague terms of the current DGO. &lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span&gt;The Police Commission is set to consider the matter on October 14.&lt;/span&gt;&lt;span&gt; You can &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/eff-public-comment-sf-dgo-1012&quot;&gt;&lt;span&gt;read EFF’s full comment here&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 28 Sep 2026 20:30:00 +0000</pubDate>
 <guid isPermaLink="false">112403 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/street-level-surveillance">Street-Level Surveillance</category>
 <category domain="https://www.eff.org/issues/surveillance-drones">Surveillance Drones</category>
 <dc:creator>Beryl Lipton</dc:creator>
 <dc:creator>Saira Hussain</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/drone-first-responders.png" alt="police spy drones hover above an urban city" type="image/png" length="337229" />
  </item>
  <item>
    <title>EFF to Court: Trump&#039;s Use of Truth Social&#039;s Pay-To-See-Posts-First Scheme Violates Americans&#039; 1st Amendment Equal Access Rights </title>
    <link>https://www.eff.org/deeplinks/2026/09/ff-court-trumps-use-truth-socials-pay-see-posts-first-scheme-violates-americans</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;em&gt;EFF legal intern Simar Kaur also contributed to this article.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Americans’ First Amendment right to equal access to official government statements is violated by the Trump administration’s use of Truth Social’s preferential treatment scheme, which blocks people who won’t pay Trump’s company up to $100,000 a month for early access to government news, EFF &lt;a href=&quot;https://www.eff.org/document/intercept-media-inc-et-al-v-trump-et-al-effs-amicus-brief-iso-plaintiffs-pi-motion&quot;&gt;told a federal court.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;The First Amendment guarantees that members of the public have equal access to public officials’ public comments, we reminded the court.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;EFF filed an &lt;a href=&quot;https://www.eff.org/document/intercept-media-inc-et-al-v-trump-et-al-effs-amicus-brief-iso-plaintiffs-pi-motion&quot;&gt;amicus brief&lt;/a&gt; in support of &lt;a href=&quot;https://www.citizensforethics.org/wp-content/uploads/2026/09/ECF-36.01-Exhibit-Memorandum-in-Support-of-Preliminary-Injunction_Redacted.pdf&quot;&gt;a motion for a preliminary injunction&lt;/a&gt; in the &lt;/span&gt;&lt;a href=&quot;https://storage.courtlistener.com/recap/gov.uscourts.nysd.670362/gov.uscourts.nysd.670362.1.0.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;lawsuit&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; filed by The Intercept Media and the Freedom of the Press Foundation against&lt;/span&gt;&lt;a href=&quot;https://storage.courtlistener.com/recap/gov.uscourts.nysd.670362/gov.uscourts.nysd.670362.1.0.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt; President Trump&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; and other administration officials. The lawsuit challenges their use of Truth Social as their primary social media method of making official announcements when that platform provides people who pay a fee for early access to such posts. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Trump uses his Truth Social account as his primary means of communicating with the public, including to announce military operations and ceasefires, foreign and domestic policy, and the removal and appointment of heads of federal agencies. Earlier in the year, Trump Media, which owns Truth Social, &lt;/span&gt;&lt;a href=&quot;https://s3.amazonaws.com/b2icontent.irpass.cc/2660/rl168199.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;announced “Truth API,”&lt;/span&gt;&lt;/a&gt; &lt;span data-contrast=&quot;auto&quot;&gt;a service that provides investors early access to “market-moving” messages from the president and other high-ranking officials for a fee of up to $100,000 per month.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;The plaintiffs, the Freedom of the Press Foundation and The Intercept, contend that the president and other officials’ preferred use of Truth Social with this service violates the First and Fifth Amendments of the Constitution. The plaintiffs are asking the court to immediately prevent the president from posting on Truth Social in a manner that allows him to profit from selling early access to government information.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;EFF’s amicus makes two main points.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;First, the brief establishes that social media is pervasively used by government officials and agencies as a medium for official communication with the public, including to disseminate critical public safety information and make official announcements.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Second, the brief explains that the challenged practice violates the First Amendment, which guarantees a right to access public officials’ public comments on equal terms with other members of the press and public. Giving some people preferential access must at a minimum be reasonably justified to satisfy First Amendment scrutiny, a test the administration does not meet.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Lining the president and his company&#039;s pockets is not a legitimate government interest for restricting timely access to the government&#039;s statements. Further, the fact that the public could ultimately access the information from other, less direct channels does not eliminate the need for First Amendment scrutiny; mere delays in timely access still trigger First Amendment scrutiny.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;EFF has been advancing the First Amendment right of equal access to government’s public social media posts &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/knight-first-amendment-institute-v-trump&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;since at least 2018&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. We’ve argued that the right of equal access, which is well established in offline contexts, must apply to official government social media posts as well. This case presents an excellent opportunity for a court to directly adopt that position.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 25 Sep 2026 21:04:11 +0000</pubDate>
 <guid isPermaLink="false">112398 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>David Greene</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/trump-freespeech_1.png" alt="Trump free speech" type="image/png" length="20760" />
  </item>
  <item>
    <title>DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising </title>
    <link>https://www.eff.org/deeplinks/2026/09/draftkings-using-ai-supercharge-harms-online-behavioral-advertising</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Online sports betting company DraftKings &lt;/span&gt;&lt;a href=&quot;https://www.nytimes.com/2026/09/19/business/draftkings-ai.html&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;is using AI to target customers&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; who are most likely to place losing bets and respond to gambling promotions. This kind of targeting is a form of &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;online behavioral advertising&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, which is when companies personalize the ads they show you based on the data they’ve collected about you. The more data a company has, the more personalized the ad can be. While DraftKings is using AI to supercharge the harmful effects of online behavioral advertising, EFF has long &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/03/ban-online-behavioral-advertising&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;argued&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;auto&quot;&gt;all&lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;auto&quot;&gt; behavioral advertising should be banned.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;According to the &lt;/span&gt;&lt;a href=&quot;http://www.nytimes.com/2026/09/19/business/draftkings-ai.html&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;New York Times&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, DraftKings is using its customers’ betting records to train a &lt;/span&gt;&lt;a href=&quot;https://hai.stanford.edu/ai-definitions/what-is-machine-learning&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;machine learning model&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to find losing gamblers. Once found, DraftKings sends these customers targeted advertising designed to lure them back to the site to place more bets—bets that DraftKings thinks will be losing ones. DraftKings has a business incentive to keep losing gamblers coming back to their site, because these are the users actually making DraftKings money. Unfortunately, those considered “problem gamblers” (people who repeatedly gamble despite harm to themselves, their finances, and their relationships) are highly likely to be targeted by this model. By re-engaging these individuals through targeted promotions aimed at keeping them on the platform, DraftKings is capitalizing on their vulnerability for profit instead of mitigating their risk.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;Predatory online behavioral advertising isn’t new, but companies’ use of AI to process data and target customers has magnified its harms. Online behavioral advertising incentivizes the collection of vast quantities of data to power ad tech. Adding AI into the mix means that even more data is collected to train and refine models. Because AI operates as &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/01/open-data-and-ai-black-box&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;a black box&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, the humans building the models can rarely predict which data points are the most useful to the AI, driving them to continuously collect more data. AI also allows companies to process enormous data sets much faster, and, as a result, supercharges the harms of online behavioral advertising.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;A direct consequence of online behavioral advertising is that it provides the data the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how?language=en&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;surveillance industry&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; needs to run. Data collected for targeted placement of ads is being &lt;/span&gt;&lt;a href=&quot;http://calmatters.org/economy/technology/2026/09/whos-buying-your-personal-data-disney-gm-your-insurer-and-bank/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;sold&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; to insurance companies, banks, and state and federal government law enforcement agencies &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/targeted-advertising-gives-your-location-government-just-ask-cbp&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;such as CBP&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. ICE is also taking an interest in the data fueling ad tech: earlier this year, ICE published a &lt;/span&gt;&lt;a href=&quot;http://sam.gov/workspace/contract/opp/411452e8b3614944b9c50cc3aa24fb42/view&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Request for Information&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; “seeking information to better understand how the industry’s commercial Big Data and Ad Tech providers can directly support investigations activities.” &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;DraftKings seems to be using solely “first party data” to target their ads, meaning that they’re using only the data they collect directly from their users and are not buying any additional data from third parties to fuel their machine learning model. This highlights how policy solutions that only limit third-party data sharing and selling would not be enough to prevent these predatory advertisements. Rather, policymakers must ban online behavioral ads.  &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;What DraftKings is doing with their targeted promotions is just one example of how online behavioral advertising causes real harm to real people. But there are ways to take back control over your own data: EFF offers resources such as our &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Surveillance Self Defense project,&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; along with other tips for how you can protect yourself &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/11/creators-police-location-tracking-tool-arent-vetting-buyers-heres-how-protect&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;on mobile apps&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://privacybadger.org/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;on websites&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;DraftKings’ use of AI to target losing gamblers illustrates how ad tech evolves and how companies find new ways to use our data against us. This is why EFF believes that &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/03/ban-online-behavioral-advertising&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;all behavioral advertising should be banned&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. If companies can’t send personalized ads, they’ll have less incentive to collect the behavioral data powering them.  &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 24 Sep 2026 20:11:52 +0000</pubDate>
 <guid isPermaLink="false">112396 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/online-behavioral-tracking">Online Behavioral Tracking</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Devanshi Nishar</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/mobile-privacy.png" alt="" type="image/png" length="23559" />
  </item>
  <item>
    <title>D.C. Circuit Must Vacate a Drone Flight Restriction That Criminalized Recording Immigration Agents </title>
    <link>https://www.eff.org/deeplinks/2026/09/dc-circuit-must-vacate-drone-flight-restriction-criminalized-recording-immigration</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;EFF joined an &lt;/span&gt;&lt;a href=&quot;https://www.aclu.org/cases/levine-v-faa?document=Amicus-Brief-&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;amicus brief&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; with ACLU, ACLU of D.C., National Press Photographers Association, and Professional Photographers of America to urge the D.C. Circuit to vacate an FAA drone flight restriction that violated the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/right-record&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;First Amendment right to record law enforcement&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. This is an important case—&lt;/span&gt;&lt;a href=&quot;https://www.rcfp.org/litigation/levine-v-federal-aviation-administration/&quot;&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;Levine v. FAA&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;—challenging the ability of the government to punish drone pilots who record law enforcement officers engaged in official business.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;As we wrote about &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/faas-temporary-flight-restriction-drones-blatant-attempt-criminalize-filming-ice&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;earlier this year&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, the FAA issued a flight restriction for drones that had effectively criminalized the recording of Department of Homeland Security officers, including immigration agents from ICE and CBP, and their vehicles (what the FAA called “mobile assets” including “ground vehicle convoys and their associated escorts”) even if the drone was over half a mile away.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;A drone operator, represented by the Reporters Committee for Freedom of the Press, &lt;/span&gt;&lt;a href=&quot;https://www.rcfp.org/wp-content/uploads/2026/03/2026-03-16-Levine-v.-FAA-Petition.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;sued the FAA in March&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; [PDF]. But in April, the &lt;/span&gt;&lt;a href=&quot;https://www.rcfp.org/faa-drops-drone-restrictions-dhs/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;FAA rescinded the flight restriction&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The petitioner argued in his &lt;/span&gt;&lt;a href=&quot;https://www.courtlistener.com/docket/72514131/robert-levine-v-faa/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;opening brief&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; that the court should evaluate the legality of the flight restriction even though it was withdrawn. Drone pilots could still be punished for violations that occurred when the flight restriction was in effect. And the FAA could reinstate the flight restriction at any time, given that the rescission did not seem to reflect “a true change of heart” but rather an effort by the agency to avoid judicial review.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The amicus brief, filed in support of the petitioner, noted that drones are unique because they provide “perspectives that cannot be captured by ground-based imagery,” and they “are far more maneuverable than ground-level cameras, and they are both much cheaper and much safer than using a chartered plane or helicopter to record newsworthy events from above.” The brief highlighted that drones have captured “bird’s-eye images of protest activity” and “police uses of force against protestors,” and have “allowed journalists to provide the public with up-to-the-minute information about natural disasters without putting themselves in harm’s way.”&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The brief argued that using drones to capture images and video is information-gathering activity protected by the First Amendment (similar to using &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/yes-you-have-right-film-ice&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cell phones to record law enforcement&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;). The brief also argued that the FAA’s flight restriction appeared to be issued specifically to ban the recording of immigration agents and thus hinder accountability for their enforcement actions—it surely wasn’t a coincidence that the FAA imposed “no-drone zones around all roving DHS patrols just as those patrols were provoking intense national backlash.” If that’s true, it would make the FAA’s action a content-based restriction on speech that is subject to strict scrutiny—the highest First Amendment standard—and presumptively unconstitutional. And even under less rigorous standards of First Amendment scrutiny, the flight restriction is unconstitutional because the FAA can’t articulate any valid governmental interest justifying such a sweeping restriction on speech.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Resolving this issue to protect First Amendment rights is especially urgent as government agencies continue to &lt;/span&gt;&lt;a href=&quot;https://fedscoop.com/dhs-drone-defense-counter-uas-contracts/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;sink billions of dollars&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; into technology designed to counter drones—technology that could easily be deployed against journalists and other people hoping to use drones to document government abuse. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;We urge the D.C. Circuit to review the petition and to vacate the FAA’s flight restriction, which would send a message that the government can’t avoid accountability by punishing those who exercise their First Amendment rights.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt; &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 21 Sep 2026 22:59:32 +0000</pubDate>
 <guid isPermaLink="false">112381 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Sophia Cope</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/protest-recording-bigboot.jpg" alt="Protesters record on their phones as a massive boot positions to crush." type="image/jpeg" length="267518" />
  </item>
  <item>
    <title>EU Kids Act Won&#039;t Keep the Internet Accountable and Trustworthy </title>
    <link>https://www.eff.org/deeplinks/2026/09/eu-kids-act-wont-keep-internet-accountable-and-trustworthy</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The EU Commission draft law to restrict young people’s access to the internet that it &lt;/span&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/proposal-eu-kids-act-eu-keeping-internet-digital-spaces-accountable-and-trustworthy&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;presented&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; last week will &lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;come at a high cost: it will put online services behind age gates, expand the use of intrusive age verification, and undermine the privacy of all users.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The &lt;/span&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/proposal-eu-kids-act-eu-keeping-internet-digital-spaces-accountable-and-trustworthy&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;EU Kids Act&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; aims to protect children from risks associated with social media, video games, and AI systems by introducing age-based access rules, safety requirements, and stronger enforcement and oversight measures. It presents itself as building on the Digital Services Act (DSA) and puts into “hard law” some of the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/eu-policy-principles&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;safety-by-design measures&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; specified in the non-binding DSA guidelines on minors’ protection.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;The proposal is built around the following elements: social media age “delay”, safety by design, age assurance and parental responsibility, and strong enforcement. Each of these measures are concerning. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Mandatory Age Gates for Social Media and Video-Sharing Platforms&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Following the &lt;/span&gt;&lt;a href=&quot;https://commission.europa.eu/topics/digital-economy-and-society/special-panel_en&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;advice of an expert panel&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, the proposal would create a phased access to social media and video-sharing platforms deemed risky—a threshold met simply by relying on personalized recommender systems or offering “uninterrupted content consumption”: no service accounts for children under 13; restricted accounts under tight parental supervision from 13 to 15; and autonomous accounts in a safe-by-design environment from 15 to 18. Full online access is therefore reserved for adults.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups.&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;If this sounds complex and like a compliance nightmare, that’s because it is. The access delay comes with &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/age-verification&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;privacy-intrusive&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; age verification across the board, relying on the EU age verification scheme. For teenagers, this law means significant control in the hands of their parents, who must set up accounts and prove that they are, in fact, parents, adding yet another problematic layer of verification.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;In fairness, the Kids Act’s gradual approach at least appears to be designed with some proportionality considerations, rather than imposing a blanket social media ban. J&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;ust last month a French court &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/french-top-court-gets-it-right-strikes-down-social-media-ban-youths&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;declared&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; such undifferentiated bans unconstitutional. The EU Kids Act&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt; distinguishes between age groups and certain services and follows a risk-based approach. This means, for example, that age verification is not required for existing accounts if the provider can tell with a “high degree of confidence” that the user is above the age threshold—a vaguely specified standard. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Yet, the law still indiscriminately covers social media and video-sharing, with virtually all mainstream services being covered by the proposal. The broad scope also sits uneasy with the use of age thresholds, which remain a blunt proxy for maturity. What is more, by focusing heavily on safety and harms, the EU Kids Act pays little attention to the privacy and freedom of expression rights of users, as well as the right of children themselves to access information and to participate online. &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt;, often &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/impact-age-verification-measures-goes-beyond-porn-sites#main-content&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;at the expense of marginalized groups&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. They also create a powerful infrastructure for control and further entrench the power of big tech.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The proposal exempts not-for-profit encyclopedias, scientific repositories and educational services, as well as open-source software-developing and-sharing platforms. However, no exceptions are foreseen for small and medium-sized enterprises, which will only foster the dominance of resource-laden tech companies that were already investing in similar measures. And we know that most companies are well-advised to play it safe and use privacy-unfriendly age checks across their platforms.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Safety by Design Across Covered Services&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The proposal’s second pillar, “safety by design”, casts a wider net. It applies across social media, video-sharing, online games, AI companions, chatbots and even app stores—with varying requirements. Providers must generally make child-safe design the default and can relax from the requirements only if they use age assurance to establish that the user is an adult.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;For example, rules on addictive features such as infinite scrolling, safe account settings, and more choice over recommender systems are to provide a safe internet experience to young people. As regards AI companions and chatbots, the proposal requires companies to design their services to reduce minors’ exposure to emotional dependencies and harmful interactions. Online games are covered as well: they must come with contact protections. The law also makes app stores the gate keeper for age-appropriate access, based on an age-rating system.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The devil of these measures lies in the details, but all of them raise fundamental rights concerns and some of them seem poorly suited, if at all, to the decentralized architecture of the Fediverse. The requirement for very large online platforms to set up compliance plans before rolling out new services raises additional questions about the risks of transplanting product-safety doctrines of conformity and risk control into speech regulation. &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Deciding what is “safe” can easily become a question of what content people can access or share.&lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt;  &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;Next Steps &lt;/span&gt;&lt;/b&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;By choosing to regulate all these aspects through the Kids Act, the Commission not only but creates a privacy minefield, it also intermingles the &lt;/span&gt;&lt;a href=&quot;https://commission.europa.eu/law/law-topic/consumer-protection-law/review-eu-consumer-law_en&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;digital fairness agenda&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; with the more fundamental-rights heavy questions of age assurance and access to information. An unfortunate policy choice that will politicize well-intentioned efforts to curb manipulative and addictive design practices (read our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/dos-and-donts-eus-digital-fairness-act-effs-recommendation-regulating-digital&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;position on the DFA&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;).&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;It speaks volume that the Kids Act has not gone through a full impact assessment process, which would typically require a systemic check of &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/05/keeping-people-safe-online-fundamental-rights-protective-alternatives-age-checks&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;alternative&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; policy options and stakeholder consultations. Looking forward, we &lt;/span&gt;&lt;b&gt;&lt;span data-contrast=&quot;none&quot;&gt;call on the EU lawmakers to pull the teeth of the most harmful suggestions&lt;/span&gt;&lt;/b&gt;&lt;span data-contrast=&quot;none&quot;&gt; and to make sure that the new measures don’t erode the fundamental rights of &lt;/span&gt;&lt;i&gt;&lt;span data-contrast=&quot;none&quot;&gt;all &lt;/span&gt;&lt;/i&gt;&lt;span data-contrast=&quot;none&quot;&gt;users.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 21 Sep 2026 12:27:52 +0000</pubDate>
 <guid isPermaLink="false">112379 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/eff-europe">European Union</category>
 <category domain="https://www.eff.org/issues/international">International</category>
 <category domain="https://www.eff.org/taxonomy/term/70">Commentary</category>
 <dc:creator>Christoph Schmon</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverification-banner2-1a.png" alt="A concerned parent and child stand on a large laptop keyboard, while a shadowy hand reaches out from the screen with social media icons and a magnifying glass to scan them." type="image/png" length="1146559" />
  </item>
  <item>
    <title>EFF Statement on California Governor&#039;s Executive Order on AI</title>
    <link>https://www.eff.org/deeplinks/2026/09/eff-statement-california-governors-executive-order-ai</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;California Gov. Gavin Newsom&#039;s &lt;/span&gt;&lt;a href=&quot;https://www.gov.ca.gov/2026/09/18/governor-newsom-issues-executive-order-to-accelerate-independent-oversight-and-advance-the-creation-of-an-ai-kill-switch/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;executive order&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is an opportunity for a needed, thoughtful conversation about artificial intelligence and its potential harms. Everyday Californians are feeling real anxiety about the risks of artificial intelligence, and as an organization that works to ensure technology empowers people, EFF welcomes this order as a way for the state of California to lead a much-needed dialogue that addresses these concerns. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Nonetheless, the most immediate and current concerns with this technology are not about sci-fi scenarios concerning rogue super-intelligence. They are happening right now through biased &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/algorithmic-decision-making#main-content&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;algorithmic decision-making&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for &lt;/span&gt;&lt;a href=&quot;http://www.eff.org/deeplinks/2025/09/yes-californias-no-robo-bosses-act&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;employment&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/new-records-reveal-problems-medicares-ai-prior-authorization-experiment&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;government benefits&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/ai-and-surveillance#main-content&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;AI-powered surveillance systems&lt;/span&gt;&lt;/a&gt;&lt;span&gt; such as &lt;/span&gt;&lt;a href=&quot;https://sls.eff.org/technologies/automated-license-plate-readers-alprs&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;Flock cameras&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/californias-bill-ban-surveillance-pricing&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;artificially inflated personalized pricing&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. People want state and federal leaders to act, and we urge Gov. Newsom to develop thoughtful policies to address those concerns. Today’s EO is a good start. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;To that end, EFF supports the focus on expanding the reporting requirements under &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;SB 53 (2025)&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for loss-of-control incidents, alongside third-party investigations. We urge the administration to consider how to make these third-party investigations available for smaller developers. As the Government Operations Agency prepares its recommendations for the governor, we urge leaders to also realize that the effectiveness of kill switches in advanced AI systems remains an area of active research. As such, they should ensure that - as we’ve &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/eff-lawmakers-ground-ai-cybersecurity-rules-best-practices&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;previously mentioned&lt;/span&gt;&lt;/a&gt;&lt;span&gt; - any technology regulation targeting cybersecurity practices at AI labs must be&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/07/generative-ai-policy-must-be-precise-careful-and-practical-how-cut-through-hype&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; &lt;span&gt;careful, precise, and practical&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Moreover, we also caution that government-controlled kill switches run the risk of being used as a form of retaliation against protected speech,&lt;/span&gt; &lt;span&gt;as demonstrated by the Trump Administration’s &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/judge-rules-dod-unlawfully-retaliated-against-anthropic&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span&gt;retaliatory actions against Anthropic&lt;/span&gt;&lt;/a&gt;&lt;span&gt; earlier this year.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Ultimately, true safety requires California to focus on concrete, immediate, and urgent harms of AI technologies by ensuring that algorithmic decision-making in both the government and private sectors respects people’s rights and well-being. We urge Gov. Newsom and the state of California to develop thoughtful policy in collaboration with those most at risk of harm to address these and other concerns. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 18 Sep 2026 23:25:44 +0000</pubDate>
 <guid isPermaLink="false">112378 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <dc:creator>Tori Noble</dc:creator>
 <dc:creator>Jacob Hoffman-Andrews</dc:creator>
 <dc:creator>Hayley Tsukayama</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/icon-2026-ai-robot-v2.png" alt="A human face with a bright cog inside and a colorful background" type="image/png" length="17646" />
  </item>
  <item>
    <title>How to Limit What Apple’s New Siri AI Can Access in iOS 27</title>
    <link>https://www.eff.org/deeplinks/2026/09/how-limit-what-apples-new-siri-ai-can-access-ios-27</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Apple’s new operating system is here, and along with it comes a new version of Siri, dubbed with two very familiar letters: AI. As the name suggests, this Siri power-up resembles an AI chatbot more than the &lt;/span&gt;&lt;a href=&quot;https://www.nytimes.com/2026/07/30/technology/personaltech/apple-siri-ai-prompts.html&quot;&gt;&lt;span&gt;often&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.pcmag.com/news/apples-siri-struggle-new-report-exposes-reasons-behind-recent-problems&quot;&gt;&lt;span&gt;derided&lt;/span&gt;&lt;/a&gt;&lt;span&gt; voice assistant you might be used to. It has even evolved from a blob you invoke with a verbal command or a button press to a whole app. This update comes with a slew of privacy complications, but you can take some control over what this new Siri can access and use. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There’s no denying that the new version of Siri is far more powerful than it used to be, and arguably more useful at surfacing details on your phone. But that comes at the cost of deeper access. Once enabled, Siri and Spotlight are combined, unifying the interface. Where you may have once just pulled down on the screen to search for an app or contact, you’re now also invoking Siri. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/18/siri_ai.gif&quot; width=&quot;1340&quot; height=&quot;526&quot; alt=&quot;animated gif of siri ai text input buble&quot; title=&quot;animated gif of siri ai text input buble&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Spotlight and Siri are now visually one and the same.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;By default, ask Siri a question and it’ll search through your Apple apps, like Notes, Messages, emails, and more. As time goes on, if the developer chooses to let it, Siri will gain access to more and more third-party apps. If an app developer doesn’t add that support, then Siri AI won’t be able to access the contents of that app (unless it’s shared screenshot-style via a new feature called “on-screen awareness,” which we’ll talk about more in a moment). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For example, if Signal doesn’t choose to implement Siri AI support and you only talk to Bill on Signal, you won’t get an answer when you ask Siri AI, “What was the last photo Bill sent me?” But if you talk to Bill on Apple Messages and ask that same question, Siri AI will summarize what it thinks the photo is.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Sometimes Siri processes this data on your device. Sometimes it uses Apple’s Private Cloud Compute (PCC), &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/secure-messaging-and-ai-remain-conflict-despite-promise-tees&quot;&gt;which means the data is sent off your device to a cloud server&lt;/a&gt;. While you can try digging through the &lt;/span&gt;&lt;a href=&quot;https://support.apple.com/guide/iphone/apple-intelligence-and-privacy-iphe3f499e0e/ios&quot;&gt;&lt;span&gt;Apple Intelligence Report&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to figure out what’s sent to PCC, there’s no immediate visual indication from the user’s point of view when data leaves the device or when AI can handle it on the phone, iPad, or Mac itself. In practice, ask Siri AI a question and you’ll never really know if it’s being computed on device or off.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;a href=&quot;https://security.apple.com/blog/private-cloud-compute/&quot;&gt;Apple claims&lt;/a&gt; what’s sent to PCC is not stored by the company after it is processed, but there are certain types of data or certain apps you might have on your phone that are not worth the risk. That’s especially true if you’re using a feature like Advanced Data Protection, which turns on end-to-end encryption for much of what’s stored in iCloud. Sending data that’s stored with end-to-end encryption off your device and into the cloud—no matter the privacy promises—is a fundamental change to the risk assessment you should make. “Private” means the system is engineered so that Apple shouldn’t be able to see or store the data, but it doesn’t mean it’s encrypted or doesn’t leave the device.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This leaves the privacy of certain apps up to a strange combination of an app developer’s choices and your own. You can, of course, disable Siri entirely (&lt;em&gt;&lt;strong&gt;Settings&lt;/strong&gt;&lt;/em&gt; &amp;gt; &lt;em&gt;&lt;strong&gt;Siri&lt;/strong&gt;&lt;/em&gt; &amp;gt; &quot;Turn Off Siri&lt;em&gt;&quot;&lt;/em&gt;), or choose not to invoke Siri to ask questions, but perhaps you don’t want to fully disable or disengage with the system. Thankfully, you can put some guardrails on Siri AI’s access. Once you’ve updated to iOS 27, here are the steps to take. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;i&gt;Note&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span&gt;: only iPhone 15 Pro/Pro Max, as well as all models of the iPhone 16 and newer support Apple’s AI features. Siri AI is currently only available in English, and &lt;a href=&quot;https://support.apple.com/en-us/127893&quot;&gt;not available worldwide&lt;/a&gt;.&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;How to Restrict Siri’s Access to the Content Inside Apps&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;&lt;img src=&quot;/files/2026/09/18/showcontentinsearch.png&quot; width=&quot;2048&quot; height=&quot;2048&quot; alt=&quot;screenshot of settings app showing &amp;quot;show content in search&amp;quot; unchecked&quot; title=&quot;screenshot of settings app showing &amp;quot;show content in search&amp;quot; unchecked&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;By default, how (and if) Siri AI can access data inside apps is up to the app developer. If an app developer &lt;/span&gt;&lt;a href=&quot;https://developer.apple.com/documentation/appintents/apple-intelligence-and-siri-ai&quot;&gt;&lt;span&gt;chooses to index the contents of their app&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, then it may appear in search, and thus be made available to Siri AI. This means the content may pop up during general or direct searches, like “What are my plans for November&quot; might cull information from your calendar, Messages, Notes, and, as they update, third-party apps.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you do not want Siri to look through certain apps to consider the contents in results, you can tell it not to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Open &lt;/span&gt;&lt;b&gt;&lt;i&gt;Settings&lt;/i&gt;&lt;/b&gt;&lt;span&gt; &amp;gt; &lt;/span&gt;&lt;b&gt;&lt;i&gt;Apps&lt;/i&gt;&lt;/b&gt;&lt;span&gt; &amp;gt; [the app you don’t want Siri to look through] &amp;gt; &lt;/span&gt;&lt;b&gt;&lt;i&gt;Search&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Disable the option to “Show Content in Search.” &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;With this setting disabled, when you ask Siri general questions, it will not surface details from the app you selected. For example, if you disable “Show Content in Search” for Messages, it will not be able to read your Messages conversations. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/18/message_search_on_vs_off.png&quot; width=&quot;2048&quot; height=&quot;1993&quot; alt=&quot;&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Left: Asking Siri to summarize a message thread with &lt;em&gt;Show Content in Search&lt;/em&gt; enabled. Right: With the setting disabled.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There is also an “App Access” setting where you can configure some of the ways Siri interacts with apps. You’d think this is where we’d have gone to revoke access to the content of an app, but alas, this settings page is more about some basic functionality with device personalization, not Siri’s access to the contents of the app.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Open &lt;/span&gt;&lt;b&gt;&lt;i&gt;Settings&lt;/i&gt;&lt;/b&gt;&lt;span&gt; &amp;gt; &lt;/span&gt;&lt;b&gt;&lt;i&gt;Siri&lt;/i&gt;&lt;/b&gt;&lt;span&gt; &amp;gt; &lt;/span&gt;&lt;b&gt;&lt;i&gt;App Access&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Tap an app where you’d like to change Siri’s settings.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;On this screen, you’ll find a variety of options, depending on what an app supports. “Learn from this App” sounds nefarious, but is mostly about tracking usage, like how often you open an app, and if a developer supports it, what you interact with.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The rest of the options are mostly about the personalization tweaks that Siri makes, where it suggests apps it thinks you want at the moment in various places, like when searching or sharing. “Show on Home Screen,” “Suggest App,” and “Suggest Notifications” are just about whether you see apps in those places. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For example, if you have a widget of Siri-suggested apps on the home screen, that’s the “Show on Home Screen” toggle. If you see an app recommended in another app, like adding a date to your calendar from an email, that’s “Suggest App.” &lt;/span&gt;&lt;a href=&quot;https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/&quot;&gt;&lt;span&gt;Apple claims&lt;/span&gt;&lt;/a&gt;&lt;span&gt; these features all use on-device processing and the data is not stored on servers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For anything not covered here, refer to &lt;/span&gt;&lt;a href=&quot;https://support.apple.com/guide/iphone/change-siri-settings-iphc28624b81abc/27/ios/27&quot;&gt;&lt;span&gt;this documentation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for steps to disable certain features.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;The On-Screen Awareness Capability May Be Concerning for Some People&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;There is one Siri AI feature you (and app developers) can’t do as much about: on-screen awareness, a feature you can invoke at any point to prompt Siri and ask it to explain what you’re looking at and perform certain actions. For example, you can ask it to summarize a web page, cut a recipe you’re reading in half, add an event to your calendar, or try to figure out where a photo was taken. All potentially useful features.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But you can also ask it to summarize or explain a Signal group chat that you&#039;re looking at, or a meme in a WhatsApp chat, and the data from that on-screen interaction may be sent to PCC. There is currently no way for you or app developers to block this feature, so it’s up to you, and those you chat with, to simply not use it if you’re concerned about the content of conversations potentially leaving your device. It would be a large improvement to privacy, especially secure chat apps, if Apple provided developers a means to block access to Siri AI’s on-screen awareness tool. Even better if they gave you a &lt;/span&gt;&lt;a href=&quot;https://encryptitalready.org/&quot;&gt;&lt;span&gt;single control to block all Siri AI features&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from an app entirely.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Revoke Access to Training Data&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;By default, Siri AI won’t collect and use data from your interactions with it for training AI features. But during the setup process, Apple provides a way to opt in, which you might have tapped without thinking about it. If you’d rather your data not get used for training, you can opt out:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Open &lt;/span&gt;&lt;b&gt;&lt;i&gt;Settings&lt;/i&gt;&lt;/b&gt;&lt;span&gt; &amp;gt; &lt;/span&gt;&lt;b&gt;&lt;i&gt;Privacy &amp;amp; Security&lt;/i&gt;&lt;/b&gt;&lt;span&gt; &amp;gt; &lt;/span&gt;&lt;b&gt;&lt;i&gt;Analytics &amp;amp; Improvements&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Disable the option for “Improve Siri &amp;amp; Dictation.” &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;According to &lt;/span&gt;&lt;a href=&quot;https://www.apple.com/legal/privacy/data/en/improve-siri-dictation/&quot;&gt;&lt;span&gt;Apple’s privacy documentation&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, disabling this option should revoke training access to the audio and text from the Siri app.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Go Back to the Old Version of Siri (and Disable Other AI Features)&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;&lt;img src=&quot;/files/2026/09/18/allowed_siri.png&quot; width=&quot;2048&quot; height=&quot;2048&quot; alt=&quot;settings app with allowed siri version&quot; title=&quot;settings app with allowed siri version&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Want nothing to do with any of this but still find Siri useful enough to keep around (or you just have to keep it turned on in order to use CarPlay)? For the time being, you can get the old Siri back, though the process is a bit odd.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Open up &lt;/span&gt;&lt;b&gt;&lt;i&gt;Settings &lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span&gt;&amp;gt; &lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;i&gt;Screen Time &lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span&gt;&amp;gt; &lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;i&gt;Content &amp;amp; Privacy Restrictions&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;If you have never done so, enable the toggle for “Content &amp;amp; Privacy Restrictions.”&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Tap the &lt;/span&gt;&lt;b&gt;&lt;i&gt;Siri &lt;/i&gt;&lt;/b&gt;&lt;span&gt;option, then “Allowed Siri Version.” &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Select “Siri Classic.”&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;You can no longer easily disable Apple Intelligence entirely with one tap in the Settings, but on this screen you can also configure other AI features, like disabling the writing and math assistance prompts, turning off image creation, and disallowing the use of extensions. &lt;a href=&quot;https://support.apple.com/guide/iphone/turn-restrict-access-apple-intelligence-iph3fed3f2c3/ios&quot;&gt;Follow this guide&lt;/a&gt; on Apple&#039;s site for everything else.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For the most part, Apple’s handling of AI features is far less in-your-face than others, and because of that the privacy implications are easier to untangle. But even still, it’s difficult to know what’s processed on device and what’s sent off, and so the privacy trade-offs are never spelled out as clearly as they should be. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Apple could improve on this by offering an on-device only option for Siri AI and providing a clear, single setting toggle to prevent all AI features in a specific app (it &lt;a href=&quot;https://www.macrumors.com/guide/ios-27-2-beta-features/&quot;&gt;looks like Apple is planning&lt;/a&gt; a single privacy toggle in a future update. We&#039;ll update if and when it does). In general, Siri’s power-up has also made it blurry and difficult to really figure out what sorts of privacy options exist. “Siri” means many things, both on device and off, ranging from “searching the entire internet for an answer” to “setting a timer,” and users have no straightforward ways to wrangle that data to suit their needs. As it stands, it’s a confusing collection of different toggles that never feel exactly right and which many users might struggle to grasp.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 18 Sep 2026 21:55:16 +0000</pubDate>
 <guid isPermaLink="false">112375 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/end-end-encryption">End-to-End Encryption</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Thorin Klosowski</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/apple-worm.png" alt="the standard apple logo in silver, with a cartoonish green worm poking through it on each side" type="image/png" length="9851" />
  </item>
  <item>
    <title>Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs</title>
    <link>https://www.eff.org/deeplinks/2026/09/secure-messaging-and-ai-remain-conflict-despite-promise-tees</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Secure messaging platforms, like Signal, WhatsApp, and recently, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/victory-end-end-encrypted-rcs-comes-apple-and-android-chats&quot;&gt;&lt;span&gt;encrypted RCS&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, operate on a straightforward assumption: the content at each end of a conversation is private to the participants in the conversation. End-to-end encryption helps provide the mathematical guarantees that the companies who operate these messaging platforms cannot access the contents of messages. But there’s no way to guarantee what happens once the message arrives on a phone. As more devices and services introduce more artificial intelligence (AI) features into messaging apps, that line begins to blur. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;When AI features are computed entirely on device, it’s less concerning. Yet sometimes the computing requirements are heavy enough that the computation has to be done on a company server. Tech companies tell us they have a solution for this: trusted execution environments (TEEs). But do server-side TEEs really solve the problem?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;TEEs exist to serve many different functions, ranging from digital rights management (DRM) content protections to securely storing information in your phone&#039;s mobile wallet, but for our purposes, we’ll be focusing on how tech companies use them for their AI tools. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The basic idea is straightforward: most consumer devices aren’t powerful enough to handle the sorts of AI features companies want to offer, so sometimes they send data off your device to more powerful cloud servers to do the computing, then display the results on your device. Since your data is leaving your device, there’s a privacy compromise. For example, if you ask for a messaging app to summarize a conversation, it may offload that computing power to a cloud server, sending the entire contents of your messages to the cloud, then back to your phone.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;TEEs supposedly offer a way to keep those requests private. There are several implementations out there, like Apple’s &lt;/span&gt;&lt;a href=&quot;https://security.apple.com/blog/private-cloud-compute/&quot;&gt;&lt;span&gt;Private Cloud Compute&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, Google’s &lt;/span&gt;&lt;a href=&quot;https://blog.google/innovation-and-ai/products/google-private-ai-compute/&quot;&gt;&lt;span&gt;Private AI Compute&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and WhatsApp’s &lt;/span&gt;&lt;a href=&quot;https://ai.meta.com/static-resource/private-processing-technical-whitepaper&quot;&gt;&lt;span&gt;Private Processing&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. It’s not just the big tech players, we’ve &lt;/span&gt;&lt;a href=&quot;https://confer.to/blog/2026/01/private-inference/&quot;&gt;&lt;span&gt;seen chatbots built with TEEs&lt;/span&gt;&lt;/a&gt;&lt;span&gt; as well.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;TEEs can provide more security and privacy than simply running in the clear, but they are fundamentally different from actual encryption or running locally. Despite the promises of some tech companies, they will never be able to match that level of security and privacy. Because of that, a user’s device should never automatically send data to a TEE. Let’s dig through the reasons why.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;What Exactly Is a TEE, Anyway?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;A TEE is a hardened section of the computer that runs software in a way that’s supposed to be secret even from other processes running on the machine. TEEs also let users check that the code being run is the code that they think is running, and not backdoored code instead, using a process called “attestation.” You may have also heard this referred to as a “secure enclave,” or heard the brand names SGX or TrustZone.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The intention of a cloud-based TEE is simple: a company can run a server in their data center, but still process data that you provide on your behalf without being able to see that information themselves.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Is a TEE Secure?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;In practice, we&#039;ve seen multiple cracks and hacks every year that show that it is possible to get at that data. That’s because while encryption relies on math, TEEs rely on engineering to provide their security. Standard encryption algorithms are created by years-long processes collaboratively produced by mathematicians around the world and are based on problems that have been studied for decades. The math is reliable, and there is no shortcut to breaking it that would not also upend fundamental understandings of mathematics as a field. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The collective understanding of every mathematician in the world is that standard encryption algorithms are not breakable to the best of the world’s collective knowledge. No responsible engineer builds a system based on a new encryption method until after it’s been offered up for prodding.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Engineering, on the other hand, doesn’t work like that. Every individual system is the product of a group of engineers who put it out into the world, and each product will have its own quirks and bugs that have to be individually discovered and patched. These bugs are found after the system is built, not before. No one has yet built a system that is unbreakable. On the contrary, there is new research all the time that finds new ways to break into TEE systems. They’re patched as they come up, but they’re unlikely to ever become perfect, and certainly not any time soon. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;TEEs in particular are a hard engineering problem because the encryption key is physically right there on the device. Building a TEE means keeping a key fully separate and inaccessible while it’s on the same physical device as parts of the system that shouldn’t have access to the key.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Many attacks on TEEs involve “side channels.” In a side channel attack, &lt;/span&gt;&lt;a href=&quot;https://tee.fail/&quot;&gt;&lt;span&gt;the attacker measures the electrical impulses&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or other effects to figure out the timing of operations inside the TEE, then uses that to figure out the key being used. Once they have the key, they can read all the data. Compare that to end-to-end encryption, where the key is never on that machine in the first place, so an attacker would have to also run a similar attack on the user’s device.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Companies who turn to TEEs to protect data want to both have the key on the server and have it protected while still performing complex operations like running an LLM, which makes it much more difficult to protect those keys.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That being said, a TEE versus plaintext on a server is the difference between being able to easily read the data and having to do a bunch of specialized work to get at the data. That work often involves accessing the physical machine. This is most relevant for protecting against mass surveillance, and for many people, that might just be enough security.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But that&#039;s the core of the problem. “Secure enough for most cases” and “encrypted as in math” are not the same thing, and it’s important not to conflate the two. And services that currently offer “encryption as in math” have a real downgrade in security when they switch to security based on TEEs. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you want to dive into the myriad security issues and limitations of TEEs we’ve seen so far, they’re well documented &lt;/span&gt;&lt;a href=&quot;https://arstechnica.com/security/2025/10/new-physical-attacks-are-quickly-diluting-secure-enclave-defenses-from-nvidia-amd-and-intel/&quot;&gt;&lt;span&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://ieeexplore.ieee.org/document/9152801&quot;&gt;&lt;span&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://dl.acm.org/doi/10.1145/3456631&quot;&gt;&lt;span&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://ieeexplore.ieee.org/document/9935045&quot;&gt;&lt;span&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;What Does This Have To Do With LLMs and AI?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Sometimes organizations want to offer an LLM that can respond to queries in a private manner. On-device LLMs exist, but they’re limited in size. So, when organizations want to offer the ability to answer queries without being able to see the conversation, they turn to TEEs. That’s a useful way to run a chatbot that’s reasonably private. This is what Apple, Google, WhatsApp, and others are doing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Why not turn to encryption? After all, LLM inference is just a bunch of math like any other things a computer does. It takes input to a (really big) function and gives an output. We have the math to do that computation in a way that hides the inputs and outputs from the one running the computation, it&#039;s just super expensive. It’s called homomorphic encryption, and no one’s figured out how to do it fast enough that it makes sense for this sort of computation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Instead, the allure of a TEE is that it will run that computation for you inside of a special opaque section of a server. TEE manufacturers try to make it as hard as possible for the person running the TEE to peek inside. But you still have to trust the operator to not put a stethoscope to the box to try to figure out what&#039;s happening inside. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In this case, it’s reasonable to consider these systems “privacy-preserving,” but not “encrypted.” That distinction is important, especially when we talk about how the TEEs interact with secure messaging. When someone using an end-to-end encrypted chat app asks an LLM to summarize, review, or store those messages, the content of those messages is leaving the device and going to an unencrypted third-party server somewhere. That’s a major threat to the privacy of secure chat apps, and one that’s increasingly hard for users to take control of.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;How Does This Translate to Practical Advice?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The answer to this is going to vary based on an individual’s threat model, but a good rule of thumb is that a user’s device should never automatically send data to a TEE. When the person holding a phone can choose what information is sent, even if it’s a chunk of data like “unread messages,” they have the opportunity to pause and consider if that data might be too sensitive to risk sending.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In contrast, when data is sent automatically, the automatic sending becomes a feature of the system as a whole. If the system was previously end-to-end encrypted, adding automatic exfiltration makes the whole system no longer end-to-end encrypted.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Developers&lt;/b&gt;&lt;span&gt;: don’t build systems that automatically send data off a device to a TEE, especially when it’s coming from an app that is otherwise end-to-end encrypted.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Users:&lt;/b&gt;&lt;span&gt; if developers ignore us and build that system, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/when-ai-and-secure-chat-meet-users-deserve-strong-controls-over-how-they-interact&quot;&gt;&lt;span&gt;turn&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/how-push-notifications-can-betray-your-privacy-and-what-do-about-it&quot;&gt;&lt;span&gt;off&lt;/span&gt;&lt;/a&gt;&lt;span&gt; any automatic data sending features. Take a second to think about how much you’re willing to risk sending data when you choose to send it off the device.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;So, What Should I Be Concerned About?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;TEEs are useful for security in a number of circumstances. Your phone likely has a TEE where it keeps the key that encrypts your biometric unlock data and the base of the keychain where passwords are stored. It also enables certain backup systems, like how you can restore a phone with your passcode or restore WhatsApp or Signal backups.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But when we’re talking about cloud processing, it’s important to be clear this isn’t the same as end-to-end encryption and doesn’t offer the same level of privacy. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Most of our private lives are on our phones and in our messages. We’ve worked for years to secure those messages, with major wins like encrypted RCS, and the continued user experience improvements of Signal and WhatsApp. We’ve even seen real improvements to backup security with &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/05/how-enable-advanced-data-protection-ios-and-why-you-should&quot;&gt;&lt;span&gt;features like Advanced Data Protection&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that bring end-to-end encryption for a variety of data outside of messaging, like notes and photos. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But as companies roll out AI features that interact with these encrypted services, pulling data off devices and into a cloud-based TEE, they’re eroding the privacy protections of end-to-end encryption and risk causing serious confusion around what data is protected and what isn’t.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 18 Sep 2026 21:53:55 +0000</pubDate>
 <guid isPermaLink="false">112377 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/end-end-encryption">End-to-End Encryption</category>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/taxonomy/term/77">Technical Analysis</category>
 <dc:creator>Erica Portnoy</dc:creator>
 <dc:creator>Thorin Klosowski</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/keys-crossed-pink-starburst.png" alt="Crossed keys icon with pink &amp;amp; grey starburst pattern in background" type="image/png" length="20659" />
  </item>
  <item>
    <title>EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices</title>
    <link>https://www.eff.org/deeplinks/2026/09/eff-lawmakers-ground-ai-cybersecurity-rules-best-practices</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/02/smart-ai-policy-means-understanding-its-real-harms-and-benefits&quot;&gt;&lt;span&gt;immediate, demonstrated risks&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from those incidents. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf&quot;&gt;&lt;span&gt;Post-incident&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/&quot;&gt;&lt;span&gt;reports&lt;/span&gt;&lt;/a&gt;&lt;span&gt; show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public&#039;s security.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else&#039;s computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test environment, disconnected from other systems, and be monitored and logged. Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;That said, any proposal must be flexible enough to evolve with changing technology. Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time. Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Strong legislation should also mandate and fund independent third-party investigations into any serious security incidents that may occur during AI labs’ tests of new tools, and make reports of these investigations available to the public. This important transparency measure would go a long way toward providing public oversight of the industry.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As with any technology regulation, those targeting cybersecurity practices at AI labs must be &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/07/generative-ai-policy-must-be-precise-careful-and-practical-how-cut-through-hype&quot;&gt;&lt;span&gt;careful, precise, and practical&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 18 Sep 2026 01:16:10 +0000</pubDate>
 <guid isPermaLink="false">112374 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/issues/security">Security</category>
 <dc:creator>Jacob Hoffman-Andrews</dc:creator>
 <dc:creator>Tori Noble</dc:creator>
 <dc:creator>Maddie Daly</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-brain-surgery-banner.jpg" alt="robot doing brain surgery on itself" type="image/jpeg" length="673377" />
  </item>
  <item>
    <title>California’s “Addictive Feeds” Law Violates Teens’ First Amendment Rights</title>
    <link>https://www.eff.org/deeplinks/2026/09/californias-addictive-feeds-law-violates-teens-first-amendment-rights</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;A California law that prohibits teens from receiving recommended social media content from other social media users violates their First Amendment rights, EFF argued this week.&lt;/p&gt;
&lt;p&gt;The case, &lt;em&gt;Meta v. Bonta&lt;/em&gt;, challenges &lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB976&quot;&gt;SB 976&lt;/a&gt;, which requires that teen social media users get their parents’ permission before seeing other users’ recommended speech on their social media feeds. The legal challenge to SB 976 has largely centered on how the law violates social media services’ First Amendment rights to curate user-generated content and present it as they see fit.&lt;/p&gt;
&lt;p&gt;But the &lt;a href=&quot;https://www.eff.org/document/meta-v-bonta-9th-cir-consolidated-eff-cdt-wikimedia-amicus-brief&quot;&gt;friend-of-the-court brief&lt;/a&gt; EFF filed along with the Center for Democracy &amp;amp; Technology and the Wikimedia Foundation shows that the law &lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/eff-ninth-circuit-young-people-have-first-amendment-right-use-social-media-and-all&quot;&gt;violates teen users’ First Amendment rights, too&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;“SB 976 frustrates young people’s ability to use the internet to its full potential, prohibiting them from relying on tools that disseminate their speech and help them view and interact with other users’ speech,” the brief argues.&lt;/p&gt;
&lt;p&gt;Recommendation systems have a dual purpose on social media: they help all users discover speech and content by other users, and to get their own speech in front of a wider audience.&lt;/p&gt;
&lt;p&gt;“SB 976 creates significant, constitutionally violative, burdens on young users’ ability to read and comment on the news, discuss politics, find and share art, share their religious beliefs, or even practice their religion with fellow members of their faith,” the brief argues. “There is simply too much content on services for users to sift through manually, and young users may not know what to search for or even how to find content.”&lt;/p&gt;
&lt;p&gt;Because SB 976 creates such broad burdens on teens’ ability to distribute and receive speech, it should be struck down on First Amendment grounds. But as EFF’s brief argues, the First Amendment doesn’t stop California and other states from passing laws that help all users, regardless of age, avoid major social media services’ harmful surveillance business models.&lt;/p&gt;
&lt;p&gt;“One could imagine a law that required services to minimize the amount of data they collect, or limit using more invasive data analysis practices, such as tracking users across multiple services, analyzing keystrokes, and other surveillance-intensive practices,” the brief argues. “Such restrictions likely would serve the state’s aim of protecting all internet users—including minors—and would be more narrowly tailored to addressing the harms those practices cause than SB 976.”&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 17 Sep 2026 19:43:17 +0000</pubDate>
 <guid isPermaLink="false">112371 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Aaron Mackey</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/youth-3.jpg" alt="young EFF&amp;#039;ers show phones with security icons" type="image/jpeg" length="718308" />
  </item>
  <item>
    <title>Victory! Appeals Court Rejects Expansive New Copyright Claim</title>
    <link>https://www.eff.org/deeplinks/2026/09/victory-appeals-court-rejects-expansive-new-copyright-claim</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyright liability. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The case involves Section 1202 of the DMCA, which prohibits intentionally removing copyright management information (CMI) like an author’s name or a copyright notice, from a copyrighted work. Open AI and Microsoft used code from Github as part of the training data for their LLMs, along with billions of other works. A group of anonymous Github contributors sued, alleging the new code coming out of these LLMs was similar to theirs—but with the CMI stripped out. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Ninth Circuit correctly agreed with &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/07/eff-court-dmca-didnt-create-new-right-attribution-you-shouldnt-either-0&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;what we said&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; in our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/files/2025/07/18/077.1_eff_and_public_knowledge_amicus.pdf&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;brief&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;: &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;removing copyright information from a copyrighted work is fundamentally different from creating a new work that didn&#039;t have CMI in the first place. Section 1202 of the Digital Millennium Copyright Act was intended to serve as a backstop for traditional copyrights in the digital age—not to create a new, more expansive right to inhibit otherwise non-infringing uses.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;As we also explained, accepting the Does’ theory would have created a brand-new source of liability for otherwise perfectly lawful activities, undermining creativity and innovation far beyond the specific context of AI development. Copyright holders would be able to file costly lawsuits against all kinds of legitimate users, such as artists making remixes based on older works, teachers adapting works for a classroom presentation, engineers reverse engineering code to understand it better, and search engines that help us all navigate the web. The risks would have fallen especially hard on independent software developers and other small creators. Large companies can afford to litigate these claims in federal court for years, if necessary. But an independent programmer facing massive statutory damages may simply have to settle, even when their underlying use is completely lawful. That’s why EFF fights to make sure courts don’t expand copyright beyond what Congress authorized. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Copyright law still protects programmers when their work is unlawfully copied. They can still bring copyright infringement claims if someone uses a model to reproduce their code. Additionally, the plaintiffs’ contract claims against the AI companies are still in play. The specific holding here was narrow but important: that the absence of copyright information from a new work does not mean, by itself, that someone illegally removed it. &lt;/span&gt;&lt;span data-ccp-props=&quot;279}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;That’s the correct result. New technologies will keep raising hard questions about copyright. Courts should answer those questions by applying the rights that Congress actually authorized, not by inventing new rights that could harm expression and lawful use for everyone. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Additional Reading: &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.eff.org/files/2026/09/16/doe_v_github.pdf&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;9&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;th&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;&lt;a href=&quot;https://www.eff.org/files/2026/09/16/doe_v_github.pdf&quot;&gt; Circuit Opinion&lt;/a&gt; in Doe v. GitHub&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.eff.org/files/2025/07/18/077.1_eff_and_public_knowledge_amicus.pdf&quot;&gt;EFF’s Amicus Brief&lt;/a&gt; in Doe v. GitHub&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 16 Sep 2026 22:47:35 +0000</pubDate>
 <guid isPermaLink="false">112368 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <dc:creator>Joe Mullin</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/dmca-copyright-1.png" alt="" type="image/png" length="9133" />
  </item>
  <item>
    <title>Victory: Court, Using a New Test, Rules Embedding Links is Legal </title>
    <link>https://www.eff.org/deeplinks/2026/09/victory-court-using-new-test-rules-embedding-links-legal</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Courts have for two decades found that linking and embedding someone else’s web content, be it a photo, music, or an article, doesn’t violate copyright law–the entity that controls the server that hosts a copyrighted work, not the user or website that merely directs others to it, is directly liable if the content turns out to be infringing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;News publisher &lt;a href=&quot;https://www.eff.org/cases/emmerich-newspapers-v-particle-media-0&quot;&gt;Emmerich Newspapers&lt;/a&gt; sought to convince the Fifth Circuit Court of Appeals to chart a new and dangerous course, arguing that an aggregator website that published links to its copyrighted articles was in effect “displaying” them and can be directly liable for infringement. EFF, along with several other public interest organizations and trade associations, filed &lt;a href=&quot;https://www.eff.org/document/emmerich-v-particle-eff-american-library-association-et-al-amicus-brief&quot;&gt;a brief&lt;/a&gt; urging the court to follow multiple other circuits and reject that theory.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Fortunately, the Fifth Circuit Court of Appeals did just that. While it rejected the server test–the rule courts have used to determine copyright liability rests with whoever serves up the content–the court came to the same practical conclusion by focusing on who is responsible for transmitting content. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Applying that test, the court found that pointing or directing a user’s browser to request and receive the copyright owner’s own copy residing on its computers does not involve transmitting or communicating the content. “Although we take different routes to get there, both the server test and the test we announce end up in a similar place: a website cannot transmit a work that it does not have,” the &lt;a href=&quot;https://www.ca5.uscourts.gov/opinions/pub/25/25-60550-CV0.pdf&quot;&gt;court said&lt;/a&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We told the court that accepting Emmerich&#039;s theory would &lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/eff-court-dont-make-embedding-illegal&quot;&gt;make the common act of embedding links a legally fraught activity,&lt;/a&gt; one that many websites might be unwilling to risk, which would seriously damage the internet as a tool for creating and disseminating ideas and knowledge,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We applaud the court’s decision–even though it applied a different test, it correctly concluded that a user linking pictures, video, or articles isn’t in charge of transmitting that content to the world. The user doesn’t control what’s located on the other end of the link—that’s up to the person who controls the server.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Emmerich also claimed linking violates the &lt;a href=&quot;https://www.eff.org/issues/dmca&quot;&gt;Digital Millennium Copyright Act&lt;/a&gt; (DMCA), arguing its URLs were copyright management information (CMI) and when the aggregator displayed Emmerich’s articles under its own URL, it tampered with Emmerich’s CMI, which violates the DMCA. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Under that logic, unsuspecting internet users could face ruinous legal risk for doing something as simple as using a link shortener, particularly given potential statutory penalties of up to $25,000 per violation.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In our brief, we told the court that URLs don’t necessarily equate to a copyrighted work or provide sufficient information about the nature of the underlying content, making it highly unlikely that anyone would expect a URL to contain CMI. Quoting EFF’s brief, the court concluded that URLs are first and foremost a locational reference tool and while it may be &lt;/span&gt;&lt;i&gt;&lt;span&gt;possible&lt;/span&gt;&lt;/i&gt;&lt;span&gt; for a URL to contain CMI, the bar to that conclusion is high.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Overall, this was a good and sensible decision that will protect ordinary online expression, communication, and access to knowledge. Hopefully this issue is laid to rest at last.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-related-cases field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Related Cases:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;/cases/emmerich-newspapers-v-particle-media-0&quot;&gt;Emmerich Newspapers v. Particle Media&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 16 Sep 2026 16:50:43 +0000</pubDate>
 <guid isPermaLink="false">112366 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <dc:creator>Karen Gullo</dc:creator>
 <dc:creator>Corynne McSherry</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/icon-2019-innovation.png" alt="Innovation" type="image/png" length="16801" />
  </item>
  <item>
    <title>EFF Welcomes Alexander Macgillivray to its Board of Directors</title>
    <link>https://www.eff.org/deeplinks/2026/09/eff-welcomes-alexander-macgillivray-its-board-directors</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;The Electronic Frontier Foundation (EFF) is honored to announce today that &lt;a href=&quot;https://www.eff.org/about/staff/alexander-amac-macgillivray&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Alexander &lt;span&gt;“&lt;/span&gt;amac&lt;span&gt;”&lt;/span&gt; Macgillivray&lt;/a&gt; — a former White House official who also served in top legal capacities at Twitter and Google — has joined EFF’s Board of Directors. &lt;/p&gt;
&lt;p&gt;Macgillivray &lt;span&gt;&lt;a href=&quot;https://fedscoop.com/former-obama-administration-tech-policy-leader-joins-white-house-ostp/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;served in the Biden Administration&lt;/a&gt;&lt;/span&gt; as Deputy Assistant to the President and Principal Deputy U.S. Chief Technology Officer in the Office of Science and Technology Policy, and earlier had held a similar position in the Obama Administration.&lt;span&gt; Macgillivray was one of the co-authors of the Biden Administration’s Blueprint for an AI Bill of Rights and oversaw many of the Administration’s AI initiatives, such as organizing its AI CEO convening, leading its working group on federal AI policy, and overseeing the creation of the National AI Research and Development Strategic Plan and National AI Research Resource.&lt;/span&gt; &lt;/p&gt;

&lt;p&gt;He was Twitter&#039;s General Counsel from 2009 to 2013, leading the Corporate Development, Public Policy, Communications, and Trust &amp;amp; Safety teams. Before that he was Deputy General Counsel at Google from 2003 to 2009, where he created the Product Counsel team.  &lt;/p&gt;
&lt;p&gt;&lt;span&gt;“One of the things I am currently focused on is positively impacting AI development,” Macgillivray said. “The EFF is uniquely situated for that purpose because it combines top-notch legal, technical and advocacy staff with a long history of fighting for people’s rights while encouraging the positive development of technology. I’m thrilled to be joining the board.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Macgillivray joins a dynamic &lt;span&gt;&lt;a href=&quot;https://www.eff.org/about/board&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;EFF Board&lt;/a&gt;&lt;/span&gt; led by Board Chair Gigi Sohn and Vice Chair Brian Behlendorf, and including fellow Board Members Erica Astrella, Anil Dash, Sarah Deutsch, Tadayoshi Kohno, Pamela Samuelson, Bruce Schneier, James Vasile, Tarah Wheeler, and Jonathan Zittrain.&lt;/p&gt;
&lt;p&gt;“The EFF Board is thrilled to have Alex join our ranks,&lt;span&gt;”&lt;/span&gt; Sohn said. &lt;span&gt;“&lt;/span&gt;I’ve worked with Alex for over two decades and have always been impressed not only with his intelligence and grace, but also his ability to think outside the box. His deep experience with non-profit boards will be invaluable as EFF enters a new and exciting chapter.”&lt;/p&gt;
&lt;p&gt;Macgillivray currently also serves on the boards of &lt;span&gt;&lt;a href=&quot;https://www.trustandsafetyfoundation.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;The Trust &amp;amp; Safety Foundation&lt;/a&gt;, &lt;a href=&quot;https://tspa.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;The Trust &amp;amp; Safety Professional Association&lt;/a&gt; and &lt;a href=&quot;https://public.resource.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Public Resource&lt;/a&gt;.&lt;/span&gt; He is an affiliate at the &lt;span&gt;&lt;a href=&quot;https://cyber.harvard.edu/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Berkman Klein Center for Internet &amp;amp; Society at Harvard University&lt;/a&gt;&lt;/span&gt;. Macgillivray earned a law degree from Harvard&lt;span&gt;, &lt;/span&gt;a bachelor’s degree in Reasoning &amp;amp; Decision Making from Princeton University&lt;span&gt;, and a New Jersey Teaching Certificate&lt;/span&gt;. &lt;/p&gt;
&lt;p&gt;“The vanguard leadership of EFF Board members to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical,&lt;span&gt;”&lt;/span&gt; EFF Executive Director Nicole Ozer said. &lt;span&gt;“&lt;/span&gt;Many of the threats that once seemed hypothetical are now reality and the work of our EFF community is fundamental to the future of our countries, our livelihoods, and literally our lives. I feel fortunate to have amac join as a Board member as I begin my tenure as Executive Director. His diverse expertise will be invaluable to make sure that EFF is stronger than ever to meet this moment.” &lt;/p&gt;
&lt;p&gt;Members of the Board of Directors ensure the managerial and financial health of the organization.  EFF is the leading nonprofit organization defending civil liberties in the digital world. &lt;a href=&quot;https://www.eff.org/issues/ai&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Learn more about our cutting-edge work on AI issues&lt;/a&gt;, and please donate today to help keep us fighting for a brighter digital future.&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://supporters.eff.org/donate/amac-form--bdaa&quot; title=&quot;Donate to EFF&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt;Donate to EFF&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 16 Sep 2026 16:36:37 +0000</pubDate>
 <guid isPermaLink="false">112363 at https://www.eff.org</guid>
 <dc:creator>Josh Richman</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/alexander-macgillivray2_0.jpg" alt="Alexander “amac” Macgillivray" type="image/jpeg" length="99824" />
  </item>
  <item>
    <title>👮 Flock Searches for the LOLs | EFFector 38.16</title>
    <link>https://www.eff.org/deeplinks/2026/09/flock-searches-lols-effector-3816</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Mass surveillance isn&#039;t a joke. But police are treating it like one when using automated license plate reader (ALPR) networks. &lt;/span&gt;&lt;span&gt;In &lt;/span&gt;&lt;a href=&quot;https://eff.org/effector/38/16&quot;&gt;our latest EFFector newsletter&lt;/a&gt;&lt;span&gt;, we&#039;re covering &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/high-crime-lmao-how-cops-are-treating-mass-surveillance-joke?utm_source=effector&quot;&gt;a new EFF report&lt;/a&gt; on how&lt;/span&gt; officers across the country are routinely logging completely nonsensical &quot;reasons&quot; for their Flock searches, including &quot;LOL,&quot; &quot;LMAO,&quot; and even (yuck) &quot;Sexy.&quot;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.eff.org/effector/&quot;&gt;JOIN OUR NEWSLETTER&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For over 35 years, &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFFector&lt;/a&gt; has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers a settlement &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/metas-17-billion-settlement-bad-deal-teens-and-all-social-media-users?utm_source=effector&quot;&gt;enshrining Meta&#039;s harmful surveillance&lt;/a&gt; into law, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/texas-and-florida-step-back-alprs?utm_source=effector&quot;&gt;states pushing back against ALPR&lt;/a&gt;, and how police are &lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/high-crime-lmao-how-cops-are-treating-mass-surveillance-joke?utm_source=effector&quot;&gt;turning our privacy into a punchline&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Prefer to listen in? EFFector is now available on all major podcast platforms. This time we&#039;re asking EFF&#039;s Adam Schwartz what has united people against Flock cameras — and how we can make sure that today&#039;s backlash leads to lasting change. You can find the episode and subscribe&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://effector.simplecast.com/&quot;&gt;on your podcast platform of choice&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;mytube&quot; style=&quot;width: 100%px;&quot;&gt;
  &lt;div class=&quot;mytubetrigger&quot; tabindex=&quot;0&quot;&gt;

    &lt;img src=&quot;https://www.eff.org/sites/all/modules/custom/mytube/play.png&quot; class=&quot;mytubeplay&quot; alt=&quot;play&quot; style=&quot;top: 70px; left: 20px;&quot; /&gt;
    &lt;div hidden class=&quot;mytubeembedcode&quot;&gt;%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F93770148-4558-4033-b345-6ff2d136d3c0%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class=&quot;mytubetext&quot;&gt;
    &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2008/02/embedded-video-and-your-privacy&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;Privacy info.&lt;/a&gt;&lt;/span&gt;
    &lt;span&gt;This embed will serve content from &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://player.simplecast.com/93770148-4558-4033-b345-6ff2d136d3c0?dark=false&quot;&gt;simplecast.com&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;i&gt;&lt;a href=&quot;https://open.spotify.com/show/6Q48ICplENdQ4ZarUIgfLZ&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/spotify-podcast-badge-blk-wht-330x80.png&quot; alt=&quot;Listen on Spotify Podcasts Badge&quot; width=&quot;198&quot; height=&quot;48&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/effector/id1882562931&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/applebadge2.png&quot; alt=&quot;Listen on Apple Podcasts Badge&quot; width=&quot;195&quot; height=&quot;47&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://music.amazon.com/podcasts/83be1062-f511-47b3-bd2b-fc44e831c3ad&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img height=&quot;47&quot; width=&quot;195&quot; src=&quot;https://eff.org/files/styles/kittens_types_wysiwyg_small/public/2024/02/15/us_listenon_amazonmusic_button_charcoal.png?itok=YFXPE4Ii&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;https://feeds.eff.org/effector&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;img src=&quot;https://www.eff.org/files/2021/11/01/subscriberss.png&quot; alt=&quot;Subscribe via RSS badge&quot; width=&quot;194&quot; height=&quot;50&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Want to protect your right to digital privacy? Sign up for &lt;a href=&quot;https://eff.org/effector&quot;&gt;EFF&#039;s EFFector newsletter&lt;/a&gt; for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you &lt;a href=&quot;https://eff.org/join&quot;&gt;support EFF today&lt;/a&gt;!&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 16 Sep 2026 16:23:19 +0000</pubDate>
 <guid isPermaLink="false">112365 at https://www.eff.org</guid>
 <dc:creator>Hudson Hongo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/effector-green-web.png" alt="" type="image/png" length="78242" />
  </item>
  <item>
    <title>How the Meta Settlement Silences Youth Activism</title>
    <link>https://www.eff.org/deeplinks/2026/09/meta-settlement-yet-another-example-online-youth-organizing-under-threat</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Since its integration into our digital world, social media has played a pivotal role in youth organizing and social mobilization. Yet, people’s access to these platforms is increasingly coming under threat from courts and legislatures under the guise of protecting young people online—presenting a significant hindrance to youth organizing.  &lt;/p&gt;
&lt;p&gt;In a major recent example, Meta &lt;a href=&quot;https://oag.ca.gov/system/files/attachments/press-docs/23-05448-ecf-572-1-exhibit-1-mdl-consent-judgment-final-settlment-agreement-fully-executed.pdf&quot;&gt;settled in a lawsuit&lt;/a&gt; with 52 states and territories regarding the use of Instagram and Facebook by young people. The settlement will require Meta, and pressure other non-Meta owned platforms like TikTok and YouTube, to embed age gating practices into every product while also requiring restrictions on the accounts of people under-18, such as a two-hour daily time limit and content restrictions.   &lt;/p&gt;
&lt;h3&gt;Youth Power on Social Media &lt;/h3&gt;
&lt;p&gt;Young people have been using social media for political advocacy and community organizing for more than a decade. From organizing &lt;a href=&quot;https://news.medill.northwestern.edu/chicago/six-south-side-teens-spark-activism-using-social-media/&quot;&gt;protests speaking out against police brutality&lt;/a&gt;, to organizing &lt;a href=&quot;https://web.archive.org/web/20190401203349/https://www.crimsonhexagon.com/blog/march-for-our-lives-was-born-on-social-media/&quot;&gt;nationwide school walkouts&lt;/a&gt; demanding safety in schools from gun violence, and &lt;a href=&quot;https://www.earthday.org/youth-digital-striking-fridays-for-future/&quot;&gt;striking to demand&lt;/a&gt; lawmakers take action to protect the climate, social media has become an instrumental tool for youth to both speak out and connect with other young activists.  &lt;/p&gt;
&lt;p&gt;Instagram has &lt;a href=&quot;https://www.teenvogue.com/story/social-media-activism-changed-everything&quot;&gt;become especially useful&lt;/a&gt; for activism online by young people. The features on the app make it a helpful tool for being able to efficiently and quickly spread awareness, which is especially important when people need to share real-time information. For example, 17-year-old &lt;a href=&quot;https://www.npr.org/sections/trial-over-killing-of-george-floyd/2021/04/21/989480867/darnella-frazier-teen-who-filmed-floyds-murder-praised-for-making-verdict-possib&quot;&gt;Darnella Frazier’s video on Facebook&lt;/a&gt; showed the world the murder of George Floyd. &lt;/p&gt;
&lt;p&gt;The impact of youth activism online is also evident on non-Meta owned platforms, with services like TikTok and YouTube being &lt;a href=&quot;https://www.tandfonline.com/doi/full/10.1080/14742837.2024.2415672#d1e210&quot;&gt;particularly&lt;/a&gt; prevalent &lt;a href=&quot;https://www.bbc.com/worklife/article/20220803-gen-z-how-young-people-are-changing-activism&quot;&gt;spaces&lt;/a&gt; for young people to share their stories, build movements, and amplify collective engagement.&lt;/p&gt;
&lt;p&gt;However, in a digital world operating under the settlement’s new guidelines, young people risk not being able to read crucial news due to the content being labeled as “age-inappropriate,” which has &lt;a href=&quot;https://www.theguardian.com/australia-news/2026/may/19/australias-social-media-ban-preventing-teens-from-accessing-the-news-research-finds&quot;&gt;already happened for teenagers in Australia&lt;/a&gt; under its social media ban.  &lt;/p&gt;
&lt;p&gt;A two-hour daily time limit and a block on Meta’s apps between midnight and 6am leaves little room for young activists to organize rapid response efforts. Being unable to see likes on a post will make it difficult to gauge the effectiveness of their campaigns.   &lt;/p&gt;
&lt;p&gt;Add to this &lt;a href=&quot;https://www.usermag.co/p/instagram-blocked-teens-from-searching&quot;&gt;what we already know&lt;/a&gt; about Meta’s content policies which claim to “protect children” and keep sites “family-friendly” but instead label content like &lt;a href=&quot;https://www.eff.org/deeplinks/2018/10/blunt-policies-and-secretive-enforcement-mechanisms-lgbtq-and-sexual-health&quot;&gt;LGBTQ+ content&lt;/a&gt; as “adult” or “harmful,” youth will be left with no choice in what content they see once the ‘age-appropriate’ content filter is turned on by default. One &lt;a href=&quot;https://www.usermag.co/p/instagram-blocked-teens-from-searching&quot;&gt;recent report&lt;/a&gt; noted that Meta had hidden posts that reference LGBTQ+ hashtags like #lesbian, #bisexual, #gay, #trans, and #queer for users with the sensitive content filter on. This would specifically curtail the efforts of young activists doing work on comprehensive sex education.   &lt;/p&gt;
&lt;h3&gt;Global Trends &lt;/h3&gt;
&lt;p&gt;Measures like this are being discussed across the globe, but not all courts have taken such a short-sighted approach. In August, the French Constitutional Council &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/french-top-court-gets-it-right-strikes-down-social-media-ban-youths&quot;&gt;got a lot right&lt;/a&gt; in its &lt;a href=&quot;https://www.conseil-constitutionnel.fr/actualites/communique/decision-n-2026-911-dc-du-14-aout-2026-communique-de-presse&quot;&gt;decision&lt;/a&gt; to strike down the country’s legislation banning under-15s from social media for infringing free expression and communication for everyone online, not just young people.  &lt;/p&gt;
&lt;p&gt;The French Court also called attention to its infringement on privacy as the legislation would have forced people of all ages to hand over &lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/face-scans-estimate-our-age-creepy-af-and-harmful&quot;&gt;government IDs&lt;/a&gt;, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/lgbt-qa-what-data-are-companies-uk-collecting-when-verifying-my-age&quot;&gt;face scans&lt;/a&gt;, and &lt;a href=&quot;https://www.eff.org/deeplinks/2023/05/law-should-not-require-parental-consent-all-minors-access-social-media&quot;&gt;other sensitive information&lt;/a&gt; to prove their age and access online content.  &lt;/p&gt;
&lt;p&gt;Requiring this much data from users puts activists in danger of &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists&quot;&gt;even more surveillance&lt;/a&gt;. Meta has already previously complied with &lt;a href=&quot;https://www.npr.org/2022/08/12/1117092169/nebraska-cops-used-facebook-messages-to-investigate-an-alleged-illegal-abortion&quot;&gt;demands from law enforcement to hand over the messages&lt;/a&gt; of users. The amount of personal information that will be logged and that could be demanded via a warrant from police to stifle or investigate activists’ actions or plans could cause a chilling effect, forcing advocates to pause or terminate their work.  &lt;/p&gt;
&lt;p&gt;This is egregious because these systems misidentify or lock out &lt;a href=&quot;https://www.pewresearch.org/journalism/2025/12/03/young-adults-and-the-future-of-news/&quot;&gt;people of color&lt;/a&gt;, &lt;a href=&quot;https://journals.sagepub.com/doi/10.1177/1461444820912530&quot;&gt;people with disabilities&lt;/a&gt;, and &lt;a href=&quot;https://dl.acm.org/doi/10.1145/3274357&quot;&gt;trans or gender-nonconforming&lt;/a&gt; individuals whose IDs may not match their chosen name or align with what the system expects them to look like upon verification. And it’s often these communities that benefit from online organizing the most, especially for &lt;a href=&quot;https://medicalxpress.com/news/2020-07-marginalized-youth-socially-isolated-previous.html&quot;&gt;marginalized youth&lt;/a&gt; as social media can often be the only place to organize and build community. &lt;/p&gt;
&lt;h3&gt;What Young People Deserve &lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://www.bbc.co.uk/news/live/cy5v0vrlp4xt?post=asset%3Abb15e39d-e124-4883-884e-edc6e4a2fbd7#post&quot;&gt;The settlement generates headlines&lt;/a&gt;, but it will not solve the core problem. Instead of tackling Meta’s surveillance capitalism business model that turns all online content into potential profit and centers lining the company’s pockets over protecting the speech and privacy of users, this settlement gives the tech giant an opportunity to carve out a new digital world that prioritizes its own needs, not those of young people.  &lt;/p&gt;
&lt;p&gt;As we’ve been &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/uks-new-under-16-social-media-ban-will-cause-more-harm-it-prevents&quot;&gt;calling&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/how-and-why-fight-back-against-social-media-bans&quot;&gt;attention&lt;/a&gt; to in other contexts, this will force young people into digital isolation—curtailing vital access to &lt;a href=&quot;https://www.pewresearch.org/journalism/2025/12/03/young-adults-and-the-future-of-news/&quot;&gt;news&lt;/a&gt; and &lt;a href=&quot;https://www.woodhullfoundation.org/press-release/report-age-verification-sex-educators/&quot;&gt;resources&lt;/a&gt; for health and development. It also completely ignores the &lt;a href=&quot;https://www.eff.org/deeplinks/2024/03/thousands-young-people-told-us-why-kids-online-safety-act-will-be-harmful-minors&quot;&gt;calls of youths themselves&lt;/a&gt; &lt;a href=&quot;https://nofiltr.org/bluebook/&quot;&gt;who favor digital literacy&lt;/a&gt; and education over surveillance and government control.   &lt;/p&gt;
&lt;p&gt;Young people deserve a better internet than one regulated through panic. They deserve better than the government or Big Tech getting to decide how they use social media and what they can or cannot be exposed to or learn about. They deserve better than having their right to free expression minimized. This must not be lost in the pursuit of building a better and safer online ecosystem and environment.   &lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 16 Sep 2026 16:04:50 +0000</pubDate>
 <guid isPermaLink="false">112348 at https://www.eff.org</guid>
 <dc:creator>Paige Collings</dc:creator>
 <dc:creator>Kenyatta Thomas</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  <item>
    <title>California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety</title>
    <link>https://www.eff.org/deeplinks/2026/09/california-tell-governor-stand-net-neutrality-affordability-and-public-safety</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;The federal government has inserted a &lt;/span&gt;&lt;a href=&quot;https://broadbandusa.ntia.gov/sites/default/files/2026-02/BEAD_GTCs_Nov_18_2025.pdf&quot;&gt;&lt;span&gt;provision into a funding deal&lt;/span&gt;&lt;/a&gt;&lt;span&gt; with the state of California that would make the state abandon its gold standard net neutrality law, broadband affordability laws, and public safety protections. Doing so would be a huge step back for California, and would actually end up being more expensive for Californians in the long run. Tell the governor to reject this provision before accepting these funds from the federal government.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/169499/&quot;&gt;Take Action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety&lt;/p&gt;
&lt;p&gt;&lt;span&gt;On August 31, the National Telecommunications and Information Administration announced it would be awarding California $1.4 billion to expand broadband connectivity in the state. In that deal is a provision that says that California agrees to not enforce any law, order, or policy that imposes any sort of restriction on internet service providers (ISPs). These ISPs will get awarded the funding in order to connect Californians they have neglected for years. The ban on enforcing our laws would &lt;/span&gt;&lt;a href=&quot;https://www.ntia.gov/sites/default/files/2025-06/bead-restructuring-policy-notice.pdf&quot;&gt;&lt;span&gt;last 14 years&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. This is disastrous for a lot of reasons. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;First, California is one of the only states with a strong state &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2018/08/victory-california-passes-net-neutrality-bill&quot;&gt;&lt;span&gt;net neutrality law&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. Recreating much of the FCC’s Open Internet Order, the law prevents ISPs from blocking, throttling, zero rating, and instituting paid prioritization on internet service. Put another way, the law ensures that users, not companies, decide how they can see on the internet. If California is not allowed to enforce our gold standard law, there will be little stopping ISPs from controlling how everyone experiences the internet. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Second, California has a number of affordability protections that would also fall under this agreement. For example, when the state approved the merger of Verizon and Frontier earlier this year, &lt;/span&gt;&lt;a href=&quot;https://docs.cpuc.ca.gov/PublishedDocs/Published/G000/M595/K045/595045510.pdf&quot;&gt;&lt;span&gt;it required&lt;/span&gt;&lt;/a&gt;&lt;span&gt; the new merged company to offer a $20 internet plan to low-income Californians—saving Californians billions of dollars over the next decade. Just this year the California Public Utilities Commission found that the &lt;/span&gt;&lt;a href=&quot;https://www.publicadvocates.cpuc.ca.gov/-/media/cal-advocates-website/files/press-room/reports-and-analyses/260114-public-advocates-broadband-competition-and-pricing-strategies-in-california-urban-markets.pdf&quot;&gt;&lt;span&gt;average cost of broadband&lt;/span&gt;&lt;/a&gt;&lt;span&gt; across four major urban markets (San Mateo, Oakland, Los Angeles, and San Diego) was $51 per month. In 2023, &lt;/span&gt;&lt;a href=&quot;https://advocacy.consumerreports.org/press_release/consumer-reports-survey-of-american-consumers-on-cost-and-accessibility-of-broadband-internet-services/&quot;&gt;&lt;span&gt;Consumer Reports&lt;/span&gt;&lt;/a&gt;&lt;span&gt; found that 84% of American consumers pay at least $50 per month, with many paying more. That $30 difference per month—which is likely to actually be more—makes all the difference for low-income Californians. It is how Californians will save billions from this merger requirement. In contrast, $1.4 billion in new connectivity and infrastructure doesn&#039;t matter if the most vulnerable Californians cannot afford it. Eviscerations of this and the net neutrality protections will, ultimately, cost Californians more than they will get. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Third, this deal will impact public safety. The same California net neutrality law which protects consumers also ensures reliable service for first responders during emergencies by banning throttling. In 2018, Verizon throttled, or slowed down, the service of firefighters as they were battling what was, at the time, the largest wildfire in California history. In reaction, fire departments came out in support of what would become California’s net neutrality law. If California cannot enforce its net neutrality law it will leave its first responders in a weaker position as natural disasters only become more intense. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Most people &lt;/span&gt;&lt;a href=&quot;https://ilsr.org/article/community-broadband-networks/report-most-americans-have-no-real-choice-in-internet-providers/&quot;&gt;&lt;span&gt;do not have a choice&lt;/span&gt;&lt;/a&gt;&lt;span&gt; in ISP as it is. California’s net neutrality law is one of the few things protecting Californians from the whims of these monopolistic giants. Californians should not give up our few hard-won protections in return for a hand out to these behemoths. Tell Governor Newsom to reject this provision before he accepts these funds from the federal government. &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;take-action&quot;&gt;&lt;a href=&quot;https://www.acteff.org/campaign/169499/&quot;&gt;Take Action&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;take-explainer&quot;&gt;Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 15 Sep 2026 18:35:24 +0000</pubDate>
 <guid isPermaLink="false">112359 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/net-neutrality">Net Neutrality</category>
 <dc:creator>Katharine Trendacosta</dc:creator>
 <dc:creator>Chao Liu</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/og-neutrality-banner.png" alt="" type="image/png" length="772396" />
  </item>
  <item>
    <title>The High Crime of “LMAO”: How Cops Are Treating Flock&#039;s Mass Surveillance As a Joke</title>
    <link>https://www.eff.org/deeplinks/2026/09/high-crime-lmao-how-cops-are-treating-mass-surveillance-joke</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Here&#039;s a riddle: Why did a Goshen Police Department officer search 6,474 automated license plate reader (ALPR) networks, representing data from 82,413 cameras, on May 7, 2025? &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If your answer is &quot;I don&#039;t know,&quot; it turns out you&#039;re 100% correct. The officer left the letters &quot;idk&quot; in the search field where cops are supposed to document the reason for the search.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;When law enforcement and tech salespeople pitch ALPRs to city councils, they stick to a familiar script. They trumpet the technology, which is often provided by private companies like &lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/blog/safety-is-a-fundamental-right&quot;&gt;&lt;span&gt;Flock Safety,&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.motorolasolutions.com/en_us.html&quot;&gt;&lt;span&gt;Motorola Solutions&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, or &lt;/span&gt;&lt;a href=&quot;https://www.axon.com/help/fleet-3/cameras-and-sensors/fleet/3/alpr/alpr-introduction.htm&quot;&gt;&lt;span&gt;Axon&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, as an essential tool for solving high-stakes crimes, such as car jacking, kidnapping, or murder.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But when you strip away the carefully &lt;/span&gt;&lt;a href=&quot;https://www.documentcloud.org/documents/28163832-wpd-flock-emails-janjul2025-text-1/?mode=document#document/p24/a2818282&quot;&gt;&lt;span&gt;curated talking points&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the data continues to reveal a different (and frankly, ridiculous) story. An EFF analysis of ALPR search logs from Flock Safety systems shows that officers across the country are spying on drivers for completely nonsensical &quot;reasons.&quot; Police are routinely searching the Flock database without providing any legitimate justification, making a mockery of our civil liberties by logging reasons like &quot;LOL&quot; (short for “laugh out loud”), &quot;LMAO&quot; (short for &quot;laughing my ass off&quot;), &quot;sexy,&quot; and &quot;idk&quot; (short for “I don’t know”) to access sensitive ALPR location data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And in some cases, officers are just mashing keyboard buttons rather than articulating the nature of their searches.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Flock Safety claims it has improved its system by requiring officers to select from a &lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/blog/offense-type-dropdown-a-simpler-more-accurate-audit&quot;&gt;&lt;span&gt;dropdown&lt;/span&gt;&lt;/a&gt;&lt;span&gt; list of crimes before running a search–but that only makes it easier for officers to hide improper searches behind the veneer of uniformity. The system does not require proof that the dropdown reason actually matches the true purpose of the search. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;With no warrant requirements, limited guardrails, and deficient audit processes, ALPR databases have fostered a culture of unrestricted access to everyone’s location information. This culture of abuse has allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-school-residency-verification-background&quot;&gt;&lt;span&gt;low-level complaints&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.usatoday.com/story/news/investigations/2026/09/11/new-flock-misuse-cases-police-arrests-firings-investigation/91691881007/&quot;&gt;&lt;span&gt;personal whims&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and sometimes, seemingly, &lt;/span&gt;&lt;a href=&quot;https://www.urbandictionary.com/define.php?term=for+the+lols&quot;&gt;&lt;i&gt;&lt;span&gt;for the lols.&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;A Documented Culture of Abuse&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;ALPR misuse isn’t a new phenomenon; it has dominated headlines for more than a year. We already know that officers regularly abuse these systems to &lt;/span&gt;&lt;a href=&quot;https://www.washingtonpost.com/technology/2026/08/02/how-police-officers-used-vast-network-cameras-spy-their-exes/&quot;&gt;&lt;span&gt;stalk past&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://reason.com/2026/07/10/florida-police-officer-used-mass-surveillance-network-to-stalk-romantic-interest/&quot;&gt;&lt;span&gt;potential romantic partners&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. We’ve seen ALPRs used to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists&quot;&gt;&lt;span&gt;surveil protests&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which can chill First Amendment-protected dissent, and seen officers try to use an ALPR system to &lt;/span&gt;&lt;a href=&quot;http://www.eff.org/deeplinks/2025/10/flock-safety-and-texas-sheriff-claimed-license-plate-search-was-missing-person-it&quot;&gt;&lt;span&gt;track down a woman seeking an abortion&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Typically, we learn about these uses from documents called &quot;network audits,&quot; which are long spreadsheets that document all the searches that run through an agency&#039;s system. It is not unusual for even a small agency to have a record of &lt;/span&gt;&lt;a href=&quot;https://www.whro.org/virginia-center-for-investigative-journalism/2025-09-17/va-flock-data-shared-millions-of-times&quot;&gt;&lt;span&gt;millions of searches&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from thousands of external agencies across the United States.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We’ve also uncovered horrific &lt;/span&gt;&lt;a href=&quot;http://www.eff.org/deeplinks/2025/11/license-plate-surveillance-logs-reveal-racist-policing-against-romani-people&quot;&gt;&lt;span&gt;systemic profiling&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, with more than 80 law enforcement agencies using terms like &quot;roma&quot; and &quot;g*psy&quot; to target ethnic Romani people—often without any mention of a suspected crime. And when police aren’t using ALPRs for stalking or profiling, they routinely use them for extreme low-level investigations: verifying whether a student lives in a &lt;/span&gt;&lt;a href=&quot;https://www.theregister.com/on-prem/2026/03/12/school-district-cites-plate-reader-data-to-deny-enrollment/5222086&quot;&gt;&lt;span&gt;specific school zone&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-school-residency-verification-background&quot;&gt;&lt;span&gt;running employment background checks, following up on loud music complaints&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, or &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/traffic-violation-license-plate-reader-mission-creep-already-here&quot;&gt;&lt;span&gt;targeting a motorcyclist&lt;/span&gt;&lt;/a&gt;&lt;span&gt; simply for holding a cell phone.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But somehow, it gets worse.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;The Absurdity of Documented Search Reasons&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;EFF’s analysis of Flock Safety’s ALPR search data obtained through public records requests has uncovered a disturbing trend. In the absence of judicial oversight, officers are inputting ridiculously unserious terms to justify their searches. Here is just a snapshot of what police consider a &quot;reason&quot; to track someone’s vehicle:&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;b&gt;Surveillance as a Joke&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/12/screenshot_2026-09-12_at_4.37.14_pm.png&quot; width=&quot;906&quot; height=&quot;538&quot; alt=&quot;&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Audit logs sample&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Barberton Police Department (Ohio) employees ran numerous searches between March 2024 and May 2026, listing “&lt;/span&gt;&lt;b&gt;LOL&lt;/b&gt;&lt;span&gt;” or “&lt;/span&gt;&lt;b&gt;lol&lt;/b&gt;&lt;span&gt;” as the reason.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Harris County Sheriff&#039;s Office (Texas) employees ran several searches between April and May 2026 listing &lt;/span&gt;&lt;b&gt;“LOL”&lt;/b&gt;&lt;span&gt; or &lt;/span&gt;&lt;b&gt;“lol”&lt;/b&gt;&lt;span&gt; as the case number.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Lake County Sheriff&#039;s Department (Ind.) employees ran searches in July 2025 for “&lt;/span&gt;&lt;b&gt;LMAO&lt;/b&gt;&lt;span&gt;.”&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Richmond Police Department (Calif.) employees ran over multiple searches in November 2024 for &lt;/span&gt;&lt;b&gt;“Hehe.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Riverside County Sheriff&#039;s Department (Calif.) employees ran searches in 2024 for &lt;/span&gt;&lt;b&gt;“Haha.”&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;b&gt;&quot;Don’t Know, Don’t Care&quot; Approach&lt;/b&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Kankakee County, Sheriff&#039;s Office (Ill.) employees ran searches (2023–2025) for &lt;/span&gt;&lt;b&gt;“idk”&lt;/b&gt;&lt;span&gt; or &lt;/span&gt;&lt;b&gt;“idk lol.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Goshen Police Department (Ind.) ran searches (May–June 2025) for &lt;/span&gt;&lt;b&gt;“idk.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Fishers Police Department (Ind.) ran searches in May 2025 for &lt;/span&gt;&lt;b&gt;“blah.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Pasco Police Department (Wash.) employee searched for at least four different license plates, leaving &quot;&lt;/span&gt;&lt;b&gt;robbery i don&#039;t remember the case number leave me alone&lt;/b&gt;&lt;span&gt;&quot; in the reason field.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;The San Diego Sheriff&#039;s Department (Calif.) ran searches in May 2025 with &quot;&lt;strong&gt;idk&lt;/strong&gt;&quot; in the reason field. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;More than 30 agencies ran more than 6,300 searches with &quot;&lt;/span&gt;&lt;b&gt;TBD&lt;/b&gt;&lt;span&gt;&quot; (short for &quot;To Be Determined&quot;) as the &quot;reason.&quot; These included the Arizona Department of Public Safety, the Manteca Police Department (Calif.), and the Baton Rouge Police Department (La.). The Priceville Police Department (Ala.) alone ran 1,954 searches with reasons &quot;TBD.&quot; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;b&gt;Insults and Inappropriate Searches&lt;/b&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Belton Police Department (Mo.) ran searches (Aug–Sept 2024) for &lt;/span&gt;&lt;b&gt;“d*ckhead.” &lt;/b&gt;&lt;span&gt; (asterisk/redaction our own)&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;A Manteca Police Department (Ill.) employee ran searches in June 2024 for &lt;strong&gt;“sh*thead”&lt;/strong&gt;  (asterisk/redaction our own)&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Norton Police Department (Mass.) employee ran searches in December 2024 for &lt;/span&gt;&lt;b&gt;“Sexy.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Corona&lt;/span&gt; &lt;span&gt;Police Department (Calif.) employees ran searches (2023–2025) for &lt;/span&gt;&lt;b&gt;“weird”&lt;/b&gt;&lt;span&gt; or &lt;/span&gt;&lt;b&gt;“WEIRD KID.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Thornton Police Department (Colo.) employees ran several searches in October 2025 for &lt;/span&gt;&lt;b&gt;“driving around being weird.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Columbus Police Department (Ohio) officer ran searches in 2023 for &lt;/span&gt;&lt;b&gt;“idiot.”&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Michigan City Police Department&lt;/span&gt; &lt;span&gt;Officer (Ind.) ran searches in June 2025 listing &lt;/span&gt;&lt;b&gt;“f*ck this new search engine.”&lt;/b&gt;&lt;span&gt; (asterisk/redaction our own)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;Button Mashing &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/12/screenshot_2026-09-12_at_4.33.19_pm.png&quot; width=&quot;1024&quot; height=&quot;407&quot; alt=&quot;&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Button mashing audit logs sample&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&lt;span&gt;One of the more alarming discoveries we found in the network audit data is a large number of &quot;reasons&quot; that appear to be nothing more than an officer mashing buttons. These typically involve a nonsensical long string of characters from the same line or area of the keyboard.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For example: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;An Eatonton Police Department (Ga.) employee ran searches with reasons such as &lt;/span&gt;&lt;b&gt;HJKNUILH&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;uiokjk.kuj&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;GJLHBNMN&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;hjhbnmg&lt;/b&gt;&lt;span&gt;, and &lt;/span&gt;&lt;b&gt;iuohjk.&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;An Atlanta Police Department (Ga.) employee ran searches with &lt;/span&gt;&lt;b&gt;asdfga&lt;/b&gt;&lt;span&gt; as the reason. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Bay County Sheriff&#039;s Office (Fla.) employees ran searches with reasons such as  &lt;/span&gt;&lt;b&gt;;&#039;lkjh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;/lkjh&lt;/b&gt;&lt;span&gt; and &lt;/span&gt;&lt;b&gt;lkjhg&lt;/b&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Brown County Sheriff&#039;s Office (Wis.) employee ran searches with reasons such as &lt;/span&gt;&lt;b&gt;gyghkkghghjkghjk&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;ggyjgyujdsrdghdfhjkghjghk&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;HJHJKLHLKHJK&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;hjjkjkhjkljk &lt;/b&gt;&lt;span&gt;and &lt;/span&gt;&lt;b&gt;JHLJKHHJKL&lt;/b&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Lake County Sheriff&#039;s Office (Ohio) employee ran searches with reasons such as &lt;/span&gt;&lt;b&gt;asdfg&lt;/b&gt;&lt;span&gt; and &lt;/span&gt;&lt;b&gt;ghjkl&lt;/b&gt;&lt;span&gt;, and a second officer ran a series of searches that started off with &quot;investigation&quot; but then devolved into button mashing, including: &lt;/span&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Investigatafy&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;Investigatafyd&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;Investigatafydl&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;Investigatafydlh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafydlhj&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafydlhji&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhji&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjigkfgty&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjigkfgtyy&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjij&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjik&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjikf&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjikfg&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjikfgty&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;investigatafyfdlhjikfgy&lt;/b&gt;&lt;span&gt; and &lt;/span&gt;&lt;b&gt;investigatafyfdlhjiy&lt;/b&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;&lt;span&gt;A Moore Police Department (Okla.) ran searches with reasons such as &lt;/span&gt;&lt;b&gt;jhjhjkhj&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;jhjkhjh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;jhjkhjkh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;jkhhkjhjk&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;Jkhjkhj&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;Jkhjkhjk&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;Jkhjkhjkh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;jkhjkhkjh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;jkjkhjkh&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;kjjkhjk&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;loiuiou&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;ukjhjkh&lt;/b&gt;&lt;span&gt; and &lt;/span&gt;&lt;b&gt;ulkuiou&lt;/b&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Westlake Police Department (Ohio) employee ran searches with reasons such as &lt;/span&gt;&lt;b&gt;fghjkl&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;ghjkl&lt;/b&gt;&lt;span&gt;, and &lt;/span&gt;&lt;b&gt;lkjhg&lt;/b&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;A Kentucky State Police employee ran searches with reasons such as &lt;/span&gt;&lt;b&gt;mhghjk&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;mhgnhjkj&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;nbvcxcvbn&lt;/b&gt;&lt;span&gt;, &lt;/span&gt;&lt;b&gt;nmbvcbnm&lt;/b&gt;&lt;span&gt;, and &lt;/span&gt;&lt;b&gt;sdfghj&lt;/b&gt;&lt;span&gt;. &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;It&#039;s hard to imagine a situation where these characters add up to a legitimate police code. However, it&#039;s easy to imagine an officer cutting corners with a text field they know no one is checking, especially if they are accessing the Flock Safety app from their phones while driving. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;How Police Departments Are Responding&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;When confronted with these flagrantly unserious searches, police departments offered a mix of bureaucratic deflections and excuses. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In response to EFF’s request for comment, Thornton Police Department (Colo.) claimed the system didn&#039;t require officers to select from a defined list at the time, but it does today. They also audited the “driving around being weird” searches, claiming they were all actually for &quot;legitimate public safety purposes.&quot; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Other police departments we reached out to for comment shared the following: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Richmond Police Department (Calif.) stated that the officers involved with the &quot;Hehe&quot; and &quot;idk&quot; searches were &quot;counseled.&quot;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Corona Police Department (Calif.) noted that the employees searching for &quot;WEIRD KID&quot; are no longer employed by the city for unrelated reasons.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Columbus Police Department (Ohio) pointed to their union contract, stating their Inspector General only has jurisdiction to investigate incidents within the last 90 days, giving the officer who searched for &quot;idiot&quot; in 2023 a free pass.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Belton Police Department (Mo.) promised a &quot;thorough investigation&quot; of the &quot;d*ckhead&quot; searches through existing union and personnel policies.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Manteno Police Department (Ill.) said it will &quot;review the searches and the circumstances surrounding them thoroughly&quot; and &quot;take whatever action is determined to be appropriate based on the facts and circumstances.”&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Manteca Police Department (Calif.) said: &quot;Since the beginning of 2026, our personnel have been directed that the reason field for ALPR searches must identify the law enforcement purpose for the search and that &#039;TBD&#039; is not an acceptable entry.&quot; The spokesperson added: &quot;The presence of &#039;TBD&#039; in the reason field in prior searches should not, by itself, be interpreted to mean that the associated search was conducted without a legitimate law enforcement purpose or that reasonable suspicion was required.&quot; EFF has asked the agency to clarify whether it verified the hundreds of &quot;TBD&quot; searches were legitimate, and we will update this post with a response if we receive one. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Fishers Police Department (Ind.) said that the detective that searched for “blah” has done so “when he has issues with the technology” and that the term “is used when he is actively using the technology to solve a criminal case, and the technology is not moving fast enough for him.” The department shared that “he has been told to use “test” in the future.”&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;The Cobb County Police Department (Ga.) acknowledged that &quot;TBD&quot; stood for &quot;To Be Determined&quot; and is no longer an acceptable search reason: &quot;We have instituted a new policy that took place after the dates listed in your audit that now require, in addition to a criminal offense and a reason, a case number for any search conducted on FLOCK.&quot; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;The San Diego County Sheriff&#039;s Department says that it checked the cases where &quot;idk&quot; was used and determined &quot;there was an active investigation associated with the searches.&quot; The department said that this was due to the reason field being optional at the time (which was true on a software level) but California law has required officers to document a purpose for accessing ALPR data &lt;/span&gt;&lt;a href=&quot;https://calmatters.digitaldemocracy.org/bills/ca_201520160sb34&quot;&gt;&lt;span&gt;since 2015&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. The sheriff&#039;s spokesperson says the reason field is now mandatory, and involves a dropdown menu. &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span&gt;Other agencies did not respond to EFF’s requests for comment. We will update with responses as they are received.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;The Cop Out of the Drop-Down Menu “Feature Update”&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Under the guise of streamlining audit logs, in late 2025, Flock safety &lt;/span&gt;&lt;a href=&quot;https://www.flocksafety.com/blog/offense-type-dropdown-a-simpler-more-accurate-audit&quot;&gt;&lt;span&gt;announced&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that they will be replacing the required, free-text search “reasons” with a pre-populated dropdown menu of generic offense categories. Since this update, officers are no longer required to type out why they are digging through a driver&#039;s movement history, and instead can select a pre-packaged option like &quot;Traffic infraction&quot; or “Other” in half a second. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Replacing the requirement to articulate the reason for the search with one-click searches is a loss for transparency, but also may explain why audit logs including the searches we highlight in this piece significantly decreased since early 2026. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;The Punchline is Our Privacy&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;&lt;img src=&quot;/files/2026/09/14/flock_newer_model.png&quot; width=&quot;1273&quot; height=&quot;849&quot; alt=&quot;Two Flock cameras and a solar panel on a light pole. &quot; title=&quot;Two Flock cameras and a solar panel on a light pole. &quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Entries like these defeat transparency, undermine accountability, and entirely fail to satisfy what many jurisdictions require by law or policy: an actual reason for the search. And this keeps happening because police use ALPRs as a convenient shortcut around constitutional privacy safeguards. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In other contexts, such as &lt;/span&gt;&lt;a href=&quot;https://www.supremecourt.gov/opinions/25pdf/25-112_0am4.pdf&quot;&gt;&lt;span&gt;searches of cell phone location information&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, police have to go to a judge, demonstrate probable cause, and get a search warrant. But because laws and courts have not caught up with the pace of ALPR technology, police do not do the same before searching ALPR databases. Instead, they are given free rein to track a person’s movements without a sliver of judicial oversight.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-school-residency-verification-background&quot;&gt;&lt;span&gt;we mention in our piece&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about the use of ALPR surveillance for low-level investigations, if a police chief stood in front of a city council and asked for permission to install hundreds of cameras just so his officers could investigate the high crime of &quot;haha,&quot; they would be laughed out of the room. The same could be said if an officer asked a judge to sign a warrant to track someone down for &quot;LOL.&quot;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The fact that these searches were not only missed by the agency supervising the officer, but by the often thousands of other agencies whose systems were searched, demonstrates how agencies cannot be trusted to oversee themselves. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Mass surveillance is incompatible with a free society, and especially so when the people with access to this data are treating it like a joke. This ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. But because it does, EFF continues to urge courts and state legislatures to immediately step in and impose strict, enforceable restrictions to rein in this abuse. At an absolute minimum, this means mandating rigid data deletion deadlines and an ironclad warrant requirement. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If police want the power to track a person&#039;s movements, they must be required to convince a judge with evidence and probable cause. They should not be able to bypass the Constitution with a search for &quot;haha.&quot;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 14 Sep 2026 15:21:05 +0000</pubDate>
 <guid isPermaLink="false">112360 at https://www.eff.org</guid>
 <dc:creator>Rindala Alajaji</dc:creator>
 <dc:creator>Dave Maass</dc:creator>
 <dc:creator>Dave Maass</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/flock-dystopia-scene-1.png" alt="Flock cameras and surveillance cameras among barbed wire in a dystopian scene" type="image/png" length="153685" />
  </item>
  <item>
    <title>Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans</title>
    <link>https://www.eff.org/deeplinks/2026/09/governor-newsom-signs-student-backed-digital-literacy-bills-alongside-misguided</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/press/releases/we-all-deserve-better-internet-not-smaller-one&quot;&gt;&lt;span&gt;AB 1709&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billHistoryClient.xhtml?bill_id=202520260AB2071&quot;&gt;&lt;span&gt;AB 2071&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB2298&quot;&gt;&lt;span&gt;AB 2298&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which require that children learn critical digital literacy and cybersecurity topics. The bills are an affirmative and constitutional way for the state to address valid concerns about young people’s internet use &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/eff-ninth-circuit-young-people-have-first-amendment-right-use-social-media-and-all&quot;&gt;&lt;span&gt;without violating&lt;/span&gt;&lt;/a&gt;&lt;span&gt; their &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/states-tried-censor-kids-online-courts-and-eff-mostly-stopped-them-2025-review&quot;&gt;&lt;span&gt;First Amendment rights&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Unlike &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/how-and-why-fight-back-against-social-media-bans&quot;&gt;&lt;span&gt;blanket bans&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, A.B. 2071 and A.B. 2298 address online safety through education rather than prohibition. Young people rely on the internet not just for entertainment, but for &lt;/span&gt;&lt;a href=&quot;https://www.pbs.org/newshour/classroom/classroom-voices/student-voices/2020/11/student-voice-how-young-people-use-social-media-to-engage-civically&quot;&gt;&lt;span&gt;civic engagement&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.theguardian.com/australia-news/2026/may/19/australias-social-media-ban-preventing-teens-from-accessing-the-news-research-finds&quot;&gt;&lt;span&gt;education&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/03/thousands-young-people-told-us-why-kids-online-safety-act-will-be-harmful-minors&quot;&gt;&lt;span&gt;self-expression&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://news-decoder.com/social-media-bans-shut-door-to-those-who-lack-safe-spaces/&quot;&gt;&lt;span&gt;community&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—especially &lt;/span&gt;&lt;a href=&quot;https://www.lgbttech.org/post/lgbt-tech-leads-coalition-statement-in-opposition-to-age-minimum-social-media-bans&quot;&gt;&lt;span&gt;vulnerable youth&lt;/span&gt;&lt;/a&gt;&lt;span&gt; who may lack support in their physical surroundings. This is why real digital safety comes from preparation, not isolation. Research consistently shows that open, honest conversations about &lt;/span&gt;&lt;a href=&quot;https://www.psychologytoday.com/us/blog/positively-media/202305/why-proposed-social-media-bans-wont-keep-your-kids-safe&quot;&gt;&lt;span&gt;digital literacy&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and privacy with trusted adults are &lt;/span&gt;&lt;a href=&quot;https://www.npr.org/2026/06/26/nx-s1-5843233/a-psychologist-makes-the-case-against-social-media-bans-for-kids&quot;&gt;&lt;span&gt;far more effective&lt;/span&gt;&lt;/a&gt;&lt;span&gt; at protecting youth than restrictive censorship laws. Young people themselves recognize this need; in fact, A.B. 2071 was &lt;/span&gt;&lt;a href=&quot;https://edsource.org/2026/social-media-ai-mental-health/755990&quot;&gt;&lt;span&gt;co-authored by a group of students&lt;/span&gt;&lt;/a&gt;&lt;span&gt; actively seeking better resources to navigate their digital lives safely.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Education vs. Censorship &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;A.B. 2071 and A.B. 2298 fill critical gaps in California’s school curricula by equipping students with actionable skills. A.B. 2071 integrates digital wellness into middle and high school health classes, teaching students how to identify unhealthy tech habits, protect their personal safety, and evaluate digital content—including AI-generated media—for credibility and bias. Meanwhile, A.B. 2298 adds cybersecurity concepts to recommended school curricula, teaching young people how to safeguard their personal data from online threats.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;While &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/press/releases/we-all-deserve-better-internet-not-smaller-one&quot;&gt;&lt;span&gt;the state’s turn toward social media bans&lt;/span&gt;&lt;/a&gt;&lt;span&gt; remains a harmful and misguided policy direction, the passage and signing of A.B. 2071 and A.B. 2298 show there is a better way. Lawmakers must stop treating censorship as a quick fix and instead focus on constitutional, empowering solutions that give youth the tools they need to thrive online. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 11 Sep 2026 20:25:57 +0000</pubDate>
 <guid isPermaLink="false">112357 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <dc:creator>Chao Liu</dc:creator>
 <dc:creator>Rindala Alajaji</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/youth-3.jpg" alt="young EFF&amp;#039;ers show phones with security icons" type="image/jpeg" length="718308" />
  </item>
  <item>
    <title>Cold TAKE: Amazon&#039;s New Encryption Method Still Doesn&#039;t Deliver Real Privacy</title>
    <link>https://www.eff.org/deeplinks/2026/09/cold-take-amazons-new-encryption-method-still-doesnt-deliver-real-privacy</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Amazon recently debuted a new feature for its Ring cameras that the company is calling &lt;/span&gt;&lt;a href=&quot;https://www.aboutamazon.com/news/devices/ring-take-encryption&quot;&gt;&lt;span&gt;Throw Away the Key Encryption&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn’t deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;TAKE introduces a new way for Ring to manage encryption keys, where the user’s device has its key, then the company holds encryption keys temporarily within its own cloud infrastructure. Ring’s servers receive the keys temporarily so it can offer a variety of the features it says it can’t offer when a user chooses to use end-to-end encryption, like video descriptions, smart alerts, video search, &lt;/span&gt;&lt;a href=&quot;https://ring.com/support/articles/7e3lk/using-video-end-to-end-encryption-e2ee&quot;&gt;&lt;span&gt;and more&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, then deletes the key after 24 hours. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This differs from how it works now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Comparatively, this is an improvement to the default settings Ring has now, because it at least puts some restrictions on historical footage, but it has some serious holes worth exploring.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Ring Gets Access to Unencrypted Video for a Short Period&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Ring has designed its service so many of its camera features, including smart alerts and video search, need cloud processing to work. That means to provide those features, Ring needs to decrypt the footage while it’s stored in Ring’s cloud servers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;With TAKE, in order to decrypt footage to offer these features, Ring gets access to footage stored in the cloud for 24 hours. TAKE adds some small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, the cloud processing does its thing and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys. The client device essentially takes the place of a &lt;/span&gt;&lt;a href=&quot;https://docs.cloud.google.com/docs/security/cloud-hsm-architecture&quot;&gt;&lt;span&gt;hardware security module (HSM)&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, including making those keys available to the server whenever they’re needed. The end result is an improvement from the status quo, but still not even close to the privacy protections of &lt;a href=&quot;https://ssd.eff.org/glossary/end-to-end-encryption&quot;&gt;end-to-end encryption&lt;/a&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The company says it does not keep backups of the keys and there’s no way for a Ring employee to access footage. It also claims that any decrypted content is deleted from its servers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But that doesn’t mean much when user actions send the keys back to the server. And making features like “Video Search” and “Smart Video Descriptions” available to the device owner means that while the footage can’t be seen by Ring, descriptions are readily available to the company. In response to a question about capability, Ring responded to us that, “As Ring continues to expand and further strengthen TAKE&#039;s protections, video descriptions will be included.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Plus, account recovery keys are stored in the camera itself by default. When that’s paired with the fact that currently, indices of video contents are available to the company, it means that TAKE isn’t even a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest from the device-owner, decrypting account backups, and using that information to decrypt encrypted videos. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Law Enforcement May Still Seek to Compel Access to Footage&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Because of the ways the access and key rotations work, it’s technically still possible for Ring to alter its current practice if compelled to do so by law enforcement, in much the same way as other existing encryption-at-rest systems where the company holds the keys. For example, Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they’d retain some level of access. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In an email to EFF, Ring stated, “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring&#039;s policy to object to overbroad legal requests.” EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;End-to-end encryption works to maintain trust by its user base because the company that employs it never has access to the keys at any point, making it impossible for itself to access the encrypted contents. This also means law enforcement can’t demand the service retain keys or choose not to rotate them. As described, this level of protection isn’t offered with TAKE.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Ultimately, Ring is the one managing this software and its implementation, and beyond a white paper, “trust us” is the only level of verification they’re offering outside observers. While it doesn’t fix the issues, at the bare minimum, the company needs to open the entire infrastructure up to third-party auditors to verify its claims. Ring seems to agree, as they told us that, “Ring conducts rigorous security reviews of all products before launch and critical components of TAKE’s infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn’t claim it as such. Ring already offers the option for end-to-end encryption, and &lt;/span&gt;&lt;a href=&quot;https://encryptitalready.org/&quot;&gt;&lt;span&gt;turning that on by default&lt;/span&gt;&lt;/a&gt;&lt;span&gt; would offer the real sorts of privacy improvements we all want from video doorbells. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 11 Sep 2026 16:56:34 +0000</pubDate>
 <guid isPermaLink="false">112356 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/law-enforcement-access">Law Enforcement Access</category>
 <category domain="https://www.eff.org/issues/mass-surveillance-technologies">Surveillance Technologies</category>
 <dc:creator>Erica Portnoy</dc:creator>
 <dc:creator>Thorin Klosowski</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ring_banner.png" alt="The shadow of a police officer looms in front of a Ring device on a closed door." type="image/png" length="82172" />
  </item>
  <item>
    <title>We All Deserve a Better Internet, Not A Smaller One  </title>
    <link>https://www.eff.org/press/releases/we-all-deserve-better-internet-not-smaller-one</link>
    <description>&lt;div class=&quot;field field--name-field-pr-subhead field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Bans Like California’s Don’t Fix What’s Wrong With Social Media Companies &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;SAN FRANCISCO - Technology and the laws that regulate it should support and empower young people. California’s AB 1709 - signed into law today by Gov. Gavin Newsom - falls far short of this goal, say the Electronic Frontier Foundation (EFF) and its allies.  &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Using technology is how we learn and build community in today’s world. Laws such as AB 1709, a functional ban on social media use for people under the age of 16, instead cut young people off from essential information and experiences. That particularly harms those already facing increased challenges, who often find safety in supportive online communities that they can’t always access in the physical world. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;&quot;California should be passing laws to ensure that technology really works for people of all ages, not enacting social media bans that cut young people off from digital lifelines, communities, and speech,&quot; said EFF Associate Director of State Affairs Rindala Alajaji. &quot;Denying minors access to digital forums - or stripping out basic tools needed to navigate them - is not going to help make young people safer or healthier in the AI age.&quot; &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Research shows social media bans are ineffectual, while also denying young people opportunities to develop their own voices and perspectives—to share their art, practice religion or engage in politics.  &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Age-gating requirements also force everyone to give up more personal information. To verify who can pass through their online gates, companies will collect even more data, and this further concentrates power in the hands of companies, rather than protecting people. &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;AB 1709 is also inconsistent with rights to free expression and California will be spending resources to defend a law tied up in court. Instead, we should redouble our efforts to get technology law&lt;/span&gt;&lt;span&gt;s&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt; right—and support the passage of new robust privacy laws that target surveillance business models. That’s how we protect everyone in the AI age.  &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Young people should be able to use technology in safe and healthy ways. The Golden State should model the gold standard laws that ensure technology works for everyone, rather than shut down access to digital forums in ways that do more harm than good.&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;&quot;Social media bans like AB1709 make kids less safe, while undermining privacy and freedom of expression for everyone,” said Evan Greer, Director of &lt;/span&gt;&lt;a href=&quot;https://www.fightforthefuture.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Fight for the Future&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. “Young people have been on the forefront of every social movement throughout history that has led to positive social change. We need policies that empower young people rather than silencing them. These kid-focused bans are a gift to Big Tech giants, allowing them to continue operating their harmful business model while incentivizing them to collect even more data. California lawmakers should be ashamed. They didn&#039;t do anything to protect the kids, they just used kids as pawns to make good headlines.&quot; &lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;“In a world of increasing stigma and marginalization for LGBTQ+ families, AB 1709 continues that trend by stripping people with LGBTQ+ parents of the ability to meet and build community with one another on the internet” said Jordan Wilson, Executive Director of &lt;/span&gt;&lt;a href=&quot;https://www.colage.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;COLAGE&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. “Beyond obstructing the right of youth with LGBTQ+ parents to access information, this bill places an undue burden on all Californians by forcing age verification at a time when digital privacy rights are being eroded globally. We cannot ‘protect children’ by stripping them of their primary avenue for connection.”&lt;/span&gt;&lt;span data-ccp-props=&quot;0}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-contact field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Contact:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;div  class=&quot;ds-1col node node--profile view-mode-node_embed node--node-embed node--profile--node-embed clearfix&quot;&gt;

  
  &lt;div class=&quot;&quot;&gt;
    &lt;div class=&quot;field field--name-field-profile-first-name field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Rindala&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-last-name field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Alajaji&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-title field--type-text field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;Associate Director of State Affairs&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-profile-email field--type-email field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;mailto:rin@eff.org&quot;&gt;rin@eff.org&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;  &lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 10 Sep 2026 19:12:08 +0000</pubDate>
 <guid isPermaLink="false">112330 at https://www.eff.org</guid>
 <dc:creator>Josh Richman</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  <item>
    <title>Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR    </title>
    <link>https://www.eff.org/deeplinks/2026/09/cops-play-hide-and-seek-about-using-spy-tech-avoid-scrutiny-and-bad-pr</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Law enforcement agencies across the country are increasingly relying on spying technologies—&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/02/effecting-change-get-flock-out-our-city&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;automated license plate readers&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; (ALPR), &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/cell-site-simulators&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cell-site simulators&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/police-use-face-recognition-continues-wrack-real-world-harms&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;facial recognition&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, to name a few--causing an outcry in many communities where people are rightly concerned about the threat to civil rights and civil liberties these tools present.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;Some authorities are responding to these concerns by trying to hide what they’re doing. Police departments are telling officers not to mention ALPRs when stopping vehicles and concealing their use of ALPRs to avoid citizens’ public records requests. Concealing the use of unpopular spying tools isn’t anything particularly new for law enforcement—cops have been doing it for years—but it’s just as wrong now as it was 20 years ago.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;These practices prevent the public from knowing about and questioning how agencies are spending taxpayer dollars on spying technologies and holding them accountable. This is especially troubling when many towns are signing contracts with Flock and other ALPR vendors with little to no public oversight. The practice also violates disclosure obligations, allows cops and prosecutors to hide their tactics from judges, and cheats defendants from being able to challenge the use of evidence gathered by spy tech from being used against them.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;404 Media recently &lt;/span&gt;&lt;a href=&quot;https://www.404media.co/do-not-mention-alpr-usage-how-cops-are-trying-to-hide-the-existence-of-flock/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;revealed&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; that in its usage policy for Flock ALPR cameras, one county in Iowa tells police to keep them a secret when detaining people: &lt;/span&gt;&lt;span data-contrast=&quot;auto&quot;&gt;“DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” If writing a report about an incident, police are told to say they used “county resources” in making a stop instead of acknowledging use of ALPRs.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;In Houston, police officers are likewise instructed to &lt;/span&gt;&lt;a href=&quot;https://www.404media.co/police-told-to-be-as-vague-as-permissible-about-why-they-use-flock/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;“be as vague as permissible”&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; about why they are using Flock because the searches they run on Flock’s surveillance system could be obtained via public records requests.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;There is growing public alarm about the threat to civil liberties posed by ALPR cameras and reports of police abusing the tech by &lt;/span&gt;&lt;a href=&quot;https://wisconsinwatch.org/2026/08/wisconsin-sheboygan-flock-safety-cameras-covered-up-police-license-plate-reader/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;using it to spy on their exes&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Some cities have the cameras &lt;/span&gt;&lt;a href=&quot;https://wisconsinwatch.org/2026/08/wisconsin-sheboygan-flock-safety-cameras-covered-up-police-license-plate-reader/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;covered up&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and others are &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/procurement-power-when-cities-realized-they-can-just-say-no-2025-review&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;cancelling&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; their use of ALPR networks. Two states have recently &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/09/texas-and-florida-step-back-alprs&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;stepped back&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; from ALPRs. This trend is certainly not lost on law enforcement agencies. Hiding the fact that they’re using ALPRs from Flock and other vendors is one way of avoiding scrutiny and bad PR.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;But law enforcement and their spy tech vendors keeping people in the dark about the surveillance technologies trained on them predates the Flock backlash by decades. For example, AT&amp;amp;T built a powerful phone surveillance tool for police, called Hemisphere, in the mid 2000s, and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2016/10/att-requires-police-hide-hemisphere-phone-spying&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;the company required agencies&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; not to use evidence gathered by Hemisphere in court unless there was no other admissible evidence. If evidence obtained through Hemisphere was used, police were required to recreate it through a traditional subpoena, a process they called &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2018/12/and-after-what-we-learned-about-hemisphere-program-after-suing-dea&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;“parallel construction.”&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; We called it “evidence laundering.”&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;Likewise, police and prosecutors have taken far-reaching steps to hide from the public and courts their use of cell site simulators, also known as stingrays. Police have used these devices, which trick cell phones into connecting to them instead of phone towers to try locating suspects, to obtain people’s location data without a warrant by &lt;/span&gt;&lt;a href=&quot;https://sls.eff.org/technologies/cell-site-simulators-imsi-catchers&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;deceptively obtaining&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; basic pen register orders from courts. Pen register orders are for obtaining call log data and police don’t need to prove they have probable cause to get one.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;In Baltimore, for example, a judge concluded that law enforcement had used a standard pen register order &lt;/span&gt;&lt;a href=&quot;https://www.aclu.org/documents/state-v-andrews-stingray-june-4-2015-transcript?redirect=state-v-andrews-stingray-june-4-2015-transcript&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;to intentionally hide its use of a Stingray&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; from the court in violation of its legal disclosure obligations, leading to a landmark 2015 privacy ruling that cops need a warrant to use the device.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;That didn’t stop police from continuing to try to pull the wool over the eyes of courts and defense attorneys when they used stingrays, however. &lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;Prosecutors have &lt;/span&gt;&lt;a href=&quot;https://www.washingtonpost.com/world/national-security/secrecy-around-police-surveillance-equipment-proves-a-cases-undoing/2015/02/22/ce72308a-b7ac-11e4-aa05-1ce812b3fdd2_story.html&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;accepted plea deals&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; to hide their use of cell-site simulators and have even &lt;/span&gt;&lt;a href=&quot;http://arstechnica.com/tech-policy/2015/04/fbi-would-rather-prosecutors-drop-cases-than-disclose-stingray-details/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;dropped cases&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; rather than reveal information about their use of the technology. U.S. Marshalls have &lt;/span&gt;&lt;a href=&quot;https://arstechnica.com/tech-policy/2014/06/us-marshals-step-in-thwart-efforts-to-learn-about-cell-tracking-devices/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;driven files hundreds of miles&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; to thwart public records requests.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;Fortunately, our commitment to shining a light on the use of surveillance tech is just as strong, if not stronger, than law enforcement’s quest to hide it. We’re working with privacy advocates and community groups to bring awareness about existing and emerging spy tools that threaten civil liberties and we’re encouraging policymakers and lawmakers to do more to restrain warrantless mass surveillance and stop it before it ever takes hold. &lt;/span&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;300}&quot;&gt;If you&#039;re curious about whether your local police have contracts for ALPRS or other surveillance technologies, you can search EFF&#039;s &lt;a href=&quot;https://www.atlasofsurveillance.org/&quot;&gt;Atlas of Surveillance.&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 09 Sep 2026 20:09:10 +0000</pubDate>
 <guid isPermaLink="false">112347 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/mass-surveillance-technologies">Surveillance Technologies</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Karen Gullo</dc:creator>
 <dc:creator>Adam Schwartz</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/flock-dystopia-scene-1.png" alt="Flock cameras and surveillance cameras among barbed wire in a dystopian scene" type="image/png" length="153685" />
  </item>
  <item>
    <title>Digital Sovereignty: What It Is, What It Could Be</title>
    <link>https://www.eff.org/deeplinks/2026/09/digital-sovereignty-what-it-what-it-could-be</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about &lt;/span&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada&quot;&gt;&lt;span&gt;cloud infrastructure, AI&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/proposal-chips-act-20&quot;&gt;&lt;span&gt;semiconductors&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and platform regulation. Governments throughout the global majority use it to &lt;/span&gt;&lt;a href=&quot;https://www.usatoday.com/story/opinion/2024/03/18/tiktok-sale-ban-chinese-government-us-security/72988111007/&quot;&gt;&lt;span&gt;argue for greater control&lt;/span&gt;&lt;/a&gt;&lt;span&gt; over data and communications infrastructure and boost their economies. Companies market “&lt;/span&gt;&lt;a href=&quot;https://www.ibm.com/think/topics/sovereign-cloud&quot;&gt;&lt;span&gt;sovereign cloud&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” products designed to reassure their customers that their information stays under local jurisdiction. But digital sovereignty could be something more: an opportunity for users around the world to build more resilient, open  systems and the skills and infrastructure to maintain them.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There is no singular definition of digital sovereignty, nor is there a single coherent position in the digital rights space. Despite its growing popularity, the term remains frustratingly vague. Policymakers, regulators, civil society groups, and others can mean very different things when they use the term. But to start simply with a broad definition, we can say that it means having the capacity to control one’s digital destiny—though the implications of that will obviously differ considerably whether you’re talking about an individual or a country.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;We can start by developing  a shared understanding of what digital sovereignty actually means. We’ve also included a glossary of terms at the bottom of this post. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In Europe and other places where digital sovereignty has become a topic of policy, discussions focus on reducing dependency: on foreign (and particularly American) cloud infrastructure, chips, platforms, and at times, foreign political priorities. The concern is both economic and geopolitical. If essential infrastructure is controlled by companies elsewhere—and thus subject to the laws of another jurisdiction—then what control does a country actually have over its own digital future?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In global majority countries in particular, wars, sanctions, and the growing fragmentation of the internet have demonstrated for many that the physical infrastructure that underlies digital life is neither neutral nor invulnerable. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Amidst this increasing geopolitical instability governments and civil society should consider whether digital sovereignty can help shore up that infrastructure. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;What are we talking about when we talk about digital sovereignty? &lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;A recent &lt;/span&gt;&lt;a href=&quot;https://www.entreprises.gouv.fr/files/files/presse/2026/20260617-franco-german-joint-paper-digital-on-sovereignty.pdf&quot;&gt;&lt;span&gt;Franco-German joint paper&lt;/span&gt;&lt;/a&gt;&lt;span&gt; on digital sovereignty defines it as the “capability and capacity to develop, provide, use, adapt and control digital technologies including hardware in an independent, self-determined and secure manner” and puts forward a framework to operationalize Europe’s capacity to act in the digital domain. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Some governments, such as Germany’s, have started to put funding behind sovereignty efforts through initiatives like the&lt;/span&gt;&lt;a href=&quot;https://www.sovereign.tech/programs/fund&quot;&gt;&lt;span&gt; Sovereign Tech Agency&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which “invest[s] globally in the open software components that underpin Germany&#039;s and Europe&#039;s competitiveness and ability to innovate.” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Positions on digital sovereignty among EFF’s allies across Europe vary.&lt;/span&gt;&lt;a href=&quot;https://www.openrightsgroup.org/&quot;&gt; &lt;span&gt;Open Rights Group&lt;/span&gt;&lt;/a&gt;&lt;span&gt; have &lt;/span&gt;&lt;a href=&quot;https://www.openrightsgroup.org/publications/tech-giants-and-giant-slayers-the-case-for-digital-sovereignty-and-the-digital-commons/&quot;&gt;&lt;span&gt;defined digital sovereignty&lt;/span&gt;&lt;/a&gt;&lt;span&gt; as “the ability of a country to have control over its digital infrastructure, data, and technology” and states it to be “critical for the UK’s economic and national security.” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Similarly, the European Partnership for Democracy has&lt;/span&gt;&lt;a href=&quot;https://www.techpolicy.press/if-europe-wants-digital-sovereignty-it-must-reinvent-who-owns-tech/&quot;&gt; &lt;span&gt;expressed concern&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that “a few Big Tech corporations decide our collective destiny,” and argue that the EU should explore “alternative ownership models for tech companies and clearly [define] their purpose and mission.” And our friends at&lt;/span&gt;&lt;a href=&quot;https://edri.org/&quot;&gt; &lt;span&gt;EDRi&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (of which EFF is a member) have&lt;/span&gt;&lt;a href=&quot;https://edri.org/our-work/europes-digital-sovereignty-starts-with-open-source/&quot;&gt; &lt;span&gt;stated clearly&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that “Europe’s digital sovereignty starts with open source.” Some initiatives, such as &lt;/span&gt;&lt;a href=&quot;https://di.day/en/partners&quot;&gt;&lt;span&gt;DI.DAY&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, consider digital sovereignty an opportunity to free users from Big Tech dependencies.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Elsewhere in the world, conversations about digital sovereignty often take a different shape. Indigenous&lt;/span&gt;&lt;a href=&quot;https://www.digitalinclusion.org/blog/indigenous-digital-sovereignty/&quot;&gt; &lt;span&gt;discussions&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of the topic have been ongoing for more than a decade and focus on the inherent right of Native nations to govern their own digital ecosystems. In Southeast Asia, the desire for digital sovereignty has &lt;/span&gt;&lt;a href=&quot;https://techwireasia.com/2025/12/digital-sovereignty-ibm-ceo-mandate-asia-pacific/&quot;&gt;&lt;span&gt;created growth&lt;/span&gt;&lt;/a&gt;&lt;span&gt; in the sovereign cloud industry, but the conversation isn’t purely economic: &lt;/span&gt;&lt;a href=&quot;https://www.computerweekly.com/opinion/Why-Asia-needs-its-own-model-of-digital-sovereignty&quot;&gt;&lt;span&gt;Concerns about jurisdiction&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for where data is held are driving much of the conversation. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In Latin America,&lt;/span&gt;&lt;a href=&quot;https://www.opendemocracy.net/en/south-america-big-tech-brazil-chile-data-centres-united-states/&quot;&gt; &lt;span&gt;digital public infrastructure&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is often a key aspect of debates. Across Africa, leaders &lt;/span&gt;&lt;a href=&quot;https://africarenewal.un.org/en/magazine/africa-pushes-data-sovereignty-and-digital-independence%3Fdebt%3Ddebt&quot;&gt;&lt;span&gt;speak&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of a desire to shift the continent from being consumers of technology to becoming architects of their own digital infrastructure and data ecosystems. And in the Middle East and North Africa, concerns about reliance on U.S. technology companies—which have &lt;/span&gt;&lt;a href=&quot;https://www.iiss.org/online-analysis/charting-middle-east/2026/04/the-proliferation-of-ai-enabled-military-technology-in-the-middle-east/&quot;&gt;&lt;span&gt;engaged in conflict&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and disproportionate censorship (&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/05/amid-systemic-censorship-palestinian-voices-facebook-owes-users-transparency&quot;&gt;&lt;span&gt;particularly of Palestinian voices&lt;/span&gt;&lt;/a&gt;&lt;span&gt;) in the region—are often paramount.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Reem Almasri, a senior researcher based in Jordan, recently&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/digital-hopes-real-power-connection-collective-action&quot;&gt; &lt;span&gt;spoke to EFF&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about digital sovereignty, which she sees as “the ability of people and communities to choose, control, and use technology that serves their needs and values,” particularly in light of the role that U.S. companies have played in regional conflicts.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;In a January&lt;/span&gt;&lt;a href=&quot;https://untoldmag.org/digital-sovereignty-cloud/&quot;&gt; &lt;span&gt;article&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, Almasri pointed to growing concerns about granting greater sovereignty and influence to governments over citizens’ data, communications, and websites, writing: “This is particularly worrisome in countries that impose high levels of internet and media censorship and run unaccountable surveillance programs on their citizens’ data.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Indeed, while pushing for greater sovereignty from Big Tech has benefits, there is an inherent risk that some states will pursue digital sovereignty as a means of cutting off or &lt;/span&gt;&lt;a href=&quot;https://www.theguardian.com/world/2026/feb/21/splinternet-online-shutdowns-are-getting-cheaper-and-easier-to-impose-iran-blackout&quot;&gt;&lt;span&gt;splintering access&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—as we’ve already seen in Iran, Russia, and elsewhere.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For that reason, it’s no surprise that some, such as Iranian professor Azadeh Akbari,&lt;/span&gt;&lt;a href=&quot;https://www.techpolicy.press/irans-case-should-put-an-end-to-illusions-about-digital-sovereignty/&quot;&gt; &lt;span&gt;believe that&lt;/span&gt;&lt;/a&gt;&lt;span&gt; “the current wave pushing digital sovereignty as the key to ending dependency on American and Chinese technology is negligent of its Eurocentric bias.” &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;What does EFF believe?&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;In a world where people have digital sovereignty, civil society should be able to communicate freely, privately, and anonymously if they wish. People should be able to easily understand where their data lives and who has access to it. That data should be easily portable between platforms and services.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;At EFF, we view digital sovereignty not as a walled garden, but as an opportunity for resilience and development of industries and skills. We believe that governments can and should take a role in crafting digital sovereignty that centers the autonomy of users rather than just re-creating a state of digital dependency with a new set of companies. Governments should support and use free and open source tools and projects built using principles of interoperability and data portability. This support should include employing full-time developers, UX designers, and community managers. Government policy and legislation should grant users control of their own data and a clear understanding of who can lawfully access it. Digital sovereignty should &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/dos-and-donts-eus-digital-fairness-act-effs-recommendation-regulating-digital&quot;&gt;&lt;span&gt;foster users’ ability&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to choose how they use digital products and services, free from unfair lock-ins, coercive terms and manipulative defaults. It should also foster the broader &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/issues/public-interest-internet&quot;&gt;&lt;span&gt;public interest internet&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the part of the web that provides public goods and useful services without requiring the scale or the business practices of the tech giants.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Encryption backdoors are fundamentally incompatible with a vision of data sovereignty that centers user control. Governments should support the development and normalization of reputable end-to-end encrypted communications as well as strong encryption for data at rest. This support should include employing cryptographers and contributing to strong, peer-reviewed encryption standards strengthened by data minimization as a fundamental design principle, as well as refraining from legislating mandates for “lawful access” or any other reason. &lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;As technologists, we don’t have to wait for governments to act in order to create the digital sovereignty we want. We get the internet that we build. We can contribute to open source, decentralized, and end-to-end encrypted projects. We can build standards that make interoperability and data portability a feature from the very beginning. We can resist the call of proprietary solutions, user lock-in, and encryption backdoors.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;And finally, while digital sovereignty is often framed as a response to the dominance of Big Tech, that does not mean that there is no role for private companies to play. There is no point in replacing the influence of a few mostly US-based tech companies with a handful of giants based elsewhere. Companies can and should build platforms and services on top of open source, decentralized protocols and contribute to the ecosystem. Companies should also &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/wp/privacy-first-better-way-address-online-harms#Legislation&quot;&gt;&lt;span&gt;minimize processing a person’s data&lt;/span&gt;&lt;/a&gt;&lt;span&gt; except as strictly necessary to provide them what they asked for, and only with opt-in consent that makes it clear to users what data they are gathering, where it is stored, and who has access to it. And companies should build their tools and platforms in a way that allows interoperability and that makes it easy for users to leave with their data. Some of these practices are already required by law in some jurisdictions, but companies don’t have to merely do the bare minimum the law demands: they should respect their users and support data sovereignty right now.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;A glossary of terms&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;The following terms are useful for understanding this blog post as well as the broader conversation about Digital Sovereignty:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Intermediary liability:&lt;/strong&gt; the legal responsibility of online service providers (ISPs, websites, social media platforms) for unlawful activities by their users, such as defamation, copyright infringement, or illegal hate speech.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;The stack:&lt;/strong&gt; a secure, open-source technology framework, often focusing on European alternatives, designed to break dependencies on (mostly) US-based technology providers. It comprises interoperable, vendor-neutral, and transparent digital infrastructures designed to regain control over data, infrastructure, and technology.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Digital sovereignty:&lt;/strong&gt; the ability of people, as nations, organizations, and individuals, to control their own digital destiny by retaining authority over their own data, technology, and infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Data sovereignty:&lt;/strong&gt; the principle that digital information is subject to the laws and governance frameworks of the country or region where it is physically collected, stored, or processed. It dictates that data remains bound by the specific privacy protections and regulations of its originating jurisdiction, regardless of where the collecting organization is located.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Digital commons:&lt;/strong&gt; a shared, online resource, such as knowledge, software, and data, that is collectively produced, governed, and maintained by a community, intended for public access. Examples include Wikipedia, open source operating systems such as Linux, and Creative Commons licensed content.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Data portability/interoperability:&lt;/strong&gt; the ability to easily transfer personal data from one service provider to another, or to a personal system, in a structured, machine-readable format. It empowers users to move away from &quot;walled gardens,&quot; reducing vendor lock-in and enhancing user autonomy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Digital dependency:&lt;/strong&gt; the opposite of digital sovereignty. The inability of people as nations, organizations, and individuals to control their own digital destiny through control over their own data, technology, and infrastructure. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Decentralization:&lt;/strong&gt; a shift away from relying on centralized, often US-based, corporate platforms toward a distributed, user-centric internet where individuals, communities, and nations maintain control over their data, digital identity, and infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;End-to-end encryption (e2ee):&lt;/strong&gt; a secure communication process where only the sender and intended recipient can access, read, or decrypt messages or data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;Fairness (à la the Digital Fairness Act):&lt;/strong&gt; the absence of deceptive, manipulative, or addictive design practices that distort consumer choice and exploit vulnerabilities. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;strong&gt;User sovereignty:&lt;/strong&gt; the concept that individuals possess absolute control over their personal data, digital identity, and online privacy, rejecting the centralization of power by large technology platforms. It emphasizes user consent, decentralization, and the ability to manage personal data using secure and independent tools.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 09 Sep 2026 18:04:27 +0000</pubDate>
 <guid isPermaLink="false">112349 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/end-end-encryption">End-to-End Encryption</category>
 <category domain="https://www.eff.org/issues/security">Security</category>
 <dc:creator>Jillian C. York</dc:creator>
 <dc:creator>Eva Galperin</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/digital-sovereignty-1c_0.jpg" alt="a series of multi-colored hands (green, purple, etc) hold a series of multi-colored flags" type="image/jpeg" length="64719" />
  </item>
  <item>
    <title>2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights </title>
    <link>https://www.eff.org/deeplinks/2026/09/2026-eff-award-winners-access-now-7amleh-arab-center-advancement-social-media</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;EFF is pleased to announce that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights have received 2026 EFF Awards for their vital work in ensuring that technology supports freedom, justice, and innovation for all people.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The EFF Awards recognize specific and substantial technical, social, economic, or cultural contributions in diverse fields including journalism, art, digital access, legislation, technology development, and law.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/awards/past-winners&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;For the past 30 years&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, the EFF Awards—previously known as the Pioneer Awards—have recognized and honored key leaders in the fight for freedom and innovation online. Started when the internet was new, the Awards now reflect the fact that the online world has become both a necessity in modern life and a continually evolving set of tools for communication, organizing, creativity, and increasing human potential. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Supporting a global community advancing digital rights, defending digital access in crisis zones, empowering communities to take action against surveillance, and providing free legal assistance for creators and consumers to fight back against digital threats are high callings that help bring about a better tech future for all. We are pleased to honor these organizations with 2026 EFF Awards.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;Access Now – Fostering Change in Human Rights and Technology &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;img src=&quot;/files/2026/09/01/access_now_logo-primary.png&quot; width=&quot;1454&quot; height=&quot;280&quot; alt=&quot;Access Now logo&quot; title=&quot;Access Now logo&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.accessnow.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Access Now&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, founded in 2009 as an emergency response team helping Iranian activists get back online and communicate safely, has grown into one of the world’s foremost organizations defending and extending the digital rights of people and communities at risk and supporting the global fight against technological repression. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Its 24/7 &lt;/span&gt;&lt;a href=&quot;https://www.accessnow.org/help&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Digital Security Helpline&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; offers real-time, direct technical assistance and advice to civil society groups and activists, media organizations, journalists and bloggers, and human rights defenders. It provides grants to frontline organizations working with people and communities most impacted by digital rights violations. It educates decision makers and pressures the powerful. And it organizes &lt;/span&gt;&lt;a href=&quot;https://www.rightscon.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;RightsCon&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, a leading annual summit on human rights in the digital age, where activists, technologists, policymakers, business leaders, journalists, philanthropists, researchers, and artists can connect, collaborate, and drive change at the intersection of human rights and technology. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;7amleh – The Arab Center for the Advancement of Social Media – Defending and Advancing Digital Access and Rights Across the MENA Region&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;/files/2026/09/01/7amleh_logo_green_cropped.jpg&quot; width=&quot;1491&quot; height=&quot;550&quot; alt=&quot;7amleh logo&quot; title=&quot;7amleh logo&quot; /&gt;&lt;a href=&quot;https://7amleh.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;7amleh - The Arab Center for the Advancement of Social Media&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; protects and expands digital access and rights for Palestinians and across the MENA region. The nonprofit investigates and monitors challenges to digital rights, focusing on internet access, privacy, freedom of expression and association online. It builds the capacity of activists, human rights defenders, and civil society organizations to provide training about digital rights, gender sensitive digital security, and effective online advocacy. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;7amleh also advocates for changes to the digital rights policies and practices of governments, corporations and other influential institutions and individuals locally, regionally and internationally. It plans and manages advocacy and awareness-raising campaigns and builds networks and coalitions to promote access to safe, fair and free online spaces. For example, 7amleh has led the #ReconnectGaza campaign, supported by dozens of international NGOs &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/03/eff-joins-7amleh-campaign-reconnectgaza&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;including EFF&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, to restore full internet access in Gaza – a crucial lifeline for residents, journalists, activists, and first responders. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;DeFlock – Exposing the ALPR Surveillance Network &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;img src=&quot;/files/2026/09/01/deflock-logo.jpg&quot; width=&quot;3594&quot; height=&quot;938&quot; alt=&quot;DeFlock logo&quot; title=&quot;DeFlock logo&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://deflock.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;DeFlock&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; is an open-source, volunteer-powered project that maps surveillance devices across the world, helping communities hold their governments and surveillance vendors accountable and understand where and how they&#039;re being watched. Founded in 2024 by software engineer and privacy advocate Will Freeman, DeFlock shines a light on the widespread use of automated license plate reader (ALPR) technology and the threats it poses to personal privacy and civil liberties. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;DeFlock resources help people request public records, speak to local lawmakers, and take action against ALPR surveillance. Its work has helped foster a national grassroots community of anti-surveillance activists fighting back against this dangerous surveillance technology. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;auto&quot;&gt;New Media Rights – Helping Creators Fight Back Against IP Bullies&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;&lt;img src=&quot;/files/2026/09/01/nmr_highresolution_logotransparent_background.png&quot; width=&quot;21600&quot; height=&quot;4432&quot; alt=&quot;New Media Rights logo&quot; title=&quot;New Media Rights logo&quot; /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://newmediarights.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;New Media Rights&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; (NMR) is a San Diego-based nonprofit program of California Western School of Law dedicated to defending digital rights through legal services, education, and public policy advocacy. Since its inception, NMR has been at the forefront of protecting creators, entrepreneurs, and internet users from digital threats such as copyright abuse, online harassment, and privacy violations.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;In addition to providing free legal assistance, NMR has produced hundreds of freely available video and written legal education guides for creators and consumers, including the &lt;/span&gt;&lt;a href=&quot;https://newmediarights.org/fairuse/index.php&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Fair Use App&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; for filmmakers and video creators. It has participated in regulatory proceedings on net neutrality, Digital Millennium Copyright Act anti-circumvention, and copyright reform. Its work has also helped support access to public information and greater business and government accountability.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 09 Sep 2026 16:00:33 +0000</pubDate>
 <guid isPermaLink="false">112334 at https://www.eff.org</guid>
 <dc:creator>Josh Richman</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/eff-awards-2023.png" alt="EFF Awards text on circuitboard texture" type="image/png" length="139073" />
  </item>
  <item>
    <title>New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment</title>
    <link>https://www.eff.org/deeplinks/2026/09/new-records-reveal-problems-medicares-ai-prior-authorization-experiment</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;EFF &lt;a href=&quot;https://www.eff.org/press/releases/eff-sues-answers-about-medicares-ai-experiment&quot;&gt;sued&lt;/a&gt; the government back in March for information about the &lt;a href=&quot;https://www.cms.gov/priorities/innovation/innovation-models/wiser&quot;&gt;Wasteful and Inappropriate Service Reduction (WISeR) model&lt;/a&gt;, a new Medicare program that uses AI to evaluate prior authorization requests for certain medical services. Today, we’re releasing approximately 1,000 pages of records obtained from the Centers for Medicare &amp;amp; Medicaid Services (CMS) through this litigation, including contracts with tech companies, internal status reports and providers’ complaints about the program. The documents (available &lt;a href=&quot;https://www.eff.org/cases/eff-v-cms&quot;&gt;here&lt;/a&gt;) show that WISeR has resulted in widespread delays and denials of care, operational chaos, and reports of patient harm.&lt;/p&gt;
&lt;h2&gt;Why We Sued for Records about WISeR&lt;/h2&gt;
&lt;p&gt;EFF filed the &lt;a href=&quot;https://www.eff.org/press/releases/eff-sues-answers-about-medicares-ai-experiment&quot;&gt;FOIA lawsuit&lt;/a&gt; to gain badly needed transparency into an experimental AI program that could jeopardize Medicare beneficiaries&#039; access to care. In January 2026, CMS launched the WISeR model, subjecting seniors in six states to AI-driven prior authorization decisions. Medical providers must now request permission before delivering certain medical treatments if they want assurance that Medicare will cover them. Private companies contracted by CMS evaluate the requests using AI. In the absence of rigorous safeguards, AI-driven prior authorization determinations can lead to unwarranted—and even discriminatory—delays or denials of necessary medical care. &lt;/p&gt;
&lt;p&gt;Little is known about the AI systems that WISeR vendors are using to process prior authorization requests. Although CMS says that a qualified human clinician must review all denials, &lt;a href=&quot;https://link.springer.com/article/10.1186/s41235-023-00529-3&quot;&gt;research&lt;/a&gt; &lt;a href=&quot;https://arc.aiaa.org/doi/10.2514/6.2004-6313&quot;&gt;has&lt;/a&gt; &lt;a href=&quot;https://link.springer.com/article/10.1007/s00146-025-02422-7&quot;&gt;shown&lt;/a&gt; that AI-generated recommendations often influence human decisions. And the design of the WISeR program creates a financial incentive for vendors to deny care, since they are paid for averted expenditures. Just months after the program launched, medical providers &lt;a href=&quot;https://www.marketwatch.com/story/a-new-medicare-program-that-uses-ai-for-prior-authorizations-is-hurting-patients-and-delaying-care-9e25b98b&quot;&gt;reported&lt;/a&gt; improper denials, administrative friction, and lengthy delays that have left patients &lt;a href=&quot;https://www.seattletimes.com/business/new-medicare-program-in-wa-leaves-patients-in-pain-awaiting-approvals/&quot;&gt;waiting in pain&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/document/exhibit-eff-v-cms-wiser&quot;&gt;EFF’s FOIA request&lt;/a&gt; sought records pertaining to the CMS contracts with WISeR software vendors; any tests for accuracy, bias, or hallucinations in vendors&#039; technology; and any audits, monitoring, or evaluation of WISeR and participating vendors.&lt;/p&gt;
&lt;h2&gt;CMS Documents Highlight Issues with the WISeR Model&lt;/h2&gt;
&lt;p&gt;CMS records obtained by EFF echo issues that medical providers, patient advocates, and lawmakers have &lt;a href=&quot;https://kffhealthnews.org/medicare/medicare-ai-prior-authorization-wiser-delays-errors/&quot;&gt;warned about&lt;/a&gt; since WISeR began. This includes long wait times, rampant technical failures, inappropriate denials, and harm to patients.&lt;/p&gt;
&lt;h3&gt;Delayed Responses to Prior Authorization Requests&lt;/h3&gt;
&lt;p&gt;CMS &lt;a href=&quot;https://www.cms.gov/priorities/innovation/files/document/wiser-model-frequently-asked-questions&quot;&gt;publicly states&lt;/a&gt; that WISeR vendors should respond to prior authorization requests within 72 hours, but records received by EFF show widespread delays. Internal status reports from the first few months of the program show that a significant number of prior authorization requests took far longer than 72 hours to resolve. One status report cites a prior authorization request that went unanswered for 83 days (&quot;&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records,&lt;/a&gt;&quot; page 234). These delayed responses can have serious consequences for patients. &lt;a href=&quot;https://healthcareuncovered.substack.com/p/ai-gatekeepers-in-medicare-wiser&quot;&gt;Medical providers reported&lt;/a&gt; that WISeR has delayed medically necessary care and &lt;a href=&quot;https://www.seattletimes.com/business/new-medicare-program-in-wa-leaves-patients-in-pain-awaiting-approvals/&quot;&gt;left patients in pain&lt;/a&gt; as they waited for approvals.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/08/timeliness-january-2026.png&quot; alt=&quot;&quot; width=&quot;974&quot; height=&quot;318&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Timeliness data for two WISeR vendors in January 2026 show that a significant number of requests did not receive a response within 72 hours (&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;, page 410)&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;h3&gt;Payment Methodology Provides Financial Incentive to Deny Care &lt;/h3&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.eff.org/cases/eff-v-cms&quot;&gt;released records&lt;/a&gt; confirm that WISeR’s payment methodology creates a financial incentive to deny care. Specifically, WISeR vendors are paid for requests that they deny (though not for denials reversed on appeal). This profit motive aggravates the risk that AI-assisted decision-making may unfairly deprive people of the services they need.&lt;/p&gt;
&lt;p&gt;CMS &lt;a href=&quot;https://www.cms.gov/priorities/innovation/files/document/wiser-model-frequently-asked-questions&quot;&gt;publicly claims&lt;/a&gt; that it safeguards against inappropriate denials by tying vendors’ payment rates to “quality scores,” which reflect the timeliness and accuracy of vendors’ decisions. However, the recently released &lt;em&gt;WISeR Data Reporting Guide&lt;/em&gt; shows that low quality scores reduce payments by only 5-10%.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/08/aqs-quality-multiplier.png&quot; alt=&quot;&quot; width=&quot;1608&quot; height=&quot;528&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;Impact of low quality scores on payment rates described in the WISeR Data Reporting Guide (&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;, page 99)&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;h3&gt;WISeR Vendors Have Denied Thousands of Prior Authorization Requests&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Documents obtained by EFF appear to &lt;/span&gt;&lt;span&gt;&lt;a href=&quot;https://www.risehealth.org/insights-articles/article/new-report-medicare-wiser-prior-authorization-pilot-program-causing-care-delays/&quot; title=&quot;https://www.risehealth.org/insights-articles/article/new-report-medicare-wiser-prior-authorization-pilot-program-causing-care-delays/&quot; data-outlook-id=&quot;402d9468-a984-4372-900a-e5e3edf8982e&quot;&gt;&lt;u&gt;support&lt;/u&gt;&lt;/a&gt;&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;&lt;a href=&quot;https://wpintelligence.washingtonpost.com/topics/2026/03/18/exclusive-medicares-ai-experiment-leads-delayed-care-some-seniors/&quot; title=&quot;https://wpintelligence.washingtonpost.com/topics/2026/03/18/exclusive-medicares-ai-experiment-leads-delayed-care-some-seniors/&quot; data-outlook-id=&quot;7b3cbe44-f24d-4618-aa45-6346f025de8b&quot;&gt;&lt;u&gt;reports&lt;/u&gt;&lt;/a&gt;&lt;/span&gt;&lt;span&gt; that WISeR vendors may be denying claims at &lt;a href=&quot;https://www.kff.org/patient-consumer-protections/prior-authorization-metrics-provide-new-insights-into-insurer-practices-but-gaps-remain/#7171f955-705e-4924-ac06-af3277569201&quot; data-outlook-id=&quot;152ab8d2-2ffb-40e4-9288-5e879111ef80&quot; title=&quot;https://www.kff.org/patient-consumer-protections/prior-authorization-metrics-provide-new-insights-into-insurer-practices-but-gaps-remain/#7171f955-705e-4924-ac06-af3277569201&quot;&gt;unusually&lt;/a&gt; &lt;a href=&quot;https://www.kff.org/medicare/medicare-advantage-insurers-deny-prior-authorization-requests-for-post-acute-care-at-substantially-higher-rates-than-the-overall-denial-rate/&quot; data-outlook-id=&quot;805556d1-2af3-481e-92e2-be90cc1af047&quot; title=&quot;https://www.kff.org/medicare/medicare-advantage-insurers-deny-prior-authorization-requests-for-post-acute-care-at-substantially-higher-rates-than-the-overall-denial-rate/&quot;&gt;high&lt;/a&gt; rates.&lt;/span&gt; Two companies alone denied 5,944 prior authorization requests in the first 3 months of the program. One company, Virtix, the vendor that CMS &lt;a href=&quot;https://delbene.house.gov/news/documentsingle.aspx?DocumentID=4426&quot;&gt;required to submit a Corrective Action Plan&lt;/a&gt;, denied more requests than it approved during this time period.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/08/decisions-received-march-2026.png&quot; alt=&quot;&quot; width=&quot;1554&quot; height=&quot;366&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;&lt;span&gt;Prior authorization decision data for two vendors in a March 30th, 2026 status report (&lt;/span&gt;&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;&lt;span&gt;, page 322)&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;h3&gt;Medical Provider Feedback Ties WISeR Delays to Patient Harm&lt;/h3&gt;
&lt;p&gt;Feedback from medical providers emphasize that WISeR delays have harmed patients. The &lt;a href=&quot;https://www.eff.org/cases/eff-v-cms&quot;&gt;released records&lt;/a&gt; include March 2026 responses to a feedback form about Innovaccer, the WISeR vendor processing requests for Ohio. Medical providers complained about a lack of communication, administrative issues, and long response times. Several responses emphasize that long response times from the WISeR vendor harmed patients (&quot;&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-feedback-survey-1&quot;&gt;WISeR FOIA Response - Feedback Survey Responses&lt;/a&gt;&quot;):&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;“We have patients calling our offices crying in pain because their procedures are being delayed while awaiting approvals or guidance tied to this model. A 3–4 day delay for necessary pain procedures is already difficult for vulnerable patients, but when providers cannot obtain answers for weeks, the situation becomes unacceptable.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“I HAVE HAD TO WATCH 3 PATIENTS CRY AT BEDSIDE FOR NOT HEARING BACK ON THEIR PRIOR AUTH FOR KYPHOPLASTY/VERTABRAL AUGMENTIATION PROCEDURE. THESE PATIENTS ARE IN DEEP PAIN.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“I have had cases submitted and waiting over 1 1/2 months for a UTN to be generated… In the meantime patients are having to be cancelled for surgeries they need. This is not acceptable they are severely hindering patient care.”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Rushed Rollout Amidst Widespread Technical Failures &lt;/h3&gt;
&lt;p&gt;CMS WISeR launched in January 2026, just six months after it was &lt;a href=&quot;https://www.cms.gov/newsroom/press-releases/cms-launches-new-model-target-wasteful-inappropriate-services-original-medicare&quot;&gt;announced&lt;/a&gt;. Despite warnings from both &lt;a href=&quot;https://www.aha.org/lettercomment/2025-10-23-aha-comments-cms-wiser-model&quot;&gt;medical providers&lt;/a&gt; and a vendor about insufficient preparation time, CMS chose not to delay the launch. &lt;/p&gt;
&lt;p&gt;Approximately a month before the launch, one of the vendors, Innovaccer, alerted CMS that it intended to go live with a version of its software that lacked full functionality and had not been fully tested. It cited several barriers to going live with full functionality, including changing requirements and expectations, unclear governance processes, and lack of time for end-to-end testing with the provider community (&quot;&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;,&quot;, page 216-217). Innovaccer said it would auto-affirm all prior authorization requests until it could develop full functionality and explained that “Given CMS&#039;s decision not to delay the model start date, auto-affirming is the only path available” (&quot;&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;,&quot; page 217).&lt;/p&gt;
&lt;p&gt;Innovaccer had not yet finished developing or testing some features several months into the program, according to an April 2026 status report. Innovaccer was not the only vendor who faced technical challenges before and after WISeR launched. Weekly status reports and provider feedback in the &lt;a href=&quot;https://www.eff.org/cases/eff-v-cms&quot;&gt;released records&lt;/a&gt; show widespread challenges associated with WISeR’s rushed rollout (for example, &quot;&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;&lt;em&gt;,&quot; &lt;/em&gt;pages 238 and 383).&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/08/innovaccer-april-challenges.png&quot; alt=&quot;&quot; width=&quot;1548&quot; height=&quot;246&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;A status report from April 6th, 2026 describes issues with incomplete solutions from Innovaccer (&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;, page 200)&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;h3&gt;More Urgent Medical Services Considered for Inclusion in Future Years of WISeR Model&lt;/h3&gt;
&lt;p&gt;In its first year, the WISeR model introduced prior authorization requirements for a set of 13 medical services. The June 2025 &lt;em&gt;Innovation Center Investment Plan&lt;/em&gt; for WISeR lists medical services that could be added to the program in future years. This planning document considers the possibility of adding services “where prior authorization would have to be done on a more urgent or emergent basis,” including air ambulance transport, cancer treatment, MRI scans, and medications without publicly available coverage criteria.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;caption caption-center&quot;&gt;&lt;div class=&quot;caption-width-container&quot;&gt;&lt;div class=&quot;caption-inner&quot;&gt;&lt;img src=&quot;/files/2026/09/08/icip-future-plans.png&quot; alt=&quot;&quot; width=&quot;1728&quot; height=&quot;1034&quot; /&gt;&lt;p class=&quot;caption-text&quot;&gt;A planning document from June 2025 lists ideas for the expansion of WISeR to additional medical services (&lt;a href=&quot;https://www.eff.org/document/wiser-foia-response-combined-records&quot;&gt;WISeR FOIA Response - Combined Records&lt;/a&gt;, page 22)&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;h3&gt;More Transparency is Needed About Medicare’s AI Experiment&lt;/h3&gt;
&lt;p&gt;CMS continues to produce records in response to EFF’s lawsuit. Records released thus far echo concerns that providers have raised since WISeR launched, including long delays, financial incentives to deny care, and technical problems. But important questions remain about the AI systems private companies are using to inform decisions about whether to provide people with Medicare benefits. As CMS continues to produce documents, we will continue to make them available to the public. The public deserves to know how AI is driving decisions that affect patients’ access to care.&lt;/p&gt;

&lt;p&gt;&lt;span&gt;&lt;i&gt;Correction: An earlier version of this post misstated the number of prior authorization requests that had been denied by two WISeR vendors in the first &lt;/i&gt;&lt;/span&gt;&lt;span&gt;&lt;i&gt;three&lt;/i&gt;&lt;/span&gt;&lt;span&gt;&lt;i&gt; months of the program. This version has been corrected to reflect &lt;/i&gt;&lt;/span&gt;&lt;span&gt;&lt;i&gt;that&lt;/i&gt;&lt;/span&gt;&lt;span&gt;&lt;i&gt; the number of denials was 5,944. The post has also been updated to clarify that reported turnaround times reflect the full request pathway and are not solely controlled by WISeR vendors.&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field--name-field-related-cases field--type-node-reference field--label-above&quot;&gt;&lt;div class=&quot;field__label&quot;&gt;Related Cases:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;a href=&quot;/cases/eff-v-cms&quot;&gt;EFF v. CMS&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 08 Sep 2026 19:19:44 +0000</pubDate>
 <guid isPermaLink="false">112346 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <category domain="https://www.eff.org/issues/transparency">Transparency</category>
 <dc:creator>Lena Cohen</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/adm-bureaucratic-final-1200x600.jpg" alt="A robot oversees a factory conveyor belt. Its finger hovers over the reject button, as a red light scans a woman and her baby." type="image/jpeg" length="186891" />
  </item>
  <item>
    <title>Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal</title>
    <link>https://www.eff.org/deeplinks/2026/09/court-rules-against-citizen-journalists-dmca-takedown-case-eff-will-appeal</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was brought by our client, Channel 781 News, after takedown notices temporarily shut down the citizen journalism group&#039;s YouTube channel. We think the court set the bar far too low for copyright takedowns, and we plan to appeal.&lt;/p&gt;
&lt;p&gt;Channel 781 is a group of independent, volunteer journalists who report on local affairs in Waltham, Massachusetts. That includes posting short, newsworthy excerpts from recordings of city government meetings produced by Waltham Community Access Corporation (WCAC), the city&#039;s public access television station.&lt;/p&gt;
&lt;p&gt;In September 2023, WCAC sent three copyright takedown notices to YouTube targeting fifteen of Channel 781&#039;s videos. YouTube removed the videos and, under its three-strikes policy, temporarily disabled Channel 781&#039;s entire account—just days before a local election.&lt;/p&gt;
&lt;p&gt;Represented by EFF and Brown Rudnick LLP, &lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/fair-use-right-ignoring-it-has-consequences&quot;&gt;Channel 781 sued WCAC under Section 512(f)&lt;/a&gt; of the Digital Millennium Copyright Act (DMCA), which provides a remedy when a copyright holder knowingly makes material misrepresentations in a takedown notice.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;When Is a Copyright Holder Responsible for a Wrongful Takedown?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Fair use is the legal right to use copyrighted material without permission, when doing so serves purposes like criticism, commentary, or creating something new. Fair use is not copyright infringement, and courts have recognized that copyright holders &lt;a href=&quot;https://www.eff.org/press/releases/important-win-fair-use-dancing-baby-lawsuit&quot;&gt;must consider fair use&lt;/a&gt; before using the DMCA&#039;s powerful notice-and-takedown process.&lt;/p&gt;
&lt;p&gt;In this case, Channel 781 argued that WCAC accused it of copyright infringement without making a good-faith assessment of whether its videos were fair use.&lt;/p&gt;
&lt;p&gt;The evidence showed that WCAC&#039;s analysis was seriously deficient. The court noted that Chris Wangler, the WCAC employee who sent the notices, didn’t consider several facts relevant to fair use. For instance, Channel 781 used relatively small portions of WCAC&#039;s recordings, and the underlying recordings were factual public meetings, not a creative work. WCAC also gave little or no weight to whether Channel 781&#039;s use harmed any market for the recordings.&lt;/p&gt;
&lt;p&gt;There’s also strong evidence that WCAC had motivations unrelated to copyright. WCAC objected to its footage being used to criticize local officials and advance political viewpoints. And WCAC sent the takedown notices during a local election, shortly after Channel 781 posted a campaign statement by Waltham&#039;s mayor that WCAC had mistakenly made available online.&lt;/p&gt;
&lt;p&gt;Despite this evidence, the court concluded that WCAC had a subjective good-faith belief that Channel 781&#039;s videos were infringing. We disagree.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;A Subjective Belief Should Not Be a Free Pass&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Channel 781 argued that a copyright holder’s belief that material is infringing must be both genuinely held and objectively reasonable. WCAC argued that a subjective good-faith belief is good enough. Unfortunately, the court agreed with WCAC.&lt;/p&gt;
&lt;p&gt;The court emphasized that Wangler had read up on fair use, watched a short YouTube video explaining the doctrine, and distinguished between videos he thought might qualify as fair use and those he believed did not. That was enough, the court concluded, to establish subjective good faith—even though Wangler’s analysis ignored important facts relevant to fair use. As the court put it, Section 512(f) does not require “a perfect or even reasonable fair use analysis.”&lt;/p&gt;
&lt;p&gt;That is an alarmingly low bar for copyright holders seeking to remove someone else’s speech from the internet. A DMCA takedown can cause lawful speech to disappear almost immediately. As Channel 781 experienced, multiple notices can even result in an entire channel being disabled.&lt;/p&gt;
&lt;p&gt;If a copyright holder can avoid liability despite a cursory, incomplete, and objectively unreasonable analysis that ignores important facts—even when there’s evidence that the copyright holder wanted to suppress critical speech—the obligation to consider fair use risks becoming little more than a box-checking exercise. That interpretation threatens to strip Section 512(f) of much of its force.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Even Under a Subjective Standard, WCAC Fell Short&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Even accepting the court’s subjective standard, WCAC&#039;s cursory consideration of fair use should not have been enough. WCAC disregarded important fair use considerations, and the record included statements suggesting that it believed people generally needed permission to reuse its footage—an understanding at odds with fair use. There was also evidence that WCAC objected to Channel 781&#039;s political use of its footage, and had motivations for the takedowns unrelated to copyright.&lt;/p&gt;
&lt;p&gt;Taken together, these facts raise serious questions about whether WCAC genuinely considered fair use, rather than using copyright as a rationale for removing material it did not like.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;The Court Did Not Find That Channel 781&#039;s Videos Infringed&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Importantly, the court&#039;s analysis recognized Channel 781’s strong fair use argument: the group used short excerpts from factual recordings of public government proceedings, selecting clips for their newsworthiness, and making them easier for the public and journalists to find, share, and discuss.&lt;/p&gt;
&lt;p&gt;The opinion even states that WCAC&#039;s fair use analysis “may have been deficient.” But under the purely subjective standard it adopted, the court concluded that it could not reject WCAC&#039;s professed belief—even if the court itself “would have reached the opposite conclusion” on fair use.&lt;/p&gt;
&lt;p&gt;We plan to appeal this decision to the First Circuit Court of Appeals. Copyright law should not allow a rightsholder to suppress critical reporting or political speech through the DMCA and escape accountability simply by claiming it believed the speech was infringing. Section 512(f) is supposed to provide protection against wrongful takedowns. We will keep fighting to ensure that safeguard actually protects people. &lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Thu, 03 Sep 2026 19:11:56 +0000</pubDate>
 <guid isPermaLink="false">112338 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/dmca">DMCA</category>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <dc:creator>Betty Gedlu</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/fair-use-og-1.png" alt="4 volume controls for fair use on purple background" type="image/png" length="7773" />
  </item>
  <item>
    <title>Texas and Florida Step Back from ALPRs</title>
    <link>https://www.eff.org/deeplinks/2026/09/texas-and-florida-step-back-alprs</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/procurement-power-when-cities-realized-they-can-just-say-no-2025-review&quot;&gt;&lt;span&gt;years of successful&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://arstechnica.com/tech-policy/2026/08/cities-terminate-flock-contracts-at-record-pace-in-august/&quot;&gt;&lt;span&gt;grassroots battles&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to pull these cameras from local streets, &lt;/span&gt;&lt;a href=&quot;https://spectrumlocalnews.com/us/snplus/politics/2026/08/31/flock-safety-cameras-bipartisan-scrutiny-misuse&quot;&gt;&lt;span&gt;bipartisan momentum&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is sweeping the country.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;On August 28, Texas Governor Greg Abbott &lt;/span&gt;&lt;a href=&quot;https://www.texastribune.org/2026/08/28/texas-greg-abbott-flock-cameras-order-state-money/&quot;&gt;&lt;span&gt;banned state agencies from spending public funds on Flock cameras&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. The order dropped just as &lt;/span&gt;&lt;i&gt;&lt;span&gt;The Texas Tribune&lt;/span&gt;&lt;/i&gt;&lt;span&gt; prepared to &lt;/span&gt;&lt;a href=&quot;https://www.texastribune.org/2026/08/28/texas-flock-cameras-auto-insurance-fee-mvcpa-grants/&quot;&gt;&lt;span&gt;publish an investigation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; revealing that a state agency had quietly funneled at least $30 million into building a sprawling surveillance network. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Then on August 31, the Florida Department of Transportation (FDOT) &lt;/span&gt;&lt;a href=&quot;https://fdotwww.blob.core.windows.net/sitefinity/docs/default-source/design/bulletins/eom26-01.pdf&quot;&gt;&lt;span&gt;issued a memo&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.wctv.tv/2026/08/31/gov-desantis-set-remove-flock-cameras-state-roadways/&quot;&gt;&lt;span&gt;announced&lt;/span&gt;&lt;/a&gt;&lt;span&gt; by Governor Ron DeSantis, ordering the removal of all ALPRs from the right-of-way on state highways within 30 days. The order revokes all previously approved permits to install ALPRs, and bars transportation officials from issuing future permits. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;FDOT officials &lt;/span&gt;&lt;a href=&quot;https://thehill.com/homenews/state-watch/6064333-florida-flock-camera-state-highway-removal/&quot;&gt;&lt;span&gt;stated&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that “the recent exponential increase in deployments along our roadways, coupled with concerning reports of misuse, data privacy concerns, and surveillance schemes merit immediate action to preserve Floridians’ sovereignty and quality of life.” FDOT’s action has been followed by &lt;/span&gt;&lt;a href=&quot;https://www.actionnewsjax.com/news/local/county-by-county-how-local-sheriffs-are-responding-fdots-order-remove-flock-cameras/AOYXI65SLFGSHKHIYXN5M22ZNE/&quot;&gt;&lt;span&gt;a surge&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of &lt;/span&gt;&lt;a href=&quot;https://www.firstcoastnews.com/article/news/community/transportation/jacksonville-flock-license-plate-recognition-camera-removal/77-b266d834-fbac-4ce9-bcef-490f00a0a2e5&quot;&gt;&lt;span&gt;local governments&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.miamiherald.com/news/local/community/miami-dade/article317088755.html&quot;&gt;&lt;span&gt;in Florida&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://spacecoastdaily.com/2026/09/melbourne-police-suspend-use-of-flock-license-plate-readers/&quot;&gt;&lt;span&gt;canceling&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or &lt;/span&gt;&lt;a href=&quot;https://www.floridatoday.com/story/news/local/2026/08/31/video-shows-brevard-sheriff-terminate-flock-camera-usage/91554536007/&quot;&gt;&lt;span&gt;pausing&lt;/span&gt;&lt;/a&gt;&lt;span&gt; their &lt;/span&gt;&lt;a href=&quot;https://www.miamiherald.com/news/local/community/miami-dade/article317088755.html&quot;&gt;&lt;span&gt;vendor contracts&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Much more work remains. Many ALPRs in Florida are not on state highways, but sit on city streets, county roads, residential driveways, and shopping center parking lots—and FDOT&#039;s order doesn&#039;t touch any of them. Likewise, the Texas directive leaves local agencies free to use city, county, federal, and private funds to install cameras.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This week’s good news follows &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/procurement-power-when-cities-realized-they-can-just-say-no-2025-review&quot;&gt;&lt;span&gt;years of pushback&lt;/span&gt;&lt;/a&gt;&lt;span&gt; from local advocates that has seen &lt;/span&gt;&lt;a href=&quot;https://ij.org/institute-for-justice-unveils-new-database-tracking-cancelations-of-license-plate-reader-contracts/&quot;&gt;&lt;span&gt;dozens of cities sever ties&lt;/span&gt;&lt;/a&gt;&lt;span&gt; with surveillance companies. According to &lt;/span&gt;&lt;a href=&quot;https://arstechnica.com/tech-policy/2026/08/cities-terminate-flock-contracts-at-record-pace-in-august/&quot;&gt;&lt;span&gt;some metrics&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, during the last 30 days, an average of three localities per day has halted contracts with Flock. Other advocates have been resisting ALPRs in &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2021/01/eff-joins-effort-restrict-automated-license-plate-readers-california&quot;&gt;&lt;span&gt;statehouses&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/cases/siren-v-san-jose&quot;&gt;&lt;span&gt;court&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/eff-urges-virgina-court-appeals-require-search-warrants-access-alpr-databases&quot;&gt;&lt;span&gt;houses&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and by &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/effs-investigations-expose-flock-safetys-surveillance-abuses-2025-review/&quot;&gt;&lt;span&gt;blowing the whistle&lt;/span&gt;&lt;/a&gt;&lt;span&gt; with investigative activism.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The moves in Florida and Texas also illustrate the power that the executive branch can wield to curtail mass surveillance with almost immediate results. We hope that the California Governor Gavin Newsom and the California Department of Transportation will take notice and initiate steps to curb this technology, starting with &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/press/releases/coalition-urges-california-revoke-permits-federal-license-plate-reader-surveillance&quot;&gt;&lt;span&gt;removing the ALPRs&lt;/span&gt;&lt;/a&gt;&lt;span&gt; that U.S. Border Patrol and the Drug Enforcement Administration have installed on California highways.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/effs-policy-position-alpr-surveillance-eliminate-it-and-reduce-its-harms&quot;&gt;&lt;span&gt;EFF’s position remains&lt;/span&gt;&lt;/a&gt;&lt;span&gt;: ALPR mass surveillance – the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion – should not exist. This past week’s actions in Texas and Florida are good steps forward, but we are still far from the finish line. We will continue working alongside community groups to keep cameras off local streets, while urging judges and state lawmakers to impose enforceable restraints on this warrantless mass surveillance.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 02 Sep 2026 17:31:31 +0000</pubDate>
 <guid isPermaLink="false">112336 at https://www.eff.org</guid>
 <dc:creator>Rindala Alajaji</dc:creator>
 <dc:creator>Adam Schwartz</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/flock-dystopia-scene-1.png" alt="Flock cameras and surveillance cameras among barbed wire in a dystopian scene" type="image/png" length="153685" />
  </item>
  <item>
    <title>Judge Rules DOD Unlawfully Retaliated Against Anthropic</title>
    <link>https://www.eff.org/deeplinks/2026/09/judge-rules-dod-unlawfully-retaliated-against-anthropic</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;A federal judge has sided with Anthropic on its claims that the Department of Defense illegally retaliated against Anthropic’s protected speech by labeling the AI company a “supply chain risk.” The judge found that designation, intended to penalize Anthropic for telling the U.S. military it would not allow their technology to be used for mass surveillance of U.S. persons, “constituted unlawful retaliation in violation of the First Amendment.” EFF joined a coalition of organizations in filing multiple amicus briefs (&lt;a href=&quot;https://www.eff.org/document/anthropic-v-department-war-et-al-amicus-brief&quot;&gt;here&lt;/a&gt;, &lt;a href=&quot;https://www.eff.org/files/2026/06/18/26-cv-01996_amicus_curiae_brief_in_support_of_plaintiffs_motion_for_summary_judgment.pdf&quot;&gt;here&lt;/a&gt;) arguing that the Pentagon had trampled on Anthropics First Amendment rights. We agree with &lt;a href=&quot;https://www.eff.org/document/anthropic-v-us-dept-war-order-cross-motions-summary-judgment&quot;&gt;the court’s decision&lt;/a&gt; and applaud the judge for slapping down such an obvious act of illegal and unconstitutional retribution by the Pentagon—even as the court left open the broader question of whether a company’s choices about how its technology may be used are protected speech in their own right. &lt;/p&gt;&lt;p&gt;From the start of this conflict, EFF argued that &lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/ai-regulation-should-be-rational-not-retaliatory&quot;&gt;companies should not be penalized&lt;/a&gt; for not wanting to conduct mass surveillance of US persons. Nor do we want to live in a legal system where our susceptibility to surveillance is hashed out and decided in &lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/anthropic-dod-conflict-privacy-protections-shouldnt-depend-decisions-few-powerful&quot;&gt;closed-door contract negotiations&lt;/a&gt; between a few powerful people at the military and an AI company. Unfortunately, this ruling does little to address the bigger problem: that Congress has abdicated its responsibility to adopt statutory safeguards to protect our privacy, and instead left us reliant on the whims of private companies to decide when they are and are not willing to help the government conduct mass surveillance. &lt;/p&gt;&lt;p&gt;In February 2026, the government &lt;a href=&quot;https://www.eff.org/deeplinks/2026/02/tech-companies-shouldnt-be-bullied-doing-surveillance&quot;&gt;began threatening to penalize Anthropic&lt;/a&gt; unless it backed off its position that it did not want the U.S. military using its AI product Claude for mass surveillance of Americans or to power autonomous weapons systems. Ultimately, the Department of Defense, deciding that it did not want military contractors dictating what its products could or could not be used for, declared the company a “supply chain risk.” This national security designation means the government and companies that do business with it cannot use the company’s products for government projects. It was, in essence, an attempted blacklisting of Anthropic for setting boundaries and articulating unacceptable use cases for its products. &lt;/p&gt;&lt;p&gt;None of this is to say that Anthropic is a morally unimpeachable company, or that it and other companies would never permit their products to be used under specific conditions to aid in surveillance or analysis of collected data that could affect U.S. persons—but the facts remain: the government cannot punish a company for having preferences regarding unconstitutional uses of its technology. &lt;/p&gt;&lt;p&gt;Unsupported claims that a company poses a national security risk should never be an excuse for government retaliation. This ruling correctly recognizes the dangerous implications of allowing the government to punish a company for its critical speech and for refusing to allow its technology to be used for mass surveillance. While we applaud the court&#039;s decision, we continue to urge lawmakers to take the protection of our privacy seriously. We shouldn&#039;t have to rely on private companies to protect us from the surveillance state. It&#039;s past time for Congress to act.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 02 Sep 2026 01:13:50 +0000</pubDate>
 <guid isPermaLink="false">112335 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <dc:creator>Matthew Guariglia</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-soldiers-3b.png" alt="AI Military" type="image/png" length="8125" />
  </item>
  <item>
    <title>Meta&#039;s $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users</title>
    <link>https://www.eff.org/deeplinks/2026/09/metas-17-billion-settlement-bad-deal-teens-and-all-social-media-users</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/eff-statement-meta-settlement&quot;&gt;we said&lt;/a&gt; the day the settlement was announced.&lt;/p&gt;
&lt;p&gt;In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process&lt;/li&gt;
&lt;li&gt;The Settlement places severe restrictions on Teens that can largely only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;&lt;/li&gt;
&lt;li&gt;The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;&lt;/li&gt;
&lt;li&gt;The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism. And the Settlement in no way limits the attorneys general from seeking the user information for their own law enforcement purposes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.&lt;/p&gt;
&lt;p&gt;Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.&lt;/p&gt;
&lt;h3&gt;Age Gates Reinforced By Age Estimation Technology&lt;/h3&gt;
&lt;p&gt;In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And further, Meta will now enforce these age gates with age assurance technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, &lt;a href=&quot;https://www.eff.org/issues/age-verification&quot;&gt;as we’ve said before&lt;/a&gt;. The technology also &lt;a href=&quot;https://www.eff.org/issues/age-verification&quot;&gt;just adds a layer of creepiness&lt;/a&gt; into the use of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) or age assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Those methods might include commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has &lt;a href=&quot;https://www.medianama.com/2023/11/223-meta-age-verification-app-store-downloads/&quot;&gt;previously advocated for&lt;/a&gt; age assurance requirements to fall on Google and Apple rather than on individual services.&lt;/p&gt;
&lt;p&gt;This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.&lt;/p&gt;
&lt;p&gt;For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.&lt;/p&gt;
&lt;p&gt;Those estimated to be 13-17 years old will be limited to Teen User accounts.&lt;/p&gt;
&lt;p&gt;Those estimated to be under-13 will lose their accounts altogether.&lt;/p&gt;
&lt;p&gt;Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement, and that seems to require a formal assessment of accuracy.&lt;/p&gt;
&lt;p&gt;How accurate does the age assurance process need to be?&lt;/p&gt;
&lt;p&gt;The Settlement sets maximum false-positive rates for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more than 10% for ages 16-17 and no more than 3% for ages 13-15. &lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;6. Age Assurance Standards.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(a) U18 False Positive Rate Thresholds.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall&lt;/em&gt;&lt;br /&gt;&lt;em&gt;meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: &lt;/em&gt;&lt;br /&gt;&lt;em&gt;(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement generally shows little concern for those falsely placed in its Teen User category. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to&lt;strong&gt; proactively monitor adult accounts&lt;/strong&gt; to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and &lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Any age assurance process Meta uses must be tested annually.&lt;/p&gt;
&lt;h3&gt;Data minimization&lt;/h3&gt;
&lt;p&gt;The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” The “reasonable period of time” is not defined. And the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information ... where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;8. Data minimization and security.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)&lt;/h3&gt;
&lt;p&gt;Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to those estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.&lt;/p&gt;
&lt;h4&gt;Time restrictions&lt;/h4&gt;
&lt;p&gt;Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits, and that some teens may need to work at the restricted times to support their families and themselves:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.&lt;/li&gt;
&lt;li&gt;School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.&lt;/li&gt;
&lt;li&gt;Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”&lt;/li&gt;
&lt;li&gt;“Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be momentarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;div class=&quot;media media-element-container media-default&quot;&gt;&lt;div id=&quot;file-59782&quot; class=&quot;file file-image file-image-jpeg&quot; class=&quot;file file-image file-image-jpeg&quot;&gt;

        &lt;h2 class=&quot;element-invisible&quot;&gt;&lt;a href=&quot;/file/exhibitgmetajpg&quot;&gt;exhibit_g_meta.jpg&lt;/a&gt;&lt;/h2&gt;
    
  
  &lt;div class=&quot;content&quot;&gt;
    &lt;img alt=&quot;Exhibit G from Meta Settlement showing phone warnings&quot; title=&quot;Exhibit G from Meta Settlement showing phone warnings&quot; height=&quot;612&quot; width=&quot;873&quot; class=&quot;media-element file-default&quot; data-delta=&quot;1&quot; src=&quot;https://www.eff.org/files/exhibit_g_meta.jpg&quot; /&gt;&lt;div class=&quot;field field--name-field-disable-stretch field--type-list-boolean field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;  &lt;/div&gt;

  
&lt;/div&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;p&gt;To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such user controls would have recognized that teens have human rights, agency, and autonomy.&lt;/p&gt;
&lt;p&gt;But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.&lt;/p&gt;
&lt;h4&gt;Feature restrictions (§II.C-D)&lt;/h4&gt;
&lt;p&gt;Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service. &lt;/p&gt;
&lt;p&gt;Again, these would be useful user controls that should be offered to users of all ages. And while a Teen User potentially has control over these features, they cede that control to their parent once they enroll in Parental Supervision, part of the Parental Supervision Tradeoff discussed below.&lt;/p&gt;
&lt;p&gt;Also, by default, teens will not see the number of likes or other reactions to their posts.&lt;/p&gt;
&lt;p&gt;Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques.&lt;span&gt;”&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Meta has &lt;a href=&quot;https://www.technologyreview.com/2022/08/19/1057133/fight-for-instagram-face/&quot;&gt;had rules about cosmetic effects&lt;/a&gt; directed at teens &lt;a href=&quot;https://www.technologyreview.com/2022/08/19/1057133/fight-for-instagram-face/&quot;&gt;since 2019&lt;/a&gt;. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. &lt;/p&gt;
&lt;h4&gt;Content restrictions (P.1, §II.E, as defined by §I.C, E, F)&lt;/h4&gt;
&lt;p&gt;For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity &amp;amp; Sexual Activity, Restricted Goods &amp;amp; Services, Suicide, Self-Harm or Eating Disorders.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;D. “Age Assurance Methods” shall have the meaning set forth in Section II.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity &amp;amp; Sexual Activity, Restricted Goods &amp;amp; Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity &amp;amp; Sexual Activity, Restricted Goods &amp;amp; Services, Suicide, Self-Harm or Eating Disorders.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot;&gt;The &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot;&gt;issue &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot;&gt;here is that some of these categories are problematic. For example, the Restricted Goods &amp;amp; Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.eff.org/pages/stop-censoring-abortion&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;Stop Censoring Abortion campaign&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot;&gt;, and in &lt;/span&gt;&lt;span class=&quot;NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW248964249 BCX0&quot;&gt;our&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.eff.org/deeplinks/2026/08/meta-must-stop-silencing-reproductive-health-information&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;comment to the Meta Oversight Board&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot;&gt;. And under the Adult Nudity &amp;amp; Sexual Activity standard, Meta blocks teens from “&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot; data-ccp-charstyle-defn=&quot;[201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Aptos&amp;quot;,469777842,&amp;quot;&amp;quot;,469777843,&amp;quot;Aptos&amp;quot;,469777844,&amp;quot;Aptos&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Aptos&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;x1motxo8&amp;quot;,201340122,&amp;quot;1&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;x1motxo8&amp;quot;,335572020,&amp;quot;1&amp;quot;,469778324,&amp;quot;Default Paragraph Font&amp;quot;]}&quot;&gt;real world art of visible genitalia ... &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.oversightboard.com/decision/bun-s8141rab/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;representations of indigenous women&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;, &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.oversightboard.com/decision/bun-0w49p93l/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;breast cancer awareness&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.oversightboard.com/decision/ig-7thr3si1/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;posts&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;, &lt;/span&gt;&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.oversightboard.com/decision/bun-8s1h6eu5/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;educational posts about ovulation&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;, &lt;/span&gt;&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;and posts about &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.oversightboard.com/decision/fb-exvb8ktw/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;testicular&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt; and &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.oversightboard.com/decision/fb-i04m3kvf/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;breast self-exams&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;. &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;And it has &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.eff.org/pages/impact-age-verification-measures-goes-beyond-porn-sites&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;disproportionately applied&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun CommentStart CommentHighlightPipeRest CommentHighlightRest SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt; t&lt;/span&gt;&lt;span class=&quot;NormalTextRun CommentHighlightPipeRest SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt;he standard negatively &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW248964249 BCX0&quot; href=&quot;https://www.usermag.co/p/instagram-blocked-teens-from-searching&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;to gay and lesbian content&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW248964249 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW248964249 BCX0&quot; data-ccp-charstyle=&quot;x1motxo8&quot;&gt; as compared to straight content. &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP Selected SCXW248964249 BCX0&quot; data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class=&quot;EOP Selected SCXW248964249 BCX0&quot; data-ccp-props=&quot;{}&quot;&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW99573947 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;And even more worrisome, even though this is just Meta continuing its existing &lt;/span&gt;&lt;span class=&quot;NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW99573947 BCX0&quot;&gt;practices,&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; the Settlement empowers the s&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;t&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;ates &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;to&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; enforc&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;e&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; its provisions&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;. &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;[P. 40, &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;§&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;IV.C.&lt;/span&gt;&lt;span class=&quot;NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW99573947 BCX0&quot;&gt;1.i&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;; &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;§&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;VII.C&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; That means &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;that &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;over the next ten yea&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;r&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;s, the duration of the Settlement, Meta will&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;face the threat &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;that &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;a state attorney general will pursue legal action against it &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;because it disagrees with how &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;M&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;eta interprets these categories of community standards&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;, and pressures Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;. &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;And Meta will now lack the &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW99573947 BCX0&quot; href=&quot;https://www.courtlistener.com/opinion/10600039/moody-v-netchoice-llc/?q=moody+v+netchoice&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW99573947 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;hard-earned&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW99573947 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;a class=&quot;Hyperlink SCXW99573947 BCX0&quot; href=&quot;https://www.eff.org/deeplinks/2024/08/through-line-suprme-courts-social-media-cases-same-first-amendment-rules-apply&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;span data-contrast=&quot;none&quot; lang=&quot;EN-US&quot; class=&quot;TextRun Underlined SCXW99573947 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot; data-ccp-charstyle=&quot;Hyperlink&quot;&gt;First Amendment defenses&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW99573947 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt; to make its own curatorial decisions&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW99573947 BCX0&quot;&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP Selected SCXW99573947 BCX0&quot; data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Parental Supervision Tradeoff&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;All of these Teen User restrictions can be modified – but only if the Teen User enrolls in Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW247459893 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;Parental Supervision comes with &lt;/span&gt;&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun MacChromeBold SCXW247459893 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;huge tradeoffs&lt;/span&gt;&lt;/span&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW247459893 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;. There is a huge privacy tradeoff: i&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;n exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;the usernames of all of the teen’s connections, reports on &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;h&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;ow much time &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;the Teen User &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;spen&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;ds&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; on &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;a Meta &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;service,&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; the&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; time spent watching longf&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;o&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;rm &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;content&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;, &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;usernames of all &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;those messaging with the Teen&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets n&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;otices of&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; the teen’s&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; repeated searches related to suicide, self-&lt;/span&gt;&lt;span class=&quot;NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW247459893 BCX0&quot;&gt;harm&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt; and eating disorders&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;. &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;[P. 28, §&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW247459893 BCX0&quot;&gt;II.G]&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP Selected SCXW247459893 BCX0&quot; data-ccp-props=&quot;{}&quot;&gt; And there are huge autonomy tradeoffs: once enrolled in Parental Supervision, the ability to control features like recommendations and autoplay, discussed above, transfer from the Teen user over to their parent.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;&lt;span class=&quot;EOP Selected SCXW247459893 BCX0&quot; data-ccp-props=&quot;{}&quot;&gt;Parental Supervision&lt;br /&gt;1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.&lt;br /&gt;2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.&lt;br /&gt;3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.&lt;br /&gt;4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.&lt;br /&gt;5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.&lt;br /&gt;6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This may be ultimately workable for young people with healthy and safe relationships with their parent or guardian. But obviously it is not good at all for a Teen User lacking such a safe relationship.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW210200653 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW210200653 BCX0&quot;&gt;More Surveillance, Not Less &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users&#039; use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended. &lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For example:&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;3&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;3&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;2&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;3&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;3&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Meta pledges to utilize and improve its existing “soft matching models” that track signals such as “device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;3&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;4&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;3&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;5&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;&quot; data-font=&quot;Symbol&quot; data-listid=&quot;3&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;6&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E]&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Moreover, one of the chief threats of Meta’s surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Meta Has To Pay The States And Pays To Establish Norms Beyond Meta&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten-year life of the Settlement, these annual payments will total over $11 billion. And the states then get an additional $5 billion if Meta competitors adopt the same measures. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get the additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance, age-gating, and the ceding of teen autonomy as the norm across online services.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.&lt;br /&gt;(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt;&lt;span data-contrast=&quot;auto&quot; lang=&quot;EN-US&quot; class=&quot;TextRun SCXW145697998 BCX0&quot; xml:lang=&quot;EN-US&quot;&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;The Settlement is thus a bad deal &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;for all users of Facebook and Instagram&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;. It &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;normalizes age gating and age assurance for millions of internet users. &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;It denies teens the tools to &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;create their own safe experiences online&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt; and places their social media experien&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;c&lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;e firmly under the control of either Meta or their parents. And rather than &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;addressing Meta’s collection, analysis, and retention of &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;data about teens’ use of Instagram and Facebook, it binds Meta to &lt;/span&gt;&lt;span class=&quot;NormalTextRun SCXW145697998 BCX0&quot;&gt;continued surveillance, and does nothing to protect access to such data by the states.&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;EOP SCXW145697998 BCX0&quot; data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Tue, 01 Sep 2026 20:51:07 +0000</pubDate>
 <guid isPermaLink="false">112332 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/cda230">Section 230</category>
 <dc:creator>David Greene</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/age_verification-cell_phone-access_denied.png" alt="A blue hand holding a cellphone showing a verification screen and ACCESS DENIED in the background" type="image/png" length="990456" />
  </item>
  <item>
    <title>EFF to Governor Newsom: Veto California’s AB 1709</title>
    <link>https://www.eff.org/deeplinks/2026/08/eff-gov-newsom-veto-californias-ab-1709</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/amending-ab-1709-doesnt-fix-it-californias-social-media-ban-still-threatens-free&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;sweeping ban on social media use&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cuts young people off from essential information and experiences, particularly harming vulnerable youth and marginalized groups who often find safety in supportive online communities they can&#039;t access offline. That’s why we’re &lt;a href=&quot;https://www.eff.org/document/re-ab-1709-request-veto&quot;&gt;urging Governor Gavin Newsom to veto the measure&lt;/a&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Should the law go into effect in January, platforms would be prohibited from offering virtually every functional recommendation algorithm and basic input, such as who a user follows or what posts they like, to anyone under 16. These so-called &quot;addictive features,&quot; are in reality the basic tools that online services use to identify what other user-generated content a particular user might want to see. Users also rely on these features to find audiences for their own speech, as well as community. By labeling these basic tools as &quot;addictive,&quot; the bill relies on sweeping generalizations regarding the &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/05/science-not-settled-how-weak-evidence-fueling-national-push-ban-social-media-youth&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;unsettled science&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; of youth social media use. Because nearly every major service relies on automated feeds, the ultimate result is that young people under 16 will still be locked out of major digital services as they currently exist. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;&lt;span data-contrast=&quot;auto&quot;&gt;A.B. 1709 is a massive privacy and free speech nightmare. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;A.B. 1709 is a massive privacy and free speech nightmare. Denying young people access to digital forums (or stripping out the basic tools needed to navigate them) does nothing to make young people safer or healthier. Research shows that social media bans are &lt;/span&gt;&lt;a href=&quot;https://www.brookings.edu/articles/how-will-bans-on-social-media-affect-children/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;ineffectual&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and can be harmful when they deny young people opportunities to develop their own voices and perspectives, whether that means sharing art, practicing religion, or engaging in politics.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Far from protecting children, the bill will also severely restrict access to constitutionally protected speech and push platforms to implement invasive age-verification methods, such as requiring government IDs or biometric scanning. Age-gating requirements will force everyone to give big tech companies even more personal &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/face-scans-estimate-our-age-creepy-af-and-harmful&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;information&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. To verify who can pass through online gates, companies will collect even more data, &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/age-verification-windfall-big-tech-and-death-sentence-smaller-platforms&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;concentrating power&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; in corporate hands rather than protecting users. This creates massive honeypots of &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/pages/age-verification-systems-are-surveillance-systems#main-content&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;sensitive personal data&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, severely damages online &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/03/age-verification-mandates-would-undermine-anonymity-online&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;anonymity&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;, and exposes users of all ages to &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/06/hack-age-verification-company-shows-privacy-danger-social-media-laws&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;heightened&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.404media.co/the-discord-hack-is-every-users-worst-nightmare/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;data breach&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://www.bbc.com/news/articles/ce87rer52k3o&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;risks&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Finally, A.B. 1709 introduces legal confusion by creating provisions that conflict with already enacted legislation like &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/ab-1043s-internet-age-gates-hurt-everyone&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;A.B. 1043&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/eff-ninth-circuit-young-people-have-first-amendment-right-use-social-media-and-all&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;S.B. 976&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;auto&quot;&gt;. Rather than offering regulatory clarity on already-passed laws, California will only end up spending valuable resources to defend a law bound to be tied up in court. &lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;For more details, you can read our full letter to the Governor &lt;a href=&quot;https://www.eff.org/document/re-ab-1709-request-veto&quot;&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;240}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 31 Aug 2026 23:37:39 +0000</pubDate>
 <guid isPermaLink="false">112313 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <category domain="https://www.eff.org/issues/social-networks">Social Networks</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  <item>
    <title>EFF to Courts: Don’t Rewrite Copyright Over AI Hype</title>
    <link>https://www.eff.org/deeplinks/2026/08/eff-courts-dont-rewrite-copyright-over-ai-hype</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;The history of technology is rife with copyright panics.  In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public &lt;a href=&quot;https://www.wombatnation.com/2002/09/29/jack-valentis-1982-testimony-on-the-vcrs-assault-on-life-as-we-know-it/&quot;&gt;as the Boston strangler is to the woman home alone&lt;/a&gt;.” Then, the Supreme Court declined to embrace the hype, noting that the VTR was capable of all kinds of non-infringing uses, like time-shifting and cautioning courts to avoid rewriting copyright law in response to new technologies. We believe that courts now should be similarly wary about the hype surrounding AI.&lt;/p&gt;
&lt;p&gt;Hollywood’s hyperbole has &lt;a href=&quot;https://arstechnica.com/tech-policy/2009/10/100-years-of-big-content-fearing-technologyin-its-own-words/&quot;&gt;echoed that of composer John Phillip Sousa&lt;/a&gt;, who claimed in 1906 that the player piano and the gramophone would destroy music composition; portrait artists who &lt;a href=&quot;https://daily.jstor.org/did-photography-really-kill-portrait-painting/&quot;&gt;feared the camera&lt;/a&gt; would replace the paintbrush. None of these things happened. Cameras, for example, sparked a resurgence of portraiture and, by making it possible for more people to create images, led to unexpected developments—like the rise of photojournalism.&lt;/p&gt;
&lt;p&gt;New markets, new ideas, and new creators are actually what copyright is supposed to promote, not restrict. Using copyright to lock in existing gatekeepers and massive rightsholders’ profits helps neither the public nor individual artists.&lt;/p&gt;
&lt;p&gt;Generative AI has sparked the latest wave of anxiety and with it a massive wave of litigation. In multiple cases around the U.S. and the world, rightsholders are asking courts to do precisely what the Supreme Court warned against: dramatically expand copyright protections based in substantial part on hyperbole and speculation. They should decline to do so.&lt;/p&gt;
&lt;p&gt;Copyright owners claim that unless courts abandon 300-year-old copyright principles—and give rightsholders the power to control &lt;em&gt;non-infringing &lt;/em&gt;works created by others—an imagined flood of AI-generated works will devastate creative markets. Under this “market dilution” theory, building generative AI tools cannot be fair use because those tools might be encourage the proliferation of competing works.&lt;/p&gt;
&lt;p&gt;As EFF has explained to the courts in multiple amicus briefs in &lt;em&gt;&lt;a href=&quot;https://www.eff.org/document/brief-amicus-curiae-electronic-frontier-foundation&quot;&gt;Concord Music Group, Inc. v. Anthropic PBC&lt;/a&gt; &lt;/em&gt;and &lt;em&gt;&lt;a href=&quot;https://www.eff.org/document/brief-amici-curiae-electronic-frontier-foundation-et-al&quot;&gt;In re Mosaic LLM Litigation&lt;/a&gt;&lt;/em&gt;, that’s not how copyright works. In fact, accepting this theory would undermine copyright’s constitutional purpose: promoting the creation of expressive works for the public’s benefit. Because copyright law is designed to encourage others to build freely on existing works, it punishes &lt;em&gt;infringement&lt;/em&gt;, not competition. The “market dilution” theory would eviscerate not only the fair use doctrine, but also other limits on copyright that work specifically to prevent rightsholders from unfairly suppressing competition by claiming broad ownership over tropes, genres, styles, and so on. In other words, publishers would wield unchecked veto power over any expression that might conceivably compete with a work they own.&lt;/p&gt;
&lt;p&gt;The result? Art doesn’t get created, ideas are never expressed, and we’re all worse off. Copyright shouldn’t be a tool to silence future creative competitors—whether or not they use AI in their work.&lt;/p&gt;
&lt;p&gt;And the plaintiffs in these cases get at least two other things wrong. First, &lt;a href=&quot;https://news.mit.edu/2026/when-ai-art-has-no-author-generated-images-often-cant-be-traced-to-training-data-0818&quot;&gt;research&lt;/a&gt; shows that large generative AI models are unlikely to produce infringing works because the more data on which a model is trained, the less any individual training example matters to any particular output.&lt;/p&gt;
&lt;p&gt;Second, AI tools aren’t necessarily displacing human creativity. To take a just a few examples:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Boston-based artist Nettrice Gaskins uses AI to create Afro-futurist art, including a portrait of Octavia Butler displayed at the San Francisco Airport&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Indian artists Prateek Arora and Varun Gupta use generative AI to reimagine Western science fiction.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Philadelphia-based artist Alex Smith uses generative AI to reimagine Afrofuturism with queer, plus-sized Black superheroes.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Ana Miljački, a professor of architecture at MIT, used generative AI to create a “non-liner documentary” film on Yugoslav World War II memorials and the values they embodied.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;A research-creation project used AI generated visual art to both amplify the voices of activists in the Iran Woman Life Freedom Movement and evaluate AI’s role in sociopolitical advocacy through art.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;AI company Bronze works with musicians like Disclosure and Jai Paul to create songs that never sound the same when played back twice, challenging audience conceptions of what music could be.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It is not the place of courts to say these people are not artists or that AI cannot augment human creativity in a positive way.&lt;/p&gt;
&lt;p&gt;Given this range of experimentation, courts should be reluctant to decide in advance what tools do and do not foster “human creativity.” Like the VTR, large language models are general purpose tools, used by humans to do a broad variety of things far beyond generating lyrics. The effects of this particular technological innovation will doubtless be far-reaching, disruptive, and potentially harmful for some—but distorting copyright law is not the way to address those harms.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 31 Aug 2026 19:45:54 +0000</pubDate>
 <guid isPermaLink="false">112312 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/innovation">Creativity &amp; Innovation</category>
 <category domain="https://www.eff.org/issues/intellectual-property">Fair Use</category>
 <category domain="https://www.eff.org/issues/ai">Artificial Intelligence</category>
 <dc:creator>Tori Noble</dc:creator>
 <dc:creator>Corynne McSherry</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ai-robot-warhol-2.png" alt="robot portraits Warhol-style" type="image/png" length="211803" />
  </item>
  <item>
    <title>Doxxing Safety Part II: Incident Response</title>
    <link>https://www.eff.org/deeplinks/2026/08/doxxing-safety-part-ii-incident-response</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This guide is a followup from a &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management&quot;&gt;previous post&lt;/a&gt; that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There&#039;s a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Incident Log&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;An incident log is a way to keep track of suspicious or harmful activity online. It doesn&#039;t need to be beautiful or complex, just a place where you can quickly note details around the different things you&#039;re seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/files/2026/08/28/screenshot_2026-08-28_at_2.56.12_pm.png&quot; width=&quot;1342&quot; height=&quot;428&quot; alt=&quot; Where/Site, Date &amp;amp; Time, Brief Description of Action, Threat-Actor Name/Description, Any Other People Involved.&quot; title=&quot; Where/Site, Date &amp;amp; Time, Brief Description of Action, Threat-Actor Name/Description, Any Other People Involved.&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management&quot;&gt;previous blog post&lt;/a&gt;. If you haven&#039;t yet done that, here&#039;s a brief refresher:&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Assign Team Roles&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Remember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you&#039;ve already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Monitoring Hate Forums&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;So often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you&#039;re a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/how-to-use-tor&quot;&gt;&lt;span&gt;We recommend you use the Tor browser&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Set Up Search Alerts&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://support.google.com/websearch/answer/4815696?hl=en&quot;&gt;&lt;span&gt;Google alerts&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you&#039;re the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For a more sophisticated approach, you could use a tool like&lt;/span&gt;&lt;a href=&quot;https://openmeasures.io/&quot;&gt; &lt;span&gt;Open Measures&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to automate the task of tracking coordinated campaigns. It&#039;s important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Hardening Your Public Facing Accounts&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;For accounts that you can&#039;t or don&#039;t want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/how-enable-two-factor-authentication&quot;&gt;&lt;span&gt;two-factor authentication&lt;/span&gt;&lt;/a&gt;&lt;span&gt; isn&#039;t already on, now is the time to do so. For social media accounts, consider switching the account to &quot;private,&quot; where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you&#039;re less likely to encounter stressful content when on the app. Every app&#039;s options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Shut Down Affected Accounts&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;If a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you&#039;ve done so and things have cooled off.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Revisit Your Data Broker Removal Strategies&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Although this is more of a doxxing preventative measure, it&#039;s a good idea to get on top of removing the information that&#039;s available about you via data brokers. In case you&#039;re unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, &lt;/span&gt;&lt;a href=&quot;https://innovation.consumerreports.org/new-report-data-defense-evaluating-people-search-site-removal-services/&quot;&gt;&lt;span&gt;a recent study&lt;/span&gt;&lt;/a&gt;&lt;span&gt; revealed that &lt;/span&gt;&lt;a href=&quot;https://github.com/yaelwrites/big-ass-data-broker-opt-out-list&quot;&gt;&lt;span&gt;doing it DIY&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you&#039;d rather have someone else take care of it.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Revisit Public Records&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;As covered in the &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management&quot;&gt;previous blog post&lt;/a&gt;, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren&#039;t able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Consider Contacting Law Enforcement&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;For many, talking to &lt;/span&gt;&lt;a href=&quot;https://magazine.publichealth.jhu.edu/2022/physical-and-mental-impact-contact-police&quot;&gt;&lt;span&gt;law enforcement will only make things worse&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that&#039;s a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you&#039;re dealing with. It&#039;s in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Revisit PACE Documents, Enact Those Steps&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;If you&#039;re involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/files/2026/08/28/screenshot_2026-08-28_at_2.56.36_pm.png&quot; width=&quot;1330&quot; height=&quot;262&quot; alt=&quot;Example spreadsheet of a PACE document for a hypothetical group attending a protest. It has four columns, Primary, Alternate, Contingency, and Emergency. Each column describes what the hypothetical group plans to do in the event of various disruptions taking place, with agreements to each other about communications strategies, meeting times and places.&quot; title=&quot;Example spreadsheet of a PACE document for a hypothetical group attending a protest. It has four columns, Primary, Alternate, Contingency, and Emergency. Each column describes what the hypothetical group plans to do in the event of various disruptions taking place, with agreements to each other about communications strategies, meeting times and places.&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This is another step that&#039;s best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Put A Lock on Your Bank Accounts and Cell Subscriptions&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;One of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: &lt;/span&gt;&lt;a href=&quot;https://www.verizon.com/about/account-security/sim-swapping&quot;&gt;&lt;span&gt;Verizon&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href=&quot;https://www.att.com/support/article/wireless/000102016/&quot;&gt;&lt;span&gt;AT&amp;amp;T&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href=&quot;https://www.t-mobile.com/support/plans-features/help-with-t-mobile-account-fraud&quot;&gt;&lt;span&gt;T-Mobile&lt;/span&gt;&lt;/a&gt;&lt;span&gt;).&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Regulate Your Nervous System&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;It’s an understatement to say that being doxxed is scary and potentially very dysregulating. You&#039;re much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Flexibility and Resiliency&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management&quot;&gt;the previous one,&lt;/a&gt; and stay clued into the strategies laid out on &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/&quot;&gt;&lt;span&gt;Surveillance Self-Defense&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, you&#039;re well on your way.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 31 Aug 2026 19:02:37 +0000</pubDate>
 <guid isPermaLink="false">112305 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/security-education">Security Education</category>
 <dc:creator>Daly Barnett</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/communityprivacy-kittens.jpg" alt="People tend to a community garden of wifi poppies -- the raised bed is a neighborhood block of businesses." type="image/jpeg" length="901248" />
  </item>
  <item>
    <title>Doxxing Safety Pt I: Prevention and Footprint Management</title>
    <link>https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It&#039;s a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there&#039;s little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there&#039;s a lot you can do to &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/how-to-manage-your-digital-footprint&quot;&gt;&lt;span&gt;reduce your digital footprint&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and take control of your data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This post is part one of a &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/doxxing-safety-part-ii-incident-response&quot;&gt;two-part series&lt;/a&gt; discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/doxxing-safety-part-ii-incident-response&quot;&gt;The second&lt;/a&gt; focuses on incident response, as in, steps to take if you&#039;re in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it&#039;s worth reading each and gaining familiarity with the steps well ahead of time.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;OSINT&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Open source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different &lt;/span&gt;&lt;a href=&quot;https://start.me/p/L1rEYQ/osint4all&quot;&gt;&lt;span&gt;OSINT resource&lt;/span&gt;&lt;/a&gt; &lt;a href=&quot;https://osintframework.com/&quot;&gt;&lt;span&gt;lists that index&lt;/span&gt;&lt;/a&gt;&lt;span&gt; together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Breach Databases&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;When a company gets hacked and their &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/breachies-2025-worst-weirdest-most-impactful-data-breaches-year&quot;&gt;&lt;span&gt;customer data is leaked&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, that information often ends up in “breach databases,” that is, troves of peoples&#039; data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like &lt;/span&gt;&lt;a href=&quot;https://haveibeenpwned.com/&quot;&gt;&lt;span&gt;haveibeenpwned&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like &lt;/span&gt;&lt;a href=&quot;https://dehashed.com/&quot;&gt;&lt;span&gt;DeHashed&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, offer a similar sort of tracking, but for a fee. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;You may not have control over a company&#039;s digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Open Records&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Public records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Instead of requiring a formal request through the courts, &lt;/span&gt;&lt;a href=&quot;https://voterrecords.com/&quot;&gt;&lt;span&gt;mirroring sites&lt;/span&gt;&lt;/a&gt;&lt;span&gt; make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Some states have programs called “&lt;/span&gt;&lt;a href=&quot;https://trynova.org/wp-content/uploads/2026/02/US-State-Address-Confidentiality-Programs-List-1.pdf&quot;&gt;&lt;span&gt;Address Confidentiality Programs&lt;/span&gt;&lt;/a&gt;&lt;span&gt;” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Social Media&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Going through and &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/protecting-yourself-social-networks&quot;&gt;&lt;span&gt;tightening the security and privacy settings&lt;/span&gt;&lt;/a&gt;&lt;span&gt; of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;To get a quick overview of the various accounts you have registered online, especially if you&#039;ve been online for a long time, use a username search engine like &lt;/span&gt;&lt;a href=&quot;https://whatsmyname.app/&quot;&gt;&lt;span&gt;What&#039;s My Name&lt;/span&gt;&lt;/a&gt;&lt;span&gt; or &lt;/span&gt;&lt;a href=&quot;https://namechk.com/&quot;&gt;&lt;span&gt;Namechk&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Data Brokers and Removals&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Data brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/04/digital-privacy-legislation-civil-rights-legislation&quot;&gt;&lt;span&gt;is no more&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, it&#039;s up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. &lt;/span&gt;&lt;a href=&quot;https://github.com/yaelwrites/big-ass-data-broker-opt-out-list&quot;&gt;&lt;span&gt;Yael Grauer&#039;s BADBOOL project&lt;/span&gt;&lt;/a&gt;&lt;span&gt; compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. &lt;/span&gt;&lt;a href=&quot;https://innovation.consumerreports.org/new-report-data-defense-evaluating-people-search-site-removal-services/&quot;&gt;&lt;span&gt;Though they&#039;ve been found to be less effective&lt;/span&gt;&lt;/a&gt;&lt;span&gt; than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/what-you-need-know-about-californias-drop-tool&quot;&gt;&lt;span&gt;easily opt out through the new and exciting DROP tool&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Reverse Image Searching and FR Services&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Services like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They &lt;/span&gt;&lt;a href=&quot;https://pimeyes.com/en/blog/the-role-of-ai-and-face-search-in-modern-law-enforcement&quot;&gt;&lt;span&gt;contribute to law enforcement&lt;/span&gt;&lt;/a&gt;&lt;span&gt; investigations and predictive policing systems, as well as &lt;/span&gt;&lt;a href=&quot;https://www.npr.org/2023/10/11/1204822946/facial-recognition-search-engine-ai-pim-eyes-google&quot;&gt;&lt;span&gt;providing commercial services to abusers and stalkers&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you&#039;re under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Extra Monitoring, Automated&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you&#039;re in the Google ecosystem of products, consider enrolling in their &lt;/span&gt;&lt;a href=&quot;https://landing.google.com/intl/en_in/advancedprotection/&quot;&gt;&lt;span&gt;Advanced Protection Program&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which offers a number of different features to keep you and your account safe. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you&#039;re the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like &lt;/span&gt;&lt;a href=&quot;https://openmeasures.io/&quot;&gt;&lt;span&gt;Open Measures&lt;/span&gt;&lt;/a&gt;&lt;span&gt; is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Get Others Involved&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Coordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using &lt;/span&gt;&lt;a href=&quot;https://signal.org/&quot;&gt;&lt;span&gt;secure technology&lt;/span&gt;&lt;/a&gt;&lt;span&gt; like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;It&#039;s a Process; Keep Yourself Apace for the Marathon, Not the Race&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;The process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don&#039;t underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you&#039;re first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/&quot;&gt;&lt;span&gt;Surveillance Self-Defense project&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 31 Aug 2026 18:52:45 +0000</pubDate>
 <guid isPermaLink="false">112304 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/security-education">Security Education</category>
 <dc:creator>Daly Barnett</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/communityprivacy-kittens.jpg" alt="People tend to a community garden of wifi poppies -- the raised bed is a neighborhood block of businesses." type="image/jpeg" length="901248" />
  </item>
  <item>
    <title>Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections</title>
    <link>https://www.eff.org/deeplinks/2026/08/privacy-map-part-2-progress-pitfalls-and-fight-enforceable-location-data</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Regulating commercial location tracking has reached a turning point. Last year, we published &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/privacy-map-how-states-are-fighting-location-surveillance&quot;&gt;our rubric&lt;/a&gt;&lt;/span&gt; for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with &lt;span&gt;&lt;a href=&quot;https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF&quot;&gt;Connecticut&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf&quot;&gt;Maryland&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://njleg.state.nj.us/bill-search/2026/A5328/bill-text?f=A5500&amp;amp;n=5328_R1&quot;&gt;New Jersey&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://olis.oregonlegislature.gov/liz/2025R1/Downloads/MeasureDocument/HB2008/Enrolled&quot;&gt;Oregon&lt;/a&gt;,&lt;/span&gt; and &lt;span&gt;&lt;a href=&quot;https://lis.blob.core.windows.net/files/1222750.PDF&quot;&gt;Virginia&lt;/a&gt;&lt;/span&gt; enacting new consumer privacy restraints on an industry that profits off our physical movements.&lt;/p&gt;
&lt;p&gt;Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Why Location Privacy Is Important&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Imagine spending a couple of hours in a coffee shop, a friend&#039;s house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.&lt;/p&gt;
&lt;p&gt;This is the reality of &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/04/googles-sensorvault-can-tell-police-where-youve-been&quot;&gt;geofence warrants&lt;/a&gt; for &lt;a href=&quot;https://www.eff.org/issues/location-privacy&quot;&gt;location data&lt;/a&gt;&lt;/span&gt;, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-data&quot;&gt;&lt;em&gt;Chatrie v. United States&lt;/em&gt;&lt;/a&gt;&lt;/span&gt;. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court&#039;s ruling in &lt;em&gt;Chatrie&lt;/em&gt; established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data&quot;&gt;commercial data brokers&lt;/a&gt;&lt;/span&gt; operating in a largely &lt;span&gt;&lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-will-ban-inmarket-selling-precise-consumer-location-data?utm_source=govdelivery&quot;&gt;unregulated market&lt;/a&gt;&lt;/span&gt;. These brokers regularly harvest, aggregate, and sell physical location data to &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/11/creators-police-location-tracking-tool-arent-vetting-buyers-heres-how-protect&quot;&gt;anyone with a credit card&lt;/a&gt;&lt;/span&gt; (including government agencies, which are among &lt;span&gt;&lt;a href=&quot;https://www.npr.org/2026/03/25/nx-s1-5752369/ice-surveillance-data-brokers-congress-anthropic&quot;&gt;their regular clients&lt;/a&gt;&lt;/span&gt;). Especially for individuals seeking &lt;span&gt;&lt;a href=&quot;https://www.404media.co/inside-the-u-s-government-bought-tool-that-can-track-phones-at-abortion-clinics/&quot;&gt;reproductive or gender-affirming care&lt;/a&gt;&lt;/span&gt;, attending a &lt;span&gt;&lt;a href=&quot;https://www.icnl.org/post/analysis/protesting-in-an-age-of-government-surveillance&quot;&gt;protest&lt;/a&gt;&lt;/span&gt;, or visiting an &lt;span&gt;&lt;a href=&quot;https://www.theverge.com/2022/5/10/23065080/ice-surveillance-dragnet-data-brokers-georgetown-law&quot;&gt;immigration law clinic,&lt;/a&gt;&lt;/span&gt; this pervasive commercial location surveillance represents an immediate threat.&lt;/p&gt;
&lt;p&gt;In &lt;span&gt;&lt;a href=&quot;http://www.eff.org/deeplinks/2025/04/privacy-map-how-states-are-fighting-location-surveillance&quot;&gt;Part 1 of this series&lt;/a&gt;&lt;/span&gt;, we urged lawmakers to &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/12/location-tracking-tools-endanger-abortion-access-lawmakers-must-act-now&quot;&gt;protect people from the growing harms&lt;/a&gt;&lt;/span&gt; of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars &lt;a href=&quot;https://www.washingtonpost.com/dc-md-va/2023/03/09/catholics-gay-priests-grindr-data-bishops/&quot;&gt;buying app location data to track priests across multiple dioceses&lt;/a&gt; and used app-harvested location data to &lt;span&gt;&lt;a href=&quot;https://www.courthousenews.com/priest-outed-via-grindr-app-highlights-rampant-data-tracking/&quot;&gt;“out” a priest&lt;/a&gt;&lt;/span&gt; after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to &lt;span&gt;&lt;a href=&quot;https://www.404media.co/inside-the-u-s-government-bought-tool-that-can-track-phones-at-abortion-clinics/&quot;&gt;Locate X&lt;/a&gt;&lt;/span&gt;, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like &lt;span&gt;&lt;a href=&quot;https://www.lawfaremedia.org/article/data-broker-caught-running-anti-abortion-ads%E2%80%94-people-sitting-clinics&quot;&gt;Near Intelligence&lt;/a&gt;&lt;/span&gt; have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to &lt;a href=&quot;https://www.reuters.com/business/media-telecom/pentagon-says-us-military-personnel-are-reportedly-being-targeted-using-location-2026-05-28/&quot;&gt;locate U.S. military personnel in war zones.&lt;/a&gt; Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how&quot;&gt;real-time bidding ad networks&lt;/a&gt;&lt;/span&gt; to track individuals attending &lt;span&gt;&lt;a href=&quot;https://www.ftc.gov/system/files/ftc_gov/pdf/2023196mobilewallacomplaint.pdf&quot;&gt;demonstrations&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy&quot;&gt;a recent EFF investigation&lt;/a&gt; identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users&#039; location data whenever app-level location permissions are granted. These advertising libraries automatically feed users&#039; location data into &lt;a href=&quot;https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-fuel-surveillance-industry-heres-how&quot;&gt;ad systems that location data brokers &lt;/a&gt;have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;State Legislative Progress&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Last year, we outlined &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/privacy-map-how-states-are-fighting-location-surveillance&quot;&gt;six essential core principles&lt;/a&gt;&lt;/span&gt; that any meaningful location privacy law must contain:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Strong definitions,&lt;/li&gt;
&lt;li&gt;Clear rules,&lt;/li&gt;
&lt;li&gt;Affirmation that all precise geolocation data is sensitive,&lt;/li&gt;
&lt;li&gt;Empowerment of consumers through a strong private right of action,&lt;/li&gt;
&lt;li&gt;Prohibition of “pay-for-privacy” schemes, and&lt;/li&gt;
&lt;li&gt;Transparency through clear privacy policies.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While the bills we highlighted from &lt;span&gt;&lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1355&quot;&gt;California&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://www.ilga.gov/legislation/billstatus.asp?DocNum=3712&amp;amp;GAID=18&amp;amp;GA=104&amp;amp;DocTypeID=HB&amp;amp;LegID=162535&amp;amp;SessionID=114&quot;&gt;Illinois&lt;/a&gt;&lt;/span&gt;, and&lt;span&gt; &lt;a href=&quot;https://malegislature.gov/Bills/194/S197&quot;&gt;Massachusetts&lt;/a&gt;&lt;/span&gt; are yet to pass into law, a new wave of state location privacy legislation has taken effect across &lt;span&gt;&lt;a href=&quot;https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF&quot;&gt;Connecticut&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf&quot;&gt;Maryland&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://njleg.state.nj.us/bill-search/2026/A5328/bill-text?f=A5500&amp;amp;n=5328_R1&quot;&gt;New Jersey&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://olis.oregonlegislature.gov/liz/2025R1/Downloads/MeasureDocument/HB2008/Enrolled&quot;&gt;Oregon&lt;/a&gt;, and &lt;a href=&quot;https://lis.blob.core.windows.net/files/1222750.PDF&quot;&gt;Virginia&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;These five laws represent progress, and share two strong features.  First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (&lt;span&gt;&lt;a href=&quot;https://www.ilga.gov/Legislation/ILCS/Articles?ActID=3004&amp;amp;ChapterID=57&quot;&gt;BIPA&lt;/a&gt;&lt;/span&gt;), which bans the sale of biometric information such as face scans.&lt;/p&gt;
&lt;p&gt;Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from&lt;span&gt; &lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB45&amp;amp;firstNav=tracking&quot;&gt;California’s A.B. 45&lt;/a&gt;&lt;/span&gt; of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.&lt;/p&gt;
&lt;p&gt;These five laws vary regarding whether, on top of the ban on sale, they require &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/06/how-build-washingtons-my-health-my-data-act&quot;&gt;consent and/or minimization&lt;/a&gt;&lt;/span&gt; for other kinds of processing of precise geolocation data. &lt;span&gt;&lt;a href=&quot;https://oag.maryland.gov/resources-info/Pages/data-privacy.aspx&quot;&gt;Maryland’s Online Data Privacy Act (MODPA&lt;/a&gt;&lt;/span&gt;) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “&lt;span&gt;&lt;a href=&quot;https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf?ref=SB_14062021-KB_05072021-KB_05072021-cydoc-cydoc-cydoc-cydoc-SFB2802025&quot;&gt;strictly necessary&lt;/a&gt;&lt;/span&gt; to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;a href=&quot;https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF&quot;&gt;Connecticut&lt;/a&gt;&lt;/span&gt; requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;a href=&quot;https://njleg.state.nj.us/bill-search/2026/A5328/bill-text?f=A5500&amp;amp;n=5328_R1&quot;&gt;New Jersey&lt;/a&gt;&lt;/span&gt; requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;a href=&quot;https://lis.blob.core.windows.net/files/1222750.PDF&quot;&gt;Virginia&lt;/a&gt;&lt;/span&gt; protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”&lt;/p&gt;
&lt;p&gt;Beyond its ban on sale, &lt;span&gt;&lt;a href=&quot;https://olis.oregonlegislature.gov/liz/2025R1/Downloads/MeasureDocument/HB2008/Enrolled&quot;&gt;Oregon&lt;/a&gt;&lt;/span&gt; does not limit the processing of precise geolocation data.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Gaps in Current Legislation&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;While these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;The Enforcement Void: Why Every Law Needs a Private Right of Action&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;A privacy law without a&lt;span&gt; &lt;a href=&quot;https://www.eff.org/deeplinks/2019/01/you-should-have-right-sue-companies-violate-your-privacy&quot;&gt;Private Right of Action&lt;/a&gt;&lt;/span&gt; is a law &quot;without&lt;span&gt; &lt;a href=&quot;https://idioms.thefreedictionary.com/toothless+laws&quot;&gt;teeth&lt;/a&gt;&lt;/span&gt;”.&lt;/p&gt;
&lt;p&gt;None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.&lt;/p&gt;
&lt;p&gt;The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (&lt;span&gt;&lt;a href=&quot;https://www.nclc.org/topic/unfair-deceptive-and-abusive-practices-udap/&quot;&gt;UDAP&lt;/a&gt;&lt;/span&gt;). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.&lt;/p&gt;
&lt;p&gt;Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2022/04/stop-forced-arbitration-data-privacy-legislation&quot;&gt;mandatory arbitration&lt;/a&gt;&lt;/span&gt;. This ensures that compliance isn&#039;t optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;The &quot;Pay-for-Privacy&quot; Trap&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Privacy is a fundamental right, not a luxury tier. So EFF opposes &lt;a href=&quot;https://www.eff.org/deeplinks/2020/10/why-getting-paid-your-data-bad-deal&quot;&gt;pay-for-privacy schemes&lt;/a&gt;, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.&lt;/p&gt;
&lt;p&gt;Unfortunately, all three of these states that require consent to process precise geolocation information (&lt;span&gt;&lt;a href=&quot;https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF&quot;&gt;Connecticut&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://law.justia.com/codes/new-jersey/title-56/section-56-8-166-8/&quot;&gt;New Jersey&lt;/a&gt;&lt;/span&gt;, and &lt;span&gt;&lt;a href=&quot;https://lis.blob.core.windows.net/files/1222750.PDF&quot;&gt;Virginia&lt;/a&gt;&lt;/span&gt;) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/privacy-map-how-states-are-fighting-location-surveillance&quot;&gt;eschew this loophole&lt;/a&gt;&lt;/span&gt;, as in the ban on pay-for-privacy in &lt;a href=&quot;https://www.eff.org/deeplinks/2025/04/privacy-map-how-states-are-fighting-location-surveillance&quot;&gt;last year’s location data privacy bills in Illinois and Massachusetts&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2020/10/why-getting-paid-your-data-bad-deal&quot;&gt;in exchange for essential discounts or services&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Dark Patterns&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Any law that requires consent also needs to ban company techniques that subvert consent. These are often called &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/02/designing-welcome-mats-invite-user-privacy-0&quot;&gt;dark patterns&lt;/a&gt;&lt;/span&gt;, &lt;span&gt;&lt;a href=&quot;https://www.consumerreports.org/electronics/internet-of-things/smart-devices-trying-to-manipulate-you-with-dark-patterns-a6366326597/&quot;&gt;predatory design&lt;/a&gt;&lt;/span&gt;, and &lt;span&gt;&lt;a href=&quot;https://uxdesign.cc/user-manipulation-thinking-beyond-dark-patterns-3d17cf408753&quot;&gt;manipulative user interface (UI/UX) practices&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.&lt;/p&gt;
&lt;p&gt;To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult&lt;span&gt; &lt;a href=&quot;https://ssd.eff.org/&quot;&gt;EFF&#039;s Surveillance Self-Defense Guide&lt;/a&gt;&lt;/span&gt; to learn practical steps for reducing location tracking on their personal devices.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 31 Aug 2026 16:49:34 +0000</pubDate>
 <guid isPermaLink="false">112303 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/location-privacy">Locational Privacy</category>
 <dc:creator>Rindala Alajaji</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/locationdata_v2.mov1_.gif" alt="An animated image showing location pins dropping onto a street map from above, tracing several paths" type="image/gif" length="2071190" />
  </item>
  <item>
    <title>LGBT Q&amp;A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person? </title>
    <link>https://www.eff.org/deeplinks/2026/08/lgbt-qa-whats-one-thing-i-can-do-today-improve-my-safety-and-security-online-lgbtq</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;i&gt;&lt;span&gt;This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our &lt;a href=&quot;https://www.tiktok.com/@efforg/video/7678719236637756686&quot;&gt;TikTok&lt;/a&gt; or &lt;a href=&quot;https://www.instagram.com/p/DctbDCRIGei/&quot;&gt;Instagram&lt;/a&gt; to watch! &lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF answers all the queer digital rights questions you submit to us through our &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/06/lgbt-qa-were-back-season-2&quot;&gt;&lt;span&gt;LGBT Q&amp;amp;A&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. You asked us: &lt;/span&gt;&lt;b&gt;What’s one thing I can do today to improve my safety and security online as an LGBTQ+ person? &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;i&gt;And for this question, we’ve brought in our friends from the Trevor Project to answer together:&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Hi, I’m Tommy from the &lt;/span&gt;&lt;a href=&quot;http://thetrevorproject.org&quot;&gt;&lt;span&gt;Trevor Project&lt;/span&gt;&lt;/a&gt;&lt;span&gt;! The Trevor Project’s mission is to end suicide among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ+) young people. Our vision is to create a world where all LGBTQ+ young people see a bright future for themselves.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF and the Trevor Project know that digital security and online safety can feel overwhelming, especially because we all have different levels of concern for different parts of our online lives. Some might be focused on the dangers of doxxing, another might only want to ensure they&#039;re not outed. And queer people can be particularly vulnerable to these kinds of online threats. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;This might seem like a big task, but the one way you can do today to protect yourself is to revise the information you’ve shared with services and platforms to ensure you’re as in control of your information and data as possible:&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Protect Your Personal Information&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Be cautious about sharing sensitive details like your full name, address, school, phone number, and personal photos as it might expose identifying information you want to keep private. Consider using an avatar as your profile picture to avoid sharing your personal photos if that makes you more comfortable. Keep it lowkey when talking about work stuff or sharing details about where you’re studying.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you do share personal photos, don’t accompany them with information that identifies your location or frequent whereabouts, and make sure &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/attending-protest#scrub-metadata-on-photos&quot;&gt;&lt;span&gt;EXIF data in photos is turned off&lt;/span&gt;&lt;/a&gt;&lt;span&gt; (which could inadvertently include your location); the easiest way to do this is to take a screenshot of the photo and share that instead. Don’t post pictures with obvious spots in the background, like your front door or porch. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Understand the Importance of Login Information&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;When you create an account on websites and platforms, you can often use your phone number or a third party account, such as Facebook, Google, or Apple. These external accounts might share data with the apps you&#039;re logging into, but they can be helpful if you struggle with managing a lot of logins. Deciding if that trade-off is worth it is up to you but, when you can, use strong, unique passwords for your accounts, and be sure to enable two-factor authentication when offered.&lt;span&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Review Permissions with Social Media Apps&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;Review which apps have access to things like your location and camera roll, and possibly change those permissions in line with what information you would like to keep private. Location is particularly important&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt; For example, some apps might need some location information to function. But you can typically at least deny access to your device&#039;s &quot;precise location&quot; or enter in a city or zip code manually.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Consider What You Share When Speaking with Others Online&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;It’s important to be mindful of what you share with others when you post online or speak with people. Avoid disclosing sensitive information like financial details, and trust your gut if something feels off. It’s also useful to review your profile’s privacy settings and information now and again to make sure you’re still comfortable sharing what you’ve listed there.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Good privacy decisions begin with proper &lt;/span&gt;&lt;a href=&quot;https://ssd.eff.org/module/seven-steps-digital-security#2-the-weakest-link&quot;&gt;&lt;span&gt;knowledge&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about your situation and a &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/privacy-loves-company&quot;&gt;&lt;span&gt;community-oriented approach&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. To dig in deeper, read EFF’s blog post on &lt;/span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/02/building-community-privacy-plan&quot;&gt;&lt;span&gt;Building a Community Privacy Plan&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and the Trevor Project’s &lt;/span&gt;&lt;a href=&quot;https://www.thetrevorproject.org/resources/guide/online-safety-for-lgbtq-young-people/&quot;&gt;&lt;span&gt;Guide to Online Safety for LGBTQ+ Young People&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Mon, 31 Aug 2026 15:57:37 +0000</pubDate>
 <guid isPermaLink="false">112256 at https://www.eff.org</guid>
 <dc:creator>Paige Collings</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/pride-banner.jpg" alt="EFF&amp;#039;s LGBT Q&amp;amp;A, cat in a spacesuit surrounded by planets with pride flag colors" type="image/jpeg" length="169538" />
  </item>
  <item>
    <title>EFF and Allies on Brazil&#039;s Elections: Privacy Protections are Crucial to Electoral Integrity </title>
    <link>https://www.eff.org/deeplinks/2026/08/eff-and-allies-brazils-elections-privacy-protections-are-crucial-electoral</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil&#039;s elections. The recommendations stress the close relationship between violations of personal data protection and challenges to the integrity of electoral processes. They underscore how privacy and data protection guarantees are a crucial tool for curbing the targeted spread of false or manipulative content and other problematic strategies used by political actors that are amplified by digital technologies such as artificial intelligence systems.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The recommendations are part of a &lt;/span&gt;&lt;a href=&quot;https://www.accessnow.org/publication/vinculo-entre-desinformacion-y-privacidad/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;broader regional initiative&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; and build on the legal and institutional safeguards already in place in Brazil. They seek to promote greater coordination among oversight institutions, civil society, and digital platforms, and encourage the solid implementation of privacy and data protection guarantees as drivers of electoral integrity. Read the full document below.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span data-contrast=&quot;none&quot;&gt;The Link Between the Integrity of the Electoral Process and Privacy&lt;/span&gt;&lt;span data-ccp-props=&quot;80}&quot;&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Protecting the integrity of the electoral process in the face of internet and social media use is a challenge that many policymakers are addressing or are willing to address. Online, content that can affect the integrity of the electoral process is increasingly personalized. This phenomenon is so concerning &lt;/span&gt;&lt;a href=&quot;https://www.weforum.org/publications/global-risks-report-2026/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;that it has been identified as one of the main global short- and medium-term risks&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;In an era of generative AI, the economic cost and technical difficulty of producing and spreading false or synthetic content to deceive, manipulate, or simulate authenticity have been considerably reduced. That intensifies concern over the integrity of the electoral process. Meanwhile, online privacy and personal data protection remain unfinished business in Latin America.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;There is an intrinsic connection between the ability to collect and process large amounts of personal data and the way false or manipulative content is created and distributed—on social media and messaging apps in particular, and on the internet in general. For this reason, applying strict laws and policies on personal data protection and privacy makes it possible to reduce the impact of false or manipulative content. This is especially important in electoral contexts, where such content affects and impoverishes public debate, directly affecting political and electoral rights and the integrity of the electoral process.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://moadoph.gov.au/explore/democracy/the-history-of-misinformation-and-disinformation&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;This phenomenon predates the emergence of the internet&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. However, the rise of new technologies accelerates the generation and spread of false and manipulative content. This is supported by the very economic model that sustains the platforms, amplifying its effectiveness and reach. On the one hand, social media platforms have content recommendation algorithms that use personal data to generate profiles to which they can then serve targeted advertising content, including explicitly political propaganda. This technique is known as &quot;microtargeting.&quot;&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://policyreview.info/articles/analysis/double-harm-voters-data-driven-micro-targeting-and-democratic-public-discourse&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Political microtargeting seeks to have a direct or indirect impact on democracy&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;. It is used to persuade voters, to encourage or discourage turnout at the polls, or to raise funds using information that is deliberately taken out of context, inaccurate, or erroneous.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;The control exercised by these companies raises serious concerns about people&#039;s rights. By having access to massive amounts of personal information, these companies have the ability to shape the content that users see and interact with. This happens through the construction of profiles that can reveal habits, social relationships, political preferences, and opinions, to mention a few examples. Personal data is the fuel that amplifies risks to the integrity of the electoral process. That’s true whether it’s provided by the users themselves or generated by the platforms from their interactions online.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;For disinformation actors, access to sophisticated tools—such as those used to create &quot;deepfakes&quot; through generative AI, or &quot;bots&quot; programmed to spread content and seek to manipulate public opinion—&lt;/span&gt;&lt;a href=&quot;https://www.cambridge.org/core/journals/data-and-policy/article/role-of-artificial-intelligence-in-disinformation/7C4BF6CA35184F149143DE968FC4C3B6&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;boosts the effectiveness&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; of this microtargeting in terms of quality and scalability, making it harder to detect as false or manipulative content. &lt;/span&gt;&lt;a href=&quot;https://olhardigital.com.br/2026/05/04/pro/eleicoes-2026-ia-cria-eleitores-sinteticos-e-faz-em-horas-o-trabalho-de-dias/&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;AI-generated avatars and synthetic characters that simulate voters&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt;, influencers, hosts, commentators, or community leaders can produce footage that appears spontaneous, fabricate the voices of artificial political actors, and make it harder for users to identify if a given public statement was created or mediated by technology.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;In this context, paid promotion with nanotargeting &lt;/span&gt;&lt;a href=&quot;https://www1.folha.uol.com.br/poder/2026/05/inteligencia-artificial-provoca-terremoto-em-campanhas-eleitorais-de-2026.shtml&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;seeks to reach&lt;/span&gt;&lt;/a&gt;&lt;span data-contrast=&quot;none&quot;&gt; increasingly specific profiles with customized content, and AI-based tools are used to assess and map its impact on social networks. Drawing on the personal data of groups of voters, profiles of &quot;synthetic voters&quot; are created to test messages or strategies in search of the most efficient way to influence real voters.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;This rapid expansion of AI systems and hyper-personalization with data can lead to a problem of &quot;epistemic erosion&quot; for democratic societies, as pointed out by the UN&#039;s Independent Scientific Panel on AI Governance in 2026.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;At Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation, we point to the enforcement of personal data protection laws and public privacy policies as an efficient mechanism for improving the quality of our democracies and reducing the manipulation of public discourse in digital environments and its impact in electoral contexts. Measures to broaden access to information for electoral decision-making, and to ensure transparency about campaigns&#039; and political parties&#039; use of digital technologies built on the massive processing of personal data, also play a relevant role in guaranteeing the integrity of the electoral process.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span data-contrast=&quot;none&quot;&gt;Recommendations for Safeguarding the Integrity of Electoral Processes in Brazil in the Face of New Technologies&lt;/span&gt;&lt;span data-ccp-props=&quot;80}&quot;&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Concern about the effects of spreading false, manipulative, or deliberately decontextualized content is particularly heightened in electoral contexts. From Argentina to Mexico, many countries in Latin America, including Brazil, are holding or will hold significant electoral processes in the coming period.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Providing the public with quality information from a range of sources is an essential element for the exercise of political rights. In order to safeguard the electoral process, these countries must enforce their privacy and personal data protection laws through their competent authorities, in coordination with their judiciaries and electoral courts.&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation propose the following recommendations to protect the integrity of the electoral process by guaranteeing privacy and data protection during electoral contexts:&lt;/span&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;192}&quot;&gt;1. Strengthen personal data protection guarantees and policies as a key element for the integrity of the electoral process, in particular the principles of necessity, purpose, and proportionality:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Prohibit the processing of sensitive personal data (such as philosophical beliefs and the labeling of ideological leanings), including inferred data, that reveals or could reveal people&#039;s political preferences for the purpose of targeting political content. In electoral contexts, the processing of sensitive personal data is only legitimate when the person has given their consent in advance, explicitly, and with strictly limited and clearly disclosed purposes of use and transfer.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Processing must be carried out only on personal data that is strictly necessary for the purpose being pursued.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Prohibit adding users to instant messaging groups for political outreach purposes, except in exceptional cases involving lists of political party members or where prior and informed consent has been given by the data subject.&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Free, specific, and informed consent means that the person is able to make a real choice, set apart from other choices, and does not run any risk of deception, intimidation, coercion, denial of access to products or services, or other significant negative consequences if they do not give their consent.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;2. Political parties, federations, and coalitions must improve the information made available to the general public about their personal data processing activities in electoral contexts, including:&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li data-leveltext=&quot;%2.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;2&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;The personal data processing policy adopted, in compliance with data protection legislation and electoral legislation, including the measures adopted to prevent breaches of the general protection principles, to record personal data processing operations, to obtain consent appropriately, and to ensure technical and administrative security in data processing;&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%2.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;2&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Communication channels where the data subject can obtain information about the processing of their personal data, exercise the rights provided by law, and request to opt out of receiving electronic and instant messages.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%2.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;1&quot; data-aria-level=&quot;2&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Information about the profiling they carry out for electoral purposes and about the procurement and use of data-based digital technologies in this context, including for purposes of paid promotion, microtargeting, network analysis, and prediction of voters&#039; reactions or behavior.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;3. Strengthen cooperation mechanisms between the National Data Protection Authority (ANPD) and the Superior Electoral Court in order to:&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt;Improve communication channels and strengthen joint initiatives to oversee compliance with data protection guarantees in the electoral context, with the publication of periodic enforcement reports.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt;Identify and dismantle coordinated strategies that compromise the integrity of the electoral process and carry out online activities that pretend to be &quot;organic&quot; and citizen-based when they are in fact funded or coordinated by a party, government, or company, such as bot farms, fake personal accounts managed by a single entity, AI avatars and synthetic characters that simulate real voters in order to manipulate public opinion, among others.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li data-leveltext=&quot;%1.&quot; data-font=&quot;Open Sans&quot; data-listid=&quot;1&quot; data-list-defn-props=&quot;&amp;quot;hybridMultilevel&amp;quot;}&quot; data-aria-posinset=&quot;6&quot; data-aria-level=&quot;1&quot;&gt;&lt;span data-contrast=&quot;none&quot;&gt;Within the scope of their powers, require the preparation and publication of a data protection impact assessment in cases involving the use of sensitive personal data or emerging technologies for voter profiling.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;4. Authorities, political parties, communicators, and social media platforms must ensure, as far as possible, that the population has access to adequate and relevant information for electoral decision-making.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt;Political parties, electoral authorities, and data protection authorities must allocate a percentage of their communications budget to warning about the consequences of microtargeting in electoral contexts&lt;/span&gt;&lt;span&gt;;&lt;/span&gt;&lt;span data-contrast=&quot;none&quot;&gt; and about the use of AI avatars or synthetic voters to simulate support, rejection, outrage, or spontaneous political mobilization.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt;Strengthen alliances with fact-checkers and other relevant communicators, such as civil society organizations, influencers, and others, to identify campaigns that compromise the integrity of the electoral process and to inform the public about such alliances through different channels, including official government channels.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span data-contrast=&quot;none&quot;&gt;Systematize the electoral proposals developed by candidates and their electoral platforms according to thematic areas to facilitate comparison between political parties.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span data-contrast=&quot;none&quot;&gt;Agree on strategies between authorities and online platform companies, including social media platforms and chatbots, at the start of electoral periods, so that priority is given to content developed by electoral authorities.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span data-contrast=&quot;none&quot;&gt;Every body, protocol, or policy created that involves authorities or public entities must be communicated in accordance with proactive transparency standards.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;5. Platforms must disable microtargeting tools for political and electoral content during previously established periods.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt;6. Authorities, technical actors, academics, civil society, and/or social media platforms must collaborate in creating an algorithmic impact analysis lab that makes it possible to oversee compliance with these recommendations.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt;Produce reports on the results achieved, in particular those that document the existence of microtargeting, the use of personal data for targeting, and exposure to varied content in electoral contexts.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span data-contrast=&quot;none&quot;&gt;Establish strict cybersecurity protocols so that the labs prevent access to real users&#039; private information.&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span data-contrast=&quot;none&quot;&gt;7. The authorities responsible for overseeing personal data protection and electoral matters must have sufficient functional, economic, and technical autonomy and independence to guarantee the proper exercise of their powers.&lt;/span&gt;&lt;span data-ccp-props=&quot;120}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Fri, 28 Aug 2026 03:46:26 +0000</pubDate>
 <guid isPermaLink="false">112302 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/international">International</category>
 <dc:creator>Veridiana Alimonti</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/eff-work-icons-3-COLOR-fix.png" alt="EFF Work Icons" type="image/png" length="17132" />
  </item>
  <item>
    <title>A List of ICE Subpoenas to Tech Companies  </title>
    <link>https://www.eff.org/deeplinks/2026/08/list-ice-subpoenas-tech-companies</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.&lt;/p&gt;
&lt;p&gt;A favored tool in these speech chilling investigations are administrative subpoenas sent to technology companies, requesting basic subscriber data about their users. For example, from 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter (now X), according to documents obtained by &lt;a href=&quot;https://www.documentcloud.org/documents/?q=%2Bproject%3Afoia-on-ices-use-of-admi-214199%20&quot;&gt;Just Futures Law&lt;/a&gt;. In just the second half of 2025, the Department of Homeland Security (DHS) sent 21 administrative subpoenas to Reddit, according to its &lt;a href=&quot;https://redditinc.com/policies/transparency-report-july-to-december-2025-reddit&quot;&gt;Transparency Report&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;While some subpoenas are routine, ICE has been forced to withdraw others after &lt;a href=&quot;https://www.eff.org/deeplinks/2026/02/open-letter-tech-companies-protect-your-users-lawless-dhs-subpoenas&quot;&gt;users challenged them in court&lt;/a&gt; or &lt;a href=&quot;https://www.eff.org/deeplinks/2026/08/some-tech-companies-have-privately-pushed-back-ice-subpoenas-they-should-all-do&quot;&gt;companies pushed back&lt;/a&gt;. These challenged subpoenas exceeded the agency&#039;s statutory authority and violated users&#039; First Amendment rights.&lt;/p&gt;
&lt;p&gt;Below is a non-comprehensive list of DHS subpoenas that we gathered going back to 2025, looking at public reporting and court cases. This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report (so far, only Reddit appears to break out specific numbers on DHS subpoenas). In addition, DHS has been slow to respond to our &lt;a href=&quot;https://www.eff.org/cases/eff-v-dhs-ice-administrative-subpoenas&quot;&gt;Freedom of Information Act requests and lawsuits&lt;/a&gt; seeking records that would show how many administrative subpoenas ICE has sent to social media companies since 2025.&lt;/p&gt;
&lt;p&gt;If you know of other subpoenas that are not on this list, please reach out to info@eff.org. While the government has abused the subpoena process &lt;a href=&quot;https://www.nytimes.com/2026/03/13/us/politics/jerome-powell-trump-subpoenas.html&quot;&gt;in other areas&lt;/a&gt;, &lt;a href=&quot;https://www.aclu.org/press-releases/appeals-court-rejects-trump-administrations-latest-effort-to-seize-private-medical-records-of-transgender-new-yorkers&quot;&gt;particularly to hospitals&lt;/a&gt;, this list focuses on DHS and ICE subpoenas to technology companies for user data. &lt;/p&gt;
&lt;table&gt;

&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;&lt;strong&gt;DATE ISSUED &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;(and link to subpoena)&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;TARGETED COMPANY&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;INDIVIDUAL USER TARGETED &lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;OUTCOME &lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3/17/25&lt;/td&gt;
&lt;td&gt;Facebook &lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.cnn.com/2025/03/31/us/cornell-student-activist-deportation&quot;&gt;Momodou Taal&lt;/a&gt;, international student who attended pro-Palestinian protest&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://theintercept.com/2025/09/16/google-facebook-subpoena-ice-students-gaza/&quot;&gt;Withdrawn&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3/23/25&lt;/td&gt;
&lt;td&gt;Google &lt;/td&gt;
&lt;td&gt;&lt;span&gt;Momodou Taal, international student who attended pro-Palestinian protest&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://theintercept.com/2025/09/16/google-facebook-subpoena-ice-students-gaza/&quot;&gt;Withdrawn&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/files/2026/04/13/eff_letter_re_google_notice_-_exhibits.pdf&quot;&gt;4/1/25&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google &lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/google-broke-its-promise-me-now-ice-has-my-data&quot;&gt;Amandla Thomas-Johnson&lt;/a&gt;, international student who attended pro-Palestinian protest&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/files/2026/04/13/eff_letter_re_google_notice_-_exhibits.pdf&quot;&gt;Google disclosed data to ICE on 5/8/25&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://storage.courtlistener.com/recap/gov.uscourts.cand.456560/gov.uscourts.cand.456560.1.3.pdf&quot;&gt;9/4/25&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Meta &lt;/td&gt;
&lt;td&gt;6 accounts in Southern California that documented immigration activity, including &lt;a href=&quot;https://storage.courtlistener.com/recap/gov.uscourts.cand.456560/gov.uscourts.cand.456560.1.3.pdf&quot;&gt;LB_Protest&lt;/a&gt;, &lt;a href=&quot;https://koltunattorney.com/2025/11/doe-lbrrn-v-united-states-department-of-homeland-security/&quot;&gt;Long Beach Rapid Response Network&lt;/a&gt;, and &lt;a href=&quot;https://cldc.org/legality-of-exposing-ice/&quot;&gt;Stopice.net&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclunorcal.org/cases/j-doe-v-united-states-department-homeland-security-0/?document=Stipulation-of-Dismissal&quot;&gt;Withdrawn after court challenge on 11/24/25&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclupa.org/cases/doe_dhs/?document=001-4-Exhibit-B-to-Doe-Declaration#documents&quot;&gt;9/11/25&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;Meta (Instagram)&lt;/td&gt;
&lt;td&gt;Pennsylvania account called &quot;&lt;a href=&quot;https://www.nytimes.com/2026/02/13/technology/dhs-anti-ice-social-media.html&quot;&gt;MontCo Community Watch&lt;/a&gt;&quot; that documented immigration activity&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclupa.org/cases/doe_dhs/?document=037-Order-granting-stipulation-fo-dismissal#documents&quot;&gt;Withdrawn after court challenge on 1/16/26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclupa.org/cases/doe_dhs/?document=001-3-Exhibit-A-to-Doe-Declaration#documents&quot;&gt;9/11/25&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;&lt;span&gt;Meta (Facebook)&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;span&gt;Pennsylvania account called &quot;MontCo Community Watch&quot; that documented immigration activity&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclupa.org/cases/doe_dhs/?document=037-Order-granting-stipulation-fo-dismissal#documents&quot;&gt;Withdrawn after court challenge on 1/16/26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclu.org/cases/doe-v-dhs?document=Exhibit-E-to-Doe-Declaration#legal-documents&quot;&gt;10/30/25&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google &lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.washingtonpost.com/investigations/2026/02/03/homeland-security-administrative-subpoena/&quot;&gt;Retired Philadelphia user&lt;/a&gt; who emailed criticism to U.S. prosecutor  &lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclu.org/cases/doe-v-dhs?document=Notice-of-dismissal#legal-documents&quot;&gt;Withdrawn after court challenge on 2/5/26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.acludc.org/cases/challenging-dhs-action-to-unmask-social-media-critics/?document=Exhibit-A-Redacted-summons&quot;&gt;2/4/26&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Social media user&lt;span&gt; who regularly posts criticism of the President&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.aclu.org/press-releases/canadian-trump-critic-sues-to-stop-google-from-sharing-personal-information-with-department-of-homeland-security&quot;&gt;Subpoena challenged in Court&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/nd-cal-26-mc-80074-dckt-000001002&quot;&gt;2/19/26&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;Reddit&lt;/td&gt;
&lt;td&gt;&quot;Tired_Thumb,&quot; user who posted about ICE officer&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/files/2026/03/30/n.d._cal._26-mc-80074_dckt_000009_001_filed_2026-03-30-2.pdf&quot;&gt;Withdraw after court challenge on 3/27/26&lt;/a&gt;; &lt;a href=&quot;https://www.bloomberg.com/news/articles/2026-05-28/trump-s-doj-ramps-up-probes-of-anonymous-ice-critics-with-x-reddit-subpoenas?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NzE3MzUwMCwiZXhwIjoxNzg3Nzc4MzAwLCJhcnRpY2xlSWQiOiJURlFRRTJLR0lGVEYwMCIsImJjb25uZWN0SWQiOiIwRDUwMUFGOUVBRkU0NTI4ODk3RDQyNzNBMTlCNDY2NCJ9.KlolPSTeccwlI7o83GWm6T2kDC9v6_8KeKarMeLCDuI&quot;&gt;replaced with grand jury subpoena&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/wd-tex-26-mc-00861-dckt-000001002&quot;&gt;2/27/26&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;X&lt;/td&gt;
&lt;td&gt;&quot;podslurp,” who posted publicly available address information about ICE officer&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.bloomberg.com/news/articles/2026-05-28/trump-s-doj-ramps-up-probes-of-anonymous-ice-critics-with-x-reddit-subpoenas?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NzE3MzUwMCwiZXhwIjoxNzg3Nzc4MzAwLCJhcnRpY2xlSWQiOiJURlFRRTJLR0lGVEYwMCIsImJjb25uZWN0SWQiOiIwRDUwMUFGOUVBRkU0NTI4ODk3RDQyNzNBMTlCNDY2NCJ9.KlolPSTeccwlI7o83GWm6T2kDC9v6_8KeKarMeLCDuI&quot;&gt;Withdrawn May 2026; replaced with grand jury subpoena&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3/7/26&lt;/td&gt;
&lt;td&gt;PayPal/Venmo&lt;/td&gt;
&lt;td&gt;&quot;&lt;a href=&quot;https://storage.courtlistener.com/recap/gov.uscourts.mnd.234416/gov.uscourts.mnd.234416.212.0_2.pdf&quot;&gt;Voices of Racial Justice&lt;/a&gt;,&quot; a racial justice organization in Minnesota &lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/minn-26-cr-00115-dckt-000212010&quot;&gt;PayPal/Venmo disclosed data 3/20/26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/d-minn-26-cr-00025-dckt-000642004&quot;&gt;4/3/26&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;Google (YouTube)&lt;/td&gt;
&lt;td&gt;@TheDonLemonShow, GeorgiaFort, @DemocracyNow, and seven other accounts that reported on &lt;a href=&quot;https://www.nytimes.com/2026/01/30/us/who-is-georgia-fort-journalist-arrested-church-protest.html&quot;&gt;protest at Minnesota church&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/d-minn-26-cr-00025-dckt-000642006&quot;&gt;Google Objected 4/7/26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/d-minn-26-cr-00025-dckt-000642005&quot;&gt;4/12/26&lt;/a&gt;*&lt;/td&gt;
&lt;td&gt;T-Mobile&lt;/td&gt;
&lt;td&gt;Minnesota &lt;a href=&quot;https://www.eff.org/document/d-minn-26-cr-00025-dckt-000641000&quot;&gt;journalist Georgia Fort&lt;/a&gt; and others&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.eff.org/document/d-minn-26-cr-00025-dckt-000642007&quot;&gt;T-Mobile disclosed data on 4/12/26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;First half of 2025&lt;/td&gt;
&lt;td&gt;Reddit &lt;/td&gt;
&lt;td&gt;Reddit account&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://redditinc.com/policies/transparency-report-january-to-june-2025-reddit&quot;&gt;Subpoena withdrawn after questions from Reddit&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Second half of 2025&lt;/td&gt;
&lt;td&gt;Reddit &lt;/td&gt;
&lt;td&gt;11 Reddit accounts that posted content &quot;critical of ICE actions&quot;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://redditinc.com/policies/transparency-report-july-to-december-2025-reddit&quot;&gt;3 subpoenas withdrawn after Reddit objected&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;
&lt;p&gt;* = denotes summonses issued under 19 U.S.C. 1509, an authority that has been abused in the past, according to &lt;a href=&quot;https://www.oig.dhs.gov/sites/default/files/assets/Mga/2017/oig-18-18-nov17.pdf&quot;&gt;DHS&#039;s inspector general&lt;/a&gt;.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 26 Aug 2026 21:31:14 +0000</pubDate>
 <guid isPermaLink="false">112286 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <dc:creator>Mario Trujillo</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/law-4.png" alt="scales of justice icon + starburst" type="image/png" length="21589" />
  </item>
  <item>
    <title>EFF&#039;s Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms</title>
    <link>https://www.eff.org/deeplinks/2026/08/effs-policy-position-alpr-surveillance-eliminate-it-and-reduce-its-harms</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span&gt;Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool that can be made safe with the right policy or feature update—they are irredeemably harmful.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;pull-quote&quot;&gt;EFF&#039;s position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines.&lt;/p&gt;
&lt;p&gt;EFF&#039;s position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines. EFF applies every tool available to eliminate ALPR surveillance and the harm it enacts.&lt;/p&gt;
&lt;h4&gt;The Case Against ALPRs&lt;/h4&gt;
&lt;p&gt;&lt;em&gt;A note about scope: This post addresses ALPR mass surveillance. It does not address the wider universe of automated traffic enforcement (ATE) such as conventional red light and speed cameras that solely ticket a specific violation, without retaining or networking data on uninvolved drivers. But lawmakers and purchasers should guard against efforts by vendors to piggyback on ATE contracts to market ALPR mass surveillance systems.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;ALPRs are frequently marketed as a narrow tool for specific purposes, such as recovering stolen vehicles. But in practice, these sensors sweep up data on every driver who passes a camera, and store it in searchable databases. That indiscriminate collection and retention is precisely why ALPR-fed surveillance systems can be easily weaponized against immigrants, political dissidents, and other targeted communities as ICE and other federal agencies escalate their assault on civil liberties. There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it.&lt;/p&gt;
&lt;p&gt;Of course, ALPRs cause other predictable harms. Innocent drivers are recurringly &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/11/human-toll-alpr-errors&quot;&gt;arrested and menaced&lt;/a&gt;&lt;/span&gt; by police because of ALPR errors. Officers regularly abuse ALPR systems to &lt;span&gt;&lt;a href=&quot;https://www.404media.co/i-saw-a-shiny-thing-cop-explains-why-he-used-license-plate-reader-to-stalk-woman/&quot;&gt;stalk&lt;/a&gt;&lt;/span&gt; past and potential romantic partners. Creating any database of personal information—including ALPR surveillance databases—inherently creates &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2024/06/new-alpr-vulnerabilities-prove-mass-surveillance-public-safety-threat&quot;&gt;risk of data theft&lt;/a&gt;&lt;/span&gt; and subsequent harm to data subjects. And ALPR &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists&quot;&gt;surveillance of protests&lt;/a&gt;&lt;/span&gt; and targeting of activists chill participation in First Amendment-protected dissent. But even if these downstream harms could all be prevented (and they likely can’t), ALPRs would remain an intolerable form of mass surveillance.&lt;/p&gt;
&lt;h4&gt;Fighting on Every Front to Eliminate ALPR Surveillance&lt;/h4&gt;
&lt;p&gt;At the city level, EFF works with community members and decision makers to &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/local-communities-are-winning-against-alpr-surveillance-heres-how-2025-review&quot;&gt;outright refuse ALPR purchasing&lt;/a&gt;&lt;/span&gt;. ALPRs are not inevitable. The same &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/procurement-power-when-cities-realized-they-can-just-say-no-2025-review&quot;&gt;decision mechanisms&lt;/a&gt;&lt;/span&gt; used to facilitate runaway surveillance purchasing in U.S. localities can be turned against these systems to dismantle them.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;EFF also pushes state legislatures to establish &lt;a href=&quot;https://www.eff.org/deeplinks/2021/01/eff-joins-effort-restrict-automated-license-plate-readers-california&quot;&gt;strict state-level limits&lt;/a&gt; on ALPR surveillance, such as data-deletion rules and use restrictions. Building such constraints into statute can mitigate the harms of existing ALPR systems. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;In courts across the country, EFF files amicus briefs arguing that warrantless police searches of ALPR databases &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/eff-urges-virgina-court-appeals-require-search-warrants-access-alpr-databases&quot;&gt;violate the Fourth Amendment&lt;/a&gt;&lt;/span&gt;. In California state court, EFF and the ACLU of Northern California are suing on behalf of two community groups, SIREN and CAIR-CA, arguing that the San Jose Police Department&#039;s practice of letting officers search stored plate data—to the tune of over 100,000 times a year—without a warrant &lt;span&gt;&lt;a href=&quot;https://www.eff.org/cases/siren-v-san-jose&quot;&gt;violates the California Constitution&lt;/a&gt;&lt;/span&gt;. We’ve also sued to block California law enforcement from &lt;span&gt;&lt;a href=&quot;https://www.eff.org/document/lagleva-v-marin-county-sheriff&quot;&gt;sharing ALPR data&lt;/a&gt;&lt;/span&gt; with federal and out-of-state agencies, in violation of a &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2023/10/victory-california-department-justice-declares-out-state-sharing-license-plate&quot;&gt;California statute&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;A big part of EFF’s work is exposing the &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/12/effs-investigations-expose-flock-safetys-surveillance-abuses-2025-review/&quot;&gt;harms&lt;/a&gt;&lt;/span&gt; of ALPR surveillance. Our investigative team tirelessly &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/open-records-laws-reveal-alprs-sprawling-surveillance-now-states-want-block-what&quot;&gt;collects&lt;/a&gt;&lt;/span&gt; information about how law enforcement uses ALPRs with public records requests, &lt;span&gt;&lt;a href=&quot;https://www.eff.org/cases/automated-license-plate-readers-aclu-eff-v-lapd-lasd&quot;&gt;sues&lt;/a&gt;&lt;/span&gt; to enforce such requests, and &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/license-plate-surveillance-logs-reveal-racist-policing-against-romani-people&quot;&gt;publishes reports&lt;/a&gt;&lt;/span&gt; about them. We’ve also successfully lobbied for a &lt;span&gt;&lt;a href=&quot;https://www.eff.org/deeplinks/2019/06/victory-california-orders-state-audit-automated-license-plate-readers&quot;&gt;State Auditor investigation&lt;/a&gt;&lt;/span&gt; of law enforcement’s use of ALPRs.&lt;/p&gt;
&lt;h4&gt;Coordinated Action Against Mass Surveillance&lt;/h4&gt;
&lt;p&gt;EFF practices integrated advocacy because all of these tools work best together. City refusals, statehouse restrictions, impact litigation, and investigative activism are different levers EFF pulls toward the same end: eliminating ALPR surveillance, and building the durable public power needed to keep it off our streets. A council vote against a Flock contract and a warrant argument in Santa Clara County Superior Court are both, at their core, the same fight: rejecting mass surveillance infrastructure outright, and using every venue available to eliminate its harmful presence and consequences.&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 26 Aug 2026 17:44:34 +0000</pubDate>
 <guid isPermaLink="false">112282 at https://www.eff.org</guid>
 <dc:creator>Sarah Hamid</dc:creator>
 <dc:creator>Adam Schwartz</dc:creator>
 <dc:creator>Hayley Tsukayama</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/flock-vector-1b.png" alt="A flock camera with spying eye, silhouetted against a dark purple ground." type="image/png" length="9712" />
  </item>
  <item>
    <title>EFF Statement on Meta Settlement</title>
    <link>https://www.eff.org/deeplinks/2026/08/eff-statement-meta-settlement</link>
    <description>&lt;div class=&quot;field field--name-body field--type-text-with-summary field--label-hidden&quot;&gt;&lt;div class=&quot;field__items&quot;&gt;&lt;div class=&quot;field__item even&quot;&gt;&lt;p&gt;&lt;span data-contrast=&quot;auto&quot;&gt;Under &lt;a href=&quot;https://oag.ca.gov/system/files/attachments/press-docs/23-05448-ecf-572-1-exhibit-1-mdl-consent-judgment-final-settlment-agreement-fully-executed.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;this settlement&lt;/a&gt;, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta&#039;s harmful surveillance into law, and it will compromise users&#039; privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care.&lt;/span&gt;&lt;span data-ccp-props=&quot;{}&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
     <pubDate>Wed, 26 Aug 2026 16:34:41 +0000</pubDate>
 <guid isPermaLink="false">112285 at https://www.eff.org</guid>
 <category domain="https://www.eff.org/issues/free-speech">Free Speech</category>
 <category domain="https://www.eff.org/issues/privacy">Privacy</category>
 <category domain="https://www.eff.org/issues/age-verification">Age Verification and Age Gating: Resource Hub</category>
 <category domain="https://www.eff.org/issues/social-media-surveilance">Social Media Surveillance</category>
 <dc:creator>David Greene</dc:creator>
 <enclosure url="https://www.eff.org/files/banner_library/ageverificationbanner-3.png" alt="A hand holding a cellphone showing a verification screen and ACCESS DENIED in the background." type="image/png" length="536728" />
  </item>
  </channel>
</rss>
