Skip to main content
technology Support = Good

User Privacy

Supporting means...

Strong privacy protections; minimal data collection; user control; transparent data practices

Opposing means...

Aggressive data harvesting; privacy violations; selling user data; surveillance

Recent Incidents

reactive

Norway's national criminal investigation service (Kripos) charged Telenor with complicity in crimes against humanity, and Norway's domestic security service (PST) separately charged the company with breaching the Sanctions Act, following a joint raid on Telenor's Fornebu headquarters on September 15, 2026. Prosecutors allege that Telenor Myanmar Ltd (TML) repeatedly handed the military junta customer call logs, names, addresses, and location data after the February 2021 coup, which the junta used to track, arrest, and imprison dissidents; documents show roughly 500 customers were put at risk of arrest, and a civil suit alleges the data sharing contributed to the 2022 execution of activist-lawmaker Phoe Zeya Thaw. The Sanctions Act charge concerns Telenor's March 2022 sale of TML, which allegedly included surveillance equipment transferred without required Foreign Ministry authorization. Telenor, 54%-owned by the Norwegian state, said its employees faced imprisonment or death if they had refused military orders and that it is cooperating fully with prosecutors. The charges are described as among the first criminal prosecutions of a major telecom for authoritarian surveillance complicity.

negligent

Revolut confirmed a data breach in which attackers impersonating a government agency via a spoofed official email address obtained sensitive KYC data on an undisclosed number of customers, described by a crypto security researcher as appearing targeted at high-net-worth users. Exposed data included full names, dates of birth, occupations, postal and email addresses, phone numbers, passport and driver's license images, facial verification selfies, IBANs, and full transaction histories including Bitcoin transactions. Revolut declined to name the government agency involved or specify affected markets, and did not explain why email domain authentication alone was sufficient to release such sensitive data. On September 14, 2026, the attackers began publicly leaking customer data and threatened to release more daily until paid, escalating from theft to extortion.

incidental

In July 2026, two UK parliamentary committees (Science and Technology; Health and Social Care) urged the Labour government to exercise a February 2027 break clause and terminate Palantir's seven-year, £330M contract to run the NHS Federated Data Platform, citing use of Palantir's software to support military strikes in Gaza and Iran, its role in US ICE immigration operations, and data-security concerns. In September 2026, Health Innovation Minister James Frith disclosed to the Commons Health Committee that roughly 60,000 additional patients withdrew their medical records from NHS research between mid-May and mid-July 2026, attributing at least part of the rise to public 'mistrust' of Palantir that moved in step with press attention on the company's NHS role, while describing the increase as 'modest' but requiring continued monitoring. DHSC and Frith gave conflicting public statements over whether NHS trusts are required to use the platform.

Healing Paper, operator of the Gangnam Unni cosmetic-procedure platform, disclosed that an unauthorized party accessed consultation records for 219,665 users via an API on September 4, 2026, with a second attempted breach the next day through a different channel. Exposed data included names, contact details, and sensitive medical information such as procedure and hospital names, consultation photos, appointment details, and payment records, affecting roughly 160,000 users in South Korea, 48,000 in Japan, and others in Taiwan, Thailand and China. The company reported the breach to the Korea Internet & Security Agency (KISA) and police.

Wipro expanded a digital activity-monitoring tool called TimeScope to company-issued laptops and desktops across India in September 2026, after an initial deployment to roughly 5,000 employees in May 2026. The tool tracks login duration, active time on work applications (Word, Excel, PowerPoint, Outlook, Chrome, etc.), and idle periods, covering fixed-price, billable, support, and undeployed roles. Under an internal policy, a day with no device login, no approved leave, no office swipe record, and no logged client-site visit can trigger an automatic leave deduction, which employees must contest to reverse. Wipro said the tool does not track personal activity, keystrokes, or screen content, and attributed the rollout to client requests for productivity visibility and concerns about employees logging in remotely while on vacation. The move follows a similar monitoring rollout at rival TCS weeks earlier and reflects an industry-wide shift toward outcome-based billing.

On August 24, 2026, X Corp sent cease-and-desist letters to the maintainer of Nitter, a 7-year-old open-source project that let users read X posts without an account, ads, tracking cookies, or JavaScript, and to XCancel, a service built on Nitter. X accused the projects of unlawful circumvention of its API and scraping, citing the Texas Harmful Access by Computer Act and the Lanham Act, and gave a roughly 24-hour deadline. Both services went offline and development on Nitter stopped.

In August 2026, Indian media reported that Tata Consultancy Services had installed a 'Digital User Experience Monitoring' tool on company-issued laptops covering roughly 600,000 employees, without prior formal communication to staff about the deployment. TCS did not publicly disclose the software vendor, what data was stored or reviewed, or which teams could access monitoring dashboards. Following the reports, TCS issued a statement calling characterizations of the tool as employee surveillance 'baseless and inaccurate,' saying it monitors only macro-level network performance rather than individual employee activity.

Effective August 17, 2026, Atlassian's updated data contribution policy made metadata contribution (statistical characteristics, content patterns, search query keywords, Rovo Chat conversations) mandatory and non-optional for Free, Standard, and Premium tier customers; only Enterprise-tier customers retain the ability to opt out, and that ability is lost if an org downgrades from Enterprise. Atlassian's own support documentation states de-identified and aggregated data may be retained for up to seven years, and its sub-processor list names OpenAI as an authorized processor despite Atlassian's stated zero-data-retention agreements with third-party LLM partners.

A stockholder derivative lawsuit filed July 31, 2026 in the US District Court for the Northern District of Illinois (Berliner v. Huang et al.) accused Nvidia's CEO Jensen Huang, CFO Colette Kress, and the board of breaching fiduciary duty by knowingly training NeMo Megatron and other language models on pirated 'shadow library' datasets (Anna's Archive, LibGen, Sci-Hub, Z-Library, Books3/SlimPajama), including material Nvidia allegedly sourced directly from Anna's Archive in 2023 despite an internal warning about copyright issues. The complaint also alleges Nvidia's Magpie TTS, FUGATTO, PersonaPlex and other voice-synthesis models extracted biometric voiceprints from hundreds of thousands of hours of speech recordings without notice or consent, in violation of the Illinois Biometric Information Privacy Act, and that proxy filings misrepresented data-sourcing compliance.

South Korea's Personal Information Protection Commission (PIPC) fined TikTok 10.3 billion won (~$7 million) on July 23, 2026 for unlawfully collecting cross-app user data to target advertising without obtaining proper consent, ordering corrective measures and public disclosure. The PIPC stated that consent must be freely given after users are fully informed how their data will be processed, and clarified that the rule applies to overseas companies processing Korean users' data, including transfers to affiliates located outside Korea's jurisdiction. The action follows a pattern of international data-protection enforcement against TikTok, including a €530 million Irish fine in 2025 for transferring European user data to China and a UK fine over children's data handling; separately, Korea's Communication Commission has scrutinized TikTok Korea's cash-reward promotions.

$44.0M

On July 21, 2026, the São Paulo Public Ministry (MPSP) filed a civil lawsuit against Tools for Humanity Corporation (operator of Sam Altman's World ID/Worldcoin project) and Amazon AWS Servicos Brasil, seeking a minimum R$240 million in collective moral damages. The suit alleges Tools for Humanity scanned the irises of more than 400,000 people in Sao Paulo -- concentrated at metro stations and Poupatempo government-service offices in low-income peripheral areas -- paying R$300-700 per scan while presenting the effort as a humanitarian identity initiative without disclosing its economic purpose tied to Worldcoin cryptocurrency. Prosecutors say the company continued offering compensation through 'internal benefits' in the World App even after Brazil's data protection authority (ANPD) ordered a suspension of paid iris collection in January 2025. AWS Brasil, named as co-defendant for hosting the biometric data, did not deny the hosting contract but said any responsibility would lie with AWS's foreign entity. The case follows a 161-page report from a Sao Paulo City Council inquiry (CPI da Iris) finding the operation posed high legal, social and data-protection risks.

On July 13, 2026, the European Union imposed sanctions on VK Company for developing MAX, a messaging app mandatorily preinstalled on all smartphones, tablets, computers, and smart TVs sold in Russia since September 2025. MAX's terms of service explicitly permit sharing user data with Russian government institutions, and human rights lawyers say law enforcement has access to VK-administered platforms including VKontakte, Odnoklassniki, and MAX. The EU action, part of a package that also sanctioned developers of the FSB's SORM surveillance system, followed a Russian government crackdown on independent apps such as Telegram and WhatsApp. MAX had over 45 million registered accounts and 18 million daily active users as of late 2025.

Colombia's Superintendencia de Industria y Comercio (SIC) confirmed on July 8, 2026 (Resolution 45710) the permanent and immediate closure of all data-processing operations by World Foundation and Tools for Humanity Corporation (the entities behind Sam Altman's World/Worldcoin iris-scanning project) in Colombia, with no further appeal available. The SIC found the companies violated Colombia's data protection law by collecting biometric iris data without valid free consent (conditioning it on cryptocurrency payments), failing to adequately disclose processing purposes, lacking compliant data-handling procedures, and mischaracterizing encrypted iris codes as 'anonymous' data. The ruling upheld and finalized sanctions first imposed in October 2025. This follows earlier bans/restrictions on the project in Brazil, Kenya, Indonesia, the Philippines, Thailand, Spain, Portugal and Hong Kong.

Ranking Digital Rights' 2026 Telco Giants Edition, published June 22, 2026, ranked MTN Group 2nd of the world's major telecom companies on digital rights disclosure (behind Telefónica), up from 6th place previously, making it the first emerging-market telco to reach the top 3. RDR credited MTN with strengthened governance disclosures, a new advertising content policy, and enhanced user-data-protection disclosures, while noting MTN still lacks detailed AI governance policies, including on AI risk review and whether user data is used to train AI models, and that its transparency gains face testing from the regulatory and political realities of the markets it operates in.

negligent

On June 12, 2026, Kenya's High Court (Milimani Constitutional and Human Rights Division), ruling on a petition by the Kenya Association of Radiologists, ordered the immediate suspension of Rology's Kenyan operations. The court found Rology had operated in over 40 public health facilities serving more than 60,000 patients without registering as a data controller/processor under Kenya's Data Protection Act, without Digital Health Act compliance, and without verifying that all reviewing radiologists held Kenyan licenses. Patient medical imaging (X-rays, CT scans, MRIs) with identifying metadata was transferred to Rology's Cairo-based cloud infrastructure without explicit patient consent. The court found violations of the constitutional rights to privacy, consumer protection, fair labor practices, and health, and ordered regulators to cancel any licenses issued to Rology for handling patient data.

negligent

Brazil's National Data Protection Authority (ANPD) announced on June 8, 2026 that it opened an administrative sanction process against Claro (América Móvil's Brazilian mobile, broadband, and pay-TV unit) for sharing more than 100 data points per customer -- including ZIP codes, complaint volumes, pay-per-view consumption, and mobile data usage -- with credit bureau Serasa Experian under a 2021-2023 partnership, without consulting affected customers. ANPD's Superintendent of Inspection said the sharing exceeded what was necessary and lacked transparency, and customers had difficulty reaching Claro's data protection officer. Claro said the data were used only for internal studies and not incorporated into market solutions, and that the partnership, authorized by antitrust regulator CADE, ended in 2023. The process could result in fines of up to R$50 million per violation or 2% of revenue under Brazil's LGPD.

reactive

Discord publicly confirmed a major data breach in 2026 that exposed user information, originating through a third-party vendor in its supply chain. The disclosure was part of a broader pattern of 2026 breaches affecting platforms including Instructure (Canvas), Hasbro, and several open-source security tooling vendors. Discord emphasized two-factor authentication adoption in its post-incident guidance.

negligent

Meta confirmed in June 2026 that approximately 20,000 Instagram accounts had been compromised by attackers who abused Meta's own AI tools to automate the hijacking process. Meta took action to lock down the abused tools and notify users, but the disclosure highlights how Meta's AI features are being weaponized against its own user base and raises questions about safeguards Meta deployed before shipping these tools.

Middle East Eye reported in June 2026 that Israeli spyware firm NSO Group continued to target WhatsApp users with Pegasus despite a binding US court order arising from the Meta v. NSO Group litigation. The reporting cited evidence of continued infections after the judgment, raising the prospect of contempt proceedings and renewed pressure on US sanctions enforcement against the company.

Reliance Jio announced 'Jio Call Agent,' a network-level (not app-based) AI feature for its 500+ million subscribers that transcribes calls, identifies up to 10 speakers, generates summaries and action items, and can execute tasks (booking cabs, reservations) via a 'Hey Jio' voice trigger, across 22 Indian languages. Indian outlet MediaNama and other press raised concerns that the network-level design implies continuous processing of calls to detect the wake phrase; that Jio had not disclosed transcript retention periods, access controls, or whether call data trains AI models; that non-Jio participants on a call would have their voice data processed without any direct relationship to Jio's terms of service; and that notification-only consent for the other party may not satisfy the 'free, specific, informed, and unambiguous' consent standard of India's DPDP Act.