Skip to main content
technology Support = Good

User Privacy

Supporting means...

Strong privacy protections; minimal data collection; user control; transparent data practices

Opposing means...

Aggressive data harvesting; privacy violations; selling user data; surveillance

Recent Incidents

$44.0M

On July 21, 2026, the São Paulo Public Ministry (MPSP) filed a civil lawsuit against Tools for Humanity Corporation (operator of Sam Altman's World ID/Worldcoin project) and Amazon AWS Servicos Brasil, seeking a minimum R$240 million in collective moral damages. The suit alleges Tools for Humanity scanned the irises of more than 400,000 people in Sao Paulo -- concentrated at metro stations and Poupatempo government-service offices in low-income peripheral areas -- paying R$300-700 per scan while presenting the effort as a humanitarian identity initiative without disclosing its economic purpose tied to Worldcoin cryptocurrency. Prosecutors say the company continued offering compensation through 'internal benefits' in the World App even after Brazil's data protection authority (ANPD) ordered a suspension of paid iris collection in January 2025. AWS Brasil, named as co-defendant for hosting the biometric data, did not deny the hosting contract but said any responsibility would lie with AWS's foreign entity. The case follows a 161-page report from a Sao Paulo City Council inquiry (CPI da Iris) finding the operation posed high legal, social and data-protection risks.

On July 13, 2026, the European Union imposed sanctions on VK Company for developing MAX, a messaging app mandatorily preinstalled on all smartphones, tablets, computers, and smart TVs sold in Russia since September 2025. MAX's terms of service explicitly permit sharing user data with Russian government institutions, and human rights lawyers say law enforcement has access to VK-administered platforms including VKontakte, Odnoklassniki, and MAX. The EU action, part of a package that also sanctioned developers of the FSB's SORM surveillance system, followed a Russian government crackdown on independent apps such as Telegram and WhatsApp. MAX had over 45 million registered accounts and 18 million daily active users as of late 2025.

Colombia's Superintendencia de Industria y Comercio (SIC) confirmed on July 8, 2026 (Resolution 45710) the permanent and immediate closure of all data-processing operations by World Foundation and Tools for Humanity Corporation (the entities behind Sam Altman's World/Worldcoin iris-scanning project) in Colombia, with no further appeal available. The SIC found the companies violated Colombia's data protection law by collecting biometric iris data without valid free consent (conditioning it on cryptocurrency payments), failing to adequately disclose processing purposes, lacking compliant data-handling procedures, and mischaracterizing encrypted iris codes as 'anonymous' data. The ruling upheld and finalized sanctions first imposed in October 2025. This follows earlier bans/restrictions on the project in Brazil, Kenya, Indonesia, the Philippines, Thailand, Spain, Portugal and Hong Kong.

reactive

Discord publicly confirmed a major data breach in 2026 that exposed user information, originating through a third-party vendor in its supply chain. The disclosure was part of a broader pattern of 2026 breaches affecting platforms including Instructure (Canvas), Hasbro, and several open-source security tooling vendors. Discord emphasized two-factor authentication adoption in its post-incident guidance.

negligent

Meta confirmed in June 2026 that approximately 20,000 Instagram accounts had been compromised by attackers who abused Meta's own AI tools to automate the hijacking process. Meta took action to lock down the abused tools and notify users, but the disclosure highlights how Meta's AI features are being weaponized against its own user base and raises questions about safeguards Meta deployed before shipping these tools.

Middle East Eye reported in June 2026 that Israeli spyware firm NSO Group continued to target WhatsApp users with Pegasus despite a binding US court order arising from the Meta v. NSO Group litigation. The reporting cited evidence of continued infections after the judgment, raising the prospect of contempt proceedings and renewed pressure on US sanctions enforcement against the company.

Al Jazeera's 'Invisible Eyes' documentary (May 2026) exposed that Safaricom allowed Kenyan security agencies access to subscriber location data, call records, and M-Pesa financial transactions -- often without court orders -- to surveil, locate, and track activists and protesters. A Safaricom employee admitted in court to complying with a government data request without a court order. The Law Society of Kenya filed a constitutional petition seeking a court audit of all data requests from June 2024 to December 2025.

negligent $77K

On May 18, 2026 the High Court of Kenya ordered Safaricom to pay 9.9 million Kenyan shillings to a customer over a client data breach, holding that Safaricom could not escape liability by blaming individual employees. The judgment established that companies bear institutional responsibility for documented access controls, monitoring systems, and breach detection. Local commentary described the ruling as exposing systemic failures in Safaricom's customer-data protection regime.

$12.8M

On May 8, 2026, General Motors and OnStar agreed to a $12.75M settlement with California -- the largest CCPA penalty ever. GM collected and sold geolocation and driving behavior data from hundreds of thousands of California consumers to data brokers without adequate consent. This was the first data minimization enforcement action under CCPA, establishing that companies must limit data collection to what is reasonably necessary for the disclosed purpose.

negligent

Between April 18-20, 2026, Vercel suffered a data breach originating from a compromise of Context.ai, a third-party AI productivity tool. A Context.ai employee downloaded malware (Lumma Stealer), leading to credential theft and OAuth token compromise that gave attackers access to Vercel internal systems. Approximately 580 employee records, API keys, database credentials, source code, internal dashboards, and limited customer credentials were compromised. An attacker claiming to be 'ShinyHunters' demanded $2 million ransom. CEO Guillermo Rauch said the attack was 'significantly accelerated by AI.'

negligent

In March 2026, T-Mobile confirmed a data breach affecting 47.8 million people including current, former, and prospective customers. Approximately 7.8 million current postpaid customer records were stolen, ~40 million former/prospective customer records, and 850,000 active prepaid customers had phone numbers and account PINs exposed. Exposed data included names, dates of birth, Social Security numbers, and driver's license/ID information. T-Mobile discovered the breach through an online forum post and shut down the leak.

$135.0M

A $135 million Google settlement received preliminary court approval on March 5, 2026, resolving class action allegations that Google unlawfully surveilled and collected private information from cellular data purchased by Android users. The settlement covers over 100 million Americans, with payouts of up to $100 per person. As part of the settlement, Google will be required to obtain users' affirmative consent before using cellular data.

On February 19, 2026, West Virginia AG JB McCuskey filed a consumer protection lawsuit alleging Apple allowed child sexual abuse materials (CSAM) to be stored and distributed on iCloud services. The lawsuit claims Apple 'prioritized user privacy over child safety for years' - Apple filed only 267 CSAM reports to the National Center for Missing and Exploited Children in 2023, compared to Google's 1.47 million reports. The state seeks statutory and punitive damages plus injunctive relief requiring Apple to implement effective CSAM detection.

negligent

A bug (CW1226324) allowed Microsoft Copilot Chat to read and summarize customers' confidential emails without permission for approximately four weeks (January 21 to mid-February 2026). Emails marked with confidentiality labels and protected by DLP policies were incorrectly processed across Word, Excel, and PowerPoint. Affected organizations included the UK's National Health Service. Microsoft did not disclose the number of affected customers or what data was accessed. This was the second trust boundary violation in eight months, following CVE-2025-32711 'EchoLeak' in June 2025 (CVSS 9.3).

$2.8M

On February 11, 2026, California AG Rob Bonta announced the largest CCPA settlement to date with Disney. The company's opt-out webform only stopped sharing through Disney's own ad platform while continuing to sell data to third-party ad-tech companies. Disney failed to provide in-app opt-out in streaming apps, ignored device-specific Global Privacy Control signals for logged-in users, and required bundle subscribers to opt out up to 10 separate times to fully stop data sharing.

On February 10, 2026, PayPal disclosed a data breach affecting approximately 100 PayPal Working Capital loan applicants due to a software coding error. Personal data including Social Security numbers, dates of birth, and business contact information was exposed from July 1 to December 13, 2025. Some customers experienced unauthorized transactions and received refunds. PayPal offered 2 years of free credit monitoring through Equifax.

In February 2026, Anthropic aired anti-OpenAI advertisements during the Super Bowl, criticizing OpenAI's announced plans to add 'Instagram-style' advertising to ChatGPT. The ads resulted in an 11% boost in Anthropic users. Sam Altman called the ads 'deceptive.' The rivalry escalated at the India AI Summit where Altman and Dario Amodei refused to hold hands during a group photo with PM Modi.

On February 4, 2026, Kakao notified KakaoTalk's 47M+ users it would begin collecting and analyzing usage records and patterns for targeted advertising. After public backlash over privacy invasion, Kakao revised its terms on February 11, deleting some controversial provisions. This followed a September 2025 redesign debacle that was rolled back in 5 days after user revolt, and criticism of a location-sharing feature that allegedly enabled stalking.

Microsoft issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability tracked as CVE-2026-21509, with a CVSS score of 7.8 out of 10.0. The vulnerability allows attackers to bypass document security checks and is being actively exploited in the wild via malicious files. The emergency patch was released outside Microsoft's normal Patch Tuesday schedule due to active exploitation.

Cisco released a patch for a critical vulnerability affecting its Unified Communications and WebEx products that allowed remote code execution. The vulnerability was actively exploited in the wild before the patch was released, representing a significant security risk to enterprise communications infrastructure.