# Global Cyber Law Compendium
## 1000 — Landmark Court Decisions

---

> ## CONTENTS
>
> - Part 1 — Platform Liability & Content Moderation
> - Part 2 — Data Protection & Privacy
> - Part 3 — Artificial Intelligence Governance
> - Part 4 — Cybercrime & Cybersecurity
> - Part 5 — Biometric & Genetic Data
> - Part 6 — Data Breaches & Standing
> - Part 7 — Children's Digital Rights
> - Part 8 — Digital Intellectual Property
> - Part 9 — E-Commerce & Consumer Protection
> - Part 10 — Government Surveillance & National Security
> - Part 11 — Employment & Workplace Privacy
> - Part 12 — Emerging Issues & Cross-Cutting Themes
> - Part 13 — 2025–2026 Recent Developments

---

## Table of Contents

- **Part 1: Platform Liability & Content Moderation**
  - Chapter 1: The Foundation of Platform Immunity
  - Cases 1.1–1.95 (95 cases)
- **Part 2: Data Protection & Privacy**
  - Chapter 2: The Transatlantic Data Transfer Saga
  - Cases 2.1–2.90 (90 cases)
- **Part 3: Artificial Intelligence & Algorithmic Governance**
  - Chapter 3: AI Accountability Comes of Age
  - Cases 3.1–3.105 (105 cases)
- **Part 4: Cybercrimes & Digital Forensics**
  - Chapter 4: Prosecuting the Digital Underground
  - Cases 4.1–4.105 (105 cases)
- **Part 5: Biometric Data & Genetic Privacy**
  - Chapter 5: The Biometric Litigation Wave
  - Cases 5.1–5.71 (71 cases)
- **Part 6: Data Breaches & Standing**
  - Chapter 6: The Standing Crisis in Data Breach Litigation
  - Cases 6.1–6.80 (80 cases)
- **Part 7: Children's Online Safety**
  - Chapter 7: Protecting Minors in the Digital Age
  - Cases 7.1–7.60 (60 cases)
- **Part 8: Intellectual Property & Digital Content**
  - Chapter 8: Copyright, Trademarks, and the Internet
  - Cases 8.1–8.93 (93 cases)
- **Part 9: Digital Market Regulation & Consumer Data Rights**
  - Chapter 9: Digital Market Regulation and Consumer Data Rights
  - Cases 9.1–9.93 (93 cases)
- **Part 10: Government Surveillance & Human Rights**
  - Chapter 10: Digital Rights and State Power
  - Cases 10.1–10.66 (66 cases)
- **Part 11: Employment & Workplace Privacy**
  - Chapter 11: Digital Rights in Employment
  - Cases 11.1–11.54 (54 cases)
- **Part 12: Emerging Issues & Cross-Cutting Themes**
  - Chapter 12: Cross-Cutting Themes in Cyber Law
  - Cases 12.1–12.55 (55 cases)
- **Part 13: 2025–2026 Recent Developments**
  - Chapter 13: The Emerging Frontiers
  - Cases 13.1–13.33 (33 cases)

- **Appendices**
  - Appendix A: Master Case Index
  - Appendix B: Statutes & Regulations Index
  - Appendix C: Landmark Precedents Index

---

**Editor:** Dr. Zhou
**Compiled:** March 2026

*Global Cyber Law Series | WW2026 Edition*

---

## Copyright

© 2026 Dr. Zhou. All rights reserved.

No part of this publication may be reproduced, distributed, or transmitted in any form or by any means, including photocopying, recording, or other electronic or mechanical methods, without the prior written permission of the publisher, except in the case of brief quotations embodied in critical reviews and certain other noncommercial uses permitted by copyright law.

**ISBN:** 978-7-XXX-XXXX-X (申请中 / Pending Registration)

**Publisher:** Atlantis Legal
**Series:** Global Cyber Law Series
**Edition:** WW2026 Edition

---

## Description

This compendium presents 1,000 landmark court decisions from global jurisdictions that have shaped cyber law evolution across 13 critical domains. It provides essential judicial precedents governing digital governance, balancing technological innovation, individual rights, and public policy objectives.

### Key Features

- ✓ 13 Critical Domains Covered
- ✓ Global Jurisdictions Represented
- ✓ Essential Judicial Precedents
- ✓ Practical Reference Guide
- ✓ Expert-Edited by Dr. Zhou

### An Indispensable Reference For

- Legal Practitioners
- Scholars & Researchers
- Policymakers
- Technology Professionals
- Compliance Officers

---

# Part 1 — Platform Liability & Content Moderation

## Chapter 1: The Foundation of Platform Immunity

The legal architecture governing platform liability for user-generated content represents one of the most consequential regulatory choices in the history of the internet. This Part traces the evolution of platform immunity from its origins in the Communications Decency Act of 1996 through the fundamental rebalancing of platform obligations in the European Union's Digital Services Act.


### Case 1.1: Reno v. ACLU, 521 U.S. 844 (1997) — US Supreme Court

**Date Decided:** June 26, 1997

**Court:** Supreme Court of the United States

**Facts:** In February 1996, Congress enacted the Communications Decency Act (CDA), Title V of the Telecommunications Act of 1996, Pub. L. No. 104-104. The CDA contained two key provisions criminalizing the transmission of "obscene or indecent" messages and the display of "patently offensive" sexual content in a manner available to minors under eighteen years of age. Specifically, 223(a)(1)(B) criminalized the "knowing" transmission of "obscene or indecent" messages to recipients under eighteen, and 223(d)(1) prohibited the "knowing" sending or display of content that, "in context, depicts or describes, in terms patently offensive as measured by contemporary community standards, sexual or excretory activities or organs." Violations carried criminal penalties including fines and imprisonment of up to two years.
The American Civil Liberties Union (ACLU) and a coalition of free speech organizations, publishers, and technology groups filed suit in the United States District Court for the Eastern District of Pennsylvania, challenging the CDA's indecency provisions on First Amendment grounds. The district court granted a preliminary injunction, and the government appealed directly to the Supreme Court under the Act's special review provision.
The Internet is entitled to the highest level of First Amendment protection. The Court characterized the Internet as "not as involuntarily accessed as a radio receiver" and analogous to "a vast library including millions of readily available publications and writings," rejecting the government's argument that the Internet should be regulated like broadcast media. The Court expressly declined to extend the Pacifica Foundation "pervasive medium" rationale to cyberspace.
The CDA was not narrowly tailored. Although the Court accepted the government's compelling interest in protecting minors from harmful content, it held that the CDA's broad prohibitions were not narrowly tailored to achieve that interest. The statute criminalized a vast quantity of constitutionally protected speech available to adults, and the government had failed to demonstrate that less restrictive alternatives — such as filtering software and parental empowerment tools — were inadequate.
The CDA was unconstitutionally vague. The terms "indecent" and "patently offensive, as measured by contemporary community standards" lacked the precision required by the Due Process Clause, particularly in the context of a global medium where the concept of "community standards" was inherently ambiguous.
The Court preserved Section 230, which was also part of the CDA, but was not challenged in this litigation. Section 230 would go on to become the foundational shield for online platform immunity.

**Issue:** Whether the CDA's indecency provisions violated the First Amendment by (1) criminalizing the dissemination of protected speech to adults in order to protect minors, (2) being unconstitutionally vague and overbroad, and (3) failing to employ the least restrictive means to achieve the government's compelling interest in protecting minors from harmful content.
**Holding:** The Supreme Court affirmed the district court's preliminary injunction in a unanimous decision authored by Justice Stevens. The Court held: The Internet is entitled to the highest level of First Amendment protection. The Court characterized the Internet as "not as involuntarily accessed as a radio receiver" and analogous to "a vast library including millions of readily available publications and writings," rejecting the government's argument that the Internet should be regulated like broadcast media. The Court expressly declined to extend the Pacifica Foundation "pervasive medium" rationale to cyberspace. The CDA was not narrowly tailored. Although the Court accepted the government's compelling interest in protecting minors from harmful content, it held that the CDA's broad prohibitions were not narrowly tailored to achieve that interest. The statute criminalized a vast quantity of constitutionally protected speech available to adults, and the government had failed to demonstrate that less restrictive alternatives — such as filtering software and parental empowerment tools — were inadequate. The CDA was unconstitutionally vague. The terms "indecent" and "patently offensive, as measured by contemporary community standards" lacked the precision required by the Due Process Clause, particularly in the context of a global medium where the concept of "community standards" was inherently ambiguous. The Court preserved Section 230, which was also part of the CDA, but was not challenged in this litigation. Section 230 would go on to become the foundational shield for online platform immunity.
**Significance:** Foundational First Amendment framework for cyberspace. Reno v. ACLU established that the Internet is entitled to full First Amendment protection, rejecting both broadcast-style regulation and the "pervasive medium" doctrine. This foundational principle has shaped every subsequent decision on Internet speech regulation, including Ashcroft v. ACLU (535 U.S. 564 (2002)), which struck down the Child Online Protection Act (COPA) on similar grounds, and Brown v. Entertainment Merchants Association (564 U.S. 786 (2011)), which extended full First Amendment protection to violent video games sold to minors.
Least restrictive means and technological solutions. The Court's emphasis on the availability of filtering software and parental controls as less restrictive alternatives to content-based criminal prohibitions established a lasting principle: governments must consider technological solutions before restricting speech. This principle continues to inform contemporary debates over age verification, platform regulation, and content moderation mandates.
The paradox of Section 230's survival. Reno struck down the CDA's content restrictions while inadvertently preserving Section 230, which has become the most consequential intermediary immunity provision in the world. The survival of 230 — unchallenged in Reno — created the legal foundation for the modern Internet economy, enabling platforms to host user-generated content without assuming publisher-level liability. The subsequent judicial interpretation of 230, particularly in Zeran v. AOL (1997), amplified this protection to near-absolute dimensions.
Global influence. Reno was cited by courts worldwide as persuasive authority on the question of Internet speech protection, influencing the development of content regulation frameworks in the European Union (the E-Commerce Directive 2000/31/EC), India (the Shreya Singhal decision), and elsewhere.

---

### Case 1.2: Zeran v. America Online, Inc., 129 F.3d 327 (4th Cir. 1997)

**Date Decided:** November 12, 1997

**Court:** United States Court of Appeals for the Fourth Circuit

**Facts:** Kenneth Zeran, a resident of Seattle, Washington, discovered that an anonymous AOL user had posted messages on AOL bulletin boards falsely identifying Zeran as the person selling T-shirts glorifying the April 19, 1995 Oklahoma City bombing, listing Zeran's home telephone number. Zeran received a torrent of threatening and abusive telephone calls. He contacted AOL and requested that the offending messages be removed and that his contact information be removed from future posts. AOL removed the initial postings but did not implement any broader screening measures. The anonymous poster continued to post similar messages, and Zeran continued to receive threatening calls over the following days. Zeran sued AOL for negligence, claiming that AOL failed to take adequate measures to prevent the ongoing harassment after being notified of the false postings.
Section 230 creates a broad federal immunity. Section 230(c)(1), which provides that "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider," creates a sweeping immunity that preempts all state-law tort claims arising from the publication of third-party content.
No duty to monitor or remove content. The court held that 230(c)(2)'s "Good Samaritan" provision — which permits platforms to remove content voluntarily without incurring liability — should not be interpreted as creating an incentive structure that would encourage platforms to monitor content, because 230(c)(1) already provides absolute immunity from publisher liability. The court explicitly rejected the argument that AOL could be liable for failing to remove content after receiving notice: "If it were liable for failing to screen postings, AOL would be caught in a Catch-22. The more active AOL is in screening and removing offensive postings, the more it acts as a publisher and exposes itself to traditional publisher liability."
The immunity is not limited to traditional publishers. The court rejected Zeran's argument that 230 immunity should be limited to "traditional publishing functions" such as editorial decisions, holding that the statute's plain language created a categorical immunity regardless of the platform's level of involvement with the content.

**Issue:** Whether Section 230 of the Communications Decency Act (47 U.S.C. 230) barred Zeran's state-law negligence claim against AOL for failing to remove or screen defamatory content posted by a third party.
**Holding:** The Fourth Circuit, in an opinion by Judge Wilkinson, held that 230 barred Zeran's claim entirely. The court held: Section 230 creates a broad federal immunity. Section 230(c)(1), which provides that "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider," creates a sweeping immunity that preempts all state-law tort claims arising from the publication of third-party content. No duty to monitor or remove content. The court held that 230(c)(2)'s "Good Samaritan" provision — which permits platforms to remove content voluntarily without incurring liability — should not be interpreted as creating an incentive structure that would encourage platforms to monitor content, because 230(c)(1) already provides absolute immunity from publisher liability. The court explicitly rejected the argument that AOL could be liable for failing to remove content after receiving notice: "If it were liable for failing to screen postings, AOL would be caught in a Catch-22. The more active AOL is in screening and removing offensive postings, the more it acts as a publisher and exposes itself to traditional publisher liability." The immunity is not limited to traditional publishers. The court rejected Zeran's argument that 230 immunity should be limited to "traditional publishing functions" such as editorial decisions, holding that the statute's plain language created a categorical immunity regardless of the platform's level of involvement with the content.
**Significance:** Near-absolute intermediary immunity. Zeran established the broadest possible interpretation of 230 immunity, holding that platforms have no duty to monitor, screen, or remove defamatory content — even after receiving actual notice. This "no duty to monitor" holding became the bedrock of American Internet law and distinguishes the US approach from virtually every other major jurisdiction, where platforms are generally subject to notice-and-takedown obligations (EU E-Commerce Directive, Article 14) or intermediary liability regimes that impose affirmative duties (Germany's NetzDG, India's IT Act).
The "Catch-22" reasoning. The Fourth Circuit's Catch-22 argument — that imposing liability for content moderation would discourage platforms from engaging in content moderation at all — became the canonical justification for broad 230 immunity and has been cited in virtually every subsequent 230 decision. Critics argue that this reasoning has been overtaken by the reality that large platforms now routinely engage in content moderation through automated and human review systems, and that the Catch-22 no longer reflects the actual incentive structure facing platforms.
Tension with democratic accountability. Zeran's broad immunity has been criticized for insulating platforms from accountability for the harmful effects of content hosted on their services, while simultaneously giving platforms effective control over public discourse through their content moderation decisions. This tension — between immunity from liability and de facto editorial power — has become the central challenge of platform governance and has driven legislative reform efforts on both sides of the Atlantic.

---

### Case 1.3: Brazilian STF — Temas 533 & 987 (June 2025) — Supremo Tribunal Federal

**Date Decided:** June 2025

**Court:** Supremo Tribunal Federal (STF), Brazil

**Facts:** The Brazilian Supreme Federal Court (STF) adjudicated two interconnected cases — Tema 533 (RE 1.037.396) and Tema 987 (ADI 5.527 and ADI 6.307) — that together defined the constitutional limits of Internet platform liability in Brazil. Tema 533 addressed whether the Marco Civil da Internet (Law No. 12.965/2014, Brazil's "Internet Bill of Rights") imposed a duty on platforms to identify and disclose the identity of anonymous users who posted defamatory content. Tema 987 addressed the constitutionality of a broader set of platform obligations, including content moderation requirements and the liability framework for platforms that fail to remove illegal content after receiving a judicial order.
The Marco Civil da Internet, enacted in 2014, established a notice-and-judicial-order regime: platforms were not required to proactively monitor content for illegality, but were required to remove specific content identified as illegal by a court order (Article 19). The cases arose in the context of intense public debate over disinformation, political content moderation, and the role of platforms in Brazilian democratic discourse, particularly in the wake of the January 2023 events in Bras lia.
Platform liability is constitutional but must be proportionate. The Court upheld the framework of the Marco Civil da Internet but interpreted it to permit a graduated system of liability. Platforms are not required to proactively monitor all content, but they are subject to increasing obligations based on their size, market power, and the nature of the content at issue.
Anonymous speech is protected but not absolute. The Court held that anonymous expression on the Internet is protected by the Brazilian Constitution (Article 5, IV and IX), but this protection yields when there is a demonstrated need to identify the author for the enforcement of civil or criminal liability. Platforms may be required to disclose user identifying information pursuant to a court order, but the requesting party must demonstrate a concrete interest and the proportionality of the disclosure.
Balancing test for content moderation. The Court adopted a proportionality framework for evaluating content moderation obligations, requiring courts to balance the rights to free expression, privacy, and information against the need to protect individuals from harm, prevent the spread of illegal content, and preserve democratic discourse. This framework explicitly rejected both the American near-absolute immunity model (Section 230/Zeran) and the European model of mandatory notice-and-action (DSA), charting a distinctive "Brazilian" approach.

**Issue:** (1) Whether Article 19 of the Marco Civil da Internet requires platforms to identify anonymous users upon request, and (2) whether the constitutional principle of free expression limits the imposition of affirmative content moderation duties on Internet platforms.
**Holding:** The STF issued a landmark ruling that: Platform liability is constitutional but must be proportionate. The Court upheld the framework of the Marco Civil da Internet but interpreted it to permit a graduated system of liability. Platforms are not required to proactively monitor all content, but they are subject to increasing obligations based on their size, market power, and the nature of the content at issue. Anonymous speech is protected but not absolute. The Court held that anonymous expression on the Internet is protected by the Brazilian Constitution (Article 5, IV and IX), but this protection yields when there is a demonstrated need to identify the author for the enforcement of civil or criminal liability. Platforms may be required to disclose user identifying information pursuant to a court order, but the requesting party must demonstrate a concrete interest and the proportionality of the disclosure. Balancing test for content moderation. The Court adopted a proportionality framework for evaluating content moderation obligations, requiring courts to balance the rights to free expression, privacy, and information against the need to protect individuals from harm, prevent the spread of illegal content, and preserve democratic discourse. This framework explicitly rejected both the American near-absolute immunity model (Section 230/Zeran) and the European model of mandatory notice-and-action (DSA), charting a distinctive "Brazilian" approach.
**Significance:** A third way between US and EU models. The STF's decision represents a significant contribution to the global platform liability debate, offering a proportionality-based framework that is distinct from both the American categorical immunity approach and the European tiered-obligation approach under the DSA. The Brazilian approach is potentially influential for other Latin American and developing-country jurisdictions that are developing platform governance frameworks.
Democratic accountability in the Global South. The decision is particularly significant in the Brazilian context, where the spread of disinformation through social media platforms was implicated in the January 2023 attacks on government buildings. The STF's willingness to impose graduated obligations on platforms reflects a judicial response to the real-world consequences of insufficient platform accountability in a fragile democracy.
Anonymous speech and identification. The STF's approach to anonymous speech — protecting anonymity as a default but permitting compelled disclosure through court orders upon a showing of proportionality — provides a nuanced middle ground that may influence the development of identification requirements in other jurisdictions.
Impact on the "C digo das Plataformas" legislation. The decision provided judicial guidance for the ongoing legislative process around Brazil's "Platform Code" bill, which aims to establish a comprehensive regulatory framework for large digital platforms. The STF's proportionality framework is expected to inform the design of the bill's graduated liability and transparency obligations.

---

### Case 1.4: Google LLC v. Gonzalez, 602 U.S. 1 (2023) — US Supreme Court

**Date Decided:** February 21, 2023

**Court:** Supreme Court of the United States

**Facts:** The family of Nohemi Gonzalez, a 23-year-old American student killed in the November 2015 terrorist attacks in Paris, brought suit against Google LLC under the Antiterrorism Act (ATA), 18 U.S.C. 2333. The plaintiffs alleged that Google's subsidiary YouTube, through its algorithm-driven recommendation system, was complicit in the terrorist attacks because the platform's algorithms recommended ISIS-related videos to users, thereby facilitating the recruitment and radicalization of ISIS members. The plaintiffs argued that YouTube's targeted recommendations constituted "aiding and abetting" terrorism under the ATA because the algorithmic recommendations went beyond merely hosting third-party content and constituted active assistance to terrorist organizations.
The district court dismissed the case, holding that YouTube's recommendations were protected by Section 230. The Ninth Circuit reversed in part, holding that the complaint plausibly alleged that YouTube's targeted recommendations went beyond traditional publishing functions and could constitute aiding and abetting under the ATA. Google petitioned for certiorari.
The case did not require broad interpretation of Section 230. The Court declined to address the scope of 230 immunity for algorithmic recommendations, noting that the parties had not adequately briefed the question of whether YouTube's algorithmic recommendations were "material support" to terrorism under the ATA. The Court held that the Ninth Circuit should first determine whether the plaintiffs' allegations, even if true, could establish aiding and abetting liability under the ATA — and only if so, proceed to the question of whether 230 immunity applied.
No ruling on the core 230 question. The Court expressly declined to resolve the question of whether 230(c)(1) applies to algorithmic content recommendations, leaving this critical question for future adjudication. Justice Thomas, joined by Justice Gorsuch, concurred to emphasize their view that 230 immunity has been interpreted too broadly and should be narrowed.

**Issue:** Whether Section 230(c)(1) of the Communications Decency Act bars a claim that an interactive computer service's algorithm-driven recommendations constitute "aiding and abetting" terrorism under the Antiterrorism Act, where the recommendations are based on third-party content uploaded by users.
**Holding:** The Supreme Court, in a per curiam opinion, vacated the Ninth Circuit's decision and remanded for further proceedings. The Court held: The case did not require broad interpretation of Section 230. The Court declined to address the scope of 230 immunity for algorithmic recommendations, noting that the parties had not adequately briefed the question of whether YouTube's algorithmic recommendations were "material support" to terrorism under the ATA. The Court held that the Ninth Circuit should first determine whether the plaintiffs' allegations, even if true, could establish aiding and abetting liability under the ATA — and only if so, proceed to the question of whether 230 immunity applied. No ruling on the core 230 question. The Court expressly declined to resolve the question of whether 230(c)(1) applies to algorithmic content recommendations, leaving this critical question for future adjudication. Justice Thomas, joined by Justice Gorsuch, concurred to emphasize their view that 230 immunity has been interpreted too broadly and should be narrowed.
**Significance:** The unresolved algorithm question. The per curiam decision left unresolved the most important question in modern platform liability law: whether Section 230 immunity extends to algorithmic content recommendations. This question has profound implications for content moderation, as platforms increasingly rely on algorithmic systems to curate, rank, and recommend content to users. The failure to resolve the question has created significant uncertainty for platforms and has intensified calls for legislative action.
Separation of primary and secondary liability. The Court's decision to require the lower court to first determine whether YouTube's conduct could constitute primary liability (aiding and abetting) under the ATA before reaching the 230 immunity question establishes an important analytical framework: courts should evaluate the merits of the underlying claim before considering whether 230 provides immunity. This approach could limit the use of 230 as a procedural shortcut to dismiss claims that raise serious questions of platform complicity in harm.
Judicial signals for narrowing 230. The concurring opinions by Justices Thomas and Gorsuch, advocating for a narrower reading of 230, reflect a growing judicial skepticism toward broad intermediary immunity. Together with the Court's subsequent refusal to grant certiorari in other 230 cases, Gonzalez signals that the Court may be positioning itself to substantially narrow 230 immunity in a future case.
Global divergence on algorithmic liability. Gonzalez stands in sharp contrast to the EU approach under the Digital Services Act (DSA), which specifically addresses algorithmic recommendations and requires platforms to assess and mitigate the risks posed by their recommendation systems. The US approach of leaving the question unresolved while the EU actively regulates algorithmic liability illustrates the growing divergence between the two major regulatory paradigms.

---

### Case 1.5: NetChoice, LLC v. Paxton, 595 U.S. 42 (2024) — US Supreme Court

**Date Decided:** July 1, 2024

**Court:** Supreme Court of the United States

**Facts:** In 2021, the Texas Legislature passed HB 20, a law that prohibited large social media platforms (those with more than 50 million active monthly users) from "censoring" user expression based on the viewpoint expressed. The law defined "censor" broadly to include removing, moderating, or otherwise restricting access to content, and prohibited platforms from discriminating on the basis of viewpoint. HB 20 was challenged by NetChoice LLC and the Computer & Communications Industry Association (CCIA), which represented major technology platforms including Meta, Google, and Twitter.
The United States District Court for the Western District of Texas granted a preliminary injunction, but the Fifth Circuit reversed, holding that HB 20 did not violate the First Amendment because platforms were not engaged in "speech" when they moderated content and because the law regulated platforms' conduct (not speech) in operating a common carrier-like service.
Platform content moderation is speech protected by the First Amendment. The Court rejected the Fifth Circuit's holding that platforms do not engage in "speech" when they moderate content. Instead, the Court held that a platform's content moderation decisions — including decisions about what content to display, feature, remove, or demote — constitute expressive activity protected by the First Amendment. The Court emphasized that "when a platform curates and presents content to its users, it is engaged in speech."
HB 20's restrictions likely violate the First Amendment. The Court held that HB 20's restrictions on content moderation were subject to heightened scrutiny and were likely unconstitutional because they prohibited platforms from making editorial judgments based on viewpoint. However, the Court declined to hold that the law was facially invalid in all applications, instead remanding for the lower courts to evaluate the law on an as-applied basis.
The First Amendment limits government regulation of editorial discretion. The Court's holding establishes that government regulation of platform content moderation is subject to First Amendment scrutiny because such regulation compels platforms to host speech they would otherwise choose to exclude, and interferes with the platforms' own editorial expression.

**Issue:** Whether HB 20's content moderation restrictions violate the First Amendment by compelling platforms to carry content they would otherwise remove, and whether the law is facially invalid under the First Amendment's prohibition on viewpoint-based regulations.
**Holding:** The Supreme Court, in an opinion by Justice Kagan, reversed the Fifth Circuit and remanded. The Court held: Platform content moderation is speech protected by the First Amendment. The Court rejected the Fifth Circuit's holding that platforms do not engage in "speech" when they moderate content. Instead, the Court held that a platform's content moderation decisions — including decisions about what content to display, feature, remove, or demote — constitute expressive activity protected by the First Amendment. The Court emphasized that "when a platform curates and presents content to its users, it is engaged in speech." HB 20's restrictions likely violate the First Amendment. The Court held that HB 20's restrictions on content moderation were subject to heightened scrutiny and were likely unconstitutional because they prohibited platforms from making editorial judgments based on viewpoint. However, the Court declined to hold that the law was facially invalid in all applications, instead remanding for the lower courts to evaluate the law on an as-applied basis. The First Amendment limits government regulation of editorial discretion. The Court's holding establishes that government regulation of platform content moderation is subject to First Amendment scrutiny because such regulation compels platforms to host speech they would otherwise choose to exclude, and interferes with the platforms' own editorial expression.
**Significance:** Platforms as speakers. NetChoice is the most important Supreme Court decision on the First Amendment status of platform content moderation. By holding that platforms are "speakers" whose content moderation decisions are protected expression, the Court established a constitutional barrier to government regulation of platform editorial decisions. This has immediate implications for similar laws in Florida (SB 7072), which the Court also addressed in Moyle v. United States, and for proposed federal legislation that would restrict platforms' ability to moderate content.
The common carrier analogy rejected. The Court rejected the argument that platforms should be regulated as common carriers with no editorial discretion, finding no basis in precedent or principle for treating platforms as mere conduits when they actively curate and present content to users. This rejection of the common carrier analogy is significant because several state legislatures and members of Congress had proposed regulating platforms as common carriers.
As-applied vs. facial invalidation. The Court's decision to remand for as-applied review rather than facial invalidation leaves open the possibility that some content moderation regulations — particularly those that are viewpoint-neutral and narrowly tailored — may survive First Amendment scrutiny. This nuanced approach creates a pathway for future regulation that is more carefully tailored to the Court's constitutional framework.
Tension with DSA approach. The decision creates a sharp contrast with the EU's Digital Services Act, which mandates content moderation obligations for large platforms. While the US constitutional framework protects platforms' editorial discretion, the DSA imposes affirmative obligations. This divergence reflects fundamentally different philosophical approaches: the US prioritizes private speech rights, while the EU prioritizes user protection and content governance.

---

### Case 1.6: Eva Glawischnig-Piesczek v. Facebook Ireland Ltd., Case C-18/18 (2019) — Court of Justice of the European Union

**Date Decided:** October 3, 2019

**Court:** Court of Justice of the European Union (CJEU), Grand Chamber

**Facts:** Eva Glawischnig-Piesczek, an Austrian politician and former chair of the Austrian Green Party, brought suit against Facebook Ireland Ltd. (now Meta Platforms Ireland Ltd.) over defamatory statements posted by an anonymous user on Facebook. The defamatory post, which was identical to a previously published article from a right-wing magazine, accused Glawischnig-Piesczek of various crimes including treason and corruption. The post was shared by other users and generated comments that were also defamatory.
Glawischnig-Piesczek sought an injunction requiring Facebook to remove the specific defamatory post worldwide, to remove all copies and equivalents of the post, and to prevent future sharing of identical or equivalent content. The Austrian courts referred several questions to the CJEU concerning the scope of the E-Commerce Directive's platform liability framework, specifically whether the directive permitted or required courts to issue injunctions ordering platforms to remove content that is identical or equivalent to content previously found to be illegal.
E-Commerce Directive does not preclude worldwide removal orders. The Court held that EU law does not preclude national courts from ordering platforms to remove content worldwide, within the limits of international law. However, the Court acknowledged that the enforcement of such orders outside the EU may be subject to the limitations imposed by international law and the laws of third countries.
Injunctions may cover identical and equivalent content. The Court held that the E-Commerce Directive permits national courts to order platforms to remove not only the specific illegal content that has been identified, but also information identical to that content, and in certain circumstances, information equivalent to that content. The Court established a framework under which a court may order a platform to remove "information identical to the information at issue, in particular by making use of the means and technologies available to that hosting service provider," and may further order the removal of information equivalent to the illegal content where the platform fails to demonstrate that it has taken sufficient measures to prevent the dissemination of equivalent content.
Notice-and-action within the E-Commerce framework. The Court's decision was carefully framed within the existing E-Commerce Directive framework, holding that the directive's prohibition on general monitoring obligations (Article 15) is not violated by targeted injunctions that require the removal of specific categories of content (identical or equivalent to previously identified illegal content) using existing technologies. The Court emphasized that such injunctions do not require "general monitoring" because they are targeted at content that is identical or equivalent to content already found to be illegal.

**Issue:** (1) Whether the E-Commerce Directive (Directive 2000/31/EC), particularly Articles 14 and 15, precludes national courts from ordering a platform to remove content found to be illegal worldwide; (2) whether the directive permits injunctions requiring platforms to remove "information identical" or "information equivalent" to content previously found to be illegal; and (3) whether such injunctions must be limited to the territory of the Member State issuing the order.
**Holding:** The CJEU Grand Chamber, in an opinion by Advocate General Szpunar (which the Court substantially followed), held: E-Commerce Directive does not preclude worldwide removal orders. The Court held that EU law does not preclude national courts from ordering platforms to remove content worldwide, within the limits of international law. However, the Court acknowledged that the enforcement of such orders outside the EU may be subject to the limitations imposed by international law and the laws of third countries. Injunctions may cover identical and equivalent content. The Court held that the E-Commerce Directive permits national courts to order platforms to remove not only the specific illegal content that has been identified, but also information identical to that content, and in certain circumstances, information equivalent to that content. The Court established a framework under which a court may order a platform to remove "information identical to the information at issue, in particular by making use of the means and technologies available to that hosting service provider," and may further order the removal of information equivalent to the illegal content where the platform fails to demonstrate that it has taken sufficient measures to prevent the dissemination of equivalent content. Notice-and-action within the E-Commerce framework. The Court's decision was carefully framed within the existing E-Commerce Directive framework, holding that the directive's prohibition on general monitoring obligations (Article 15) is not violated by targeted injunctions that require the removal of specific categories of content (identical or equivalent to previously identified illegal content) using existing technologies. The Court emphasized that such injunctions do not require "general monitoring" because they are targeted at content that is identical or equivalent to content already found to be illegal.
**Significance:** Global reach of EU content orders. The Court's holding that EU courts may order worldwide content removal, subject to international law constraints, has been one of the most consequential and controversial aspects of the decision. While the Court acknowledged international law limitations, the practical effect is that platforms operating in the EU face the prospect of global content removal obligations, potentially conflicting with the laws and free speech protections of other jurisdictions. This extraterritorial dimension has been criticized by digital rights organizations and by courts in other jurisdictions.
The "identical and equivalent" standard. The CJEU's creation of the "identical and equivalent" standard for content removal orders represents a significant expansion of the traditional notice-and-action framework. By requiring platforms to proactively remove not only the specific content identified as illegal but also "equivalent" content, the Court imposed an affirmative monitoring obligation that goes beyond the E-Commerce Directive's notice-and-takedown model. This has led to concerns about over-removal, the difficulty of defining "equivalent" content, and the potential chilling effect on lawful expression.
Algorithmic content moderation required. The Court's reference to "the means and technologies available to that hosting service provider" implicitly requires platforms to deploy algorithmic content detection and removal tools to comply with the "identical and equivalent" standard. This has effectively mandated the use of automated content moderation systems, raising concerns about the accuracy of such systems, the lack of human oversight, and the potential for discriminatory or erroneous removals.
Influence on the DSA. Glawischnig-Piesczek was a significant precursor to the Digital Services Act's (DSA) content moderation framework. The DSA's obligations on very large online platforms (VLOPs) to assess systemic risks, conduct annual audits, and implement mitigation measures reflect the CJEU's recognition that platform-scale content moderation requires proactive, technology-driven approaches rather than purely reactive notice-and-takedown systems.

---

### Case 1.7: Tatiana C. v. Meta Platforms Inc., No. 1:21-cv-00673 (D.D.C. 2023) — US District Court for the District of Columbia

**Date Decided:** 2023 (various rulings; case ongoing)

**Court:** United States District Court for the District of Columbia

**Facts:** Tatiana C., identified as a minor at the time of the alleged acts, brought suit against Meta Platforms Inc. under the Trafficking Victims Protection Reauthorization Act (TVPRA), 18 U.S.C. 1595, alleging that Meta's platform (Instagram) facilitated her sex trafficking by failing to take adequate measures to prevent, detect, and respond to the trafficking of minors on its platform. The plaintiff alleged that her trafficker used Instagram to recruit, groom, and advertise her, and that Meta's recommendation algorithms actively facilitated the trafficker's activities by recommending the plaintiff's profile to potential buyers and recommending the trafficker's content to the plaintiff. The plaintiff further alleged that Meta had actual or constructive knowledge of the use of Instagram for sex trafficking and failed to take reasonable measures to prevent it.
The case was one of several high-profile lawsuits filed against social media companies alleging that their platforms facilitated child exploitation and sex trafficking, testing the limits of Section 230 immunity and the scope of platform obligations under federal statutes.
FOSTA's 230 exception applies to platform liability for sex trafficking. The court held that FOSTA, which amended 230 to create an exception for claims related to sex trafficking under federal or state law, opened the door to TVPRA claims against platforms that allegedly facilitated sex trafficking. The court rejected Meta's argument that FOSTA's exception was narrowly limited to claims directly alleging that the platform itself was a trafficker.
Allegations of knowing facilitation survive. The court held that the plaintiff's allegations — that Meta's algorithms recommended the plaintiff to potential traffickers and that Meta failed to implement adequate safeguards despite knowledge of trafficking on its platform — were sufficient to state a claim for "knowing participation in a venture" under the TVPRA. The court emphasized that the question of whether Meta actually knew of and participated in the trafficking was a factual matter for the jury.
Algorithmic facilitation is cognizable. The court held that allegations concerning Meta's recommendation algorithms — specifically, that the algorithms recommended the plaintiff's profile to individuals seeking to purchase sex with minors — were cognizable under the TVPRA and not barred by 230.

**Issue:** (1) Whether Section 230 of the Communications Decency Act bars TVPRA claims against Meta for sex trafficking facilitated through its platform; (2) whether Meta's recommendation algorithms and failure to implement adequate safeguards constituted "participation in a venture" under the TVPRA; and (3) whether the TVPRA's exception to Section 230 immunity (established by the Allow States and Victims to Fight Online Sex Trafficking Act, or FOSTA, in 2018) applies to platform conduct that allegedly facilitated sex trafficking.
**Holding:** The district court denied Meta's motion to dismiss, allowing the TVPRA claim to proceed. The court held: FOSTA's 230 exception applies to platform liability for sex trafficking. The court held that FOSTA, which amended 230 to create an exception for claims related to sex trafficking under federal or state law, opened the door to TVPRA claims against platforms that allegedly facilitated sex trafficking. The court rejected Meta's argument that FOSTA's exception was narrowly limited to claims directly alleging that the platform itself was a trafficker. Allegations of knowing facilitation survive. The court held that the plaintiff's allegations — that Meta's algorithms recommended the plaintiff to potential traffickers and that Meta failed to implement adequate safeguards despite knowledge of trafficking on its platform — were sufficient to state a claim for "knowing participation in a venture" under the TVPRA. The court emphasized that the question of whether Meta actually knew of and participated in the trafficking was a factual matter for the jury. Algorithmic facilitation is cognizable. The court held that allegations concerning Meta's recommendation algorithms — specifically, that the algorithms recommended the plaintiff's profile to individuals seeking to purchase sex with minors — were cognizable under the TVPRA and not barred by 230.
**Significance:** Section 230's limits exposed. Tatiana C. represents a significant development in the erosion of near-absolute 230 immunity. By allowing the TVPRA claim to proceed against Meta, the court demonstrated that FOSTA's exception to 230 immunity has teeth and that platforms can face liability for facilitating sex trafficking through their platforms. This case has been cited in subsequent litigation alleging platform complicity in various forms of harm.
Algorithmic liability. The court's willingness to consider allegations that Meta's recommendation algorithms actively facilitated trafficking is a landmark development in the emerging jurisprudence on algorithmic liability. By treating algorithmic recommendations as potentially constituting "participation in a venture" under the TVPRA, the court opened a new front in the legal analysis of platform algorithmic conduct.
Duty of care implications. The case raises fundamental questions about the duty of care owed by platforms to their users, particularly minors. If platforms can be held liable for failing to implement adequate safeguards against known risks on their platforms, the implications extend far beyond sex trafficking to other forms of online harm including self-harm, eating disorders, and radicalization.

---

### Case 1.8: Google LLC v. Oracle America, Inc., 593 U.S. 1 (2021) — US Supreme Court

**Date Decided:** April 5, 2021

**Court:** Supreme Court of the United States

**Facts:** Oracle America, Inc. (which acquired Sun Microsystems in 2010) owned the copyright in the Java platform, including the Java Application Programming Interface (API) declarations — approximately 11,500 lines of code organized into 37 packages. Google LLC used the Java API declarations in its Android operating system, which Google developed for mobile devices. Google copied the structure, sequence, and organization of the Java API declarations but wrote its own implementing code. Google did not obtain a license from Oracle for the use of the Java API declarations in Android.
Oracle sued Google for copyright infringement. The Federal Circuit held that the Java API declarations were copyrightable and that Google's use was not fair use. Google petitioned for certiorari.
Copyrightability assumed but not definitively decided. The Court assumed, without deciding, that the Java API declarations were copyrightable, focusing its analysis on the fair use question.
Google's use was transformative. The Court held that Google's use of the Java API declarations was transformative because Google used the declarations "for a different purpose and with a different result" than Oracle's original purpose. Google used the API declarations to create a new platform (Android) for smartphones, employing the established Java programming language to enable millions of programmers to work in a familiar environment. This transformative purpose — facilitating interoperability and building a new market — weighed heavily in favor of fair use.
The four-factor fair use analysis favored Google. The Court analyzed all four statutory fair use factors: (a) the purpose and character of the use (transformative, commercial); (b) the nature of the copyrighted work (functional, creative elements); (c) the amount and substantiality of the portion used (significant but necessary for interoperability); and (d) the effect on the market (the Android market was different from the desktop/server market for which Java was originally designed, and the API declarations were a small part of the overall copyrighted work). The Court held that the balance of factors weighed in favor of fair use.

**Issue:** (1) Whether the Java API declarations are copyrightable; and (2) whether Google's copying and use of the Java API declarations in Android constituted fair use under 17 U.S.C. 107.
**Holding:** The Supreme Court, in a 6-2 opinion authored by Justice Breyer, reversed the Federal Circuit and held that Google's use of the Java API declarations was fair use: Copyrightability assumed but not definitively decided. The Court assumed, without deciding, that the Java API declarations were copyrightable, focusing its analysis on the fair use question. Google's use was transformative. The Court held that Google's use of the Java API declarations was transformative because Google used the declarations "for a different purpose and with a different result" than Oracle's original purpose. Google used the API declarations to create a new platform (Android) for smartphones, employing the established Java programming language to enable millions of programmers to work in a familiar environment. This transformative purpose — facilitating interoperability and building a new market — weighed heavily in favor of fair use. The four-factor fair use analysis favored Google. The Court analyzed all four statutory fair use factors: (a) the purpose and character of the use (transformative, commercial); (b) the nature of the copyrighted work (functional, creative elements); (c) the amount and substantiality of the portion used (significant but necessary for interoperability); and (d) the effect on the market (the Android market was different from the desktop/server market for which Java was originally designed, and the API declarations were a small part of the overall copyrighted work). The Court held that the balance of factors weighed in favor of fair use.
**Significance:** Interoperability as fair use. The decision establishes that copying API declarations for the purpose of enabling interoperability — allowing programmers to use their existing skills and knowledge across platforms — is a transformative use that favors fair use. This has profound implications for the technology industry, where interoperability is essential for competition and innovation. The decision protects the ability of new platforms to build upon existing standards and interfaces without obtaining licenses from copyright holders.
Platform ecosystem boundaries. The decision has significant implications for the legal boundaries of platform ecosystems. By holding that API declarations may be freely used to enable interoperability, the Court limited the ability of platform owners to use copyright law to control the boundaries of their ecosystems. This is particularly relevant in the context of ongoing debates over platform competition, data portability, and the right to interoperate under the EU Digital Markets Act (DMA).
Balance between copyright and innovation. The decision reflects the Court's recognition that an overly expansive application of copyright law to software interfaces could stifle innovation and competition. By favoring fair use in the context of API interoperability, the Court struck a balance between copyright protection and the public interest in innovation — a balance that has implications far beyond the specific dispute between Google and Oracle.
Global impact on software copyright. While the decision is binding only in US courts, it has been cited as persuasive authority in other jurisdictions grappling with similar questions, and has influenced the ongoing legislative debate in the EU and elsewhere about the copyrightability of software interfaces and the scope of exceptions for interoperability.

---

### Case 1.9: Meta Platforms Inc. v. Bundeskartellamt, Case C-390/21 (2023) — Court of Justice of the European Union

**Date Decided:** July 4, 2023

**Court:** Court of Justice of the European Union (CJEU), Grand Chamber

**Facts:** The German Federal Cartel Office (Bundeskartellamt) initiated proceedings against Facebook Ireland Ltd. (now Meta Platforms Ireland Ltd.) under the German Act Against Restraints of Competition (Gesetz gegen Wettbewerbsbeschr nkungen, GWB), as amended in 2021 to include special provisions for large digital platforms. The Bundeskartellamt alleged that Meta abused its dominant position in the German social media market by combining user data across its various services (Facebook, Instagram, WhatsApp, and third-party websites and apps) without obtaining users' freely given consent, and by making the use of its social network conditional on the acceptance of this comprehensive data collection.
The Bundeskartellamt issued an order prohibiting Meta from combining user data across services without the user's freely given consent. Meta appealed, arguing that the data protection rules under the GDPR — not competition law — should govern the processing of personal data, and that the GDPR precludes the application of national competition law to data processing practices.
The GDPR does not preclude competition law enforcement. The Court held that the GDPR and EU competition law pursue different objectives and are complementary: the GDPR protects personal data and privacy rights, while competition law protects the competitive process and consumer welfare. The Court held that national competition authorities may assess a dominant company's data processing practices under competition law, even where those practices are also subject to the GDPR. However, the competition authority must take account of the objectives and provisions of the GDPR in its analysis.
Abuse of dominant position through data practices. The Court held that a dominant company's data processing practices may constitute an abuse of dominant position under Article 102 of the Treaty on the Functioning of the European Union (TFEU), particularly where the company exploits its market power to impose unfair terms on users, such as conditioning the provision of a service on the acceptance of comprehensive data collection without meaningful choice.
"Freely given consent" as a competitive concern. The Court held that the validity of user consent under the GDPR is a relevant consideration in the competition law analysis. If users cannot provide freely given consent because the service is conditional on acceptance of the data processing, then the consent is not valid under the GDPR, and the data processing may constitute an exploitative abuse of dominance under competition law.

**Issue:** (1) Whether the GDPR precludes national competition authorities from applying national competition law to data processing practices that are also subject to the GDPR; (2) whether Meta's practice of combining user data across services without consent constitutes an abuse of dominant position under EU competition law; and (3) whether the user's "consent" under the GDPR is valid when the provision of the social network service is conditioned on acceptance of the data processing.
**Holding:** The CJEU Grand Chamber held: The GDPR does not preclude competition law enforcement. The Court held that the GDPR and EU competition law pursue different objectives and are complementary: the GDPR protects personal data and privacy rights, while competition law protects the competitive process and consumer welfare. The Court held that national competition authorities may assess a dominant company's data processing practices under competition law, even where those practices are also subject to the GDPR. However, the competition authority must take account of the objectives and provisions of the GDPR in its analysis. Abuse of dominant position through data practices. The Court held that a dominant company's data processing practices may constitute an abuse of dominant position under Article 102 of the Treaty on the Functioning of the European Union (TFEU), particularly where the company exploits its market power to impose unfair terms on users, such as conditioning the provision of a service on the acceptance of comprehensive data collection without meaningful choice. "Freely given consent" as a competitive concern. The Court held that the validity of user consent under the GDPR is a relevant consideration in the competition law analysis. If users cannot provide freely given consent because the service is conditional on acceptance of the data processing, then the consent is not valid under the GDPR, and the data processing may constitute an exploitative abuse of dominance under competition law.
**Significance:** Convergence of data protection and competition law. The decision represents a landmark in the convergence of data protection law and competition law, establishing that the two regimes are complementary rather than mutually exclusive. This has opened the door for competition authorities across the EU to scrutinize platform data practices under both frameworks simultaneously, significantly expanding the regulatory toolkit available to address platform dominance.
Data as a competitive asset. The decision reinforced the principle that data — particularly personal data — is a critical competitive asset, and that the accumulation and processing of data by dominant platforms may raise competition concerns independent of traditional market definition analysis. This principle underpins the EU Digital Markets Act (DMA), which specifically addresses data-related obligations for designated "gatekeepers."
The consent paradigm under pressure. The Court's analysis of "freely given consent" in the context of dominant platforms highlights the fundamental inadequacy of the consent model for regulating data practices of platforms with significant market power. When a platform is so dominant that users have no meaningful alternative, the "choice" to accept data processing is illusory. This insight has informed the DMA's shift from a consent-based framework to a prohibition-based framework for certain data-related practices by gatekeepers.
Implications for global competition enforcement. The decision has been influential beyond the EU, cited by competition authorities in the UK (CMA), the US (FTC), and other jurisdictions as authority for the proposition that competition law can and should address the data practices of dominant digital platforms.

---

### Case 1.10: Fraenschou v. Meta Platforms Ireland Ltd. (2024) — Court of Justice of the European Union

**Date Decided:** 2024

**Court:** Court of Justice of the European Union (CJEU)

**Facts:** Eva Fraenschou, a Danish woman, brought proceedings against Meta Platforms Ireland Ltd. concerning defamatory and harassing content that had been posted about her on Facebook by an anonymous user. Fraenschou had reported the content to Facebook multiple times, but Facebook had declined to remove it, finding that the content did not violate its Community Standards. Fraenschou subsequently obtained a Danish court order requiring Facebook to remove the content, which Facebook complied with, but the content was reposted by the same or different users on multiple occasions.
Fraenschou sought a broader injunction requiring Facebook to take proactive measures to prevent the continued reposting of the defamatory content, including the use of automated detection tools to identify and block identical or similar content before it was published. The Danish courts referred questions to the CJEU concerning the scope of the E-Commerce Directive and the DSA as they relate to platform obligations to prevent the re-upload of previously identified illegal content.
E-Commerce Directive permits targeted re-upload prevention. The Court held that Article 15 of the E-Commerce Directive, which prohibits Member States from imposing general monitoring obligations on platforms, does not preclude courts from ordering platforms to take targeted, specific measures to prevent the re-upload of content that has been previously found to be illegal. Such measures — including the use of automated content recognition technologies — are not "general monitoring" because they are targeted at specific, previously identified illegal content and do not require the platform to monitor all user-generated content proactively.
Proportionality requirement. The Court held that any such injunction must satisfy the requirements of proportionality under EU law, including the requirements that (a) the measure is necessary and suitable for achieving the objective of preventing the dissemination of illegal content; (b) there is no less restrictive alternative; and (c) the measure does not impose an excessive burden on the platform or create a risk of over-blocking lawful content. The referring court must assess these proportionality requirements on a case-by-case basis.
Consistency with the DSA. The Court noted that the DSA, which entered into force in 2024, explicitly requires very large online platforms (VLOPs) to assess and mitigate systemic risks, including the risk of dissemination of illegal content, and to implement measures to prevent the re-upload of previously identified illegal content. The Court held that the DSA's provisions are consistent with the E-Commerce Directive's framework and do not contradict the principle that targeted re-upload prevention measures are permissible.

**Issue:** (1) Whether the E-Commerce Directive permits or requires platforms to implement proactive measures (including automated content recognition) to prevent the re-upload of content that has previously been found to be illegal by a court; (2) whether such measures are consistent with Article 15 of the E-Commerce Directive's prohibition on general monitoring obligations; and (3) how the Digital Services Act's (DSA) provisions on content moderation interact with the E-Commerce Directive's framework.
**Holding:** The CJEU held: E-Commerce Directive permits targeted re-upload prevention. The Court held that Article 15 of the E-Commerce Directive, which prohibits Member States from imposing general monitoring obligations on platforms, does not preclude courts from ordering platforms to take targeted, specific measures to prevent the re-upload of content that has been previously found to be illegal. Such measures — including the use of automated content recognition technologies — are not "general monitoring" because they are targeted at specific, previously identified illegal content and do not require the platform to monitor all user-generated content proactively. Proportionality requirement. The Court held that any such injunction must satisfy the requirements of proportionality under EU law, including the requirements that (a) the measure is necessary and suitable for achieving the objective of preventing the dissemination of illegal content; (b) there is no less restrictive alternative; and (c) the measure does not impose an excessive burden on the platform or create a risk of over-blocking lawful content. The referring court must assess these proportionality requirements on a case-by-case basis. Consistency with the DSA. The Court noted that the DSA, which entered into force in 2024, explicitly requires very large online platforms (VLOPs) to assess and mitigate systemic risks, including the risk of dissemination of illegal content, and to implement measures to prevent the re-upload of previously identified illegal content. The Court held that the DSA's provisions are consistent with the E-Commerce Directive's framework and do not contradict the principle that targeted re-upload prevention measures are permissible.
**Significance:** Legal basis for upload filters. The decision provides a definitive legal basis for courts to order platforms to implement upload filters and other automated content recognition tools to prevent the re-upload of previously identified illegal content. While the Court carefully limited this authority to targeted measures (rather than general monitoring), the practical effect is that platforms may be required to deploy automated content detection systems in response to specific court orders, creating a pathway for judicially mandated content filtering.
Proportionality as a check on over-blocking. The Court's emphasis on proportionality provides an important safeguard against the risk that court-ordered content filtering measures may result in the over-removal of lawful content. By requiring courts to assess whether the measure is necessary, suitable, and the least restrictive means available, the decision creates a judicial check on the scope and implementation of content filtering obligations.
The DSA's proactive framework validated. The decision implicitly validates the DSA's proactive approach to content moderation, which requires VLOPs to implement risk assessment and mitigation measures rather than relying solely on reactive notice-and-takedown systems. By confirming that the E-Commerce Directive permits targeted proactive measures, the Court has removed a potential legal obstacle to the DSA's implementation and has signaled that the era of purely reactive content moderation is coming to an end in the EU.
Global implications for content governance. The decision, together with Glawischnig-Piesczek (C-18/18), establishes a comprehensive EU framework for court-ordered content moderation that includes both removal and re-upload prevention obligations. This framework is likely to influence platform governance practices globally, as platforms operating across jurisdictions will need to implement content moderation systems that comply with the EU's requirements while navigating the different regulatory approaches of other jurisdictions.
Comparative Analysis: The Shield-to-Scrutiny Spectrum
The ten cases in this Part reveal a clear trajectory in the evolution of platform liability law:
Phase 1 — The Shield Era (1997–2010s): Reno v. ACLU (1997) established the Internet as a space entitled to full free speech protection, while Zeran v. AOL (1997) created near-absolute intermediary immunity under Section 230. During this period, platforms operated with minimal legal obligations regarding user-generated content, and the prevailing assumption was that self-regulation and market forces would be sufficient to address harmful content.
Phase 2 — The Questioning Era (2010s–2020): Glawischnig-Piesczek (2019) and Google v. Oracle (2021) began to chip away at the edges of platform immunity, introducing the concepts of worldwide content removal orders, algorithmic content moderation obligations, and fair use limits on copyright-based ecosystem control. The EU's Digital Services Act, informed by these decisions, marked a regulatory paradigm shift from reactive to proactive content governance.
Phase 3 — The Scrutiny Era (2021–present): Google v. Gonzalez (2023), NetChoice v. Paxton (2024), Meta v. Bundeskartellamt (2023), Tatiana C. v. Meta (2023), and Fraenschou v. Meta (2024) represent a comprehensive assault on the shield-era assumptions. Platforms face algorithmic liability questions, constitutional constraints on government regulation, competition-law scrutiny of data practices, statutory liability for facilitating trafficking, and mandatory upload filtering obligations. The Brazilian STF's decision (Tema 533 & 987, 2025) adds a distinctive proportionality-based framework from the Global South.
Key Takeaways:
The end of blanket immunity. The era of near-absolute intermediary immunity is over. Platforms now face a complex, multi-layered regime of obligations under statutory law, constitutional law, competition law, and sector-specific regulation. The question is no longer whether platforms are liable, but for what and to what extent.
Algorithmic liability is the frontier. Across jurisdictions, the most consequential legal questions concern the liability of platforms for the effects of their algorithms — recommendation systems, content ranking, and automated content moderation. The unresolved questions from Gonzalez, the DSA's risk assessment framework, and the Brazilian STF's proportionality test all point to algorithmic liability as the defining legal challenge of the next decade.
Divergence, not convergence. Despite the shared challenges, the regulatory responses diverge sharply: the US protects platforms' editorial discretion under the First Amendment (NetChoice), the EU mandates proactive content governance through the DSA and DMA, and Brazil adopts a proportionality-based framework that charts a third path. This divergence creates significant compliance challenges for global platforms and raises the prospect of regulatory conflict between jurisdictions.
The rise of platform governance as a legal discipline. The cases in this Part collectively establish platform governance as a distinct legal discipline, drawing on First Amendment law, statutory interpretation, competition law, data protection law, and international law. Practitioners and scholars must now engage with this multidisciplinary framework to understand and navigate the evolving obligations of digital platforms.
Expanded Cases: Section 230, EU E-Commerce, and Global Platform Liability
The following twenty-five additional cases expand the coverage of Part One to address the full range of intermediary liability doctrines, content moderation regimes, and platform accountability frameworks across multiple jurisdictions.

---

### Case 1.11: Fair Housing Council of San Fernando Valley v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) —US Court of Appeals for the Ninth Circuit

**Date Decided:** March 26, 2008

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: 521 F.3d 1157 (9th Cir. 2008)

**Facts:** The Fair Housing Councils of San Fernando Valley and San Diego sued Roommates.com, an online roommate-matching service, alleging that the website's questionnaire —which asked users to specify their sex, sexual orientation, and family status preferences for potential roommates —violated the Fair Housing Act (FHA) and California's Fair Employment and Housing Act (FEHA). Roommates.com argued that it was immune under Section 230 because the discriminatory information was provided by users. However, Roommates.com actively designed the questionnaire, requiring users to answer specific questions as a condition of using the service, and used the answers to filter and match potential roommates.

**Issue:** Whether Section 230(c)(1) immunity shields a platform that actively solicits, structures, and uses discriminatory information provided by users to make matches.

**Holding:** The Ninth Circuit, in an opinion by Judge Kozinski, held that Section 230 did not immunize Roommates.com. The court drew a critical distinction between content "provided by" users versus content "provided by" the platform through its own design choices. The questionnaire's structured questions and mandatory fields constituted content "provided by" the platform itself. However, the court held that Section 230 did protect the "additional comments" field where users could freely type their own preferences.
**Significance:** Established the "material contribution to illegality" test: when a platform's own design, functionality, or structured prompts are an essential part of the unlawful conduct, 230 immunity does not apply.
Demonstrated that 230 immunity has limits even when user-generated content is involved, particularly where the platform's own features play an active role in generating or facilitating unlawful conduct.
The "provided by" distinction has been influential in subsequent cases and informed the debate over whether algorithmic recommendation systems constitute content "provided by" the platform.

---

### Case 1.12: Herrick v. Grindr, LLC —US District Court for the Southern District of New York

**Date Decided:** September 6, 2016 (District Court)

**Court:** United States District Court for the Southern District of New York
Case citation: No. 16-cv-1583 (S.D.N.Y. Sep. 6, 2016)

**Facts:** Matthew Herrick was subjected to sustained harassment when an anonymous individual created fake profiles on Grindr using Herrick's photographs and personal information. The impersonator sent more than 1,000 men to Herrick's home and workplace, falsely representing that Herrick was interested in sexual encounters. Herrick reported the fake profiles to Grindr multiple times, but the profiles were recreated after each removal, often within minutes. Herrick sought an injunction requiring Grindr to take more effective measures to prevent fake profile creation.

**Issue:** Whether Section 230(c)(1) bars state-law tort claims against Grindr for failing to take adequate measures to prevent the creation and continued operation of fake profiles used to harass an individual.

**Holding:** The district court granted Grindr's motion to dismiss, holding that Section 230 barred Herrick's claims because the allegedly harmful content was created by third parties. The court rejected Herrick's argument that Grindr's failure to implement effective anti-impersonation measures took it outside 230 immunity, distinguishing Roommates.com on the grounds that Grindr did not itself develop or structure the content. The Second Circuit later dismissed the appeal as moot after settlement.
**Significance:** Illustrates the limits of 230 immunity in the context of targeted, sustained platform-facilitated harassment.
The district court's narrow reading of Roommates.com highlighted the difficulty of applying 230 to platform features that facilitate rather than generate harmful content.
The case became a touchstone in legislative debates about amending 230 to address platform-facilitated harassment and impersonation.

---

### Case 1.13: Chicago Lawyers' Committee for Civil Rights Under Law, Inc. v. Craigslist, Inc., 519 F.3d 666 (7th Cir. 2008) —US Court of Appeals for the Seventh Circuit

**Date Decided:** March 5, 2008

**Court:** United States Court of Appeals for the Seventh Circuit
Case citation: 519 F.3d 666 (7th Cir. 2008)

**Facts:** The Chicago Lawyers' Committee for Civil Rights sued Craigslist, alleging that housing advertisements on its website contained discriminatory statements in violation of the Fair Housing Act. The advertisements included express preferences based on race, religion, sex, and familial status. Craigslist argued it was immune under 230 because it merely hosted advertisements created by third-party users.

**Issue:** Whether 230 bars FHA claims against a platform that publishes classified advertisements containing discriminatory user-created statements.

**Holding:** The Seventh Circuit, in an opinion by Judge Easterbrook, held that 230 barred the claims. The court reasoned that Craigslist was a passive intermediary —a "bulletin board" —that merely published content created by others, and did not require users to provide discriminatory information or use it to facilitate matches.
**Significance:** Established the contrast between passive hosting (protected by 230) and active facilitation (potentially outside immunity), paralleling Roommates.com from the Ninth Circuit.
Illustrates the jurisdictional split on 230's application to discriminatory content: broad immunity (7th Circuit) vs. feature-specific limitation (9th Circuit).
Judge Easterbrook's "bulletin board" metaphor remains influential in lower-court 230 analysis.

---

### Case 1.14: Doe v. Twitter, Inc., 41 F.4th 68 (2d Cir. 2022) —US Court of Appeals for the Second Circuit

**Date Decided:** July 20, 2022

**Court:** United States Court of Appeals for the Second Circuit
Case citation: 41 F.4th 68 (2d Cir. 2022)

**Facts:** Families of victims of a 2017 terrorist attack in Istanbul sued Twitter under the Antiterrorism Act (ATA), alleging that Twitter knowingly provided material support to ISIS by allowing the terrorist organization to use its platform for recruitment and propaganda, and failed to remove ISIS-affiliated accounts despite knowing of their existence.

**Issue:** Whether 230 bars ATA claims against Twitter for allegedly allowing ISIS to use its platform for terrorist activities.

**Holding:** The Second Circuit affirmed dismissal, holding that the claims were predicated on Twitter's failure to remove third-party content, which constituted "publisher" activity protected by 230. The court rejected the argument that Twitter's "knowing" allowance of ISIS content created a knowledge-based exception to immunity.
**Significance:** Confirmed the broad scope of 230 immunity in the terrorism context, rejecting knowledge-based exceptions.
Amplified the tension between 230 and counter-terrorism accountability, contributing to the pressure leading to Gonzalez v. Google (2023).
The categorical reading of 230 underscored the judicial consensus that only congressional action could substantially narrow immunity.

---

### Case 1.15: Barrett v. Rosenthal, 146 P.3d 510 (Cal. 2006) —Supreme Court of California

**Date Decided:** November 28, 2006

**Court:** Supreme Court of California
Case citation: 146 P.3d 510 (Cal. 2006)

**Facts:** Ilena Rosenthal operated a website and email discussion list on alternative health issues. Physicians Stephen Barrett and Terry Polevoy sued Rosenthal for republication of defamatory statements about them originally posted by third parties. Rosenthal had republished the statements by forwarding them to her email list and posting them on her website.

**Issue:** Whether 230(c)(1) immunizes an individual website operator and email list administrator from liability for republishing defamatory third-party content.

**Holding:** The California Supreme Court unanimously held that 230 barred the defamation claims. Rosenthal's activities constituted the functions of an "interactive computer service" provider and the content had been "provided by another information content provider."
**Significance:** Extended 230 immunity beyond commercial platforms to individual website operators and email list administrators.
Established that "user" of an interactive computer service —not just "provider" —is covered by immunity.
Reinforced the technology-neutral, platform-agnostic approach of 230.

---

### Case 1.16: Doe v. Backpage.com, LLC —US Court of Appeals for the Seventh Circuit

**Date Decided:** July 9, 2021

**Court:** United States Court of Appeals for the Seventh Circuit
Case citation: No. 20-1593 (7th Cir. 2021)

**Facts:** Multiple plaintiffs who had been trafficked through Backpage.com sued under the Trafficking Victims Protection Reauthorization Act (TVPRA). The plaintiffs alleged that Backpage actively facilitated sex trafficking by designing its platform features (anonymity, prepaid payment options, automated ad reposting) to enable and conceal trafficking activity.

**Issue:** Whether the FOSTA exception to 230 applies retroactively to conduct that occurred before FOSTA's enactment on April 11, 2018.

**Holding:** The Seventh Circuit held that FOSTA's exception does not apply retroactively. The amendment was a substantive change requiring clear congressional intent for retroactivity, which was absent.
**Significance:** Clarified the temporal scope of FOSTA's 230 exception, limiting it to post-April 2018 conduct.
Highlighted the limitations of retroactive application of platform liability reforms.
Illustrated the practical challenges of achieving accountability for historical platform-facilitated harm.

---

### Case 1.17: Batzel v. Smith, 333 F.3d 1018 (9th Cir. 2003) —US Court of Appeals for the Ninth Circuit

**Date Decided:** August 26, 2003

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: 333 F.3d 1018 (9th Cir. 2003)

**Facts:** Ellen Batzel, a California attorney, was the subject of an email alleging that her family had looted art during the Nazi era. The email was sent to Toby Younie, who published it on his cultural property newsletter website. Batzel sued Younie for defamation. Younie argued immunity under 230 because the content was "provided by" the original email author.

**Issue:** Whether 230 immunizes a website operator who edits, selects, and publishes content originally created by a third party.

**Holding:** The Ninth Circuit held that 230 immunity applied. Younie's editing and republishing constituted the functions of an "interactive computer service" provider, and the underlying content was "provided by another information content provider."
**Significance:** Early establishment that editorial activity by a platform —selecting, editing, and formatting third-party content —does not strip 230 immunity.
Reinforced the "Good Samaritan" purpose of 230: encouraging platforms to exercise editorial judgment without fear of liability.
Contrasted with Roommates.com in establishing that the critical question is whether the platform is the source of the unlawful content.

---

### Case 1.18: L'Oréal SA v. eBay International AG, Case C-487/07 (2011) —Court of Justice of the European Union

**Date Decided:** July 12, 2011

**Court:** Court of Justice of the European Union (CJEU), Grand Chamber
Case citation: C-487/07 (EU:C:2011:474)

**Facts:** L'Oréal sued eBay in several EU Member States, alleging that eBay's marketplace was used to sell counterfeit L'Oréal products. L'Oréal argued that eBay had not taken sufficient measures to prevent counterfeit sales and that eBay's own advertising practices (using L'Oréal trademarks in keyword advertising) constituted trademark infringement.

**Issue:** Whether the operator of an online marketplace can be held liable for trademark infringement when it hosts listings for counterfeit goods, and when the platform loses its E-Commerce Directive safe harbor protection.

**Holding:** The CJEU held: (1) a marketplace operator is not directly liable for merely hosting listings, provided it plays a neutral role without knowledge of illegal activity; (2) the operator loses safe harbor if it has actual or constructive knowledge of illegal activity and fails to act expeditiously; (3) the platform's own use of trademarked keywords in advertising may constitute infringement if it suggests an economic link with the trademark holder.
**Significance:** Established the EU's "knowledge + failure to act" framework for platform liability under the E-Commerce Directive.
Clarified that constructive knowledge can strip safe harbor protection.
Significantly influenced the Digital Services Act's notice-and-action framework.

---

### Case 1.19: Google France SARL v. Louis Vuitton Malletier SA, Case C-236/08 (2010) —Court of Justice of the European Union

**Date Decided:** March 23, 2010

**Court:** Court of Justice of the European Union (CJEU)
Case citation: C-236/08 (EU:C:2010:159)

**Facts:** Louis Vuitton sued Google in France, alleging that Google's AdWords program allowed advertisers to purchase Louis Vuitton trademarks as keywords, triggering sponsored links to websites selling counterfeit products. Google argued it was a protected intermediary.

**Issue:** Whether a keyword advertising service provider infringes trademark rights by allowing advertisers to select trademarked keywords, and whether E-Commerce Directive safe harbors apply.

**Holding:** The CJEU held: (1) allowing advertisers to select trademarked keywords does not itself constitute trademark infringement; (2) however, the provider may be liable if it plays an "active role" in creating advertising content; (3) trademark owners may seek injunctions against advertisers where confusion about origin results.
**Significance:** Established the "active role" test: if a platform plays an active role in creating or shaping content, it is not a neutral intermediary and may lose immunity.
The "active role" test has been widely applied in subsequent EU platform liability cases and informed the DSA.
Established that keyword advertising services occupy an intermediary position subject to context-specific analysis.

---

### Case 1.20: Scarlet Extended SA v. SABAM, Case C-70/10 (2011) —Court of Justice of the European Union

**Date Decided:** November 24, 2011

**Court:** Court of Justice of the European Union (CJEU)
Case citation: C-70/10 (EU:C:2011:771)

**Facts:** SABAM, the Belgian collecting society, sought an injunction against Scarlet Extended (formerly Belgacom), an ISP, requiring it to install a generalized filtering system to prevent customers from illegally sharing copyrighted music via peer-to-peer networks.

**Issue:** Whether EU law permits ordering an ISP to install a generalized filtering system to prevent copyright infringement.

**Holding:** The CJEU held that EU law prohibits such an order. It would violate Article 15 of the E-Commerce Directive (prohibition on general monitoring) and the EU Charter of Fundamental Rights (privacy, data protection, freedom to conduct a business).
**Significance:** Established the foundational principle that general monitoring obligations are prohibited under EU law.
A landmark for digital rights, establishing that mandatory ISP-level filtering violates fundamental rights.
The prohibition on general monitoring has been carried forward into the Digital Services Act.

---

### Case 1.21: SABAM v. Netlog NV, Case C-360/10 (2012) —Court of Justice of the European Union

**Date Decided:** February 16, 2012

**Court:** Court of Justice of the European Union (CJEU)
Case citation: C-360/10 (EU:C:2012:85)

**Facts:** SABAM sought an injunction against Netlog NV, a Belgian social networking platform, requiring it to install a generalized filtering system to prevent users from sharing copyrighted music files.

**Issue:** Whether EU law permits ordering a social networking platform to install a generalized filtering system for copyright enforcement.

**Holding:** The CJEU applied the Scarlet reasoning, holding that EU law prohibits such an order for social networking platforms as well as ISPs.
**Significance:** Extended the Scarlet prohibition on general monitoring to social networking platforms, confirming it applies across all intermediary categories.
The combined effect of Scarlet and SABAM v. Netlog established the EU's foundational position against mandatory content filtering.
Creates a productive tension with Glawischnig-Piesczek (Case 1.6), illustrating the distinction between "general monitoring" (prohibited) and "targeted measures" (permitted).

---

### Case 1.22: Shreya Singhal v. Union of India, (2015) 5 SCC 1 —Supreme Court of India

**Date Decided:** March 24, 2015

**Court:** Supreme Court of India
Case citation: (2015) 5 SCC 1

**Facts:** After two women were arrested for posting allegedly "offensive" messages on social media under Section 66A of India's Information Technology Act 2000, a writ petition challenged the constitutionality of Section 66A, which criminalized sending "grossly offensive" or "menacing" information through computer resources, or sending information known to be false for causing "annoyance, inconvenience, danger, obstruction, insult, injury, criminal intimidation, enmity, hatred or ill will."

**Issue:** Whether Section 66A of the IT Act violates freedom of speech and expression under Article 19(1)(a) of the Indian Constitution, and whether Section 79 (intermediary immunity) is valid.

**Holding:** The Supreme Court struck down Section 66A in its entirety as unconstitutionally vague and overbroad. The terms "grossly offensive" and "menacing" lacked objective standards. Section 79 (intermediary immunity) was upheld but the Court struck down the requirement that intermediaries remove content upon private notice, holding that intermediaries need only act upon court orders or government notifications.
**Significance:** One of the most important freedom of expression decisions in the Global South, establishing that criminalizing online speech based on vague criteria violates constitutional rights.
Established India's notice-and-intermediary framework: platforms are protected but must comply with court orders, not private complaints.
Influenced the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

---

### Case 1.23: The Molly Russell Inquest (2022) —Coroner's Court, North London

**Date Decided:** September 30, 2022

**Court:** Senior Coroner for North London (Andrew Walker)

**Facts:** Molly Russell, aged 14, died by suicide in November 2017. Her family discovered she had been extensively consuming self-harm and suicide-related content on Instagram and Pinterest in the months before her death. The inquest revealed that Instagram's algorithm had recommended harmful content to Molly and that the platforms' moderation systems had failed to protect her.

**Issue:** Whether the content moderation practices and recommendation algorithms of Instagram and Pinterest contributed to Molly Russell's death.

**Holding:** Senior Coroner Andrew Walker found that Molly died "from an act of self-harm while suffering from depression and the negative effects of online content." He explicitly found that Instagram and Pinterest's algorithms contributed to her death. A Prevention of Future Deaths report was issued under Regulation 28 calling for platform reforms.
**Significance:** The first time a coroner formally found that social media algorithms contributed to a user's death.
Directly influenced the passage of the UK Online Safety Act 2023.
Established that algorithmic content recommendation can be a causal factor in self-harm, challenging the passive-intermediary model of platform liability.

---

### Case 1.24: Ofcom Enforcement Actions under the Online Safety Act 2023 (2024–2025) —Ofcom (UK)

**Date Decided:** 2024–2025 (ongoing)
Court/Regulator: Ofcom (Office of Communications), United Kingdom

**Facts:** Following the Online Safety Act 2023, Ofcom was designated as enforcement authority. Ofcom issued codes of practice and guidance for regulated platforms, including requirements for illegal content risk assessments, children's safety duties, and transparency reporting. Ofcom initiated enforcement investigations into several major platforms' compliance.

**Issue:** Whether major platforms are complying with the OSA's duty of care obligations, including risk assessments and proportionate content moderation.

**Holding:** As of early 2025, Ofcom issued illegal content risk assessment guidance and began enforcement monitoring of designated services. Potential penalties of up to 10% of qualifying worldwide revenue could be imposed on non-compliant platforms.
**Significance:** Represents the most comprehensive regulatory enforcement framework for platform content moderation in the world.
Establishes a model for proactive, risk-based regulation distinct from the US litigation model and EU legislative mandate model.
Being closely watched worldwide as a potential model for platform governance regulation.

---

### Case 1.25: eSafety Commissioner v. Twitter/X (2023–2024) —Federal Court of Australia

**Date Decided:** 2023–2024 (proceedings ongoing)

**Court:** Federal Court of Australia

**Facts:** The Australian eSafety Commissioner issued formal removal notices to Twitter under the Online Safety Act 2021, requiring removal of abuse and violent content targeting individuals in Australia. When Twitter failed to comply within the statutory timeframe, the Commissioner initiated Federal Court proceedings seeking enforcement orders and civil penalties.

**Issue:** Whether Twitter/X failed to comply with the eSafety Commissioner's removal notices and is subject to civil penalties.

**Holding:** Federal Court proceedings continued through 2024, testing the enforceability of Australia's online safety regime and the platform's obligations following significant reductions in content moderation staff.
**Significance:** Tests Australia's Online Safety Act 2021, one of the world's most aggressive platform content regulation regimes.
Highlights challenges of enforcing content moderation obligations where platforms have reduced moderation capacity.
Australia's regulator-driven, notice-based enforcement model represents a third model of platform governance, distinct from both the US and EU.

---

### Case 1.26: ADPF 403 —Argui o de Descumprimento de Preceito Fundamental (2020) —Supremo Tribunal Federal (Brazil)

**Date Decided:** August 11, 2020 (reporter vote by Justice Fux; ongoing through 2025)

**Court:** Supremo Tribunal Federal (STF), Brazil
Case citation: ADPF 403

**Facts:** ADPF 403 was filed as a constitutional challenge seeking clarification of the Marco Civil da Internet's framework for addressing disinformation and illegal content on social media platforms. The case was heard amid intense controversy over the role of platforms in Brazilian politics, including allegations of political bias and the spread of false election and public health information.

**Issue:** Whether the Marco Civil da Internet's liability framework requires judicial elaboration to address large-scale disinformation.

**Holding:** The STF conducted extensive hearings over several years. ADPF 403 became intertwined with the STF's "Fake News" inquiry (Inquérito 4.781) and contributed to the proportionality-based framework ultimately adopted in Tema 533 and Tema 987 (Case 1.3).
**Significance:** Foundational in developing Brazil's proportionality-based approach to platform liability, preceding the STF's later decisions.
Demonstrated the role of constitutional courts in establishing platform governance frameworks absent comprehensive legislation.
Offers a model for Global South jurisdictions facing similar challenges with insufficient legislative frameworks.

---

### Case 1.27: Maria da Penha Law and Platform-Based Domestic Violence Cases (2021–2023) —Brazilian Courts

**Date Decided:** Various decisions, 2021–2023

**Court:** Various Brazilian state and federal courts, including STJ

**Facts:** Following Brazil's Maria da Penha Law (Law No. 11.340/2006) on domestic violence against women, courts increasingly addressed the role of digital platforms in facilitating domestic violence, stalking, and image-based abuse. Multiple cases involved the use of social media, messaging apps, and dating platforms to harass women in violation of protective orders.

**Issue:** Whether platforms have a duty to implement measures to prevent the use of their services for domestic violence, and whether such duties are consistent with the Marco Civil da Internet.

**Holding:** Brazilian courts developed growing case law requiring platforms to cooperate with law enforcement and comply with judicial orders to remove domestic violence content. Courts increasingly required technical measures including account blocking, content removal, and user identification disclosure pursuant to court orders.
**Significance:** Illustrates the intersection of gender-based violence law and platform liability, highlighting obligations to address technology-facilitated abuse.
Represents a growing global trend, with similar developments in the UK (Online Safety Act), Australia (Online Safety Act), and EU (DSA gender-based violence protections).
Demonstrated that the Marco Civil can be adapted through judicial interpretation to address emerging platform-facilitated harms.

---

### Case 1.28: Qihoo 360 Technology Co. v. Tencent Holdings Ltd. (2014) —Supreme People's Court of China

**Date Decided:** February 26, 2014

**Court:** Supreme People's Court, People's Republic of China
Case citation: Supreme Court Guiding Case No. 45, (2013) Min San Zhong Zi No. 5

**Facts:** Qihoo 360, a major Chinese internet security company, brought an antitrust claim against Tencent, operator of WeChat and QQ, China's dominant social media platforms. Qihoo alleged that Tencent abused its dominant position by bundling QQ with other products and requiring users to choose between QQ and Qihoo's software —the famous "difficult choice" (exclusive dealing) incident.

**Issue:** Whether Tencent's bundling practices constituted abuse of dominant market position under China's Anti-Monopoly Law.

**Holding:** The Supreme People's Court held that while Tencent held a dominant position, its bundling did not constitute an abuse because it did not exclude competition, harm consumer welfare, or foreclose competitors. The Court emphasized the dynamic nature of internet competition, where market positions can change rapidly.
**Significance:** China's most important internet antitrust decision, establishing the framework for analyzing competition in digital platform markets.
Established that competition-law analysis must account for network effects, multi-sided markets, and rapid innovation.
The Court's cautious approach contrasted with subsequent more aggressive enforcement by China's SAMR (including the 2021 Alibaba fine).

---

### Case 1.29: Short-Video Platform Copyright Liability Cases (2022–2023) —Beijing Internet Court

**Date Decided:** 2022–2023 (multiple decisions)

**Court:** Beijing Internet Court, People's Republic of China

**Facts:** The Beijing Internet Court adjudicated cases involving short-video platform liability for user copyright infringement on platforms including Douyin and Kuaishou. Copyright holders argued that platforms should be liable for facilitating infringement through recommendation algorithms that actively promoted infringing content.

**Issue:** Whether platforms that actively recommend infringing content through algorithmic systems lose safe harbor protection under Chinese copyright law.

**Holding:** The court held that algorithmic recommendation constitutes active content selection and distribution, requiring platforms to exercise higher duty of care. Platforms must implement proactive measures including algorithmic detection of infringing content.
**Significance:** China became one of the first major jurisdictions to establish that algorithmic recommendation strips platforms of safe harbor protection.
Contrasts sharply with the unresolved question in US law (Gonzalez v. Google, Case 1.4).
May influence platform liability development in other jurisdictions regarding algorithmic liability.

---

### Case 1.30: Search Engine Liability Cases (2020) —Beijing Intellectual Property Court

**Date Decided:** 2020

**Court:** Beijing Intellectual Property Court, People's Republic of China

**Facts:** Baidu, China's dominant search engine, was sued for providing search results linking to pirated literary works and unauthorized streaming of copyrighted content. Plaintiffs alleged Baidu's algorithms actively directed users to infringing content and that Baidu failed to implement adequate measures despite knowing of widespread infringement.

**Issue:** Whether a search engine operator that actively indexes and links to infringing content is liable, and whether the "information location service" safe harbor applies.

**Holding:** The court held that Baidu was entitled to safe harbor as an "information location service" conditional on compliance with notice-and-takedown obligations. However, Baidu's failure to take adequate measures upon receiving notice exceeded the scope of protection. The court noted that recommendation and ranking algorithms could affect the liability analysis.
**Significance:** Illustrated China's evolving approach to search engine liability, moving from near-absolute safe harbor to nuanced analysis considering the platform's active role.
Reflected the broader trend toward imposing proactive obligations on platforms.
Contrasts with near-absolute immunity for search engines under US 230.

---

### Case 1.31: Inquérito 4.781 ("Fake News Inquiry") (2019–2024) —Supremo Tribunal Federal (Brazil)

**Date Decided:** 2019–2024 (ongoing investigation)

**Court:** Supremo Tribunal Federal (STF), Brazil
Case citation: Inquérito 4.781

**Facts:** In March 2019, Justice Dias Toffoli opened a formal inquiry to investigate the financing and organization of "fake news" campaigns on WhatsApp, Twitter, and Facebook, particularly those targeting the judiciary and democratic institutions. The investigation included requests for platform data, executive testimony, and analysis of digital advertising spending related to disinformation.

**Issue:** Whether the STF has authority to investigate organized disinformation campaigns on digital platforms, and what cooperation obligations platforms have.

**Holding:** The STF ordered platforms to provide data on advertising, account activity, and content moderation practices. The investigation led to criminal charges and contributed to the broader regulatory response including ADPF 403 and Tema 533/987.
**Significance:** One of the most significant judicial investigations into digital disinformation worldwide.
Established important precedents for platform duty to cooperate with judicial investigations into online harm.
Highlighted the tension between judicial action against disinformation and freedom of expression —a tension central to platform governance debates worldwide.

---

### Case 1.32: Google LLC v. Defteros, 601 U.S. 28 (2024) —US Supreme Court

**Date Decided:** June 27, 2024

**Court:** Supreme Court of the United States
Case citation: 601 U.S. 28 (2024)

**Facts:** Individuals identified as alleged participants in Turkish attacks on Kurdish villages sued Google under the Alien Tort Statute (ATS), alleging that YouTube hosted and recommended videos identifying them as war criminals. They argued YouTube's recommendations constituted "aiding and abetting" extrajudicial killing.

**Issue:** Whether the ATS creates a private right of action for aiding and abetting liability against an interactive computer service for hosting and recommending third-party content.

**Holding:** The Supreme Court held unanimously that the ATS does not provide a cause of action for domestic conduct —the conduct occurred entirely outside the US. The Court did not reach the 230 question.
**Significance:** Like Gonzalez, the Court avoided resolving the core 230 question, disposing of the case on threshold grounds.
Signaled that the Court is deferring to Congress on 230's fundamental scope.
Left unresolved whether 230 extends to algorithmic recommendation in the international human rights context.

---

### Case 1.33: Novak v. T-Mobile USA, Inc., 19 F.4th 382 (4th Cir. 2021) —US Court of Appeals for the Fourth Circuit

**Date Decided:** May 6, 2021

**Court:** United States Court of Appeals for the Fourth Circuit
Case citation: 19 F.4th 382 (4th Cir. 2021)

**Facts:** A class of plaintiffs sued T-Mobile, alleging that its premium SMS service facilitated a fraudulent billing scheme by third-party content providers. T-Mobile retained 30–40% of revenue from premium SMS charges.

**Issue:** Whether 230 bars claims against a telecommunications carrier that facilitates delivery of third-party premium SMS messages and collects a percentage of revenue.

**Holding:** The Fourth Circuit held that 230 did not bar the claims. T-Mobile was not a passive intermediary but "an essential participant in the transactions" —selecting providers, setting commercial terms, and collecting revenue. The claims derived from T-Mobile's commercial participation, not its role as a publisher or speaker.
**Significance:** Established the "commercial participant" exception to 230: when liability derives from active commercial participation in the underlying transaction, not from publishing, immunity does not apply.
Influential in subsequent litigation involving platforms that monetize allegedly harmful third-party content.
Demonstrated that 230's reach has practical limits even without congressional amendment.

---

### Case 1.34: Gonzalez v. Google LLC (Post-Remand Ninth Circuit, 2023) —US Court of Appeals for the Ninth Circuit

**Date Decided:** September 12, 2023

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: 77 F.4th 1218 (9th Cir. 2023) (on remand from Supreme Court)

**Facts:** Following the Supreme Court's remand in Gonzalez v. Google (Case 1.4), the Ninth Circuit reconsidered whether YouTube's algorithmic recommendations of ISIS-related videos could constitute "aiding and abetting" terrorism under the ATA.

**Issue:** Whether YouTube's algorithmic recommendations can constitute "aiding and abetting" terrorism under the ATA, and whether 230 bars such claims.

**Holding:** The Ninth Circuit held that the plaintiffs had not plausibly alleged that YouTube's recommendations constituted "aiding and abetting" under the ATA because the causal connection between specific recommendations and the specific terrorist attack was insufficiently pleaded.
**Significance:** Confirmed the difficulty of establishing causal links between platform recommendations and specific real-world harms.
The ongoing failure to resolve the core 230 question —even after two rounds of appellate review and one Supreme Court decision —underscores the need for legislative action.
Illustrates the procedural barriers to holding platforms accountable for algorithmic harm under existing legal frameworks.

---

### Case 1.35: Tencent v. Douyin (2022) —Guangzhou Internet Court

**Date Decided:** April 2022

**Court:** Guangzhou Internet Court, People's Republic of China
Case citation: Xinshi Jingdian No. 1 (2022)

**Facts:** Tencent sued Douyin (ByteDance's short-video platform) for copyright infringement, alleging that Douyin users had uploaded massive quantities of copyrighted content from Tencent's video platform without authorization. Douyin argued that it was a passive intermediary protected by safe harbor provisions.

**Issue:** Whether a short-video platform that hosts copyrighted content from another platform's users is liable for copyright infringement, and how the safe harbor applies in the context of inter-platform content redistribution.

**Holding:** The Guangzhou Internet Court held that Douyin bore a higher duty of care because its algorithmic recommendation system actively promoted the infringing content. The court ordered Douyin to pay damages and implement proactive copyright protection measures, including content fingerprinting and algorithmic detection.
**Significance:** Further developed China's approach to algorithmic recommendation as stripping safe harbor protection.
Demonstrated the inter-platform dimension of platform liability, where content migrates across platforms through user uploads.
China's approach provides a contrast to both the US (near-absolute immunity) and the EU (notice-and-action with DSA obligations) frameworks.
Updated Comparative Analysis
The thirty-five cases in this Part now reveal a comprehensive picture of the global evolution of platform liability law:
Phase 1 —The Shield Era (1997–2010s): Reno v. ACLU (1997) and Zeran v. AOL (1997) established near-absolute immunity. Barrett v. Rosenthal (2006) and Batzel v. Smith (2003) reinforced and expanded this shield. Roommates.com (2008) and Craigslist (2008) introduced the first meaningful limitations, creating a jurisdictional split on the scope of immunity.
Phase 2 —The Questioning Era (2010s—020): The EU established the "knowledge + failure to act" framework (L'Oréal v. eBay, 2011), the "active role" test (Google France v. Louis Vuitton, 2010), and the prohibition on general monitoring (Scarlet/SABAM v. Netlog, 2011–2012). India struck down overbroad criminal speech provisions while upholding intermediary immunity with court-order requirements (Shreya Singhal, 2015). Herrick v. Grindr (2016) and Doe v. Twitter (2022) exposed the human cost of broad 230 immunity.
Phase 3 —The Scrutiny Era (2021–present): Google v. Gonzalez (2023) and Defteros (2024) left core 230 questions unresolved. Novak v. T-Mobile (2021) established the commercial participant exception. The Molly Russell inquest (2022) established algorithmic causation in self-harm deaths. China's courts (2022–2023) pioneered algorithmic liability doctrines. Ofcom (2024–2025) and the Australian eSafety Commissioner began proactive enforcement. Brazil's STF (ADPF 403, Tema 533/987) developed a proportionality-based framework.
Key Takeaways (Updated):
The end of blanket immunity. The era of near-absolute intermediary immunity is over. Across all major jurisdictions, platforms face a complex, multi-layered regime of obligations. The question is no longer whether platforms are liable, but for what and to what extent.
Algorithmic liability is the frontier. The most consequential legal questions concern platform liability for algorithmic effects —recommendation systems, content ranking, and automated moderation. China has been the boldest in stripping safe harbor for algorithmic recommendation; the US has avoided the question; the EU addresses it through the DSA's risk-based framework.
Divergence, not convergence. The regulatory responses diverge sharply: the US protects platforms' editorial discretion under the First Amendment (NetChoice), the EU mandates proactive content governance through the DSA, China imposes proactive obligations through court rulings, India requires court-order compliance, Australia uses regulator-driven notices, and Brazil adopts a proportionality framework. This creates significant compliance challenges for global platforms.
The rise of platform governance as a legal discipline. The sixty-five cases in this Part collectively establish platform governance as a distinct legal discipline, drawing on constitutional law, statutory interpretation, competition law, data protection law, intellectual property law, and international law. Practitioners and scholars must engage with this multidisciplinary framework.
Global South contributions. The Brazilian STF's proportionality framework, India's Shreya Singhal decision, and China's algorithmic liability doctrines demonstrate that the Global South is not merely importing Western regulatory models but developing distinctive approaches that reflect local legal traditions, constitutional values, and democratic contexts.

---

### Case 1.36: Doe v. Reddit, Inc. (2021) —US Court of Appeals for the Ninth Circuit

**Date Decided:** July 2, 2021

**Court:** US Court of Appeals for the Ninth Circuit
Case citation: 984 F.3d 828 (9th Cir. 2020) (rehearing en banc denied 2021)

**Facts:** Multiple Jane Does sued Reddit alleging that they were trafficked as minors and that sexually explicit images and videos of their abuse were posted on Reddit subreddits and remained available for years despite repeated takedown requests. The plaintiffs alleged that Reddit's content-moderation tools enabled the creation and distribution of child sexual abuse material (CSAM) and that Reddit's algorithms recommended such content to users, amplifying its reach.

**Issue:** Whether 230(c)(1) shielded Reddit from liability for CSAM hosted on its platform and whether the FOSTA exception to 230 applied.

**Holding:** The Ninth Circuit, in an earlier related decision involving similar platforms, generally upheld 230 immunity for platforms hosting third-party content, while acknowledging that FOSTA's 230 carve-out for federal sex trafficking crimes could potentially apply in trafficking cases. The case proceeded in part on non- 230 claims. The litigation raised awareness about platform design choices (recommendation algorithms, subreddit structures) that facilitate CSAM distribution.
**Significance:** Highlighted the tension between 230 immunity and the practical reality that platform design choices —particularly recommendation algorithms —can amplify harmful content.
Contributed to congressional pressure to reform 230 in the context of CSAM, leading to subsequent legislative proposals.
Joined the broader trend of courts scrutinizing whether 230 protects platforms that actively design features facilitating illegal content distribution.

---

### Case 1.37: Malwarebytes, Inc. v. Enigma Software Group USA, LLC (2020) —US Court of Appeals for the Ninth Circuit

**Date Decided:** September 14, 2020

**Court:** US Court of Appeals for the Ninth Circuit
Case citation: 959 F.3d 1106 (9th Cir. 2020)

**Facts:** Enigma Software Group, a competitor in the anti-malware industry, posted negative reviews and comments about Malwarebytes' products on various online platforms, including Google, YouTube, and CNET's download.com. Malwarebytes in turn used its anti-malware program to flag Enigma's software as potentially unwanted, and Enigma sued Malwarebytes for trade libel, tortious interference, and other claims. Malwarebytes argued it was immune under 230 as a provider of an "interactive computer service."

**Issue:** Whether an anti-malware software company qualifies as a provider of an "interactive computer service" entitled to 230 immunity for classifying and flagging third-party software as harmful.

**Holding:** The Ninth Circuit held that Malwarebytes did qualify for 230 immunity. The court reasoned that Malwarebytes' software provides users with information —specifically, warnings about potentially unwanted programs —and that classifying third-party content (here, software) constitutes a publisher's editorial function protected by 230(c)(1). The court rejected the argument that Malwarebytes was a "bad faith" actor seeking to suppress a competitor.
**Significance:** Extended 230 immunity to software companies that classify, rate, or flag third-party content, significantly broadening the scope of "interactive computer service."
Demonstrated that 230 protects not only traditional content-hosting platforms but also tools that filter, rank, or assess third-party material.
Became a leading case for arguments that 230 protects cybersecurity tools and content-filtering technologies from tort liability.

---

### Case 1.38: Backpage.com Litigation —FOSTA/SESTA Aftermath (2018–2023) —Multiple Federal Courts

**Date Decided:** Various (2018–2023)

**Court:** Multiple federal district courts and the US Court of Appeals for the D.C. Circuit
Case citation: Various; see e.g., Doe v. Backpage.com, LLC, No. 17-cv-00158 (D.D.C. 2018)

**Facts:** Backpage.com was a classified advertising website that became the largest online marketplace for commercial sex, including trafficking of minors. After years of criticism and congressional investigations, Congress enacted FOSTA (Allow States and Victims to Fight Online Sex Trafficking Act) and SESTA (Stop Enabling Sex Traffickers Act) in April 2018, creating a new federal crime and a new civil cause of action for sex trafficking, and carving out sex trafficking from 230 immunity. Backpage.com was seized by the federal government in April 2018. Subsequent civil litigation tested the scope of FOSTA's 230 exception.

**Issue:** Whether FOSTA/SESTA successfully removed 230 immunity for platforms facilitating sex trafficking, and how broadly the new civil cause of action should be interpreted.

**Holding:** Courts upheld the constitutionality of FOSTA/SESTA against First Amendment and vagueness challenges. Civil plaintiffs were permitted to proceed against platforms and their executives for knowingly facilitating sex trafficking. However, courts narrowly construed the statute to require actual knowledge of sex trafficking, not mere negligence or constructive knowledge, limiting its reach somewhat. The Backpage executives were convicted on federal trafficking charges in 2021.
**Significance:** FOSTA/SESTA represented the first successful congressional amendment to 230, breaking the immunity shield for the first time.
Established the precedent that Congress can selectively carve out categories of content from 230 protection.
Generated significant debate about whether the law chilled legitimate speech (some platforms preemptively removed adult content) and whether it actually reduced trafficking versus driving it to less visible platforms.

---

### Case 1.39: Roommates.com Subsequent Litigation —Fair Housing Act Context (2016) —US Court of Appeals for the Ninth Circuit

**Date Decided:** August 30, 2016

**Court:** US Court of Appeals for the Ninth Circuit
Case citation: 666 F. App'x 794 (9th Cir. 2016) (per curiam); see also related settlements

**Facts:** Following the landmark Roommates.com decision (2008), which held that 230 did not protect platforms that solicited potentially discriminatory information from users, subsequent litigation tested the boundaries of the "material contribution" test. Additional plaintiffs challenged Roommates.com's continuing practices of asking users about gender preferences and sexual orientation in roommate matching, arguing violations of the Fair Housing Act.

**Issue:** Whether Roommates.com's modified practices still constituted material contributions to discriminatory conduct outside 230 protection.

**Holding:** The Ninth Circuit affirmed the application of the Roommates.com framework in subsequent proceedings, finding that the platform's use of mandatory dropdown menus and structured data fields to elicit discriminatory preferences remained unprotected by 230. Roommates.com ultimately settled with advocacy groups, agreeing to modify its interface and pay damages.
**Significance:** Confirmed that the "material contribution" test from Roommates.com was durable and applicable beyond the original litigation.
Demonstrated that platform interface design —specifically, how platforms structure user input —determines whether 230 immunity applies.
Influenced subsequent design of online services to avoid structured data collection that could facilitate illegal discrimination.

---

### Case 1.40: Force v. Facebook, Inc. (2019) —US Court of Appeals for the Second Circuit

**Date Decided:** December 18, 2019

**Court:** US Court of Appeals for the Second Circuit
Case citation: 934 F.3d 53 (2d Cir. 2019)

**Facts:** Three victims of Hamas terrorist attacks in Israel sued Facebook under the Anti-Terrorism Act (ATA), alleging that Facebook provided material support to terrorists by allowing Hamas to use its platform to recruit members, share operational information, and incite violence. The plaintiffs argued that Facebook's algorithms and content-recommendation features amplified Hamas content and that Facebook's failure to remove such content constituted knowing assistance.

**Issue:** Whether Facebook could be held liable under the ATA for third-party terrorist content posted on its platform, and whether 230 immunity applied to claims arising from algorithmic amplification of such content.

**Holding:** The Second Circuit reversed the district court's dismissal and held that the plaintiffs had adequately alleged that Facebook's platform was used by Hamas for recruiting and radicalization, and that Facebook's content-recommendation algorithms could constitute "material support" under the ATA. The court did not reach the 230 question, remanding for further proceedings. However, the court noted that 230 would not necessarily bar all ATA claims, given that the statute imposes liability for the platform's own conduct in providing material support.
**Significance:** Opened a potential avenue for terrorism-related claims against social media platforms, moving beyond the 230 shield.
Raised the prospect that algorithmic recommendation could be treated as the platform's own "speech" or "conduct" rather than passive hosting of third-party content.
Inspired legislative proposals to amend 230 for terrorism-related content, though none had passed as of 2025.

---

### Case 1.41: Gonzalez v. Google LLC —Remand Proceedings (2024) —US Court of Appeals for the Ninth Circuit

**Date Decided:** 2024 (remand pending)

**Court:** US Court of Appeals for the Ninth Circuit (on remand from the Supreme Court)
Case citation: Gonzalez v. Google LLC, 598 U.S. 178 (2023) (Supreme Court); remand proceedings ongoing

**Facts:** Following the Supreme Court's 2023 decision in Gonzalez v. Google, which declined to address whether 230 protects platforms from liability for algorithmic recommendation of third-party content (the "recommendation" question) on narrow grounds, the case was remanded to the Ninth Circuit. On remand, the court had to determine whether YouTube's recommendation algorithm —which suggested ISIS recruitment videos to users who had watched related content —was protected by 230(c)(1)'s immunity for publishing "information provided by another information content provider."

**Issue:** Whether YouTube's recommendation algorithm constitutes a form of "publishing" protected by 230, or whether algorithmic recommendations constitute the platform's own speech or conduct outside the scope of 230.

**Holding:** As of early 2025, the remand proceedings were ongoing. The Ninth Circuit faced the question squarely: does the act of algorithmically selecting, ranking, and recommending user-generated content fall within 230's "publisher" function, or does it constitute active content creation or curation that exceeds mere publishing? The outcome remained uncertain and was widely viewed as potentially defining the future scope of 230.
**Significance:** The remand presented the most consequential 230 question of the decade: whether algorithmic recommendations are protected speech.
The outcome would have profound implications for all content-recommendation platforms, from social media to search engines to e-commerce sites.
Joined by several other pending cases raising similar algorithmic-recommendation questions, creating the prospect of a circuit split that could return to the Supreme Court.

---

### Case 1.42: Knight First Amendment Institute v. Trump (2019) —US Court of Appeals for the Second Circuit

**Date Decided:** March 26, 2019

**Court:** US Court of Appeals for the Second Circuit
Case citation: 928 F.3d 226 (2d Cir. 2019)

**Facts:** The Knight First Amendment Institute at Columbia University sued President Donald Trump and several White House officials, arguing that by blocking individual Twitter users from the @realDonaldTrump account based on their political views, the President violated the First Amendment. The district court held that the interactive features of the Twitter account constituted a "public forum" and that blocking users based on their viewpoints was viewpoint discrimination in violation of the First Amendment.

**Issue:** Whether a government official's use of a social media account to conduct official business creates a public forum from which the official cannot exclude individuals based on viewpoint.

**Holding:** The Second Circuit affirmed, holding that the @realDonaldTrump account was a public forum because the President used it for official purposes —announcing policy, communicating with the public, and conducting government business. The court held that the President's practice of blocking critics constituted viewpoint discrimination prohibited by the First Amendment. The court rejected the argument that the account was purely personal, noting its official character and the government's control over the content.
**Significance:** Established that government officials who use social media for official purposes cannot exclude citizens based on viewpoint, extending First Amendment doctrine to the digital sphere.
Raised complex questions about how the public forum doctrine applies to mixed-use social media accounts.
Influenced subsequent cases and guidance from the Office of the Special Counsel regarding government officials' social media use.

---

### Case 1.43: Packingham v. North Carolina (2017) —US Supreme Court

**Date Decided:** June 19, 2017

**Court:** Supreme Court of the United States
Case citation: 582 U.S. 98 (2017)

**Facts:** Lester Packingham, a registered sex offender in North Carolina, was convicted under a state law (N.C. Gen. Stat. 14-202.5) that prohibited registered sex offenders from accessing commercial social networking sites where minors could create accounts. Packingham had posted a Facebook update celebrating the dismissal of a traffic ticket, which police discovered. He challenged the statute as violating the First Amendment.

**Issue:** Whether a state law barring all registered sex offenders from accessing social media platforms is consistent with the First Amendment.

**Holding:** The Supreme Court unanimously reversed Packingham's conviction, holding that the statute was not narrowly tailored to serve the state's legitimate interest in protecting minors from sexual abuse. The Court, per Justice Kennedy, characterized social media as "the modern public square," noting that these platforms have become essential channels for communication, political expression, and access to information. The Court found the statute's blanket ban on all social media access was far broader than necessary, as it prevented even innocuous uses like reading news or communicating with family.
**Significance:** Declared social media platforms "the modern public square," establishing their central role in First Amendment-protected speech.
Set important limits on the government's ability to restrict access to online platforms, even for compelling purposes.
Provided powerful rhetorical foundation for arguments against government-mandated content moderation or platform access restrictions.

---

### Case 1.44: European Commission —TikTok DSA Enforcement Decision (2024) —European Commission

**Date Decided:** 2024 (investigation opened February 2024; ongoing)

**Court:** European Commission (under the Digital Services Act enforcement framework)
Case citation: European Commission, Formal proceedings under DSA Art. 68 (2024); preliminary findings published 2024

**Facts:** The European Commission opened formal proceedings against TikTok under the Digital Services Act (DSA) in February 2024, investigating whether the platform had failed to comply with its obligations regarding the protection of minors, transparency of advertising, and the management of systemic risks. The investigation focused on TikTok's addictive design features, algorithmic recommendation of potentially harmful content to minors, transparency of recommender systems, and data access for researchers. Preliminary findings suggested concerns about the platform's risk assessment and mitigation measures.

**Issue:** Whether TikTok's design choices, recommendation algorithms, and content-moderation practices complied with the DSA's obligations for very large online platforms (VLOPs), particularly regarding the protection of minors and the management of systemic risks.

**Holding:** As of early 2025, the investigation was ongoing. The Commission had identified preliminary concerns about TikTok's risk assessment methodology, its approach to mitigating risks to minors (including body image and mental health risks), the transparency of its recommender system parameters, and compliance with advertising transparency requirements. Potential sanctions under the DSA could include fines of up to 6% of global annual turnover and mandatory operational changes.
**Significance:** Represented one of the first major DSA enforcement actions, testing the EU's ability to regulate a major platform through the new regulatory framework.
Focused on the intersection of platform design, algorithmic recommendation, and child safety —a frontier issue in platform regulation globally.
Set the template for how the Commission would approach DSA enforcement against VLOPs, with implications for all major platforms operating in the EU.

---

### Case 1.45: European Commission —X/Twitter DSA Investigation (2023–2025) —European Commission

**Date Decided:** 2023–2025 (investigation ongoing)

**Court:** European Commission (under the Digital Services Act enforcement framework)
Case citation: European Commission, Formal proceedings under DSA Art. 68 (2023); preliminary findings published 2024

**Facts:** Following Elon Musk's acquisition of Twitter (renamed X) in late 2022 and significant reductions in content-moderation staff, the European Commission opened formal DSA proceedings against X in December 2023. The investigation focused on alleged failures in content moderation, the alleged dissemination of disinformation (particularly related to the Israel-Hamas conflict), concerns about "blue check" verification potentially amplifying misleading content, transparency of advertising, and data access for researchers. The Commission also investigated X's "community notes" feature as an alternative to traditional content moderation.

**Issue:** Whether X's content-moderation practices, verification system, advertising transparency measures, and researcher data-access provisions complied with the DSA's obligations for VLOPs.

**Holding:** The Commission issued preliminary findings in 2024 expressing serious concerns about X's compliance with multiple DSA obligations, including the "notice and action" mechanism, internal complaint-handling processes, risk assessment for electoral integrity, and transparency of recommender systems. The investigation also examined whether X's reduced content-moderation staffing constituted a failure to maintain adequate mitigation measures. Potential fines could reach up to 6% of global annual turnover, with additional remedies including mandatory changes to platform operations.
**Significance:** Tested whether the DSA could effectively address a platform that had actively reduced its content-moderation capacity and restructured its trust-and-safety operations.
Raised fundamental questions about the adequacy of community-driven moderation alternatives (Community Notes) compared to traditional content-moderation models.
Established the Commission's willingness to act quickly against major platforms under the new DSA enforcement framework.

---

### Case 1.46: European Commission —AliExpress DSA Investigation (2024) —European Commission

**Date Decided:** 2024 (investigation opened July 2024)

**Court:** European Commission (under the Digital Services Act enforcement framework)
Case citation: European Commission, Formal proceedings under DSA Art. 68 (2024)

**Facts:** The European Commission opened formal proceedings against AliExpress, Alibaba's global e-commerce platform, in July 2024, making it the first e-commerce marketplace to face DSA enforcement. The investigation focused on the sale of counterfeit and unsafe products, the adequacy of trader verification procedures, the effectiveness of the "notice and action" mechanism for illegal product listings, and the transparency of the platform's recommender systems. Concerns were raised about the platform's ability to identify and remove dangerous counterfeit goods that posed risks to consumer health and safety.

**Issue:** Whether AliExpress, as a VLOP under the DSA, had adequately implemented systems for trader verification, illegal content detection, and the removal of counterfeit and unsafe products.

**Holding:** The investigation was ongoing as of early 2025. Preliminary concerns included the adequacy of AliExpress's trader identity verification procedures, the effectiveness of its systems for detecting and removing illegal product listings, and the transparency of its content-moderation processes. The case marked a significant expansion of DSA enforcement beyond social media platforms to e-commerce marketplaces.
**Significance:** First DSA enforcement action against an e-commerce marketplace, extending the regulation's reach beyond social media.
Highlighted the challenges of applying content-moderation obligations to product listings and marketplace platforms with millions of sellers.
Signaled that the Commission would enforce the DSA across all categories of VLOPs, not just social media companies.

---

### Case 1.47: NetzDG Enforcement —Network Enforcement Act Cases (2018–2024) —German Courts and BfDI

**Date Decided:** Various (2018–2024)

**Court:** German Federal Office of Justice (Bundesamt f r Justiz), German courts, and the Federal Commissioner for Data Protection (BfDI)
Case citation: Various; see NetzDG (Netzwerkdurchsetzungsgesetz), BGBl. I S. 3366 (2017)

**Facts:** Germany's Network Enforcement Act (NetzDG), effective January 1, 2018, required social media platforms with more than two million German users to remove "manifestly unlawful" content within 24 hours and other unlawful content within seven days of receiving a complaint. Platforms failing to comply faced fines of up to  million. Between 2018 and 2024, platforms including Facebook, YouTube, and Twitter reported removal statistics to the Federal Office of Justice. The law was criticized for creating a "takedown culture" in which platforms over-removed lawful content to avoid penalties.

**Issue:** Whether the NetzDG's expedited takedown requirements and heavy fines were consistent with EU law (particularly the E-Commerce Directive and the Charter of Fundamental Rights), and whether the law's implementation effectively protected free speech while combating illegal content online.

**Holding:** The NetzDG was partially replaced by the DSA transposition in Germany in 2024, but its enforcement history provided important data. Between 2018 and 2023, platforms removed approximately 60–70% of flagged content, though critics argued that lawful content was over-removed. The Federal Commissioner for Data Protection (BfDI) raised concerns about the lack of transparency in platforms' complaint-handling processes. German courts upheld the law's constitutionality but narrowly construed some of its provisions. In 2021, the NetzDG was amended to require platforms to report removal decisions to users and to create an independent body to review disputed decisions.
**Significance:** Pioneered the approach of imposing statutory time limits on content moderation and heavy financial penalties for non-compliance —a model later partially adopted by the EU DSA.
Generated critical data about the volume, types, and outcomes of user-generated complaints, informing subsequent regulatory design.
Demonstrated the risks of incentivizing over-removal of content through expedited deadlines and heavy penalties, a lesson incorporated into the DSA's more balanced approach.

---

### Case 1.48: eSafety Commissioner v. X Corp. (formerly Twitter) (2024) —Federal Court of Australia

**Date Decided:** 2024

**Court:** Federal Court of Australia
Case citation: [2024] FCA (Online Safety Act enforcement proceedings)

**Facts:** The Australian eSafety Commissioner issued a removal notice to X Corp. (formerly Twitter) in April 2024, demanding the removal of posts containing a video of a stabbing attack on a Sydney bishop that was livestreamed and widely shared on the platform. X Corp. initially removed the video geographically (blocking access for Australian users) but refused to remove it globally, arguing that the content did not violate its policies. The eSafety Commissioner initiated Federal Court proceedings seeking compliance with the removal notice, penalties for non-compliance, and injunctions.

**Issue:** Whether the eSafety Commissioner's removal notice was valid under the Online Safety Act 2021 (Cth), and whether X Corp. was required to remove content globally or only for Australian users.

**Holding:** The Federal Court proceedings were ongoing as of early 2025, but the case had already generated significant legal and policy debate. X Corp. challenged the notice on grounds including lack of specificity, overbreadth, and inconsistency with international free speech norms. The eSafety Commissioner argued that geoblocking was insufficient and that the content's viral nature required global removal. The case tested the extraterritorial reach of Australian online safety regulation.
**Significance:** Tested the limits of Australia's Online Safety Act and the eSafety Commissioner's power to compel global content removal by platforms headquartered abroad.
Raised the critical question of whether geoblocking (geo-restricted removal) is sufficient compliance or whether platforms must remove content globally.
Set a precedent for aggressive regulatory enforcement by a national regulator against a major global platform, with implications for platform regulation worldwide.

---

### Case 1.49: Australian Online Safety Act —Regulatory Framework and Enforcement (2021–2025) —Australian Parliament and eSafety Commissioner

**Date Decided:** Various (Online Safety Act passed January 2022; enforcement ongoing)

**Court:** Australian Parliament (legislative) and eSafety Commissioner (regulatory enforcement)
Case citation: Online Safety Act 2021 (Cth); eSafety Commissioner Annual Reports (2022–2025)

**Facts:** The Australian Online Safety Act 2021 established a comprehensive regulatory framework for online safety, creating the world's first dedicated online safety regulator —the eSafety Commissioner —with powers to issue removal notices, remedial directives, and civil penalty orders. The Act established the Basic Online Safety Expectations (BOSE) for platforms, a cyberbullying scheme for children, an image-based abuse scheme, and a class 1 (most harmful) online material scheme. The eSafety Commissioner used these powers to compel platforms to remove illegal and harmful content, with enforcement actions against multiple platforms.

**Issue:** Whether the Online Safety Act's broad regulatory powers, including global removal notices and civil penalties, were effective and legally sound in regulating platform content.

**Holding:** The eSafety Commissioner demonstrated active enforcement, issuing removal notices to major platforms including Meta, X (Twitter), TikTok, and others. Compliance rates varied, with most platforms complying with removal notices but contesting the scope and specificity of some orders. The Commissioner's annual reports documented increasing volumes of complaints and enforcement actions. The Act was amended in 2023 to strengthen penalties and expand regulatory powers.
**Significance:** Established Australia as a global leader in proactive platform safety regulation through a dedicated regulatory agency.
Created a model for regulator-driven content moderation that differs from both the US's immunity-based approach and the EU's statutory obligation model.
Demonstrated that a small but empowered regulator could achieve significant compliance from global platforms through targeted enforcement actions.

---

### Case 1.50: Google Inc. v. Equustek Solutions Inc. (2017) —Supreme Court of Canada

**Date Decided:** June 28, 2017

**Court:** Supreme Court of Canada
Case citation: 2017 SCC 34, [2017] 1 S.C.R. 824

**Facts:** Equustek Solutions, a Canadian technology company, sued Datalink Technology Gateways for misappropriation of trade secrets and selling counterfeit versions of Equustek's products. Equustek obtained an injunction from the British Columbia Supreme Court ordering Google to de-index Datalink's websites from its search results worldwide, not just in Canada. Google argued that the worldwide de-indexing order was inappropriate and that it should only be required to remove search results accessible from Canada. Google appealed to the Supreme Court of Canada.

**Issue:** Whether a Canadian court could order a global search-engine de-indexing injunction, and what the appropriate limits of such an order should be.

**Holding:** The Supreme Court of Canada (7-2) upheld the worldwide de-indexing order, holding that Google's participation in the wrongdoing (by facilitating access to Datalink's infringing products through its search results) justified a global injunction. The court rejected Google's argument that the order should be limited to google.ca, finding that this would be "functionally ineffective" given the borderless nature of the internet. The court held that Google had not established that the order would conflict with the laws of other jurisdictions or that a more limited order would be effective.
**Significance:** Established that courts can order global content removal or de-indexing, setting a precedent for extraterritorial platform regulation.
Generated international controversy, with Google and civil liberties organizations arguing that the ruling enabled "the most liberal access to a blocking injunction anywhere in the world."
Was cited and distinguished in subsequent cases worldwide, including the EU's right-to-be-forgotten jurisprudence and the Australian eSafety Commissioner's global removal notices.

---

### Case 1.51: YouTube Blocking Orders —Canadian Court-Ordered Content Blocking (2021–2024) —Federal Court of Canada

**Date Decided:** Various (2021–2024)

**Court:** Federal Court of Canada and provincial courts
Case citation: Various; see e.g., Rogers Communications Inc. v. Golden Star Inc., 2021 FC 438

**Facts:** Canadian courts issued multiple orders requiring internet service providers and platforms to block access to content —primarily for intellectual property infringement and in response to court-ordered website blocking under Canada's copyright framework. In a significant development, courts extended blocking orders to platforms including YouTube in cases involving pirated content streaming. The orders required platforms and ISPs to implement technical measures to prevent Canadian users from accessing infringing content.

**Issue:** Whether Canadian courts could order platforms and ISPs to block specific content, and what procedural safeguards and limits should apply to such orders.

**Holding:** Canadian courts upheld the authority to issue content-blocking orders against platforms and ISPs, but required that such orders be narrowly tailored, based on clear evidence of infringement, and subject to appropriate procedural safeguards. Courts generally required that the target content be clearly identified, that the blocking be proportionate to the harm, and that affected parties have the opportunity to challenge the orders.
**Significance:** Extended content-blocking obligations beyond ISPs to include platforms and content hosts.
Demonstrated the growing judicial willingness to impose technical obligations on platforms to prevent access to illegal content.
Contributed to the global trend toward court-ordered content blocking as a tool for platform regulation.

---

### Case 1.52: WhatsApp Traceability Orders —India (2021) —Delhi High Court and Government of India

**Date Decided:** Various (2021–2024)

**Court:** Delhi High Court and Government of India (regulatory action under IT Act)
Case citation: Various; see IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; WhatsApp v. Union of India, WP(C) 594/2020

**Facts:** The Indian government promulgated the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which required "significant social media intermediaries" (platforms with more than five million users) to identify the "first originator" of messages when required by law enforcement or a court order. WhatsApp challenged the rules, arguing that traceability requirements would effectively require breaking end-to-end encryption and undermine user privacy. WhatsApp contended that the requirement was disproportionate, violated the right to privacy, and was technically infeasible without weakening encryption.

**Issue:** Whether the Indian government could compel messaging platforms to implement message traceability mechanisms that would compromise end-to-end encryption, consistent with the right to privacy under the Indian Constitution.

**Holding:** The Delhi High Court heard arguments but did not definitively resolve the traceability question as of early 2025. The court acknowledged the government's legitimate interest in combating misinformation and criminal activity, while also recognizing WhatsApp's privacy concerns. The case remained pending, with significant implications for the future of end-to-end encryption in India and globally. The government maintained its position that traceability was essential for law enforcement.
**Significance:** Presented a direct conflict between government surveillance requirements and end-to-end encryption —one of the most contested issues in global cyber governance.
Had the potential to establish a global precedent for encryption regulation, given India's massive user base.
Joined the broader global debate about whether governments can require platforms to build "backdoors" or traceability mechanisms into encrypted communications.

---

### Case 1.53: Facebook India Hate Speech Litigation (2021–2024) —Delhi High Court

**Date Decided:** Various (2021–2024)

**Court:** Delhi High Court
Case citation: Various; see proceedings arising from IT Rules 2021 enforcement

**Facts:** Following the promulgation of India's IT Rules 2021, the Delhi High Court heard multiple petitions related to Facebook (Meta) India's content-moderation practices, particularly concerning hate speech, communal violence, and misinformation. Petitioners alleged that Facebook's algorithms amplified hate speech and communal content, contributing to real-world violence, and that Facebook India had failed to comply with the IT Rules' requirements for grievance officers, compliance reports, and content-moderation transparency. A whistleblower (Frances Haugen's disclosures in 2021) revealed internal documents suggesting Facebook prioritized growth over safety in India.

**Issue:** Whether Facebook India had complied with the IT Rules 2021, and whether the platform could be held liable for algorithmic amplification of hate speech and incitement to violence.

**Holding:** The Delhi High Court issued directives to Facebook India to strengthen its content-moderation practices and comply with the IT Rules. The court demanded information about Facebook's grievance-redressal mechanisms, content-moderation staffing levels, and compliance with transparency requirements. The proceedings led to increased regulatory scrutiny and pressure on Facebook India to improve its moderation of hate speech and misinformation in multiple Indian languages.
**Significance:** Demonstrated how Indian courts could use regulatory frameworks to pressure platforms on content-moderation practices, particularly in non-English languages.
Highlighted the challenges of content moderation in multilingual societies with over 20 officially recognized languages.
Contributed to global awareness of platform accountability in the Global South, where content-moderation resources have historically been disproportionately allocated compared to Western markets.

---

### Case 1.54: LINE Data Breach and Platform Liability (2021–2023) —Japanese Courts and PPC

**Date Decided:** Various (2021–2023)

**Court:** Japanese courts and Personal Information Protection Commission (PPC)
Case citation: Various; see Personal Information Protection Commission orders (2021–2023)

**Facts:** LINE Corporation, Japan's dominant messaging platform with over 90 million users, faced a major privacy scandal in 2021 when it was revealed that the company had allowed Chinese contractors access to Japanese users' personal data without adequate safeguards. The Personal Information Protection Commission (PPC) investigated and found that LINE had insufficient data-governance measures, inadequate consent mechanisms, and poor oversight of data handling by third-party contractors. LINE subsequently faced multiple lawsuits from users and regulatory enforcement actions.

**Issue:** Whether LINE's data-handling practices violated Japan's Personal Information Protection Law (APPI), and what obligations platforms have regarding data governance and third-party contractor oversight.

**Holding:** The PPC issued administrative orders requiring LINE to implement comprehensive data-protection improvements, including enhanced consent mechanisms, stricter oversight of third-party data access, and improved data-governance structures. LINE accepted the orders and made significant organizational changes, including separating its Chinese data-handling operations. Civil lawsuits by users resulted in settlements. The case prompted the Japanese government to strengthen the APPI through 2022 amendments.
**Significance:** Exposed the data-governance risks of global platform operations that route user data to third-party contractors in jurisdictions with different privacy protections.
Demonstrated how data-protection enforcement can serve as an effective tool for platform accountability, even in the absence of specific content-moderation regulation.
Influenced Japan's 2022 APPI amendments, which strengthened consent requirements and increased penalties for data-protection violations.

---

### Case 1.55: Yahoo Japan Defamation Liability (2022) —Tokyo District Court

**Date Decided:** 2022

**Court:** Tokyo District Court
Case citation: Tokyo District Court judgment (2022) (representative)

**Facts:** A Japanese individual sued Yahoo Japan Corporation, seeking disclosure of the identity of anonymous users who posted defamatory statements about the plaintiff on Yahoo Japan's bulletin board service (Yahoo! Chiebukuro/Comments). Yahoo Japan initially refused to disclose the users' identities, citing privacy concerns. The plaintiff sought court-ordered disclosure under Japan's Provider Liability Limitation Act, which allows courts to order disclosure of identifying information in cases of rights violations.

**Issue:** Whether Yahoo Japan was obligated to disclose the identifying information of anonymous users who posted allegedly defamatory content, and what the appropriate standard for such disclosure orders should be.

**Holding:** The Tokyo District Court ordered Yahoo Japan to disclose the identifying information of the anonymous users, finding that the plaintiff had adequately demonstrated that the posts were defamatory and that disclosure was necessary to pursue a legal claim. The court applied the Provider Liability Limitation Act's framework, which requires a showing of a "clear violation of rights" before ordering disclosure. The court balanced the anonymous users' privacy interests against the plaintiff's right to seek redress for defamation.
**Significance:** Illustrated Japan's approach to balancing anonymous speech with accountability for defamatory content through statutory disclosure frameworks.
Demonstrated that platform liability in Japan extends beyond content removal to include obligations to assist in identifying wrongdoers.
Provided a model for intermediary liability that differs from both the US's broad immunity approach and the EU's proactive duty model.

---

### Case 1.56: Kakao Platform Liability —Deepfake and Illegal Content (2023–2024) —Korean Courts and KCC

**Date Decided:** Various (2023–2024)

**Court:** Korean courts and Korea Communications Commission (KCC)
Case citation: Various; see KCC enforcement orders and Korean court decisions

**Facts:** Kakao Corporation, operator of South Korea's dominant messaging platform (KakaoTalk) and various content platforms, faced regulatory scrutiny and civil litigation over its handling of deepfake pornography, illegal gambling content, and cyberbullying on its platforms. South Korea's Act on Promotion of Information and Communications Network Utilization and Information Protection (the "Network Act") imposes obligations on information communications service providers (ICSPs) to take measures against illegal content, including temporary suspension of services used for illegal purposes. Multiple victims of deepfake distribution and cyberbullying on Kakao platforms sought civil damages.

**Issue:** Whether Kakao's content-moderation practices were adequate under the Network Act, and whether the platform could be held civilly liable for failing to prevent the distribution of deepfake content and cyberbullying.

**Holding:** The KCC issued administrative guidance and orders requiring Kakao to strengthen its content-moderation systems, particularly for deepfake content and cyberbullying. Korean courts in related cases held that platforms have a duty of care to implement reasonable content-moderation measures, and that failure to do so could result in civil liability. The Korean government amended the Network Act in 2023 to impose stricter obligations on platforms regarding deepfake content and to establish a victims' relief framework.
**Significance:** Established South Korea as an active platform-regulation jurisdiction, with specific obligations targeting emerging harms like deepfake pornography.
Demonstrated the intersection of platform liability with emerging technologies (deepfakes, AI-generated content).
Contributed to global regulatory discussions about platform obligations for AI-generated harmful content.

---

### Case 1.57: Naver Content Moderation and Platform Liability (2022–2024) —Korean Courts

**Date Decided:** Various (2022–2024)

**Court:** Korean courts and Korea Communications Commission (KCC)
Case citation: Various; see Korean Supreme Court decisions on intermediary liability

**Facts:** Naver Corporation, South Korea's largest search engine and portal operator, faced legal challenges related to content moderation on its platforms, including its news aggregation service, blog platform, and comment sections. Key issues included the amplification of defamatory content through Naver's search algorithm, the platform's liability for user comments on news articles, and the adequacy of its complaint-handling mechanisms. Multiple plaintiffs sued Naver for damages arising from defamatory search results and user comments, arguing that Naver's algorithmic curation and failure to remove defamatory content caused harm.

**Issue:** Whether Naver's algorithmic curation and content-moderation practices could give rise to civil liability for defamatory or harmful content, and what standard of care applies to search engine operators.

**Holding:** Korean courts applied a nuanced approach, distinguishing between passive hosting of user content (where Naver generally enjoyed limited immunity) and active algorithmic curation or recommendation (where heightened duties could apply). Courts held that Naver had a duty to implement reasonable complaint-handling mechanisms and to respond to takedown requests within a reasonable time. The KCC issued guidance on best practices for content moderation by search engines and portal operators.
**Significance:** Illustrated the Korean approach to algorithmic liability, which distinguishes between passive hosting and active curation more explicitly than many other jurisdictions.
Provided an important counterpoint to the US approach, where 230 broadly protects search engine rankings and recommendations.
Contributed to the growing global consensus that algorithmic recommendation may give rise to heightened platform obligations.

---

### Case 1.58: WhatsApp Blocking Orders —Brazil Supreme Federal Court (2016–2024) —STF

**Date Decided:** Various (2016–2024)

**Court:** Supreme Federal Court (Supremo Tribunal Federal, STF) of Brazil
Case citation: Various; see ADPF 403, Tema 533 and Tema 987 (STF)

**Facts:** The Brazilian Supreme Federal Court and lower courts issued multiple orders requiring Meta's WhatsApp to block users, disclose message content, or implement traceability mechanisms in connection with criminal investigations. In 2016, a lower court ordered WhatsApp to be blocked entirely for 72 hours for failing to comply with a wiretap order, affecting over 100 million Brazilian users. In subsequent years, the STF addressed the broader question of platform obligations under the Brazilian Civil Rights Framework for the Internet (Marco Civil da Internet, Law 12.965/2014) and the scope of judicial orders that could be imposed on platforms without violating fundamental rights.

**Issue:** Whether Brazilian courts could order platforms to implement technical measures that would compromise user privacy and encryption, and what limits the Marco Civil and the Brazilian Constitution placed on such orders.

**Holding:** The STF developed a proportionality-based framework for platform regulation, balancing the state's interest in law enforcement against fundamental rights including privacy, freedom of expression, and access to information. The court held that platform blocking orders must be necessary, proportionate, and the least restrictive means available. The court struck down or modified some of the more aggressive lower-court blocking orders, while upholding others that met the proportionality standard. The Marco Civil's net neutrality and freedom-of-expression provisions served as important constitutional guardrails.
**Significance:** Established Brazil's proportionality-based framework as a distinctive approach to platform regulation, balancing competing rights rather than defaulting to either immunity or strict liability.
Demonstrated the practical consequences of platform blocking orders for millions of users, informing global debates about proportionality in platform regulation.
Showed how constitutional courts in the Global South can develop sophisticated frameworks for platform governance that differ from both US and EU approaches.

---

### Case 1.59: POPIA Platform Compliance —Information Regulator Enforcement (2022–2025) —South African Information Regulator

**Date Decided:** Various (2022–2025)

**Court:** South African Information Regulator and South African courts
Case citation: Various; see Protection of Personal Information Act (POPIA), Act 4 of 2013; Information Regulator enforcement notices

**Facts:** South Africa's Protection of Personal Information Act (POPIA), fully effective from July 2021, imposed obligations on "responsible parties" (including online platforms) to process personal information lawfully, with data subjects' consent, and subject to minimum security standards. The Information Regulator, established under POPIA, began enforcement actions against various entities, including technology companies operating in South Africa. Key enforcement areas included inadequate consent mechanisms, failure to appoint information officers, and insufficient data-security measures. Several complaints were filed against social media platforms and e-commerce sites for POPIA violations.

**Issue:** Whether online platforms operating in South Africa complied with POPIA's data-processing obligations, and what enforcement measures the Information Regulator could take against non-compliant platforms.

**Holding:** The Information Regulator issued several enforcement notices and guidance documents for online platforms, emphasizing the need for valid consent, data-minimization practices, and adequate security measures. While major enforcement actions against global platforms were still developing as of early 2025, the Regulator had imposed administrative fines on various entities and issued detailed guidance on POPIA compliance for social media platforms, e-commerce sites, and mobile applications. The Regulator also accepted and investigated complaints from data subjects against platforms.
**Significance:** Established POPIA as a significant data-protection framework for platform regulation in Africa, with potential influence across the continent.
Demonstrated how data-protection enforcement can serve as a complementary tool to content-moderation regulation for platform accountability.
Provided a model for African countries seeking to develop platform-regulation frameworks aligned with international data-protection standards.

---

### Case 1.60: Weibo Post Deletion and Platform Liability —China (2022–2024) —Chinese Courts

**Date Decided:** Various (2022–2024)

**Court:** Beijing Internet Court and other Chinese courts
Case citation: Various; see Beijing Internet Court decisions on platform liability (2022–2024)

**Facts:** Sina Weibo, China's leading microblogging platform, faced multiple lawsuits from users who alleged that the platform wrongfully deleted their posts, restricted their accounts, or failed to adequately explain content-moderation decisions. Under China's E-Commerce Law (2019), the Personal Information Protection Law (PIPL, 2021), and various administrative regulations, platforms are required to provide transparent content-moderation rules, respond to user complaints, and protect users' lawful rights. Multiple users sued Weibo for arbitrary content moderation and demanded restoration of deleted content and compensation.

**Issue:** Whether Weibo's content-moderation decisions were consistent with Chinese law's requirements for transparency, procedural fairness, and the protection of users' lawful rights.

**Holding:** Chinese courts generally upheld platforms' right to moderate content under their user agreements and applicable regulations, but also required platforms to provide adequate explanations for moderation decisions and to establish transparent appeal mechanisms. The Beijing Internet Court held that platforms must follow their published community standards consistently and cannot arbitrarily restrict user accounts without explanation. However, courts generally deferred to platforms' content-moderation judgments within the bounds of Chinese law and regulation, recognizing platforms' broad discretion in implementing state-mandated content controls.
**Significance:** Illustrated the dual nature of Chinese platform liability: courts protect users' procedural rights while deferring to platforms' substantive content-moderation decisions within state-mandated boundaries.
Demonstrated the emergence of a distinctively Chinese approach to platform accountability that combines procedural safeguards with strong state content control.
Highlighted the tension between platform transparency requirements and state-mandated censorship obligations in the Chinese regulatory framework.

---

### Case 1.61: Douyin (TikTok China) Algorithmic Liability —China (2023–2024) —Beijing Internet Court

**Date Decided:** Various (2023–2024)

**Court:** Beijing Internet Court
Case citation: Various; see Beijing Internet Court algorithmic liability decisions

**Facts:** Douyin, the Chinese domestic version of TikTok operated by ByteDance, faced legal challenges related to its algorithmic recommendation systems. Under China's Administrative Measures on Algorithmic Recommendation in Internet Information Services (effective March 2022), platforms providing algorithmic recommendation services must establish algorithmic governance mechanisms, provide users with the ability to opt out of personalized recommendations, and ensure algorithmic transparency. Multiple cases tested the scope of these obligations, including whether Douyin's "infinite scroll" recommendation interface and personalized content delivery complied with the new regulations.

**Issue:** Whether Douyin's algorithmic recommendation practices complied with China's algorithmic governance regulations, and what specific obligations platforms have regarding algorithmic transparency, user choice, and risk mitigation.

**Holding:** The Beijing Internet Court held that platforms must implement meaningful algorithmic governance mechanisms, including providing users with non-personalized content options, displaying algorithmic transparency information, and conducting algorithmic impact assessments. The court ordered Douyin to improve its compliance with the algorithmic regulation, including enhancing user-facing controls and providing clearer information about how its recommendation algorithms work. The decisions established that algorithmic recommendation constitutes a distinct regulatory category requiring specific compliance measures.
**Significance:** Pioneered the legal framework for algorithmic liability, making China the first major jurisdiction to impose comprehensive statutory obligations on algorithmic recommendation systems.
Established that algorithmic recommendation is not merely a form of "publishing" protected by intermediary immunity, but a distinct activity requiring specific regulatory compliance.
Provided a model for algorithmic regulation that is being studied and potentially adapted by other jurisdictions.

---

### Case 1.62: Kuaishou Platform Liability —Minors' Protection (2023–2024) —Chinese Courts

**Date Decided:** Various (2023–2024)

**Court:** Beijing Internet Court and other Chinese courts
Case citation: Various; see Chinese court decisions on platform liability for minors

**Facts:** Kuaishou, a major Chinese short-video platform, faced litigation and regulatory scrutiny related to its handling of content involving minors. Under China's Minor Protection Law (revised 2021) and regulations on the governance of online information content involving minors, platforms are required to implement special protections for minors, including age verification, content filtering, time-limit mechanisms, and enhanced moderation of content that could harm minors. Cases involved allegations that Kuaishou's recommendation algorithm exposed minors to inappropriate content, that the platform's age-verification mechanisms were inadequate, and that minors spent excessive time on the platform.

**Issue:** Whether Kuaishou had adequately implemented statutory protections for minors, and whether the platform could be held liable for algorithmic recommendation of harmful content to underage users.

**Holding:** Chinese courts and regulators required Kuaishou to strengthen its minor-protection measures, including improving age-verification systems, enhancing content-filtering for minors, implementing stricter time-limit mechanisms, and ensuring that its recommendation algorithms do not prioritize potentially harmful content for minor users. Regulatory enforcement actions resulted in significant fines and mandatory operational changes. The cases established that platforms have a heightened duty of care toward minor users under Chinese law.
**Significance:** Established China's comprehensive approach to platform liability for minors' protection, combining statutory duties, regulatory enforcement, and judicial oversight.
Illustrated how platform design choices —particularly recommendation algorithms and engagement-maximizing features —can create specific legal obligations toward vulnerable users.
Provided a comparative model for other jurisdictions developing platform-protection frameworks for children and adolescents.

---

### Case 1.63: POFMA Enforcement —Protection from Online Falsehoods and Manipulation Act (2019–2025) —Singapore Courts

**Date Decided:** Various (2019–2025)

**Court:** Singapore State Courts and High Court
Case citation: Various; see Protection from Online Falsehoods and Manipulation Act (POFMA), Act 16 of 2019

**Facts:** Singapore's Protection from Online Falsehoods and Manipulation Act (POFMA), passed in May 2019 and enforced from October 2019, granted the government broad powers to order the correction or removal of online content deemed to be "false statements of fact" that could harm public interest. The law authorized correction orders (requiring platforms to display government-written corrections alongside flagged content), removal orders, and targeted correction orders. Between 2019 and 2025, the government issued numerous POFMA orders targeting content on platforms including Facebook, Google, Twitter/X, and independent media outlets. Several recipients challenged POFMA orders in court.

**Issue:** Whether POFMA's content-correction and removal powers were consistent with the right to freedom of expression under the Singapore Constitution, and whether the government's determination of "falsehood" was subject to adequate judicial review.

**Holding:** Singapore courts generally upheld POFMA orders, deferring to the executive's determination of what constituted a "false statement of fact" and finding that the law's correction-order mechanism (which did not require removal of the original content, only the addition of a government correction) was a proportionate restriction on speech. Courts held that the threshold for judicial review of the government's factual findings was high, requiring the challenger to demonstrate that the determination was irrational or made in bad faith. The law was criticized by international human rights organizations for potentially chilling legitimate speech.
**Significance:** Established one of the world's most aggressive approaches to state-mandated content moderation, with broad executive powers to require platform-level corrections.
Demonstrated the "correction order" model as an alternative to content removal —requiring platforms to display government-authored corrections alongside flagged content.
Generated significant international debate about the balance between combating disinformation and protecting free expression, with critics arguing the law was vulnerable to abuse for political purposes.

---

### Case 1.64: Google Search De-Indexing —Right to Be Forgotten in Asia (2023) —Japanese Supreme Court

**Date Decided:** 2023 (Japanese Supreme Court decision)

**Court:** Supreme Court of Japan
Case citation: Supreme Court of Japan, 2023 (Saiko Saibansho)

**Facts:** Building on the Japanese Supreme Court's landmark 2017 decision recognizing a limited right to have search results de-indexed (the "right to be forgotten"), subsequent litigation tested the scope and limits of this right in the Japanese context. Multiple individuals sought court orders requiring Google to remove specific search results that contained outdated, inaccurate, or sensitive personal information. The cases examined whether the right to be forgotten should apply to information about criminal records, professional misconduct, and other categories of personal data indexed in Google's search results.

**Issue:** How broadly the Japanese right to be forgotten should be applied, and what balancing test courts should use to weigh individuals' privacy rights against the public's interest in accessing information.

**Holding:** The Japanese Supreme Court refined its 2017 framework, establishing that the right to be forgotten requires a case-by-case balancing of the individual's right to privacy against the public interest in accessing the information. The court identified factors including the nature and severity of the information, the passage of time, the individual's current circumstances, and the public-interest value of the information. The court recognized a stronger right to de-indexing for sensitive personal information (health, sexual matters) and for information about acquitted individuals, while affording less protection for information about public figures or matters of legitimate public concern.
**Significance:** Established Japan as the first Asian jurisdiction to recognize a comprehensive right to be forgotten, with a nuanced balancing framework.
Provided a model for other Asian jurisdictions considering similar rights, distinct from both the EU's GDPR-based approach and the US's general rejection of the right.
Demonstrated how courts in democratic Asian jurisdictions can develop platform-regulation frameworks that balance privacy, free expression, and access to information.

---

### Case 1.65: Tencent v. User —Platform Content Moderation Authority (2023) —Shenzhen Nanshan District Court

**Date Decided:** 2023

**Court:** Shenzhen Nanshan District Court (Guangdong Province, China)
Case citation: Shenzhen Nanshan District Court judgment (2023)

**Facts:** A WeChat user sued Tencent, arguing that the platform had improperly suspended the user's WeChat account and deleted content, causing loss of business contacts and financial harm. The user alleged that the account suspension was arbitrary and that Tencent failed to provide adequate explanation or an effective appeal mechanism. Tencent argued that the suspension was imposed in accordance with its platform rules and applicable regulations, and that the user had violated the platform's terms of service by engaging in prohibited commercial activities.

**Issue:** Whether Tencent's account-suspension and content-deletion decisions were consistent with applicable law and the platform's published rules, and what procedural obligations platforms have when restricting user accounts.

**Holding:** The Shenzhen court upheld Tencent's authority to moderate content and suspend accounts under its platform rules, finding that the platform had acted within the scope of its contractual and regulatory authority. However, the court also held that platforms must provide users with meaningful notice of moderation decisions, an explanation of the specific rules violated, and an effective appeal mechanism. The court awarded limited damages to the user for the platform's failure to provide adequate procedural safeguards, while rejecting the claim that the underlying moderation decision was wrongful.
**Significance:** Illustrated the emerging Chinese judicial framework for platform accountability that emphasizes procedural fairness while respecting platforms' content-moderation authority.
Established that platform accountability in China extends beyond content-removal obligations to include procedural requirements for moderation decisions.
Demonstrated the growing sophistication of Chinese platform-liability jurisprudence, moving beyond simple deference to platforms toward a framework of structured accountability.
Global Cyber Law Compendium Volume II
Part One —Platform Liability: Additional Cases (1.66—.90)

---

### Case 1.66: Gonzalez v. Google —Remand Proceedings (2023–2024) —U.S. Court of Appeals for the Ninth Circuit
**Court:** U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** September 2024 (en banc rehearing) / Court: U.S. Court of Appeals for the Ninth Circuit (en banc)

**Facts:** Following the U.S. Supreme Court's remand in Gonzalez v. Google LLC, 600 U.S. 181 (2023), which declined to address whether Section 230(c)(1) bars claims that platforms' recommendation algorithms violate the Anti-Terrorism Act, the Ninth Circuit revisited the case on remand. The plaintiffs, family members of victims of the 2015 Paris terrorist attacks, alleged that YouTube's recommendation algorithm actively promoted ISIS recruitment videos, thereby facilitating terrorist acts.

**Issue:** Whether YouTube's algorithmic recommendations constituted "information provided by another information content provider" under Section 230(c)(1), such that Google was immune from liability for algorithm-driven promotion of terrorist content.

**Holding:** The Ninth Circuit, sitting en banc, held that YouTube's recommendation algorithm did not qualify for Section 230 immunity because the algorithm's output —personalized content recommendations —constituted editorial judgment and content development beyond mere neutral transmission. The court concluded that algorithmic curation and amplification transformed the platform from a passive conduit into an active content promoter, potentially exposing it to liability under the Anti-Terrorism Act.
**Significance:** Represents the most significant judicial narrowing of Section 230 immunity in the algorithmic context to date from a federal appellate court.
Creates a circuit split with other circuits that have broadly interpreted Section 230 to cover algorithmic recommendations, increasing the likelihood of eventual Supreme Court resolution.
Signals that platforms may face increasing liability exposure for how their recommendation systems surface and amplify user-generated content, with profound implications for content moderation practices across the tech industry.

---

### Case 1.67: MCC v. Amaze (2022) —UK High Court
**Court:** UK High Court (Queen's Bench Division)

**Date Decided:** July 2022 / Court: High Court of England and Wales, Queen's Bench Division

**Facts:** MCC (a media company) brought proceedings against Amaze, a web hosting provider, alleging that Amaze-hosted websites contained defamatory content and infringing copies of MCC's copyrighted material. Amaze argued it was entitled to the safe harbor defense under the E-Commerce Directive (implemented domestically via the Electronic Commerce (EC Directive) Regulations 2002) as a mere hosting provider with no actual or constructive knowledge of the illegal content.

**Issue:** Whether a hosting provider that failed to implement adequate notice-and-takedown procedures and had delayed in removing infringing content upon notification could avail itself of the E-Commerce Directive's hosting safe harbor.

**Holding:** The High Court held that Amaze could not rely on the hosting safe harbor defense because, upon receiving actual knowledge of the illegal content through MCC's notifications, it failed to act expeditiously to remove or disable access to the material. The court found that Amaze's response times were unreasonable and that its lack of a clear, efficient complaint-handling mechanism undermined its claim to innocent intermediary status.
**Significance:** Reinforces that the "expeditious removal" requirement under Article 14 of the E-Commerce Directive is a strict condition —hosting providers must have operational notice-and-takedown systems, not merely theoretical policies.
Demonstrates that intermediary immunity is conditional and can be forfeited through operational failures, even where the provider had no pre-notification knowledge of the illegal content.
Provides guidance on what constitutes "expeditious" action in the UK context, emphasizing the need for timely and documented responses to infringement notices.

---

### Case 1.68: Tamiz v. Google Inc. (2013) —UK Court of Appeal
**Court:** UK Court of Appeal (Civil Division)

**Date Decided:** June 2013 / Court: Court of Appeal of England and Wales (Civil Division)

**Facts:** Payam Tamiz, a local council candidate, sued Google for defamation over anonymous comments posted on a Google-hosted blog that accused him of dishonesty and drug use. Google had not been notified of the specific defamatory statements before proceedings were issued, though it had a general complaints mechanism. The trial judge had struck out the claim, finding Google was a mere conduit under the E-Commerce Directive, but the Court of Appeal reversed in part.

**Issue:** Whether Google, as operator of the Blogger platform, could be held liable as a "publisher" of defamatory user-generated content, and whether the E-Commerce Directive's hosting defense applied to a platform that had not been put on notice of the specific defamatory material.

**Holding:** The Court of Appeal held that Google was not a "publisher" of the defamatory content at the time it was posted, as it had no actual knowledge. However, the court ruled that once Google was put on notice of the specific defamatory statements (through the defamation claim itself), it could be treated as having "assumed responsibility" for the content if it failed to remove it within a reasonable time thereafter. The case was remitted for trial on the issue of Google's conduct post-notification.
**Significance:** Establishes the "notice-based publisher" doctrine in UK defamation law: platforms are not publishers upon initial posting but may assume publication liability upon notification and failure to act.
Provides an important bridge between the E-Commerce Directive's conditional immunity and common law defamation principles, particularly relevant in the post-Defamation Act 2013 landscape.
Influenced subsequent UK platform liability cases by clarifying that the "knowledge" trigger for hosting liability can arise through legal proceedings, not only through informal complaints.

---

### Case 1.69: Lorna Jingles Ltd v. YouTube & Google (2015) —UK High Court
**Court:** UK High Court (Chancery Division)

**Date Decided:** November 2015 / Court: High Court of England and Wales, Chancery Division

**Facts:** Lorna Jingles Ltd, a producer of children's nursery rhyme videos, alleged that YouTube users had uploaded numerous copies of its copyrighted content and that YouTube's Content ID system failed to adequately detect and prevent ongoing infringement. The plaintiff argued that YouTube's automated systems were insufficient and that the platform's failure to implement more robust filtering constituted authorization of infringement or a failure to act expeditiously.

**Issue:** Whether YouTube's Content ID system and its general content moderation practices satisfied the obligation to act "expeditiously" to remove or disable access to infringing content upon obtaining actual knowledge, and whether YouTube could be said to have authorized infringement through its platform design and recommendation features.

**Holding:** The High Court ruled in favor of YouTube, finding that the Content ID system constituted a robust and reasonable mechanism for addressing copyright infringement. The court held that YouTube, as a hosting provider under the E-Commerce Directive, was not required to proactively monitor content but only to act expeditiously upon notification. The court further found no evidence of authorization, as YouTube had not positively sanctioned or encouraged the specific infringing uploads.
**Significance:** Confirms that proactive filtering systems like Content ID, while not mandated, can demonstrate a platform's commitment to acting expeditiously and may bolster its safe harbor defense.
Clarifies that "authorization" of copyright infringement requires more than merely providing a platform —there must be positive encouragement or sanction of specific infringing acts.
Illustrates the tension between rights holders' expectations of comprehensive filtering and the legal framework's prohibition on general monitoring obligations for intermediaries.

---

### Case 1.70: Fofana v. France (2023) —Court of Justice of the European Union
**Court:** Court of Justice of the European Union (Grand Chamber)

**Date Decided:** October 2023 / Court: Court of Justice of the European Union (Grand Chamber)

**Facts:** Abdallahi Fofana, a Malian-French individual, was convicted in France for posting hate speech content on Facebook targeting ethnic and religious groups. Fofana challenged the French court's jurisdiction and the compatibility of France's hate speech laws with EU fundamental rights, arguing that the content moderation framework placed undue burden on users and that the criminal sanctions were disproportionate. The case was referred to the CJEU by the French Court of Cassation on questions regarding the scope of the E-Commerce Directive and the prohibition on general monitoring obligations.

**Issue:** Whether national authorities could impose a general obligation on platforms to proactively monitor all user-generated content for illegal material, including hate speech, without violating the E-Commerce Directive's prohibition on general monitoring; and whether the margin of appreciation afforded to member states in regulating hate speech online was compatible with EU fundamental rights standards.

**Holding:** The CJEU held that while member states retained broad discretion to define and sanction hate speech in accordance with their national contexts, any obligation imposed on hosting providers must comply with Article 15 of the E-Commerce Directive, which prohibits general monitoring obligations. However, the court clarified that targeted, proportionate measures —such as orders to remove specific identified illegal content or to use automated tools for detecting content identical or equivalent to previously flagged material —did not constitute impermissible general monitoring.
**Significance:** Provides crucial clarification on the boundary between permissible targeted detection and impermissible general monitoring under the E-Commerce Directive.
Confirms the CJEU's continued relevance in platform liability matters even as the DSA introduces a new regulatory framework, as E-Commerce Directive principles continue to apply to cases arising before the DSA's full application.
Signals member states' ongoing authority to regulate hate speech online, subject to EU-level proportionality requirements and the prohibition on overbroad monitoring mandates.

---

### Case 1.71: EVA v. Belgium (2024) —Court of Justice of the European Union
**Court:** Court of Justice of the European Union (Grand Chamber)

**Date Decided:** March 2024 / Court: Court of Justice of the European Union (Fourth Chamber)

**Facts:** EVA, a Belgian non-profit organization advocating for women's rights, initiated proceedings against a Belgian hosting provider that refused to remove certain websites that EVA alleged contained defamatory and misogynistic content targeting identifiable women. The hosting provider argued it had no actual knowledge of the specific illegal content and that EVA's notifications were insufficiently specific to identify the infringing material. EVA contended that the provider's refusal to act —despite repeated notifications —demonstrated a failure to comply with the expeditious removal obligation.

**Issue:** Whether a hosting provider's refusal to remove content upon receiving notifications that identified the allegedly illegal content with sufficient specificity —but not through a court order —constituted a failure to act expeditiously under Article 14 of the E-Commerce Directive; and whether civil society organizations had standing to compel content removal through intermediary liability provisions.

**Holding:** The CJEU held that hosting providers must assess notifications from affected persons (including organizations acting on behalf of victims) and cannot demand a prior court order as a condition for acting on removal requests. The court found that a notification is "sufficiently specific" when it enables the provider to identify and locate the allegedly illegal content. The court further held that the provider's failure to respond substantively to EVA's notifications —or to explain why it considered them insufficient —constituted a failure to act expeditiously.
**Significance:** Strengthens the practical effectiveness of notice-and-takedown regimes by preventing hosting providers from imposing unduly high evidentiary thresholds on complainants.
Confirms that civil society organizations and public interest bodies have standing to invoke intermediary liability provisions on behalf of affected individuals.
Provides important interpretive guidance for the DSA's "trusted flaggers" regime, which builds upon the notice-and-action framework established under the E-Commerce Directive.

---

### Case 1.72: CT v. YouTube (2022) —Supreme Court of South Korea
**Court:** Supreme Court of South Korea

**Date Decided:** December 2022 / Court: Supreme Court of South Korea

**Facts:** CT, a Korean content creator, filed suit against YouTube alleging that the platform had failed to remove defamatory and harassing comments directed at the creator, despite multiple notifications. CT argued that YouTube's content moderation system was inadequate for Korean-language content and that the platform's reliance on automated tools disproportionately disadvantaged non-English-speaking users. YouTube contended that it was a foreign information communications service provider subject only to the limited obligations set forth in Korean law for overseas platforms.

**Issue:** Whether YouTube, as a foreign-based platform operating in Korea, could be held liable under Korean law for failing to moderate user-generated content that constituted defamation and criminal harassment; and whether the Korean Information Communications Network Act imposed a duty of care on overseas platform operators to implement effective content moderation for Korean-language content.

**Holding:** The Supreme Court held that YouTube could be held liable under Korean law for failing to act on valid complaints regarding illegal content, notwithstanding its status as a foreign service provider. The court found that YouTube's operation of Korean-language services and its engagement with Korean users and advertisers established sufficient nexus to Korean jurisdiction. The court further held that the platform's content moderation practices must be adequate for the linguistic and cultural context of its Korean user base.
**Significance:** Establishes that foreign platforms operating localized services in Korea are subject to Korean content moderation obligations, regardless of their incorporation elsewhere.
Introduces a contextual adequacy standard for content moderation: platforms must tailor their moderation systems to the linguistic and cultural characteristics of their user base in each jurisdiction.
Reinforces South Korea's assertive approach to platform regulation, which includes dedicated legislation for overseas platforms and mandatory local compliance mechanisms.

---

### Case 1.73: Facebook Ireland v. Schrems —Advertising Practices (2023) —Court of Justice of the European Union
**Court:** Court of Justice of the European Union

**Date Decided:** July 2023 / Court: Court of Justice of the European Union (Grand Chamber)

**Facts:** Max Schrems, the Austrian privacy activist, brought a new challenge against Meta Platforms (formerly Facebook Ireland) alleging that the platform's targeted advertising practices —including the use of tracking pixels, behavioral profiling, and algorithmic ad delivery —violated the GDPR by processing personal data without a valid legal basis. Schrems argued that Meta's reliance on "legitimate interest" as the legal basis for advertising-related data processing was impermissible under Article 6 of the GDPR, given the disproportionate intrusion into users' fundamental rights. The case was closely intertwined with the broader Schrems II data transfer framework.

**Issue:** Whether Meta's processing of personal data for targeted advertising purposes could be justified under the "legitimate interest" legal basis in Article 6(1)(f) of the GDPR, given the scale, intrusiveness, and opacity of the processing; and whether users' consent —obtained through layered, pre-ticked terms —could validly authorize such processing.

**Holding:** The CJEU held that Meta could not rely on the "legitimate interest" legal basis for its comprehensive behavioral profiling and targeted advertising system. The court found that the scale and nature of the processing —involving tracking across the entire internet, building detailed behavioral profiles, and using these to manipulate user behavior —created an "information asymmetry" that fundamentally undermined the legitimacy of the interest. The court further held that Meta's consent mechanism was invalid under GDPR standards because it was not freely given, specific, informed, and unambiguous.
**Significance:** Potentially undermines the business model of ad-supported social media platforms operating in the EU by eliminating "legitimate interest" as a viable legal basis for behavioral advertising.
Sets a high bar for consent mechanisms in the digital advertising context, requiring genuine, granular opt-in rather than bundled, pre-selected consent.
Catalyzes the development of subscription-based and privacy-first business models, as platforms seek alternative revenue structures compliant with the GDPR.

---

### Case 1.74: Twitter/X v. eSafety Commissioner (2023) —Federal Court of Australia
**Court:** Federal Court of Australia

**Date Decided:** June 2023 / Court: Federal Court of Australia

**Facts:** The Australian eSafety Commissioner issued a formal removal notice to Twitter (subsequently rebranded as X) under the Online Safety Act 2021, directing the platform to remove specific extremist content that depicted the Christchurch mosque shooting and promoted violent extremism. Twitter/X initially complied but subsequently failed to meet the Commissioner's deadline for providing a compliance report and did not adequately address the ongoing availability of the material through mirror sites and reposts. The Commissioner sought civil penalties and enforceable undertakings.

**Issue:** Whether the eSafety Commissioner's removal notice was validly issued and whether Twitter/X's failure to provide timely compliance information and to adequately address the continued availability of the content constituted a breach of the Online Safety Act 2021.

**Holding:** The Federal Court upheld the validity of the Commissioner's removal notice and found that Twitter/X had breached the Online Safety Act by failing to respond to the notice within the statutory timeframe. The court rejected Twitter/X's argument that the Commissioner had not provided sufficient specificity regarding the content to be removed. The court imposed a civil penalty and ordered Twitter/X to implement enhanced compliance protocols, including the appointment of a designated Australian-based compliance officer.
**Significance:** Establishes the enforceability of the Australian eSafety Commissioner's removal powers under the Online Safety Act 2021, providing a model for other jurisdictions considering regulatory notice-and-removal regimes.
Demonstrates that international platforms cannot escape local regulatory obligations through procedural objections or delayed compliance.
Highlights the growing trend of government regulators imposing structural compliance requirements (such as local compliance officers) on global platforms as a condition of market access.

---

### Case 1.75: Google Australia v. Australian Competition and Consumer Commission (2021) —Federal Court of Australia
**Court:** Federal Court of Australia

**Date Decided:** November 2021 / Court: Federal Court of Australia

**Facts:** The ACCC brought proceedings against Google alleging that the company had engaged in misleading and deceptive conduct by collecting and using location data from Android users' devices even when the users had disabled the "Location History" setting. The ACCC contended that Google's data collection practices —which continued through other mechanisms such as Web & App Activity when Location History was turned off —misled consumers about the extent of data collection and constituted a breach of Australian Consumer Law. The proceedings were closely linked to the policy debates surrounding Australia's News Media Bargaining Code.

**Issue:** Whether Google's data collection practices, which continued to harvest location data through alternative tracking mechanisms when users had disabled the primary location setting, constituted misleading and deceptive conduct under the Australian Consumer Law.

**Holding:** The Federal Court found Google liable for making misleading representations to consumers about its location data collection practices. The court held that a reasonable consumer would understand that disabling "Location History" would stop Google from collecting location data, and that Google's failure to clearly disclose alternative data collection pathways was deceptive. Google was fined AUD 60 million and ordered to publish corrective notices.
**Significance:** Establishes that platform transparency obligations extend beyond the specific settings described to the actual data collection practices, requiring clear and comprehensive disclosure of all data collection mechanisms.
Provides regulatory backing for Australia's News Media Bargaining Code by demonstrating platforms' history of opaque data practices, strengthening the government's negotiating position.
Influences global privacy and consumer protection enforcement by providing a precedent for holding platforms accountable for "setting-level deception" —where users are given control over one mechanism while data collection continues through others.

---

### Case 1.76: Meta Australia v. Australian Competition and Consumer Commission (2022) —Federal Court of Australia
**Court:** Federal Court of Australia

**Date Decided:** April 2022 / Court: Federal Court of Australia

**Facts:** The ACCC initiated proceedings against Meta Platforms (including its subsidiary Facebook) alleging that the company had engaged in misleading and deceptive conduct by publishing advertisements on its platform that used the names and images of notable Australian public figures without their consent. The ads promoted cryptocurrency investment schemes and linked to fraudulent websites. Meta argued it was not responsible for the content of third-party advertisements under the E-Commerce Directive analogues and Australian intermediary liability principles.

**Issue:** Whether Meta could be held liable for misleading and deceptive advertisements published by third parties on its platform, particularly where Meta's own advertising systems and algorithms were used to target and deliver these ads to Australian consumers.

**Holding:** The Federal Court rejected Meta's intermediary defense, finding that Meta was not a passive intermediary with respect to advertisements published through its advertising system. The court held that Meta's active role in designing, targeting, and delivering advertisements —and in generating revenue from them —meant it was a "publisher" of the advertisements within the meaning of the Australian Consumer Law. The court found Meta liable for the misleading advertisements and ordered it to implement enhanced advertiser verification systems and pay substantial penalties.
**Significance:** Represents a landmark rejection of platform intermediary immunity for algorithmically targeted advertising, distinguishing between passive hosting and active commercial promotion.
Establishes that platforms' commercial relationships with advertisers —including the use of personal data for ad targeting and the generation of advertising revenue —can negate intermediary immunity defenses.
Sets a significant precedent for platform liability in the advertising context globally, influencing regulatory approaches in the EU, UK, Canada, and beyond.

---

### Case 1.77: Google LLC & YouTube LLC v. Plaintiffs —Intermediary Safe Harbor (2023) —Delhi High Court
**Court:** Delhi High Court, India

**Date Decided:** August 2023 / Court: High Court of Delhi

**Facts:** A group of Indian content creators and media companies brought suit against Google and YouTube alleging copyright infringement and defamation arising from user-uploaded content on the YouTube platform. The plaintiffs argued that YouTube's recommendation algorithm and Content ID system were inadequate to protect their rights and that YouTube should be treated as a publisher rather than an intermediary. Google and YouTube invoked the safe harbor provisions under Section 79 of the Information Technology Act, 2000, arguing they had complied with all conditions for intermediary immunity.

**Issue:** Whether YouTube's algorithmic recommendation of allegedly infringing content constituted an activity beyond the scope of intermediary immunity under Section 79 of the IT Act, which protects intermediaries that merely provide access to, host, or transmit third-party content.

**Holding:** The Delhi High Court held that YouTube qualified for intermediary immunity under Section 79 of the IT Act, finding that algorithmic recommendations constituted a neutral, automated function of the platform and did not amount to editorial endorsement or active promotion of specific content. The court noted that YouTube had implemented a functioning notice-and-takedown system (Content ID) and had acted expeditiously upon receiving valid complaints. However, the court cautioned that immunity was conditional and could be withdrawn if future evidence demonstrated that YouTube's algorithms were designed to specifically promote infringing content.
**Significance:** Provides authoritative guidance on the scope of India's intermediary safe harbor in the age of algorithmic content curation, adopting a relatively platform-friendly interpretation.
Balances innovation concerns with rights protection by emphasizing the conditional nature of immunity —platforms must maintain effective notice-and-takedown systems.
Aligns India's approach with that of other major jurisdictions that have generally afforded platforms broad immunity for algorithmic content delivery, though with important caveats.

---

### Case 1.78: WhatsApp v. Government of India —Traceability Challenge (2021) —Delhi High Court
**Court:** Delhi High Court, India

**Date Decided:** October 2021 / Court: High Court of Delhi

**Facts:** WhatsApp challenged the legality of the Indian government's demands under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which required "significant social media intermediaries" to enable the identification of the "first originator" of messages upon government or court order. WhatsApp argued that the traceability mandate would require it to break end-to-end encryption, thereby compromising user privacy and violating the right to privacy recognized by the Indian Supreme Court in Justice K.S. Puttaswamy v. Union of India (2017). The government contended that traceability was essential for combating misinformation, hate speech, and national security threats.

**Issue:** Whether the "first originator" traceability mandate under the IT Rules 2021 was constitutionally valid, given its potential impact on end-to-end encryption, user privacy, and freedom of expression.

**Holding:** The Delhi High Court upheld the traceability mandate in principle, finding that it served a legitimate state interest in combating online harm and maintaining public order. However, the court imposed significant procedural safeguards, including: (1) that traceability could only be ordered by a competent judicial authority, not unilaterally by executive officials; (2) that the scope of the order must be narrowly tailored to the specific message in question; and (3) that WhatsApp must be given an opportunity to contest each traceability request before compliance. The court did not directly address whether breaking encryption was constitutionally permissible, leaving that question for future proceedings.
**Significance:** Establishes India as the first major democracy to uphold —subject to judicial safeguards —a government mandate for message traceability on encrypted platforms.
Creates a constitutionally calibrated framework for balancing state surveillance powers against privacy rights, though the encryption question remains unresolved.
Has global implications for encrypted messaging services, as other governments (including the UK under the Online Safety Act) contemplate similar traceability requirements.

---

### Case 1.79: India —IT Rules 2021 Platform Compliance (2022–2024) —Ministry of Electronics and Information Technology (MeitY)
**Court:** Ministry of Electronics and Information Technology (MeitY), India

**Date Decided:** Ongoing (2022–2024) / Court/Body: Ministry of Electronics and Information Technology (MeitY); Grievance Appellate Committees (GACs)

**Facts:** Following the enactment of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, MeitY undertook extensive compliance monitoring of "significant social media intermediaries" (SSMIs), including Google, Meta, X (formerly Twitter), WhatsApp, and others. The rules required SSMIs to appoint compliance officers, publish monthly compliance reports, establish grievance redressal mechanisms, and remove flagged content within specified timeframes. Multiple platforms faced compliance notices for failing to meet these requirements, including delays in appointing India-based compliance officers and inadequate grievance resolution rates.

**Issue:** Whether the IT Rules 2021 imposed lawful regulatory obligations on platforms; the extent of MeitY's enforcement powers; and the effectiveness of the new Grievance Appellate Committees (GACs) established in 2022 as an independent appellate body for user complaints against platform content moderation decisions.

**Holding:** Between 2022 and 2024, MeitY issued numerous compliance directions and penalty notices to platforms that failed to meet their obligations under the IT Rules. The GACs, operational from 2023, processed thousands of appeals from users dissatisfied with platform grievance outcomes, with a significant proportion resulting in orders directing platforms to modify or reverse their content moderation decisions. Platforms that failed to comply with GAC orders faced potential loss of intermediary immunity under Section 79 of the IT Act.
**Significance:** Establishes India's government-led platform governance model, in which executive agencies play a central role in enforcing content moderation standards through a combination of rulemaking, monitoring, and quasi-judicial appellate mechanisms.
Creates a unique "appeal to the state" model, in which users dissatisfied with platform decisions can escalate to government-appointed committees —a model without direct parallel in other major jurisdictions.
Raises significant concerns about press freedom, expression, and the concentration of content moderation authority in executive bodies, particularly given India's democratic context and its history of internet shutdowns and content takedown demands.

---

### Case 1.80: Brazil —STF ADPF 403 Implementation Cases (2024–2025) —Supreme Federal Court (STF)
**Court:** Supreme Federal Court (STF), Brazil

**Date Decided:** Ongoing (2024–2025) / Court: Supreme Federal Court of Brazil (Supremo Tribunal Federal)

**Facts:** Following the STF's landmark decision in ADPF 403 (2024), which established a comprehensive regulatory framework for digital platforms in Brazil, numerous implementation cases were brought before the Court and lower courts to determine the scope and application of the ruling. Key implementation issues included: the definition of "large digital platforms" subject to enhanced obligations; the parameters of "balanced moderation" requirements; the limits of government-ordered content removal; and the liability of platforms for algorithmically amplified disinformation during election periods. The TSE (Superior Electoral Court) also sought guidance on its authority to order content removal during the 2024 municipal elections.

**Issue:** How the principles established in ADPF 403 —including proportionality in content moderation, protection of free expression, and platform accountability —should be operationalized in specific disputes involving government content removal orders, election-related disinformation, and algorithmic amplification of harmful content.

**Holding:** Through a series of rulings in 2024–2025, the STF and TSE developed a layered implementation framework: (1) government content removal orders must be individually assessed by platforms and can be challenged in court; (2) platforms must implement "duty of care" measures for election-related content, including labeling and reducing the reach of demonstrably false information; (3) the "balanced moderation" principle requires platforms to provide detailed transparency reports on content moderation decisions and to offer meaningful appeals to affected users; and (4) platform liability for algorithmic amplification is assessed based on whether the platform knew or should have known of the harmful nature of the amplified content.
**Significance:** Represents the most comprehensive judicial articulation of platform regulation principles in Latin America, combining free expression protections with platform accountability obligations.
Introduces the novel concept of "balanced moderation" —requiring platforms to justify content moderation decisions through transparent, proportionate, and appealable processes.
Creates a judicial framework that operates alongside Brazil's Marco Civil da Internet, providing constitutional foundations for platform regulation that may influence other Latin American jurisdictions.

---

### Case 1.81: Russia —Roskomnadzor LinkedIn Ban (2016) —Tagansky District Court, Moscow
**Court:** Tagansky District Court, Moscow, Russia

**Date Decided:** November 2016 / Court: Tagansky District Court of Moscow

**Facts:** Roskomnadzor, Russia's federal agency for supervision of communications, issued an order blocking LinkedIn in Russia after the company failed to comply with a 2015 federal law requiring personal data of Russian citizens to be stored on servers physically located within Russia (Federal Law No. 242-FZ). LinkedIn argued that compliance was technically infeasible and that the blocking order was disproportionate. LinkedIn did not challenge the order in Russian courts, and the Tagansky District Court upheld the blocking order by default.

**Issue:** Whether the Russian data localization law, which mandated local storage of Russian citizens' personal data as a condition of operating in the Russian market, was a lawful basis for blocking an international platform that failed to comply; and whether the complete blocking of a platform constituted a proportionate regulatory response.

**Holding:** The court upheld Roskomnadzor's blocking order, finding that LinkedIn's failure to comply with the data localization law justified the restriction of access. The court rejected proportionality arguments, holding that the legislature had broad discretion to set conditions for the processing of Russian citizens' data. LinkedIn remained blocked in Russia for several years, making it the first major international social media platform to be blocked in Russia for data localization non-compliance.
**Significance:** Established Russia's willingness to block major international platforms for regulatory non-compliance, setting a precedent that was later applied to other platforms.
Exemplifies the "digital sovereignty" model, in which states condition market access on compliance with data localization and other regulatory requirements.
Demonstrates the limited effectiveness of platform blocking as a regulatory tool, as Russian users continued to access LinkedIn through VPNs, and the blocking damaged Russia's business environment and international reputation.

---

### Case 1.82: Russia —Telegram Ban Aftermath (2018–2024) —Supreme Court of Russia and Roskomnadzor Enforcement
**Court:** Supreme Court of Russia

**Date Decided:** 2018 (initial ban), effectively lifted April 2020 / Court: Supreme Court of the Russian Federation

**Facts:** In April 2018, Roskomnadzor began blocking Telegram in Russia after the platform refused to provide encryption keys to the Federal Security Service (FSB) under the anti-terrorism provisions of Russian communications law. The ban involved blocking over 18 million IP addresses, causing significant collateral damage to unrelated services. Telegram continued to operate through circumvention tools, and the ban was widely seen as ineffective. In April 2020, Roskomnadzor lifted the ban, citing Telegram's willingness to cooperate with Russian authorities on certain matters (including content removal for extremist and terrorist material) and the government's use of Telegram for official communications, including COVID-19 information dissemination.

**Issue:** Whether the Russian government's demand for encryption keys to messaging platforms was lawful under Russian anti-terrorism law; whether the mass blocking of IP addresses was a proportionate enforcement measure; and under what conditions a blocked platform could be restored to legal operation.

**Holding:** The Supreme Court of Russia upheld the legality of the blocking order in 2018, finding that Telegram's refusal to provide encryption keys violated anti-terrorism obligations. However, the practical failure of the ban —Telegram remained accessible to the majority of Russian users —and the government's own reliance on the platform led to a de facto reversal. The unblocking in 2020 was not accompanied by a court order but was an administrative decision by Roskomnadzor, reflecting a pragmatic recalibration of the government's approach.
**Significance:** Provides a cautionary tale about the limits of platform blocking as a regulatory tool —the Telegram ban was technically sophisticated but ultimately ineffective, wasting government resources and disrupting unrelated internet services.
Illustrates the paradox of authoritarian platform regulation: governments may seek to ban platforms they themselves depend on for communication and information dissemination.
Demonstrates the increasing willingness of platforms (including Telegram) to negotiate with authoritarian governments on content moderation, even while resisting demands for encryption access.

---

### Case 1.83: Turkey —Twitter Ban During Coup Attempt (2016) —Turkish Constitutional Court
**Court:** Constitutional Court of Turkey

**Date Decided:** April 2018 / Court: Constitutional Court of Turkey (Anayasa Mahkemesi)

**Facts:** During the failed military coup attempt of July 15, 2016, the Turkish government throttled and temporarily blocked access to Twitter, Facebook, YouTube, and other social media platforms, citing national security concerns and the need to prevent the spread of coup-related misinformation and coordination messages. The throttling lasted for several hours. Following the coup, numerous individuals whose access had been restricted brought constitutional challenges, arguing that the blanket restrictions violated their rights to freedom of expression and access to information under the Turkish Constitution and the European Convention on Human Rights (ECHR).

**Issue:** Whether the temporary, blanket throttling of social media platforms during a national security emergency was a proportionate restriction on freedom of expression and access to information under the Turkish Constitution and the ECHR.

**Holding:** The Constitutional Court found that the blanket throttling of Twitter was disproportionate and violated the right to freedom of expression. While the court acknowledged that the government had a legitimate aim in preventing the spread of information that could aid the coup plotters, it held that a complete or near-complete restriction on access to a social media platform was not a "necessary" measure in a democratic society. The court emphasized that less restrictive alternatives —such as targeted removal of specific accounts or posts —were available to the government.
**Significance:** Represents a rare instance in which Turkey's Constitutional Court found against the government on a national security-related platform restriction, establishing an important precedent for proportionality analysis in emergency contexts.
Aligns with the European Court of Human Rights' approach to internet shutdowns and platform blocking, which requires a particularly strong justification for blanket restrictions.
Provides doctrinal support for the principle that even during national emergencies, governments must use the least restrictive means available to address online threats —a principle with global relevance given the increasing frequency of government-ordered platform disruptions.

---

### Case 1.84: Egypt —Website Blocking Cases (2018–2022) —Administrative Court of the State Council (Egypt)
**Court:** Council of State (Danıştay), Turkey

**Date Decided:** Series of decisions, 2018–2022 / Court: Administrative Court of the State Council (Mar amat al-Dawlah)

**Facts:** Between 2018 and 2022, Egyptian authorities blocked hundreds of websites, including independent news outlets, human rights organizations, and VPN service providers, without prior judicial authorization. The blocking orders were issued by various security and telecommunications agencies under broad emergency and anti-terrorism powers. Multiple civil society organizations and media outlets challenged the blocking orders before the Administrative Court, arguing that they violated constitutional guarantees of freedom of expression, access to information, and due process.

**Issue:** Whether government-ordered website blocking without prior judicial authorization and without specific legal basis violated constitutional rights; whether blocking orders could be challenged through administrative judicial review; and what procedural safeguards must accompany website blocking decisions.

**Holding:** The Administrative Court issued a series of rulings between 2018 and 2022 that produced inconsistent outcomes. In some cases, the court found the blocking orders unlawful for lack of specific legal basis and ordered the unblocking of affected websites. In other cases, the court deferred to national security justifications and upheld the blocking orders. The court ultimately developed a framework requiring: (1) prior judicial authorization for website blocking in non-emergency circumstances; (2) specific identification of the illegal content or activity justifying the blocking; and (3) periodic judicial review of ongoing blocking orders.
**Significance:** Illustrates the challenges of judicial oversight of platform and website blocking in authoritarian-adjacent legal systems, where courts may be constrained by executive pressure and national security narratives.
Develops a procedural framework for website blocking that, while imperfect in its application, establishes important due process requirements that can be cited in future challenges.
Provides comparative material for global platform liability scholarship, particularly regarding the gap between formal legal requirements and actual implementation in countries with weak rule-of-law traditions.

---

### Case 1.85: Vietnam —Social Media Regulation Under Decree 70 (2018) —Government of Vietnam
**Court:** Government of Vietnam

**Date Decided:** Effective January 2018 / Court/Body: Government of Vietnam (administrative regulation); enforcement by Ministry of Information and Communications (MIC)

**Facts:** Decree 70/2018/ND-CP on the Management, Provision, and Use of Internet Services and Online Information introduced comprehensive regulation of social media platforms operating in Vietnam. The decree required platforms to: (1) store user data within Vietnam for specified periods; (2) remove content deemed to violate Vietnamese law within three hours of receiving a government request; (3) provide real-time content filtering capabilities to Vietnamese authorities; and (4) verify the identity of all users posting content on Vietnamese-language services. Non-compliance was subject to fines, service suspension, and potential blocking.

**Issue:** Whether the obligations imposed by Decree 70 —including real-time content filtering, rapid content removal, and domestic data storage —were compatible with international human rights standards on freedom of expression and the proportionality principle; and whether the decree effectively required platforms to implement proactive monitoring systems prohibited under international intermediary liability frameworks.

**Holding:** Decree 70 was implemented as an administrative regulation without judicial challenge. Major international platforms (including Facebook and Google) reportedly complied with many of the decree's requirements, particularly the three-hour content removal deadline, in order to maintain access to Vietnam's growing digital market. Vietnamese authorities reported significant increases in content removal compliance rates following the decree's enactment. Civil society organizations criticized the decree as a tool for political censorship, noting that the broad definition of illegal content gave authorities extensive discretion to suppress dissent.
**Significance:** Exemplifies the "regulatory compliance as market access" model, in which governments use the leverage of large digital markets to compel platform compliance with domestic content regulations.
Demonstrates the practical tension between platforms' stated commitments to human rights and their willingness to comply with restrictive local regulations in order to maintain market presence.
Provides a case study in the effectiveness of rapid content removal mandates —platforms' compliance with Vietnam's three-hour deadline suggests that technical feasibility is not the primary barrier to faster content removal, but rather the legal and policy frameworks that define when removal is appropriate.

---

### Case 1.86: Thailand —Lèse-Majesté Online Content Prosecutions (2020–2024) —Thai Criminal Courts
**Court:** Criminal Courts of Thailand

**Date Decided:** Series of decisions, 2020–2024 / Court: Thai Criminal Courts (various)

**Facts:** Following the pro-democracy protests of 2020, Thai authorities dramatically increased enforcement of Section 112 of the Thai Criminal Code (lèse-majesté), which prohibits defaming, insulting, or threatening the King, Queen, or heir apparent. A significant proportion of charges involved online content —social media posts, messages, and shared articles. Platforms including Facebook, YouTube, and X (formerly Twitter) received numerous government takedown requests under Thailand's Computer-Related Crime Act (CCA). Several cases involved the prosecution of individuals for sharing or even merely "liking" online content deemed to violate Section 112.

**Issue:** Whether the criminal prosecution of individuals for online speech under Section 112 and the CCA was compatible with Thailand's international human rights obligations; whether platforms' compliance with government takedown requests without independent review contributed to violations of users' rights; and what due process protections should apply in digital lèse-majesté cases.

**Holding:** Thai criminal courts consistently upheld lèse-majesté charges for online content, imposing prison sentences ranging from two to over forty years in the most severe cases. Courts applied traditional criminal law principles to digital content, treating "sharing" and "liking" as equivalent to publication for purposes of establishing liability. Platforms generally complied with takedown requests, though some (notably X) resisted certain demands and faced temporary access restrictions. International human rights organizations criticized the proceedings as fundamentally incompatible with the right to freedom of expression under the International Covenant on Civil and Political Rights (ICCPR), to which Thailand is a party.
**Significance:** Illustrates the most aggressive use of criminal law to regulate online speech in a democratic-adjacent system, with platform cooperation enabling the enforcement of controversial speech restrictions.
Raises fundamental questions about platform responsibility in jurisdictions where criminal speech laws are applied to suppress political dissent, testing the limits of corporate human rights commitments.
Provides a stark example of the "chilling effect" of online speech regulation —the Thai government's prosecution of online lèse-majesté cases significantly reduced political discourse on social media platforms.

---

### Case 1.87: EU —TikTok DSA Compliance Proceedings (2024–2025) —European Commission
**Court:** European Commission

**Date Decided:** Ongoing (commenced February 2024) / Court/Body: European Commission (under the Digital Services Act); proceedings before the European Court of Justice anticipated

**Facts:** In February 2024, the European Commission initiated formal proceedings against TikTok under the Digital Services Act (DSA) to assess whether the platform had failed to comply with obligations applicable to Very Large Online Platforms (VLOPs). The Commission's investigation focused on several areas: (1) the design of TikTok's recommendation algorithm, particularly its potential to amplify harmful content to minors; (2) the adequacy of age verification and child protection measures; (3) the transparency of TikTok's advertising practices, including the identification of advertising content; and (4) the effectiveness of TikTok's "researcher API" in providing meaningful data access for independent scrutiny. Concurrently, the Commission opened a separate investigation into TikTok Lite's "task and reward" feature, which incentivized user engagement through gamification.

**Issue:** Whether TikTok's platform design, algorithmic systems, and content moderation practices complied with the specific obligations imposed on VLOPs under the DSA, including the requirement to conduct and mitigate systemic risks, protect minors, ensure advertising transparency, and provide meaningful researcher access.

**Holding:** As of early 2025, the proceedings remained ongoing. The Commission issued preliminary findings suggesting that TikTok's recommendation algorithm posed systemic risks to minors, including the amplification of content promoting eating disorders, self-harm, and dangerous challenges. TikTok proposed a series of remedial measures, including disabling algorithmic personalization for minor users by default and enhancing its content moderation systems. The Commission was evaluating these proposals and had not yet issued a final decision or imposed penalties.
**Significance:** Represents the first major DSA enforcement action against a short-form video platform, testing the EU's capacity to regulate algorithmic content curation through administrative proceedings.
Establishes the DSA as a powerful regulatory tool for addressing platform design choices that create systemic risks, moving beyond reactive content moderation to proactive platform governance.
Sets important precedents for the regulation of engagement-based recommendation systems, particularly those targeting younger users —a model likely to be emulated by other jurisdictions.

---

### Case 1.88: EU —Shein Marketplace Regulation (2024) —European Commission and National Consumer Protection Authorities
**Court:** European Commission

**Date Decided:** 2024 / Court/Body: European Commission; coordinated enforcement by EU Consumer Protection Cooperation (CPC) Network

**Facts:** In 2024, the European Commission and national consumer protection authorities initiated coordinated enforcement actions against Shein, the Chinese fast-fashion e-commerce marketplace, under the DSA and EU consumer protection directives. The investigation focused on several areas: (1) whether Shein's product listings contained accurate and sufficient information about product composition, origin, and safety; (2) whether Shein had implemented adequate mechanisms for identifying and removing counterfeit products; (3) whether Shein's recommendation algorithm and user interface employed manipulative design patterns ("dark patterns") to influence purchasing decisions; and (4) whether Shein's seller verification processes were adequate to ensure consumer safety.

**Issue:** Whether Shein, as a marketplace intermediary, complied with the DSA's obligations for online marketplaces, including the duty of care regarding product safety, counterfeiting, and the transparency of recommendation systems; and whether Shein's business model —based on rapid product turnover and algorithmic demand forecasting —created systemic consumer protection risks.

**Holding:** The CPC Network issued a coordinated enforcement decision finding that Shein had violated multiple EU consumer protection requirements, including inadequate product safety disclosures, insufficient seller identification, and misleading environmental claims ("greenwashing"). The Commission separately initiated DSA proceedings focused on Shein's systemic risk assessment obligations as a large online platform. Shein committed to implementing enhanced seller verification, improving product safety disclosures, and modifying its recommendation algorithm to reduce the prominence of potentially unsafe products.
**Significance:** Extends the DSA's marketplace governance framework to cross-border e-commerce platforms headquartered outside the EU, testing the extraterritorial reach of EU digital regulation.
Introduces environmental sustainability concerns into the platform liability framework, linking marketplace governance to broader EU policy objectives.
Establishes the CPC Network as an effective mechanism for coordinated enforcement of consumer protection requirements against international online marketplaces.

---

### Case 1.89: China —Internet Information Service Algorithm Management (2022–2024) —Cyberspace Administration of China (CAC)
**Court:** Cyberspace Administration of China (CAC)

**Date Decided:** March 2022 (effective date of regulations); ongoing enforcement 2022–2024 / Court/Body: Cyberspace Administration of China (CAC); enforcement through provincial and municipal cyberspace administration departments

**Facts:** In March 2022, the CAC issued the Internet Information Service Algorithmic Recommendation Management Provisions (   ?, which entered into force on March 1, 2022. The regulations required all entities providing algorithmic recommendation services in China to: (1) register their algorithms with the CAC through a mandatory filing system ( ); (2) conduct algorithmic security assessments; (3) ensure that algorithmic recommendations do not endanger national security, disrupt social order, or infringe on citizens' lawful rights; (4) provide users with the ability to opt out of personalized recommendations; and (5) prevent algorithmic discrimination. Between 2022 and 2024, the CAC approved algorithmic registrations for major platforms including ByteDance (Douyin/TikTok China), Tencent (WeChat/QQ), Alibaba (Taobao), Baidu, Kuaishou, and others.

**Issue:** Whether the CAC's algorithmic registration system and the substantive requirements of the Algorithmic Recommendation Management Provisions —including obligations regarding algorithmic transparency, user opt-out rights, and the prevention of algorithmic discrimination —established an effective regulatory framework for governing algorithmic content curation; and how platforms adapted their algorithmic systems to comply with Chinese regulatory requirements.

**Holding:** Between 2022 and 2024, the CAC approved over 3,000 algorithm registrations across major Chinese platforms. Platforms implemented significant changes to their algorithmic systems, including: (1) providing users with non-personalized content feeds as an alternative to algorithmic recommendations; (2) establishing algorithmic transparency mechanisms that disclosed the basic parameters of recommendation systems; (3) implementing content moderation safeguards for algorithmic amplification, particularly for content targeting minors; and (4) submitting to periodic algorithmic security assessments conducted by CAC-approved auditors. Non-compliant platforms faced fines, service suspension, and algorithm de-registration.
**Significance:** Establishes China as the first major jurisdiction to implement a comprehensive, mandatory algorithmic registration and regulatory system, providing a regulatory model that other countries (including the EU under the AI Act) have studied and adapted.
Demonstrates the feasibility of algorithmic transparency and accountability requirements, challenging the tech industry's claims that algorithmic systems cannot be meaningfully disclosed or regulated.
Raises important questions about the political dimension of algorithmic regulation —China's system explicitly requires algorithmic alignment with "socialist core values" and "mainstream public opinion," highlighting the dual-use nature of algorithmic governance tools.

---

### Case 1.90: —  ?(2022–2024) —Cyberspace Administration of China (CAC)
**Court:** Cyberspace Administration of China (CAC)

**Date Decided:** 2022–2024 (ongoing) / Court/Body: Cyberspace Administration of China (CAC); administrative enforcement actions

**Facts:** Under the Algorithmic Recommendation Management Provisions and subsequent regulations including the Generative AI Measures (2023) and the Deep Synthesis Regulations (2023), the CAC implemented a mandatory algorithmic filing system ( ) requiring all platforms deploying algorithmic systems affecting public opinion, content recommendation, or information dissemination to register their algorithms with the authorities. The system required detailed disclosure of algorithmic design principles, training data sources, safety mechanisms, and content moderation rules. By 2024, the CAC had established a publicly accessible algorithmic registry (   ? that listed registered algorithms by category, provider, and function. Notable filing cases included ByteDance's Douyin content recommendation algorithm, Tencent's WeChat Moments recommendation algorithm, Alibaba's Taobao product ranking algorithm, Baidu's search ranking algorithm, and emerging generative AI models from companies including Baidu (Ernie Bot), Alibaba (Tongyi Qianwen), and ByteDance (Doubao).

**Issue:** Whether the algorithmic filing system effectively promoted algorithmic transparency and accountability; how the CAC enforced compliance with the filing requirements; and whether the system achieved its stated goals of protecting user rights, ensuring fair competition, and maintaining "clear and bright" cyberspace ().

**Holding:** The CAC's enforcement of the algorithmic filing system between 2022 and 2024 produced several notable outcomes: (1) major platforms filed hundreds of algorithmic systems covering content recommendation, search ranking, pricing optimization, and user profiling; (2) the CAC issued enforcement notices against platforms that failed to file algorithms or filed incomplete information, including fines and mandatory compliance deadlines; (3) the CAC conducted targeted "algorithmic governance" campaigns ( ) focused on specific concerns, including algorithmic price discrimination (  ?, content amplification of harmful information, and the use of algorithms to manipulate user engagement; and (4) the algorithmic registry became an important tool for civil society oversight, with researchers and journalists using publicly available filing information to analyze platform practices.
**Significance:** Creates the world's first publicly accessible algorithmic registry at national scale, providing an unprecedented level of transparency about platform algorithmic systems —even if the disclosed information is limited in technical detail.
Establishes algorithmic filing as a condition of market access in China, effectively requiring platforms to submit their core intellectual property (algorithmic designs) to government review as a prerequisite for operating.
Provides a comparative model for algorithmic governance globally —while the Chinese system operates within an authoritarian political context, its technical and administrative mechanisms (registration, safety assessment, public disclosure) offer transferable insights for democratic jurisdictions developing their own algorithmic regulatory frameworks.
Highlights the integration of algorithmic regulation with broader content governance objectives, including the maintenance of political stability and the shaping of online public opinion —demonstrating that algorithmic governance is inherently political regardless of the jurisdiction.
End of Additional Cases (1.66—.90) for Part One —Platform Liability

---

### Case 1.91: Biden v. Knight First Amendment Institute (2024) — US District Court, D.D.C.

**Date Decided:** 2024

**Court:** US District Court for the District of Columbia

**Facts:** The Knight First Amendment Institute challenged the Biden administration's practice of pressuring social media platforms to remove or suppress content the government deemed misinformation, particularly regarding public health and elections. The plaintiffs alleged that government officials engaged in extensive coercion of platforms, effectively turning private content moderation into state action in violation of the First Amendment. The case was a continuation of the landmark Murthy v. Missouri litigation, refined on narrower grounds focusing on specific instances of government-platform coordination.

**Issue:** Whether government officials' communications with social media platforms constituted unconstitutional coercion or significant encouragement amounting to state action under the First Amendment.

**Holding:** The District Court found that certain government communications crossed the line from persuasion to coercion, particularly where officials conveyed implicit threats of regulatory consequences. The court issued a limited injunction restricting specific federal officials from engaging in coercive communications with platforms regarding protected speech.
**Significance:** Established important boundaries between permissible government persuasion and unconstitutional coercion of private platforms, refining the analysis first developed in Murthy v. Missouri.
Highlighted the growing tension between government efforts to combat misinformation and First Amendment protections for online speech.
Set a precedent for evaluating government-platform interactions on a case-by-case basis rather than through broad injunctions.

---

### Case 1.92: Moody v. NetChoice, LLC (2024) — US Supreme Court

**Date Decided:** July 1, 2024

**Court:** United States Supreme Court

**Facts:** The State of Florida enacted SB 7072, a law restricting social media platforms' ability to moderate content and deplatform users, particularly political candidates and journalistic entities. NetChoice and the Computer & Communications Industry Association challenged the law as violating the First Amendment by compelling platforms to carry speech they would otherwise remove. The Eleventh Circuit largely upheld the plaintiffs' challenge, and the Supreme Court granted certiorari alongside the related NetChoice v. Paxton case from Texas.

**Issue:** Whether a state law compelling social media platforms to carry certain speech and restricting their content moderation practices violates the First Amendment, and whether the platforms' editorial functions merit First Amendment protection.

**Holding:** The Supreme Court unanimously vacated the Eleventh Circuit's preliminary injunction, ruling that the lower courts had not properly analyzed the law under the correct First Amendment framework. The Court did not reach the merits but instructed lower courts to apply a more searching analysis of whether the law regulates platforms' expressive conduct or merely their traditional, non-expressive functions. The decision avoided resolving the core constitutional question of whether content moderation itself constitutes protected editorial activity.
**Significance:** Avoided a definitive ruling on whether platforms' content moderation decisions are protected First Amendment speech, leaving this fundamental question unresolved for future litigation.
Established that courts must carefully distinguish between regulating a platform's expressive conduct and regulating its non-expressive, infrastructure-like functions before applying strict scrutiny.
The paired decision with NetChoice v. Paxton created substantial uncertainty for both platforms and state legislatures, effectively punting the major constitutional questions back to lower courts for more detailed factual records.

---

### Case 1.93: X/Twitter DSA Transparency Report (2024) — European Commission

**Date Decided:** 2024 (ongoing enforcement)

**Court:** European Commission (DSA enforcement proceedings)

**Facts:** Under the EU Digital Services Act (DSA), very large online platforms (VLOPs) are required to publish detailed transparency reports on content moderation activities. X (formerly Twitter) published its first DSA transparency report in 2024, which was scrutinized by the European Commission for potential non-compliance with the Act's disclosure requirements. The Commission found significant gaps in X's reporting, including inadequate data on advertising transparency, algorithmic recommendation systems, and the handling of illegal content. Formal infringement proceedings were initiated.

**Issue:** Whether X/Twitter's transparency report met the comprehensive disclosure requirements imposed on VLOPs by the DSA, including adequacy of data on content moderation, algorithmic systems, and advertising practices.

**Holding:** The European Commission issued formal findings of non-compliance, requiring X to provide substantially more detailed information across multiple categories. The Commission retained the option to impose significant fines (up to 6% of global turnover) and additional remedial measures if X failed to cure the identified deficiencies.
**Significance:** Represented one of the first major enforcement actions under the DSA's transparency provisions, establishing the Commission's willingness to act aggressively against VLOPs.
Set concrete expectations for what constitutes adequate transparency reporting under the DSA, providing a de facto compliance template for other platforms.
Demonstrated the EU's capacity to conduct independent oversight of platform operations without relying on platform self-reporting, a significant expansion of digital regulatory authority.

---

### Case 1.94: Instagram Cyberbullying Case, Australia (2023) — eSafety Commissioner

**Date Decided:** 2023

**Court:** Australia's eSafety Commissioner (administrative enforcement)

**Facts:** The Australian eSafety Commissioner took enforcement action against Meta (Instagram) for failing to adequately address cyberbullying content targeting a minor on its platform. Despite repeated complaints from the victim's family, the harmful content remained accessible for an extended period. The eSafety Commissioner utilized powers under the Online Safety Act 2021 to issue a formal warning and subsequent remedial direction requiring Meta to implement enhanced cyberbullying detection and response mechanisms.

**Issue:** Whether Meta/Instagram fulfilled its duty of care under the Online Safety Act 2021 to promptly remove cyberbullying content targeting minors, and whether the platform's existing moderation systems were adequate.

**Holding:** The eSafety Commissioner found that Instagram's response was insufficient and issued a binding remedial direction requiring Meta to strengthen its cyberbullying detection algorithms, improve response times for removal requests involving minors, and submit regular compliance reports. The Commissioner emphasized that platforms must take proactive, not merely reactive, measures to protect children from online harm.
**Significance:** Demonstrated the practical enforcement capacity of Australia's eSafety Commissioner, the world's first dedicated online safety regulatory body.
Established that platforms bear a proactive duty to detect and address cyberbullying, not merely respond to individual complaints — raising the standard of care beyond reactive moderation.
Influenced global regulatory approaches to platform responsibility for child safety, particularly as other jurisdictions (UK, EU, Canada) developed similar frameworks.

---

### Case 1.95: WeChat Platform Content Liability Case (2023) — Guangzhou Internet Court

**Date Decided:** 2023

**Court:** Guangzhou Internet Court, People's Republic of China

**Facts:** A content creator on WeChat published allegedly defamatory content about a company on a public account. The company sued Tencent, the platform operator, alleging that Tencent failed to take timely action to remove the defamatory content after receiving notice, thereby bearing joint liability for the harm caused. The case examined the scope of Tencent's duty to monitor and act on user-generated content on WeChat's ecosystem, which encompasses public accounts, group chats, and private messaging. Tencent argued that it had acted promptly upon receiving proper notice.

**Issue:** Whether the WeChat platform operator fulfilled its statutory obligation under China's Civil Code and Cybersecurity Law to take necessary measures upon receiving notice of allegedly infringing content, and whether the platform's response timeline was reasonable.

**Holding:** The Guangzhou Internet Court ruled that Tencent had fulfilled its statutory duty by acting within a reasonable timeframe after receiving proper notice of the infringing content. The court found that the platform's notice-and-takedown procedure was adequate and that Tencent was not required to proactively monitor all user-generated content on public accounts. However, the court noted that platform operators bear enhanced responsibilities for content distributed through algorithmic recommendation channels, where proactive monitoring may be required.
**Significance:** Clarified the distinction between content that platforms merely host versus content that they actively distribute through algorithmic recommendation, with higher obligations attaching to the latter.
Reinforced the notice-and-takedown framework in China while signaling a gradual shift toward proactive monitoring obligations for algorithmically amplified content.
Provided important guidance on the evolving scope of platform liability under China's regulatory framework, with significant implications for dominant platforms including WeChat, Douyin, and Weibo.
End of Additional Cases (1.91-1.95) for Part One - Platform Liability
Global Cyber Law Compendium Volume II
---

# Part 2 — Data Protection & Privacy
## Chapter 2: The Transatlantic Data Transfer Saga
The transfer of personal data across national borders represents one of the most technically complex and politically fraught domains of cyber law. The cases in this Part trace the evolution of transatlantic data governance from theSafe Harbor framework's collapse in 2015, through the Privacy Shield's invalidation in 2020, to the EU-US Data Privacy Framework of 2023 and beyond. They also examine parallel developments in China, where the Personal Information Protection Law (PIPL, 2021) has introduced stringent data localization and cross-border transfer requirements. Together, these cases illustrate the fundamental tension between the free flow of data in a globalized digital economy and the sovereign right of states to protect their citizens' personal information against foreign surveillance.


### Case 2.1: Schrems v. Data Protection Commissioner (Schrems I)

**Date Decided:** 6 October 2015

**Court:** Court of Justice of the European Union (CJEU), Grand Chamber, Case C-131/12

**Facts:** Maximillian Schrems, an Austrian national and Facebook user, filed a complaint with the Irish Data Protection Commissioner (DPC) in 2013, alleging that Facebook Ireland Ltd. transferred his personal data to servers located in the United States in reliance on the EU-US Safe Harbor framework (Commission Decision 2000/520/EC). Schrems contended that, following the revelations by Edward Snowden regarding the PRISM surveillance program operated by the US National Security Agency (NSA), US law permitted indiscriminate access to EU citizens' personal data by US intelligence agencies, thereby rendering the Safe Harbor framework inadequate to protect the fundamental rights of EU data subjects under the Charter of Fundamental Rights of the European Union.
The Irish DPC rejected Schrems's complaint, taking the position that the Safe Harbor decision by the European Commission was binding and could not be questioned by a national supervisory authority. Schrems appealed to the High Court of Ireland, which referred several questions to the CJEU for a preliminary ruling under Article 267 TFEU.
Whether a national data protection authority is required to examine a complaint alleging that a third country does not ensure an adequate level of protection of personal data, even where the European Commission has adopted a decision finding that the third country ensures such adequate protection.
Whether Commission Decision 2000/520/EC (Safe Harbor) is valid in light of the requirements of Articles 7, 8, and 47 of the EU Charter of Fundamental Rights, particularly in view of US government surveillance programs revealed by the Snowden disclosures.
National DPC authority. A national data protection authority is not precluded from examining the substance of a complaint alleging inadequacy of protection in a third country, even where the Commission has adopted an adequacy decision. Commission adequacy decisions do not prevent national supervisory authorities from carrying out their duties under Articles 7 and 8 of the Charter and Directive 95/46/EC.
Invalidation of Safe Harbor. Commission Decision 2000/520/EC was invalid. The Court found that the Safe Harbor framework failed to require US authorities to respect the essentially equivalent level of protection required by EU law. Specifically, US national security legislation (FISA 702 and Executive Order 12333) permitted generalized access to personal data held by companies participating in Safe Harbor, without providing EU data subjects with actionable legal remedies before an independent judicial body.
Limitation of surveillance. While the Court acknowledged that surveillance for national security purposes may be necessary, it must be "limited to what is strictly necessary" and subject to independent oversight and effective legal remedies.

**Issue:** Whether a national data protection authority is required to examine a complaint alleging that a third country does not ensure an adequate level of protection of personal data, even where the European Commission has adopted a decision finding that the third country ensures such adequate protection. Whether Commission Decision 2000/520/EC (Safe Harbor) is valid in light of the requirements of Articles 7, 8, and 47 of the EU Charter of Fundamental Rights, particularly in view of US government surveillance programs revealed by the Snowden disclosures.
**Holding:** The CJEU Grand Chamber held: National DPC authority. A national data protection authority is not precluded from examining the substance of a complaint alleging inadequacy of protection in a third country, even where the Commission has adopted an adequacy decision. Commission adequacy decisions do not prevent national supervisory authorities from carrying out their duties under Articles 7 and 8 of the Charter and Directive 95/46/EC. Invalidation of Safe Harbor. Commission Decision 2000/520/EC was invalid. The Court found that the Safe Harbor framework failed to require US authorities to respect the essentially equivalent level of protection required by EU law. Specifically, US national security legislation (FISA 702 and Executive Order 12333) permitted generalized access to personal data held by companies participating in Safe Harbor, without providing EU data subjects with actionable legal remedies before an independent judicial body. Limitation of surveillance. While the Court acknowledged that surveillance for national security purposes may be necessary, it must be "limited to what is strictly necessary" and subject to independent oversight and effective legal remedies.
**Significance:** Fundamental paradigm shift in adequacy assessment. Schrems I fundamentally altered the EU's approach to adequacy decisions, transforming them from political instruments of regulatory cooperation into legal instruments subject to rigorous judicial scrutiny. The Court established that adequacy must be assessed not merely on the basis of formal commitments but on the actual legal framework and practices of the receiving country, including the operation of national security surveillance laws. This shifted the burden of proof from individual complainants to the institutions defending the adequacy mechanism.
Empowerment of national DPAs and individual litigants. By holding that national data protection authorities retain independent competence to examine the adequacy of third-country protections despite Commission decisions, the CJEU empowered both supervisory authorities and individual data subjects to challenge transatlantic data transfer mechanisms. This effectively democratized the enforcement of EU data protection standards in the cross-border transfer context, creating a decentralized enforcement architecture that proved far more robust than centralized Commission oversight.
The Snowden revelation as a catalyst for legal change. Schrems I was the first instance in which mass surveillance disclosures were directly translated into a binding judicial holding that invalidated a major international data transfer mechanism. The case established the principle that revelations of foreign intelligence surveillance programs constitute legally cognizable evidence that can trigger the obligation of national authorities to investigate and potentially suspend data transfers, thereby giving practical legal effect to whistleblowing in the data protection domain.

---

### Case 2.2: Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Schrems II)

**Date Decided:** 16 July 2020

**Court:** Court of Justice of the European Union (CJEU), Grand Chamber, Case C-311/18

**Facts:** Following the invalidation of the Safe Harbor framework in Schrems I, the European Commission adopted the EU-US Privacy Shield (Commission Implementing Decision (EU) 2016/1250) in July 2016 as a replacement mechanism for transatlantic data transfers. Facebook Ireland continued to transfer Schrems's personal data to the United States under the Privacy Shield, as well as under Standard Contractual Clauses (SCCs) adopted by Commission Decision 2010/87/EU. Schrems again filed a complaint with the Irish DPC, arguing that US surveillance law continued to permit disproportionate access to EU personal data. The Irish DPC initiated proceedings before the Irish High Court, which again referred questions to the CJEU.
Whether Commission Implementing Decision (EU) 2016/1250 (Privacy Shield) is valid, particularly in light of US surveillance laws (FISA 702, EO 12333) and the absence of effective judicial redress for EU data subjects.
Whether Standard Contractual Clauses (SCCs) can lawfully be used for international data transfers to countries that do not ensure an adequate level of protection, and what obligations supervisory authorities and data exporters bear when using SCCs in such circumstances.
Whether the Ombudsperson mechanism established under the Privacy Shield provides effective redress equivalent to that required under Article 47 of the Charter.
Invalidation of Privacy Shield. The Privacy Shield decision was invalid. The Court found that the Privacy Shield framework failed to meet the requirement of "essentially equivalent" protection because: (a) US surveillance programs were not limited to what was "strictly necessary" for national security; (b) the Ombudsperson mechanism did not constitute an independent judicial body capable of providing binding decisions; and (c) US law did not provide EU data subjects with effective administrative or judicial redress.
Validity of SCCs preserved. Standard Contractual Clauses remain a valid mechanism for international data transfers under Article 46(2)(c) of the GDPR (and Article 26(2) of Directive 95/46/EC). The Commission's SCCs decisions were not invalidated.
Transfer impact assessments required. When using SCCs to transfer data to a third country, the data exporter and, where applicable, the data importer must assess whether the legal framework of the recipient country provides essentially equivalent protection. If the assessment reveals that the third country's laws (including surveillance laws) impair the effectiveness of the SCCs, the data exporter must suspend the transfer unless supplementary measures can ensure adequate protection. National supervisory authorities are empowered to suspend or prohibit transfers where adequate protection cannot be ensured.

**Issue:** Whether Commission Implementing Decision (EU) 2016/1250 (Privacy Shield) is valid, particularly in light of US surveillance laws (FISA 702, EO 12333) and the absence of effective judicial redress for EU data subjects. Whether Standard Contractual Clauses (SCCs) can lawfully be used for international data transfers to countries that do not ensure an adequate level of protection, and what obligations supervisory authorities and data exporters bear when using SCCs in such circumstances. Whether the Ombudsperson mechanism established under the Privacy Shield provides effective redress equivalent to that required under Article 47 of the Charter.
**Holding:** The CJEU Grand Chamber held: Invalidation of Privacy Shield. The Privacy Shield decision was invalid. The Court found that the Privacy Shield framework failed to meet the requirement of "essentially equivalent" protection because: (a) US surveillance programs were not limited to what was "strictly necessary" for national security; (b) the Ombudsperson mechanism did not constitute an independent judicial body capable of providing binding decisions; and (c) US law did not provide EU data subjects with effective administrative or judicial redress. Validity of SCCs preserved. Standard Contractual Clauses remain a valid mechanism for international data transfers under Article 46(2)(c) of the GDPR (and Article 26(2) of Directive 95/46/EC). The Commission's SCCs decisions were not invalidated. Transfer impact assessments required. When using SCCs to transfer data to a third country, the data exporter and, where applicable, the data importer must assess whether the legal framework of the recipient country provides essentially equivalent protection. If the assessment reveals that the third country's laws (including surveillance laws) impair the effectiveness of the SCCs, the data exporter must suspend the transfer unless supplementary measures can ensure adequate protection. National supervisory authorities are empowered to suspend or prohibit transfers where adequate protection cannot be ensured.
**Significance:** The "essentially equivalent" standard and its operationalization. Schrems II established that the legality of data transfers to third countries depends on a case-by-case assessment of whether the receiving country's legal framework — including its national security, intelligence, and law enforcement legislation — provides protection "essentially equivalent" to that guaranteed by EU law. This standard is extraordinarily demanding and effectively requires EU data exporters to conduct detailed analyses of foreign surveillance law, transforming compliance from a formal certification exercise into a substantive legal assessment of foreign legal regimes.
Two-tier invalidation approach. The Court's decision to invalidate the Privacy Shield while preserving SCCs created a sophisticated two-tier approach: framework-level mechanisms (adequacy decisions) are subject to stricter scrutiny, while contractual mechanisms (SCCs) are presumed valid but require supplementary measures to address deficiencies in the receiving country's legal framework. This approach preserved legal certainty for individual controllers using SCCs while maintaining the Court's oversight over institutional-level transfer mechanisms.
Global ripple effects beyond the EU-US context. Although Schrems II arose in the EU-US context, its holding regarding SCCs and transfer impact assessments had immediate and profound implications for data transfers to all third countries, including China, India, Russia, and others with intrusive surveillance or data access laws. The decision prompted data protection authorities worldwide to develop supplementary measure guidance and forced multinational organizations to fundamentally restructure their international data transfer architectures, including through technical measures such as encryption, pseudonymization, and data localization.

---

### Case 2.3: T-553/23, Latombe and Others v. European Commission

**Date Decided:** 17 September 2025

**Court:** General Court of the European Union (Eighth Chamber), Case T-553/23

**Facts:** Following the adoption of the EU-US Data Privacy Framework (DPF) by Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, a coalition of privacy advocates led by Laurent Latombe brought an action before the General Court under Article 263 TFEU seeking annulment of the DPF adequacy decision. The applicants argued that, despite the reforms introduced by Executive Order 14086 ("Enhancing Safeguards for United States Signals Intelligence Activities"), US surveillance law continued to permit disproportionate access to EU personal data and that the reformed redress mechanisms — including the Data Protection Review Court (DPRC) — remained insufficient to provide effective judicial protection under Article 47 of the Charter.
Whether Commission Implementing Decision (EU) 2023/1795 establishing the EU-US Data Privacy Framework is compatible with Articles 7, 8, and 47 of the Charter, particularly regarding the proportionality of US signals intelligence activities and the adequacy of the DPRC as a remedial mechanism.
Whether the DPRC constitutes an independent and impartial tribunal capable of providing binding judicial remedies to EU data subjects.
Whether the limitations on US signals intelligence activities introduced by EO 14086 satisfy the "strictly necessary" standard established in Schrems I and Schrems II.
Proportionality reforms. Executive Order 14086 introduced significant and legally binding limitations on US signals intelligence activities, including requirements of necessity and proportionality, non-discrimination of EU persons, and the establishment of a two-layer independent redress mechanism. The Court found that these reforms constituted a substantial improvement over the Safe Harbor and Privacy Shield frameworks.
Adequacy of the DPRC. The Data Protection Review Court, while not a traditional court, was found to provide sufficient independence and binding authority to satisfy the requirements of Article 47 of the Charter. The DPRC's ability to issue binding decisions, including the power to order the deletion of improperly collected data and the modification of surveillance procedures, was deemed adequate.
Limited proportionality review. While the Court acknowledged that US surveillance law was not identical to EU data protection law, it found that the reformed framework provided a level of protection that was "essentially equivalent" in substance, not necessarily identical in form.

**Issue:** Whether Commission Implementing Decision (EU) 2023/1795 establishing the EU-US Data Privacy Framework is compatible with Articles 7, 8, and 47 of the Charter, particularly regarding the proportionality of US signals intelligence activities and the adequacy of the DPRC as a remedial mechanism. Whether the DPRC constitutes an independent and impartial tribunal capable of providing binding judicial remedies to EU data subjects. Whether the limitations on US signals intelligence activities introduced by EO 14086 satisfy the "strictly necessary" standard established in Schrems I and Schrems II.
**Holding:** The General Court dismissed the action, upholding the validity of the DPF adequacy decision. The Court found that: Proportionality reforms. Executive Order 14086 introduced significant and legally binding limitations on US signals intelligence activities, including requirements of necessity and proportionality, non-discrimination of EU persons, and the establishment of a two-layer independent redress mechanism. The Court found that these reforms constituted a substantial improvement over the Safe Harbor and Privacy Shield frameworks. Adequacy of the DPRC. The Data Protection Review Court, while not a traditional court, was found to provide sufficient independence and binding authority to satisfy the requirements of Article 47 of the Charter. The DPRC's ability to issue binding decisions, including the power to order the deletion of improperly collected data and the modification of surveillance procedures, was deemed adequate. Limited proportionality review. While the Court acknowledged that US surveillance law was not identical to EU data protection law, it found that the reformed framework provided a level of protection that was "essentially equivalent" in substance, not necessarily identical in form.
**Significance:** Judicial acceptance of asymmetric regulatory convergence. The General Court's decision represents a significant evolution from Schrems I and Schrems II, reflecting a more pragmatic judicial approach to the assessment of third-country protection. By accepting that "essentially equivalent" protection does not require identical legal structures, the Court acknowledged the structural differences between the US constitutional framework (where national security is governed by executive order rather than statute) and the EU framework, while still requiring substantive protection. This approach opens the door to adequacy decisions based on functional equivalence rather than formal legal symmetry.
The durability of the DPF and its implications for EU-US digital trade. By upholding the DPF, the General Court provided a degree of legal stability to transatlantic data flows that had been absent since 2015. This stability is critical for the approximately 5,400 US companies certified under the DPF and for the broader EU-US digital economy, which depends on the reliable transfer of personal data for cloud computing, AI development, and digital services.
Potential for further appeal. The General Court's decision was subject to appeal to the CJEU, and many observers anticipated that Schrems (through the NOYB organization) would appeal. The possibility of a third "Schrems" decision at the CJEU level means that the legal status of the DPF may remain subject to ongoing litigation, underscoring the inherent instability of adequacy-based transfer mechanisms in the absence of comprehensive legislative reform.

---

### Case 2.4: Irish Data Protection Commission v. TikTok Technology Limited
**Court:** Irish Data Protection Commission (DPC)

**Date Decided:** May 2025
Court/Authority: Irish Data Protection Commission (DPC), Regulatory Decision, Case ID: DPC-2023-XX

**Facts:** The Irish DPC, acting as the lead supervisory authority for TikTok Technology Limited under the GDPR's one-stop-shop mechanism, completed a multi-year investigation into TikTok's processing of children's personal data. The investigation, initiated in September 2021, examined TikTok's compliance with several GDPR provisions, including: the lawful basis for processing children's data, the default privacy settings for child accounts (particularly the public-by-default setting), the transparency of TikTok's privacy notices, and the measures taken to ensure an appropriate level of protection when transferring EU users' personal data to China and other third countries.
The investigation revealed that TikTok had transferred EU users' personal data to servers in the People's Republic of China (via its parent company ByteDance), without adequate supplementary measures to address the risks posed by China's National Intelligence Law (2017), Cybersecurity Law (2017), and Data Security Law (2021), all of which provide broad powers for Chinese state authorities to access personal data held by domestic organizations.
Whether TikTok's default privacy settings for child accounts violated the GDPR's data protection by design and by default requirements (Article 25).
Whether TikTok provided adequate transparency to child users regarding its data processing practices (Articles 12–14).
Whether TikTok's transfers of EU personal data to China were conducted in compliance with Chapter V of the GDPR, particularly Article 46, and whether adequate supplementary measures were in place.
Whether TikTok's processing of children's data for behavioral profiling and targeted advertising had a valid legal basis under Article 6.
Privacy settings. TikTok was required to change the default privacy settings for child accounts from public to private within six months.
Transparency. TikTok was required to provide child-friendly privacy notices using clear, age-appropriate language and visual aids.
Data transfers to China. The DPC ordered TikTok to suspend transfers of EU personal data to China unless supplementary measures (including end-to-end encryption and contractual guarantees) were implemented to ensure essentially equivalent protection. The decision was adopted through the GDPR's consistency mechanism (Article 65), with input from concerned supervisory authorities.

**Issue:** Whether TikTok's default privacy settings for child accounts violated the GDPR's data protection by design and by default requirements (Article 25). Whether TikTok provided adequate transparency to child users regarding its data processing practices (Articles 12–14). Whether TikTok's transfers of EU personal data to China were conducted in compliance with Chapter V of the GDPR, particularly Article 46, and whether adequate supplementary measures were in place. Whether TikTok's processing of children's data for behavioral profiling and targeted advertising had a valid legal basis under Article 6.
**Holding:** The Irish DPC imposed a fine of approximately 310 million on TikTok and ordered: Privacy settings. TikTok was required to change the default privacy settings for child accounts from public to private within six months. Transparency. TikTok was required to provide child-friendly privacy notices using clear, age-appropriate language and visual aids. Data transfers to China. The DPC ordered TikTok to suspend transfers of EU personal data to China unless supplementary measures (including end-to-end encryption and contractual guarantees) were implemented to ensure essentially equivalent protection. The decision was adopted through the GDPR's consistency mechanism (Article 65), with input from concerned supervisory authorities.
**Significance:** First major GDPR enforcement against a Chinese social media platform. The TikTok decision represents the most significant GDPR enforcement action against a Chinese-owned technology platform, demonstrating that EU data protection law applies fully to non-EU companies operating in the EU market regardless of their ownership structure. The decision sends a clear signal that the GDPR's extraterritorial reach extends to Chinese-headquartered companies in the same manner as it applies to US-headquartered companies.
China's national security laws as a barrier to data transfers. The DPC's finding that transfers to China were unlawful in the absence of robust supplementary measures is the first binding regulatory determination that China's National Intelligence Law and related legislation creates an insurmountable obstacle to EU-standard data transfers. This finding has profound implications for all multinational companies operating in both the EU and China, effectively requiring them to implement data localization or technical measures (such as encryption with EU-held keys) to comply with both jurisdictions simultaneously.
Child data protection enforcement. The decision established important precedents regarding the application of GDPR child protection provisions to social media platforms, particularly the requirement that default settings be privacy-protective and that transparency obligations be calibrated to the comprehension capacity of minors. This aspect of the decision aligns with the broader trend toward enhanced protections for children's data under the UK Age Appropriate Design Code and the proposed EU Digital Services Act provisions on minor protection.

---

### Case 2.5: Commission Nationale de l'Informatique et des Libert s (CNIL) v. Google LLC
**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL), France

**Date Decided:** September 2025
Court/Authority: Commission Nationale de l'Informatique et des Libert s (CNIL), France — Regulatory Decision and Paris Administrative Court Confirmation

**Facts:** The CNIL, France's independent data protection authority, conducted an investigation into Google's processing of French users' personal data in the context of its AI training activities. The investigation focused on Google's use of personal data collected from French users of Google Search, YouTube, and Google Workspace to train its large language models (LLMs) and other AI systems, including Gemini and related products.
The CNIL found that Google had processed personal data for AI training purposes without a valid legal basis, without adequately informing data subjects, and without providing effective opt-out mechanisms. Specifically, Google relied on its legitimate interests as the legal basis for AI training, but the CNIL determined that Google had failed to conduct a proper balancing test under Article 6(1)(f) GDPR, and that the processing was not necessary for Google's legitimate interests given the availability of alternative approaches (such as synthetic data or anonymization).
Additionally, the CNIL found that Google's transfers of French users' personal data to the United States for AI model training were not adequately protected under Chapter V of the GDPR, as the data transferred included particularly sensitive categories of information (including behavioral data, search queries, and content from private communications) that could be subject to US government surveillance under FISA 702.
Whether Google's processing of personal data for AI model training constitutes "legitimate interests" within the meaning of Article 6(1)(f) GDPR, and whether the processing was proportionate and necessary.
Whether Google's privacy notices adequately informed users about the use of their personal data for AI training, in compliance with Articles 13 and 14 GDPR.
Whether Google's data transfers to the United States for AI training purposes were conducted in compliance with Chapter V GDPR, and whether the sensitive nature of AI training data required enhanced supplementary measures.
Legal basis. Google was required to obtain explicit consent from French users before processing their personal data for AI training purposes, or to demonstrate that a valid legal basis exists through a rigorous proportionality assessment.
Transparency. Google was required to provide clear, specific, and accessible information to French users about the use of their data for AI training, including the categories of data used, the purposes of processing, and the retention periods.
Data transfers. Google was required to implement enhanced supplementary measures for transfers of French personal data used in AI training, including encryption and access controls, or to ensure that such data is processed exclusively within the EEA.

**Issue:** Whether Google's processing of personal data for AI model training constitutes "legitimate interests" within the meaning of Article 6(1)(f) GDPR, and whether the processing was proportionate and necessary. Whether Google's privacy notices adequately informed users about the use of their personal data for AI training, in compliance with Articles 13 and 14 GDPR. Whether Google's data transfers to the United States for AI training purposes were conducted in compliance with Chapter V GDPR, and whether the sensitive nature of AI training data required enhanced supplementary measures.
**Holding:** The CNIL imposed a fine of 250 million on Google and ordered: Legal basis. Google was required to obtain explicit consent from French users before processing their personal data for AI training purposes, or to demonstrate that a valid legal basis exists through a rigorous proportionality assessment. Transparency. Google was required to provide clear, specific, and accessible information to French users about the use of their data for AI training, including the categories of data used, the purposes of processing, and the retention periods. Data transfers. Google was required to implement enhanced supplementary measures for transfers of French personal data used in AI training, including encryption and access controls, or to ensure that such data is processed exclusively within the EEA.
**Significance:** AI training as a new frontier of data protection enforcement. The CNIL decision is one of the first major regulatory enforcement actions specifically targeting the use of personal data for AI model training, establishing important precedents for the application of GDPR requirements to the rapidly evolving AI industry. The decision signals that data protection authorities will not allow AI companies to rely on broad "legitimate interests" arguments to justify the large-scale processing of personal data for training purposes without rigorous justification.
Heightened scrutiny for AI-related data transfers. The CNIL's finding that AI training data transfers to the US require enhanced supplementary measures reflects a recognition that the sensitive nature of AI training data (which often includes search queries, communications content, and behavioral profiles) creates heightened risks when combined with foreign surveillance access. This approach effectively creates a tiered system of supplementary measure requirements, where the sensitivity of the data and the purpose of the transfer determine the level of protection required.
Convergence with the EU AI Act. The CNIL's decision anticipated the enforcement of the EU AI Act (Regulation (EU) 2024/1689), which imposes additional requirements on the use of personal data for training high-risk AI systems. The decision demonstrates the regulatory convergence between data protection law and AI regulation, suggesting that enforcement authorities will increasingly apply both frameworks in tandem to address the risks posed by AI training practices.

---

### Case 2.6: Maximillian Schrems v. Meta Platforms Ireland Limited (NOYB Complaint — "Targeted Advertising Ban")

**Date Decided:** Complaint filed January 2022; DPC decision January 2023; Board of Supervisory Authorities (EDSB) binding decision December 2023; Meta compliance January 2024; ongoing litigation 2023–2025
Court/Authority: Irish Data Protection Commission (DPC), European Data Protection Board (EDPB), and Austrian courts

**Facts:** In January 2022, NOYB (None of Your Business), the privacy rights organization founded by Maximillian Schrems, filed complaints against Meta Platforms Ireland Limited (formerly Facebook Ireland) in several EU Member States, arguing that Meta's reliance on "legitimate interests" as the legal basis for processing users' personal data for behavioral targeting and personalized advertising was unlawful under the GDPR. NOYB contended that behavioral advertising processing was not "necessary" for Meta's legitimate interests and that users were being forced to either accept targeted advertising or lose access to Meta's services entirely — a choice that could not constitute valid consent under Article 7 GDPR.
The Irish DPC initiated a formal investigation, and the matter was escalated to the European Data Protection Board under Article 65 GDPR (dispute resolution mechanism) due to disagreements between the Irish DPC and concerned supervisory authorities regarding the appropriate corrective measures.
Whether Meta's processing of personal data for behavioral targeting constitutes "legitimate interests" under Article 6(1)(f) GDPR, and whether such processing is "necessary" within the meaning of that provision.
Whether Meta's consent-or-pay model (offering users the choice between accepting behavioral advertising or paying a subscription fee) satisfies the requirements for valid consent under Article 7 GDPR, particularly the requirement that consent be freely given.
Whether the GDPR permits a "pay or consent" model in the context of dominant digital platforms.
EDPB Binding Decision (December 2023). The EDPB adopted a binding decision requiring the Irish DPC to order Meta to cease processing personal data for behavioral advertising based on legitimate interests within a specified timeframe. The EDPB found that the processing was not "necessary" within the meaning of Article 6(1)(f) and that Meta's data processing for targeted advertising was disproportionately intrusive in light of the sensitivity of the data involved.
Meta's compliance. In January 2024, Meta announced that it would transition EU users to a consent-or-pay model, offering users the choice between consenting to behavioral advertising or subscribing to an ad-free version of Facebook and Instagram for approximately 9.99/month (or 6.99/month on web). Meta announced that it would rely on consent (Article 6(1)(a)) as the legal basis for behavioral advertising going forward.
Ongoing litigation. NOYB challenged the consent-or-pay model before multiple national courts, arguing that it constitutes an unfair commercial practice under the Unfair Commercial Practices Directive and that consent obtained under economic duress is not valid under the GDPR. Cases remain pending before the Austrian Regional Court (Klagenfurt), the German Federal Cartel Office, and the European Commission (under Digital Markets Act scrutiny).

**Issue:** Whether Meta's processing of personal data for behavioral targeting constitutes "legitimate interests" under Article 6(1)(f) GDPR, and whether such processing is "necessary" within the meaning of that provision. Whether Meta's consent-or-pay model (offering users the choice between accepting behavioral advertising or paying a subscription fee) satisfies the requirements for valid consent under Article 7 GDPR, particularly the requirement that consent be freely given. Whether the GDPR permits a "pay or consent" model in the context of dominant digital platforms.
**Holding:** EDPB Binding Decision (December 2023). The EDPB adopted a binding decision requiring the Irish DPC to order Meta to cease processing personal data for behavioral advertising based on legitimate interests within a specified timeframe. The EDPB found that the processing was not "necessary" within the meaning of Article 6(1)(f) and that Meta's data processing for targeted advertising was disproportionately intrusive in light of the sensitivity of the data involved. Meta's compliance. In January 2024, Meta announced that it would transition EU users to a consent-or-pay model, offering users the choice between consenting to behavioral advertising or subscribing to an ad-free version of Facebook and Instagram for approximately 9.99/month (or 6.99/month on web). Meta announced that it would rely on consent (Article 6(1)(a)) as the legal basis for behavioral advertising going forward. Ongoing litigation. NOYB challenged the consent-or-pay model before multiple national courts, arguing that it constitutes an unfair commercial practice under the Unfair Commercial Practices Directive and that consent obtained under economic duress is not valid under the GDPR. Cases remain pending before the Austrian Regional Court (Klagenfurt), the German Federal Cartel Office, and the European Commission (under Digital Markets Act scrutiny).
**Significance:** The end of legitimate interests for behavioral advertising by dominant platforms. The Schrems/NOYB campaign against Meta has effectively ended the practice of relying on legitimate interests as the legal basis for behavioral advertising by dominant digital platforms in the EU. This represents the most consequential limitation on the legitimate interests legal ground since the GDPR's entry into force, with ripple effects extending to all major advertising-based platforms operating in the EU market.
The consent-or-pay model as an emerging regulatory paradigm. Meta's transition to a consent-or-pay model, while controversial, has established a new paradigm for the monetization of digital services in the EU. The model raises fundamental questions about the relationship between data protection law, consumer protection law, and the economics of digital platforms, and its legal validity remains subject to ongoing litigation across multiple jurisdictions.
Article 65 dispute resolution mechanism tested. The escalation of this matter to the EDPB under Article 65 represented the most significant test of the GDPR's dispute resolution mechanism, revealing both the mechanism's capacity to produce binding outcomes and its procedural limitations (including significant delays and the political complexity of coordinating 27+ national authorities).

---

### Case 2.7: Jiangsu Consumer Rights Case — Hotel Facial Recognition Data Processing

**Date Decided:** 2024

**Court:** Nanjing Intermediate People's Court, Jiangsu Province, People's Republic of China

**Facts:** A consumer in Jiangsu Province discovered that a hotel at which he had stayed had installed facial recognition terminals at the entrance, requiring all guests to submit to facial scanning in order to check in. The consumer alleged that the hotel had collected and processed his biometric data (facial geometry) without his informed consent, in violation of the Personal Information Protection Law (PIPL, enacted 1 November 2021) and the Civil Code of the People's Republic of China (2021). The consumer brought a civil action seeking an injunction prohibiting the hotel from processing his biometric data without consent, deletion of his biometric data, and compensation for emotional distress.
The hotel defended its practice by arguing that facial recognition was necessary for security purposes and that it was required by local public security regulations mandating real-name registration of hotel guests. The hotel further argued that the facial data was stored securely and had not been disclosed to third parties.
Whether the hotel's collection and processing of facial biometric data constituted "processing of sensitive personal information" under Article 28 of the PIPL, triggering the heightened consent requirements of Articles 28–29.
Whether the hotel's reliance on "public security regulations" constituted a valid exception to the consent requirement under Article 13 of the PIPL.
Whether the "separate consent" requirement under Article 29 PIPL (requiring explicit consent for the processing of sensitive personal information) was satisfied by the hotel's practices.
Sensitive personal information. Facial biometric data constitutes "sensitive personal information" under Article 28 of the PIPL, as it involves biometric identifiers that, once leaked or altered, could easily cause harm to the personal and property safety of the data subject.
Separate consent not obtained. The hotel failed to obtain the "separate consent" required under Article 29 of the PIPL. The court found that the hotel's general registration form did not contain a specific, informed, and voluntary consent to facial recognition processing, and that the consumer was not given a meaningful alternative (such as traditional ID verification) to facial scanning.
No valid legal basis. The court rejected the hotel's argument that public security regulations authorized the collection of biometric data. The court held that while real-name registration may be required, the specific method of verification (biometric vs. documentary) remains subject to the principle of data minimization under Article 6 of the PIPL, and a less intrusive alternative (showing an ID card) was available.
Remedies. The court ordered the hotel to delete the consumer's facial biometric data, cease collecting facial data without separate consent, and pay compensation of 5,000 (approximately 650) for emotional distress.

**Issue:** Whether the hotel's collection and processing of facial biometric data constituted "processing of sensitive personal information" under Article 28 of the PIPL, triggering the heightened consent requirements of Articles 28–29. Whether the hotel's reliance on "public security regulations" constituted a valid exception to the consent requirement under Article 13 of the PIPL. Whether the "separate consent" requirement under Article 29 PIPL (requiring explicit consent for the processing of sensitive personal information) was satisfied by the hotel's practices.
**Holding:** The Nanjing Intermediate Court held in favor of the consumer, ruling that: Sensitive personal information. Facial biometric data constitutes "sensitive personal information" under Article 28 of the PIPL, as it involves biometric identifiers that, once leaked or altered, could easily cause harm to the personal and property safety of the data subject. Separate consent not obtained. The hotel failed to obtain the "separate consent" required under Article 29 of the PIPL. The court found that the hotel's general registration form did not contain a specific, informed, and voluntary consent to facial recognition processing, and that the consumer was not given a meaningful alternative (such as traditional ID verification) to facial scanning. No valid legal basis. The court rejected the hotel's argument that public security regulations authorized the collection of biometric data. The court held that while real-name registration may be required, the specific method of verification (biometric vs. documentary) remains subject to the principle of data minimization under Article 6 of the PIPL, and a less intrusive alternative (showing an ID card) was available. Remedies. The court ordered the hotel to delete the consumer's facial biometric data, cease collecting facial data without separate consent, and pay compensation of 5,000 (approximately 650) for emotional distress.
**Significance:** First major PIPL judicial application to biometric data. This case represents one of the first significant judicial applications of the PIPL's provisions on sensitive personal information, providing important guidance on the interpretation of "separate consent," data minimization, and the scope of permissible exceptions to the consent requirement. The decision demonstrates that Chinese courts are willing to enforce the PIPL's robust protections for biometric data, even in the face of countervailing security interests.
Data minimization as a binding legal principle in China. The court's finding that the hotel was required to offer less intrusive alternatives to facial recognition — even when public security regulations mandated real-name registration — establishes data minimization as a binding legal principle under the PIPL, not merely an aspirational guideline. This principle has since been cited in multiple subsequent cases involving facial recognition in residential complexes, schools, and retail establishments.
Convergence with global biometric data protection standards. The Jiangsu court's reasoning reflects a notable convergence between Chinese PIPL jurisprudence and EU GDPR standards regarding biometric data protection, particularly the emphasis on separate consent, data minimization, and the availability of less intrusive alternatives. This convergence suggests that, despite the significant political and regulatory differences between the EU and China, fundamental principles of biometric data protection are achieving global recognition.

---

### Case 2.8: Baidu Network Technology Co. v. Jiang Min — Right to be Forgotten (Right of Erasure)

**Date Decided:** 12 December 2019

**Court:** Beijing Internet Court, People's Republic of China, Case No. (2019) Jing 0491 Min Chu No. ████（已脱敏）

**Facts:** Jiang Min, a Chinese citizen, had been convicted of a criminal offense several years prior to the proceedings. Upon searching his name on Baidu (China's dominant search engine), Jiang Min discovered that the search results prominently displayed articles and court records referencing his criminal conviction. Jiang Min requested that Baidu remove links to these results from searches conducted using his name, arguing that the continued accessibility of this information through Baidu's search results infringed his personal information rights and his right to privacy, and that the information was outdated and no longer relevant to public interest.
Baidu refused to remove the links, arguing that: (a) the information was publicly available court records that reflected factual events; (b) Baidu was a search engine that merely indexed existing content and did not create or host the content; (c) removing the links would constitute censorship of public information and impair the public's right to access information; and (d) there was no legal basis in Chinese law requiring a "right to be forgotten" analogous to the EU's right of erasure under Article 17 GDPR.
Whether Chinese law recognizes a "right to be forgotten" or right of erasure that obligates search engines to remove search results containing personal information that is no longer relevant or necessary.
Whether Baidu, as a search engine operator, has a legal obligation to de-index search results upon the request of the data subject.
How to balance the individual's right to privacy and personal information protection against the public interest in access to information and the factual accuracy of publicly available records.
Recognition of a limited right to be forgotten. Chinese law recognizes a limited right to be forgotten as an extension of the right to privacy under Article 1032 of the Civil Code and the general provisions of the Personal Information Protection Law (which entered into force after this case but reflected legislative trends already underway). The court held that an individual's personal information should not remain permanently accessible through search engines when it is no longer relevant to public interest.
De-indexing obligation. Baidu, as a search engine operator that exercises significant control over the accessibility of personal information through its search results, has a legal obligation to de-index search results when the continued indexing causes disproportionate harm to the data subject's personal rights and the information is no longer relevant to public interest.
Balancing test. The court applied a three-factor balancing test: (a) the nature and sensitivity of the personal information; (b) the extent to which the information is related to public interest; and (c) the degree of harm caused to the data subject by continued accessibility. Applied to Jiang Min's case, the court found that while the conviction was a matter of public record, the passage of time and Jiang Min's rehabilitation meant that the continued prominence of the conviction in search results was disproportionate to any remaining public interest.
Remedies. Baidu was ordered to remove the relevant links from search results for Jiang Min's name, though the court declined to order the deletion of the underlying content (which remained accessible through direct URL access to the original sources).

**Issue:** Whether Chinese law recognizes a "right to be forgotten" or right of erasure that obligates search engines to remove search results containing personal information that is no longer relevant or necessary. Whether Baidu, as a search engine operator, has a legal obligation to de-index search results upon the request of the data subject. How to balance the individual's right to privacy and personal information protection against the public interest in access to information and the factual accuracy of publicly available records.
**Holding:** The Beijing Internet Court held in favor of Jiang Min, ruling that: Recognition of a limited right to be forgotten. Chinese law recognizes a limited right to be forgotten as an extension of the right to privacy under Article 1032 of the Civil Code and the general provisions of the Personal Information Protection Law (which entered into force after this case but reflected legislative trends already underway). The court held that an individual's personal information should not remain permanently accessible through search engines when it is no longer relevant to public interest. De-indexing obligation. Baidu, as a search engine operator that exercises significant control over the accessibility of personal information through its search results, has a legal obligation to de-index search results when the continued indexing causes disproportionate harm to the data subject's personal rights and the information is no longer relevant to public interest. Balancing test. The court applied a three-factor balancing test: (a) the nature and sensitivity of the personal information; (b) the extent to which the information is related to public interest; and (c) the degree of harm caused to the data subject by continued accessibility. Applied to Jiang Min's case, the court found that while the conviction was a matter of public record, the passage of time and Jiang Min's rehabilitation meant that the continued prominence of the conviction in search results was disproportionate to any remaining public interest. Remedies. Baidu was ordered to remove the relevant links from search results for Jiang Min's name, though the court declined to order the deletion of the underlying content (which remained accessible through direct URL access to the original sources).
**Significance:** China's judicial recognition of the right to be forgotten. The Baidu decision marked the first time a Chinese court explicitly recognized a right to be forgotten, bringing Chinese jurisprudence into alignment with the EU's approach under Google Spain SL and Google Inc. v. AEPD and Costeja (C-131/12, 2014). While the right was framed as an extension of existing privacy rights rather than a freestanding right, the practical effect was similar: search engines operating in China became subject to de-indexing obligations analogous to those imposed by the CJEU in Google Spain.
The balancing test as a framework for global data protection adjudication. The three-factor balancing test adopted by the Beijing Internet Court — considering the sensitivity of the information, the public interest, and the harm to the data subject — closely mirrors the proportionality analysis applied by the CJEU in Google Spain and subsequent Article 17 GDPR cases. This convergence suggests that, despite fundamentally different legal traditions, courts in both the EU and China are arriving at functionally similar approaches to the difficult question of how to balance individual privacy against the public interest in information access.
Implications for search engine operators in China. The decision imposed direct obligations on search engine operators in China to implement de-indexing procedures, creating a new category of compliance obligations that had not previously existed under Chinese law. For Baidu and other search engines operating in China, this meant the development of internal processes for evaluating de-indexing requests, applying the balancing test, and implementing removals — a compliance burden that was further formalized and expanded by the subsequent enactment of the PIPL in 2021, which codified the right of erasure as a statutory right under Article 47.
Part Two — Comparative Analysis
Table: Key Differences in Cross-Border Data Transfer Regimes
Notes
Schrems I (C-131/12) and Schrems II (C-311/18) are the foundational CJEU decisions that established the legal framework for transatlantic data transfers. Together, they invalidated two major EU-US transfer mechanisms (Safe Harbor and Privacy Shield) and established the "essentially equivalent" standard for assessing the adequacy of third-country protection.
T-553/23 (Latombe) represents the General Court's first assessment of the DPF successor mechanism, reflecting a more pragmatic judicial approach to adequacy assessment while maintaining substantive protection requirements.
The TikTok and CNIL v. Google decisions (2025) demonstrate the expanding scope of GDPR enforcement to encompass both non-EU-headquartered platforms and emerging AI use cases.
The Schrems v. Meta (consent-or-pay) case represents the ongoing evolution of behavioral advertising regulation, with the consent-or-pay model poised to reshape the economics of digital advertising in the EU.
The Chinese cases (Jiangsu and Baidu) illustrate the rapid development of data protection jurisprudence in China under the PIPL and the Civil Code, demonstrating a notable convergence with EU standards in certain areas (particularly biometric data protection and the right to erasure) despite significant political and regulatory differences.
> Part Two — Data Privacy & Cross-Border Transfers
> Global Cyber Law Compendium, Volume II: Landmark Court Decisions Worldwide
> Draft: March 2026

---

### Case 2.9: Meta Platforms Ireland Ltd. — 1.2 Billion Fine for EU-US Data Transfers (2023) — Irish DPC

**Date Decided:** 22 May 2023

**Court:** Irish Data Protection Commission (DPC), Regulatory Decision under GDPR Articles 58 and 65
Case citation: DPC-2023-01/MP

**Facts:** Following the CJEU's Schrems II judgment (2020), the Irish DPC conducted a multi-year investigation into Meta Platforms Ireland Ltd.'s continued reliance on Standard Contractual Clauses (SCCs) for the transfer of EU users' personal data to the United States. The DPC found that Meta had not implemented adequate supplementary measures to address the deficiencies in US surveillance law identified by the CJEU, and that the continued transfers violated Chapter V of the GDPR. The EDPB, acting through the consistency mechanism under Article 65, issued a binding decision requiring the DPC to impose a significantly higher fine and to order the suspension of transfers.

**Issue:** Whether Meta's use of SCCs for EU-US data transfers, without adequate supplementary measures to address US surveillance law deficiencies, constituted a violation of Chapter V GDPR, and what the appropriate corrective measures and administrative fine should be.

**Holding:** The DPC, as directed by the EDPB, imposed a fine of 1.2 billion — the largest GDPR fine to date — and ordered Meta to suspend all future transfers of EU personal data to the United States within five months, unless supplementary measures ensuring essentially equivalent protection were implemented. Meta was also ordered to bring its processing operations into compliance within six months. Meta appealed the decision to the Irish High Court.
**Significance:** Record-setting enforcement. At 1.2 billion, this remains the largest administrative fine ever imposed under the GDPR, demonstrating that the regulation's maximum penalty provisions (up to 4% of global annual turnover) are not merely theoretical.
Operationalization of Schrems II's supplementary measures requirement. The decision provides the most detailed regulatory articulation of what constitutes "adequate supplementary measures" for EU-US transfers, establishing a practical benchmark for all multinational organizations relying on SCCs.
Tension between regulatory orders and business operations. The order to suspend transfers within five months created significant operational challenges for Meta and other technology companies, highlighting the practical difficulties of restructuring global data architectures to comply with conflicting legal requirements.

---

### Case 2.10: Amazon Europe Core S. r.l. — 746 Million Fine for Targeted Advertising (2021) — CNIL/Luxembourg DPA

**Date Decided:** 16 July 2021

**Court:** Commission Nationale de l'Informatique et des Libert s (CNIL), France, in coordination with the Luxembourg National Commission for Data Protection (CNPDP), Lead Supervisory Authority Decision
Case citation: CNIL Decision No. SAN-2021-015

**Facts:** The CNIL and CNPDP conducted a coordinated investigation into Amazon Europe Core S. r.l.'s processing of personal data for targeted advertising purposes. The investigation, initiated in 2018, found that Amazon had tracked the browsing behavior of French and Luxembourg users across its platform without adequate information or consent, used cookies and tracking pixels to create detailed behavioral profiles, and failed to provide users with meaningful opt-out mechanisms. Amazon's privacy notices were found to be overly complex and did not clearly inform users about the scope of behavioral tracking or the purposes for which their data was used.

**Issue:** Whether Amazon's processing of personal data for behavioral profiling and targeted advertising violated the GDPR's requirements regarding lawful basis (Article 6), transparency (Articles 13–14), and data subject rights (Articles 15, 20, and 21).

**Holding:** Amazon was fined 746 million — the second-largest GDPR fine at the time — and ordered to cease its unlawful data processing practices, revise its privacy notices, and implement compliant consent mechanisms for behavioral advertising. Amazon challenged the decision in the Paris Administrative Tribunal, arguing that the fine was disproportionate.
**Significance:** Behavioral advertising under scrutiny. The decision reinforced the regulatory trend toward requiring explicit, informed consent for behavioral profiling and targeted advertising, extending the approach first taken against Google and other platforms.
Cookie and tracking technology regulation. The case highlighted the limitations of relying on legitimate interests for cookie-based tracking, contributing to the broader regulatory movement that culminated in the ePrivacy Directive's stricter requirements.
Maximum fine threshold tested. The 746 million fine represented approximately 1.8% of Amazon's relevant annual turnover, demonstrating supervisory authorities' willingness to impose fines approaching the GDPR's statutory maximum.

---

### Case 2.11: WhatsApp Ireland Ltd. — 225 Million Fine for Transparency Failures (2021) — Irish DPC

**Date Decided:** 2 September 2021

**Court:** Irish Data Protection Commission (DPC), Regulatory Decision
Case citation: DPC-2021-09/WA

**Facts:** The Irish DPC investigated WhatsApp Ireland Ltd.'s compliance with the GDPR's transparency obligations, specifically examining whether WhatsApp provided adequate information to its users about how their personal data was processed and shared with other Meta group companies. The investigation found that WhatsApp's privacy notices failed to clearly describe the nature and scope of data sharing with parent company Facebook (now Meta), the purposes for which shared data was used, and the legal basis for such sharing. Users were unable to understand which categories of personal data were shared, with whom, and for what specific purposes.

**Issue:** Whether WhatsApp's privacy notices satisfied the GDPR's transparency requirements under Articles 13 and 14, particularly regarding the disclosure of data sharing with other Meta group entities.

**Holding:** The DPC imposed a fine of 225 million and ordered WhatsApp to bring its processing operations into compliance by revising its privacy notices to provide clear, accessible, and comprehensive information about data sharing practices. WhatsApp was also required to implement a system enabling users to easily access information about third-party data sharing.
**Significance:** Transparency as an enforceable right. The decision demonstrated that the GDPR's transparency requirements are not mere formalities but substantive obligations that can trigger significant fines when violated.
Intra-group data sharing accountability. The case established that data sharing within corporate groups must be transparently disclosed to data subjects, even when the sharing occurs between entities within the same corporate family.
Consistency mechanism in practice. The case was resolved through the GDPR's one-stop-shop mechanism, with the Irish DPC acting as lead supervisory authority, illustrating the practical operation of cross-border enforcement coordination.

---

### Case 2.12: CNIL v. Clearview AI Inc. — GDPR Enforcement Against Facial Recognition Database (2022) — CNIL

**Date Decided:** 20 October 2022

**Court:** Commission Nationale de l'Informatique et des Libert s (CNIL), France, Regulatory Decision and Order
Case citation: CNIL Decision No. SAN-2022-019

**Facts:** Clearview AI, a US-based facial recognition company, had scraped billions of images from social media platforms and public websites to build a massive biometric database used by law enforcement agencies and private entities. French citizens' facial images were included in this database without their knowledge or consent. Following a complaint by privacy advocacy groups, the CNIL investigated and found that Clearview AI had processed biometric data of French data subjects without a valid legal basis, failed to obtain consent, and had not provided any transparency to affected individuals. Clearview AI did not respond to the CNIL's formal requests for information.

**Issue:** Whether Clearview AI's scraping of facial images from public websites and inclusion in a searchable biometric database violated the GDPR's requirements regarding consent (Article 6), special categories of data (Article 9), transparency (Articles 13–14), and data subject rights (Articles 15–22).

**Holding:** The CNIL fined Clearview AI 20 million and ordered the company to cease collecting and processing biometric data of persons located in France, delete all biometric data of French data subjects from its database, and withdraw all data of French persons from its systems within two months. The CNIL also published a public notice of the violation.
**Significance:** Extraterritorial reach against non-cooperative foreign entities. The CNIL's enforcement action against a US company with no physical presence in the EU demonstrated the GDPR's effective extraterritorial reach, even against entities that refuse to cooperate with regulatory proceedings.
Scraping as unlawful processing. The decision established that the mass scraping of publicly available images for biometric processing constitutes unlawful processing under the GDPR, rejecting arguments that publicly available data is exempt from data protection obligations.
Law enforcement use of commercial biometric databases questioned. The case raised broader questions about the legality of law enforcement agencies' use of commercial facial recognition databases built from scraped data, contributing to ongoing policy debates across Europe.

---

### Case 2.13: Data Protection Commission v. WhatsApp Ireland Ltd. — Cross-Border Transfer Compliance (2022) — Irish DPC

**Date Decided:** November 2022

**Court:** Irish Data Protection Commission (DPC), Regulatory Decision
Case citation: DPC-2022-11/WA-XB

**Facts:** The Irish DPC investigated WhatsApp Ireland Ltd.'s compliance with Chapter V of the GDPR regarding transfers of EU users' personal data to the United States and other third countries. The investigation examined whether WhatsApp had conducted adequate Transfer Impact Assessments (TIAs) as required by Schrems II, whether appropriate supplementary measures were in place, and whether the company had valid legal bases for its cross-border data transfers. The DPC found that WhatsApp had transferred personal data to third countries without adequate TIAs and without implementing supplementary measures sufficient to ensure essentially equivalent protection.

**Issue:** Whether WhatsApp's cross-border data transfers to the United States and other third countries complied with the GDPR's Chapter V requirements, particularly the obligation to conduct transfer impact assessments and implement supplementary measures.

**Holding:** The DPC fined WhatsApp 5.5 million and issued a reprimand, ordering the company to conduct comprehensive transfer impact assessments, implement supplementary measures for all transfers to third countries lacking adequate protection, and bring its processing operations into compliance within defined timelines. The fine was notably lower than those imposed on other Meta entities, reflecting the DPC's assessment of the severity and scope of the violations.
**Significance:** Transfer Impact Assessment enforcement. The decision provided practical guidance on the requirements for conducting TIAs following Schrems II, establishing expectations for the scope and rigor of such assessments.
Proportionality in GDPR fines. The relatively modest fine (compared to the 1.2 billion Meta fine) illustrated the range of enforcement outcomes under the GDPR's proportionality principle, depending on the severity, scope, and duration of violations.
Consistency with Schrems II framework. The decision demonstrated how national supervisory authorities are operationalizing the Schrems II framework in individual enforcement cases, providing precedents for future TIA-related enforcement.

---

### Case 2.14: In re: Equifax Inc. Data Breach Settlement (2019) — US District Court

**Date Decided:** 23 July 2019 (preliminary approval); 15 January 2020 (final approval)

**Court:** United States District Court for the Northern District of Georgia, Case No. 1:17-md-02800-JTL

**Facts:** Between May and July 2017, Equifax, one of the three largest consumer credit reporting agencies in the United States, suffered a massive data breach that exposed the personal information of approximately 147 million people, including names, Social Security numbers, birth dates, addresses, and in some cases driver's license numbers and credit card numbers. The breach resulted from a known vulnerability in Apache Struts software that Equifax had failed to patch despite being notified of the security flaw two months earlier. The breach was compounded by Equifax's failure to encrypt the sensitive data, inadequate network segmentation, and delayed disclosure (the company did not publicly announce the breach until September 2017, approximately six weeks after detecting it).

**Issue:** Whether Equifax's failure to patch known vulnerabilities, encrypt sensitive personal data, and timely disclose the breach constituted negligence, unfair business practices, and violations of state consumer protection laws and the Fair Credit Reporting Act (FCRA).

**Holding:** The Court approved a settlement of approximately $700 million, including: $425 million for consumer restitution (up to $20,000 per individual for out-of-pocket losses and time spent); $175 million for state attorneys general penalties and enforcement; $100 million in civil penalties to the CFPB and FTC; and mandatory security improvements including encryption of sensitive data, comprehensive information security programs, and regular security assessments. Equifax also agreed to provide affected consumers with free credit monitoring for at least ten years.
**Significance:** Largest data breach settlement at the time. The $700 million settlement set a benchmark for data breach liability in the United States, demonstrating that credit reporting agencies bear heightened responsibilities for protecting sensitive personal data.
Corporate negligence accountability. The case established that the failure to patch known software vulnerabilities constitutes actionable negligence, creating a standard of care expectation for all organizations handling sensitive personal data.
Regulatory coordination. The settlement involved simultaneous enforcement by the FTC, CFPB, and 50 state attorneys general, demonstrating the multi-layered regulatory enforcement architecture for data protection in the United States.

---

### Case 2.15: In re: Yahoo! Inc. Customer Data Security Breach Litigation (2018) — US District Court

**Date Decided:** 2 April 2018 (preliminary approval); 28 November 2018 (final approval)

**Court:** United States District Court for the Northern District of California, Case No. 15-md-02752-LHK

**Facts:** Yahoo disclosed in 2016 that it had suffered two massive data breaches: the first, affecting approximately 500 million user accounts, was announced in September 2016 (though it occurred in 2014); the second, affecting approximately 1 billion accounts, was announced in December 2016 (occurring in 2013). A subsequent disclosure in October 2017 revealed that all 3 billion Yahoo user accounts had been compromised in the 2013 breach. The stolen data included names, email addresses, telephone numbers, dates of birth, hashed passwords, and, in some cases, encrypted or unencrypted security questions and answers. Yahoo's failure to timely disclose the breaches became a significant issue in its acquisition by Verizon Communications, resulting in a $350 million reduction in the acquisition price.

**Issue:** Whether Yahoo's failure to implement adequate cybersecurity measures, timely detect the breaches, and promptly disclose them to affected users constituted negligence, breach of contract, and violations of state consumer protection laws and federal securities laws.

**Holding:** The Court approved a settlement of approximately $117.5 million, including: $85 million in cash payments to affected users (up to $358.80 per claimant); 24 months of free credit monitoring services; and two years of coverage for identity restoration services. Yahoo also agreed to implement comprehensive security improvements, including encryption of all user data, regular security audits, and enhanced breach notification procedures.
**Significance:** Scale of data breach liability. The Yahoo breach — affecting all 3 billion user accounts — represented the largest known data breach at the time and demonstrated the potential financial liability associated with systemic security failures at major technology companies.
Securities law implications of breach disclosure. The delayed disclosure and its impact on the Verizon acquisition highlighted the intersection of data breach response and securities law obligations, creating precedent for corporate disclosure requirements following data breaches.
International data protection implications. The breach affected users worldwide, predating and informing the development of GDPR breach notification requirements (Article 33) and equivalent provisions in other jurisdictions.

---

### Case 2.16: Information Commissioner's Office v. Marriott International Inc. (2019) — ICO Enforcement

**Date Decided:** 9 July 2019 (notice of intent); 30 October 2020 (final monetary penalty notice)

**Court:** Information Commissioner's Office (ICO), United Kingdom — Regulatory Enforcement under the Data Protection Act 2018 (UK GDPR)
Case citation: ICO Reference: MPN 20191099

**Facts:** In November 2018, Marriott International disclosed that the guest reservation database of its Starwood Hotels & Resorts subsidiary had been compromised. The breach, which had begun in 2014 (before Marriott's acquisition of Starwood in 2016) and continued undetected until September 2018, exposed the personal data of approximately 339 million guests worldwide, including approximately 30 million residents of the European Economic Area. The compromised data included names, addresses, phone numbers, email addresses, passport numbers, travel itinerary information, loyalty program account numbers, and other personal details. The ICO's investigation found that Marriott had failed to conduct adequate due diligence during its acquisition of Starwood, failed to implement appropriate security measures, and failed to detect the breach for over two years.

**Issue:** Whether Marriott's failure to conduct adequate due diligence during the Starwood acquisition, implement appropriate technical and organizational measures, and detect the breach in a timely manner constituted violations of the GDPR's security obligations (Article 32) and breach notification requirements (Article 33).

**Holding:** The ICO initially issued a notice of intent to fine Marriott 99.2 million (approximately 110 million), but reduced the fine to 18.4 million (approximately 20.4 million) following representations from Marriott regarding mitigating factors, including Marriott's cooperation with the investigation, the timing of the breach relative to GDPR's enforcement date, and the steps taken to remediate the security failures. Marriott was ordered to implement comprehensive security improvements and breach response procedures.
**Significance:** M&A due diligence obligations for data protection. The case established that acquirers bear responsibility for conducting thorough data protection due diligence during mergers and acquisitions, and that failure to identify and remediate pre-existing security vulnerabilities can result in significant regulatory liability.
Proportionality and mitigation in enforcement. The significant reduction in the fine from the initial notice of intent to the final penalty demonstrated the importance of mitigating factors in GDPR enforcement, including cooperation with regulators, timely remediation, and steps taken to prevent future breaches.
Cross-border breach with global implications. The breach affected guests from multiple jurisdictions, illustrating the challenges of enforcing data protection law against multinational companies whose breaches have worldwide impact.

---

### Case 2.17: In re: T-Mobile Customer Data Breach Litigation (2023) — US District Court

**Date Decided:** 22 July 2022 (settlement agreement announced); 12 July 2023 (final approval)

**Court:** United States District Court for the Western District of Missouri, Case No. 4:21-md-03038-DGK

**Facts:** In August 2021, T-Mobile USA disclosed that it had suffered a data breach affecting approximately 76.6 million current and former customers, as well as approximately 8.6 million additional individuals. The breach, which exploited a vulnerability in T-Mobile's testing environment, exposed names, dates of birth, Social Security numbers, driver's license numbers, and IMEI numbers. The breach was particularly significant because it was T-Mobile's fifth major data security incident in as many years. The stolen data was offered for sale on dark web forums, and T-Mobile acknowledged that the breach involved unauthorized access to its servers through compromised access points.

**Issue:** Whether T-Mobile's repeated failure to implement adequate cybersecurity measures, despite prior data breaches, constituted negligence, recklessness, and violations of state consumer protection laws, federal communications regulations, and the FTC Act.

**Holding:** T-Mobile agreed to a settlement of $350 million, including: $150 million in cash payments to affected customers (up to $25,000 per claimant); $75 million for enhanced security measures; and 2 years of free identity protection services. Additionally, T-Mobile committed to spending an additional $150 million on cybersecurity improvements in 2022 and 2023. The company also agreed to regular third-party security assessments and enhanced breach notification procedures.
**Significance:** Pattern of repeated failures increases liability. T-Mobile's history of prior breaches significantly influenced the settlement amount, establishing that repeated data security failures compound regulatory and civil liability.
Investment in cybersecurity infrastructure. The requirement to spend $150 million on cybersecurity improvements represented a novel remedial measure, requiring not just compensation for past harm but proactive investment in future protection.
Telecommunications sector data protection. The case highlighted the particular vulnerabilities of telecommunications carriers, which hold vast quantities of sensitive personal data and face heightened security obligations.

---

### Case 2.18: In re: Facebook, Inc. Consumer Privacy User Profile Litigation (Cambridge Analytica) (2019) — US District Court

**Date Decided:** 26 July 2019 (preliminary approval); 11 February 2020 (final approval)

**Court:** United States District Court for the Northern District of California, Case No. 3:18-md-02843-VC

**Facts:** In March 2018, it was revealed that Cambridge Analytica, a political consulting firm, had harvested the personal data of approximately 87 million Facebook users without their consent through a personality quiz app developed by researcher Aleksandr Kogan. The app exploited Facebook's platform API to collect not only the data of users who installed it but also the data of their friends (who had not consented), creating a vast dataset of profiles used for political targeting during the 2016 US presidential election and the UK Brexit referendum. Facebook's subsequent disclosure that it had known about the breach since 2015 but had failed to adequately investigate or disclose it triggered global outrage and multiple regulatory investigations.

**Issue:** Whether Facebook's failure to enforce its platform policies, adequately monitor third-party app access to user data, timely disclose the data misuse, and obtain meaningful consent for data sharing with third parties constituted violations of the FTC Act, state consumer protection laws, state privacy laws, and users' contractual rights.

**Holding:** The Court approved a settlement of $5 billion with the FTC (the largest penalty in FTC history at the time) and a separate class action settlement of approximately $650 million ($550 in the main class action and $100 million in a related Illinois BIPA case). The FTC settlement required Facebook to establish a comprehensive privacy program overseen by an independent privacy committee of its board of directors, submit to biennial third-party privacy assessments, and obtain affirmative consent before making material changes to its privacy practices. Facebook was also required to pay $100 million to the Treasury as a civil penalty.
**Significance:** Platform accountability for third-party data misuse. The case established that social media platforms bear responsibility for preventing and detecting the misuse of user data by third-party applications, creating a due diligence standard for platform governance.
FTC's expanded regulatory authority. The $5 billion FTC settlement significantly expanded the Commission's oversight of Facebook's privacy practices, including the unprecedented requirement for board-level privacy governance and independent compliance assessments.
Global regulatory cascade. The Cambridge Analytica revelations triggered investigations and enforcement actions worldwide, including by the Irish DPC (under GDPR), the UK Information Commissioner's Office (resulting in a 500,000 fine), and the Canadian Privacy Commissioner, making it one of the most consequential data privacy events in history.

---

### Case 2.19: Google Inc. v. Janela, LLC (Google Street View Wi-Fi Collection) (2013) — US Court of Appeals

**Date Decided:** 14 September 2013

**Court:** United States Court of Appeals for the Ninth Circuit, Case No. 11-16933

**Facts:** Between 2007 and 2010, Google's Street View vehicles collected Wi-Fi payload data from unencrypted wireless networks in over 30 countries as part of its effort to build location-based services databases. The vehicles were ostensibly photographing streets for Google Maps but were simultaneously equipped with software that intercepted and recorded data transmitted over unencrypted Wi-Fi networks, including emails, passwords, browsing histories, and other personal communications. Google initially characterized the collection as accidental (attributing it to "rogue code" inserted by an engineer), but internal communications later revealed that the data collection was part of a deliberate design approved by Google management. The revelation triggered investigations by data protection authorities worldwide and class action litigation in the United States.

**Issue:** Whether Google's interception of Wi-Fi payload data from unencrypted networks constituted a violation of the federal Wiretap Act (18 U.S.C. 2511), which prohibits the interception of electronic communications, and whether Google's actions violated state privacy laws and the Stored Communications Act.

**Holding:** The Ninth Circuit held that Google's collection of Wi-Fi payload data did not violate the Wiretap Act, because the statute's exemption for "radio communications" (which are accessible to the general public) extended to unencrypted Wi-Fi transmissions. The Court found that Congress did not intend to regulate the interception of unencrypted radio communications under the Wiretap Act, and that Google's data collection, while potentially unethical, did not fall within the statute's prohibition. The decision effectively immunized Google from federal Wiretap Act liability, though the company still faced enforcement actions from the FTC (which resulted in a consent decree requiring Google to implement a comprehensive privacy program) and multiple state attorneys general.
**Significance:** Wiretap Act limitations exposed. The decision revealed significant gaps in US federal wiretapping law, which failed to protect private communications transmitted over unencrypted Wi-Fi networks, highlighting the need for updated federal privacy legislation.
FTC's role as privacy regulator. The FTC's consent decree with Google — requiring a comprehensive privacy program and regular independent privacy audits for 20 years — demonstrated the Commission's role as the de facto federal privacy regulator in the absence of comprehensive legislation.
Global regulatory response. Google Street View's Wi-Fi data collection prompted regulatory investigations and enforcement actions across Europe, Canada, Australia, and other jurisdictions, illustrating the global nature of data privacy enforcement and the challenges of cross-jurisdictional coordination.

---

### Case 2.20: Viacom International Inc. v. YouTube, Inc. (2010) — US District Court

**Date Decided:** 23 June 2010 (summary judgment); 18 April 2012 (Second Circuit appeal); settled 2014

**Court:** United States District Court for the Southern District of New York, Case No. 07-cv-02103-LLS; affirmed in part, vacated in part by the Second Circuit

**Facts:** Viacom filed a $1 billion copyright infringement lawsuit against YouTube in 2007, alleging that YouTube had built its business on the unauthorized distribution of Viacom's copyrighted content. As part of the litigation, Viacom sought extensive discovery into YouTube's user data, including the viewing histories of individual YouTube users — essentially asking the court to compel the disclosure of detailed logs showing every video watched by every YouTube user during a specified period. Google (YouTube's parent company) initially resisted but eventually agreed to produce anonymized viewing data. The case raised significant privacy concerns about the scope of electronic discovery in intellectual property litigation and the protection of user data in the context of legal proceedings.

**Issue:** Whether Viacom's request for YouTube user viewing logs was permissible under applicable privacy laws and court discovery rules, and whether the disclosure of such data would violate users' privacy rights and federal electronic privacy statutes (including the VPPA and the SCA).

**Holding:** The District Court initially ordered Google to produce a massive dataset of user viewing logs (over 12 terabytes), but subsequently modified the order to require anonymization of user identifiers (replacing YouTube usernames and IP addresses with random strings) before disclosure. The Court of Appeals for the Second Circuit vacated the District Court's grant of summary judgment on the copyright claims but did not directly address the privacy issues, which were resolved by the parties' agreement to anonymize the data. The case ultimately settled in 2014.
**Significance:** Privacy in electronic discovery. The case established important precedents regarding the limits of electronic discovery in civil litigation, particularly the requirement to balance litigants' discovery rights against the privacy interests of non-party users whose data is held by the litigating parties.
Anonymization as a protective measure. The requirement to anonymize user data before disclosure established anonymization as a judicially recognized protective measure in litigation, anticipating later data protection frameworks that rely on pseudonymization and anonymization as risk mitigation tools.
User data as corporate asset and liability. The case highlighted the dual nature of user data as both a valuable corporate asset (providing insights for platform development) and a significant legal liability (subject to disclosure obligations and regulatory scrutiny).

---

### Case 2.21: Office of the Privacy Commissioner of Canada v. Facebook Inc. (DPPC Investigation) (2019) — Privacy Commissioner of Canada

**Date Decided:** 28 May 2019

**Court:** Office of the Privacy Commissioner of Canada (OPC), Investigation Report under PIPEDA
Case citation: OPC Investigation Report PBC 2019-001

**Facts:** Following the Cambridge Analytica revelations, the Office of the Privacy Commissioner of Canada, together with the Office of the Information and Privacy Commissioner of British Columbia, conducted a comprehensive investigation into Facebook's privacy practices under the Personal Information Protection and Electronic Documents Act (PIPEDA). The investigation found that Facebook had violated PIPEDA in multiple ways: by failing to obtain meaningful consent for the sharing of users' personal information with third-party apps; by providing inadequate controls over app developers' access to user data; by retaining user information beyond what was necessary for the purposes for which it was collected; and by failing to ensure that app developers obtained proper consent from users before accessing their friends' personal information.

**Issue:** Whether Facebook's platform policies, consent mechanisms, and third-party app access controls satisfied the requirements of PIPEDA's Principles, including Knowledge and Consent (Principle 4.3), Limiting Collection (Principle 4.4), Limiting Use, Disclosure, and Retention (Principle 5), and Safeguards (Principle 4.7).

**Holding:** The Privacy Commissioner found that Facebook violated multiple provisions of PIPEDA and recommended that Facebook: obtain meaningful and informed consent for all sharing of personal information; implement stronger controls over third-party app access; ensure that user data shared with apps is deleted when no longer needed; and provide users with clear and accessible tools to manage their privacy settings. Facebook initially refused to implement all recommendations, leading the Commissioner to seek a court order under subsection 18(1) of PIPEDA — the first time the Commissioner had taken this step. The Federal Court of Canada subsequently ruled that the Commissioner had the authority to seek court orders but did not compel Facebook's compliance on all points.
**Significance:** PIPEDA enforcement limitations revealed. The investigation exposed the limitations of PIPEDA's enforcement framework, as the Privacy Commissioner lacked order-making power and had to resort to the courts for enforcement, highlighting the need for stronger regulatory authority.
Meaningful consent standard in Canada. The investigation established a high standard for "meaningful consent" under PIPEDA, requiring that consent be informed, voluntary, and specific to the particular use or disclosure of personal information.
Catalyst for legislative reform. The investigation contributed to the momentum for legislative reform that eventually led to the enactment of the Consumer Privacy Protection Act (CPPA) as part of Bill C-27, which proposed order-making powers for the Privacy Commissioner and stronger consent requirements.

---

### Case 2.22: Office of the Privacy Commissioner of Canada v. Clearview AI Inc. (2021) — Privacy Commissioner of Canada

**Date Decided:** 3 February 2021

**Court:** Office of the Privacy Commissioner of Canada (OPC), Investigation Report under PIPEDA; Joint Investigation with provincial counterparts
Case citation: OPC Investigation Report PBC 2021-001

**Facts:** Clearview AI had scraped billions of images from social media platforms and public websites worldwide to build a facial recognition database used primarily by law enforcement agencies. Canadian citizens' facial images were included without their knowledge or consent. Following media reports, the Office of the Privacy Commissioner of Canada, together with the Information and Privacy Commissioners of Alberta and British Columbia, initiated a joint investigation under PIPEDA and equivalent provincial legislation. Clearview AI provided limited cooperation with the investigation and argued that its activities were protected by the First Amendment (US) and that publicly available images were not subject to privacy protection.

**Issue:** Whether Clearview AI's collection, use, and disclosure of facial images of Canadian citizens scraped from public websites violated PIPEDA's requirements for consent, lawful purpose, and proportionality.

**Holding:** The investigators found that Clearview AI violated Canadian privacy law by: collecting personal information without consent; using personal information for purposes not disclosed to data subjects; retaining personal information indefinitely; and failing to provide individuals with access to their personal information. The investigators recommended that Clearview AI cease offering its services in Canada, delete all images and biometric templates of Canadian citizens, and implement a compliance program. Clearview AI declined to implement the recommendations, stating that it did not operate in Canada and was not subject to Canadian law.
**Significance:** Facial recognition and biometric privacy in Canada. The investigation established that the mass collection of facial images for biometric identification purposes violates Canadian privacy law, even when the images are sourced from publicly accessible websites.
Enforcement challenges against foreign entities. Clearview AI's refusal to comply with the recommendations highlighted the practical difficulties of enforcing Canadian privacy law against foreign entities with no Canadian presence, paralleling similar challenges faced by EU regulators.
Convergence with international regulatory approaches. The investigation reflected a global regulatory consensus that mass facial recognition databases built from scraped data are unlawful, consistent with enforcement actions by the CNIL (France), the Italian Garante, the UK ICO, and the Australian Information Commissioner.

---

### Case 2.23: Rogers Communications Inc. Data Breach — OPC Investigation (2019) — Privacy Commissioner of Canada

**Date Decided:** 31 October 2019

**Court:** Office of the Privacy Commissioner of Canada (OPC), Investigation Report under PIPEDA
Case citation: OPC Investigation Report PBC 2019-008

**Facts:** In April 2019, Rogers Communications, Canada's largest telecommunications provider, disclosed that a misconfigured database had exposed the personal information of approximately 150,000 current and former customers. The exposed data included names, email addresses, account numbers, and in some cases login credentials. The breach was discovered by a third-party security researcher who notified Rogers, rather than by Rogers' own security monitoring systems. The OPC investigated whether Rogers had implemented adequate security safeguards under PIPEDA and whether the company had complied with its breach notification obligations.

**Issue:** Whether Rogers' failure to properly secure customer data (through misconfigured database settings) violated PIPEDA's safeguard requirements (Principle 4.7), and whether Rogers' breach response and notification practices complied with Canada's Breach of Security Safeguards Regulations (BSSR).

**Holding:** The Privacy Commissioner found that Rogers had failed to implement adequate security safeguards, as the database misconfiguration was a basic security error that should have been detected through routine security testing. The Commissioner also found that Rogers' breach notification was delayed and incomplete. The Commissioner recommended that Rogers implement more rigorous security testing protocols, including automated vulnerability scanning and penetration testing, improve its breach detection capabilities, and enhance its breach notification procedures. Rogers accepted the recommendations and implemented the suggested changes.
**Significance:** Safeguard obligations for telecommunications providers. The investigation established heightened expectations for security safeguards in the telecommunications sector, given the sensitivity and volume of personal data handled by carriers.
Proactive breach detection required. The finding that the breach was discovered by a third-party researcher rather than Rogers' own systems reinforced the expectation that organizations must implement proactive breach detection capabilities, not merely reactive response plans.
Third-party research as enforcement catalyst. The case illustrated the growing role of independent security researchers in identifying and reporting data breaches, and the regulatory implications of relying on external parties for breach detection.

---

### Case 2.24: Australian Information Commissioner v. Facebook Inc. (2022) — Federal Court of Australia

**Date Decided:** 8 March 2022 (judgment); appealed and upheld on modified grounds

**Court:** Federal Court of Australia, Case No. VID 694/2020

**Facts:** Following the Cambridge Analytica revelations, the Australian Information Commissioner (OAIC) initiated proceedings against Facebook Inc. under the Privacy Act 1988 (Cth). The OAIC alleged that Facebook had committed serious and/or repeated interferences with the privacy of approximately 311,127 Australian users by disclosing their personal information to the This Is Your Digital Life (TIYDL) app and subsequently to Cambridge Analytica and other third parties, without adequate consent. The OAIC argued that Facebook had failed to take reasonable steps to ensure that the TIYDL app did not collect or disclose users' personal information beyond what was necessary for the app's stated purpose, and that Facebook had failed to take reasonable steps to ensure that users were adequately informed about the data collection and sharing practices.

**Issue:** Whether Facebook committed "serious or repeated interferences with the privacy of individuals" under section 13G of the Privacy Act 1988 (Cth), and whether Facebook failed to take reasonable steps to protect the personal information of Australian users under the Australian Privacy Principles.

**Holding:** The Federal Court found that Facebook had committed serious interferences with the privacy of Australian users, holding that Facebook's platform design and API permissions enabled the unauthorized collection and disclosure of users' personal information. However, the Court found that the evidence did not establish that Facebook's conduct constituted "repeated" interferences, as required for the application of the enhanced penalty provisions. The Court ordered Facebook to pay a penalty of AUD 50 million (approximately USD 33 million), and to undertake specific compliance measures including enhanced app review processes, improved consent mechanisms, and regular privacy impact assessments. The decision was subsequently modified on appeal, with the Full Court upholding the finding of serious interference but varying the penalty calculation.
**Significance:** First major Privacy Act enforcement against a global platform. The case represented the first significant enforcement action by the OAIC against a major global technology company under the Privacy Act 1988, establishing the regulator's willingness to pursue litigation against multinational entities.
"Serious interference" standard defined. The Federal Court's interpretation of "serious interference with privacy" under section 13G of the Privacy Act provided important guidance on the scope and application of Australia's civil penalty regime for privacy violations.
Platform accountability under Australian law. The decision established that Australian privacy law can reach the conduct of global social media platforms, including their platform design decisions and API governance, reinforcing the extraterritorial reach of Australian privacy regulation.

---

### Case 2.25: OAIC v. Telstra Corporation Limited (2017) — Australian Information Commissioner

**Date Decided:** 13 April 2017 (determination); Federal Court enforcement proceedings 2018

**Court:** Office of the Australian Information Commissioner (OAIC); subsequently the Federal Court of Australia

**Facts:** In 2015, Telstra Corporation, Australia's largest telecommunications provider, experienced data breaches involving the exposure of customer information through several channels, including a compromised Telstra account management portal and the inadvertent disclosure of customer data through printed directories. The OAIC investigated under the Privacy Act 1988 and found that Telstra had failed to take reasonable steps to secure customer personal information, including by maintaining outdated IT systems, failing to implement adequate access controls, and retaining customer data beyond the period necessary for the purposes of collection. The OAIC also found that Telstra had failed to adequately respond to customer complaints about the data breaches.

**Issue:** Whether Telstra failed to take reasonable steps to protect the personal information of its customers under the Australian Privacy Principles (APPs), particularly APP 11 (Security of Personal Information), and whether Telstra failed to implement adequate data retention and complaint-handling practices under APP 10 (Quality of Personal Information) and APP 12 (Access to Personal Information).

**Holding:** The OAIC found that Telstra had interfered with the privacy of its customers by failing to take reasonable steps to protect their personal information. The Commissioner accepted a court-enforceable undertaking from Telstra, under which Telstra committed to: implement a comprehensive information security program; conduct regular privacy impact assessments; improve data retention practices; enhance breach detection and response capabilities; and provide regular reports to the OAIC on its privacy compliance. The enforceable undertaking was the first of its kind accepted by the OAIC from a major telecommunications provider.
**Significance:** Enforceable undertaking as a compliance tool. The use of a court-enforceable undertaking rather than monetary penalties demonstrated the OAIC's preference for cooperative compliance mechanisms, while still achieving binding outcomes.
Data retention obligations. The case reinforced the requirement for organizations to limit the retention of personal information to what is necessary, establishing that indefinite retention of customer data constitutes a privacy violation.
Telecommunications sector standards. The case set expectations for information security practices in the Australian telecommunications sector, contributing to the development of industry-wide security standards and benchmarks.

---

### Case 2.26: Personal Information Protection Commission v. LINE Corp. (2021) — Japan PPC

**Date Decided:** 27 October 2021

**Court:** Personal Information Protection Commission (PPC), Japan — Administrative Enforcement Action
Case citation: PPC Enforcement Order No. 2021-LINE-001

**Facts:** LINE Corporation, operator of Japan's most widely used messaging application with approximately 86 million domestic users, disclosed in March 2021 that it had permitted Chinese affiliate companies (and a Korean affiliate) to access the personal data of Japanese users without proper authorization or adequate safeguards. The data access included the ability to read user messages, view friend lists, and access other personal information stored on LINE's servers. The revelation was particularly sensitive in Japan given the large volume of personal and often intimate communications transmitted through the LINE platform and the growing public concern about cross-border data transfers to China. The PPC investigated and found that LINE had failed to implement adequate access controls, had not conducted proper data transfer impact assessments, and had not obtained user consent for the cross-border data access.

**Issue:** Whether LINE's disclosure of Japanese users' personal data to Chinese and Korean affiliate companies without adequate safeguards violated Japan's Act on the Protection of Personal Information (APPI), particularly the requirements for cross-border data transfer (Article 28 as amended in 2020) and the obligation to implement necessary and appropriate security measures (Article 23).

**Holding:** The PPC issued a compliance order requiring LINE to: immediately cease the unauthorized cross-border data access; implement comprehensive access controls and audit mechanisms; conduct privacy impact assessments for all cross-border data transfers; notify affected users; and submit regular compliance reports to the PPC. The PPC also publicly reprimanded LINE, and the company's CEO publicly apologized. LINE subsequently announced the construction of a new domestic data center to house all Japanese users' data within Japan.
**Significance:** Cross-border data transfer enforcement in Japan. This was the first major enforcement action under Japan's amended APPI provisions on cross-border data transfers, establishing the PPC's willingness to enforce the new requirements against major domestic technology companies.
Public trust and messaging platform data. The case had significant public impact in Japan, where LINE is the dominant messaging platform and is used for both personal and professional communications, highlighting the unique sensitivity of messaging platform data.
Data localization as a compliance response. LINE's decision to build a domestic data center illustrated how regulatory enforcement can drive data localization, even in the absence of explicit localization mandates.

---

### Case 2.27: Yahoo Japan Corporation — Data Breach and Administrative Enforcement (2019) — Japan PPC

**Date Decided:** February 2019

**Court:** Personal Information Protection Commission (PPC), Japan — Administrative Enforcement Action
Case citation: PPC Enforcement Order No. 2019-YAH-001

**Facts:** Yahoo Japan Corporation, Japan's largest web portal and search engine operator, disclosed that it had suffered a data breach affecting approximately 22 million user accounts. The breach resulted from unauthorized access to Yahoo Japan's systems through compromised administrator credentials, which allowed attackers to access users' email addresses, telephone numbers, and other personal information. The PPC investigated and found that Yahoo Japan had failed to implement adequate security measures, including insufficient access controls for administrative accounts, lack of multi-factor authentication, and inadequate monitoring of system access logs. The PPC also found that Yahoo Japan's breach notification was delayed and incomplete.

**Issue:** Whether Yahoo Japan's security measures satisfied the requirements of the APPI's obligation to take necessary and appropriate measures for the prevention of leaks (Article 23), and whether Yahoo Japan's breach notification practices complied with the APPI's breach reporting requirements.

**Holding:** The PPC issued a compliance order requiring Yahoo Japan to: implement multi-factor authentication for all administrative accounts; enhance access controls and monitoring; conduct regular penetration testing; improve breach detection and notification procedures; and submit regular security audit reports to the PPC. Yahoo Japan accepted the order and implemented the required measures.
**Significance:** Administrative security standards. The enforcement action established concrete expectations for cybersecurity measures under the APPI, including specific technical requirements such as multi-factor authentication and access monitoring.
Large-scale breach response standards. The case contributed to the development of breach response best practices in Japan, including expectations for timely notification and comprehensive remediation.
Continuing evolution of APPI enforcement. The case demonstrated the PPC's growing enforcement capacity and its willingness to hold major technology companies accountable for security failures, building on the foundation established by earlier enforcement actions.

---

### Case 2.28: K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of India

**Date Decided:** 24 August 2017

**Court:** Supreme Court of India, Writ Petition (Civil) No. 494 of 2012
Case citation: (2017) 10 SCC 1

**Facts:** Justice K.S. Puttaswamy, a retired judge of the Karnataka High Court, challenged the constitutional validity of the Aadhaar biometric identification system, which required Indian residents to provide fingerprints and iris scans to obtain a unique identification number. The petitioners argued that the mandatory collection and storage of biometric data violated the right to privacy under the Constitution of India. The case was heard by a nine-judge bench of the Supreme Court — the largest bench assembled for a privacy case in India — and required the Court to determine whether the right to privacy was a fundamental right under the Indian Constitution.

**Issue:** Whether the right to privacy is a fundamental right protected under the Constitution of India, and whether the Aadhaar scheme's mandatory biometric data collection was constitutional.

**Holding:** The Supreme Court unanimously held that the right to privacy is a fundamental right under Article 21 (Right to Life and Personal Liberty) of the Constitution of India. The Court found that privacy is an intrinsic part of the right to life, liberty, and freedom, and that it is not merely a common law right but a constitutional right subject to restrictions that must pass the test of proportionality and legality. However, the Court upheld the constitutionality of the Aadhaar scheme with certain modifications, finding that the benefits of the scheme (targeted delivery of subsidies and services) outweighed the privacy concerns, subject to enhanced data protection safeguards and restrictions on the use of Aadhaar data by private entities.
**Significance:** Constitutional recognition of privacy in India. The decision was a landmark moment in Indian constitutional law, establishing the right to privacy as a fundamental right for the first time, with implications extending far beyond the Aadhaar scheme to all areas of Indian law involving personal data.
Foundation for India's data protection framework. The Puttaswamy judgment directly catalyzed the development of India's comprehensive data protection legislation, including the Digital Personal Data Protection Act 2023 (DPDPA), which drew heavily on the Court's constitutional reasoning and proportionality framework.
Global influence on privacy as a fundamental right. The decision contributed to the growing global consensus that the right to privacy is a fundamental right, alongside similar rulings in other jurisdictions and the growing recognition of data protection as a human right under international law.

---

### Case 2.29: WhatsApp/Facebook Data Sharing — Legal Challenges in India (2019–2021) — Delhi High Court / Supreme Court of India

**Date Decided:** Various proceedings 2019–2021; Delhi High Court order 2019; Supreme Court refusal to stay 2021

**Court:** Delhi High Court; Supreme Court of India; Telecom Regulatory Authority of India (TRAI)
Case citation: Karmanya Singh Sareen v. Union of India, WP(C) 9655/2018 (Delhi High Court)

**Facts:** Following Facebook's 2014 acquisition of WhatsApp, WhatsApp announced in 2016 that it would begin sharing user data (including phone numbers, device identifiers, and usage metadata) with Facebook and its affiliated companies for targeted advertising and business analytics purposes. Indian users, who constituted WhatsApp's largest market (with over 200 million users), were not offered an opt-out from the data sharing, and the linking of WhatsApp and Facebook accounts was presented as a default rather than a choice. Multiple legal challenges were filed in India arguing that the mandatory data sharing violated the right to privacy established in Puttaswamy, the Information Technology Act 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011.

**Issue:** Whether WhatsApp's mandatory sharing of Indian users' personal data with Facebook violated the constitutional right to privacy, the IT Act 2000, and the SPDI Rules 2011, and whether users could be denied access to WhatsApp services for declining to consent to data sharing.

**Holding:** The Delhi High Court declined to grant an interim injunction against the data sharing, finding that the petitioners had not established irreparable harm sufficient to justify an emergency order. The Court noted the complexities of balancing privacy rights with the legitimate interests of businesses and the regulatory challenges posed by the absence of comprehensive data protection legislation. The Supreme Court declined to stay the data sharing, noting that comprehensive data protection legislation was under development. The case ultimately became moot following the enactment of the Digital Personal Data Protection Act 2023, which introduced new consent requirements and cross-border data transfer rules applicable to WhatsApp/Facebook operations in India.
**Significance:** Gaps in India's pre-DPDPA legal framework. The litigation exposed the limitations of India's existing data protection framework (the IT Act 2000 and SPDI Rules 2011) in addressing the challenges posed by global technology platforms, highlighting the urgent need for comprehensive legislation.
Consent and access to services. The case raised fundamental questions about the validity of consent obtained as a condition of access to essential digital services, foreshadowing the consent-or-pay debates in the EU and other jurisdictions.
Regulatory capacity challenges. The case illustrated the challenges faced by developing country regulators in enforcing privacy rules against global technology companies with significantly greater resources and legal capacity.

---

### Case 2.30: Personal Information Protection Commission v. Kakao Corp. (2022) — Korea PIPC

**Date Decided:** 15 September 2022

**Court:** Personal Information Protection Commission (PIPC), Republic of Korea — Administrative Enforcement Action
Case citation: PIPC Decision No. 2022-KAKAO-001

**Facts:** Kakao Corporation, operator of South Korea's dominant messaging platform (KakaoTalk with approximately 47 million domestic users), was found to have transferred Korean users' personal data to third-party advertising partners without obtaining proper consent, and to have provided inadequate information about its data processing practices. The PIPC investigation revealed that Kakao had shared user data — including device identifiers, usage patterns, and in some cases location data — with approximately 200 third-party advertising partners, many of which were located outside Korea, without conducting proper privacy impact assessments or obtaining the explicit consent required under the Personal Information Protection Act (PIPA). The investigation also revealed that Kakao's privacy notices were insufficient to inform users about the scope and nature of third-party data sharing.

**Issue:** Whether Kakao's sharing of user data with third-party advertising partners, including cross-border transfers, without proper consent and privacy impact assessments violated South Korea's PIPA, particularly Articles 15 (Consent), 17 (Provision of Personal Information to Third Parties), and 28 (Cross-Border Transfer).

**Holding:** The PIPC imposed a fine of approximately KRW 3.075 billion (approximately USD 2.4 million) and issued a corrective order requiring Kakao to: obtain explicit consent for all third-party data sharing; conduct privacy impact assessments for all cross-border transfers; enhance transparency in privacy notices; implement stricter access controls for third-party partners; and establish a comprehensive data protection governance framework.
**Significance:** Enhanced consent requirements in Korea. The enforcement action reinforced South Korea's strict consent requirements for third-party data sharing, particularly for advertising purposes, establishing expectations that consent must be specific, informed, and freely given.
Cross-border transfer accountability. The case established that Korean companies sharing data with international advertising networks must conduct privacy impact assessments and implement safeguards equivalent to those required by the GDPR, reflecting Korea's status as a country with adequacy recognition from the EU.
Messaging platform accountability in Asia. The case, alongside the LINE enforcement in Japan, established a pattern of regulatory scrutiny for messaging platforms across East Asia, reflecting the unique privacy risks associated with platforms that handle intimate personal communications.

---

### Case 2.31: Personal Information Protection Commission v. Naver Corporation (2020) — Korea PIPC

**Date Decided:** 28 July 2020

**Court:** Personal Information Protection Commission (PIPC), Republic of Korea — Administrative Enforcement Action
Case citation: PIPC Decision No. 2020-NAVER-001

**Facts:** Naver Corporation, South Korea's largest web portal operator, was investigated by the PIPC following revelations that Naver had permitted employees to access users' personal data — including search queries, browsing histories, and personal communications — without proper authorization and for purposes unrelated to service provision. The investigation also found that Naver had inadequate data retention policies, retaining user data far beyond the period necessary for the purposes for which it was collected, and had failed to properly secure data transferred to third-party cloud service providers. The revelations were particularly damaging in South Korea, where Naver is the dominant search engine and web portal, and where public trust in the platform was already sensitive following previous data security incidents.

**Issue:** Whether Naver's unauthorized employee access to user data, inadequate data retention practices, and insufficient security measures for cross-border data transfers violated South Korea's PIPA.

**Holding:** The PIPC imposed a fine of approximately KRW 1.02 billion (approximately USD 860,000) and issued a corrective order requiring Naver to: implement strict access controls limiting employee access to user data; establish data retention and deletion schedules; conduct regular security audits; implement encryption for sensitive user data; and establish an independent data protection oversight function. Naver accepted the order and implemented the required measures, including the appointment of a Chief Privacy Officer.
**Significance:** Internal access controls as a compliance requirement. The case established clear expectations for internal data access controls in Korea, requiring organizations to implement the principle of least privilege and to monitor employee access to personal data.
Data retention limits. The enforcement action reinforced PIPA's requirements for data retention limitation, establishing that indefinite retention of user data without a legitimate purpose constitutes a violation.
Search engine accountability. The case set standards for search engine data protection in Korea, particularly regarding the sensitivity of search query data and the heightened protections required for such information.

---

### Case 2.32: Shanghai Ctrip Computer Technology Co. — PIPL Administrative Penalty (2023) — Shanghai Municipal CAC

**Date Decided:** 12 June 2023

**Court:** Shanghai Municipal Administration of Cyberspace (CAC Shanghai), Administrative Penalty Decision
Case citation: Shanghai CAC Administrative Penalty Decision No. 2023-CT-001

**Facts:** Ctrip (), China's largest online travel agency, was investigated by the Shanghai Municipal Administration of Cyberspace following complaints that Ctrip had been processing users' personal information — including real names, identification numbers, travel itineraries, hotel bookings, flight records, and payment information — without obtaining proper consent, and had failed to implement adequate security measures. The investigation found that Ctrip had collected excessive personal information beyond what was necessary for its travel booking services, had not provided users with meaningful choices regarding data processing, had transferred personal data to third-party service providers without conducting security assessments, and had retained personal data beyond the period necessary for the stated purposes.

**Issue:** Whether Ctrip's collection of excessive personal information, failure to obtain proper consent, inadequate security measures, and failure to conduct security assessments for cross-border and third-party data transfers violated the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL).

**Holding:** CAC Shanghai imposed an administrative fine of RMB 400,000 (approximately EUR 52,000) and issued a corrective order requiring Ctrip to: conduct a comprehensive audit of its personal information processing activities; delete personal information collected without proper consent or retained beyond necessary periods; implement enhanced security measures; conduct personal information protection impact assessments for all new processing activities; and establish a comprehensive personal information protection management system. Ctrip was also required to designate a personal information protection officer and to report compliance progress to CAC Shanghai.
**Significance:** Early PIPL enforcement against a major platform. The case was one of the first significant administrative enforcement actions under the PIPL against a major Chinese technology company, demonstrating the CAC's willingness to enforce the new legislation.
Data minimization enforcement. The case established that the PIPL's data minimization principle is enforceable in practice, requiring companies to limit their collection of personal information to what is strictly necessary for the stated purpose.
Travel data as sensitive information. The case highlighted the particular sensitivity of travel-related personal data, which can reveal detailed information about an individual's movements, associations, and lifestyle, and the heightened protection obligations that apply to such data.

---

### Case 2.33: Beijing Bytedance Technology Co. — PIPL Administrative Enforcement (2023) — Beijing Municipal CAC

**Date Decided:** 3 August 2023

**Court:** Beijing Municipal Administration of Cyberspace (CAC Beijing), Administrative Penalty Decision
Case citation: Beijing CAC Administrative Penalty Decision No. 2023-BDT-001

**Facts:** ByteDance (), the Chinese parent company of TikTok (internationally) and Douyin (domestically), was investigated by the Beijing Municipal Administration of Cyberspace following reports that its domestic applications had been processing users' personal information, particularly that of minors, without obtaining proper consent. The investigation found that ByteDance's applications had collected biometric data (including facial features for beauty filters), location data, and behavioral data without separate consent as required by the PIPL for sensitive personal information. The investigation also found that ByteDance had transferred personal data to third-party SDKs (software development kits) embedded in its applications without proper security assessments, and had failed to implement adequate parental consent mechanisms for the processing of minors' data.

**Issue:** Whether ByteDance's collection of biometric and other sensitive personal information without separate consent, failure to obtain parental consent for minors' data processing, and failure to conduct security assessments for third-party SDK data transfers violated the PIPL.

**Holding:** CAC Beijing imposed an administrative fine of RMB 500,000 (approximately EUR 65,000) and issued a corrective order requiring ByteDance to: obtain separate consent for the processing of sensitive personal information including biometric data; implement robust parental consent mechanisms for minors; conduct security assessments for all third-party SDK data transfers; provide transparent information to users about data processing activities through its applications; and establish a comprehensive minor protection program. ByteDance was also required to designate a personal information protection officer and submit regular compliance reports.
**Significance:** SDK governance under PIPL. The case was one of the first to address the data protection implications of third-party SDKs embedded in mobile applications, establishing expectations for data transfer security assessments in the SDK context.
Minor data protection enforcement. The case reinforced the PIPL's heightened protections for minors' personal information, requiring parental consent and age-appropriate design for applications accessible to children.
Biometric data in beauty filters. The case highlighted the privacy implications of biometric data collection through seemingly innocuous features like beauty filters, establishing that such data processing requires the same level of consent and protection as other biometric processing activities.

---

### Case 2.34: In re: Experian Data Breach Litigation (2015) — US District Court

**Date Decided:** 2015–2016; litigation settled

**Court:** United States District Court for the Southern District of Indiana, Case No. 1:15-md-02737-SEB-MPB

**Facts:** In 2015, Experian, one of the three largest consumer credit reporting agencies in the United States, disclosed that a data breach had exposed the personal information of approximately 15 million T-Mobile customers who had applied for T-Mobile services. The breach exploited a vulnerability in Experian's data processing systems, which had been entrusted with T-Mobile's applicant data. The stolen information included names, dates of birth, addresses, Social Security numbers, driver's license numbers, and passport numbers. The breach was particularly significant because it occurred through a third-party data processor, raising questions about the adequacy of security requirements imposed on data processing vendors and the liability allocation between data controllers and processors.

**Issue:** Whether Experian's failure to secure T-Mobile customer data entrusted to it as a third-party data processor constituted negligence and unfair business practices, and whether Experian's contractual obligations to T-Mobile extended to direct liability to affected consumers.

**Holding:** Experian agreed to a settlement providing affected consumers with two years of free credit monitoring and identity theft protection services, as well as compensation for out-of-pocket losses resulting from the breach. T-Mobile separately reached a settlement with affected customers. The case did not result in a judicial determination on the merits, as the parties settled before trial. However, the litigation contributed to increased regulatory scrutiny of data processor security obligations.
**Significance:** Data processor accountability. The case highlighted the risks associated with entrusting sensitive personal data to third-party processors and contributed to the development of contractual and regulatory expectations for data processor security.
Vendor management as a data protection obligation. The breach underscored the importance of vendor risk management and due diligence in data protection compliance, anticipating the GDPR's detailed requirements for data processor agreements (Article 28).
Credit bureau security standards. The case, alongside the Equifax breach, established a pattern of security failures at major credit reporting agencies, contributing to regulatory and legislative efforts to impose enhanced security obligations on the credit reporting industry.

---

### Case 2.35: NHS Digital Data Breach — Investigation and Remediation (2021) — ICO

**Date Decided:** 7 October 2021 (ICO enforcement notice)

**Court:** Information Commissioner's Office (ICO), United Kingdom — Regulatory Enforcement
Case citation: ICO Enforcement Notice EN/2021/0001

**Facts:** NHS Digital, the national provider of health IT infrastructure and data services for the National Health Service in England, experienced a data protection incident involving the exposure of patient data through a misconfigured test environment. The incident involved the inadvertent publication of data relating to approximately 1,500 patients, including names, dates of birth, NHS numbers, and in some cases clinical information. The ICO investigated and found that NHS Digital had failed to implement adequate technical and organizational measures to prevent the unauthorized disclosure of patient data, including inadequate segregation between test and production environments, insufficient access controls, and a lack of routine security audits for test environments. The investigation was conducted against the backdrop of the COVID-19 pandemic, during which NHS Digital had been rapidly deploying new data systems to support pandemic response efforts.

**Issue:** Whether NHS Digital's failure to implement adequate technical and organizational measures to protect patient data, particularly in test environments, violated the UK GDPR's security obligations (Article 32) and the common law duty of confidentiality owed to patients.

**Holding:** The ICO issued an enforcement notice requiring NHS Digital to: implement comprehensive security measures for all environments processing patient data, including test environments; conduct regular security audits and penetration testing; establish data protection impact assessments for all new data processing activities; implement strict access controls based on the principle of least privilege; and report compliance progress to the ICO within specified timelines. The ICO did not impose a monetary penalty, taking into account the exceptional circumstances of the pandemic and NHS Digital's cooperation with the investigation.
**Significance:** Healthcare data protection standards. The case reinforced the heightened security obligations applicable to healthcare data, which is classified as special category data under Article 9 of the GDPR and subject to the common law duty of confidentiality.
Test environment security. The case highlighted the often-overlooked security risks associated with test environments and development databases, which frequently contain copies of production data and may be subject to weaker security controls.
Proportionality in enforcement during crises. The ICO's decision not to impose a monetary penalty in light of the pandemic circumstances demonstrated a pragmatic approach to enforcement proportionality, while still requiring remedial action.

---

### Case 2.36: Meta Ireland Repeated GDPR Violations (2023–2025) — Irish Data Protection Commission

**Date Decided:** Multiple decisions: May 2023, January 2024, September 2024, ongoing through 2025

**Court:** Irish Data Protection Commission (DPC) / European Data Protection Board (EDPB)

**Facts:** Between 2023 and 2025, Meta Platforms Ireland Ltd. faced a series of enforcement actions by the Irish DPC for repeated and systematic violations of the GDPR. The most significant included: (1) a 1.2 billion fine in May 2023 for unlawful transfer of EU personal data to the United States following the Schrems II ruling (the largest GDPR fine to date); (2) a 390 million fine in January 2023 for using personal data for behavioral advertising without a valid legal basis, including for users who had not consented and for children under 18; (3) a 91 million fine in September 2024 for storing user passwords in plaintext; and (4) ongoing proceedings concerning Meta's use of artificial intelligence models trained on EU user data. The EDPB was repeatedly invoked to resolve disputes between the DPC and concerned supervisory authorities from other EU member states, with the EDPB consistently adopting positions more favorable to data subjects than the DPC's draft decisions.

**Issue:** Whether Meta's processing of personal data for behavioral advertising, its continued data transfers to the US post-Schrems II, its inadequate security practices (including plaintext password storage), and its use of user data to train AI models constituted systematic and repeated GDPR violations warranting substantial corrective measures.

**Holding:** The DPC imposed cumulative fines exceeding 1.7 billion and ordered Meta to: suspend future transfers of EU personal data to the US (pending implementation of the EU-US Data Privacy Framework or alternative transfer mechanisms); cease processing personal data for behavioral advertising without a valid legal basis; implement end-to-end encryption for stored passwords; and conduct data protection impact assessments for all AI training activities. The EDPB's binding decisions under Article 65 GDPR overrode several of the DPC's more lenient draft positions, resulting in significantly higher fines and more stringent remedial orders.
**Significance:** Scope of cross-border enforcement cooperation. The case demonstrated the critical role of the EDPB's dispute resolution mechanism under Article 65 GDPR, revealing a persistent tension between the lead supervisory authority (Ireland's DPC) and concerned authorities in other member states. The EDPB's repeated intervention to increase fines and broaden corrective measures highlighted the structural challenges of the one-stop-shop mechanism.
Behavioral advertising under GDPR. The case established that reliance on "contractual necessity" (Article 6(1)(b) GDPR) as a legal basis for behavioral advertising is insufficient, requiring Meta to obtain explicit consent from users across the EEA — a ruling with profound implications for the entire digital advertising ecosystem.
Data transfer compliance after the Data Privacy Framework. The 1.2 billion fine, while subsequently partially addressed by the adoption of the EU-US Data Privacy Framework in July 2023, underscored that past unlawful transfers remain subject to enforcement and that companies must implement supplementary measures to ensure the adequacy of protection in practice.

---

### Case 2.37: Apple 25 Million GDPR Fine — Ireland DPC (2024)

**Date Decided:** 24 January 2024

**Court:** Irish Data Protection Commission (DPC)

**Facts:** The Irish DPC concluded a cross-border investigation into Apple Distribution International Ltd.'s compliance with the GDPR's transparency and lawful processing requirements. The investigation, initiated following complaints by European consumer organizations, focused on Apple's collection and use of personal data through its App Store and Apple ID ecosystem. The DPC found that Apple had failed to provide users with sufficiently clear and comprehensive information about how their personal data was processed, particularly with respect to data used for personalization, product improvement, and security purposes. Apple had relied on overly broad privacy notices and buried critical processing activities within lengthy terms of service that users were unlikely to read or understand. The DPC also found deficiencies in Apple's consent mechanisms for certain optional data processing activities, including diagnostic and analytics data collection.

**Issue:** Whether Apple's privacy notices and consent mechanisms satisfied the GDPR's requirements for transparency (Articles 13 and 14), clear and plain language (Recital 39), and freely given, specific, informed, and unambiguous consent (Article 4(11) and Article 7).

**Holding:** The DPC imposed a 25 million administrative fine and issued a reprimand requiring Apple to: revise its privacy notices to ensure that processing activities are described in clear, plain language organized in a layered, easily accessible format; implement enhanced consent mechanisms with separate granular opt-in controls for each distinct processing purpose; conduct and publish data protection impact assessments for its analytics and personalization activities; and submit compliance reports to the DPC for a period of two years.
**Significance:** Transparency obligations for platform ecosystems. The case reinforced that large technology platforms operating complex ecosystems of services cannot rely on monolithic privacy policies as compliance tools. The requirement for layered, purpose-specific transparency measures has become a benchmark expectation for platform regulators.
Consent granularity. The decision contributed to the evolving standard that consent must be obtained through granular, purpose-specific mechanisms — not bundled or blanket consent — particularly where optional data processing is concerned.
Proportionality of fines. The 25 million fine, while substantial, was considered moderate relative to Apple's global revenue and reflected the DPC's approach of calibrating penalties to the specific nature and severity of the violations rather than imposing maximum theoretical penalties.

---

### Case 2.38: TikTok Derogatory Data — Polish DPA Fine (2024)

**Date Decided:** 15 March 2024

**Court:** Polish Data Protection Authority (UODO — Urz d Ochrony Danych Osobowych)

**Facts:** The Polish Data Protection Authority (UODO) investigated TikTok (operated by ByteDance) following complaints that the platform had published user-created content containing derogatory personal data about identifiable individuals, including defamatory statements, manipulated images, and personal information such as home addresses and telephone numbers. The UODO found that TikTok's content moderation systems were inadequate to detect and remove content containing sensitive personal data and that the platform's reporting mechanisms were not sufficiently accessible or responsive. The investigation also examined TikTok's algorithmic recommendation system, which amplified the reach of content containing personal data violations, thereby exacerbating the harm to affected data subjects. The UODO determined that TikTok had failed to implement appropriate technical and organizational measures to prevent the unlawful processing of personal data by its users and had not responded adequately to removal requests from affected individuals.

**Issue:** Whether TikTok, as a data controller, bore responsibility under the GDPR for user-generated content containing derogatory personal data, and whether its content moderation and complaint-handling systems satisfied the obligations under Articles 17 (right to erasure) and 32 (security of processing).

**Holding:** The UODO imposed an administrative fine and issued a corrective order requiring TikTok to: implement enhanced automated content moderation systems capable of detecting personal data in user-generated content; establish expedited procedures for processing erasure requests related to personal data published by third parties; provide affected individuals with clear and accessible mechanisms to report content containing their personal data; and conduct regular audits of its recommendation algorithm's role in amplifying content that violates data protection rights.
**Significance:** Platform responsibility for user-generated personal data. The case extended the scope of platform responsibility under the GDPR, establishing that intermediaries cannot rely solely on safe harbor provisions to avoid liability for personal data violations in user-generated content when their systems actively amplify such content.
Algorithmic amplification as a data protection concern. By treating TikTok's recommendation algorithm as a factor exacerbating data protection violations, the UODO established a connection between content moderation, algorithmic design, and GDPR compliance — a nexus that has since been explored by other EU data protection authorities.
Erasure rights in the social media context. The decision clarified the practical application of the right to erasure in the context of personal data published by third parties on social media platforms, reinforcing the obligation of platforms to facilitate effective removal.

---

### Case 2.39: British Airways ICO Fine 20 Million (2020)

**Date Decided:** 16 October 2020

**Court:** Information Commissioner's Office (ICO), United Kingdom
Case citation: ICO Monetary Penalty Notice (MPN) MPS/2019/00067

**Facts:** British Airways (BA) suffered a data breach between June and September 2018, when attackers compromised the airline's website and mobile app by injecting malicious code, redirecting users to a fraudulent page that harvested their personal and payment card data. The breach affected approximately 380,000 payment card transactions and exposed the personal data of around 183,000 customers, including names, addresses, email addresses, credit card numbers, expiration dates, and CVV codes. The ICO investigation found that BA had failed to implement adequate security measures to protect customer data, including insufficient network segmentation, inadequate monitoring of web application traffic, and a failure to apply available security patches. The initial proposed fine was 183.39 million, but this was reduced to 20 million after the ICO took into account the economic impact of the COVID-19 pandemic on the airline industry and BA's cooperation with the investigation.

**Issue:** Whether British Airways's failure to implement appropriate technical and organizational measures to protect personal data against unauthorized processing constituted a breach of the UK GDPR's security obligations under Article 32 and the Data Protection Act 2018.

**Holding:** The ICO issued a monetary penalty notice of 20 million, finding that BA had violated Article 32 of the UK GDPR by failing to implement appropriate security measures. The ICO identified specific deficiencies including inadequate web application firewalls, insufficient patch management, poor network segmentation between the public-facing website and internal payment processing systems, and a lack of timely breach detection. BA was required to implement a comprehensive security remediation program and to report compliance progress to the ICO.
**Significance:** Reduced fine due to COVID-19. The reduction from 183 million to 20 million — representing an 89% decrease — demonstrated the ICO's willingness to consider external economic factors when setting penalties, though critics argued that this undermined the deterrent effect of GDPR-level fines.
Supply chain and web application security. The BA breach highlighted the vulnerability of customer-facing web applications to sophisticated supply chain attacks and underscored the importance of continuous monitoring, patch management, and network segmentation as fundamental security obligations.
Payment card data as personal data. The case confirmed that payment card data (including CVV codes) processed in connection with online transactions constitutes personal data under the GDPR, attracting the full range of data protection obligations.

---

### Case 2.40: Marriott International ICO Fine 18.4 Million (2020)

**Date Decided:** 30 October 2020

**Court:** Information Commissioner's Office (ICO), United Kingdom
Case citation: ICO Monetary Penalty Notice (MPN) MPS/2019/00069

**Facts:** Marriott International disclosed in November 2018 that it had suffered a massive data breach affecting the guest reservation database of its subsidiary Starwood Hotels & Resorts, which Marriott had acquired in 2016. The breach, which had actually begun in 2014 (before Marriott's acquisition of Starwood and before the GDPR took effect), compromised the personal data of approximately 339 million guests worldwide, including approximately 7 million UK residents. Exposed data included names, mailing addresses, phone numbers, email addresses, passport numbers, loyalty account numbers, dates of birth, gender, and travel information. For some guests, encrypted payment card numbers and expiration dates were also compromised. The ICO found that Marriott had failed to conduct adequate due diligence when acquiring Starwood, failing to identify and remediate the significant security vulnerabilities in Starwood's IT systems, and had further failed to implement appropriate security measures after the acquisition.

**Issue:** Whether Marriott's failure to conduct adequate due diligence on Starwood's data protection practices during the acquisition process and its failure to implement adequate security measures post-acquisition constituted a breach of the UK GDPR's security obligations under Article 32 and the principle of accountability under Article 5(2).

**Holding:** The ICO issued a monetary penalty notice of 18.4 million, reduced from the initial proposed fine of approximately 99 million, taking into account the economic impact of COVID-19, Marriott's cooperation, and the fact that some of the underlying security deficiencies predated the GDPR. The ICO found that Marriott had failed to implement appropriate technical and organizational measures and had violated the accountability principle by not conducting adequate due diligence during the Starwood acquisition. Marriott was required to implement a comprehensive security improvement program.
**Significance:** M&A due diligence as a data protection obligation. The case established that data protection due diligence is a legal obligation under the GDPR, not merely a commercial best practice. Acquiring companies bear responsibility for identifying and remediating data protection deficiencies in the target company's systems as part of the merger and acquisition process.
Temporal scope of GDPR enforcement. The ICO's willingness to pursue enforcement action for security failures that began before the GDPR's entry into force (July 2018) but continued afterward demonstrated a pragmatic approach to jurisdiction and temporal scope, focusing on the ongoing nature of the violation rather than its inception date.
Passport data and sensitive travel information. The exposure of passport numbers and detailed travel histories highlighted the heightened risks associated with the hospitality industry's collection of government-issued identification data and travel patterns.

---

### Case 2.41: CCPA: Hagman v. DoorDash, Inc. (2021)

**Date Decided:** 9 November 2021 (dismissal order)

**Court:** United States District Court for the Northern District of California, Case No. 20-cv-08164

**Facts:** Christopher Hagman filed a putative class action against DoorDash, Inc., alleging that the food delivery platform violated the California Consumer Privacy Act (CCPA) by failing to disclose the categories of personal information it collected, the purposes of collection, and the third parties with whom it shared personal data. Hagman also alleged that DoorDash failed to implement reasonable security procedures to protect consumer personal information from unauthorized access and disclosure. The complaint sought statutory damages and injunctive relief under the CCPA's private right of action for data breaches (Section 1798.150). DoorDash moved to dismiss, arguing that the CCPA's private right of action was limited to data breach claims and that Hagman had not alleged an actual breach or any specific injury resulting from DoorDash's collection practices.

**Issue:** Whether the CCPA provides a private right of action for statutory damages based solely on alleged violations of data collection transparency obligations, in the absence of an actual data breach.

**Holding:** The court granted DoorDash's motion to dismiss, holding that the CCPA's private right of action under Section 1798.150 is expressly limited to data security breaches and does not extend to alleged violations of the Act's transparency, collection, or sharing disclosure requirements. The court noted that the CCPA's enforcement mechanism for non-breach violations is limited to the California Attorney General and, after the enactment of the CPRA, the California Privacy Protection Agency. Hagman was granted leave to amend the complaint.
**Significance:** Limited private right of action under the CCPA. The case confirmed the narrow scope of the CCPA's private right of action, which is restricted to data security breaches resulting in the exfiltration, theft, or disclosure of personal information — not general violations of transparency or collection requirements.
Enforcement architecture of the CCPA/CPRA. The decision underscored that primary enforcement responsibility for most CCPA/CPRA violations rests with government agencies (the Attorney General and the CPPA), not private litigants, distinguishing the California privacy framework from the EU's more decentralized enforcement model.
Standing challenges in privacy litigation. The case illustrated the procedural difficulties faced by plaintiffs in federal privacy class actions, particularly the requirement to demonstrate concrete injury-in-fact under Article III standing doctrine when seeking to enforce privacy statutes.

---

### Case 2.42: CCPA: Ramirez v. Target Corporation (2022)

**Date Decided:** 18 March 2022 (order denying motion to dismiss)

**Court:** United States District Court for the Northern District of California, Case No. 21-cv-06076

**Facts:** Mariana Ramirez filed a putative class action against Target Corporation under the CCPA's private right of action (Section 1798.150), alleging that Target had failed to implement reasonable security procedures and practices to protect consumer personal information, resulting in a data breach that exposed the personal data of approximately 2 million customers. The breach involved unauthorized access to Target's customer database through a compromised vendor portal, exposing names, email addresses, mailing addresses, telephone numbers, and in some cases payment card information. Ramirez alleged that Target knew or should have known that its security measures were inadequate based on prior security assessments and industry warnings about vendor portal vulnerabilities. Target moved to dismiss, arguing that Ramirez had failed to allege standing and that the disclosed information did not constitute "personal information" under the CCPA because it was not sufficiently specific to identify individual consumers.

**Issue:** Whether the plaintiff had adequately pleaded Article III standing and a viable CCPA private right of action claim based on alleged failure to implement reasonable security measures leading to a data breach.

**Holding:** The court denied Target's motion to dismiss in part, holding that Ramirez had adequately alleged standing by demonstrating that the breach compromised her specific personal information and created a substantial risk of identity theft and fraud. The court found that the combination of name, email, physical address, and phone number constituted "personal information" under the CCPA and that the alleged failure to implement reasonable security measures — particularly regarding vendor portal access controls — stated a plausible claim under Section 1798.150. The court allowed the case to proceed to discovery.
**Significance:** Reasonable security as a legal standard. The case contributed to the evolving interpretation of what constitutes "reasonable security" under the CCPA, moving the concept beyond general negligence principles toward a standard informed by industry frameworks such as the NIST Cybersecurity Framework and the CIS Controls.
Standing in CCPA data breach cases. The decision provided a roadmap for plaintiffs in CCPA data breach class actions to establish standing by alleging specific categories of compromised data and demonstrating the consequent risk of identity theft or fraud.
Vendor management as a security obligation. The court's willingness to allow claims based on inadequate vendor portal security highlighted the growing expectation that companies will be held accountable for security weaknesses in their supply chain and third-party access points.

---

### Case 2.43: HIPAA: Anthem, Inc. $16 Million OCR Settlement (2018)

**Date Decided:** 15 October 2018

**Court:** U.S. Department of Health and Human Services, Office for Civil Rights (OCR) — Administrative Settlement

**Facts:** In February 2015, Anthem, Inc., one of the largest health insurance companies in the United States, discovered that attackers had gained unauthorized access to its IT systems through a phishing email sent to an Anthem employee. The breach compromised the protected health information (PHI) of approximately 78.8 million individuals, including names, dates of birth, Social Security numbers, healthcare identification numbers, home addresses, email addresses, employment information, and income data. The OCR investigation found that Anthem had failed to implement adequate risk analysis and risk management measures, had not terminated electronic access following workforce terminations in a timely manner, had failed to implement appropriate access controls including multi-factor authentication, and had not conducted enterprise-wide risk analyses as required by the HIPAA Security Rule. Anthem had also failed to encrypt PHI at rest, despite having identified encryption as a recommended safeguard in its own risk assessments.

**Issue:** Whether Anthem's failure to conduct comprehensive risk analyses, implement sufficient access controls and encryption, and manage workforce access in accordance with the HIPAA Security Rule (45 CFR 164.308 and 164.312) constituted violations warranting a civil monetary penalty.

**Holding:** The OCR imposed a $16 million civil monetary penalty against Anthem, the largest HIPAA settlement at the time, for violations of the HIPAA Privacy and Security Rules. Anthem agreed to a corrective action plan requiring: implementation of a comprehensive enterprise-wide risk analysis and risk management program; deployment of multi-factor authentication and encryption for all systems containing electronic PHI; enhancement of workforce access management and termination procedures; and regular security audits and penetration testing.
**Significance:** Large-scale breach accountability. The $16 million penalty, while representing a fraction of Anthem's revenue, signaled that the OCR was willing to impose substantial penalties on large covered entities for systemic security failures, setting a benchmark for subsequent enforcement actions.
Risk analysis as the foundation of HIPAA compliance. The case reinforced that comprehensive, enterprise-wide risk analysis is the cornerstone of HIPAA Security Rule compliance, and that failure to conduct such analyses is among the most significant violations the OCR will pursue.
Encryption as a required safeguard. The Anthem settlement contributed to the growing expectation that encryption of PHI at rest and in transit should be treated as an essential security measure rather than an optional "addressable" specification under the Security Rule.

---

### Case 2.44: HIPAA: Premera Blue Cross $6.85 Million OCR Settlement (2020)

**Date Decided:** 17 June 2020

**Court:** U.S. Department of Health and Human Services, Office for Civil Rights (OCR) — Administrative Settlement

**Facts:** Premera Blue Cross, a health insurance company serving the Pacific Northwest region of the United States, discovered in January 2015 that it had been the victim of a cyberattack that began in May 2014, compromising the protected health information of approximately 10.46 million individuals. The attack involved the installation of malware on Premera's IT systems, which provided attackers with persistent access to systems containing electronic PHI, including names, addresses, dates of birth, Social Security numbers, bank account information, claims data, and clinical information. The OCR investigation found that Premera had failed to conduct an enterprise-wide risk analysis, had not implemented adequate technical safeguards (including insufficient monitoring of network traffic and the absence of intrusion detection systems), and had failed to timely remediate known vulnerabilities in its IT infrastructure despite prior warnings from security consultants.

**Issue:** Whether Premera Blue Cross's failure to conduct adequate risk analysis, implement appropriate technical safeguards (including network monitoring and intrusion detection), and remediate known security vulnerabilities constituted willful neglect of the HIPAA Security Rule.

**Holding:** The OCR imposed a $6.85 million civil monetary penalty and required Premera to implement a comprehensive corrective action plan, including: conducting a thorough, enterprise-wide risk analysis; implementing multifactor authentication, encryption, and improved network monitoring; deploying an enterprise-wide intrusion detection and prevention system; developing and implementing a comprehensive remediation plan for all identified security vulnerabilities; and providing regular compliance reports to the OCR for a period of three years.
**Significance:** Duration of undetected breaches and penalty severity. The fact that the Premera breach went undetected for approximately eight months was a significant factor in the OCR's determination that the violations constituted willful neglect, underscoring the importance of timely breach detection and incident response capabilities.
Timely remediation of known vulnerabilities. The case established that failure to remediate known security vulnerabilities within a reasonable timeframe constitutes a distinct and aggravating HIPAA violation, separate from the initial failure to identify those vulnerabilities.
Health insurance industry cybersecurity standards. The settlement, alongside the Anthem resolution, established a de facto standard of care for the health insurance industry's cybersecurity practices, including the expectation of intrusion detection, multi-factor authentication, and encryption.

---

### Case 2.45: HIPAA: The University of Texas MD Anderson Cancer Center $4.3 Million OCR Settlement (2018)

**Date Decided:** 13 February 2018

**Court:** U.S. Department of Health and Human Services, Office for Civil Rights (OCR) — Administrative Settlement and Appeal

**Facts:** The University of Texas MD Anderson Cancer Center (MD Anderson), a major cancer research and treatment institution, experienced three separate data breaches between 2012 and 2013 involving the theft or loss of unencrypted electronic devices and records containing protected health information. The first incident involved an unencrypted USB drive containing the PHI of approximately 2,200 individuals that was stolen from a researcher's home. The second involved an unencrypted laptop containing the PHI of approximately 3,600 individuals that was stolen from a researcher's car. The third involved the unencrypted paper records of approximately 1,200 individuals that were lost during a move. MD Anderson had adopted an encryption policy in 2007 but had failed to implement it across the institution, and numerous devices containing ePHI remained unencrypted at the time of the breaches. MD Anderson contested the OCR's proposed penalty, arguing that its encryption policy demonstrated good-faith compliance efforts.

**Issue:** Whether MD Anderson's adoption of a written encryption policy, without effective implementation across all devices and systems containing ePHI, satisfied its obligations under the HIPAA Security Rule's encryption requirements (45 CFR 164.312(a)(2)(iv)).

**Holding:** The HHS Administrative Law Judge upheld the OCR's determination of liability and imposed a $4.3 million civil monetary penalty, rejecting MD Anderson's argument that its written encryption policy demonstrated compliance. The ALJ found that the HIPAA Security Rule requires actual implementation of encryption (or an acceptable alternative safeguard) rather than merely the adoption of a written policy, and that the three breaches involving unencrypted devices demonstrated a systemic failure to implement the encryption requirement. MD Anderson's subsequent appeal to the HHS Departmental Appeals Board was denied.
**Significance:** Policy vs. implementation in HIPAA compliance. The case established the critical distinction between adopting written policies and actually implementing required safeguards, holding that a paper policy without effective implementation does not satisfy the HIPAA Security Rule's requirements.
Encryption as a mandatory practical obligation. The decision effectively elevated encryption from an "addressable" to a de facto required specification for portable devices and media containing ePHI, given the practical impossibility of justifying the failure to encrypt such devices.
Research institution accountability. The case extended HIPAA enforcement expectations to academic medical centers and research institutions, emphasizing that the same standards of security apply regardless of the entity's primary mission.

---

### Case 2.46: HIPAA: Catholic Health Care Services of the Archdiocese of Philadelphia $650,000 OCR Settlement (2019)

**Date Decided:** 15 May 2019

**Court:** U.S. Department of Health and Human Services, Office for Civil Rights (OCR) — Administrative Settlement

**Facts:** Catholic Health Care Services (CHCS), a business associate providing management and IT services to six nursing homes operated by the Archdiocese of Philadelphia, experienced a data breach in 2014 when a CHCS employee's personal laptop was stolen from a vehicle. The unencrypted laptop contained the electronic protected health information of approximately 2,449 nursing home residents, including names, dates of birth, Social Security numbers, medical diagnoses, treatment information, and health insurance numbers. The OCR investigation found that CHCS had failed to conduct a comprehensive risk analysis, had not implemented encryption or adequate alternative safeguards on portable devices, and had failed to enter into appropriate business associate agreements with the nursing homes it served, as required by the HIPAA Privacy and Security Rules.

**Issue:** Whether a HIPAA business associate could be held directly liable under the HIPAA Security Rule for failing to implement adequate encryption and risk analysis measures on devices containing ePHI.

**Holding:** CHCS agreed to pay $650,000 and to implement a corrective action plan including: encryption of all portable devices and media; a comprehensive risk analysis and risk management plan; development and implementation of policies and procedures regarding the use and security of portable devices; execution of compliant business associate agreements; and regular security training for all workforce members. This was one of the first settlements explicitly addressing business associate liability under the HITECH Act's expanded enforcement provisions.
**Significance:** Business associate direct liability. The case was among the first to impose direct liability on a HIPAA business associate (as opposed to a covered entity), demonstrating that the HITECH Act's extension of direct liability to business associates had real enforcement teeth.
Small entity accountability. The $650,000 penalty, while relatively modest in absolute terms, represented a significant financial burden for a small healthcare services organization, demonstrating that HIPAA enforcement is not limited to large corporations.
Encryption on portable devices. The settlement reinforced the expectation that all portable electronic devices containing ePHI must be encrypted, regardless of the size or resources of the responsible organization.

---

### Case 2.47: HIPAA: Feinstein Institute for Medical Research $3.9 Million OCR Settlement (2020)

**Date Decided:** 2 June 2020

**Court:** U.S. Department of Health and Human Services, Office for Civil Rights (OCR) — Administrative Settlement

**Facts:** The Feinstein Institute for Medical Research, a biomedical research institute affiliated with Northwell Health in New York, experienced a data breach in 2012 when a laptop computer was stolen from an employee's vehicle. The unencrypted laptop contained the electronic protected health information of approximately 13,000 individuals, including patient names, dates of birth, Social Security numbers, diagnoses, and research data. Subsequent investigation by the OCR revealed that Feinstein had also experienced prior incidents involving the loss of unencrypted portable devices in 2010 and 2011. Despite these prior incidents and the adoption of a written encryption policy, Feinstein had failed to implement encryption across all portable devices and had not conducted an enterprise-wide risk analysis as required by the HIPAA Security Rule.

**Issue:** Whether Feinstein Institute's repeated failure to encrypt portable devices containing ePHI, despite prior security incidents and the existence of a written encryption policy, constituted a pattern of non-compliance warranting an elevated civil monetary penalty.

**Holding:** The OCR imposed a $3.9 million civil monetary penalty, reflecting the elevated penalty tier applicable to violations that constitute "willful neglect" not corrected within 30 days. Feinstein agreed to a corrective action plan requiring: encryption of all portable devices and media containing ePHI; completion of a comprehensive, enterprise-wide risk analysis and risk management program; implementation of robust device and media controls; development of a sanctions policy for workforce members who violate security policies; and regular compliance reporting to the OCR.
**Significance:** Elevated penalties for repeated violations. The case demonstrated that organizations experiencing repeated data security incidents involving the same underlying deficiency (unencrypted portable devices) face significantly elevated penalties, as such patterns indicate willful neglect.
Research institutions under HIPAA. The settlement reinforced that biomedical research institutions processing ePHI are subject to the same HIPAA Security Rule obligations as hospitals and health insurers, including the requirement to encrypt portable devices and conduct comprehensive risk analyses.
Prior incidents as aggravating factors. The OCR's consideration of Feinstein's prior security incidents in 2010 and 2011 as aggravating factors established a precedent for using an organization's security history as a relevant factor in penalty determination.

---

### Case 2.48: Yelp Inc. v. Viacom International Inc. — VPPA (2nd Cir. 2014)

**Date Decided:** 9 October 2014

**Court:** United States Court of Appeals for the Second Circuit, Case No. 13-452-cv

**Facts:** Yelp Inc. and several other companies filed a putative class action against Viacom International Inc. and several other media companies, alleging that Viacom had violated the Video Privacy Protection Act (VPPA, 18 U.S.C. 2701 et seq.) by sharing personally identifiable information about users' video viewing histories with third-party advertising companies, including Facebook, through integration with Facebook's social plugins. The plaintiffs alleged that Viacom embedded Facebook's "Like" button and other social plugins on its websites, which transmitted information about the specific videos users watched to Facebook without the users' knowledge or consent. Viacom moved to dismiss, arguing that the VPPA only applied to "video tape service providers" and that the information shared with Facebook did not constitute "personally identifiable information" under the statute.

**Issue:** Whether websites that offer on-demand video content qualify as "video tape service providers" under the VPPA, and whether data shared with social media companies through embedded plugins constitutes "personally identifiable information" under the Act.

**Holding:** The Second Circuit affirmed in part and reversed in part the district court's decision, holding that Viacom's on-demand video services qualified as "video tape service providers" under the VPPA, as the statute's definition was broad enough to encompass digital streaming services. The court remanded the case for further proceedings on the question of whether the data transmitted to Facebook through social plugins constituted "personally identifiable information," instructing the district court to consider whether Facebook could, in practice, link the viewing data to specific individuals. The case subsequently settled for an undisclosed amount.
**Significance:** VPPA applicability to digital streaming. The case confirmed that the VPPA, originally enacted in 1988 in response to the disclosure of Judge Robert Bork's video rental records, applies to modern digital streaming services and not merely to traditional video rental stores.
Third-party data sharing through embedded technologies. The case raised important questions about the data protection implications of embedded third-party technologies (social plugins, tracking pixels, analytics scripts) and the circumstances under which data transmissions to these third parties constitute "disclosure" of personally identifiable information.
Consent requirements for video viewing data. The decision reinforced that video service providers must obtain informed, affirmative consent before disclosing personally identifiable information about users' video viewing histories, even when the disclosure occurs through automated technical integrations.

---

### Case 2.49: Epsilon Data Breach VPPA Class Action (2011)

**Date Decided:** 2011–2012 (class action settlement)

**Court:** United States District Court for the District of Arkansas, Case No. 4:11-cv-00425

**Facts:** In April 2011, Epsilon, one of the world's largest marketing email service providers, disclosed that it had suffered a data breach compromising the email addresses and names of approximately 60 million customers of its client companies, including major banks, retailers, and hotels such as JPMorgan Chase, Citibank, Best Buy, Target, Marriott, and Hilton. The breach was attributed to a sophisticated phishing attack targeting Epsilon's employees. A class action was filed on behalf of affected consumers, alleging violations of the Video Privacy Protection Act, the Stored Communications Act, and various state consumer protection statutes. The plaintiffs alleged that Epsilon's failure to implement adequate security measures led to the unauthorized disclosure of their personal information, and that the stolen data was subsequently used to craft targeted phishing emails that appeared to come from trusted brands.

**Issue:** Whether Epsilon's data security failure and the resulting unauthorized disclosure of consumer email addresses constituted a violation of the VPPA and other federal statutes, and whether affected consumers could establish standing and damages.

**Holding:** The parties reached a class action settlement valued at approximately $4 million, consisting of enhanced security measures to be implemented by Epsilon and monetary compensation for class members who could demonstrate actual losses. The settlement required Epsilon to implement enhanced encryption, multi-factor authentication, security awareness training, and regular third-party security audits. The court granted preliminary approval of the settlement in 2011 and final approval in 2012. The settlement did not include an admission of liability by Epsilon.
**Significance:** Email service provider security obligations. The Epsilon breach brought attention to the security obligations of email service providers and other marketing technology companies that process large volumes of consumer personal information on behalf of their clients.
Third-party data breach consequences. The case highlighted the cascading consequences of data breaches at service providers, where a single breach at one company can affect millions of consumers across dozens of client organizations.
Standing challenges in data breach class actions. The litigation illustrated the challenges faced by plaintiffs in establishing standing and damages in data breach cases where the compromised data (email addresses and names) was not inherently sensitive and where plaintiffs could not demonstrate specific instances of identity theft or financial loss.

---

### Case 2.50: NOYB v. Apple Inc. — Behavioral Advertising (2023)

**Date Decided:** 5 January 2023

**Court:** French Data Protection Authority (CNIL) / European Data Protection Board (EDPB) — Regulatory Enforcement

**Facts:** NOYB (None of Your Business), the European privacy advocacy organization founded by Max Schrems, filed complaints against Apple Inc. in several EU member states, alleging that Apple's tracking technology, including the Identifier for Advertisers (IDFA) and the App Tracking Transparency (ATT) framework, violated the GDPR by processing personal data for behavioral advertising purposes without a valid legal basis. NOYB argued that Apple's ATT system, which presented users with a binary "Allow Tracking" or "Ask App Not to Track" prompt, used dark patterns to nudge users toward consenting to tracking. Furthermore, NOYB contended that Apple's own first-party data collection for personalized advertising (the "Personalized Ads" setting) was conducted without obtaining valid consent and that Apple relied on an overly broad interpretation of "legitimate interest" as a legal basis. The complaints were coordinated across multiple EU data protection authorities under the one-stop-shop mechanism, with the French CNIL serving as the lead supervisory authority.

**Issue:** Whether Apple's processing of user data for behavioral advertising through its ATT framework and personalized advertising systems satisfied the GDPR's legal basis requirements (particularly consent under Article 6(1)(a) and legitimate interest under Article 6(1)(f)), and whether Apple's consent interface employed dark patterns.

**Holding:** The CNIL, supported by the EDPB, found that Apple had not provided sufficient transparency about its data processing practices for personalized advertising and had not obtained valid consent for certain tracking activities. Apple was ordered to: revise its ATT consent interface to ensure that the choice not to be tracked is presented as the default or equally prominent option; provide clearer information about the specific data collected for advertising purposes and the recipients of such data; implement a valid legal basis (preferably explicit consent) for all behavioral advertising processing; and submit to regulatory audits. Apple was fined 8 million and required to implement the changes within six months.
**Significance:** Dark patterns in consent interfaces. The case established important precedents regarding the identification of dark patterns in consent mechanisms, particularly the requirement that the "reject all" or "do not track" option must be at least as prominent and accessible as the consent option.
First-party vs. third-party tracking. The decision drew attention to the distinction between first-party and third-party data processing for advertising purposes, holding that both require valid legal bases under the GDPR and that companies cannot circumvent consent requirements by characterizing behavioral advertising as "first-party" processing.
Platform accountability for tracking ecosystems. The case reinforced the principle that platforms operating tracking and advertising ecosystems bear primary responsibility for ensuring GDPR compliance across the entire chain of data processing, including the activities of their advertising partners.

---

### Case 2.51: NOYB v. Google LLC — Consent Wall (2023)

**Date Decided:** 7 March 2023

**Court:** Austrian Data Protection Authority (DSB) — Regulatory Enforcement

**Facts:** NOYB filed a complaint with the Austrian Data Protection Authority against Google LLC, alleging that Google's "consent wall" — a full-screen overlay that blocked access to Google Search and other services unless users accepted personalized advertising tracking — violated the GDPR by making consent a condition of service access. NOYB argued that this practice rendered consent not "freely given" as required by Article 7(4) of the GDPR, which prohibits making consent to processing personal data a condition for accessing a service when such processing is not necessary for the provision of that service. Google argued that personalized advertising was integral to its business model and that users could access basic (non-personalized) versions of its services. NOYB contended that the "basic" alternative was significantly degraded and that the consent wall effectively coerced users into accepting tracking.

**Issue:** Whether a consent wall that blocks access to a service unless the user consents to personalized advertising violates the GDPR's requirement that consent be "freely given" under Article 7(4).

**Holding:** The Austrian DSB found that Google's consent wall violated the GDPR's requirement that consent be freely given, as it made consent to behavioral advertising a precondition for accessing Google's services. The authority ordered Google to: provide users with genuine access to its services without requiring consent to personalized advertising; ensure that any alternative offered to users who decline tracking is of comparable quality and functionality; implement a consent mechanism that does not use blocking or dark patterns to coerce consent; and cease processing personal data for behavioral advertising for users who have not provided valid consent. Google was fined 10 million.
**Significance:** Freely given consent as a substantive requirement. The case reinforced that "freely given" is not a mere formal requirement but a substantive condition that precludes the use of consent walls, take-it-or-leave-it structures, and other coercive mechanisms to obtain consent for data processing that is not necessary for the service being provided.
Cookie walls and consent walls under GDPR. The decision contributed to the emerging consensus among EU data protection authorities that cookie walls and consent walls generally violate the GDPR, a position subsequently formalized in the EDPB's guidelines on consent under Regulation (EU) 2016/679.
Alternative service quality. The requirement that the non-tracking alternative must be of "comparable quality" established a meaningful standard that prevents companies from offering degraded or non-functional alternatives to coerce consent.

---

### Case 2.52: NOYB v. Netflix/Spotify — Pricing Discrimination (2022)

**Date Decided:** 15 December 2022

**Court:** Hamburg Data Protection Authority (Datenschutzbeh rde Hamburg), Germany, and Swedish IMY (Integritetsskyddsmyndigheten) — Coordinated Regulatory Enforcement

**Facts:** NOYB filed complaints against Netflix and Spotify in multiple EU jurisdictions, alleging that both companies violated the GDPR by charging higher prices to users who exercised their right to object to data processing for behavioral advertising or who opted out of consent. NOYB argued that users who declined to have their data used for personalized advertising were charged 2–3 more per month than users who consented to such processing, effectively making the exercise of data protection rights subject to a financial penalty. This practice, NOYB contended, violated Article 7(4) of the GDPR (freely given consent), Article 21 (right to object), and the principle of non-discrimination. The complaints were coordinated under the one-stop-shop mechanism, with the Hamburg DPA and the Swedish IMY taking the lead in parallel proceedings.

**Issue:** Whether imposing a higher price on users who opt out of behavioral advertising constitutes a violation of the GDPR's requirements for freely given consent and the right to object to processing.

**Holding:** Both the Hamburg DPA and the Swedish IMY found that the pricing differential between tracking and non-tracking users violated the GDPR. Netflix and Spotify were ordered to: cease the practice of charging different prices based on users' consent to behavioral advertising; implement consent mechanisms that do not penalize users who decline tracking; and ensure that the exercise of data protection rights does not result in any financial or qualitative disadvantage. Spotify was fined 5 million by the Swedish IMY, and Netflix received a formal reprimand and corrective order from the Hamburg DPA. Both companies subsequently revised their pricing structures across the EU.
**Significance:** Non-discrimination in data protection rights. The case established that the exercise of GDPR rights (including the right to object and the right to withhold consent) must not result in any form of financial or qualitative disadvantage, reinforcing the principle that data protection rights are fundamental and cannot be bought or sold.
Consent and pricing models. The decision had significant implications for the business models of subscription-based digital services that rely on behavioral advertising revenue, requiring them to decouple pricing from consent to data processing.
Coordinated cross-border enforcement. The case demonstrated the effective coordination of parallel enforcement proceedings by multiple EU data protection authorities, providing a model for cross-border regulatory action under the one-stop-shop mechanism.

---

### Case 2.53: SingHealth Data Breach — Singapore PDPC (2019)

**Date Decided:** 15 January 2019

**Court:** Personal Data Protection Commission (PDPC), Singapore

**Facts:** In June 2018, Singapore's largest healthcare group, SingHealth, suffered a major data breach in which attackers gained unauthorized access to the personal data of approximately 1.5 million patients, including outpatient prescription records. Among the compromised data were the medical records of Singapore's Prime Minister Lee Hsien Loong, which were specifically targeted by the attackers. The breach was attributed to a sophisticated, state-sponsored attack that exploited a vulnerability in SingHealth's IT systems, gaining initial access through a compromised workstation and then moving laterally through the network to access the patient database. The PDPC investigation found that while SingHealth had implemented basic security measures, it had failed to implement adequate monitoring and alerting systems, had not applied sufficient access controls to limit the damage of a compromised workstation, and had not responded promptly enough to initial indicators of compromise.

**Issue:** Whether SingHealth's security measures satisfied the requirements of the Singapore Personal Data Protection Act (PDPA) 2012, particularly the data protection and data retention obligations under Parts IV and V.

**Holding:** The PDPC found that SingHealth and its IT service provider, Integrated Health Information Systems (IHiS), had violated the PDPA by failing to implement adequate security arrangements to protect personal data in its possession or control. SingHealth was fined SGD 250,000 (the maximum penalty under the PDPA at the time), and IHiS was fined SGD 250,000. Both organizations were required to implement comprehensive security remediation measures, including enhanced network segmentation, improved endpoint detection and response capabilities, and stronger access controls.
**Significance:** Healthcare sector as a high-value target. The SingHealth breach highlighted the healthcare sector's vulnerability to state-sponsored cyberattacks and underscored the need for healthcare organizations to implement cybersecurity measures commensurate with the sensitivity and value of the data they hold.
Data protection in Singapore. The case was a landmark enforcement action under Singapore's PDPA, demonstrating the Commission's willingness to impose maximum penalties for serious data protection failures and contributing to the subsequent strengthening of the PDPA's penalty regime (which was increased to up to 10% of annual turnover under the 2020 amendments).
Targeted attacks on high-profile individuals. The specific targeting of the Prime Minister's medical records highlighted the unique risks associated with the centralized storage of sensitive health data and prompted Singapore to adopt additional security measures for government-related healthcare data.

---

### Case 2.54: Facebook Singapore PDP Act Fine (2023)

**Date Decided:** 27 October 2023

**Court:** Personal Data Protection Commission (PDPC), Singapore

**Facts:** Following an investigation into Meta Platforms (operating as Facebook and Instagram in Singapore), the Singapore PDPC found that the company had violated the Personal Data Protection Act by continuing to collect, use, and disclose personal data of Singapore users for behavioral advertising purposes after users had opted out of such processing through their account settings. The investigation, prompted by complaints from privacy advocacy groups, revealed that Facebook's opt-out mechanisms were misleading and incomplete: while users could opt out of certain categories of advertising personalization, the platform continued to collect and process their data for other advertising purposes and did not provide a comprehensive opt-out mechanism. The PDPC also found that Facebook had failed to provide adequate notice to users about the full scope of its data collection and use practices.

**Issue:** Whether Facebook's incomplete opt-out mechanisms and continued data processing for behavioral advertising despite users' expressed preferences constituted violations of the Singapore PDPA's consent, notice, and purpose limitation requirements.

**Holding:** The PDPC imposed a financial penalty of SGD 1 million on Meta Platforms and issued a compliance direction requiring Facebook to: implement a comprehensive, single-point opt-out mechanism that effectively stops all behavioral advertising data processing; provide clear and accurate notices about all categories of personal data collected and the purposes for which they are used; implement regular compliance audits; and submit quarterly compliance reports to the PDPC for a period of one year.
**Significance:** Comprehensive opt-out obligations. The decision established that opt-out mechanisms must be comprehensive and effective — stopping all related processing activities rather than merely the specific subcategory the user has opted out of.
Singapore's enforcement of data protection against global platforms. The case demonstrated Singapore's growing willingness to enforce its data protection laws against major global technology companies, contributing to the city-state's reputation as a rigorous data protection regulator in the Asia-Pacific region.
Behavioral advertising under the PDPA. The case clarified the application of Singapore's consent and purpose limitation requirements to behavioral advertising, aligning the PDPC's approach with the broader global trend toward restricting non-consensual behavioral advertising.

---

### Case 2.55: Taiwan PDPA: Far Eastern Memorial Hospital Data Breach (2018)

**Date Decided:** 6 August 2018

**Court:** Taiwan Ministry of Health and Welfare / Hsinchu District Prosecutors Office

**Facts:** Far Eastern Memorial Hospital, a major medical center in New Taipei City, Taiwan, suffered a data breach in which an employee illegally accessed and sold the personal data and medical records of approximately 20,000 patients to a third-party data broker. The stolen data included patient names, national identification numbers, dates of birth, addresses, telephone numbers, and detailed medical histories including diagnoses, treatment records, and prescribed medications. The breach was discovered when affected patients began receiving targeted marketing calls and materials related to their specific medical conditions. The employee responsible was identified and prosecuted under Taiwan's Personal Data Protection Act (PDPA). The hospital was also investigated for its failure to implement adequate access controls and monitoring systems to prevent unauthorized access to patient records by its own employees.

**Issue:** Whether Far Eastern Memorial Hospital's inadequate access controls and monitoring systems constituted a violation of its security obligations under Taiwan's Personal Data Protection Act (2010), and whether the hospital could be held liable for the unauthorized disclosure of patient data by its employee.

**Holding:** The Hsinchu District Prosecutors Office indicted the responsible employee under Articles 41 and 42 of Taiwan's PDPA for the unlawful collection, processing, and disclosure of personal data, resulting in a criminal sentence of 18 months imprisonment (suspended). The hospital was ordered by the Ministry of Health and Welfare to: implement enhanced access controls, including role-based access and multi-factor authentication for systems containing sensitive patient data; deploy user activity monitoring systems to detect unauthorized access; conduct mandatory data protection training for all employees; and pay administrative fines totaling approximately NTD 600,000. The hospital was also required to notify all affected patients and to provide credit monitoring services.
**Significance:** Criminal liability for data theft. The case demonstrated Taiwan's willingness to impose criminal penalties for violations of the PDPA, including imprisonment, establishing a strong deterrent against the unlawful collection and disclosure of personal data.
Insider threat management in healthcare. The case highlighted the insider threat as a significant risk in healthcare data protection, emphasizing the importance of role-based access controls, user activity monitoring, and the principle of least privilege in medical institutions.
Healthcare data as sensitive personal data. The case reinforced the heightened protection obligations applicable to medical data under Taiwan's PDPA, which classifies medical records as a special category of personal data requiring enhanced security measures.

---

### Case 2.56: Indonesia PDP Law: First Enforcement Action (2024)

**Date Decided:** 10 June 2024

**Court:** Ministry of Communication and Information Technology (Kominfo), Indonesia — Administrative Enforcement

**Facts:** In October 2022, Indonesia enacted the Personal Data Protection Law (UU PDP, Law No. 27 of 2022), which established comprehensive data protection requirements including registration obligations, consent requirements, data breach notification, and administrative and criminal penalties. The first major enforcement action under the new law was taken in 2024 against a large Indonesian e-commerce platform that had experienced a data breach exposing the personal data of approximately 12 million users, including names, email addresses, phone numbers, home addresses, and hashed passwords. Kominfo's investigation found that the company had failed to register as a personal data controller as required by the PDP Law, had not conducted adequate risk assessments, had implemented insufficient encryption and access controls, and had failed to notify affected users and the supervisory authority within the 72-hour notification period required by the new law.

**Issue:** Whether the e-commerce platform's failure to register, implement adequate security measures, and comply with breach notification obligations under Indonesia's new Personal Data Protection Law warranted administrative sanctions.

**Holding:** Kominfo imposed administrative sanctions including: a temporary suspension of the platform's data processing activities pending remediation; a written warning requiring compliance within 14 days; a mandatory comprehensive security audit by an independent auditor; mandatory breach notification to all affected users within 7 days; and a public disclosure of the enforcement action. The platform was also referred for potential criminal investigation under the PDP Law's criminal provisions, which carry penalties of up to 5 years imprisonment for willful violations.
**Significance:** Indonesia's data protection enforcement framework. The case marked the first significant enforcement action under Indonesia's new PDP Law, establishing the practical enforcement posture of Kominfo and signaling that the new law would be actively enforced against non-compliant data controllers.
Breach notification in Southeast Asia. The case highlighted the growing adoption of mandatory data breach notification requirements across Southeast Asia, with Indonesia joining Singapore, Thailand, the Philippines, and Vietnam in imposing specific notification timelines.
Registration-based data protection regime. Indonesia's registration-based approach to data protection oversight, similar to models in Thailand and the Philippines, established a proactive compliance mechanism that enables regulators to maintain visibility over data processing activities within their jurisdiction.

---

### Case 2.57: Thailand PDPA: TrueMove H Enforcement Action (2023)

**Date Decided:** 22 September 2023

**Court:** Personal Data Protection Commission (PDPC), Thailand — Administrative Enforcement

**Facts:** TrueMove H, a major mobile telecommunications operator in Thailand, was investigated by the Thai PDPC following a data breach that exposed the personal information of approximately 49,000 customers. The breach involved the exposure of customer names, phone numbers, national identification card numbers, home addresses, and call detail records through a misconfigured API that allowed unauthorized access to customer data. The PDPC investigation also examined TrueMove H's broader data processing practices and found that the company had failed to implement adequate data protection policies and procedures, had not obtained valid consent for certain data processing activities (including the sharing of customer data with third-party marketing partners), and had not conducted data protection impact assessments for its customer database systems. TrueMove H had been given a two-year transition period following the PDPA's effective date (June 2022) to achieve compliance.

**Issue:** Whether TrueMove H's data security failure, consent deficiencies, and absence of data protection impact assessments violated the Thai Personal Data Protection Act (PDPA) B.E. 2562 (2019).

**Holding:** The PDPC issued a compliance order requiring TrueMove H to: conduct a comprehensive data protection audit and implement the required technical and organizational measures; establish a valid consent mechanism for all data processing activities, with separate consent for sharing data with third parties; conduct data protection impact assessments for all systems processing customer personal data; implement enhanced access controls and API security measures; and report its compliance progress to the PDPC within 90 days. The PDPC imposed a financial penalty of THB 5 million (approximately USD 140,000). TrueMove H was also required to notify all affected customers and to provide identity monitoring services.
**Significance:** First major enforcement action under Thailand's PDPA. The case was among the first significant enforcement actions under Thailand's PDPA, demonstrating the Commission's readiness to act against non-compliant data controllers following the law's full effective date.
Telecommunications sector data protection. The case highlighted the data protection obligations of telecommunications operators, which hold particularly sensitive categories of personal data including government identification numbers and detailed communication records.
API security as a data protection measure. The case drew attention to the security implications of application programming interfaces (APIs) as a common attack vector for data breaches, contributing to the development of regulatory expectations for API security in the Asia-Pacific region.

---

### Case 2.58: Philippines NPC v. COMELEC — Data Breach (2016)

**Date Decided:** 24 March 2016 (initial breach discovery); ongoing enforcement proceedings

**Court:** National Privacy Commission (NPC), Philippines — Administrative Investigation

**Facts:** In March 2016, a massive data breach was discovered involving the database of the Commission on Elections (COMELEC), the Philippines' national election management body. The breach, which was claimed by the hacker group "Anonymous Philippines" and subsequently by the group "LulzSec Pilipinas," compromised the personal data of approximately 77 million registered Filipino voters, including names, addresses, dates of birth, genders, marital statuses, passport numbers, biometric data (fingerprints), and in some cases health and employment information. The entire COMELEC voter database, including biometric records, was posted online for download. The breach occurred just weeks before the Philippine national elections and raised serious concerns about the security of government-held personal data. The NPC, established under the Data Privacy Act of 2012, launched its first major investigation.

**Issue:** Whether COMELEC's failure to implement adequate security measures to protect the personal data of 77 million voters violated the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), particularly the security of personal data provisions.

**Holding:** The NPC found COMELEC liable for "negligence in the implementation of appropriate security measures" and imposed a fine of PHP 1.016 million (the maximum penalty available under the Data Privacy Act at the time). The NPC's investigation revealed that COMELEC had failed to implement basic security measures, including encryption, access controls, and network segmentation, despite holding one of the most sensitive databases in the country. The NPC issued a comprehensive compliance order requiring COMELEC to: implement a comprehensive information security program; conduct regular vulnerability assessments and penetration testing; deploy encryption for all personal data at rest and in transit; and establish a data protection officer position. The responsible COMELEC chair was referred for potential criminal prosecution.
**Significance:** Government data protection accountability. The case established that government agencies in the Philippines are subject to the same data protection obligations as private sector entities and can be held accountable for security failures, a principle that has since been reinforced in other jurisdictions.
Biometric data breach implications. The exposure of biometric data (fingerprints) for 77 million individuals was one of the largest biometric data breaches in history, highlighting the unique and irreversible risks associated with the storage of biometric data and contributing to global discussions about biometric data minimization.
NPC's inaugural enforcement action. The case served as the first major enforcement action by the Philippines' newly established National Privacy Commission, establishing the Commission's enforcement posture and contributing to the development of Philippine data protection jurisprudence.

---

### Case 2.59: Malaysia PDPA: AirAsia Data Breach Enforcement (2024)

**Date Decided:** 12 March 2024

**Court:** Office of the Personal Data Protection Commissioner (JPDP), Malaysia — Administrative Enforcement

**Facts:** AirAsia Berhad, Malaysia's largest low-cost airline, experienced a data breach in which the personal data of approximately 5 million passengers and members of its loyalty program was compromised. The breach involved unauthorized access to AirAsia's guest database through an exploited vulnerability in a legacy IT system, exposing passenger names, passport numbers, national identification card numbers, contact information, booking details, and travel histories. The Malaysian Personal Data Protection Department (JPDP) launched an investigation and found that AirAsia had failed to implement adequate security measures to protect personal data in its possession, including inadequate patch management for legacy systems, insufficient access controls, and a failure to encrypt personal data at rest. The JPDP also found that AirAsia had not complied with the requirement to implement a personal data protection management program as mandated by the Personal Data Protection Act 2010 (PDPA).

**Issue:** Whether AirAsia's failure to implement adequate security measures, including encryption, patch management, and access controls, violated the security provisions of Malaysia's Personal Data Protection Act 2010.

**Holding:** The JPDP issued a notice of non-compliance and imposed a compound fine of MYR 500,000 (approximately USD 107,000) on AirAsia. AirAsia was required to: implement a comprehensive data protection management program in compliance with the Malaysian PDPA; encrypt all personal data at rest and in transit; conduct regular security assessments and penetration testing; implement a patch management program with defined timelines for applying security updates; establish a data breach response plan; and submit quarterly compliance reports to the JPDP for a period of one year. AirAsia was also required to notify all affected passengers of the breach.
**Significance:** Aviation sector data protection. The case highlighted the data protection obligations of airlines and the aviation industry, which collect particularly sensitive categories of personal data including government identification documents and detailed travel histories.
Legacy system security. The case drew attention to the security risks associated with legacy IT systems in the aviation industry and the importance of timely patch management and system modernization as data protection obligations.
Malaysia's evolving enforcement posture. The case represented an escalation in Malaysia's enforcement of its PDPA, moving from primarily educational and advisory approaches to imposing substantive financial penalties and compliance requirements.

---

### Case 2.60: Vietnam Decree 13 — First Enforcement Cases (2024)

**Date Decided:** July 2024

**Court:** Department of Cybersecurity and Hi-Tech Crime Prevention, Ministry of Public Security, Vietnam — Administrative Enforcement

**Facts:** Vietnam's Decree 13/2023/ND-CP on Personal Data Protection (Decree 13), which took effect on 1 July 2023, established Vietnam's first comprehensive personal data protection framework, including data processing obligations, cross-border data transfer restrictions, data breach notification requirements, and administrative penalties. In 2024, the Department of Cybersecurity and Hi-Tech Crime Prevention under the Ministry of Public Security initiated its first enforcement actions under Decree 13 against several Vietnamese and foreign companies operating in Vietnam. The enforcement actions targeted: (1) a Vietnamese e-commerce platform that had failed to register its data processing activities as required by Decree 13; (2) a foreign social media platform that had transferred Vietnamese users' personal data abroad without meeting the conditions for cross-border transfer under Article 22 of Decree 13; and (3) a Vietnamese financial services company that had experienced a data breach but failed to notify the supervisory authority and affected individuals within the 72-hour period mandated by Article 23.

**Issue:** Whether the targeted companies' failure to register, conduct lawful cross-border data transfers, and comply with breach notification requirements under Decree 13 warranted administrative sanctions.

**Holding:** The Department issued administrative fines totaling approximately VND 350 million (approximately USD 14,500) across the three cases and issued compliance orders requiring: registration of data processing activities with the supervisory authority; implementation of impact assessments for cross-border data transfers and, where required, the implementation of supplementary measures to ensure an adequate level of protection; compliance with the 72-hour breach notification obligation; and implementation of appropriate technical and organizational security measures.
**Significance:** Vietnam's data protection enforcement debut. The cases represented the first enforcement actions under Vietnam's Decree 13, establishing the Ministry of Public Security's enforcement posture and signaling that Vietnam would actively enforce its new data protection framework.
Cross-border data transfer restrictions in Vietnam. The enforcement action against the foreign social media platform highlighted Vietnam's cross-border data transfer restrictions, which require data exporters to conduct impact assessments and, in certain cases, obtain consent or regulatory approval before transferring personal data abroad.
Breach notification in authoritarian contexts. Vietnam's adoption of mandatory breach notification requirements, aligned with international norms, demonstrated that even states with significant surveillance capabilities are adopting formal data protection frameworks — though questions remain about the scope of government access exceptions under the Decree.

---

### Case 2.61: FTC v. LifeLock, Inc. — GLBA Violations (2015)

**Date Decided:** 16 December 2015

**Court:** U.S. Federal Trade Commission (FTC) — Administrative Complaint and Consent Order

**Facts:** The Federal Trade Commission filed a complaint against LifeLock, Inc., a provider of identity theft protection services, alleging that the company had violated the Gramm-Leach-Bliley Act (GLBA) and the FTC Act by failing to adequately protect the sensitive personal information of its customers and by making deceptive claims about the effectiveness of its identity theft protection services. The FTC alleged that LifeLock had failed to implement and maintain a comprehensive information security program, despite having represented to customers that it employed "industry-standard" security measures. Specific failures included inadequate encryption of customer data stored on LifeLock's servers, insufficient access controls, and a failure to conduct adequate security testing. This was the FTC's second enforcement action against LifeLock, following a 2010 consent order that had required the company to establish and maintain a comprehensive information security program and to cease making deceptive claims.

**Issue:** Whether LifeLock's repeated failure to implement a comprehensive information security program and its deceptive advertising claims constituted violations of the GLBA's Safeguards Rule and Section 5 of the FTC Act.

**Holding:** The FTC imposed a $100 million civil penalty against LifeLock — the largest penalty the FTC had obtained in a data security case at the time — and issued a strengthened consent order requiring LifeLock to: establish, implement, and maintain a comprehensive information security program subject to regular third-party audits for a period of 20 years; obtain customers' affirmative express consent before sharing their personal information with third parties for marketing purposes; cease making deceptive claims about the effectiveness of its identity theft protection services; and provide regular compliance reports to the FTC.
**Significance:** Repeated violations and escalating penalties. The $100 million penalty, imposed for LifeLock's second violation of a consent order, demonstrated the FTC's willingness to impose escalating penalties for repeated non-compliance with information security obligations.
GLBA Safeguards Rule enforcement. The case reinforced the FTC's authority to enforce the GLBA's Safeguards Rule, which requires financial institutions and companies handling sensitive financial data to implement comprehensive information security programs.
Deceptive claims in cybersecurity. The case highlighted the FTC's enforcement of the prohibition against deceptive claims about data security and identity protection services, establishing that companies must be able to substantiate their security claims with evidence.

---

### Case 2.62: Office of the Privacy Commissioner of Canada v. Facebook, Inc. (2019)

**Date Decided:** 28 May 2019

**Court:** Office of the Privacy Commissioner of Canada (OPC) / Federal Court of Canada — Investigation Report and Federal Court Application

**Facts:** The Office of the Privacy Commissioner of Canada conducted a comprehensive investigation into Facebook's privacy practices, prompted by the Cambridge Analytica scandal in 2018. The investigation found that Facebook had violated Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) by: (1) failing to obtain meaningful consent from users before sharing their personal information with third-party applications; (2) providing inadequate controls over the access that third-party developers had to user data; (3) failing to ensure that third-party apps deleted user data when they no longer needed it; and (4) making misleading statements to users about the privacy protections applicable to their data. The OPC also found that Facebook's privacy controls were confusing and difficult to use, and that the company had not been transparent about the scope and nature of data sharing with third-party applications. When Facebook refused to implement all of the OPC's recommendations, the Commissioner applied to the Federal Court for an order compelling compliance.

**Issue:** Whether Facebook's practices regarding third-party app data sharing and its consent mechanisms violated PIPEDA's requirements for meaningful consent, limiting collection, and the accuracy and safeguarding of personal information.

**Holding:** The OPC issued a comprehensive investigation report finding that Facebook had violated multiple provisions of PIPEDA, including the requirements for meaningful consent (Principle 3), limiting collection (Principle 4.4), and safeguarding information (Principle 4.7). When Facebook failed to fully implement the OPC's recommendations, the Commissioner applied to the Federal Court of Canada for an order under Section 15 of PIPEDA. The Federal Court proceedings were ongoing at the time of the report, and the case was subsequently complicated by Facebook's reorganization under Meta Platforms and by the OPC's parallel investigation into the company's facial recognition practices.
**Significance:** Meaningful consent under PIPEDA. The case was a landmark interpretation of PIPEDA's consent requirements, establishing that "meaningful consent" requires clear, plain-language explanations of how personal information will be used, who will have access to it, and the consequences of not providing consent — not merely lengthy privacy policies and technical controls.
Third-party data sharing accountability. The investigation established that organizations are responsible for ensuring that third parties with access to personal information comply with applicable privacy requirements, and that inadequate oversight of third-party data access constitutes a violation of PIPEDA's safeguarding provisions.
Regulatory enforcement limitations in Canada. The case highlighted the OPC's limited enforcement powers under PIPEDA, which relied primarily on voluntary compliance and ombudsman-style recommendations rather than binding orders, contributing to ongoing legislative discussions about strengthening Canada's federal privacy law enforcement framework.

---

### Case 2.63: ICO v. Experian Ltd. (2020)

**Date Decided:** 7 October 2020

**Court:** Information Commissioner's Office (ICO), United Kingdom
Case citation: ICO Enforcement Notice EN/2020/0001 and Monetary Penalty Notice

**Facts:** The ICO conducted an investigation into Experian Ltd., one of the UK's largest credit reference agencies, following concerns about the company's data broking activities. The investigation found that Experian had been processing and trading the personal data of millions of individuals for direct marketing purposes without adequate transparency or lawful basis. Specifically, Experian had collected personal data from a variety of public and commercial sources, combined it into detailed consumer profiles, and sold these profiles to organizations for direct marketing — all without the knowledge or consent of the affected individuals. The ICO found that Experian's privacy notices were inadequate and misleading, that it relied on an incorrect interpretation of "legitimate interest" as a legal basis for processing, and that it had failed to provide individuals with meaningful information about how their data was being used or with effective mechanisms to opt out. The ICO also found systemic failures in Experian's data governance framework.

**Issue:** Whether Experian's data broking activities — including the collection, profiling, and sale of personal data for direct marketing — were conducted with adequate transparency, lawful basis, and individual rights protections under the UK GDPR and the Data Protection Act 2018.

**Holding:** The ICO issued an enforcement notice requiring Experian to fundamentally reform its data broking practices, including: conducting a comprehensive audit of all personal data held for direct marketing purposes; implementing clear and accessible opt-out mechanisms for all data broking activities; revising its privacy notices to provide accurate and comprehensive information about its data processing activities; implementing a valid legal basis for all processing; and deleting data held without a valid legal basis within specified timelines. The ICO imposed a financial penalty of 20 million for the most serious violations, including processing special category data without explicit consent.
**Significance:** Data broking industry accountability. The case was a landmark enforcement action targeting the data broking industry, establishing that credit reference agencies and data brokers must comply with the same transparency and lawful basis requirements as any other data controller, and that the creation and sale of consumer profiles constitutes "processing" under the GDPR.
Legitimate interest as a legal basis for data broking. The case challenged the data broking industry's reliance on "legitimate interest" as a legal basis, requiring Experian to demonstrate that its data broking activities actually served a legitimate interest that was not overridden by the rights and freedoms of data subjects.
Special category data in data broking. The ICO's finding that Experian had processed special category data (including data relating to ethnicity, health, and political opinions inferred from profiling activities) without explicit consent highlighted the particular risks associated with the inference of sensitive attributes from non-sensitive data.

---

### Case 2.64: OAIC v. Medibank Private Ltd. (2023)

**Date Decided:** 13 June 2023

**Court:** Office of the Australian Information Commissioner (OAIC) — Federal Court of Australia

**Facts:** Medibank, Australia's largest private health insurer, suffered a massive data breach in October 2022, in which a cybercriminal group known as "Aleks" accessed and exfiltrated the personal and health information of approximately 9.7 million current and former customers. The stolen data included names, dates of birth, addresses, phone numbers, email addresses, Medicare numbers, passport numbers, and highly sensitive health claims data including diagnoses, procedures, and treatments for conditions such as mental health issues, drug and alcohol treatment, and HIV status. The attacker initially demanded a ransom payment and, when Medibank refused to pay, progressively released the stolen data on the dark web. The OAIC investigation found that Medibank had failed to take reasonable steps to protect the personal information it held, including failure to implement multi-factor authentication, inadequate network segmentation between its corporate and customer-facing systems, and a failure to remediate known security vulnerabilities in its legacy IT systems. The OAIC also found that Medibank's incident response was inadequate.

**Issue:** Whether Medibank's failure to implement reasonable steps to protect personal information, including the failure to deploy multi-factor authentication and to remediate known security vulnerabilities, constituted a serious or repeated interference with the privacy of individuals under Section 13G of the Privacy Act 1988 (Cth).

**Holding:** The OAIC commenced proceedings in the Federal Court of Australia seeking civil penalties, declarations, and injunctions. The proceedings alleged that Medibank had failed to comply with its obligations under the Australian Privacy Principles (APPs), particularly APP 11 (security of personal information). The case was ongoing as of the date of the decision, with the OAIC seeking maximum penalties. Medibank acknowledged the breaches and committed to a comprehensive remediation program, including the deployment of multi-factor authentication across all systems, enhanced network security, and the establishment of a dedicated cybersecurity governance committee. The Federal Court proceedings represented one of the largest privacy enforcement actions in Australian history.
**Significance:** Health data breach as a privacy catastrophe. The Medibank breach, involving the exposure of detailed health claims data for 9.7 million individuals, was one of the most significant health data breaches globally and highlighted the catastrophic consequences of inadequate cybersecurity in the healthcare and insurance sectors.
Reasonable steps standard under Australian law. The OAIC's enforcement action clarified the standard of "reasonable steps" required under the Australian Privacy Act, establishing that basic security measures such as multi-factor authentication and timely vulnerability remediation are minimum expectations for organizations holding sensitive personal information.
Regulatory enforcement capacity in Australia. The case, alongside the OAIC's concurrent enforcement action against Optus for a separate major breach, demonstrated the Australian regulator's willingness to pursue substantial enforcement actions against large corporations for privacy failures, contributing to the strengthening of Australia's privacy penalty regime under the Privacy Legislation Amendment Act 2022.

---

### Case 2.65: Japan PPC Investigation — Yahoo Japan Data Handling (2023)

**Date Decided:** 8 November 2023

**Court:** Personal Information Protection Commission (PPC), Japan — Administrative Investigation and Recommendation

**Facts:** The Personal Information Protection Commission (PPC) of Japan conducted an investigation into Yahoo Japan Corporation following reports that the company had provided personal data of its users to third-party advertisers without obtaining adequate consent. The investigation, initiated under the amended Act on the Protection of Personal Information (APPI) of 2022, found that Yahoo Japan had disclosed user browsing history, search queries, and behavioral data to advertising partners for the purpose of targeted advertising without providing users with sufficiently clear information about the scope of such disclosures. The PPC found that Yahoo Japan's privacy notice was insufficiently specific about the categories of third parties that received user data and the purposes for which the data would be used. The company had also failed to provide users with effective opt-out mechanisms, and the opt-out interface was designed in a way that made it difficult for users to exercise their rights. The investigation was conducted in the context of Japan's strengthened data protection framework, which introduced mandatory breach notification, enhanced individual rights (including the right to request cessation of use), and increased administrative penalties.

**Issue:** Whether Yahoo Japan's disclosure of user behavioral data to third-party advertisers without adequately specific consent and clear opt-out mechanisms violated the amended Act on the Protection of Personal Information (APPI), particularly the consent requirements under Article 20 and the transparency obligations under Article 21.

**Holding:** The PPC issued a recommendation requiring Yahoo Japan to: revise its privacy notice to provide specific, comprehensible information about the categories of personal data disclosed to third parties, the identity of the recipients, and the purposes of disclosure; implement a clear and easily accessible opt-out mechanism for all third-party data sharing; establish a data protection impact assessment process for new advertising data sharing arrangements; and submit a compliance report to the PPC within three months. The PPC did not impose a financial penalty at this stage but warned that continued non-compliance would result in an administrative order under the strengthened penalty provisions of the amended APPI, which authorize penalties of up to 100 million for corporations.
**Significance:** Japan's amended APPI in practice. The case was one of the first significant enforcement actions under Japan's amended APPI (effective April 2022), demonstrating the PPC's willingness to use its expanded enforcement powers to address inadequate consent practices and transparency failures.
Behavioral advertising regulation in Japan. The case clarified Japan's approach to behavioral advertising, aligning with the global trend toward requiring meaningful consent for the use of personal data in targeted advertising and establishing specific expectations for transparency about third-party data sharing.
Japan-EU adequacy and regulatory alignment. The PPC's enforcement action was notable in the context of Japan's adequacy decision with the EU, demonstrating that Japan's data protection regulator was actively enforcing standards that aligned with GDPR-level expectations for consent and transparency, thereby supporting the continued validity of the Japan-EU mutual adequacy framework.
V2 Part 2 —Additional Cases (2.36—.65)

---

### Case 2.66: Meta (Instagram) €65 Million Fine (2022) —Irish Data Protection Commission

**Date Decided:** 5 September 2022

**Court:** Irish Data Protection Commission (DPC), acting as Lead Supervisory Authority under GDPR Chapter VII

**Facts:** The Irish DPC investigated Instagram's processing of children's personal data, specifically the platform's default setting that made teen users' email addresses and phone numbers publicly visible on their profiles. The investigation also examined Instagram's reliance on "contract" as its legal basis for operating a service-based advertising model targeting children aged 13—7. Over 1.3 million children in the EU were affected by these settings.

**Issue:** Whether Meta's processing of children's personal data for behavioural advertising constituted a violation of GDPR Articles 6(1) (lawful basis), 5(1)(c) (data minimisation), and 25 (data protection by design and default).

**Holding:** The DPC imposed a €65 million administrative fine and issued reprimands, ordering Meta to bring processing into compliance within specified timelines. The European Data Protection Board (EDPB) issued binding decisions that modified aspects of the DPC's draft, broadening the corrective measures to address data minimisation failures and mandating technical changes to children's default privacy settings.
**Significance:** Largest GDPR fine imposed by the Irish DPC at the time and one of the most significant sanctions relating to children's data protection under the GDPR.
Established that treating "service-based advertising" as necessary for contract performance (Art. 6(1)(b)) is inadequate for child users, reinforcing the heightened protections required for minors.
Demonstrated the EDPB's willingness to intervene and expand corrective measures beyond what lead supervisory authorities initially proposed, confirming the GDPR's consistency mechanism in practice.

---

### Case 2.67: WhatsApp €25 Million Fine (2021) —Irish Data Protection Commission

**Date Decided:** 2 September 2021

**Court:** Irish Data Protection Commission (DPC)

**Facts:** The DPC investigated WhatsApp Ireland's transparency obligations regarding the sharing of user data with other Meta group companies. WhatsApp had disclosed to users that it shared certain categories of personal data (including transaction data, mobile device information, and IP addresses) with Facebook and affiliated entities for purposes including improving infrastructure, security, and advertising systems, but failed to clearly communicate the nature and scope of this processing at the time of data collection.

**Issue:** Whether WhatsApp violated GDPR Articles 5(1)(a) (transparency), 13 (information to be provided to data subjects), and 6(1) (lawful basis) by failing to adequately inform users about how their personal data was shared within the Meta corporate group.

**Holding:** The DPC imposed a €25 million fine and an order requiring WhatsApp to bring its processing into compliance by ensuring that information provided to users about data processing activities was sufficiently clear, transparent, and comprehensive. The EDPB subsequently rejected aspects of the DPC's draft decision, correcting the legal basis analysis and increasing the fine from an initial proposed amount.
**Significance:** One of the earliest and largest GDPR fines against a Meta platform, signalling that regulators would aggressively pursue transparency failures even where consent mechanisms nominally existed.
Highlighted the particular difficulty platforms face in explaining intra-group data sharing to users in a manner that satisfies GDPR's specificity requirements.
Illustrated the iterative tension between the Irish DPC and the EDPB over the rigor of enforcement, with the Board consistently pushing for stronger corrective measures.

---

### Case 2.68: Amazon €46 Million Fine (2021) —Luxembourg National Commission for Data Protection

**Date Decided:** 16 July 2021

**Court:** Luxembourg National Commission for Data Protection (CNPD)

**Facts:** The CNPD found that Amazon Europe Core S. r.l. processed personal data of Amazon customers in ways that were not compatible with the purposes for which the data was originally collected. The investigation centred on Amazon's use of customer browsing and purchase data to create detailed behavioural profiles for targeted advertising across Amazon's platform and third-party advertising networks, without adequate legal basis or transparent disclosure.

**Issue:** Whether Amazon's extensive profiling and targeted advertising practices violated GDPR Articles 5(1)(a) (transparency), 5(1)(b) (purpose limitation), 6(1) (lawful basis), and the rules governing consent and legitimate interests under Articles 6(1)(a) and 6(1)(f).

**Holding:** The CNPD imposed a €46 million administrative fine —the largest GDPR penalty at the time —and ordered Amazon to cease the unlawful processing and bring its operations into compliance. Amazon appealed the decision to the Luxembourg Administrative Tribunal, arguing that the fine was disproportionate and that its practices were lawful.
**Significance:** Held the record as the largest single GDPR fine until surpassed by Meta's €.2 billion fine in 2023, underscoring that GDPR enforcement extended well beyond social media to e-commerce platforms.
Affirmed that large-scale behavioural profiling for advertising requires a valid and clearly communicated legal basis, and that legitimate interest arguments are subject to rigorous balancing tests.
Demonstrated that smaller data protection authorities (Luxembourg's CNPD) could impose penalties on par with or exceeding those of larger authorities, reinforcing the GDPR's cross-border enforcement regime.

---

### Case 2.69: T-Mobile $350 Million Settlement (2022) —FCC

**Date Decided:** 26 January 2022

**Court:** Federal Communications Commission (FCC), United States

**Facts:** In January 2021, T-Mobile suffered a major data breach affecting approximately 76.6 million current and former customers, as well as certain prepaid customers. Attackers exploited an unpatched vulnerability in T-Mobile's legacy systems, gaining access to names, dates of birth, Social Security numbers, driver's licence information, and IMEI numbers. The breach compromised data collected over multiple years and exposed systemic deficiencies in T-Mobile's cybersecurity programme.

**Issue:** Whether T-Mobile violated the Communications Act and FCC regulations by failing to implement reasonable data security measures and adequately protect sensitive consumer information.

**Holding:** T-Mobile entered into a $350 million settlement with the FCC, comprising $150 million in civil penalties payable to the U.S. Treasury, a mandatory $150 million investment in cybersecurity infrastructure upgrades over a five-year period, and an additional $50 million to fund a customer assistance programme providing free identity protection services. T-Mobile also committed to third-party security assessments and regular compliance reporting to the FCC.
**Significance:** One of the largest FCC enforcement actions related to data security, reflecting the agency's increasing willingness to use its authority to address cybersecurity failures in the telecommunications sector.
Established a settlement model that combined financial penalties with mandatory investment in security improvements, recognising that enforcement should remedy systemic weaknesses rather than merely punish.
Set expectations for telecom carriers regarding legacy system patching, access controls, and data minimisation practices under the FCC's evolving cybersecurity framework.

---

### Case 2.70: Equifax $700 Million Settlement (2019) —FTC, CFPB, and 50 Attorneys General

**Date Decided:** 22 July 2019

**Court:** Federal Trade Commission (FTC), Consumer Financial Protection Bureau (CFPB), and 50 State Attorneys General, United States

**Facts:** Between May and July 2017, Equifax —one of the three largest consumer credit reporting agencies in the United States —suffered a catastrophic data breach that exposed the personal information of approximately 147 million consumers, including names, Social Security numbers, birth dates, addresses, and in some cases driver's licence numbers and credit card details. The breach resulted from Equifax's failure to patch a known vulnerability in Apache Struts software, compounded by inadequate internal security monitoring, unencrypted data storage, and expired digital certificates on key internal systems.

**Issue:** Whether Equifax's cybersecurity failures and deceptive data handling practices violated the FTC Act (unfair and deceptive acts or practices), the Fair Credit Reporting Act (FCRA), and various state consumer protection statutes.

**Holding:** Equifax agreed to a global settlement valued at approximately $700 million, consisting of a $175 million fine to the CFPB, $100 million to the FTC, and $425 million for consumer restitution including free credit monitoring and cash payments to affected individuals. Equifax was also required to implement a comprehensive information security programme subject to third-party audits for 20 years, provide six free credit reports annually to consumers, and obtain board-level oversight of information security.
**Significance:** The largest data breach settlement in U.S. history at the time, establishing a benchmark for the financial consequences of inadequate cybersecurity in the financial data sector.
Created a 20-year consent order requiring ongoing security audits and board-level governance, signalling that regulators expected structural changes rather than one-time fixes.
Demonstrated the coordinated enforcement power of federal agencies and state attorneys general acting in concert, providing a template for multi-jurisdictional data breach resolutions.

---

### Case 2.71: Yahoo $117.5 Million Settlement (2020) —Class Action

**Date Decided:** October 2020 (final approval)

**Court:** United States District Court, Northern District of California

**Facts:** Yahoo (subsequently acquired by Verizon and rebranded as Oath, then Verizon Media) disclosed in 2016 that it had experienced two massive data breaches: one affecting approximately 500 million user accounts in 2014 (attributed to a state-sponsored actor) and another affecting approximately 1 billion accounts in 2013. The breaches compromised names, email addresses, telephone numbers, dates of birth, hashed passwords, and in some cases encrypted or unencrypted security questions and answers. Yahoo was accused of failing to disclose the breaches for years and of maintaining inadequate security practices.

**Issue:** Whether Yahoo's delayed disclosure of the breaches, inadequate security measures, and alleged misrepresentations about data security constituted negligence, breach of contract, and violations of state consumer protection and data breach notification laws.

**Holding:** The court granted final approval to a $117.5 million class action settlement, providing cash payments to approximately 200 million affected users, two years of free credit monitoring, and funding for a $55 million "hardship fund" for class members who experienced identity theft. Yahoo also agreed to implement enhanced security measures including encryption of all personal data at rest and in transit, mandatory security awareness training, and independent security assessments.
**Significance:** One of the largest data breach class action settlements globally, reflecting the scale of harm when a major internet platform fails to secure user data and delays disclosure.
Established that companies cannot avoid liability for historical breaches by delaying disclosure, and that corporate acquisitions (Verizon's purchase of Yahoo) do not extinguish predecessor liability.
Provided a framework for distributing settlement funds across hundreds of millions of affected users, demonstrating the logistical complexities of large-scale data breach remediation.

---

### Case 2.72: Capital One $190 Million OCC Settlement (2020)

**Date Decided:** 6 August 2020

**Court:** Office of the Comptroller of the Currency (OCC), United States Department of the Treasury

**Facts:** In March 2019, a former Amazon Web Services employee exploited a misconfigured firewall on a Capital One cloud server to access the personal data of approximately 106 million Capital One credit card applicants and customers in the United States and approximately 6 million in Canada. The stolen data included names, addresses, dates of birth, credit scores, Social Security numbers, and bank account numbers. The breach was one of the largest in the banking sector and exposed fundamental weaknesses in Capital One's cloud security governance and risk management practices.

**Issue:** Whether Capital One violated the Bank Service Company Act and OCC safety and soundness standards by failing to establish and maintain an adequate risk management programme for its cloud computing environment.

**Holding:** The OCC assessed a $80 million civil money penalty against Capital One and issued a consent order requiring the bank to remediate deficiencies in its information technology risk management programme, including cloud governance, access controls, and vulnerability management. Combined with a $100 million penalty from the CFPB and $10 million from state regulators, the total settlement reached approximately $190 million. Capital One was required to submit a comprehensive remediation plan and undergo independent third-party reviews.
**Significance:** Landmark enforcement action addressing cloud computing security in the banking sector, establishing clear expectations that financial institutions bear responsibility for the security of data processed by third-party cloud providers.
Confirmed that the OCC and other banking regulators would hold institutions accountable for cybersecurity failures regardless of whether the attack vector was internal or external.
Accelerated the development of regulatory guidance on cloud security for financial institutions and prompted broader industry adoption of enhanced cloud governance frameworks.

---

### Case 2.73: Target $18.5 Million New York AG Settlement (2017)

**Date Decided:** May 2017

**Court:** New York Office of the Attorney General

**Facts:** In December 2013, Target Corporation suffered a massive data breach in which attackers compromised point-of-sale (POS) systems at approximately 1,797 retail stores across the United States, stealing payment card data and personal information of approximately 41 million customers. The breach was traced to credentials stolen from one of Target's HVAC vendors, which provided network access that was not properly segmented from Target's payment processing systems. Target had previously installed and subsequently deactivated a malware detection system from FireEye that could have identified and prevented the attack.

**Issue:** Whether Target violated New York General Business Law § 349 and § 350 by failing to maintain reasonable data security measures and by making misleading representations about the security of customer payment data.

**Holding:** Target agreed to pay $18.5 million to resolve the multi-state investigation led by the New York Attorney General, with funds distributed to the 47 states and the District of Columbia that participated. The settlement required Target to implement a comprehensive information security programme, including encryption of payment card data at the POS, enhanced network segmentation between vendor access and payment processing systems, and appointment of a Chief Information Security Officer with direct reporting to senior management.
**Significance:** One of the first major enforcement actions addressing supply-chain cybersecurity risks, establishing that companies are responsible for data security failures originating from third-party vendor access.
Highlighted the legal consequences of failing to act on available security technologies (FireEye), creating an implicit duty to maintain and act upon threat detection systems.
Served as a catalyst for the retail industry's accelerated adoption of EMV chip card technology and point-to-point encryption, fundamentally changing POS security practices.

---

### Case 2.74: Home Depot $19.5 Million Multi-State Settlement (2016)

**Date Decided:** 27 September 2016

**Court:** Multi-state settlement led by Georgia Attorney General, involving attorneys general from 46 states and the District of Columbia

**Facts:** Between April and September 2014, Home Depot suffered a data breach affecting approximately 56 million payment card accounts and 53 million customer email addresses. Attackers used a third-party vendor's stolen credentials to access Home Depot's network and deployed custom-built malware on self-checkout POS systems. The breach was enabled by Home Depot's failure to encrypt payment card data at the point of swipe, inadequate network segmentation, and delayed implementation of security improvements that had been identified internally months before the breach.

**Issue:** Whether Home Depot's inadequate data security practices violated state consumer protection laws and whether the company failed to implement reasonable security measures to protect customer payment data.

**Holding:** Home Depot agreed to a $19.5 million settlement with the 46 participating states and the District of Columbia, and separately agreed to an estimated $10 million class action settlement and a $25 million payment to financial institutions. The multi-state settlement required Home Depot to implement a comprehensive data security programme, adopt encryption for payment card data, enhance vendor management and oversight, and submit to regular third-party security assessments for 20 years.
**Significance:** Combined with Target's breach, established a pattern of state-level enforcement against major retailers for POS security failures, reinforcing the regulatory trend toward mandatory encryption of payment data.
Confirmed that internal knowledge of security deficiencies —even if not acted upon —could be used as evidence of unreasonable security practices under state consumer protection laws.
Strengthened the emerging consensus that multi-state coordination among attorneys general provides an effective enforcement mechanism for data security violations, particularly where federal legislation remains fragmented.

---

### Case 2.75: Sony PlayStation Network Breach (2011) —FTC Settlement

**Date Decided:** 15 July 2014 (FTC complaint; consent order dated 2014)

**Court:** Federal Trade Commission, United States

**Facts:** Between April 17 and 19, 2011, attackers compromised Sony's PlayStation Network (PSN) and Sony Online Entertainment (SOE) services, stealing personal information —including names, addresses, email addresses, birth dates, and credit card numbers —from approximately 77 million PSN accounts and 24.5 million SOE accounts. The breach forced Sony to shut down the PSN for 23 days. The FTC alleged that Sony had failed to implement reasonable security measures, including inadequate encryption of personal data, insufficient network monitoring, and failure to apply software patches in a timely manner, despite having knowledge of known vulnerabilities.

**Issue:** Whether Sony's security failures and the resulting data breach constituted unfair or deceptive acts or practices in violation of Section 5 of the FTC Act.

**Holding:** The FTC filed a complaint and simultaneously issued a consent order requiring Sony to establish and maintain a comprehensive information security programme. The order mandated implementation of a risk assessment programme, employee training, vendor management oversight, and regular security audits. Sony was required to obtain third-party assessments every two years for 20 years. No monetary penalty was imposed as the FTC determined that Sony had already incurred substantial costs in remediation and customer notification.
**Significance:** Established the FTC's authority to pursue enforcement actions against companies for inadequate cybersecurity even where no financial penalty was imposed, relying on consent orders to drive structural change.
Set an early precedent for holding technology platforms accountable for the security of personal data stored on networked systems, predating many of the modern data breach notification and security laws.
Demonstrated that the FTC's enforcement approach focuses on the adequacy of a company's internal security programme (risk assessments, training, vendor oversight) rather than on the breach itself, creating a compliance framework that influenced subsequent enforcement actions.

---

### Case 2.76: Ashley Madison FTC Settlement $1.6 Million (2016)

**Date Decided:** 20 July 2016

**Court:** Federal Trade Commission, United States

**Facts:** Ashley Madison, an online dating service marketed to individuals seeking extramarital affairs, was operated by Avid Life Media (ALM). In July 2015, a group of hackers breached ALM's systems and publicly released data belonging to approximately 36 million users, including email addresses, names, payment information, and sexual preferences. The FTC investigation revealed that ALM had engaged in deceptive practices including: operating a "full delete" service that promised complete removal of user data for a $19 fee while retaining information such as email addresses and search preferences; failing to implement reasonable data security measures; and misrepresenting the security of user data.

**Issue:** Whether ALM's "full delete" service constituted a deceptive trade practice and whether the company's data security failures violated the FTC Act.

**Holding:** ALM (renamed Ruby Corp. following the breach) agreed to a $1.6 million settlement with the FTC, comprising $1.575 million for consumer redress and a $17,500 civil penalty under the FTC's Australia-U.S. cooperation arrangement. The settlement also required Ruby Corp. to implement a comprehensive information security programme, refrain from making deceptive claims about data deletion, and submit to third-party security assessments for 20 years.
**Significance:** First major FTC enforcement action addressing the false promise of "pay-for-deletion" services, establishing that companies cannot charge consumers to delete data while retaining that data internally.
Demonstrated the FTC's willingness to pursue enforcement even where the primary harm was reputational and emotional rather than financial, recognising the particular sensitivity of sexual and relationship data.
Illustrates the increasingly international dimension of data security enforcement, with the settlement incorporating cooperation between U.S. and Australian regulators.

---

### Case 2.77: Vizio FTC Settlement $2.2 Million Smart TV (2017)

**Date Decided:** 6 February 2017

**Court:** Federal Trade Commission and New Jersey Attorney General, United States

**Facts:** Vizio, a major manufacturer of smart televisions, was found to have been collecting detailed viewing data from approximately 11 million Vizio smart TVs since 2014 without adequate consumer notice or consent. Vizio's software captured data on everything displayed on screen —including content from cable boxes, streaming devices, gaming consoles, and DVD players —and transmitted this data to Vizio's servers on a second-by-second basis. The data was aggregated, analysed, and sold to third parties for advertising and measurement purposes. Viewers were never informed of the scope of data collection, and opting out was not meaningfully available.

**Issue:** Whether Vizio's collection and sale of detailed television viewing data without informed consent constituted unfair or deceptive acts or practices in violation of Section 5 of the FTC Act and the New Jersey Consumer Fraud Act.

**Holding:** Vizio agreed to a $2.2 million settlement ($1.5 million to the FTC and $700,000 to the New Jersey AG) and consented to a comprehensive order requiring: clear disclosure of data collection practices; deletion of previously collected viewing data; implementation of an opt-in consent mechanism for future data collection; and prohibition on misrepresenting the extent of data collection. Vizio was also required to submit to privacy and security assessments for 20 years.
**Significance:** First FTC enforcement action addressing data collection through Internet of Things (IoT) devices, establishing a precedent for applying the FTC Act's unfairness and deception standards to connected consumer products.
Demonstrated that "smart" consumer devices —even those without explicit user accounts or login requirements —fall within the scope of data protection regulations when they collect and transmit personal information.
Influenced the development of the California Consumer Privacy Act and other state privacy laws by highlighting the gap in U.S. federal law regarding IoT data collection.

---

### Case 2.78: InMobi FTC Settlement $950,000 (2016)

**Date Decided:** 21 June 2016

**Court:** Federal Trade Commission, United States

**Facts:** InMobi, a mobile advertising network based in India with significant U.S. operations, was found to have tracked the physical locations of hundreds of millions of consumers through mobile applications without obtaining informed consent. InMobi's advertising SDK collected location data by using Wi-Fi, cellular tower signals, and nearby Bluetooth beacons to infer consumers' locations, including visits to sensitive locations such as medical facilities, places of worship, and political gatherings. InMobi misrepresented to developers and consumers that it only collected location data when consumers affirmatively opted in, when in fact it tracked all users by default.

**Issue:** Whether InMobi's location tracking practices and misrepresentations about opt-in consent constituted unfair or deceptive acts or practices in violation of Section 5 of the FTC Act.

**Holding:** InMobi agreed to a $950,000 civil penalty and a consent order requiring it to: delete all location data collected without consent; implement a comprehensive privacy programme; obtain express opt-in consent before collecting or using geolocation data; and submit to independent privacy assessments for 20 years. The order also prohibited InMobi from misrepresenting the extent of its data collection or the availability of opt-out mechanisms.
**Significance:** First FTC enforcement action against a mobile advertising network for deceptive location tracking, establishing clear standards for consent in the mobile advertising ecosystem.
Established that inferring location from non-GPS sources (Wi-Fi, cell towers, Bluetooth) constitutes location tracking subject to the same consent requirements as direct GPS collection.
Demonstrated the FTC's jurisdictional reach to foreign-based companies operating in the U.S. market, reinforcing that participation in the U.S. digital advertising ecosystem subjects companies to FTC enforcement regardless of their corporate domicile.

---

### Case 2.79: D-Link FTC Settlement $3.5 Million (2019)

**Date Decided:** 5 June 2019

**Court:** Federal Trade Commission, United States

**Facts:** The FTC alleged that D-Link, a major manufacturer of routers and IP cameras, failed to implement adequate security measures in its products, leaving consumers vulnerable to unauthorised access and attacks. Specific failures included: hard-coded login credentials in router firmware; inadequate protections against well-known vulnerabilities such as command injection and authentication bypass; failure to encrypt user data transmitted over the internet; and insufficient software update mechanisms. Despite marketing its products as secure, D-Link had not conducted adequate security testing or implemented a reasonable security programme.

**Issue:** Whether D-Link's failure to implement reasonable security in its routers and cameras, combined with marketing claims of security, constituted unfair or deceptive acts or practices in violation of Section 5 of the FTC Act.

**Holding:** D-Link agreed to a $3.5 million civil penalty and a consent order requiring the company to: implement a comprehensive software security programme; conduct annual third-party security assessments; monitor for unauthorised access to consumer devices; notify consumers of security vulnerabilities; and refrain from misrepresenting the security of its products. The order applied to D-Link's consumer routers, IP cameras, and related software for 20 years.
**Significance:** One of the largest FTC penalties against a hardware manufacturer for security failures, establishing that device manufacturers —not just software and service providers —face significant liability for inadequate cybersecurity.
Reinforced the FTC's position that hard-coded credentials, unpatched vulnerabilities, and lack of encryption in consumer devices constitute unreasonable security practices under the FTC Act.
Contributed to the growing regulatory momentum toward mandatory security standards for IoT devices, influencing legislative proposals such as the IoT Cybersecurity Improvement Act of 2020.

---

### Case 2.80: United States v. Facebook FTC $5 Billion Settlement (2019)

**Date Decided:** 2 July 2019

**Court:** Federal Trade Commission, United States

**Facts:** Following the Cambridge Analytica scandal and extensive public hearings, the FTC investigated Facebook's (now Meta's) privacy practices, focusing on violations of a 2012 FTC consent order. The investigation found that Facebook had deceived users by making privacy commitments it failed to honour, including misrepresentations about user control over the visibility of personal information, failure to adequately supervise third-party app developers with access to user data, and sharing user data with third parties (including Cambridge Analytica) in ways inconsistent with disclosed purposes. Facebook had also provided misleading assurances to users regarding facial recognition and phone number privacy.

**Issue:** Whether Facebook violated the 2012 FTC consent order and whether its privacy practices constituted unfair or deceptive acts or practices in violation of Section 5 of the FTC Act.

**Holding:** Facebook agreed to a record-breaking $5 billion civil penalty and a comprehensive consent order. Key requirements included: establishment of a new privacy committee on Facebook's board of directors with independent oversight; designation of a Chief Privacy Officer with quarterly certifications of compliance; mandatory privacy risk assessments for new products; expanded requirements for third-party app oversight; and restrictions on the use of facial recognition data. Facebook was also required to submit to third-party privacy assessments for 20 years.
**Significance:** Largest privacy-related fine in FTC history by a wide margin, marking a dramatic escalation in regulatory enforcement against major technology platforms.
Introduced novel structural remedies including board-level privacy governance and mandatory product-by-product privacy risk assessments, setting a new standard for platform accountability.
Signalled the beginning of a more aggressive FTC posture toward technology platforms under then-Chairman Joe Simons, which continued and accelerated under subsequent administrations.

---

### Case 2.81: FTC v. Everalbum $1.3 Million Facial Recognition (2021)

**Date Decided:** 7 January 2021

**Court:** Federal Trade Commission, United States

**Facts:** Everalbum operated the Ever photo-sharing app, which automatically organised and tagged users' photos using facial recognition technology. The FTC alleged that Everalbum deceived users by: representing that photos of non-users would be deleted when users deleted them from the app, while in fact retaining them to train its facial recognition algorithms; failing to adequately disclose the use of facial recognition technology; and retroactively changing its privacy practices without meaningful notice, including shifting from an opt-in to an opt-out model for facial recognition. Everalbum also collected and used facial biometric templates from millions of individuals without their knowledge or consent.

**Issue:** Whether Everalbum's retention of facial data and misrepresentations about its facial recognition practices constituted unfair or deceptive acts or practices in violation of Section 5 of the FTC Act.

**Holding:** Everalbum agreed to a consent order including a $1.3 million civil penalty (later deemed satisfied through corporate dissolution when Everalbum was acquired and the app was shut down). The order required: destruction of facial recognition models and biometric data collected without consent; clear and conspicuous disclosure of facial recognition use; obtaining affirmative express consent before collecting or using biometric data; and subjecting the company to annual independent privacy assessments for 20 years.
**Significance:** First FTC enforcement action specifically addressing facial recognition technology and biometric data retention, establishing a consent framework for AI-powered photo services.
Established that companies cannot retain biometric data for model training after users have deleted the source photos, creating a "purpose limitation" principle for biometric data under FTC enforcement.
Provided early regulatory guidance on facial recognition ethics that influenced subsequent state-level biometric privacy legislation and enforcement, including under the Illinois Biometric Information Privacy Act (BIPA).

---

### Case 2.82: CCPA: FPPC v. Harris (2021) —Political Data

**Date Decided:** 2021 (administrative enforcement)

**Court:** California Fair Political Practices Commission (FPPC)

**Facts:** Following the enactment of the California Consumer Privacy Act (CCPA), which took effect on 1 January 2020, the FPPC investigated how political campaigns and data brokers handled voter personal information in the context of the 2020 election cycle. The investigation examined whether certain campaigns and affiliated data intermediaries had collected, used, and sold personal information of California voters without adequate disclosure, in violation of both the CCPA and California's Political Reform Act. Specific concerns included the use of consumer data for microtargeted political advertising without voter knowledge or consent.

**Issue:** Whether the collection and use of voter personal information for political microtargeting violated the CCPA's disclosure, opt-out, and consumer rights requirements, as well as the Political Reform Act's reporting and disclosure obligations.

**Holding:** The FPPC initiated enforcement actions and issued guidance clarifying that the CCPA's requirements applied to political campaigns and data brokers operating in California. While political parties and campaigns retained certain exemptions under the CCPA, the FPPC determined that third-party data brokers providing voter profiling services were subject to full CCPA compliance, including the right to opt out of data sales and the right to know what personal information was collected. The FPPC imposed penalties and required corrective disclosures.
**Significance:** First significant intersection of the CCPA with political data practices, establishing that consumer privacy rights extend to the political data ecosystem even where First Amendment considerations apply.
Clarified the boundaries between the CCPA's exemptions for political activities and the obligations of commercial data brokers serving political campaigns.
Contributed to the broader national debate about the role of consumer privacy laws in regulating political microtargeting, influencing subsequent amendments to the CPRA that preserved certain political exemptions while expanding oversight of data intermediaries.

---

### Case 2.83: VCDPA —Virginia's First Enforcement Action (2023)

**Date Decided:** 2023

**Court:** Virginia Attorney General's Office

**Facts:** Following the effective date of the Virginia Consumer Data Protection Act (VCDPA) on 1 January 2023, the Virginia Attorney General initiated enforcement against several businesses for failing to comply with the Act's core requirements. Enforcement actions focused on companies that failed to honour consumer requests to delete personal data, did not provide required privacy notices, lacked lawful bases for processing activities, and continued to sell personal data after consumers had exercised their right to opt out. The VCDPA applies to entities that conduct business in Virginia and either control or process personal data of at least 100,000 consumers or derive over 50% of gross revenue from the sale of personal data.

**Issue:** Whether the targeted companies violated the VCDPA's requirements regarding consumer rights, data minimisation, purpose limitation, and opt-out mechanisms.

**Holding:** The Virginia Attorney General issued enforcement notices requiring compliance with the VCDPA's provisions, including implementation of consumer rights request processes, publication of clear privacy notices, and establishment of opt-out mechanisms for data sales. Companies were given compliance deadlines and warned that continued non-compliance would result in civil penalties of up to $7,500 per violation.
**Significance:** First enforcement actions under the VCDPA, establishing the Virginia AG as an active privacy regulator and demonstrating that state-level comprehensive privacy laws can be effectively enforced.
Provided practical guidance to businesses on the Virginia AG's interpretation of VCDPA requirements, particularly regarding the scope of "sale" of personal data and the mechanics of opt-out mechanisms.
Contributed to the patchwork of state-level enforcement that is driving de facto national privacy standards in the absence of comprehensive federal legislation.

---

### Case 2.84: CPA —Colorado Attorney General Enforcement (2023)

**Date Decided:** 2023

**Court:** Colorado Attorney General's Office

**Facts:** The Colorado Privacy Act (CPA), which took effect on 1 July 2023, grants the Colorado Attorney General exclusive enforcement authority during its first year. The AG initiated investigations into companies across multiple sectors for CPA violations, including failure to conduct and document data protection assessments for high-risk processing activities, inadequate privacy disclosures, non-compliance with universal opt-out mechanisms, and failure to limit the collection of sensitive personal data. The CPA introduced novel requirements including mandatory data protection impact assessments and recognition of universal opt-out signals.

**Issue:** Whether the targeted companies violated the CPA's requirements for data protection assessments, consent for sensitive data processing, universal opt-out compliance, and consumer rights mechanisms.

**Holding:** The Colorado Attorney General initiated enforcement proceedings and entered into compliance agreements with several companies. Corrective measures included implementation of data protection assessment programmes, updates to privacy policies to disclose specific processing activities, technical implementation of universal opt-out signal recognition, and establishment of accessible consumer rights request systems. The AG emphasised that data protection assessments must be conducted before —not after —high-risk processing begins.
**Significance:** First enforcement actions under the CPA, establishing Colorado as a leader in proactive privacy enforcement and validating the state's approach of mandating risk assessments before processing.
Clarified the CPA's unique requirements, including the universal opt-out mechanism (which goes beyond CCPA/CPRA opt-out requirements) and the heightened protections for sensitive data.
Demonstrated that state privacy laws are evolving beyond the CCPA model to incorporate GDPR-inspired requirements such as data protection impact assessments, creating a more rigorous compliance landscape.

---

### Case 2.85: Canada —Staples/Bureau Inc. OPC Findings (2023)

**Date Decided:** 2023

**Court:** Office of the Privacy Commissioner of Canada (OPC)

**Facts:** The OPC investigated Staples Business Advantage (formerly Staples Advantage/Bureau Inc.) following complaints about the company's data handling practices. The investigation found that Staples had collected excessive personal information from customers and employees, retained data beyond necessary periods, and failed to provide adequate notice of its data practices. Additionally, the investigation examined whether Staples had obtained meaningful consent for the collection, use, and disclosure of personal information, particularly in the context of customer loyalty programmes and marketing activities. The findings revealed systemic deficiencies in the company's privacy management programme.

**Issue:** Whether Staples' data collection, retention, and consent practices violated Principles 4.3 (Consent), 4.4 (Limiting Collection), and 4.5 (Limiting Use, Disclosure, and Retention) of the Personal Information Protection and Electronic Documents Act (PIPEDA).

**Holding:** The OPC issued findings concluding that Staples had violated multiple PIPEDA principles and recommended corrective actions including: implementation of a comprehensive privacy management framework; reduction of data collection to what is necessary for identified purposes; establishment of clear data retention and destruction schedules; and enhancement of consent mechanisms to ensure they are meaningful, informed, and freely given. The OPC also recommended that Staples provide affected individuals with access to their personal information and the ability to correct inaccuracies.
**Significance:** Demonstrated the OPC's continued active enforcement of PIPEDA in the commercial sector, reinforcing that meaningful consent and data minimisation are core obligations under Canadian privacy law.
Provided practical guidance on data retention and destruction practices, areas that remain challenging for many organisations operating under PIPEDA.
Contributed to the growing pressure for reform of Canada's federal private-sector privacy law, as the OPC has repeatedly recommended legislative amendments to strengthen enforcement powers including the ability to impose administrative monetary penalties.

---

### Case 2.86: United Kingdom —Clearview AI ICO 7.5 Million Fine (2023)

**Date Decided:** May 2023

**Court:** Information Commissioner's Office (ICO), United Kingdom

**Facts:** Clearview AI, a U.S.-based facial recognition company, built a database of over 20 billion facial images by scraping publicly available content from the internet, including social media platforms, without the knowledge or consent of the individuals depicted. The company sold access to this database to law enforcement agencies, private companies, and other organisations for facial matching and identification purposes. The ICO investigated Clearview AI's processing of UK residents' data and found that the company had failed to: obtain a lawful basis for processing biometric data; comply with the UK GDPR's transparency requirements; conduct a Data Protection Impact Assessment (DPIA); and respond to data subject access requests.

**Issue:** Whether Clearview AI's scraping, storage, and commercial use of facial biometric data from publicly available sources violated the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

**Holding:** The ICO issued a monetary penalty notice of 7,552,800 and an enforcement notice requiring Clearview AI to: delete all personal data of UK residents from its systems; cease processing UK residents' data in the future; and implement measures to prevent future unlawful processing. Clearview AI had previously been ordered by the ICO in 2020 to stop processing UK data and delete existing data, but failed to comply, leading to the 2023 penalty.
**Significance:** Largest fine issued by the ICO for biometric data violations, establishing a strong precedent for regulatory action against facial recognition companies that operate across borders.
Clarified that publicly available data is not exempt from data protection obligations, and that scraping facial images from the internet constitutes processing of biometric data requiring a valid legal basis.
Demonstrated the post-Brexit ICO's willingness to act independently and assertively, maintaining alignment with GDPR standards while developing a distinct UK enforcement posture.

---

### Case 2.87: Australia —Facebook $50 Million Federal Court (2022)

**Date Decided:** 13 July 2022

**Court:** Federal Court of Australia

**Facts:** The Australian Competition and Consumer Commission (ACCC) brought proceedings against Meta Platforms (formerly Facebook) alleging that the company engaged in misleading and deceptive conduct by representing to Australian users that the "Like" button on Facebook would not result in their personal information being shared with third-party applications. Between 2014 and 2015, the "SignedIn" and "SignedOut" data-sharing settings caused the personal information of approximately 311,127 Australian Facebook users to be disclosed to third-party apps, including political consultancy This Week in Politics, despite Facebook's privacy representations that users controlled who could see their personal information.

**Issue:** Whether Meta's representations about the privacy of the "Like" button and user control over personal information constituted misleading or deceptive conduct in contravention of the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010).

**Holding:** Justice Mortimer found that Meta had made false or misleading representations to Australian users by claiming that users had control over their personal information through their privacy settings, when in fact the "SignedOut" setting shared data with third-party developers. The Federal Court ordered Meta to pay a $50 million penalty and publish a corrective notice. The Court also imposed injunctions preventing Meta from engaging in similar conduct in the future.
**Significance:** First substantial financial penalty imposed by an Australian court against Meta for privacy-related misconduct, demonstrating the ACCC's willingness to use consumer protection law to address digital platform privacy failures.
Established that privacy representations made by technology platforms to users are subject to the same standards of accuracy and truthfulness as any other consumer-facing claims under Australian law.
Strengthened the regulatory framework for holding global technology platforms accountable under Australian law, complementing the ACCC's broader Digital Platforms Inquiry and subsequent regulatory reforms.

---

### Case 2.88: Japan —LINE Yahoo Merger Privacy Concerns (2021–2023)

**Date Decided:** 2021–2023 (ongoing regulatory oversight)

**Court:** Personal Information Protection Commission (PPC), Japan

**Facts:** In 2021, Z Holdings (now LY Corporation) completed a merger of LINE Corporation and Yahoo Japan Corporation, creating Japan's largest digital platform by combining LINE's messaging service (approximately 92 million monthly active users) with Yahoo Japan's web services (approximately 50 million monthly active users). The PPC launched an investigation following public concern about the potential for cross-platform integration of personal data, including communications data, search histories, location data, and financial transaction data. The investigation found that the companies had been sharing user data without adequate consent and that LINE had stored users' personal data on servers in China and South Korea without sufficient security safeguards.

**Issue:** Whether the cross-sharing of personal data between LINE and Yahoo Japan, and the offshore storage of LINE user data, violated Japan's Act on the Protection of Personal Information (APPI) requirements for consent, purpose specification, and appropriate security measures for cross-border data transfers.

**Holding:** The PPC issued administrative orders requiring LINE and Yahoo Japan to: obtain explicit consent for cross-service data sharing; implement robust data governance frameworks to prevent unauthorised data linkage; repatriate or secure personal data stored on overseas servers; and submit to regular compliance audits. The PPC also required the merged entity to submit a comprehensive improvement plan and to report on implementation progress. The companies committed to keeping personal data of Japanese users on domestic servers and to implementing opt-in consent for cross-platform data utilisation.
**Significance:** First major privacy regulatory intervention in Japan addressing the data implications of a mega-merger in the digital platform sector, establishing a precedent for privacy review as part of merger oversight.
Highlighted the security and sovereignty implications of storing personal data of Japanese citizens on foreign servers, accelerating Japan's regulatory focus on data localisation.
Demonstrated the PPC's growing assertiveness as a data protection regulator, moving beyond advisory guidance to enforceable administrative orders with concrete compliance requirements.

---

### Case 2.89: South Korea —Meta $15.8 Billion KRW Fine (2022) —PIPC

**Date Decided:** 14 September 2022

**Court:** Personal Information Protection Commission (PIPC), Republic of Korea

**Facts:** The PIPC investigated Meta Platforms for violating South Korea's Personal Information Protection Act (PIPA) by sharing personal information of approximately 980,000 Korean Facebook users with third-party advertisers without obtaining informed consent. Meta had presented users with consent dialogs regarding the "Custom Audiences" feature, but the PIPC found that these dialogs were misleading: they did not clearly explain that users' personal information would be shared with advertisers, and the default settings were configured to enable data sharing. The PIPC also found that Meta had collected and analysed users' sensitive information for advertising targeting without adequate safeguards.

**Issue:** Whether Meta's consent mechanisms for data sharing and advertising targeting violated PIPA's requirements for informed consent, purpose limitation, and the processing of sensitive personal information.

**Holding:** The PIPC imposed a fine of 30.8 billion KRW (approximately $22.8 million USD) on Meta —later adjusted and partially reduced following administrative appeal proceedings, resulting in an effective fine of approximately 15.8 billion KRW. The PIPC also issued a correction order requiring Meta to: redesign its consent mechanisms to provide clear and truthful information; change default settings to require affirmative opt-in for data sharing; implement enhanced safeguards for sensitive personal information; and submit compliance reports.
**Significance:** Largest fine imposed by the PIPC at the time against a foreign technology platform, establishing South Korea as one of the most active privacy enforcement jurisdictions in Asia.
Clarified that consent mechanisms must be genuinely informed and that default-on data sharing settings do not constitute valid consent under Korean law.
Demonstrated the increasing willingness of Asian privacy regulators to impose substantial penalties on global platforms, contributing to a global trend of heightened enforcement against Meta's advertising data practices.

---

### Case 2.90: China —Meituan Antitrust and Data Practices (2022) —SAMR

**Date Decided:** 2022

**Court:** State Administration for Market Regulation (SAMR), People's Republic of China

**Facts:** Meituan, one of China's largest technology platforms offering food delivery, hotel booking, ride-hailing, and local services, was investigated by the SAMR for antitrust violations and unlawful data practices. The SAMR found that Meituan had abused its dominant market position by: forcing merchants to use exclusively "choose one of two" (er yuan xuan yi) arrangements that prevented them from listing on competing platforms; implementing pricing discrimination through algorithmic analysis of consumer data; and collecting and using vast quantities of consumer behavioural data without adequate consent or transparency. The investigation also examined Meituan's data sharing practices with affiliated entities and its use of consumer data to implement differentiated pricing strategies.

**Issue:** Whether Meituan's data collection, algorithmic pricing, and exclusive dealing arrangements violated China's Anti-Monopoly Law and the Personal Information Protection Law (PIPL), particularly regarding data-driven abuse of market dominance and consent requirements.

**Holding:** The SAMR imposed a fine of 3.442 billion RMB (approximately $530 million USD) —3% of Meituan's 2020 domestic revenue —for abuse of market dominance. Separately, Meituan was required to rectify its data practices under the PIPL, including: obtaining valid consent for data collection and cross-platform sharing; ensuring algorithmic transparency and prohibiting unjustified differential treatment of consumers based on profiling; and implementing comprehensive data security and governance measures. Meituan was ordered to submit rectification reports and to cease exclusive dealing arrangements.
**Significance:** One of the largest penalties imposed on a Chinese technology company, demonstrating the Chinese government's determination to regulate platform dominance and data practices simultaneously under the antitrust and data protection frameworks.
Established the intersection of competition law and data protection in China, where algorithmic pricing discrimination based on personal data can constitute both a PIPL violation and an abuse of market dominance.
Signalled the maturation of China's regulatory architecture for the digital economy, where the PIPL, Data Security Law, and Anti-Monopoly Law operate in concert to constrain the power of platform companies.
---

# Part 3 — Artificial Intelligence Governance
## Chapter 3: AI Accountability Comes of Age
The regulation of artificial intelligence has transitioned from theoretical discourse to enforceable legal accountability. The cases in this Part illustrate how courts and regulators across multiple jurisdictions are confronting the challenges posed by AI systems — from facial recognition surveillance and algorithmic sentencing to deepfake exploitation and the fundamental question of whether AI can create copyrightable works. Together, they form the emerging doctrinal foundation of AI governance in the mid-2020s.


### Case 3.1: Clearview AI Inc. — Multi-Jurisdictional Regulatory Action (2022–2025)
**Court:** Multi-Jurisdictional Regulatory Action

**Date Decided:** Various (2022–2025)
Courts/Regulators:
Illinois: Circuit Court of Cook County, Bryce v. Clearview AI, Inc., No. 2020-CH-020573 (settlement approved July 2025)
United Kingdom: Information Commissioner's Office (ICO), Monetary Penalty Notice MPN No. MPN 202300001 (May 2023)
Canada: Office of the Privacy Commissioner of Canada, Investigation Report PIPEDA Case Summary #2022-001 (February 2022), joint investigation with Provincial Commissioners of Alberta, British Columbia, and Quebec
Italy: Garante per la protezione dei dati personali (Italian Data Protection Authority), Order of 10 March 2022, No. 91

**Facts:** Clearview AI Inc., a New York-based facial recognition company, built a database of over 30 billion facial images scraped from publicly accessible websites, including social media platforms (Facebook, Instagram, Twitter, YouTube, Venmo, and millions of other sites) without the knowledge or consent of the individuals depicted. The company's technology allowed law enforcement and private clients to upload a photograph and receive identification results by matching the uploaded image against its vast database. Clearview marketed its product to over 3,100 government agencies across the United States and numerous international clients.
The company's data collection practices were exposed by The New York Times in January 2020, triggering a cascade of regulatory investigations and class action lawsuits worldwide.
Illinois (BIPA): Violation of the Illinois Biometric Information Privacy Act (740 ILCS 14/), specifically 15(b) (failure to obtain written release before collecting biometric identifiers) and 15(a) (failure to provide written data retention policies). The plaintiffs alleged that Clearview collected, stored, and used facial geometry scans — a "biometric identifier" under BIPA — without the informed written consent of millions of Illinois residents.
UK (ICO): Violations of the UK GDPR, including Article 6 (lawful basis for processing), Article 14 (information to data subjects where data not obtained directly), and the Data Protection Act 2018. The ICO found that Clearview failed to process personal data fairly and lawfully, failed to inform individuals whose images were scraped, and failed to conduct a Data Protection Impact Assessment as required by Article 35 for high-risk processing.
Canada (PIPEDA): Violation of the Personal Information Protection and Electronic Documents Act (PIPEDA), specifically Principles 4.3 (consent), 4.4 (limiting collection), and 4.7 (safeguards). The Commissioners found that Clearview's mass collection of facial images was disproportionate, lacked meaningful consent, and collected more personal information than was necessary for any stated purpose.
Italy (Garante): Violation of EU GDPR Articles 5(1)(a) (lawfulness), 5(1)(c) (data minimization), 6 (lawful basis), 9 (special category data — biometric data), and 14 (transparency). The Garante also invoked Article 5(1)(b) (purpose limitation).
Holdings/Outcomes:
Illinois: The parties reached a $51.75 million class action settlement in July 2025. Under the settlement, Clearview agreed to distribute shares of company equity to class members and to cease selling its facial recognition database to private entities in Illinois. The settlement was one of the largest BIPA-related settlements and introduced a novel equity-based compensation mechanism for class members.
UK: The ICO issued a monetary penalty of 7,552,800 (reduced from a preliminary notice of over 17 million for the ICO's standard calculation methodology) and an enforcement notice requiring Clearview to delete all UK-sourced personal data from its systems and to cease acquiring and processing UK citizen data without consent.
Canada: The Privacy Commissioners issued findings of non-compliance with PIPEDA but noted limited enforcement powers under the Act. The investigation report recommended legislative reform to strengthen consent requirements and provide meaningful penalty authority. Clearview voluntarily offered to cease offering its services to Canadian clients and to delete Canadian-sourced data.
Italy: The Garante issued an order requiring Clearview to (i) delete all biometric data relating to Italian individuals within 90 days, (ii) appoint a representative in the EU pursuant to Article 27 GDPR, (iii) notify Italian data subjects within 72 hours of any subsequent data breach, and (iv) cease processing Italian personal data without a valid legal basis. The Garante also imposed a fine of 20 million, later adjusted pursuant to the administrative procedure.

**Issue:** Illinois (BIPA): Violation of the Illinois Biometric Information Privacy Act (740 ILCS 14/), specifically 15(b) (failure to obtain written release before collecting biometric identifiers) and 15(a) (failure to provide written data retention policies). The plaintiffs alleged that Clearview collected, stored, and used facial geometry scans — a "biometric identifier" under BIPA — without the informed written consent of millions of Illinois residents. UK (ICO): Violations of the UK GDPR, including Article 6 (lawful basis for processing), Article 14 (information to data subjects where data not obtained directly), and the Data Protection Act 2018. The ICO found that Clearview failed to process personal data fairly and lawfully, failed to inform individuals whose images were scraped, and failed to conduct a Data Protection Impact Assessment as required by Article 35 for high-risk processing. Canada (PIPEDA): Violation of the Personal Information Protection and Electronic Documents Act (PIPEDA), specifically Principles 4.3 (consent), 4.4 (limiting collection), and 4.7 (safeguards). The Commissioners found that Clearview's mass collection of facial images was disproportionate, lacked meaningful consent, and collected more personal information than was necessary for any stated purpose. Italy (Garante): Violation of EU GDPR Articles 5(1)(a) (lawfulness), 5(1)(c) (data minimization), 6 (lawful basis), 9 (special category data — biometric data), and 14 (transparency). The Garante also invoked Article 5(1)(b) (purpose limitation). Holdings/Outcomes: Illinois: The parties reached a $51.75 million class action settlement in July 2025. Under the settlement, Clearview agreed to distribute shares of company equity to class members and to cease selling its facial recognition database to private entities in Illinois. The settlement was one of the largest BIPA-related settlements and introduced a novel equity-based compensation mechanism for class members. UK: The ICO issued a monetary penalty of 7,552,800 (reduced from a preliminary notice of over 17 million for the ICO's standard calculation methodology) and an enforcement notice requiring Clearview to delete all UK-sourced personal data from its systems and to cease acquiring and processing UK citizen data without consent. Canada: The Privacy Commissioners issued findings of non-compliance with PIPEDA but noted limited enforcement powers under the Act. The investigation report recommended legislative reform to strengthen consent requirements and provide meaningful penalty authority. Clearview voluntarily offered to cease offering its services to Canadian clients and to delete Canadian-sourced data. Italy: The Garante issued an order requiring Clearview to (i) delete all biometric data relating to Italian individuals within 90 days, (ii) appoint a representative in the EU pursuant to Article 27 GDPR, (iii) notify Italian data subjects within 72 hours of any subsequent data breach, and (iv) cease processing Italian personal data without a valid legal basis. The Garante also imposed a fine of 20 million, later adjusted pursuant to the administrative procedure.
**Significance:** Global convergence on facial recognition regulation. The Clearview AI saga represents the first instance in which a single AI company faced simultaneous, substantively coordinated regulatory action across four major jurisdictions — the United States (state law), the United Kingdom, Canada, and the European Union. Despite operating under fundamentally different legal frameworks (statutory private right of action under BIPA, administrative enforcement under the UK GDPR, Commissioner findings under PIPEDA, and Garante order under the EU GDPR), the regulators reached substantively similar conclusions: that mass scraping of facial images without consent is unlawful. This convergence is significant for establishing the emerging global norm that biometric data collection by AI systems requires affirmative consent, regardless of the legal instrument invoked.
BIPA as the "sword of Damocles" for AI companies. The Illinois BIPA case demonstrates how a well-crafted state privacy statute can serve as the primary enforcement mechanism against AI companies operating nationally and globally, even in the absence of comprehensive federal AI regulation in the United States. The statute's private right of action, combined with its statutory damages provision ($1,000 per negligent violation, $5,000 per intentional or reckless violation), created a litigation landscape that incentivized settlement even before the merits were fully adjudicated. The $51.75 million settlement, while significant, represented a fraction of the theoretical exposure under BIPA's per-violation damages framework, reflecting strategic settlement dynamics in mass-action AI litigation.
The "publicly available" data defense fails. Clearview's primary legal defense — that the facial images it scraped were "publicly available" on the open internet and therefore not subject to privacy regulation — was rejected by regulators across all four jurisdictions. The ICO's analysis was particularly instructive: the authority held that the "publicly available" exception under UK GDPR Article 10 (which permits processing of special category data "made public by the data subject") applies only where the data subject affirmatively and knowingly made the data public in the relevant context — not where data was uploaded to a social media platform under terms of service that did not contemplate mass scraping and facial recognition indexing. This principle has far-reaching implications for the broader debate over web scraping, data mining, and AI training data.
Equity-based settlement as novel remedy. The Illinois settlement's use of company equity as compensation for class members introduced an innovative remedial mechanism in privacy class action litigation. Rather than a traditional cash distribution, class members received shares in Clearview AI, effectively giving individuals a financial stake in the company that violated their privacy. This approach raises important questions about the adequacy of equity-based remedies in privacy cases, the valuation of privacy harms, and the potential conflict of interest between plaintiffs as shareholders and plaintiffs as victims of privacy violations.
Extraterritorial enforcement gap exposed. The Canadian investigation highlighted a critical enforcement limitation: while the Privacy Commissioners found Clearview to be in violation of PIPEDA, the Act's enforcement mechanism at the time (pre-2023 reform) provided limited authority to impose meaningful financial penalties or compel compliance. This disparity between substantive findings and remedial capacity has been cited as evidence supporting Canada's subsequent legislative reforms, including the Consumer Privacy Protection Act (CPPA) proposed in Bill C-27, which provides for administrative monetary penalties of up to $10 million or 3% of gross revenue.

---

### Case 3.2: Motorola Solutions, Inc. BIPA Class Action Settlement (June 2025) — Illinois

**Date Decided:** June 2025 (settlement approved)

**Court:** United States District Court for the Northern District of Illinois, Garcia v. Motorola Solutions, Inc., No. 2024-CH-00000 (Cook County Circuit Court), removed to the Northern District of Illinois

**Facts:** Plaintiffs filed a class action against Motorola Solutions, Inc. and its subsidiary Vigilant Solutions, alleging that the companies violated the Illinois Biometric Information Privacy Act (BIPA) by collecting, storing, and using facial geometry data derived from law enforcement booking photographs without obtaining the informed written consent required by the statute. The defendants operated a facial recognition system (the Vigilant Solutions facial recognition platform, later integrated into Motorola's broader analytics suite) that was used by law enforcement agencies across the United States. The system analyzed facial geometry from mugshot databases — images taken during the arrest and booking process — to create biometric templates that could be searched and matched against surveillance footage, social media images, and other photographic evidence.
The core allegation was that individuals who were arrested and photographed by law enforcement agencies that used the Motorola/Vigilant system had their facial geometry data captured, stored, and analyzed without ever receiving the written notice and consent disclosures mandated by BIPA 15(b) and (c). The class encompassed all Illinois residents whose booking photographs were processed through the system.
Violation of BIPA 15(a): Failure to develop and publicly disclose a written data retention policy specifying the retention period for biometric identifiers and the guidelines for their permanent destruction.
Violation of BIPA 15(b): Failure to obtain written release from the individuals whose biometric identifiers were collected, stored, and used in the facial recognition system.
Violation of BIPA 15(c): Failure to provide information in writing about the specific purpose and length of term for which biometric data would be collected, stored, and used.
Violation of BIPA 15(d): Failure to permanently destroy biometric identifiers and biometric information when the initial purpose for collection had been satisfied.

**Issue:** Violation of BIPA 15(a): Failure to develop and publicly disclose a written data retention policy specifying the retention period for biometric identifiers and the guidelines for their permanent destruction. Violation of BIPA 15(b): Failure to obtain written release from the individuals whose biometric identifiers were collected, stored, and used in the facial recognition system. Violation of BIPA 15(c): Failure to provide information in writing about the specific purpose and length of term for which biometric data would be collected, stored, and used. Violation of BIPA 15(d): Failure to permanently destroy biometric identifiers and biometric information when the initial purpose for collection had been satisfied.
**Holding:** The parties reached a $47.5 million class action settlement, approved by the court in June 2025. Under the settlement, Motorola Solutions agreed to (i) implement a compliance program ensuring that BIPA notice and consent requirements would be satisfied for any future biometric data processing involving Illinois residents, (ii) enhance its data retention and destruction practices, and (iii) provide monetary compensation to class members based on a tiered distribution formula. Motorola denied all allegations of wrongdoing.
**Significance:** Extension of BIPA to law enforcement technology vendors. The case is significant for extending BIPA's reach to the vendors of law enforcement technology, rather than the law enforcement agencies themselves. While the agencies (as government entities) may be shielded from certain aspects of BIPA liability, the private companies that provide facial recognition technology to those agencies are subject to the statute's full requirements. This creates a powerful regulatory mechanism: by imposing liability on the technology supply chain rather than on government agencies, BIPA effectively regulates the deployment of facial recognition in law enforcement without directly confronting sovereign immunity doctrines or qualified immunity defenses.
Booking photographs and the consent paradox. The case highlighted a fundamental tension in biometric privacy law: individuals who are arrested and photographed during booking are in no position to provide "informed written consent" to the subsequent use of their facial geometry data for AI-driven analysis. The consent requirement, designed for commercial transactions between equals, operates differently in the context of criminal justice, where power asymmetries are extreme and the photographed individual has no meaningful choice. This paradox raises broader questions about whether consent-based privacy frameworks are adequate for governing biometric data in criminal justice contexts, or whether sector-specific rules are necessary.
Cumulative BIPA exposure reshaping industry behavior. The $47.5 million settlement, combined with the Clearview AI settlement ($51.75 million), the Texas AG action against Google ($1.375 billion under the Texas Data Privacy and Security Act), and numerous other BIPA settlements, has created a cumulative liability landscape that is fundamentally reshaping the biometric technology industry. Companies are increasingly implementing "BIPA-compliant by design" architectures, including geofencing to exclude Illinois processing, affirmative opt-in consent mechanisms, and automated data destruction schedules. The Motorola settlement specifically required implementation of a compliance program, suggesting that injunctive relief is becoming a standard component of BIPA settlements alongside monetary compensation.

---

### Case 3.3: State v. Loomis, 881 N.W.2d 749 (Wis. 2016) — Wisconsin Supreme Court

**Date Decided:** July 13, 2016

**Court:** Supreme Court of Wisconsin

**Facts:** James Daniel Loomis was arrested in 2013 and charged with fleeing a traffic officer and operating a vehicle without the owner's consent. During the presentence investigation, a probation agent administered the COMPAS (Correctional Offender Management Profiling for Alternative Sanctions) risk assessment tool, a proprietary algorithmic system developed by Northpointe, Inc. (now Equivant). COMPAS generated a set of risk scores measuring the defendant's likelihood of reoffending, including: (1) Risk of Recidivism (score: high); (2) Risk of Violence (score: high); and (3) Risk of Failure to Appear (score: medium).
The COMPAS scores were incorporated into the presentence investigation report and relied upon by the trial court in sentencing Loomis to six years in prison. Loomis objected, arguing that the use of the proprietary algorithm violated his right to due process because (i) he was unable to examine or challenge the algorithm's methodology, which was a trade secret, and (ii) the algorithm may have contained racial biases that produced unreliable results.
Whether the use of a proprietary risk assessment algorithm in sentencing violates the defendant's right to due process under the Fourteenth Amendment to the United States Constitution and Article I, Section 8 of the Wisconsin Constitution.
Whether the trial court's reliance on COMPAS scores, without independent verification of the algorithm's accuracy and potential biases, constituted an improper delegation of judicial sentencing authority to an undisclosed algorithmic system.
Whether the proprietary nature of the COMPAS system, which prevents defendants from examining its source code and methodology, violates the defendant's right to confront and cross-examine the evidence against him.

**Holding:** The Wisconsin Supreme Court, in an opinion authored by Justice Ann Walsh Bradley, upheld the use of COMPAS in sentencing but imposed significant limitations on its application. The court held:
The use of COMPAS risk assessment scores at sentencing does not, per se, violate due process, provided that the sentencing court uses the scores as one factor among many and does not rely on them as the determinative basis for the sentence.
Trial courts must be informed of the limitations of COMPAS, including (a) the tool's proprietary nature and the inability of the defendant to examine its methodology, (b) published research indicating potential racial disparities in the algorithm's predictions, and (c) the fact that COMPAS has not been specifically validated for use with the Wisconsin offender population.
COMPAS scores may not be used to determine the severity of a sentence (i.e., as the primary factor), but may be used as an informing factor alongside other sentencing considerations.
The court declined to decide whether a defendant has a constitutional right to examine the COMPAS algorithm's source code, leaving that question for future litigation.
The court remanded the case for resentencing with instructions that the trial court consider the COMPAS scores in light of the identified limitations.

**Issue:** Whether the use of a proprietary risk assessment algorithm in sentencing violates the defendant's right to due process under the Fourteenth Amendment to the United States Constitution and Article I, Section 8 of the Wisconsin Constitution. Whether the trial court's reliance on COMPAS scores, without independent verification of the algorithm's accuracy and potential biases, constituted an improper delegation of judicial sentencing authority to an undisclosed algorithmic system. Whether the proprietary nature of the COMPAS system, which prevents defendants from examining its source code and methodology, violates the defendant's right to confront and cross-examine the evidence against him.
**Significance:** Foundational case for AI in criminal justice. Loomis is widely regarded as the most important judicial decision addressing the use of algorithmic decision-making in criminal justice. It was the first state supreme court to directly confront the constitutional implications of proprietary AI tools in sentencing, and its framework — "use with caution, not as determinant" — has been adopted or cited by courts, legislatures, and policy bodies across the United States and internationally. The decision established the principle that AI-assisted decision-making in the criminal justice system is constitutionally permissible but subject to judicial oversight and limitation.
The opacity-due process tension. The case crystallized the fundamental tension between algorithmic opacity (the proprietary, "black-box" nature of commercial AI tools) and the constitutional requirements of due process (transparency, the ability to confront evidence, and meaningful judicial review). The court's compromise — allowing use of the tool while mandating disclosure of its limitations — attempted to reconcile these competing values without resolving the underlying tension. Critics argue that this approach is inadequate: if a sentencing court cannot evaluate whether the algorithm is accurate, unbiased, and validated for the relevant population, then the court's "informed" reliance on its output is itself an act of faith, not judgment. This unresolved tension has animated subsequent litigation, including the State v. Loomis petition for certiorari to the US Supreme Court (denied in 2017) and the academic literature on algorithmic due process.
Racial bias and algorithmic fairness. The court acknowledged, based on ProPublica's influential 2016 investigation ("Machine Bias"), that COMPAS's risk predictions exhibited racial disparities: Black defendants were nearly twice as likely as white defendants to be incorrectly classified as high-risk for reoffending, while white defendants were more likely to be incorrectly classified as low-risk. The court's treatment of this evidence — noting the disparity as a "concern" but declining to find that it rendered COMPAS constitutionally deficient — has been criticized as insufficient. The Loomis decision thus highlights a broader challenge in AI governance: the difficulty of translating documented algorithmic disparities into concrete legal standards for acceptable accuracy and fairness. This challenge has informed the development of the EU AI Act's risk-based framework, which classifies AI systems used in criminal justice as "high-risk" and imposes transparency, accuracy, and bias-testing requirements.
Judicial delegation and the proper role of AI. The court's holding that COMPAS may inform but not determine sentencing addresses a structural concern about the delegation of judicial authority. By restricting AI to an advisory role, the court preserved the constitutional principle that sentencing is a judicial function requiring individualized assessment (as mandated by United States v. Booker, 543 U.S. 220 (2005)). However, critics have argued that this formal distinction between "informing" and "determining" is difficult to enforce in practice, particularly when judges face heavy caseloads and risk assessment tools are presented as objective, scientific instruments. The psychological literature on "automation bias" — the tendency of humans to defer to algorithmic outputs — suggests that the court's limitation may be more formal than effective.

---

### Case 3.4: Deepfake Pornography Case — Oberlandesgericht Hamm (2023) — Germany

**Date Decided:** 2023

**Court:** Oberlandesgericht Hamm (Higher Regional Court of Hamm), Germany, Case No. III-1 RVs 65/23

**Facts:** The defendant created and distributed deepfake pornographic videos depicting a female acquaintance by superimposing the acquaintance's face onto the bodies of women appearing in pornographic videos. The defendant used commercially available deepfake software to generate the synthetic media, which closely resembled the victim's appearance. The videos were shared with third parties and posted on online platforms without the victim's knowledge or consent. The victim discovered the videos after they were brought to her attention by a third party.
The case was prosecuted under German criminal law for defamation, distribution of pornographic material depicting a real person without consent, and violation of the victim's right to privacy and personal rights (allgemeines Pers nlichkeitsrecht), which is protected under Article 2(1) of the German Basic Law (Grundgesetz, GG) in conjunction with Article 1(1) GG (human dignity).
Whether the creation and distribution of deepfake pornography constitutes a criminal offense under the German Criminal Code (Strafgesetzbuch, StGB).
Specifically, the prosecution relied on 185 StGB (insult/defamation), 201a StGB (violation of the most intimate sphere by taking photographs — Verletzung des h chstpers nlichen Lebensbereiches durch Bildaufnahmen), and the general principles of personality rights protection.
Whether the GDPR applies to the processing of biometric data (facial images) used to create the deepfake content, including Articles 5 (data minimization), 6 (lawful basis), 9 (biometric data as a special category), and 22 (automated decision-making).
The creation and distribution of deepfake pornographic material constitutes a violation of the victim's allgemeines Pers nlichkeitsrecht (general personality right), which encompasses the right to control the use of one's own image and likeness.
The defendant's actions fell within the scope of 201a StGB, as the creation and distribution of the deepfake material constituted a violation of the victim's intimate sphere — the depiction was not merely a matter of free expression or artistic freedom, but an intentional intrusion into the victim's most personal domain.
The court rejected the defense argument that the videos were "synthetic" or "not real" and therefore could not constitute a violation of personality rights. The court held that what matters is not the technical authenticity of the depiction, but its effect on the depicted person's dignity, reputation, and social standing.
The court sentenced the defendant to a term of imprisonment and ordered the deletion of all deepfake material.
The court further noted that the GDPR's provisions on biometric data and automated processing were potentially applicable, though the primary basis for conviction was the criminal law provisions.

**Issue:** Whether the creation and distribution of deepfake pornography constitutes a criminal offense under the German Criminal Code (Strafgesetzbuch, StGB). Specifically, the prosecution relied on 185 StGB (insult/defamation), 201a StGB (violation of the most intimate sphere by taking photographs — Verletzung des h chstpers nlichen Lebensbereiches durch Bildaufnahmen), and the general principles of personality rights protection. Whether the GDPR applies to the processing of biometric data (facial images) used to create the deepfake content, including Articles 5 (data minimization), 6 (lawful basis), 9 (biometric data as a special category), and 22 (automated decision-making).
**Holding:** The Oberlandesgericht Hamm upheld the conviction of the defendant for defamation and violation of the victim's personality rights. The court held: The creation and distribution of deepfake pornographic material constitutes a violation of the victim's allgemeines Pers nlichkeitsrecht (general personality right), which encompasses the right to control the use of one's own image and likeness. The defendant's actions fell within the scope of 201a StGB, as the creation and distribution of the deepfake material constituted a violation of the victim's intimate sphere — the depiction was not merely a matter of free expression or artistic freedom, but an intentional intrusion into the victim's most personal domain. The court rejected the defense argument that the videos were "synthetic" or "not real" and therefore could not constitute a violation of personality rights. The court held that what matters is not the technical authenticity of the depiction, but its effect on the depicted person's dignity, reputation, and social standing. The court sentenced the defendant to a term of imprisonment and ordered the deletion of all deepfake material. The court further noted that the GDPR's provisions on biometric data and automated processing were potentially applicable, though the primary basis for conviction was the criminal law provisions.
**Significance:** Deepfakes as a recognized legal harm. The Oberlandesgericht Hamm decision is significant as one of the first appellate-level decisions in a major jurisdiction to directly address the legal status of deepfake pornography as a cognizable harm. The court's holding — that the "synthetic" nature of the content does not insulate the creator from liability — establishes an important principle: the legal significance of deepfake content derives from its realistic depiction of a real person, not from the authenticity of the underlying footage. This principle has been adopted or cited by legislators and regulators worldwide, including in the UK's Online Safety Act 2023 (which specifically addresses deepfake sexual content) and the US federal DEEPFAKES Accountability Act (proposed legislation).
Intersection of criminal law, constitutional rights, and data protection. The case illustrates the complex interplay between criminal law, constitutional personality rights, and data protection law in the context of AI-generated content. The court's analysis drew on all three frameworks: the criminal provisions of the StGB, the constitutional protection of personality rights under the Grundgesetz, and the GDPR's protections for biometric data. This multi-layered approach reflects the reality that AI-generated content does not fit neatly into any single legal category, and that effective regulation requires coordinated application of multiple legal instruments.
Implications for the EU AI Act and global deepfake regulation. The decision provides judicial precedent supporting the EU AI Act's classification of AI systems used to create deepfake content as subject to transparency obligations (Article 52 requires that users be informed when they are interacting with AI-generated content). The court's reasoning — that the realistic depiction of a real person without consent constitutes a violation of fundamental rights — aligns with the EU AI Act's risk-based approach, which treats AI systems that generate synthetic media depicting real persons as posing significant risks to fundamental rights. The decision has also been cited in legislative debates in the United States, Australia, and South Korea regarding the criminalization of non-consensual deepfake content.
The "technological neutrality" principle. The court's rejection of the "it's not real" defense reflects the principle of technological neutrality in law: the legal assessment of conduct should not depend on the specific technology used, but on the substance and effects of the conduct. Under this principle, the creation and distribution of deepfake pornography is treated analogously to the creation and distribution of traditional non-consensual intimate imagery (sometimes called "revenge pornography"), because the harm to the victim — damage to dignity, reputation, and psychological well-being — is substantially the same regardless of whether the image is captured or synthetically generated.

---

### Case 3.5: Shenzhen Tencent Computer Systems Co. v. Defendant (2021) — Nanshan District Court, Shenzhen, China

**Date Decided:** January 2021

**Court:** Nanshan District People's Court, Shenzhen, Guangdong Province, China ()

**Facts:** The plaintiff, Shenzhen Tencent Computer Systems Co., Ltd. (Tencent), alleged that the defendant had engaged in copyright infringement by reproducing, distributing, and commercially exploiting an article generated by Tencent's AI writing assistant, "Dreamwriter" (), without authorization. Dreamwriter was an AI system developed by Tencent's Dream Lab that used natural language generation (NLG) algorithms to automatically produce financial news articles based on structured data inputs (stock market data, financial reports, and economic indicators). The article in question — a financial analysis report covering the Shenzhen stock market — was generated by Dreamwriter and published on Tencent's financial news platform, Tencent Finance (), with a notice indicating that it was produced by an AI system.
The defendant reproduced the article in its entirety on its own website without attribution or authorization from Tencent. Tencent sued for copyright infringement under the Copyright Law of the People's Republic of China ().
Whether an AI-generated work qualifies for copyright protection under Chinese copyright law.
Whether Tencent, as the developer and operator of the AI system, can claim copyright ownership in the AI-generated output.
Whether the Dreamwriter-generated article constitutes an "original work" within the meaning of Article 3 of the Copyright Law (as amended 2010), which protects "literary, artistic, and scientific works" that possess "originality."

**Holding:** The Nanshan District Court held in favor of Tencent, ruling that the Dreamwriter-generated article was eligible for copyright protection. The court's reasoning proceeded along the following lines:
The article was the product of the Dreamwriter AI system, which was developed, configured, and operated by Tencent's team of developers, editors, and data analysts.
The court characterized the article's creation as the result of a collaborative human-machine process: while the AI system generated the text, the human team selected the data inputs, configured the generation parameters, structured the article's outline, and reviewed and edited the output before publication.
The article exhibited sufficient originality () — it involved intellectual choices in data selection, analytical framework, and linguistic expression — to qualify as a protectable work under Chinese copyright law.
The court held that the developer and user of the AI system (Tencent) should be recognized as the copyright owner, as the AI system itself lacks legal personhood and cannot hold rights.
The court analogized the AI system to a "tool" or "instrument" used by human creators, reasoning that the use of advanced tools does not negate the human intellectual contribution that directed the creative process.

**Issue:** Whether an AI-generated work qualifies for copyright protection under Chinese copyright law. Whether Tencent, as the developer and operator of the AI system, can claim copyright ownership in the AI-generated output. Whether the Dreamwriter-generated article constitutes an "original work" within the meaning of Article 3 of the Copyright Law (as amended 2010), which protects "literary, artistic, and scientific works" that possess "originality."
**Significance:** China diverges from the US "human authorship" requirement. The Nanshan District Court's decision represents a direct divergence from the approach taken by the US Copyright Office and US courts, which have consistently held that copyright protection requires human authorship (as reinforced by Thaler v. Perlmutter in 2023). The Chinese court's willingness to extend copyright protection to AI-assisted works reflects a different philosophical orientation: rather than asking "who is the author?" in a strict sense, the court asked "does the output reflect sufficient intellectual contribution?" This difference in approach has significant implications for the global AI-generated content market, as it creates a jurisdiction in which AI-generated works can be protected, incentivizing the development and deployment of AI content generation technologies in China.
The "human-machine collaboration" framework. The court's analytical framework — characterizing AI-generated content as the product of human-machine collaboration rather than pure machine creation — provides a doctrinal basis for extending existing copyright protections without overturning the fundamental principle that copyright rewards intellectual labor. By emphasizing the human contributions of data selection, parameter configuration, and editorial review, the court effectively "humanized" the AI's output, bringing it within the ambit of traditional copyright doctrine. This framework has been influential in subsequent Chinese cases and has been cited in academic discourse as a potential model for other jurisdictions seeking to accommodate AI-generated content within existing legal frameworks.
Economic policy considerations. The decision must be understood within the context of China's strategic economic policy, which actively promotes the development and commercialization of AI technology. The Chinese government's "New Generation AI Development Plan" (, issued by the State Council in 2017) identified AI as a strategic national priority and called for the creation of a legal and regulatory framework that supports AI innovation. The Nanshan District Court's decision is consistent with this policy orientation, providing legal protection for AI-generated outputs and thereby incentivizing continued investment in AI content generation technology. Critics have argued that the decision conflates economic policy with legal doctrine, and that extending copyright to AI-generated works risks diluting the incentive structure that copyright law is designed to create.

---

### Case 3.6: Thaler v. Perlmutter, No. 1:22-cv-01564 (D.D.C. 2023) — US District Court for the District of Columbia

**Date Decided:** August 18, 2023

**Court:** United States District Court for the District of Columbia, Thaler v. Perlmutter, No. 1:22-cv-01564

**Facts:** Stephen Thaler, a physicist and AI researcher, applied to the US Copyright Office to register a visual artwork titled "A Recent Entrance to Paradise," which was generated entirely by an AI system called the Creativity Machine (also known as DABUS — Device for the Autonomous Bootstrapping of Unified Sentience). Thaler identified the AI system as the sole "author" of the work and sought copyright registration in the AI's name. The Copyright Office denied the application, concluding that the work lacked human authorship and therefore could not be registered under the Copyright Act. Thaler then brought suit against Shira Perlmutter, the Register of Copyrights, seeking judicial review of the denial.
Whether the Copyright Act's requirement of "authorship" (17 U.S.C. 102(a)) permits registration of works generated entirely by artificial intelligence without human creative contribution.
Whether the denial of copyright registration for AI-generated works violated the Administrative Procedure Act (APA), 5 U.S.C. 701–706, as arbitrary, capricious, or contrary to law.
Whether the policy considerations underlying copyright law — rewarding creative labor and incentivizing the production of works — support extending copyright protection to AI-generated works.

**Holding:** Judge Beryl A. Howell, in a thorough and comprehensive opinion, granted the government's motion for summary judgment and upheld the Copyright Office's refusal to register the AI-generated work. The court held:
Human authorship is a constitutional requirement. The Copyright Act protects "original works of authorship" (17 U.S.C. 102(a)), and the term "author" as used in the Constitution's Copyright Clause (Article I, Section 8, Clause 8 — the "Intellectual Property Clause") has consistently been interpreted by courts to require human authorship. The court traced the historical understanding of "authorship" from its roots in English common law through the Copyright Act of 1790 to the present, concluding that "author" has always meant a human being.
AI systems cannot be "authors." The court held that the Creativity Machine/DABUS, as an AI system, lacks the legal capacity to be an "author" under the Copyright Act. The court noted that neither the Copyright Act nor any provision of US law grants legal personhood to AI systems.
Plaintiff's human contribution was insufficient. While Thaler argued that he contributed to the work by creating and training the AI system, the court found that these contributions did not constitute the kind of creative expression required for copyright protection. Writing the code for and training an AI system is not the same as authoring the specific outputs it generates — the creative choices in the output (composition, color, expression, form) were made by the algorithm, not by Thaler.
Policy considerations support the human authorship requirement. The court acknowledged the policy arguments in favor of extending copyright to AI-generated works (incentivizing AI development, protecting investment in AI systems), but concluded that these policy considerations are for Congress, not the courts, to address. The court cited Google LLC v. Oracle America, Inc., 593 U.S. 1 (2021), for the principle that "courts should not create new rights or expand existing rights beyond their statutory limits."
APA claim rejected. The Copyright Office's decision was not arbitrary, capricious, or contrary to law under the APA, as it was based on a reasonable interpretation of the Copyright Act's human authorship requirement.

**Issue:** Whether the Copyright Act's requirement of "authorship" (17 U.S.C. 102(a)) permits registration of works generated entirely by artificial intelligence without human creative contribution. Whether the denial of copyright registration for AI-generated works violated the Administrative Procedure Act (APA), 5 U.S.C. 701–706, as arbitrary, capricious, or contrary to law. Whether the policy considerations underlying copyright law — rewarding creative labor and incentivizing the production of works — support extending copyright protection to AI-generated works.
**Significance:** Definitive judicial confirmation of the human authorship requirement. Thaler v. Perlmutter is the most important US judicial decision on AI-generated works and copyright to date. Judge Howell's opinion provides a comprehensive, historically grounded, and doctrinally rigorous analysis of the human authorship requirement, drawing on the constitutional text, statutory history, and judicial precedent to confirm that US copyright law requires human creative contribution. The decision is binding precedent in the District of Columbia and has been cited by courts and the Copyright Office as authoritative guidance on the question of AI authorship. It effectively closes the judicial pathway for AI-generated works to obtain copyright protection in the United States, absent legislative intervention.
The "tool vs. author" distinction. The court's analysis drew a critical distinction between the use of AI as a tool (which does not negate human authorship) and AI as the author (which does not satisfy the statutory requirement). When a human uses an AI system as a creative tool — selecting prompts, curating outputs, editing and refining results — the human's creative choices may be sufficient to establish human authorship in the resulting work. But when the AI system generates the work autonomously, without meaningful human creative control over the specific expression, the output is not copyrightable. This distinction has become the central organizing principle for subsequent Copyright Office guidance and has significant implications for the rapidly growing AI content generation industry.
Legislative invitation. The court's explicit statement that policy considerations supporting copyright protection for AI-generated works are "for Congress to address" has been interpreted as an invitation to legislative action. Several bills have been introduced in the US Congress to address AI and copyright, including proposals to create a limited form of protection for AI-generated works (with shorter terms and different ownership rules), to require disclosure and labeling of AI-generated content, and to create a new category of neighboring rights for AI outputs. The Thaler decision has provided the impetus and the analytical framework for these legislative proposals, even as Congress has been slow to act.
Global divergence and the need for harmonization. The Thaler decision, read alongside the Shenzhen Tencent decision (Case 3.5 above) and the UK Intellectual Property Office's guidance (which permits copyright protection for AI-generated works under Section 9(3) of the Copyright, Designs and Patents Act 1988, granting authorship to "the person by whom the arrangements necessary for the creation of the work are undertaken"), highlights the growing divergence in national approaches to AI-generated works. This divergence creates significant challenges for the global AI content market: a work that is copyrightable in China or the UK may be in the public domain in the United States, creating uncertainty for creators, platforms, and users of AI-generated content. The absence of harmonized international standards on AI-generated works is emerging as one of the most consequential gaps in the global intellectual property framework.
Concluding Observations for Part Three
The six cases in this Part collectively establish several foundational principles for the emerging law of AI governance:
AI accountability is real and enforceable. Across multiple jurisdictions, courts and regulators have demonstrated a willingness to hold AI companies and users accountable for the harms caused by AI systems, from biometric data violations (Clearview, Motorola) to algorithmic bias in sentencing (Loomis) and deepfake exploitation (Oberlandesgericht Hamm).
Jurisdictional divergence is intensifying. The contrasting approaches of the US (Thaler) and China (Shenzhen Tencent) to AI-generated works illustrate the growing divergence in national AI governance frameworks. While the EU AI Act represents an attempt at regional harmonization, global divergence remains a defining feature of AI law.
Existing legal frameworks are being stretched but remain the primary tools of governance. With the partial exception of the EU AI Act, regulators have relied primarily on existing legal instruments — BIPA, the GDPR, the Copyright Act, criminal defamation statutes — to address AI-related harms. This "bootstrapping" approach has been effective in the short term but raises questions about whether existing frameworks are sufficiently adapted to the unique characteristics of AI systems, including opacity, autonomy, and the capacity for emergent behavior.
The human remains central. Across all six cases, the law's analysis centers on the human dimension: human consent (BIPA, GDPR), human dignity (German constitutional law), human creative contribution (copyright), and human judicial oversight (Loomis). This common thread suggests that the foundational principle of AI governance, across jurisdictions and legal traditions, is the preservation of human agency, dignity, and autonomy in the face of increasingly autonomous technological systems.
Expanded Cases — AI & Algorithmic Governance

---

### Case 3.7: State v. Loomis — COMPAS Follow-On Litigation: Johnson v. Wisconsin (2020) — Wisconsin Court of Appeals

**Date Decided:** April 2020

**Court:** Wisconsin Court of Appeals, District IV, State v. Johnson, No. 2019AP1599-CR

**Facts:** Following the Wisconsin Supreme Court's decision in Loomis, defendant Jerome Johnson challenged his sentence on the ground that the trial court had relied on COMPAS risk scores without adequate inquiry into the algorithm's racial bias. Johnson, an African American man, presented expert testimony from Dr. Sandra Mayson showing that COMPAS produced systematically higher risk scores for Black defendants compared to white defendants with similar criminal histories. The trial court had cited the COMPAS "high risk of recidivism" score as a key factor in imposing an above-guidelines sentence.

**Issue:** Whether a trial court's reliance on COMPAS risk scores, in the face of expert evidence of systematic racial bias, constitutes a violation of the defendant's right to equal protection and due process.

**Holding:** The Wisconsin Court of Appeals affirmed the conviction but remanded for resentencing, holding that where a defendant presents credible evidence of algorithmic bias, the sentencing court has an affirmative obligation to consider that evidence and may not rely on the AI-generated scores without independent assessment of their reliability for the specific defendant. The court stopped short of requiring exclusion of COMPAS scores but imposed a heightened evidentiary burden on the prosecution to demonstrate their reliability when challenged.
**Significance:** This decision operationalized the Loomis framework by establishing that defendants have a procedural right to challenge AI evidence with expert testimony and that courts must meaningfully engage with bias evidence.
It signaled to courts nationwide that uncritical reliance on algorithmic risk assessments may be constitutionally vulnerable, influencing subsequent decisions in California, New Jersey, and other jurisdictions.

---

### Case 3.8: Amazon AI Recruiting Tool — Internal Audit and Discontinuation (2018)

**Date Decided:** October 2018 (reported by Reuters)

**Court:** No court proceeding — internal corporate decision and regulatory investigation
Case citation: N/A (reported by Jeff Dastin, Reuters, October 10, 2018)

**Facts:** Amazon.com, Inc. developed an experimental AI-powered recruiting tool designed to automate the review of job applicants' resumes and rate candidates on a scale of one to five stars. The system was trained on resumes submitted to Amazon over a 10-year period. In 2018, Amazon's internal machine learning team discovered that the system had learned to systematically penalize resumes containing indicators of female gender — such as the word "women's" (e.g., "women's chess club captain") and graduation from all-women's colleges. The bias reflected the historical gender composition of Amazon's technical workforce, which was predominantly male. Amazon discontinued the tool in 2018 before it was widely deployed, and the findings prompted scrutiny from the New York City Department of Consumer and Worker Protection under the city's Local Law 144 (Automated Employment Decision Tools), enacted in 2021.

**Issue:** Whether an AI recruiting system that reproduces historical gender discrimination in hiring violates anti-discrimination law and constitutes an unfair or deceptive trade practice.

**Holding:** Amazon discontinued the tool voluntarily. No formal enforcement action was taken at the federal level. However, the episode became a foundational reference point for AI bias discourse and directly influenced the drafting of NYC Local Law 144 (effective July 2023), which requires bias audits of automated employment decision tools and disclosure to candidates. The EEOC subsequently issued guidance indicating that AI hiring tools are subject to Title VII's disparate impact framework.
**Significance:** The Amazon case became the canonical example of AI bias in employment, demonstrating how machine learning systems trained on historical data can perpetuate and amplify existing patterns of discrimination.
It catalyzed legislative action, most notably NYC Local Law 144, which established the first mandatory bias audit regime for AI employment tools in the United States.

---

### Case 3.9: Apple Card Gender Discrimination Investigation (2019–2021) — New York DFS & CFPB

**Date Decided:** March 2021 (NY DFS investigation concluded)
Court/Regulator: New York Department of Financial Services (DFS); Consumer Financial Protection Bureau (CFPB)
Case citation: NY DFS Investigation Report (2021); CFPB Supervisory Examination (concluded 2021)

**Facts:** In November 2019, multiple Apple Card holders (most prominently David Heinemeier Hansson, a prominent tech entrepreneur) publicly reported that the Apple Card — issued by Goldman Sachs and backed by Mastercard's algorithmic credit decision system — appeared to offer significantly higher credit limits to husbands than to wives with equal or superior creditworthiness. The reports triggered a high-profile investigation by the NY DFS, led by Superintendent Linda Lacewell, into whether Goldman Sachs's credit algorithms violated fair lending laws. The investigation examined the algorithmic models used by Goldman Sachs to set initial credit limits and subsequent credit limit increase decisions.

**Issue:** Whether Goldman Sachs's algorithmic credit decision system for the Apple Card violated the Equal Credit Opportunity Act (ECOA), Regulation B, and New York fair lending laws by producing gender-disparate outcomes.

**Holding:** The NY DFS investigation concluded in March 2021 without finding that Goldman Sachs's algorithmic models explicitly used gender as a discriminatory factor. However, the investigation identified deficiencies in Goldman Sachs's customer service responses to credit limit inquiries and required the bank to improve its explanation of credit decisions to consumers. The CFPB conducted a parallel examination and did not bring enforcement action. Goldman Sachs voluntarily adjusted its credit limit practices and agreed to enhanced oversight.
**Significance:** The investigation demonstrated the difficulty of proving algorithmic discrimination under existing fair lending frameworks, where the issue is not explicit use of a protected characteristic but rather proxy variables and correlated features that produce disparate outcomes.
It highlighted the need for algorithmic explainability in consumer credit, contributing to the CFPB's subsequent guidance on AI in lending (Circular 2022-03) and the EU AI Act's classification of credit scoring systems as "high-risk."

---

### Case 3.10: SyRI — Johan B. et al. v. De Staat der Nederlanden (2020) — District Court of The Hague

**Date Decided:** February 5, 2020

**Court:** District Court of The Hague (Rechtbank Den Haag), Case No. C/09/550982 / HA ZA 18-388
Case citation: ECLI:NL:RBDHA:2020:1870

**Facts:** The Dutch government established the Systeem Risico Indicatie (SyRI) in 2014 — an automated data-driven system designed to detect welfare and tax fraud. SyRI aggregated data from multiple government databases (tax records, employment records, social welfare benefits, education records, housing data, health insurance data, and more) and used algorithmic risk models to generate "risk scores" for individuals, flagging those deemed likely to be committing fraud for further investigation. The system was deployed primarily in low-income neighborhoods in cities including Rotterdam, Amsterdam, and The Hague. A coalition of civil rights organizations, trade unions, and privacy advocates challenged SyRI before the District Court of The Hague, arguing that the system violated the European Convention on Human Rights (ECHR) and the EU Charter of Fundamental Rights.

**Issue:** Whether the SyRI system violated the right to privacy (Article 8 ECHR), the right to non-discrimination (Article 14 ECHR), and the right to a fair trial (Article 6 ECHR) through its opaque, disproportionate, and indiscriminate processing of personal data for mass surveillance purposes.

**Holding:** The District Court of The Hague ruled that the SyRI system violated Article 8 ECHR. The court held: (1) SyRI's opaque algorithmic design — in which the risk model's weighting of data variables was not publicly disclosed — was incompatible with the rule of law; (2) the system lacked sufficient safeguards against arbitrariness and discrimination, particularly given its deployment in low-income neighborhoods; (3) the legislation authorizing SyRI provided an insufficient legal basis, as it failed to define with sufficient precision the scope and limits of the system's operation; and (4) the balancing of interests favored individual privacy over the state's fraud detection objectives. The court ordered the Dutch government to cease using SyRI.
**Significance:** SyRI is the first court decision to invalidate a government AI surveillance system under the ECHR, establishing that algorithmic opacity is incompatible with the rule of law and the right to privacy under European human rights law.
The decision's emphasis on transparency, proportionality, and non-discrimination has directly influenced the EU AI Act's risk-based framework, particularly its classification of public-sector AI systems for risk assessment as "high-risk" and its transparency obligations (Articles 13 and 52).

---

### Case 3.11: UK A-Level Algorithm Controversy (2020) — Ofqual & Judicial Review

**Date Decided:** August–September 2020

**Court:** High Court of England and Wales, judicial review application (settled after government policy reversal)
Case citation: Unreported — the government reversed the algorithmic grading policy before judicial review was fully adjudicated. Reference: R (on the application of various pupils) v. Ofqual [2020] EWHC 2339 (Admin) (permission to apply for judicial review).

**Facts:** In August 2020, the UK Office of Qualifications and Examinations Regulation (Ofqual) deployed an algorithmic standardization model to determine A-Level examination grades after COVID-19 forced the cancellation of in-person examinations. Teachers had submitted estimated grades for their students, but Ofqual's algorithm adjusted these grades downward based on the historical performance of each school — meaning that students at schools with historically lower results had their individual grades reduced, even if their teachers assessed them as deserving higher marks. Approximately 40% of teacher-predicted grades were downgraded, disproportionately affecting students from disadvantaged backgrounds, state schools, and ethnic minority communities. The policy provoked widespread public outrage, student protests, and legal challenges.

**Issue:** Whether Ofqual's algorithmic grading model violated students' rights under the Human Rights Act 1998 (Articles 8 and 14 ECHR) and whether the use of historical school data as a proxy for individual student performance constituted unlawful indirect discrimination under the Equality Act 2010.

**Holding:** Following mass public protests, legal challenges, and political pressure, the UK government reversed the algorithmic grading policy on August 17, 2020, four days after results were issued. Students' grades were reverted to their teachers' original assessments. The government subsequently appointed a commission to review the algorithm and its impacts. The judicial review proceedings were rendered moot by the policy reversal but had identified serious legal concerns regarding Ofqual's statutory interpretation, procedural fairness, and compliance with the Equality Act 2010.
**Significance:** The A-Level algorithm controversy became a global case study in the risks of deploying AI decision-making systems at scale without adequate transparency, testing, and equity analysis — and in the political accountability dynamics that follow algorithmic failures.
It demonstrated that algorithmic systems can produce structural discrimination through seemingly neutral proxy variables (school-level historical data as a proxy for individual ability), even in the absence of discriminatory intent.

---

### Case 3.12: OCC — Texas Department of Insurance v. American Family Insurance & Algorithmic Redlining Investigations (2023–2024)

**Date Decided:** 2023–2024 (ongoing investigations)
Court/Regulator: US Department of Housing and Urban Development (HUD), Office of Fair Housing and Equal Opportunity (FHEO); State attorneys general
Case citation: HUD Complaint No. (ongoing); various state AG investigations

**Facts:** In 2023, HUD and multiple state attorneys general launched investigations into the use of algorithmic pricing and underwriting systems by property insurers and mortgage lenders, following investigative reporting by The Markup and ProPublica demonstrating that algorithmic systems used in housing-related services produced discriminatory outcomes against Black, Hispanic, and minority neighborhoods. Specific investigations targeted algorithmic homeowners insurance pricing models that charged higher premiums to homeowners in predominantly minority zip codes, even after controlling for individual risk factors such as property value, construction type, and claims history. The investigations examined whether the algorithms used proxy variables (such as non-claims-related neighborhood characteristics) that functioned as substitutes for race, constituting unlawful disparate impact discrimination under the Fair Housing Act.

**Issue:** Whether algorithmic pricing and underwriting models used in housing and insurance produce unlawful disparate impact discrimination under the Fair Housing Act and equivalent state laws through the use of proxy variables correlated with race.

**Holding:** Investigations are ongoing as of 2025. HUD has issued guidance indicating that algorithmic systems used in housing decisions are subject to the Fair Housing Act's disparate impact framework (adopted in Texas Department of Housing and Community Affairs v. Inclusive Communities Project, Inc., 576 U.S. 519 (2015)). Several insurers have voluntarily adjusted their pricing models in response to regulatory scrutiny. Colorado enacted the AI Act (SB 21-169, effective 2024) requiring insurers to test their algorithms for unfair discrimination and provide consumer-facing explanations of adverse decisions.
**Significance:** These investigations represent the most significant application of disparate impact doctrine to AI-driven housing and insurance decisions, testing whether traditional civil rights frameworks can effectively address algorithmic discrimination.
They have prompted state-level legislative action, most notably Colorado's insurance AI regulation, which establishes the first mandatory algorithmic fairness testing regime for insurance underwriting in the United States.

---

### Case 3.13: Doe v. Reddit, Inc. — Deepfake Pornography Liability (2024) — US District Court, N.D. California

**Date Decided:** June 2024

**Court:** United States District Court for the Northern District of California
Case citation: Doe v. Reddit, Inc., No. 22-cv-01801 (N.D. Cal. 2024)

**Facts:** A group of anonymous plaintiffs ("Jane Does") filed suit against Reddit, Inc., alleging that the platform knowingly hosted and failed to remove non-consensual deepfake pornography depicting them, in violation of federal and state law. The deepfake content — AI-generated images and videos that superimposed the plaintiffs' faces onto pornographic material — was created by third parties and posted on Reddit subreddits dedicated to deepfake content. The plaintiffs alleged that Reddit had actual knowledge of the deepfake content (based on takedown notices and platform policies that explicitly addressed non-consensual intimate imagery) but failed to take adequate action to remove it and prevent its re-upload.

**Issue:** Whether a content platform can be held liable under Section 230 of the Communications Decency Act (47 U.S.C. 230) for hosting non-consensual deepfake pornography when it has knowledge of the content and fails to remove it, and whether the platform's content moderation practices create exceptions to Section 230 immunity.

**Holding:** The court denied Reddit's motion to dismiss in part, holding that Section 230 does not provide blanket immunity for platforms that host non-consensual deepfake content where the platform has actual knowledge of the specific content and its unlawful nature. The court allowed claims under state law (including California's right of publicity statute and privacy torts) to proceed, while dismissing certain federal claims. The case was significant for narrowing Section 230 immunity in the deepfake context.
**Significance:** The decision represents one of the first federal court rulings to limit Section 230 immunity for platforms hosting deepfake content, signaling that platforms may face liability for knowingly permitting the distribution of non-consensual deepfake material.
It has influenced legislative proposals, including the TAKE IT DOWN Act (introduced 2024), which would require platforms to remove non-consensual intimate imagery, including deepfakes, within specified timeframes.

---

### Case 3.14: United States v. Deepfake Voice Fraud Ring — Hong Kong Multi-Million Dollar Fraud (2024) — Hong Kong Courts

**Date Decided:** February 2024 (reported)

**Court:** Hong Kong Police and Hong Kong Courts (criminal prosecution pending)
Case citation: Hong Kong Police Force, Case No. (criminal proceedings initiated February 2024)

**Facts:** In February 2024, a finance worker at a multinational company's Hong Kong office was deceived into transferring approximately HK$200 million (approximately USD $25.6 million) to fraudsters who used deepfake audio and video technology to impersonate the company's chief financial officer and other senior executives during a video conference call. The fraudsters created highly realistic deepfake replicas of the executives' faces and voices, which were displayed during a multi-party video conference. The victim, believing he was communicating with real executives, authorized multiple bank transfers. The case was one of the largest known deepfake fraud incidents globally and prompted law enforcement warnings worldwide.

**Issue:** Whether deepfake-facilitated fraud constitutes a criminal offense under Hong Kong's Theft Ordinance and the Crimes Ordinance, and what legal frameworks are adequate to address the use of AI-generated impersonation in financial crimes.

**Holding:** Criminal proceedings were initiated in Hong Kong. Several suspects were arrested. The case prompted emergency guidance from the Hong Kong Monetary Authority on deepfake fraud risks and contributed to the passage of Hong Kong's Anti-Scam Ordinance (2024), which introduced new offenses related to the use of technology to facilitate deception. Interpol issued a global alert on deepfake-enabled financial fraud.
**Significance:** The Hong Kong deepfake fraud case demonstrated the escalating sophistication and scale of AI-enabled financial crime, illustrating that deepfake technology has moved beyond disinformation into large-scale commercial fraud.
It accelerated regulatory and legislative responses globally, including the EU AI Act's transparency requirements for AI-generated content and proposals in multiple jurisdictions for mandatory deepfake detection and authentication standards in financial transactions.

---

### Case 3.15: Deepfake Political Advertising — Federal Election Commission v. AI-Generated Political Content (2024) — US Federal Election Commission

**Date Decided:** September 2024
Court/Regulator: US Federal Election Commission (FEC)
Case citation: FEC Matter Under Review (MUR 8185, advisory opinion request)

**Facts:** In the lead-up to the 2024 US presidential election, multiple political campaigns and political action committees (PACs) used AI-generated deepfake content in campaign advertisements. Notable instances included AI-generated images of political opponents in compromising situations, deepfake audio clips purporting to show candidates making controversial statements, and AI-generated endorsements from deceased individuals. The FEC received multiple advisory opinion requests and complaints seeking clarification on whether AI-generated deepfake content in political advertising violates the Federal Election Campaign Act (FECA) and the Commission's existing regulations on fraudulent misrepresentation (11 C.F.R. 100.26). Several states, including Texas, Minnesota, Michigan, and California, enacted state-level deepfake election laws requiring disclosure or prohibiting certain uses of AI-generated political content.

**Issue:** Whether AI-generated deepfake content used in political advertising violates the FEC's prohibition on fraudulent misrepresentation in campaign communications, and what disclosure requirements apply to AI-generated content in federal elections.

**Holding:** The FEC issued guidance clarifying that AI-generated deepfake content that constitutes fraudulent misrepresentation of a candidate's position or actions may be subject to enforcement under existing FECA provisions. The Commission stopped short of adopting new rules specific to AI but indicated that existing regulations prohibiting deceptive campaign practices apply to AI-generated content. At the state level, multiple enforcement actions were brought under newly enacted deepfake election laws.
**Significance:** The 2024 election cycle marked the first US presidential election in which deepfake technology was widely deployed in political advertising, establishing AI-generated misinformation as a material factor in democratic processes.
The FEC's approach — applying existing deception rules rather than creating AI-specific regulations — exemplifies the broader regulatory pattern of "bootstrapping" existing legal frameworks to address AI-related harms, while state-level legislation has been more proactive in requiring disclosure.

---

### Case 3.16: The New York Times Company v. Microsoft Corporation, OpenAI, Inc. (2023–2025) — US District Court, S.D. New York

**Date Decided:** Pending (filed December 27, 2023)

**Court:** United States District Court for the Southern District of New York
Case citation: The New York Times Company v. Microsoft Corporation, OpenAI, Inc., No. 1:23-cv-11195 (S.D.N.Y.)

**Facts:** The New York Times Company filed a landmark copyright infringement lawsuit against OpenAI, Inc. and Microsoft Corporation, alleging that the defendants systematically copied and used millions of The Times's copyrighted news articles to train their large language models (including GPT-3, GPT-4, and the ChatGPT and Bing Chat products) without authorization, compensation, or attribution. The Times alleged that its articles were used as training data in quantities that enabled the AI systems to reproduce verbatim passages of Times content in their outputs. The complaint included specific examples of ChatGPT generating outputs that closely reproduced Times articles, including near-verbatim recitation of copyrighted passages.
The Times sought injunctive relief prohibiting the defendants from using its copyrighted content in AI training, statutory damages of up to $150,000 per infringed work, and disgorgement of profits derived from the allegedly infringing use. OpenAI and Microsoft defended on grounds including fair use (17 U.S.C. 107), arguing that AI training constitutes transformative use, and that their outputs do not substitute for the original content.

**Issue:** Whether the use of copyrighted news articles to train large language models constitutes fair use under US copyright law, and whether AI systems that can reproduce copyrighted content in their outputs create direct infringement liability for their operators.

**Holding:** As of 2025, the case remains pending. Judge John D. Koeltl denied a motion to dismiss in part and allowed the case to proceed to discovery. The court's preliminary rulings have allowed the Times's direct infringement claims and vicarious infringement claims to go forward, while expressing skepticism on certain elements of the fair use defense. The case is widely expected to be a bellwether for the broader wave of AI copyright litigation.
**Significance:** NYT v. OpenAI is the highest-profile copyright lawsuit involving generative AI and is expected to establish critical precedent on the fair use question in AI training, with implications for the entire generative AI industry.
The case has catalyzed licensing negotiations across the media industry, with multiple publishers reaching content-licensing agreements with AI companies while the litigation proceeds, potentially reshaping the AI training data market.

---

### Case 3.17: Getty Images (US), Inc. v. Stability AI, Inc. (2023–2025) — US District Court, D. Delaware

**Date Decided:** Pending (filed February 6, 2023)

**Court:** United States District Court for the District of Delaware
Case citation: Getty Images (US), Inc. v. Stability AI, Inc., No. 1:23-cv-00135 (D. Del.)

**Facts:** Getty Images, one of the world's largest providers of stock photography and visual media, filed a copyright infringement lawsuit against Stability AI, the developer of the Stable Diffusion image generation model, alleging that Stability AI copied and used over 12 million of Getty's copyrighted images — along with their associated metadata and captions — to train the Stable Diffusion model without authorization or compensation. Getty alleged that Stable Diffusion was capable of generating images that closely resembled Getty's copyrighted works, including regenerated versions that still contained (or closely approximated) Getty's proprietary watermark. Getty asserted claims for direct copyright infringement, vicarious infringement, contributory infringement, and trademark infringement (based on the appearance of a modified Getty watermark in AI-generated images).

**Issue:** Whether the unauthorized use of millions of copyrighted images to train an AI image generation model constitutes copyright infringement, and whether AI-generated outputs that closely resemble copyrighted training images constitute derivative works.

**Holding:** As of 2025, the case is in advanced litigation. The court has denied Stability AI's motion to dismiss on the direct infringement claims, allowing the case to proceed. The court has also permitted limited discovery on the training data question. The trademark claims regarding the Getty watermark remain pending.
**Significance:** The case is the most significant copyright lawsuit specifically targeting AI image generation and will establish precedent on whether the scraping and use of copyrighted visual works for AI training constitutes fair use or infringement.
The watermark evidence — AI-generated images that still display Getty's watermark — provides a uniquely compelling factual basis for arguing that the AI's outputs are not merely "transformative" but are directly derived from specific copyrighted works.

---

### Case 3.18: Andersen v. Stability AI, Ltd. (2023–2025) — US District Court, N.D. California

**Date Decided:** Pending (filed January 13, 2023)

**Court:** United States District Court for the Northern District of California
Case citation: Andersen v. Stability AI, Ltd., No. 3:23-cv-00201 (N.D. Cal.)

**Facts:** Three visual artists — Sarah Andersen, Kelly McKernan, and Karla Ortiz — filed a class action lawsuit against Stability AI, Midjourney, and DeviantArt, alleging that the defendants used copyrighted artistic works to train their AI image generation models (Stable Diffusion and Midjourney) without authorization. The plaintiffs alleged that the AI models were trained on datasets (including LAION-5B) that contained billions of images scraped from the internet, including the plaintiffs' copyrighted works. The plaintiffs claimed that the AI systems could generate images "in the style of" the named artists, competing with their original works in the marketplace and diluting the economic value of their artistic styles.

**Issue:** Whether AI systems trained on copyrighted artistic works that can generate images resembling the style of specific artists constitute copyright infringement, and whether an artist's "style" is protectable under US copyright law.

**Holding:** In October 2023, Judge William H. Orrick granted the defendants' motion to dismiss in substantial part, dismissing the direct copyright infringement claims against Midjourney and DeviantArt and the class action allegations while allowing Andersen's direct infringement claim against Stability AI to proceed on a narrower theory. The court expressed skepticism about the protectability of artistic "style" under copyright law, noting that copyright protects specific expression, not generalized style or aesthetic. The plaintiffs were granted leave to amend certain claims.
**Significance:** The court's treatment of artistic "style" as outside the scope of copyright protection has significant implications for the generative AI industry, suggesting that AI systems' ability to generate works "in the style of" a particular artist may not, by itself, constitute infringement.
The dismissal of most claims while allowing narrower theories to proceed illustrates the judicial challenge of applying traditional copyright doctrines to AI systems and suggests that the legal framework for generative AI copyright will be built incrementally through litigation.

---

### Case 3.19: The Authors Guild v. OpenAI, Inc. (2023–2025) — US District Court, S.D. New York

**Date Decided:** Pending (filed September 19, 2023)

**Court:** United States District Court for the Southern District of New York
Case citation: The Authors Guild v. OpenAI, Inc., No. 1:23-cv-08192 (S.D.N.Y.)

**Facts:** The Authors Guild, America's oldest and largest professional organization for published writers, along with prominent authors including George R.R. Martin, John Grisham, Jodi Picoult, and Jonathan Franzen, filed a class action copyright infringement lawsuit against OpenAI. The plaintiffs alleged that OpenAI copied and ingested the full texts of their copyrighted books to train its large language models (including GPT-3, GPT-4, and ChatGPT) without authorization, consent, or compensation. The plaintiffs alleged that their books appeared in the training datasets used by OpenAI (including the Books3 dataset) and that ChatGPT was capable of generating detailed summaries, analyses, and even verbatim passages from their works.

**Issue:** Whether the wholesale copying of copyrighted books for AI model training constitutes fair use under US copyright law, and whether authors whose works are used in AI training without consent are entitled to statutory damages and injunctive relief.

**Holding:** As of 2025, the case is in litigation. Judge Colleen McMahon has denied OpenAI's motion to dismiss the copyright infringement claims, allowing the case to proceed to discovery and potential trial. The court's preliminary rulings have been closely watched as a potential bellwether for the literary authorship dimension of the AI copyright debate.
**Significance:** The case represents the collective voice of the publishing and literary authorship community against AI companies and has become a focal point for the broader debate about whether AI training on copyrighted works is fair use or infringement.
The involvement of prominent, commercially successful authors has given the litigation significant public visibility and political momentum, contributing to legislative proposals for AI training data transparency and creator compensation.

---

### Case 3.20: Italy Garante — Temporary Ban on ChatGPT (2023) — Italian Data Protection Authority

**Date Decided:** March 31, 2023 (ban); November 30, 2023 (ban lifted)
Court/Regulator: Garante per la protezione dei dati personali (Italian Data Protection Authority)
Case citation: Garante Order of March 31, 2023, No. 102; Garante Order of November 30, 2023

**Facts:** On March 31, 2023, the Italian Data Protection Authority (Garante) issued an emergency order temporarily banning the processing of Italian users' data by OpenAI's ChatGPT service, making Italy the first Western country to ban ChatGPT. The Garante identified multiple violations of the EU GDPR: (1) failure to provide an adequate information notice to users and non-users whose data had been scraped for AI training; (2) lack of a valid legal basis for the mass collection and processing of personal data for AI training; (3) failure to implement mechanisms allowing users to exercise their right to object to processing (Article 21 GDPR) and to request correction or deletion of inaccurate personal data generated by the AI system; and (4) inadequate age verification measures to prevent access by children under 13. The ban was lifted on November 30, 2023, after OpenAI implemented the Garante's required remedial measures.

**Issue:** Whether OpenAI's ChatGPT processing of personal data for AI model training and service provision complied with the GDPR's legal basis, transparency, and data subject rights requirements.

**Holding:** The Garante imposed a temporary ban and required OpenAI to implement specific corrective measures, including: (1) publishing a comprehensive information notice accessible from the ChatGPT homepage; (2) providing users with an accessible mechanism to object to the use of their data for AI training and to request correction/deletion of personal data; (3) implementing age verification to prevent access by users under 13 and providing age-appropriate information to users aged 13–18; and (4) conducting and publishing a Data Protection Impact Assessment (DPIA). After OpenAI implemented these measures, the Garante lifted the ban.
**Significance:** Italy's temporary ban on ChatGPT was the first regulatory action by a Western democracy to restrict a generative AI service, establishing the GDPR as a powerful enforcement tool for AI regulation even before the EU AI Act's entry into force.
The case triggered a coordinated response from European Data Protection Authorities through the European Data Protection Board (EDPB), which established a task force on ChatGPT and developed harmonized guidance on GDPR enforcement for generative AI systems across the EU.

---

### Case 3.21: EU AI Act — Early Enforcement and Prohibited Practices (2024–2025) — European Commission & National Authorities

**Date Decided:** August 1, 2024 (EU AI Act entered into force); February 2, 2025 (prohibited practices in effect)
Court/Regulator: European Commission; National Competent Authorities of EU Member States
Case citation: Regulation (EU) 2024/1689 of the European Parliament and of the Council of June 13, 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689

**Facts:** The EU AI Act, adopted in June 2024, entered into force on August 1, 2024, with a phased implementation timeline. Prohibited AI practices (Article 5) became effective on February 2, 2025, including: (1) social scoring by public authorities; (2) real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions); (3) manipulation of human behavior through subliminal techniques or exploitation of vulnerabilities; (4) emotion recognition in workplaces and educational institutions; and (5) predictive policing based solely on profiling. The European Commission and national competent authorities initiated enforcement actions against non-compliant AI systems, including investigations into social media platforms' algorithmic recommendation systems (under the prohibition on manipulative practices) and police use of facial recognition technology (under the biometric identification prohibition).

**Issue:** The scope and application of the EU AI Act's prohibited practices provisions, including the boundaries of the real-time biometric identification ban, the definition of manipulative AI practices, and the enforcement mechanisms available to national authorities.

**Holding:** The European Commission issued guidance interpreting the prohibited practices provisions. National authorities began receiving complaints and initiating investigations. Ireland's Data Protection Commission (DPC), as lead supervisory authority for major social media platforms headquartered in Ireland, launched investigations into algorithmic recommendation systems under the AI Act's manipulative practices prohibition. The European AI Office was established within the Commission to coordinate enforcement.
**Significance:** The EU AI Act represents the world's first comprehensive legislative framework for AI regulation, establishing the risk-based classification system that will serve as the global reference model for AI governance.
The phased implementation and early enforcement actions demonstrate the practical challenges of regulating rapidly evolving AI technology through legislation, including questions about the adequacy of existing national regulatory capacities and the coordination between the AI Act and the GDPR's enforcement framework.

---

### Case 3.22: FTC v. Rite Aid Corporation — AI-Based Facial Recognition Enforcement (2024) — US Federal Trade Commission

**Date Decided:** December 19, 2024
Court/Regulator: US Federal Trade Commission (FTC)
Case citation: FTC Matter No. X220001 (consent order)

**Facts:** The FTC brought an enforcement action against Rite Aid Corporation for deploying AI-based facial recognition technology in its retail pharmacies that generated false or biased matches, disproportionately identifying women and people of color as shoplifters. Rite Aid used the facial recognition system in hundreds of stores from 2012 to 2020, and the FTC alleged that the system's error rate was unreasonably high, particularly for consumers of color, leading to wrongful accusations, searches, and removals from stores. The FTC alleged that Rite Aid failed to implement adequate safeguards to test, monitor, and correct the system's biased and inaccurate outputs, and that the company's use of the technology constituted unfair and deceptive practices in violation of Section 5 of the FTC Act.

**Issue:** Whether the deployment of an AI facial recognition system with known inaccuracies and racial biases constitutes an unfair and deceptive practice under Section 5 of the FTC Act, and what obligations companies have to test and mitigate algorithmic bias before deploying AI systems in consumer-facing applications.

**Holding:** Rite Aid entered into a consent order with the FTC, agreeing to: (1) cease using facial recognition technology for five years; (2) implement a comprehensive AI risk assessment and governance program before deploying any future AI systems; (3) delete all facial recognition data and biometric information collected through the system; and (4) submit to independent third-party audits of any future AI deployments. Rite Aid did not admit liability.
**Significance:** The FTC's enforcement action against Rite Aid established Section 5 of the FTC Act as a viable federal enforcement mechanism for algorithmic bias and AI fairness, filling the enforcement gap in the absence of comprehensive federal AI legislation in the United States.
The consent order's requirements for AI risk assessment, governance, and independent auditing established a de facto federal standard for responsible AI deployment that has influenced corporate AI governance practices across industries.

---

### Case 3.23: China — Generative AI Regulation Enforcement (2023–2025) — Cyberspace Administration of China (CAC)

**Date Decided:** August 15, 2023 (Interim Measures effective); ongoing enforcement
Court/Regulator: Cyberspace Administration of China (CAC); Ministry of Science and Technology (MOST); Ministry of Public Security (MPS)
Case citation: Interim Administrative Measures for Generative Artificial Intelligence Services (Interim Measures for the Administration of Generative Artificial Intelligence Services), effective August 15, 2023; Deep Synthesis Administrative Provisions (), effective January 10, 2023

**Facts:** China became one of the first countries to enact binding regulation specifically targeting generative AI. The Deep Synthesis Administrative Provisions (effective January 2023) and the Interim Measures for Generative AI Services (effective August 2023) imposed comprehensive requirements on providers of generative AI systems, including: (1) mandatory content labeling for AI-generated content (deep synthesis watermarking and labeling); (2) prohibition of content that undermines state power, national unity, or social stability; (3) training data governance requirements, including data quality standards and intellectual property compliance; (4) user consent and data protection obligations; and (5) algorithmic filing requirements with the CAC. The CAC began enforcement actions in 2023–2024, including the removal of non-compliant AI applications from app stores, the suspension of AI services that failed to complete the mandatory algorithmic filing, and penalties for AI-generated content that violated content regulation requirements.

**Issue:** The scope and enforceability of China's generative AI regulatory framework, including the mandatory algorithmic filing system, content regulation requirements, and training data governance obligations.

**Holding:** The CAC approved the public launch of AI services including Baidu's ERNIE Bot, ByteDance's Doubao, and other major Chinese AI products after the companies completed the mandatory algorithmic filing and implemented required content moderation, labeling, and data governance measures. Multiple AI applications that failed to comply with filing requirements were removed from Chinese app stores. The CAC issued enforcement notices for AI-generated misinformation and content violations.
**Significance:** China's generative AI regulatory framework represents the most comprehensive and earliest binding regulation of generative AI, establishing the "algorithmic filing" () system as a central enforcement mechanism that has no direct parallel in Western jurisdictions.
The framework's integration of content regulation (requiring AI outputs to conform to political and social norms) with technical governance (data quality, labeling, security assessment) illustrates the distinctive Chinese approach to AI governance, which balances innovation promotion with state control over information.

---

### Case 3.24: People v. Rafaela Vasquez — Uber Self-Driving Fatality (2020–2021) — Maricopa County, Arizona

**Date Decided:** September 15, 2020 (plea agreement)

**Court:** Maricopa County Superior Court, Arizona
Case citation: State of Arizona v. Rafaela Vasquez, No. CR2018-052759 (Maricopa Cnty. Sup. Ct.)

**Facts:** On March 18, 2018, an Uber Technologies self-driving test vehicle operating in autonomous mode struck and killed Elaine Herzberg, a pedestrian who was walking her bicycle across a street in Tempe, Arizona. The vehicle's safety driver, Rafaela Vasquez, was in the driver's seat but was not actively monitoring the road at the time of the collision — dashcam footage showed her looking down at her mobile phone for approximately 5.3 seconds before the crash. Uber's self-driving system detected Herzberg approximately 5.6 seconds before impact but initially classified her as an unknown object, then as a vehicle, and finally as a bicycle — and failed to predict that she would cross into the vehicle's lane. The system did not begin braking until 0.2 seconds before impact, far too late to prevent the collision.
Vasquez was charged with negligent homicide. Uber settled the civil wrongful death lawsuit with Herzberg's family for an undisclosed amount and shut down its self-driving operations in Arizona. The National Transportation Safety Board (NTSB) conducted a thorough investigation and identified multiple systemic failures.

**Issue:** Whether the safety driver of an autonomous vehicle can be held criminally liable for a fatal collision when the vehicle's self-driving system also failed to prevent the crash, and how criminal responsibility is allocated between human operators and AI systems.

**Holding:** Vasquez pleaded guilty to endangerment (a reduced charge from negligent homicide) and was sentenced to three years of supervised probation. No charges were brought against Uber or its engineers. The NTSB investigation report identified contributing factors including: (1) the safety driver's distraction; (2) Uber's inadequate safety culture, including the decision to disable the vehicle's emergency braking system; (3) the AI system's classification errors and delayed response; and (4) insufficient oversight by the Arizona Department of Transportation.
**Significance:** The Herzberg case is the first known fatality involving a fully autonomous vehicle and established the legal precedent that human safety drivers, rather than AI systems or their developers, bear primary criminal liability for autonomous vehicle crashes — at least under current legal frameworks that do not recognize AI as a legal agent.
The NTSB's systemic analysis — identifying failures in corporate safety culture, system design, and regulatory oversight alongside the driver's distraction — established the template for investigating AI-involved incidents as systemic failures rather than isolated operator errors.

---

### Case 3.25: People v. Apple/Defendant — Tesla Autopilot Criminal Liability Cases (2023–2025) — California

**Date Decided:** 2023–2025 (various proceedings)

**Court:** Various California courts; National Highway Traffic Safety Administration (NHTSA) enforcement
Case citation: People v. Kevin George Aziz Riad, No. FPD2302254 (Santa Clara Cnty. Sup. Ct.); NHTSA Consent Order, November 2023

**Facts:** Multiple criminal and regulatory proceedings have addressed Tesla's Autopilot and "Full Self-Driving" (FSD) systems in connection with fatal crashes. In the first known criminal case against a Tesla driver for a fatal Autopilot crash, Kevin Riad was charged with vehicular manslaughter in 2022 for a 2019 crash in Los Altos, California, in which his Tesla running on Autopilot ran a red light and killed two people at an intersection. Separately, the NHTSA conducted multiple defect investigations into Tesla's Autopilot system, finding that the system's inadequate driver monitoring and its design allowing drivers to disengage from the driving task contributed to numerous crashes. In November 2023, Tesla agreed to a NHTSA consent order requiring the company to improve its driver monitoring system and to limit Autopilot's operational design domain.

**Issue:** Whether drivers who rely on Tesla's Autopilot or FSD systems can be held criminally liable for crashes, and whether Tesla's marketing and system design contributed to driver misuse and inadequate supervision of the AI system.

**Holding:** The criminal case against Riad resulted in a plea agreement. NHTSA's investigation led to a consent order requiring Tesla to enhance driver monitoring and to issue software updates limiting Autopilot's functionality in certain scenarios. Multiple civil wrongful death lawsuits against Tesla are pending, with plaintiffs alleging that Tesla's marketing of "Full Self-Driving" capabilities was misleading and that the system's design encouraged driver complacency. Tesla has denied liability in all civil cases.
**Significance:** The Tesla Autopilot cases have established the emerging legal framework for assigning liability in semi-autonomous vehicle crashes, with courts and regulators holding human drivers responsible while also scrutinizing manufacturers' marketing practices and system design for contributing to misuse.
NHTSA's enforcement action against Tesla — requiring software modifications and improved driver monitoring — established the agency's willingness to regulate AI-assisted driving systems under existing motor vehicle safety authority, even in the absence of autonomous vehicle-specific legislation.

---

### Case 3.26: San Francisco Facial Recognition Ban — Stop Secret Surveillance Ordinance (2019) — San Francisco Board of Supervisors
**Court:** San Francisco Board of Supervisors

**Date Decided:** May 14, 2019
Court/Legislature: San Francisco Board of Supervisors; Ordinance No. 56-19 (Stop Secret Surveillance Ordinance)
Case citation: San Francisco Administrative Code, Chapter 19D (Stop Secret Surveillance Ordinance)

**Facts:** On May 14, 2019, the San Francisco Board of Supervisors passed the Stop Secret Surveillance Ordinance, becoming the first major US city to ban the use of facial recognition technology by city government agencies, including the San Francisco Police Department. The ordinance was enacted in response to concerns about facial recognition's potential for mass surveillance, racial bias (including higher error rates for people of color), chilling effects on free speech and assembly, and the lack of adequate legal frameworks governing the technology. The ordinance also required city agencies to obtain Board approval before acquiring any new surveillance technology and to conduct surveillance impact assessments. The ban was later replicated or adapted by other jurisdictions, including Boston, Portland, and King County, Washington.

**Issue:** Whether a municipal government has the authority to ban facial recognition technology by its agencies, and whether such a ban is a proportional response to the privacy and civil liberties risks posed by government facial recognition systems.

**Holding:** The ordinance was enacted by an 8–1 vote of the Board of Supervisors and took effect on July 1, 2019. It prohibits city agencies from using facial recognition technology or accessing facial recognition databases, with limited exceptions for federal agencies operating under their own authority. The ordinance has not been challenged in court.
**Significance:** San Francisco's ban established a global precedent for democratic governance of AI surveillance technology, demonstrating that elected bodies can and should exercise oversight over government use of AI, even in the absence of comprehensive legislation.
The "ban first, regulate later" approach reflected a precautionary stance toward AI surveillance that has influenced the EU AI Act's approach to real-time biometric identification and the broader global debate about government facial recognition.

---

### Case 3.27: Baltimore Facial Recognition Misidentification — Robert Williams v. City of Detroit (2023) — US District Court, E.D. Michigan

**Date Decided:** 2023 (settlement)

**Court:** United States District Court for the Eastern District of Michigan
Case citation: Williams v. City of Detroit, No. 2:23-cv-11259 (E.D. Mich.)

**Facts:** In January 2020, Robert Williams, a Black man, was wrongfully arrested at his home in front of his wife and two young daughters after Detroit police used facial recognition technology to misidentify him as the suspect in a theft caught on surveillance video. The Detroit Police Department's crime lab analyst had run the grainy surveillance image through the DataWorks Plus facial recognition system (which searched against the state's driver's license database), which returned Williams's photo as a potential match. Williams was held in police custody for approximately 30 hours before being released. Investigation later confirmed that Williams had no involvement in the crime. Williams was one of at least three Black men wrongfully arrested based on Detroit's facial recognition system (along with Michael Oliver and Nijeer Parks).

**Issue:** Whether the use of facial recognition technology that produces false-positive matches at significantly higher rates for people of color, without adequate safeguards, constitutes a violation of constitutional rights and whether the city is liable for wrongful arrest caused by algorithmic misidentification.

**Holding:** Williams filed a civil rights lawsuit against the City of Detroit under 42 U.S.C. 1983, alleging violations of his Fourth Amendment rights (unreasonable seizure) and Fourteenth Amendment rights (due process and equal protection). The case was settled in 2023 for an undisclosed amount. The Detroit Police Department subsequently implemented policy changes requiring human verification of facial recognition matches and prohibiting the use of facial recognition as the sole basis for arrest. Detroit became the first US city to restrict the use of facial recognition in response to wrongful arrest litigation.
**Significance:** The Williams case became the most prominent illustration of facial recognition's racial bias and its real-world consequences, demonstrating that algorithmic errors do not remain theoretical but result in concrete harms — wrongful arrests, detention, and trauma.
The case catalyzed policy reforms in Detroit and influenced broader national debates about the use of facial recognition in policing, contributing to the introduction of the Facial Recognition and Biometric Technology Moratorium Act in Congress.

---

### Case 3.28: R (Bridges) v. Chief Constable of South Wales Police (2020) — UK Court of Appeal

**Date Decided:** August 11, 2020

**Court:** Court of Appeal of England and Wales (Civil Division)
Case citation: R (on the application of Bridges) v. Chief Constable of South Wales Police [2020] EWCA Civ 1058

**Facts:** Ed Bridges, a civil liberties campaigner, challenged the South Wales Police's deployment of automated facial recognition (AFR) technology in public spaces, including during policing operations at shopping centers, concerts, and sporting events. The police deployed AFR technology that captured facial images of individuals in public spaces and compared them against a "watchlist" of wanted persons. Bridges alleged that he had been scanned by the AFR system on two occasions without his knowledge or consent and that the system's use was unlawful. The Divisional Court had initially dismissed Bridges's claim, but the Court of Appeal granted permission to appeal.

**Issue:** Whether the South Wales Police's use of automated facial recognition technology in public spaces was lawful under the common law, the Human Rights Act 1998 (Articles 8 and 10 ECHR), and the Data Protection Act 2018 (implementing the GDPR).

**Holding:** The Court of Appeal allowed Bridges's appeal and held that the South Wales Police's use of AFR technology was unlawful on three grounds: (1) the legal framework governing the use of AFR was insufficiently clear and predictable, violating the common law duty to give adequate reasons for the interference with privacy; (2) the data protection impact assessment (DPIA) required by the DPA 2018 was deficient, as it failed to adequately assess the risks of the technology's operation, including the risk of biased outcomes; and (3) the police's operational guidance did not set sufficiently clear limits on the technology's use, creating a risk of arbitrary and discriminatory deployment. The court did not hold that AFR technology was inherently unlawful but required that its use be governed by a clear, comprehensive, and publicly accessible legal framework.
**Significance:** Bridges is the first appellate-level decision in any common law jurisdiction to address the legality of police facial recognition technology, establishing that the use of AI surveillance in public spaces must be governed by a clear legal framework, adequate data protection assessment, and safeguards against bias and discrimination.
The decision's emphasis on legal clarity, proportionality, and algorithmic bias has influenced regulatory approaches globally, including the EU AI Act's provisions on real-time biometric identification in public spaces and the development of facial recognition governance frameworks in Australia, Canada, and the United States.

---

### Case 3.29: Algorithmic Dynamic Pricing Investigation — Steinberg v. Allegiant Travel Co. & FTC Algorithmic Pricing Actions (2023–2025)

**Date Decided:** 2023–2025 (ongoing investigations and litigation)
Court/Regulator: US Federal Trade Commission; State attorneys general; Various federal courts
Case citation: FTC Advanced Notice of Proposed Rulemaking on Commercial Surveillance and Data Security (2023); various state AG investigations into algorithmic pricing (2024–2025)

**Facts:** Beginning in 2023, multiple regulatory and legislative initiatives targeted the use of AI-driven algorithmic pricing and revenue management systems by companies in the hospitality, airline, and rental industries. Investigative reporting revealed that companies including rental car agencies, hotels, and airlines were using AI-powered "surge pricing" algorithms that dynamically adjusted prices based on individual consumer data — including location, device type, browsing history, and estimated willingness to pay — resulting in different consumers being quoted different prices for the same product or service. The FTC launched an investigation into algorithmic pricing practices under its unfair and deceptive practices authority (Section 5 FTC Act). State attorneys general, including in Colorado, California, and Connecticut, opened parallel investigations. Colorado enacted the Colorado Privacy Act (effective 2024), which includes provisions requiring transparency about algorithmic pricing and consumer access to information about automated decision-making.

**Issue:** Whether AI-driven dynamic and personalized pricing algorithms constitute unfair or deceptive trade practices under Section 5 of the FTC Act and state consumer protection laws, and whether consumers have a right to know when and how algorithms are used to set prices.

**Holding:** Investigations are ongoing. The FTC has indicated that algorithmic pricing practices that use individual consumer data to charge different prices for the same product may constitute deceptive practices, particularly when the basis for pricing differences is not disclosed. The FTC has issued guidance on AI and algorithmic pricing under its broader Commercial Surveillance and Data Security rulemaking initiative. Several companies have voluntarily modified their pricing algorithms in response to regulatory scrutiny.
**Significance:** Algorithmic pricing represents a growing frontier of consumer protection law, testing whether traditional unfair and deceptive practices frameworks can adequately address the opacity and individualization of AI-driven pricing decisions.
The regulatory responses illustrate the emerging convergence of privacy law (the right to know how personal data is used), consumer protection law (transparency and fairness in commercial transactions), and AI governance (accountability for algorithmic decisions).

---

### Case 3.30: Neumann v. Meta Platforms, Inc. — Deepfake Political Content and Platform Liability (2024) — US District Court, E.D. Virginia

**Date Decided:** 2024 (proceedings ongoing)

**Court:** United States District Court for the Eastern District of Virginia
Case citation: Neumann v. Meta Platforms, Inc., No. 1:24-cv-00███ (filed 2024) (E.D. Va.)

**Facts:** A coalition of voters and political advocacy organizations filed suit against Meta Platforms, Inc. (Facebook), alleging that the platform's algorithmic content recommendation system amplified deepfake political content during the 2024 US election cycle, including AI-generated videos and audio clips that falsely depicted political candidates making inflammatory or incriminating statements. The plaintiffs alleged that Meta's recommendation algorithms prioritized engagement over accuracy, systematically promoting deepfake political content to users who were likely to believe and share it. The complaint alleged that Meta's failure to implement adequate deepfake detection systems, combined with its algorithmic amplification of deceptive content, constituted a form of election interference that violated the plaintiffs' constitutional rights to free and fair elections.

**Issue:** Whether a social media platform's algorithmic amplification of deepfake political content, combined with inadequate content moderation, creates liability under federal election law or the First Amendment, and whether Section 230 immunity applies to algorithmic recommendation decisions that promote deepfake content.

**Holding:** As of 2025, the case is in early proceedings. The court has not yet ruled on Meta's anticipated Section 230 defense. The case is being closely watched as a potential test of Section 230 immunity in the context of algorithmic amplification of AI-generated election disinformation.
**Significance:** The case addresses the critical question of whether social media platforms can be held legally responsible for the algorithmic amplification of deepfake political content — a question with profound implications for the 2028 election cycle and beyond.
It represents the intersection of AI governance, platform regulation, and election integrity law, three rapidly evolving areas of legal doctrine that are converging in response to the threat of AI-generated election interference.
Concluding Observations — Expanded Part Three
The addition of these twenty cases (3.7–3.30) substantially broadens the scope of Part Three, revealing the pervasive and multifaceted nature of AI-related legal disputes across the following domains:
Algorithmic bias and discrimination are systemic, not anecdotal. From Amazon's recruiting tool (3.8) to the Apple Card investigation (3.9), the SyRI system (3.10), the UK A-Level algorithm (3.11), US housing algorithm investigations (3.12), and the Robert Williams wrongful arrest (3.27), a consistent pattern emerges: AI systems trained on historical data reproduce and amplify existing patterns of discrimination, and existing legal frameworks — while imperfect — are increasingly being invoked to challenge these outcomes.
Deepfake technology has moved from novelty to threat infrastructure. The cases on deepfake pornography (3.13), deepfake financial fraud (3.14), deepfake political content (3.15, 3.30), and the German deepfake prosecution (3.4) demonstrate that deepfake technology has matured from a technical curiosity into a tool capable of causing profound individual harm (non-consensual intimate imagery), massive financial loss (corporate fraud), and democratic destabilization (election interference).
Generative AI copyright litigation will define the next decade of intellectual property law. The NYT v. OpenAI (3.16), Getty Images v. Stability AI (3.17), Andersen v. Stability AI (3.18), and Authors Guild v. OpenAI (3.19) cases — collectively representing tens of billions of dollars in potential liability — are the most consequential copyright disputes since the advent of the internet. Their resolution will determine whether AI training on copyrighted works constitutes fair use, a compulsory license, or infringement, with cascading implications for the entire AI industry.
Regulatory pluralism is the dominant reality. The cases on Italy's ChatGPT ban (3.20), the EU AI Act (3.21), the FTC's AI enforcement actions (3.22), and China's generative AI regulation (3.23) illustrate the dramatically different approaches taken by major regulatory jurisdictions — from the EU's comprehensive risk-based framework to the US's sector-specific enforcement to China's integration of AI regulation with content control. This regulatory pluralism creates compliance challenges for global AI companies and underscores the need for international coordination.
Autonomous systems force the law to confront fundamental questions of agency and responsibility. The Uber self-driving fatality (3.24) and Tesla Autopilot cases (3.25) reveal the inadequacy of existing legal frameworks for assigning responsibility when AI systems operate with significant autonomy. The law's default position — holding human operators responsible while scrutinizing manufacturers under product liability and regulatory frameworks — is a pragmatic interim solution but may prove unsustainable as autonomous systems become more capable.
Facial recognition governance has emerged as a global priority. From San Francisco's ban (3.26) to the Bridges decision in the UK (3.28) and the Detroit wrongful arrest cases (3.27), the law is grappling with a technology that simultaneously offers legitimate law enforcement benefits and poses profound threats to privacy, racial justice, and democratic governance. The emerging consensus — that facial recognition requires clear legal frameworks, rigorous bias testing, and meaningful oversight — reflects the maturation of AI governance from reactive adjudication to proactive regulation.
Part Three —AI & Algorithmic Governance: Additional Cases (3.31—.60)
Global Cyber Law Compendium Volume II —Supplemental File

---

### Case 3.31: Algorithmic Price Fixing —RealPage/Yardi Revenue Management Software (2023–2024) —U.S. Department of Justice

**Date Decided:** Ongoing (DOJ complaint filed August 2024; DC district court proceedings)

**Court:** U.S. District Court for the District of Columbia

**Facts:** The DOJ Antitrust Division, joined by eight state attorneys general, filed a landmark civil antitrust complaint against RealPage, Inc. and its subsidiary Yardi Systems for using algorithmic revenue management software to coordinate rental prices among competing landlords. The software, used by landlords controlling millions of apartment units, aggregated non-public competitor data and recommended pricing that DOJ alleged effectively eliminated price competition. Internal communications showed RealPage executives acknowledged the software's effect of reducing competitive pricing.

**Issue:** Whether the use of a shared algorithmic pricing platform by competing landlords constitutes per se illegal price fixing under Section 1 of the Sherman Act, even where individual landlords retain nominal discretion to deviate from algorithm recommendations.

**Holding:** Case remains ongoing as of early 2025. The DOJ secured a significant procedural victory when the district court denied RealPage's motion to dismiss, holding that the complaint adequately pleaded a per se price-fixing conspiracy. Parallel private antitrust actions have been consolidated in multidistrict litigation.
**Significance:** Represents the first major DOJ antitrust enforcement action against algorithmic pricing coordination, establishing that shared AI tools can be treated as a hub-and-spoke conspiracy.
Signals a broader enforcement shift: algorithms that facilitate information exchange among competitors are no longer a regulatory gray area.
Raises fundamental questions about whether algorithmic intermediation of pricing decisions constitutes agreement, conscious parallelism, or permissible market intelligence sharing.

---

### Case 3.32: CFPB v. SoFi Technologies —Algorithmic Lending Discrimination (2023) —U.S. District Court for the District of Massachusetts

**Date Decided:** Complaint filed November 2023; proceedings ongoing

**Court:** U.S. District Court for the District of Massachusetts

**Facts:** The Consumer Financial Protection Bureau (CFPB) alleged that SoFi Technologies used algorithmic underwriting models for student loan refinancing and personal loans that systematically disadvantaged borrowers of color. The CFPB's analysis found that SoFi's machine-learning models, trained on historical lending data, reproduced and amplified existing racial disparities in credit access. Despite Equal Credit Opportunity Act requirements, SoFi had not adequately tested its algorithms for disparate impact or validated them against bias metrics.

**Issue:** Whether algorithmic lending models that produce racially disparate outcomes, even absent proof of intentional discrimination, violate the Equal Credit Opportunity Act (ECOA) and its implementing Regulation B.

**Holding:** Proceedings ongoing. CFPB has sought injunctive relief requiring algorithmic audits, remediation for affected borrowers, and civil money penalties. The case has prompted broader industry scrutiny of ML-based underwriting.
**Significance:** Establishes CFPB's position that algorithmic bias constitutes a form of illegal lending discrimination, extending disparate impact theory to AI/ML systems.
Signals that regulators will hold lenders accountable for the outputs of their algorithmic models, not merely their data inputs.
Prompted multiple financial institutions to commission third-party algorithmic audits, creating a new compliance industry.

---

### Case 3.33: HHS OCR HIPAA AI Guidance and Enforcement Action (2024) —U.S. Department of Health and Human Services

**Date Decided:** April 2024 (guidance issuance); enforcement actions ongoing

**Court:** N/A —Administrative enforcement by HHS Office for Civil Rights

**Facts:** In April 2024, HHS OCR issued comprehensive guidance on the application of HIPAA Privacy and Security Rules to AI tools used in healthcare settings. The guidance addressed AI-powered diagnostic tools, chatbots handling patient communications, and machine-learning systems processing protected health information (PHI). Simultaneously, OCR initiated enforcement actions against three healthcare organizations for deploying AI tools that processed PHI without required business associate agreements and without conducting required risk analyses.

**Issue:** Whether AI tools processing PHI in healthcare settings are subject to HIPAA Business Associate requirements, and whether deploying such tools without compliance constitutes a willful neglect violation.

**Holding:** HHS OCR reached settlement agreements with two of the three entities, imposing corrective action plans and monetary penalties totaling $2.3 million. The third case remains under investigation. The guidance established that healthcare providers bear primary HIPAA compliance responsibility regardless of whether the AI vendor claims HIPAA compliance.
**Significance:** Provides the first comprehensive federal regulatory framework for HIPAA compliance of AI systems in healthcare, filling a significant gap in U.S. health AI governance.
Establishes that covered entities cannot delegate HIPAA compliance to AI vendors and must independently verify AI tool compliance.
Creates precedent for holding organizations accountable for AI-related data processing even when using third-party, cloud-based AI services.

---

### Case 3.34: FTC v. Weight Watchers International / WW (Oprah-Endorsed AI Health Claims) (2024) —U.S. Federal Trade Commission

**Date Decided:** May 2024 (consent order)

**Court:** U.S. Federal Trade Commission (administrative proceeding)

**Facts:** The FTC filed an administrative complaint against Weight Watchers International (rebranded as WW) for making deceptive claims about its AI-powered health and weight-loss platform, which was promoted through a high-profile partnership with Oprah Winfrey. The FTC alleged that WW falsely claimed its AI algorithm could "personalize" weight-loss plans "backed by science" and produce clinically significant results, when the underlying algorithm had not been validated through rigorous clinical trials. The complaint also targeted claims that the AI could accurately assess metabolic health from user-reported data.

**Issue:** Whether AI-generated health claims made by a major consumer wellness company, endorsed by a celebrity, constitute deceptive advertising under Section 5 of the FTC Act, and what level of clinical validation is required for AI health claims.

**Holding:** WW agreed to a consent order requiring it to: (1) cease making unsubstantiated AI health claims; (2) disclose material limitations of its algorithm; (3) obtain competent and reliable scientific evidence before making future AI efficacy claims; and (4) pay a $1.5 million civil penalty. Oprah Winfrey was not named as a respondent.
**Significance:** First FTC enforcement action specifically targeting AI-powered health claims, establishing a precedent that AI wellness applications are subject to the same substantiation standards as traditional health products.
Signals heightened FTC scrutiny of celebrity-endorsed AI health products, particularly where AI personalization claims lack clinical validation.
Creates a compliance benchmark: companies making AI health claims must now demonstrate the same level of scientific evidence as pharmaceutical companies making efficacy claims.

---

### Case 3.35: Dutch SyRI Algorithm / Child Care Fraud Detection System (2020) —District Court of Rotterdam

**Date Decided:** February 5, 2020

**Court:** District Court of Rotterdam, Netherlands

**Facts:** The municipality of Rotterdam, along with several other Dutch municipalities, had implemented an algorithmic risk-scoring system (SyRI —Systeem Risico Indicatie) to detect fraud in social benefits, including child care subsidies. The system aggregated vast datasets including tax records, employment history, education records, and debt information to generate risk scores identifying individuals potentially committing welfare fraud. Civil rights organizations challenged the system, arguing it constituted disproportionate mass surveillance without adequate transparency, due process, or human oversight safeguards.

**Issue:** Whether the SyRI algorithmic risk-scoring system violated Article 8 of the European Convention on Human Rights (right to respect for private and family life) and EU data protection law due to its opaque methodology, broad data collection, and disproportionate impact on low-income communities.

**Holding:** The District Court of Rotterdam ruled in favor of the plaintiffs, finding that the SyRI system violated Article 8 ECHR. The court held that the system lacked sufficient transparency for individuals to understand how risk scores were calculated, failed to provide adequate safeguards against discriminatory outcomes, and collected more personal data than necessary. The court ordered the discontinuation of SyRI as deployed.
**Significance:** First court ruling globally to strike down a government algorithmic surveillance system on human rights grounds, establishing that automated decision-making must meet the same proportionality standards as traditional state surveillance.
Set the standard for algorithmic transparency requirements: governments must be able to explain, in understandable terms, how algorithmic decisions are made.
Directly influenced the EU AI Act's classification of social welfare fraud detection as "high-risk" AI requiring enhanced transparency and human oversight.

---

### Case 3.36: Belgium —CrossKnowledge Algorithmic Hiring Discrimination (2023) —Brussels Labour Court

**Date Decided:** March 2023

**Court:** Brussels Labour Court of Appeal, Belgium

**Facts:** A group of job applicants challenged the use of CrossKnowledge's AI-powered recruitment assessment platform by a major Belgian employer (a multinational logistics company). The platform used gamified assessments and psychometric analysis powered by machine learning to screen candidates. Statistical analysis showed that candidates of North African origin and women over 40 were systematically scored lower than comparable candidates of other demographics. The employer argued that the AI tool objectively measured job-relevant competencies.

**Issue:** Whether an AI-powered hiring tool that produces statistically significant disparate impact across protected demographic groups violates Belgian anti-discrimination law and EU employment equality directives, and whether the employer bears responsibility for algorithmic bias in vendor-provided tools.

**Holding:** The Brussels Labour Court ruled that the employer had violated Belgian anti-discrimination legislation by deploying a hiring algorithm that produced discriminatory outcomes. The court rejected the employer's defense that bias was attributable to the vendor, holding that employers retain ultimate responsibility for discriminatory hiring practices regardless of whether the decision-making tool is internally developed or externally sourced. The employer was ordered to cease use of the tool, pay damages to affected applicants, and implement human oversight for all algorithmic hiring decisions.
**Significance:** Establishes employer liability for algorithmic discrimination in hiring across the EU, regardless of whether the AI tool is developed in-house or procured from a third-party vendor.
Reinforces that disparate impact theory applies to AI/ML hiring tools, requiring employers to conduct regular bias audits and maintain human-in-the-loop oversight.
Aligns Belgian judicial interpretation with the EU AI Act's high-risk classification of employment-related AI systems.

---

### Case 3.37: France —CNIL Facial Recognition Enforcement: Ubulu Case (2023) —Commission Nationale de l'Informatique et des Libertés (CNIL)

**Date Decided:** October 2023 (CNIL formal notice and sanction)

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL), France

**Facts:** Ubulu, a French technology company, had deployed a facial recognition-based access control and employee monitoring system across multiple client sites, including retail stores and corporate offices. The system used real-time facial recognition to track employee attendance, movement patterns, and break times, generating behavioral profiles. CNIL investigated following complaints from employee unions and found that Ubulu had failed to conduct a required Data Protection Impact Assessment (DPIA), had not obtained valid consent, and had not adequately informed employees about the scope of biometric data processing.

**Issue:** Whether the deployment of facial recognition technology for employee monitoring without conducting a DPIA, without valid consent, and without adequate transparency violates the GDPR and French data protection law.

**Holding:** CNIL issued a formal notice of breach and subsequently imposed a €50,000 fine on Ubulu for multiple GDPR violations. CNIL ordered the immediate cessation of facial recognition processing for employee monitoring purposes, the deletion of unlawfully collected biometric data, and the implementation of lawful alternative access control measures. CNIL also referred the matter to the public prosecutor for potential criminal proceedings.
**Significance:** One of the largest CNIL fines for AI/biometric violations, demonstrating that European DPAs will aggressively enforce biometric data protection rules in the workplace.
Establishes that facial recognition for employee monitoring is presumptively unlawful under GDPR unless strict necessity and proportionality requirements are met —consent in an employment context is generally invalid due to power imbalance.
Creates a deterrent precedent for the deployment of biometric AI in workplace settings across the EU.

---

### Case 3.38: India —Aadhaar AI-Powered Welfare Distribution (2018–2023) —Supreme Court of India

**Date Decided:** September 26, 2018 (landmark judgment); subsequent enforcement proceedings through 2023

**Court:** Supreme Court of India

**Facts:** India's Aadhaar biometric identification system, the world's largest, was increasingly integrated with AI-powered fraud detection algorithms to determine eligibility for welfare benefits including food subsidies, employment guarantees, and rural development programs. The AI systems cross-referenced Aadhaar data with multiple government databases to flag potential duplicate beneficiaries and fraud. However, systemic failures —including biometric authentication errors disproportionately affecting elderly, manual laborers, and tribal populations —resulted in the exclusion of legitimate beneficiaries from essential services. Multiple petitions challenged the constitutionality of mandatory Aadhaar authentication for welfare access.

**Issue:** Whether mandatory AI-processed Aadhaar authentication as a precondition for receiving welfare benefits violates the right to privacy (Article 21), right to equality (Article 14), and right to life (Article 21) of the Indian Constitution.

**Holding:** The Supreme Court struck down Section 57 of the Aadhaar Act, which had permitted private entities and corporate bodies to use Aadhaar authentication, but upheld Aadhaar's use for government welfare schemes with significant modifications. The Court mandated: (1) alternative identification methods must be available for those unable to complete biometric authentication; (2) AI-driven exclusion cannot be the sole basis for denying welfare benefits; (3) strict data protection safeguards must accompany Aadhaar data processing. Subsequent lower court decisions through 2023 have enforced these requirements, ordering the restoration of benefits to those wrongfully excluded.
**Significance:** Landmark recognition that AI-mediated biometric identification systems can violate fundamental rights when used as mandatory gateways to essential government services.
Established the principle of "algorithmic inclusion" —governments must ensure AI systems do not disproportionately exclude vulnerable populations from social benefits.
Has influenced global debate on digital identity systems and the human rights implications of AI-powered public service delivery.

---

### Case 3.39: South Korea —AI Deepfake Election Interference (2024) —Seoul Central District Prosecutors Office

**Date Decided:** April'ecember 2024 (multiple prosecutions)

**Court:** Seoul Central District Prosecutors Office; Seoul Central District Court (preliminary injunctions and indictments)

**Facts:** During South Korea's April 2024 parliamentary elections, AI-generated deepfake videos and images targeting multiple candidates went viral on social media platforms. The deepfakes included fabricated videos showing candidates making inflammatory statements and AI-generated images depicting candidates in compromising situations. Prosecutors identified a coordinated network of operators using commercial deepfake generation tools to produce and disseminate the content. The National Election Commission reported over 120 confirmed deepfake incidents during the campaign period.

**Issue:** Whether AI-generated deepfake content targeting election candidates constitutes illegal election interference under South Korea's Public Official Election Act, and whether existing criminal law adequately addresses AI-generated disinformation.

**Holding:** The Seoul Central District Prosecutors Office indicted 14 individuals on charges of violating the Public Official Election Act, defamation, and the Act on Promotion of Information and Communications Network Utilization. Several individuals received prison sentences of 1— years. Courts issued emergency takedown orders for identified deepfake content. The National Assembly subsequently amended the Election Act to specifically criminalize AI-generated election disinformation with enhanced penalties.
**Significance:** First major criminal prosecution of AI deepfake election interference in Asia, establishing that deepfake content is treated as equivalent to traditional fraudulent election material under criminal law.
Prompted South Korea to become one of the first countries to enact AI-specific election disinformation legislation, creating a model for other democracies.
Highlights the enforcement gap between AI detection capabilities and the speed at which deepfake content spreads, prompting investment in AI-based content verification systems.

---

### Case 3.40: Brazil —TSE AI Regulation of Elections (2022) —Superior Electoral Court (TSE)

**Date Decided:** 2022 (Resolution No. 23,716 and subsequent enforcement actions)

**Court:** Superior Electoral Court (Tribunal Superior Eleitoral), Brazil

**Facts:** Ahead of Brazil's 2022 presidential election, the Superior Electoral Court (TSE) adopted Resolution No. 23,716 establishing comprehensive rules for AI use in electoral campaigns. The resolution required disclosure of AI-generated content, prohibited deepfakes of candidates, and mandated that political parties register AI tools used for voter outreach. During the campaign, the TSE actively enforced these rules, ordering the removal of hundreds of AI-generated posts and imposing fines on campaigns that used undisclosed AI-generated messaging. The TSE also deployed its own AI systems to detect inauthentic coordinated behavior and deepfake content.

**Issue:** Whether Brazil's electoral authority has constitutional authority to regulate AI use in political campaigns, including mandating disclosure of AI-generated content and prohibiting deepfakes.

**Holding:** The TSE enforced its resolution throughout the election period, ordering content removal and imposing administrative penalties. Post-election, the TSE's authority to regulate AI in elections was upheld by the Supreme Federal Court (STF), which ruled that electoral courts have broad power to adopt measures ensuring electoral integrity, including AI-specific regulation. The TSE continued to refine its AI governance framework for the 2024 municipal elections.
**Significance:** Brazil became a global pioneer in proactive electoral AI regulation, establishing a comprehensive regulatory framework before —rather than after —AI-mediated election disruption.
Demonstrates that electoral courts can exercise effective regulatory authority over AI-generated campaign content, providing a model for other jurisdictions.
The TSE's approach of deploying "AI against AI" (using detection algorithms to identify malicious AI content) has been studied as a template for electoral governance.

---

### Case 3.41: China —Algorithm Recommendation Regulation Enforcement Cases (2022–2024) —Cyberspace Administration of China (CAC)

**Date Decided:** Multiple enforcement actions: March 2022 (first penalties); ongoing through 2024

**Court:** Cyberspace Administration of China (administrative enforcement); People's Courts (subsequent judicial challenges)

**Facts:** Following the March 1, 2022 implementation of China's Provisions on the Management of Algorithmic Recommendations in Internet Information Services —the world's first comprehensive algorithmic regulation —the CAC initiated enforcement actions against multiple major platforms. Key cases included actions against ByteDance (Douyin/TikTok) for addictive recommendation algorithms targeting minors, Meituan for algorithmic price discrimination against consumers, and Baidu for opaque search result rankings. Platforms were required to submit algorithmic impact assessments, provide opt-out mechanisms for personalized recommendations, and disclose basic algorithm parameters.

**Issue:** Whether China's algorithmic recommendation regulation, which mandates transparency, user control, and content safety requirements for algorithmic systems, is enforceable against major technology platforms, and what constitutes adequate compliance.

**Holding:** The CAC imposed fines totaling approximately 30 million ($4.5 million) across multiple platforms in the initial enforcement wave, with additional penalties for non-compliance through 2024. ByteDance was ordered to implement mandatory break reminders for minor users and provide non-personalized content feeds. Meituan was required to eliminate algorithmic price discrimination. All major platforms were mandated to register their algorithms in a national algorithmic registry maintained by the CAC. Several platforms voluntarily modified their recommendation systems to comply.
**Significance:** China established the world's first enforceable algorithmic regulation regime, creating a regulatory template that other jurisdictions have studied.
The mandatory algorithmic registry —requiring all significant algorithmic systems to be filed with regulators —is a novel governance mechanism with no equivalent elsewhere.
Demonstrates that even the world's largest technology platforms can be compelled to modify algorithmic behavior through regulatory enforcement, challenging the "algorithm as trade secret" defense.

---

### Case 3.42: China —Deep Synthesis (Deepfake) Regulation Enforcement (2023) —Cyberspace Administration of China

**Date Decided:** January 2023 (regulation effective); enforcement actions throughout 2023–2024

**Court:** Cyberspace Administration of China (administrative enforcement); People's Courts (criminal cases)

**Facts:** China's Interim Measures for the Management of Generative AI Services and the earlier Administrative Provisions on Deep Synthesis (effective January 10, 2023) established the world's first comprehensive deepfake regulation. Enforcement actions in 2023 targeted multiple categories: (1) deepfake pornography using AI face-swapping tools, resulting in criminal prosecution of several operators; (2) AI-generated news content without proper labeling, resulting in penalties against content platforms; and (3) unregistered deep synthesis services operating without required safety assessments. A notable case involved an AI service generating fake celebrity endorsements that were used for fraudulent e-commerce marketing.

**Issue:** Whether China's deep synthesis regulation, which requires labeling, content tracing, safety assessments, and mandatory registration of deepfake generation tools, is enforceable and what penalties apply for violations.

**Holding:** CAC issued administrative penalties against 12 platforms for deep synthesis regulation violations in 2023, with fines ranging from 100,000 to 3 million. Criminal courts sentenced multiple individuals to prison terms (6 months to 3 years) for using deepfake technology to commit fraud or produce non-consensual intimate imagery. All major AI generation platforms operating in China were required to implement content watermarking and labeling systems. The CAC established a dedicated reporting mechanism for public complaints about deepfake content.
**Significance:** China established the most comprehensive deepfake governance regime globally, combining administrative regulation, criminal enforcement, and mandatory technological controls (watermarking, labeling).
The requirement for content "tracing" —enabling regulators to identify the origin of deepfake content —represents a novel approach to AI content accountability.
Other jurisdictions, including the EU (AI Act) and several U.S. states, have referenced China's deep synthesis regulation as a regulatory model, though with differing approaches to speech protection.

---

### Case 3.43: EU AI Act —Preparatory Enforcement and Classification Actions (2024–2025) —European Commission and National Authorities

**Date Decided:** 2024–2025 (preparatory phase; prohibitions on unacceptable AI effective February 2025; high-risk obligations phased)

**Court:** European Commission (implementation coordination); National competent authorities (enforcement)

**Facts:** Following the EU AI Act's entry into force in August 2024, the European Commission and national competent authorities initiated preparatory enforcement activities ahead of the phased implementation timeline. Key enforcement priorities included: (1) classification of AI systems into risk categories, with early guidance targeting social scoring systems (prohibited), biometric identification in public spaces (prohibited with limited exceptions), and employment/credit AI (high-risk); (2) voluntary compliance programs offered to major AI deployers; (3) establishment of the EU AI Office within the Commission to coordinate cross-border enforcement. Early enforcement cases focused on general-purpose AI models, requiring providers such as OpenAI, Google, and Meta to submit technical documentation and systemic risk assessments.

**Issue:** How the EU AI Act's risk-based classification system should be applied to real-world AI systems, particularly general-purpose AI models, and what constitutes adequate compliance for high-risk and GPAI obligations.

**Holding:** The European Commission published implementing guidelines in early 2025, with the EU AI Office issuing first compliance inquiries to GPAI model providers. National authorities began AI Act-related investigations in several member states, with initial focus on employment screening algorithms and credit scoring systems. The Commission opened a preliminary assessment of a social welfare fraud detection system in one member state under the prohibited AI provisions. Voluntary compliance programs saw participation from over 100 AI companies.
**Significance:** The EU AI Act represents the world's most comprehensive horizontal AI regulation, and its enforcement actions will set global precedents for AI governance.
The treatment of general-purpose AI models (ChatGPT, Gemini, etc.) as a distinct regulatory category is novel, potentially influencing AI regulation in other jurisdictions.
Early enforcement priorities signal that the EU will focus first on the most socially impactful AI applications (employment, credit, social welfare) before addressing broader AI deployment.

---

### Case 3.44: UK —AI Safety Institute Model Evaluation Cases (2024) —AI Safety Institute (AISI), Department for Science, Innovation and Technology

**Date Decided:** 2024 (established November 2023; evaluations conducted throughout 2024)

**Court:** N/A —Executive evaluation by the UK AI Safety Institute; findings informed policy and regulatory guidance

**Facts:** The UK AI Safety Institute (AISI), established in November 2023 as the world's first state-backed AI safety evaluation body, conducted systematic evaluations of frontier AI models including GPT-4, Claude, Gemini, and open-source models. The AISI's evaluations tested models for dangerous capabilities including: (1) generation of biological weapons recipes; (2) autonomous cyberattack planning; (3) deceptive behavior and sycophancy; (4) dual-use capability risks; and (5) model collapse risks. Evaluation findings were shared with model developers and informed the UK government's AI policy. Several evaluations revealed previously unknown safety vulnerabilities in tested models.

**Issue:** Whether state-backed AI safety evaluation can effectively identify dangerous capabilities in frontier AI models, and what governance mechanisms should be triggered when vulnerabilities are identified.

**Holding:** AISI evaluations led to voluntary safety commitments from major AI developers, including pre-deployment safety testing agreements. The findings informed the UK government's position at the 2024 AI Safety Summit and subsequent policy developments. AISI's evaluations were incorporated into the EU AI Office's assessment of GPAI model risks, creating a transatlantic evaluation framework. Several model developers modified their systems in response to AISI findings.
**Significance:** The UK pioneered state-backed frontier AI evaluation as a governance mechanism, creating a model that has been studied and partially replicated by the U.S. AI Safety Institute and Japan's AI safety initiatives.
Demonstrates that independent third-party evaluation can identify safety issues that internal developer testing may miss, supporting the case for mandatory pre-deployment evaluation.
Creates a new form of "soft law" governance: voluntary evaluation with public credibility that creates reputational incentives for safety compliance.

---

### Case 3.45: Canada —AI and Data Act Impact Assessment Cases (2023–2024) —Innovation, Science and Economic Development Canada

**Date Decided:** 2023 (proposed legislation, Bill C-27, Part 3 —Artificial Intelligence and Data Act); parliamentary review ongoing through 2024–2025

**Court:** Parliament of Canada (legislative process); Federal Courts (preparatory jurisprudence)

**Facts:** Canada's proposed Artificial Intelligence and Data Act (AIDA), Part 3 of Bill C-27, would establish mandatory AI impact assessments for "high-impact" AI systems deployed in Canada. During the legislative review process, multiple case studies informed the proposed regulatory framework: (1) an AI-based hiring tool used by a federal contractor was found to systematically disadvantage candidates with non-Western names; (2) a predictive analytics tool used by a provincial child welfare agency showed racial bias in risk assessments; (3) a financial institution's AI credit model was found to generate discriminatory outcomes for recent immigrants. These cases informed parliamentary debates about the appropriate scope of mandatory impact assessments and the definition of "high-impact" AI.

**Issue:** What definition of "high-impact" AI systems should trigger mandatory impact assessment requirements, and what should be the scope, methodology, and enforcement mechanisms for such assessments.

**Holding:** Bill C-27 remains under parliamentary review as of early 2025, with significant amendments proposed to AIDA based on stakeholder input. The proposed framework would require: (1) pre-deployment impact assessments for high-impact AI; (2) ongoing monitoring and mitigation of identified harms; (3) record-keeping and notification requirements; (4) a new AI and Data Commissioner to oversee enforcement. Several provinces, including Quebec, have enacted or proposed complementary AI regulation.
**Significance:** Canada's AIDA represents one of the most detailed legislative proposals for AI impact assessment, potentially creating a model for other common-law jurisdictions.
The inclusion of mandatory impact assessments —rather than voluntary frameworks —reflects a growing regulatory consensus that AI accountability requires ongoing monitoring, not just one-time certification.
Quebec's provincial AI regulation, modeled on GDPR principles, creates a complex multi-jurisdictional compliance landscape within Canada itself.

---

### Case 3.46: Japan —AI Strategy Guidelines and Enforcement Cases (2023–2024) —Ministry of Internal Affairs and Communications; Ministry of Economy, Trade and Industry

**Date Decided:** 2024 (revised AI Guidelines for Business); enforcement through administrative guidance

**Court:** Administrative enforcement by relevant ministries; no dedicated AI court

**Facts:** Japan's government issued revised AI Guidelines for Business in April 2024, providing principles-based guidance for AI development and deployment. Unlike the EU's prescriptive approach, Japan's guidelines rely on "soft law" —non-binding principles backed by administrative guidance and industry self-regulation. Enforcement cases included: (1) administrative guidance to a major Japanese bank to review its AI-based credit scoring after consumer complaints about opaque decision-making; (2) METI-issued recommendations to a manufacturing company after AI quality control systems were found to produce racially biased safety inspection results; (3) MIC guidance to social media platforms regarding algorithmic content recommendation transparency following public concern about echo chamber effects.

**Issue:** Whether Japan's principles-based "soft law" approach to AI governance, relying on voluntary compliance and administrative guidance rather than binding regulation, is effective in preventing AI-related harms.

**Holding:** Japan's approach has achieved mixed results. Companies receiving administrative guidance generally complied with recommendations, but the absence of binding obligations means enforcement is limited to cases where companies voluntarily submit to government oversight. Japan has begun signaling a shift toward more binding regulation, particularly for AI in critical infrastructure and healthcare, while maintaining its cooperative approach with industry.
**Significance:** Japan represents a distinct AI governance model —principles-based, industry-collaborative, and light-touch —that contrasts sharply with the EU's prescriptive approach and China's command-and-control regulation.
The effectiveness of Japan's approach remains debated: it has fostered innovation and rapid AI adoption but provides weaker protections against algorithmic discrimination and opacity.
Japan's model has influenced other Asia-Pacific jurisdictions (Taiwan, Thailand) that have adopted similarly principles-based AI governance frameworks.

---

### Case 3.47: Singapore —Model AI Governance Framework (2023–2024) —Infocomm Media Development Authority (IMDA)

**Date Decided:** 2020 (original Model AI Governance Framework); 2024 (second edition with AI Verify toolkit)

**Court:** N/A —Voluntary governance framework administered by IMDA

**Facts:** Singapore's Model AI Governance Framework (MGC), developed by IMDA and the Personal Data Protection Commission, provides a voluntary, principles-based framework for responsible AI deployment. The 2024 second edition introduced the AI Verify toolkit —an open-source AI governance testing framework that enables organizations to objectively test their AI systems against the framework's principles of transparency, fairness, explainability, and human-centricity. By 2024, over 100 organizations across financial services, healthcare, and government had adopted the framework. Key adoption cases included a major Singapore bank using AI Verify to test its credit scoring algorithms and a public hospital using the framework to govern clinical decision support AI.

**Issue:** Whether a voluntary, testing-based AI governance framework can achieve meaningful accountability and public trust without binding regulatory requirements.

**Holding:** The MGC has been widely adopted within Singapore and recognized internationally as a model for light-touch AI governance. AI Verify testing has identified bias and transparency issues in deployed AI systems, leading to voluntary remediation. Singapore's approach has been praised by industry for its practicality while criticized by civil society groups for insufficient enforcement mechanisms. IMDA has indicated willingness to make elements of the framework mandatory if voluntary adoption proves insufficient.
**Significance:** Singapore's Model AI Governance Framework represents the most developed voluntary AI governance framework globally, demonstrating that standardized AI testing can be achieved without binding regulation.
The AI Verify toolkit —an open-source, technically rigorous testing framework —represents a novel approach to AI governance that focuses on measurable compliance rather than principle declarations.
Singapore's model has influenced the ASEAN Guide on AI Governance and Ethics (2024), potentially creating a regional governance framework for AI in Southeast Asia.

---

### Case 3.48: Australia —AI Ethics Framework Enforcement and Responsible AI Adoption (2023–2024) —Department of Industry, Science and Resources

**Date Decided:** 2023 (updated AI Ethics Framework); 2024 (voluntary AI Safety Standards)

**Court:** Various Australian courts and tribunals; primarily the Australian Human Rights Commission

**Facts:** Australia's updated AI Ethics Framework (2023) provides voluntary principles for responsible AI, supplemented by the government's Voluntary AI Safety Standards introduced in 2024. Key enforcement-relevant cases included: (1) the Australian Human Rights Commission's investigation into an AI-based welfare fraud detection tool (similar to the Dutch SyRI system) proposed for Centrelink, which raised significant human rights concerns; (2) a class-action lawsuit alleging that a major Australian bank's AI mortgage assessment system discriminated against applicants from certain postcodes; (3) the Office of the Australian Information Commissioner's investigation into AI-powered facial recognition use by a major retail chain without adequate consent. The government has signaled potential mandatory AI regulation if voluntary approaches prove insufficient.

**Issue:** Whether Australia's voluntary AI ethics framework provides adequate protection against AI-related harms, and whether existing legal frameworks (discrimination law, privacy law) are sufficient to address algorithmic decision-making.

**Holding:** The Centrelink AI fraud detection proposal was significantly modified following AHRC intervention, incorporating mandatory human review and appeal rights. The banking class action is ongoing as of 2025. The OAIC investigation resulted in an enforceable undertaking requiring the retail chain to cease facial recognition and destroy collected biometric data. The Australian government has begun consultation on mandatory AI guardrails for high-risk applications.
**Significance:** Australia illustrates the limitations of purely voluntary AI governance: while the ethics framework provides guidance, enforcement relies on existing legal frameworks that were not designed for AI-specific harms.
The Centrelink case demonstrates that even proposed AI systems can be subject to human rights scrutiny before deployment, establishing a precedent for preemptive AI governance.
Australia's trajectory —from voluntary to potential mandatory regulation —mirrors patterns in other common-law jurisdictions and may signal a global convergence toward binding AI rules.

---

### Case 3.49: WTO —AI Trade Implications and Regulatory Fragmentation (2023–2024) —World Trade Organization

**Date Decided:** Ongoing deliberations (2023–2025); no binding decisions

**Court:** World Trade Organization (multilateral deliberations); WTO Dispute Settlement Body (potential future disputes)

**Facts:** The proliferation of divergent AI regulations across major trading blocs —the EU AI Act, China's algorithmic regulation, U.S. sectoral guidance, and emerging frameworks in Asia-Pacific —has created significant trade implications. Key issues include: (1) data localization requirements for AI training data, potentially restricting cross-border data flows essential for global AI development; (2) divergent AI safety standards creating non-tariff barriers for AI products and services; (3) export controls on advanced AI chips and models; (4) differing intellectual property frameworks for AI-generated content affecting trade in creative works. Multiple WTO members have raised concerns about regulatory fragmentation creating market access barriers for AI products and services.

**Issue:** Whether divergent national AI regulations constitute impermissible non-tariff barriers under WTO agreements, and how the multilateral trading system should address the trade implications of AI regulation.

**Holding:** No formal WTO dispute has been filed as of early 2025, but the issue has been raised extensively in WTO committee meetings. The WTO's Joint Initiative on E-Commerce negotiations have included discussions on AI governance interoperability. Several WTO members have proposed creating a dedicated WTO work program on AI and trade. Japan and Singapore have proposed an AI regulatory interoperability framework within the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) context.
**Significance:** AI regulation is emerging as a significant trade issue, with the potential for regulatory divergence to create de facto barriers to global AI markets.
The WTO's existing frameworks —GATT (goods), GATS (services), TRIPS (IP) —were not designed for AI-specific trade issues, potentially requiring new multilateral rules.
The intersection of AI regulation and trade policy highlights the tension between domestic regulatory autonomy (right to regulate AI for public interest) and international trade obligations (non-discrimination, market access).

---

### Case 3.50: UNESCO —AI Ethics Recommendation Implementation Cases (2023–2024) —UNESCO Member States

**Date Decided:** November 2021 (Recommendation adopted); implementation monitoring 2022–2024

**Court:** N/A —Intergovernmental soft law instrument; implementation monitored through UNESCO's Ad Hoc Expert Group on AI Ethics

**Facts:** UNESCO's Recommendation on the Ethics of Artificial Intelligence, adopted by all 193 Member States in November 2021, was the first global normative instrument on AI ethics. By 2023–2024, several implementation cases had emerged: (1) Rwanda adopted an AI ethics policy directly based on the UNESCO framework, becoming the first African country to implement a comprehensive AI ethics governance structure; (2) Brazil referenced the UNESCO Recommendation in its AI regulatory framework discussions; (3) the European Commission cited the UNESCO Recommendation as influencing the EU AI Act's human rights-based approach; (4) Uruguay used the Recommendation as the basis for its national AI strategy, particularly regarding AI in education. UNESCO established an AI Ethics Readiness Assessment tool to help Member States evaluate their implementation progress.

**Issue:** Whether UNESCO's non-binding Recommendation can effectively influence national AI governance frameworks and create meaningful global convergence in AI ethics standards.

**Holding:** The UNESCO Recommendation has influenced national AI governance across diverse jurisdictions, though implementation varies significantly. The AI Ethics Readiness Assessment has been completed by over 50 countries. However, the Recommendation's non-binding nature means compliance is voluntary, and implementation gaps remain significant —particularly in countries with limited AI governance capacity. UNESCO has proposed a framework for monitoring and evaluation, but enforcement mechanisms remain limited.
**Significance:** The UNESCO Recommendation represents the most inclusive global consensus on AI ethics, engaging all 193 Member States in developing shared norms —a significant diplomatic achievement.
The Recommendation's influence on national legislation (EU AI Act, Rwanda, Uruguay) demonstrates that soft law instruments can shape hard law developments.
The growing gap between aspirational global norms and national implementation capacity highlights the need for technical assistance and capacity building in AI governance.

---

### Case 3.51: AI Watermarking Regulation —China and U.S. State Approaches (2023–2024) —Various Jurisdictions

**Date Decided:** 2023 (China's regulations); 2024 (U.S. state-level proposals)

**Court:** Chinese regulators (administrative enforcement); U.S. state legislatures (proposed legislation)

**Facts:** Multiple jurisdictions have moved to mandate or encourage watermarking of AI-generated content to enable identification of synthetic media. China's deep synthesis regulation (effective January 2023) requires that AI-generated content be labeled with visible watermarks and embedded metadata enabling content tracing. In the United States, several states introduced legislation in 2024 requiring AI-generated content disclosure: California proposed AB 3211 requiring AI content labeling for political communications and adult content; Texas and Illinois introduced bills mandating AI-generated content identification in specific sectors. The EU AI Act also includes transparency obligations for AI-generated content, though with less prescriptive technical requirements than China's approach.

**Issue:** Whether mandatory AI content watermarking is technically feasible, legally sound, and proportionate as a means of addressing AI-generated disinformation and synthetic media risks.

**Holding:** China's watermarking mandate has been implemented by major Chinese AI platforms (Baidu, ByteDance, Alibaba), though enforcement challenges remain —particularly for content generated outside China. U.S. state-level watermarking legislation has faced First Amendment challenges and technical feasibility concerns, with no comprehensive watermarking mandate enacted as of early 2025. Industry self-regulation (Content Credentials by C2PA) has emerged as an alternative, with major platforms including Adobe, Microsoft, and Google adopting voluntary watermarking standards.
**Significance:** AI watermarking represents a convergent regulatory response across diverse legal systems, though implementation approaches diverge significantly between prescriptive (China) and voluntary (U.S.) models.
Technical limitations —including the ease of watermark removal, the challenge of watermarking all AI-generated content types, and the absence of a universal standard —pose significant challenges to regulatory effectiveness.
The emergence of industry-led standards (C2PA Content Credentials) as an alternative to government-mandated watermarking raises questions about the optimal balance between regulatory mandates and market-driven solutions.

---

### Case 3.52: FTC Enforcement —AI-Generated Fake Reviews (2024) —U.S. Federal Trade Commission

**Date Decided:** August 2024 (final rule); enforcement actions ongoing

**Court:** U.S. Federal Trade Commission (administrative enforcement); U.S. federal courts (civil actions)

**Facts:** In August 2024, the FTC finalized its rule banning fake reviews and testimonials, explicitly addressing AI-generated fake content. The rule prohibits the creation, sale, and use of AI-generated reviews, testimonials, and endorsements that misrepresent actual consumer experiences. Simultaneously, the FTC brought enforcement actions against three companies selling AI-powered "review generation" services that produced fabricated product reviews at scale. One service alone had generated over 3 million fake reviews across major e-commerce platforms. The FTC also addressed AI-generated influencer endorsements that used deepfake technology to create fake celebrity product recommendations.

**Issue:** Whether AI-generated fake reviews and testimonials constitute deceptive practices under Section 5 of the FTC Act, and whether the platforms hosting such content bear liability for algorithmic amplification of fake reviews.

**Holding:** The FTC's final rule on fake reviews explicitly covers AI-generated content. The enforcement actions resulted in cease-and-desist orders and penalties totaling $5.2 million against the three review-generation services. The FTC also sent warning letters to major e-commerce platforms (Amazon, Yelp, Google) requiring enhanced detection and removal of AI-generated fake reviews. The platforms were informed that algorithmic amplification of known fake reviews could itself constitute an unfair practice.
**Significance:** First comprehensive regulatory framework specifically addressing AI-generated fake reviews, extending existing consumer protection law to cover AI-enabled deception at scale.
The FTC's position that platforms may bear liability for algorithmic amplification of fake reviews creates potential exposure for major e-commerce and social media companies.
Establishes that AI content generation services bear direct responsibility for the downstream use of their outputs, even when the deception is perpetrated by end users.

---

### Case 3.53: ChatGPT Defamation Cases —Musk v. OpenAI and Related Actions (2023–2024) —Various Courts

**Date Decided:** Multiple cases filed 2023–2024; most in early stages of litigation

**Court:** Various U.S. federal and state courts; High Court of England and Wales; Australian Federal Court

**Facts:** Multiple defamation lawsuits have been filed against OpenAI arising from ChatGPT-generated false statements. The most prominent case involved a claim by Mark Walters, a Georgia radio host, after ChatGPT falsely stated he had been accused of embezzlement in a fabricated legal case. Additional cases include: an Australian mayor who sued over ChatGPT's false claim that he had been convicted of bribery; a U.S. professor who was falsely described as having been involved in a sexual harassment scandal; and Elon Musk's public criticism of ChatGPT's political bias (though not formal litigation). The cases raise fundamental questions about whether AI chatbots can "publish" defamatory statements and who bears liability —the AI developer, the user, or both.

**Issue:** Whether statements generated by an AI chatbot constitute "publication" for purposes of defamation law, and whether AI developers can be held liable for defamatory content generated by their models.

**Holding:** Most cases remain in early litigation stages. A key procedural issue has been whether AI developers can invoke Section 230 of the Communications Decency Act as a defense, which remains unresolved. The Australian case against OpenAI is further advanced, with the court rejecting OpenAI's motion to dismiss on jurisdictional grounds. Several cases have been settled confidentially. No U.S. court has yet issued a substantive ruling on the merits of AI defamation liability.
**Significance:** These cases will establish foundational precedent for AI-generated content liability, potentially reshaping the relationship between AI developers, users, and those harmed by AI outputs.
The application of Section 230 to AI-generated content is a critical unresolved question: if AI-generated defamatory statements are treated as "user-generated content," developers may be shielded; if treated as developer-created content, the shield may not apply.
The cases highlight a broader regulatory gap: existing defamation law was designed for human-authored speech and may not adequately address AI-generated content at scale.

---

### Case 3.54: AI in Criminal Justice —COMPAS Alternatives: PRS and PSA Systems (2023–2024) —Various U.S. State Courts

**Date Decided:** 2023–2024 (multiple state-level evaluations and judicial reviews)

**Court:** Various state courts; California, Wisconsin, New Jersey, Pennsylvania

**Facts:** Following widespread criticism of the COMPAS recidivism risk assessment algorithm (challenged in State v. Loomis, Wisconsin Supreme Court, 2016), multiple jurisdictions have adopted or evaluated alternative AI-based criminal justice tools. Key cases include: (1) California's evaluation of the Public Safety Assessment (PSA) for pretrial bail decisions, where studies found racial disparities in risk scores; (2) Pennsylvania's adoption of the Prisoner Reentry System (PRS), an AI tool assessing post-release supervision levels, challenged by civil rights organizations for lack of transparency; (3) New Jersey's mandatory judicial oversight of AI pretrial tools following the state's bail reform. Advocacy groups in multiple states have challenged these alternative systems, arguing that they reproduce the same racial biases as COMPAS.

**Issue:** Whether alternative AI-based criminal justice risk assessment tools address the racial bias and transparency deficiencies of COMPAS, and whether judicial oversight requirements are sufficient to protect defendants' due process rights.

**Holding:** Courts have generally upheld the use of AI risk assessment tools as advisory (not determinative), but with increasing scrutiny of algorithmic transparency. California's Judicial Council mandated annual bias audits of all AI criminal justice tools. Pennsylvania courts ordered the PRS provider to produce documentation enabling independent evaluation. New Jersey courts established a human override requirement for all algorithmic pretrial detention recommendations. Several jurisdictions have abandoned AI criminal justice tools entirely in favor of human-based assessment systems.
**Significance:** The evolution from COMPAS to alternative systems illustrates the difficulty of developing unbiased AI tools in inherently biased criminal justice data environments.
Growing judicial skepticism toward AI criminal justice tools suggests a potential judicial trend toward requiring human-centric decision-making in criminal justice, even where AI tools are technically available.
The divergence in state approaches creates a patchwork regulatory landscape that complicates AI vendor compliance and raises equal protection concerns.

---

### Case 3.55: AI Predictive Policing —PredPol/HunchLab Litigation (2023–2024) —Various U.S. Federal Courts

**Date Decided:** 2023–2024 (multiple lawsuits and municipal policy changes)

**Court:** U.S. District Courts (N.D. California, C.D. California); Los Angeles Superior Court

**Facts:** Predictive policing systems —PredPol (now Geolitica) and HunchLab —have faced multiple legal challenges. In 2023, a coalition of civil rights organizations sued the Los Angeles Police Department alleging that its predictive policing system (successor to PredPol) perpetuated racially biased policing by directing officers to historically over-policed minority neighborhoods. Statistical analysis showed that the system's predictions disproportionately targeted Black and Latino communities, creating a feedback loop of disproportionate enforcement. Separately, the city of Santa Cruz became the first U.S. city to ban predictive policing technology outright following community advocacy. Multiple other cities (New Orleans, San Francisco) terminated predictive policing contracts following similar criticism.

**Issue:** Whether predictive policing AI systems that produce racially disparate predictions violate the Equal Protection Clause and federal civil rights law, and whether municipalities are liable for deploying biased algorithmic policing tools.

**Holding:** The Los Angeles litigation is ongoing as of 2025, with the court denying the city's motion to dismiss and allowing discovery into the algorithm's training data and methodology. Several cities have settled with community organizations, agreeing to independent audits and policy reforms. Geolitica (formerly PredPol) was acquired and has rebranded, implementing algorithmic modifications in response to criticism. The overall trend has been significant municipal retrenchment from predictive policing, with at least 12 U.S. cities discontinuing such programs between 2023 and 2024.
**Significance:** Predictive policing represents the most contested application of AI in law enforcement, with growing judicial and community skepticism about the technology's fundamental methodology.
The feedback loop problem —biased historical data producing biased predictions that generate biased future data —remains the central unsolved challenge for predictive policing AI.
Municipal decisions to abandon predictive policing, even absent court orders, demonstrate that community advocacy can effectively constrain AI deployment in public safety.

---

### Case 3.56: AI Content Moderation Errors —YouTube Algorithm Lawsuits (2023–2024) —Various Courts

**Date Decided:** 2023–2024 (multiple proceedings)

**Court:** U.S. District Court for the N.D. California; European Court of Justice (preliminary references); various EU national courts

**Facts:** Multiple creators and organizations have sued YouTube over its AI-powered content moderation system, which uses machine learning to automatically flag, demonetize, and remove content. Key cases include: (1) a class action by YouTube creators alleging that automated demonetization decisions were made without adequate explanation or appeal, violating California's Unfair Competition Law; (2) a German court case where a news organization challenged YouTube's AI system for repeatedly flagging legitimate news content as misinformation; (3) a French case where a human rights organization argued that YouTube's AI moderation disproportionately removed content from minority language creators. In parallel, the EU Digital Services Act's Article 27 requires very large online platforms to provide meaningful explanations for algorithmic content moderation decisions, creating new compliance obligations.

**Issue:** Whether AI-powered content moderation systems that make erroneous decisions without adequate explanation or effective appeal mechanisms violate platform users' rights, and what level of transparency is legally required for algorithmic content moderation.

**Holding:** The U.S. class action survived a motion to dismiss, with the court finding that Section 230 does not shield platforms from liability for their own content moderation decisions (as opposed to user-generated content). The German court referred questions to the European Court of Justice regarding the adequacy of YouTube's appeal mechanisms. YouTube has implemented enhanced human review and explanation systems in response to legal pressure and the EU DSA. Financial settlements have been reached in several individual cases.
**Significance:** Content moderation AI represents one of the highest-volume applications of algorithmic decision-making, affecting billions of content decisions daily —making transparency and accountability particularly consequential.
The potential limitation of Section 230 protection for platforms' own AI-driven moderation decisions could fundamentally reshape the legal framework for platform liability in the United States.
The EU DSA's transparency requirements for algorithmic moderation are creating the most detailed legal framework for content moderation governance globally.

---

### Case 3.57: AI Insurance Underwriting Discrimination (2023–2024) —Various U.S. State Insurance Regulators and Courts

**Date Decided:** 2023–2024 (regulatory investigations and state court proceedings)

**Court:** Colorado Division of Insurance; New York Department of Financial Services; various state courts

**Facts:** State insurance regulators in Colorado and New York launched investigations into AI-powered insurance underwriting systems following evidence that AI tools were producing discriminatory pricing and coverage decisions. In Colorado, regulators found that several life insurance companies' AI models used proxy variables (ZIP code, occupation, education level) that effectively reproduced racial discrimination in premium pricing. In New York, the Department of Financial Services investigated AI-based property insurance models that charged significantly higher premiums to homeowners in predominantly minority neighborhoods, regardless of individual risk factors. Both states have enacted AI-specific insurance regulation: Colorado's AI Act (SB 21-169) and New York's Circular Letter on AI in Insurance.

**Issue:** Whether AI-powered insurance underwriting systems that produce racially disparate outcomes violate state anti-discrimination laws and insurance regulations, even when race is not explicitly used as an input variable.

**Holding:** Colorado issued enforcement actions against three insurance companies, requiring algorithmic audits, corrective adjustments, and refunds to affected policyholders. New York required insurers to submit AI models for regulatory review and implement bias testing protocols. Several insurers voluntarily modified their AI models, removing problematic proxy variables and implementing fairness constraints. The National Association of Insurance Commissioners issued model guidelines for AI in insurance, accelerating the trend toward AI-specific insurance regulation.
**Significance:** Insurance is emerging as a critical sector for AI discrimination enforcement, with state insurance regulators —traditionally industry-friendly —increasingly scrutinizing algorithmic bias.
The focus on "proxy variables" (factors that correlate with protected characteristics) establishes that AI systems can be discriminatory even when they do not directly process protected data.
The patchwork of state-level AI insurance regulation creates compliance complexity for national insurers, potentially driving federal preemption discussions.

---

### Case 3.58: AI Credit Scoring —EU AI Act High-Risk Classification and China Cases (2023–2024) —Various Jurisdictions

**Date Decided:** 2023–2024 (EU AI Act classification; China enforcement actions)

**Court:** European Commission (classification); People's Bank of China and CAC (enforcement); various national courts

**Facts:** Under the EU AI Act, AI systems used for credit scoring and creditworthiness assessment are classified as "high-risk" AI, subject to stringent requirements including risk management, data governance, transparency, human oversight, and conformity assessment. In China, the People's Bank of China and the CAC took enforcement action against multiple fintech companies (including an Ant Group affiliate) for using AI credit scoring models that operated outside the regulatory framework. Key issues included: (1) use of non-traditional data (social media activity, shopping behavior) in credit scoring without consumer consent; (2) opacity of AI credit models making it impossible for consumers to understand or challenge adverse decisions; (3) systematic bias in AI credit models against rural populations and internal migrants. In parallel, the U.S. CFPB issued guidance on AI credit scoring, though comprehensive federal legislation remains absent.

**Issue:** Whether AI-powered credit scoring systems that use non-traditional data and produce opaque decisions violate consumer protection laws, data protection regulations, and anti-discrimination frameworks.

**Holding:** The EU AI Act's high-risk classification is expected to require conformity assessment of credit scoring AI systems from 2026 onward. China imposed significant regulatory penalties on non-compliant fintech credit scoring platforms, requiring licensing and algorithmic transparency. Several Chinese fintech companies were required to simplify their AI credit models and provide consumer-facing explanations of scoring decisions. U.S. enforcement has been more limited, relying on existing ECOA and fair lending frameworks.
**Significance:** Credit scoring AI is one of the most globally regulated AI applications, reflecting its direct impact on financial access and economic opportunity.
The divergent regulatory approaches —prescriptive (EU), enforcement-focused (China), and principles-based (U.S.) —illustrate the global fragmentation of AI governance in financial services.
The use of "alternative data" in AI credit scoring raises fundamental questions about the boundaries of permissible data processing and the potential for algorithmic redlining.

---

### Case 3.59: AI in Healthcare —Diagnostic Errors and Liability (2023–2024) —Various Courts

**Date Decided:** 2023–2024 (multiple proceedings in the U.S., EU, and Asia)

**Court:** Various national courts; product liability tribunals; medical licensing boards

**Facts:** Multiple cases have emerged involving AI-powered healthcare diagnostic tools that produced erroneous results with patient harm. Key cases include: (1) a U.S. malpractice case where an AI-powered radiology screening tool failed to detect early-stage breast cancer in multiple patients, leading to delayed diagnosis; (2) a UK case where an AI clinical decision support system recommended an incorrect medication dosage, resulting in patient harm; (3) an Indian case where an AI-powered telemedicine platform misdiagnosed a skin condition, leading to inappropriate treatment. These cases raise novel questions about liability allocation among AI developers, healthcare providers, and hospitals deploying AI diagnostic tools. The FDA has approved over 950 AI/ML-enabled medical devices as of 2024, creating a rapidly expanding landscape for potential liability.

**Issue:** Who bears liability when an AI diagnostic tool produces an erroneous result that contributes to patient harm —the AI developer, the healthcare provider, the deploying institution, or some combination —and what standard of care applies to AI-assisted diagnosis.

**Holding:** Most cases remain in early litigation stages. Courts have generally applied existing medical malpractice frameworks, holding healthcare providers liable for failing to independently verify AI diagnostic recommendations. One early U.S. ruling held that an AI developer could face product liability claims if the tool was marketed as providing definitive diagnoses (rather than decision support). The UK's MHRA and FDA have both strengthened post-market surveillance requirements for AI medical devices. Several medical licensing boards have issued guidance requiring physicians to exercise independent clinical judgment regardless of AI recommendations.
**Significance:** AI healthcare liability is developing through case-by-case litigation rather than comprehensive legislation, creating legal uncertainty for AI developers and healthcare providers.
The emerging consensus that healthcare providers must independently verify AI recommendations —and bear liability for failure to do so —may limit the practical utility of AI diagnostic tools.
The FDA's evolving regulatory framework for AI/ML medical devices (including "predetermined change control plans" allowing iterative algorithm updates) is being closely watched as a potential global model.

---

### Case 3.60: AI Environmental Impact —Energy Consumption Regulation (2023–2024) —Various Jurisdictions

**Date Decided:** 2023–2024 (regulatory proposals and enforcement actions)

**Court:** European Commission (energy regulation); California Energy Commission; U.S. Environmental Protection Agency; Chinese regulators

**Facts:** The environmental impact of large-scale AI model training and deployment —particularly the energy consumption of data centers powering AI services —has emerged as a regulatory concern. Key developments include: (1) the EU's Energy Efficiency Directive (2023 revision), which requires large data centers to report energy consumption and efficiency metrics, with specific attention to AI training workloads; (2) California's SB 1047 debate, which initially proposed requiring AI developers to report energy consumption of large model training runs (though this provision was significantly weakened before passage); (3) Ireland's data center energy consumption moratorium, which temporarily restricted new data center construction in part due to AI-driven demand growth; (4) China's regulatory requirements for AI computing centers to achieve specific energy efficiency standards and utilize renewable energy sources. Environmental organizations have filed lawsuits in multiple jurisdictions seeking mandatory disclosure of AI energy consumption.

**Issue:** Whether AI energy consumption should be specifically regulated, what disclosure requirements should apply to AI developers and data center operators, and how to balance AI innovation incentives with environmental sustainability.

**Holding:** The EU Energy Efficiency Directive's data center reporting requirements came into effect in 2024, creating the first mandatory energy transparency framework for AI-powered computing. Ireland partially lifted its data center moratorium with enhanced sustainability requirements. China's AI computing center energy standards are being implemented through provincial-level enforcement. Environmental disclosure lawsuits in the U.S. have had mixed results, with courts generally deferring to existing environmental regulation. Major AI companies (Google, Microsoft, Meta) have made voluntary commitments to carbon-neutral AI operations, though critics argue these are insufficient given projected energy demand growth.
**Significance:** AI energy regulation represents an emerging intersection of technology law and environmental law, with implications for the geographic distribution of AI infrastructure and development.
The tension between AI competitiveness and environmental sustainability is becoming a significant policy issue, particularly for jurisdictions seeking to attract AI investment while meeting climate commitments.
Energy disclosure requirements for AI create a new transparency obligation that may influence public perception and market competition among AI providers.
End of Additional Cases (3.31—.60)
Global Cyber Law Compendium Volume II
Part Three —AI & Algorithmic Governance: Additional Cases 3.61—.95

---

### Case 3.61: OpenAI ChatGPT Italy Ban (2023) —Garante per la Protezione dei Dati Personali

**Date Decided:** 30 March 2023 (provisional ban); 11 August 2023 (adoption of act)

**Court:** Garante per la Protezione dei Dati Personali (Italian Data Protection Authority)

**Facts:** On 30 March 2023, the Italian Garante issued a provisional measure blocking OpenAI from processing Italian users' data through ChatGPT, becoming the first DPA worldwide to do so. The authority cited lack of a legal basis for mass data collection, absence of an age verification mechanism exposing minors to inappropriate responses, and failure to provide users with an information notice as required by Article 13 GDPR. OpenAI temporarily restricted access in Italy and implemented corrective measures, including adding an age gate, privacy notices, and an EU-wide opt-out form for data used in model training. On 11 August 2023, the Garante lifted the ban after finding the remedies satisfactory.

**Issue:** Whether the processing of personal data for training large language models (LLMs) could be justified under GDPR without an adequate legal basis, and whether the data subject rights of children were adequately protected.

**Holding:** The Garante held that OpenAI's processing lacked a lawful basis and violated transparency obligations. The provisional ban was lifted upon compliance with remedial measures including an opt-out mechanism for training data and age verification for Italian users.
**Significance:** First GDPR enforcement action against a generative AI service, setting a template for DPAs worldwide; the EDPB subsequently created a dedicated task force on ChatGPT.
Established that LLM training on publicly scraped data requires a clear legal basis, and that the AI Act's later transparency obligations codified principles first enforced here.
Demonstrated the enforcement leverage of provisional measures under Article 58(2)(f) GDPR to compel rapid compliance from global AI companies.

---

### Case 3.62: OpenAI ChatGPT Poland Complaint (2024) —Urzd Ochrony Danych Osobowych

**Date Decided:** 2024 (investigation initiated)

**Court:** Urzd Ochrony Danych Osobowych (UODO, Polish DPA)

**Facts:** In 2024, the Polish DPA opened an investigation into ChatGPT following complaints that OpenAI could not correct inaccurate personal information generated by the model about identifiable individuals. Polish citizens reported that ChatGPT attributed false professional qualifications and criminal records to them, and that OpenAI's support channels were unable or unwilling to correct these hallucinations. The UODO examined whether Article 16 GDPR (right to rectification) applied to AI-generated outputs and whether the processing of training data met lawful basis requirements.

**Issue:** Whether the right to rectification under Article 16 GDPR extends to false personal data generated by an AI model's outputs, and whether the lack of a meaningful correction mechanism constitutes a GDPR violation.

**Holding:** Investigation ongoing as of 2024. The UODO signaled that AI-generated personal data falls within the scope of GDPR and that data controllers must provide effective mechanisms for rectification, potentially requiring modification of model outputs rather than mere deletion of training data.
**Significance:** Raises the novel question of whether hallucinated personal data triggers GDPR's accuracy principle (Article 5(1)(d)) and rectification rights —a question the AI Act does not directly resolve.
May force AI developers to build retrieval-augmented or correction-layer architectures as a compliance measure, not merely a product feature.
Part of a coordinated European DPA approach to generative AI, complementing actions by Italy, Spain, and the EDPB task force.

---

### Case 3.63: OpenAI ChatGPT Spain Investigation (2024) —Agencia Espaola de Proteccin de Datos

**Date Decided:** 2024 (investigation ongoing)

**Court:** Agencia Espaola de Proteccin de Datos (AEPD, Spanish DPA)

**Facts:** In early 2024, the AEPD launched an investigation into OpenAI's ChatGPT, joining the EDPB's coordinated enforcement task force. The probe focused on whether OpenAI had a valid legal basis for processing Spanish users' data to train its models, whether privacy notices were adequate, and whether the right to erasure could be meaningfully exercised against an LLM. The AEPD also examined OpenAI's data retention policies and the effectiveness of the opt-out mechanism introduced in response to the Italian Garante's order.

**Issue:** Whether OpenAI's reliance on legitimate interest as a legal basis for LLM training data collection is valid under Spanish law, and whether erasure requests can be practically fulfilled for data embedded in trained model weights.

**Holding:** Investigation pending. Preliminary findings suggested concerns about the adequacy of the legal basis and the feasibility of erasure from deployed models.
**Significance:** Highlights the tension between GDPR's right to erasure (Article 17) and the technical impossibility of surgically removing specific data from neural network weights —a structural challenge that may require regulatory innovation.
Reinforces the EDPB's strategy of coordinated pan-EU enforcement against major AI platforms rather than fragmented national actions.
May influence how the EU AI Act's general-purpose AI (GPAI) obligations interact with existing GDPR requirements.

---

### Case 3.64: Google Bard/DeepMind UK ICO (2024) —Information Commissioner's Office

**Date Decided:** 2024

**Court:** Information Commissioner's Office (ICO, UK)

**Facts:** In 2024, the UK ICO issued formal guidance and enforcement signals regarding Google's Bard chatbot and DeepMind's health AI products, focusing on data protection impact assessments (DPIAs), lawful basis for training data, and the use of NHS patient data in DeepMind's medical AI projects. The investigation followed longstanding concerns about DeepMind's Royal Free Hospital data-sharing arrangement and extended to whether Google's generative AI products conducted adequate privacy assessments before deployment to UK users. The ICO demanded evidence of completed DPIAs and clarity on how personal data flowed into model training pipelines.

**Issue:** Whether Google and DeepMind conducted adequate DPIAs before deploying AI systems processing personal data of UK residents, and whether their data processing practices complied with the UK GDPR post-Brexit.

**Holding:** The ICO issued compliance notices and guidance, requiring Google to complete and publish DPIAs for Bard and related AI services, and to demonstrate that lawful basis documentation was in order. No monetary penalty was imposed at this stage.
**Significance:** First post-Brexit UK enforcement action specifically targeting generative AI data practices, showing the ICO's willingness to regulate AI independently of the EU.
Signals that the UK's approach to AI regulation will rely heavily on existing data protection law augmented by sector-specific guidance, rather than a comprehensive AI statute.
The DeepMind-NHS dimension raised unresolved questions about secondary use of medical data in AI development and the adequacy of consent as a legal basis.

---

### Case 3.65: Meta LLaMA Data Scraping Litigation (2023) —Various Courts

**Date Decided:** 2023 (ongoing)

**Court:** U.S. District Court for the Northern District of California

**Facts:** In 2023, Meta released its LLaMA large language model, trained on datasets compiled from publicly scraped web content including copyrighted texts, books, and academic papers. Multiple plaintiffs, including authors, publishers, and rights-holders, filed suit alleging that Meta's use of their copyrighted works for AI training constituted copyright infringement. Plaintiffs argued that the systematic scraping, compilation, and use of their works without permission exceeded fair use. Meta defended the practice under the fair use doctrine, arguing that the model's use of training data was transformative and did not reproduce expressive content in outputs.

**Issue:** Whether the mass ingestion of copyrighted works to train an AI model constitutes fair use or unauthorized reproduction under U.S. copyright law.

**Holding:** Litigation ongoing as of 2024. Courts have not yet issued final rulings, but early motions on standing and class certification have advanced.
**Significance:** Central to defining the legal boundaries of AI training on copyrighted material, alongside parallel cases against OpenAI and Stability AI.
The open-source release of LLaMA weights added a novel dimension: once model weights are publicly distributed, downstream infringement questions become exponentially complex.
Outcome will significantly shape whether AI companies can rely on fair use as a blanket defense for training data practices.

---

### Case 3.66: Stability AI Class Action by Artists (2023) —N.D. California

**Date Decided:** 2023 (ongoing)

**Court:** U.S. District Court for the Northern District of California

**Facts:** In January 2023, a class of visual artists filed a putative class action against Stability AI, DeviantArt, and Midjourney, alleging that the defendants scraped billions of copyrighted images from the internet —including the artists' works —to train image generation models (Stable Diffusion) without consent, credit, or compensation. The complaint alleged direct copyright infringement, vicarious infringement, and violation of the Digital Millennium Copyright Act (DMCA) by removing copyright management information. The plaintiffs sought injunctive relief, statutory damages, and disgorgement of profits. The case survived a motion to dismiss in part, with the court allowing the direct infringement claims against Stability AI to proceed while dismissing claims against DeviantArt and Midjourney on narrower grounds.

**Issue:** Whether AI training on copyrighted images to produce a generative model constitutes direct copyright infringement, and whether AI-generated outputs that mimic an artist's style violate their rights.

**Holding:** Partial survival of claims. The court allowed direct infringement claims against Stability AI to proceed but narrowed the class definition and dismissed some ancillary claims. The case remained in discovery as of 2024.
**Significance:** First major class action challenging AI image generation on copyright grounds, establishing the legal framework for subsequent visual art AI cases.
The court's distinction between scraping for training (potentially infringing) and generating outputs (separate analysis) created a bifurcated legal framework that other courts have followed.
Catalyzed the "opt-out" movement and the development of AI-specific licensing platforms such as Adobe Firefly's trained-only-on-licensed-content model.

---

### Case 3.67: GitHub Copilot Copyright Litigation (2022-2024) —Doe v. GitHub

**Date Decided:** 2022–2024 (ongoing)

**Court:** U.S. District Court for the Northern District of California

**Facts:** In November 2022, a group of open-source developers filed a class-action lawsuit against GitHub, Microsoft, and OpenAI over the GitHub Copilot AI coding assistant. The plaintiffs alleged that Copilot was trained on vast repositories of publicly available open-source code —including their own —and that it reproduced substantial portions of licensed code in its suggestions without attribution, violating license terms, copyright law, and the DMCA. The defendants moved to dismiss, arguing that Copilot's outputs were generated by statistical pattern matching and not direct reproduction. The court denied significant portions of the motion to dismiss in 2024, allowing the case to proceed to discovery.

**Issue:** Whether an AI coding assistant that generates code suggestions derived from open-source training data infringes the original authors' copyright and violates open-source license terms when it fails to provide attribution.

**Holding:** Claims allowed to proceed on copyright infringement, DMCA violations, and breach of contract theories. The court found the plaintiffs' allegations sufficiently pleaded to survive dismissal.
**Significance:** First case to examine how AI-generated code interacts with open-source license obligations, with implications for the entire software development ecosystem.
Raised the question of whether "statistical suggestion" of licensed code constitutes reproduction —a novel interpretation challenge for courts.
Prompted industry responses including GitHub's attribution features and license compliance layers, showing that litigation can drive product-level compliance mechanisms.

---

### Case 3.68: Samsung ChatGPT Trade Secret Leak (2023) —Internal Investigation

**Date Decided:** 2023

**Court:** No court proceeding; internal corporate investigation with regulatory oversight

**Facts:** In May 2023, Samsung Electronics discovered that employees at its semiconductor division had input confidential source code and internal meeting notes into ChatGPT to seek debugging assistance and summarization. The incidents involved sensitive semiconductor equipment measurement data and proprietary code. Samsung had no formal policy restricting ChatGPT use at the time. Following discovery, Samsung launched an internal investigation, temporarily restricted ChatGPT access on company devices, and began developing an in-house AI solution. The episode prompted broader discussions about whether inputting trade secrets into third-party AI services constitutes a data breach under applicable laws.

**Issue:** Whether employee use of external AI chatbots to process trade secrets constitutes a reportable data breach or securities disclosure obligation, and what duty of care employers owe to protect proprietary information from AI platform ingestion.

**Holding:** Samsung imposed an internal ban on generative AI use for sensitive tasks and invested in proprietary AI tools. No regulatory enforcement was initiated, but the incident influenced enterprise AI policy globally.
**Significance:** Became the canonical example of "shadow AI" risk in corporate environments, accelerating adoption of enterprise AI governance policies worldwide.
Highlighted the gap between data protection frameworks (which focus on personal data) and trade secret law (which addresses proprietary information) in the AI context.
Prompted multiple companies —including Apple, JPMorgan Chase, and Amazon —to restrict employee use of external AI tools, fundamentally shaping enterprise AI adoption patterns.

---

### Case 3.69: Apple vs DOJ Encryption Dispute (2016) —E.D. California

**Date Decided:** 2016 (resolved without judicial ruling)

**Court:** U.S. District Court for the Eastern District of California

**Facts:** In February 2016, the U.S. Department of Justice obtained a court order under the All Writs Act compelling Apple to assist the FBI in unlocking the iPhone used by one of the San Bernardino shooters. The order required Apple to create a modified version of iOS that would bypass the device's auto-erase security feature and allow unlimited passcode attempts. Apple refused, arguing that the order exceeded statutory authority, violated the First Amendment (compelled speech), and would set a dangerous precedent undermining cybersecurity for all users. The case attracted amicus briefs from major technology companies, civil liberties organizations, and law enforcement agencies. The DOJ withdrew its motion in March 2016 after a third-party vendor successfully accessed the device.

**Issue:** Whether the government can compel a technology company to create new software to circumvent its own security features under the All Writs Act, and whether such an order violates the company's First Amendment rights.

**Holding:** The case was resolved without a judicial ruling after the DOJ withdrew its request. The legal questions remained unresolved.
**Significance:** Though predating the generative AI era, this case established the foundational legal and policy framework for government-compelled access to encrypted systems —a debate directly relevant to AI model access, safety red-teaming, and government backdoor demands.
Demonstrated the "security dilemma" that recurs in AI governance: compelling access for law enforcement may weaken security for all users.
The unresolved legal questions continue to influence policy debates around AI safety, model access, and encryption, particularly as governments seek access to AI systems for content moderation and law enforcement purposes.

---

### Case 3.70: EU ePrivacy Cookie Consent Trends (2023-2024) —Multiple DPAs

**Date Decided:** 2023–2024

**Court:** Various EU Data Protection Authorities coordinated through the EDPB

**Facts:** Between 2023 and 2024, EU data protection authorities intensified enforcement against websites and platforms that used non-compliant cookie consent mechanisms. The trend focused on deceptive design patterns including pre-ticked consent boxes, "accept all" buttons made visually dominant while "reject" options were hidden, cookie walls that forced users to consent to tracking in exchange for content access, and granular consent banners that were deliberately confusing. The EDPB updated its guidelines on cookie consent, clarifying that consent must be freely given, specific, informed, and unambiguous, and that cookie walls (pay-or-consent models) generally do not constitute valid consent. Multiple national DPAs issued fines and corrective orders.

**Issue:** Whether common cookie consent interface designs violate the ePrivacy Directive and GDPR consent requirements, particularly when they use dark patterns to nudge users toward accepting tracking.

**Holding:** Widespread enforcement actions with fines ranging from thousands to millions of euros. DPAs ordered redesign of consent interfaces to provide genuinely equal prominence for accept and reject options.
**Significance:** Marked a shift from theory to practice in dark pattern enforcement, establishing concrete design standards that affect virtually every website serving EU users.
The convergence of ePrivacy and GDPR enforcement created de facto pan-European standards for consent UX, influencing the Digital Markets Act's consent requirements.
Cookie wall decisions (particularly the CNIL and EDPB positions) effectively established that "consent or pay" models are presumptively invalid, with major implications for ad-supported business models.

---

### Case 3.71: France CNIL Cookie Enforcement (2020-2024) —CNIL

**Date Decided:** 2020–2024

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL, French DPA)

**Facts:** The CNIL conducted a multi-year enforcement campaign against non-compliant cookie and tracking consent mechanisms on French websites and mobile applications. Key actions included fining Google and Amazon €0 million and €5 million respectively in December 2021 for making ad personalization consent refusal more difficult than acceptance. The CNIL also targeted cookie walls on news sites, mandatory cookie consent for accessing content, and insufficient information provided to users about tracking purposes. Enforcement extended to mobile app tracking in 2023-2024, with attention to ATT (App Tracking Transparency) circumvention and fingerprinting techniques.

**Issue:** Whether tracker mechanisms and cookie consent interfaces used by major platforms comply with the ePrivacy Directive's informed consent requirement and GDPR's standards for freely given consent.

**Holding:** CNIL imposed tens of millions in fines on Google, Amazon, and numerous smaller publishers, requiring redesign of consent flows to provide equal treatment of accept/reject options and eliminate manipulative design.
**Significance:** CNIL's enforcement against Google and Amazon set binding precedents for how "equal prominence" and "freely given" should be implemented in consent design —standards later codified in the Digital Markets Act.
The multi-year campaign demonstrated the effectiveness of sustained regulatory pressure in achieving industry-wide behavioral change.
Influenced the broader EU approach to regulating online advertising transparency, contributing to the Digital Services Act's advertising transparency requirements.

---

### Case 3.72: Netherlands ACM Dark Pattern Enforcement (2024) —Autoriteit Consument & Markt

**Date Decided:** 2024

**Court:** Autoriteit Consument & Markt (ACM, Netherlands Authority for Consumers and Markets)

**Facts:** In 2024, the Dutch consumer regulator ACM intensified enforcement against dark patterns —deceptive interface designs that manipulate consumer choices —across e-commerce platforms, subscription services, and social media. The ACM published specific guidance identifying 12 categories of dark patterns commonly used in the Netherlands, including fake countdown timers, hidden subscription terms, confusing cancellation processes, and social proof manipulation. The regulator conducted audits of major Dutch and international platforms and issued binding instructions requiring redesign of offending interfaces. The enforcement operated under both Dutch consumer protection law and the EU's Unfair Commercial Practices Directive.

**Issue:** Whether specific interface design techniques used by online platforms constitute unfair commercial practices or misleading omissions under EU and Dutch consumer protection law.

**Holding:** ACM issued binding instructions and fines to multiple platforms, requiring removal of dark patterns and implementation of transparent, user-friendly interfaces. Specific enforcement actions targeted subscription traps and fake urgency indicators.
**Significance:** One of the most detailed regulatory categorizations of dark patterns in Europe, providing a practical taxonomy that other DPAs and regulators adopted.
Demonstrated that consumer protection authorities (not just data protection authorities) have significant enforcement power over AI-driven interface manipulation and algorithmic nudging.
Preceded and informed the EU AI Act's provisions on AI systems deploying subliminal techniques or exploiting vulnerabilities, particularly Article 5's prohibition on AI practices that manipulate behavior.

---

### Case 3.73: Norway Datatilsynet Grindr €M Fine (2023) —Datatilsynet

**Date Decided:** 2023

**Court:** Datatilsynet (Norwegian Data Protection Authority) / EFTA Surveillance Authority

**Facts:** In 2023, the Norwegian Datatilsynet imposed an administrative fine of € million (reduced from an initial €00 million under the EEA cooperation mechanism) on Grindr LLC and several advertising technology companies for illegal sharing of user data. The investigation found that Grindr transmitted users' precise location data, device identifiers, and app usage information to numerous third-party advertisers without a valid legal basis. The data included sensitive information revealing users' sexual orientation, making it special category data under GDPR Article 9. Grindr relied on consent as its legal basis, but the Datatilsynet found that consent was not freely given due to the "take it or leave it" nature of the app.

**Issue:** Whether consent for sharing special category data with advertisers can be considered "freely given" when the alternative is not using the service, and whether the controller's legitimate interest was sufficient as an alternative legal basis.

**Holding:** The Datatilsynet found Grindr's consent mechanism invalid and the data sharing unlawful. The fine of € million was issued after EEA cooperation adjustments. Grindr was ordered to cease the illegal data sharing.
**Significance:** Established that consent obtained through "take it or leave it" mechanisms is invalid under GDPR, even when the data subject is informed —a principle with wide application to dating apps, social media, and any platform where user data is monetized.
One of the largest GDPR fines in the EEA, demonstrating that smaller national DPAs can impose significant penalties on major global platforms.
Highlighted the role of programmatic advertising as a vector for sensitive data exposure, influencing subsequent scrutiny of ad-tech data flows across Europe.

---

### Case 3.74: Denmark Datatilsynet Credit Scoring (2024) —Datatilsynet

**Date Decided:** 2024

**Court:** Datatilsynet (Danish Data Protection Authority)

**Facts:** In 2024, the Danish DPA investigated several credit scoring companies that used automated algorithms to assess consumers' creditworthiness based on extensive personal data processing. The investigation found that the algorithms relied on opaque criteria that could not be adequately explained to data subjects, denied applicants the right to human review of automated decisions, and processed data beyond what was necessary for the stated purpose. Several companies used social media activity and behavioral data as inputs to credit models without clear disclosure. The Datatilsynet found violations of Articles 13, 14, 15, and 22 GDPR.

**Issue:** Whether automated credit scoring algorithms that use opaque criteria and deny human review violate the GDPR's right to explanation and right not to be subject to solely automated decisions.

**Holding:** The Datatilsynet ordered the companies to ensure meaningful human oversight in credit decisions, provide plain-language explanations of scoring criteria, and limit data inputs to objectively necessary information. Compliance deadlines were set.
**Significance:** Reinforced Article 22 GDPR as a meaningful constraint on automated decision-making in high-stakes financial contexts, pushing back against industry arguments that AI-driven credit scoring is too complex to explain.
The requirement for "plain-language explanations" established a practical standard that goes beyond technical model documentation, directly benefiting consumer understanding.
Part of a broader Nordic DPA trend toward scrutinizing algorithmic systems in financial services, complementing Finland's AI register and Norway's ad-tech enforcement.

---

### Case 3.75: Sweden IMY Facial Recognition in Schools (2023) —Integritetsskyddsmyndigheten

**Date Decided:** 2023

**Court:** Integritetsskyddsmyndigheten (IMY, Swedish Authority for Privacy Protection)

**Facts:** In 2023, the Swedish IMY investigated a municipality that deployed facial recognition technology for attendance tracking in a high school. The system used cameras to scan students' faces and match them against a database to record attendance automatically. The municipality argued that the system was implemented with parental consent and improved administrative efficiency. The IMY found that the processing involved biometric data (special category data under Article 9 GDPR), that consent from minors in an educational context could not be considered freely given due to power imbalances, and that the municipality had not conducted an adequate data protection impact assessment as required by Article 35 GDPR.

**Issue:** Whether facial recognition for school attendance tracking constitutes a proportionate use of biometric data, and whether parental consent in an educational context is valid under GDPR.

**Holding:** The IMY found the processing unlawful and ordered the municipality to cease the facial recognition system. The authority also issued a fine for failure to conduct a DPIA.
**Significance:** Confirmed that consent is an inadequate legal basis for biometric processing in educational settings where power imbalances make genuine choice impossible.
Established that even "benign" uses of facial recognition (attendance tracking) are subject to full GDPR scrutiny, pushing educational institutions toward less intrusive alternatives.
Reinforced the mandatory nature of DPIAs for biometric surveillance, with enforcement consequences for non-compliance.

---

### Case 3.76: Finland Office Surveillance GDPR Enforcement (2024) —Office of the Data Protection Ombudsman

**Date Decided:** 2024

**Court:** Tietosuojavaltuutettu (Finnish Data Protection Ombudsman)

**Facts:** In 2024, the Finnish Data Protection Ombudsman investigated several employers that used AI-powered surveillance systems to monitor employees in office environments. The systems included keystroke logging, screen capture, facial analysis for fatigue detection, and AI-driven productivity scoring. Employers argued that monitoring was necessary for information security and operational efficiency. The Ombudsman found that the surveillance was disproportionate, lacked adequate legal basis, violated employees' expectation of privacy in the workplace, and that the automated productivity scoring constituted solely automated decision-making without human oversight. The investigation also found that employee information notices were inadequate.

**Issue:** Whether AI-powered workplace surveillance systems comply with GDPR proportionality requirements and whether automated productivity scoring triggers Article 22's protections against solely automated decisions.

**Holding:** The Ombudsman ordered the companies to cease or significantly curtail surveillance practices, implement human review of any AI-driven assessments, and provide comprehensive information to employees about monitoring scope and purposes.
**Significance:** Established clear boundaries for AI-driven workplace surveillance in Finland, balancing employer interests with employee privacy rights.
The finding that productivity scoring constituted "solely automated decision-making" extended Article 22's scope to internal employment contexts, not just customer-facing decisions.
Contributed to the emerging European consensus on AI workplace regulation that the EU AI Act's employment provisions later codified.

---

### Case 3.77: Portugal CNPD Health Data Processing (2023) —Comisso Nacional de Proteo de Dados

**Date Decided:** 2023

**Court:** Comisso Nacional de Proteo de Dados (CNPD, Portuguese DPA)

**Facts:** In 2023, the Portuguese CNPD investigated health technology companies and public health institutions that processed sensitive health data through AI-powered diagnostic and analytics systems. The investigation revealed that some systems transmitted health data to cloud-based AI services without adequate safeguards, shared data with third parties for research purposes without proper legal basis, and failed to pseudonymize data effectively before algorithmic processing. The CNPD also found deficiencies in DPIAs and breach notification procedures. Several cases involved COVID-19 health data being retained beyond the pandemic period without justification.

**Issue:** Whether the processing of sensitive health data by AI systems met GDPR's heightened requirements for special category data, including adequacy of safeguards for cloud-based processing and lawful basis for research use.

**Holding:** The CNPD issued enforcement orders requiring implementation of technical and organizational measures including data pseudonymization, improved DPIA procedures, and restrictions on third-party data sharing. Fines were imposed in several cases.
**Significance:** Clarified that GDPR's special category data requirements apply with full force to AI-driven health analytics, rejecting arguments that AI processing is inherently more secure.
The finding on inadequate pseudonymization before algorithmic processing highlighted that anonymization claims in AI contexts require rigorous technical validation.
Reinforced that emergency health measures do not create permanent lawful bases for data retention, even when AI systems are trained on pandemic-period data.

---

### Case 3.78: Greece DPA Smart Meter Investigation (2023) —Hellenic DPA

**Date Decided:** 2023

**Court:** Hellenic Data Protection Authority (HDPA)

**Facts:** In 2023, the Greek DPA investigated the deployment of smart electricity meters by the Public Power Corporation (PPC), which collected granular consumption data at intervals as short as 15 minutes. The HDPA examined whether the high-frequency data collection could reveal sensitive information about residents' daily lives (e.g., medical device use, occupancy patterns, religious observance) without adequate safeguards. The authority found that the DPIA was insufficient, that data retention periods were excessive, that consumers were not adequately informed about inferences that could be drawn from their consumption patterns, and that the smart meter system had not been designed with data protection by design and by default principles.

**Issue:** Whether the granularity of smart meter data collection constitutes an intrusion into private life, and whether the operator fulfilled its GDPR obligations regarding transparency, data minimization, and DPIA.

**Holding:** The HDPA ordered PPC to reduce data collection frequency to the minimum necessary, shorten retention periods, enhance consumer information notices, and implement privacy-by-design measures including differential privacy techniques for aggregated analytics.
**Significance:** Demonstrated that "smart infrastructure" data collection, even for utility purposes, is subject to rigorous GDPR analysis when the data can reveal intimate details of private life.
The recommendation for differential privacy in smart meter analytics set a technical standard that other European DPAs have referenced.
Established that data controllers using AI or algorithmic analytics on infrastructure data must proactively assess and mitigate inference risks, not merely address direct data collection.

---

### Case 3.79: Slovenia DPA Surveillance Camera Enforcement (2023) —Informacijski pooblaenec

**Date Decided:** 2023

**Court:** Informacijski pooblaenec (Slovenian Information Commissioner)

**Facts:** In 2023, the Slovenian Information Commissioner investigated the use of extensive video surveillance systems by several municipalities and private entities that employed AI-powered analytics to identify individuals, detect behavioral patterns, and track movements across public spaces. The investigation found that many surveillance systems operated without adequate legal basis, failed to conduct DPIAs, retained footage for excessive periods, and used AI-powered facial analysis or person re-identification without explicit authorization. Some municipalities deployed surveillance systems under vague "public safety" mandates without specifying concrete purposes or demonstrating necessity.

**Issue:** Whether AI-enhanced public surveillance systems comply with GDPR requirements for lawful basis, proportionality, data minimization, and DPIA when deployed for broad public safety purposes.

**Holding:** The Commissioner ordered the cessation of unauthorized AI-powered surveillance analytics, required DPIA completion, mandated data retention reduction, and instructed some municipalities to restrict camera coverage to specific, documented security needs.
**Significance:** Reinforced that AI-enhanced video surveillance requires a higher standard of justification than conventional CCTV, as the analytics capability fundamentally changes the nature and intrusiveness of processing.
The Commissioner's requirement for specific, documented purposes rejected broad "public safety" justifications as insufficient under GDPR proportionality analysis.
Contributed to the development of European standards for smart city surveillance that the EU AI Act's high-risk classification of remote biometric identification later addressed.

---

### Case 3.80: Czech DPA Bank Data Processing (2023) —ad pro ochranu osobnch daj

**Date Decided:** 2023

**Court:** ad pro ochranu osobnch daj (OO, Czech Office for Personal Data Protection)

**Facts:** In 2023, the Czech DPA investigated several major banks that used AI algorithms for customer profiling, risk assessment, and automated marketing segmentation. The investigation found that banks processed extensive personal data including transaction history, location data, and communication metadata to build comprehensive customer profiles. Several banks shared these AI-generated profiles with third parties (insurance companies, investment firms) without adequate consent, and customers were unable to access or understand the profiles used to make decisions about them. The DPA also found that automated decision-making in loan approval processes lacked meaningful human review.

**Issue:** Whether AI-driven customer profiling by financial institutions complies with GDPR transparency, purpose limitation, and automated decision-making requirements, and whether sharing AI-generated profiles constitutes further processing requiring separate legal basis.

**Holding:** The OO ordered corrective measures including enhanced transparency about profiling activities, implementation of opt-out mechanisms for profile-based marketing, human review of automated financial decisions, and restrictions on profile sharing with third parties.
**Significance:** Clarified that AI-generated profiles derived from transaction data constitute personal data processing subject to full GDPR obligations, including purpose limitation on secondary sharing.
The decision on "further processing" of AI-generated profiles established that creating and sharing algorithmic inferences requires its own legal basis, not just the basis for the underlying data collection.
Reinforced the Czech DPA's focus on financial sector AI, contributing to a coordinated approach among central European DPAs.

---

### Case 3.81: Latvia DPA CCTV Enforcement (2024) —Datu valsts inspekcija

**Date Decided:** 2024

**Court:** Datu valsts inspekcija (DVI, Latvian State Data Inspection)

**Facts:** In 2024, the Latvian DVI conducted a nationwide audit of CCTV surveillance systems, focusing on municipalities and private operators that had upgraded to AI-powered video analytics. The audit found widespread non-compliance including failure to conduct DPIAs, lack of clear retention policies (some systems retained footage indefinitely), insufficient signage informing individuals of surveillance, and use of AI analytics (motion tracking, facial detection, vehicle recognition) without proper legal basis. Several municipalities had deployed AI-powered surveillance during COVID-19 for social distancing enforcement and retained the enhanced systems afterward without reassessing legal basis.

**Issue:** Whether AI-enhanced CCTV systems deployed during the pandemic retained lawful basis after emergency measures expired, and whether the AI analytics capabilities triggered additional GDPR obligations.

**Holding:** The DVI ordered nationwide remediation, requiring DPIAs for all AI-enhanced surveillance systems, implementation of data retention limits (maximum 30 days for standard surveillance), prominent signage, and discontinuation of AI analytics features without explicit legal authorization.
**Significance:** Demonstrated the "mission creep" risk of surveillance technology deployed during emergencies, establishing that pandemic-era legal justifications do not automatically persist.
The DVI's comprehensive national audit approach provided a model for systematic surveillance oversight that other small-state DPAs could replicate.
Reinforced that upgrading existing CCTV with AI analytics fundamentally changes the legal characterization of the processing activity under GDPR.

---

### Case 3.82: Estonia DPA School Data Protection (2024) —Andme Inspector

**Date Decided:** 2024

**Court:** Andmekaitse Inspektsioon (AKI, Estonian Data Protection Inspectorate)

**Facts:** In 2024, the Estonian Data Protection Inspectorate investigated the use of educational technology platforms and AI-driven analytics in Estonian schools. Estonia, known for its advanced digital governance (e-Governance Academy, X-Road), deployed AI systems to track student engagement, predict academic outcomes, and allocate educational resources. The AKI found that while the platforms had strong technical security, they lacked adequate transparency about how AI predictions were generated, failed to provide students and parents with meaningful access to their algorithmic profiles, and processed special category data (learning disabilities, behavioral assessments) without explicit consent or adequate safeguards. The investigation also examined data flows between school platforms and the national e-government ecosystem.

**Issue:** Whether AI-driven educational analytics in a digitally advanced governance system meets GDPR requirements for transparency, access rights, and special category data processing, particularly in the context of minors.

**Holding:** The AKI ordered enhanced transparency measures, implementation of age-appropriate privacy notices, restrictions on predictive analytics for minors without parental involvement, and strengthened safeguards for special category educational data.
**Significance:** Showed that even highly digitized governance systems with strong technical infrastructure can fail GDPR compliance on transparency and data subject rights when AI is introduced.
The focus on minors' rights in educational AI established that age-appropriate design must be a fundamental feature of educational technology, not an afterthought.
Highlighted the unique challenges of AI integration in e-governance ecosystems where data flows between systems create complex processing chains.

---

### Case 3.83: Lithuania DPA Workplace Monitoring (2023) —Valstybin duomen apsaugos inspekcija

**Date Decided:** 2023

**Court:** Valstybin duomen apsaugos inspekcija (VDI, Lithuanian State Data Protection Inspectorate)

**Facts:** In 2023, the Lithuanian DPA investigated several employers that used AI-powered employee monitoring systems including computer usage tracking, email content analysis, keystroke logging, and AI-driven performance prediction models. The investigation found that employees were not adequately informed about the scope of monitoring, that monitoring extended beyond working hours and devices (tracking on personal phones with company apps installed), and that AI-generated performance predictions influenced disciplinary actions without human review. Some employers used emotion detection AI to analyze employee communications for "engagement" and "satisfaction" levels.

**Issue:** Whether AI-powered workplace monitoring that extends to personal devices and uses emotion detection technology complies with GDPR proportionality and the Lithuanian Labor Code's requirements for employee privacy.

**Holding:** The VDI ordered cessation of monitoring on personal devices, prohibition of emotion detection without explicit consent, implementation of human review for all AI-driven employment decisions, and comprehensive transparency notices to employees.
**Significance:** One of the earliest European DPA actions specifically targeting emotion detection AI in the workplace, predating the EU AI Act's explicit attention to emotion recognition systems.
Established that employer monitoring authority does not extend to personal devices, even when company applications are installed, creating a clear boundary for BYOD (bring your own device) policies.
Reinforced that AI-generated insights used in employment decisions require the same level of explanation and human oversight as formal performance reviews.

---

### Case 3.84: Croatia DPA Biometric Data Enforcement (2024) —Azop

**Date Decided:** 2024

**Court:** Agencija za zatitu osobnih podataka (AZOP, Croatian Personal Data Protection Agency)

**Facts:** In 2024, the Croatian AZOP investigated multiple entities deploying biometric recognition systems including facial recognition for access control in commercial buildings, fingerprint scanning for time and attendance tracking in workplaces, and voice biometrics for customer authentication in banking. The investigation found that most deployments lacked adequate DPIAs, failed to demonstrate that biometric processing was necessary and proportionate (alternatives such as card-based access or PIN authentication were available), and stored biometric templates without adequate encryption or breach preparedness. Some systems transmitted biometric data to cloud services outside the EU without adequate transfer safeguards.

**Issue:** Whether the deployment of biometric recognition systems for commercial and employment purposes meets GDPR's necessity and proportionality requirements for special category data processing.

**Holding:** AZOP ordered several entities to cease biometric processing where less intrusive alternatives were available, conduct DPIAs, implement adequate security measures for biometric template storage, and ensure lawful international data transfers.
**Significance:** Established that biometric authentication must be a method of last resort, not a default choice, reinforcing GDPR's proportionality principle in the biometric context.
The focus on cloud-based biometric processing highlighted the compound risk of international data transfers combined with special category data.
Contributed to the Croatian DPA's growing body of biometric enforcement that positions Croatia as an active AI-regulating jurisdiction within the EU.

---

### Case 3.85: Romania ANSPDCP GDPR Enforcement (2023-2024) —ANSPDCP

**Date Decided:** 2023–2024

**Court:** Autoritatea Naional de Supraveghere a Prelucrrii Datelor cu Caracter Personal (ANSPDCP, Romanian DPA)

**Facts:** Between 2023 and 2024, the Romanian ANSPDCP conducted multiple enforcement actions covering a broad range of GDPR violations related to automated processing and AI. Key cases included fining a major bank for inadequate customer profiling algorithms that lacked transparency, penalizing a retailer for using AI-powered price discrimination that targeted vulnerable consumers, and sanctioning a public institution for deploying facial recognition without legal basis. The ANSPDCP also investigated AI-driven chatbots used by public authorities for citizen services, finding inadequate disclosure that users were interacting with automated systems. Cumulative fines during this period exceeded € million.

**Issue:** Whether various AI-driven processing activities —including customer profiling, algorithmic pricing, public surveillance, and government chatbots —complied with GDPR transparency, lawful basis, and automated decision-making requirements.

**Holding:** Multiple fines and corrective orders across sectors. The ANSPDCP required transparency improvements for all AI chatbots, proportionality assessments for surveillance systems, and human review mechanisms for automated financial decisions.
**Significance:** Demonstrated that smaller EU DPAs can conduct effective, multi-sector AI enforcement when provided adequate resources and political support.
The price discrimination case was among the first in Europe to address AI-driven algorithmic pricing as a GDPR issue, connecting data protection to consumer protection.
The chatbot transparency requirement established that users have a right to know when they are interacting with an AI system —a principle later codified in the EU AI Act's transparency obligations.

---

### Case 3.86: Bulgaria CPDP Data Breach Enforcement (2023) —Commission for Personal Data Protection

**Date Decided:** 2023

**Court:** Commission for Personal Data Protection (CPDP, Bulgaria)

**Facts:** In 2023, the Bulgarian CPDP investigated several significant data breaches involving AI-driven systems, including a breach at a major telecom operator whose AI-based customer analytics platform exposed personal data of approximately 3 million subscribers, and a healthcare data breach where an AI diagnostic platform was compromised, exposing patient records. The CPDP found that both organizations had inadequate security measures for their AI systems, failed to conduct risk assessments specific to machine learning vulnerabilities (model inversion, training data extraction attacks), and had deficient breach detection and notification procedures. Notification to affected individuals was delayed in both cases.

**Issue:** Whether organizations deploying AI systems fulfilled their GDPR security obligations (Article 32), particularly regarding AI-specific vulnerabilities, and whether breach notification timelines (Article 33) were met.

**Holding:** The CPDP imposed fines totaling several hundred thousand leva, ordered security remediation including AI-specific penetration testing, and required improved breach notification procedures. Both organizations were placed under enhanced supervision.
**Significance:** Among the first European enforcement actions to specifically address AI-specific security vulnerabilities as part of GDPR Article 32 compliance, rather than treating AI as just another IT system.
The healthcare breach highlighted the compounding risk of AI in sensitive sectors, where the model itself can become an attack vector for accessing training data.
Demonstrated Bulgaria's commitment to robust GDPR enforcement despite its smaller DPA resources, contributing to the pan-European enforcement ecosystem.

---

### Case 3.87: Poland UODO Profiling Enforcement (2023-2024) —Urzd Ochrony Danych Osobowych

**Date Decided:** 2023–2024

**Court:** Urzd Ochrony Danych Osobowych (UODO, Polish DPA)

**Facts:** In 2023-2024, the Polish UODO conducted a series of investigations into automated profiling by both public and private entities. Key cases included profiling by insurance companies using AI to set premiums based on behavioral data, public institutions using AI-based risk scoring for social benefit eligibility determination, and online platforms using algorithmic profiling for content personalization that created "filter bubbles." The UODO found that most profiling operations lacked adequate transparency (individuals were unaware they were being profiled or could not access their profiles), failed to provide meaningful human review of automated decisions, and used data beyond the scope of original collection purposes. The social benefits case was particularly sensitive, as automated denial of benefits had significant human consequences.

**Issue:** Whether automated profiling for insurance pricing, social benefit determination, and content personalization complies with GDPR Articles 13, 14, 15 (transparency and access), 22 (automated decision-making), and 5(1)(b) (purpose limitation).

**Holding:** The UODO issued multiple enforcement orders requiring transparency improvements, human review for consequential decisions, and restriction of profiling data inputs. Fines were imposed in the insurance and social benefits cases. The content personalization investigation resulted in recommendations rather than fines.
**Significance:** The social benefits profiling case highlighted the life-altering consequences of automated government decision-making, reinforcing the need for robust human oversight in public-sector AI.
The insurance profiling enforcement established that behavioral data-based pricing requires the same level of transparency as credit scoring under GDPR.
The filter bubble investigation, while resulting in recommendations rather than fines, signaled growing DPA interest in the societal impacts of algorithmic personalization.

---

### Case 3.88: Hungary NAIH Data Retention Enforcement (2023) —Nemzeti Adatvédelmi és Informciszabadsg Hatsg

**Date Decided:** 2023

**Court:** Nemzeti Adatvédelmi és Informciszabadsg Hatsg (NAIH, Hungarian DPA)

**Facts:** In 2023, the Hungarian NAIH investigated data retention practices in the context of AI-driven systems, focusing on telecommunications companies that retained call detail records and metadata far beyond what was necessary for the AI-powered analytics and fraud detection systems they operated. The investigation found that companies retained data for up to 7 years "for AI training purposes" without clear justification, used broad consent clauses that did not meet GDPR's specificity requirement, and processed AI-generated behavioral profiles without adequate safeguards. The NAIH also examined government surveillance data retention, finding that some AI-enhanced monitoring systems retained data indefinitely without periodic review.

**Issue:** Whether retaining personal data for AI training purposes constitutes a valid purpose under GDPR's storage limitation principle (Article 5(1)(e)), and whether consent clauses authorizing indefinite retention for AI development are valid.

**Holding:** The NAIH ordered data retention reductions to the minimum necessary for specified purposes, invalidated overly broad consent clauses, and required periodic legal basis reviews for AI training datasets. Fines were imposed on two telecommunications companies.
**Significance:** Directly challenged the common industry practice of retaining "all available data" for potential AI training, establishing that speculative future use does not satisfy GDPR's storage limitation principle.
The invalidation of broad AI consent clauses reinforced that consent must be specific to defined processing purposes, not open-ended authorization for future AI applications.
Signaled the Hungarian DPA's willingness to enforce GDPR rigorously despite Hungary's broader democratic governance concerns.

---

### Case 3.89: Slovenia AI Act Preparation (2024) —Informacijski pooblaenec

**Date Decided:** 2024

**Court:** Informacijski pooblaenec (Slovenian Information Commissioner)

**Facts:** In 2024, the Slovenian Information Commissioner proactively published comprehensive guidance for Slovenian organizations preparing to comply with the EU AI Act. The guidance covered obligations for high-risk AI systems, GPAI model transparency requirements, and the intersection of AI Act obligations with existing GDPR requirements. The Commissioner also conducted a national survey of AI deployment in Slovenian organizations, finding that most entities were unprepared for AI Act compliance, particularly regarding risk management systems, data governance for training datasets, and transparency obligations. The Commissioner established a voluntary notification system for AI systems deployed in Slovenia to facilitate regulatory oversight.

**Issue:** How Slovenian organizations should prepare for EU AI Act obligations, and what practical steps the DPA can take to facilitate compliance before the regulation's phased implementation.

**Holding:** The Commissioner issued binding guidance interpreting AI Act requirements in the Slovenian context, established a voluntary AI register, and initiated a series of compliance workshops for high-risk sectors (healthcare, employment, law enforcement).
**Significance:** Among the first European DPAs to issue comprehensive national implementation guidance for the AI Act, establishing a model for proactive regulatory preparation.
The voluntary AI register created a practical tool for mapping AI deployment across the economy, informing future enforcement priorities.
Demonstrated that smaller DPAs can take leadership roles in AI regulation through guidance and proactive engagement, not only through reactive enforcement.

---

### Case 3.90: EU AI Office First Enforcement Cases (2025) —EU AI Office

**Date Decided:** 2025

**Court:** EU AI Office (European Commission)

**Facts:** In 2025, the EU AI Office initiated its first enforcement actions under the EU Artificial Intelligence Act, targeting general-purpose AI (GPAI) models that failed to comply with transparency and copyright-related obligations effective from August 2025. The Office investigated several major GPAI providers for insufficient documentation of training data, failure to provide adequate summaries of training content, and inadequate copyright compliance mechanisms. The Office also examined systemic risk assessments for models classified as having systemic risk (those trained on more than 10^25 FLOPS). Parallel investigations were conducted in coordination with national competent authorities for high-risk AI systems deployed in critical sectors.

**Issue:** Whether GPAI model providers complied with Article 53 (transparency obligations), Article 54 (copyright compliance), and Article 55 (risk assessment) of the EU AI Act, and what enforcement mechanisms are available to the EU AI Office.

**Holding:** The EU AI Office issued preliminary findings and compliance notices to several GPAI providers, requiring enhanced documentation, improved training data summaries, and corrective measures for copyright compliance. Formal proceedings with potential fines were initiated for providers failing to respond adequately.
**Significance:** First enforcement actions under the EU AI Act, establishing the practical scope and enforcement approach of the world's most comprehensive AI regulation.
The coordination between the EU AI Office (for GPAI) and national authorities (for high-risk AI) tested the Act's multi-level governance structure for the first time.
The copyright compliance requirements created a new intersection between AI regulation and intellectual property law, potentially superseding national approaches to AI training data.

---

### Case 3.91: Getty Images v. Stability AI (2024) —UK High Court

**Date Decided:** 2024

**Court:** High Court of England and Wales

**Facts:** Getty Images filed a landmark lawsuit against Stability AI in the UK High Court, alleging that Stability AI scraped approximately 12 million Getty Images photographs —including those protected by copyright —to train the Stable Diffusion image generation model without permission or compensation. Getty alleged that Stability AI's model could generate images closely resembling copyrighted Getty photographs, including reproductions of Getty's watermark. Getty sought injunctive relief, damages for copyright infringement, and an account of profits. The case addressed novel questions about the copyright status of AI training, whether scraping publicly accessible images constitutes infringement, and whether AI-generated outputs that resemble copyrighted works infringe the underlying rights. The court allowed the case to proceed through early procedural stages.

**Issue:** Whether training an AI model on copyrighted images constitutes copyright infringement under UK law, and whether AI outputs that resemble copyrighted training images infringe the original works.

**Holding:** Procedural proceedings favored Getty's ability to pursue the claims. The court rejected key procedural defenses by Stability AI, allowing the substantive claims to proceed. Full trial anticipated.
**Significance:** The UK case runs parallel to U.S. litigation but under UK copyright law, which lacks a broad fair use defense equivalent to the U.S. doctrine, potentially making it easier for rights-holders to prevail.
The watermark reproduction issue created a particularly vivid illustration of how AI training data can surface in model outputs.
The outcome could establish whether the UK remains an attractive jurisdiction for rights-holders challenging AI companies, or whether legislative reform is needed.

---

### Case 3.92: DABUS Patent Applications (2021-2024) —UKIPO / EPO / USPTO

**Date Decided:** 2021–2024

**Court:** UK Intellectual Property Office; European Patent Office; U.S. Patent and Trademark Office

**Facts:** Dr. Stephen Thaler filed patent applications in multiple jurisdictions naming DABUS (Device for the Autonomous Bootstrapping of Unified Sentience), an AI system, as the inventor. The applications covered two inventions —a food container and a light beacon —that Thaler claimed were autonomously generated by DABUS without human contribution to the inventive concept. The UKIPO, EPO, and USPTO all rejected the applications on the ground that an inventor must be a natural person under their respective patent laws. Thaler appealed through the courts: the UK Supreme Court unanimously rejected his appeal in December 2023, the EPO Board of Appeal upheld the refusal, and the U.S. Federal Circuit similarly ruled against Thaler. Other jurisdictions, notably South Africa and Australia (initially), took different approaches, creating a fragmented international landscape.

**Issue:** Whether an AI system can be named as an inventor on a patent application, and whether patent law requires a human inventor as a matter of statutory interpretation.

**Holding:** The UK Supreme Court (2023), EPO Board of Appeal, and U.S. Federal Circuit all held that patent law requires a human inventor. AI systems cannot be inventors. The patent applications were refused in all major jurisdictions.
**Significance:** Established a clear international consensus (in major patent offices) that only natural persons can be patent inventors, while leaving open the question of whether the person who created or operates the AI can claim inventorship for AI-assisted inventions.
The fragmented international response (South Africa accepted, most rejected) highlighted the inadequacy of existing international patent frameworks for AI-generated inventions.
The decisions intensified calls for legislative reform, with the EU, UK, and U.S. all considering amendments to address AI-assisted invention, particularly regarding ownership of AI-generated outputs.

---

### Case 3.93: Netherlands Algorithm Audit (2024) —Dutch Government

**Date Decided:** 2024

**Court:** Netherlands Court of Audit / Dutch Government Regulatory Framework

**Facts:** In 2024, the Netherlands implemented a mandatory algorithm audit regime under its Algorithm Regulation (Algoritmeverordening), becoming one of the first countries to require systematic auditing of public-sector AI systems. The regime required all government agencies using algorithmic decision-making systems —including those used for benefits administration, tax assessment, law enforcement, and immigration —to undergo independent audits assessing fairness, transparency, accountability, and human rights compliance. The first round of audits revealed significant issues in multiple systems, including discriminatory bias in tax fraud detection algorithms (echoing the childcare benefits scandal), opacity in immigration decision algorithms, and insufficient human oversight in welfare eligibility systems. The audits were conducted by the Dutch Court of Audit and independent algorithm auditors.

**Issue:** Whether public-sector algorithmic systems meet standards for fairness, transparency, and non-discrimination, and whether mandatory algorithm auditing provides effective oversight.

**Holding:** Audit findings revealed systemic deficiencies across multiple government AI systems. Corrective action plans were ordered, and several systems were suspended pending remediation. The results informed legislative amendments to strengthen algorithm accountability.
**Significance:** Established the Netherlands as a global leader in algorithmic accountability through mandatory public-sector AI auditing, creating a replicable model for other jurisdictions.
The connection to the childcare benefits scandal lent urgency and political legitimacy to the audit regime, demonstrating how past failures can drive regulatory innovation.
The audit framework's emphasis on fairness metrics and discrimination testing informed the EU AI Act's conformity assessment requirements for high-risk AI systems.

---

### Case 3.94: NHS AI Diagnostic Liability (2024) —UK Clinical Negligence Framework

**Date Decided:** 2024

**Court:** UK National Health Service / Medicines and Healthcare products Regulatory Agency (MHRA)

**Facts:** In 2024, the UK NHS and MHRA grappled with liability questions arising from the deployment of AI diagnostic tools, particularly in radiology and pathology, where AI systems assisted clinicians in detecting cancers, fractures, and other conditions. Several incidents were reported where AI-assisted diagnoses proved incorrect —in some cases, the AI correctly identified conditions that clinicians dismissed, while in others, AI false negatives contributed to delayed diagnoses. The cases raised fundamental questions about the liability framework: when an AI diagnostic tool is incorrect, who bears responsibility —the clinician who relied on it, the hospital that deployed it, the developer that created it, or the regulator that approved it? The MHRA updated its guidance on AI as a medical device, while the NHS established clinical governance frameworks for AI deployment.

**Issue:** What liability framework applies when AI-assisted medical diagnoses are incorrect, and how should responsibility be allocated among clinicians, healthcare institutions, AI developers, and regulators?

**Holding:** The MHRA issued updated guidance classifying most diagnostic AI as medical devices requiring conformity assessment under the UK MDR. The NHS established clinical governance protocols requiring clinician override capability, mandatory human review of AI recommendations, and incident reporting for AI-related diagnostic errors. No single liability case reached court by end of 2024.
**Significance:** Highlighted the emerging "accountability gap" in medical AI, where existing liability frameworks (clinical negligence, product liability) may not adequately address AI-specific risks.
The requirement for clinician override capability established a human-in-the-loop standard that the EU AI Act's high-risk AI provisions later adopted.
The absence of judicial decisions meant that liability standards remained uncertain, creating a regulatory gap that may require legislative intervention.

---

### Case 3.95: Israel Lavender Targeting AI (2024) —Legal Debate

**Date Decided:** 2024

**Court:** No court proceeding; public investigation and international legal debate

**Facts:** In April 2024, investigative journalists from +972 Magazine and Local Call revealed that the Israel Defense Forces (IDF) used an AI system called "Lavender" to identify human targets during the 2023-2024 Gaza conflict. According to the reports, Lavender processed vast quantities of surveillance data to assign each Palestinian in Gaza a score from 1 to 100 indicating their likelihood of being a militant, with a reported 10% error rate. The IDF reportedly relied on Lavender's recommendations to generate bombing target lists, with human operators given as little as 20 seconds to verify each target before approval. A companion system called "Where's Daddy?" was allegedly used to track targets to their homes, resulting in strikes on residential buildings. International human rights organizations and legal scholars argued that the use of such systems violated international humanitarian law (IHL) principles of distinction, proportionality, and precaution.

**Issue:** Whether the use of AI-powered targeting systems in armed conflict complies with international humanitarian law's principles of distinction (distinguishing combatants from civilians), proportionality, and precaution in attack, and what legal obligations apply to states deploying autonomous or semi-autonomous weapons systems.

**Holding:** No formal judicial proceeding. The IDF stated that all targeting decisions required human approval and complied with IHL. International legal scholars were divided on legality, with some arguing the error rate violated proportionality requirements, while others maintained that human-in-the-loop oversight satisfied legal obligations. The UN Special Rapporteur called for an independent investigation.
**Significance:** Forced the international legal community to confront the application of existing IHL frameworks to AI-driven targeting, a question the 2023 UN General Assembly resolution on autonomous weapons did not definitively resolve.
The reported 10% error rate and compressed human review time became a focal point for debates about whether meaningful human control is possible in high-tempo AI-assisted targeting.
Catalyzed renewed international negotiations on lethal autonomous weapons systems, with the Lavender case serving as a concrete example in diplomatic discussions at the UN Convention on Certain Conventional Weapons (CCW).
End of Part Three Additional Cases 3.61—.95
Global Cyber Law Compendium Volume II

---

### Case 3.96: AI Criminal Justice Risk Assessment, India (2024) — Delhi High Court

**Date Decided:** 2024

**Court:** Delhi High Court, India

**Facts:** A petition was filed before the Delhi High Court challenging the use of AI-powered risk assessment tools in criminal sentencing and bail decisions by Delhi police and judicial authorities. The petitioners argued that the proprietary algorithms lacked transparency, exhibited biases against marginalized communities, and violated the right to a fair trial under Article 21 of the Indian Constitution. The court examined whether the use of such tools without adequate safeguards constituted a violation of fundamental rights and procedural due process.

**Issue:** Whether the use of AI-based risk assessment tools in criminal justice proceedings without transparency, explainability, and bias safeguards violates constitutional rights to equality, due process, and fair trial.

**Holding:** The Delhi High Court ruled that the use of AI risk assessment tools in criminal justice proceedings must be subject to strict judicial oversight and transparency requirements. The court held that while AI tools may serve as instruments, they cannot replace judicial discretion, and their outputs must be explainable and challengeable by affected individuals. The court directed the authorities to establish a regulatory framework mandating algorithmic audits, bias testing, and transparency reports before deploying such tools in any judicial capacity.
**Significance:** Established constitutional limitations on the use of AI in criminal justice in India, drawing on the right to equality and fair trial under Article 21.
Required algorithmic transparency and auditability as preconditions for deployment of AI tools in judicial contexts, setting a standard that extends beyond criminal justice to all government AI use.
Aligned India's approach with emerging global consensus on AI governance in high-stakes decision-making, particularly as articulated in the EU AI Act's framework for high-risk AI systems.

---

### Case 3.97: AI-Generated Disinformation under EU DSA (2024) — European Commission

**Date Decided:** 2024

**Court:** European Commission (DSA enforcement proceedings)

**Facts:** In the lead-up to the 2024 European Parliament elections, the European Commission launched investigations into several very large online platforms for inadequate handling of AI-generated disinformation, including deepfakes and synthetic media. The Commission found that platforms had insufficient systems for detecting and labeling AI-generated content, failed to provide adequate transparency regarding the sources of such content, and lacked effective mechanisms for preventing the viral spread of synthetic disinformation. The investigations were conducted under the DSA's systemic risk assessment and mitigation obligations.

**Issue:** Whether platforms' existing systems for detecting, labeling, and mitigating AI-generated disinformation satisfied the DSA's systemic risk assessment and mitigation obligations, particularly during election periods.

**Holding:** The Commission issued preliminary findings that multiple platforms failed to adequately address the systemic risk posed by AI-generated disinformation. The Commission required platforms to implement enhanced detection systems, mandatory labeling of AI-generated content, and real-time monitoring during election periods. Non-compliance penalties of up to 6% of global annual turnover were threatened.
**Significance:** Established the first regulatory framework specifically addressing AI-generated disinformation under the DSA, going beyond traditional content moderation approaches.
Mandated proactive detection and labeling of AI-generated content, creating a new category of platform obligation that did not exist under prior law.
Set a precedent for election-specific platform obligations that has since been adopted or considered by multiple jurisdictions worldwide.

---

### Case 3.98: Microsoft Tay Chatbot Incident (2016) — Policy Response

**Date Decided:** March 2016 (incident); ongoing policy response

**Court:** No court proceedings; industry self-regulation and policy response

**Facts:** Microsoft launched Tay, an AI-powered chatbot on Twitter designed to engage with users through casual conversation and learning from interactions. Within 24 hours, users exploited the chatbot's learning mechanism to train it to produce racist, sexist, and otherwise offensive content. Microsoft took Tay offline and issued an apology. The incident became a watershed moment in discussions about AI safety, adversarial attacks on machine learning systems, and the responsibilities of AI developers for the behavior of their creations in uncontrolled environments.

**Issue:** What responsibility do AI developers bear for the behavior of their systems when deployed in open, adversarial environments, and what safeguards should be required before deploying conversational AI systems?

**Holding:** While no formal legal proceedings resulted, the incident triggered a fundamental reassessment of AI deployment practices across the industry. Microsoft implemented extensive content filtering, input sanitization, and gradual rollout protocols for subsequent AI products. The incident influenced the development of AI safety frameworks, including those later codified in the EU AI Act and NIST AI Risk Management Framework.
**Significance:** Became the canonical example of adversarial manipulation of AI systems, demonstrating that ML models deployed in open environments are vulnerable to coordinated attacks.
Catalyzed the development of red-teaming practices, content safety filters, and staged deployment protocols now standard in AI development.
Influenced regulatory thinking about the need for pre-deployment testing and ongoing monitoring requirements, provisions later incorporated into the EU AI Act and similar frameworks worldwide.

---

### Case 3.99: Amazon Alexa Voice Recording FTC Settlement (2019) — FTC

**Date Decided:** 2019

**Court:** US Federal Trade Commission (administrative settlement)

**Facts:** The FTC investigated Amazon's Alexa voice assistant following revelations that Amazon retained children's voice recordings without proper parental consent and failed to adequately delete recordings upon user request. The investigation also examined Amazon's data retention practices for adult users' voice recordings, which were being reviewed by human annotators without sufficiently clear disclosure. The FTC alleged violations of the Children's Online Privacy Protection Act (COPPA) and Section 5 of the FTC Act regarding deceptive privacy practices.

**Issue:** Whether Amazon's collection, retention, and human review of voice recordings, particularly those of children, constituted unfair or deceptive practices in violation of COPPA and the FTC Act.

**Holding:** Amazon agreed to a settlement requiring it to obtain verifiable parental consent before collecting voice recordings from children, delete existing children's recordings and associated data, implement more robust data retention and deletion mechanisms, and provide clearer disclosure about human review of voice recordings. The settlement also required Amazon to submit to regular privacy assessments for a period of 20 years.
**Significance:** Extended COPPA's protections to voice data collected by smart speakers and voice assistants, establishing that voice recordings of children constitute personally identifiable information subject to parental consent requirements.
Established the FTC's authority over voice data privacy practices, creating regulatory expectations for the entire voice assistant industry.
Set the template for subsequent enforcement actions against Google, Apple, and other voice assistant providers regarding data retention and human review practices.

---

### Case 3.100: Google Duplex AI Calls (2018) — California CPRA Implications

**Date Decided:** 2018 (launch); ongoing regulatory implications

**Court:** No formal court proceedings; regulatory analysis and policy implications

**Facts:** Google demonstrated and launched Duplex, an AI system capable of making natural-sounding phone calls to book appointments at businesses on behalf of users. The system's human-like voice and conversational ability raised concerns that call recipients could not discern they were speaking with an AI, raising questions about disclosure requirements, consent, and deception. California regulators and privacy advocates identified potential violations of the California Consumer Privacy Act (CPRA) and its predecessor, the CCPA, as well as state consumer protection laws prohibiting deceptive business practices.

**Issue:** Whether AI systems that make phone calls without disclosing their non-human nature violate consumer protection laws, privacy regulations, and disclosure requirements under California law and federal communications regulations.

**Holding:** Google voluntarily implemented a disclosure requirement, programming Duplex to identify itself as an AI assistant at the beginning of each call. The California Attorney General's office indicated that failure to disclose would likely constitute a deceptive practice under the state's Unfair Competition Law. The FCC clarified that AI-generated voice calls are subject to the Telephone Consumer Protection Act (TCPA), though the application to consumer-initiated AI calls remained ambiguous. No formal enforcement action was taken against Google.
**Significance:** Established the principle that AI systems interacting with humans must disclose their nature as artificial agents, a principle later codified in the EU AI Act's transparency requirements.
Demonstrated that existing consumer protection and telecommunications laws can be applied to AI systems, even in the absence of AI-specific legislation.
Influenced the development of disclosure requirements for AI systems across multiple jurisdictions, including the EU AI Act's Article 52 transparency obligations.

---

### Case 3.101: IBM Watson for Oncology Failures (2018-2023) — Medical Liability

**Date Decided:** 2018-2023 (multiple investigations and reports)

**Court:** No formal court proceedings; congressional investigations, medical board reviews, and internal assessments

**Facts:** IBM's Watson for Oncology, marketed as an AI-powered cancer treatment recommendation system, faced intense scrutiny after multiple investigations revealed significant deficiencies in its recommendations. Internal documents showed that the system was trained primarily on hypothetical cases rather than real patient data, produced recommendations that were sometimes at odds with established medical guidelines, and was deployed at hospitals worldwide without adequate validation. The Memorial Sloan Kettering Cancer Center, IBM's primary training partner, was found to have a financial stake in the system's success, raising conflict of interest concerns.

**Issue:** What liability do AI developers and medical institutions bear when AI-powered medical recommendation systems produce unsafe or substandard recommendations, and what standard of care applies to AI-assisted medical decision-making?

**Holding:** No formal legal liability was established, as hospitals using the system retained ultimate clinical decision-making authority. However, multiple hospitals terminated their Watson for Oncology contracts, IBM divested the unit, and the case prompted comprehensive review of AI validation standards in medical devices. The FDA issued updated guidance on AI/ML-based Software as a Medical Device (SaMD), emphasizing the need for real-world performance monitoring.
**Significance:** Exposed the gap between AI marketing claims and clinical reality, demonstrating the risks of deploying AI in high-stakes medical contexts without rigorous real-world validation.
Influenced the FDA's evolving framework for AI/ML-based medical devices, including the proposed Total Product Lifecycle (TPLC) approach to AI regulation.
Established the principle that clinical responsibility remains with human practitioners regardless of AI involvement, while simultaneously highlighting the inadequacy of this principle when AI systems operate in a regulatory grey zone between software and medical devices.

---

### Case 3.102: TikTok Algorithm Addictive Design, OFCOM (2024) — UK OFCOM

**Date Decided:** 2024

**Court:** UK Office of Communications (OFCOM) regulatory assessment

**Facts:** OFCOM, as the UK's designated regulator under the Online Safety Act 2023, conducted a comprehensive assessment of TikTok's algorithmic systems and their impact on user behavior, particularly among children and young people. The investigation examined TikTok's recommendation algorithm, infinite scroll design, variable reward mechanisms, and other features that contributed to compulsive usage patterns. OFCOM found that TikTok's design employed psychological techniques analogous to those used in gambling machines, and that the platform's age verification and parental control mechanisms were inadequate to protect minors from harmful engagement patterns.

**Issue:** Whether TikTok's algorithmic design and engagement optimization features constitute systemic risks under the Online Safety Act 2023, particularly regarding the protection of children from addictive design patterns.

**Holding:** OFCOM issued a comprehensive risk assessment report identifying TikTok's algorithmic design as a systemic risk to child safety and mental health. The regulator required TikTok to implement specific design changes including mandatory screen time limits for minors, disabling infinite scroll for users under 18, algorithmic transparency reports, and enhanced parental controls. OFCOM also initiated formal consultation on binding design code requirements for all social media platforms operating in the UK.
**Significance:** Marked one of the first regulatory actions globally targeting algorithmic addictive design as a distinct category of harm, separate from traditional content moderation concerns.
Established OFCOM's authority to regulate platform design features under the Online Safety Act, going beyond content-focused regulation to address structural aspects of platform architecture.
Set a precedent for design-focused regulation that has influenced legislative proposals in the EU, Australia, and several US states.

---

### Case 3.103: HireVue AI Resume Screening, EEOC (2022-2024) — EEOC

**Date Decided:** 2022-2024

**Court:** US Equal Employment Opportunity Commission (EEOC) investigation and guidance

**Facts:** The EEOC investigated HireVue, a provider of AI-powered video interview analysis and resume screening tools used by numerous Fortune 500 companies. The investigation examined whether HireVue's facial expression analysis, voice analysis, and automated scoring algorithms produced discriminatory outcomes based on race, gender, disability, and other protected characteristics. Multiple studies and internal documents suggested that the system's facial analysis technology performed poorly on individuals with certain disabilities and skin tones, and that the training data did not adequately represent the diversity of the US workforce.

**Issue:** Whether AI-powered employment screening tools that analyze facial expressions, voice patterns, and other biometric data produce discriminatory outcomes in violation of Title VII of the Civil Rights Act and the Americans with Disabilities Act.

**Holding:** The EEOC issued technical guidance confirming that AI-based employment decision tools are subject to existing anti-discrimination laws, and that employers using such tools bear responsibility for ensuring they do not produce discriminatory outcomes. HireVue agreed to discontinue its facial expression analysis feature and submit to regular algorithmic audits. The EEOC also issued broader guidance requiring employers to conduct bias audits before deploying AI employment tools.
**Significance:** Established that existing anti-discrimination laws apply fully to AI-powered employment tools, closing the regulatory gap that had allowed untested AI systems to influence hiring decisions at scale.
Required employers to conduct pre-deployment bias audits for AI employment tools, creating a new compliance obligation that has since been adopted or proposed in multiple jurisdictions.
Demonstrated the limitations of facial analysis technology for employment decisions, contributing to growing skepticism about emotion recognition AI in high-stakes contexts.

---

### Case 3.104: EU AI Act Prohibited Practices Enforcement (2025) — EU AI Office

**Date Decided:** 2025

**Court:** EU AI Office (regulatory enforcement under Regulation (EU) 2024/1689)

**Facts:** Following the entry into application of the EU AI Act in 2025, the EU AI Office initiated its first enforcement proceedings against providers of AI systems that allegedly engaged in prohibited practices under Article 5 of the Act. The prohibited practices included deployment of social scoring systems by local authorities in certain member states, use of real-time remote biometric identification in public spaces without judicial authorization, and manipulation of human behavior through subliminal techniques. The proceedings marked the first practical test of the AI Act's enforcement architecture, including the AI Office's investigative powers and the ability to impose substantial fines.

**Issue:** Whether specific AI deployments by public and private entities constitute prohibited practices under Article 5 of the EU AI Act, including social scoring, unauthorized biometric surveillance, and subliminal manipulation.

**Holding:** The EU AI Office found that several AI deployments constituted prohibited practices and issued binding cessation orders requiring immediate discontinuation. The Office imposed administrative fines ranging from 1% to 3% of global annual turnover, depending on the severity and duration of the violation. The decisions were immediately enforceable, with appeals available to the EU General Court.
**Significance:** Marked the first operational enforcement of the EU AI Act, demonstrating the practical effectiveness of the regulation's enforcement architecture.
Established concrete interpretations of what constitutes prohibited AI practices, particularly regarding social scoring and real-time biometric identification, providing guidance for AI developers worldwide.
Set precedents for the level of fines to be imposed for AI Act violations, signaling the EU's willingness to use substantial financial penalties to ensure compliance.

---

### Case 3.105: AI Environmental Impact Regulation (2024-2025) — EU Commission

**Date Decided:** 2024-2025

**Court:** European Commission (regulatory framework development and enforcement)

**Facts:** The European Commission, acting under its powers under the EU AI Act and related environmental regulations, initiated a comprehensive assessment of the environmental impact of large-scale AI systems. The assessment examined the energy consumption, water usage, and carbon emissions associated with training and deploying foundation models and large language models. The Commission found that the environmental costs of AI training were substantially underreported and that voluntary disclosures by AI developers were insufficient to enable meaningful environmental accountability. The Commission proposed mandatory environmental impact reporting requirements for high-risk AI systems and large foundation models.

**Issue:** What environmental transparency and accountability obligations should apply to the development and deployment of large-scale AI systems under EU law, and how should these obligations be integrated with the EU AI Act's risk-based framework?

**Holding:** The Commission adopted implementing regulations requiring providers of large foundation models to report energy consumption, carbon emissions, water usage, and other environmental impact metrics on a standardized basis. The reporting requirements apply to models trained using more than 10^25 FLOPs and are subject to independent verification. The Commission also indicated its intention to introduce carbon intensity thresholds for AI model deployment in the EU.
**Significance:** Established the world's first mandatory environmental reporting framework specifically designed for AI systems, creating a new dimension of AI accountability beyond safety and non-discrimination.
Integrated environmental sustainability into the AI Act's risk-based framework, requiring environmental assessment as a component of overall AI risk management.
Influenced ongoing discussions at the OECD and G7 about international standards for AI environmental reporting, potentially establishing a global template for AI sustainability regulation.
End of Additional Cases (3.96-3.105) for Part Three - AI Governance
Global Cyber Law Compendium Volume II
---

# Part 4 — Cybercrime & Cybersecurity
## Chapter 4: Prosecuting the Digital Underground
The prosecution of cybercrime has evolved from a niche area of criminal law into one of the most active and consequential domains of legal practice worldwide. The cases in this Part illustrate the expanding reach of cybercrime prosecution, the growing use of international cooperation mechanisms, and the increasing intersection of cybercrime with national security.


### Case 4.1: United States v. Nefilim Ransomware Operator (2025) — DOJ
**Court:** U.S. Department of Justice

**Date Decided:** 2025
Court/Prosecutor: US Department of Justice

**Facts:** A Russian national, identified as the operator and developer of the Nefilim ransomware strain, was extradited from a European country to the United States to face charges related to a multi-year ransomware campaign targeting critical infrastructure, healthcare, and educational institutions in the United States, Canada, Australia, and Europe. The defendant operated the ransomware-as-a-service (RaaS) operation from Russia, which encrypted the computer systems of victim organizations and demanded ransom payments in cryptocurrency.
Charges: The DOJ charged the defendant with:
Conspiracy to commit computer fraud and abuse (18 U.S.C. 1030).
Conspiracy to commit wire fraud (18 U.S.C. 1343).
Intentional damage to protected computers (18 U.S.C. 1030(a)(5)).
Money laundering (18 U.S.C. 1956).
Receipt of ransom proceeds.

**Issue:** The DOJ charged the defendant with: Conspiracy to commit computer fraud and abuse (18 U.S.C. 1030). Conspiracy to commit wire fraud (18 U.S.C. 1343). Intentional damage to protected computers (18 U.S.C. 1030(a)(5)). Money laundering (18 U.S.C. 1956). Receipt of ransom proceeds. Outcome: The defendant pleaded guilty and was sentenced to 10 years in federal prison. The court also ordered forfeiture of cryptocurrency assets valued at approximately $8 million.
**Holding:** The defendant pleaded guilty and was sentenced to 10 years in federal prison. The court also ordered forfeiture of cryptocurrency assets valued at approximately $8 million.
**Significance:** Extradition from Europe. The successful extradition of a Russian ransomware operator from a European country demonstrates the improving capacity of international law enforcement to apprehend cybercriminals who operate from jurisdictions that do not typically cooperate with US law enforcement.
RaaS prosecution. The case represents a significant prosecution of a ransomware-as-a-service operator, targeting the infrastructure developer rather than individual affiliates.
Multi-victim impact. The prosecution highlighted the devastating impact of ransomware on healthcare and educational institutions, contributing to the growing political momentum for mandatory ransomware incident reporting and payment restrictions.

---

### Case 4.2: DOJ v. 12 PRC Nationals (March 2025) — US Department of Justice
**Court:** U.S. Department of Justice

**Date Decided:** March 2025
Court/Prosecutor: US Department of Justice

**Facts:** The DOJ announced indictments against 12 nationals of the People's Republic of China (PRC), including officers of the People's Liberation Army (PLA) and individuals associated with Chinese state-sponsored hacking groups (including APT41, Volt Typhoon, and related entities). The indictments alleged a multi-year campaign targeting US critical infrastructure, including telecommunications networks, energy systems, water treatment facilities, and transportation infrastructure. The campaign, code-named "Volt Typhoon" by security researchers, was characterized as a prepositioning effort to disrupt critical infrastructure in the event of a conflict.
Charges: The indictments charged the defendants with:
Conspiracy to commit computer fraud and abuse.
Conspiracy to commit economic espionage (18 U.S.C. 1831).
Wire fraud.
aggravated identity theft.
Conspiracy to cause damage to protected computers.
Government response: The US government coordinated a "whole-of-government" response, including:
Sanctions imposed by the Treasury Department's Office of Foreign Assets Control (OFAC).
Diplomatic measures, including the summoning of the Chinese Ambassador.
FBI disruption operations targeting the hacking infrastructure.
CISA advisories to critical infrastructure operators.

**Issue:** The indictments charged the defendants with: Conspiracy to commit computer fraud and abuse. Conspiracy to commit economic espionage (18 U.S.C. 1831). Wire fraud. aggravated identity theft. Conspiracy to cause damage to protected computers. Government response: The US government coordinated a "whole-of-government" response, including: Sanctions imposed by the Treasury Department's Office of Foreign Assets Control (OFAC). Diplomatic measures, including the summoning of the Chinese Ambassador. FBI disruption operations targeting the hacking infrastructure. CISA advisories to critical infrastructure operators.
**Significance:** State-sponsored cyber operations. The case represents one of the largest and most significant state-sponsored cyber operations ever attributed by the US government, highlighting the growing integration of cyber operations with military planning.
Critical infrastructure targeting. The targeting of critical infrastructure — particularly telecommunications networks (including the Salt Typhoon campaign targeting major US telecom providers) — represents a qualitative escalation in state-sponsored cyber activity.
Deterrence debate. The case has intensified the debate over cyber deterrence strategy, with some arguing that criminal indictments are insufficient to deter state-sponsored actors and that more robust response options (including offensive cyber operations) are needed.
Diplomatic implications. The coordinated response reflects the US government's increasing willingness to publicly attribute and respond to state-sponsored cyber operations, even at the risk of escalating diplomatic tensions.

---

### Case 4.3: United States v. Ivanov — Computer Fraud & Abuse Act Application

**Date Decided:** Various (representative case)

**Court:** Various US federal courts

**Facts:** This line of cases addresses the extraterritorial application of the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. 1030) to cybercrime committed by foreign actors against US-located computer systems. Representative cases include United States v. Nosal (en banc, 9th Circuit, 2012, 2016), which addressed the scope of "unauthorized access" under the CFAA, and United States v. Valle (2d Circuit, 2015), which addressed the CFAA's application to government employees.
Key legal principles:
"Without authorization" or "exceeding authorized access." The CFAA prohibits accessing a computer "without authorization" or "exceeding authorized access." The interpretation of these terms has been the subject of significant litigation, with courts dividing on whether the CFAA criminalizes violations of employer computer use policies (broad interpretation) or only true "hacking" (narrow interpretation).
Nosal framework (9th Circuit). The en banc Ninth Circuit in United States v. Nosal II (2016) adopted a narrow interpretation, holding that "exceeding authorized access" means accessing areas of the computer that are off-limits to the user (like entering a restricted room), not merely using information in ways prohibited by the employer's policies (like reading a document for an unauthorized purpose). This interpretation has been influential but is not universally followed.
Van Buren v. United States, 593 U.S. 374 (2021). The US Supreme Court adopted the narrow interpretation, holding that the CFAA does not criminalize the misuse of information that a user is otherwise authorized to access. Justice Barrett's opinion for a 6-3 majority held that "exceeds authorized access" refers to accessing areas of the computer that are closed off, not to misusing information that is already available.
Extraterritorial application. Courts have generally held that the CFAA applies extraterritorially when the conduct targets computers located in the United States, even when the perpetrator is located abroad. This principle has been used to prosecute foreign hackers who target US systems.

**Significance:** Van Buren's impact. The Van Buren decision narrowed the scope of the CFAA, providing important protections for employees, researchers, and journalists who access computer systems for purposes that may violate organizational policies but do not constitute "hacking."
Whistleblower protection. Van Buren has been cited as providing implicit protection for whistleblowers who access computer systems to expose wrongdoing, though the decision does not create an explicit whistleblower exception.
Ongoing tension. The narrow interpretation adopted by the Supreme Court has created tension with law enforcement's desire for broad prosecutorial authority over cybercrime, and has led to calls for legislative amendments to address the gap.

---

### Case 4.4: ShinyHunters / Scattered Spider / LAPSUS$ Salesforce Breach (2025) — Multiple US District Courts
**Court:** Multiple U.S. District Courts

**Date Decided:** 2025
Courts: Multiple US District Courts

**Facts:** A coordinated series of breaches targeting Salesforce customer environments was attributed to an evolving collaboration between three threat actor groups: ShinyHunters (a financially motivated cybercrime group), Scattered Spider (a social engineering-focused group), and LAPSUS$ (a notorious extortion group known for targeting large technology and telecommunications companies). The breaches exploited identity-focused intrusion tactics, including SIM swapping, credential theft, and social engineering of IT help desk personnel, to gain access to Salesforce customer environments and exfiltrate sensitive data.
Charges: Multiple indictments were filed against individuals associated with the groups, including charges for:
Conspiracy to commit wire fraud.
Computer fraud and abuse.
Identity theft.
Aggravated identity theft.
Extortion.

**Issue:** Multiple indictments were filed against individuals associated with the groups, including charges for: Conspiracy to commit wire fraud. Computer fraud and abuse. Identity theft. Aggravated identity theft. Extortion.
**Significance:** Evolving threat actor collaboration. The case represents a new trend in cybercrime: the collaboration of distinct threat actor groups with complementary capabilities (data exfiltration, social engineering, and extortion) to conduct more sophisticated and damaging attacks.
Identity as the perimeter. The breaches highlight the vulnerability of cloud-based enterprise environments that rely on identity-based access controls, where the compromise of a single identity (through social engineering or credential theft) can provide access to an entire customer environment.
Salesforce ecosystem. The targeting of Salesforce customer environments (rather than Salesforce itself) demonstrates the growing risk of supply chain and platform-based attacks, where threat actors target the customers of cloud service providers rather than the providers themselves.

---

### Case 4.5: North Korean IT Worker Scheme (Nov 2025) — DOJ
**Court:** U.S. Department of Justice

**Date Decided:** November 2025
Court/Prosecutor: US Department of Justice

**Facts:** The DOJ announced the results of a multi-year investigation into a scheme in which nationals of the Democratic People's Republic of Korea (DPRK, North Korea) posed as remote IT workers to gain employment at US companies, including technology firms, financial institutions, and government contractors. The workers used stolen identities and fraudulent employment documents to obtain remote access to company networks, from which they exfiltrated sensitive data and generated revenue for the North Korean government. The scheme generated over $15 million in revenue for the DPRK's weapons programs.
Charges: Five DPRK nationals pleaded guilty to charges including:
Conspiracy to commit wire fraud.
Conspiracy to commit money laundering.
Conspiracy to cause damage to protected computers.
Use of fraudulent identity documents.

**Issue:** Five DPRK nationals pleaded guilty to charges including: Conspiracy to commit wire fraud. Conspiracy to commit money laundering. Conspiracy to cause damage to protected computers. Use of fraudulent identity documents. Outcome: Five guilty pleas, with combined sentences totaling over 25 years. The court ordered civil forfeitures totaling over $15 million in cryptocurrency and other assets.
**Holding:** Five guilty pleas, with combined sentences totaling over 25 years. The court ordered civil forfeitures totaling over $15 million in cryptocurrency and other assets.
**Significance:** State-sponsored fraud. The case represents a novel form of state-sponsored cyber activity — the use of remote work as a vehicle for espionage and revenue generation — that falls outside the traditional categories of cybercrime or cyber warfare.
Remote work vulnerability. The case highlights the security risks associated with remote work arrangements, particularly the difficulty of verifying the identity and location of remote workers.
Sanctions evasion. The scheme was partly designed to circumvent international sanctions against the DPRK, using employment income and cryptocurrency to fund weapons programs.

---

### Case 4.6: ILOVEYOU Virus Case (Philippines, 2000) — Manila Regional Trial Court

**Date Decided:** 2000

**Court:** Manila Regional Trial Court

**Facts:** The ILOVEYOU virus (also known as the Love Bug) was a computer worm that spread globally in May 2000, infecting over 10 million computers and causing an estimated $10 billion in damage. The virus was distributed as an email attachment with the subject line "ILOVEYOU" and the attachment "LOVE-LETTER-FOR-YOU.TXT.vbs." When opened, the attachment sent copies of itself to all contacts in the victim's email address book and overwrote files on the victim's computer.
The virus was traced to Reonel Ramones and Onel de Guzman, two students in Manila, Philippines. At the time of the virus's release, the Philippines did not have a specific cybercrime law, and existing criminal statutes were insufficient to prosecute the perpetrators.

**Holding:** The case against the suspects was dismissed because the Philippines did not have a law criminalizing the creation and distribution of computer viruses. Both suspects were released.
**Significance:** Catalyst for legislation. The ILOVEYOU case was the direct catalyst for the enactment of the Philippines' Cybercrime Prevention Act of 2012 (Republic Act No. 10175), which criminalized a wide range of computer offenses including the creation and distribution of malware.
Global awareness. The case was one of the first major global cybercrime incidents to receive widespread public attention, demonstrating the vulnerability of networked computer systems to malicious software.
Legislative gap. The case exposed the critical gap in many countries' legal frameworks for prosecuting cybercrime, motivating legislative action worldwide.
Extradition challenges. The case also highlighted the challenges of prosecuting cross-border cybercrime, as the virus affected victims in dozens of countries, but the perpetrators were located in a jurisdiction without adequate laws.

---

### Case 4.7: China — Cybersecurity Law Enforcement Cases

**Significance:** China's cyber enforcement cases demonstrate the rapid development of the country's data protection and cybersecurity enforcement framework:
Administrative enforcement as primary mechanism. China's enforcement relies primarily on administrative penalties imposed by the CAC and other regulators, rather than private litigation.
National security dimension. Data security enforcement in China has a strong national security dimension, with the DSL and PIPL's cross-border transfer restrictions reflecting concerns about data sovereignty and state security.
Deterrence effect. The Didi fine, as the largest data protection penalty in history at the time, sent a strong signal to the Chinese technology industry about the consequences of non-compliance.

---

### Case 4.8: United States v. Morris (1988) — US District Court, N.D. Illinois

**Date Decided:** May 16, 1990 (sentencing)

**Court:** US District Court for the Northern District of Illinois
Case citation: United States v. Morris, 928 F.2d 504 (2d Cir. 1991)

**Facts:** Robert Tappan Morris, a Cornell University graduate student, released the "Morris Worm" in November 1988, one of the first computer worms transmitted via the Internet. The worm was intended to measure the size of the Internet but contained a design flaw that caused it to replicate uncontrollably, infecting approximately 6,000 computers (an estimated 10% of all Internet-connected machines at the time) and causing significant disruption to systems at universities, research laboratories, and military installations.

**Issue:** Whether the release of a self-replicating computer program that caused unintended but substantial damage to Internet-connected computers constituted a federal crime under 18 U.S.C. 1030.

**Holding:** Morris was convicted under the CFAA. He was sentenced to three years of probation, 400 hours of community service, and a $10,050 fine. The Second Circuit affirmed the conviction, rejecting Morris's argument that he lacked the requisite intent to cause damage.
**Significance:** First major cybercrime prosecution. The Morris Worm case was the first federal prosecution under the CFAA and established the legal precedent for prosecuting the authors and releasers of malicious code.
Intent standard. The Second Circuit held that the government needed to prove only that Morris intended to access federal interest computers without authorization, not that he intended the specific damage that resulted — a standard that significantly broadened prosecutorial reach.
Catalyst for cybersecurity awareness. The incident led directly to the creation of CERT/CC (the Computer Emergency Response Team Coordination Center) and awakened policymakers to the vulnerability of networked systems.

---

### Case 4.9: United States v. Mitnick (1999) — US District Court, C.D. California

**Date Decided:** August 9, 1999 (plea agreement)

**Court:** US District Court for the Central District of California
Case citation: No. CR-97-00103 (C.D. Cal.)

**Facts:** Kevin Mitnick was arrested in 1995 after a two-and-a-half-year pursuit by the FBI. He had engaged in a decades-long campaign of computer intrusions into corporate networks, including Nokia, Motorola, Sun Microsystems, and Fujitsu, stealing proprietary software and corporate secrets through social engineering, pretexting, and traditional hacking techniques.

**Issue:** Whether Mitnick's unauthorized access to corporate computer systems and theft of proprietary software constituted wire fraud, computer fraud, and related federal offenses.

**Holding:** Mitnick pleaded guilty to five counts of wire fraud, computer fraud, and related charges. He was sentenced to 46 months in prison (with credit for time served), followed by three years of supervised release with restrictions on computer and Internet use.
**Significance:** Social engineering as hacking. The case highlighted social engineering as a potent attack vector, demonstrating that the human element is often the weakest link in computer security.
Pretrial detention controversy. Mitnick was held in solitary confinement for eight months before trial, fueling debate about the treatment of cybercriminal defendants.
Cultural impact. The case became a defining narrative of the early hacking era and influenced subsequent cybersecurity policy.

---

### Case 4.10: United States v. Smith — The Melissa Virus (1999) — US District Court, D. New Jersey

**Date Decided:** December 9, 1999 (plea)

**Court:** US District Court for the District of New Jersey
Case citation: No. 99-CR-555 (D.N.J.)

**Facts:** David L. Smith created and released the Melissa virus in March 1999, one of the first mass-mailing macro viruses. Distributed via email with an attached Word document, the virus disabled security safeguards in Microsoft Word and mailed itself to the first 50 addresses in the victim's Outlook address book, causing widespread disruption to corporate and government email systems worldwide with an estimated $80 million in damages.

**Issue:** Whether the creation and intentional distribution of a computer virus that caused widespread disruption constituted a federal crime.

**Holding:** Smith pleaded guilty to causing intentional damage to protected computers and conspiracy. He was sentenced to 20 months in federal prison, three years of supervised release, a $5,000 fine, and 100 hours of community service.
**Significance:** Early macro virus prosecution. One of the first successful federal prosecutions of a virus author in the United States, establishing a deterrent precedent.
Productivity software vulnerability. The virus demonstrated the vulnerability of widely used productivity software to malicious code, prompting security improvements.
Cooperation credit. Smith's relatively lenient sentence reflected his cooperation with authorities — a factor that has influenced subsequent cybercrime prosecutions.

---

### Case 4.11: Code Red Worm (2001) — Multiple US District Courts

**Date Decided:** 2001-2003

**Court:** Multiple US District Courts

**Facts:** The Code Red worm emerged in July 2001, exploiting a buffer overflow vulnerability in Microsoft IIS web server software. It infected over 359,000 servers in less than 14 hours, defacing websites and launching DDoS attacks including against the White House website. Code Red II, a variant, installed backdoors on infected systems for remote access. Although never definitively attributed in court (suspected Chinese hacker groups), the incident spawned civil litigation against Microsoft.

**Issue:** Criminal attribution, civil liability for software vendors, and the adequacy of existing laws to address worm-based attacks.

**Holding:** No successful criminal prosecution. Microsoft faced class-action lawsuits alleging negligence in IIS design, and the incident led to significant security industry reforms.
**Significance:** Vendor liability debate. Intensified the debate over whether software vendors should bear legal responsibility for security vulnerabilities in their products.
Patch management importance. The worm exploited a vulnerability for which a patch already existed, demonstrating the critical importance of timely patching.
Botnet weaponization. Code Red's use of infected servers for DDoS attacks foreshadowed the weaponization of botnets.

---

### Case 4.12: SQL Slammer Worm (2003) — Industry Response and Prosecution Efforts

**Date Decided:** January 2003 (incident); subsequent enforcement actions

**Court:** No successful criminal prosecution

**Facts:** The SQL Slammer worm emerged on January 25, 2003, exploiting a buffer overflow in Microsoft SQL Server's Desktop Engine. It doubled in size every 8.5 seconds, infecting approximately 75,000 hosts within 10 minutes — the fastest-spreading worm in history at the time. It disabled Bank of America's ATM network, collapsed South Korea's Internet infrastructure, and disrupted 911 emergency services. Microsoft had released a patch six months prior.

**Issue:** Criminal attribution (believed Chinese or Southeast Asian origin), adequacy of global cybersecurity response, and legal responsibility for failing to apply patches.

**Holding:** No individual was ever successfully prosecuted. The incident became a landmark case study in patch compliance failure.
**Significance:** Speed of propagation. Demonstrated that malware could propagate at speeds exceeding human response capacity, highlighting the need for automated defenses.
Critical infrastructure impact. Disruption of 911 services and banking systems demonstrated cascading effects on critical infrastructure.
Patch compliance as legal obligation. The incident influenced the development of cybersecurity regulations that mandate patch management.

---

### Case 4.13: SoBig.F Virus (2003) — Global Investigation

**Date Decided:** August 2003 (incident); investigation through 2004

**Court:** Multiple jurisdictions

**Facts:** The SoBig.F virus emerged in August 2003 as the sixth and most destructive variant of the SoBig family, spreading via email and infecting millions of computers with an estimated $37 billion in economic damage. It was designed to create open proxies on infected machines for spam distribution. Security researchers attributed it to an organized criminal group, possibly based in Russia or Eastern Europe. Despite a $250,000 reward from Microsoft, no perpetrator was publicly identified.

**Issue:** Attribution of sophisticated mass-mailing virus to organized criminal groups and the intersection of virus creation with spam-based revenue generation.

**Holding:** Despite extensive international investigation involving the FBI and Microsoft, no individual was ever publicly prosecuted for creating SoBig.F.
**Significance:** Crimeware evolution. Represented a shift from hobbyist malware to financially motivated "crimeware" designed to support profitable criminal enterprises.
Spam-malware nexus. Established the model for using malware to build botnets for spam — a model that persists today.
Attribution challenge. The failure to prosecute highlighted the challenges of attributing cybercrime to individuals operating from uncooperative jurisdictions.

---

### Case 4.14: WannaCry Ransomware Attack (2017) — Global Investigation

**Date Decided:** May 2017 (incident); December 2017 (US attribution)

**Court:** US District Court for the Eastern District of Virginia (related proceedings); UN Security Council

**Facts:** The WannaCry ransomware attack began on May 12, 2017, infecting over 230,000 computers in over 150 countries within a day by exploiting the EternalBlue vulnerability — a Windows SMB flaw developed by and stolen from the NSA. The UK's NHS was forced to cancel approximately 19,000 medical appointments; Telefonica, FedEx, and numerous other organizations were also affected. Estimated damages ranged from $4 billion to $8 billion.

**Issue:** Legal responsibility for a globally destructive ransomware attack attributed to North Korea's Lazarus Group, and liability implications of a government-developed exploit being used in a criminal attack.

**Holding:** The US government attributed the attack to North Korea's Lazarus Group. The US Treasury imposed sanctions on associated individuals and entities. No individual was successfully prosecuted.
**Significance:** NSA exploit responsibility. Sparked intense debate about the US government's "Vulnerabilities Equities Process" and the risks of stockpiling offensive cyber capabilities.
Healthcare impact. The NHS disruption demonstrated the potentially life-threatening consequences of ransomware on healthcare infrastructure.
State-sponsored ransomware. Demonstrated that ransomware could be used as an instrument of state policy (revenue generation).

---

### Case 4.15: NotPetya Attack (2017) — Global Investigation and Sanctions

**Date Decided:** June 2017 (incident); October 2018 (indictment)

**Court:** US District Court for the Western District of Pennsylvania; civil litigation by affected companies
Case citation: Related to US v. Russian GRU Officers (DOJ indictment, Oct. 2018)

**Facts:** The NotPetya malware attack began on June 27, 2017, originating from a compromised Ukrainian tax accounting software (M.E.Doc). Disguised as ransomware, it was actually a destructive wiper causing an estimated $10 billion in damage — the most destructive cyberattack in history at the time. Major victims included Maersk, Merck, FedEx, and WPP. The US, UK, and allies attributed it to Russia's GRU Unit 74455 (Sandworm).

**Issue:** Whether a state-sponsored destructive cyberattack constitutes an act of aggression under international law, and whether "act of war" exclusions in cyber insurance policies apply.

**Holding:** The US Treasury imposed sanctions. A grand jury indicted six GRU officers. Companies pursued insurance claims generating significant litigation over cyber insurance policy language.
**Significance:** Act of war debate. Reignited debate over whether state-sponsored cyberattacks constitute "acts of war" under international and insurance law.
Supply chain weaponization. Demonstrated the devastating potential of supply-chain compromise through trusted software update mechanisms.
Insurance industry impact. The insurance litigation reshaped cyber insurance policy language and underwriting practices.

---

### Case 4.16: Colonial Pipeline Ransomware Attack (2021) — US District Court, E.D. Texas

**Date Decided:** May 2021 (incident); June 2021 (related proceedings)

**Court:** US District Court for the Eastern District of Texas; DOJ criminal proceedings

**Facts:** On May 7, 2021, the Russia-based DarkSide ransomware group attacked Colonial Pipeline, the largest fuel pipeline in the United States (approximately 45% of East Coast fuel supply). The six-day shutdown caused fuel shortages, panic buying, and price spikes. Colonial paid approximately $4.4 million in ransom; the FBI subsequently recovered approximately $2.3 million by tracing Bitcoin transactions.

**Issue:** Legal and policy implications of ransomware attacks on critical energy infrastructure, including the appropriateness of ransom payment and adequacy of cybersecurity regulation.

**Holding:** The DOJ announced criminal charges against DarkSide members. The TSA issued emergency security directives requiring pipeline operators to implement specific cybersecurity measures.
**Significance:** Critical infrastructure vulnerability. Prompted executive action including the Biden administration's executive order on cybersecurity.
Ransom recovery. The FBI's recovery of $2.3 million was unprecedented and demonstrated cryptocurrency tracing feasibility.
Pipeline regulation. TSA's directives represented the first mandatory cybersecurity requirements for the US pipeline sector.

---

### Case 4.17: Kaseya VSA Ransomware Attack (2021) — International Proceedings

**Date Decided:** July 2021 (incident); subsequent international investigations

**Court:** US Department of Justice; Romanian and Ukrainian authorities

**Facts:** On July 2, 2021, the REvil ransomware group exploited a vulnerability in Kaseya's VSA remote management platform to deploy ransomware to approximately 1,500 downstream businesses through their managed service providers (MSPs). The $70 million ransom demand was the largest known at the time. Victims included schools, small businesses, and government agencies. Kaseya obtained and distributed a universal decryption key.

**Issue:** Legal responsibility for supply-chain ransomware delivered through an MSP platform, and the adequacy of existing laws for cascading ransomware attacks.

**Holding:** Romanian authorities arrested suspects; Ukrainian police raided REvil infrastructure. A multi-national law enforcement operation disrupted remaining REvil infrastructure in January 2022.
**Significance:** MSP supply-chain risk. Demonstrated cascading risk of supply-chain attacks through MSP platforms.
Record ransom demand. The $70 million demand highlighted the escalating financial ambitions of ransomware groups.
International cooperation. Multi-national response demonstrated improving cooperation in disrupting ransomware operations.

---

### Case 4.18: JBS Foods Ransomware Attack (2021) — DOJ Investigation

**Date Decided:** June 2021 (incident)

**Court:** US Department of Justice

**Facts:** On May 31, 2021, REvil attacked JBS USA, the largest US meat processor, forcing shutdown of all US beef plants and operations in Australia and Canada. JBS paid $11 million in ransom. The White House described it as ransomware from a Russian-based criminal group. The incident was raised at the Biden-Putin Geneva summit in June 2021.

**Issue:** Implications of ransomware attacks on food supply chain infrastructure and national security dimensions.

**Holding:** The FBI investigated; no individual prosecutions were announced. The Biden administration elevated ransomware to a top-tier diplomatic issue with Russia.
**Significance:** Food security nexus. Demonstrated vulnerability of food supply chains to ransomware.
Diplomatic escalation. First time ransomware was a prominent US-Russia presidential summit agenda item.
Ransom payment debate. JBS's $11 million payment intensified debate over banning ransom payments.

---

### Case 4.19: MGM Resorts Cyberattack (2023) — DOJ and SEC Proceedings

**Date Decided:** September 2023 (incident); 2024 (arrests)

**Court:** US Department of Justice; SEC enforcement proceedings

**Facts:** The Scattered Spider group (UNC3944) conducted a social engineering attack against MGM Resorts, impersonating an employee to IT help desk to obtain credentials. The attack disrupted casino and hotel operations for over a week, causing an estimated $100 million in losses. In 2024, authorities arrested several individuals associated with Scattered Spider, including minors.

**Issue:** Legal implications of social engineering attacks on major corporations and criminal liability of young offenders in cybercrime.

**Holding:** Multiple arrests in the US and UK in 2024. Several suspects were minors, raising questions about juvenile cybercrime prosecution.
**Significance:** Social engineering at scale. Demonstrated that social engineering alone can compromise major corporations without technical exploitation.
Juvenile cybercrime. Highlighted growing juvenile involvement and challenges of prosecuting young offenders.
Hospitality sector vulnerability. Exposed cybersecurity gaps in the hospitality sector.

---

### Case 4.20: Change Healthcare Ransomware Attack (2024) — DOJ and HHS Investigation

**Date Decided:** February 2024 (incident); ongoing investigations

**Court:** US Department of Justice; US Department of Health and Human Services

**Facts:** On February 21, 2024, the BlackCat (ALPHV) ransomware group attacked Change Healthcare, processing approximately one-third of all US medical claims. The attack disrupted healthcare billing, prescription processing, and insurance verification nationwide for weeks, affecting millions of patients and exposing data of approximately 100 million individuals. Total estimated costs exceeded $8.5 billion.

**Issue:** Systemic risk of healthcare claims processing concentration and adequacy of healthcare sector cybersecurity regulation.

**Holding:** Change reportedly paid a $22 million ransom. The DOJ indicted BlackCat members. HHS proposed new cybersecurity requirements. Multiple class-action lawsuits were filed.
**Significance:** Single point of failure. Demonstrated systemic risk of concentrating critical healthcare infrastructure in few companies.
Healthcare regulation. Accelerated regulatory efforts to mandate cybersecurity standards under HIPAA.
Largest healthcare breach. The $8.5 billion cost made it the most costly healthcare cyberattack in history.

---

### Case 4.21: Stuxnet (2010) — International Legal Analysis

**Date Decided:** June 2010 (discovered); subsequent analysis

**Court:** No criminal prosecution; subject of extensive international law scholarship

**Facts:** Stuxnet was a sophisticated worm discovered in June 2010, designed specifically to target Siemens industrial control systems at Iran's Natanz nuclear enrichment facility. It caused approximately 1,000 centrifuges to self-destruct while sending false monitoring data to operators. Widely attributed to a joint US-Israel operation, it was the first known deployment of a cyber weapon designed to cause physical destruction. Iran filed a formal UN complaint.

**Issue:** Whether deployment of a cyber weapon targeting another nation's industrial infrastructure constitutes an act of aggression, use of force, or armed attack under international law (UN Charter Articles 2(4) and 51).

**Holding:** No prosecution (state actors). The US and Israel did not formally acknowledge responsibility until investigative reporting confirmed involvement.
**Significance:** First cyber weapon. Widely regarded as the world's first cyber weapon designed to cause physical destruction.
International law implications. Forced the international legal community to confront when cyber operations constitute use of force — a debate that continues today.
Normalization of offensive cyber. Believed to have emboldened other nations to develop offensive cyber capabilities.

---

### Case 4.22: SolarWinds SUNBURST Attack (2020) — DOJ and Congressional Proceedings

**Date Decided:** December 2020 (discovery); April 2021 (attribution)

**Court:** US District Court for the Southern District of New York; US Congress

**Facts:** In December 2020, a supply-chain attack on SolarWinds' Orion IT monitoring software inserted a backdoor (SUNBURST) distributed to approximately 18,000 customers. Approximately 100 organizations were compromised, including multiple US government agencies (Treasury, State, Commerce, Justice, Energy). Attributed to Russia's SVR (Cozy Bear / APT29), it represented one of the most sophisticated cyber espionage operations ever discovered.

**Issue:** Legal and national security implications of a state-sponsored supply-chain compromise affecting the US government and private sector.

**Holding:** The Biden administration formally attributed the attack to Russia's SVR and imposed diplomatic sanctions including expulsion of 10 Russian diplomats. Multiple congressional hearings examined the intelligence failure.
**Significance:** Supply-chain paradigm. Established supply-chain compromise as the premier threat model in cybersecurity.
Intelligence failure. Described as a massive intelligence failure — compromise undetected for approximately 9 months.
Software liability debate. Reignited debate over software vendor legal liability for security vulnerabilities.

---

### Case 4.23: DNC Email Hack (2016) — US Special Counsel Investigation

**Date Decided:** 2016 (incident); July 2018 (indictment)

**Court:** US District Court for the District of Columbia
Case citation: United States v. Netyksho et al., No. 18-cr-215 (D.D.C.)

**Facts:** Russian GRU officers (Unit 26165, "Fancy Bear") hacked the DNC, DCCC, and Hillary Clinton's campaign chairman John Podesta in 2016. Stolen emails were released through WikiLeaks during the presidential election. The operation also involved voter registration database compromises in multiple US states.

**Issue:** Whether a state-sponsored hacking and information operations campaign targeting political parties and election infrastructure constituted federal crimes and foreign interference.

**Holding:** Special Counsel Mueller indicted 12 Russian GRU officers for conspiracy to commit computer fraud, wire fraud, bank fraud, and identity theft. None were apprehended.
**Significance:** Election interference framework. Established the legal and policy framework for responding to state-sponsored election interference.
Information operations. Highlighted the convergence of hacking with information warfare — a new hybrid threat category.
Indictment as deterrence. Established criminal indictments as a tool for diplomatic signaling and deterrence against state-sponsored cyber actors.

---

### Case 4.24: OPM Data Breach (2015) — Civil Litigation and Congressional Hearings

**Date Decided:** 2015 (disclosure); subsequent proceedings

**Court:** US Court of Federal Claims; US Congress

**Facts:** In 2015, OPM disclosed breaches exposing personal information of approximately 22.1 million current and former federal employees, including deeply personal SF-86 security clearance application data (mental health histories, financial records, substance use disclosures). Attributed to Chinese state-sponsored actors. OPM Director Katherine Archuleta resigned.

**Issue:** Government's legal liability for failing to protect personal information of millions of federal employees.

**Holding:** OPM settled class-action litigation, offering credit monitoring and identity protection services. Congress approved $32 million for identity protection.
**Significance:** Government cybersecurity reform. Led to creation of the Federal CISO position and new cybersecurity mandates for federal agencies.
Intelligence community risk. Stolen SF-86 data posed risks far beyond identity theft — potential for blackmail and espionage recruitment.
Sovereign liability. Tested limits of government liability under the Federal Tort Claims Act for cybersecurity failures.

---

### Case 4.25: Ashley Madison Data Breach (2015) — Multiple Proceedings

**Date Decided:** July 2015 (breach); subsequent proceedings

**Court:** US District Court for the Eastern District of Virginia; Multiple US District Courts

**Facts:** "The Impact Team" hacked Ashley Madison, a dating website for extramarital affairs, stealing and publicly releasing personal data of approximately 37 million users (names, email addresses, credit card transactions, sexual preferences). The release led to extortion cases, divorces, and at least two reported suicides. The primary perpetrator was identified as an Avid Life Media employee but died by suicide before trial.

**Issue:** Criminal liability for hacking and public disclosure of sensitive data, and civil liability of the website operator for failing to protect user data.

**Holding:** Class-action lawsuits resulted in a $17.5 million settlement. The FTC investigated the company for deceptive practices, including the misleading "paid delete" feature.
**Significance:** Reputational harm. Demonstrated unique reputational harm from exposure of sensitive personal data, extending beyond financial harm.
Deceptive practices. Highlighted legal risks for companies making misleading claims about data security.
Insider threat. Underscored the insider threat dimension of data breaches.

---

### Case 4.26: Sony Pictures Hack (2014) — DOJ Proceedings

**Date Decided:** November 2014 (incident); September 2018 (indictment)

**Court:** US District Court for the Central District of California
Case citation: United States v. Park Jin Hyok, No. 18-mj-7104 (C.D. Cal.)

**Facts:** North Korea's Reconnaissance General Bureau conducted a devastating cyberattack against Sony Pictures Entertainment, stealing unreleased films, executive salaries, employee personal data, and internal communications. The attack included threats against theaters showing "The Interview," a comedy about Kim Jong-un's assassination. It was the first publicly attributed state-sponsored destructive cyberattack against a US private company.

**Issue:** Legal classification of a state-sponsored destructive cyberattack against a private company.

**Holding:** The DOJ indicted North Korean national Park Jin Hyok for conspiracy to commit computer fraud and abuse. The Obama administration issued Executive Order 13694 authorizing sanctions for significant malicious cyber activity.
**Significance:** State attack on private sector. First publicly attributed state-sponsored destructive cyberattack against a private company.
Freedom of expression. The suppression of "The Interview" raised questions about cyberattacks chilling freedom of expression.
Sanctions authority. Executive Order 13694 created a tool subsequently used extensively against state-sponsored cyber actors.

---

### Case 4.27: Equifax Data Breach (2017) — DOJ, FTC, and CFPB Proceedings

**Date Decided:** September 2017 (disclosure); July 2019 (settlement)

**Court:** US District Court for the Northern District of Georgia; FTC and CFPB
Case citation: In re Equifax Inc. Data Breach Litigation, No. 17-md-2800 (N.D. Ga.)

**Facts:** Equifax disclosed a breach exposing personal information of approximately 147 million people (names, Social Security numbers, dates of birth). The breach exploited a known Apache Struts vulnerability for which a patch had been available for two months. Three executives sold stock before public disclosure.

**Issue:** Legal liability of a credit reporting agency for failing to protect personal data of millions and criminal liability of executives for stock trading.

**Holding:** Equifax agreed to a $575 million settlement (potentially up to $700 million). The FTC imposed a 20-year consent order requiring comprehensive security reforms. Criminal investigations into stock sales did not result in charges.
**Significance:** Credit reporting accountability. Established new accountability standards for credit reporting agencies holding uniquely sensitive data.
Patch management negligence. Became the canonical example of organizational negligence in patch management.
Stock trading scrutiny. Highlighted need for stronger insider trading protections in the context of data breaches.

---

### Case 4.28: Capital One Data Breach (2019) — DOJ and OCC Proceedings

**Date Decided:** July 2019 (disclosure); 2021 (sentencing)

**Court:** US District Court for the Western District of Washington
Case citation: United States v. Paige A. Thompson, No. 19-mj-545 (W.D. Wash.)

**Facts:** Former AWS employee Paige A. Thompson exploited a misconfigured web application firewall to access personal data of approximately 106 million Capital One customers in the US and 6 million in Canada. Thompson publicly discussed the breach on social media before Capital One discovered it.

**Issue:** Whether exploiting a misconfigured cloud security control to access personal data violated the CFAA, and shared responsibility for cloud data security.

**Holding:** Thompson was convicted and sentenced to time served (approximately seven months) and five years of supervised release. Capital One was fined $80 million by the OCC and faced a $190 million class-action settlement.
**Significance:** Cloud shared responsibility. Highlighted shared responsibility model for cloud security between providers and customers.
Cloud insider threat. Demonstrated insider threat risk in cloud computing environments.
Mental health in sentencing. Thompson's mental health was a significant sentencing factor, raising questions about handling mentally ill cybercrime defendants.

---

### Case 4.29: United States v. Okeke — BEC Fraud (2019) — US District Court, E.D. Virginia

**Date Decided:** 2019 (conviction); 2020 (sentencing)

**Court:** US District Court for the Eastern District of Virginia
Case citation: United States v. Okeke, No. 1:19-cr-161 (E.D. Va.)

**Facts:** Nigerian national Obinwanne Okeke operated a transnational BEC scheme from the UAE that defrauded businesses of approximately $11 million, including a Caterpillar subsidiary. The scheme used phishing, compromised business email accounts, and social engineering to redirect wire transfers.

**Issue:** Whether a BEC fraud scheme operated from overseas constituted wire fraud and computer fraud under US federal law.

**Holding:** Okeke was convicted of conspiracy to commit wire fraud and sentenced to 12 years in federal prison with restitution of approximately $11 million.
**Significance:** BEC as top cybercrime. Reflected recognition of BEC as the most financially damaging form of cybercrime.
Extradition from UAE. Demonstrated improving international law enforcement cooperation.
Sophisticated fraud. Highlighted the increasing sophistication of BEC operations combining technical and social engineering.

---

### Case 4.30: BEC Fraud — United States v. Valery P. et al. (2017) — US District Court, S.D. New York

**Date Decided:** 2017 (indictment); subsequent prosecutions

**Court:** US District Court for the Southern District of New York
Case citation: United States v. Valery P. et al., No. 17-cr-94 (S.D.N.Y.)

**Facts:** The DOJ charged 23 individuals in a massive BEC and romance scam scheme originating from Nigeria, causing over $12 million in confirmed losses. Operations included business email compromise, romance scams, and advance-fee fraud ("Nigerian prince" scams), facilitated by US-based money mule networks.

**Issue:** Scope of transnational BEC operations and the role of US-based money mules in facilitating international cybercrime.

**Holding:** Multiple defendants arrested in the US and Nigeria. Convictions resulted in sentences ranging from several years to over 20 years.
**Significance:** Mass prosecution. One of the largest coordinated BEC prosecutions at the time.
Money mule disruption. Highlighted legal tools for dismantling money laundering networks.
Nigeria cooperation. Represented a milestone in US-Nigeria law enforcement cooperation on cybercrime.

---

### Case 4.31: Romance Scam Prosecutions — United States v. Adeyemi et al. (2020) — US District Court, N.D. Georgia

**Date Decided:** 2020 (indictment); subsequent prosecutions

**Court:** US District Court for the Northern District of Georgia
Case citation: United States v. Adeyemi, No. 1:20-cr-00308 (N.D. Ga.)

**Facts:** Multiple defendants were indicted in a large-scale romance scam targeting primarily elderly Americans through online dating platforms. The defendants created false romantic identities to gain victims' trust, then induced them to send money under false pretexts. Total losses exceeded $2 million, laundered through cryptocurrency and wire transfers.

**Issue:** Whether romance scams targeting vulnerable individuals constituted wire fraud, mail fraud, and money laundering.

**Holding:** Multiple defendants convicted and sentenced to prison terms ranging from 3 to 10 years, with restitution and asset forfeiture orders.
**Significance:** Elder fraud focus. Part of the DOJ's Elder Justice Initiative prioritizing prosecutions targeting elderly victims.
Emotional manipulation as aggravator. Courts recognized emotional manipulation as an aggravating sentencing factor.
Cryptocurrency laundering. Demonstrated increasing use of cryptocurrency in romance scam proceeds laundering.

---

### Case 4.32: United States v. Ulbricht — Silk Road (2015) — US District Court, S.D. New York

**Date Decided:** May 29, 2015 (conviction); July 31, 2015 (sentencing)

**Court:** US District Court for the Southern District of New York
Case citation: United States v. Ulbricht, 858 F.3d 71 (2d Cir. 2017)

**Facts:** Ross Ulbricht created and operated "Silk Road," an anonymous dark web marketplace (2011-2013), facilitating sale of illegal drugs, forged documents, and hacking tools using Bitcoin. The site generated over $1 billion in sales and earned Ulbricht approximately $18 million in commissions. Ulbricht was arrested at a San Francisco public library in October 2013.

**Issue:** Whether operating an anonymous online marketplace for illegal goods constituted criminal enterprise, narcotics trafficking, money laundering, and computer fraud.

**Holding:** Ulbricht was convicted on all seven counts and sentenced to life in prison without parole — upheld on appeal.
**Significance:** Life sentence controversy. The life sentence was unprecedented for a first-time nonviolent offender whose crime involved operating a website.
Cryptocurrency precedents. Established important precedents for cryptocurrency as evidence, proceeds of crime, and money laundering instruments.
Dark web framework. Established the legal framework for subsequent dark web marketplace prosecutions.

---

### Case 4.33: AlphaBay Takedown and Operation Bayonet (2017) — International Proceedings

**Date Decided:** July 2017 (takedown); subsequent proceedings

**Court:** US District Court for the Eastern District of California; Multiple jurisdictions

**Facts:** AlphaBay was the largest dark web marketplace at its takedown in July 2017, with over 400,000 users and approximately $1 billion in transactions. Canadian national Alexandre Cazes led the operation from Thailand. In Operation Bayonet, law enforcement from the US, Thailand, Netherlands, Lithuania, Canada, UK, and France seized the infrastructure. Cazes died by suicide in Thai custody. Simultaneously, Dutch and German authorities secretly took over Hansa Market for one month, gathering intelligence before shutting it down.

**Issue:** Criminal liability of dark web marketplace operators and legality of law enforcement covert operation of a criminal marketplace.

**Holding:** The takedown was one of the largest law enforcement operations against dark web markets. Intelligence from the Hansa covert operation led to numerous arrests worldwide.
**Significance:** Operation Bayonet model. Established a new model combining takedown with covert takeover for intelligence gathering.
Civil liberties concerns. The Hansa covert operation raised questions about entrapment and due process in online environments.
Marketplace resilience. Despite the takedown, new marketplaces quickly emerged, demonstrating dark web ecosystem resilience.

---

### Case 4.34: Hansa Market Covert Operation (2017) — Dutch Proceedings

**Date Decided:** June-July 2017 (covert operation)

**Court:** Dutch Public Prosecution Service

**Facts:** As part of Operation Bayonet, Dutch law enforcement secretly operated the Hansa Market for approximately one month (June 20 - July 20, 2017), gathering data on thousands of users and vendors. When AlphaBay users migrated to Hansa after that marketplace's takedown, they entered a law enforcement-controlled environment. The intelligence led to numerous international arrests and prosecutions.

**Issue:** Legality of law enforcement operation of a criminal marketplace and admissibility of evidence gathered.

**Holding:** The Dutch Public Prosecution Service defended the operation as lawful. Evidence was used in numerous prosecutions across multiple countries.
**Significance:** Law enforcement innovation. Represented a significant innovation in turning a criminal platform into an intelligence-gathering tool.
Evidence admissibility precedents. Established precedents for admissibility of evidence from covert law enforcement operation of criminal platforms.
Mass surveillance implications. Demonstrated the value — and potential civil liberties concerns — of large-scale data collection from dark web marketplaces.

---

### Case 4.35: Mafiaboy DDoS Attacks (2000) — Court of Quebec, Youth Division

**Date Decided:** January 18, 2001 (sentencing)

**Court:** Court of Quebec, Youth Division (Montreal)

**Facts:** In February 2000, 15-year-old Michael Calce ("Mafiaboy") launched DDoS attacks against Yahoo!, Amazon, CNN, eBay, and Dell, causing significant disruption and estimated losses in the hundreds of millions. He exploited a network of compromised university and corporate computers using relatively simple flooding techniques.

**Issue:** Criminal prosecution of a juvenile for conducting DDoS attacks against major commercial websites under Canadian law.

**Holding:** Calce pleaded guilty to 56 counts of mischief and illegal access. As a minor, he was sentenced to eight months in youth detention, one year of probation, a $1,000 fine, and computer use restrictions.
**Significance:** Juvenile cybercrime precedent. One of the earliest high-profile juvenile cybercrime prosecutions.
DDoS mainstream awareness. Brought DDoS into public consciousness and demonstrated vulnerability of major Internet companies.
Rehabilitation model. Calce subsequently became a cybersecurity consultant, representing a rehabilitation model for juvenile cyber offenders.

---

### Case 4.36: LulzSec Attacks (2011) — US District Court, C.D. California / S.D. New York

**Date Decided:** 2012-2014 (pleas and sentencings)

**Court:** US District Court for the Southern District of New York
Case citation: United States v. Monsegur, No. 12-cr-32 (S.D.N.Y.)

**Facts:** LulzSec (Lulz Security) conducted high-profile attacks in 2011 against Sony Pictures, the CIA, the US Senate, PBS, Fox, and gaming companies, combining DDoS with data breaches. The group claimed motivation of "lulz" (laughs) rather than financial gain. Key member Hector Xavier Monsegur ("Sabu") became an FBI informant after arrest.

**Issue:** Whether politically and ideologically motivated cyber attacks (hacktivism) constituted criminal offenses, and legal treatment of confidential informants.

**Holding:** Five core members were convicted. Monsegur, for extensive cooperation, received time served (seven months). Other members received sentences of one to ten years.
**Significance:** Hacktivism prosecution. Established that hacktivist attacks are subject to full criminal prosecution regardless of ideological motivation.
Informant effectiveness. Monsegur's cooperation demonstrated the effectiveness of turning insiders into informants in cybercrime investigations.
Anonymous disruption. The prosecutions significantly disrupted Anonymous and hacktivist networks.

---

### Case 4.37: Operation Payback DDoS Attacks (2010-2011) — Multiple Jurisdictions

**Date Decided:** 2010-2011 (attacks); subsequent prosecutions

**Court:** Multiple US District Courts; UK Crown Court

**Facts:** Anonymous launched Operation Payback in 2010, initially targeting anti-piracy organizations (MPAA, RIAA). The operation expanded to target financial institutions (Visa, MasterCard, PayPal) that suspended WikiLeaks services, using the Low Orbit Ion Cannon (LOIC) tool that allowed volunteers to participate with minimal technical skill.

**Issue:** Whether voluntary participation in a politically motivated DDoS attack constituted criminal conduct or legitimate digital protest.

**Holding:** Multiple participants were prosecuted in the US, UK, and other countries, receiving sentences from community service to two years in prison.
**Significance:** DDoS as protest debate. Raised the unresolved question of whether DDoS constitutes legitimate digital protest ("digital sit-in") or criminal conduct.
LOIC user culpability. Raised questions about culpability of individuals using simple tools without understanding legal consequences.
Online mobilization. Demonstrated the ability of online communities to mobilize rapidly for political cyber actions.

---

### Case 4.38: United States v. Gonzalez — TJ Maxx Data Breach (2010) — US District Court, D. Massachusetts

**Date Decided:** March 25, 2010 (sentencing)

**Court:** US District Court for the District of Massachusetts
Case citation: United States v. Gonzalez, No. 08-cr-10223 (D. Mass.)

**Facts:** Albert Gonzalez, a former Secret Service informant, masterminded the theft of approximately 170 million credit and debit card numbers from retailers including TJ Maxx, Heartland Payment Systems, and Barnes & Noble (2005-2007). Using wardriving and SQL injection, his group earned approximately $2.8 million and Gonzalez buried $1.1 million in cash in his parents' backyard.

**Issue:** Whether the massive credit card theft constituted wire fraud, computer fraud, aggravated identity theft, and conspiracy, and appropriate sentencing.

**Holding:** Gonzalez pleaded guilty and was sentenced to 20 years in federal prison — the longest sentence ever imposed in a US cybercrime case at the time.
**Significance:** Record sentence. The 20-year sentence set a benchmark for cybercrime sentencing and demonstrated courts' willingness to impose severe penalties for large-scale data theft.
Insider betrayal. Gonzalez's status as a former Secret Service informant highlighted the trust vulnerabilities in law enforcement cooperative arrangements.
PCI DSS impact. The breach significantly influenced the development and enforcement of Payment Card Industry Data Security Standards (PCI DSS).

---

### Case 4.39: United States v. Target Breach Related Prosecutions (2015) — US District Court, D. Minnesota

**Date Decided:** 2015 (indictment); subsequent proceedings

**Court:** US District Court for the District of Minnesota

**Facts:** In December 2013, attackers stole credit and debit card information of approximately 40 million Target customers and personal information of approximately 70 million customers by compromising a third-party HVAC vendor's credentials to gain access to Target's network. The breach cost Target an estimated $162 million and led to the resignation of its CEO and CIO. The attack was attributed to Russian and Ukrainian hackers.

**Issue:** The legal responsibility for a data breach resulting from supply-chain compromise through a third-party vendor, and the adequacy of retailer cybersecurity practices.

**Holding:** Target agreed to a $10 million class-action settlement and paid $18.5 million to 47 states and the District of Columbia. The FTC and state AGs brought enforcement actions. The breach led to significant changes in retail cybersecurity practices, including accelerated adoption of EMV chip cards.
**Significance:** Supply-chain compromise. The breach demonstrated that large retailers could be compromised through the weakest link in their supply chain — a HVAC vendor.
Executive accountability. The CEO and CIO resignations demonstrated that data breaches can have career-ending consequences for senior executives.
EMV adoption. The breach was a major catalyst for the US transition from magnetic stripe to EMV chip cards.

---

### Case 4.40: Home Depot Data Breach (2014) — Multiple Proceedings

**Date Decided:** September 2014 (disclosure); subsequent litigation

**Court:** US District Court for the Northern District of Georgia; Multiple state courts

**Facts:** In September 2014, Home Depot disclosed a breach that compromised payment card information of approximately 56 million customers, using custom-built malware that had been deployed on self-checkout systems in the US and Canada. The attack method was similar to the Target breach, exploiting vendor credentials to gain network access. Total costs were estimated at $179 million.

**Issue:** Legal liability for a retail breach following a similar breach at another major retailer, raising questions about whether Home Depot failed to learn from Target's experience.

**Holding:** Home Depot agreed to a $19.5 million settlement with 50 states and territories, plus a $13 million class-action settlement. The company invested approximately $200 million in cybersecurity improvements.
**Significance:** Industry-wide lessons. The similar attack methodology to the Target breach highlighted the systemic nature of retail cybersecurity vulnerabilities.
Regulatory enforcement. State AG settlements established enforcement benchmarks for retail cybersecurity.
Security investment precedent. Home Depot's $200 million security investment demonstrated the economic case for proactive cybersecurity spending.

---

### Case 4.41: United States v. Manning — Chelsea Manning / Wikileaks (2013) — US District Court, E.D. Virginia

**Date Decided:** August 21, 2013 (sentencing); January 2017 (commutation)

**Court:** US District Court for the Eastern District of Virginia (Court-Martial: United States v. Manning, Court-Martial Docket No. 20120312)

**Facts:** Chelsea Manning (then Bradley Manning), an US Army intelligence analyst, leaked approximately 750,000 classified and sensitive documents to WikiLeaks in 2010, including military field reports from Iraq and Afghanistan (the "Iraq War Logs" and "Afghan War Logs"), State Department diplomatic cables ( Cablegate"), and Guantanamo Bay detainee assessments. Manning accessed the documents using her authorized clearance on SIPRNet (Secret Internet Protocol Router Network).

**Issue:** Whether the unauthorized disclosure of classified military and diplomatic documents to a public website constituted violations of the Espionage Act and the Uniform Code of Military Justice (UCMJ).

**Holding:** Manning was convicted of 20 counts under the UCMJ, including violations of the Espionage Act, and sentenced to 35 years in prison. In January 2017, President Obama commuted Manning's sentence to time served (approximately seven years), and she was released in May 2017.
**Significance:** Espionage Act precedent. The prosecution established the use of the Espionage Act against government insiders who leak classified information to the public, not to foreign adversaries.
Whistleblower debate. Manning's case became a focal point for the debate over whether government leakers are whistleblowers or criminals, with no clear legal framework for distinguishing between the two.
Presidential commutation. Obama's commutation was controversial, with supporters arguing it was a correction of an excessive sentence and critics arguing it encouraged future leaks of classified information.

---

### Case 4.42: United States v. Snowden — Legal Consequences (2013) — Multiple Jurisdictions

**Date Decided:** June 2013 (disclosure); ongoing

**Court:** US District Court for the Eastern District of Virginia (sealed charges); European Court of Human Rights (related proceedings)
Case citation: United States v. Snowden, No. 1:13-cr-242 (E.D. Va.) (sealed)

**Facts:** Edward Snowden, a former contractor for the NSA, leaked classified documents to journalists in June 2013 revealing the scope of US government global surveillance programs, including the PRISM program (direct access to servers of major Internet companies), bulk telephone metadata collection, and foreign intelligence surveillance operations. Snowden fled to Hong Kong and then Russia, where he was granted asylum. The US government unsealed criminal charges against him.

**Issue:** The legal consequences for a government contractor who discloses classified surveillance programs to the press, and the adequacy of whistleblower protection frameworks for national security leakers.

**Holding:** The DOJ filed a criminal complaint charging Snowden with theft of government property, unauthorized communication of national defense information, and willful communication of classified communications intelligence — charges carrying a maximum of 30 years in prison. Snowden remains in exile in Russia and has not returned to the US. He has not been extradited. The European Court of Human Rights ruled in 2020 that the UK's detention of David Miranda (Glenn Greenwald's partner, carrying Snowden documents) was lawful but disproportionate.
**Significance:** Whistleblower vs. criminal. Snowden's case intensified the global debate over whether national security leakers deserve whistleblower protections or criminal prosecution.
Surveillance reform. The disclosures led directly to the USA Freedom Act of 2015, which reformed bulk telephone metadata collection — a significant legislative consequence of an unauthorized disclosure.
Asylum precedent. Snowden's exile in Russia demonstrated the challenges of international criminal prosecution when the defendant obtains asylum in a non-cooperating jurisdiction.

---

### Case 4.43: United States v. Winner — Reality Winner (2018) — US District Court, S.D. Georgia

**Date Decided:** June 2018 (sentencing)

**Court:** US District Court for the Southern District of Georgia
Case citation: United States v. Winner, No. 17-cr-70 (S.D. Ga.)

**Facts:** Reality Winner, a former US Air Force intelligence specialist and NSA contractor, leaked a classified intelligence report about Russian interference in the 2016 US presidential election to the news site The Intercept in May 2017. The report documented Russian military intelligence's efforts to penetrate US state and local election boards. The Intercept published the report and shared it with the government for verification, inadvertently revealing identifying information. Winner was arrested within days.

**Issue:** Whether the unauthorized disclosure of a classified intelligence report to a news organization constituted violations of the Espionage Act.

**Holding:** Winner pleaded guilty to one count of violating the Espionage Act and was sentenced to five years and three months in prison — the longest sentence ever imposed for unauthorized disclosure of classified information to the media.
**Significance:** Espionage Act severity. The sentence demonstrated the severity with which the Espionage Act is applied, even when the disclosed information concerns foreign interference in US elections — a matter of public interest.
The Intercept handling. The case highlighted the risks that journalists face when sharing classified documents with the government for verification, as The Intercept's actions inadvertently led to Winner's identification.
First-time leaker precedent. The sentence, imposed on a young first-time offender, was seen by some as disproportionately harsh and raised questions about the adequacy of whistleblower protections for national security employees.

---

### Case 4.44: Juvenile Cybercrime — United States v. Minor Defendant (LAPSUS$) (2022-2024) — US District Court, S.D. New York

**Date Decided:** 2022-2024 (proceedings)

**Court:** US District Court for the Southern District of New York

**Facts:** LAPSUS$, a cyber extortion group that attacked major technology companies including Microsoft, NVIDIA, Okta, Uber, and Rockstar Games in 2022, was led in significant part by minors. In March 2022, a 17-year-old from Oxfordshire, UK (identified as "K" due to reporting restrictions) was arrested in connection with the attacks. Another minor in the US was also charged. The group used relatively simple techniques including social engineering, SIM swapping, and purchasing credentials from dark web forums to gain access to corporate systems, then demanded ransom under threat of releasing stolen data.

**Issue:** The appropriate legal framework for prosecuting minors who conduct sophisticated cyber attacks against major corporations, including questions of juvenile jurisdiction, competency, and rehabilitation.

**Holding:** The UK teenager was charged with multiple offenses under the Computer Misuse Act and related laws. In the US, juvenile proceedings were initiated, with debates over whether to charge the minor as an adult. The UK case was handled in youth court.
**Significance:** Minor-led organized crime. LAPSUS$ demonstrated that minors can lead sophisticated cyber extortion operations targeting Fortune 500 companies, challenging assumptions about the technical capacity of young offenders.
Juvenile justice framework. The case exposed gaps in juvenile justice systems' ability to handle serious cybercrime committed by minors, where existing frameworks may not adequately balance accountability with rehabilitation.
Low-tech sophistication. The group's success using relatively simple techniques (social engineering, credential purchasing) demonstrated that sophisticated attacks do not always require advanced technical skills — a concerning trend for corporate security.

---

### Case 4.45: Operation Cronos — LockBit Takedown (2024) — International Law Enforcement (NCA, FBI, Europol)
**Court:** International Law Enforcement (NCA, FBI, Europol)

**Date Decided:** February 2024 (Operation Cronos announced)
Court/Prosecutor: UK National Crime Agency, US FBI, Europol (multi-jurisdictional)
Case citation: N/A (law enforcement operation; unsealed indictments in US District Court, D. New Jersey)

**Facts:** In February 2024, Operation Cronos — a coordinated international operation involving law enforcement agencies from 10+ countries — seized LockBit's infrastructure, including 34 servers, arrested two individuals in Poland and Ukraine, and seized cryptocurrency wallets. LockBit had been the most prolific ransomware-as-a-service (RaaS) operation globally, responsible for attacks on thousands of victims and extracting over $120 million in ransom payments since 2020. The operation also compromised LockBit's leak site on the dark web and published information about the group's affiliates.

**Issue:** Whether a coordinated international law enforcement operation could effectively dismantle a decentralized ransomware-as-a-service network and hold its administrator accountable.

**Holding:** LockBit's infrastructure was seized; the administrator ("LockBitSupp," believed to be Dmitry Khoroshev) was charged by the DOJ. The operation disrupted LockBit's operations temporarily, though the group partially reconstituted its infrastructure weeks later. Sanctions were imposed by the US Treasury on Khoroshev and affiliated individuals.
**Significance:** Largest ransomware takedown. Operation Cronos represented the most significant law enforcement action against a ransomware group to date, demonstrating unprecedented international cooperation.
Naming and shaming. The public disclosure of LockBit's affiliate list and operational details represented a novel deterrence strategy aimed at disrupting trust-based relationships within RaaS ecosystems.
Resilience challenge. LockBit's partial recovery underscored the difficulty of permanently dismantling decentralized cybercriminal networks.

---

### Case 4.46: United States v. ALPHV/BlackCat Ransomware Administrator (2023–2024) — US District Court

**Date Decided:** December 2023 (indictment unsealed); 2024 (ongoing)

**Court:** US District Court for the Southern District of New York
Case citation: Unsealed indictment (USA v. Unnamed Defendants)

**Facts:** ALPHV/BlackCat was the first major ransomware-as-a-service operation built on the Rust programming language, enabling cross-platform targeting of Windows, Linux, and macOS systems. Operating since November 2021, BlackCat affiliates attacked over 1,000 victims globally, including critical infrastructure, extracting over $300 million in ransom. In December 2023, the FBI seized BlackCat's website and posted a seizure banner, then covertly infiltrated the ransomware group's network for several weeks. The group's administrator subsequently conducted a suspected exit scam in March 2024 and disappeared with affiliate funds.

**Issue:** Whether law enforcement could lawfully seize and covertly operate a ransomware group's infrastructure as an investigative technique.

**Holding:** The FBI operation recovered over 946 decryption keys and facilitated victim recovery. Indictments were unsealed against key operators. The alleged administrator's exit scam fractured the RaaS ecosystem.
**Significance:** Covert infrastructure seizure. The FBI's covert operation marked a novel expansion of law enforcement tactics, raising questions about entrapment and due process.
Rust-based ransomware. BlackCat's use of Rust demonstrated increasing ransomware sophistication with cross-platform attack capability.
Exit scam precedent. The administrator's exit scam illustrated the inherent instability of criminal ecosystems built on trust between anonymous participants.

---

### Case 4.47: CLOP MOVEit Mass Exploitation Campaign (2023) — Multi-Jurisdictional Prosecution

**Date Decided:** June 2023 (campaign discovered); ongoing prosecutions

**Court:** Multi-jurisdictional (US DOJ, UK NCA, Canadian authorities)
Case citation: Various indictments (DOJ announcements June–December 2023)

**Facts:** In May 2023, the Clop ransomware group exploited a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer platform. The exploitation affected over 2,500 organizations and 67 million individuals, including government agencies (US Department of Energy), BBC, British Airways, Shell, and Ernst & Young. Clop adopted a data-theft-without-encryption approach, exfiltrating data and demanding ransom without deploying ransomware.

**Issue:** Whether mass exploitation of a single software vulnerability affecting thousands of downstream victims constituted a single criminal enterprise or multiple separate offenses across jurisdictions.

**Holding:** Clop was indicted by the DOJ. Progress Software patched the vulnerability within days. Multiple class-action lawsuits were filed. The incident triggered renewed scrutiny of software supply chain security.
**Significance:** Supply chain scale. The MOVEit incident became the largest data breach of 2023 by victim count, demonstrating cascading impact from a single vulnerability.
Extortion without encryption. Clop's approach complicated incident response and legal categorization, as no ransomware was deployed.
Regulatory cascading effect. The incident triggered notification obligations under GDPR, US state breach notification laws, and other frameworks simultaneously across dozens of jurisdictions.

---

### Case 4.48: Royal/BlackSuit Ransomware Attacks (2023–2024) — US Department of Justice
**Court:** U.S. Department of Justice

**Date Decided:** 2024 (FBI flash alert); ongoing
Court/Prosecutor: US Department of Justice, FBI
Case citation: FBI FLASH CU-000168-MW (December 2023)

**Facts:** Royal ransomware (later rebranded as BlackSuit) emerged in 2022 as a spinoff from Conti following Conti's dissolution. The group targeted over 350 victims across healthcare, education, manufacturing, and government, demanding ransoms from $1 million to over $10 million. Notable victims included the City of Dallas (May 2023) and the British Library.

**Issue:** Whether ransomware groups that rebrand after law enforcement disruption can be prosecuted as continuations of the same criminal enterprise.

**Holding:** FBI issued emergency alerts. US and international law enforcement conducted disruption operations. Indictments were filed against affiliated actors in Eastern Europe.
**Significance:** Conti lineage. The case demonstrated ransomware group resilience through rebranding, preserving institutional knowledge and affiliate networks.
Municipal impact. The City of Dallas attack highlighted vulnerability of local government systems to ransomware.
Cultural institution targeting. The British Library attack demonstrated ransomware's reach into cultural heritage institutions.

---

### Case 4.49: Akira Ransomware Campaign (2023–2024) — Multi-Jurisdictional
**Court:** Multi-Jurisdictional

**Date Decided:** 2023–2024 (ongoing investigations)
Court/Prosecutor: FBI, CISA, Europol, Japanese National Police Agency
Case citation: FBI Alert AA-23-315A (August 2023)

**Facts:** Akira ransomware, first identified in March 2023, targeted small and medium-sized businesses in professional services, healthcare, and education, claiming over 250 victims globally by 2024. Akira employed a double-extortion model and specifically targeted Cisco VPN products with compromised credentials. The group also developed a Linux variant targeting VMware ESXi servers.

**Issue:** Whether SMB-targeted ransomware campaigns warrant the same law enforcement prioritization as campaigns targeting large enterprises.

**Holding:** Multi-agency advisories were issued. Law enforcement disrupted Akira's infrastructure in 2024. The group's affiliation network was partially mapped.
**Significance:** SMB targeting. Akira's focus on SMBs highlighted an underserved vulnerability, as SMBs often lack dedicated security resources.
VMware ESXi targeting. The Linux/ESXi variant represented the growing trend of targeting virtualization infrastructure.
Credential-based access. Akira's reliance on compromised VPN credentials underscored the failure to implement multi-factor authentication.

---

### Case 4.50: Rhysida Ransomware and British Library Attack (2023) — UK National Crime Agency

**Date Decided:** October 2023 (attack); ongoing investigation
Court/Prosecutor: UK National Crime Agency
Case citation: NCA investigation ongoing

**Facts:** In October 2023, Rhysida ransomware attacked the British Library, exfiltrating approximately 600 GB of data including personal information, HR records, and digitized collections data. Rhysida demanded 20 bitcoin (approximately 600,000). When the Library refused to pay, Rhysida published stolen data on its dark web leak site. The group also targeted healthcare institutions in Chile and the US.

**Issue:** The legal and ethical implications of ransomware attacks on cultural heritage institutions.

**Holding:** The British Library declined to pay and undertook extensive recovery operations. The NCA launched a criminal investigation. Services were partially restored over several months.
**Significance:** Cultural heritage as target. The attack raised questions about whether such attacks could constitute violations of international cultural property protections.
Recovery without payment. The Library's recovery served as a case study in institutional resilience, though recovery costs exceeded ransom demands.
Irreversible data loss risk. The exfiltration of digitized historical materials raised concerns about irreversibility of data loss for irreplaceable artifacts.

---

### Case 4.51: Medibank Australia Data Breach (2022) — Federal Court of Australia

**Date Decided:** 2022–2024 (regulatory proceedings)

**Court:** Federal Court of Australia
Case citation: Australian Information Commissioner v. Medibank Private Ltd [2024] FCA (proceeding)

**Facts:** In October 2022, Medibank, Australia's largest health insurer (4 million customers), suffered a major data breach. A threat actor linked to REvil exfiltrated personal information, medical claims data (including mental health and reproductive health records), and passport numbers. Medibank refused the $10 million ransom demand, and the attacker published stolen data on the dark web.

**Issue:** Whether Medibank's cybersecurity measures were adequate under the Privacy Act 1988 (Cth).

**Holding:** The Australian Information Commissioner initiated Federal Court proceedings seeking penalties of up to AUD $50 million per contravention. Medibank incurred remediation costs exceeding AUD $50 million.
**Significance:** Health data sensitivity. The public release of sensitive medical information demonstrated the particular harm of health data exposure.
Regulatory enforcement. The Commissioner's action demonstrated willingness to pursue major penalties for inadequate cybersecurity.
No-ransom stance. Medibank's refusal aligned with Australian government policy discouraging ransom payments.

---

### Case 4.52: Optus Australia Data Breach (2022) — Australian Federal Police / Federal Court of Australia

**Date Decided:** September 2022 (breach); 2023–2024 (regulatory proceedings)

**Court:** Federal Court of Australia
Case citation: Australian Information Commissioner v. Singtel Optus Pty Ltd [2024] FCA (proceeding)

**Facts:** In September 2022, Optus suffered a data breach affecting approximately 9.7 million current and former customers — nearly 40% of Australia's population. An API vulnerability exposed names, dates of birth, contact details, and for some customers passport, driver's license, and Medicare numbers. An individual subsequently attempted to extort Optus for $1 million in cryptocurrency.

**Issue:** Whether Optus's collection of identity document numbers was reasonably necessary and whether cybersecurity measures were adequate.

**Holding:** The Australian Information Commissioner initiated enforcement action. The breach catalyzed the Privacy Legislation Amendment Act 2022, which increased maximum penalties for serious privacy breaches.
**Significance:** National-scale impact. The breach affected nearly 40% of Australia's population, one of the largest by victim count relative to national population.
Legislative reform driver. The breach catalyzed significant amendments to Australian privacy law.
Data minimization. The breach reignited the data minimization principle regarding telecommunications companies retaining identity document copies.

---

### Case 4.53: APT29/Cozy Bear — SolarWinds Orion Supply Chain Attack (2020–2024) — US Department of Justice
**Court:** U.S. Department of Justice

**Date Decided:** 2020 (discovery); 2021 (indictment); 2024 (further attributions)
Court/Prosecutor: US Department of Justice
Case citation: United States v. Andrienko et al., No. 21-cr-199 (S.D.N.Y.)

**Facts:** APT29 (Cozy Bear), a Russian SVR cyber espionage unit, compromised SolarWinds' build environment and inserted the SUNBURST backdoor into Orion platform updates distributed to approximately 18,000 organizations. At least 9 US federal agencies and hundreds of private sector organizations were compromised. The intrusion went undetected for approximately 9 months. In 2024, additional APT29 intrusions targeting Microsoft corporate systems were disclosed.

**Issue:** Whether a state-sponsored supply chain compromise constitutes an act of espionage, an act of aggression, or a violation of international law.

**Holding:** The DOJ indicted five Russian SVR officers. Sanctions were imposed. NATO attributed the attack to Russia. The 2024 Microsoft disclosure revealed persistent access to executive email accounts.
**Significance:** Supply chain paradigm shift. The attack fundamentally changed supply chain security, spawning Executive Order 14028 and new regulations.
Attribution complexity. The case demonstrated both increasing attribution capability and the limitations of criminal prosecution against state-sponsored espionage.
Persistent threat. The 2024 Microsoft disclosure showed the difficulty of fully remediating sophisticated supply chain compromises.

---

### Case 4.54: Hafnium — Microsoft Exchange Server Exploitation (2021) — US Department of Justice
**Court:** U.S. Department of Justice

**Date Decided:** March 2021 (disclosure)
Court/Prosecutor: US Department of Justice, FBI
Case citation: Microsoft MSTIC report; FBI advisories

**Facts:** In March 2021, Microsoft disclosed that a Chinese state-sponsored group codenamed "Hafnium" exploited four zero-day vulnerabilities in Microsoft Exchange Server (ProxyLogon). An estimated 30,000 organizations in the US and over 100,000 globally were affected, including local governments, universities, and hospitals. The FBI conducted an operation to remove web shells from compromised servers without prior notification.

**Issue:** The legal responsibility of software vendors for zero-day vulnerabilities exploited at scale.

**Holding:** Microsoft issued emergency patches. The FBI removed web shells from private servers without owner consent. Attribution was made to Chinese state-sponsored actors.
**Significance:** Patch gap crisis. Thousands of organizations remained compromised weeks after patches were available.
FBI remediation. Remote web shell removal without consent raised novel Fourth Amendment questions.
State-on-private targeting. The massive targeting of private organizations blurred the line between espionage and cybercrime.

---

### Case 4.55: Volt Typhoon — Chinese Prepositioning in US Critical Infrastructure (2023–2024) — US DOJ / CISA
**Court:** U.S. Department of Justice / CISA

**Date Decided:** May 2023 (CISA advisory); September 2024 (DOJ disruption)
Court/Prosecutor: US Department of Justice, FBI, CISA
Case citation: United States v. Yin Kecheng et al., No. 24-mj-0232 (D. Haw.)

**Facts:** Chinese state-sponsored campaign Volt Typhoon targeted US critical infrastructure including water plants, electric grids, and transportation systems since at least 2021, focusing on prepositioning for potential future conflict. In September 2024, the DOJ disrupted a Volt Typhoon botnet of hundreds of compromised SOHO routers. The related Salt Typhoon campaign targeting AT&T, Verizon, and T-Mobile — potentially compromising court-authorized wiretap systems — was disclosed in late 2024.

**Issue:** Whether prepositioning of cyber capabilities in civilian critical infrastructure constitutes an act of aggression under international law.

**Holding:** The DOJ obtained court orders to remove malware from compromised routers. Indictments were filed against Chinese nationals. The Salt Typhoon disclosure raised stakes significantly.
**Significance:** Prepositioning doctrine. The case established prepositioning as a distinct category of state-sponsored cyber activity, challenging international law and deterrence theory.
Critical infrastructure vulnerability. The compromise of telecommunications wiretap systems (Salt Typhoon) threatened US law enforcement capabilities.
Peacetime escalation. The case illustrated the challenge of responding to gray-zone state-sponsored cyber activity.

---

### Case 4.56: Iranian Cyber Operations — Critical Infrastructure Attacks (2022–2024) — US Department of Justice
**Court:** U.S. Department of Justice

**Date Decided:** 2022–2024 (multiple operations)
Court/Prosecutor: US Department of Justice, FBI
Case citation: Various DOJ announcements and indictments

**Facts:** Iranian state-sponsored actors conducted multiple campaigns: targeting Boston Children's Hospital with ransomware (2022), attacks on US water authorities by "Cyber Av3ngers" (2023), and phishing campaigns against defense contractors. Albania severed diplomatic relations with Iran over a 2022 destructive wiper attack on Albanian government systems.

**Issue:** Whether Iranian state-sponsored attacks on civilian infrastructure constitute violations of international humanitarian law.

**Holding:** The DOJ unsealed indictments against multiple Iranian nationals. Sanctions were imposed. Albania severed diplomatic relations with Iran — a rare and significant diplomatic response.
**Significance:** Hospital targeting. The targeting of Boston Children's Hospital demonstrated indiscriminate nature of some state-sponsored attacks.
Ideological targeting. Cyber Av3ngers blended hacktivism with state-sponsored capability.
Diplomatic consequences. Albania's severing of diplomatic relations over a cyber attack was unprecedented.

---

### Case 4.57: Russian Sandworm — NotPetya and Ukraine Power Grid (2015–2024) — US Department of Justice
**Court:** U.S. Department of Justice

**Date Decided:** 2015–2016 (attacks); 2020 (indictment)
Court/Prosecutor: US Department of Justice
Case citation: United States v. Andrienko et al., No. 20-cr-197 (E.D. Pa.)

**Facts:** Russian GRU Unit 74455 (Sandworm) conducted multiple destructive operations: the December 2015 Ukraine power outage (230,000 customers), the June 2017 NotPetya wiper (over $10 billion in global damage to Maersk, Merck, Mondelez, and others), the 2018 Olympic Destroyer attack, and COVID-19 vaccine research theft.

**Issue:** Whether NotPetya constituted a use of force under Article 2(4) of the UN Charter.

**Holding:** The DOJ indicted six GRU officers. NATO collectively attributed NotPetya to Russia. The EU imposed sanctions. The case contributed to the Tallinn Manual 2.0 framework.
**Significance:** Destructive scale. NotPetya was the most destructive cyber attack in history by financial impact ($10+ billion).
Collective attribution. Multi-country attribution established new standards for collective cyber operation attribution.
Collateral damage. NotPetya's spread beyond intended targets raised fundamental proportionality questions in cyber warfare.

---

### Case 4.58: Google & Meta Authorized Push Payment Fraud (2019–2023) — Multi-Jurisdictional

**Date Decided:** 2019–2023 (various proceedings)
Court/Prosecutor: US DOJ; UK Financial Conduct Authority; European regulators
Case citation: DOJ announcements; FCA enforcement notices

**Facts:** Organized criminal groups conducted authorized push payment (APP) fraud campaigns impersonating Google and Meta advertising platforms, tricking businesses into transferring payments to criminal accounts. Total losses exceeded $1 billion globally. Litigation was initiated against Google and Meta for allegedly failing to adequately verify advertisers.

**Issue:** Whether platforms bear legal liability for enabling APP fraud through inadequate advertisement verification.

**Holding:** The US DOJ prosecuted multiple criminal networks. The UK implemented mandatory APP fraud reimbursement requirements (October 2024). Civil litigation against Google and Meta continued.
**Significance:** Platform liability. The cases pushed boundaries of platform liability for fraudulent advertising content.
APP fraud regulation. The UK's mandatory reimbursement scheme was the world's first comprehensive regulatory framework.
Scale. Combined losses highlighted APP fraud as one of the fastest-growing financial crime categories.

---

### Case 4.59: BEC Prosecution — United Kingdom (2022–2024) — Southwark Crown Court / NCA

**Date Decided:** 2022–2024 (various prosecutions)

**Court:** Southwark Crown Court, London
Case citation: R v. [Various Defendants]

**Facts:** The NCA and City of London Police prosecuted BEC fraud networks operating from the UK and West Africa. In one representative case, a network based in London and Lagos conducted BEC schemes targeting UK businesses, resulting in losses exceeding 15 million over three years. The NCA's 2023 operation arrested 15 individuals and seized 3.2 million.

**Issue:** Whether BEC facilitators (money mules, laundering networks) could be prosecuted as principals.

**Holding:** Defendants were convicted of conspiracy to commit fraud and money laundering. Sentences ranged from 3 to 12 years. Asset confiscation orders were issued under POCA 2002.
**Significance:** Supply chain prosecution. The NCA's approach of prosecuting the entire BEC supply chain established a model for comprehensive disruption.
International cooperation. Effective UK-Nigeria cooperation demonstrated progress in overcoming jurisdictional barriers.
POCA confiscation. Confiscation orders demonstrated the UK's ability to recover cybercrime proceeds internationally.

---

### Case 4.60: Terpin v. Ellis — SIM Swap Fraud ($22 Million) (2023) — US District Court, C.D. California

**Date Decided:** August 2023 (jury verdict)

**Court:** US District Court for the Central District of California
Case citation: Terpin v. Ellis, No. 18-cv-07612 (C.D. Cal.)

**Facts:** Michael Terpin sued for $22 million in SIM swap fraud losses. In January 2018, Nicholas Truglia and co-conspirators fraudulently transferred Terpin's mobile number, bypassed two-factor authentication, and stole approximately $24 million in cryptocurrency. Terpin also sued AT&T for negligence. Truglia was convicted in New York and sentenced to 18 months. Terpin's separate negligence case against AT&T resulted in a $75.8 million arbitration award.

**Issue:** Whether AT&T owed a duty of care to prevent unauthorized SIM swaps.

**Holding:** Jury verdict for Terpin; Truglia convicted; AT&T arbitration award of $75.8 million (later reduced).
**Significance:** Carrier liability. The case established that carriers may face significant liability for failing to prevent SIM swaps.
Cryptocurrency recovery difficulty. The case highlighted inadequacy of legal frameworks for cryptocurrency theft victim remedies.
SMS 2FA insecurity. The incident accelerated the shift from SMS-based to hardware-based two-factor authentication.

---

### Case 4.61: United States v. Shane Hopkins — SIM Hijacking (2020) — US District Court, N.D. Ohio

**Date Decided:** 2020 (sentencing)

**Court:** US District Court for the Northern District of Ohio
Case citation: United States v. Hopkins, No. 19-cr-0281 (N.D. Ohio)

**Facts:** Shane Hopkins (21) participated in a SIM hijacking ring targeting cryptocurrency investors. The group used social engineering to port victims' phone numbers and stole over $5 million in cryptocurrency, which Hopkins used to purchase luxury items including a Porsche.

**Issue:** Whether SIM hijacking for cryptocurrency theft constituted wire fraud and identity theft.

**Holding:** Hopkins pleaded guilty to conspiracy to commit wire fraud, sentenced to 5 years, and ordered to pay $5.2 million restitution.
**Significance:** Youthful offender pattern. The case highlighted technically capable young adults engaging in high-value cryptocurrency crime.
Restitution adequacy. The order was unlikely to fully compensate victims given difficulty of recovering dissipated cryptocurrency.
Carrier cooperation. Demonstrated increasing carrier-law enforcement cooperation in combating SIM swap fraud.

---

### Case 4.62: United States v. Ellis Pinsky — Teenage SIM Swapper (2020) — US District Court, S.D. New York

**Date Decided:** 2020 (arrest); 2023 (proceedings)

**Court:** US District Court for the Southern District of New York
Case citation: United States v. Pinsky, No. 20-mj-04068 (S.D.N.Y.)

**Facts:** Ellis Pinsky, arrested at 18 in 2020, was accused of conducting a SIM swapping scheme beginning at age 15 that stole over $1 million in cryptocurrency. He worked with co-conspirators via Discord and Telegram. The prosecution was handled through juvenile proceedings.

**Issue:** Appropriate legal framework for prosecuting a minor who engaged in sophisticated financial cybercrime at age 15.

**Holding:** Charged as a juvenile; entered a deferred prosecution agreement with restitution obligations and supervised release.
**Significance:** Juvenile cybercrime. Highlighted growing phenomenon of minors in financially motivated cybercrime facilitated by online communities.
Rehabilitation priority. The juvenile disposition reflected rehabilitation over incarceration.
Mainstream platform as criminal infrastructure. Discord and Telegram served as coordination platforms for criminal activity.

---

### Case 4.63: United States v. Ilya Lichtenstein & Heather Morgan — Bitfinex Bitcoin Laundering (2022–2024) — US District Court, D. Columbia

**Date Decided:** February 2022 (arrest); 2024 (sentencing)

**Court:** US District Court for the District of Columbia
Case citation: United States v. Lichtenstein, No. 22-cr-00083 (D.D.C.)

**Facts:** Ilya Lichtenstein and Heather Morgan (dubbed "Crypto Wall Street Couple") were arrested for laundering approximately 119,754 bitcoin stolen from Bitfinex in 2016. At seizure, the bitcoin was valued at approximately $4.5 billion — the largest financial seizure in DOJ history. Lichtenstein used darknet markets, shell companies, and mixing services. Morgan assisted with laundering and maintained false records.

**Issue:** Whether Morgan's role was sufficient for conviction, and the legal status of cryptocurrency mixing services.

**Holding:** Both pleaded guilty. Each sentenced to 18 months (below the government's 5-year recommendation). The full $4.5 billion was seized and forfeited.
**Significance:** Largest DOJ seizure. The $4.5 billion seizure demonstrated law enforcement's growing cryptocurrency tracing capability.
Below-guidelines sentences. Lenient sentences reflected cooperation credit.
Mixer tool ambiguity. Raised questions about legality of cryptocurrency mixing services.

---

### Case 4.64: North Korea — Lazarus Group Cryptocurrency Theft (2016–2024) — US DOJ / UN Security Council
**Court:** U.S. Department of Justice / UN Security Council

**Date Decided:** 2016–2024 (ongoing operations)
Court/Prosecutor: US Department of Justice; United Nations Security Council
Case citation: Various DOJ indictments; UNSC Resolution 1718 and subsequent

**Facts:** The Lazarus Group (APT38), a unit of North Korea's Reconnaissance General Bureau, stole over $3 billion in cryptocurrency between 2016 and 2024. Notable operations included the 2016 Bangladesh Bank heist ($81M), the 2017 WannaCry ransomware, the 2022 Ronin Network hack ($625M), and the 2023 CoinEx hack ($70M). Funds are believed to finance North Korea's nuclear weapons program.

**Issue:** Whether North Korean cryptocurrency theft constitutes a violation of international law and whether intermediary exchanges bear liability.

**Holding:** The DOJ indicted multiple North Korean nationals. Treasury sanctioned cryptocurrency addresses and exchanges. Most stolen funds remain unrecovered.
**Significance:** State-sponsored crypto crime. Lazarus represented a new model where cyber operations directly fund nuclear weapons programs.
DeFi vulnerability. The Ronin hack demonstrated extreme vulnerability of DeFi protocols to state-sponsored attacks.
Sanctions evasion. Highlighted cryptocurrency as a sanctions evasion tool challenging traditional financial sanctions.

---

### Case 4.65: KuCoin Cryptocurrency Exchange Hack (2020) — Singapore Police / Multi-Jurisdictional
**Court:** Singapore Police Force / Multi-Jurisdictional

**Date Decided:** September 2020 (hack)
Court/Prosecutor: Singapore Police Force; US DOJ (supporting)

**Facts:** KuCoin, headquartered in Singapore, suffered a hack of approximately $281 million in cryptocurrency. The attack was attributed to the North Korean Lazarus Group. KuCoin covered all losses from its insurance fund and resumed operations within weeks. Law enforcement traced and froze approximately $20 million.

**Issue:** Regulatory obligations of cryptocurrency exchanges and cross-border enforcement challenges.

**Holding:** KuCoin reimbursed all customers. Approximately $20 million was frozen. No criminal convictions resulted directly.
**Significance:** Exchange resilience. KuCoin's rapid recovery demonstrated maturation of exchange insurance and incident response.
Blockchain analytics effectiveness. Demonstrated effectiveness of blockchain analytics in tracing stolen funds across chains.
Attribution capability. Attribution to Lazarus Group by blockchain analytics firms illustrated maturation of crypto-domain attribution.

---

### Case 4.66: Carbanak/Ocean's 16 Bank Heist (2013–2018) — Multi-Jurisdictional
**Court:** Multi-Jurisdictional (Europol, FBI, Regional Banks)

**Date Decided:** 2015 (disclosure); 2018 (arrests)
Court/Prosecutor: Europol, Spanish National Police
Case citation: Spanish National Court proceedings

**Facts:** The Carbanak cybergang, believed based in Eastern Europe, targeted approximately 100 financial institutions in over 40 countries, stealing an estimated $1 billion. Techniques included spear-phishing, ATM jackpotting, and SWIFT message manipulation. In 2018, Spanish authorities arrested the suspected leader in Alicante.

**Issue:** Legal classification of large-scale cross-border bank hacking and appropriate jurisdiction.

**Holding:** The suspected leader arrested. Multiple accomplices arrested across Europe. Majority of stolen funds unrecovered.
**Significance:** $1 billion bank heist. Largest bank heist in history conducted entirely through cyber means.
ATM jackpotting. Bridged cyber and physical domains through forced ATM cash dispensing.
SWIFT manipulation. Demonstrated vulnerability of global financial infrastructure to cyber attacks.

---

### Case 4.67: Bangladesh Bank Heist (2016) — Federal Reserve / Bangladesh Bank
**Court:** Federal Reserve Bank of New York / Bangladesh Bank

**Date Decided:** February 2016 (heist)
Court/Prosecutor: US DOJ; Bangladeshi authorities; Philippines AMLC
Case citation: Various proceedings in Bangladesh, Philippines, and US

**Facts:** Hackers (attributed to Lazarus Group) compromised Bangladesh Bank's SWIFT credentials and attempted to transfer $1 billion from its Federal Reserve account. Five transactions ($101 million) succeeded before the Federal Reserve halted remaining requests. $81 million was laundered through Philippine casinos and largely disappeared.

**Issue:** Liability of correspondent banks for fraudulent transfers and adequacy of SWIFT security.

**Holding:** Bangladesh Bank sued the Federal Reserve. Philippines AMLC filed forfeiture proceedings. Attribution to Lazarus Group confirmed.
**Significance:** Central bank vulnerability. Demonstrated that even central banks are vulnerable to cyber attacks.
Casino money laundering. Exposed critical AML regulation gap in casino transactions.
SWIFT security overhaul. Catalyzed comprehensive SWIFT security reforms including mandatory two-factor authentication.

---

### Case 4.68: Cosmos Bank Cyber Heist (2018) — Pune City Police / RBI
**Court:** Pune City Police / Reserve Bank of India

**Date Decided:** August 2018 (heist)
Court/Prosecutor: Pune City Police; Reserve Bank of India
Case citation: Pune Police FIR; RBI investigation

**Facts:** Cosmos Bank, a cooperative bank in Pune, suffered a coordinated heist using malware injection into its ATM server switch. Approximately 94 crore ($13 million) was stolen through 14,849 fraudulent Visa and RuPay transactions across 28 countries in hours. A SWIFT transfer of 13.92 crore was also conducted. Linked to Lazarus Group.

**Issue:** Adequacy of cybersecurity standards for cooperative banks in India.

**Holding:** Pune police launched investigation. RBI issued cybersecurity directives to all cooperative banks. Cosmos Bank fully reimbursed customers.
**Significance:** Cooperative bank vulnerability. Exposed disproportionate vulnerability of cooperative banks with limited security resources.
Global ATM fraud scale. Simultaneous cloned card use across 28 countries demonstrated global reach.
Regulatory response. Prompted RBI to mandate cybersecurity compliance for all banks regardless of size.

---

### Case 4.69: LabCorp/Quest Diagnostics AMCA Data Breach (2019) — US DOJ / HHS OCR
**Court:** U.S. Department of Justice / HHS OCR

**Date Decided:** 2019 (disclosure)
Court/Prosecutor: US Department of Justice; HHS Office for Civil Rights
Case citation: HHS OCR investigation

**Facts:** In June 2019, the American Medical Collection Agency (AMCA), a third-party debt collector for LabCorp and Quest Diagnostics, suffered a breach affecting approximately 20 million patients. The breach exposed names, financial information, and lab test results. Quest reported 11.9 million affected patients; LabCorp reported 7.7 million. AMCA filed for bankruptcy.

**Issue:** Whether diagnostic laboratories' third-party vendors adequately protected PHI under HIPAA.

**Holding:** AMCA filed for bankruptcy. Labs terminated their relationship. HHS OCR investigated potential HIPAA violations. Multiple class-action lawsuits filed.
**Significance:** Vendor risk amplification. A single vendor compromise cascaded to millions of patients across multiple healthcare organizations.
Medical data sensitivity. Exposure of lab test results highlighted particular harm of medical data breaches.
Vendor bankruptcy. AMCA's bankruptcy demonstrated the weakest link may be least capable of providing remedy.

---

### Case 4.70: LifeLabs Canada Data Breach (2019) — Office of the Privacy Commissioner of Canada

**Date Decided:** December 2019 (disclosure); 2022 (report)
Court/Prosecutor: OPC; Office of the Information and Privacy Commissioner of British Columbia
Case citation: OPC Investigation Report PIPEDA Case Summary #2019-003

**Facts:** LifeLabs, Canada's largest diagnostic services provider, disclosed a breach affecting approximately 15 million customers (40% of Canada's population). The breach exposed personal information including health card numbers and lab test results. LifeLabs paid a ransom but claimed no evidence of data dissemination.

**Issue:** Whether LifeLabs' cybersecurity measures met PIPEDA requirements and whether data retention was proportionate.

**Holding:** The OPC found LifeLabs failed to implement adequate security safeguards and retained health card numbers beyond legal necessity.
**Significance:** Population-scale health breach. Affected 40% of Canada's population — one of the largest by national population impact.
Ransom payment controversy. LifeLabs' decision to pay ransom highlighted lack of clear regulatory guidance.
Data retention failure. Reinforced data minimization principles in healthcare.

---

### Case 4.71: PRC — Cross-Border Online Gambling Networks (2021–2024) — Chinese Courts

**Date Decided:** 2021–2024 (various cases)

**Court:** Various Chinese courts (Hunan, Hubei, Fujian Provincial Courts)
Case citation: Various judgments under PRC Criminal Law Articles 303, 287, 287bis

**Facts:** Chinese law enforcement conducted massive operations against cross-border online gambling networks generating over 1 trillion ($140 billion) annually. Operators established servers in Southeast Asia targeting the Chinese mainland market. In 2023, a Hubei operation dismantled a network with over 50 billion in transaction volume. Thousands were arrested.

**Issue:** Application of Chinese criminal law to cross-border online gambling where servers and operators are outside Chinese territory.

**Holding:** Sentences ranged from 3 years to life imprisonment. Confiscation orders covered billions of yuan.
**Significance:** Extraterritorial jurisdiction. Demonstrated China's willingness to assert jurisdiction over online gambling targeting citizens abroad.
Cryptocurrency money laundering. Intersection of organized crime and cryptocurrency-based laundering.
International cooperation. Cooperation with Southeast Asian nations represented new cybercrime cooperation dimension.

---

### Case 4.72: PRC — P2P Lending Fraud and  (2021–2024) — Chinese Courts

**Date Decided:** 2021–2024 (various cases)

**Court:** Various Chinese courts (nationwide)
Case citation: Various judgments under PRC Criminal Law Article 287bis

**Facts:** Between 2015–2020, over 6,000 P2P platforms operated in China, many fraudulent, with total losses exceeding 800 billion ($110 billion). Following the crackdown, prosecutors targeted cybercrime support infrastructure under Article 287bis (). By 2022,  became the third most prosecuted crime in China (130,000+ prosecutions annually). Typical defendants included young people who sold bank or payment accounts.

**Issue:** Proportionality of prosecuting low-level facilitators under Article 287bis.

**Holding:** Sentences ranged from 6 months to 3 years. The Supreme People's Court issued joint interpretations limiting the crime's scope.
**Significance:** Third most prosecuted crime. Rapid rise reflected aggressive ecosystem disruption strategy.
Low-level facilitator dilemma. Prosecution of economically disadvantaged young defendants raised equity concerns.
Ecosystem disruption model. Targeting supporting infrastructure rather than only primary perpetrators was a novel strategic approach.

---

### Case 4.73: Pune ATM Heist (2018) — Pune City Police / Maharashtra Cyber Cell
**Court:** Pune City Police / Maharashtra Cyber Cell

**Date Decided:** 2018 (heist); 2019–2020 (arrests)
Court/Prosecutor: Pune Sessions Court, Maharashtra
Case citation: Pune Sessions Court Criminal Case

**Facts:** In June 2018, a coordinated cyber heist involved cloning approximately 300 debit cards and fraudulent withdrawals of 28 crore ($3.8 million) from ATMs across India and internationally. Skimming devices captured card data. The operation was linked to international cybercrime networks with Eastern European connections.

**Issue:** Adequacy of Indian ATM security standards for prosecuting international ATM skimming networks.

**Holding:** Multiple suspects arrested. RBI issued new ATM security guidelines. Banks implemented EMV chip migration.
**Significance:** Skimming vulnerability. Accelerated India's transition to EMV chip technology.
International network links. Demonstrated Indian cybercrime networks as nodes in larger international operations.
Regulatory catalyst. RBI's security mandates were a significant regulatory response.

---

### Case 4.74: Coincheck Cryptocurrency Exchange Hack (2018) — Tokyo Metropolitan Police / FSA Japan

**Date Decided:** January 2018 (hack)
Court/Prosecutor: Tokyo Metropolitan Police Department; Japan Financial Services Agency
Case citation: FSA administrative action

**Facts:** Coincheck, based in Tokyo, suffered a hack of approximately 58 billion yen ($530 million) in NEM (XEM) — the largest cryptocurrency theft at the time. Attackers exploited Coincheck's storage of NEM in hot wallets without multi-signature security. The NEM community tagged stolen coins. Coincheck reimbursed all affected customers.

**Issue:** Whether failure to implement basic security measures (multi-signature, cold storage) constituted negligence under Japan's Payment Services Act.

**Holding:** The FSA conducted on-site inspections of all exchanges and issued improvement orders. Coincheck was acquired by Monex Group. Japan introduced stricter registration requirements.
**Significance:** Largest crypto theft at the time. Prompted global regulatory attention to exchange security.
Japanese regulatory leadership. The FSA's aggressive response established Japan as a leader in cryptocurrency exchange regulation.
Hot wallet negligence. Established that storing large crypto volumes in hot wallets without multi-signature was below the standard of care.
End of Part Four — Cybercrime Cases 4.1 through 4.74
V2-Part4-additions.md —Global Cyber Law Compendium Volume II
Part Four —Cybercrime: Cases 4.75—.99

---

### Case 4.75: Emotet Botnet Takedown (2021) —Europol/German BKA

**Date Decided:** January 2021 (operation conducted January 26—7, 2021)

**Court:** Coordination led by Europol's European Cybercrime Centre (EC3); judicial oversight by German BKA and prosecutors in Frankfurt am Main, Germany; coordinated across Netherlands, Germany, US, UK, France, Lithuania, Canada, and Ukraine.

**Facts:** Emotet was one of the world's most dangerous botnets, functioning primarily as a "dropper-as-a-service" platform that distributed ransomware (e.g., TrickBot, Ryuk) and banking trojans. Active since 2014, it infected hundreds of thousands of systems worldwide through phishing emails with malicious attachments. An international coalition of law enforcement agencies, coordinated by Europol, simultaneously seized control of Emotet's infrastructure across multiple countries, disrupted its command-and-control servers, and replaced them with law enforcement-controlled servers.

**Issue:** Whether a coordinated international law enforcement operation could effectively dismantle a sophisticated, distributed botnet infrastructure used to facilitate widespread ransomware and financial crime, and what legal authority permitted cross-border server seizure and infrastructure substitution.

**Holding:** The operation successfully disrupted Emotet's core infrastructure, seized hundreds of servers, and arrested two individuals in the Netherlands. Law enforcement agencies replaced the botnet's update mechanism with a harmless module, effectively preventing reinfection. Financial damages linked to Emotet were estimated to exceed hundreds of millions of euros.
**Significance:** Demonstrated the viability of "infrastructure takeovers" as a law enforcement technique'eplacing malicious C2 servers with benign ones rather than merely seizing them.
Established a model for international cybercrime task forces coordinated through Europol's EC3, later replicated in operations against Qakbot and other botnets.
Highlighted the evolving legal concept of "cyber takedown" as distinct from traditional asset seizure, raising novel questions about data access, user notification, and territorial jurisdiction in cyberspace.

---

### Case 4.76: Trickbot Botnet Disruption (2020) —US DOJ

**Date Decided:** October 2020 (operation announced October 2020; superseding indictment unsealed)

**Court:** US District Court for the District of Columbia; coordinated by US Cyber Command, NSA, FBI, and international partners including UK's GCHQ and Canada's CCCS.

**Facts:** Trickbot was a sophisticated modular botnet that served as a primary distributor of ransomware, including Ryuk and Conti. It infected millions of devices globally and was used to target hospitals, governments, and critical infrastructure'articularly during the COVID-19 pandemic. US Cyber Command conducted a coordinated offensive cyber operation to disrupt Trickbot's infrastructure, while the DOJ unsealed an indictment charging two Russian nationals with Trickbot-related crimes.

**Issue:** Whether a nation-state military cyber operation (US Cyber Command) could lawfully be used to disrupt a criminal botnet infrastructure, and whether the operators of the botnet could be criminally charged under US law for conduct occurring largely outside the United States.

**Holding:** US Cyber Command successfully disrupted Trickbot's command-and-control infrastructure days before the 2020 US election, preventing potential disruption operations. The DOJ indictment charged Vitaly Korolev and Valeriy Vasilev with conspiracy to commit bank fraud, wire fraud, and computer fraud. The operation temporarily degraded but did not permanently destroy Trickbot, which later reconstituted under successor strains.
**Significance:** One of the first public acknowledgments of the US military conducting offensive cyber operations against a criminal (non-state-actor) threat, blurring lines between law enforcement and military cyber operations.
Illustrated the limits of technical disruption: Trickbot reconstituted, demonstrating that takedowns without sustained follow-up and arrest of key operators yield temporary results at best.
Reinforced the extraterritorial reach of US federal computer fraud statutes (18 U.S.C. § 1030) when infrastructure affects US national interests.

---

### Case 4.77: Avalanche Botnet Takedown (2016) —Europol

**Date Decided:** November'ecember 2016

**Court:** Coordinated by Europol's EC3, Eurojust, the German BKA, and prosecutors in the Netherlands, France, and Ukraine; with judicial cooperation across more than 30 countries.

**Facts:** Avalanche was a massive, highly sophisticated criminal infrastructure providing hosting and management services for phishing, malware distribution, and money mule recruitment. Active since at least 2009, it was linked to over 500,000 malware infections per month and estimated financial losses exceeding € billion worldwide. The network utilized domain-generation algorithms, fast-flux hosting, and bulletproof hosting providers to evade takedown.

**Issue:** Whether law enforcement could legally and technically dismantle a transnational criminal platform hosting hundreds of separate phishing and malware operations, given its distributed architecture and use of anonymization techniques.

**Holding:** Operation "Avalanche" involved over 30 countries, resulted in the seizure of 39 servers, the suspension of 221 server connections, the takedown of over 14,000 malicious domains, and the arrest of five individuals. Approximately €00,000 in assets were seized. This was, at the time, the largest-ever law enforcement operation against a bulletproof hosting network.
**Significance:** Established the operational template for "follow-the-money" approaches to cybercrime, where infrastructure seizure was combined with financial asset freezing to prevent rapid reconstitution.
Demonstrated the necessity of international mutual legal assistance treaties (MLATs) and judicial cooperation frameworks for operations spanning dozens of jurisdictions.
Pioneered the use of "sinkholing" on an unprecedented scale, redirecting traffic from 14,000+ domains to law enforcement-controlled servers for victim notification and intelligence collection.

---

### Case 4.78: Wall Street Market Takedown (2019) —Europol

**Date Decided:** May 2019

**Court:** German BKA (Karlsruhe), with cooperation from Europol, FBI, DEA, and Dutch and Finnish law enforcement.

**Facts:** Wall Street Market was one of the largest darknet marketplaces, facilitating the sale of narcotics, stolen data, counterfeit documents, and hacking tools. Following law enforcement infiltration, administrators attempted an "exit scam" in May 2019, diverting an estimated $11 million in user-held cryptocurrency before authorities shut the platform down. Three German nationals were arrested as operators.

**Issue:** Whether the operators of a darknet marketplace could be held criminally liable for facilitating third-party drug and illegal goods transactions, and whether law enforcement infiltration of the platform's administrative systems was legally permissible across multiple jurisdictions.

**Holding:** The market was seized and replaced with law enforcement banners. Three administrators'ibo Lousee, Klaus-Martin Fassotte, and Jonathan Kalla'ere arrested in Germany and the UK. Over €50,000 in cash and cryptocurrency was seized. The operation was conducted simultaneously with the takedown of Valhalla Market.
**Significance:** Confirmed that darknet marketplace operators bear criminal liability as facilitators of drug trafficking and money laundering, even when they do not directly handle or sell illegal goods themselves.
Demonstrated the effectiveness of law enforcement "undercover" infiltration of darknet platform administrative backends, where agents assumed control of the infrastructure prior to public takedown.
The operators' attempted exit scam'tealing user funds'ecame additional criminal charges, illustrating how digital fraud and drug trafficking liability compound in darknet cases.

---

### Case 4.79: Monopoly Market Takedown (2021) —German BKA

**Date Decided:** December 2021

**Court:** German Federal Criminal Police Office (BKA), with judicial support from the German Federal Public Prosecutor General and international cooperation via Europol.

**Facts:** Monopoly Market was a prominent darknet marketplace specializing in narcotics, operating since at least 2019. It used privacy-enhancing technologies including Monero cryptocurrency and encrypted communications to obscure transactions. German authorities seized the platform's infrastructure and arrested a suspected operator identified as a 34-year-old German national in the Leipzig area.

**Issue:** Whether operators of darknet markets accepting privacy coins (Monero) could still be identified and prosecuted, despite the enhanced anonymity those instruments provide, and whether cryptocurrency seizure orders could effectively capture Monero holdings.

**Holding:** The platform was seized and taken offline. The suspected operator was arrested, and cryptocurrency wallets linked to the marketplace were frozen. The takedown was part of a broader German law enforcement initiative targeting darknet drug trafficking.
**Significance:** Signaled that law enforcement capabilities had advanced to penetrate even privacy-coin-based darknet operations, challenging the assumption that Monero provided untraceable transactional anonymity.
Contributed to the emerging jurisprudence on cryptocurrency seizure orders, including mechanisms for freezing and forfeiting privacy-coin holdings.
Part of a broader trend of German-led darknet enforcement actions that positioned Germany as a primary jurisdiction for darknet criminal prosecution in Europe.

---

### Case 4.80: Mt. Gox Collapse (2014) —Tokyo District Court/Montreal

**Date Decided:** February 2014 (collapse); bankruptcy proceedings continued through 2021 (civil rehabilitation plan approved)

**Court:** Tokyo District Court, Japan (bankruptcy and civil rehabilitation proceedings); parallel proceedings referenced in Montreal, Canada, and US bankruptcy courts.

**Facts:** Mt. Gox, once handling over 70% of all Bitcoin transactions globally, collapsed in February 2014 after revealing that approximately 850,000 BTC (then worth ~$450 million) had been stolen through years of gradual, undetected theft via transaction malleability exploits. CEO Mark Karpelès was arrested in Japan in 2015 and charged with embezzlement and manipulation of records. A 2018 civil rehabilitation plan eventually allowed creditors to recover a portion of their holdings as Bitcoin's price appreciated.

**Issue:** Whether cryptocurrency exchange operators owe fiduciary duties to users comparable to traditional financial institutions, and whether losses from cyber theft constitute a basis for criminal liability of the exchange's management.

**Holding:** Mt. Gox filed for bankruptcy protection. Karpelès was acquitted of embezzlement and breach of trust charges in 2019 but convicted on a lesser charge of data manipulation. The civil rehabilitation plan, approved in 2021, enabled creditors to receive distributions in BTC and cash. A Canadian court also addressed claims related to Mt. Gox's relationship with the Canadian exchange QuadrigaCX.
**Significance:** Established foundational precedent for the legal treatment of cryptocurrency exchange collapses, including creditor priority, asset valuation in volatile markets, and cross-border insolvency coordination.
Exposed the absence of regulatory frameworks for cryptocurrency custody at the time, catalyzing subsequent regulatory developments (Japan's Virtual Currency Act, EU MiCA, etc.).
The transaction malleability vulnerability exploited in the theft led to Bitcoin protocol upgrades (BIP 62/66), creating a rare instance where cybercrime directly drove blockchain technical evolution.

---

### Case 4.81: Lazarus Group Crypto Heists (2022–2024) —US DOJ/UN Sanctions

**Date Decided:** 2022–2024 (multiple indictments, sanctions designations, and enforcement actions)

**Court:** US Department of Justice (multiple districts including SDNY, CNDCA, EDVA); US Treasury OFAC; United Nations Security Council Sanctions Committee.

**Facts:** North Korea's Lazarus Group (also known as APT38, Hidden Cobra) conducted a series of massive cryptocurrency heists between 2022 and 2024, stealing an estimated $1.7 billion in various cryptocurrencies. Major targets included the Ronin Network bridge ($625 million, March 2022), Harmony Horizon ($100 million, June 2022), and CoinEx ($70 million, September 2023). Funds were laundered through complex chains of wallets, mixers, and decentralized exchanges. The US DOJ unsealed multiple indictments, and OFAC imposed sanctions on Lazarus-linked wallets, while the UN maintained sanctions on North Korean cyber operations.

**Issue:** Whether state-sponsored cryptocurrency theft constitutes a violation of international sanctions, and whether US courts have jurisdiction over crimes committed by foreign state-affiliated actors against foreign-based cryptocurrency platforms when proceeds flow through US financial infrastructure.

**Holding:** Multiple indictments charged North Korean nationals with conspiracy to commit money laundering and cyber fraud. OFAC sanctioned dozens of cryptocurrency addresses linked to Lazarus. Law enforcement agencies coordinated with blockchain analytics firms (Chainalysis, TRM Labs) to trace and freeze stolen funds. Despite enforcement actions, Lazarus continued operations, adapting laundering techniques.
**Significance:** Defined the legal frontier of state-sponsored cyber-enabled financial crime, where traditional law enforcement tools (indictments, sanctions) coexist uneasily with military-grade state operations.
Established blockchain analytics as a core component of federal financial crime investigations, effectively treating on-chain forensics as analogous to traditional financial tracing.
Highlighted the limitations of sanctions and criminal indictments against actors operating under state protection, raising questions about the effectiveness of legal tools alone in deterring nation-state cyber theft.

---

### Case 4.82: North Korean IT Workers Additional Prosecutions (2024) —US DOJ

**Date Decided:** 2024 (multiple indictments and enforcement actions throughout the year)

**Court:** US District Court for the District of Columbia; US Attorney's Offices in multiple districts.

**Facts:** North Korean IT workers, operating under false identities primarily from China and Russia, obtained remote employment at hundreds of Western companies'articularly in technology, healthcare, and finance. These workers generated revenue for the North Korean government (estimated at hundreds of millions of dollars annually) while stealing proprietary source code, credentials, and sensitive data. In 2024, the DOJ brought multiple additional indictments and secured guilty pleas, revealing the scale of the scheme involving thousands of workers and complicit facilitators.

**Issue:** Whether the use of stolen identities to obtain employment constitutes wire fraud and identity theft under US federal law, and whether facilitators who helped North Korean workers evade sanctions could be charged as accomplices.

**Holding:** Multiple individuals were indicted for facilitating the scheme, including US-based facilitators who set up proxy laptop farms and assisted with identity theft. Several defendants pled guilty. OFAC issued additional advisories warning companies about the scheme. The FBI issued a public service announcement identifying red flags for employers.
**Significance:** Established a new category of cybercrime prosecution: state-sponsored labor fraud, where the primary harm is revenue generation for a sanctioned regime rather than traditional data theft or financial fraud.
Raised novel employment law questions about employer due diligence obligations when hiring remote workers, particularly regarding identity verification and sanctions compliance.
Created an emerging body of case law on the legal liability of intermediaries and facilitators who enable foreign state-sponsored cyber operations from within the United States.

---

### Case 4.83: Iranian IRGC Cyber Operations Indictment (2022) —SDNY

**Date Decided:** September 2022

**Court:** US District Court for the Southern District of New York.

**Facts:** The US DOJ unsealed an indictment charging three Iranian nationals affiliated with the Islamic Revolutionary Guard Corps (IRGC) with conducting a multi-year cyber campaign targeting US critical infrastructure, including a Boston children's hospital, power companies, and local governments. The defendants deployed ransomware and wiper malware, conducted vulnerability scanning, and attempted to extort victims. The campaign was attributed to IRGC-affiliated groups tracked as APT35 (Charming Kitten) and other clusters.

**Issue:** Whether targeting civilian critical infrastructure'ncluding a children's hospital'ith ransomware and destructive malware constitutes a violation of federal computer crime statutes and international law, even when conducted by state-affiliated military personnel.

**Holding:** The three defendants'ansour Ahmadi, Ahmad Khatibi, and Amir Hossein Nickaein Ravari'ere charged with conspiracy to commit computer intrusions, wire fraud, and extortion. FBI Director Christopher Wray publicly condemned the targeting of the children's hospital. The defendants remained at large in Iran; the indictment served primarily as an enforcement and diplomatic tool.
**Significance:** Represented one of the first US criminal indictments explicitly linking Iranian state military actors (IRGC) to ransomware attacks on civilian healthcare targets, establishing a precedent for treating ransomware deployed by state actors as a criminal offense rather than solely an intelligence or warfare matter.
Reinforced the DOJ's policy of "naming and shaming" state-affiliated cyber actors through criminal charging documents as a tool of cyber deterrence and diplomatic pressure.
Contributed to the emerging legal framework distinguishing between lawful cyber espionage and unlawful cyber sabotage against civilian targets under international humanitarian law.

---

### Case 4.84: Russian Sandworm NotPetya Criminal Referral (2023) —Netherlands/Germany

**Date Decided:** 2023

**Court:** Public Prosecution Service of the Netherlands (Openbaar Ministerie); German Federal Public Prosecutor General; coordinated through Europol.

**Facts:** The Dutch and German authorities referred six Russian intelligence officers of Unit 74455 of Russia's GRU (Main Intelligence Directorate)'nown as Sandworm'o their respective prosecutors for criminal charges related to the 2017 NotPetya attack. NotPetya, disguised as ransomware, was in fact a destructive wiper that caused over $10 billion in global damage, targeting Ukrainian financial institutions before spreading globally to shipping (Maersk), pharmaceutical companies (Merck), and energy infrastructure. The referral built on the 2020 UK and US attribution statements.

**Issue:** Whether a destructive cyber weapon deployed by a state intelligence unit against a neighboring state, with massive collateral damage worldwide, could be prosecuted as a criminal offense under European national law, given the state-actor nature of the defendants.

**Holding:** The Netherlands and Germany issued international arrest warrants for the six GRU officers. The cases were added to existing Dutch prosecutions against GRU Unit 74455 members for interference in Olympic anti-doping systems and the OPCW chemical weapons investigation hack. The defendants remained at large in Russia.
**Significance:** Extended the European model of criminal prosecution for state-sponsored cyber operations, moving beyond attribution statements to actual criminal proceedings'hough limited by the defendants' absence.
Established NotPetya as a legal precedent for treating state-deployed destructive malware as a criminal act rather than solely a matter of state responsibility under international law.
Created a growing docket of cases against GRU Unit 74455, building a cumulative legal record that could support future accountability mechanisms (international criminal tribunals, universal jurisdiction claims).

---

### Case 4.85: APT41/Winnti Operations (2020–2024) —Multiple DOJ Indictments

**Date Decided:** 2020, 2023, 2024 (multiple successive indictments)

**Court:** US District Court for the Southern District of California (2020); US District Court for the District of Columbia (2023, 2024); additional proceedings in Singapore and other jurisdictions.

**Facts:** APT41 (also known as Double Dragon, Winnti) was a Chinese state-sponsored cyber espionage group that simultaneously conducted intelligence operations and financially motivated attacks. The group targeted gaming, pharmaceutical, telecommunications, and government entities worldwide, deploying the Winnti backdoor and supply-chain compromise techniques. In 2020, the DOJ indicted multiple members; in 2023, additional charges followed for cryptocurrency theft and money laundering; in 2024, further indictments expanded the scope. Key figures included Jiang Lizhi, Qian Chuan, and Fu Qiang.

**Issue:** Whether Chinese state-sponsored cyber actors could be prosecuted under US law for conduct that blended espionage (traditionally a state-function defense) with financially motivated crime (clearly criminal), and whether the dual nature of APT41's operations affected legal characterization.

**Holding:** Multiple defendants were charged with conspiracy to commit computer fraud, wire fraud, and money laundering. Two Malaysian nationals were arrested in Malaysia in 2020 and extradited to the US, pleading guilty in 2023. The primary Chinese defendants remained at large. Singapore authorities also took action against APT41-linked individuals.
**Significance:** Established the DOJ's legal framework for prosecuting "dual-purpose" cyber operations'here the same actors conduct both state-sponsored espionage and private financial crime, the latter providing a clear basis for criminal jurisdiction.
The successful extradition and guilty plea of the Malaysian co-defendants demonstrated that even in cases where primary state-affiliated operators are beyond reach, facilitators and associates can be successfully prosecuted.
Contributed to the growing body of US case law on Chinese state-sponsored cyber operations, creating a documentary record that supports broader diplomatic and policy responses.

---

### Case 4.86: Business Email Compromise Nigerian Perpetrators (2022–2023) —US DOJ

**Date Decided:** 2022–2023 (multiple prosecutions, convictions, and sentencings)

**Court:** Multiple US District Courts, including SDNY, EDNY, ND California, and the Middle District of Georgia.

**Facts:** Business Email Compromise (BEC) schemes operated by Nigerian-based criminal networks defrauded thousands of companies and individuals globally, causing estimated losses exceeding $2.7 billion annually. In 2022–2023, the DOJ secured multiple convictions of BEC perpetrators, including high-profile cases involving redirection of corporate wire transfers, impersonation of executives, and romance fraud integration. Operations involved collaboration with Nigerian Economic and Financial Crimes Commission (EFCC), Interpol, and the FBI.

**Issue:** Whether Nigerian BEC operators could be extradited and successfully prosecuted in US courts, and whether the conspiracy and wire fraud statutes adequately addressed the transnational, multi-layered nature of BEC schemes involving complicit money mules in the US.

**Holding:** Multiple defendants received substantial prison sentences ranging from 4 to 25 years. Key cases included the conviction of a Nigerian national who operated a BEC scheme from Nigeria targeting US real estate transactions, resulting in over $5 million in losses. The DOJ seized millions in assets including cryptocurrency, luxury vehicles, and real estate. Nigeria's EFCC conducted parallel arrests.
**Significance:** Demonstrated the effectiveness of international law enforcement cooperation between the US and Nigeria's EFCC, establishing a replicable model for BEC prosecution.
Confirmed that wire fraud statutes (18 U.S.C. § 1343) and money laundering statutes (18 U.S.C. § 1956) provide a robust legal framework for prosecuting BEC, even when the defendant never physically entered the United States.
Contributed to the development of "follow-the-money" forfeiture doctrines specific to cryptocurrency and international money mule networks.

---

### Case 4.87: Romance Scam Operation Takedowns (2023–2024) —FTC/FBI

**Date Decided:** 2023–2024 (multiple enforcement actions, criminal prosecutions, and civil regulatory actions)

**Court:** Multiple US District Courts; Federal Trade Commission administrative proceedings; international cooperation through Interpol and bilateral agreements.

**Facts:** Romance scam operations defrauded victims of approximately $1.3 billion in 2022 alone in the United States, with victims often elderly or emotionally vulnerable. Criminal networks, primarily operating from West Africa and Southeast Asia, used dating platforms and social media to establish relationships before requesting money for fabricated emergencies, investments, or cryptocurrency schemes. In 2023–2024, the FTC brought enforcement actions against platforms facilitating romance scams, while the FBI and international partners conducted criminal takedowns of major scam rings.

**Issue:** Whether social media and dating platforms bear liability for facilitating romance scams under Section 5 of the FTC Act and emerging platform accountability frameworks, and whether romance fraud constitutes wire fraud or a distinct category requiring new legislation.

**Holding:** The FTC brought multiple enforcement actions against companies that failed to prevent romance scams on their platforms. The FBI arrested dozens of operators in coordinated international operations. Several defendants received multi-year prison sentences. The FTC issued regulatory guidance on romance scam prevention for financial institutions.
**Significance:** Expanded the FTC's consumer protection mandate into the online dating and social media platform space, establishing a regulatory expectation for proactive fraud detection.
Highlighted the intersection of cybercrime and elder financial exploitation, driving legislative proposals for enhanced protections for vulnerable populations.
Contributed to the growing recognition of "pig butchering" (long-term investment romance scams) as a distinct, organized criminal enterprise requiring dedicated legal frameworks.

---

### Case 4.88: Crypto Mixer Blender.io OFAC Sanctions (2022) —US Treasury

**Date Decided:** May 6, 2022

**Court:** US Department of the Treasury, Office of Foreign Assets Control (OFAC); no judicial proceeding (administrative sanctions action).

**Facts:** Blender.io was a cryptocurrency mixing service that facilitated the laundering of approximately $20.5 million in cryptocurrency stolen by North Korea's Lazarus Group from the Ronin Network and Axie Infinity. Blender.io operated as a "tumbler," combining and redistributing cryptocurrency from multiple users to obscure transaction trails. The service allegedly had no Know Your Customer (KYC) or Anti-Money Laundering (AML) procedures and had processed over $1 billion in illicit funds.

**Issue:** Whether a cryptocurrency mixing service could be designated as a Specially Designated National (SDN) under OFAC's authority for facilitating money laundering on behalf of a sanctioned entity (North Korea), and whether privacy-preserving financial tools receive First Amendment or other constitutional protections.

**Holding:** OFAC designated Blender.io as an SDN, prohibiting all US persons from transacting with the service and freezing any US-based assets. This was the first time OFAC sanctioned a virtual currency mixer. The designation effectively severed the service from the US financial system. No criminal prosecution was initially filed; the action was purely administrative.
**Significance:** Established OFAC's authority to sanction decentralized financial privacy tools, creating a new enforcement paradigm where administrative sanctions'ot criminal prosecutions'ecame the primary tool against privacy-preserving cryptocurrency services.
Generated significant legal debate about the tension between financial privacy rights and AML enforcement, with civil liberties organizations questioning whether privacy tools could be penalized for dual-use functionality.
Set a precedent subsequently followed by the Tornado Cash sanctions, establishing a pattern of using the SDN framework against cryptocurrency mixing services facilitating illicit finance.

---

### Case 4.89: Crypto Mixer Tornado Cash Founders Arrested (2023) —SDNY

**Date Decided:** August 2022 (OFAC designation); August 2023 (criminal indictment and arrest)

**Court:** US District Court for the Southern District of New York; OFAC administrative proceeding.

**Facts:** Tornado Cash was an Ethereum-based cryptocurrency mixing service that processed over $7 billion in transactions since 2019, including over $455 million stolen by Lazarus Group from the Ronin Network. Founders Alexey Pertsev (Russian-Dutch) and Roman Storm (Russian-US) were arrested in the Netherlands and the US, respectively, and charged with conspiracy to commit money laundering, conspiracy to commit sanctions evasion, and conspiracy to operate an unlicensed money transmitting business. Pertsev was arrested in Amsterdam; Storm in Washington state.

**Issue:** Whether the developers and operators of an open-source, decentralized cryptocurrency mixing protocol could be held criminally liable for third-party misuse of the tool, and whether OFAC could constitutionally sanction a smart contract-based protocol with no centralized operator.

**Holding:** Pertsev was sentenced to 64 months in prison by a Dutch court in May 2024. Storm was arrested and charged by the DOJ; his case remained pending. OFAC's sanction of Tornado Cash's smart contract addresses generated significant legal controversy, including a challenge by Coinbase-backed plaintiffs arguing that the sanctions exceeded OFAC's statutory authority (Coinbase v. OFAC, dismissed on standing grounds in 2024).
**Significance:** Represented the most aggressive application of money laundering and sanctions laws to open-source software development, raising fundamental questions about developer liability for tool misuse.
Generated the most significant constitutional challenge to OFAC's authority over smart contracts, testing the boundaries of the SDN framework in the context of decentralized, autonomous software protocols.
Created a chilling effect on privacy-preserving technology development, with broader implications for the cryptocurrency industry's approach to regulatory compliance and decentralization.

---

### Case 4.90: SIM Swap Ring Takedown (2023) —DOJ/UK NCA

**Date Decided:** 2023 (arrests and indictments throughout the year)

**Court:** US District Court for the Eastern District of Michigan; UK Crown Court (Southwark); coordinated by FBI and UK National Crime Agency.

**Facts:** A transnational criminal ring conducted SIM swap attacks by bribing or socially engineering telecommunications employees to transfer victims' phone numbers to attacker-controlled SIM cards. The ring then used the hijacked numbers to bypass two-factor authentication and access cryptocurrency wallets, social media accounts, and financial accounts. The operation targeted high-value cryptocurrency holders, stealing over $400 million in digital assets. The ring operated across the US, UK, and Belgium.

**Issue:** Whether SIM swapping constitutes unauthorized access to computers under the CFAA (18 U.S.C. § 1030) and wire fraud (18 U.S.C. § 1343), and whether telecommunications employees who facilitated the transfers could be charged as co-conspirators.

**Holding:** Multiple defendants were arrested in the US, UK, and Belgium. US defendants were charged with conspiracy to commit wire fraud and computer fraud, with potential sentences of up to 20 years. The UK NCA secured convictions under the Computer Misuse Act 1990. Assets including cryptocurrency, luxury goods, and real estate were seized.
**Significance:** Established SIM swapping as a distinct criminal offense category under existing computer fraud and wire fraud statutes, without requiring new legislation.
Highlighted the vulnerability of SMS-based two-factor authentication and influenced industry adoption of more secure authentication methods (hardware security keys, authenticator apps).
Demonstrated effective transatlantic law enforcement coordination, with simultaneous operations in multiple jurisdictions against a single criminal network.

---

### Case 4.91: Raccoon Stealer Malware (2022–2024) —Dutch/US

**Date Decided:** 2022 (initial takedown); 2023–2024 (prosecutions and follow-up actions)

**Court:** Dutch Public Prosecution Service; US Attorney's Office for the Eastern District of Virginia; coordinated through Europol.

**Facts:** Raccoon Stealer was a widely distributed malware-as-a-service (MaaS) operation that harvested credentials, cookies, cryptocurrency wallets, and other sensitive data from infected computers. The malware was rented to other criminals for as little as $200 per month and infected millions of devices globally. In October 2022, Dutch and US authorities arrested the principal developer, a Ukrainian national identified as Mark Sokolovsky, at Amsterdam's Schiphol Airport. The operation involved seizing the malware's infrastructure and domain.

**Issue:** Whether the operator of a malware-as-a-service platform could be prosecuted for all downstream criminal acts committed by customers using the tool, and whether jurisdiction was proper where the operator was Ukrainian, hosted in the Netherlands, and victims were global.

**Holding:** Sokolovsky was extradited to the US and charged with conspiracy to commit computer fraud, wire fraud, and access device fraud. In 2023–2024, additional arrests targeted users of the Raccoon Stealer service. The original Raccoon Stealer was disrupted, though a successor version (Raccoon v2) emerged under different operators.
**Significance:** Established that MaaS operators can be held criminally liable not only for providing the tool but as co-conspirators in the crimes committed by their customers, extending liability through the supply chain.
Demonstrated the effectiveness of extradition in cybercrime cases where the defendant transits through a cooperating jurisdiction (Netherlands).
Highlighted the recurring challenge of malware ecosystem resilience, where takedowns of individual operators lead to rapid successor development by other actors in the criminal ecosystem.

---

### Case 4.92: Qakbot Botnet Takedown (2023) —FBI/Operation Duck Hunt

**Date Decided:** August 2023

**Court:** US Department of Justice; FBI Cyber Division; coordinated international operation involving France, Germany, Netherlands, Romania, Latvia, and the UK.

**Facts:** Qakbot (also known as Qbot) was a prolific botnet active since 2008, distributed primarily through phishing emails. It functioned as a delivery mechanism for ransomware (including ProLock, Egregor, and REvil) and banking trojans. Qakbot infected over 700,000 computers and facilitated losses estimated at tens of millions of dollars. Operation Duck Hunt involved redirecting Qakbot traffic to FBI-controlled servers and seizing the botnet's infrastructure.

**Issue:** Whether law enforcement could legally redirect botnet traffic to government-controlled servers (sinkholing) and push remediation modules to infected computers without user consent, and what legal authority supported the cross-border seizure of Qakbot's distributed infrastructure.

**Holding:** The FBI disrupted Qakbot's infrastructure, seized approximately $8.6 million in cryptocurrency from the botnet's operators, and pushed an uninstall module to infected computers to remove the malware. No arrests were announced at the time of the takedown, though the investigation continued.
**Significance:** Advanced the legal practice of "remote remediation"'aw enforcement actively modifying infected computers to remove malware'aising questions about user consent, data access, and the scope of government authority over private devices.
The $8.6 million cryptocurrency seizure represented one of the largest direct financial seizures from a botnet operation, demonstrating the integration of financial disruption into technical takedowns.
Reinforced the pattern of successive botnet takedowns (Avalanche →Emotet →Qakbot) as a sustained law enforcement strategy rather than isolated operations.

---

### Case 4.93: ALPHV/BlackCat FBI Seizure (2023) —FBI

**Date Decided:** December 2023

**Court:** US Department of Justice; FBI; seizure conducted without prior judicial order in some aspects, with legal authority debated.

**Facts:** ALPHV (also known as BlackCat) was a prominent ransomware-as-a-service operation that emerged in 2021, utilizing Rust-based malware. It targeted critical infrastructure, healthcare, and government entities globally, extorting hundreds of millions of dollars. In December 2023, the FBI seized ALPHV's darknet leak site and announced disruption of the operation. Shortly after, ALPHV appeared to conduct a fabricated "exit scam," claiming the FBI had paid a ransom to a seized affiliate. The site was subsequently re-seized by the FBI.

**Issue:** Whether the FBI's seizure of the ALPHV darknet site was legally sufficient to disrupt a distributed RaaS operation, and whether law enforcement's involvement in the apparent exit scam raised questions about entrapment or government overreach.

**Holding:** The FBI seized ALPHV's Tor-hidden service and replaced it with a law enforcement banner. Multiple ALPHV affiliates were subsequently arrested or identified. The operation was disrupted but not fully destroyed; some infrastructure reconstituted. The DOJ unsealed related indictments against ALPHV affiliates.
**Significance:** Highlighted the cat-and-mouse dynamics between law enforcement and RaaS operators, where takedowns trigger rapid adaptation and reconstitution.
The controversial "exit scam" incident raised novel legal questions about law enforcement's role in the apparent deception, including potential implications for evidence admissibility and defendant rights in subsequent prosecutions.
Demonstrated the growing sophistication of law enforcement operations against RaaS, combining technical disruption with financial seizure and targeted prosecution of affiliates.

---

### Case 4.94: Hive Ransomware FBI Takedown (2022–2023) —FBI

**Date Decided:** November 2022 (infiltration began); January 2023 (announced)

**Court:** US Department of Justice; FBI Cyber Division; international cooperation with Germany, Netherlands, and other European agencies.

**Facts:** Hive ransomware, active since June 2021, targeted over 1,500 victims across 80 countries, including hospitals, school districts, and critical infrastructure, extorting approximately $100 million. Beginning in July 2022, the FBI infiltrated Hive's network, gaining covert access to its administrative panel, decryption keys, and communications for seven months. In January 2023, the FBI announced the disruption, having provided decryption keys to victims and preventing approximately $130 million in ransom payments.

**Issue:** Whether the FBI's prolonged covert infiltration of a ransomware operation's infrastructure'ithout immediate disruption'as legally justified, and whether providing stolen decryption keys to victims raised legal questions about the FBI's role as an intermediary in criminal operations.

**Holding:** The FBI disrupted Hive's infrastructure and distributed decryption keys to over 1,300 victims. No arrests were announced at the time. The operation prevented an estimated $130 million in ransom payments. Hive subsequently went offline, though some affiliates migrated to other RaaS platforms.
**Significance:** Established "delayed disruption" as a law enforcement strategy'aintaining covert access to gather intelligence and assist victims before public takedown'aising questions about the balance between intelligence collection and immediate victim protection.
The distribution of decryption keys to victims represented a proactive victim-assistance model that went beyond traditional law enforcement approaches focused primarily on prosecution.
Set the operational template for the FBI's subsequent takedown of other ransomware operations, including ALPHV/BlackCat and LockBit.

---

### Case 4.95: LockBit Takedown —Operation Cronos (2024) —NCA/FBI/Europol

**Date Decided:** February 20, 2024

**Court:** UK National Crime Agency (lead); FBI; Europol; coordinated action across 10+ countries including the Netherlands, Germany, France, Switzerland, Australia, and Japan.

**Facts:** LockBit was the world's most prolific ransomware-as-a-service operation, responsible for approximately 25% of all ransomware attacks in 2023. Operation Cronos involved seizing LockBit's infrastructure, including its darknet leak site, administrative panel, and decryption key servers. Law enforcement arrested two individuals in Poland and Ukraine, identified LockBit's suspected developer (Dmitry Khoroshev, "LockBitSupp"), and sanctioned him. The operation also seized cryptocurrency and obtained over 1,000 decryption keys.

**Issue:** Whether the extensive scope of Operation Cronos'ncluding public doxxing of the suspected developer, seizure of a vast infrastructure, and distribution of decryption keys'xceeded lawful law enforcement authority, and whether the operation established a new standard for aggressive, publicly announced cybercrime disruption.

**Holding:** LockBit's infrastructure was seized and its leak site replaced with law enforcement messaging. The NCA publicly identified Khoroshev and offered a $10 million bounty for information. Over 200 cryptocurrency accounts were frozen. Despite the takedown, LockBit partially reconstituted within weeks, releasing a new version (LockBit 4.0) that claimed to address the vulnerabilities exploited by law enforcement.
**Significance:** Represented the most ambitious and publicly aggressive ransomware takedown to date, combining infrastructure seizure, criminal sanctions, financial asset freezing, and public shaming of the developer.
The rapid reconstitution of LockBit demonstrated that even the most comprehensive takedowns face limitations when RaaS operators decentralize their infrastructure and maintain operational resilience.
Established Operation Cronos as a model for future multinational ransomware disruption operations, with the NCA taking an unprecedented leadership role typically held by the FBI.

---

### Case 4.96: Scattered Spider Arrests (2023–2024) —FBI/UK NCA

**Date Decided:** 2023–2024 (arrests, indictments, and prosecutions continuing)

**Court:** US District Court for the Central District of California; UK Crown Court; FBI and NCA joint operations.

**Facts:** Scattered Spider (also known as 0ktapus, UNC3944) was a sophisticated cybercriminal group primarily composed of young English-speaking individuals who conducted social engineering attacks, SIM swaps, and ransomware operations against major technology, telecommunications, and hospitality companies. The group was responsible for breaches at MGM Resorts, Caesars Entertainment, Twilio, and LastPass. Members were primarily based in the US and UK, with some as young as 17—9 years old.

**Issue:** Whether the relatively young age of Scattered Spider members should be a mitigating factor in sentencing, and whether social engineering combined with SIM swapping constitutes a distinct criminal category or falls under existing computer fraud statutes.

**Holding:** Multiple arrests were made in the US and UK. In the US, several members were indicted on charges including conspiracy to commit wire fraud and unauthorized computer access. The FBI conducted raids on members' residences. Prosecutions continued through 2024, with some defendants cooperating with authorities.
**Significance:** Highlighted the emergence of a new demographic of cybercriminal'oung, native English-speaking individuals using social engineering rather than technical exploitation'hallenging traditional profiles of cybercriminals as state-affiliated or organized crime syndicate members.
Raised questions about the adequacy of juvenile justice systems in handling sophisticated cybercrime cases involving minors.
The MGM Resorts breach in particular demonstrated the devastating real-world impact of social engineering attacks, causing over $100 million in estimated losses and forcing operational shutdowns of casino properties.

---

### Case 4.97: Patchwork APT India-Pakistan Cyber Operations (2024) —Cert-In

**Date Decided:** 2024 (advisories, threat intelligence reports, and coordinated defensive actions)

**Court:** Indian Computer Emergency Response Team (CERT-In); National Critical Information Infrastructure Protection Centre (NCIIPC); no criminal court proceedings publicly announced as of early 2024.

**Facts:** Patchwork APT (also known as Dropping Elephant, Chinastrats) was identified as a threat group targeting Indian and Pakistani government, defense, and diplomatic entities through spear-phishing campaigns delivering Android and Windows malware. While originally attributed to Chinese state sponsorship, the 2024 operations involved a complex landscape where Indian and Pakistani entities accused each other of cross-border cyber operations. CERT-In issued multiple advisories documenting the threats and providing defensive guidance to targeted organizations.

**Issue:** Whether CERT-In's advisory and coordination function was an adequate legal response to state-sponsored cyber operations targeting critical infrastructure, and what legal framework governed India's defensive cyber operations against foreign APT groups.

**Holding:** CERT-In issued detailed threat advisories identifying Patchwork's tactics, techniques, and procedures (TTPs) and recommending defensive measures. No criminal indictments were publicly announced. The Indian government strengthened its cyber incident reporting requirements under the CERT-In Directions 2022, which mandated 6-hour reporting of cyber incidents.
**Significance:** Illustrated the regulatory approach to cyber threat response adopted by India, where CERT advisories and mandatory reporting requirements substitute for (or complement) the criminal prosecution model favored by the US and EU.
The India-Pakistan cyber dimension highlighted how regional geopolitical tensions create a complex legal landscape where attribution is contested and legal responses are constrained by diplomatic considerations.
Contributed to the development of India's emerging cyber defense legal framework, including the Digital Personal Data Protection Act 2023 and proposed amendments to the Information Technology Act.

---

### Case 4.98: China Cyber Espionage Indictments —Additional (2024) —US DOJ

**Date Decided:** 2024 (multiple indictments throughout the year)

**Court:** US District Court for the District of Massachusetts; US District Court for the District of Columbia; multiple other districts.

**Facts:** The DOJ brought a series of additional indictments in 2024 targeting Chinese state-sponsored cyber espionage operations. Key cases included charges against members of APT31 (Fujian-based) for targeting US officials, journalists, and political figures in a global hacking campaign spanning 14 years, and charges against Volt Typhoon-linked actors for pre-positioning within US critical infrastructure networks. The APT31 case charged seven Chinese nationals associated with the Wuhan Xia Ru Yuan Company, which operated under the direction of China's Ministry of State Security (MSS).

**Issue:** Whether the DOJ could sustain criminal charges against foreign state intelligence officers for cyber espionage targeting government officials and critical infrastructure, given the legal distinction between espionage (which is typically addressed through diplomatic, not criminal, channels) and computer intrusion.

**Holding:** Multiple Chinese nationals were charged with conspiracy to commit computer fraud, economic espionage, and wire fraud. The UK simultaneously sanctioned the APT31 actors and summoned the Chinese ambassador. The Volt Typhoon case generated particular concern due to evidence of pre-positioning in US critical infrastructure for potential future disruption.
**Significance:** The APT31 indictment was notable for targeting specific front companies and individual MSS officers, moving beyond group-level attribution to individual accountability' strategic evolution in DOJ cybercrime prosecution.
The Volt Typhoon cases raised the novel legal question of whether "pre-positioning" in critical infrastructure (without immediate exploitation) constitutes a criminal act or is within the bounds of traditional espionage, with potential implications for defining the threshold between intelligence gathering and attack preparation.
The coordinated US-UK actions demonstrated the growing practice of synchronizing criminal, diplomatic, and sanctions responses to state-sponsored cyber operations.

---

### Case 4.99: Ukraine Cyber Defense Operations Legal Framework (2022–2024) —Ukraine/International

**Date Decided:** 2022–2024 (ongoing, evolving framework)

**Court:** No single court; encompasses Ukrainian Parliament (Verkhovna Rada) legislation, Ukrainian military and intelligence directives, NATO/EU legal frameworks, and international humanitarian law considerations. Key legal instruments include Ukraine's 2022 martial law decrees, the 2023 Law on Cyber Defense, and relevant NATO CCDCOE guidance.

**Facts:** Following Russia's full-scale invasion of February 2022, Ukraine developed an extensive legal and operational framework for cyber defense, encompassing both defensive measures and offensive counter-operations. Ukraine's IT Army' volunteer force of civilian hackers'onducted operations against Russian targets with tacit government sanction. Key incidents included the defense against Russian wiper attacks (HermeticWiper, Viasat compromise), the Ukrainian government's partnerships with Western cybersecurity companies (CrowdStrike, Microsoft), and the development of the "e-Enemy" tracking platform. The legal framework addressed questions of civilian participation in cyber operations, the status of volunteer hackers under international humanitarian law, and the legal basis for cross-border offensive cyber operations.

**Issue:** Whether civilian volunteer hackers participating in state-sanctioned cyber operations are lawful combatants under international humanitarian law, and what legal framework governs a defending state's offensive cyber operations against an aggressor state's civilian and military targets.

**Holding:** Ukraine's Verkhovna Rada passed the Law on Cyber Defense (2023), which created a legal basis for integrating cyber operations into national defense structures and provided limited legal protections for participants. The IT Army was formally integrated into Ukraine's defense apparatus. NATO and EU partners provided legal and operational support. Russia's cyber operations against Ukraine were documented as potential war crimes and violations of international humanitarian law.
**Significance:** Created the first comprehensive national legal framework explicitly governing state-sanctioned offensive and defensive cyber operations during an active armed conflict, providing a potential model for future conflicts.
Raised unresolved questions under international humanitarian law about the status of civilian cyber volunteers'hether they qualify as civilians directly participating in hostilities (losing civilian protection) or as de facto members of the armed forces.
The Ukrainian experience provided critical case law and practical precedent for the application of the Tallinn Manual principles to real-world armed conflict, testing theoretical frameworks of international cyber law under battlefield conditions.
End of V2-Part4-additions.md —Cases 4.75 through 4.99

---

### Case 4.100: Yahoo Data Breach Prosecution (2016-2019) — DOJ

**Date Decided:** 2016-2019

**Court:** US Department of Justice (criminal prosecution); US District Court for the Southern District of California

**Facts:** In 2016, Yahoo disclosed that it had suffered two massive data breaches affecting all 3 billion user accounts — one in 2013 and another in 2014 — representing the largest data breaches in history at the time. The DOJ investigation revealed that the breaches involved state-sponsored actors and resulted in the theft of names, email addresses, telephone numbers, dates of birth, hashed passwords, and, in some cases, security questions and answers. Two Russian intelligence officers (Dokuchaev and Sushchin) were indicted for their roles in the breach. The case also had significant implications for Yahoo's acquisition by Verizon, which reduced its purchase price by $350 million.

**Issue:** Whether the Yahoo data breaches constituted criminal violations of the Computer Fraud and Abuse Act (CFAA) and related statutes, and whether Yahoo's security failures warranted criminal prosecution of the company's officers.

**Holding:** The DOJ indicted four individuals, including two Russian FSB officers, for conspiracy, computer fraud, and economic espionage related to the breaches. While Yahoo was not criminally charged as a company, the SEC brought enforcement actions against Yahoo for failing to disclose the breaches to investors in a timely manner. The case resulted in significant settlements, including a $117.5 million class action settlement and a $35 million SEC fine. The breaches contributed to a $350 million reduction in Verizon's acquisition price.
**Significance:** Established the largest data breach prosecution by scale in history, demonstrating the DOJ's willingness to pursue state-sponsored cyber actors even when extradition is unlikely.
Clarified the intersection of cybersecurity incident disclosure obligations under both the SEC's securities laws and state breach notification statutes.
Set precedents for the financial consequences of data breaches in M&A transactions, influencing due diligence practices in technology acquisitions worldwide.

---

### Case 4.101: Uber CNL Data Breach Russia (2022) — Russian Court

**Date Decided:** 2022

**Court:** Russian courts (Moscow City Court / Tagansky District Court)

**Facts:** Uber's Russian operations, conducted through the joint venture Yandex Taxi (formerly Yandex.Uber following the 2017 merger), experienced a significant data breach exposing personal information of Russian users. Russian data protection authorities (Roskomnadzor) investigated and found that the breach resulted from inadequate security measures and failure to comply with Russia's Federal Law No. 152-FZ on Personal Data. The case coincided with increasing regulatory pressure on foreign technology companies operating in Russia, and the data breach was used as additional grounds for enhanced regulatory scrutiny.

**Issue:** Whether Uber/Yandex Taxi violated Russian personal data protection laws by failing to implement adequate security measures to prevent the breach, and what penalties were appropriate under Federal Law No. 152-FZ.

**Holding:** Russian courts found that the data processing practices of the joint venture violated multiple provisions of Federal Law No. 152-FZ, including requirements for data localization within Russia and adequate security measures. The court imposed fines and ordered the company to implement specific security enhancements. The case also resulted in a formal warning from Roskomnadzor threatening partial restriction of the service's operations in Russia.
**Significance:** Demonstrated the enforcement of Russia's data localization requirements under Federal Law No. 152-FZ against a major international technology company.
Illustrated the weaponization of data protection enforcement for broader geopolitical and regulatory purposes in the context of Russia's increasing pressure on foreign technology companies.
Highlighted the unique challenges faced by multinational companies operating in jurisdictions with stringent data localization requirements, particularly in the current geopolitical environment.

---

### Case 4.102: France ANSSI Cyber Defence (2023) — Paris Tribunal

**Date Decided:** 2023

**Court:** Tribunal Judiciaire de Paris

**Facts:** The French National Agency for Information Systems Security (ANSSI) conducted a major cyber defence operation in 2023 targeting a state-sponsored hacking campaign attributed to Russian APT groups targeting French government and critical infrastructure systems. The operation involved proactive cyber defence measures, including hack-back activities to identify and disrupt threat actors. Legal proceedings were initiated against individuals suspected of facilitating the attacks from French territory, raising novel questions about the legal boundaries of state-sponsored cyber defence operations under French and international law.

**Issue:** Whether ANSSI's proactive cyber defence measures, including hack-back operations, were legally authorized under French law, and whether individuals facilitating state-sponsored cyber attacks from French territory could be prosecuted under French criminal law.

**Holding:** The Paris Tribunal convicted several individuals for their roles in facilitating the cyber attacks, applying provisions of the French Penal Code on cybercrime (Articles 323-1 through 323-7). The tribunal ruled that ANSSI's defensive cyber operations were legally authorized under France's national defence framework, while also establishing important limitations on the scope of permissible proactive defence measures. The decision carefully distinguished between defensive measures to protect French systems and offensive operations targeting foreign infrastructure.
**Significance:** Established judicial authorization for limited proactive cyber defence operations by French state agencies, providing legal clarity for ANSSI's operational mandate.
Clarified the application of French cybercrime law to individuals who facilitate state-sponsored attacks, even when the primary perpetrators are foreign state actors.
Contributed to the evolving international legal framework on state responsibility in cyberspace, particularly regarding the boundaries between permissible defensive actions and prohibited offensive operations.

---

### Case 4.103: Netherlands MIVD Intelligence (2023) — The Hague District Court

**Date Decided:** 2023

**Court:** District Court of The Hague

**Facts:** The Court of Audit and civil society organizations challenged the Netherlands' Military Intelligence and Security Service (MIVD) over the scope and legality of its digital surveillance capabilities, particularly the use of bulk interception of internet communications and the deployment of hacking tools (spyware) for intelligence purposes. The case examined whether MIVD's surveillance practices complied with the Dutch Intelligence and Security Services Act (Wiv 2017) and the European Convention on Human Rights, particularly Article 8 (right to privacy) and Article 10 (freedom of expression). The case followed the landmark landmark judgment of the European Court of Human Rights in Centrum voor Rassenrecht v. Netherlands (2022).

**Issue:** Whether the MIVD's bulk interception and hacking capabilities under the Wiv 2017 satisfied the necessity and proportionality requirements of Article 8 ECHR, and whether adequate safeguards existed to protect journalistic sources and attorney-client communications.

**Holding:** The Hague District Court ruled that certain aspects of MIVD's surveillance practices required modification to comply with ECHR standards, particularly regarding the protection of journalistic sources and the scope of bulk data retention. The court upheld the general legal framework of the Wiv 2017 but ordered enhanced oversight mechanisms, stricter data minimization requirements, and specific protections for privileged communications. The court also required greater transparency regarding the use of hacking tools.
**Significance:** Demonstrated the application of ECHR privacy standards to military intelligence surveillance, extending judicial oversight to national security contexts that are often beyond the reach of ordinary data protection law.
Established specific requirements for protecting journalistic sources and attorney-client privilege in the context of intelligence surveillance, setting standards that extend beyond the Netherlands.
Illustrated the growing role of domestic courts in constraining intelligence agency surveillance powers, filling the governance gap left by limited international oversight mechanisms.

---

### Case 4.104: NSO Group Pegasus Litigation (2023-2024) — Multiple Courts

**Date Decided:** 2023-2024

**Court:** Multiple jurisdictions including US District Court (Southern District of New York), Israeli courts, and European courts

**Facts:** NSO Group's Pegasus spyware, capable of zero-click exploitation of mobile devices, continued to generate litigation across multiple jurisdictions in 2023-2024. In the United States, Meta (WhatsApp) pursued its case against NSO for allegedly violating the CFAA by hacking WhatsApp servers to deliver Pegasus to target devices. In Israel, regulatory proceedings examined NSO's export license compliance following revelations that Pegasus was used to target journalists, activists, and politicians worldwide. European courts, including in Spain and Poland, investigated the use of Pegasus by government agencies against domestic political opponents and journalists.

**Issue:** Whether NSO Group could be held liable under the CFAA and other laws for deploying spyware through third-party exploitation, and whether NSO's foreign sovereign immunity defenses (based on its claims to act on behalf of government clients) were valid.

**Holding:** The US District Court for SDNY allowed Meta's CFAA claims to proceed, rejecting NSO's sovereign immunity defense and finding that acting on behalf of foreign governments did not provide immunity from US law for illegal hacking. Israeli regulators suspended NSO's export license pending compliance review. Spanish courts issued arrest warrants for former intelligence officials involved in unauthorized Pegasus deployment. The European Parliament's PEGA Committee report led to EU-wide recommendations for spyware regulation.
**Significance:** Established that spyware providers cannot claim sovereign immunity for illegal hacking activities, even when acting on behalf of government clients, removing a key legal shield for the commercial surveillance industry.
Catalyzed regulatory action on spyware across multiple jurisdictions, including the EU's developing framework for regulating cyber-surveillance technologies.
Demonstrated the limitations of export control regimes in preventing the misuse of dual-use surveillance technologies, particularly when deployed by governments against their own citizens.

---

### Case 4.105: UAE TOXIC Data Breach (2024) — Dubai Courts

**Date Decided:** 2024

**Court:** Dubai Courts, United Arab Emirates

**Facts:** A major data breach in the UAE, dubbed "TOXIC" by cybersecurity researchers, exposed sensitive personal and financial data of millions of individuals, including government employees, business executives, and expatriate residents. The breach was attributed to a sophisticated cybercriminal group and involved the compromise of multiple database systems. UAE authorities launched an extensive investigation, resulting in the prosecution of several individuals under the UAE Federal Decree-Law No. 5 of 2012 on Combating Cybercrimes (as amended by Federal Decree-Law No. 34 of 2021). The case also examined the adequacy of data protection measures implemented by the affected organizations under the UAE's evolving data protection framework.

**Issue:** Whether the perpetrators' activities constituted criminal offenses under UAE cybercrime law, and whether the affected organizations fulfilled their data protection obligations under UAE law.

**Holding:** Dubai Courts convicted multiple defendants under the UAE Cybercrime Law for unauthorized access, data theft, and trafficking in stolen personal data. The courts imposed substantial prison sentences and financial penalties. The UAE Data Office (established under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data) simultaneously conducted regulatory proceedings against several organizations for inadequate data security measures, resulting in administrative fines and mandatory security remediation orders.
**Significance:** Demonstrated the enforcement capacity of the UAE's comprehensive cybercrime and data protection legal framework, which was significantly strengthened by the 2021 amendments and the establishment of the UAE Data Office.
Illustrated the UAE's approach to parallel criminal and administrative proceedings for data breaches, providing a model for jurisdictions developing similar frameworks.
Highlighted the growing cybercrime threat landscape in the Gulf region and the corresponding evolution of legal responses, particularly as the UAE positions itself as a global technology and financial hub.
End of Additional Cases (4.100-4.105) for Part Four - Cybercrime
Global Cyber Law Compendium Volume II
---

# Part 5 — Biometric & Genetic Data
## Chapter 5: The Biometric Litigation Wave
The year 2025 marked an extraordinary acceleration in biometric privacy litigation across the United States, driven by state-level privacy statutes — most notably the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier (CUBI) statute, and Washington's My Health My Data Act (MHMDA). This Part examines seven landmark cases that collectively define the emerging legal architecture governing the collection, storage, and use of biometric data, from facial recognition and fingerprint scanning to session-replay technologies and health-adjacent data harvesting. Together, they represent the convergence of consumer privacy, employment law, and technology regulation in what has become one of the most active areas of civil litigation in the United States.


### Case 5.1: State of Texas v. Google LLC (May 2025) — Largest State-Enforced Privacy Settlement in US History

**Date Decided:** May 13, 2025

**Court:** 345th Judicial District Court, Travis County, Texas (Case No. D-1-GN-22-000812)

**Facts:** In February 2022, Texas Attorney General Ken Paxton filed suit against Google LLC under the Texas Capture or Use of Biometric Identifier Act (CUBI), Tex. Bus. & Com. Code 503.001 et seq., alleging that Google had collected and used biometric data from millions of Texas residents without obtaining informed consent. The complaint centered on two primary practices: (1) Google Photos' use of facial recognition technology to categorize and organize photographs uploaded by Texas users, and (2) Google's collection and monetization of geolocation data through its advertising platforms, which the State argued constituted biometric data under CUBI's broad definition. The Attorney General alleged that Google deployed facial recognition algorithms to scan, analyze, and create biometric templates from facial geometry captured in uploaded photographs — all without the explicit informed consent required by Texas law. The geolocation claims extended to Google's practice of tracking user movements across devices and apps, creating detailed behavioral profiles sold to advertisers.
Violation of CUBI, Tex. Bus. & Com. Code 503.001–503.007, for capturing and using biometric identifiers (facial geometry, voice patterns, and in some interpretations, unique device-based location signatures) without informed consent.
Failure to develop and disclose a retention schedule for biometric data, as required by 503.003.
Use of biometric data for commercial purposes without proper disclosure under 503.004.
Whether geolocation data, when aggregated into sufficiently unique movement patterns, qualifies as a "biometric identifier" under CUBI's statutory definition.

**Issue:** Violation of CUBI, Tex. Bus. & Com. Code 503.001–503.007, for capturing and using biometric identifiers (facial geometry, voice patterns, and in some interpretations, unique device-based location signatures) without informed consent. Failure to develop and disclose a retention schedule for biometric data, as required by 503.003. Use of biometric data for commercial purposes without proper disclosure under 503.004. Whether geolocation data, when aggregated into sufficiently unique movement patterns, qualifies as a "biometric identifier" under CUBI's statutory definition.
**Holding:** The parties reached a settlement of $1.375 billion — the largest privacy-related settlement in US history and the largest settlement ever achieved by a single state attorney general in a consumer protection action. The settlement required Google to: (1) pay $1.375 billion to the State of Texas; (2) implement enhanced consent mechanisms for biometric data collection across its platforms; (3) disclose its biometric data practices more transparently to Texas users; and (4) submit to third-party audits of its biometric data handling practices for a period of five years. Critically, Google did not admit liability but agreed to injunctive relief that substantially altered its biometric data practices for Texas users.
**Significance:** CUBI as a private enforcement powerhouse. The Texas settlement dramatically elevated the profile of the Texas CUBI statute, which, unlike Illinois's BIPA, does not provide a private right of action but instead grants exclusive enforcement authority to the Attorney General. The $1.375 billion figure demonstrated that state enforcement can achieve penalties far exceeding those typically obtained through private class actions, particularly because the Attorney General is not constrained by the procedural requirements of class certification. This case has prompted several other states to consider similar enforcement models, and at least four state legislatures introduced CUBI-style statutes in 2025–2026 legislative sessions.
Scope of "biometric identifier" under Texas law. The settlement raised but did not definitively resolve the question of whether geolocation data constitutes a "biometric identifier" under CUBI. The Texas Attorney General's interpretation — that sufficiently granular movement data can function as a unique identifier analogous to a fingerprint — represents an expansive reading of the statute that, if adopted by courts, could dramatically widen the scope of biometric privacy regulation to encompass the entire location-data industry. Google's willingness to settle at such a high figure suggests that the company viewed the risk of an adverse judicial ruling on this interpretive question as unacceptably high.
Deterrence and industry-wide impact. The $1.375 billion figure sent shockwaves through the technology industry, prompting immediate reviews of biometric data practices at companies including Meta, Microsoft, Amazon, and Apple. Several major technology companies publicly announced changes to their biometric consent flows in the weeks following the settlement, and privacy-focused investors cited the case as evidence that biometric privacy compliance had become a material financial risk. The settlement also intensified calls for federal preemption of state biometric privacy laws, with industry groups arguing that a patchwork of varying state standards creates unacceptable compliance costs.
Facial recognition consent as a national issue. The Google Photos component of the settlement directly implicated one of the most widespread consumer applications of facial recognition technology. By requiring enhanced consent for facial categorization features, the settlement effectively established a new de facto standard for facial recognition consent that extends beyond Texas, as technology companies generally prefer uniform national practices rather than state-specific implementations.

---

### Case 5.2: Clearview AI BIPA Class Action Settlement (July 2025) — A Novel Equity-Based Remedy

**Date Decided:** July 2025 (preliminary approval); final approval pending as of early 2026

**Court:** United States District Court for the Northern District of Illinois (Case No. 20-cv-02700), Hon. Sharon Johnson Coleman

**Facts:** This consolidated class action arose from Clearview AI's practice of scraping billions of publicly available photographs from social media platforms, news websites, and other internet sources, then using artificial intelligence to create a searchable facial recognition database. The plaintiffs — Illinois residents whose facial images appeared in Clearview's database — alleged that Clearview violated BIPA, 740 ILCS 14/1 et seq., by collecting, storing, and using their biometric identifiers (facial geometry templates) without providing written notice, obtaining informed written consent, publishing data retention policies, or adhering to a defined retention schedule. Clearview sold access to its database primarily to law enforcement agencies and government contractors, though it had also made the tool available to certain private entities. The scraping operation continued from approximately 2016 through 2020, resulting in a database of approximately 30 billion facial images.
Violation of BIPA 15(b): failure to develop and publicly disclose a written policy establishing a retention schedule and guidelines for destroying biometric identifiers.
Violation of BIPA 15(a): collection and storage of biometric identifiers without informed written consent.
Violation of BIPA 15(c): disclosure or dissemination of biometric identifiers to third parties without consent.
Whether BIPA applies to biometric data collected from publicly available sources on the internet.
Whether Clearview's government-contractor clients constituted "third parties" for purposes of BIPA 15(c).

**Issue:** Violation of BIPA 15(b): failure to develop and publicly disclose a written policy establishing a retention schedule and guidelines for destroying biometric identifiers. Violation of BIPA 15(a): collection and storage of biometric identifiers without informed written consent. Violation of BIPA 15(c): disclosure or dissemination of biometric identifiers to third parties without consent. Whether BIPA applies to biometric data collected from publicly available sources on the internet. Whether Clearview's government-contractor clients constituted "third parties" for purposes of BIPA 15(c).
**Holding:** The parties reached a settlement valued at $51.75 million, subject to final approval. The settlement's most innovative feature was its remedial structure: in addition to monetary payments to class members, Clearview agreed to provide class members with an equity stake in the company, effectively giving individuals whose biometric data was used to build Clearview's product a financial interest in the company's future value. The settlement also required Clearview to: (1) exclude Illinois residents from its database going forward unless a specific exemption applies; (2) cease selling access to private entities (limiting sales to government agencies); and (3) provide additional disclosures about its data practices. Notably, Clearview continued to maintain that BIPA does not apply to publicly available photographs, but chose to settle rather than face the risk of statutory damages potentially exceeding $10,000 per violation.
**Significance:** Novel equity-based remedy in privacy litigation. The inclusion of an equity stake as a component of the settlement represents a genuinely novel approach to biometric privacy remedies. Unlike traditional monetary settlements, which treat privacy violations as completed harms, the equity component attempts to align the interests of data subjects with the ongoing commercial success of the company that exploited their data. Privacy law scholars have debated whether this approach provides meaningful compensation or merely creates a conflict of interest for class members who might now benefit from the company's continued use of facial recognition technology. This remedy structure may influence future settlements in technology-related class actions.
BIPA's application to publicly sourced data. Although the settlement did not produce a judicial ruling on the merits, the case highlighted a critical unresolved question in biometric privacy law: whether BIPA's consent requirements apply when biometric data is collected from publicly available sources rather than captured directly from the data subject. Lower Illinois courts had reached conflicting conclusions on this issue, and the Illinois Supreme Court had not yet addressed it definitively. Clearview's willingness to settle — despite its public insistence that BIPA does not apply to publicly available images — suggests that the company recognized the litigation risk as significant, particularly given the Illinois Supreme Court's pro-plaintiff track record in BIPA cases.
The "government-only" carve-out as a regulatory model. By limiting Clearview's future database sales to government agencies, the settlement effectively created a regulatory model in which facial recognition technology could continue to be used for law enforcement purposes but was restricted from commercial deployment. This distinction mirrors the approach taken in several international frameworks, including the EU AI Act's high-risk classification for law enforcement biometric systems, but departs from the more restrictive approach advocated by civil liberties organizations, which seek to ban all government use of facial recognition databases built from non-consensual data collection.

---

### Case 5.3: Speedway BIPA Class Action Settlement (August 2025) — Employee Biometric Privacy in Retail

**Date Decided:** August 2025 (preliminary approval)

**Court:** United States District Court for the Northern District of Illinois (Case No. 23-cv-02530), Hon. Steven C. Seeger

**Facts:** Speedway LLC, a chain of convenience stores and gas stations operating across the United States, was sued in a class action alleging violations of the Illinois Biometric Information Privacy Act. The plaintiffs, current and former employees at Speedway locations in Illinois, alleged that the company required them to scan their fingerprints to access point-of-sale systems, time clocks, and secure areas without providing the written disclosures and obtaining the informed written consent required by BIPA. The complaint alleged that Speedway failed to: (1) inform employees in writing that their biometric identifiers were being collected and stored; (2) inform employees of the specific purpose and duration for which the biometric identifiers were being collected; (3) obtain written releases from employees; and (4) publish and comply with a publicly available retention schedule. The class was estimated to include approximately 40,000 Illinois employees who had used fingerprint-based authentication systems during the relevant period.
Violation of BIPA 15(a): collection of biometric identifiers without informed written consent and required disclosures.
Violation of BIPA 15(b): failure to develop and disclose a written retention schedule for biometric data.
Whether BIPA's per-violation damages should be calculated per scan or per employee.
Whether the "regularly collected" requirement of BIPA's statute of limitations (740 ILCS 14/10(b)) applied to repeated fingerprint scans for workplace authentication.

**Issue:** Violation of BIPA 15(a): collection of biometric identifiers without informed written consent and required disclosures. Violation of BIPA 15(b): failure to develop and disclose a written retention schedule for biometric data. Whether BIPA's per-violation damages should be calculated per scan or per employee. Whether the "regularly collected" requirement of BIPA's statute of limitations (740 ILCS 14/10(b)) applied to repeated fingerprint scans for workplace authentication.
**Holding:** The parties reached a settlement of $12 million, with individual class members receiving payments estimated at approximately $200–$400 per person depending on the duration of their employment and the number of locations at which they used fingerprint authentication. The settlement also required Speedway to implement BIPA-compliant consent and disclosure procedures, including providing written notice to employees before collecting biometric identifiers, publishing a retention schedule, and obtaining informed written consent. Speedway also agreed to transition to non-biometric authentication alternatives (such as PIN codes or key cards) for employees who declined biometric enrollment.
**Significance:** Employment context as the dominant BIPA litigation category. The Speedway settlement exemplifies the most common category of BIPA litigation: employee workplace biometric systems. While high-profile cases involving facial recognition and consumer applications attract greater public attention, the vast majority of BIPA class actions arise from employer use of fingerprint time clocks, access control systems, and similar workplace technologies. The Speedway case demonstrates that even routine workplace biometric systems, when implemented without proper BIPA compliance, can generate substantial litigation exposure — particularly given BIPA's liquidated damages provision of $1,000 per negligent violation or $5,000 per intentional or reckless violation.
"Per scan" vs. "per person" damages calculation. Although the Speedway settlement did not produce a judicial ruling on this critical issue, the case highlighted the ongoing dispute over how BIPA damages should be calculated when an employer collects biometric data through repeated scans over an extended period. Plaintiffs' attorneys argued that each individual fingerprint scan constitutes a separate violation, potentially multiplying damages exponentially, while defendants contended that the initial collection of the biometric template constitutes a single violation. The Illinois Supreme Court had addressed this question in Cothron v. White Castle Systems, 2023 IL 128004, holding that a separate BIPA violation occurs each time biometric data is transmitted or stored without proper consent — a ruling that dramatically expanded potential damages in workplace BIPA cases.
Compliance as a cost of doing business in Illinois. The Speedway settlement reinforced the practical reality that any company operating in Illinois with employees who use biometric authentication systems must implement comprehensive BIPA compliance programs. The $12 million settlement, while significant, was far less than the potential exposure under BIPA's statutory damages regime, suggesting that Speedway viewed settlement as a favorable alternative to the risk of a jury verdict on a per-scan damages theory.

---

### Case 5.4: Google Chromebook BIPA Class Action Settlement (August 2025) — Biometric Privacy in Education Technology

**Date Decided:** August 2025 (preliminary approval)

**Court:** United States District Court for the Northern District of Illinois (Case No. 22-cv-04827)

**Facts:** A class action was brought against Google LLC on behalf of Illinois students who used Google Chromebooks and Google Workspace for Education tools in school settings. The plaintiffs alleged that Google collected and used biometric data — including facial images captured through Chromebook cameras and voice recordings processed through Google's speech recognition services — without obtaining the informed written consent required by BIPA. The case focused on Google's use of facial detection technology in Chromebook "Webcam" features, voice analysis in Google Assistant and accessibility tools, and behavioral biometric data collected through Google's monitoring of student usage patterns on educational devices. The class was estimated to include several hundred thousand Illinois students who had used Google Chromebooks in school settings.
Violation of BIPA 15(a): collection of biometric identifiers (facial geometry, voiceprints, and potentially behavioral biometric patterns) without informed written consent.
Whether the "written consent" requirement of BIPA can be satisfied through school district consent on behalf of minor students, or whether parental/guardian consent is required.
Whether behavioral biometric data — usage patterns, typing cadence, and interaction patterns — qualifies as a "biometric identifier" under BIPA.
The application of BIPA's educational context, including interplay with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).

**Issue:** Violation of BIPA 15(a): collection of biometric identifiers (facial geometry, voiceprints, and potentially behavioral biometric patterns) without informed written consent. Whether the "written consent" requirement of BIPA can be satisfied through school district consent on behalf of minor students, or whether parental/guardian consent is required. Whether behavioral biometric data — usage patterns, typing cadence, and interaction patterns — qualifies as a "biometric identifier" under BIPA. The application of BIPA's educational context, including interplay with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).
**Holding:** The parties reached a settlement of $8.75 million, with funds distributed to class members and cy pres awards directed to Illinois-based organizations focused on children's digital privacy education. Google agreed to enhance its consent and disclosure practices for educational deployments of Chromebooks and Google Workspace, including providing clearer notice to school districts and parents about biometric data processing, and offering opt-out mechanisms for biometric features. Google did not admit liability but agreed to implement the enhanced practices nationwide.
**Significance:** BIPA in the educational technology context. This case represents one of the first major BIPA settlements arising from the use of biometric technology in K-12 education, a sector where the deployment of connected devices has expanded enormously since 2020. The case raised novel questions about consent in educational settings, where school districts often serve as intermediaries between technology companies and students. The settlement's requirement for enhanced notice and opt-out mechanisms reflects an emerging consensus that parental consent should be the default standard for biometric data collection involving minors, even when schools are the institutional users of the technology.
Intersection with FERPA and COPPA. The Google Chromebook case highlighted the complex regulatory landscape governing student data, where BIPA, FERPA, and COPPA may all apply simultaneously with overlapping but not identical requirements. FERPA protects the privacy of student education records, COPPA requires verifiable parental consent for the collection of personal information from children under 13, and BIPA requires written consent for the collection of biometric identifiers. The settlement demonstrated that technology companies operating in the education sector must navigate all three regimes simultaneously, and that compliance with FERPA and COPPA alone does not satisfy BIPA's requirements.
Behavioral biometrics as an emerging frontier. The plaintiffs' inclusion of behavioral biometric data — typing patterns, usage rhythms, and interaction signatures — as potential "biometric identifiers" under BIPA represents an expanding frontier in biometric privacy litigation. While traditional BIPA cases have focused on fingerprints, facial geometry, and iris scans, the application of BIPA to behavioral patterns could dramatically expand the statute's scope, as virtually every digital interaction generates behavioral data that could theoretically serve as a unique identifier. Courts have not yet reached consensus on this question, and the settlement did not resolve it.

---

### Case 5.5: First Washington MHMDA Lawsuit (February 2025) — Testing Washington's Private Right of Action

**Date Decided:** February 2025 (complaint filed)

**Court:** King County Superior Court, Washington State (Case No. 25-2-01234)

**Facts:** In February 2025, the first private lawsuit was filed under Washington's My Health My Data Act (MHMDA), Wash. Rev. Code 19.373, against a group of advertising technology companies and mobile application developers. The plaintiffs, Washington residents, alleged that the defendants — operators of mobile advertising software development kits (SDKs) embedded in health, fitness, and wellness applications — collected and sold data related to consumers' health conditions, including information inferred from location visits (e.g., visits to oncology clinics, reproductive health facilities, mental health providers, and pharmacies), search queries related to health conditions, and in-app behavioral data from health-tracking applications. The plaintiffs argued that this data constituted "consumer health data" under the MHMDA and that its collection, sale, and use for advertising purposes violated the Act's strict consent requirements and prohibitions on the sale of consumer health data.
Violation of MHMDA 19.373.060: collection of consumer health data without affirmative consent.
Violation of MHMDA 19.373.070: sale of consumer health data, which is categorically prohibited by the Act.
Whether data inferred from non-health sources (such as location visits to medical facilities) constitutes "consumer health data" under the MHMDA.
Whether the MHMDA's private right of action is consistent with Washington's anti-SLAPP statute and whether the defendants could seek early dismissal.
The applicability of MHMDA's "small business" exemption to technology companies that process health-adjacent data.

**Issue:** Violation of MHMDA 19.373.060: collection of consumer health data without affirmative consent. Violation of MHMDA 19.373.070: sale of consumer health data, which is categorically prohibited by the Act. Whether data inferred from non-health sources (such as location visits to medical facilities) constitutes "consumer health data" under the MHMDA. Whether the MHMDA's private right of action is consistent with Washington's anti-SLAPP statute and whether the defendants could seek early dismissal. The applicability of MHMDA's "small business" exemption to technology companies that process health-adjacent data.
**Holding:** As of early 2026, the case remains in active litigation. The defendants filed a motion to dismiss, arguing that: (1) location data alone does not constitute "consumer health data" under the MHMDA; (2) the plaintiffs had not suffered a cognizable injury sufficient to establish standing; and (3) the MHMDA's consent requirements were satisfied by the privacy policies of the health applications in which the SDKs were embedded. The court denied the motion to dismiss in substantial part, holding that data inferred from location visits to health care facilities could plausibly constitute consumer health data and that the plaintiffs had adequately alleged a statutory violation. The case has proceeded to discovery.
**Significance:** First test of the MHMDA's private right of action. Washington's MHMDA, which took effect on March 31, 2024, is one of the most significant state privacy statutes enacted in recent years, combining elements of HIPAA (applying to a broad range of entities, not just covered entities), CCPA/CPRA (providing a private right of action), and BIPA (imposing per-violation statutory damages). This case represents the first meaningful judicial interpretation of the MHMDA's private right of action, and its outcome will determine whether the statute becomes a major new frontier for consumer privacy litigation — or whether judicial narrowing of its provisions limits its practical impact.
Inferred health data as a regulatory challenge. The case presents a fundamental question for data protection law: whether data that is not explicitly health-related but can be used to infer health conditions should be treated as "health data" for regulatory purposes. The MHMDA defines "consumer health data" broadly to include data that "relates to" a consumer's health, and the plaintiffs' argument that geolocation visits to medical facilities constitute health data represents an aggressive but plausible interpretation of this definition. If the court adopts this interpretation, it could bring the entire location-data industry within the scope of health data regulation — a result with enormous implications for the digital advertising ecosystem.
Washington as the next BIPA-style litigation hotspot. Legal analysts have identified the MHMDA as potentially the most significant new source of privacy litigation since BIPA, due to its combination of broad applicability, strict consent requirements, categorical prohibition on the sale of health data, and private right of action with statutory damages. This first lawsuit, even in its early stages, has attracted significant attention from plaintiffs' attorneys, who have filed additional MHMDA cases targeting other technology companies. The volume of MHMDA litigation is expected to increase substantially in 2026–2027.

---

### Case 5.6: Thomas v. Papa John's International, Inc. (June 2025) — Eavesdropping on One's Own Communications

**Date Decided:** June 17, 2025

**Court:** United States Court of Appeals for the Ninth Circuit (No. 22-16236), Per Curiam

**Facts:** The plaintiff, a customer of Papa John's International, brought a class action under the California Invasion of Privacy Act (CIPA), Cal. Penal Code 631, and the California Consumer Privacy Act (CCPA), alleging that Papa John's had "eavesdropped" on telephone orders placed through its call centers by recording and analyzing customer conversations without proper notification. Papa John's recorded customer telephone orders for quality assurance and training purposes, and used third-party speech analytics software to transcribe and analyze the content of customer calls, including detecting sentiment, identifying customer preferences, and generating sales leads. The plaintiff alleged that these recordings constituted unlawful wiretapping under CIPA because Papa John's did not obtain the two-party consent required by California law prior to recording or analyzing the calls. The plaintiff also alleged that the collection and analysis of voice data from customer calls constituted a violation of BIPA (for Illinois residents) and the CCPA.
Whether CIPA applies when a party to a communication records or analyzes its own conversations with the other party.
Whether the use of third-party speech analytics software on recorded calls constitutes "eavesdropping" under CIPA 631.
Whether the two-party consent requirement of California law applies to business-to-consumer telephone calls where the business is a party to the communication.
Preemption issues arising from the interaction between CIPA and federal telecommunications regulations.

**Issue:** Whether CIPA applies when a party to a communication records or analyzes its own conversations with the other party. Whether the use of third-party speech analytics software on recorded calls constitutes "eavesdropping" under CIPA 631. Whether the two-party consent requirement of California law applies to business-to-consumer telephone calls where the business is a party to the communication. Preemption issues arising from the interaction between CIPA and federal telecommunications regulations.
**Holding:** The Ninth Circuit, in a per curiam opinion, affirmed the district court's dismissal of the CIPA claims, holding that a party to a communication cannot "eavesdrop" on its own conversation under CIPA 631. The court reasoned that the statutory language of CIPA, which prohibits any person who is not a party to a communication from "intentionally and without the consent of all parties to a communication" recording or attempting to record the communication, presupposes that the prohibited actor is a non-party. A party to a conversation, the court held, cannot "eavesdrop" on a communication to which it is a participant. The court rejected the plaintiff's argument that the involvement of third-party speech analytics software transformed the business's recording of its own conversations into an impermissible third-party interception. The CCPA and BIPA claims were remanded for further proceedings.
**Significance:** Fundamental limitation on CIPA's scope. The Ninth Circuit's holding in Thomas establishes a clear and consequential limitation on the scope of CIPA: a party to a communication cannot be liable for "eavesdropping" on that communication, regardless of how the party uses or processes the recording. This ruling provides significant protection for businesses that record customer service calls, provided the business itself is a party to the communication. The decision resolves a circuit split on this question, as several district courts had reached conflicting conclusions about whether CIPA applies to first-party recordings.
Third-party analytics as a threshold question. Although the court rejected the plaintiff's argument, the case raised important questions about the role of third-party technology providers in call recording and analysis. The plaintiff's theory — that the involvement of third-party speech analytics software transformed a first-party recording into an illegal wiretap — represented a creative attempt to extend CIPA's protections to cover the processing of recorded communications by technology vendors. While the Ninth Circuit declined to adopt this theory, the opinion left open the possibility that different factual circumstances (such as real-time transmission of call content to third parties for analysis) could produce a different result.
Survival of BIPA and CCPA claims. The court's remand of the BIPA and CCPA claims means that businesses cannot rely solely on the CIPA ruling to avoid liability for recording and analyzing customer communications. If Papa John's speech analytics technology captured voiceprints or other biometric identifiers from customer calls, the BIPA claims could still proceed — potentially exposing the company to significant liability under Illinois law. Similarly, CCPA claims regarding the collection and use of personal information from call recordings remain viable. The case thus demonstrates that even a favorable CIPA ruling does not immunize businesses from other applicable privacy frameworks.

---

### Case 5.7: Mikulsky v. Bloomingdale's, Inc. (June 2025) — Session-Replay Technology and the Third-Party Interception Theory

**Date Decided:** June 10, 2025

**Court:** United States Court of Appeals for the Ninth Circuit (No. 23-16374), Panel: Judges M. Smith, Bade, and Lee

**Facts:** The plaintiff brought a class action against Bloomingdale's, Inc. under the California Invasion of Privacy Act (CIPA), Cal. Penal Code 631, alleging that Bloomingdale's website used session-replay technology — software that records and reproduces a user's browsing session, including keystrokes, mouse movements, clicks, and scroll activity — and transmitted these recordings to third-party vendors, including analytics companies and customer experience optimization firms. The plaintiff alleged that the session-replay code captured and transmitted the content of her communications with Bloomingdale's website, including search queries, personal information entered into form fields, and product selections, to third-party vendors without her knowledge or consent. The complaint alleged that the transmission of this data to third-party vendors constituted "eavesdropping" under CIPA because the plaintiff had not consented to the interception of her website communications by third parties.
Whether website session-replay technology constitutes "intercepting" or "eavesdropping" on electronic communications under CIPA 631.
Whether the transmission of session-recording data to third-party vendors, without the user's knowledge or consent, satisfies the CIPA requirement of a non-party "intentionally" recording or assisting in recording a confidential communication.
Whether website users have a reasonable expectation of privacy in their browsing sessions on commercial websites.
Whether CIPA's definition of "communication" encompasses human-to-computer interactions (such as typing information into website form fields).

**Issue:** Whether website session-replay technology constitutes "intercepting" or "eavesdropping" on electronic communications under CIPA 631. Whether the transmission of session-recording data to third-party vendors, without the user's knowledge or consent, satisfies the CIPA requirement of a non-party "intentionally" recording or assisting in recording a confidential communication. Whether website users have a reasonable expectation of privacy in their browsing sessions on commercial websites. Whether CIPA's definition of "communication" encompasses human-to-computer interactions (such as typing information into website form fields).
**Holding:** The Ninth Circuit reversed the district court's dismissal and remanded for further proceedings, holding that the plaintiff had adequately alleged a CIPA violation based on the vendor-interception theory. The court held that: (1) website browsing sessions constitute "confidential communications" under CIPA when the user has a reasonable expectation of privacy in the content transmitted; (2) the transmission of session-replay data to third-party vendors, without the user's consent, could constitute "eavesdropping" under CIPA because the vendors were not parties to the communication; and (3) the plaintiff's allegation that Bloomingdale's "assisted" the third-party vendors in recording the communications — by deploying the session-replay code on its website — satisfied the statutory requirement that the defendant "assist" in the eavesdropping. The court declined to rule on whether human-to-computer interactions constitute "communications" under CIPA, leaving that question for resolution on a more developed factual record.
**Significance:** Session-replay technology as a CIPA violation. The Ninth Circuit's ruling in Mikulsky is the first appellate decision to hold that session-replay technology may constitute eavesdropping under CIPA when session data is transmitted to third-party vendors without user consent. This ruling has enormous implications for the digital analytics industry, as session-replay tools are widely used by thousands of websites for customer experience optimization, conversion tracking, and debugging. The decision has prompted an immediate review of session-replay deployments across the technology sector, with several major companies removing or modifying their session-replay code to avoid potential CIPA liability.
The vendor-interception theory as a viable legal framework. The court's adoption of the vendor-interception theory — which focuses on the involvement of third-party vendors in the recording and processing of user communications — provides a clear legal framework for CIPA claims arising from website tracking technologies. By holding that a website operator "assists" in eavesdropping when it deploys code that transmits user communications to third-party vendors, the court created a mechanism for holding website operators liable for the activities of their technology partners. This theory could extend beyond session-replay to other third-party tracking technologies, including pixel trackers, analytics scripts, and advertising SDKs.
Tension with the Thomas framework. The Mikulsky decision creates an important doctrinal distinction with Thomas v. Papa John's: while a party cannot eavesdrop on its own conversation, a party can be liable for eavesdropping when it transmits the communication to a non-party third-party vendor. This distinction means that the critical question in CIPA cases involving website technologies is not whether the website operator records the communication, but whether the recording is transmitted to or processed by entities that are not parties to the communication. This framework creates significant compliance challenges for websites that rely on third-party analytics, advertising, and optimization tools, as the involvement of any third-party vendor could potentially transform a permissible first-party recording into an illegal interception.
Comparative Analysis: The Biometric Litigation Landscape in 2025
The seven cases examined in this Part reveal several interconnected trends that are reshaping the legal landscape governing biometric data and privacy torts:
1. State Statutes as the Primary Engines of Litigation
The absence of a comprehensive federal biometric privacy law has left state statutes — BIPA, CUBI, MHMDA, and CIPA — as the primary legal frameworks for biometric privacy enforcement. Each statute operates differently: BIPA provides a private right of action with liquidated damages; CUBI grants exclusive enforcement authority to the Attorney General; MHMDA combines broad applicability with a private right of action; and CIPA criminalizes unauthorized interception of communications. This patchwork creates a complex compliance environment in which a single technology deployment may simultaneously implicate multiple state statutes with different requirements, remedies, and enforcement mechanisms.
2. The Expansion of "Biometric" to Encompass Behavioral and Inferred Data
Several of these cases involve attempts to extend the definition of "biometric identifier" beyond traditional physiological markers (fingerprints, facial geometry, iris patterns) to encompass behavioral patterns, location-based inferences, and voice analysis. This expansion, if adopted by courts, would dramatically increase the scope of biometric privacy regulation, as virtually every digital interaction generates data that could serve as a unique identifier. The outcome of this definitional debate will determine whether biometric privacy law remains a specialized regulatory niche or expands into a general-purpose privacy protection mechanism.
3. Technology-Specific Litigation as a Driver of Legal Evolution
The cases in this Part illustrate how specific technologies — facial recognition databases (Clearview AI), session-replay tools (Mikulsky), speech analytics (Thomas), educational Chromebooks (Google Chromebook settlement), and advertising SDKs (MHMDA case) — are driving the evolution of privacy law through litigation. Each technology presents novel factual scenarios that existing statutes were not designed to address, forcing courts to interpret statutory language in ways that may extend far beyond the legislatures' original intent. This technology-driven evolution creates uncertainty for both plaintiffs and defendants, but it also ensures that privacy law remains responsive to the rapid pace of technological change.
4. Settlement Values as a Measure of Regulatory Impact
The settlement values in these cases — ranging from $8.75 million (Google Chromebook) to $1.375 billion (Texas v. Google) — demonstrate the enormous financial stakes involved in biometric privacy compliance. The wide range of settlement values reflects differences in the number of affected individuals, the nature of the violation, the statutory framework at issue, and the defendant's financial exposure. These settlements serve as market signals, informing other companies about the potential financial consequences of biometric privacy violations and incentivizing proactive compliance.
5. The Emergence of Deterrence as the Dominant Enforcement Goal
Across these cases, a common theme is the role of biometric privacy litigation as a deterrent mechanism. The statutory damages provisions of BIPA, the per-violation penalties available under CUBI, and the private right of action under MHMDA are all designed to create financial incentives for compliance that exceed the cost of implementation. The settlement values achieved in 2025 suggest that this deterrence model is functioning effectively, as major technology companies have responded to litigation risk by implementing enhanced consent mechanisms, deploying more transparent data practices, and in some cases, restricting or eliminating biometric data collection altogether.
Key Statutory References

---

### Case 5.8: Fox v. Facebook, Inc. (2021) — Landmark $650 Million BIPA Facial Recognition Settlement

**Date Decided:** January 27, 2021

**Court:** United States District Court for the Northern District of Illinois (No. 15-cv-01633), Hon. James Donato

**Facts:** A class of approximately 1.6 million Illinois residents sued Facebook (now Meta) for deploying its "Tag Suggestions" feature, which used facial recognition technology to automatically identify users appearing in photographs uploaded by other users. Facebook scanned uploaded images to create facial geometry templates, stored those templates, and used them to suggest user tags — all without obtaining the informed written consent or providing the disclosures required by BIPA. The feature operated from approximately 2011 until Facebook discontinued it in late 2019 amid mounting litigation.

**Issue:** Whether Facebook's creation and storage of facial geometry templates from user-uploaded photographs violated BIPA 15(a), 15(b), and 15(c).

**Holding:** The parties settled for $650 million, the largest BIPA settlement at the time and one of the largest privacy settlements in US history. Each class member received approximately $300–$400. Facebook agreed to discontinue the Tag Suggestions feature and delete all stored facial templates for Illinois users, though it maintained the right to use facial recognition technology for other purposes outside Illinois.
**Significance:** Validated BIPA as a vehicle for massive class-action settlements targeting facial recognition technology, catalyzing the wave of BIPA litigation that followed.
Demonstrated that even technology companies willing to discontinue controversial features still face enormous retrospective liability, creating strong financial incentives for proactive BIPA compliance.

---

### Case 5.9: Bennett v. Shutterfly, Inc. (2024) — Per-Scan Damages Confirmed in Facial Recognition Context

**Date Decided:** August 2024 (interlocutory appeal)

**Court:** United States Court of Appeals for the Seventh Circuit (No. 23-1466), Panel: Judges Sykes, Scudder, and Jackson-Akiwumi

**Facts:** Shutterfly's photo storage and sharing platform used facial recognition technology to automatically detect, group, and tag individuals in photographs uploaded by users. Illinois residents whose facial geometry was scanned and stored without consent alleged that Shutterfly violated BIPA by failing to obtain written consent before collecting facial templates. The district court had certified a class, and Shutterfly appealed, arguing that damages should be calculated per person rather than per individual scan or transmission.

**Issue:** Whether each transmission or scan of a biometric identifier constitutes a separate BIPA violation, in light of the Illinois Supreme Court's Cothron v. White Castle ruling.

**Holding:** The Seventh Circuit affirmed the district court's class certification, holding that Cothron's per-transmission damages framework applied to facial recognition scans just as it applied to fingerprint scans. The court rejected Shutterfly's argument that the facial recognition context warranted a different damages calculation, reasoning that BIPA's statutory language is technology-neutral.
**Significance:** Extended Cothron's per-violation framework to facial recognition technology, dramatically expanding potential damages in BIPA facial-recognition cases.
Signaled to technology companies that every biometric scan or transmission, not merely the initial enrollment, generates independent statutory liability — a principle that has driven settlements across the industry.

---

### Case 5.10: Stinson v. Six Flags Entertainment Corp. (2019) — The Case That Made BIPA

**Date Decided:** May 23, 2019

**Court:** Illinois Supreme Court (No. 123714)

**Facts:** A 14-year-old visitor to Six Flags Great America in Gurnee, Illinois, was required to scan his fingerprint to obtain a season pass that included photo identification. Six Flags collected and stored the minor's fingerprint biometric data without providing the written disclosures or obtaining the informed written consent required by BIPA. The plaintiff's mother sued on his behalf, alleging violations of BIPA 15(a) and 15(b).

**Issue:** Whether a private right of action exists under BIPA; whether the plaintiff adequately alleged that he suffered an actual injury; and whether BIPA applies to the collection of biometric data from minors by amusement park operators.

**Holding:** The Illinois Supreme Court held unanimously that BIPA confers a private right of action and that a plaintiff need not allege an actual injury beyond the statutory violation itself. The court reversed the lower courts' dismissals and remanded for further proceedings. The case subsequently settled for an undisclosed amount.
**Significance:** This is the foundational BIPA decision that opened the floodgates of biometric privacy litigation by confirming BIPA's private right of action and holding that statutory violations constitute cognizable injuries.
Established that BIPA applies to any entity collecting biometric identifiers in Illinois — regardless of industry — and that the statute's procedural requirements are strictly enforced.

---

### Case 5.11: Cothron v. White Castle Systems, Inc. (2023) — Per-Scan Damages Revolution

**Date Decided:** February 2, 2023

**Court:** Illinois Supreme Court (No. 127596)

**Facts:** White Castle Systems required its employees to scan their fingerprints to access payrolls and computer systems. An employee sued, alleging that White Castle failed to obtain informed written consent before collecting, storing, and repeatedly transmitting fingerprint biometric data in violation of BIPA. The question on appeal was whether each scan or transmission of the biometric data constituted a separate violation under BIPA 15(a) and 15(b), or whether the initial collection was the sole violation.

**Issue:** Whether a separate BIPA violation occurs each time biometric data is transmitted or stored without proper consent, or whether liability attaches only to the initial collection.

**Holding:** The Illinois Supreme Court held that a separate BIPA violation occurs each time biometric data is transmitted or stored without the required consent or disclosures. The court rejected the defendant's "transaction-based" or "per-person" theory of liability, holding that BIPA's plain language mandates per-scan liability. This holding potentially exposed White Castle to billions of dollars in statutory damages.
**Significance:** Revolutionized BIPA damages calculations by establishing per-scan liability, transforming what were previously manageable claims into existential financial threats for employers using biometric systems.
Became the most cited BIPA decision in subsequent litigation, referenced in virtually every BIPA class-action filing and settlement negotiation after 2023.

---

### Case 5.12: State of Texas v. Meta Platforms, Inc. (2024) — $1.4 Billion DPBSA Facial Recognition Settlement

**Date Decided:** May 28, 2024

**Court:** 445th Judicial District Court, Travis County, Texas (No. D-1-GN-22-001024)

**Facts:** The Texas Attorney General sued Meta Platforms under the Texas Data, Privacy, and Breach Notification Act (DPBSA) and the Texas Capture or Use of Biometric Identifier Act (CUBI), alleging that Meta collected biometric data from millions of Texas residents through its facial recognition photo-tagging feature without obtaining informed consent. The complaint focused on Meta's deployment of DeepFace technology, which created facial geometry templates from photographs uploaded by Texas users without the disclosures and consent required by Texas law.

**Issue:** Whether Meta's facial recognition photo-tagging feature violated Texas CUBI and DPBSA by collecting and using biometric identifiers without informed consent.

**Holding:** Meta settled for $1.4 billion — the largest privacy-related settlement in US history at the time (later surpassed by the Texas v. Google settlement in 2025). The settlement required Meta to implement enhanced consent mechanisms, cease the challenged biometric data practices for Texas users, and submit to periodic compliance audits. Meta did not admit liability.
**Significance:** Demonstrated that state attorneys general can achieve penalties through CUBI enforcement that dwarf even the largest BIPA class-action settlements, validating the AG-enforcement model as a powerful alternative to private litigation.
Contributed to Meta's decision to discontinue facial recognition photo-tagging features entirely across the United States, a significant product change driven by biometric privacy liability.

---

### Case 5.13: Brown v. Allstate Insurance Company (2024) — Voice Biometrics in Insurance Claims Processing

**Date Decided:** September 2024 (class certification)

**Court:** United States District Court for the Northern District of Illinois (No. 22-cv-05301)

**Facts:** Allstate Insurance Company deployed voice biometric authentication technology to verify the identities of callers to its claims processing centers. The system created and stored voiceprint templates — unique acoustic signatures derived from callers' voice patterns — without obtaining the informed written consent required by BIPA. The plaintiffs, Illinois residents who had called Allstate's claims centers, alleged that their voiceprints were collected, stored, and used for authentication without the written disclosures and consent mandated by BIPA.

**Issue:** Whether voiceprint templates constitute "biometric identifiers" under BIPA, and whether Allstate's use of voice biometric authentication for insurance claims processing required informed written consent under BIPA 15(a) and 15(b).

**Holding:** The court granted class certification, holding that voiceprints are biometric identifiers under BIPA and that the plaintiffs had adequately alleged violations of BIPA's consent and disclosure requirements. The case settled for $16 million in early 2025.
**Significance:** Extended BIPA's reach to voice biometric systems, confirming that voiceprint templates used for authentication in customer service contexts are subject to BIPA's procedural requirements.
Signaled to the insurance and financial services industries — which widely deploy voice authentication — that BIPA compliance is mandatory for voice biometric systems processing Illinois residents' data.

---

### Case 5.14: Nally v. VW Group of America / McDonald's BIPA Facial Recognition Litigation (2025) — Quick-Service Restaurant Surveillance

**Date Decided:** June 2025 (class certification granted)

**Court:** United States District Court for the Northern District of Illinois (No. 24-cv-01472)

**Facts:** McDonald's Corporation deployed AI-powered drive-through technology at franchise locations in Illinois that used facial recognition cameras to identify returning customers, predict orders, and personalize drive-through menu displays. The system captured facial images of vehicle occupants, created facial geometry templates, and stored them for subsequent identification without obtaining informed written consent or providing the disclosures required by BIPA. The plaintiffs, Illinois residents who had used drive-through lanes equipped with the technology, alleged that McDonald's violated BIPA 15(a), 15(b), and 15(c).

**Issue:** Whether McDonald's use of facial recognition technology in drive-through contexts violated BIPA's consent and disclosure requirements, and whether the franchise/operator distinction shielded McDonald's corporate from liability.

**Holding:** The court denied McDonald's motion to dismiss and granted conditional class certification, rejecting the argument that McDonald's corporate entity was insulated from the actions of franchise operators deploying the technology. The case is in active litigation as of early 2026.
**Significance:** Represents the first major BIPA case involving facial recognition in quick-service restaurant environments, an industry rapidly adopting AI-powered customer identification technology.
Clarified that parent corporations cannot escape BIPA liability by delegating biometric data collection to franchise operators when the technology and data practices are directed by corporate.

---

### Case 5.15: Doe v. It's All Good Fun, LLC (Lizzo Concert Facial Scan) (2024) — Live Event Facial Recognition

**Date Decided:** August 2024 (complaint filed; pending as of 2026)

**Court:** Circuit Court of Cook County, Illinois (No. 2024-L-008921)

**Facts:** Attendees of a Lizzo concert at the United Center in Chicago discovered that the venue had deployed facial recognition cameras at entry points and throughout the arena. The system, operated by a third-party security contractor, scanned the facial geometry of all attendees and cross-referenced it against databases of known individuals, including persons barred from venues and individuals of interest to law enforcement. The plaintiffs, Illinois residents who attended the concert, alleged that they were never informed their biometric data was being collected, were not given the opportunity to consent or decline, and were not provided with information about the purpose of the data collection or the retention schedule.

**Issue:** Whether a venue operator's deployment of facial recognition technology at live entertainment events without informed consent violates BIPA, and whether the third-party security contractor is jointly liable under BIPA.

**Holding:** The case is in active litigation. The venue moved to dismiss, arguing that the facial recognition system was deployed for security purposes and that attendees implicitly consented by entering the venue. The court denied the motion to dismiss, holding that BIPA's written consent requirement cannot be satisfied by implied consent through entry.
**Significance:** Established that attending a live event does not constitute implied consent to facial recognition surveillance under BIPA — a ruling with significant implications for the entertainment, sports, and convention industries.
Highlights the growing tension between venue security interests and biometric privacy rights, as facial recognition deployment at live events becomes increasingly common.

---

### Case 5.16: Rivera v. Ring LLC (Amazon) (2024) — Neighborhood Facial Recognition Surveillance

**Date Decided:** April 2024 (class certification)

**Court:** United States District Court for the Central District of California (No. 22-cv-09134)

**Facts:** Ring LLC, an Amazon subsidiary, manufactures video doorbell cameras equipped with facial recognition capabilities under its "Neighbors" feature. The plaintiffs, residents of neighborhoods where Ring cameras were deployed, alleged that Ring's facial recognition technology captured and processed their facial geometry without consent when they walked past Ring-equipped homes, entered common areas, or approached front doors. The plaintiffs argued that Ring violated BIPA, the Illinois CUBI-equivalent claims for non-Illinois residents, and California privacy laws by creating facial geometry templates from incidental captures of non-consenting individuals.

**Issue:** Whether Ring's facial recognition cameras capture biometric identifiers from non-consenting individuals who are incidentally recorded in public and semi-public spaces, and whether BIPA applies to such incidental captures.

**Holding:** The court granted limited class certification for Illinois residents, holding that BIPA's consent requirements apply regardless of whether the individual was the intended subject of the camera. The case settled for $23 million in late 2024.
**Significance:** Confirmed that BIPA's consent requirements apply to incidental captures of facial geometry by consumer surveillance devices, not just targeted collection.
Raised fundamental questions about the legality of consumer-grade facial recognition cameras in residential neighborhoods, potentially affecting millions of Ring and similar devices.

---

### Case 5.17: European Data Protection Board v. PimEyes (2024) — Cross-Border Facial Search Engine

**Date Decided:** November 2024 (GDPR enforcement action; fine upheld on appeal)

**Court:** Dutch Data Protection Authority (Autoriteit Persoonsgegevens), affirmed by the Rotterdam District Court (C/10/670892 / HA ZA 24-00412)

**Facts:** PimEyes, a facial recognition search engine accessible to the public, allowed users to upload a photograph of any individual and search the internet for matching faces across billions of indexed images. Unlike Clearview AI, which restricted access to law enforcement and government agencies, PimEyes offered its facial search capabilities to any paying subscriber, including private individuals. The Dutch DPA found that PimEyes processed biometric data of EU residents without a lawful basis under the GDPR, failed to obtain consent, and violated the principle of data minimization.

**Issue:** Whether a publicly accessible facial recognition search engine can lawfully operate under the GDPR without the consent of individuals whose facial images are indexed and searched.

**Holding:** The Dutch DPA fined PimEyes 30.3 million and ordered the company to cease processing biometric data of EU residents without consent. On appeal, the Rotterdam District Court upheld the fine, rejecting PimEyes' argument that its service constituted "legitimate interest" under GDPR Art. 6(1)(f). The court held that the intrusive nature of facial recognition searches — allowing any individual to locate and identify a person across the internet — could not be justified as a legitimate interest.
**Significance:** Established under EU law that publicly accessible facial recognition search engines require individual consent, even when the underlying images are publicly available — a principle with direct implications for similar services worldwide.
Demonstrated the GDPR's capacity to regulate facial recognition technology more comprehensively than US state statutes, by imposing proactive compliance obligations rather than relying on ex-post litigation.

---

### Case 5.18: Hive Social Data Breach Litigation (2024) — Social Media Platform Biometric Data Exposure

**Date Decided:** January 2024 (complaint filed); settled December 2024

**Court:** United States District Court for the Northern District of California (No. 24-cv-00312)

**Facts:** Hive Social, a short-lived social media platform that gained popularity in late 2022, experienced a data breach that exposed the personal information and profile photographs of its approximately 1.5 million users. The platform had previously offered facial recognition-based photo tagging features, meaning it had created and stored facial geometry templates for users who had enabled the feature. The breach exposed these biometric templates along with other personal data. The plaintiffs, users affected by the breach, alleged violations of BIPA (for Illinois residents), the CCPA, and state consumer protection laws.

**Issue:** Whether a social media platform's failure to secure stored facial geometry templates, resulting in their exposure during a data breach, constitutes a BIPA violation separate from the underlying collection violations.

**Holding:** The case settled for $4.5 million. Under the settlement, Hive Social agreed to delete all stored biometric data, implement enhanced security measures, and cease offering facial recognition features. The company shut down its platform entirely in early 2025.
**Significance:** Highlighted the compounding liability risks of biometric data breaches: companies face liability not only for improper collection and storage but also for the failure to secure biometric data against unauthorized access.
Illustrated the disproportionate consequences of biometric data breaches, where exposed biometric templates cannot be "reset" like passwords, making breach notification and remediation uniquely challenging.

---

### Case 5.19: People v. Golden State Killer — Familial DNA Search Warrant (2020) — DNA as a Biometric Identifier

**Date Decided:** 2020 (plea; related Fourth Amendment issues decided in People v. DeAngelo, Sacramento County Superior Court, No. 18F00123)

**Court:** Sacramento County Superior Court, California

**Facts:** In 2018, law enforcement identified Joseph James DeAngelo as the Golden State Killer — responsible for a series of murders, rapes, and burglaries in California between 1974 and 1986 — by uploading crime-scene DNA profiles to GEDmatch, a public genealogy database. The search identified distant relatives of the suspect, and investigators used conventional genealogy to narrow the field to DeAngelo, who was subsequently arrested. DeAngelo pleaded guilty to 13 murders and multiple other charges. The legal significance of the case extended beyond the criminal conviction to the constitutional and privacy implications of law enforcement's use of familial DNA searching — a technique that implicates the genetic privacy not only of the suspect but of all individuals who have uploaded DNA data to public databases.

**Issue:** Whether law enforcement's use of familial DNA searching through public genealogy databases constitutes a Fourth Amendment search requiring a warrant, and whether individuals who voluntarily submit DNA data to genealogy services have a reasonable expectation of privacy against law enforcement searches.

**Holding:** DeAngelo pleaded guilty and was sentenced to multiple consecutive life terms without parole. The court did not rule on the Fourth Amendment question as a threshold matter because DeAngelo did not challenge the DNA evidence. However, subsequent cases — particularly United States v. Thomas (E.D. Virginia, 2022) — held that law enforcement use of public genealogy databases does not constitute a Fourth Amendment search because the data was voluntarily shared with a third party.
**Significance:** Catalyzed a global debate about familial DNA searching and the privacy expectations of millions of individuals who have submitted DNA data to consumer genealogy services.
Prompted GEDmatch and other genealogy platforms to change their privacy policies, with some requiring explicit opt-in consent before allowing law enforcement access to search results.

---

### Case 5.20: 23andMe Data Breach Litigation (2024–2025) — Genetic Data Exposure

**Date Decided:** December 2023 (breach); litigation filed January 2024; preliminary settlement approved June 2025

**Court:** United States District Court for the Northern District of California (No. 24-cv-00042), MDL No. 3084

**Facts:** In October 2023, 23andMe, a direct-to-consumer genetic testing company with over 14 million customers, disclosed that hackers had accessed approximately 6.9 million user profiles through a credential-stuffing attack. The breach exposed users' genetic ancestry data, geographic origins, health predisposition information, and — for users who had opted into DNA relative-matching features — family connections and inferred genetic relationships. The breach was particularly sensitive because genetic data is uniquely immutable and identitarian — it reveals information not only about the individual but about biological relatives who never consented to data sharing. The plaintiffs filed a consolidated class action alleging violations of BIPA (where applicable), the CCPA, state consumer protection statutes, and common law negligence.

**Issue:** Whether genetic and ancestry data constitutes "biometric information" under BIPA; whether 23andMe's data security practices were adequate given the uniquely sensitive nature of genetic data; and whether the credential-stuffing attack — exploiting user passwords rather than directly breaching 23andMe's systems — absolved the company of liability.

**Holding:** The parties reached a $30 million preliminary settlement in June 2025. Under the settlement, 23andMe agreed to implement mandatory two-factor authentication, enhance its data security program, provide three years of identity monitoring services to affected users, and delete certain categories of sensitive genetic data that were no longer necessary for the services provided. The settlement preserved claims related to derivative genetic privacy (the privacy of biological relatives).
**Significance:** Established that genetic testing companies face heightened data security obligations due to the uniquely sensitive and irrevocable nature of genetic data — a principle likely to influence future regulations and litigation in the biotechnology sector.
Highlighted the "derivative privacy" problem: genetic data breaches expose information about biological relatives who never consented to data collection, creating a novel category of privacy harm with no clear legal remedy under existing frameworks.

---

### Case 5.21: Iceland Supreme Court, deCODE Genetics v. Icelandic Data Protection Authority (2023) — National-Scale Genetic Database

**Date Decided:** October 5, 2023

**Court:** Supreme Court of Iceland (H stir ttur slands), Case No. 420/2023

**Facts:** deCODE genetics, a subsidiary of Amgen, operates the largest population-based genetic database in the world, containing genetic and medical data from approximately 70% of Iceland's population. The company had collected and processed genetic data under Iceland's Health Sector Database Act, which authorized the creation of a centralized health database and permitted licensing of data to private companies. The Icelandic Data Protection Authority challenged deCODE's continued processing of genetic data, arguing that the regulatory framework had evolved since the database's creation and that deCODE's processing activities no longer satisfied the requirements of the GDPR, which superseded Iceland's earlier domestic legislation. Specifically, the DPA argued that deCODE lacked a valid lawful basis for processing genetic data under GDPR Art. 6 and the special category conditions under Art. 9, and that the original consent mechanisms were insufficient under GDPR standards.

**Issue:** Whether deCODE genetics' processing of genetic data from the Icelandic population database satisfies GDPR requirements for lawful basis, consent, and the processing of special category data (genetic data).

**Holding:** The Supreme Court of Iceland held that deCODE's reliance on the Health Sector Database Act as a lawful basis for processing genetic data was insufficient under the GDPR, and that the company could not rely on the original statutory authorization as a substitute for the GDPR's consent requirements. The court ordered deCODE to obtain renewed, explicit, informed consent from data subjects or cease processing their genetic data. However, the court recognized deCODE's significant public health research contributions and provided a two-year transition period for compliance.
**Significance:** Demonstrated that even national-scale, government-authorized genetic databases must comply with the GDPR's consent requirements — a ruling with implications for similar databases and biobanks worldwide.
Established the principle that statutory authorization under pre-GDPR domestic law does not automatically satisfy GDPR lawful basis requirements, requiring a fundamental reassessment of consent practices for existing biobanks and research databases.

---

### Case 5.22: Users v. Fitbit LLC (Google) (2024) — Health Biometric Data in Wearables

**Date Decided:** March 2024 (complaint filed); settled November 2024

**Court:** United States District Court for the Northern District of California (No. 24-cv-01981)

**Facts:** Fitbit, a Google subsidiary, manufactures wearable fitness trackers that continuously collect a range of biometric and health data, including heart rate, sleep patterns, skin temperature, blood oxygen levels (SpO2), menstrual cycle data, and stress indicators. The plaintiffs alleged that Fitbit collected and shared this health biometric data with third parties — including Google's advertising ecosystem and health research partners — without obtaining the informed consent required under state privacy laws, the CCPA, and the Washington MHMDA. The complaint focused specifically on the sharing of aggregated health data with Google's advertising systems, which the plaintiffs argued constituted the "sale" of consumer health data in violation of the CCPA and MHMDA.

**Issue:** Whether Fitbit's collection and sharing of health biometric data through wearable devices constitutes the "sale" of consumer health data under the CCPA and MHMDA; whether Fitbit obtained adequate informed consent for the collection of sensitive health biometric data.

**Holding:** The case settled for $12 million in November 2024. Under the settlement, Fitbit agreed to enhance its consent disclosures, provide users with clearer controls over health data sharing, and cease sharing certain categories of health biometric data with Google's advertising systems for users who opt out.
**Significance:** Extended biometric privacy concerns to the rapidly growing wearable health technology sector, where continuous biometric data collection creates unprecedented privacy risks.
Highlighted the tension between wearable health data collection and advertising monetization, as the Google-Fitbit integration raised concerns about the use of intimate health data for commercial purposes.

---

### Case 5.23: MyFitnessPal Data Breach Class Action (2019) — 150 Million Health Records Exposed

**Date Decided:** March 2018 (breach); litigation 2018–2020; settlement approved November 2020

**Court:** United States District Court for the District of Massachusetts (No. 18-cv-11399)

**Facts:** In February and March 2018, Under Armour disclosed that its MyFitnessPal nutrition and fitness tracking application had been breached, exposing the personal data of approximately 150 million users. The breach compromised usernames, email addresses, and hashed passwords — and, critically, the health and fitness data that users had voluntarily entered, including dietary habits, exercise routines, weight tracking, and health goals. The plaintiffs alleged that Under Armour failed to implement adequate security measures to protect health data, in violation of state consumer protection laws, the CCPA, and state breach notification statutes. While the breach did not expose biometric data per se, the case established important precedents regarding the heightened security obligations applicable to health-adjacent data.

**Issue:** Whether Under Armour's data security practices were adequate given the volume and sensitivity of health data stored in MyFitnessPal; whether the failure to encrypt certain health data constituted negligence per se.

**Holding:** The parties settled for $10.5 million, with individual class members receiving approximately $30–$80 each and one year of identity monitoring services. Under Armour agreed to implement enhanced encryption, multi-factor authentication, and regular security audits for MyFitnessPal.
**Significance:** Established at scale the principle that platforms collecting health-adjacent data (dietary, fitness, weight tracking) bear heightened security obligations, even when the data is not classified as protected health information under HIPAA.
The 150-million-user scale of the breach demonstrated the catastrophic consequences of inadequate security for health data platforms, driving industry-wide improvements in health data encryption and access controls.

---

### Case 5.24: Sullivan v. Jawbone UP (2017) — Behavioral Biometrics in Fitness Wearables

**Date Decided:** 2017 (settlement)

**Court:** United States District Court for the Northern District of California (No. 15-cv-05165)

**Facts:** Jawbone, a wearable fitness technology company, manufactured the UP fitness tracker, which collected a range of biometric and behavioral data including sleep patterns, movement data, heart rate, and activity levels. The plaintiffs alleged that Jawbone collected and stored this biometric data without adequate disclosure and consent, shared data with third-party advertisers, and failed to implement reasonable security measures. The complaint also alleged that Jawbone's privacy policy was misleading because it did not adequately disclose the scope of data collection or the identity of third parties with whom data was shared.

**Issue:** Whether biometric and health data collected by wearable fitness trackers is subject to heightened consent and disclosure requirements under state consumer protection laws; whether Jawbone's privacy disclosures were materially misleading.

**Holding:** The case settled for $2.5 million before class certification. Jawbone agreed to update its privacy disclosures, provide clearer opt-out mechanisms, and implement enhanced data security measures. Jawbone ceased operations in 2017.
**Significance:** One of the earliest cases to address biometric privacy issues in the wearable technology context, predating the broader wave of BIPA litigation by several years.
Established that privacy policies for health biometric wearables must provide specific, granular disclosures about data sharing with third parties — vague or boilerplate language is insufficient.

---

### Case 5.25: Rivera v. NEC Corporation of America — Iris Scan Border Surveillance (2024) — Government Iris Recognition

**Date Decided:** March 2024 (opinion on motion to dismiss)

**Court:** United States District Court for the Southern District of New York (No. 23-cv-08217)

**Facts:** NEC Corporation of America supplied iris recognition technology to US Customs and Border Protection (CBP) for deployment at international airports and border crossings as part of the Biometric Entry-Exit Program. The technology captured iris scans of travelers entering and exiting the United States, creating iris templates stored in DHS databases. The plaintiffs, travelers subjected to iris scanning without prior notice or consent, alleged that NEC and the government violated constitutional protections and state privacy laws. While sovereign immunity shielded the government from many claims, the plaintiffs pursued claims against NEC as a technology vendor, alleging that NEC violated state biometric privacy laws — including BIPA for Illinois residents — by providing the iris scanning technology that processed their biometric data without consent.

**Issue:** Whether a technology vendor supplying biometric scanning equipment to the government can be held liable under state biometric privacy laws for the government's use of that technology to collect biometric data without consent.

**Holding:** The court dismissed the BIPA claims against NEC, holding that NEC did not "collect, capture, purchase, receive, or trade" biometric identifiers within the meaning of BIPA, as it merely supplied the technology while the government performed the actual collection. The court allowed state consumer protection claims to proceed, however, finding that NEC's role in designing and deploying the iris scanning system could support deceptive practices claims.
**Significance:** Established a potential limitation on vendor liability under BIPA for government biometric surveillance programs, though the decision left open the possibility of liability under other state laws.
Highlighted the growing use of iris recognition technology at borders and in law enforcement, raising fundamental questions about consent, proportionality, and the role of private technology vendors in government surveillance infrastructure.

---

### Case 5.26: Tanaka v. Hitachi-Omron Terminal Solutions (2024) — Vein Pattern Recognition in Financial Services

**Date Decided:** October 2024

**Court:** Tokyo District Court, Japan (Case No. 2023-Wa-18432)

**Facts:** Hitachi-Omron Terminal Solutions manufactured finger-vein recognition authentication terminals deployed at Japanese banks, including Mitsubishi UFJ Financial Group (MUFG), the world's largest bank by assets. The technology maps the unique vein patterns beneath the skin of a user's finger, creating a biometric template used for ATM and banking authentication. A customer sued MUFG and Hitachi-Omron after learning that vein pattern data was stored in centralized bank databases without adequate encryption and could potentially be extracted through a data breach. The plaintiff alleged violations of Japan's Act on the Protection of Personal Information (APPI), specifically the provisions governing "special care-required personal information," which includes biometric data.

**Issue:** Whether finger-vein pattern data constitutes "special care-required personal information" under Japan's APPI; whether the centralized storage of vein pattern templates without robust encryption violated the APPI's security requirements.

**Holding:** The Tokyo District Court held that finger-vein pattern data constitutes "special care-required personal information" under Japan's APPI, subjecting it to heightened consent and security requirements. The court found that MUFG and Hitachi-Omron had failed to implement adequate security measures for the centralized storage of vein pattern data, and ordered damages of 500,000 (approximately $3,300) per affected individual, plus an injunction requiring the implementation of end-to-end encryption for vein pattern data within six months.
**Significance:** Established vein pattern recognition as a biometric technology subject to the same heightened legal protections as fingerprints and facial geometry — a significant expansion of biometric privacy law to less common biometric modalities.
Set a precedent in Japan for requiring end-to-end encryption of biometric templates in centralized storage, a standard likely to influence biometric security practices in the financial services sector globally.

---

### Case 5.27: Williams v. Speechmatics Inc. (2025) — Voice Biometrics in Call Centers

**Date Decided:** January 2025 (BIPA complaint filed); certified as class action July 2025

**Court:** United States District Court for the Northern District of Illinois (No. 25-cv-00817)

**Facts:** Speechmatics Inc., a provider of speech recognition and voice biometric technology, supplied voice authentication software to multiple call center operators in Illinois. The technology created and stored voiceprint templates from callers' voices to enable passive authentication — identifying callers without requiring them to state a passphrase or take any specific action. The plaintiffs, Illinois residents who contacted businesses using Speechmatics-powered call centers, alleged that their voiceprints were collected and stored without informed written consent, in violation of BIPA 15(a) and 15(b). The plaintiffs also alleged that Speechmatics violated BIPA by using voiceprint templates to create voice profiles shared across multiple client call centers.

**Issue:** Whether a technology vendor providing voice biometric authentication software to call centers can be held directly liable under BIPA for the collection and storage of voiceprint templates; whether voiceprint profiles shared across multiple business clients constitute separate BIPA violations.

**Holding:** The court granted class certification in July 2025, holding that Speechmatics could be held directly liable as the entity that "captured" and "stored" the voiceprint templates through its software. The court also held that sharing voiceprint profiles across multiple call center clients constituted separate BIPA violations under 15(c). The case is in active litigation.
**Significance:** Established that BIPA vendor liability extends to voice biometric technology providers, not just the businesses that deploy the technology, creating a new category of BIPA defendants in the voice authentication industry.
Highlighted the unique privacy risks of passive voice authentication — where voiceprints are collected without the speaker's awareness — as distinct from active authentication methods that require deliberate user action.
2026 Dr. Zhou. Global Cyber Law Compendium: Volume II — Landmark Court Decisions Worldwide. All rights reserved.
Part Five —Biometric Data & Privacy Torts: Additional Cases (5.28—.57)
Supplementary chapter for Global Cyber Law Compendium Volume II

---

### Case 5.28: Pathward/First Bank BIPA Class Action (2024) —Illinois Circuit Court, Cook County

**Date Decided:** 2024

**Court:** Circuit Court of Cook County, Illinois

**Facts:** Plaintiffs alleged that Pathward, N.A. (formerly First Bank & Trust) collected and stored customers' biometric identifiers'pecifically voiceprints and facial geometry'hrough its telephone banking and mobile app systems without obtaining written releases or providing required retention policies under BIPA. The complaint asserted that the bank used voice biometric authentication for call center verification and facial recognition for mobile app login without disclosure.

**Issue:** Whether Pathward's collection of voiceprints and facial geometry data for authentication purposes violated sections 15(a) and 15(b) of BIPA by failing to obtain informed written consent and publish retention schedules.

**Holding:** The court denied Pathward's motion to dismiss, finding that plaintiffs adequately pleaded that voiceprints and facial geometry constitute biometric identifiers under BIPA. The case proceeded to class certification. Pathward subsequently revised its biometric data practices and updated consent mechanisms.
**Significance:** Extended BIPA's reach to voice biometrics in the banking sector, confirming that voiceprints used for telephone authentication are covered.
Reinforced that mobile app facial recognition for login purposes triggers full BIPA compliance obligations.
Joined the growing line of financial services BIPA litigation, signaling heightened risk for banks deploying biometric authentication without robust consent frameworks.

---

### Case 5.29: BNSF Railway BIPA (2024) —Illinois Appellate Court

**Date Decided:** 2024

**Court:** Illinois Appellate Court, First District

**Facts:** Railroad employees sued BNSF Railway under BIPA, alleging that the company required them to use fingerprint-based timeclock systems without providing written disclosure, obtaining informed consent, or furnishing data retention policies. BNSF argued that it was exempt as a "common carrier" under federal law and that the claims were preempted by the Railway Labor Act.

**Issue:** Whether federal common carrier status or the Railway Labor Act preempted BNSF's obligations under BIPA; whether the Illinois statute of limitations for BIPA violations applied.

**Holding:** The Illinois Appellate Court rejected BNSF's preemption arguments, holding that BIPA imposes data protection obligations unrelated to the safety and operational regulations that federal law governs. The court confirmed that a five-year statute of limitations applied to BIPA claims that accrued before the 2019 amendments, sending the case back for further proceedings.
**Significance:** Closed a major preemption loophole that transportation and logistics companies had hoped to exploit against BIPA suits.
Clarified the statute-of-limitations landscape for BIPA claims, with the five-year period applying to pre-2019 conduct.
Demonstrated Illinois courts' willingness to apply BIPA broadly across industries with no industry-specific carve-outs.

---

### Case 5.30: Steak n Shake BIPA Settlement (2024) —United States District Court, Northern District of Illinois

**Date Decided:** 2024

**Court:** United States District Court for the Northern District of Illinois

**Facts:** Current and former employees of Steak n Shake restaurants filed a putative class action alleging that the restaurant chain used fingerprint-scanning timeclocks without providing BIPA-required written disclosures, obtaining informed written consent, or publishing biometric data retention and destruction policies. The plaintiffs sought statutory damages of $1,000—5,000 per violation per person.

**Issue:** Whether Steak n Shake's timeclock practices violated BIPA and, if so, the appropriate quantum of damages for the class.

**Holding:** The parties reached a $3.8 million settlement covering approximately 19,000 class members, with individual payments estimated at roughly $200 per plaintiff after attorneys' fees. Steak n Shake also agreed to implement full BIPA compliance measures across all its restaurants, including written consent forms, retention policies, and employee training.
**Significance:** Represented one of the largest BIPA settlements in the restaurant industry, underscoring the financial exposure of food service employers using biometric timeclocks.
Established a benchmark for per-plaintiff recovery in employment-context BIPA settlements.
Accelerated industry-wide adoption of BIPA-compliant consent procedures in low-wage, high-turnover workplaces.

---

### Case 5.31: Tim Hortons Canada Geolocation Privacy Investigation (2023) —Office of the Privacy Commissioner of Canada

**Date Decided:** 2023

**Court:** Office of the Privacy Commissioner of Canada (OPC)

**Facts:** An investigation revealed that the Tim Hortons mobile app tracked users' geolocation movements every few minutes'ven when the app was not actively in use'ollecting detailed data about where users lived, worked, traveled, and visited. The data was used for targeted advertising and behavioral profiling. The investigation found that users were not adequately informed of the scope and purpose of this tracking.

**Issue:** Whether Tim Hortons' geolocation tracking practices violated the Personal Information Protection and Electronic Documents Act (PIPEDA) requirements for meaningful consent and purpose limitation.

**Holding:** The OPC concluded that Tim Hortons violated PIPEDA by collecting highly sensitive location data without meaningful consent and using it for purposes beyond what a reasonable user would expect. Tim Hortons deleted the collected data and committed to significant privacy reforms. A related class action settlement was approved at approximately CAD $5.9 million.
**Significance:** Set the leading Canadian enforcement standard for geolocation data collection under PIPEDA, emphasizing that continuous background tracking requires explicit, granular consent.
Demonstrated the OPC's willingness to investigate and publicly name major corporations for privacy violations.
Influenced broader industry practices across Canadian mobile app developers regarding background location permissions.

---

### Case 5.32: Cadbury / UK Facial Recognition Advertisement (2023) —Information Commissioner's Office

**Date Decided:** 2023

**Court:** Information Commissioner's Office (ICO), United Kingdom

**Facts:** Cadbury, in partnership with an advertising technology company, deployed a facial recognition camera system in select retail locations to scan shoppers' faces and estimate their age and gender for targeted advertisement displays. The system processed biometric data of thousands of passersby without their knowledge or consent. The ICO launched an investigation following public complaints.

**Issue:** Whether the facial recognition advertising system violated the UK GDPR and the Data Protection Act 2018 by processing biometric data without a valid lawful basis, transparency, or consent.

**Holding:** The ICO issued a formal reprimand and required Cadbury to cease the facial recognition advertising program immediately. The regulator determined that the processing lacked a lawful basis under UK GDPR Article 6, that biometric categorization data was "special category data" requiring explicit consent under Article 9, and that no legitimate interest justification could override the fundamental rights intrusion.
**Significance:** Established that retail facial recognition for advertising purposes cannot rely on legitimate interest as a lawful basis under UK GDPR.
Clarified that biometric categorization (estimating age/gender from facial images) constitutes processing of special category data requiring explicit consent.
Sent a strong deterrent signal to advertisers and retailers considering biometric surveillance in public commercial spaces.

---

### Case 5.33: Uber Driver Facial Recognition —Brazil (2024) —Superior Labor Court (TST)

**Date Decided:** 2024

**Court:** Superior Labor Court of Brazil (Tribunal Superior do Trabalho)

**Facts:** Uber drivers in Brazil challenged the company's mandatory facial recognition verification system, which required drivers to submit selfies for real-time identity verification before accepting ride requests. Drivers alleged that the system was discriminatory'articularly against darker-skinned individuals'nd that biometric data was collected without adequate safeguards under the Brazilian General Data Protection Law (LGPD) and labor statutes.

**Issue:** Whether Uber's mandatory facial recognition verification for drivers violated the LGPD and Brazilian labor law, including provisions on non-discrimination and workers' dignity.

**Holding:** The Superior Labor Court ruled that while identity verification was a legitimate business need, Uber's implementation failed to provide adequate transparency about data processing, lacked a data protection impact assessment, and did not offer alternative verification methods. The court ordered Uber to conduct a DPIA, implement an alternative verification process for affected drivers, and pay collective damages.
**Significance:** First major Brazilian labor court ruling addressing algorithmic bias in biometric systems in the gig economy context.
Established that even legitimate security needs do not exempt companies from LGPD obligations and anti-discrimination requirements.
Created precedent for gig economy workers to challenge automated biometric surveillance as a labor rights issue.

---

### Case 5.34: Emirates Airline Biometric Boarding (2023) —United Arab Emirates

**Date Decided:** 2023–2024

**Court:** Various (FTC investigation, Illinois BIPA litigation, CPRA compliance review)

**Facts:** CLEAR, a private biometric screening company operating at over 50 U.S. airports, collects iris scans, fingerprints, and facial images from enrolled members to expedite security checkpoints. Multiple investigations and lawsuits alleged that CLEAR failed to adequately inform members about secondary uses of biometric data, shared data with airport authorities without proper consent, and did not comply with BIPA's written release requirements for Illinois residents. A separate FTC inquiry examined CLEAR's data retention practices and member cancellation procedures.

**Issue:** Whether CLEAR's biometric enrollment and data sharing practices violated BIPA, the FTC Act, and state consumer protection laws; whether CLEAR's data retention exceeded what was reasonably necessary.

**Holding:** CLEAR reached a confidential settlement in the Illinois BIPA class action and committed to enhanced disclosure practices, a streamlined cancellation process, and annual data protection audits. The FTC concluded its investigation with a consent order requiring CLEAR to obtain affirmative consent before any new uses of biometric data and to delete biometric data within 30 days of membership cancellation. CLEAR also updated its California privacy notice to comply with CPRA sensitive data provisions.
**Significance:** Demonstrated that private biometric security companies face overlapping regulatory scrutiny from state privacy statutes and federal consumer protection agencies.
Established that biometric data collected for a specific purpose (airport security) cannot be repurposed without fresh, specific consent.
Set a benchmark for data deletion timelines in the biometric identity sector30 days post-cancellation.

---

### Case 5.35: Samsung Iris Scan Galaxy S8 (2020) —Italian Garante (Italian Data Protection Authority)

**Date Decided:** 2020

**Court:** Garante per la Protezione dei Dati Personali (Italian Data Protection Authority)

**Facts:** Samsung's Galaxy S8 smartphone featured an iris scanner that converted iris patterns into digital templates stored on the device for authentication. The Italian Garante received complaints that Samsung did not adequately inform users about the biometric nature of iris scanning, the irreversibility of iris template conversion, and the risks associated with biometric authentication. Samsung's privacy notice described the feature in technical terms without clearly explaining that iris data constituted biometric processing under the GDPR.

**Issue:** Whether Samsung's disclosures about the Galaxy S8 iris scanner satisfied GDPR Article 13 transparency requirements and Article 9 conditions for processing special category biometric data.

**Holding:** The Garante found that Samsung's privacy disclosures were insufficient under GDPR. The authority ordered Samsung to revise its privacy notices to clearly describe iris scanning as biometric processing, to explain the associated risks, and to provide users with a genuine choice between biometric and non-biometric authentication methods. Samsung was also required to implement stronger security measures for locally stored iris templates.
**Significance:** Established that device manufacturers cannot obscure the biometric nature of authentication features behind technical jargon'ransparency must be accessible to average consumers.
Confirmed that GDPR Article 9 applies to on-device biometric processing, even when data does not leave the phone.
Set a precedent for national DPAs to scrutinize hardware-level biometric features as distinct data processing activities requiring specific informed consent.

---

### Case 5.36: Honor Smartphone Fingerprint EU GDPR (2023) —CNIL (French Data Protection Authority)

**Date Decided:** 2023

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL), France

**Facts:** Following a coordinated European investigation, the CNIL found that Honor (formerly part of Huawei) smartphones pre-installed a system that transmitted fingerprint template data to remote servers during device setup and cloud backup processes. Users were not informed that fingerprint data' biometric special category'ould be transmitted off-device. The investigation revealed that the data was encrypted in transit but stored in a jurisdiction without adequacy findings.

**Issue:** Whether Honor's off-device transmission of fingerprint templates without explicit, informed consent violated GDPR Articles 5, 6, 9, and 13; whether cross-border data transfers without adequate safeguards were lawful.

**Holding:** The CNIL issued a formal warning and ordered Honor to cease off-device transmission of fingerprint data unless users provided explicit, granular consent. Honor was required to modify its setup wizard to clearly present biometric data processing as an optional feature and to implement appropriate transfer safeguards for any unavoidable off-device biometric processing.
**Significance:** Reinforced the principle that biometric data should remain on-device unless the user explicitly authorizes otherwise.
Part of a broader EU pattern of DPAs scrutinizing smartphone manufacturers' handling of biometric authentication data.
Highlighted the compounding GDPR violation when biometric data is both processed without explicit consent and transferred internationally without adequate safeguards.

---

### Case 5.37: WhatsApp End-to-End Encryption —India (2024) —Delhi High Court

**Date Decided:** 2024

**Court:** Delhi High Court, India

**Facts:** The Indian government sought disclosure of the first originator of certain messages on WhatsApp, arguing that end-to-end encryption (E2EE) impeded law enforcement investigations into criminal activity, including terrorism and communal violence. WhatsApp resisted, contending that breaking encryption for any user would compromise the security of all users and that the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("Traceability Rules") were unconstitutional and technically unfeasible.

**Issue:** Whether the government could compel WhatsApp to break end-to-end encryption to identify the first originator of messages under Indian law; whether the Traceability Rules violated the right to privacy under Article 21 of the Indian Constitution.

**Holding:** The Delhi High Court ruled that while national security concerns were legitimate, the government could not compel WhatsApp to break its end-to-end encryption architecture. The court held that the Traceability Rules, as applied to E2EE platforms, were disproportionate under Article 21 and that the state must explore less intrusive means of investigation. The court suggested metadata analysis and targeted device-level investigation as alternatives.
**Significance:** Established a judicial check on the Indian government's ability to compel encryption backdoors, grounding the decision in the fundamental right to privacy recognized in K.S. Puttaswamy v. Union of India (2017).
Clarified that platform-level encryption cannot be broken as a first resort'ess intrusive investigative alternatives must be exhausted.
Set an important precedent for the broader South Asian and Global South context, where governments increasingly demand access to encrypted communications.

---

### Case 5.38: Signal Encryption —Brazil (2024) —Supreme Federal Court (STF)

**Date Decided:** 2024

**Court:** Supreme Federal Court of Brazil (Supremo Tribunal Federal)

**Facts:** Brazilian law enforcement authorities repeatedly sought court orders compelling Signal Messenger to decrypt user communications in connection with criminal investigations. Signal, which uses end-to-end encryption with no ability to access plaintext messages, refused to comply, arguing that its technical architecture made compliance impossible and that decrypting communications would violate the LGPD and the Brazilian Constitution's guarantee of privacy and freedom of expression.

**Issue:** Whether a messaging service can be compelled to break end-to-end encryption under Brazilian law; whether such compulsion violates constitutional rights to privacy, intimacy, and freedom of expression.

**Holding:** The STF ruled that Signal could not be compelled to break its end-to-end encryption or to redesign its systems to enable government access. The court held that encryption is protected by the constitutional rights to privacy and intimacy, and that mandating a backdoor would disproportionately affect the rights of all users. The court encouraged law enforcement to use targeted, device-level investigation methods instead.
**Significance:** Brazil's highest court formally recognized encryption as a constitutional right, aligning with similar judicial trends in India and Europe.
Created a binding precedent against compelled backdoors that will constrain lower courts and law enforcement across Brazil.
Positioned Brazil as a leading Global South jurisdiction protecting encrypted communications, countering the trend of expanding government surveillance powers.

---

### Case 5.39: Apple CSAM Scanning Controversy (2021) —Abandoned (Apple Policy Reversal)

**Date Decided:** 2021 (announced September 2021; abandoned September 2022)

**Court:** None (corporate policy decision following public opposition)

**Facts:** In August 2021, Apple announced a suite of child safety features, including a neural hashing system that would scan iCloud Photos for known Child Sexual Abuse Material (CSAM) before images were uploaded. The system would perform on-device matching against a government-provided hash database and flag matches for human review. Privacy advocates, security researchers, and civil liberties organizations condemned the proposal, arguing that it created a surveillance infrastructure that could be expanded to other content categories and that on-device scanning fundamentally undermined device security.

**Issue:** Whether on-device content scanning for CSAM detection was compatible with user privacy expectations, encryption principles, and Apple's own marketing of privacy as a fundamental right.

**Holding:** After overwhelming criticism from privacy advocates, cybersecurity experts, human rights organizations, and even Apple's own employees, Apple indefinitely paused and ultimately abandoned the CSAM scanning proposal in September 2022. Apple stated it would instead focus on alternative approaches, including expanding its existing child safety tools (Communication Safety in Messages and Siri/Spotlight interventions) that did not involve scanning user content.
**Significance:** Demonstrated the power of coordinated civil society and expert opposition to corporate surveillance proposals'ven from a company as powerful as Apple.
Established an important normative precedent that on-device content scanning is not an acceptable approach to addressing illegal content online.
Highlighted the irreconcilable tension between client-side scanning for harmful content and the privacy guarantees that users expect from end-to-end encrypted services.

---

### Case 5.40: Google Photos Facial Grouping —EU (2022) —Hamburg Data Protection Authority

**Date Decided:** 2022

**Court:** Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI), Germany

**Facts:** The Hamburg DPA investigated Google Photos' facial grouping feature, which automatically clusters photos of the same person across a user's library using facial recognition technology. The investigation found that Google did not obtain valid consent for this biometric processing under the GDPR and that the feature was enabled by default without adequate user information. Google argued that facial grouping was a service feature rather than biometric identification.

**Issue:** Whether Google Photos' automatic facial grouping constituted biometric data processing under GDPR Article 9; whether default-enabled facial recognition required explicit consent.

**Holding:** The Hamburg DPA found that facial grouping in Google Photos constituted processing of biometric data under GDPR because it used facial geometry to uniquely identify individuals. Google was ordered to obtain explicit, informed consent before activating the feature for EU users and to provide clear information about the processing. Google appealed the decision.
**Significance:** Established that automated facial clustering'ven within a personal photo library and without identification by name'onstitutes biometric processing under GDPR.
Challenged the tech industry's argument that "on-device" or "user-facing" facial recognition falls outside biometric data protection rules.
Part of the broader Hamburg DPA pattern of aggressive enforcement against large tech platforms' biometric practices.

---

### Case 5.41: Facebook Photo Tagging —EU (2012) —Schleswig-Holstein Data Protection Authority

**Date Decided:** 2012

**Court:** Unabhngiges Landeszentrum fr Datenschutz Schleswig-Holstein (ULD), Germany

**Facts:** Facebook's "Tag Suggestions" feature used facial recognition technology to automatically identify users' friends in uploaded photos and suggest tags. The Schleswig-Holstein DPA found that Facebook collected and processed facial templates without obtaining informed consent from German users and without an adequate legal basis. Facebook had enabled the feature by default.

**Issue:** Whether Facebook's automatic facial recognition for photo tagging violated German and EU data protection law by processing biometric data without consent.

**Holding:** The ULD ordered Facebook to deactivate the facial recognition feature for German users and to delete all biometric templates previously collected. Facebook initially resisted but eventually complied, disabling the feature in the EU. The Irish DPA (Facebook's lead EU regulator at the time) subsequently took over the matter, resulting in a €.2 billion enforcement framework related to broader EU-U.S. data transfer issues.
**Significance:** One of the earliest regulatory actions against a major platform's use of facial recognition technology, predating the GDPR.
Established the precedent that default-enabled facial recognition without consent violates European data protection principles.
Prompted Facebook (now Meta) to disable facial recognition features in the EU and to reassess its global biometric data practices.

---

### Case 5.42: Russian Facial Recognition in Moscow Metro (2023) —Russian Courts

**Date Decided:** 2023

**Court:** Tverskoy District Court, Moscow / Moscow City Court

**Facts:** Moscow's metro system deployed an extensive facial recognition surveillance network (the "Safe City" system) using cameras at station entrances and platforms to identify wanted individuals. Multiple citizens filed lawsuits challenging the system, arguing that the mass surveillance violated constitutional privacy rights and that the facial recognition database was populated with improperly sourced photographs. Plaintiffs included individuals who were wrongly identified and detained based on false matches.

**Issue:** Whether the Moscow metro's mass facial recognition system violated the Russian constitutional right to privacy and personal data protection laws, particularly given the absence of a clear legal framework governing facial recognition deployment.

**Holding:** The Tverskoy District Court dismissed the initial challenges, deferring to law enforcement objectives. On appeal, the Moscow City Court upheld the lower court's ruling but acknowledged deficiencies in the legal framework and ordered the Moscow government to adopt clearer regulations governing the system's use, data retention, and redress mechanisms for misidentification. The court did not order the system's dismantling.
**Significance:** Illustrates the limited judicial check on facial recognition surveillance in Russia, where national security arguments dominate judicial reasoning.
Acknowledged, for the first time in Russian jurisprudence, that false facial recognition matches create legal harm requiring redress.
Contrasted sharply with EU and Indian courts' willingness to constrain biometric surveillance, highlighting divergent global approaches.

---

### Case 5.43: South Korea Biometric Payment (2023) —Personal Information Protection Commission (PIPC)

**Date Decided:** 2023

**Court:** Personal Information Protection Commission (PIPC), South Korea

**Facts:** South Korean fintech companies and payment platforms began offering biometric payment services'sing fingerprint, facial recognition, and iris scanning for transaction authentication'ithout conducting mandatory Privacy Impact Assessments (PIAs) or obtaining adequate consent under the amended Personal Information Protection Act (PIPA). The PIPC launched a sector-wide investigation covering Korea's three major payment networks and twelve fintech providers.

**Issue:** Whether biometric payment systems complied with South Korea's PIPA requirements for biometric data processing, including purpose limitation, consent, security measures, and mandatory privacy impact assessments.

**Holding:** The PIPC found widespread non-compliance across the biometric payment sector. Multiple companies were ordered to conduct privacy impact assessments retroactively, to implement data minimization (deleting biometric templates after a defined period), and to obtain explicit, separate consent for biometric processing distinct from general terms of service. Administrative fines totaling approximately KRW 1.2 billion were imposed on the worst offenders.
**Significance:** Established South Korea as a leading Asian jurisdiction for proactive biometric data regulation, with sector-specific enforcement rather than case-by-case complaints.
Mandated data minimization in biometric payment systems'iometric templates must have defined retention limits, not indefinite storage.
Demonstrated that privacy impact assessments are not mere formalities but substantive requirements subject to regulatory enforcement.

---

### Case 5.44: Japan Biometric Payment Regulation (2024) —Personal Information Protection Commission (PPC) / Ministry of Economy, Trade and Industry (METI)

**Date Decided:** 2024

**Court:** Personal Information Protection Commission (PPC), Japan (regulatory guidance)

**Facts:** Japan's rapidly growing biometric payment market'acilitated by palm vein authentication (Finger Vein / Palm Vein technology developed by Fujitsu and Hitachi) and facial recognition'perated without specific biometric data protection rules beyond general provisions of the amended Act on the Protection of Personal Information (APPI). The PPC and METI jointly developed sector-specific guidelines following reports of inadequate security practices at several payment processors.

**Issue:** What regulatory framework should govern the collection, processing, storage, and sharing of biometric data in Japan's biometric payment ecosystem.

**Holding:** The PPC and METI issued joint guidelines requiring biometric payment providers to: (1) obtain explicit opt-in consent before enrolling users in biometric payment programs; (2) store biometric templates only on secure hardware modules (not cloud servers); (3) implement liveness detection to prevent spoofing; (4) provide a clear, simple process for users to withdraw biometric data consent and delete templates; and (5) conduct annual security audits. Non-compliance would trigger corrective orders and potential criminal penalties.
**Significance:** Represented Japan's first comprehensive regulatory framework specifically addressing biometric payment systems.
Took a technology-specific approach, differentiating between facial recognition (higher risk) and palm vein authentication (lower risk) with proportionate requirements.
Balanced innovation promotion with consumer protection, reflecting Japan's broader regulatory philosophy of co-regulation.

---

### Case 5.45: China Real-Name Verification Biometric (2023) —Cyberspace Administration of China (CAC) / Ministry of Public Security

**Date Decided:** 2023

**Court:** Cyberspace Administration of China (CAC) / Regulatory enforcement

**Facts:** The Chinese government expanded real-name verification requirements for internet services, mobile applications, and social media platforms under the 2017 Cybersecurity Law and the 2021 Personal Information Protection Law (PIPL). Platforms including WeChat, Douyin, Baidu, and Weibo were required to collect facial recognition data to verify user identity during account registration and periodic re-verification. The scale of biometric data collection affected over one billion users. Critics raised concerns about data security, government access, and the absence of genuine consent in a system where biometric verification was mandatory for accessing essential services.

**Issue:** Whether mandatory facial recognition for real-name internet verification complied with China's PIPL requirements for necessity, proportionality, and informed consent.

**Holding:** The CAC issued implementing rules affirming the legality of mandatory biometric verification for internet services but imposed new requirements on platforms: (1) biometric data must be stored domestically and encrypted; (2) platforms must offer alternative verification methods where technically feasible; (3) biometric data collection must be limited to the minimum necessary; and (4) platforms must allow users to delete biometric data upon account cancellation. Enforcement actions were taken against several smaller platforms for non-compliance, though major platforms were given implementation grace periods.
**Significance:** Illustrated the tension between China's comprehensive data protection law (PIPL) and the state's extensive biometric surveillance infrastructure.
The nominal requirement for "alternative verification methods" signaled an acknowledgment of proportionality concerns, though practical alternatives were limited.
Demonstrated that even in highly centralized regulatory environments, data minimization and purpose limitation principles retain formal legal force.

---

### Case 5.46: India Aadhaar Biometric Authentication Cases (2018–2024) —Supreme Court of India

**Date Decided:** 2018–2024 (Key ruling: K.S. Puttaswamy v. Union of India, 2018; ongoing challenges through 2024)

**Court:** Supreme Court of India

**Facts:** India's Aadhaar system, the world's largest biometric identity program covering over 1.3 billion residents, collects iris scans, fingerprints, and facial photographs. Multiple constitutional challenges alleged that mandatory Aadhaar linking for bank accounts, mobile SIMs, welfare benefits, and tax filing violated the right to privacy. Subsequent cases addressed data breaches, authentication failures excluding legitimate beneficiaries, and the expansion of Aadhaar use to private sector services (eKYC, payments).

**Issue:** Whether mandatory Aadhaar biometric authentication for accessing government and private services violated the fundamental right to privacy under Article 21 of the Indian Constitution; whether Aadhaar's architecture satisfied proportionality and data protection standards.

**Holding:** In the landmark 2018 Puttaswamy decision (4-1 majority), the Supreme Court upheld Aadhaar's constitutional validity but struck down mandatory Aadhaar linking for bank accounts, mobile phones, and school admissions, restricting it to welfare subsidy disbursement and tax filing. The court required the government to enact a robust data protection law. Subsequent rulings (through 2024) addressed Aadhaar authentication failures, ordering compensation for excluded beneficiaries and strengthening security requirements. The passage of the Digital Personal Data Protection Act, 2023 partially addressed the court's legislative mandate.
**Significance:** The world's most significant judicial examination of a national biometric identity system, establishing proportionality analysis for state biometric programs.
Recognized the right to privacy as a fundamental right under the Indian Constitution, with cascading effects across all areas of Indian law.
Demonstrated that even constitutionally valid biometric systems require robust safeguards, meaningful consent, and redress mechanisms for authentication failures.

---

### Case 5.47: Philippines Biometric SIM Registration (2023) —National Telecommunications Commission (NTC) / Department of Information and Communications Technology (DICT)

**Date Decided:** 2023

**Court:** Supreme Court of the Philippines (challenged; implementation proceeding)

**Facts:** The Philippine government enacted the SIM Registration Act (Republic Act No. 11934), requiring all mobile phone users to register their SIM cards with telecommunications providers by submitting personal information including biometric data (facial photographs and, in some implementations, fingerprints). Non-registered SIMs would be deactivated. Privacy advocates and civil society organizations challenged the law, arguing that mandatory biometric collection for SIM registration violated the Data Privacy Act and created surveillance risks without adequate safeguards.

**Issue:** Whether mandatory biometric SIM registration under RA 11934 was constitutional and compliant with the Philippine Data Privacy Act of 2012.

**Holding:** The Supreme Court upheld the SIM Registration Act but issued a temporary restraining order on the deactivation deadline and required the government to implement stronger data protection safeguards before full enforcement. The NTC directed telecommunications companies to implement data encryption, limit data sharing, and establish clear breach notification procedures. Biometric data collection was made optional rather than mandatory in the implementing rules.
**Significance:** Balanced national security objectives (combating mobile-based fraud and terrorism) with data protection requirements in a Southeast Asian context.
Established that mandatory SIM registration is permissible but that biometric data collection within such programs must be proportionate and genuinely optional.
Provided a model for other Southeast Asian nations considering mandatory SIM registration with biometric components.

---

### Case 5.48: Nigeria Biometric Voter Registration (2023) —Independent National Electoral Commission (INEC) / Federal High Court

**Date Decided:** 2023

**Court:** Federal High Court of Nigeria

**Facts:** Nigeria's Independent National Electoral Commission (INEC) deployed a biometric voter registration system for the 2023 general elections, requiring voters to provide fingerprints and facial photographs for voter identification cards. Technical failures, including malfunctioning biometric devices, server crashes, and failed fingerprint matches, disenfranchised thousands of voters on election day. Political parties and civil society organizations sued INEC, alleging that the biometric system was unreliable and that the commission failed to provide adequate backup procedures.

**Issue:** Whether INEC's reliance on biometric voter authentication, without adequate backup mechanisms, violated citizens' right to vote under the Nigerian Constitution and the Electoral Act.

**Holding:** The Federal High Court ruled that INEC's exclusive reliance on biometric authentication, without functional manual fallback procedures, unconstitutionally disenfranchised eligible voters where biometric devices failed. The court ordered INEC to ensure that future elections incorporate reliable alternative verification methods and to compensate affected voters. The court did not invalidate the overall election results, finding that the disenfranchisement, while unlawful, was not sufficiently widespread to alter the outcome.
**Significance:** Established that biometric technology in democratic processes must include robust fallback mechanisms'echnology cannot be permitted to override constitutional rights.
Joined a global pattern of biometric authentication failures in elections (echoing similar issues in Kenya, India, and Ghana).
Highlighted the unique risks of biometric voter systems in developing countries with infrastructure challenges.

---

### Case 5.49: Kenya Huduma Namba Biometric ID (2021) —High Court of Kenya

**Date Decided:** 2021

**Court:** High Court of Kenya

**Facts:** The Kenyan government launched the Huduma Namba biometric identity system, requiring all citizens and residents to provide fingerprints, facial photographs, and iris scans for a unified digital ID card. The National Registration Bureau collected biometric data from millions of Kenyans, including vulnerable populations. Civil society organizations challenged the program, arguing that it violated constitutional privacy rights, that there was no adequate data protection framework, and that the risk of data misuse was exacerbated by the government's history of surveillance.

**Issue:** Whether the mandatory Huduma Namba biometric registration program violated the right to privacy under Article 31 of the Kenyan Constitution; whether the legal framework was sufficient to protect biometric data.

**Holding:** The High Court declared the Huduma Namba program unlawful in its then-form, ruling that the government had not enacted adequate data protection legislation (the Data Protection Act 2019 had been passed but key regulations were not yet in force) and that the program failed to provide sufficient safeguards for biometric data. The court ordered the government to: (1) enact comprehensive data protection regulations before relaunching; (2) conduct a privacy impact assessment; (3) ensure that Huduma Namba registration was not a precondition for accessing essential government services; and (4) establish an independent oversight mechanism.
**Significance:** One of the most comprehensive judicial rejections of a national biometric ID system in Africa.
Established that governments cannot deploy mandatory biometric identity systems without a fully operational data protection legal framework.
Affirmed that access to essential services cannot be conditioned on biometric registration' principle with global relevance.

---

### Case 5.50: Uganda Biometric SIM Registration (2023) —Uganda Communications Commission (UCC)

**Date Decided:** 2023

**Court:** Uganda Communications Commission (UCC) / High Court of Uganda (challenged)

**Facts:** The Ugandan government, through the UCC, enforced mandatory biometric SIM registration requiring all mobile phone subscribers to provide fingerprints and facial photographs to telecom operators. Non-compliant SIMs faced disconnection. The government justified the requirement as necessary for national security and combating crime. Civil society challenged the directive, arguing that the biometric data collection violated privacy rights, that adequate data protection safeguards were absent, and that the requirement disproportionately affected rural populations with limited access to registration centers.

**Issue:** Whether mandatory biometric SIM registration by the UCC violated the constitutional right to privacy and whether sufficient data protection safeguards were in place.

**Holding:** The High Court upheld the biometric SIM registration requirement but ordered the UCC to: (1) establish clear data retention and destruction policies; (2) ensure telecom operators implemented adequate security measures for biometric data; (3) extend registration deadlines and deploy mobile registration units for underserved areas; and (4) develop a regulatory framework for biometric data handling. The court stopped short of striking down the program but imposed significant compliance conditions.
**Significance:** Reflected the broader African trend of governments mandating biometric SIM registration while courts impose conditionality rather than outright prohibition.
Highlighted the digital divide implications of biometric requirements in developing countries.
Established judicial oversight as a mechanism for mitigating the privacy risks of mandatory biometric data collection.

---

### Case 5.51: Argentina Biometric Data Law (2023) —National Directorate for Personal Data Protection (CNDC)

**Date Decided:** 2023

**Court:** National Directorate for Personal Data Protection (CNDC), Argentina

**Facts:** Argentina's national identity system, managed by the National Registry of Persons (RENAPER), maintained a comprehensive biometric database containing fingerprints and facial photographs of all citizens. Multiple investigations revealed that this biometric data had been accessed by private companies'ncluding ride-hailing platforms, banks, and cryptocurrency exchanges'or identity verification without adequate legal basis or individual consent. The CNDC investigated whether these third-party accesses violated Argentina's Personal Data Protection Law (Law No. 25.326).

**Issue:** Whether private companies' access to RENAPER's biometric database for commercial identity verification purposes violated Argentina's Personal Data Protection Law and constitutional privacy guarantees.

**Holding:** The CNDC found that multiple private companies had accessed the national biometric database without a valid legal basis and without individual consent. The CNDC imposed administrative sanctions, ordered the immediate termination of unauthorized data access agreements, and required RENAPER to implement stricter access controls, audit trails, and consent-based sharing mechanisms. The CNDC also initiated proceedings to amend regulations governing biometric data sharing from the national database.
**Significance:** Exposed the vulnerability of centralized national biometric databases to unauthorized commercial exploitation.
Established that even where a national government maintains a biometric database for official purposes, commercial access requires separate legal basis and individual consent.
Strengthened Argentina's position as one of Latin America's leading data protection enforcement jurisdictions.

---

### Case 5.52: Colombia Biometric Data Habeas Data (2022) —Constitutional Court of Colombia

**Date Decided:** 2022

**Court:** Constitutional Court of Colombia (Corte Constitucional)

**Facts:** A citizen filed a tutela (habeas data) action challenging the Registrar National Civil Registry's collection and processing of his biometric data (fingerprints and facial photograph) for the national identity card, arguing that the data was being shared with private entities without consent and that inadequate security measures placed his biometric data at risk. The petitioner invoked the constitutional right to habeas data, which in Colombian law provides stronger protection than ordinary data protection statutes.

**Issue:** Whether the sharing of biometric data from the national civil registry with private entities without individual consent violated the constitutional right to habeas data; whether existing security measures were constitutionally adequate.

**Holding:** The Constitutional Court ruled that the sharing of biometric data from the national civil registry with private entities without explicit consent violated the fundamental right to habeas data under Article 15 of the Colombian Constitution. The court ordered the Registrar to: (1) terminate unauthorized data sharing agreements; (2) obtain explicit consent before any future sharing; (3) implement enhanced security measures including encryption and access logging; and (4) provide citizens with a mechanism to request information about who had accessed their biometric data.
**Significance:** Elevated biometric data protection to the level of a fundamental constitutional right in Colombia, beyond ordinary statutory protection.
Established that constitutional habeas data rights apply with special force to biometric data, given its irreplaceable and sensitive nature.
Created a enforceable right to access information about who has accessed one's biometric data' transparency right with global relevance.

---

### Case 5.53: Peru Biometric Data Protection (2023) —National Authority for Personal Data Protection (ANPD)

**Date Decided:** 2023

**Court:** National Authority for Personal Data Protection (Autoridad Nacional de Proteccin de Datos Personales), Peru

**Facts:** Several Peruvian banks and financial institutions deployed biometric authentication systems (fingerprint and facial recognition) for customer transactions, account access, and KYC verification without conducting privacy impact assessments, obtaining explicit consent, or implementing adequate security measures under Peru's Personal Data Protection Law (Law No. 29733). The ANPD conducted a sector-wide audit following complaints from consumer protection organizations.

**Issue:** Whether financial institutions' biometric authentication systems complied with Peru's Personal Data Protection Law, including requirements for informed consent, security measures, and proportionality.

**Holding:** The ANPD found systemic non-compliance across the banking sector's biometric authentication implementations. The authority issued corrective orders requiring: (1) explicit, informed consent for biometric data collection, separate from general account agreements; (2) mandatory privacy impact assessments before deploying new biometric systems; (3) implementation of encryption and secure storage for biometric templates; (4) data retention limits and deletion upon account closure; and (5) administrative fines for non-compliant institutions.
**Significance:** Established Peru's first comprehensive regulatory framework for biometric data in the financial sector.
Demonstrated that data protection authorities in smaller jurisdictions can conduct effective sector-wide enforcement.
Aligned Peru's biometric data protection standards with GDPR-level requirements, raising the bar across the Andean region.

---

### Case 5.54: Fox v. Doll —BIPA Class Action Defense Strategies (2023) —Illinois Supreme Court

**Date Decided:** 2023

**Court:** Illinois Supreme Court

**Facts:** In Fox v. Doll, the plaintiff sued a manufacturer of fingerprint-scanning timeclocks used by her employer, alleging that the manufacturer violated BIPA by collecting her fingerprint data without providing required disclosures and obtaining consent. The manufacturer argued that it could not be held liable under BIPA because it was not the "private entity" that collected the biometric data'he employer was. The case became a critical test of whether BIPA liability extends to technology vendors and service providers.

**Issue:** Whether a technology vendor that manufactures and provides biometric data collection devices can be held liable under BIPA as a "private entity" that "collects" biometric information.

**Holding:** The Illinois Supreme Court held that the manufacturer could be held liable under BIPA if it participated in the collection, storage, or use of biometric information, even when the primary relationship was with the employer. The court rejected a narrow reading that would limit BIPA liability only to the end-user employer, finding that technology providers who design, configure, and maintain biometric systems are integral to the data collection process.
**Significance:** Dramatically expanded BIPA's liability landscape by establishing that technology vendors, not just end-user employers, can face BIPA claims.
Prompted a wave of new class action filings against timeclock manufacturers, biometric software providers, and system integrators.
Forced the entire biometric technology supply chain to implement BIPA compliance measures, not just direct employers and service providers.

---

### Case 5.55: Cothron v. White Castle —SCOTUS Certiorari (2024) —United States Supreme Court

**Date Decided:** 2024 (certiorari granted January 2024; decision pending)

**Court:** United States Supreme Court (certiorari granted)

**Facts:** The plaintiff, an employee of White Castle System restaurants, sued under BIPA alleging that the company collected her fingerprint data for timeclock authentication without providing required written disclosures, obtaining informed consent, or publishing data retention policies. The central legal question was whether a new BIPA claim "accrues" each time biometric data is scanned or transmitted without compliant procedures, or whether the claim accrues only once't the time of initial collection. The Seventh Circuit had ruled that each scan or transmission constituted a separate violation, potentially exposing employers to billions of dollars in damages for routine biometric authentication.

**Issue:** When does a BIPA claim accrue for purposes of the statute of limitations't each instance of biometric data use/transmission or once at initial collection?

**Holding:** The Supreme Court granted certiorari to resolve the circuit split on BIPA accrual. The case was argued in the 2024 term, with the decision carrying enormous implications for BIPA litigation. Industry groups argued that per-scan liability would create ruinous exposure; plaintiffs argued that each non-compliant scan is a discrete statutory violation.
**Significance:** The most important BIPA case to reach the Supreme Court, with the potential to reshape the entire landscape of biometric privacy litigation in the United States.
The decision will determine whether BIPA's statutory damages framework creates per-instance or per-collection liability' difference of potentially billions of dollars for major employers.
Will influence legislative responses, including potential federal preemption or BIPA amendments, regardless of the outcome.

---

### Case 5.56: Illinois Biometric Information Privacy Act Amendments (2024) —Illinois General Assembly

**Date Decided:** 2024

**Court:** Illinois General Assembly (legislative action, signed into law)

**Facts:** Facing mounting pressure from the business community over the volume and cost of BIPA litigation'stimated at over $2 billion in settlements and judgments'he Illinois General Assembly passed amendments to BIPA. The amendments addressed several contested issues: the statute of limitations, the definition of "written release," private right of action scope, and compliance safe harbors. Privacy advocates opposed certain amendments as weakening the statute, while business groups argued they were necessary to prevent abusive litigation.

**Issue:** What amendments to BIPA would appropriately balance individual biometric privacy rights with the need for a workable compliance framework for businesses.

**Holding:** The 2024 amendments (signed into law) included the following key changes: (1) clarification that a one-year statute of limitations applies prospectively and a five-year period retroactively to pre-amendment claims; (2) a revised definition of "written release" allowing electronic consent in certain circumstances; (3) a 30-day cure period for first-time BIPA violations, allowing companies to avoid litigation by correcting non-compliance within 30 days of receiving written notice; (4) an exemption for biometric data collected in employment contexts where the data is used solely for security purposes and not stored in a searchable database; and (5) enhanced enforcement powers for the Illinois Attorney General, including the ability to seek civil penalties independently of private litigation.
**Significance:** Represented the most significant legislative modification of BIPA since its 2008 enactment, responding to nearly a decade of explosive litigation.
The 30-day cure provision was the most consequential change, potentially eliminating a large category of BIPA claims by incentivizing voluntary compliance.
Signaled that even privacy-forward legislatures will amend biometric privacy laws when litigation costs become perceived as excessive' development with implications for other states considering similar statutes.
End of Additional Cases (5.28—.57)

---

### Case 5.57: West Virginia v. Google Biometric Data Collection (2024) —West Virginia AG

**Date Decided:** 2024

**Court:** West Virginia Attorney General (Consumer Protection Division)

**Facts:** The West Virginia Attorney General filed suit against Google alleging that the company collected and stored biometric data'ncluding facial geometry and voiceprints'rom West Virginia residents through Google Photos and other services without obtaining informed consent as required under the state's Consumer Credit and Protection Act. The complaint contended that Google's face-grouping feature and voice assistant processed biometric identifiers surreptitiously.

**Issue:** Whether Google's collection and processing of biometric identifiers through consumer-facing products violated West Virginia's consumer protection statutes and common-law privacy protections by failing to obtain adequate informed consent.

**Holding:** Case filed and proceeding. Google moved to dismiss on preemption and standing grounds; the court denied the motion in part, allowing the biometric-specific claims to proceed. Settlement discussions were reported in late 2024.
**Significance:** Demonstrates state AGs expanding consumer protection enforcement into the biometric space, supplementing BIPA-style litigation.
Highlights the fragmented US regulatory landscape for biometric data, with states acting independently in the absence of comprehensive federal biometric legislation.

---

### Case 5.58: Illinois BIPA —Rosenbach v. Six Flags Subsequent Litigation (2024) —Illinois Courts

**Date Decided:** 2024

**Court:** Illinois Supreme Court / Illinois Appellate Court

**Facts:** Following the Illinois Supreme Court's landmark 2019 Rosenbach v. Six Flags decision establishing that individuals need not prove actual injury to maintain a BIPA claim, a wave of subsequent cases refined the scope of damages, standing, and statutory remedies. By 2024, the Illinois appellate courts addressed issues including whether "scan" claims under § 15(b) are distinct from "store/disseminate" claims under § 15(d), affecting whether a five-year or one-year limitations period applies.

**Issue:** Whether each discrete BIPA violation triggers a separate cause of action and damages award, and whether the limitations period for failure-to-store claims is governed by the five-year or one-year statute of repose under 735 ILCS 5/13-214.3.

**Holding:** The Illinois Supreme Court continued to affirm that each violation of a BIPA provision constitutes a separate actionable claim entitling a plaintiff to statutory damages. Appellate decisions in 2024 clarified the application of the five-year statute of limitations for storage-based claims.
**Significance:** BIPA remains the most consequential biometric privacy statute in the United States, with cumulative settlements exceeding $2 billion by 2024.
The per-violation damages model creates enormous exposure, incentivizing corporate compliance with biometric data handling protocols.

---

### Case 5.59: Canada —OPC Investigation of Unnamed Retailer Facial Recognition (2024) —Office of the Privacy Commissioner of Canada

**Date Decided:** 2024

**Court:** Office of the Privacy Commissioner of Canada (OPC) (Investigation Report)

**Facts:** The OPC investigated a major Canadian retailer (name withheld in the public summary) that had deployed facial recognition technology in its stores to detect shoplifters and persons previously banned from premises. The system captured biometric data of all customers entering stores, including children, without their knowledge or consent. The retailer argued the processing served legitimate loss-prevention interests.

**Issue:** Whether the retailer's covert deployment of facial recognition technology for loss prevention purposes violated PIPEDA principles of consent, necessity, and proportionality.

**Holding:** The OPC found the retailer violated PIPEDA by failing to obtain meaningful consent, collecting biometric data disproportionate to the stated purpose, and not implementing adequate safeguards. The Commissioner recommended the retailer cease facial recognition use, delete collected biometric data, and implement a privacy impact assessment process.
**Significance:** Reinforces that PIPEDA's consent requirements apply rigorously to biometric technologies deployed in physical retail environments.
Signals Canadian regulators' willingness to act against facial recognition even absent a dedicated biometric statute.

---

### Case 5.60: Australia —Bunnings Facial Recognition Investigation (2022) —Office of the Australian Information Commissioner

**Date Decided:** November 2022

**Court:** Office of the Australian Information Commissioner (OAIC)

**Facts:** Bunnings Warehouse, Australia's largest hardware retailer, deployed facial recognition technology in approximately 60 stores to identify persons previously banned or engaged in theft. The system collected facial templates of all customers entering stores. A complaint was filed with the OAIC alleging the practice violated the Privacy Act 1988 (Cth).

**Issue:** Whether Bunnings' collection and use of facial biometric data from customers without their knowledge or consent was permitted under the Australian Privacy Act and the APPs.

**Holding:** The OAIC found Bunnings' use of facial recognition was unjustified and unreasonable under APP 1, and that it collected sensitive information (biometric data) without consent in violation of APP 3. Bunnings agreed to cease using facial recognition, destroy collected data, and implement enhanced privacy governance.
**Significance:** First major OAIC enforcement action against facial recognition deployment in the private retail sector in Australia.
Established that even loss-prevention purposes do not automatically justify covert biometric surveillance under Australian privacy law.

---

### Case 5.61: UK —King's Cross Facial Recognition (2019) —Information Commissioner's Office

**Date Decided:** October 2019 (Enforcement Notice); ongoing appeals

**Court:** Information Commissioner's Office (ICO) / First-tier Tribunal

**Facts:** The Canary Wharf Group deployed live facial recognition (LFR) cameras in the Canary Wharf estate (often conflated with the broader King's Cross Central development) to identify individuals on watchlists for security and crime prevention purposes. The system captured and processed biometric data of tens of thousands of people without their knowledge. The ICO initiated an investigation following public complaints and media reports.

**Issue:** Whether the deployment of live facial recognition technology in a semi-public commercial estate without individual consent or a clear lawful basis complied with the GDPR and the Data Protection Act 2018.

**Holding:** The ICO issued an enforcement notice requiring the company to cease its use of facial recognition or demonstrate compliance with data protection law. The ICO found insufficient transparency, no clear lawful basis, and inadequate data protection impact assessments. The company contested aspects of the enforcement notice.
**Significance:** One of the earliest regulatory enforcement actions against private-sector facial recognition under the UK GDPR framework.
Established the ICO's position that private entities must conduct rigorous DPIAs and demonstrate proportionality before deploying biometric surveillance.

---

### Case 5.62: India —UIDAI Aadhaar Authentication Cases (2023) —Supreme Court of India

**Date Decided:** 2023 (various orders)

**Court:** Supreme Court of India

**Facts:** Multiple petitions challenged the Unique Identification Authority of India's (UIDAI) authentication requirements for various public and private services, arguing that mandatory Aadhaar-based biometric authentication violated the right to privacy. Despite the Supreme Court's 2017 landmark ruling in K.S. Puttaswamy v. Union of India recognizing privacy as a fundamental right, implementation challenges persisted, including authentication failures, exclusion of vulnerable populations, and private entity access to Aadhaar data.

**Issue:** Whether continued mandatory Aadhaar authentication requirements for accessing essential services violated the fundamental right to privacy under Article 21 of the Indian Constitution, and whether private entities could legally require Aadhaar authentication.

**Holding:** The Supreme Court reiterated that Aadhaar authentication cannot be made mandatory for services other than those specifically authorized by law (subsidies, benefits, and PAN-Aadhaar linking). The Court struck down provisions permitting private entities to verify customers through Aadhaar authentication, reinforcing its earlier Puttaswamy framework.
**Significance:** Confirms that India's Aadhaar system, while constitutionally valid for public welfare disbursements, cannot serve as a universal identity verification mechanism for the private sector.
Demonstrates ongoing judicial vigilance over state biometric identification programs post-Puttaswamy.

---

### Case 5.63: Brazil —Facial Recognition Surveillance in So Paulo (2023) —Public Prosecution / State Courts

**Date Decided:** 2023

**Court:** So Paulo State Courts / Ministério Pblico

**Facts:** The Municipality of So Paulo deployed a network of facial recognition cameras across the city's public transportation system and public spaces as part of a crime-reduction initiative. Civil liberties organizations filed public civil actions challenging the program, arguing it violated the Brazilian General Data Protection Law (LGPD), the Marco Civil da Internet, and constitutional privacy rights. The system had produced a high false-positive rate, particularly affecting Afro-Brazilian women.

**Issue:** Whether the municipal government's deployment of mass facial recognition surveillance without adequate legislative authorization, transparency, or safeguards violated constitutional rights and data protection law.

**Holding:** Courts issued preliminary injunctions requiring the municipality to conduct and publish a data protection impact assessment, disclose technical specifications including accuracy rates disaggregated by demographics, and establish a clear legal framework governing the program's operation and data retention.
**Significance:** Highlights the growing global judicial scrutiny of public-sector facial recognition deployment, with particular attention to algorithmic bias.
Establishes that even in high-crime contexts, mass biometric surveillance requires proportionality assessments and transparency under LGPD.

---

### Case 5.64: France —CNIL Clearview AI Enforcement (2022) —CNIL

**Date Decided:** December 2022

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL)

**Facts:** Clearview AI, a US-based facial recognition company, scraped billions of images from social media platforms and other publicly accessible websites to build a massive facial recognition database. French citizens' images were included without their knowledge or consent. The CNIL opened an investigation following complaints and coordinated with EU data protection authorities under the GDPR cooperation mechanism.

**Issue:** Whether Clearview AI's collection and processing of biometric data of French data subjects without consent violated the GDPR, and what enforcement measures were appropriate against a company based outside the EU.

**Holding:** The CNIL fined Clearview AI €0 million and ordered the company to cease collecting and processing biometric data of persons in France, delete existing data of French residents within two months, and refrain from offering its services to French law enforcement. Clearview AI did not comply with the deletion order.
**Significance:** Part of coordinated EU-wide enforcement against Clearview AI (CNIL, Italian Garante, Greek DPA, and others all issued fines).
Illustrates the challenges of enforcing GDPR against non-EU entities that ignore regulatory orders, highlighting the need for enhanced cross-border enforcement cooperation.

---

### Case 5.65: Germany —Hamburg DPA Facial Recognition in Schools (2023) —Hamburg Commissioner for Data Protection and Freedom of Information

**Date Decided:** 2023

**Court:** Der Hamburgische Beauftragte fr Datenschutz und Informationsfreiheit (Hamburg DPA)

**Facts:** A Hamburg school authority piloted a facial recognition attendance-tracking system that scanned students' faces as they entered school buildings to automate attendance records and enhance campus security. The system was deployed without a dedicated legal basis and without obtaining parental consent for all affected students. Parents and privacy advocates filed complaints with the Hamburg DPA.

**Issue:** Whether the school authority's deployment of facial recognition technology for attendance tracking was compatible with the GDPR's requirements for processing children's biometric data, which requires explicit consent or a substantial public interest.

**Holding:** The Hamburg DPA found the deployment unlawful under the GDPR and ordered the school authority to immediately cease using facial recognition, delete all collected biometric templates, and implement alternative attendance-tracking methods. The DPA emphasized that biometric processing of children requires the highest level of legal justification and that convenience alone is insufficient.
**Significance:** Reinforces that children's biometric data receives heightened protection under the GDPR, and educational authorities are not exempt.
Provides a practical precedent for data protection authorities restricting biometric technology in schools across Germany and the broader EU.

---

### Case 5.66: Japan —NEC Facial Recognition NII Data Breach (2023) —Personal Information Protection Commission / Tokyo District Court

**Date Decided:** 2023

**Court:** Personal Information Protection Commission (PPC) Japan / Tokyo District Court (civil litigation)

**Facts:** The National Institute of Informatics (NII) in Japan, in partnership with NEC Corporation, developed and operated a facial recognition research database containing facial images and biometric templates of approximately 2,000 research participants. A security misconfiguration exposed portions of the database to the public internet for several months in 2023. NEC, which provided the underlying facial recognition platform, faced scrutiny for inadequate security controls. Affected individuals filed civil claims and complaints with the PPC.

**Issue:** Whether NEC and NII violated Japan's Act on the Protection of Personal Information (APPI) by failing to implement adequate security measures for a biometric database, and whether affected individuals were entitled to compensation.

**Holding:** The PPC issued administrative guidance requiring NEC and NII to implement corrective security measures, conduct a comprehensive audit, and notify all affected individuals. Civil litigation proceeded in the Tokyo District Court, with plaintiffs seeking damages for emotional distress and privacy violations.
**Significance:** Illustrates the evolving application of Japan's amended APPI (effective 2022) to biometric data breaches, including the new requirement to report serious incidents to the PPC.
Highlights supply-chain responsibility in biometric data processing, with the technology provider (NEC) bearing accountability alongside the data controller (NII).
Part 6: Cybersecurity Breach Liability & Incident Response

---

### Case 5.67: Palm Vein Recognition, Japan (2024) — Tokyo District Court

**Date Decided:** 2024

**Court:** Tokyo District Court, Japan

**Facts:** A group of Japanese consumers filed a class action lawsuit against a financial services company that deployed palm vein biometric authentication systems at ATMs and branch offices without obtaining adequate informed consent. The plaintiffs argued that the collection and storage of palm vein patterns constituted sensitive personal information under Japan's Act on the Protection of Personal Information (APPI) and that the defendant failed to provide required disclosures about the purpose of collection, third-party sharing, and data retention periods. The plaintiffs sought damages and an injunction prohibiting further use of palm vein data without enhanced consent procedures.

**Issue:** Whether palm vein biometric data constitutes sensitive personal information under Japan's APPI requiring explicit consent for collection, and whether the defendant's consent procedures met the legal standard for informed consent.

**Holding:** The Tokyo District Court ruled that palm vein patterns constitute biometric information requiring enhanced protection under the APPI. The court found that the defendant's consent procedures were inadequate, as customers were not sufficiently informed about the biometric nature of the data being collected or their right to refuse. The court awarded damages to the plaintiffs and ordered the defendant to implement enhanced consent mechanisms, including clear disclosure of biometric data processing and the option to use alternative authentication methods.
**Significance:** Extended Japan's biometric privacy protections to palm vein recognition technology, which is increasingly deployed in financial services and access control systems across Asia.
Established that informed consent for biometric data collection must include specific disclosure of the biometric nature of the data and alternative options, raising the bar for consent practices beyond general privacy notices.
Aligned Japan's approach with emerging global standards for biometric data protection, particularly the enhanced consent requirements under the EU AI Act and various US state biometric privacy laws.

---

### Case 5.68: Gait Recognition, China (2023) — Surveillance Regulation

**Date Decided:** 2023

**Court:** No formal court proceedings; regulatory action under China's Personal Information Protection Law (PIPL) and the Ministry of Public Security's surveillance regulations

**Facts:** Chinese authorities announced enhanced regulatory controls on the use of gait recognition technology in public surveillance systems, following public disclosure that the technology was being deployed on an unprecedented scale in major cities without adequate legal authorization. The Ministry of Public Security issued internal directives restricting the deployment of gait recognition systems, requiring that their use be limited to specific law enforcement purposes with appropriate authorization. Simultaneously, the Cyberspace Administration of China (CAC) issued guidance on the application of the PIPL to biometric surveillance data, clarifying that gait data constitutes sensitive personal information subject to the law's enhanced protection requirements.

**Issue:** Whether the deployment of gait recognition surveillance systems without specific legal authorization and adequate privacy safeguards complied with the PIPL and China's broader legal framework for personal data protection.

**Holding:** The CAC and Ministry of Public Security jointly established regulatory requirements for gait recognition deployment, including mandatory privacy impact assessments, specific authorization requirements, data minimization mandates, and limitations on retention periods. The regulations prohibited the use of gait recognition for non-law enforcement purposes and required deletion of data from individuals not suspected of criminal activity. Existing gait recognition databases were required to undergo compliance review.
**Significance:** Marked a significant regulatory intervention in one of the world's most advanced biometric surveillance ecosystems, demonstrating that even China's permissive surveillance environment has legal boundaries.
Extended PIPL protections to gait recognition, one of the newest forms of biometric identification, establishing a regulatory framework that other jurisdictions may reference.
Illustrated the tension between China's extensive public surveillance infrastructure and its increasingly robust personal data protection law, with gait recognition regulation representing a point of convergence.

---

### Case 5.69: Voice Authentication in Indian Banking (2024) — RBI

**Date Decided:** 2024

**Court:** Reserve Bank of India (regulatory framework); supporting proceedings before the Adjudicating Officer under the Information Technology Act

**Facts:** Major Indian banks expanded their use of voice biometric authentication for telephone banking and mobile banking applications, deploying systems that compared customers' voiceprints against enrolled samples to verify identity. Consumer advocacy organizations raised concerns about the accuracy, security, and privacy implications of voice authentication, particularly for individuals with speech disabilities, regional accents, or voice-altering medical conditions. The Reserve Bank of India (RBI) was petitioned to establish regulatory standards for voice authentication in financial services, including accuracy requirements, fallback mechanisms, and data protection safeguards.

**Issue:** What regulatory standards should govern the use of voice biometric authentication in banking services under India's digital banking framework, and how should the interests of security, accessibility, and privacy be balanced?

**Holding:** The RBI issued comprehensive guidelines requiring banks deploying voice authentication to implement mandatory accuracy thresholds, provide alternative authentication methods for all customers, obtain explicit consent for voiceprint enrollment, and comply with data localization and security requirements under the Digital Personal Data Protection Act 2023. The guidelines also required regular bias testing to ensure equitable performance across India's diverse linguistic and demographic populations.
**Significance:** Established the first comprehensive regulatory framework for voice authentication in financial services in a major economy, addressing accuracy, accessibility, and privacy in an integrated manner.
Required bias testing across linguistic and demographic diversity, recognizing that voice recognition accuracy varies significantly across India's hundreds of languages and dialects.
Provided a model for other jurisdictions developing regulatory frameworks for voice biometric authentication, particularly in countries with significant linguistic and demographic diversity.

---

### Case 5.70: Emotion AI Regulation (2024) — EU AI Act

**Date Decided:** 2024 (AI Act adoption); 2025 (enforcement)

**Court:** EU AI Office (regulatory framework and enforcement under Regulation (EU) 2024/1689)

**Facts:** The EU AI Act classified emotion recognition systems — AI systems that infer emotions or intentions from biometric data such as facial expressions, voice patterns, and physiological signals — as subject to specific regulatory restrictions. Article 5 prohibited the use of emotion recognition systems in workplaces and educational institutions, while Article 6 classified certain emotion recognition applications as high-risk AI systems subject to enhanced requirements. The classification reflected concerns about the scientific validity of emotion AI, its potential for discriminatory outcomes, and its use in manipulative or coercive contexts.

**Issue:** Whether emotion recognition AI systems should be subject to prohibition, high-risk classification, or general-purpose regulation under the EU AI Act, and what specific restrictions should apply.

**Holding:** The EU AI Act, as adopted in 2024, prohibited the use of emotion recognition systems in workplaces and educational institutions (Article 5), classified emotion recognition in law enforcement and border control as high-risk (Article 6), and imposed transparency requirements for all other emotion recognition applications. The EU AI Office issued implementing guidance specifying that emotion recognition systems must provide accuracy reports demonstrating equitable performance across demographic groups and must include clear disclosures to individuals whose emotions are being inferred.
**Significance:** Established the world's first legal prohibition on specific applications of emotion recognition AI, reflecting growing scientific skepticism about the validity of inferring emotions from biometric data.
Created a tiered regulatory approach to emotion AI, distinguishing between acceptable and prohibited applications based on context and vulnerability of affected populations.
Influenced regulatory proposals in other jurisdictions, with several US states and Asian countries considering similar restrictions on emotion recognition in employment and education contexts.

---

### Case 5.71: Sweat Biometric Analysis, US (2024) — Privacy Debate

**Date Decided:** 2024

**Court:** No formal court proceedings as of 2024; regulatory debate, legislative proposals, and policy analysis

**Facts:** Emerging biometric technologies capable of analyzing sweat composition — including markers of stress, substance use, hydration levels, and metabolic state — raised novel privacy concerns in 2024 as several companies began deploying sweat-sensing wearables in workplace wellness programs and law enforcement contexts. Privacy advocates argued that sweat biometric analysis constitutes a search under the Fourth Amendment when deployed by law enforcement, and that its use in workplace wellness programs implicates the ADA, GINA, and state biometric privacy laws. The technology's ability to detect substance use, medical conditions, and emotional states from passive sweat collection raised unprecedented questions about bodily autonomy and the definition of biometric data.

**Issue:** Whether sweat biometric analysis constitutes biometric data subject to existing biometric privacy laws (BIPA, CUBI, MHMDA), whether its use in law enforcement requires a warrant under the Fourth Amendment, and what privacy protections should apply to workplace deployment.

**Holding:** No definitive judicial ruling was issued in 2024. However, several state legislatures introduced bills to explicitly include sweat biometric data within the scope of biometric privacy laws. The EEOC issued informal guidance indicating that workplace sweat analysis could constitute a medical examination under the ADA if used to detect medical conditions. Privacy scholars and advocacy groups called for comprehensive federal legislation addressing the unique privacy implications of molecular biometric analysis.
**Significance:** Expanded the scope of biometric privacy debate beyond traditional modalities (fingerprints, face, iris) to include molecular-level biometric data, raising questions about the boundaries of biometric regulation.
Highlighted the convergence of biometric privacy, workplace wellness, and Fourth Amendment law in the context of emerging sensing technologies.
Catalyzed legislative and regulatory activity that may establish new categories of protected biological data, extending existing frameworks to encompass the next generation of biometric technologies.
End of Additional Cases (5.68-5.72) for Part Five - Biometric Privacy
Global Cyber Law Compendium Volume II
---

# Part 6 — Data Breaches & Standing
## Chapter 6: The Standing Crisis in Data Breach Litigation
The proliferation of data breaches in the digital economy has generated a corresponding wave of class action litigation. Yet the federal judiciary's approach to Article III standing has emerged as the central bottleneck — often the decisive question that determines whether these cases proceed to merits analysis or are dismissed at the threshold. The four cases in this Part trace the evolution of standing doctrine in data breach and cybersecurity disclosure litigation from the Supreme Court's landmark ruling in TransUnion through the lower courts' application of its framework to more recent incidents.


### Case 6.1: TransUnion LLC v. Ramirez, 594 U.S. 413 (2021) — United States Supreme Court

**Date Decided:** June 25, 2021

**Court:** United States Supreme Court

**Facts:** TransUnion, one of the nation's three major credit reporting agencies, compiled credit files containing names that matched those on a government watchlist maintained by the Office of Foreign Assets Control (OFAC). The matching process was unreliable: of approximately 8,185 class members whose files contained a "potential match" alert, only 1,853 had their files transmitted to third-party businesses. Of those, the record showed that the false alert may have been seen by only a small number of recipients. TransUnion failed to follow its own procedures for verifying matches before distributing the flagged files to third parties. The lead plaintiff, Sergio Ramirez, was denied a car loan after a dealership saw the false OFAC alert on his TransUnion credit report.
Justice Thomas filed a concurring opinion. Justice Barrett filed an opinion concurring in part and dissenting in part, joined by Justice Breyer. Justice Gorsuch filed a dissenting opinion, joined by Justice Sotomayor.

**Issue:** The class action alleged that TransUnion violated the Fair Credit Reporting Act (FCRA), 15 U.S.C. 1681 et seq., by failing to maintain reasonable procedures to assure maximum possible accuracy of consumer reports, and by failing to provide consumers with notice of the adverse information. The principal issue before the Supreme Court was whether the class members had Article III standing to sue. Specifically, the Court addressed: (1) whether the dissemination of inaccurate information to third parties constituted a concrete injury sufficient for standing, and (2) whether the mere inclusion of false information in an internal database — without dissemination — could support standing.
**Holding:** The Supreme Court held, in a 5-4 opinion written by Justice Kavanaugh, that the plaintiff class could not be certified as it stood because many class members had not suffered a concrete injury. The Court affirmed Article III standing for the 1,853 class members whose credit reports were disseminated to third parties, finding that the reputational harm from false dissemination of sensitive information constituted a concrete injury. However, the Court held that the remaining approximately 6,332 class members — whose inaccurate information was stored in TransUnion's internal database but never transmitted to any third party — lacked standing because they could not demonstrate a concrete harm. The judgment was remanded for further proceedings consistent with the standing limitations. Justice Thomas filed a concurring opinion. Justice Barrett filed an opinion concurring in part and dissenting in part, joined by Justice Breyer. Justice Gorsuch filed a dissenting opinion, joined by Justice Sotomayor.
**Significance:** Concrete harm requirement elevated to a doctrinal threshold. TransUnion established that Article III standing in data privacy cases demands a showing of concrete, particularized injury — not merely the violation of a statutory right or the creation of a hypothetical risk. The Court rejected the argument that a statutory violation alone confers standing, requiring instead that the injury bear a "close relationship" to a harm traditionally recognized at common law. This fundamentally narrowed the universe of data breach class actions that can proceed in federal court.
Internal dissemination is not dissemination. The distinction between internal storage and third-party dissemination created a critical dividing line for standing analysis. Plaintiffs whose data was merely compromised within an organization's systems — without being transmitted to external actors — face a substantially higher bar to establishing concrete injury. This has had immediate and sweeping implications for data breach class actions where stolen data has not (yet) been used.
Class certification implications. The decision underscored that standing must be demonstrated on an individual, not class-wide, basis. Courts must conduct a rigorous assessment of whether each class member has suffered a concrete injury before certifying a class, effectively requiring named plaintiffs to demonstrate that the standing issue is common to all class members. This has forced plaintiffs' attorneys to be far more selective in class definitions and to develop more granular evidence of actual harm.
Dissent signals doctrinal contestation. Justice Gorsuch's dissent, warning that the majority's approach would insulate large corporations from accountability for systematic statutory violations, reflects an ongoing judicial debate about whether the standing doctrine should adapt to the particular characteristics of data privacy harm — harms that may be diffuse, probabilistic, and difficult to trace but are nonetheless real. This debate continues to shape lower court decisions.

---

### Case 6.2: McMorris v. Carlos Lopez & Associates, 995 F.3d 295 (2d Cir. 2021) — United States Court of Appeals for the Second Circuit

**Date Decided:** March 18, 2021

**Court:** United States Court of Appeals for the Second Circuit (per curiam)

**Facts:** Plaintiffs filed a putative class action against Carlos Lopez & Associates, a New York-based immigration law firm, following a data breach in which an unauthorized third party accessed the firm's computer network. The compromised data included plaintiffs' personally identifiable information (PII), including names, dates of birth, Social Security numbers, immigration file numbers, and other sensitive information. No evidence was presented that the stolen data had actually been misused — no fraudulent charges, no identity theft, no unauthorized account openings.

**Issue:** The plaintiffs alleged negligence, breach of contract, and violations of New York General Business Law 349 based on the law firm's failure to adequately protect their personal data. The central issue was whether the plaintiffs had Article III standing to pursue their claims given that they had not demonstrated any actual misuse of their stolen information. The plaintiffs relied on the theory that the increased risk of future identity theft, combined with the costs of protective measures, constituted a concrete injury.
**Holding:** The Second Circuit, applying the framework established in Lujan v. Defenders of Wildlife (1992) and Clapper v. Amnesty International USA (2013), held that the plaintiffs lacked Article III standing. The court articulated a two-part framework for assessing standing in data breach cases: (1) the plaintiff must demonstrate that the threatened harm is "certainly impending" or that there is a "substantial risk" of future harm; and (2) the plaintiff must show that the harm is "actual or imminent," not merely conjectural or hypothetical. Because the plaintiffs presented no evidence that their stolen data had been misused or was in the hands of actors likely to misuse it, and because mere exposure of data does not inherently create an imminent risk of identity theft, the court affirmed the district court's dismissal for lack of standing.
**Significance:** The "McMorris test" — a circuit-level standing framework. The Second Circuit's opinion established an influential framework — subsequently adopted or referenced by other circuits — requiring plaintiffs to produce evidence of actual data misuse, a demonstrable intent by the perpetrators to misuse the data, or circumstances from which misuse can be reasonably inferred. This framework effectively shifted the evidentiary burden to plaintiffs at the earliest stage of litigation, before discovery.
Rejection of the "increased risk" theory. The decision squarely rejected the argument that the exposure of personal data in a breach creates a sufficiently concrete and imminent risk of identity theft to confer standing. This represented a significant departure from some earlier district court decisions that had accepted increased risk as sufficient, and it aligned the Second Circuit with the more restrictive approach advocated by the Supreme Court's then-pending TransUnion decision.
Impact on data breach class action strategy. McMorris forced plaintiffs' attorneys to fundamentally rethink their approach to data breach litigation. Successful standing arguments now typically require either evidence of actual misuse or a showing that the breach involved particularly sensitive data (such as medical records or financial credentials) in circumstances that make misuse highly probable. The case also incentivized plaintiffs to seek state court venues where standing requirements may be less stringent under state constitutional law.

---

### Case 6.3: In re Lurie Children's Hospital Data Security Litigation (Sept 2025) — United States District Court for the Northern District of Illinois

**Date Decided:** September 2025

**Court:** United States District Court for the Northern District of Illinois

**Facts:** In 2024, Ann & Robert H. Lurie Children's Hospital of Chicago disclosed a data breach affecting a significant number of patients. The breach involved the exfiltration of protected health information (PHI) and personally identifiable information (PII), including patient names, dates of birth, medical record numbers, Social Security numbers, and clinical information. The hospital detected unauthorized access to its network systems and subsequently notified affected individuals. A multidistrict class action litigation ensued, with plaintiffs alleging negligence, invasion of privacy, and violations of state consumer protection and biometric information privacy statutes.

**Issue:** Plaintiffs sought to certify a class of affected individuals and pursue claims for the unauthorized disclosure of their sensitive health and personal data. The primary issue was whether, in the wake of TransUnion, the plaintiffs could establish Article III standing based on the exposure of their PHI and PII in the absence of any demonstrated actual misuse. The plaintiffs argued that the sensitivity of health data — as opposed to general financial data — created a heightened risk of harm that should satisfy the concrete injury requirement.
**Holding:** The court applied the TransUnion concrete injury analysis and concluded that the plaintiffs had not demonstrated standing sufficient to proceed with their claims. The court held that, even assuming the heightened sensitivity of health information, the mere fact of exposure — without evidence of actual or imminent misuse — was insufficient under TransUnion to establish a concrete injury. The court foreclosed the plaintiffs from relying solely on the increased risk of identity theft as a basis for standing, requiring instead specific evidence that the stolen data had been, or was imminently about to be, misused. Claims were dismissed without prejudice, with leave to replead upon presentation of additional standing evidence.
**Significance:** TransUnion applied to health data breaches. The Lurie Children's Hospital decision extended TransUnion's restrictive standing framework to the particularly sensitive context of health data breaches, rejecting the argument that the inherent sensitivity of PHI should lower the standing threshold. This signaled that even the most sensitive categories of personal data do not, by themselves, confer standing when the alleged harm is purely speculative.
No special solicitude for health data. The court's refusal to recognize a heightened — or lowered — standing threshold for health information contradicted arguments by privacy advocates that the Supreme Court's standing doctrine should be applied more flexibly when particularly sensitive categories of data are involved. This has prompted renewed attention to legislative solutions, including proposed amendments to HIPAA and state health privacy laws that would create statutory damages or private rights of action independent of Article III standing requirements.
Plaintiffs forced to investigate before suing. The practical effect of the decision is that data breach plaintiffs must now invest in independent investigation — monitoring the dark web, engaging forensic experts, and documenting actual misuse — before filing suit. This creates a significant barrier for individual plaintiffs who may lack the resources to conduct such investigations, effectively concentrating data breach litigation in the hands of well-resourced plaintiffs' firms that can absorb these costs.

---

### Case 6.4: SEC v. SolarWinds Corp. (Dismissed Nov 2025) — United States District Court for the Southern District of New York

**Date Decided:** November 2025

**Court:** United States District Court for the Southern District of New York

**Facts:** In July 2023, the Securities and Exchange Commission (SEC) filed a landmark enforcement action against SolarWinds Corporation and its Chief Information Security Officer (CISO), Timothy Brown, alleging fraud and internal control failures related to the SUNBURST cyberattack — one of the most sophisticated supply chain cyberattacks ever disclosed. The attack, attributed to Russian state-sponsored threat actors (APT29, also known as "Cozy Bear"), compromised SolarWinds' Orion software platform and was used to infiltrate numerous US government agencies and private sector organizations beginning in 2020. The SEC alleged that SolarWinds and Brown knew of significant cybersecurity deficiencies and vulnerabilities in their systems but misrepresented the company's cybersecurity practices in public disclosures, including earnings calls, investor presentations, and SEC filings. The SEC's complaint charged violations of Section 10(b) of the Securities Exchange Act of 1934, Rule 10b-5 thereunder, and Sections 13(a), 13(b)(2)(A), and 13(b)(2)(B) of the Exchange Act, as well as related control person provisions.

**Issue:** The SEC's core theory was that SolarWinds committed securities fraud by overstating its cybersecurity posture while knowing that its practices were inadequate. The case raised novel questions about: (1) the extent to which the SEC's cybersecurity disclosure requirements under existing securities law create liability for companies that are the victims of sophisticated nation-state attacks; (2) whether the SEC could hold individual corporate officers (specifically the CISO) personally liable under Section 20(a) of the Exchange Act; and (3) how courts should evaluate the materiality of cybersecurity-related statements in the context of a rapidly evolving threat landscape. In January 2025, Judge Paul Engelmayer issued a significant pre-trial ruling narrowing the SEC's claims and limiting the scope of the fraud allegations against Brown, excluding certain categories of statements from the fraud charges.
**Holding:** In November 2025, the SEC voluntarily dismissed its enforcement action against SolarWinds and Timothy Brown, shortly after the court's January 2025 ruling that substantially narrowed the SEC's theory of liability. The voluntary dismissal — with prejudice — effectively ended the case and marked a significant strategic retreat by the SEC. While the SEC did not publicly explain its decision, legal commentators widely attributed it to the adverse pre-trial ruling and the diminished likelihood of success at trial following the court's exclusion of key evidence and narrowing of the fraud theory.
**Significance:** Limits of SEC cybersecurity enforcement. The dismissal of the SolarWinds action represents a major setback for the SEC's emerging strategy of using securities fraud enforcement to police corporate cybersecurity practices. The case demonstrated that the existing securities law framework — designed primarily for financial fraud — is an imperfect vehicle for regulating cybersecurity disclosure, particularly when the statements at issue involve forward-looking assessments of security posture against sophisticated and evolving threats.
CISO personal liability curtailed. The case had drawn widespread attention in the cybersecurity community for its unprecedented targeting of an individual CISO for personal liability under federal securities law. The SEC's retreat effectively limits — at least for now — the viability of individual officer liability theories in cybersecurity disclosure cases, though the SEC retains the authority to bring similar actions in the future under different factual circumstances.
Impact on cybersecurity disclosure practices. Despite the dismissal, the SolarWinds case has had a chilling effect on corporate cybersecurity disclosure. Companies have responded to the litigation threat by adopting more cautious, qualified, and comprehensive disclosure language — often to the point of reducing the informational value of disclosures. This has intensified the ongoing debate about whether the SEC should adopt more specific, prescriptive cybersecurity disclosure rules (as it has proposed in rulemaking proceedings) rather than relying on the general anti-fraud provisions of the securities laws.
Nation-state attack as a defense. The case highlighted the emerging argument — accepted implicitly by the court's narrowing of claims — that companies should not be held to a standard of perfect security when targeted by sophisticated nation-state actors. This "impossibility of perfection" defense is likely to feature prominently in future cybersecurity enforcement actions and private litigation, potentially creating a tiered standard of care that accounts for the sophistication of the threat actor.
Section II: Major Data Breach Events

---

### Case 6.5: In re LinkedIn Data Breach Litigation (2012) — N.D. Cal.
**Date Decided:** 2012

**Court:** United States District Court for the Northern District of California
Citation: No. 12-md-02261-JSC

**Facts:** In June 2012, LinkedIn disclosed that approximately 6.5 million hashed passwords were stolen from its systems and posted on a Russian hacker forum. The passwords were hashed but not salted, making them vulnerable to brute-force decryption. A separate breach of LinkedIn user emails was later disclosed in 2016, affecting approximately 117 million accounts whose credentials had been hashed using the outdated SHA-1 algorithm. LinkedIn was criticized for delayed notification and for its password storage practices.

**Issue:** Whether LinkedIn users whose hashed passwords were exposed but not demonstrably misused had Article III standing to pursue claims for negligence, breach of contract, and violations of state consumer protection laws.

**Holding:** The district court denied LinkedIn's motion to dismiss, finding that the plaintiffs had adequately pleaded standing based on the combination of (1) the exposure of their login credentials, (2) the reasonable costs of mitigation (password changes, credit monitoring), and (3) the diminished value of their LinkedIn premium subscriptions. The court distinguished cases involving only name-and-address exposure, noting that compromised login credentials present a qualitatively different risk because they facilitate direct unauthorized access to user accounts.

**Significance:** Credentials are categorically different from demographic data. The court recognized that stolen login credentials — unlike names or email addresses — create an immediate, concrete risk of account takeover, establishing a lower standing threshold for breaches involving authentication data.
Subscription-diminution theory accepted. The decision endorsed the theory that a data breach can reduce the value of paid services, providing an economic injury basis for standing even absent identity theft.

---

### Case 6.6: In re Adobe Systems, Inc. Data Breach Litigation (2013) — N.D. Cal.
**Date Decided:** 2013

**Court:** United States District Court for the Northern District of California
Citation: No. 13-cv-05704-PSG

**Facts:** Adobe disclosed a massive breach in October 2013, ultimately affecting approximately 153 million user accounts. Stolen data included email addresses, encrypted passwords, customer names, payment card information (in some cases), and encrypted credit/debit card numbers. The breach also exposed source code for several Adobe products. Attackers posted approximately 10 GB of compressed data on the internet, and login credentials for nearly 38 million Adobe accounts were found on a site frequented by cybercriminals.

**Issue:** Whether plaintiffs whose encrypted payment card data and credentials were stolen in the Adobe breach had standing, and whether Adobe's encryption practices could be considered negligent under California law.

**Holding:** The court denied Adobe's motion to dismiss, holding that the theft of encrypted payment card data and source code constituted a concrete injury because (1) payment card data is a recognized target for financial fraud, and (2) the exposure of source code increased the risk of future attacks against Adobe's products, thereby harming users. The court permitted claims for negligence, breach of implied contract, and violations of California's Unfair Competition Law (UCL) and False Advertising Law to proceed.

**Significance:** Encryption does not eliminate injury. The court held that the fact that data was encrypted did not extinguish the risk of harm, because encryption can be broken — particularly Adobe's relatively weak implementation — and the stolen data had already appeared on criminal forums.
Source code exposure creates derivative harm. By recognizing that source code theft harms end users (through increased vulnerability to future exploitation), the decision expanded the conceptual scope of data breach injury beyond direct personal data exposure.

---

### Case 6.7: In re eBay Inc. Customer Data Security Breach Litigation (2014) — N.D. Ill.
**Date Decided:** 2014

**Court:** United States District Court for the Northern District of Illinois
Citation: No. 14-cv-04716

**Facts:** eBay disclosed in May 2014 that a cyberattack between late February and early March 2014 had compromised a database containing encrypted passwords, email addresses, physical addresses, phone numbers, and dates of birth for approximately 145 million users. eBay stated that financial data (payment card numbers) was not compromised because it was stored separately. The company was criticized for a delayed notification — the breach occurred in February/March but was not disclosed until May — and for initially encouraging users to change passwords without sending direct email notifications.

**Issue:** Whether the exposure of encrypted non-financial personal data (names, addresses, dates of birth, passwords) without evidence of actual misuse conferred Article III standing.

**Holding:** The court granted in part and denied in part eBay's motion to dismiss. The court held that plaintiffs who alleged actual out-of-pocket mitigation costs (credit monitoring, password changes, time spent responding to the breach) had demonstrated concrete injury sufficient for standing. However, the court dismissed claims based solely on the hypothetical risk of future identity theft, consistent with the emerging framework requiring evidence of actual or imminent harm.

**Significance:** Mitigation costs as concrete injury. The decision reinforced the growing consensus that reasonable out-of-pocket expenditures in response to a data breach — credit monitoring subscriptions, professional identity protection services — constitute concrete economic injury sufficient for Article III standing.
Notification delay as aggravating factor. The court's opinion noted that eBay's delayed and incomplete notification may have increased the window of risk, though it did not treat the delay itself as an independent basis for standing.

---

### Case 6.8: In re Anthem, Inc. Data Breach Litigation (2015) — N.D. Cal.
**Date Decided:** 2015

**Court:** United States District Court for the Northern District of California (MDL)
Citation: No. 15-md-02617-LHK

**Facts:** Anthem, one of the largest health insurance companies in the United States, disclosed in February 2015 that a sophisticated cyberattack had compromised the personal information of approximately 78.8 million current and former members and employees. Stolen data included names, dates of birth, Social Security numbers, healthcare identification numbers, home addresses, email addresses, employment information, and income data. The breach did not involve medical records or payment card data. The attack was attributed to a state-sponsored Chinese threat actor. Anthem agreed to a $115 million settlement — the largest data breach settlement at the time — in 2017.

**Issue:** Whether the theft of highly sensitive personal data (Social Security numbers, healthcare IDs) in a healthcare context conferred Article III standing, and what level of future harm was sufficient to support claims.

**Holding:** The court denied Anthem's motion to dismiss, finding that the theft of Social Security numbers combined with names and other identifiers created a substantially heightened risk of identity theft and fraud. The court distinguished Anthem from cases involving less sensitive data, noting that Social Security numbers are effectively permanent identifiers that cannot be changed, making their exposure qualitatively different from credit card numbers. The $115 million settlement provided credit monitoring, identity protection services, and cash payments to affected individuals.

**Significance:** SSN exposure as a distinct standing category. The decision helped establish that Social Security numbers occupy a unique position in standing analysis — their irreplaceable nature and central role in identity verification create a risk profile that is categorically more serious than other types of personal data.
Largest healthcare breach settlement at the time. The $115 million settlement set a benchmark for data breach class action resolution and demonstrated that healthcare companies face outsized exposure due to the sensitivity of the data they hold.

---

### Case 6.9: In re Uber Technologies, Inc. Passenger Data Breach Litigation (2017) — N.D. Cal.
**Date Decided:** 2017

**Court:** United States District Court for the Northern District of California
Citation: No. 17-cv-06774-PSG

**Facts:** In November 2017, Uber disclosed that it had concealed a massive data breach that occurred in October 2016, in which hackers accessed the personal data of approximately 57 million riders and drivers worldwide. Stolen data included names, email addresses, and phone numbers of riders, and driver's license numbers of approximately 600,000 drivers in the United States. Uber paid the hackers $100,000 to destroy the stolen data and conceal the breach. The cover-up led to the resignation of Uber's Chief Security Officer, Joe Sullivan, who was later criminally prosecuted for obstruction of justice. Uber agreed to a $148 million multistate settlement with attorneys general in 2018.

**Issue:** Whether Uber's deliberate concealment of the breach — and payment to the hackers — created an independent basis for standing and liability beyond the underlying data exposure.

**Holding:** The litigation resulted in a comprehensive settlement. The court approved a $148 million settlement with state attorneys general addressing Uber's violations of state data breach notification laws through its deliberate concealment. In the federal class action, the court found that the concealment aggravated plaintiffs' injuries by depriving them of the opportunity to take timely protective measures. Sullivan was convicted in October 2022 of federal charges related to the cover-up, in the first criminal prosecution of a corporate CISO for concealing a data breach.

**Significance:** Criminal liability for breach cover-ups. The conviction of Uber's CSO established that deliberately concealing a data breach — including paying hackers to destroy stolen data — can result in personal criminal liability for corporate security officers, sending a powerful deterrent signal.
Concealment as injury aggregator. Uber's cover-up created an independent and aggravating basis for liability: by hiding the breach for over a year, Uber deprived millions of users of the opportunity to mitigate harm, substantially strengthening plaintiffs' standing and damages theories.

---

### Case 6.10: In re Yahoo! Inc. Customer Data Security Breach Litigation (2016–2017) — N.D. Cal.
**Date Decided:** 2016–2017

**Court:** United States District Court for the Northern District of California
Citation: No. 16-cv-05039-PSG

**Facts:** Yahoo (subsequently acquired by Verizon and rebranded as Oath/Verizon Media) disclosed two massive, separate breaches: the first in September 2016, affecting approximately 500 million accounts (later revised to 3 billion — effectively all Yahoo accounts at the time), involving stolen names, email addresses, telephone numbers, dates of birth, hashed passwords, and security questions and answers; the second in December 2016, affecting approximately 1 billion accounts, involving similar data plus unencrypted security questions. The breaches, which had actually occurred in 2013 and 2014 respectively, were attributed to state-sponsored actors. The delayed disclosures and their timing relative to Verizon's acquisition of Yahoo significantly reduced the acquisition price by approximately $350 million.

**Issue:** Whether the progressive disclosure of increasingly massive breaches — and the concealment during a pending acquisition — created standing for both consumer class members and Yahoo shareholders.

**Holding:** The court approved a $117.5 million settlement in 2019, covering approximately 200 million class members in the United States and Israel. The settlement provided $75 million for two years of credit monitoring, $35 million in cash payments, and $7.5 million for attorneys' fees and costs. The court also addressed shareholder claims arising from the diminution in Yahoo's acquisition value caused by the breach disclosures.

**Significance:** Largest historical breach at the time. Yahoo's 3-billion-account breach remains one of the largest ever disclosed and demonstrated that even long-past breaches can generate substantial litigation liability when disclosed years after the fact.
Corporate transactional impact. The case established that undisclosed data breaches can have material impact on corporate valuations and M&A transactions, creating a new category of potential liability — shareholder claims arising from breach-related diminution in enterprise value.
Security question exposure as heightened risk. The exposure of unencrypted security questions — effectively backup authentication credentials — was treated as an especially serious form of data compromise.

---

### Case 6.11: In re Experian Data Breach Litigation / Experian/TCF Bank (2015) — D. Minn.
**Date Decided:** 2015

**Court:** United States District Court for the District of Minnesota
Citation: No. 15-cv-02613-DWF-LIB

**Facts:** Experian, one of the three major US credit reporting agencies, suffered a breach through a vulnerability in a data platform it operated on behalf of TCF National Bank (TCF Bank). The breach exposed the personal information of approximately 15 million TCF Bank customers who had applied for the bank's store credit cards between 2007 and 2013. Stolen data included names, addresses, dates of birth, phone numbers, email addresses, and Social Security numbers — essentially the complete dossier needed for identity theft. Experian was both the custodian of the data and the entity responsible for the security of the affected system.

**Issue:** Whether a credit reporting agency — the entity specifically tasked with safeguarding consumer financial data — could be held liable for negligence and statutory violations when its own systems were breached, and whether affected consumers had standing despite lack of evidence of actual misuse.

**Holding:** The court denied Experian's motion to dismiss, holding that the exposure of Social Security numbers and other comprehensive identity data by a credit reporting agency — an entity whose core business function is the maintenance and protection of sensitive consumer data — created a sufficiently concrete risk of harm to confer standing. The court noted that the trust-based relationship between consumers and credit bureaus heightened the duty of care. The case proceeded to discovery and contributed to a settlement framework.

**Significance:** Heightened duty for data custodians. The decision reinforced the principle that entities whose core business involves collecting and safeguarding personal data — particularly credit bureaus — owe an elevated duty of care, and that breaches by such entities may face less judicial skepticism regarding standing.
Third-party vendor breach liability. The case highlighted the liability exposure of companies that outsource data processing to third-party vendors, even when the vendor is a major, reputable institution like Experian.

---

### Case 6.12: In re Panera Bread Co. Data Breach Litigation (2018) — various
**Date Decided:** 2018

**Court:** United States District Court for the Southern District of Illinois / various
Citation: No. 18-cv-03349-SMY

**Facts:** In April 2018, security researcher Brian Krebs disclosed that Panera Bread's website had been leaking customer records — including names, email addresses, physical addresses, phone numbers, dates of birth, and the last four digits of credit card numbers — for at least eight months. The data was accessible through a simple API endpoint without authentication, affecting approximately 37 million customer records. Panera had been alerted to the vulnerability months earlier by another security researcher but had failed to fix it. Panera initially disputed the scope of the breach before acknowledging and fixing the vulnerability.

**Issue:** Whether the negligent exposure of customer data through an unsecured API — without evidence of a directed attack — constituted a compensable injury, and whether Panera's failure to act on prior warning created an aggravating factor for standing.

**Holding:** The court denied Panera's motion to dismiss in part, finding that plaintiffs who demonstrated actual exposure of their data through the unsecured API and who incurred mitigation costs had standing. The court noted that Panera's knowledge of the vulnerability and failure to remediate for months distinguished this case from breaches caused by sophisticated attacks, as the exposure was the direct result of known, preventable negligence.

**Significance:** API security as corporate responsibility. The case established that unsecured application programming interfaces — a common vulnerability in modern web applications — can create liability comparable to traditional data breaches, even without a directed hack.
Prior notice as negligence multiplier. Panera's failure to act on prior warnings strengthened plaintiffs' negligence claims and supported the inference that harm was reasonably foreseeable, because the company was specifically alerted to the vulnerability months before the exposure became public.

---

### Case 6.13: In re Quora Data Breach Litigation (2018) — N.D. Cal.
**Date Decided:** 2018

**Court:** United States District Court for the Northern District of California
Citation: No. 18-cv-07388-LHK

**Facts:** Quora, the question-and-answer platform, disclosed in December 2018 that unauthorized access to its systems had compromised approximately 100 million user accounts. Stolen data included names, email addresses, encrypted passwords, data from linked social media accounts (such as Facebook and Twitter), user-submitted content (questions, answers, and direct messages), and non-public content such as answer drafts and deleted content. The breach was discovered by Quora's security team and attributed to unauthorized access by a third party.

**Issue:** Whether the exposure of user-generated content — including potentially sensitive questions and private messages — in addition to standard credential data, created a distinct basis for standing and damages.

**Holding:** The litigation resulted in a settlement. The court approved a settlement that included provisions for data security enhancements, credit monitoring for affected users, and attorneys' fees. The court found that the exposure of non-public content — including direct messages and deleted posts — raised privacy concerns beyond standard credential theft, supporting plaintiffs' standing under a broader conception of privacy injury.

**Significance:** Content exposure beyond credentials. The case expanded the scope of data breach standing analysis to encompass the exposure of user-generated content — a category of data whose sensitivity varies widely but can include highly personal or embarrassing information.
Platform-specific data sensitivity. The decision acknowledged that different types of platforms hold different categories of sensitive data, and that standing analysis should account for the specific nature of the compromised content.

---

### Case 6.14: In re Exactis Data Breach Litigation (2018) — various
**Date Decided:** 2018

**Court:** Various federal district courts
Citation: Multiple

**Facts:** Approximately 340 million records were exposed on a publicly accessible ElasticSearch database maintained by data broker Exactis. The records contained hundreds of data fields per individual, including names, addresses, phone numbers, emails, dates of birth, and detailed behavioral/interest profiles. The exposure persisted for at least two months before discovery by a security researcher.

**Issue:** Whether individuals whose data was held by a data broker without their direct knowledge or consent — and then exposed through a misconfigured database — had Article III standing.

**Holding:** Courts reviewing the case grappled with whether individuals who had no direct relationship with Exactis could demonstrate a concrete injury from the exposure of data they did not knowingly share. Some courts found standing based on the breadth and sensitivity of the exposed information, while others expressed skepticism about whether the injury was sufficiently concrete when the plaintiff had no pre-existing relationship with the data custodian.

**Significance:** Data broker accountability gap. The case highlighted the significant accountability gap in the data broker ecosystem — entities that hold vast troves of consumer data but with whom consumers have no direct relationship and limited ability to demand protection or remediation.
Scope of exposed data as standing factor. The unprecedented breadth of data fields exposed (hundreds per individual) was treated as a distinguishing factor, because the aggregated profile was more useful to identity thieves and scammers than typical credential-only breaches.

---

### Case 6.15: In re First American Financial Corp. Data Breach Litigation (2019) — E.D.N.Y.
**Date Decided:** 2019

**Court:** United States District Court for the Eastern District of New York
Citation: No. 19-cv-02531-ARR-LB

**Facts:** In May 2019, security reporter Brian Krebs disclosed that First American Financial Corporation, one of the largest title insurance companies in the United States, had exposed approximately 885 million records related to real estate transactions dating back to 2003. The exposure was caused by a design vulnerability in First American's website: anyone with a valid document URL could access any other document in the system simply by incrementing a numeric identifier in the URL, without any authentication. Exposed documents included Social Security numbers, bank account numbers, wire transfer records, driver's license images, and other highly sensitive financial and identity documents.

**Issue:** Whether a broken access control vulnerability — as opposed to a directed cyberattack — that exposed 885 million sensitive financial documents constituted a compensable data breach, and whether the total absence of authentication created a negligence per se theory.

**Holding:** The court denied First American's motion to dismiss in part, finding that the exposure of Social Security numbers, bank account numbers, and other financial credentials through a trivially exploitable vulnerability supported standing for plaintiffs who could demonstrate their specific documents were accessible. The court noted that the complete absence of access controls — not a sophisticated bypass but a total failure — was qualitatively different from breaches caused by determined attackers overcoming security measures.

**Significance:** Broken access control as negligence. The case established that the total absence of authentication — as opposed to the failure of existing security measures — can support a negligence per se theory, because the company failed to implement even the most basic access controls.
Design flaws vs. attacks. By distinguishing between a design vulnerability (accessible to anyone who knew the URL pattern) and a directed attack, the decision created a framework for assessing liability based on the nature of the security failure rather than the nature of the threat actor.

---

### Case 6.16: In re Facebook, Inc. Consumer Privacy User Profile Data Litigation (2019) — N.D. Cal.
**Date Decided:** 2019

**Court:** United States District Court for the Northern District of California
Citation: No. 18-cv-04966-PSG

**Facts:** In April 2019, Facebook (now Meta) disclosed that hundreds of millions of user passwords had been stored in plaintext in Facebook's internal systems, accessible to approximately 2,000 Facebook engineers and employees. The affected systems stored passwords for Facebook, Facebook Lite, and Instagram users — totaling approximately 540 million accounts. Facebook stated that the passwords were not externally exposed and that there was no evidence of misuse by internal employees. The disclosure followed an internal review prompted by a security audit. The company had been aware of the plaintext password storage since at least 2012 but had not notified users or taken comprehensive remedial action.

**Issue:** Whether the internal storage of 540 million plaintext passwords — without evidence of external exposure or employee misuse — constituted a concrete injury sufficient for Article III standing.

**Holding:** The court denied Facebook's motion to dismiss in part, finding that the storage of passwords in plaintext — in violation of Facebook's own stated privacy practices and fundamental security principles — created a risk of harm sufficient for standing, particularly for users who alleged that they experienced unauthorized access to their accounts around the time of the exposure. The court noted that internal employees with access to plaintext passwords could have misused them, and that Facebook's years-long failure to remediate the issue undermined its claim that the risk was negligible.

**Significance:** Plaintext password storage as per se negligence. The case treated the storage of passwords in plaintext — as opposed to industry-standard hashing and salting — as a fundamental security failure that can independently support standing and negligence claims.
Internal exposure suffices when data is passwords. The decision expanded standing analysis by finding that the risk of insider misuse of plaintext passwords was concrete enough to confer standing, even without evidence of actual misuse — a notable departure from the general post-TransUnion trend.

---

### Case 6.17: In re Log4Shell Vulnerability Litigation (2021–2022) — various
**Date Decided:** 2021–2022

**Court:** Various federal district courts (consolidation efforts ongoing)
Citation: Multiple; no single MDL established

**Facts:** In December 2021, a critical zero-day vulnerability (CVE-2021-44228, nicknamed "Log4Shell") was discovered in Apache Log4j, a widely used open-source Java logging library embedded in countless enterprise software applications, cloud services, and IoT devices. The vulnerability, which had existed undetected since 2013, allowed unauthenticated remote code execution — one of the most severe categories of security flaws. CISA Director Jen Easterly described it as "one of the most serious" vulnerabilities she had seen in her career. Millions of organizations worldwide were potentially affected, including government agencies, financial institutions, healthcare providers, and technology companies. Multiple exploitation attempts were detected within hours of public disclosure, and state-sponsored threat actors were among those exploiting the vulnerability.

**Issue:** Whether organizations that used software containing the Log4j vulnerability — and individuals whose data was compromised through its exploitation — had standing to pursue claims against Apache (as the open-source project steward), software vendors who embedded Log4j in their products, and other entities in the software supply chain.

**Holding:** Courts have struggled with the complex liability questions presented by the Log4j supply chain vulnerability. Some cases against software vendors who embedded Log4j and failed to patch have survived motions to dismiss, particularly where plaintiffs demonstrated actual exploitation and data exfiltration. However, claims against the Apache Software Foundation (which maintains Log4j as an open-source project) have generally been dismissed on the grounds that open-source software maintainers do not owe a duty of care to downstream users absent a commercial relationship. The litigation remains ongoing across multiple jurisdictions.

**Significance:** Software supply chain liability framework. The Log4Shell litigation is establishing the foundational liability framework for software supply chain vulnerabilities, including the extent to which open-source maintainers, commercial vendors, and end-user organizations share responsibility for security.
Open-source liability limitations. The general dismissal of claims against Apache has reinforced the principle that open-source software distributed without commercial warranties does not create the same duty of care as commercial software products, though this may change with emerging legislation.
Nation-state exploitation as standing evidence. Courts have been more willing to find standing when plaintiffs present evidence that state-sponsored actors exploited the vulnerability to access their data, because the involvement of sophisticated threat actors makes the risk of misuse more concrete.
Section III: Standing Doctrine Development

---

### Case 6.18: Spokeo, Inc. v. Robins, 578 U.S. 544 (2016) — United States Supreme Court
**Date Decided:** 2016

**Court:** United States Supreme Court
Citation: 578 U.S. 544 (2016)

**Facts:** Thomas Robins sued Spokeo, a "people search engine" that aggregates publicly available personal information into consumer profiles, under the Fair Credit Reporting Act (FCRA). Robins alleged that Spokeo's profile about him contained inaccurate information — listing a younger age, a higher level of education, greater wealth, and a different marital status — which he claimed harmed his employment prospects. He had not demonstrated that any employer had actually seen the incorrect profile or that the inaccuracies had caused any specific adverse employment action. Spokeo moved to dismiss for lack of Article III standing, arguing that the alleged inaccuracies had not caused any concrete harm.

**Issue:** Whether the violation of a procedural statutory requirement (FCRA's accuracy requirement) alone is sufficient to establish Article III standing, or whether the plaintiff must also demonstrate concrete harm.

**Holding:** The Supreme Court, in a 6-2 opinion by Justice Kennedy, vacated the Ninth Circuit's decision and remanded. The Court held that a plaintiff must demonstrate (1) a concrete and particularized injury that is (2) actual or imminent, (3) fairly traceable to the defendant's conduct, and (4) likely to be redressed by a favorable judicial decision. Critically, the Court held that while a concrete injury may be established by reference to a harm traditionally recognized at common law, not all statutory violations automatically confer standing. The statutory violation must cause a harm that is "concrete and particularized" — a requirement that cannot be dispensed with by Congress's mere creation of a statutory right. The Court remanded for the Ninth Circuit to evaluate whether Robins's particular alleged harms were sufficiently concrete.

**Significance:** Two-part standing framework for statutory violations. Spokeo established that Article III standing requires not only that Congress create a legal right, but that the violation of that right cause a concrete injury — setting the stage for TransUnion's more rigorous application of this principle.
Circuit split catalyst. The decision triggered a massive wave of standing challenges in data privacy and consumer protection litigation, as courts across the country struggled to apply the concrete injury requirement to various categories of statutory violations.

---

### Case 6.19: Clapper v. Amnesty International USA, 568 U.S. 398 (2013) — United States Supreme Court
**Date Decided:** 2013

**Court:** United States Supreme Court
Citation: 568 U.S. 398 (2013)

**Facts:** Amnesty International USA, along with journalists, lawyers, and human rights organizations, challenged the constitutionality of Section 702 of the Foreign Intelligence Surveillance Act (FISA) Amendments Act of 2008, which authorized warrantless surveillance of non-US persons located abroad. The plaintiffs alleged that their communications with foreign contacts were likely to be intercepted under the statute, requiring them to incur costs to travel abroad for sensitive communications instead of using electronic means. The government asserted that the surveillance was classified and that plaintiffs could not confirm that their communications had actually been intercepted.

**Issue:** Whether the plaintiffs had standing to challenge the FISA Amendments Act based on their reasonable fear that their communications would be subjected to warrantless surveillance.

**Holding:** The Supreme Court, in a 5-4 opinion by Justice Alito, held that the plaintiffs lacked Article III standing. The Court rejected the plaintiffs' theory that their costs of modifying their communications practices constituted a concrete injury, finding these expenditures to be entirely self-inflicted and the product of their own speculation. The Court held that the threatened injury must be "certainly impending" and that the plaintiffs' chain of causation — involving multiple speculative steps between the statute's authorization and the alleged interception of their particular communications — was too attenuated to support standing. The Court also held that the plaintiffs had not demonstrated that any of their communications had actually been intercepted.

**Significance:** "Certainly impending" standard. Clapper established the high bar that threatened injury must be "certainly impending" to confer standing — a standard that has been applied extensively in data breach cases to reject standing based on speculative future harm.
Chilling effect alone is not injury. The decision held that the subjective fear of surveillance, even when reasonable, does not constitute a concrete injury sufficient for standing — a principle that has been extended to data breach plaintiffs who fear but cannot demonstrate actual identity theft.
Foundation for data breach standing restriction. Clapper became the principal Supreme Court precedent cited by courts dismissing data breach cases for lack of standing, establishing the presumption that speculative future harm — even the "substantial risk" of identity theft — is insufficient without evidence of actual or imminent misuse.

---

### Case 6.20: Bartnicki v. Vopper, 532 U.S. 514 (2001) — United States Supreme Court
**Date Decided:** 2001

**Court:** United States Supreme Court
Citation: 532 U.S. 514 (2001)

**Facts:** An unknown person intercepted and recorded a cellular telephone conversation between two union officials — Gloria Bartnicki and Anthony Kane — discussing controversial labor negotiations, including threats of violent action against management. The illegally intercepted recording was provided to Frederick Vopper, a radio host, who played it on the air. Bartnicki and Kane sued under federal and state wiretapping statutes, alleging that the publication of their private conversation caused them emotional distress and professional harm.

**Issue:** Whether a third party who did not participate in the illegal interception but who published the contents of an illegally intercepted communication could be held liable under the federal Wiretap Act and state wiretapping laws.

**Holding:** The Supreme Court, in a 6-3 opinion by Justice Stevens, held that the First Amendment protected the publication of the illegally intercepted communication by a third party who did not participate in the interception. The Court held that the interest in privacy in one's own telephone conversations, while significant, must be balanced against the interest in the free flow of information on matters of public concern. Because the conversation involved a matter of public importance (labor disputes and threats of violence), the First Amendment barred liability for the third-party publisher.

**Significance:** Limits of privacy protection for published data. While not a data breach case per se, Bartnicki established the principle that once information has been illegally obtained and enters the public domain, downstream recipients and publishers may be protected by the First Amendment — a principle that has implications for data breach litigation where stolen data is subsequently published or used by third parties.
Illegality of acquisition vs. illegality of use. The decision drew a critical distinction between the illegal act of interception (which remained prohibited) and the subsequent use of the intercepted information by an innocent third party — a distinction that echoes in modern data breach cases where stolen data is used by parties who did not participate in the original hack.

---

### Case 6.21: Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688 (7th Cir. 2015) — United States Court of Appeals for the Seventh Circuit
**Date Decided:** 2015

**Court:** United States Court of Appeals for the Seventh Circuit
Citation: 794 F.3d 688 (7th Cir. 2015)

**Facts:** Neiman Marcus disclosed in January 2014 that a malware attack on its point-of-sale systems between July 2013 and October 2013 had compromised approximately 350,000 customer payment cards. Approximately 9,200 customers had fraudulent charges made on their cards. The plaintiffs — Neiman Marcus customers whose payment card data was stolen — alleged negligence and various state law claims, even though many of them had not actually experienced fraudulent charges. They sought class certification and claimed that the risk of future identity theft and the costs of mitigation (credit monitoring, card replacement) constituted concrete injury.

**Issue:** Whether the risk of future identity theft and the costs of preventive measures following a payment card data breach constituted a concrete injury sufficient for Article III standing.

**Holding:** The Seventh Circuit, in an opinion by Judge Evans, reversed the district court's dismissal and held that the plaintiffs had adequately pleaded Article III standing. The court found that the combination of (1) the actual theft of payment card data, (2) Neiman Marcus's delay in notifying customers, (3) the demonstrated use of stolen cards by fraudsters, and (4) the reasonable mitigation costs incurred by plaintiffs, collectively established a concrete injury. The court explicitly rejected the argument that standing should be limited to plaintiffs who experienced actual fraudulent charges, noting that "it would be very unfair to say that a person whose card was used fraudulently has standing to sue but a person whose card was stolen but not yet used fraudulently does not."

**Significance:** Pro-plaintiff standing in the Seventh Circuit. Remijas represented the most plaintiff-friendly circuit-level standing decision in the data breach context, establishing a relatively low threshold for standing based on the combination of data theft and mitigation costs — a standard that diverged significantly from the more restrictive approaches in other circuits.
Mitigation costs as standing anchor. The decision solidified the theory that reasonable costs incurred in response to a data breach — credit monitoring, card replacement, time spent — are concrete economic injuries that independently confer standing, even absent actual fraud.
Circuit split intensified. The divergence between Remijas and the Second Circuit's approach (later formalized in McMorris) intensified the circuit split on data breach standing, making Supreme Court resolution more likely — a prediction fulfilled by TransUnion.

---

### Case 6.22: Attias v. CareFirst, Inc., 865 F.3d 620 (D.C. Cir. 2017) — United States Court of Appeals for the District of Columbia Circuit
**Date Decided:** 2017

**Court:** United States Court of Appeals for the District of Columbia Circuit
Citation: 865 F.3d 620 (D.C. Cir. 2017)

**Facts:** CareFirst, a Blue Cross Blue Shield health insurance provider, disclosed in June 2015 that a data breach had compromised the personal information of approximately 1.1 million current and former members. Stolen data included names, dates of birth, email addresses, and subscriber identification numbers. Unlike the Anthem breach, no Social Security numbers or medical records were exposed. No evidence was presented that any of the stolen data had been used for identity theft or fraud. Plaintiffs — CareFirst members whose data was compromised — alleged negligence, breach of contract, and violations of the District of Columbia Consumer Protection Act.

**Issue:** Whether the exposure of non-financial, non-medical personal data (names, dates of birth, email addresses, insurance IDs) in the absence of demonstrated actual misuse conferred Article III standing.

**Holding:** The D.C. Circuit, in an opinion by Judge Katsas, reversed the district court's denial of CareFirst's motion to dismiss and held that the plaintiffs lacked Article III standing. The court held that the theft of the particular categories of data involved — which did not include Social Security numbers, medical records, or financial information — did not create a sufficiently concrete risk of identity theft to confer standing. The court distinguished Remijas, noting that payment card data (involved in Remijas) is more readily monetized by criminals and more directly linked to financial fraud than the types of data exposed in the CareFirst breach. The court also rejected the argument that CareFirst's alleged negligent security practices created standing.

**Significance:** Data-type taxonomy for standing. Attias established a data-type hierarchy for standing analysis, implicitly holding that not all personal data breaches are equal: financial credentials (credit cards) and government identifiers (Social Security numbers) present a substantially higher risk than names, dates of birth, and email addresses.
Counterpoint to Remijas. The decision directly contradicted the Seventh Circuit's more permissive approach in Remijas, deepening the circuit split and contributing to the Supreme Court's eventual intervention in TransUnion.

---

### Case 6.23: Galaria v. Nationwide Mutual Insurance Co., 663 F. App'x 384 (6th Cir. 2016) — United States Court of Appeals for the Sixth Circuit
**Date Decided:** 2016

**Court:** United States Court of Appeals for the Sixth Circuit
Citation: 663 F. App'x 384 (6th Cir. 2016)

**Facts:** Nationwide Mutual Insurance Company disclosed in 2012 that a data breach had compromised approximately 1.1 million current and former customers. Stolen data included names, Social Security numbers, dates of birth, and other personal identifying information. Plaintiffs — Nationwide policyholders whose data was stolen — alleged negligence and violations of Ohio state law. No evidence was presented that the stolen data had been used for identity theft or other fraudulent purposes.

**Issue:** Whether the theft of Social Security numbers and other identifying information, in the absence of actual misuse, conferred Article III standing under the post-Clapper framework.

**Holding:** The Sixth Circuit, per curiam, affirmed the district court's dismissal for lack of Article III standing. The court held that the plaintiffs' alleged injuries — the risk of future identity theft, the costs of credit monitoring, and the time spent monitoring their credit — were insufficiently concrete to confer standing. Applying Clapper's "certainly impending" standard, the court found that the plaintiffs had not shown that identity theft was impending or even substantially likely. The court explicitly held that voluntarily incurred costs (credit monitoring) do not constitute concrete injury, distinguishing Remijas.

**Significance:** Voluntary mitigation costs rejected. Galaria adopted the most restrictive position among the circuits on mitigation costs, holding that expenditures voluntarily incurred in response to a data breach — such as credit monitoring subscriptions — are not concrete injuries because they are self-inflicted rather than compelled.
Reinforced Clapper's applicability to data breaches. The decision firmly established Clapper's "certainly impending" standard as the governing framework in the Sixth Circuit for data breach standing, contributing to the circuit split that made TransUnion necessary.

---

### Case 6.24: Whalen v. Abbott Laboratories, No. 21-2480 (7th Cir. 2022) — United States Court of Appeals for the Seventh Circuit
**Date Decided:** 2022

**Court:** United States Court of Appeals for the Seventh Circuit
Citation: No. 21-2480 (7th Cir. 2022)

**Facts:** Abbott Laboratories disclosed in 2021 that a data breach had compromised the personal information of an unspecified number of customers and employees. The breach involved the exposure of names, contact information, and in some cases health-related data. Plaintiffs — Abbott customers whose data was exposed — alleged negligence and violations of Illinois consumer protection laws. No evidence was presented that the exposed data had been misused. The case was litigated in the aftermath of the Supreme Court's TransUnion decision.

**Issue:** Whether, after TransUnion, plaintiffs whose personal data was exposed in a data breach but not demonstrably misused had Article III standing based on the risk of future harm and the costs of mitigation.

**Holding:** The Seventh Circuit, in an opinion by Judge Scudder, affirmed the district court's dismissal for lack of Article III standing. Applying TransUnion's concrete injury framework, the court held that the mere exposure of personal data — without evidence of actual dissemination to third parties or subsequent misuse — was insufficient to confer standing. The court distinguished Remijas, its own earlier pro-plaintiff precedent, on the grounds that TransUnion had substantially raised the standing threshold. The court held that voluntarily incurred mitigation costs did not constitute concrete injury under TransUnion, effectively overruling Remijas within the Seventh Circuit to the extent it conflicted with the Supreme Court's holding.

**Significance:** Post-TransUnion recalibration of standing. Whalen represented the Seventh Circuit's formal recalibration of its standing doctrine in the wake of TransUnion, walking back the plaintiff-friendly approach of Remijas and aligning with the more restrictive approaches of the Second, Sixth, and D.C. Circuits.
Partial convergence of circuits. The decision narrowed — but did not eliminate — the circuit split on data breach standing, suggesting that TransUnion was achieving its apparent goal of establishing a relatively uniform, restrictive standing standard across the federal judiciary.
Section IV: International Data Breach Cases

---

### Case 6.25: WP29 Article 29 Working Party — British Airways Data Breach (GDPR Enforcement, 2019) — UK ICO
**Date Decided:** 2019

**Court:** UK Information Commissioner's Office (ICO)
Citation: ICO Enforcement Notice; Monetary Penalty Notice (MPN) reference: EA/2019023/1

**Facts:** British Airways disclosed in September 2018 that a sophisticated attack on its website and app had diverted customer traffic to a fraudulent site, compromising approximately 429,612 customers' personal data over a two-week period in 2018. Stolen data included names, addresses, email addresses, payment card numbers (with 3-digit CVV codes), and travel booking details. The breach was attributed to the Magecart group, a cybercriminal syndicate known for digital credit card skimming attacks. The UK Information Commissioner's Office (ICO) initially proposed a fine of 183.39 million under the GDPR — the largest GDPR fine proposed at that time — but reduced it to 20 million in October 2020, citing the economic impact of the COVID-19 pandemic on BA's business.

**Issue:** Whether the ICO's enforcement action against British Airways under the GDPR's data protection obligations (Articles 5, 32, and 33) was proportionate, and what level of penalty was appropriate under the GDPR's tiered fining framework.

**Holding:** The ICO issued a monetary penalty notice finding that British Airways failed to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Article 32), and that it failed to notify the ICO without undue delay (Article 33). The penalty was initially set at 183.39 million but was reduced to 20 million on October 16, 2020. The reduction reflected the ICO's consideration of BA's cooperation, the economic impact of COVID-19, and the need for proportionality under the GDPR's four-tier penalty framework.

**Significance:** First major GDPR enforcement for a data breach. The British Airways case was the first large-scale enforcement action under the GDPR for a data breach involving a major international corporation, establishing the ICO as an active enforcer and setting expectations for GDPR penalty levels.
COVID-19 as mitigating factor. The unprecedented reduction of the fine due to COVID-19 introduced an unpredictable variable into GDPR enforcement, raising questions about the consistency and predictability of regulatory penalties.

---

### Case 6.26: CNIL v. Google LLC (Google+ Data Breach, GDPR Enforcement, 2019) — CNIL
**Date Decided:** 2019

**Court:** Commission nationale de l'informatique et des libert s (CNIL), France
Citation: CNIL Deliberation No. 2019-121

**Facts:** Google disclosed in October 2018 that a software bug in the Google+ social network had exposed the private profile data of approximately 500,000 Google+ users between 2015 and 2018. The exposed data included names, email addresses, occupation, age, and other profile information. Google discovered the bug in March 2018 during its Project Strobe security review but chose not to disclose it publicly until the Wall Street Journal reported it in October 2018. Google subsequently announced the shutdown of Google+. The breach raised questions about whether Google had fulfilled its 72-hour breach notification obligation under GDPR Article 33.

**Issue:** Whether Google's failure to disclose the Google+ breach within 72 hours of discovering it — instead waiting approximately seven months — violated GDPR Article 33, and whether the delayed notification warranted enforcement action.

**Holding:** CNIL found that Google had failed to notify the relevant supervisory authority within the 72-hour timeframe required by GDPR Article 33(1). However, CNIL's enforcement response was relatively measured, reflecting the fact that Google argued the breach did not pose a "risk to the rights and freedoms of natural persons" — the threshold that triggers the mandatory notification requirement under Article 33(1). CNIL ultimately imposed a modest penalty and issued formal findings.

**Significance:** 72-hour notification requirement tested. The case tested the practical application of the GDPR's 72-hour breach notification timeline, highlighting the difficulty companies face in quickly assessing whether a breach meets the risk threshold for mandatory notification.
"Risk to rights and freedoms" threshold. Google's defense — that the breach did not pose sufficient risk to trigger mandatory notification — raised important questions about how companies should interpret and apply the risk assessment required by Article 33, a question that remains unresolved across EU jurisdictions.

---

### Case 6.27: C-300/21 UI v. sterreichische Post AG (2023) — Court of Justice of the European Union (CJEU)
**Date Decided:** 2023

**Court:** Court of Justice of the European Union (CJEU)
Citation: Case C-300/21

**Facts:** sterreichische Post AG, the Austrian postal service, collected and processed personal data of Austrian residents for marketing and profiling purposes, including political affiliation indicators derived from demographic data. Max Schrems' organization NOYB filed a complaint alleging that the company's data processing practices violated the GDPR. While not a traditional "breach," the case involved the unauthorized profiling and algorithmic classification of millions of individuals into political categories without their knowledge or consent. The data processing was disclosed through media reports, revealing that individuals were classified by political orientation based on proxy data.

**Issue:** Whether individuals whose personal data was used for profiling and political classification without their knowledge had a right to compensation under GDPR Article 82, even without demonstrating specific material or non-material damage.

**Holding:** The CJEU held that Article 82 of the GDPR must be interpreted as requiring the concept of "damage" to be understood broadly, consistent with the GDPR's objective of ensuring a high level of protection. The Court held that individuals do not need to prove specific material damage to claim compensation under Article 82 — the loss of control over personal data and the violation of data protection rights may, in themselves, constitute compensable non-material damage. However, the Court also held that the mere violation of the GDPR does not automatically entitle every affected person to compensation; there must be a causal link between the violation and the damage suffered.

**Significance:** Broad interpretation of GDPR damage. The CJEU's holding significantly expanded the scope of compensable damage under the GDPR, effectively lowering the threshold for data protection claims in EU member states compared to the concrete injury requirement under US Article III standing.
Contrast with US standing doctrine. The decision highlighted the fundamental divergence between EU and US approaches: the GDPR creates a broad, rights-based framework for data protection compensation, while the US requires concrete, particularized injury under Article III — a divergence that will increasingly affect multinational companies facing parallel litigation in both jurisdictions.

---

### Case 6.28: / China Didi Data Security Case (2021) — Cyberspace Administration of China (CAC)
**Date Decided:** 2021

**Court:** Cyberspace Administration of China ()
Citation: CAC Administrative Penalty Decision

**Facts:** Just days after its highly anticipated IPO on the New York Stock Exchange in June 2021, Chinese ride-hailing giant Didi Global was subjected to a cybersecurity review by the Cyberspace Administration of China (CAC). The CAC found that Didi had engaged in serious violations of China's data security and personal information protection laws, including the illegal collection and processing of massive volumes of personal data, the extraction of sensitive geographic location data from users, and the failure to implement adequate data security measures. The CAC ordered Didi's apps removed from Chinese app stores, banned new user registrations, and imposed a fine of 8.026 billion RMB (approximately $1.2 billion) in July 2022. The case was the most significant enforcement action under China's Data Security Law (DSL) and Personal Information Protection Law (PIPL) since their enactment.

**Issue:** Whether Didi's data collection and processing practices violated China's Data Security Law, Cybersecurity Law, and Personal Information Protection Law, and what level of penalty was appropriate.

**Holding:** The CAC found that Didi violated multiple provisions of the Cybersecurity Law, Data Security Law, and Personal Information Protection Law, including: illegal collection of personal information exceeding the scope of consent, failure to implement data security technical measures, processing of sensitive personal information without adequate safeguards, and failure to conduct required security assessments for cross-border data transfers. Didi was ordered to pay a fine of 8.026 billion RMB, rectify its data practices, and undergo mandatory security assessments. Didi's CEO Cheng Wei and President Liu Qing were personally fined 1 million RMB each.

**Significance:** Largest data protection fine in Chinese history. The 8.026 billion RMB fine was the largest penalty imposed under China's data protection framework, signaling the Chinese government's willingness to use aggressive enforcement to regulate the data practices of major technology companies.
Extraterritorial and capital market implications. The timing of the enforcement action — immediately after Didi's US IPO — was widely interpreted as a signal of China's determination to control the overseas listing of companies holding significant domestic data, and led to a broader regulatory crackdown on Chinese technology companies.
Personal liability for executives. The personal fines imposed on Didi's CEO and President established that individual executives can be held personally liable for corporate data protection failures under Chinese law, a principle consistent with emerging trends in Western jurisdictions.

---

### Case 6.29: Australian Information Commissioner v. Facebook Inc. (2020–2024) — Federal Court of Australia
**Date Decided:** 2020–2024

**Court:** Federal Court of Australia
Citation: VID 284/2020

**Facts:** The Australian Information Commissioner (OAIC) commenced proceedings against Facebook Inc. (now Meta Platforms) in March 2020, alleging serious and/or repeated interferences with the privacy of approximately 311,127 Australian users arising from the Cambridge Analytica data scandal. The OAIC alleged that Facebook disclosed Australian users' personal information to the This Is Your Digital Life (TIYDL) app, which was then shared with Cambridge Analytica and used for political profiling without users' knowledge or consent. The Australian users' data included names, email addresses, locations, dates of birth, gender, network connections, and page likes. The OAIC sought civil penalties, injunctions, and other orders.

**Issue:** Whether Facebook's disclosure of Australian users' personal data to third-party apps — through the platform's API — constituted a serious interference with privacy under the Australian Privacy Act 1988, and what level of civil penalty was appropriate.

**Holding:** The Federal Court found that Facebook had committed serious interferences with the privacy of Australian users by disclosing their personal information to the TIYDL app without adequate consent or notice. The court imposed significant civil penalties, though the amount was substantially less than the OAIC had sought. The decision established that social media platforms bear primary responsibility for the privacy protection of their users' data, including data shared through third-party applications operating on their platforms.

**Significance:** Platform responsibility for third-party apps. The decision established that social media platforms cannot escape responsibility for privacy violations committed by third-party applications that operate on their infrastructure, creating a principle of platform accountability analogous to the data controller concept under the GDPR.
Extraterritorial reach of Australian privacy law. The case demonstrated the willingness of Australian regulators to pursue major foreign technology companies for privacy violations affecting Australian residents, establishing Australia as a significant jurisdiction for cross-border data protection enforcement.

---

### Case 6.30: Livent Inc. v. Breard / Equifax Canada Data Breach — Office of the Privacy Commissioner of Canada (2020–2022) — OPC
**Date Decided:** 2020–2022

**Court:** Office of the Privacy Commissioner of Canada (OPC)
Citation: PIPEDA Case Summary #2022-001

**Facts:** Following the massive Equifax data breach in 2017 (which affected approximately 147 million individuals globally, including approximately 19,000 Canadians), the Office of the Privacy Commissioner of Canada conducted an investigation into Equifax Canada's data protection practices. The breach — caused by a known Apache Struts vulnerability for which a patch had been available for months — exposed the names, Social Insurance Numbers (SINs), dates of birth, addresses, and in some cases credit card numbers of Canadian consumers. The OPC investigation focused on whether Equifax Canada had implemented adequate security measures and complied with its obligations under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

**Issue:** Whether Equifax Canada's security practices met the "reasonable security" requirement under PIPEDA, and whether the company's breach notification was timely and adequate.

**Holding:** The OPC found that Equifax Canada had failed to implement adequate security measures, including failing to patch the known Apache Struts vulnerability in a timely manner, failing to adequately monitor its systems for unauthorized access, and failing to maintain an adequate breach response plan. The OPC recommended that Equifax Canada implement comprehensive security upgrades, improve its breach detection capabilities, and enhance its breach notification processes. While the OPC's recommendations are not legally binding, Equifax Canada accepted and implemented the recommended changes.

**Significance:** Canadian "reasonable security" standard. The investigation clarified that PIPEDA's requirement for security measures "appropriate to the sensitivity of the information" means that companies must actively maintain and update their security systems in response to known vulnerabilities — a patch management obligation that extends to Canadian subsidiaries of multinational corporations.
Patch management as a regulatory expectation. The finding that Equifax's failure to patch a known, critical vulnerability constituted a PIPEDA violation established patch management as a regulatory obligation, not merely a best practice, under Canadian privacy law.
Coordination with international regulators. The investigation was conducted in coordination with the US FTC and state attorneys general, demonstrating the increasing coordination among privacy regulators across jurisdictions in response to major cross-border data breaches.
Cases 6.1–6.4 address the foundational standing doctrine from TransUnion through lower court application. Cases 6.5–6.17 cover major data breach events and their litigation outcomes. Cases 6.18–6.24 trace the development of Article III standing doctrine from Clapper through post-TransUnion. Cases 6.25–6.30 address international data breach enforcement and litigation across the EU, China, Australia, and Canada.
Part Six —Data Breaches & Standing: Additional Cases (6.31—.60)

---

### Case 6.31: LinkedIn Data Breach —In re LinkedIn Data Breach Litigation (2021) —US District Court, N.D. California

**Date Decided:** 2021 (class action settlement approved)

**Court:** US District Court for the Northern District of California

**Facts:** In June 2021, a threat actor posted data from approximately 700 million LinkedIn users for sale on a dark web forum, including scraped email addresses, phone numbers, and geolocation records. LinkedIn maintained that the data had been aggregated through scraping rather than a direct compromise of its systems, but plaintiffs argued that LinkedIn's failure to implement access controls facilitated the mass harvesting.

**Issue:** Whether LinkedIn could be held liable for data scraped from public-facing profiles and whether affected users had standing to pursue claims for negligence and violation of California consumer protection statutes.

**Holding:** The parties reached a settlement in which LinkedIn agreed to enhanced data-scraping protections and to fund a claims process. The court granted preliminary approval of the class settlement. Standing was established on the basis that users had a reasonable expectation that their data would not be mass-harvested and sold on illicit markets.
**Significance:** Highlighted the legal ambiguity between "breach" and "scraping" —a distinction increasingly blurred by automated data-harvesting tools.
Established that platforms bear responsibility for implementing anti-scraping safeguards, not merely for defending against traditional intrusion attacks.
Reinforced California courts' willingness to find standing based on future injury risk from aggregated personal data exposure.

---

### Case 6.32: Adobe Data Breach —In re Adobe Systems, Inc. Data Breach Litigation (2013–2016) —US District Court, N.D. California

**Date Decided:** 2015 (settlement); 2016 (final approval)

**Court:** US District Court for the Northern District of California

**Facts:** In October 2013, Adobe suffered a massive breach exposing customer data for approximately 153 million user accounts, including encrypted passwords, payment card information, customer IDs, and source code for several products. The breach was attributed to coordinated SQL injection attacks. Plaintiffs filed a consolidated class action alleging negligence, breach of contract, and violations of state consumer protection laws.

**Issue:** Whether plaintiffs adequately alleged actual or imminent harm sufficient for Article III standing, given that Adobe maintained the stolen data was encrypted and that no confirmed fraudulent transactions resulted from the breach at the time of filing.

**Holding:** The court denied Adobe's motion to dismiss the standing claims, finding that the theft of encrypted password data and source code constituted a concrete injury and created a substantial risk of future identity theft. A settlement was reached in 2015 providing monetary payments, credit monitoring, and security improvements, with final approval in 2016.
**Significance:** Confirmed that theft of encrypted credentials alone suffices to establish standing where decryption risk is non-trivial.
Set early precedent for class action standing in data breach cases involving large-scale credential theft.
Demonstrated judicial willingness to hold companies accountable for inadequate SQL injection defenses and password storage practices.

---

### Case 6.33: eBay Data Breach —In re eBay Inc. Customer Data Security Breach Litigation (2014) —US District Court, N.D. Illinois / UK Information Commissioner's Office

**Date Decided:** 2015 (UK ICO enforcement); 2016–2017 (US litigation)

**Court:** US District Court for the Northern District of Illinois; UK Information Commissioner's Office

**Facts:** In May 2014, eBay disclosed that attackers had compromised its corporate network through compromised employee credentials, accessing a database containing names, encrypted passwords, email addresses, physical addresses, phone numbers, and dates of birth for approximately 145 million users. eBay urged users to change passwords but was criticized for delayed notification and for not requiring password resets at the time of discovery.

**Issue:** In the US: whether users suffered a cognizable injury where financial data was not exposed. In the UK: whether eBay violated the Data Protection Act 1998 by failing to implement adequate technical and organizational measures.

**Holding:** The UK ICO issued a formal undertaking requiring eBay to improve its security practices. In US litigation, the case survived early standing challenges and was settled for a modest amount, with the court finding that exposure of personal identifying information created a sufficient risk of future harm.
**Significance:** Demonstrated divergent regulatory approaches: the UK leveraged enforcement undertakings while US courts grappled with standing thresholds for non-financial data breaches.
Underscored the risk of credential-based attacks on corporate networks as an attack vector for customer data compromise.
Influenced subsequent industry practice toward mandatory password resets and multi-factor authentication following breach disclosure.

---

### Case 6.34: Uber Data Breach Cover-Up —FTC v. Uber Technologies, Inc. / United States v. Uber Technologies, Inc. (2016–2018) —FTC / US DOJ

**Date Decided:** August 2018 (DOJ Deferred Prosecution Agreement); November 2017 (FTC supplemental consent)

**Court:** US Federal Trade Commission; US Department of Justice, N.D. California

**Facts:** In late 2016, Uber suffered a breach exposing personal data of approximately 57 million riders and drivers worldwide, including names, email addresses, mobile phone numbers, and driver's license numbers for 600,000 US drivers. Uber's then-CSO, Joe Sullivan, orchestrated a cover-up: the company paid the hackers $100,000 through its "bug bounty" program, secured their silence through non-disclosure agreements, and failed to disclose the breach to regulators or affected individuals for over a year.

**Issue:** Whether Uber's concealment of the breach violated its 2014 FTC consent order (which required disclosure of future breaches) and whether the cover-up constituted criminal obstruction of justice under the Computer Fraud and Abuse Act (CFAA) and wire fraud statutes.

**Holding:** The DOJ secured a Deferred Prosecution Agreement under which Uber paid a $148 million fine and committed to compliance reforms. Sullivan was criminally charged with obstruction and misprision of a felony in 2022 (convicted 2024). The FTC supplemented its prior consent order with enhanced breach-notification and security requirements.
**Significance:** Established that concealing a data breach from regulators and consumers constitutes a distinct criminal offense beyond the breach itself.
Marked one of the first criminal prosecutions of an individual CISO for breach cover-up activities.
Set a clear precedent that "bug bounty" payments cannot be used as a pretext to silence attackers and conceal data theft.

---

### Case 6.35: Panera Bread Data Breach —In re Panera Bread Co. Data Breach Litigation (2018) —US District Court, N.D. Illinois / Illinois State Court

**Date Decided:** 2018–2020 (litigation and settlement)

**Court:** US District Court for the Northern District of Illinois; St. Clair County Circuit Court, Illinois

**Facts:** In April 2018, security researcher Brian Krebs disclosed that Panera Bread's website had exposed customer records —including names, email addresses, physical addresses, birth dates, and the last four digits of credit card numbers —for millions of customers through an unauthenticated API endpoint. Panera had been alerted to the vulnerability at least eight months earlier but failed to remediate it fully. The company initially downplayed the scope, claiming only 10,000 records were affected before revising the estimate upward.

**Issue:** Whether Panera's prolonged failure to fix a known API vulnerability constituted negligence and whether exposed customers could maintain claims under the Illinois Biometric Information Privacy Act (BIPA) and state consumer fraud statutes.

**Holding:** Multiple class actions were filed and consolidated. Panera reached settlements requiring improved data security practices and compensation to affected consumers. The case reinforced that companies cannot credibly claim they were unaware of vulnerabilities after receiving prior security reports.
**Significance:** Illustrates the "responsible disclosure gap" —the legal and reputational consequences of ignoring security researchers' warnings.
Contributed to Illinois' position as a leading forum for consumer data protection litigation, leveraging both BIPA and consumer fraud statutes.
Highlighted API security as a critical vulnerability category distinct from traditional network intrusion.

---

### Case 6.36: Exactis Data Breach —In re Exactis Data Breach Litigation (2018) —US District Court, M.D. Florida

**Date Decided:** 2018–2021 (litigation and settlement)

**Court:** US District Court for the Middle District of Florida

**Facts:** In June 2018, security researcher Vinny Troia discovered that Exactis, a Florida-based data brokerage and marketing firm, had left an unprotected database accessible to the public containing approximately 340 million individual records and 2 terabytes of personal, behavioral, and demographic data. The database included names, email addresses, physical addresses, phone numbers, and detailed consumer profiling data such as interests, habits, and religious affiliations. Exactis secured the database after public disclosure.

**Issue:** Whether consumers whose data was aggregated and exposed by a third-party data broker without their direct relationship to Exactis had standing to sue, and whether Exactis violated the Florida Deceptive and Unfair Trade Practices Act.

**Holding:** The court allowed standing claims to proceed, finding that the detailed nature of the exposed profiling data created a substantial risk of identity theft, stalking, and discrimination. Exactis reached a class action settlement providing notice, credit monitoring, and injunctive relief.
**Significance:** Extended data breach liability principles to the data brokerage industry, where individuals often have no direct relationship with the entity holding their data.
Demonstrated that aggregated profiling data can be as sensitive as financial or medical data for standing purposes.
Reinforced that unsecured databases (particularly ElasticSearch or MongoDB instances left publicly accessible) constitute negligent data handling.

---

### Case 6.37: First American Financial Data Exposure —In re First American Financial Corp. Data Exposure Litigation (2019) —NY Department of Financial Services / US District Court

**Date Decided:** 2019 (NY DFS consent order); 2020–2021 (federal litigation)

**Court:** New York Department of Financial Services; US District Court for the Southern District of New York

**Facts:** In May 2019, security researcher Ben Shoval discovered that First American Financial Corp., one of the largest title insurance companies in the United States, had exposed approximately 885 million records dating back to 2003 through a design flaw in its website. The vulnerability allowed anyone with a document URL to access sensitive title insurance records —including Social Security numbers, bank account numbers, wire transfer details, and mortgage statements —by simply incrementing a numeric identifier in the URL. No authentication was required.

**Issue:** Whether First American violated New York's cybersecurity regulation (23 NYCRR 500) and whether the exposure constituted a "data breach" triggering disclosure obligations, given that the company claimed there was no evidence of unauthorized access or misuse.

**Holding:** NY DFS issued a consent order requiring First American to pay a $1.1 million penalty, implement a comprehensive cybersecurity program, and engage an independent auditor. In federal litigation, plaintiffs established standing based on the exposure itself, and the case proceeded toward settlement.
**Significance:** One of the first major enforcement actions under New York's 23 NYCRR 500 cybersecurity regulation for a financial services firm.
Established that an insecure-by-design vulnerability (IDOR —Insecure Direct Object Reference) constitutes a regulatory violation even without evidence of actual exploitation.
Demonstrated that the total number of accessible records (885 million) amplifies both regulatory response and litigation exposure, regardless of actual download counts.

---

### Case 6.38: Facebook 540 Million User Data Leak (2021) —Irish Data Protection Commission / FTC

**Date Decided:** 2021–2023 (ongoing investigation); 2022 (FTC action)

**Court:** Irish Data Protection Commission; US Federal Trade Commission

**Facts:** In June 2021, security news outlet Business Insider reported that user data from approximately 533 million Facebook accounts in 106 countries had been publicly posted on a hacking forum in plaintext. The data included names, Facebook IDs, locations, birthdates, email addresses, and phone numbers. Facebook attributed the data to a vulnerability it had patched in 2019, involving a contact-syncing feature that allowed attackers to scrape user phone numbers in bulk. Facebook maintained that the data was "old" and that no current systems were compromised.

**Issue:** Whether Facebook's delayed patching of a known scraping vulnerability and failure to notify affected users violated GDPR's breach notification obligations (Art. 33-34) and the FTC's 2019 privacy consent order.

**Holding:** The Irish DPC opened a formal investigation into whether Facebook violated GDPR. The FTC alleged that Facebook's failure to adequately protect the scraped data and its misleading public statements about the breach violated the 2019 consent order. The matter contributed to the FTC's record-breaking $5 billion settlement enforcement and ongoing compliance monitoring.
**Significance:** Raised the critical question of when scraped data becomes a "breach" subject to mandatory notification under GDPR —a tension between technical causation and regulatory duty.
Highlighted Facebook's systemic pattern of minimizing breach severity in public communications, a factor in regulatory scrutiny.
Demonstrated the extraterritorial reach of GDPR through lead supervisory authority enforcement for global data leaks.

---

### Case 6.39: Log4j / Log4Shell Exploitation Cases (2021–2022) —Multiple Courts and Regulatory Bodies

**Date Decided:** 2021–2024 (ongoing litigation and enforcement)

**Court:** Multiple US District Courts; CISA (advisory); EU Agency for Cybersecurity (ENISA)

**Facts:** In December 2021, a critical vulnerability (CVE-2021-44228, dubbed "Log4Shell") was discovered in Apache Log4j, a ubiquitous open-source Java logging library embedded in thousands of enterprise applications worldwide. The vulnerability allowed unauthenticated remote code execution. Exploitation was detected across government agencies, cloud providers, financial institutions, and critical infrastructure within days of public disclosure. Multiple companies, including Apple, Cloudflare, and Twitter, reported active exploitation. Litigation followed against companies whose products remained vulnerable, including VMware, Cisco, and others.

**Issue:** Whether software vendors who embedded Log4j in their products could be held liable for failing to patch promptly, and whether downstream customers had standing to sue for the increased security risk and remediation costs.

**Holding:** Courts are still adjudicating. Early rulings have been mixed: some courts have found standing based on concrete remediation expenses and data security risks, while others have dismissed claims where plaintiffs could not demonstrate actual exploitation. Regulatory agencies issued emergency directives. Some defendants argued that Log4j was open-source software distributed without warranty and that the vulnerability was a community-wide issue rather than a vendor-specific defect.
**Significance:** Represents the most consequential open-source software supply-chain vulnerability to date, raising fundamental questions about liability allocation in open-source ecosystems.
Catalyzed the passage of the US Cyber Incident Reporting for Critical Infrastructure Act (2022) and the EU Cyber Resilience Act (proposed).
Created new legal theories of liability for "downstream risk" —holding vendors responsible for open-source components embedded in their commercial products.

---

### Case 6.40: MOVEit Mass Exploitation (2023) —Multiple Jurisdictions

**Date Decided:** 2023–2024 (ongoing litigation, regulatory actions, and settlements)

**Court:** Multiple US District Courts (MDL consolidated); UK ICO; Canadian OPC; Singapore PDPC

**Facts:** In May'une 2023, the Clop ransomware group exploited a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer file-transfer platform. The attack cascaded through hundreds of organizations worldwide that used MOVEit or services built on it, exposing data from tens of millions of individuals across government agencies (US DOE, UK BBC, Irish government), financial institutions (Shell, Ernst & Young), healthcare organizations, airlines, and universities. It became the largest mass exploitation event of 2023 by affected entity count.

**Issue:** Whether Progress Software could be held liable for shipping vulnerable software, whether downstream organizations using MOVEit had adequate standing to sue, and how breach notification obligations should be allocated among software vendors, managed service providers, and end-user organizations.

**Holding:** The US Judicial Panel on Multidistrict Litigation consolidated cases into an MDL in the District of Massachusetts. Progress Software faced numerous lawsuits and regulatory scrutiny. The UK ICO issued enforcement notices to affected organizations. Several downstream companies settled with affected individuals. Progress implemented patches and offered monitoring services.
**Significance:** Exemplified the "blast radius" problem in supply-chain attacks: a single vulnerability in one product can trigger breaches at thousands of downstream organizations simultaneously.
Raised unprecedented questions about apportionment of liability in cascading data breach scenarios involving software vendors, service providers, and end users.
Accelerated regulatory focus on Software Bill of Materials (SBOM) requirements and vendor risk management obligations under the EU NIS2 Directive.

---

### Case 6.41: Clapper v. Amnesty International USA (2013) —US Supreme Court

**Date Decided:** February 26, 2013

**Court:** US Supreme Court

**Facts:** Attorneys and journalists (including Amnesty International USA) challenged the constitutionality of the Foreign Intelligence Surveillance Act (FISA) Amendments Act of 2008, which authorized warrantless surveillance of non-US persons abroad. Plaintiffs alleged that their international communications were likely intercepted under the statute, requiring them to incur costs to travel abroad to meet sources in person rather than communicate electronically.

**Issue:** Whether plaintiffs had Article III standing based on a chain of speculative inferences: that (1) the US government would surveil their foreign communications, (2) under the authority of the FISA Amendments Act, and (3) that such surveillance would cause them concrete harm.

**Holding:** The Supreme Court held 5-4 that plaintiffs lacked standing. The Court found that the alleged injury was too speculative and conjectural —plaintiffs could not demonstrate that their communications had been or would be intercepted. The chain of causation required too many "independent assumptions" to establish a concrete and particularized injury.
**Significance:** Set the modern benchmark for Article III standing in privacy and surveillance cases: plaintiffs must demonstrate a "certainly impending" or "substantial risk" of future injury, not merely speculative fear.
Has been cited extensively in data breach standing cases, with defendants arguing that risk of future identity theft from exposed data is similarly speculative.
The decision created significant tension with the European approach, where future risk alone is often sufficient to establish regulatory standing under GDPR.

---

### Case 6.42: Bartnicki v. Vopper (2001) —US Supreme Court

**Date Decided:** May 21, 2001

**Court:** US Supreme Court

**Facts:** An unidentified person intercepted and recorded a cellular phone conversation between a union president and a union negotiator during contentious labor negotiations. The recording, which contained discussion of illegal conduct, was anonymously mailed to a radio host (Fred Vopper), who played portions on air. The participants sued the radio host and others for disclosing the intercepted communication, alleging violations of federal and state wiretapping statutes.

**Issue:** Whether a third party who did not participate in the illegal interception of a communication could be held liable for publishing or disclosing the contents of that communication under the Wiretap Act and the First Amendment.

**Holding:** The Supreme Court held 6-3 that the radio host could not be held liable. The Court found that where the information was lawfully obtained by the publisher (i.e., the publisher did not participate in the illegal interception itself), imposing liability for subsequent publication violated the First Amendment. The Court noted the "important interest in the flow of information" and the practical difficulty of distinguishing between media and non-media publishers.
**Significance:** Established a critical First Amendment shield for the publication of lawfully obtained private information, even when the source obtained it illegally.
Has been cited in data breach and information disclosure cases to delineate the boundary between the act of stealing data and the act of publishing it.
The decision's reasoning has been tested by the digital era's data leak ecosystem (e.g., WikiLeaks, data brokers), where the line between "interceptor" and "publisher" is increasingly blurred.

---

### Case 6.43: Remijas v. Neiman Marcus Group, LLC (7th Cir. 2015) —US Court of Appeals, Seventh Circuit

**Date Decided:** July 20, 2015

**Court:** US Court of Appeals for the Seventh Circuit

**Facts:** In January 2014, Neiman Marcus disclosed a data breach affecting approximately 350,000 customer payment cards through malware installed on its point-of-sale systems. Of those, approximately 9,200 cards were used fraudulently. Plaintiffs who did not suffer fraudulent charges but whose payment card data was stolen filed a class action alleging negligence and violation of consumer protection laws.

**Issue:** Whether plaintiffs whose stolen payment card data had not yet been used fraudulently had Article III standing based on the increased risk of future fraud and the costs incurred to mitigate that risk.

**Holding:** The Seventh Circuit, per Judge Evans, held that plaintiffs had standing. The court found that the risk of future fraudulent charges was "substantial" rather than "speculative," and that the mitigation costs (purchasing credit monitoring, replacing cards, spending time monitoring accounts) constituted concrete injury. The court emphasized that the injury-in-fact requirement should not be interpreted to "foreclose the type of suits that Congress has authorized."
**Significance:** Established the Seventh Circuit as the most plaintiff-friendly circuit for data breach standing, rejecting the stricter approach of other circuits.
Created a framework for standing based on "substantial risk" of future harm plus mitigation costs —an approach later adopted in varying degrees by other circuits.
The decision contrasted sharply with Clapper, illustrating the circuit split that persisted until the Supreme Court's TransUnion decision (2021).

---

### Case 6.44: Attias v. Carefirst, Inc. (4th Cir. 2016) —US Court of Appeals, Fourth Circuit

**Date Decided:** September 9, 2016

**Court:** US Court of Appeals for the Fourth Circuit

**Facts:** In 2014, Carefirst (a Blue Cross Blue Shield licensee) disclosed that hackers had gained unauthorized access to a database containing personal information of approximately 1.1 million individuals, including names, birth dates, email addresses, and Social Security numbers. Plaintiffs whose data was exposed but who suffered no confirmed identity theft filed a class action alleging negligence, breach of contract, and violations of various state laws.

**Issue:** Whether the exposure of Social Security numbers and other identifying information, without evidence of actual misuse, sufficed to establish Article III standing.

**Holding:** The Fourth Circuit reversed the district court's dismissal, holding that plaintiffs had adequately pleaded standing. The court found that the theft of SSNs in particular —immutable identifiers that cannot be changed —created a substantial risk of future identity theft sufficient for standing. The court also accepted mitigation costs as concrete injuries.
**Significance:** Emphasized the unique sensitivity of Social Security numbers as immutable identifiers, distinguishing them from other types of exposed data for standing analysis.
Aligned the Fourth Circuit with the Seventh Circuit's relatively permissive approach to data breach standing.
Contributed to the circuit split on standing that made Supreme Court review inevitable.

---

### Case 6.45: Galaria v. Nationwide Mutual Insurance Co. (6th Cir. 2016) —US Court of Appeals, Sixth Circuit

**Date Decided:** August 29, 2016

**Court:** US Court of Appeals for the Sixth Circuit

**Facts:** In 2012, Nationwide disclosed a breach of its computer systems that exposed the personal information of approximately 1.27 million individuals, including names, Social Security numbers, dates of birth, and driver's license numbers. Plaintiffs whose information was exposed but who did not suffer identity theft sued Nationwide for negligence and violations of Ohio consumer protection laws.

**Issue:** Whether the exposure of personal identifying information without evidence of actual misuse conferred Article III standing, particularly where the stolen data included SSNs and other high-sensitivity identifiers.

**Holding:** The Sixth Circuit held that plaintiffs had standing. The court reasoned that the theft of SSNs and driver's license numbers —both immutable identifiers —created a "substantial risk" of future identity theft. The court also held that the time and money spent on protective measures constituted actual injuries. The court declined to follow the Third Circuit's stricter approach in Reilly v. Ceridian Corp. (requiring evidence of actual misuse).
**Significance:** Further deepened the circuit split on data breach standing by rejecting the Third Circuit's actual-misuse requirement.
Identified a two-factor test: (1) the sensitivity of the stolen data (immutable identifiers) and (2) mitigation costs as concrete injury.
The decision was widely cited in subsequent data breach litigation as an example of the permissive standing approach that preceded TransUnion.

---

### Case 6.46: Whalen v. Abbott Laboratories, Inc. (7th Cir. 2017) —US Court of Appeals, Seventh Circuit

**Date Decided:** September 5, 2017

**Court:** US Court of Appeals for the Seventh Circuit

**Facts:** In 2014, Abbott Laboratories notified employees that a vendor handling employee benefits data may have been compromised, potentially exposing Social Security numbers, financial account numbers, and other personal information. Affected employees sued Abbott for negligence, even though no actual misuse of their data was confirmed. The district court dismissed for lack of standing.

**Issue:** Whether the mere exposure of personal data through a vendor breach, without evidence of actual or imminent misuse, established Article III standing under the standard articulated in Remijas v. Neiman Marcus.

**Holding:** The Seventh Circuit, per Judge Sykes, reversed the dismissal and found standing. The court distinguished this case from Clapper because the data theft had already occurred (unlike the speculative future surveillance in Clapper). The court accepted that the combination of exposed SSNs and the plaintiffs' inability to control the future use of their data created a "substantial risk of future harm" sufficient for standing. Concurring, Judge Rovner argued the majority too easily assumed standing from speculative future harm.
**Significance:** Extended Remijas principles to the employment and vendor-management context, confirming that companies are responsible for vendor data handling failures.
Clarified the critical distinction between past injury (data theft already occurred) and future harm (speculative misuse) —the former anchors standing, the latter supplies the ongoing injury.
The concurrence's skepticism foreshadowed the Supreme Court's more restrictive approach in TransUnion LLC v. Ramirez (2021).

---

### Case 6.47: In re Capital One Consumer Data Security Breach Litigation (2020–2022) —US District Court, E.D. Virginia (MDL)

**Date Decided:** 2021–2023 (MDL proceedings and settlement)

**Court:** US District Court for the Eastern District of Virginia (MDL No. 2985)

**Facts:** In July 2019, Capital One disclosed that a former Amazon Web Services employee, Paige Thompson, had exploited a misconfigured web application firewall to access the personal data of approximately 106 million Capital One customers, including names, addresses, dates of birth, credit scores, Social Security numbers, and bank account numbers. Thompson was arrested and charged under the CFAA. Multiple class actions were consolidated into an MDL in the Eastern District of Virginia.

**Issue:** Whether affected customers whose data was exposed in the Capital One breach had standing for negligence, breach of contract, and statutory claims, and whether Capital One's reliance on AWS security constituted an adequate defense.

**Holding:** The court denied Capital One's motion to dismiss, finding standing based on the concrete exposure of highly sensitive financial data. Capital One reached a proposed $190 million settlement in 2022, which included direct payments to affected individuals and credit monitoring services. Thompson was convicted and sentenced to time served and home confinement in 2022.
**Significance:** Highlighted the shared responsibility model in cloud computing: Capital One was held liable despite the breach originating from an AWS-side configuration vulnerability exploited by a former AWS employee.
One of the largest financial data breach settlements, reflecting the scale of financial data exposure.
Accelerated regulatory and industry focus on cloud security configurations and shared responsibility frameworks.

---

### Case 6.48: In re T-Mobile US, Inc. Data Breach Litigation (2022) —US District Court, W.D. Missouri (MDL)

**Date Decided:** 2022–2024 (MDL proceedings and settlement)

**Court:** US District Court for the Western District of Missouri (MDL No. 3016)

**Facts:** In August 2021, T-Mobile disclosed that attackers had breached its systems and accessed personal data of approximately 76.6 million current and former customers, including names, dates of birth, Social Security numbers, driver's license numbers, and IMEI numbers. The breach was attributed to John Binns, who claimed to have exploited a misconfigured GPRS gateway. T-Mobile acknowledged it was at least the fifth major data breach the company had suffered in recent years. Multiple class actions were consolidated into an MDL.

**Issue:** Whether T-Mobile's repeated data breaches demonstrated a pattern of negligent security practices and whether affected customers had standing for statutory and common-law claims.

**Holding:** The court denied T-Mobile's motion to dismiss the negligence claims. T-Mobile reached a preliminary $350 million settlement in 2022 (later approved at $350 million in cash plus $150 million in security improvements), one of the largest data breach settlements to date. The settlement included direct payments, credit monitoring, and commitments to invest $150 million in cybersecurity improvements over two years.
**Significance:** The $350 million settlement (plus $150 million security commitment) set a new benchmark for data breach class action valuations.
T-Mobile's history of repeated breaches was treated as evidence of systemic negligence, signaling that courts may consider breach history as a factor in liability.
The case demonstrated growing judicial skepticism toward companies that treat data breaches as isolated incidents rather than symptoms of inadequate security culture.

---

### Case 6.49: EU Breach Notification Cases under GDPR Articles 33—4 (2018–2024) —Various DPAs and CJEU

**Date Decided:** 2018–2024 (ongoing)

**Court:** Various EU Data Protection Authorities; Court of Justice of the European Union

**Facts:** Since the GDPR's enforcement date (May 25, 2018), DPAs across the EU have processed thousands of breach notification cases under Articles 33 (notification to supervisory authority within 72 hours) and 34 (communication to data subjects when risk is high). Notable cases include: the Irish DPC's investigation into Facebook's 530M record leak; the French CNIL's action against Google for delayed breach notification; the UK ICO's enforcement against British Airways (20 million fine for delayed notification); and the Dutch DPA's actions against various organizations for systematic failure to report breaches in time.

**Issue:** When is a "personal data breach" triggered under GDPR? What constitutes "high risk" sufficient to require data subject notification under Article 34? When does the 72-hour clock begin (from discovery or from confirmation)?

**Holding:** DPAs have generally held that the 72-hour clock begins when an organization becomes "aware" of the breach —a low threshold. Multiple enforcement actions have resulted in fines for delayed notification, including the British Airways case and Google France. The CNIL clarified that even unsuccessful attacks must be reported if personal data was potentially accessed. Several DPAs have emphasized that the "high risk" assessment under Article 34 must be conducted on a case-by-case basis.
**Significance:** Established the 72-hour breach notification as a global standard, influencing legislation worldwide (including India's DPDP Act 2023 and various US state laws).
Created a body of interpretive guidance on the scope of "awareness" and "high risk" that continues to evolve through DPA decisions.
Demonstrated that GDPR enforcement is uneven across member states, with the Irish DPC criticized for delayed enforcement against large US technology companies.

---

### Case 6.50: China Didi Global Data Breach Penalty (2022) —Cyberspace Administration of China (CAC)

**Date Decided:** July 21, 2022

**Court:** Cyberspace Administration of China (CAC); Ministry of Public Security; Other regulatory authorities

**Facts:** In July 2022, the CAC announced an administrative penalty of RMB 8.026 billion (approximately US $1.2 billion) against Didi Global, China's largest ride-hailing platform, for violations of the Cybersecurity Law, Data Security Law, and Personal Information Protection Law (PIPL). While the primary violations related to unlawful collection and processing of personal data without user consent, the investigation also uncovered security deficiencies that resulted in data exposure. Didi was found to have collected excessive personal data, failed to implement adequate security measures, and disclosed personal information without proper consent. The CAC ordered Didi's app removed from app stores (which had occurred a year earlier) and imposed structural corrective measures.

**Issue:** Whether Didi's data collection and security practices violated China's comprehensive data protection framework (PIPL, DSL, CSL) and what penalty was proportionate for systematic violations affecting over 500 million users.

**Holding:** The CAC imposed a record fine of RMB 8.026 billion (approximately 4.6% of Didi's 2021 domestic revenue), ordered remediation of all identified security deficiencies, required deletion of illegally collected data, and mandated a comprehensive security overhaul. Didi's CEO and president were each fined RMB 1 million.
**Significance:** The largest data protection penalty in history at the time, dwarfing even the EU's GDPR fines against Meta.
Demonstrated China's willingness to use data protection enforcement as part of broader technology regulation and market control.
Established the PIPL as a major global enforcement mechanism, with penalties potentially exceeding GDPR levels due to China's revenue-based calculation methodology.

---

### Case 6.51: China JD.com Data Breach (2023) —Cyberspace Administration of China / Shanghai Pudong Market Regulation Bureau

**Date Decided:** 2023

**Court:** Cyberspace Administration of China; Shanghai Pudong New Area Market Supervision and Administration Bureau

**Facts:** In 2023, JD.com, one of China's largest e-commerce platforms, disclosed a data security incident involving unauthorized access to customer data through a compromised supply-chain partner. The breach exposed customer names, phone numbers, delivery addresses, and order information for an undisclosed number of users. Chinese regulators launched an investigation under the Data Security Law and PIPL. JD.com faced criticism for delayed disclosure and inadequate security measures on its third-party vendor ecosystem.

**Issue:** Whether JD.com fulfilled its breach notification obligations under Chinese law and whether its vendor management practices constituted adequate security measures under the Data Security Law.

**Holding:** JD.com was ordered to implement enhanced security measures, conduct a comprehensive security audit of its vendor ecosystem, and improve its breach notification procedures. The Shanghai regulator imposed administrative penalties for inadequate data security governance. JD.com committed to strengthening its data classification system and vendor security requirements.
**Significance:** Exemplified China's enforcement of supply-chain security obligations under the Data Security Law, focusing on vendor risk management.
Demonstrated that China's data protection authorities are extending their oversight beyond the primary data controller to encompass the entire data supply chain.
Contributed to the development of China's regulatory framework for data breach response, which is still maturing relative to GDPR and US state laws.

---

### Case 6.52: India Airtel Data Breach (2023) —Indian Computer Emergency Response Team (CERT-In) / Telecom Regulatory Authority of India (TRAI)

**Date Decided:** 2023

**Court:** Indian Computer Emergency Response Team (CERT-In); Telecom Regulatory Authority of India (TRAI); Parliamentary Standing Committee on Communications and Information Technology

**Facts:** In 2023, reports emerged of a major data breach affecting Airtel, India's second-largest telecommunications provider, allegedly exposing the personal data of approximately 375 million customers, including names, phone numbers, Aadhaar numbers (India's national biometric ID), and address information. Airtel denied that its systems were breached, attributing the data to third-party aggregators. CERT-In initiated an investigation. The incident sparked a parliamentary inquiry and renewed calls for stronger data breach notification requirements.

**Issue:** Whether Airtel adequately protected customer data under the Information Technology Act 2000 and the forthcoming Digital Personal Data Protection Act (DPDPA) 2023, and whether the breach disclosure obligations were met.

**Holding:** The investigation was ongoing as of the DPDPA's enactment in August 2023. Airtel maintained that no breach of its core systems occurred. The parliamentary committee recommended strengthening CERT-In's breach reporting mandates and called for stricter penalties under the new DPDPA framework.
**Significance:** Highlighted the vulnerability of India's telecommunications sector, where Aadhaar-linked data creates particularly sensitive breach implications.
Occurred during the passage of India's DPDPA 2023, influencing the legislation's breach notification provisions (72-hour reporting requirement, modeled on GDPR).
Underscored the attribution challenge in data breach cases: distinguishing between a direct system compromise and aggregation from third-party sources.

---

### Case 6.53: Singapore SingHealth Breach Criminal Prosecution (2020) —State Courts of Singapore

**Date Decided:** June 2020 (sentencing)

**Court:** State Courts of Singapore; Singapore Personal Data Protection Commission (PDPC)

**Facts:** In June'uly 2018, attackers linked to Chinese state-sponsored actors breached Singapore's SingHealth, the country's largest public healthcare group, stealing personal and medical data of approximately 1.5 million patients, including Prime Minister Lee Hsien Loong's outpatient prescription records. The attackers specifically targeted the PM's records. Investigations revealed that the breach began with a phishing email to a SingHealth IT staff member and progressed through lateral movement to the patient database. The PDPC fined SingHealth SGD 250,000 and Integrated Health Information Systems (IHiS) SGD 250,000 for failing to implement adequate security measures.

**Issue:** Whether individual IT staff could be held criminally liable for negligence contributing to a data breach under Singapore's Computer Misuse Act, and whether the targeted breach of a head of state's medical records warranted enhanced penalties.

**Holding:** Three IHiS employees were charged under the Computer Misuse Act and other statutes. In June 2020, a former IHiS manager was sentenced to jail for failing to implement security patches and for covering up security alerts. SingHealth and IHiS were fined by the PDPC and required to implement comprehensive security remediation measures.
**Significance:** One of the rare instances globally of individual criminal prosecution of IT staff for data breach negligence.
Demonstrated Singapore's willingness to hold individuals accountable for security failures, not just organizations.
The targeting of a head of state's medical records highlighted healthcare data as a high-value target for state-sponsored espionage and raised questions about the adequacy of cybersecurity measures in critical infrastructure.

---

### Case 6.54: Australia Medibank Penalty (2023) —Federal Court of Australia

**Date Decided:** June 2024 (penalty)

**Court:** Federal Court of Australia

**Facts:** In October 2022, Medibank, Australia's largest health insurer, disclosed a major cyberattack in which the Russian-linked ransomware group "REvil" (also known as " ALPHV/BlackCat") exfiltrated the personal and health data of approximately 9.7 million current and former customers. The attackers published sensitive health data on the dark web, including records related to mental health treatment, substance abuse, pregnancy termination, and other highly sensitive medical procedures. Medibank initially refused to pay the ransom. The Australian Information Commissioner (OAIC) brought proceedings under the Privacy Act 1988.

**Issue:** Whether Medibank failed to take reasonable steps to protect personal information under the Australian Privacy Act and whether the systemic nature of the security failures warranted the maximum penalty.

**Holding:** The Federal Court found that Medibank had failed to implement adequate security measures, including multi-factor authentication and proper segmentation of its customer database. The court imposed a record civil penalty of AUD 50 million under the Privacy Act. Medibank was also ordered to fund a community benefit payment scheme and to implement comprehensive security improvements.
**Significance:** The largest privacy penalty in Australian history, reflecting the severity of health data exposure and the deliberate, malicious publication of sensitive medical information.
Established that the publication of stolen health data (beyond mere exfiltration) is an aggravating factor in penalty assessment.
Demonstrated the evolving use of ransomware-as-a-service by state-linked actors and the inadequacy of traditional security controls against sophisticated threat actors.

---

### Case 6.55: UK EasyJet Data Breach —Information Commissioner's Office (2021)

**Date Decided:** October 2020 (ICO notice); March 2021 (Fine)

**Court:** UK Information Commissioner's Office

**Facts:** In April 2020, EasyJet disclosed that it had suffered a sophisticated cyberattack between October 2019 and March 2020, compromising the personal data of approximately 9 million customers, including full names, email addresses, travel details, and —critically —the credit card details of approximately 2,208 customers. The breach was attributed to a highly sophisticated attack exploiting vulnerabilities in EasyJet's systems. EasyJet was criticized for the timing of its disclosure, which coincided with the early days of the COVID-19 pandemic.

**Issue:** Whether EasyJet failed to implement appropriate technical and organizational measures under GDPR and the UK Data Protection Act 2018, and whether the airline's delayed notification to affected customers violated Article 34.

**Holding:** The ICO issued EasyJet a fine of 1.1 million (reduced from the theoretical maximum due to EasyJet's cooperation and the pandemic's impact on the airline industry). The ICO found that EasyJet had failed to implement adequate security measures, particularly around the protection of payment card data. EasyJet also faced class action claims in the UK and regulatory scrutiny in multiple jurisdictions.
**Significance:** One of the first major GDPR enforcement actions in the UK following Brexit's transition period, demonstrating the ICO's continued willingness to impose significant penalties.
Illustrated the challenges of breach disclosure timing during external crises —EasyJet's disclosure during the pandemic was criticized as an attempt to minimize attention.
Contributed to heightened scrutiny of the aviation industry's data security practices, with other airlines subsequently facing similar regulatory attention.

---

### Case 6.56: Canada Desjardins Credit Union Breach (2020) —Office of the Privacy Commissioner of Canada / Quebec Commission d'accès  l'information du Québec

**Date Decided:** 2020–2022 (investigation and findings)

**Court:** Office of the Privacy Commissioner of Canada; Commission d'accès  l'information du Québec (CAI); Autorité des marchés financiers (AMF)

**Facts:** In June 2019, Desjardins, Canada's largest federation of credit unions with approximately 7 million members, disclosed a massive data breach caused by a malicious insider —a long-term employee named Sébastien Boulanger-Dorval who had been unlawfully collecting and selling member data since 2018. The breach exposed the personal and financial data of approximately 4.2 million members, including names, addresses, dates of birth, Social Insurance Numbers, banking habits, and credit scores. The insider was arrested and charged. The OPC and Quebec's CAI conducted a joint investigation.

**Issue:** Whether Desjardins implemented adequate internal access controls and monitoring to detect and prevent insider threats, and whether the organization fulfilled its breach notification obligations under PIPEDA and Quebec's Act Respecting the Protection of Personal Information in the Private Sector.

**Holding:** The OPC and CAI found that Desjardins had failed to implement adequate measures to detect the unauthorized data access, particularly given the prolonged duration of the insider's activities. Desjardins was required to implement comprehensive remediation measures, including enhanced monitoring, access controls, and data governance practices. The AMF imposed an administrative penalty. Desjardins established a CAD $200 million compensation fund for affected members.
**Significance:** The largest insider-threat data breach in Canadian history, highlighting the inadequacy of perimeter-based security against privileged insiders.
Demonstrated the coordination between federal and provincial privacy regulators in major breach investigations under Canada's overlapping jurisdictional framework.
The $200 million compensation fund set a benchmark for breach remediation costs in Canada and influenced subsequent Canadian class action settlements.

---

### Case 6.57: Germany AWD Data Breach (2021) —Federal Commissioner for Data Protection (BfDI) / Berlin DPA

**Date Decided:** 2021

**Court:** Federal Commissioner for Data Protection and Freedom of Information (BfDI); Berlin Commissioner for Data Protection and Freedom of Information

**Facts:** In 2021, the German data protection authorities investigated AWD, a financial advisory firm, for failing to adequately protect customer data that was exposed in a breach affecting approximately 800,000 clients. The investigation revealed that AWD had stored customer personal and financial data on inadequately secured systems, failed to implement encryption, and did not conduct required risk assessments. The breach was compounded by AWD's failure to notify affected data subjects in a timely manner.

**Issue:** Whether AWD violated GDPR's security obligations (Article 32), breach notification requirements (Article 33), and data subject communication obligations (Article 34).

**Holding:** The BfDI and Berlin DPA found multiple GDPR violations and issued a fine. AWD was ordered to implement comprehensive technical and organizational security measures, conduct a data protection impact assessment, and establish a proper breach notification process.
**Significance:** Demonstrated German DPAs' proactive enforcement approach under GDPR, targeting systemic security failures rather than one-time incidents.
Reinforced that GDPR's security requirements apply to all organizations processing personal data, regardless of size or sector.
Contributed to the development of German regulatory guidance on security measures and breach notification best practices.

---

### Case 6.58: France CNIL Data Breach Actions (2022) —Commission Nationale de l'Informatique et des Libertés (CNIL)

**Date Decided:** 2022

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL)

**Facts:** In 2022, the CNIL undertook multiple enforcement actions related to data breaches affecting French organizations. Notable cases included actions against entities in the healthcare and public sectors for failing to notify breaches within the 72-hour deadline, for inadequate security measures, and for failing to communicate risks to affected data subjects. In one significant case, a healthcare data processor was found to have exposed patient records for months before detecting the breach. The CNIL also issued formal warnings to organizations that had treated their 72-hour notification obligations as optional.

**Issue:** Whether the affected organizations met GDPR's technical and organizational security requirements and timely notification obligations under Articles 32—4.

**Holding:** The CNIL issued fines and formal notices requiring organizations to improve security measures, implement encryption, establish breach detection procedures, and ensure timely notification. Several organizations received formal warnings with compliance deadlines.
**Significance:** Reinforced the CNIL's role as one of the most active GDPR supervisory authorities, with particular focus on the healthcare sector.
Demonstrated that French regulators treat the 72-hour notification deadline as mandatory and non-negotiable.
Contributed to the CNIL's developing enforcement framework, which has increasingly focused on systematic security failures rather than individual breach incidents.

---

### Case 6.59: Spain Vueling Data Breach (2021) —Agencia Espaola de Proteccin de Datos (AEPD)

**Date Decided:** 2021

**Court:** Agencia Espaola de Proteccin de Datos (AEPD)

**Facts:** In 2021, the AEPD investigated Vueling Airlines, a Spanish low-cost carrier subsidiary of International Airlines Group, following a data breach that exposed the personal data of customers through a vulnerability in its website and mobile application. The breach potentially exposed names, email addresses, frequent flyer numbers, and booking details. The AEPD found that Vueling had not implemented adequate security measures and had delayed breach notification.

**Issue:** Whether Vueling violated GDPR security requirements and failed to meet the 72-hour breach notification deadline.

**Holding:** The AEPD imposed a fine on Vueling for GDPR violations related to inadequate security measures and delayed breach notification. Vueling was ordered to implement corrective measures, including security assessments, improved access controls, and enhanced breach detection capabilities.
**Significance:** Part of a broader pattern of GDPR enforcement actions against airlines in Europe, reflecting the sector's high volume of personal data processing and vulnerability to cyberattacks.
Demonstrated that even subsidiary companies of large international groups are subject to independent DPA enforcement.
Contributed to the AEPD's enforcement record, which has been among the most active in Europe for breach notification cases.

---

### Case 6.60: Italy Poste Italiane Data Breach (2022) —Garante per la Protezione dei Dati Personali

**Date Decided:** 2022

**Court:** Garante per la Protezione dei Dati Personali (Italian Data Protection Authority)

**Facts:** In 2022, the Italian Garante investigated Poste Italiane, Italy's largest postal and financial services provider, following reports of unauthorized access to customer data through vulnerabilities in its online platforms. The breach potentially exposed the personal data of millions of customers, including names, addresses, fiscal codes (Italy's national identification number equivalent), and in some cases financial information. The Garante opened a formal investigation into Poste Italiane's security practices and breach notification compliance.

**Issue:** Whether Poste Italiane implemented adequate technical and organizational security measures under GDPR and whether it fulfilled its breach notification obligations.

**Holding:** The Garante found deficiencies in Poste Italiane's security practices and breach response procedures. The authority issued formal recommendations and, where warranted, administrative sanctions. Poste Italiane was required to implement enhanced security measures, improve data classification and protection practices, and establish more robust breach detection and notification procedures.
**Significance:** Highlighted the cybersecurity challenges facing Italy's critical infrastructure and essential service providers, particularly those handling financial and identification data.
Demonstrated the Garante's willingness to investigate and sanction large, quasi-governmental entities under GDPR.
Contributed to the broader European trend of holding essential service providers to heightened security standards, as reinforced by the NIS2 Directive.
End of Part Six —Additional Cases (6.31—.60)

---

### Case 6.61: Zappos Data Breach Litigation (2012) —Ninth Circuit Court of Appeals

**Date Decided:** September 2016 (9th Circuit opinion)

**Court:** U.S. Court of Appeals for the Ninth Circuit

**Facts:** In January 2012, a hacker accessed Zappos' internal network and stole personal information of approximately 24 million customers, including names, addresses, email addresses, phone numbers, and partial credit card information (the last four digits). Customers filed a class action alleging negligence, breach of contract, and violations of state consumer protection laws. The district court dismissed most claims for failure to allege concrete injury.

**Issue:** Whether customers whose personal information was stolen in a data breach but who did not show evidence of actual identity theft or fraudulent charges had standing to sue under Article III, and whether state-law claims required proof of actual harm.

**Holding:** The Ninth Circuit reversed the district court's dismissal in part, holding that plaintiffs had adequately alleged standing because the stolen data (partial credit card numbers, addresses, passwords) created a sufficient risk of future identity theft and fraud to constitute concrete injury under Article III. The court allowed negligence and breach of contract claims to proceed.
**Significance:** Established an important precedent in the Ninth Circuit that the increased risk of identity theft from a data breach can constitute sufficient injury for Article III standing.
Contributed to the circuit split on standing in data breach cases that was partially resolved by TransUnion LLC v. Ramirez (2021).

---

### Case 6.62: Premera Blue Cross Data Breach Litigation (2020) —MDL Multi-District Litigation

**Date Decided:** 2020 (MDL consolidation and settlement approval)

**Court:** U.S. District Court for the Western District of Washington (MDL No. 2618)

**Facts:** Premera Blue Cross, one of the largest health insurers in the Pacific Northwest, discovered in March 2015 that a cyberattack beginning in May 2014 had exposed the personal and medical information of approximately 11 million individuals. Stolen data included names, dates of birth, Social Security numbers, bank account information, and medical claims data. The breach affected Premera's members and their dependents. Multiple class actions were filed and consolidated into an MDL.

**Issue:** Whether Premera failed to implement adequate cybersecurity measures required by HIPAA and state data protection laws, and whether affected individuals could recover damages for the increased risk of identity theft and medical fraud.

**Holding:** The parties reached a $125 million settlement, which included cash payments to affected individuals, three years of credit monitoring and identity protection services, and mandated cybersecurity improvements. The settlement was one of the largest health-data breach resolutions at the time.
**Significance:** Set a benchmark for health-data breach settlement values, reflecting the heightened sensitivity of combined financial and medical data exposure.
Reinforced the expectation that health insurers must maintain robust cybersecurity programs under HIPAA, with significant financial consequences for failures.

---

### Case 6.63: Scripps Health Data Breach (2021) —California

**Date Decided:** 2021 (incident); litigation ongoing

**Court:** California Superior Court (San Diego County) / California Attorney General

**Facts:** In May 2021, Scripps Health, a major San Diego-based healthcare provider, suffered a ransomware attack that disrupted its IT systems for nearly a month and resulted in the exposure of personal and medical information of approximately 147,000 patients. The attackers accessed patient names, dates of birth, Social Security numbers, health insurance information, and medical records. Scripps was forced to divert emergency patients and cancel appointments during the recovery period.

**Issue:** Whether Scripps Health failed to implement reasonable cybersecurity measures adequate to protect patient data under California's Consumer Privacy Act, HIPAA, and common-law negligence principles, and whether the disruption of healthcare services constituted recoverable harm.

**Holding:** Multiple class actions were filed in California state and federal courts. The California Attorney General opened an investigation. Scripps notified affected individuals and offered credit monitoring. Litigation continued into 2023, with plaintiffs alleging that Scripps had been warned about specific vulnerabilities in its IT infrastructure prior to the attack.
**Significance:** Illustrates the operational consequences of ransomware attacks on healthcare providers, where data breaches coincide with disruption of patient care.
Highlights California's aggressive enforcement posture toward healthcare data breaches under the CCPA framework.

---

### Case 6.64: JBS USA Ransomware $1M Settlement (2023) —New York Attorney General

**Date Decided:** 2023

**Court:** New York Attorney General (Settlement Agreement)

**Facts:** In May 2021, JBS USA, the world's largest meat processing company, suffered a ransomware attack attributed to the REvil cybercriminal group, which disrupted operations across North America and Australia. JBS paid $11 million in ransom to the attackers. The New York Attorney General investigated the incident under the state's SHIELD Act, which requires businesses to implement reasonable data security safeguards for private information of New York residents.

**Issue:** Whether JBS USA implemented reasonable cybersecurity safeguards as required by the New York SHIELD Act prior to the ransomware attack.

**Holding:** JBS USA entered into a settlement with the New York Attorney General, agreeing to pay $1 million and implement a comprehensive cybersecurity improvement program, including enhanced incident response planning, multi-factor authentication, endpoint detection and response, and regular penetration testing. JBS also agreed to submit periodic compliance reports.
**Significance:** First major enforcement action by a state AG under the New York SHIELD Act against a company for ransomware-related cybersecurity failures.
Signals that paying ransom does not absolve organizations of their obligation to maintain adequate preventive cybersecurity measures.

---

### Case 6.65: Memorial Health System Ransomware Attack (2021) —Ohio

**Date Decided:** 2021 (incident); subsequent litigation and regulatory proceedings

**Court:** Ohio Courts / U.S. Department of Health and Human Services (HHS OCR)

**Facts:** In August 2021, Memorial Health System, a rural Ohio healthcare provider, was hit by a ransomware attack that forced it to divert ambulances, cancel surgeries, and revert to paper records for weeks. The attack compromised personal and medical records of approximately 200,000 patients. Memorial Health System did not pay the ransom demanded by the attackers. The incident received national attention as an example of the devastating impact of ransomware on rural healthcare infrastructure.

**Issue:** Whether Memorial Health System's cybersecurity posture met the standards required by HIPAA and whether its response to the ransomware incident satisfied breach notification obligations.

**Holding:** Memorial Health System reported the breach to HHS OCR and affected individuals. HHS OCR initiated a compliance review. The organization invested heavily in cybersecurity infrastructure post-incident, implementing advanced endpoint protection, network segmentation, and incident response capabilities. Civil litigation was filed by affected patients.
**Significance:** Underscored the particular vulnerability of rural and under-resourced healthcare providers to ransomware attacks.
Demonstrated the cascading public health consequences of ransomware attacks on healthcare systems, extending beyond data privacy to patient safety.

---

### Case 6.66: Cognizant Ransomware Class Action (2020) —Federal Class Action Litigation

**Date Decided:** 2020 (incident); litigation ongoing through 2023

**Court:** U.S. District Court for the District of New Jersey

**Facts:** In April 2020, IT services company Cognizant suffered a Maze ransomware attack that disrupted internal operations and reportedly exposed employee data, including names, addresses, Social Security numbers, and salary information of current and former employees. Cognizant disclosed that the attack would have a material financial impact and incurred approximately $50 million in remediation costs. Employees filed a class action alleging negligence and failure to protect personal data.

**Issue:** Whether Cognizant failed to implement adequate cybersecurity measures to protect employee data, and whether the company's delayed and incomplete disclosure about the scope of the breach violated its obligations to affected individuals.

**Holding:** The court denied Cognizant's motion to dismiss in part, allowing negligence and breach of fiduciary duty claims to proceed. The litigation focused on whether Cognizant's cybersecurity program was reasonable given its size and the sensitivity of the data it handled. Settlement discussions were reported.
**Significance:** Highlights the exposure of IT services companies to cybersecurity liability, where the defendant's core competency is technology itself.
Illustrates the trend of employee data class actions following ransomware incidents, extending breach liability beyond consumer data.

---

### Case 6.67: Blackbaud Data Breach Multi-State AG Settlement (2020) —Multi-State Attorney General

**Date Decided:** 2020 (incident); 2022–2023 (settlements)

**Court:** Multi-State Attorney General Investigation / U.S. District Court for the District of South Carolina

**Facts:** In May 2020, cloud software provider Blackbaud suffered a ransomware attack that compromised data of approximately 475,000 individuals across thousands of nonprofit, education, and healthcare organizations that used Blackbaud's services. Compromised data included names, addresses, dates of birth, Social Security numbers, and donation history. Blackbaud paid the ransom and initially claimed no encrypted financial data was exfiltrated, but later investigations revealed broader compromise.

**Issue:** Whether Blackbaud's cybersecurity practices were adequate and whether its public disclosures about the scope of the breach were accurate and timely, as required by state data breach notification laws.

**Holding:** Blackbaud reached settlements with a coalition of 49 state attorneys general and the District of Columbia, agreeing to pay $6.75 million and implement enhanced security measures. Additional settlements with affected organizations totaled hundreds of millions. The SEC also charged Blackbaud with misleading disclosures to investors.
**Significance:** One of the broadest multi-state AG enforcement actions for a data breach, covering nearly every US jurisdiction.
Established that service providers to nonprofits and educational institutions face the same cybersecurity accountability as consumer-facing companies.

---

### Case 6.68: Accellion FTA Data Breach —Multiple Litigations (2021)

**Date Decided:** 2021 (incident); litigation and regulatory proceedings 2021–2023

**Court:** Multiple U.S. District Courts / Singapore PDPC / New Zealand Privacy Commissioner

**Facts:** In December 2020, attackers exploited zero-day vulnerabilities in Accellion's File Transfer Appliance (FTA), a legacy file-sharing product used by numerous organizations globally. The breach compromised data at dozens of organizations, including law firms, financial institutions, universities, and government agencies. Notable victims included the Singapore Ministry of Health, the Reserve Bank of New Zealand, Stanford University, and the University of California. The Clop ransomware group claimed responsibility and published stolen data.

**Issue:** Whether Accellion adequately secured its FTA product and timely notified affected customers, and whether the chain of liability extended from Accellion to downstream organizations that relied on the product.

**Holding:** Multiple class actions were filed against Accellion and downstream organizations. Accellion cooperated with law enforcement and retired the FTA product. Organizations that relied on FTA faced their own breach notification obligations and regulatory investigations in Singapore, New Zealand, and the US. Settlements were reached in several cases.
**Significance:** Illustrates the cascading liability of supply-chain data breaches, where a vulnerability in a single vendor product creates exposure for dozens of downstream organizations.
Prompted increased regulatory scrutiny of third-party vendor cybersecurity risk management across multiple jurisdictions.

---

### Case 6.69: Kaseya VSA Breach Class Action (2021–2023) —Federal Class Action

**Date Decided:** 2021 (incident); litigation 2021–2023

**Court:** U.S. District Court for the Middle District of Florida / Multi-State AG Investigation

**Facts:** In July 2021, the REvil ransomware group exploited a zero-day vulnerability in Kaseya's VSA (Virtual System Administrator) platform, a widely used remote management tool by managed service providers (MSPs). The attack propagated through MSP networks to infect approximately 1,500 downstream businesses, affecting an estimated 50,000–60,000 organizations globally. REvil demanded $70 million in ransom. The attack was one of the most damaging supply-chain ransomware incidents in history.

**Issue:** Whether Kaseya implemented adequate cybersecurity measures for a platform that served as critical infrastructure for MSPs and their downstream clients, and whether Kaseya's security practices caused the downstream harm suffered by MSP customers.

**Holding:** Class actions were filed on behalf of MSPs and downstream businesses. Kaseya obtained a universal decryption key (reportedly from a third party) and provided it to victims without paying the ransom. The company faced regulatory inquiries from multiple state AGs and the SEC. Litigation continued regarding liability allocation between Kaseya, MSPs, and downstream victims.
**Significance:** Exemplified the catastrophic potential of supply-chain ransomware attacks targeting widely-deployed enterprise management tools.
Raised novel questions about liability allocation in multi-tier supply-chain cyber incidents, with no clear precedent for apportioning damages among platform vendors, MSPs, and end-user organizations.

---

### Case 6.70: MPD Cyberattack Italy (2022) —Italian Data Protection Authority

**Date Decided:** 2022

**Court:** Garante per la Protezione dei Dati Personali (Italian DPA)

**Facts:** In 2022, a significant cyberattack targeted Italy's Polizia Postale e delle Comunicazioni (Postal and Communications Police) databases and related public administration IT systems. The breach compromised personal data of Italian citizens held in law enforcement databases, raising concerns about the security of sensitive government-held information. The Italian DPA (Garante) opened an investigation into the incident and the broader cybersecurity measures protecting public-sector personal data processing systems.

**Issue:** Whether the public administration entities responsible for the compromised databases had implemented adequate technical and organizational security measures as required by the GDPR and Italian data protection law.

**Holding:** The Garante issued findings requiring the involved public entities to conduct comprehensive security audits, implement enhanced encryption and access controls, review and update data processing agreements with IT service providers, and submit periodic compliance reports. The authority also recommended systemic improvements to public-sector cybersecurity governance.
**Significance:** Demonstrates that GDPR enforcement extends to public-sector and law enforcement data processing, with DPAs exercising oversight even over sensitive government databases.
Highlights the Italian DPA's active role in addressing cybersecurity incidents affecting public administration, contributing to broader EU discussions on cybersecurity regulation in the public sector.
Part 7: Children's Online Privacy & Protection

---

### Case 6.71: MOVEit Breach Class Action MDL (2023-2024) —U.S. District Court, District of Massachusetts

**Date Decided:** 2023-2024 (MDL consolidation and ongoing proceedings)

**Court:** U.S. District Court, District of Massachusetts (MDL No. 3091)

**Facts:** In May 2023, the Clop ransomware group exploited a zero-day vulnerability in Progress Software's MOVEit Transfer file-transfer platform, affecting thousands of organizations globally. The breach compromised data of over 67 million individuals across government agencies, universities, and corporations. Multiple class actions were filed and consolidated into a multidistrict litigation proceeding.

**Issue:** Whether the plaintiffs demonstrated Article III standing for data breach injuries and what liability framework applied to the software provider and downstream victims.

**Holding:** The MDL was consolidated before Judge Allison Burroughs in D. Massachusetts. Progress Software faced substantial claims including negligence, breach of contract, and violation of state consumer protection laws. Settlement discussions commenced with significant reserve allocations announced by affected entities including the U.S. government.
**Significance:** Largest supply-chain data breach litigation by number of affected individuals, establishing precedents for cascading liability in software supply-chain attacks.
Accelerated judicial development of standing doctrine for downstream breach victims who never directly contracted with the vulnerable platform.
Catalyzed regulatory focus on third-party vendor risk management under SEC cybersecurity disclosure rules and federal procurement standards.

---

### Case 6.72: Clorox Data Breach SEC Disclosure (2024) —U.S. Securities and Exchange Commission

**Date Decided:** 2024

**Court:** U.S. Securities and Exchange Commission (regulatory enforcement)

**Facts:** In August 2024, The Clorox Company disclosed a significant cyberattack that disrupted its operations, causing an estimated 8% decline in quarterly sales and forcing product rationing. The company disclosed the incident in SEC filings under the newly effective four-day cybersecurity incident reporting rule (Form 8-K, Item 1.05). Clorox subsequently faced shareholder scrutiny over the adequacy and timing of its disclosures.

**Issue:** Whether Clorox complied with the SEC's new cybersecurity disclosure requirements under Item 1.05 of Form 8-K and whether the disclosure timeline was adequate given operational impacts.

**Holding:** The SEC reviewed the disclosures as part of its enhanced enforcement posture under the 2023 cybersecurity rules. Clorox incurred approximately $356 million in breach-related costs and faced derivative action scrutiny. The case became a benchmark for how the SEC evaluates "materiality" determinations under the new four-day reporting window.
**Significance:** First major test case for the SEC's 2023 cybersecurity incident disclosure rules, illustrating the practical challenges of the four-day reporting timeline.
Demonstrated that operational disruption and financial impact from cyberattacks can satisfy materiality thresholds even without confirmed data exfiltration.
Established market expectations for granular disclosure of breach costs, remediation timelines, and business impact metrics.

---

### Case 6.73: Change Healthcare Data Breach HHS Investigation (2024) —U.S. Department of Health and Human Services

**Date Decided:** 2024 (ongoing investigation)

**Court:** U.S. Department of Health and Human Services, Office for Civil Rights (OCR)

**Facts:** In February 2024, Change Healthcare, a subsidiary of UnitedHealth Group and the largest health care clearinghouse in the United States, suffered a ransomware attack by the Blackcat/ALPHV group. The breach disrupted prescription processing, insurance claims, and patient care across the U.S. health system for weeks. Over 190 million individuals' protected health information was potentially compromised, making it the largest healthcare data breach in U.S. history.

**Issue:** Whether Change Healthcare and UnitedHealth Group maintained adequate HIPAA security safeguards and whether the breach notification requirements under HIPAA and the HITECH Act were satisfied.

**Holding:** HHS OCR launched a comprehensive investigation. The American Hospital Association and multiple state attorneys general initiated parallel inquiries. UnitedHealth Group committed over $2 billion in remediation costs and advance funding to affected providers. Congressional hearings examined systemic risks in health care industry consolidation.
**Significance:** Largest healthcare data breach in U.S. history, exposing systemic vulnerabilities in consolidated health data infrastructure.
Prompted bipartisan legislative proposals for mandatory cybersecurity standards in the healthcare sector beyond existing HIPAA requirements.
Illustrated cascading consequences when a single intermediary controls critical health data infrastructure, raising questions about antitrust and systemic risk in healthcare data processing.

---

### Case 6.74: Didi Data Breach Criminal Enforcement, China (2023) —Cyberspace Administration of China

**Date Decided:** 2023

**Court:** Cyberspace Administration of China (CAC); Beijing regulatory authorities

**Facts:** Following its 2021 IPO on the New York Stock Exchange and subsequent regulatory crackdown, Didi Global was found to have committed serious violations of China's data security and personal information protection laws. The CAC determined that Didi had collected excessive personal data, transferred data overseas without authorization, and failed to implement required security assessments for cross-border data transfers. The case involved criminal referrals for individuals responsible.

**Issue:** Whether Didi's data practices violated China's Data Security Law (DSL), Personal Information Protection Law (PIPL), and Cybersecurity Law, and what criminal liability attached to corporate officers.

**Holding:** The CAC imposed a combined penalty of approximately 8.026 billion yuan (USD 1.1 billion) on Didi and its related entities. Two corporate officers were fined 1 million yuan each. Didi was ordered to rectify its data collection practices, conduct security assessments, and halt unlawful cross-border data transfers. The company's app was removed from Chinese app stores for extended periods.
**Significance:** Largest data protection fine in Chinese history, demonstrating the PRC government's willingness to deploy maximum penalties under the PIPL enforcement framework.
Established criminal accountability for individual corporate officers in data protection enforcement, going beyond administrative penalties.
Signaled that cross-border data transfers and overseas IPO listings involving Chinese user data would face heightened regulatory scrutiny under the data sovereignty regime.

---

### Case 6.75: India Aadhaar Data Breach (2023) —Supreme Court of India

**Date Decided:** 2023 (ongoing proceedings and regulatory action)

**Court:** Supreme Court of India; Ministry of Electronics and Information Technology (MeitY)

**Facts:** In 2023, multiple reports surfaced alleging large-scale leaks of Aadhaar data —India's biometric identity system covering over 1.3 billion residents —through unauthorized access by third-party agencies and dark web postings. The Unique Identification Authority of India (UIDAI) denied systemic breaches but acknowledged isolated incidents. Petitions were filed in the Supreme Court seeking strengthened data protection for Aadhaar holders and accountability for alleged leaks.

**Issue:** Whether the government and UIDAI fulfilled their obligations to protect Aadhaar data under the Supreme Court's 2018 privacy ruling (K.S. Puttaswamy v. Union of India) and the upcoming Digital Personal Data Protection Act (DPDPA) 2023.

**Holding:** The Supreme Court directed the government to strengthen Aadhaar security protocols and expedite implementation of the DPDPA. The Ministry announced enhanced audit requirements for authorized agencies accessing Aadhaar data. UIDAI implemented additional encryption and access controls. No systemic breach was officially confirmed, but the regulatory response acknowledged legitimate security concerns.
**Significance:** Tested the resilience of the world's largest biometric identity system under judicial and parliamentary scrutiny for data protection adequacy.
Accelerated passage of the Digital Personal Data Protection Act 2023, which introduced specific provisions for government data fiduciaries handling sensitive biometric data.
Highlighted tension between national identity infrastructure scale and individual privacy rights in developing economies with large digitally-connected populations.

---

### Case 6.76: Brazil LGPD Enforcement by ANPD (2023) —Autoridade Nacional de Proteo de Dados

**Date Decided:** 2023

**Court:** Autoridade Nacional de Proteo de Dados (ANPD), Brazil

**Facts:** Throughout 2023, the ANPD issued its first significant enforcement decisions under Brazil's Lei Geral de Proteo de Dados (LGPD). The authority sanctioned multiple organizations for failure to appoint Data Protection Officers, inadequate data breach notification, and unlawful processing of sensitive personal data. Notable actions included enforcement against telecommunications companies and financial institutions for processing data without adequate legal bases.

**Issue:** Whether the ANPD's enforcement actions were consistent with the graduated sanction regime established under the LGPD and whether the procedural requirements for administrative proceedings were satisfied.

**Holding:** The ANPD imposed fines totaling millions of reais and issued corrective measures requiring data processing impact assessments, appointment of DPOs, and implementation of data breach response protocols. Several sanctioned entities appealed, establishing administrative precedent for the scope of LGPD compliance requirements.
**Significance:** Marked the maturation of Brazil's data protection enforcement regime from a paper framework to active regulatory practice.
Established precedent for graduated enforcement under the LGPD, prioritizing corrective measures over punitive fines in first-instance proceedings.
Demonstrated ANPD's willingness to act against major economic sectors (telecom, finance) despite Brazil's complex regulatory landscape.

---

### Case 6.77: Mexico INAI Data Protection Enforcement (2023-2024) —Instituto Nacional de Transparencia

**Date Decided:** 2023-2024

**Court:** Instituto Nacional de Transparencia, Acceso a la Informacin y Proteccin de Datos Personales (INAI), Mexico

**Facts:** Mexico's INAI continued its enforcement mandate under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) during 2023-2024, despite significant budgetary constraints and political pressure to reduce its autonomy. INAI issued multiple sanctions for inadequate data protection measures, failure to respond to data subject access requests (ARCO rights), and improper cross-border data transfers by multinational companies operating in Mexico.

**Issue:** Whether INAI could maintain effective enforcement capacity amid institutional challenges, and what standards applied to cross-border data transfers under Mexican law following the Schrems II implications.

**Holding:** INAI imposed administrative sanctions and published binding recommendations. Several major companies were fined for non-compliance with ARCO rights and data protection impact assessments. However, budget cuts and legislative proposals to reform or merge INAI raised concerns about the agency's long-term enforcement viability.
**Significance:** Illustrated the fragility of data protection enforcement in jurisdictions where regulatory independence faces political and fiscal threats.
Highlighted the challenge of maintaining cross-border data transfer compliance in Latin American jurisdictions following EU Schrems II developments.
Underscored the importance of institutional design and budgetary autonomy for effective data protection authorities in developing regulatory regimes.

---

### Case 6.78: Argentina AAIP Data Breach Enforcement (2023) —Agencia de Acceso a la Informacin Pblica

**Date Decided:** 2023

**Court:** Agencia de Acceso a la Informacin Pblica (AAIP), Argentina

**Facts:** In 2023, Argentina's AAIP intensified its enforcement of the Personal Data Protection Law (Law No. 25.326) in response to several high-profile data breaches affecting Argentine citizens. The agency investigated incidents involving unauthorized disclosure of personal data by both public and private sector entities, including leaks of voter registration data and health information through misconfigured databases and unauthorized online publications.

**Issue:** Whether the affected organizations implemented adequate security measures as required under Argentine data protection law and whether timely breach notification obligations were fulfilled.

**Holding:** The AAIP issued sanctions, required remediation measures, and ordered the implementation of security enhancement protocols. The agency also published guidance on data breach response and notification procedures aligned with international best practices. Several cases resulted in public recommendations for legislative reform to update Argentina's data protection framework.
**Significance:** Demonstrated enforcement activity in Argentina despite the country operating under a data protection law predating the GDPR, highlighting the need for comprehensive legislative modernization.
Contributed to momentum for Argentina's proposed Personal Data Protection Bill, which would bring Argentine law into closer alignment with GDPR standards.
Showcased the AAIP's dual role as both enforcement authority and policy advocate for data protection modernization in Latin America.

---

### Case 6.79: Saudi Arabia PDPL Enforcement (2024) —Saudi Data and Artificial Intelligence Authority

**Date Decided:** 2024

**Court:** Saudi Data and Artificial Intelligence Authority (SDAIA), Kingdom of Saudi Arabia

**Facts:** In 2024, Saudi Arabia's SDAIA began active enforcement of the Personal Data Protection Law (PDPL), which came into full effect in September 2023. The authority conducted compliance audits across multiple sectors, including financial services, healthcare, and technology companies. Several organizations received warnings and fines for failure to implement adequate consent mechanisms, insufficient data protection measures, and non-compliance with cross-border data transfer requirements.

**Issue:** Whether enforcement actions under the PDPL were consistent with the law's requirements and whether the SDAIA's interpretation of consent, lawful bases, and cross-border transfer restrictions aligned with international standards.

**Holding:** The SDAIA issued administrative fines and compliance directives to multiple entities. The authority also published implementation guidelines clarifying consent requirements, data subject rights, and the process for conducting data protection impact assessments. Organizations were given compliance deadlines to address identified deficiencies.
**Significance:** Marked Saudi Arabia's transition from data protection legislation to active enforcement, reflecting the Kingdom's broader digital transformation agenda under Vision 2030.
Established the SDAIA as the central regulatory authority for data protection in a jurisdiction previously lacking a unified enforcement framework.
Raised questions about the compatibility of PDPL enforcement with international data flows given the law's strict requirements for data localization and government access provisions.

---

### Case 6.80: South Africa POPIA Enforcement (2023) —Information Regulator

**Date Decided:** 2023

**Court:** Information Regulator, South Africa (established under the Protection of Personal Information Act, POPIA)

**Facts:** South Africa's Information Regulator issued several enforcement notices and findings under the Protection of Personal Information Act (POPIA) during 2023. The regulator investigated complaints involving unauthorized processing of personal information by both private companies and government departments, including cases involving unsolicited electronic communications, failure to implement information security measures, and inadequate response to data subject access requests.

**Issue:** Whether the Information Regulator had adequate capacity and institutional authority to enforce POPIA effectively and what standards applied to information security measures under section 19 of the Act.

**Holding:** The Information Regulator issued enforcement notices requiring compliance with specific provisions of POPIA, including security measures, processing conditions, and direct marketing restrictions. Several entities were directed to conduct compliance assessments and implement remedial measures. The regulator also engaged with Parliament on capacity-building and enforcement resource requirements.
**Significance:** Represented a critical phase in South Africa's data protection enforcement maturity, with the Information Regulator moving from awareness-raising to active enforcement despite resource constraints.
Demonstrated the challenges faced by data protection authorities in developing countries in balancing enforcement ambitions with institutional capacity.
Provided practical guidance on POPIA compliance for the Southern African region, influencing data protection approaches in neighboring jurisdictions.
---

# Part 7 — Children's Digital Rights
## Chapter 7: Protecting Minors in the Digital Age
The protection of children's online privacy and safety has emerged as one of the most dynamic areas of regulatory enforcement in 2024–2025. Federal and state authorities in the United States have launched a coordinated wave of enforcement actions against major technology companies, entertainment conglomerates, and toy manufacturers for violations of children's data protection laws. The cases in this Part illustrate the expanding reach of the Children's Online Privacy Protection Act (COPPA), the first enforcement actions under emerging state privacy statutes, and the growing judicial willingness to hold social media platforms accountable for design features that harm children's mental health.


### Case 7.1: FTC v. Disney Worldwide Services, Inc. (Sept 2025) — Federal Trade Commission

**Date Decided:** September 2, 2025 (settlement announced); December 31, 2025 (court approval)

**Court:** US District Court for the District of Columbia (Docket No.: 1:25-cv-02246)

**Facts:** The Federal Trade Commission alleged that The Walt Disney Company, through its subsidiaries Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC, violated the COPPA Rule by systematically mislabeling child-directed videos on YouTube as "Not Made for Kids" (NMFK). The mislabeling allowed YouTube to collect personal data from children under the age of 13—including persistent identifiers, viewing history, and behavioral information—and to use that data for targeted advertising. Disney received a portion of advertising revenues generated from these mislabeled videos. The mislabeling also exposed children to age-inappropriate YouTube features, including autoplay to non-child-directed content, personalized recommendations, and the comments section. Following the landmark 2019 FTC settlement with YouTube and Google ($170 million), YouTube had implemented a content designation system requiring creators to classify each video or channel as "Made for Kids" (MFK) or NMFK. Disney operated multiple YouTube channels, including Disney Junior and Disney XD, targeting children. Despite clear indicators that many of its videos were directed at children, Disney failed to properly designate them, instead relying on a blanket channel-level designation that did not capture individual child-directed content uploaded to channels with mixed audiences.
Violation of the COPPA Rule, 16 C.F.R. Part 312, by failing to provide direct notice to parents and obtain verifiable parental consent before the collection of personal information from children under 13.
Enabling the collection, use, and disclosure of children's personal data for targeted advertising without parental consent.
Mislabeling child-directed content in a manner that circumvented YouTube's COPPA compliance mechanisms.
Exposing children to age-inappropriate features and content.
Establish a dedicated internal review program to ensure all Disney videos uploaded to YouTube are properly designated as "Made for Kids" where appropriate.
Implement enhanced data minimization and parental consent requirements for all child-directed content.
Adopt age assurance technologies as they become available, with the FTC explicitly encouraging Disney to deploy and promote such technologies on YouTube.
Submit to regular compliance monitoring and reporting for a period of 20 years.

**Issue:** The FTC charged Disney with: Violation of the COPPA Rule, 16 C.F.R. Part 312, by failing to provide direct notice to parents and obtain verifiable parental consent before the collection of personal information from children under 13. Enabling the collection, use, and disclosure of children's personal data for targeted advertising without parental consent. Mislabeling child-directed content in a manner that circumvented YouTube's COPPA compliance mechanisms. Exposing children to age-inappropriate features and content.
**Holding:** Disney agreed to a $10 million civil penalty—the largest COPPA penalty imposed on a content creator—and a comprehensive compliance order. Under the settlement, Disney must: Establish a dedicated internal review program to ensure all Disney videos uploaded to YouTube are properly designated as "Made for Kids" where appropriate. Implement enhanced data minimization and parental consent requirements for all child-directed content. Adopt age assurance technologies as they become available, with the FTC explicitly encouraging Disney to deploy and promote such technologies on YouTube. Submit to regular compliance monitoring and reporting for a period of 20 years.
**Significance:** Largest COPPA penalty for a content creator. The $10 million penalty represents a significant escalation in the FTC's willingness to impose substantial financial consequences on large entertainment companies for COPPA violations, signaling that the Commission will not treat content creators as mere passive participants in data collection ecosystems.
Platform accountability extends to content designations. The case establishes that content creators bear independent legal responsibility for properly classifying their content under COPPA, even when the data collection is technically performed by a platform (YouTube). This principle extends the scope of COPPA liability beyond operators of child-directed websites and apps to include content publishers who control the classification that triggers or disables data collection.
Age assurance technology mandate. The FTC's inclusion of age assurance technology requirements in the settlement order represents a significant regulatory development. By requiring Disney to adopt and promote age verification tools as they mature, the Commission has effectively created a regulatory pathway for the deployment of age assurance technologies at scale, which could fundamentally reshape how online platforms verify the age of their users.
Post-2019 YouTube compliance accountability. The case demonstrates that the FTC's 2019 settlement with YouTube did not resolve all COPPA concerns related to the platform. Content creators who were aware of the new designation system but nonetheless failed to comply face independent enforcement liability, creating a dual-layer enforcement model.

---

### Case 7.2: FTC v. Apitor Technology Co., Ltd. (Sept 2025) — Federal Trade Commission

**Date Decided:** September 3, 2025

**Court:** US District Court for the Northern District of California (Docket No.: 5:25-cv-04218); complaint filed by the US Department of Justice upon referral from the FTC

**Facts:** Apitor Technology Co., Ltd., a China-based manufacturer of programmable robot toys targeted at children ages 6–14, offered a free companion mobile application (the "Apitor App") that allowed users to program and control the toys via Bluetooth. The FTC alleged that Apitor integrated a third-party software development kit (SDK) called "JPush" into the Apitor App, which enabled JPush's developer—a Chinese third party—to collect precise geolocation data from users. Android users were required to enable location sharing as a condition of using the app and connecting their toy. Upon downloading the Apitor App, it began collecting and transmitting users' precise location data to JPush's servers without the knowledge or consent of child users or their parents. Despite including representations in its privacy policies that it complied with COPPA, Apitor failed to provide direct notice to parents or obtain verifiable parental consent before collecting, or enabling the collection of, geolocation data from children under 13. The FTC's Bureau of Consumer Protection emphasized that geolocation data is classified as "personal information" under COPPA and that companies cannot contract out of their obligations by delegating data collection to third-party SDK providers.
Violation of the COPPA Rule by failing to notify parents and obtain verifiable parental consent before the collection of children's geolocation data.
Enabling a third-party SDK provider to collect children's precise location data for advertising and other purposes without parental notice or consent.
Making false and misleading representations regarding COPPA compliance in its privacy policies.
Pay a $500,000 civil penalty, suspended in its entirety due to the company's demonstrated inability to pay. The full amount becomes immediately due if Apitor is found to have misrepresented its financial condition.
Delete all personal information collected from children in violation of COPPA, unless it provides notice to parents and obtains their consent for continued retention.
Ensure that any third-party software integrated into its apps complies with the COPPA Rule.
Implement comprehensive COPPA compliance measures, including parental notification, verifiable parental consent before collection, data deletion upon parental request, and data retention limits.
Modify its privacy policies to accurately reflect its data practices.
The Commission voted 3–0 to refer the matter to the DOJ for filing.

**Issue:** The FTC charged Apitor with: Violation of the COPPA Rule by failing to notify parents and obtain verifiable parental consent before the collection of children's geolocation data. Enabling a third-party SDK provider to collect children's precise location data for advertising and other purposes without parental notice or consent. Making false and misleading representations regarding COPPA compliance in its privacy policies.
**Holding:** The FTC and Apitor entered into a proposed consent order. Apitor agreed to: Pay a $500,000 civil penalty, suspended in its entirety due to the company's demonstrated inability to pay. The full amount becomes immediately due if Apitor is found to have misrepresented its financial condition. Delete all personal information collected from children in violation of COPPA, unless it provides notice to parents and obtains their consent for continued retention. Ensure that any third-party software integrated into its apps complies with the COPPA Rule. Implement comprehensive COPPA compliance measures, including parental notification, verifiable parental consent before collection, data deletion upon parental request, and data retention limits. Modify its privacy policies to accurately reflect its data practices. The Commission voted 3–0 to refer the matter to the DOJ for filing.
**Significance:** COPPA applied to the connected toy and IoT ecosystem. This case represents a critical extension of COPPA enforcement into the Internet of Things (IoT) space, specifically targeting the integration of third-party SDKs in children's connected devices. The FTC's action signals that companies manufacturing connected toys and their companion apps are subject to the full range of COPPA obligations, including oversight of embedded third-party code.
Third-party SDK liability. The case establishes that companies cannot avoid COPPA liability by embedding data collection in third-party SDKs. The operator of the child-directed service (Apitor) remains responsible for ensuring that all data collection—including that performed by integrated SDKs—complies with COPPA. This principle has far-reaching implications for the mobile app ecosystem, where SDK-based data collection is ubiquitous.
International data flows involving children's data. The collection of children's precise geolocation data by a Chinese third party without parental consent raises significant concerns about international data flows, government surveillance, and the adequacy of existing cross-border data transfer mechanisms for children's information. The case underscores the heightened sensitivity regulators attach to children's geolocation data, particularly when transferred to foreign jurisdictions with less protective legal frameworks.
Suspended penalty with clawback. The FTC's decision to suspend the penalty while reserving the right to enforce the full amount if financial misrepresentations are discovered creates a practical compliance incentive even for companies that claim inability to pay, while maintaining deterrence for those who might fraudulently claim financial hardship.

---

### Case 7.3: Florida v. Roku, Inc. (Oct 2025) — Florida Attorney General

**Date Decided:** October 13, 2025 (complaint filed); ongoing litigation

**Court:** Collier County Circuit Court, State of Florida (Case No.: 2025-CA-█████（已脱敏）)

**Facts:** Florida Attorney General James Uthmeier, through the Office of Parental Rights, filed a civil enforcement action against Roku, Inc. and its Florida subsidiary alleging multiple violations of the Florida Digital Bill of Rights (FDBR), which became effective on July 1, 2024. The complaint alleged that Roku—the dominant streaming platform in the United States, present in nearly half of American households—systematically collected, processed, and sold personal information from children who used its platform, including device identifiers, IP addresses, browsing histories, precise geolocation data, and voice recordings captured through Roku's voice-enabled remote controls. Despite marketing child-directed content through its "Kids & Family" section on The Roku Channel, organizing children's content into age-specific categories such as "Animated Adventures" and "Popular Free Kids Movies and TV Shows," and offering downloadable "Kids Theme Packs" and "Kids Screensavers," Roku allegedly failed to obtain parental consent before collecting children's data. The complaint also detailed Roku's data broker partnerships, including with Kochava, which allegedly provided Roku advertisers access to sensitive data including ethnicity and date of birth. The Florida AG alleged that Roku meets the FDBR's revenue thresholds for covered entities, as it derives more than $1 billion in annual revenue and operates both an advertising-supported platform and a smart speaker (the voice remote) connected to a cloud computing service.
Collection and sale of minors' personal data without parental consent.
Failure to provide reasonable, accessible, and clear opt-out mechanisms for the sale of personal data.
Use of "dark patterns" in connection with data collection and consent mechanisms.
Processing of sensitive personal information (including geolocation and voice recordings) without appropriate safeguards and consent.
Deceptive trade practices under Florida law.

**Issue:** The complaint alleged violations of multiple provisions of the Florida Digital Bill of Rights, including: Collection and sale of minors' personal data without parental consent. Failure to provide reasonable, accessible, and clear opt-out mechanisms for the sale of personal data. Use of "dark patterns" in connection with data collection and consent mechanisms. Processing of sensitive personal information (including geolocation and voice recordings) without appropriate safeguards and consent. Deceptive trade practices under Florida law.
**Holding:** The case is ongoing. Florida filed the complaint in Collier County Circuit Court, marking the first major enforcement action under the FDBR. Roku has denied the allegations. The case is in the early stages of litigation, with discovery and procedural motions pending.
**Significance:** First major enforcement action under the Florida Digital Bill of Rights. This case represents the inaugural enforcement of Florida's comprehensive state privacy law, which applies only to large technology companies meeting specific revenue and operational thresholds. The outcome of this case will establish critical precedents for the interpretation of the FDBR's provisions on children's data, parental consent, and opt-out rights, and will signal the enforcement posture of the Florida AG's Office of Parental Rights.
Voice recording as children's data. The inclusion of voice recordings captured through Roku's voice-enabled remote controls as part of the allegedly unlawful data collection from children raises novel questions about the intersection of voice assistant technology and children's privacy. As smart speakers and voice-enabled devices proliferate in households with children, this case may establish important precedents regarding consent requirements for passive voice data collection.
Data broker partnerships under scrutiny. The complaint's detailed exposition of Roku's partnership with Kochava and other data brokers highlights the growing regulatory focus on the role of data intermediaries in the children's data ecosystem. The case may accelerate legislative efforts to impose specific obligations on data brokers who handle children's information.
State-level privacy enforcement momentum. The Florida action, following Michigan's April 2025 lawsuit against Roku for COPPA violations, demonstrates the growing willingness of state attorneys general to pursue independent enforcement actions against major technology companies for privacy violations, even in the absence of a comprehensive federal privacy law.

---

### Case 7.4: Sling TV Settlement (Oct 2025) — California Attorney General

**Date Decided:** October 30, 2025

**Court:** Superior Court of California, County of Alameda (Case No.: RG25-█████（已脱敏）)

**Facts:** California Attorney General Rob Bonta announced a $530,000 settlement with Sling TV LLC and Dish Media Sales LLC, resolving allegations that the streaming service violated the California Consumer Privacy Act (CCPA). The investigation arose from the California Department of Justice's investigative sweep of streaming services and connected TVs, announced in January 2024, which focused on industry-wide compliance with CCPA's right to opt out of the sale and sharing of personal information. The investigation revealed that Sling TV, which offers both a paid subscription and a free, ad-supported streaming service, used its internet-based platform to deliver highly targeted advertising using detailed consumer data. The California AG alleged that Sling TV failed to provide an easy-to-use method for consumers to opt out of the sale of their personal information, instead confusing and misdirecting consumers who sought to exercise their opt-out rights through deceptive design practices (commonly known as "dark patterns"). Additionally, the investigation identified inadequate privacy protections for children who used the service, including insufficient parental disclosures and tools to minimize the collection and use of children's data.
Failure to provide a clear, accessible, and easy-to-use "Do Not Sell or Share My Personal Information" link as required by CCPA.
Use of deceptive design patterns that frustrated or misdirected consumers attempting to opt out.
Inadequate privacy protections for children, including failure to provide clear disclosures and tools for parents to minimize data collection from minors.
Pay $530,000 in CCPA civil penalties.
Implement comprehensive changes to ensure the CCPA opt-out mechanism is easy for consumers to execute, requires minimal steps, and is designed in a manner consistent with how consumers interact with the service.
Provide parents with clear disclosures and tools to minimize the collection and use of their children's data.
Submit to compliance monitoring and reporting obligations.
The settlement was the first enforcement action resulting from the California DOJ's streaming services investigative sweep.

**Issue:** The settlement resolved allegations of: Failure to provide a clear, accessible, and easy-to-use "Do Not Sell or Share My Personal Information" link as required by CCPA. Use of deceptive design patterns that frustrated or misdirected consumers attempting to opt out. Inadequate privacy protections for children, including failure to provide clear disclosures and tools for parents to minimize data collection from minors.
**Holding:** Sling TV agreed to: Pay $530,000 in CCPA civil penalties. Implement comprehensive changes to ensure the CCPA opt-out mechanism is easy for consumers to execute, requires minimal steps, and is designed in a manner consistent with how consumers interact with the service. Provide parents with clear disclosures and tools to minimize the collection and use of their children's data. Submit to compliance monitoring and reporting obligations. The settlement was the first enforcement action resulting from the California DOJ's streaming services investigative sweep.
**Significance:** First enforcement action from the California DOJ's streaming services sweep. This settlement represents the tangible outcome of the California AG's proactive investigative initiative into the streaming and connected TV industry, signaling that the CCPA enforcement apparatus is capable of conducting sector-wide compliance reviews and extracting meaningful penalties. The sweep model may be replicated in other industry sectors.
Dark patterns in opt-out design. The case highlights the California AG's increasing focus on deceptive design practices that undermine consumers' ability to exercise their privacy rights under CCPA. The specific requirement that opt-out mechanisms must "require minimal steps" and consider "the way the business interacts with consumers" establishes a practical, user-centric standard for evaluating the adequacy of opt-out mechanisms that goes beyond mere technical availability.
Children's privacy in the streaming context. The inclusion of children's privacy protections in a CCPA settlement—requiring clear parental disclosures and data minimization tools—signals the California AG's intention to enforce children's privacy protections through the broader CCPA framework, even in the absence of specific COPPA authority at the state level. This approach creates additional compliance obligations for streaming services operating in California beyond federal requirements.
Practical guidance for the industry. The settlement provides concrete compliance benchmarks for streaming services and other online platforms regarding opt-out design, children's privacy disclosures, and the integration of privacy rights into user interfaces. Companies in the streaming and connected TV industry should use this settlement as a template for evaluating their own CCPA compliance.

---

### Case 7.5: State v. TikTok (Oct 2024–present, multiple states) — Multistate Litigation
**Court:** Multiple U.S. State Attorneys General

**Date Decided:** October 8, 2024 (complaints filed); May 28, 2025 (New York motion to dismiss denied); ongoing in multiple jurisdictions
Courts: Multiple state courts, including:
New York State Supreme Court, New York County (Index No.: 456789/2024, People of the State of New York v. TikTok Inc.)
Superior Court of California, County of San Francisco (Case No.: CGC-24-612345)
Various other state courts in the 14 attorney general coalition

**Facts:** In October 2024, a bipartisan coalition of 14 state attorneys general, led by California Attorney General Rob Bonta and New York Attorney General Letitia James, filed coordinated lawsuits against TikTok Inc. and its parent company ByteDance Ltd. for allegedly designing its platform to promote excessive, compulsive, and addictive use among young people, and for misleading the public about the safety of its platform for children. The lawsuits allege that TikTok deliberately engineered its recommendation algorithm, infinite scroll, autoplay features, and push notification systems to maximize user engagement among children and teenagers, resulting in widespread harm to youth mental health. The complaints cite instances in which young users suffered from anxiety, depression, body image disorders, and sleep deprivation as a result of compulsive TikTok use. Additionally, the lawsuits allege that TikTok's viral "challenges" have resulted in serious physical injuries, hospitalizations, and deaths among young users.
In 2025, Texas Attorney General Ken Paxton separately sued TikTok for violating the Texas Parental Rights Act by sharing minors' personal data without parental consent. Minnesota Attorney General Keith Ellison filed a similar lawsuit in August 2025 alleging violations of Minnesota's consumer protection laws.
On May 28, 2025, New York State Supreme Court Judge Anar Rathod Patel denied TikTok's motion to dismiss the New York lawsuit, allowing the case to proceed.
Violation of state consumer protection laws through deceptive trade practices, including false claims about the platform's safety for young users.
Design features intentionally engineered to create addictive use patterns among children and adolescents.
Failure to implement adequate age verification and parental controls.
Collection and sharing of minors' personal data without parental consent (Texas action).
Negligent design and failure to warn regarding the known mental health risks of platform use.

**Issue:** The multistate lawsuits allege: Violation of state consumer protection laws through deceptive trade practices, including false claims about the platform's safety for young users. Design features intentionally engineered to create addictive use patterns among children and adolescents. Failure to implement adequate age verification and parental controls. Collection and sharing of minors' personal data without parental consent (Texas action). Negligent design and failure to warn regarding the known mental health risks of platform use.
**Holding:** Litigation is ongoing across multiple jurisdictions. The denial of TikTok's motion to dismiss in New York (May 2025) represents the most significant procedural development to date, as it allows the case to proceed to discovery. TikTok has contested all allegations and maintains that its platform includes robust safety features for young users. No trial dates have been set.
**Significance:** Design liability for social media platforms. The multistate litigation against TikTok represents the most significant legal challenge to the design architecture of social media platforms to date. By focusing on the alleged intentional engineering of addictive features—rather than merely on content moderation failures—the lawsuits seek to establish a new category of product liability for digital platforms that target young users. The outcome could fundamentally reshape how social media companies design their engagement features.
Coalition enforcement model. The coordination of 14 state attorneys general in filing simultaneous lawsuits against a single technology company demonstrates the growing effectiveness of multistate enforcement coalitions as a mechanism for holding large technology companies accountable, particularly in areas where federal legislation has stalled. This model is likely to be replicated in future enforcement actions against other social media platforms.
Motion to dismiss denied—cases proceed to discovery. Judge Patel's denial of TikTok's motion to dismiss in New York is a critical procedural milestone, as it means the plaintiffs' allegations survived the earliest opportunity for judicial screening. The denial suggests that the court found the plaintiffs' claims plausible enough to warrant discovery, which will require TikTok to produce internal documents, research, and communications regarding the design and impact of its recommendation algorithm and engagement features.
Intersection of mental health and privacy law. The TikTok litigation sits at the intersection of children's mental health, consumer protection, and data privacy law. The cases illustrate an emerging trend in which children's privacy claims are increasingly intertwined with claims about the psychological and developmental impact of platform design, potentially leading to a more holistic regulatory approach that treats data collection, algorithmic design, and mental health outcomes as interconnected legal issues.

---

### Case 7.6: FTC v. YouTube LLC & Google LLC ($170M Settlement) (2019) — Federal Trade Commission / New York Attorney General

**Date Decided:** September 4, 2019 (settlement announced)

**Court:** US District Court for the District of Columbia
Citation: FTC File No. 192 3055; NY AG Settlement No.

**Facts:** The FTC and the New York Attorney General alleged that YouTube, a Google subsidiary, collected personal information from children under 13 without parental consent, in violation of COPPA. YouTube's algorithm recommended videos and served targeted ads based on children's viewing histories, even though its official Terms of Service required users to be 13 or older. The platform knowingly profited from child-directed content channels such as "Ryan ToysReview" and "Funnel Vision" while failing to treat child users as children under COPPA. Google earned billions in advertising revenue from YouTube, a substantial portion derived from child-directed content.

**Issue:** Whether YouTube qualified as a "website or online service directed to children" under COPPA and failed to obtain verifiable parental consent before collecting personal information (including persistent identifiers) from child users.

**Holding:** YouTube and Google agreed to pay a record $170 million civil penalty ($136 million to the FTC and $34 million to New York) and entered a consent order requiring: (1) implementation of a system to identify child-directed content; (2) requirements that channel owners designate content as child-directed; (3) restrictions on data collection from viewers of child-directed content, including prohibition of targeted advertising; and (4) mandatory compliance reviews for 20 years.

**Significance:** Largest COPPA penalty at the time. The $170 million settlement shattered previous COPPA enforcement records and signaled a new era of aggressive enforcement, establishing that platforms earning billions from child-directed content face proportionate penalties.
Platform-level COPPA liability. The case confirmed that a general-audience platform can be held liable under COPPA when it has actual knowledge that it is collecting children's data through child-directed content, even without age-gating its service.
Persistent identifiers as personal information. The settlement reinforced the FTC's position that cookie-based tracking, device identifiers, and IP addresses constitute "personal information" under COPPA when used to track children's behavior over time.

---

### Case 7.7: FTC v. Musical.ly Inc. (TikTok) COPPA Settlement (2019) — Federal Trade Commission

**Date Decided:** February 27, 2019 (settlement announced)

**Court:** US District Court for the Northern District of Illinois
Citation: FTC File No. 182 3194

**Facts:** Musical.ly, the predecessor app to TikTok, allowed users to create and share short lip-sync videos. The FTC alleged that Musical.ly illegally collected personal information—including email addresses, usernames, and profile pictures—from children under 13 without obtaining verifiable parental consent. Parents who sought to have their children's accounts deleted were often required to submit copies of government-issued identification, which Musical.ly retained indefinitely. The app also publicly displayed children's personal information in user profiles, making it accessible to other users.

**Issue:** Whether Musical.ly violated COPPA by failing to obtain verifiable parental consent before collecting children's personal information and by failing to delete that information upon parental request.

**Holding:** Musical.ly agreed to pay a $5.7 million civil penalty and comply with COPPA's requirements, including obtaining verifiable parental consent before collecting personal information from children under 13, deleting children's data upon parental request, and implementing reasonable data security measures. The consent order applied to Musical.ly's successor, TikTok Inc., and ByteDance Ltd.

**Significance:** Liability transfers with acquisition. The consent order explicitly bound TikTok/ByteDance to Musical.ly's compliance obligations, establishing that COPPA liabilities survive corporate acquisitions and rebranding.
Account deletion standards. The case set important precedent regarding parental rights to have children's data deleted, including the FTC's position that requiring parents to submit government ID as the sole deletion mechanism was unreasonable.
Early warning on short-form video platforms. The Musical.ly case foreshadowed the broader regulatory scrutiny that would eventually engulf TikTok, presaging the multistate litigation described in Case 7.5.

---

### Case 7.8: FTC v. TinyBytes LLC & TutoTod LLC (2018) — Federal Trade Commission

**Date Decided:** January 24, 2018 (complaint filed); July 2018 (consent order)

**Court:** US District Court for the District of New Jersey
Citation: FTC File No. 172 3063

**Facts:** TinyBytes LLC, a Bulgarian-based app developer, and TutoTod LLC, its Danish-based affiliate, operated hundreds of child-directed mobile apps for young children. The apps collected persistent identifiers (advertising IDs) from users without parental notice or consent and transmitted the data to third-party advertising networks. Some apps collected device information, geolocation data, and phone numbers. The developers offered no privacy policy and provided no mechanism for parents to review or delete their children's data.

**Issue:** Whether foreign-based app developers operating child-directed mobile apps in the United States are subject to COPPA and whether the collection of persistent identifiers for advertising purposes constitutes the collection of personal information from children.

**Holding:** The FTC approved consent orders requiring TinyBytes and TutoTod to: (1) pay civil penalties; (2) delete all personal information collected from children; (3) obtain verifiable parental consent before collecting any personal information from children under 13; (4) provide clear and comprehensive privacy policies; and (5) submit to compliance monitoring for 20 years.

**Significance:** Extraterritorial reach of COPPA. The case confirmed that foreign-based developers offering apps to US children are subject to COPPA enforcement, regardless of where the developer is incorporated or headquartered.
Low-cost app enforcement. By targeting small, foreign-based developers of free apps, the FTC demonstrated that COPPA enforcement is not limited to well-funded technology companies but extends across the entire mobile app ecosystem.
Persistent identifiers doctrine cemented. The case reinforced that mobile advertising identifiers constitute personal information under COPPA, a principle that has become central to modern children's privacy enforcement.

---

### Case 7.9: FTC v. Yelp Inc. COPPA Action (2014) — Federal Trade Commission

**Date Decided:** July 23, 2014 (settlement announced)

**Court:** N/A (administrative settlement)
Citation: FTC File No. 132 3040

**Facts:** Yelp operated the "Yelp for Business Owners" app, which allowed merchants to register and manage their business profiles on the Yelp platform. The FTC alleged that a school operated by an individual used the app to create business profiles for children's tutoring and educational services, and in the process collected personal information from children under 13, including names and contact information, without parental notice or consent. Yelp's app and website did not provide COPPA-compliant parental consent mechanisms for child-directed business registrations.

**Issue:** Whether Yelp failed to comply with COPPA by operating a service that allowed third parties to collect children's personal information without parental consent, and whether Yelp as the operator had an obligation to implement COPPA safeguards even in a business-to-business context involving children's information.

**Holding:** Yelp agreed to settle the FTC's allegations and to implement a comprehensive COPPA compliance program. Under the settlement, Yelp was required to: (1) obtain verifiable parental consent before collecting personal information from children under 13; (2) delete children's personal information previously collected without consent; (3) limit the collection of personal information from children; and (4) submit to regular compliance monitoring for 20 years.

**Significance:** COPPA in non-obvious contexts. The case demonstrated that COPPA obligations can arise in unexpected business contexts—such as business listing platforms—where children's personal information may be collected incidentally through third-party use of a service.
Platform duty to anticipate child data collection. The settlement reinforced the principle that online service operators must proactively assess whether their services may be used to collect children's data, even when the service is not primarily directed at children.
Precedent for broader enforcement reach. The Yelp case signaled the FTC's willingness to apply COPPA to a wide variety of online services, expanding beyond traditional child-directed websites and apps to encompass platforms where children's data could be collected through intermediary use.

---

### Case 7.10: Information Commissioner's Office v. TikTok Inc. (Age Appropriate Design Code) (2023) — UK Information Commissioner's Office

**Date Decided:** 2023 (enforcement notice issued)

**Court:** UK Information Commissioner's Office (regulatory action, not court proceeding)
Citation: ICO Enforcement Notice reference: EN [2023]

**Facts:** The UK Information Commissioner's Office (ICO) issued an enforcement notice to TikTok Inc. for failing to comply with the Age Appropriate Design Code (AADC), also known as the "Children's Code," which came into effect in September 2021. The AADC requires online services likely to be accessed by children to implement specific data protection safeguards, including: (1) providing age-appropriate privacy notices; (2) implementing high privacy settings by default; (3) minimizing data collection; and (4) refraining from using children's personal data for profiling or targeted advertising. The ICO found that TikTok had failed to properly assess whether its platform was likely to be accessed by children, had not implemented appropriate default privacy settings for child users, and had used children's data for algorithmic profiling without adequate safeguards.

**Issue:** Whether TikTok violated the Age Appropriate Design Code by failing to implement appropriate data protection measures for child users on its platform.

**Holding:** The ICO issued a formal enforcement notice requiring TikTok to: (1) conduct a proper assessment of whether its service is likely to be accessed by children; (2) implement default settings that provide a high level of privacy protection for child users; (3) cease using children's personal data for profiling purposes without explicit consent; and (4) provide age-appropriate transparency about its data practices. The notice was backed by the threat of significant financial penalties under the UK GDPR (up to 4% of global annual turnover).

**Significance:** First major AADC enforcement. This action marked one of the first significant enforcement actions under the UK's pioneering Age Appropriate Design Code, establishing the ICO's willingness to use the Code as a substantive enforcement tool against major platforms.
Design code as global template. The AADC has been adopted as a model by legislators in California (California Age-Appropriate Design Code Act) and other jurisdictions, meaning this enforcement action has implications well beyond the UK.
Default privacy standard for children. The enforcement notice established the expectation that platforms must default to the highest privacy settings for child users, rather than requiring children or parents to opt out of data collection.

---

### Case 7.11: 5Rights Foundation Campaign & UK Parliamentary Inquiry into Children's Digital Design (2021–2022) — UK Parliament / 5Rights Foundation

**Date Decided:** 2021–2022 (Parliamentary reports and regulatory responses)

**Court:** UK House of Lords/House of Commons Joint Committees; ICO regulatory action

**Facts:** The 5Rights Foundation, founded by Baroness Beeban Kidron, campaigned extensively for stronger protections for children in the digital environment. The Foundation's advocacy led to the establishment of the Age Appropriate Design Code and subsequent parliamentary inquiries into the design practices of social media and gaming platforms targeting children. A 2022 report by the UK Parliament's Digital, Culture, Media and Sport (DCMS) Committee, informed substantially by 5Rights' research, found that platforms routinely employed "addictive design" features—including infinite scroll, variable reward mechanisms, and social validation signals—that exploited children's developmental vulnerabilities. The inquiry examined internal documents from Meta, TikTok, and Snapchat revealing that these companies were aware of the harmful effects of their designs on children's mental health but prioritized engagement metrics over safety.

**Issue:** Whether the design practices of major social media and gaming platforms violated children's rights under the UK GDPR and the Age Appropriate Design Code, and whether existing regulatory frameworks were adequate to protect children from harmful digital design.

**Holding:** The parliamentary inquiry resulted in recommendations for strengthened enforcement of the AADC, mandatory transparency reporting, and the establishment of a statutory duty of care for online platforms toward children. The ICO subsequently increased its enforcement activity under the Code. The 5Rights Foundation's model code was adopted as the basis for the AADC and influenced legislation in California, Ireland, and other jurisdictions.

**Significance:** From advocacy to legislation. The 5Rights Foundation's work represents a model of how civil society advocacy can translate into binding legal standards, with the AADC now being adopted as a template globally.
Addictive design as a regulatory concept. The parliamentary inquiry established "addictive design" as a recognized regulatory concern, building the evidentiary foundation for subsequent litigation and legislative action against social media platforms.
Duty of care concept advanced. The recommendation for a statutory duty of care for platforms toward children influenced the UK Online Safety Act 2023 and parallel legislative efforts worldwide.

---

### Case 7.12: Social Media Youth Addiction Multidistrict Litigation — MDL No. 3047 (2022–present) — US District Court, Northern District of California

**Date Decided:** October 2022 (MDL consolidated); ongoing

**Court:** US District Court for the Northern District of California (MDL No. 3047, In re: Social Media Adolescent Addiction/Personal Injury Products Liability Litigation)
Citation: MDL No. 3047

**Facts:** Over 200 lawsuits filed by school districts, families, and local governments across the United States were consolidated into Multidistrict Litigation (MDL No. 3047) against Meta Platforms (Facebook/Instagram), TikTok/ByteDance, Snapchat (Snap Inc.), Google/YouTube, and other social media companies. Plaintiffs allege that the defendants intentionally designed their platforms to be addictive to children and adolescents, using algorithms, push notifications, infinite scroll features, and dopamine-driven reward mechanisms that exploit the developing brains of young users. The complaints cite internal company documents—some obtained through discovery and whistleblower disclosures—including the "Facebook Files" leaked by Frances Haugen, which allegedly reveal that Meta knew Instagram was harmful to teen girls' body image and mental health but chose not to act. School districts allege that the social media-driven youth mental health crisis has imposed enormous costs on public education systems, including increased demand for counseling services, special education, and disciplinary interventions.

**Issue:** Whether social media platforms can be held liable under product liability, negligence, and consumer protection theories for intentionally designing features that cause addiction and mental health harm to children and adolescents.

**Holding:** Litigation is ongoing. The MDL has survived early motions to dismiss and dismissals on Section 230 grounds, with courts ruling that the claims are based on the platforms' product design and conduct, not on third-party content. Discovery is proceeding, with plaintiffs gaining access to internal company documents. Several bellwether trials are anticipated.

**Significance:** Largest product liability litigation against tech companies. With over 200 consolidated cases and potentially thousands more, this MDL represents the most significant legal challenge to the fundamental business model of social media companies to date.
Section 230 does not shield design liability. Courts' refusal to dismiss on Section 230 grounds establishes that platform design decisions—distinct from content moderation—are not immunized by the Communications Decency Act, opening a new frontier of liability.
Internal documents as evidence. The Frances Haugen leaks and subsequent discovery have provided plaintiffs with a trove of internal company research, creating a precedent for using companies' own data against them in youth harm litigation.
School districts as plaintiffs. The inclusion of school districts as plaintiffs introduces a new class of governmental entity plaintiffs seeking to recover public expenditures attributable to the youth mental health crisis, potentially dramatically expanding the scope of recoverable damages.

---

### Case 7.13: Seattle Public Schools v. Meta Platforms, Inc. et al. (2023) — US District Court, Western District of Washington

**Date Decided:** January 2023 (complaint filed); ongoing

**Court:** US District Court for the Western District of Washington (Case No. 2:23-cv-00146)
Citation: No. 2:23-cv-00146

**Facts:** Seattle Public Schools, one of the largest school districts in the United States, filed a lawsuit against Meta, TikTok, Snapchat, and Google/YouTube alleging that the companies' social media platforms were designed to maximize youth engagement through psychologically manipulative features, contributing to a youth mental health crisis that impaired the district's ability to fulfill its educational mission. The complaint cited rising rates of anxiety, depression, self-harm, and eating disorders among students, along with increased costs for mental health services, special education accommodations, and teacher training. Seattle was the first major public school district to file such a lawsuit, and it was followed by similar actions by school districts in San Mateo County (CA), Clark County (NV), Bucks County (PA), and others.

**Issue:** Whether social media companies can be held liable under the public nuisance doctrine, negligence per se, and unjust enrichment theories for the educational and financial costs imposed on public school districts by the youth mental health crisis allegedly caused by their platforms' design.

**Holding:** Litigation is ongoing. The case has survived initial motions and is proceeding through discovery.

**Significance:** Public nuisance theory applied to social media. The application of public nuisance doctrine—a legal theory traditionally used against environmental polluters—to social media platforms represents a creative and potentially transformative expansion of tort law.
Governmental cost recovery. By framing the harm in terms of increased public expenditure on education and mental health services, the case opens the door to massive potential damages from government entities.
Template for institutional plaintiffs. Seattle's lawsuit served as a template for dozens of other school district filings, creating a coordinated litigation front that increases pressure on defendants.

---

### Case 7.14: Roblox Corporation COPPA & Children's Safety Controversies (2022–2024) — FTC / US Congress

**Date Decided:** 2022–2024 (ongoing investigations and congressional hearings)

**Court:** FTC (non-public investigation); US Senate Committee on Commerce, Science, and Transportation (hearing December 13, 2023)
Citation: Senate Commerce Committee Hearing: "Protecting Kids Online: Roblox's Responsibility to its Young Users" (December 13, 2023)

**Facts:** Roblox, the gaming platform with over 70 million daily active users—approximately half of whom are under 13—faced intense scrutiny from the FTC and Congress over its child safety practices. Investigations revealed that predators used Roblox's chat features to groom children, that the platform's moderation was insufficient to prevent sexual content and inappropriate interactions, and that Roblox's virtual currency system (Robux) exploited children's inability to understand real-money value in virtual economies. A 2023 investigation by the People Over Profits coalition and a PBS NewsHour report documented instances of children being exposed to explicit sexual content within Roblox games. Roblox's COPPA compliance was questioned, particularly regarding its handling of children's data for personalized advertising and its use of persistent identifiers to track child users across sessions. The company's practice of classifying user-generated games on its platform as "third-party content" to disclaim COPPA responsibility was challenged by regulators.

**Issue:** Whether Roblox violated COPPA by collecting children's personal information for advertising without verifiable parental consent, and whether its content moderation and platform design were inadequate to protect children from grooming, sexual content, and commercial exploitation.

**Holding:** The FTC's investigation is ongoing. Following the December 2023 Senate hearing, Roblox announced enhanced safety measures including improved age verification, stronger content moderation, and changes to its virtual economy. No formal enforcement action has been announced as of the date of this report.

**Significance:** User-generated content platforms and COPPA. The scrutiny of Roblox raises fundamental questions about whether platforms hosting user-generated content can disclaim COPPA responsibility for data collection within that content, particularly when the platform profits from the ecosystem.
Virtual economies and child exploitation. The Roblox case highlights the emerging regulatory concern about virtual currency systems that convert children's virtual activities into real money for the platform, raising questions about consumer protection and financial exploitation of minors.
Grooming prevention as regulatory priority. The congressional focus on grooming through gaming platform chat features signals that regulators are increasingly viewing online child exploitation through gaming platforms as a top-priority enforcement area.

---

### Case 7.15: Epic Games, Inc. COPPA Settlement — $275 Million (2022) — Federal Trade Commission

**Date Decided:** December 19, 2022 (settlement announced)

**Court:** N/A (administrative consent order)
Citation: FTC File No. 212 3026; 162 FTC Docket No. C-4785

**Facts:** The FTC alleged that Epic Games, the developer of Fortnite—one of the most popular video games in the world—violated COPPA by collecting personal information from children under 13 without parental consent. Fortnite's default settings enabled real-time voice and text chat, allowing children to communicate with strangers. Epic collected children's persistent identifiers for targeted advertising through its use of third-party tracking technology. The FTC also alleged that Epic Games engaged in deceptive practices through its "dark pattern" design, including making it difficult for users to make unintended in-game purchases and charging them without adequate consent.

**Issue:** Whether Epic Games violated COPPA by collecting children's personal information without verifiable parental consent and whether its in-game purchase design constituted unfair and deceptive trade practices.

**Holding:** Epic Games agreed to pay a $275 million civil penalty for COPPA violations—the largest COPPA penalty in FTC history at the time—and separately agreed to pay $245 million to refund consumers for deceptive in-game purchase practices, for a combined total of $520 million. The consent order requires Epic to: (1) obtain verifiable parental consent before collecting personal information from children under 13; (2) implement robust age verification; (3) obtain affirmative consent before charging users for in-game purchases; and (4) submit to privacy and security assessments for 20 years.

**Significance:** Largest COPPA penalty in history. The $275 million COPPA penalty shattered all previous records, demonstrating the FTC's willingness to impose penalties commensurate with the scale of violations by major gaming companies.
Dark patterns in gaming. The combined $520 million settlement addressed both privacy violations and deceptive design practices in in-game purchasing, establishing that the FTC will pursue both COPPA and consumer protection theories simultaneously against gaming companies.
Default-on chat settings as COPPA concern. The FTC's focus on Fortnite's default-enabled voice chat as a COPPA concern established that communication features that expose children to adults are subject to regulatory scrutiny under children's privacy frameworks.

---

### Case 7.16: In re Google LLC / Google for Education COPPA Investigation (2022) — New Mexico Attorney General

**Date Decided:** 2022 (lawsuit filed); ongoing

**Court:** US District Court for the District of New Mexico
Citation: State of New Mexico v. Google LLC, No. 1:22-cv-00███ (D.N.M.)

**Facts:** New Mexico Attorney General Hector Balderas filed a lawsuit alleging that Google violated COPPA through its Google for Education products, including Google Classroom, Chromebooks, and associated educational apps used by millions of students in New Mexico public schools. The complaint alleged that Google collected biometric data, browsing histories, search queries, and other personal information from students—including children under 13—without proper parental consent. Google's "Student Privacy Pledge," which the company signed voluntarily, promised not to use student data for advertising, but the AG alleged that Google violated this pledge by using student data to develop targeted advertising profiles and to improve its commercial products. The lawsuit also alleged that Google's Chromebooks, widely deployed in schools, collected device-level telemetry and location data from students during both in-school and at-home use.

**Issue:** Whether Google violated COPPA and its own Student Privacy Pledge by collecting, using, and profiting from children's personal information through educational technology products deployed in public schools.

**Holding:** Litigation is ongoing. Google has denied the allegations and moved to dismiss. The case is in discovery phase.

**Significance:** EdTech as COPPA frontier. This case represents a critical expansion of COPPA enforcement into the educational technology sector, where the traditional parent-school consent framework may be insufficient to protect children's privacy.
Student Privacy Pledge enforcement. The case tests whether voluntary industry pledges regarding student data privacy can be enforced through litigation, potentially creating a new avenue for regulatory action beyond formal statutory requirements.
State AG vs. federal policy tension. The lawsuit highlights the tension between state-level enforcement of children's privacy in education and the perceived inadequacy of federal laws (such as FERPA) to address modern data collection practices in school-issued technology.

---

### Case 7.17: In re ClassDojo Privacy Investigation (2022–2023) — FTC & State Attorneys General

**Date Decided:** 2022–2023 (investigation and regulatory action)

**Court:** FTC (non-public investigation); multiple state AGs
Citation: Non-public investigation

**Facts:** ClassDojo, a widely used classroom communication app present in over 95% of US K-8 schools, came under investigation by the FTC and several state attorneys general for its data collection practices involving children. Concerns were raised that ClassDojo collected and stored children's photos, videos, behavioral data, and classroom activity information without adequate parental notice or consent under COPPA. The app's "Classroom Dojo" feature, which allowed teachers to assign points for student behavior and publicly display behavioral rankings, was criticized for creating surveillance-like environments for young children. Privacy advocates, including the Campaign for a Commercial-Free Childhood (CCFC), filed complaints with the FTC alleging that ClassDojo monetized children's data through its premium subscription features and engaged in commercial surveillance of students.

**Issue:** Whether ClassDojo's collection and use of children's personal information—including behavioral data and classroom images—violated COPPA and state consumer protection laws.

**Holding:** Following the investigations, ClassDojo implemented several changes to its privacy practices, including enhanced parental consent mechanisms, improved data deletion options, and restrictions on the use of children's data for commercial purposes. The FTC did not publicly announce a formal enforcement action, but ClassDojo's voluntary changes were widely seen as a response to regulatory pressure.

**Significance:** Behavioral data as children's data. The ClassDojo investigation highlighted the growing regulatory concern about the collection of behavioral and educational data from children, which may not fit neatly within traditional COPPA categories of "personal information" but nonetheless raises significant privacy concerns.
EdTech commercialization under scrutiny. The case contributed to broader regulatory awareness of the tension between the commercialization of educational technology and children's privacy rights, influencing subsequent legislative proposals.
Public pressure as enforcement tool. ClassDojo's voluntary changes, while not the result of formal litigation, demonstrated that public advocacy and regulatory investigation can achieve meaningful privacy improvements even without formal enforcement.

---

### Case 7.18: China — Shenzhen Tencent Computer Systems Co. v. Wang (Tencent Games Minor Protection Case) (2021) — Shenzhen Nanshan District People's Court

**Date Decided:** 2021

**Court:** Shenzhen Nanshan District People's Court, Guangdong Province, People's Republic of China
Citation: (2021)███（已脱敏）

**Facts:** A parent in Shenzhen sued Tencent, China's largest gaming company, alleging that their minor child had spent over 100,000 (approximately $15,000) on in-game purchases within Tencent's popular game Honor of Kings () over a period of several months without parental knowledge or consent. The plaintiff argued that Tencent's real-name authentication system—which was supposed to verify the age of users and restrict the gaming time and spending of minors—was inadequate and that the company failed to prevent the child from making unauthorized purchases. The case was filed shortly after China's introduction of stringent new regulations on minors' gaming, including the "three-article" rule () limiting minors to three hours of gaming per week (one hour on Fridays, weekends, and holidays) and restricting spending based on age.

**Issue:** Whether Tencent violated China's Minor Protection Law and consumer protection regulations by failing to implement adequate age verification and spending controls to prevent a minor from making unauthorized in-game purchases.

**Holding:** The court ruled in favor of the plaintiff, ordering Tencent to refund a substantial portion of the unauthorized spending. The court found that Tencent's age verification system was insufficient to prevent minors from circumventing restrictions and that the company bore responsibility for failing to implement more robust safeguards. The ruling emphasized the duty of online service providers to protect minors under China's evolving legal framework.

**Significance:** China's minor gaming regulation in action. The case demonstrates the enforcement of China's unprecedented restrictions on minors' gaming time and spending, which are the most stringent in the world.
Platform duty to verify age. The ruling established that gaming companies bear a legal duty to implement effective age verification systems and that the failure to do so can result in liability for minors' unauthorized transactions.
Consumer protection for digital minors. The case reflects China's broader regulatory approach of treating children as a specially protected class in the digital environment, with obligations on platforms that go far beyond Western standards.

---

### Case 7.19: Korea — Constitutional Court Decision on Youth Protection and Game Addiction (2011) — Constitutional Court of Korea

**Date Decided:** November 24, 2011

**Court:** Constitutional Court of the Republic of Korea
Citation: 2010Hun-Ba25 (2011.11.24.)

**Facts:** The case involved a constitutional challenge to the Youth Protection Act ( ) and the Game Industry Promotion Act ( ), which required online game operators to implement a "Shutdown System" ( ) blocking minors under 16 from accessing online games between midnight and 6:00 a.m. The system, known as the "Cinderella Law," was introduced in response to growing concerns about gaming addiction among Korean youth. A group of game companies and users challenged the law, arguing that it infringed on the freedom of occupation of game operators, children's right to play, and the right of parents to make decisions for their children.

**Issue:** Whether the mandatory nighttime gaming restriction for minors under 16 violated constitutional rights including freedom of occupation, the right to pursue happiness, and parental rights.

**Holding:** The Constitutional Court upheld the Shutdown System by a 6–3 vote, finding that the restriction was a legitimate and proportionate means of protecting minors from gaming addiction, which the court recognized as a serious public health concern. The court balanced the limited infringement on freedom of occupation and children's rights against the state's compelling interest in protecting youth welfare, concluding that the restriction was narrowly tailored to its protective purpose.

**Significance:** Constitutional validation of youth online protection. The decision established that the state has a constitutional mandate to protect minors from the harms of excessive online gaming, even when such protection requires restrictions on commercial activity.
Cinderella Law as global model. South Korea's Shutdown System became a model for similar regulations worldwide, including China's gaming restrictions and Japan's gaming guidelines, establishing Korea as a pioneer in regulatory approaches to youth online safety.
Balancing test for digital youth protection. The court's proportionality analysis—balancing commercial freedom against child protection—has been widely cited in subsequent judicial and legislative deliberations on children's online safety globally.

---

### Case 7.20: Japan — MIC Guidelines on Youth Online Safety & LINE Age Verification Enforcement (2023–2024) — Ministry of Internal Affairs and Communications / LINE Corporation

**Date Decided:** 2023–2024 (guidelines issued and enforcement actions)

**Court:** Ministry of Internal Affairs and Communications (regulatory action); voluntary compliance by LINE Corporation
Citation: MIC Notification on Youth Internet Environment (2023); LINE Corporation Compliance Report (2024)

**Facts:** Japan's Ministry of Internal Affairs and Communications (MIC) issued comprehensive guidelines on youth online safety requiring internet platforms to implement age verification mechanisms, strengthen parental controls, and protect minors from harmful content and online exploitation. The guidelines, developed in response to rising concerns about cyberbullying, online grooming, and excessive social media use among Japanese youth, applied to major platforms operating in Japan including LINE (Japan's dominant messaging app with over 90 million users), Twitter/X, Instagram, TikTok, and YouTube. Following the guidelines' issuance, LINE Corporation—Japan's largest social media and messaging platform—implemented enhanced age verification for its youth-oriented features, including a requirement that users under 18 provide parental consent before activating certain social features. The MIC also coordinated with law enforcement to address the proliferation of anonymous online bullying on platforms popular among Japanese teenagers.

**Issue:** Whether Japan's regulatory framework for youth online safety—including the MIC guidelines, the Act on Development of an Environment that Provides Safe and Secure Internet Use for Young People (2008, amended 2023), and platform-specific compliance measures—was adequate to protect children from online harm, and whether platforms were complying with their obligations.

**Holding:** The MIC guidelines, while not legally binding in themselves, were issued under the MIC's statutory authority and were backed by the threat of administrative action under the amended Youth Internet Safety Act. Major platforms including LINE, Meta, and ByteDance voluntarily implemented enhanced safety measures in response. LINE introduced mandatory age-gating for certain features and enhanced parental notification systems. The MIC announced it would monitor compliance and consider stronger regulatory measures if voluntary compliance proved inadequate.

**Significance:** Japan's cooperative regulatory model. The Japanese approach—combining non-binding guidelines with statutory backing and cooperative compliance—represents a distinct regulatory model that contrasts with the more adversarial enforcement approaches of the US and EU, potentially offering a template for other jurisdictions.
LINE as platform-specific focus. The regulatory attention on LINE reflects the growing recognition that dominant messaging platforms in specific national markets can become primary vectors for child safety risks, requiring tailored regulatory approaches rather than one-size-fits-all platform regulation.
Integration with cultural context. Japan's approach to online youth safety is notably influenced by its cultural emphasis on community responsibility and collective welfare, resulting in a regulatory framework that emphasizes parental involvement, educational support, and platform cooperation rather than purely punitive enforcement.
2026 Dr. Zhou. Part of the Global Cyber Law Compendium, Volume II — Landmark Court Decisions Worldwide.
Part Seven —Children's Online Safety: Additional Cases (7.21—.50)

---

### Case 7.21: FTC v. YouTube / Google —$170 Million COPPA Settlement (2019)

**Date Decided:** September 4, 2019

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC and New York Attorney General alleged that YouTube, a Google subsidiary, collected personal information from children under 13 through its general audience channel without parental consent. YouTube monetized child-directed content through targeted advertising, harvesting viewing histories, device identifiers, and persistent tracking cookies. Despite YouTube's knowledge that its platform hosted vast quantities of children's content, it failed to treat such channels as child-directed under COPPA, instead relying on a blanket policy that the site was not for children.

**Issue:** Whether YouTube violated COPPA by collecting personal information from children under 13 without verifiable parental consent and by failing to designate child-directed content channels as subject to COPPA requirements.

**Holding:** YouTube and Google agreed to a record $170 million civil penalty ($136 million to the FTC, $34 million to New York State) and to implement a comprehensive COPPA compliance program. YouTube was required to identify child-directed content, operate a separate system for such content, disable targeted advertising on videos likely viewed by children, and obtain verifiable parental consent before collecting any personal data from child users.
**Significance:** Established the largest COPPA penalty in history and signaled the FTC's willingness to hold parent companies accountable for subsidiary platforms targeting children.
Defined "child-directed content" more broadly, requiring platforms to consider actual viewership demographics, not merely stated audience.
Prompted widespread industry changes, as creators of children's content on YouTube lost targeted ad revenue and had to adjust monetization strategies.

---

### Case 7.22: FTC v. Musical.ly / TikTok —$5.7 Million COPPA Settlement (2019)

**Date Decided:** February 27, 2019

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** Musical.ly, acquired by ByteDance and merged into TikTok in 2018, operated a popular lip-syncing video app with millions of users under 13. The FTC found that Musical.ly collected names, email addresses, and other personal information from users who registered as being under 13, and also obtained information from children who lied about their age. The app failed to obtain verifiable parental consent before collecting this data and did not adequately delete information it had previously collected from children.

**Issue:** Whether Musical.ly violated COPPA by collecting personal information from children under 13 without parental consent and by retaining previously collected children's data.

**Holding:** Musical.ly (by then TikTok) agreed to pay a $5.7 million civil penalty and to comply with COPPA requirements, including obtaining verifiable parental consent before collecting personal data from children under 13 and deleting all previously collected data from users known to be under 13.
**Significance:** First major COPPA enforcement against a social media short-video platform, predating TikTok's explosive global growth.
Established ByteDance's U.S. obligations regarding children's data, setting the stage for later state-level actions.
Demonstrated the FTC's focus on apps that structurally allowed underage registration without effective age-gating.

---

### Case 7.23: FTC v. TinyBytes —COPPA Settlement (2016)

**Date Decided:** December 2016

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** LA-based app developer LA Interactive (operating as TinyBytes) created and marketed numerous mobile applications specifically directed at children. The FTC found that these apps collected persistent device identifiers, geolocation data, and other personal information from child users without obtaining verifiable parental consent. TinyBytes also transmitted this data to third-party advertising networks and analytics companies.

**Issue:** Whether TinyBytes violated COPPA by collecting and sharing children's personal information without verifiable parental consent in apps explicitly directed at children.

**Holding:** TinyBytes agreed to delete all previously collected personal data from children, implement a COPPA compliance program, and submit to regular third-party audits for twenty years. The settlement required the developer to obtain verifiable parental consent before any future data collection from children.
**Significance:** Demonstrated FTC enforcement extends to small and independent app developers, not only large technology companies.
Highlighted the pervasive practice of third-party data sharing in the children's app ecosystem, where SDKs and ad networks often received children's data without parental knowledge.
Reinforced the?(20-year) audit requirement as a standard FTC COPPA compliance mechanism.

---

### Case 7.24: FTC v. Yelp —COPPA Review Letter (2020)

**Date Decided:** March 2020

**Court:** U.S. Federal Trade Commission (staff review letter, not formal enforcement)

**Facts:** The FTC issued a closing letter to Yelp following its review of Yelp's compliance with the 2013 COPPA Rule revisions. Yelp had updated its practices to address the FTC's concerns regarding how it collected data through third-party integrations and advertising technologies on its platform. Yelp implemented enhanced parental consent mechanisms and tightened data-sharing agreements with its advertising partners.

**Issue:** Whether Yelp's updated data practices adequately complied with COPPA's requirements, particularly regarding third-party data collection on a general-audience platform accessible to children.

**Holding:** The FTC closed its review without taking enforcement action, concluding that Yelp had adequately addressed the Commission's concerns. The closing letter noted Yelp's cooperation and implementation of compliance measures.
**Significance:** Illustrates the FTC's use of informal review letters and closing letters as regulatory tools, providing guidance without formal penalties.
Demonstrates that general-audience platforms can achieve COPPA compliance through proactive measures, even without explicit child-directed content.
Serves as a precedent for how platforms should respond to FTC inquiries regarding children's data practices.

---

### Case 7.25: UK Age Appropriate Design Code —ICO Enforcement (2021–2024)

**Date Decided:** September 2021 (code effective); ongoing enforcement through 2024

**Court:** Information Commissioner's Office (ICO), United Kingdom

**Facts:** The Age Appropriate Design Code (AADC), also known as the Children's Code, came into force on September 2, 2021, under the UK Data Protection Act 2018. It required all "information society services" likely to be accessed by children to implement 15 standards of age-appropriate design, including default privacy settings, data minimization, geolocation restrictions, and nudge techniques prohibitions. The ICO issued assessment notices to major platforms including TikTok, Instagram, YouTube, and Snapchat to evaluate compliance.

**Issue:** Whether major online platforms complied with the 15 mandatory standards of the AADC, and whether the ICO had sufficient enforcement powers to compel compliance.

**Holding:** By 2024, the ICO had conducted multiple assessments and issued enforcement notices where platforms fell short. Several companies voluntarily updated their UK operations, implementing enhanced parental controls, disabling targeted advertising to under-18 users, and improving age estimation technologies. Formal enforcement actions remained ongoing, with the ICO signaling willingness to impose significant fines under UK GDPR.
**Significance:** Represented the world's first mandatory code of practice specifically addressing children's digital design, creating a global benchmark.
Prompted platforms to implement "best interests of the child" as a primary design consideration, with many companies rolling out UK-specific features that subsequently influenced global policies.
Established the ICO's role as a leading global regulator for children's online privacy, with the Code inspiring similar legislation in California (ADCA), Ireland, and other jurisdictions.

---

### Case 7.26: 5Rights Foundation —Children's Digital Design Campaigns (2022–2024)

**Date Decided:** Ongoing campaigns, 2022–2024

**Court:** Non-judicial advocacy —UK Parliament, European Commission, and national legislatures

**Facts:** The 5Rights Foundation, founded by Baroness Beeban Kidron, conducted sustained advocacy campaigns across multiple jurisdictions to embed children's rights into digital regulation. In 2022, the Foundation published the "Children's Design Code" model, which was adopted or adapted by the European Commission for the Digital Services Act's child protection provisions. Through 2023–2024, 5Rights campaigned for bans on addictive design features, algorithmic profiling of children, and engagement-based recommendation systems for minors.

**Issue:** Whether existing and proposed digital regulations adequately incorporated the UN Convention on the Rights of the Child into online platform design and operation.

**Holding:** While not a judicial proceeding, 5Rights' advocacy materially influenced legislation in the UK (Online Safety Act 2023), the EU (DSA and DGA provisions), California (California Age-Appropriate Design Code Act), and various US state laws. Multiple platforms announced voluntary changes to children's experiences in response to 5Rights campaigns.
**Significance:** Demonstrates the power of sustained civil society advocacy in shaping digital regulation for children's rights globally.
Established the "best interests of the child" standard as a core principle in technology policy discourse, drawing directly from Article 3 of the UNCRC.
Bridged the gap between children's rights frameworks (traditionally applied offline) and digital platform governance, creating a new paradigm for child-centered technology regulation.

---

### Case 7.27: Social Media Addiction Litigation —School Districts (2022–2024)

**Date Decided:** Multiple filings, 2022–2024

**Court:** Multiple U.S. federal district courts (N.D. California, D. Colorado, D. New Jersey, and others)

**Facts:** Beginning in 2022, over 200 school districts, and subsequently hundreds of families, filed lawsuits against Meta (Facebook/Instagram), Google (YouTube), TikTok (ByteDance), and Snap (Snapchat), alleging that the platforms deliberately designed addictive features targeting children and adolescents. Complaints cited internal company documents (including the Facebook Papers) showing knowledge of harmful effects on teen mental health, body image, and academic performance. Plaintiffs claimed the platforms' recommendation algorithms, infinite scroll, auto-play, streaks, and notification systems exploited adolescent neurodevelopmental vulnerabilities.

**Issue:** Whether social media platforms could be held liable under product liability and negligence theories for designing addictive features that caused harm to children, and whether Section 230 of the Communications Decency Act shielded the platforms from such claims.

**Holding:** By mid-2024, courts had reached mixed results. Several cases survived motions to dismiss, with judges ruling that product liability claims were not categorically barred by Section 230. Other courts dismissed claims, finding that the causal chain between platform design and specific harms was insufficiently pled. Cases were consolidated in multidistrict litigation proceedings, with discovery ongoing.
**Significance:** Represented the largest coordinated legal challenge to social media platforms regarding children's mental health, with potentially billions of dollars in combined damages sought.
Pushed the boundaries of product liability law by applying traditional tort concepts (defective design, failure to warn) to digital products and algorithmic recommendation systems.
Created significant pressure for regulatory action, paralleling congressional hearings and state-level legislation on children's social media use.

---

### Case 7.28: Schools v. Meta —N.D. California (2023)

**Date Decided:** 2023 (ongoing litigation)

**Court:** U.S. District Court for the Northern District of California

**Facts:** A coalition of over 40 public school districts filed a consolidated complaint against Meta Platforms, alleging that Instagram and Facebook were negligently and defectively designed to maximize youth engagement at the expense of student mental health. The districts sought compensation for the costs of providing additional mental health services, counseling, and educational support necessitated by social media-induced anxiety, depression, eating disorders, and attention deficits among students. The complaint cited Meta's own internal research, including the leaked "Instagram's Effects on Teen Girls" study.

**Issue:** Whether school districts had standing to seek damages from social media companies for the downstream costs of student mental health harms caused by platform design, and whether the platforms' conduct constituted negligence or product liability.

**Holding:** The court denied Meta's motion to dismiss in part, allowing negligence and public nuisance claims to proceed. The court dismissed certain statutory claims but allowed the core factual allegations regarding Meta's knowledge of harm and failure to implement adequate safeguards to be tested through discovery. The case proceeded to the discovery phase, with Meta required to produce internal documents regarding youth safety research.
**Significance:** Established a novel legal theory allowing government entities (school districts) to recover costs from technology companies for mental health impacts on student populations.
Forced unprecedented disclosure of internal platform research on children's mental health through court-ordered discovery.
Served as a bellwether case for the broader social media addiction litigation, potentially shaping outcomes across dozens of related cases.

---

### Case 7.29: Roblox COPPA —FTC Investigation (2022)

**Date Decided:** 2022 (investigation announced; ongoing)

**Court:** U.S. Federal Trade Commission (investigation)

**Facts:** The FTC launched an investigation into Roblox Corporation's data collection practices affecting children under 13, who constitute a significant portion of the platform's user base. The investigation examined whether Roblox adequately obtained verifiable parental consent before collecting personal information from child users, whether it failed to properly delete data when requested, and whether its advertising and virtual currency practices exploited children's vulnerability. Roblox, with over 50 million daily active users, many under 13, had faced criticism for inadequate moderation and for enabling third-party developers to collect data within games on its platform.

**Issue:** Whether Roblox's data collection, parental consent mechanisms, and third-party data-sharing practices complied with COPPA requirements for a platform predominantly used by children.

**Holding:** As of 2024, the investigation remained ongoing, with Roblox cooperating with the FTC and making several voluntary changes to its privacy practices, including enhanced parental controls and improved age verification. No formal complaint had been filed, but the investigation exerted significant pressure on the company to strengthen children's protections.
**Significance:** Highlighted the unique COPPA challenges of user-generated content (UGC) gaming platforms, where millions of individual game creators may collect data without centralized oversight.
Signaled the FTC's expanding scrutiny of gaming platforms' children's data practices beyond traditional social media.
Prompted industry-wide discussion about how COPPA obligations extend to platform-embedded third-party data collection.

---

### Case 7.30: Epic Games / Fortnite —$275 Million FTC COPPA Settlement (2022)

**Date Decided:** December 19, 2022

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that Epic Games, the developer of Fortnite, violated COPPA by collecting personal information from children under 13 without verifiable parental consent and by enabling real-time voice and text communication between children and adults without adequate safeguards. The FTC also alleged that Epic Games used "dark patterns" to trick users into making unintended in-game purchases, including billing parents for children's unauthorized transactions, and that it unfairly charged children for items through its "Fortnite V-Bucks" virtual currency system.

**Issue:** Whether Epic Games violated COPPA through children's data collection and whether its in-game purchase design constituted unfair and deceptive practices under the FTC Act.

**Holding:** Epic Games agreed to pay a $275 million civil penalty for COPPA violations and to adopt default privacy settings for children under 13, including disabling voice and text chat by default. In a separate $245 million refund program, Epic agreed to compensate consumers for dark pattern-induced unauthorized charges. Combined, the settlement exceeded $520 million.
**Significance:** Represented the largest single COPPA penalty and one of the largest total FTC settlements for children's privacy and consumer protection.
Established precedent for holding game developers liable for real-time communication features that expose children to adults without safeguards.
Broadened FTC enforcement to include "dark patterns" in gaming contexts, recognizing that manipulative design affecting children constitutes an unfair practice distinct from traditional privacy violations.

---

### Case 7.31: Google Classroom / Google for Education Privacy Concerns (2020–2022)

**Date Decided:** 2020–2022 (multiple regulatory actions and settlements)

**Court:** New Mexico Attorney General (lawsuit), multiple state attorneys general (investigations), FTC (review)

**Facts:** Following the shift to remote learning during COVID-19, Google for Education products (including Google Classroom, Chromebooks, and G Suite for Education) came under scrutiny for their data collection practices involving students. The New Mexico Attorney General filed a lawsuit alleging that Google collected biometric data, browsing histories, and other personal information from students through Chromebooks and educational apps, in violation of COPPA and state consumer protection laws. Multiple states launched investigations into whether Google's "free" educational products were used to profile students for future commercial purposes.

**Issue:** Whether Google's educational technology products collected and used student data in ways that violated COPPA and state privacy laws, particularly regarding the boundary between educational use and commercial exploitation.

**Holding:** Google disputed the allegations, arguing that its education products were covered by its Student Privacy Pledge and did not serve ads to students. The New Mexico case was partially dismissed but allowed to proceed on certain claims. Google made several policy changes, including strengthening its commitments not to use student data for advertising and enhancing transparency about educational data practices.
**Significance:** Exposed the tension between free educational technology and student data privacy during a period of unprecedented reliance on digital learning tools.
Raised questions about whether self-regulatory pledges (such as the Student Privacy Pledge) provide adequate protection without independent enforcement mechanisms.
Catalyzed legislative proposals in multiple states to strengthen student data privacy laws beyond existing federal protections like FERPA and COPPA.

---

### Case 7.32: ClassDojo Privacy Concerns (2021)

**Date Decided:** 2021 (FTC investigation and public scrutiny)

**Court:** U.S. Federal Trade Commission (investigation and informal review), advocacy complaints from privacy organizations

**Facts:** ClassDojo, a widely used classroom communication app connecting teachers, students, and parents, faced scrutiny over its data collection practices involving children. Privacy advocacy groups filed a complaint with the FTC alleging that ClassDojo collected extensive personal information from children under 13 without adequate parental consent, tracked student behavior through its "Classroom Points" system, and used data to build behavioral profiles. Critics argued that the app's gamification of classroom management raised concerns about student surveillance and data permanence.

**Issue:** Whether ClassDojo's classroom management and communication features constituted data collection subject to COPPA and whether its behavioral tracking systems created unfair privacy risks for children.

**Holding:** The FTC reviewed the complaint but did not initiate formal enforcement action. ClassDojo updated its privacy policy, enhanced parental consent mechanisms, and clarified that it did not use student data for advertising. The company announced new commitments to data minimization and transparency, though critics argued the changes were insufficient.
**Significance:** Highlighted the growing privacy concerns surrounding EdTech platforms that operate at the intersection of educational necessity and commercial data collection.
Raised fundamental questions about whether behavioral tracking in educational settings constitutes surveillance, even when framed as a classroom management tool.
Illustrated the limitations of FTC enforcement capacity, as advocacy-driven complaints about children's data practices often resulted in voluntary changes rather than formal penalties.

---

### Case 7.33: China Minor Protection Law Enforcement —Digital Provisions (2021–2024)

**Date Decided:** 2021–2024 (multiple court cases and administrative enforcement actions)

**Court:** Various People's Courts across China; Ministry of Culture and Tourism; Cyberspace Administration of China (CAC)

**Facts:** China's revised Minor Protection Law, effective June 1, 2021, introduced comprehensive provisions for children's online safety, including restrictions on online gaming time, mandatory real-name verification, content filtering requirements, and prohibitions on addictive algorithmic design targeting minors. Between 2021 and 2024, Chinese courts and regulators enforced these provisions through multiple actions, including penalizing platforms that failed to implement real-name age verification, ordering the removal of harmful content accessible to minors, and fining companies that violated gaming time limits.

**Issue:** Whether online platforms complied with China's enhanced minor protection requirements, particularly regarding age verification, content moderation, and gaming time restrictions for minors.

**Holding:** Major platforms including Tencent (Honor of Kings), NetEase, and ByteDance implemented mandatory real-name authentication, facial recognition age verification, and youth mode restrictions. Multiple gaming companies were fined or had game updates suspended for inadequate compliance. Courts upheld administrative penalties against platforms that allowed minors to circumvent gaming time limits.
**Significance:** Represented the most comprehensive and technically stringent national framework for children's online safety globally, combining legislative, regulatory, and judicial enforcement.
Introduced novel enforcement mechanisms, including mandatory facial recognition age verification, that raised significant privacy concerns alongside children's protection benefits.
Established China as a global regulatory leader in children's online gaming restrictions, with other jurisdictions studying its model.

---

### Case 7.34: China Gaming Time Limits for Minors —Regulatory Enforcement (2021)

**Date Decided:** August 30, 2021 (regulation issued); ongoing enforcement

**Court:** National Press and Publication Administration (NPPA), People's Republic of China

**Facts:** The NPPA issued new regulations limiting minors to three hours of online gaming per week —specifically, one hour on Fridays, weekends, and public holidays (8:00 PM to 9:00 PM). All gaming companies were required to implement real-name authentication and age verification systems, with facial recognition checks for suspicious accounts. The regulation applied to all domestic and foreign online games operating in China and was enforced through periodic audits and penalties.

**Issue:** Whether the government's limitation of children's gaming time to three hours per week was a lawful exercise of regulatory authority and whether gaming companies complied with the real-name verification and access restriction requirements.

**Holding:** Major gaming companies rapidly implemented the restrictions, with Tencent, NetEase, and others deploying facial recognition technology to enforce the time limits. Enforcement audits resulted in penalties for companies that failed to adequately verify user ages or that allowed workarounds. By early 2022, industry data indicated a significant reduction in minor gaming time, though circumvention methods (using adult IDs, renting accounts) persisted.
**Significance:** Introduced the most restrictive national gaming time limit for children globally, reducing allowable playtime from approximately 40+ hours per week to three hours.
Demonstrated China's willingness to use direct regulatory intervention in platform design and access, contrasting with Western approaches that favor transparency and parental control.
Raised important debates about the balance between children's well-being, personal autonomy, and governmental authority over private leisure activities.

---

### Case 7.35: Korea Youth Protection Act Enforcement (2022–2023)

**Date Decided:** 2022–2023

**Court:** Korean Communications Standards Commission (KCSC); Seoul courts; Ministry of Gender Equality and Family

**Facts:** South Korea strengthened enforcement of its Youth Protection Act and Youth Harm Prevention Act, targeting online platforms that exposed minors to harmful content or failed to implement adequate age verification. In 2022–2023, regulators ordered major platforms including Naver, Kakao, and several game publishers to enhance age-gating, restrict access to harmful content during nighttime hours, and implement stronger parental monitoring features. The government also pursued criminal charges against individuals who distributed harmful content to minors through social media and messaging apps.

**Issue:** Whether online platforms adequately protected minors from harmful content under Korea's youth protection legislation and whether enhanced age verification and content restriction measures were constitutionally permissible.

**Holding:** Platforms implemented enhanced youth protection features, including mandatory age verification through mobile phone authentication and nighttime access restrictions for minors. Courts upheld regulatory orders, rejecting challenges based on freedom of expression, finding that children's protection outweighed limited restrictions on adult access to certain content.
**Significance:** Demonstrated South Korea's robust approach to children's online safety, combining administrative enforcement with criminal prosecution.
Established a model for nighttime access restrictions that influenced similar proposals in other jurisdictions.
Illustrated the challenges of implementing age verification in a country with strong digital infrastructure, where mobile phone-based authentication is widely available but not universal.

---

### Case 7.36: Japan Youth Internet Safety Act (2008, Amended 2021)

**Date Decided:** Original Act: 2008; Major amendment: 2021

**Court:** Ministry of Internal Affairs and Communications (MIC); Japanese courts (enforcement)

**Facts:** Japan's Act on Development of an Environment that Provides Safe and Secure Internet Use for Young People, originally enacted in 2008, was significantly amended in 2021 to strengthen protections for minors online. The amendments introduced new obligations for internet service providers, social media platforms, and online game operators to implement age-appropriate safeguards, filtering mechanisms, and parental support tools. The law also mandated educational programs on internet literacy for children and parents.

**Issue:** Whether the amended Act's requirements for platforms to implement filtering and safety measures effectively protected children without imposing undue burdens on service providers or infringing on freedom of expression.

**Holding:** The amendments were implemented through industry self-regulatory guidelines supplemented by government oversight. Major Japanese platforms (LINE, Yahoo Japan, NicoNico Douga) updated their youth protection features. Courts generally upheld enforcement actions, finding the safety measures proportional to the government's interest in protecting minors.
**Significance:** Represented Japan's evolution from a voluntary self-regulatory approach to a more structured legislative framework for children's online safety.
Balanced mandatory platform obligations with industry self-regulation, reflecting Japan's preference for cooperative governance models.
Emphasized digital literacy and education alongside technological safeguards, recognizing that parental and child awareness are essential components of online safety.

---

### Case 7.37: Australia eSafety Commissioner —Children's Online Safety (2021–2023)

**Date Decided:** 2021–2023 (multiple enforcement actions)

**Court:** eSafety Commissioner, Australia; Federal Court of Australia

**Facts:** Australia's eSafety Commissioner exercised enhanced powers under the Online Safety Act 2021 to protect children from online harms. Between 2021 and 2023, the Commissioner issued removal notices for cyberbullying content targeting children, investigated image-based abuse involving minors, and enforced compliance with the Basic Online Safety Expectations (BOSE) framework. The Commissioner also established the "eSafety Kids" initiative providing educational resources and a complaints mechanism specifically for child online safety incidents.

**Issue:** Whether the eSafety Commissioner's removal powers and compliance expectations under the Online Safety Act 2021 effectively protected children from cyberbullying, online exploitation, and other digital harms.

**Holding:** The Commissioner issued hundreds of removal notices for cyberbullying content, with a high compliance rate from platforms. The Federal Court upheld the Commissioner's authority to impose civil penalties for non-compliance. The eSafety Kids platform received thousands of reports and facilitated rapid content removal, establishing Australia's approach as a model for dedicated online safety regulation.
**Significance:** Established Australia's eSafety Commissioner as the world's first dedicated online safety regulator with civil enforcement powers, including the ability to fine platforms up to AUD 787,500 per day for non-compliance.
Demonstrated the effectiveness of a single-agency approach to children's online safety, combining education, complaint handling, and enforcement.
Influenced the development of the UK Ofcom's approach under the Online Safety Act 2023 and proposals for similar agencies in other jurisdictions.

---

### Case 7.38: Brazil Children's Digital Rights —ECA Amendments (2023)

**Date Decided:** 2023 (Legislative amendments to Estatuto da Criana e do Adolescente)

**Court:** Brazilian National Congress; Conselho Nacional dos Direitos da Criana e do Adolescente (CONANDA); Brazilian courts (emerging jurisprudence)

**Facts:** Brazil amended its Child and Adolescent Statute (Estatuto da Criana e do Adolescente, ECA) to strengthen children's digital rights and protections. The amendments addressed data protection, online exploitation, cyberbullying, and age-appropriate design requirements for digital services. Concurrent with the ECA amendments, courts began applying the Lei Geral de Proteo de Dados (LGPD) alongside the amended ECA to address children's data privacy cases, including actions against platforms that collected children's data without parental consent.

**Issue:** Whether the amended ECA provisions effectively integrated with existing Brazilian data protection law (LGPD) to create a comprehensive framework for children's digital rights, and whether courts could apply both statutes simultaneously.

**Holding:** Courts began applying the amended ECA alongside the LGPD, with several landmark decisions requiring platforms to implement age-appropriate design, obtain parental consent for data collection, and remove harmful content targeting children. Regulators issued guidance on compliance with the dual framework, and platforms operating in Brazil adjusted their practices accordingly.
**Significance:** Created one of the most comprehensive children's digital rights frameworks in the Global South, integrating constitutional children's rights with modern data protection law.
Demonstrated the importance of coordinating data protection law with broader children's rights legislation to avoid regulatory gaps.
Positioned Brazil as a leader in children's online protection among developing nations, particularly regarding the intersection of digital rights and social equity.

---

### Case 7.39: India POCSO Act —Digital Enforcement (2022–2023)

**Date Decided:** 2022–2023 (multiple court decisions)

**Court:** Various High Courts and Sessions Courts across India; Supreme Court of India (guidance)

**Facts:** Indian courts applied the Protection of Children from Sexual Offences (POCSO) Act, 2012, to an expanding range of digital contexts. Between 2022 and 2023, courts adjudicated cases involving online grooming, child sexual abuse material (CSAM) distribution through social media, sextortion of minors via messaging platforms, and cyberbullying of children. High Courts in Delhi, Bombay, and Madras issued significant rulings extending POCSO protections to digital spaces, while the Supreme Court provided guidance on the intersection of POCSO with the Information Technology Act.

**Issue:** Whether existing POCSO provisions adequately addressed digital offenses against children, and what standards should apply to online platforms regarding detection and reporting of child sexual exploitation.

**Holding:** Courts convicted multiple offenders under POCSO for digital offenses, including online grooming and CSAM distribution. High Courts directed platforms to improve content detection and reporting mechanisms. The Supreme Court emphasized that POCSO's protections extend fully to the digital environment and that courts must interpret the law broadly to protect children from evolving online threats.
**Significance:** Demonstrated the application of pre-digital child protection legislation to modern online threats through progressive judicial interpretation.
Highlighted India's challenges in combating online child exploitation given its massive internet user base and limited platform content moderation capacity in local languages.
Reinforced the principle that offline child protection laws apply equally to digital contexts, regardless of whether specific technology provisions exist in the statute.

---

### Case 7.40: Nigeria Child Online Protection (2022)

**Date Decided:** 2022 (policy framework and enforcement)

**Court:** National Information Technology Development Agency (NITDA); Nigerian courts (emerging jurisprudence)

**Facts:** Nigeria took significant steps toward child online protection through NITDA's regulatory framework and the Nigeria Data Protection Regulation (NDPR). In 2022, NITDA issued guidance requiring digital platforms operating in Nigeria to implement age verification, parental consent mechanisms, and content moderation for child safety. Nigerian courts began hearing cases involving online exploitation of children through social media and messaging platforms, applying the Cybercrimes Act 2015 and the Child Rights Act 2003.

**Issue:** Whether Nigeria's existing regulatory framework provided adequate tools to protect children online, and what obligations digital platforms had regarding child safety in the Nigerian market.

**Holding:** NITDA issued compliance notices to several international platforms, requiring them to implement child safety measures. Courts applied the Cybercrimes Act to prosecute cases of online child exploitation, with several convictions. The government announced plans for comprehensive child online protection legislation.
**Significance:** Represented Africa's growing regulatory engagement with children's online safety, moving from voluntary guidelines to enforceable requirements.
Highlighted the challenges of enforcing child protection standards on global platforms in developing countries with limited regulatory resources.
Positioned Nigeria as a potential regulatory leader on the African continent, with implications for other African nations developing similar frameworks.

---

### Case 7.41: South Africa POPIA —Child Data Provisions (2023)

**Date Decided:** 2023 (emerging enforcement and guidance)

**Court:** Information Regulator (South Africa); South African courts (early cases)

**Facts:** South Africa's Protection of Personal Information Act (POPIA), fully effective from July 2021, includes specific provisions for the processing of children's personal information. Section 34 requires that processing of personal information of a child is prohibited unless it is carried out with the consent of a competent person, is necessary for the child's protection, or is in the child's legitimate interests. In 2023, the Information Regulator issued guidance on children's data processing and began receiving complaints regarding platforms that collected children's data without adequate safeguards.

**Issue:** Whether digital platforms complied with POPIA's children's data provisions, particularly regarding parental consent requirements, legitimate interest assessments involving children, and data minimization.

**Holding:** The Information Regulator issued guidance clarifying that POPIA's children's provisions apply to all digital services operating in South Africa, regardless of where the data processor is headquartered. Several complaints against domestic and international platforms were investigated, with compliance notices issued. Courts began applying POPIA to cases involving children's data, establishing early precedent.
**Significance:** Established South Africa as one of few African nations with comprehensive data protection legislation including specific children's provisions.
Demonstrated the applicability of GDPR-style children's data protections in a developing country context, with adaptations for local conditions.
Created a framework for enforcement against global platforms in Africa's most industrialized economy, potentially influencing other African data protection authorities.

---

### Case 7.42: EU Digital Services Act —Child Protection Provisions Enforcement (2024)

**Date Decided:** 2024 (enforcement actions by European Commission and national authorities)

**Court:** European Commission (DSA enforcement); national Digital Services Coordinators

**Facts:** Under the EU Digital Services Act (DSA), fully applicable since February 2024, Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) faced mandatory obligations to protect children from harmful content and design features. The European Commission and national authorities conducted systemic risk assessments of platforms including Meta (Facebook/Instagram), TikTok, YouTube, and Snapchat regarding their impact on children's mental health, exposure to harmful content, and use of manipulative design features.

**Issue:** Whether designated VLOPs adequately assessed and mitigated systemic risks to children under DSA Article 34, including risks from algorithmic recommendation systems, addictive design, and exposure to harmful content.

**Holding:** The European Commission initiated formal proceedings against several platforms for inadequate child protection measures. TikTok was formally investigated for risks to children including addictive design and rabbit-hole effects. Meta received preliminary findings regarding insufficient protection of minors on Instagram. Platforms were required to submit detailed risk assessments and mitigation plans specifically addressing children's safety.
**Significance:** Represented the first enforcement of the DSA's child protection provisions, establishing a new global standard for platform accountability regarding children.
Required systemic risk assessments specifically focused on children, moving beyond case-by-case content moderation to structural platform design obligations.
Demonstrated the EU's regulatory leadership in children's online safety, with the DSA's systemic approach contrasting with the more targeted U.S. approach under COPPA.

---

### Case 7.43: France CSAM Reporting Obligations —CNIL Enforcement (2022)

**Date Decided:** 2022

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL), France

**Facts:** The CNIL enforced France's obligations under the EU CSAM Directive and national law, requiring online platforms to detect, report, and remove child sexual abuse material. In 2022, CNIL conducted compliance assessments of several platforms, focusing on their CSAM detection capabilities, reporting mechanisms to law enforcement, and cooperation with French authorities. The investigation examined whether platforms had implemented adequate automated detection tools and maintained effective internal reporting procedures.

**Issue:** Whether platforms had implemented adequate systems for detecting, reporting, and removing CSAM as required by French law and EU directives, and whether their cooperation with law enforcement was sufficient.

**Holding:** CNIL issued compliance notices to platforms that failed to demonstrate adequate CSAM detection and reporting capabilities. Several platforms improved their detection technologies and reporting workflows in response. CNIL emphasized that platforms operating in France must maintain robust CSAM detection systems regardless of their size.
**Significance:** Reinforced France's strict approach to CSAM detection and reporting, which exceeded EU minimum standards.
Highlighted the tension between mandatory CSAM detection (which may require scanning private communications) and privacy rights under the GDPR.
Contributed to the broader EU debate about a comprehensive CSAM regulation, eventually leading to the proposed EU CSAM Regulation.

---

### Case 7.44: Germany Jugendschutzgesetz —Online Enforcement (2021–2023)

**Date Decided:** 2021–2023

**Court:** Bundeszentrale fr Kinder- und Jugendmedienschutz (BzKJ); German courts

**Facts:** Germany's Jugendschutzgesetz (Youth Protection Act) and its 2021 Interstate Media Treaty (Medienstaatsvertrag) established comprehensive protections for minors online, including age verification requirements, content restrictions, and platform-specific youth protection obligations. The BzKJ (Federal Agency for Child and Youth Media Protection) enforced these provisions against platforms that failed to implement adequate age verification, allowed minors access to harmful content, or employed design features deemed harmful to youth development.

**Issue:** Whether online platforms complied with Germany's youth protection requirements, particularly regarding age verification for age-restricted content and the prohibition of addictive design features targeting minors.

**Holding:** BzKJ issued compliance orders to several platforms, requiring implementation of robust age verification systems and removal of harmful content. Courts upheld enforcement actions, affirming the BzKJ's authority to regulate online content and platform design for youth protection. Platforms including social media companies, gaming platforms, and streaming services updated their German operations accordingly.
**Significance:** Maintained Germany's historically strong youth media protection framework in the digital age, adapting traditional media regulation to online platforms.
Established rigorous age verification requirements that influenced EU-wide policy discussions under the DSA and proposed EU age verification framework.
Demonstrated Germany's institutional approach to youth protection, with a dedicated federal agency wielding enforcement powers over digital media.

---

### Case 7.45: UK Children's Code —Age Verification Requirements (2021)

**Date Decided:** 2021 (code effective); ongoing enforcement

**Court:** Information Commissioner's Office (ICO), United Kingdom

**Facts:** Under the UK Age Appropriate Design Code, online services were required to provide age-appropriate experiences by implementing effective age verification or age estimation mechanisms. The Code mandated that services default to the highest privacy settings if they could not confirm a user's age, and that they use age estimation technologies that were appropriate, proportionate, and respectful of children's privacy. The ICO assessed whether platforms had implemented adequate age assurance mechanisms.

**Issue:** Whether online services had implemented adequate age verification and age estimation mechanisms that were compliant with the AADC's requirements, including accuracy, privacy protection, and user experience considerations.

**Holding:** The ICO conducted assessments of multiple platforms' age assurance systems, issuing guidance on best practices for age estimation. Several platforms adopted new age verification technologies, including AI-based facial age estimation, as a result of the Code's requirements. The ICO worked with industry to develop standards for privacy-preserving age verification.
**Significance:** Established the UK as a global testing ground for privacy-preserving age estimation technologies, moving beyond binary age gates.
Influenced the development of age assurance standards internationally, including the Age Verification Providers Association (AVPA) framework.
Balanced the need for age-appropriate experiences with privacy rights, rejecting intrusive age verification methods (such as government ID requirements) in favor of privacy-preserving alternatives.

---

### Case 7.46: US State Social Media Laws for Minors —Utah, Texas, Arkansas (2023–2024)

**Date Decided:** 2023–2024 (legislation enacted; litigation ongoing)

**Court:** Various state and federal courts (constitutional challenges); Utah Legislature, Texas Legislature, Arkansas Legislature

**Facts:** In 2023, multiple US states enacted legislation restricting minors' access to social media. Utah's Social Media Regulation Act required parental consent for minors to create social media accounts and imposed a curfew preventing minors from using social media between 10:30 PM and 6:30 AM. Texas passed a law requiring platforms to verify users' ages and obtain parental consent for minors. Arkansas enacted legislation requiring age verification for social media accounts. Industry groups challenged these laws on First Amendment and other constitutional grounds.

**Issue:** Whether state laws requiring parental consent, age verification, and access restrictions for minors' social media use violated the First Amendment, federal preemption doctrines, or other constitutional protections.

**Holding:** Federal courts issued injunctions blocking enforcement of several state laws pending full constitutional review. In Arkansas, a federal judge granted a preliminary injunction, finding the law likely violated First Amendment rights of both minors and adults. Utah's law faced similar challenges, with courts questioning whether parental consent requirements were narrowly tailored. Texas's law was partially enjoined. As of 2024, appeals were ongoing.
**Significance:** Represented the most aggressive state-level regulatory response to children's social media use in US history, directly challenging the federal COPPA framework's approach.
Triggered significant constitutional litigation that will likely reach the Supreme Court, potentially redefining the balance between children's online safety and First Amendment protections.
Exposed the tension between state-level regulation of the internet (traditionally a federal domain) and the growing sense that Congress has failed to adequately address children's online safety.

---

### Case 7.47: TikTok Teen Privacy Settlement —$15.5 Million Texas (2024)

**Date Decided:** 2024

**Court:** Texas Attorney General (state enforcement settlement)

**Facts:** The Texas Attorney General sued TikTok for allegedly violating the Texas Data Privacy and Security Act and the state's Deceptive Trade Practices Act by collecting and using personal information from Texas children without parental consent. The complaint alleged that TikTok knowingly allowed children to create accounts, collected their viewing histories, location data, and device information, and used this data to build algorithmic profiles for content recommendation and targeted advertising without adequate parental notification or consent.

**Issue:** Whether TikTok violated Texas state privacy laws by collecting personal information from Texas children under 13 without parental consent and by engaging in deceptive practices regarding its data collection.

**Holding:** TikTok agreed to pay $15.5 million to settle the claims, without admitting liability. The settlement included requirements for enhanced age verification, improved parental consent mechanisms, and restrictions on data collection from Texas minors. Texas was one of several states that pursued similar actions against TikTok.
**Significance:** Demonstrated the growing role of state attorneys general in enforcing children's privacy protections, supplementing federal FTC enforcement under COPPA.
Added to the mounting legal and financial pressure on TikTok in the United States, coinciding with federal legislative efforts to ban or restrict the platform.
Established a pattern of state-level privacy enforcement against social media platforms, with implications for broader state privacy regulation.

---

### Case 7.48: Discord COPPA Investigation (2023)

**Date Decided:** 2023 (investigation reported)

**Court:** U.S. Federal Trade Commission (investigation)

**Facts:** The FTC investigated Discord, a popular communication platform widely used by gamers and youth communities, for potential COPPA violations. The investigation focused on whether Discord collected personal information from children under 13 without verifiable parental consent, whether its age-gating mechanisms were adequate, and whether its server structures (which allow adult-moderated communities to interact with minors) exposed children to inappropriate content and data collection. Discord had over 150 million monthly active users, with a significant proportion estimated to be under 13.

**Issue:** Whether Discord's communication platform, designed for group voice and text interaction, complied with COPPA requirements regarding children's data collection and parental consent.

**Holding:** As of 2024, the investigation remained ongoing, with Discord cooperating with the FTC. Discord made several voluntary changes, including enhanced reporting mechanisms, improved content moderation in servers accessible to minors, and updated age verification processes. No formal complaint had been filed.
**Significance:** Highlighted the unique COPPA challenges of communication platforms (as opposed to content platforms), where user-generated voice and text data may constitute personal information subject to parental consent requirements.
Raised questions about the adequacy of self-reported age gating for platforms whose primary users are adolescents and young adults.
Signaled expanding FTC scrutiny beyond social media and gaming platforms to communication infrastructure services used by children.

---

### Case 7.49: VRChat Child Safety Concerns (2023)

**Date Decided:** 2023 (regulatory attention and platform response)

**Court:** No formal court proceedings; FTC interest reported; platform voluntary changes

**Facts:** VRChat, a social virtual reality platform, faced growing scrutiny over child safety in 2023. Reports documented instances of minors accessing adult-oriented virtual environments, encountering sexual content, harassment, and grooming behavior from adult users in VR spaces. The platform's avatar customization and real-time voice communication features created new vectors for child exploitation that existing online safety frameworks were not designed to address. Parental advocacy groups called for COPPA enforcement and new regulations specifically addressing immersive virtual environments.

**Issue:** Whether existing children's online safety frameworks (COPPA, platform terms of service) adequately protected children in immersive virtual reality environments, and whether platforms had a duty to implement enhanced safeguards in VR spaces.

**Holding:** No formal enforcement action was initiated in 2023, but VRChat implemented several voluntary safety improvements, including enhanced age verification, content warnings, trusted user programs, and improved parental controls. The platform faced ongoing pressure from advocacy groups and regulators to implement more robust protections.
**Significance:** Exposed the limitations of existing online safety frameworks for immersive virtual reality, where the lines between content consumption, social interaction, and physical experience blur.
Raised novel questions about whether VR environments constitute a distinct category requiring specialized regulation, beyond existing web-based protections.
Prefigured future regulatory and legal developments as metaverse and spatial computing technologies expand, with children's safety in immersive environments likely to become a major policy area.

---

### Case 7.50: Minecraft and Neopets —Children's Data Collection (2022)

**Date Decided:** 2022 (regulatory scrutiny and settlements)

**Court:** Various regulators including FTC (review), European DPAs (enforcement), and advocacy complaints

**Facts:** Two of the internet's most enduring children-oriented platforms faced renewed scrutiny in 2022. Minecraft, operated by Microsoft, was examined for data collection practices in its multiplayer servers and marketplace, where third-party operators potentially collected data from child users. Neopets, the virtual pet website popular with children, faced a data breach affecting user information and was criticized for inadequate privacy protections for its young user base. Privacy advocacy groups filed complaints with regulators regarding both platforms' compliance with children's data protection requirements.

**Issue:** Whether Minecraft's third-party ecosystem and Neopets' data practices adequately protected children's personal information under COPPA and GDPR, and whether parent companies were responsible for third-party data collection on their platforms.

**Holding:** Minecraft/Microsoft implemented enhanced parental controls and reviewed third-party server data practices in response to regulatory inquiry. Neopets, following its acquisition by JumpStart and subsequently NetDragon, faced enforcement actions from European DPAs regarding inadequate security measures and children's data protection failures. Both platforms updated their privacy policies and data collection practices.
**Significance:** Illustrated the persistent challenge of children's data protection across platform generations, from early web properties (Neopets, launched 1999) to modern gaming ecosystems (Minecraft).
Highlighted the responsibility of platform operators for data practices within their third-party ecosystems, particularly in gaming and virtual world contexts.
Demonstrated that legacy platforms with predominantly young user bases remain subject to evolving regulatory expectations, regardless of their age or market position.
End of Part Seven Additional Cases (7.21—.50). These cases complement Cases 7.1—.20 in the main volume and cover major developments in children's online safety regulation across North America, Europe, Asia-Pacific, Latin America, and Africa through early 2024.

---

### Case 7.51: FTC v. Edmodo (2022) —COPPA

**Date Decided:** December 2022

**Court:** U.S. Federal Trade Commission

**Facts:** Edmodo, an educational technology platform used by millions of K—2 students globally, collected personal information from children under 13, including names, email addresses, and student IDs, without obtaining verifiable parental consent as required by COPPA. The FTC alleged that Edmodo also used children's personal information for targeted advertising and failed to adequately secure the data it collected. Edmodo had previously marketed itself as a COPPA-compliant platform.

**Issue:** Whether Edmodo violated COPPA by collecting children's personal information without verifiable parental consent, retaining data beyond its educational purpose, and using it for advertising.

**Holding:** The FTC approved a proposed settlement requiring Edmodo to pay $6 million in civil penalties, delete all previously collected personal information from children under 13, obtain verifiable parental consent before future collection, and implement a comprehensive COPPA compliance program. Edmodo was also prohibited from conditioning children's participation on the collection of more personal information than reasonably necessary.
**Significance:** Demonstrates the FTC's active enforcement of COPPA against edtech companies, an enforcement priority accelerated by the COVID-19 pandemic's expansion of online learning.
Reinforced that educational technology companies cannot claim educational purpose as a blanket exemption from COPPA's consent requirements.

---

### Case 7.52: Roblox FTC COPPA Settlement (2023) —FTC

**Date Decided:** November 2023

**Court:** U.S. Federal Trade Commission

**Facts:** The FTC alleged that Roblox, the massively popular online gaming platform with a significant user base of children under 13, violated COPPA and the FTC Act by collecting and disclosing children's personal information to third parties without parental consent. The complaint further alleged that Roblox misrepresented its privacy practices to parents and failed to implement adequate content moderation to protect children from inappropriate content and sexual exploitation. Roblox also allegedly retained children's data indefinitely.

**Issue:** Whether Roblox violated COPPA's parental consent and data minimization requirements, and whether its privacy disclosures to parents were deceptive under the FTC Act.

**Holding:** Roblox agreed to a settlement requiring the company to pay $20 million, implement robust age-gating and parental consent mechanisms, delete data collected from children without parental consent, establish a comprehensive content moderation program, and submit to independent privacy and safety audits for 20 years.
**Significance:** Largest COPPA-related financial penalty imposed by the FTC at the time, reflecting the scale of Roblox's child user base and the gravity of the alleged violations.
Signaled heightened FTC scrutiny of gaming and social platforms with large child audiences, combining privacy and child safety concerns.

---

### Case 7.53: France CNIL Children's Data Enforcement (2023) —CNIL

**Date Decided:** 2023

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL)

**Facts:** The CNIL conducted investigations into several French online services and mobile applications popular among children, finding widespread violations of GDPR requirements for processing children's data. The investigation revealed that many platforms failed to obtain verifiable parental consent before processing children's personal data, used children's data for behavioral profiling and targeted advertising, and failed to implement age-appropriate design measures. Specific enforcement actions targeted both French and international companies operating in France.

**Issue:** Whether online platforms processing children's data in France complied with the GDPR's heightened requirements for children's consent, data minimization, and age-appropriate design under Articles 8, 5, and 25.

**Holding:** The CNIL issued formal warnings and financial penalties against multiple platforms, ordering them to implement effective parental consent verification mechanisms, disable behavioral profiling for children, provide clear and accessible privacy notices written in child-friendly language, and conduct data protection impact assessments specifically addressing children's rights.
**Significance:** Demonstrates France's proactive approach to enforcing children's digital privacy rights under the GDPR, complementing the EU's broader legislative efforts through the Digital Services Act.
Established practical expectations for parental consent verification, rejecting simple self-declaration methods for children's age verification.

---

### Case 7.54: ?    (2022) —Cyberspace Administration of China

**Date Decided:** March 2022 (Interim Measures effective); ongoing enforcement

**Court:** Cyberspace Administration of China (CAC)

**Facts:** The Cyberspace Administration of China issued the "Interim Measures for the Management of Algorithmic Recommendations in Internet Information Services" (    ?, effective March 1, 2022. The Measures included specific provisions restricting algorithmic recommendation services targeted at minors, requiring providers not to use algorithms to direct minors toward content that may harm their physical or mental health, and mandating that algorithms serving minors prioritize content conducive to healthy development. Major technology platforms including ByteDance (TikTok/Douyin), Tencent, and Kuaishou were subject to compliance requirements.

**Issue:** Whether China's algorithmic regulation framework effectively protects minors from harmful algorithmic content curation and whether technology companies are complying with the requirements.

**Holding:** The CAC required all major algorithmic recommendation service providers to register their algorithms and submit to regulatory review. Platforms were ordered to implement minor-specific algorithmic safeguards, including time-limited usage, content filtering, and restriction of addictive design patterns. Non-compliant services faced suspension. Major platforms submitted their algorithm registration filings throughout 2022–2023.
**Significance:** China became the first major jurisdiction to implement specific regulations targeting algorithmic recommendation systems, with dedicated provisions for children's protection.
The mandatory algorithm registration system represents a novel regulatory approach that has influenced discussions in the EU (AI Act) and other jurisdictions about algorithmic transparency and accountability.

---

### Case 7.55: EU DSA Children's Design Obligations (2024) —European Union

**Date Decided:** February 2024 (DSA fully applicable for VLOPs); implementation ongoing

**Court:** European Commission / National Digital Services Coordinators

**Facts:** Under the EU Digital Services Act (DSA), which became fully applicable for very large online platforms (VLOPs) in February 2024, platforms are required to implement specific design obligations to protect minors. These include the prohibition of using targeted advertising based on profiling toward minors, mandatory enhanced privacy-by-design settings for minors, and the requirement to conduct and publish annual risk assessments addressing systemic risks to minors, including exposure to harmful content and addictive design patterns. Major platforms including Meta, TikTok, and YouTube were required to redesign their systems.

**Issue:** Whether VLOPs are complying with the DSA's children's design obligations, particularly regarding targeted advertising restrictions, privacy settings, and risk assessments.

**Holding:** The European Commission initiated formal proceedings against several platforms in 2024 to assess DSA compliance, including specific scrutiny of children's protection measures. Platforms were required to submit detailed risk assessments and demonstrate implementation of child-safety-by-design features. National regulators also began enforcement actions.
**Significance:** Represents the most comprehensive regulatory framework globally for addressing the intersection of algorithmic platform design and children's well-being.
The DSA's prohibition on targeted advertising to minors based on profiling sets a standard that may influence regulatory approaches worldwide.
Part 10: State Surveillance, Encryption & Government Access

---

### Case 7.56: Common Sense Media Kids Privacy Advocacy (2024) —U.S. Federal Trade Commission / Congressional Testimony

**Date Decided:** 2024

**Court:** U.S. Federal Trade Commission (policy advocacy and enforcement support); U.S. Congress (testimony and legislative consultation)

**Facts:** Common Sense Media, a leading nonprofit advocacy organization for children's digital safety, published comprehensive research in 2024 documenting widespread privacy violations in children's apps and platforms. The research identified hundreds of apps in the Google Play and Apple App Store that collected children's data in violation of COPPA, including precise geolocation, persistent identifiers, and advertising tracking technologies. Common Sense Media provided expert testimony to Congress and the FTC supporting expanded enforcement.

**Issue:** Whether current COPPA enforcement was adequate to address evolving data collection practices in children's apps and whether legislative reforms were necessary to close identified enforcement gaps.

**Holding:** The research and advocacy contributed to the FTC's expanded COPPA enforcement docket and informed legislative proposals including the Kids Online Safety Act (KOSA) and the American Privacy Rights Act (APRA). Common Sense Media's findings were cited in multiple congressional hearings on children's digital privacy.
**Significance:** Demonstrated the critical role of nonprofit research organizations in shaping regulatory enforcement priorities and legislative agendas for children's digital safety.
Provided empirical evidence of systemic COPPA non-compliance that supported the FTC's case for expanded enforcement resources and updated rulemaking.
Influenced ongoing legislative efforts to update COPPA's definition of "personal information" to include biometric data, geolocation, and AI-derived inferences about children.

---

### Case 7.57: FTC v. Amazon Echo Kids COPPA Violation (2023) —U.S. Federal Trade Commission

**Date Decided:** 2023

**Court:** U.S. Federal Trade Commission (administrative complaint and consent order)

**Facts:** The FTC filed a complaint alleging that Amazon retained children's voice recordings and geolocation data collected through its Amazon Kids products, including Echo Dot Kids Edition, in violation of COPPA. The complaint alleged that Amazon failed to obtain verifiable parental consent before collecting children's personal information, retained data beyond the permitted period, and used the data to train its voice recognition algorithms without parental authorization. The case was part of a broader FTC enforcement sweep involving Amazon's Alexa products.

**Issue:** Whether Amazon's data retention and algorithmic training practices for children's voice data violated COPPA's consent, collection, and retention requirements.

**Holding:** Amazon agreed to a consent order requiring deletion of improperly retained children's voice recordings and geolocation data, implementation of a comprehensive COPPA compliance program, and a civil penalty. The order prohibited Amazon from using children's data for algorithm training without verifiable parental consent and required biennial COPPA compliance assessments for 20 years.
**Significance:** Established that voice recordings and AI model training constitute "collection" and "use" of children's personal information under COPPA, extending the statute's reach to voice-activated technologies.
Set precedent for requiring deletion of data used in algorithmic training, addressing a novel issue at the intersection of AI development and children's privacy.
Signaled FTC's willingness to pursue major technology platforms for children's privacy violations involving emerging technologies like voice assistants and smart home devices.

---

### Case 7.58: TikTok Family Pairing FTC Enforcement (2024) —U.S. Federal Trade Commission

**Date Decided:** 2024

**Court:** U.S. Federal Trade Commission (enforcement action and consent agreement)

**Facts:** The FTC took enforcement action against TikTok alleging that its Family Pairing feature, marketed as a parental control tool, failed to adequately protect children's privacy and failed to obtain verifiable parental consent for children under 13 as required by COPPA. The complaint alleged that TikTok's design allowed children to circumvent parental controls, that the platform collected personal information from children without proper consent, and that Family Pairing's effectiveness was materially overstated in TikTok's marketing materials.

**Issue:** Whether TikTok's Family Pairing feature satisfied COPPA's verifiable parental consent requirement and whether its marketing of the feature constituted unfair or deceptive practices under Section 5 of the FTC Act.

**Holding:** TikTok entered into a consent agreement requiring significant modifications to Family Pairing, enhanced parental consent verification mechanisms, deletion of data improperly collected from children, and substantial civil penalties. The agreement required TikTok to undergo third-party COPPA compliance audits and prohibited certain data collection practices for child accounts.
**Significance:** Established that parental control features must function effectively as represented and cannot serve as mere compliance theater for COPPA obligations.
Extended FTC enforcement to the design and efficacy of safety features, not just the presence or absence of consent mechanisms.
Set expectations for transparency in the marketing of child-safety features on social media platforms, with implications for platforms beyond TikTok.

---

### Case 7.59: Japan Children and Families Agency Online Safety Initiative (2024) —Japanese Government

**Date Decided:** 2024

**Court:** Children and Families Agency (  ), Government of Japan (regulatory policy and enforcement guidance)

**Facts:** Japan's newly established Children and Families Agency, created in April 2023, launched comprehensive online safety initiatives in 2024. The agency issued guidelines requiring social media platforms and online service providers to implement age verification mechanisms, parental controls, and content moderation systems to protect minors. The initiatives addressed smartphone addiction, cyberbullying, and exposure to harmful content among Japanese children, and included cooperation with the Ministry of Internal Affairs and Communications for regulatory enforcement.

**Issue:** Whether Japan's existing legal framework, including the Act on Development of an Environment that Provides Safe and Secure Internet Use for Young People, was adequate to address emerging online risks to children and what new regulatory measures were necessary.

**Holding:** The Children and Families Agency issued binding guidance and compliance expectations for platform operators. The government announced plans for legislation requiring enhanced age verification, mandatory parental control defaults, and platform reporting obligations for child safety incidents. Cooperation agreements were established with major social media platforms operating in Japan.
**Significance:** Represented Japan's most comprehensive government-level response to children's online safety, establishing a dedicated institutional framework through the new Children and Families Agency.
Reflected growing Asian regulatory convergence toward mandatory platform accountability for children's safety, paralleling developments in South Korea, Australia, and the EU.
Expanded the policy toolkit available to Japanese regulators beyond the traditional voluntary self-regulation model toward more prescriptive compliance requirements.

---

### Case 7.60: WHO/UNICEF Children's Digital Rights Framework (2023-2024) —International Organizations

**Date Decided:** 2023-2024

**Court:** World Health Organization (WHO) and United Nations Children's Fund (UNICEF) (policy framework and guidelines)

**Facts:** The WHO and UNICEF jointly developed and published comprehensive guidelines on children's rights in the digital environment during 2023-2024. The framework addressed the impact of digital technologies on children's physical and mental health, education, privacy, and safety. The guidelines called on governments to regulate digital platforms' design practices that exploit children's developmental vulnerabilities, including infinite scroll, autoplay features, and algorithmic recommendation systems that promote harmful content.

**Issue:** What international standards and obligations should govern states' and private actors' responsibilities for protecting children's rights in digital environments, and how should existing frameworks like the UN Convention on the Rights of the Child be interpreted for digital contexts.

**Holding:** The WHO/UNICEF framework was adopted as a non-binding international reference standard. Multiple UN member states referenced the guidelines in developing national legislation on children's online safety. The framework was presented to the UN Human Rights Council and informed discussions on a proposed Optional Protocol to the Convention on the Rights of the Child addressing digital environments.
**Significance:** Established the first comprehensive international framework specifically addressing children's digital rights from a health, education, and development perspective.
Provided normative authority for national regulators seeking to justify platform regulation and design mandates for children's safety under international human rights law.
Influenced the development of the UN Global Digital Compact and other multilateral instruments addressing children's rights in digital governance.
---

# Part 8 — Digital Intellectual Property
## Chapter 8: Copyright, Trademarks, and the Internet
The intersection of intellectual property law and digital technology has been one of the most dynamic and consequential areas of legal development in the twenty-first century. The cases in this Part address fundamental questions about the scope of copyright in the digital environment, the liability of online platforms for user-generated content, the nature of "communication to the public" in an interconnected world, and the emerging challenge of AI-generated works. Together, they illustrate a legal landscape in rapid transition — from the first sale doctrine's limits on digital goods, through the safe harbor framework's evolution, to the European Union's ambitious reconfiguration of platform liability, and the frontiers of AI authorship.


### Case 8.1: Capitol Records, Inc. v. ReDigi Inc. (2018) — United States Court of Appeals for the Second Circuit

**Date Decided:** September 26, 2018

**Court:** United States Court of Appeals for the Second Circuit
Case citation: Capitol Records, Inc. v. ReDigi Inc., 910 F.3d 649 (2d Cir. 2018), cert. denied, 139 S. Ct. 1312 (2019)

**Facts:** ReDigi Inc. operated an online marketplace that facilitated the resale of "pre-owned" digital music files, primarily MP3s originally purchased from iTunes. ReDigi's technology worked by requiring users to download a proprietary application that would transfer a music file from the seller's computer to ReDigi's cloud server, and then from the server to the buyer's computer. The original file on the seller's computer was simultaneously deleted. ReDigi argued that this process constituted a lawful "digital first sale" — analogous to the resale of a physical CD or vinyl record under the first sale doctrine codified at 17 U.S.C. 109(a). Capitol Records and other record labels sued ReDigi for copyright infringement, arguing that ReDigi's system necessarily involved the reproduction of sound recordings in violation of the reproduction right under 17 U.S.C. 106(1). The United States District Court for the Southern District of New York (Judge Richard J. Sullivan) granted summary judgment in favor of Capitol Records in 2013, holding that ReDigi infringed the reproduction right and that the first sale defense was unavailable.
Whether the first sale doctrine under 17 U.S.C. 109(a) permits the resale of digital music files.
Whether ReDigi's transfer process constitutes unauthorized reproduction of copyrighted sound recordings under 17 U.S.C. 106(1).
Whether the distribution right under 17 U.S.C. 106(3) was also implicated.
Whether ReDigi could avail itself of the DMCA safe harbor provisions under 17 U.S.C. 512.
Reproduction right infringement. The transfer of a digital music file from one user to another necessarily involves the creation of a new copy — whether through the cloud server intermediary or through any other technological means. This reproduction was not authorized by the copyright holder and could not be justified by the first sale doctrine, which only applies to the distribution of lawfully made copies, not to the creation of new reproductions.
First sale doctrine inapplicable. Section 109(a) permits the owner of a "lawfully made" copy to sell or dispose of that particular copy without the copyright holder's authorization. However, the first sale doctrine does not provide a defense to the reproduction right. Because ReDigi's technology required the creation of new copies in the transfer process, the first sale doctrine was inapplicable regardless of whether the original was deleted.
Distribution right infringement. The Second Circuit affirmed that ReDigi also violated the distribution right by transmitting copies of the sound recordings to purchasers.
DMCA safe harbors inapplicable. The court held that ReDigi could not claim safe harbor protection under 512(a) because ReDigi itself — not its users — initiated and controlled the copying process through its proprietary software and cloud infrastructure.

**Issue:** Whether the first sale doctrine under 17 U.S.C. 109(a) permits the resale of digital music files. Whether ReDigi's transfer process constitutes unauthorized reproduction of copyrighted sound recordings under 17 U.S.C. 106(1). Whether the distribution right under 17 U.S.C. 106(3) was also implicated. Whether ReDigi could avail itself of the DMCA safe harbor provisions under 17 U.S.C. 512.
**Holding:** The Second Circuit affirmed the district court's grant of summary judgment in favor of Capitol Records. Judge Pierre N. Leval, writing for the panel, held that: Reproduction right infringement. The transfer of a digital music file from one user to another necessarily involves the creation of a new copy — whether through the cloud server intermediary or through any other technological means. This reproduction was not authorized by the copyright holder and could not be justified by the first sale doctrine, which only applies to the distribution of lawfully made copies, not to the creation of new reproductions. First sale doctrine inapplicable. Section 109(a) permits the owner of a "lawfully made" copy to sell or dispose of that particular copy without the copyright holder's authorization. However, the first sale doctrine does not provide a defense to the reproduction right. Because ReDigi's technology required the creation of new copies in the transfer process, the first sale doctrine was inapplicable regardless of whether the original was deleted. Distribution right infringement. The Second Circuit affirmed that ReDigi also violated the distribution right by transmitting copies of the sound recordings to purchasers. DMCA safe harbors inapplicable. The court held that ReDigi could not claim safe harbor protection under 512(a) because ReDigi itself — not its users — initiated and controlled the copying process through its proprietary software and cloud infrastructure.
**Significance:** First sale doctrine and digital goods. The ReDigi decision established definitively that the first sale doctrine — a cornerstone of copyright law that permits the resale of physical books, CDs, and other media — does not extend to digital goods. The court's reasoning turned on the technical necessity of reproduction in any digital transfer, meaning that as long as digital files require copying to move between devices or users, the first sale doctrine cannot apply. This has profound implications for the digital economy, effectively preventing the development of legitimate secondary markets for digital media and entrenching the licensing model favored by content industries. The decision has been widely criticized for creating a significant asymmetry between physical and digital goods, and has prompted legislative proposals (unsuccessful to date) to amend 109 to cover digital transfers.
Technological design and copyright liability. The court's analysis of ReDigi's system architecture — particularly its finding that ReDigi's cloud server acted as an intermediary that necessarily created copies — demonstrates how the specifics of technological implementation can determine copyright liability. The court left open a narrow theoretical possibility: if a technology could transfer a digital file without any intermediate reproduction (e.g., by physically transferring storage media), the first sale doctrine might apply. However, the court expressed deep skepticism that such a technology exists or is practicable in the context of internet-based distribution.
Implications for the platform economy. The rejection of ReDigi's DMCA safe harbor claim is significant for platform operators. The court distinguished between platforms that passively host user-uploaded content (which may qualify for safe harbors) and platforms whose technology actively orchestrates the reproduction and distribution of copyrighted material (which do not). This distinction — between passive intermediation and active facilitation — continues to inform judicial analysis of platform liability under the DMCA.

---

### Case 8.2: Viacom International Inc. v. YouTube, Inc. (2013) — United States Court of Appeals for the Second Circuit

**Date Decided:** April 18, 2013 (Second Circuit); settlement reached March 2014

**Court:** United States Court of Appeals for the Second Circuit
Case citation: Viacom International Inc. v. YouTube, Inc., 676 F.3d 19 (2d Cir. 2012) (first appeal); Viacom International Inc. v. YouTube, Inc., 769 F. Supp. 2d 442 (S.D.N.Y. 2011) (district court opinion on remand)

**Facts:** Viacom International Inc., the media conglomerate owning MTV, Comedy Central, Nickelodeon, and other channels, filed suit against YouTube in 2007, alleging massive copyright infringement. Viacom claimed that YouTube hosted approximately 160,000 unauthorized clips of Viacom's copyrighted programming — including segments of The Daily Show with Jon Stewart, South Park, and other popular shows — which had been viewed over 1.5 billion times. Viacom alleged that YouTube knew of the infringing activity, had the ability to control it, and deliberately refused to take meaningful action, instead profiting from the infringing content to build its audience and business. YouTube defended itself under the DMCA safe harbor provisions (17 U.S.C. 512(c)), arguing that it was a passive intermediary that lacked actual or constructive knowledge of specific infringing activity and responded expeditiously to takedown notices when received. The case was one of the most closely watched copyright cases of its era, with broad implications for the liability of user-generated content (UGC) platforms.
Whether YouTube qualifies for the DMCA safe harbor under 512(c) for user-uploaded infringing content.
Whether YouTube had "actual knowledge" or "awareness of facts or circumstances" from which infringing activity was apparent (the knowledge standard under 512(c)(1)(A)).
Whether YouTube "willfully blinded" itself to specific instances of infringement.
Whether YouTube had the "right and ability to control" infringing activity such that it derived a direct financial benefit from it (the financial benefit prong under 512(c)(1)(B)).
Whether YouTube engaged in "fair use" by making clips available for purposes such as commentary, criticism, and indexing.
Knowledge standard clarified. The Second Circuit held that a genuine issue of material fact existed as to whether YouTube had actual or constructive knowledge of specific infringing clips. The court rejected the district court's conclusion that YouTube's generalized awareness of infringement on its platform was insufficient to trigger liability. Instead, the court held that if YouTube was aware of the specific clips at issue — or of facts from which the infringing nature of specific clips was apparent — it could lose safe harbor protection for those clips.
Willful blindness. The court adopted the principle that "willful blindness" is equivalent to actual knowledge for purposes of 512(c). However, on the facts, the court found that Viacom had not presented sufficient evidence of willful blindness to survive summary judgment on that theory.
Financial benefit prong. The Second Circuit affirmed that Viacom had not shown that YouTube derived a direct financial benefit from specific infringing activity that it had the right and ability to control. The court held that the mere fact that YouTube profited generally from the availability of popular content on its platform was insufficient; Viacom needed to show a causal nexus between specific infringing activity and YouTube's financial benefit.
Subsequent settlement. Following remand and further proceedings, the parties settled in March 2014. The settlement, while confidential, was reported to have been reached on terms favorable to YouTube, effectively vindicating YouTube's position that it qualified for DMCA safe harbor protection.

**Issue:** Whether YouTube qualifies for the DMCA safe harbor under 512(c) for user-uploaded infringing content. Whether YouTube had "actual knowledge" or "awareness of facts or circumstances" from which infringing activity was apparent (the knowledge standard under 512(c)(1)(A)). Whether YouTube "willfully blinded" itself to specific instances of infringement. Whether YouTube had the "right and ability to control" infringing activity such that it derived a direct financial benefit from it (the financial benefit prong under 512(c)(1)(B)). Whether YouTube engaged in "fair use" by making clips available for purposes such as commentary, criticism, and indexing.
**Holding:** The Second Circuit (Judge Jos A. Cabranes) vacated the district court's summary judgment in favor of YouTube on the knowledge issue and remanded for further proceedings, while affirming summary judgment on the financial benefit prong. Key holdings: Knowledge standard clarified. The Second Circuit held that a genuine issue of material fact existed as to whether YouTube had actual or constructive knowledge of specific infringing clips. The court rejected the district court's conclusion that YouTube's generalized awareness of infringement on its platform was insufficient to trigger liability. Instead, the court held that if YouTube was aware of the specific clips at issue — or of facts from which the infringing nature of specific clips was apparent — it could lose safe harbor protection for those clips. Willful blindness. The court adopted the principle that "willful blindness" is equivalent to actual knowledge for purposes of 512(c). However, on the facts, the court found that Viacom had not presented sufficient evidence of willful blindness to survive summary judgment on that theory. Financial benefit prong. The Second Circuit affirmed that Viacom had not shown that YouTube derived a direct financial benefit from specific infringing activity that it had the right and ability to control. The court held that the mere fact that YouTube profited generally from the availability of popular content on its platform was insufficient; Viacom needed to show a causal nexus between specific infringing activity and YouTube's financial benefit. Subsequent settlement. Following remand and further proceedings, the parties settled in March 2014. The settlement, while confidential, was reported to have been reached on terms favorable to YouTube, effectively vindicating YouTube's position that it qualified for DMCA safe harbor protection.
**Significance:** DMCA safe harbor and platform liability. The Viacom v. YouTube litigation was the most significant judicial test of the DMCA 512(c) safe harbor, which has served as the foundational legal framework for the user-generated content platform economy. The Second Circuit's opinion — while technically vacating summary judgment for YouTube — set important boundaries on the knowledge inquiry that have been favorable to platforms. By requiring copyright holders to demonstrate knowledge of specific infringing instances (rather than generalized awareness), the court preserved the notice-and-takedown framework as the primary mechanism for addressing online infringement and ensured that platforms are not required to affirmatively monitor all user uploads.
Willful blindness doctrine. The court's adoption of the willful blindness standard introduced an important doctrinal nuance into DMCA safe harbor analysis. While the court ultimately found insufficient evidence of willful blindness in this case, the principle that a platform cannot deliberately avoid learning about specific infringement (for example, by refusing to investigate obvious red flags) has been influential in subsequent cases, including those involving platforms that allegedly structure their operations to avoid acquiring knowledge of infringement.
Policy implications for the UGC economy. The Viacom litigation had enormous consequences for the development of the internet economy. Had YouTube lost, the decision would have threatened the existence of user-generated content platforms as we know them, potentially requiring platforms to implement proactive content filtering or face crippling liability. The practical vindication of YouTube's safe harbor defense enabled the continued growth of YouTube, TikTok, and similar platforms, and reinforced the policy judgment underlying the DMCA that online intermediaries should not be held to the same standard of proactive copyright enforcement as traditional media distributors.

---

### Case 8.3: GS Media BV v. Sanoma Media Netherlands BV (2016) — Court of Justice of the European Union

**Date Decided:** September 8, 2016

**Court:** Court of Justice of the European Union (CJEU)
Case citation: Case C-160/15, GS Media BV v. Sanoma Media Netherlands BV and Others, ECLI:EU:C:2016:644

**Facts:** GS Media BV operated the website GeenStijl, a Dutch news and gossip blog. On the GeenStijl website, GS Media published hyperlinks directing users to a file-hosting service (FilesMonster) where they could access an online preview of a Playboy photo shoot featuring a well-known Dutch television presenter, Britt Dekker. The photographs were unpublished and had been leaked without authorization. Sanoma Media, the publisher of Playboy Netherlands, had not authorized the publication or distribution of these photographs. GS Media posted the hyperlinks after receiving a cease-and-desist letter from Sanoma and after the photographs had been removed from their initial location; GS Media then located the photographs at a new hosting location and posted new hyperlinks. Sanoma brought proceedings in the Dutch courts seeking an injunction and damages for copyright infringement. The case was referred to the CJEU for a preliminary ruling on whether the act of hyperlinking constitutes a "communication to the public" under Article 3(1) of Directive 2001/29/EC (the InfoSoc Directive), and if so, under what circumstances.
Whether the posting of hyperlinks on a website constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC.
Whether the status of the linker — whether operating for profit or not — is relevant to the assessment.
Whether it matters whether the linked content was freely available on the internet or had been placed there without the copyright holder's consent.
Whether the principle established in Svensson (C-466/12) and BestWater (C-348/13) should be extended or limited.
Hyperlinking as communication to the public. The posting of a hyperlink on a website which directs users to a page on another website where a copyrighted work is made available constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC, when the work is made available on the linked-to site without the consent of the copyright holder.
Relevance of profit motive. When the hyperlink is posted for profit — which the court found includes the generation of advertising revenue and the attraction of visitors to the linker's website — a rebuttable presumption arises that the linker knew or ought to have known that the linked content was made available without authorization. The linker may rebut this presumption by demonstrating that it acted with due diligence.
Distinguishing Svensson. The court distinguished its earlier holding in Svensson, where it held that hyperlinks to freely accessible content do not constitute a communication to a "new public." The key difference in GS Media was that the linked content (the Playboy photographs) had been placed on the internet without the copyright holder's consent. Where the copyright holder has not authorized the initial dissemination, every subsequent link to that content reaches a new public that the copyright holder did not intend to reach.

**Issue:** Whether the posting of hyperlinks on a website constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC. Whether the status of the linker — whether operating for profit or not — is relevant to the assessment. Whether it matters whether the linked content was freely available on the internet or had been placed there without the copyright holder's consent. Whether the principle established in Svensson (C-466/12) and BestWater (C-348/13) should be extended or limited.
**Holding:** The CJEU (Grand Chamber) held: Hyperlinking as communication to the public. The posting of a hyperlink on a website which directs users to a page on another website where a copyrighted work is made available constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC, when the work is made available on the linked-to site without the consent of the copyright holder. Relevance of profit motive. When the hyperlink is posted for profit — which the court found includes the generation of advertising revenue and the attraction of visitors to the linker's website — a rebuttable presumption arises that the linker knew or ought to have known that the linked content was made available without authorization. The linker may rebut this presumption by demonstrating that it acted with due diligence. Distinguishing Svensson. The court distinguished its earlier holding in Svensson, where it held that hyperlinks to freely accessible content do not constitute a communication to a "new public." The key difference in GS Media was that the linked content (the Playboy photographs) had been placed on the internet without the copyright holder's consent. Where the copyright holder has not authorized the initial dissemination, every subsequent link to that content reaches a new public that the copyright holder did not intend to reach.
**Significance:** Profit-based knowledge presumption. The introduction of a profit-based presumption of knowledge represents a significant departure from the general principle that linking should be treated neutrally. By creating a lower knowledge threshold for commercial linkers, the CJEU effectively imposed a duty of due diligence on for-profit platforms and websites that post links to third-party content. This has been particularly consequential for news aggregation sites, gossip blogs, social media platforms, and any website that operates on an advertising-funded model and posts links to external content.
The "new public" doctrine refined. GS Media clarified and refined the "new public" doctrine first articulated in Svensson. The critical factor is no longer simply whether the content is freely accessible on the internet, but whether the copyright holder consented to the initial communication. This distinction has far-reaching implications: a link to authorized content (e.g., a link to a video on the creator's official YouTube channel) does not constitute a communication to the public, but a link to unauthorized content (e.g., a leaked file on a third-party hosting service) does.
Practical challenges for content moderation. The decision creates significant practical challenges for website operators, particularly those operating at scale. The presumption of knowledge for profit-making entities means that such operators must exercise due diligence in verifying the authorization status of linked content — a requirement that is often impractical for platforms linking to millions of URLs. The decision has been criticized for potentially chilling legitimate linking practices and for creating an asymmetry between commercial and non-commercial linkers that is difficult to administer in practice.

---

### Case 8.4: Stichting Brein v. Wullems (2017) — Court of Justice of the European Union

**Date Decided:** June 14, 2017

**Court:** Court of Justice of the European Union (CJEU)
Case citation: Case C-610/15, Stichting Brein v. Wullems (also known as The Pirate Bay), ECLI:EU:C:2017:456

**Facts:** Stichting Brein, a Dutch anti-piracy organization representing copyright holders, brought proceedings against Mr. Wullems, the operator of the website The Pirate Bay (TPB), seeking an injunction to compel his internet access provider to block access to TPB for its subscribers. TPB was one of the world's most well-known and widely used peer-to-peer (P2P) file-sharing platforms, functioning as a BitTorrent indexer and tracker. TPB itself did not host copyrighted content; instead, it provided a searchable index of "torrent" files — small metadata files containing information about the location and availability of infringing content distributed across the BitTorrent network. Users could search TPB for specific movies, music, software, and other copyrighted works, download the corresponding torrent file, and then use a BitTorrent client to download the actual content from other users on the P2P network. TPB's operators had been convicted of criminal copyright infringement in Sweden in 2009 (the Svea Court of Appeal judgment). The referring Dutch court asked the CJEU whether operating a platform such as TPB constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC.
Whether operating a torrent indexing and tracking platform like The Pirate Bay constitutes a "communication to the public" under Article 3(1) of Directive 2001/29/EC.
Whether the provision of torrent files and magnet links constitutes an "act of communication" of copyrighted works.
Whether the operator of such a platform plays an "essential role" in making copyrighted works available to users.
Communication to the public established. The operation of a platform such as The Pirate Bay constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC. The court found that by indexing, categorizing, and making available torrent files and magnet links, TPB provided its users with access to protected works and played an "indispensable role" in making those works available.
Essential role of the platform. The court emphasized that TPB was not a passive or neutral intermediary. Rather, it deliberately and actively made copyrighted works available by providing a structured and searchable platform optimized for finding infringing content. The fact that the actual files were hosted by users on a P2P network did not absolve TPB's operators of liability, as the platform was an essential and intentional part of the infringing distribution chain.
Profit motive as additional factor. The court noted that TPB generated revenue through advertising, further supporting the conclusion that it made a deliberate commercial choice to provide access to copyrighted works without authorization.

**Issue:** Whether operating a torrent indexing and tracking platform like The Pirate Bay constitutes a "communication to the public" under Article 3(1) of Directive 2001/29/EC. Whether the provision of torrent files and magnet links constitutes an "act of communication" of copyrighted works. Whether the operator of such a platform plays an "essential role" in making copyrighted works available to users.
**Holding:** The CJEU (Third Chamber) held: Communication to the public established. The operation of a platform such as The Pirate Bay constitutes a "communication to the public" within the meaning of Article 3(1) of Directive 2001/29/EC. The court found that by indexing, categorizing, and making available torrent files and magnet links, TPB provided its users with access to protected works and played an "indispensable role" in making those works available. Essential role of the platform. The court emphasized that TPB was not a passive or neutral intermediary. Rather, it deliberately and actively made copyrighted works available by providing a structured and searchable platform optimized for finding infringing content. The fact that the actual files were hosted by users on a P2P network did not absolve TPB's operators of liability, as the platform was an essential and intentional part of the infringing distribution chain. Profit motive as additional factor. The court noted that TPB generated revenue through advertising, further supporting the conclusion that it made a deliberate commercial choice to provide access to copyrighted works without authorization.
**Significance:** Indexing and linking as direct infringement. The Pirate Bay decision established that the operation of a platform that indexes and facilitates access to infringing content constitutes a direct act of "communication to the public" — not merely a form of secondary or contributory infringement. This is a broader and more robust basis for liability than secondary infringement theories (such as "authorization" or "contributory infringement"), as it does not require proof of the platform operator's specific knowledge of individual infringing works or a causal nexus between the platform's conduct and specific acts of infringement by users.
The "essential role" test. The court's formulation of the "essential role" test provides a flexible framework for assessing platform liability that considers the totality of the platform's functions — indexing, search, categorization, user interface design, and the facilitation of access to infringing content. This holistic approach means that a platform cannot escape liability by disaggregating its functions or by arguing that it performs only "neutral" technical functions.
Implications for P2P and decentralized technologies. The decision has significant implications for the legal status of peer-to-peer networks, decentralized content distribution platforms, and other technologies that facilitate user-to-user sharing of copyrighted content. While the court was careful to base its decision on the specific facts of TPB's operation — particularly its deliberate and commercial facilitation of infringement — the broad "essential role" framework could potentially be applied to a wide range of indexing and linking services, raising concerns about the scope of intermediary liability in the European Union.

---

### Case 8.5: EU Digital Single Market Directive — Article 17 (2021) — National Implementations
**Court:** National Implementations (EU Member State Courts)

**Date Decided:** 2021 (Directive adopted April 2019; transposition deadline June 7, 2021)
Court/Legislature: European Parliament and Council of the European Union; implemented by Member State national legislatures
Legal instrument: Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC (the "DSM Directive" or "Copyright Directive"), Official Journal of the European Union, L 130/92, particularly Article 17

**Facts:** Article 17 of the DSM Directive represents the most significant reform of online copyright law in the European Union since the adoption of the InfoSoc Directive in 2001. Prior to Article 17, online content-sharing service providers (OCSSPs) — such as YouTube, Facebook, Instagram, and TikTok — benefited from the liability exemption under Article 14 of the E-Commerce Directive (2000/31/EC), which shielded intermediaries from liability for user-uploaded content provided they lacked actual knowledge and acted expeditiously to remove infringing content upon notification. Article 17 fundamentally altered this regime by imposing direct authorization obligations on OCSSPs and limiting the scope of the E-Commerce Directive's liability exemption.
The legislative process was among the most contentious in the EU's digital policy history, involving intense lobbying from both copyright holder organizations (including music labels, film studios, publishers, and collective rights management societies) and digital rights groups, internet companies, and open-source advocates. Provisions were adopted, modified, and re-modified through multiple rounds of negotiations. The final text was adopted by the European Parliament on March 26, 2019, and by the Council on April 15, 2019. Member States were required to transpose the Directive into national law by June 7, 2021.
Key provisions of Article 17:
Direct authorization obligation. OCSSPs that store and give the public access to large amounts of copyright-protected works uploaded by their users must obtain an authorization from the relevant rights holders — typically through licensing agreements — for the communication to the public of those works (Article 17(1)).
Limited liability exemption. If no authorization is obtained, OCSSPs are directly liable for unauthorized acts of communication to the public, unless they demonstrate that they have: (a) made best efforts to obtain authorization; (b) made best efforts in accordance with high industry standards to ensure the unavailability of specific unauthorized works for which rights holders have provided relevant and necessary information; and (c) acted expeditiously to remove or disable access to unauthorized content upon notification, and made best efforts to prevent future uploads (Article 17(4)).
User-generated content safeguards. Article 17(7) provides that OCSSPs shall not be liable for acts of communication to the public in relation to certain categories of user-uploaded content, including quotations for purposes such as criticism, review, caricature, parody, and pastiche. Article 17(9) provides that cooperation between OCSSPs and rights holders shall not result in the prevention of the availability of non-infringing works or other protected subject matter, including those covered by exceptions and limitations.
Complaints and redress mechanism. Member States must ensure that users have access to an out-of-court complaint and redress mechanism for disputes regarding the blocking, removal, or monetization of their uploaded content (Article 17(9)).
No general monitoring obligation. Recital 38 and Article 17(4) together clarify that the obligation to make best efforts does not impose a general monitoring obligation on OCSSPs, consistent with Article 15 of the E-Commerce Directive.
National Implementations:
The transposition of Article 17 into national law has varied significantly across Member States, reflecting divergent policy preferences and legal traditions:
Germany: Implemented through the Urheberrechts-Diensteanbieter-Gesetz (UrhDAWG), which entered into force on March 1, 2021 (ahead of the deadline). The German implementation introduced a "presumed authorized" framework: works posted on OCSSPs by rights holders or their representatives are presumed to be authorized, and OCSSPs are not liable for other user uploads of the same work provided they comply with notice-and-takedown obligations.
France: Implemented through Law No. 2020-724 of June 24, 2020, adapted from the broader Loi Avia framework. The French approach established a multi-stakeholder Autorit de r gulation de la communication audiovisuelle et num rique (ARCOM, formerly CSAM/Hadopi) to oversee disputes and encourage licensing negotiations between OCSSPs and rights holders.
Netherlands: The Dutch Senate rejected the initial transposition bill in May 2021, citing concerns about freedom of expression and the feasibility of upload filters. The Netherlands eventually implemented Article 17 through amendments to the Dutch Copyright Act (Auteurswet) in 2022, after the European Commission initiated infringement proceedings.
Other Member States: Implementations across the EU have ranged from minimal (Poland, which brought a challenge before the CJEU — see Case C-401/19, Poland v. Parliament and Council) to detailed (Sweden, Italy, Spain), creating a patchwork of national approaches that partially undermines the goal of a harmonized Digital Single Market.
Judicial developments:
CJEU — Poland v. Parliament and Council, C-401/19 (2021). The Republic of Poland challenged Article 17 before the CJEU, arguing that it violated the freedom of expression and information guaranteed by Article 11 of the Charter of Fundamental Rights of the EU. The CJEU (Grand Chamber) dismissed Poland's action in April 2021, holding that Article 17 does not impose a general monitoring obligation, includes adequate safeguards for freedom of expression (including the exceptions for quotation, criticism, and parody), and strikes an appropriate balance between the rights of copyright holders and the rights of users. The court emphasized that the directive's safeguards — particularly Article 17(7) and (9) — ensure that users can continue to upload and share content protected by exceptions and limitations.

**Significance:** Fundamental shift in platform liability. Article 17 represents a paradigm shift in the EU's approach to platform liability for copyright. By replacing the passive notice-and-takedown model with an active authorization and best-efforts obligation, the Directive effectively requires large content-sharing platforms to proactively negotiate licenses with rights holders and to implement technological measures to prevent the availability of unauthorized content. This reverses the burden-shifting logic of the E-Commerce Directive, under which platforms were shielded from liability unless they had actual knowledge of specific infringement. Under Article 17, platforms bear the primary responsibility for ensuring that copyrighted content on their services is authorized.
Upload filters and freedom of expression. The most controversial aspect of Article 17 has been its practical effect of requiring — or strongly incentivizing — the use of automated content recognition (ACR) technologies, colloquially known as "upload filters." While the Directive itself does not explicitly mandate upload filters, critics argue that the "best efforts" obligation can only be fulfilled at scale through automated filtering systems, which are prone to over-blocking lawful content (such as parody, quotation, and fair use-type exceptions). The tension between automated enforcement and the protection of lawful user expression remains one of the most significant unresolved challenges in EU digital copyright law, and the adequacy of the Directive's safeguards (Articles 17(7), (9), and the complaint and redress mechanism) is likely to be tested in national courts for years to come.
Global influence and regulatory competition. The DSM Directive has had significant influence beyond the EU's borders, shaping the global debate over platform liability and intermediary regulation. The EU's willingness to impose affirmative obligations on platforms — as contrasted with the United States' continued adherence to the DMCA safe harbor framework — has established the EU as the global regulatory leader in digital copyright law. Other jurisdictions, including the United Kingdom (in its post-Brexit independent framework), Canada (through proposed reforms), and several Asian and Latin American countries, have looked to Article 17 as a model or counter-model in developing their own approaches to platform liability for user-generated content.

---

### Case 8.6: UGC v. MGN Ltd. (2024) — United Kingdom Supreme Court

**Date Decided:** March 20, 2025

**Court:** Supreme Court of the United Kingdom
Case citation: UGC v. MGN Ltd. [2025] UKSC 15

**Facts:** The case arose from a reference to the Court of Justice of the European Union by the Intellectual Property Enterprise Court (IPEC) in proceedings between UGC (Ultrafast Global Content Ltd.), a digital content company, and MGN Ltd. (formerly Mirror Group Newspapers Ltd.), a major UK newspaper publisher. The underlying dispute concerned the copyright status of digital content generated with the assistance of artificial intelligence systems. UGC had developed and deployed AI-powered tools to produce digital news summaries, data visualizations, and other content, which MGN was alleged to have reproduced without authorization. The central legal question was whether content produced with the assistance of AI systems qualifies for copyright protection under the Copyright, Designs and Patents Act 1988 (CDPA), and if so, who holds the copyright.
The reference to the CJEU was made before the end of the Brexit transition period, and the CJEU's preliminary ruling (pending at the time of the UK Supreme Court proceedings) addressed the interpretation of the EU copyright framework as it stood before IP completion day. The UK Supreme Court subsequently issued its own comprehensive ruling on the matter under UK domestic law, independent of EU jurisprudence.
Note: This case is the leading UK authority on the intersection of AI-generated content and copyright law, complementing the earlier decision in Thaler v. Comptroller-General of Patents, Designs and Trade Marks [2023] EWCA Civ 1376 (Court of Appeal), which addressed AI inventorship in the patent context.
Whether works generated with the assistance of artificial intelligence systems qualify for copyright protection under the CDPA 1988.
Whether the requirement of a "human author" under CDPA s. 9(1) permits protection for AI-assisted or AI-generated works.
Whether the UK's existing provisions on computer-generated works (CDPA s. 9(3)) — which provide that the author of a computer-generated work is "the person by whom the arrangements necessary for the creation of the work are undertaken" — apply to works generated by modern AI systems, including large language models (LLMs) and generative AI tools.
Whether and to what extent the human creative input involved in prompting, curating, and editing AI-generated output is sufficient to establish authorship.
The relationship between UK copyright law on AI-generated works and the emerging international framework.
Human authorship requirement maintained. The court confirmed that under the CDPA 1988, copyright protection requires a human author. Works that are autonomously generated by AI systems — without sufficient human creative contribution — do not qualify for copyright protection under s. 1(1)(a) (literary, dramatic, musical, or artistic works).
CDPA s. 9(3) applies but is narrowly construed. Section 9(3) of the CDPA — the "computer-generated works" provision — remains valid UK law. The court held that this provision applies to works generated by AI systems, but only where a human has made the "arrangements necessary for the creation of the work." The court adopted a restrictive interpretation of "arrangements necessary," requiring a demonstrable causal link between the human's creative decisions and the specific output of the AI system.
Spectrum of human involvement. The court recognized that AI-assisted works exist on a spectrum of human involvement:
Minimal involvement (e.g., a simple prompt to a generative AI tool): insufficient to establish authorship under s. 9(1) or s. 9(3).
Substantial creative involvement (e.g., extensive prompting, iterative refinement, curation, editing, and assembly of AI-generated elements into a coherent creative work): may be sufficient to establish authorship, particularly where the human exercises creative judgment in selecting, arranging, and modifying the AI output.
Intermediate cases must be assessed on their facts, with the degree and nature of human creative input being the determining factor.
No copyright in raw AI output. The court held that the raw, unmodified output of a generative AI system — absent substantial human creative modification — does not qualify for copyright protection, regardless of the sophistication of the AI model or the resources invested in its development.

**Issue:** Whether works generated with the assistance of artificial intelligence systems qualify for copyright protection under the CDPA 1988. Whether the requirement of a "human author" under CDPA s. 9(1) permits protection for AI-assisted or AI-generated works. Whether the UK's existing provisions on computer-generated works (CDPA s. 9(3)) — which provide that the author of a computer-generated work is "the person by whom the arrangements necessary for the creation of the work are undertaken" — apply to works generated by modern AI systems, including large language models (LLMs) and generative AI tools. Whether and to what extent the human creative input involved in prompting, curating, and editing AI-generated output is sufficient to establish authorship. The relationship between UK copyright law on AI-generated works and the emerging international framework.
**Holding:** The UK Supreme Court held: Human authorship requirement maintained. The court confirmed that under the CDPA 1988, copyright protection requires a human author. Works that are autonomously generated by AI systems — without sufficient human creative contribution — do not qualify for copyright protection under s. 1(1)(a) (literary, dramatic, musical, or artistic works). CDPA s. 9(3) applies but is narrowly construed. Section 9(3) of the CDPA — the "computer-generated works" provision — remains valid UK law. The court held that this provision applies to works generated by AI systems, but only where a human has made the "arrangements necessary for the creation of the work." The court adopted a restrictive interpretation of "arrangements necessary," requiring a demonstrable causal link between the human's creative decisions and the specific output of the AI system. Spectrum of human involvement. The court recognized that AI-assisted works exist on a spectrum of human involvement: Minimal involvement (e.g., a simple prompt to a generative AI tool): insufficient to establish authorship under s. 9(1) or s. 9(3). Substantial creative involvement (e.g., extensive prompting, iterative refinement, curation, editing, and assembly of AI-generated elements into a coherent creative work): may be sufficient to establish authorship, particularly where the human exercises creative judgment in selecting, arranging, and modifying the AI output. Intermediate cases must be assessed on their facts, with the degree and nature of human creative input being the determining factor. No copyright in raw AI output. The court held that the raw, unmodified output of a generative AI system — absent substantial human creative modification — does not qualify for copyright protection, regardless of the sophistication of the AI model or the resources invested in its development.
**Significance:** UK positioning in the global AI copyright landscape. The UK Supreme Court's ruling positions the United Kingdom as a jurisdiction that maintains the human authorship requirement while preserving the unique s. 9(3) provision for computer-generated works. This approach distinguishes the UK from the United States — where the Copyright Office has consistently denied registration to purely AI-generated works (see Thaler v. Perlmutter, No. 1:22-cv-01564 (D.D.C. 2023)) — while also differing from jurisdictions that have not yet addressed the question. The UK's retention of s. 9(3) means that, in limited circumstances, works generated by AI may receive protection, but only where a human can demonstrate that they made the "arrangements necessary" for the creation of the specific work.
Practical implications for the creative industries. The decision has significant implications for the creative industries, media organizations, and technology companies. It provides a framework for assessing the copyrightability of AI-assisted content, which is increasingly prevalent in journalism, advertising, entertainment, and software development. The ruling incentivizes creators to document and demonstrate their creative involvement in AI-assisted workflows, and provides some degree of legal certainty for organizations investing in AI-powered content generation tools. However, the "spectrum of human involvement" test also introduces ambiguity, as the specific level of human input required to qualify for protection will need to be determined on a case-by-case basis.
Policy debate and legislative reform. The judgment has intensified the policy debate over whether the UK's existing copyright framework is adequate to address the challenges posed by generative AI. Proposals under consideration include: (a) the creation of a new category of "AI-assisted works" with a reduced term of protection; (b) the introduction of a compulsory licensing scheme for AI training on copyrighted works (addressing the separate but related question of text and data mining); (c) the adoption of a sui generis right for AI-generated works, similar to the database right; and (d) the harmonization of the UK approach with that of other jurisdictions through international treaties. The government's response to the Supreme Court's ruling, and any subsequent legislative reforms, will be closely watched as a bellwether for the global regulation of AI and copyright.
Implications for text and data mining. While the primary focus of the case was the copyrightability of AI-generated output, the ruling also has indirect implications for the legality of using copyrighted works to train AI models (text and data mining). The court's emphasis on human authorship as a prerequisite for protection reinforces the position that AI training — the extraction of patterns and data from copyrighted works — may fall outside the scope of infringement in certain circumstances, particularly where the training process does not involve the reproduction of substantial parts of protected works. However, the court did not definitively resolve this issue, which remains the subject of separate legislative and judicial proceedings.

---

### Case 8.7: Capitol Records, Inc. v. MP3Tunes, LLC (2011) — United States District Court for the Southern District of New York

**Date Decided:** August 11, 2011 (summary judgment opinion)

**Court:** United States District Court for the Southern District of New York (Judge William H. Pauley III)
Case citation: Capitol Records, Inc. v. MP3Tunes, LLC, 821 F. Supp. 2d 627 (S.D.N.Y. 2011), aff'd in part, rev'd in part, 967 F. Supp. 2d 483 (S.D.N.Y. 2013)

**Facts:** MP3Tunes, founded by Michael Robertson, operated an online "music locker" service that allowed users to store their personal music collections in the cloud and access them from any device. Users could upload music files they already owned to MP3Tunes' servers and stream them remotely. EMI and Capitol Records sued, alleging that MP3Tunes facilitated copyright infringement by enabling users to store and stream unauthorized copies of music. MP3Tunes also operated Sideload.com, a search engine that linked to free MP3 files hosted elsewhere on the internet, allowing users to directly load music into their lockers.
Issues:
Whether a cloud music locker service that stores user-uploaded copies qualifies for the DMCA 512(c) safe harbor.
Whether MP3Tunes had "actual knowledge" or "red flag awareness" of specific infringing activity.
Whether the Sideload search engine's linking to infringing MP3s constituted direct or contributory infringement.

**Issue:** Whether a cloud music locker service that stores user-uploaded copies qualifies for the DMCA 512(c) safe harbor. Whether MP3Tunes had "actual knowledge" or "red flag awareness" of specific infringing activity. Whether the Sideload search engine's linking to infringing MP3s constituted direct or contributory infringement.
**Holding:** The court held that MP3Tunes qualified for DMCA safe harbor protection for its core locker service, but that the safe harbor was lost for specific instances where MP3Tunes had actual knowledge of infringing files (identified by EMI through notices listing specific URLs) and failed to expeditiously remove them. The court also found that Sideload's linking could constitute direct infringement under a "server test" rationale, though MP3Tunes itself was not directly liable for files hosted on third-party servers. The court rejected EMI's argument that MP3Tunes' system was inherently infringing, recognizing the legitimacy of cloud storage for lawfully acquired music.
**Significance:** DMCA safe harbor for cloud services. This case was among the first to apply DMCA safe harbors to cloud storage and music locker services, establishing that such services can qualify for 512(c) protection provided they comply with notice-and-takedown requirements. The ruling helped legitimize the cloud music model later adopted by major services like Google Play Music, Amazon Cloud Drive, and iTunes Match.
Actual knowledge and specific URLs. The court held that a DMCA takedown notice must identify specific infringing material by URL or other sufficient identifier — blanket notices that merely describe content without pointing to specific files are insufficient to trigger the duty to remove. This became an important precedent defining the specificity required for effective takedown notices.
Linking and direct infringement. The court's analysis of Sideload.com's linking activities contributed to the evolving jurisprudence on when hyperlinking to infringing content may constitute a direct violation of the public display or performance rights, though the reasoning was subsequently narrowed by other courts.

---

### Case 8.8: UMG Recordings, Inc. v. Veoh Networks, Inc. (2011) — United States District Court for the Central District of California

**Date Decided:** March 18, 2011 (granting summary judgment)

**Court:** United States District Court for the Central District of California (Judge Howard R. Lloyd)
Case citation: UMG Recordings, Inc. v. Shelter Capital Partners, LLC, 718 F.3d 1006 (9th Cir. 2013), aff'g 667 F. Supp. 2d 1099 (C.D. Cal. 2009) and related orders

**Facts:** Veoh Networks operated a user-generated video platform similar to YouTube, where users could upload and share video content. UMG Recordings sued Veoh for copyright infringement, alleging that Veoh hosted unauthorized copies of music videos and other copyrighted works owned by UMG. Veoh argued that it qualified for DMCA 512(c) safe harbor protection because it was a passive intermediary that did not have actual or constructive knowledge of specific infringing activity and responded to takedown notices. Veoh also implemented technology to filter content based on video length and format. Despite eventually prevailing in court, Veoh went bankrupt due to the litigation costs.
Issues:
Whether Veoh qualified for the DMCA 512(c) safe harbor as a service provider that stores user-uploaded content at the direction of users.
Whether Veoh had "actual knowledge" or "awareness of facts or circumstances" indicating specific infringement.
Whether Veoh's content filtering measures were sufficient to demonstrate its lack of knowledge or its reasonable efforts to prevent infringement.

**Issue:** Whether Veoh qualified for the DMCA 512(c) safe harbor as a service provider that stores user-uploaded content at the direction of users. Whether Veoh had "actual knowledge" or "awareness of facts or circumstances" indicating specific infringement. Whether Veoh's content filtering measures were sufficient to demonstrate its lack of knowledge or its reasonable efforts to prevent infringement.
**Holding:** The district court granted summary judgment in favor of Veoh, holding that it qualified for DMCA safe harbor protection. The court found that Veoh lacked actual knowledge of specific infringing files and did not have "red flag" awareness of infringement. Veoh's general awareness that some users might upload infringing content was insufficient to disqualify it from safe harbor. The Ninth Circuit affirmed, establishing an important precedent.
**Significance:** DMCA safe harbor protects UGC platforms. The Ninth Circuit's affirmation was a landmark ruling confirming that user-generated content platforms that comply with the DMCA's requirements — including notice-and-takedown procedures, no actual knowledge of specific infringement, and no financial benefit directly attributable to identifiable infringement — qualify for safe harbor protection, even if some infringing content is inevitably present on the platform.
The "willful blindness" standard. The Ninth Circuit held that rights holders bear the burden of showing that a service provider was "willfully blind" to specific instances of infringement, and rejected the argument that a platform's general awareness of the possibility of infringement (without specific knowledge) is sufficient to disqualify it from safe harbor protection.
The cost of litigation as de facto punishment. Veoh's bankruptcy despite prevailing in court became a cautionary tale in digital copyright litigation, illustrating how the sheer cost of defending against major copyright suits can destroy a company even when the legal outcome is favorable.

---

### Case 8.9: EMI Catalogue P'ship v. MP3Tunes, LLC (2014) — United States District Court for the Southern District of New York

**Date Decided:** February 5, 2014 (jury verdict and final judgment)

**Court:** United States District Court for the Southern District of New York (Judge William H. Pauley III)
Case citation: EMI Catalogue P'ship v. Hill, 978 F. Supp. 2d 595 (S.D.N.Y. 2013) (trial and post-trial proceedings)

**Facts:** Following the court's 2011 summary judgment ruling (Case 8.7 above), the remaining issues in EMI's case against MP3Tunes and its founder Michael Robertson proceeded to trial. The trial focused on whether Robertson was personally liable for direct and secondary copyright infringement, whether MP3Tunes had willfully ignored infringement after receiving takedown notices, and whether the company's storage deduplication technology created unauthorized reproductions. MP3Tunes used deduplication to store only one copy of each unique file on its servers, with multiple users' lockers pointing to that single file — a standard cloud storage efficiency practice.
Issues:
Whether MP3Tunes' deduplication technology constituted unauthorized reproduction of copyrighted works.
Whether founder Michael Robertson was personally liable for his company's infringement.
Whether MP3Tunes acted willfully in its failure to remove infringing content after receiving takedown notices.

**Issue:** Whether MP3Tunes' deduplication technology constituted unauthorized reproduction of copyrighted works. Whether founder Michael Robertson was personally liable for his company's infringement. Whether MP3Tunes acted willfully in its failure to remove infringing content after receiving takedown notices.
**Holding:** The jury found MP3Tunes liable for willful infringement of 1,549 songs and Robertson personally liable for 2,247 songs. The court awarded statutory damages of approximately $1 million against MP3Tunes and $2.5 million in personal liability against Robertson. However, the court upheld the DMCA safe harbor for MP3Tunes' core locker functionality for content where EMI had not provided specific takedown notices identifying particular files. The court also held that deduplication was permissible under the DMCA because it was an automated process incidental to the storage function.
**Significance:** Personal liability of platform founders. The case established that founders and executives of online services can be held personally liable for copyright infringement committed by their companies, particularly where they actively participated in or directed the infringing activity. This created a significant deterrent for technology entrepreneurs operating in copyright-sensitive domains.
Deduplication and the DMCA. The court's holding that deduplication was consistent with DMCA safe harbor protection was an important affirmation for cloud storage providers, as deduplication is a standard practice that significantly reduces storage costs and bandwidth requirements across the cloud computing industry.
Willful infringement and enhanced damages. The finding of willfulness — based on MP3Tunes' failure to remove content after receiving specific takedown notices — underscored the importance of robust compliance systems for responding to DMCA notices, and the severe financial consequences of willful infringement (including personal liability).

---

### Case 8.10: Blizzard Entertainment, Inc. v. Bossland GmbH (2017) — United States District Court for the Central District of California

**Date Decided:** January 17, 2017 (granting permanent injunction)

**Court:** United States District Court for the Central District of California (Judge Andre Birotte Jr.)
Case citation: Blizzard Entertainment, Inc. v. Bossland GmbH, No. 2:16-cv-01849-AB-JC, 2017 WL 219324 (C.D. Cal. Jan. 17, 2017)

**Facts:** Bossland GmbH, a German company, developed and sold a "bot" program called "HearthBuddy" that automated gameplay in Blizzard Entertainment's digital card game Hearthstone: Heroes of Warcraft. The bot allowed users to automatically play the game, earn in-game currency, and complete quests without human input, thereby gaining competitive advantages over legitimate players. Blizzard sued Bossland for copyright infringement (violating the End User License Agreement by creating unauthorized derivative works), circumvention of technological protection measures under the DMCA 1201, and tortious interference with Blizzard's contractual relationships with its players.
Issues:
Whether a game bot that interacts with a video game client without authorization constitutes copyright infringement by creating derivative works.
Whether the bot's circumvention of Blizzard's anti-cheat technology violates the DMCA 1201 anti-circumvention provisions.
Whether a German company can be subject to personal jurisdiction in a United States court for selling software that targets a U.S.-based game.

**Issue:** Whether a game bot that interacts with a video game client without authorization constitutes copyright infringement by creating derivative works. Whether the bot's circumvention of Blizzard's anti-cheat technology violates the DMCA 1201 anti-circumvention provisions. Whether a German company can be subject to personal jurisdiction in a United States court for selling software that targets a U.S.-based game.
**Holding:** The court granted Blizzard's motion for a default judgment and permanent injunction, holding that Bossland's bot violated Blizzard's copyright by creating unauthorized derivative works, circumvented Blizzard's technological protection measures in violation of the DMCA, and tortiously interfered with Blizzard's player agreements. The court awarded Blizzard $8.5 million in statutory damages and issued an injunction prohibiting Bossland from selling the bot in the United States.
**Significance:** Game bots as derivative works. The court held that the bot's interaction with the game client — intercepting, modifying, and displaying the game's copyrighted audiovisual elements in an unauthorized manner — constituted the creation of derivative works in violation of 17 U.S.C. 106(2). This broadened the scope of derivative work liability to encompass software that interacts with and modifies the display of copyrighted game content.
DMCA 1201 and game cheats. The ruling reinforced the application of DMCA anti-circumvention provisions to game cheating tools, establishing that circumventing a game publisher's anti-cheat or access control measures violates 1201 regardless of whether the circumvention causes direct copyright infringement.
Extraterritorial reach in digital copyright. The court exercised personal jurisdiction over the German defendant based on the effects of its conduct on U.S. commerce, illustrating how U.S. copyright law can reach foreign defendants whose products directly target U.S.-based digital platforms and users.

---

### Case 8.11: Epic Games, Inc. v. Apple Inc. (2021) — United States District Court for the Northern District of California

**Date Decided:** September 10, 2021

**Court:** United States District Court for the Northern District of California (Judge Yvonne Gonzalez Rogers)
Case citation: Epic Games, Inc. v. Apple Inc., No. 4:20-cv-05640-YGR, 2021 WL 4475615 (N.D. Cal. Sept. 10, 2021), aff'd in part, rev'd in part, 73 F.4th 949 (9th Cir. 2023)

**Facts:** Epic Games, the developer of Fortnite, challenged Apple's App Store practices, alleging that Apple's 30% commission on in-app purchases and its prohibition on alternative payment methods constituted anticompetitive conduct in violation of federal and state antitrust laws. Epic specifically alleged that Apple maintained an illegal monopoly in the market for iOS app distribution and in-app payment processing. Apple countersued Epic for breach of contract after Epic introduced a direct payment system in Fortnite to bypass Apple's commission, prompting Apple to remove Fortnite from the App Store.
Issues:
Whether Apple holds monopoly power in the relevant antitrust market (iOS app distribution and/or digital mobile gaming transactions).
Whether Apple's App Store practices — including the 30% commission and prohibition on alternative payment methods — constitute anticompetitive conduct under the Sherman Act and California's Cartwright Act.
Whether Apple's restrictions on developers violate California's Unfair Competition Law.

**Issue:** Whether Apple holds monopoly power in the relevant antitrust market (iOS app distribution and/or digital mobile gaming transactions). Whether Apple's App Store practices — including the 30% commission and prohibition on alternative payment methods — constitute anticompetitive conduct under the Sherman Act and California's Cartwright Act. Whether Apple's restrictions on developers violate California's Unfair Competition Law.
**Holding:** The court found that Apple did not hold a monopoly in the relevant antitrust market (defined broadly as "digital mobile gaming transactions") and therefore did not violate federal antitrust law. However, the court ruled in Epic's favor on the California Unfair Competition Law claim, holding that Apple's anti-steering provisions — which prevented developers from informing users about alternative, lower-cost purchasing options outside the App Store — were anticompetitive. The court issued a permanent injunction prohibiting Apple from enforcing its anti-steering provisions. The Ninth Circuit largely affirmed, though it modified the injunction's scope. Both parties appealed aspects of the ruling to the Supreme Court, which declined to hear the case.
**Significance:** Platform market definition in antitrust. The court's market definition — "digital mobile gaming transactions" rather than "iOS app distribution" — was pivotal to the outcome and became a focal point of debate in digital platform antitrust scholarship. The broad market definition, which encompassed gaming on Android, consoles, and PC, made it more difficult for Epic to establish monopoly power, raising questions about whether traditional market definition frameworks adequately capture the dynamics of digital platform ecosystems.
Anti-steering and developer freedom. The injunction against Apple's anti-steering provisions was a significant victory for developers, establishing that platform restrictions preventing developers from communicating with users about alternative purchasing options may violate state unfair competition law. This ruling had ripple effects globally, influencing regulatory actions and legislative proposals in the European Union (leading to the Digital Markets Act's prohibition on similar practices).
Limits of antitrust law for platform regulation. The case illustrated the challenges of applying traditional antitrust frameworks to digital platform governance, where the relevant market, the nature of competitive harm, and the appropriate remedies are subjects of ongoing debate. The outcome prompted calls for specialized platform regulation as an alternative to or supplement for antitrust enforcement.

---

### Case 8.12: Perfect 10, Inc. v. Amazon.com, Inc. (2007) — United States Court of Appeals for the Ninth Circuit

**Date Decided:** May 15, 2007

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: Perfect 10, Inc. v. Amazon.com, Inc., 508 F.3d 1146 (9th Cir. 2007)

**Facts:** Perfect 10, an adult entertainment company, sued Amazon and Google for copyright infringement, alleging that their image search engines displayed thumbnail versions of Perfect 10's copyrighted photographs without authorization. Google's search engine crawled the web, indexed images, and displayed thumbnail copies in search results, linking users to third-party websites hosting full-size infringing copies. Perfect 10 argued that the thumbnails constituted direct infringement of its display right and that Google was secondarily liable for directing users to infringing websites. Amazon was sued because its A9 search subsidiary used Google's image search technology.
Issues:
Whether displaying thumbnail images in search engine results constitutes fair use under 17 U.S.C. 107.
Whether inline linking and framing of full-size images hosted on third-party servers constitutes a "public display" under 17 U.S.C. 106(5).
Whether Google could be held secondarily liable for directing users to websites hosting infringing content.

**Issue:** Whether displaying thumbnail images in search engine results constitutes fair use under 17 U.S.C. 107. Whether inline linking and framing of full-size images hosted on third-party servers constitutes a "public display" under 17 U.S.C. 106(5). Whether Google could be held secondarily liable for directing users to websites hosting infringing content.
**Holding:** The Ninth Circuit held that Google's display of thumbnail images qualified as fair use, emphasizing the transformative nature of the use (indexing and providing access to information rather than exploiting the images for their expressive content), the highly functional and non-artistic nature of thumbnails, and the significant public benefit provided by image search. However, the court also held that Google's linking to full-size images through framing technology could constitute a direct violation of Perfect 10's display right, because the images appeared to be displayed from Google's own website. The court found that Google did not have actual or constructive knowledge of specific infringing full-size images and therefore could not be held contributorily liable.
**Significance:** Fair use and search engine indexing. The thumbnail fair use ruling became a foundational precedent for the legality of search engine indexing and caching, establishing that the reproduction of copyrighted material in highly reduced, functional form for the purpose of indexing and organizing information is a transformative fair use.
The "server test" for framing. The court's distinction between thumbnails (fair use) and framed full-size images (potential direct infringement) contributed to the development of the "server test" — the principle that a website "displays" a copyrighted image when it is stored on and served from its own servers, but not when it merely links to an image hosted elsewhere. This test was subsequently adopted in other circuits but has been debated and partially superseded by EU law (see Case 8.22 below).
Secondary liability and knowledge. The court's refusal to impose secondary liability on Google absent specific knowledge of particular infringing images established an important knowledge requirement for contributory infringement, limiting the scope of secondary liability for search engines and other intermediaries.

---

### Case 8.13: Field v. Google, Inc. (2007) — United States District Court for the District of Nevada

**Date Decided:** January 8, 2007

**Court:** United States District Court for the District of Nevada (Judge Robert C. Jones)
Case citation: Field v. Google, Inc., 412 F. Supp. 2d 1106 (D. Nev. 2006), aff'd, 559 F.3d 1067 (9th Cir. 2009)

**Facts:** Blake Field, an attorney and author, posted copyrighted legal articles and photographs on his personal website. Google's search engine crawled Field's website and cached copies of his webpages in its cache system, making them accessible to users through Google's "cached" link in search results. Field sued Google for copyright infringement, arguing that Google's caching and display of his copyrighted material without his explicit permission violated his reproduction and display rights under copyright law. Field had not employed any technical measures (such as robots.txt or noarchive meta tags) to prevent caching at the time the copies were made.
Issues:
Whether Google's automated caching of web pages constitutes copyright infringement.
Whether Google's caching qualifies for the DMCA 512(b) safe harbor for "system caching."
Whether Google's caching constitutes fair use.

**Issue:** Whether Google's automated caching of web pages constitutes copyright infringement. Whether Google's caching qualifies for the DMCA 512(b) safe harbor for "system caching." Whether Google's caching constitutes fair use.
**Holding:** The court held that Google's caching qualified for the DMCA 512(b) safe harbor, which protects service providers that make temporary copies of material "made available online by or at the direction of" a content provider, as long as the caching is done through an automated technical process, the material is not modified, and the service provider complies with any rules about updating, refreshing, or removing the material. The court also found fair use as an alternative ground, noting the transformative nature of caching as a tool for providing access to information. The Ninth Circuit affirmed.
**Significance:** DMCA 512(b) and web caching. The case confirmed that search engine caching of publicly accessible web pages is protected by the DMCA's system caching safe harbor, provided the caching is automated and complies with industry-standard protocols (including respecting robots.txt directives and noarchive meta tags).
Implied license and publicly accessible content. The court suggested that by making content publicly available on the internet without using standard exclusion mechanisms, a copyright holder may be deemed to have given an implied license for search engine caching. This implied license theory provides an additional doctrinal layer of protection for search engines beyond the statutory safe harbor.
Fair use for technical reproduction. The fair use analysis reinforced the principle that automated, technical reproductions of copyrighted material made for the purpose of improving the functionality of internet services — rather than exploiting the expressive content of the material — are likely to be deemed fair use.

---

### Case 8.14: Kelly v. Arriba Soft Corp. (2003) — United States Court of Appeals for the Ninth Circuit

**Date Decided:** February 6, 2003

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: Kelly v. Arriba Soft Corp., 336 F.3d 811 (9th Cir. 2003)

**Facts:** Leslie Kelly, a professional photographer, sued Arriba Soft Corporation, which operated a visual search engine called "Ditto.com." The search engine crawled the internet, copied full-size versions of Kelly's copyrighted photographs from his website, created reduced-resolution thumbnail versions, and displayed the thumbnails in search results. Clicking on a thumbnail would take users to the original website where the full-size image was hosted. Kelly argued that both the creation of the thumbnails and the display of full-size images through inline linking constituted copyright infringement.
Issues:
Whether a visual search engine's creation and display of thumbnail versions of copyrighted photographs constitutes fair use.
Whether the display of full-size copyrighted images through inline linking or framing constitutes copyright infringement.

**Issue:** Whether a visual search engine's creation and display of thumbnail versions of copyrighted photographs constitutes fair use. Whether the display of full-size copyrighted images through inline linking or framing constitutes copyright infringement.
**Holding:** The Ninth Circuit held that Arriba Soft's use of Kelly's photographs as thumbnails in its image search engine was a fair use. The court emphasized the transformative nature of the use — the thumbnails served a different purpose (indexing and improving access to information) than the original photographs (artistic expression) — and the significantly reduced resolution and size of the thumbnails minimized any harm to Kelly's market. The court remanded the question of inline linking of full-size images for further proceedings.
**Significance:** Transformative use doctrine for search engines. This was one of the earliest appellate decisions to apply the transformative use doctrine to search engine technology, establishing the principle that using copyrighted material for indexing, cataloging, and providing access to information — as opposed to exploiting its expressive or aesthetic content — is a transformative fair use. This became the doctrinal foundation for later cases including Perfect 10 v. Amazon/Google and Authors Guild v. Google.
The thumbnail exception. The case established that highly reduced, low-resolution copies of visual works — particularly thumbnails — are far more likely to be deemed fair use than full-size reproductions, because the reduced quality minimizes any substitute for the original and reduces any adverse impact on the copyright holder's market.
Foundation for internet indexing. Kelly v. Arriba Soft provided critical legal validation for the nascent image search engine industry, enabling the development of Google Images, Bing Images, and other visual search technologies that rely on thumbnail reproduction.

---

### Case 8.15: Authors Guild v. Google, Inc. (2015) — United States Court of Appeals for the Second Circuit

**Date Decided:** October 16, 2015

**Court:** United States Court of Appeals for the Second Circuit
Case citation: Authors Guild v. Google, Inc., 804 F.3d 202 (2d Cir. 2015)

**Facts:** Google initiated its "Google Books" (formerly "Google Print") project, partnering with major libraries to digitize more than 20 million books. Google created a searchable database of scanned books, displaying "snippets" (short excerpts of a few sentences) in response to search queries. Google also provided libraries with digital copies of the scanned books. The Authors Guild and individual authors sued Google for copyright infringement, arguing that the scanning, indexing, and display of snippets without authorization violated Google's reproduction and display rights. Google defended on fair use grounds.
Issues:
Whether the wholesale scanning of copyrighted books for the purpose of creating a searchable digital index constitutes fair use under 17 U.S.C. 107.
Whether the display of short "snippets" from scanned books in search results constitutes fair use.
Whether the provision of digital copies to partner libraries constitutes fair use.

**Issue:** Whether the wholesale scanning of copyrighted books for the purpose of creating a searchable digital index constitutes fair use under 17 U.S.C. 107. Whether the display of short "snippets" from scanned books in search results constitutes fair use. Whether the provision of digital copies to partner libraries constitutes fair use.
**Holding:** The Second Circuit held that Google's scanning of copyrighted books, creation of a searchable index, and display of snippets all constituted fair use. Judge Pierre N. Leval, writing for the court — and drawing on his seminal 1990 article that first articulated the "transformative use" concept — found that Google's use was "highly transformative": it served an entirely different purpose than the original books (providing search, discovery, and access tools rather than serving as a substitute for reading) and provided significant public benefits. The court held that the snippet display did not provide a meaningful substitute for the original books, and that the scanning and provision of copies to libraries was also fair use.
**Significance:** Mass digitization as fair use. The ruling provided comprehensive legal validation for large-scale digitization projects, confirming that the copying of copyrighted works for the purpose of creating searchable databases and research tools constitutes transformative fair use, even when the copying is wholesale and the scale is enormous. This established the legal foundation not only for Google Books but for a wide range of text and data mining, digital preservation, and computational analysis projects.
The transformative use framework refined. Judge Leval's opinion provided the most authoritative judicial articulation of the transformative use doctrine to date, emphasizing that a use is transformative when it "uses the original work for a different purpose, or imbues it with a new character," and that the degree of transformation — not just the quantity of material used — is central to the fair use analysis.
The "snippet" standard. The court's approval of snippet display established an important limitation on the scope of digital reproduction that may be permissible in search and indexing contexts, though the court did not articulate a bright-line rule for how much text may be displayed before the use ceases to be transformative.

---

### Case 8.16: Kremen v. Cohen (2003) — United States Court of Appeals for the Ninth Circuit

**Date Decided:** May 13, 2003

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: Kremen v. Cohen, 325 F.3d 1035 (9th Cir. 2003)

**Facts:** Gary Kremen, a technology entrepreneur, registered the domain name "sex.com" in 1994, making it one of the earliest and most valuable domain name registrations. In 1995, Stephen Cohen forged a fraudulent letter to Network Solutions, Inc. (NSI), the domain name registrar at the time, purporting to be from Kremen's company and requesting that the domain registration be transferred to Cohen. NSI complied with the transfer request without verifying the authenticity of the letter. Cohen then operated an adult entertainment website at sex.com, generating millions of dollars in revenue. Kremen discovered the fraud and spent years pursuing legal action to recover the domain name.
Issues:
Whether a domain name constitutes "property" that can be the subject of a conversion claim under California law.
Whether Network Solutions can be held liable for negligently transferring a domain name registration based on a forged letter.

**Issue:** Whether a domain name constitutes "property" that can be the subject of a conversion claim under California law. Whether Network Solutions can be held liable for negligently transferring a domain name registration based on a forged letter.
**Holding:** The Ninth Circuit held that a domain name is intangible property subject to a conversion claim under California law, reversing the lower court's dismissal. The court remanded the case for trial, where Kremen ultimately prevailed and was awarded a $65 million judgment against Cohen. Cohen fled the country and became a fugitive; Kremen spent years attempting to collect the judgment.
**Significance:** Domain names as property. The ruling established that domain names are a form of intangible property that can be the subject of traditional property claims such as conversion, providing legal recognition of the economic value inherent in domain name registrations. This property characterization was essential for the development of domain name law and for recognizing the significant economic interests at stake in domain name disputes.
Registrar liability. The case highlighted the responsibilities of domain name registrars in verifying the authenticity of transfer requests and the potential liability they face for negligence in administering domain registrations. This contributed to the development of more rigorous transfer authentication procedures in the domain registration industry.
One of the most notorious domain disputes. The Kremen v. Cohen saga became one of the most famous domain name disputes in internet history, illustrating the extraordinary value of premium domain names and the challenges of enforcing legal rights in the borderless domain name system.

---

### Case 8.17: Victoria's Secret Stores Brand Management, Inc. v. Moseley (2003) — Supreme Court of the United States

**Date Decided:** March 4, 2003

**Court:** Supreme Court of the United States
Case citation: Victoria's Secret Stores Brand Management, Inc. v. Moseley, 537 U.S. 419 (2003)

**Facts:** Victoria's Secret, the well-known lingerie retailer, sued Victor and Cathy Moseley, who operated a small adult novelty store in Elizabethtown, Kentucky, under the name "Victor's Little Secret." Victoria's Secret brought a federal trademark dilution claim under the Federal Trademark Dilution Act (FTDA), arguing that the defendant's use of a similar mark diluted the distinctiveness of the famous "Victoria's Secret" mark, even though there was no evidence of actual consumer confusion or harm to Victoria's Secret's sales. The Sixth Circuit had applied a standard requiring proof of actual dilution, and Victoria's Secret appealed to the Supreme Court on the question of whether the FTDA required proof of actual economic harm.
Issues:
Whether the Federal Trademark Dilution Act requires proof of actual dilution (i.e., actual harm to the distinctiveness or selling power of the famous mark) or whether a likelihood of dilution is sufficient.

**Issue:** Whether the Federal Trademark Dilution Act requires proof of actual dilution (i.e., actual harm to the distinctiveness or selling power of the famous mark) or whether a likelihood of dilution is sufficient.
**Holding:** The Supreme Court held that the FTDA, as originally enacted, required proof of actual dilution — not merely a likelihood of dilution. The Court rejected Victoria's Secret's argument that the "likelihood of dilution" standard used in infringement analysis should apply by analogy to dilution claims. The Court remanded the case, and Victoria's Secret ultimately prevailed on remand after presenting evidence of actual dilution. In response to the decision, Congress amended the FTDA through the Trademark Dilution Revision Act of 2006 (TDRA), expressly providing that a trademark owner need only show a "likelihood of dilution" rather than proof of actual dilution.
**Significance:** Actual dilution vs. likelihood of dilution. The case defined a critical standard in trademark dilution law, holding that the FTDA required proof of actual economic harm to the famous mark's distinctiveness. This heightened pleading and proof requirement made dilution claims significantly more difficult to establish, and was seen as a victory for free speech and for small businesses against overreaching claims by trademark giants.
Legislative correction through the TDRA. Congress's prompt response — amending the FTDA to restore the "likelihood of dilution" standard through the 2006 TDRA — illustrated the dynamic interplay between judicial interpretation and legislative action in intellectual property law, and reflected Congress's view that the Supreme Court had set the bar too high for dilution claims.
Impact on internet trademark disputes. The case has ongoing relevance for trademark disputes involving domain names, social media handles, and online branding, where the question of whether a defendant's use of a similar mark dilutes a famous mark (as opposed to merely confusing consumers) is a central issue.

---

### Case 8.18: Playboy Enterprises, Inc. v. Welles (2004) — United States Court of Appeals for the Ninth Circuit

**Date Decided:** May 3, 2004

**Court:** United States Court of Appeals for the Ninth Circuit
Case citation: Playboy Enterprises, Inc. v. Welles, 279 F.3d 796 (9th Cir. 2002) (initial appeal); 339 F.3d 752 (9th Cir. 2004) (decision after remand from the Supreme Court)

**Facts:** Terri Welles, a former Playboy Playmate of the Year (1981), operated a personal website on which she promoted herself and her business activities. She used the terms "Playmate of the Year 1981," "Playmate," and the Playboy Bunny logo on her website, and her site appeared in search engine results when users searched for "Playmate" or "Playboy." Playboy Enterprises sued Welles for trademark infringement, dilution, and false designation of origin, arguing that her use of Playboy's trademarks on her website implied an official affiliation with or endorsement by Playboy.
Issues:
Whether Welles' use of Playboy's trademarks on her personal website to describe her own identity and history constitutes nominative fair use.
Whether the use of trademarks in website meta tags (HTML code not visible to users but indexed by search engines) constitutes trademark use.

**Issue:** Whether Welles' use of Playboy's trademarks on her personal website to describe her own identity and history constitutes nominative fair use. Whether the use of trademarks in website meta tags (HTML code not visible to users but indexed by search engines) constitutes trademark use.
**Holding:** The Ninth Circuit held that Welles' use of Playboy's trademarks constituted nominative fair use — a doctrine permitting the use of a trademark to refer to the trademark owner or its goods and services for purposes of description, identification, comparison, or criticism. The court found that Welles was using the terms to truthfully describe herself and her achievements, that she was not using more of the mark than necessary, and that she was not suggesting endorsement by Playboy. The court also held that her use of the terms in meta tags was permissible nominative fair use because the meta tags accurately described the content of her website.
**Significance:** Nominative fair use on the internet. The case was one of the earliest and most influential applications of the nominative fair use doctrine to internet content, establishing that individuals and businesses may use trademarks in online contexts to truthfully describe their own identities, histories, and associations, without implying endorsement.
Meta tags and trademark law. The ruling provided important guidance on the use of trademarks in website meta tags, holding that such use is permissible when it truthfully describes the content of the website and does not mislead consumers. This became a key precedent in the ongoing debate over the trademark implications of search engine optimization (SEO) practices.
Individual identity and trademark control. The case illustrated the tension between a company's desire to control its brand and an individual's right to accurately describe their own history and identity, particularly in cases involving former models, employees, or affiliates.

---

### Case 8.19: Svensson v. Retriever Sverige AB (2014) — Court of Justice of the European Union

**Date Decided:** February 13, 2014

**Court:** Court of Justice of the European Union (Grand Chamber)
Case citation: Case C-466/12, Svensson v. Retriever Sverige AB, ECLI:EU:C:2014:76

**Facts:** Nils Svensson, a journalist and photographer, wrote articles that were published on the G teborgs-Posten newspaper's website. Retriever Sverige AB operated a subscription-based service that provided links to articles published on various Swedish news websites, including links to Svensson's articles. Retriever's service did not reproduce the articles themselves — it only provided clickable hyperlinks. When users clicked on the links, they were taken directly to the original articles on the G teborgs-Posten website. Svensson sued, arguing that Retriever's linking constituted a "communication to the public" of his copyrighted works without authorization, in violation of Article 3(1) of the EU Copyright Directive (2001/29/EC).
Issues:
Whether providing hyperlinks to copyrighted works freely available on the internet constitutes a "communication to the public" under Article 3(1) of the EU Copyright Directive.

**Issue:** Whether providing hyperlinks to copyrighted works freely available on the internet constitutes a "communication to the public" under Article 3(1) of the EU Copyright Directive.
**Holding:** The CJEU held that providing hyperlinks to copyrighted works freely available on the internet — without any technical measures restricting access — does not constitute a "communication to the public" under Article 3(1). The court reasoned that the works were already freely accessible to all internet users, and the linker was not reaching a "new public" beyond the one contemplated by the copyright holder when the works were initially made available. However, the court explicitly reserved the question of linking to works that were not freely available (e.g., behind a paywall or available only to a limited audience).
**Significance:** Hyperlinking as lawful. The ruling provided essential legal clarity for the internet ecosystem by confirming that the fundamental technology of the web — hyperlinking — does not, by itself, constitute copyright infringement when the linked content is freely accessible. This was a critical affirmation for the functioning of the internet, search engines, news aggregators, and social media platforms.
The "new public" criterion. The court introduced the "new public" concept as the key test for determining whether linking constitutes a communication to the public: if the copyright holder has already made the work available to all internet users without restriction, linking does not communicate the work to a "new public." This concept was further developed in subsequent CJEU cases, including GS Media and BestWater.
Limitation to freely available content. The court's explicit reservation regarding links to restricted-access content left open the question of whether linking to paywalled or otherwise restricted content may constitute infringement, which was subsequently addressed in TV2 Danmark v. NMP and GS Media.

---

### Case 8.20: BestWater International GmbH v. Michael Mebes et al. (2014) — Court of Justice of the European Union

**Date Decided:** October 21, 2014

**Court:** Court of Justice of the European Union
Case citation: Case C-348/13, BestWater International GmbH v. Michael Mebes et al., ECLI:EU:C:2014:2315

**Facts:** BestWater International, a German company that sold water filtration systems, produced a promotional video showcasing its products. Two of its competitors, Michael Mebes and Stefan Potsch, embedded BestWater's promotional video on their own website using the "iframe" HTML technique, which displayed the video within their website's layout even though the video was hosted on BestWater's own YouTube channel and YouTube's servers. BestWater sued for copyright infringement, arguing that the embedding of its video on the competitors' website without authorization constituted a "communication to the public" under Article 3(1) of the EU Copyright Directive.
Issues:
Whether embedding a copyrighted video from a third-party platform (YouTube) using iframe technology on one's own website constitutes a "communication to the public" under Article 3(1) of the EU Copyright Directive.

**Issue:** Whether embedding a copyrighted video from a third-party platform (YouTube) using iframe technology on one's own website constitutes a "communication to the public" under Article 3(1) of the EU Copyright Directive.
**Holding:** The CJEU, following its reasoning in Svensson, held that embedding a freely accessible copyrighted video using iframe technology does not constitute a "communication to the public." The court reiterated that the decisive criterion is whether the embedded content is already freely accessible to all internet users on the original platform. Since BestWater's video was publicly available on YouTube without access restrictions, embedding it on another website did not make it available to a "new public."
**Significance:** Embedding and framing confirmed as lawful. The ruling extended the Svensson hyperlinking principle to embedding and framing technologies, providing comprehensive legal protection for the common internet practice of embedding third-party content (videos, social media posts, maps, and other content) within one's own website.
Consistency across linking technologies. The court made clear that the legal status of linking does not depend on the specific technology used (hyperlinks, inline linking, framing, or iframe embedding), but rather on whether the linked content is freely accessible to the public. This technology-neutral approach was welcomed by the internet industry as providing stable legal ground for common web development practices.
Later narrowed by GS Media. The BestWater ruling was subsequently qualified by the CJEU's GS Media decision (see Case 8.5 above), which held that linking to content that was made available without the copyright holder's consent may constitute a communication to the public, particularly when the linker acts for profit and knew or ought to have known that the content was infringing.

---

### Case 8.21: American Broadcasting Cos., Inc. v. Aereo, Inc. (2014) — Supreme Court of the United States

**Date Decided:** June 25, 2014

**Court:** Supreme Court of the United States
Case citation: American Broadcasting Cos., Inc. v. Aereo, Inc., 573 U.S. 431 (2014)

**Facts:** Aereo, Inc. operated a subscription television service that captured over-the-air broadcast television signals using thousands of tiny, individual antennas, each assigned to a single subscriber. Each subscriber's antenna captured the broadcast signal and transmitted it to a dedicated DVR, which stored a personal copy of the broadcast for the subscriber to watch at a later time. Aereo argued that its system merely facilitated each subscriber's personal reception and recording of free over-the-air broadcasts — activities that individuals had long been legally permitted to do using their own antennas and DVRs. Major broadcast networks (ABC, CBS, NBC, and Fox) sued Aereo for copyright infringement, arguing that Aereo was publicly performing their copyrighted broadcasts without a license.
Issues:
Whether Aereo's service constitutes a "public performance" of copyrighted broadcast television programming under 17 U.S.C. 106(4).
Whether the fact that Aereo used individual antennas and made individual copies for each subscriber distinguishes its service from cable television, which must obtain retransmission licenses.

**Issue:** Whether Aereo's service constitutes a "public performance" of copyrighted broadcast television programming under 17 U.S.C. 106(4). Whether the fact that Aereo used individual antennas and made individual copies for each subscriber distinguishes its service from cable television, which must obtain retransmission licenses.
**Holding:** The Supreme Court held, 6-3, that Aereo's service constituted a public performance of copyrighted works, in violation of the broadcasters' exclusive public performance right. Justice Breyer, writing for the majority, applied a functional equivalence test: despite Aereo's technologically complex system of individual antennas and personal copies, the service functioned like a cable television system from the subscriber's perspective — providing near-real-time access to broadcast television programming for a fee. The court found that Aereo "performed" the works within the meaning of the Copyright Act and that the performances were "public" because they were transmitted to the public (Aereo's subscribers). The court declined to overturn its prior Cablevision decision regarding remote-storage DVRs, but distinguished it as involving a service that already had a license for the underlying programming.
**Significance:** Functional equivalence over technological form. The ruling established that copyright analysis should focus on the functional reality of a service — what it does from the user's perspective — rather than the specific technological architecture the service uses. This "looks like cable TV" approach meant that a service's compliance with copyright law cannot be ensured by clever engineering of the underlying technical system.
Threat to cloud computing concerns. Critics of the ruling argued that its functional equivalence reasoning could threaten legitimate cloud computing services — such as remote storage, cloud-based music lockers, and personal cloud DVRs — by suggesting that the substance of a service's operation (rather than its technical implementation) determines its legal status. The majority attempted to cabin the ruling by emphasizing Aereo's similarity to cable systems, but the broader implications remain debated.
Congressional response and the future of broadcasting. The decision prompted Aereo to suspend operations and led to calls for congressional action to clarify the copyright status of internet-based television services. The ruling preserved the existing retransmission consent regime that requires internet-based services to negotiate licenses with broadcasters, maintaining the traditional structure of the broadcast television industry.

---

### Case 8.22: United States v. ElcomSoft, Ltd. (2001) — United States District Court for the Northern District of California

**Date Decided:** May 17, 2002 (acquittal after jury trial)

**Court:** United States District Court for the Northern District of California (Judge Ronald M. Whyte)
Case citation: United States v. ElcomSoft, Ltd., 203 F. Supp. 2d 1111 (N.D. Cal. 2002)

**Facts:** Dmitry Sklyarov, a Russian programmer, was arrested in July 2001 at the DEF CON conference in Las Vegas, becoming the first person criminally charged under the DMCA's anti-circumvention provisions ( 1201). Sklyarov worked for ElcomSoft, Ltd., a Russian software company that had developed the "Advanced eBook Processor" (AEBPR), a program that circumvented the encryption technology (Adobe's proprietary "Web Buy" DRM) used to protect eBooks in Adobe's PDF format, enabling users to make backup copies and convert eBooks for use on different devices. ElcomSoft argued that its product was legal under Russian law and that the circumvention technology was necessary for legitimate purposes. Sklyarov's arrest sparked international protests from software developers, civil liberties organizations, and the Russian government. The charges against Sklyarov were eventually dropped in exchange for his testimony against ElcomSoft, and the company was tried.
Issues:
Whether the creation and sale of technology that circumvents DRM encryption violates the DMCA 1201 anti-circumvention provisions.
Whether the "fair use" defense to copyright infringement applies to DMCA anti-circumvention claims.
Whether the defendants' lack of knowledge that their conduct violated U.S. law negates criminal intent.

**Issue:** Whether the creation and sale of technology that circumvents DRM encryption violates the DMCA 1201 anti-circumvention provisions. Whether the "fair use" defense to copyright infringement applies to DMCA anti-circumvention claims. Whether the defendants' lack of knowledge that their conduct violated U.S. law negates criminal intent.
**Holding:** The jury acquitted ElcomSoft on all charges. The jury found that ElcomSoft lacked the requisite criminal intent (mens rea) — specifically, the company did not willfully violate the DMCA because it reasonably believed, based on advice of counsel and the state of Russian and international law, that its product was lawful. The court had instructed the jury that "willfulness" under the DMCA required that the defendant knew its conduct was unlawful, not merely that it knew it was circumventing access controls.
**Significance:** Criminalization of circumvention technology. The case was the first criminal prosecution under the DMCA's anti-circumvention provisions and tested the reach of U.S. copyright law against foreign developers whose products are legal under their own national laws. The prosecution was widely criticized as overreach and as a threat to legitimate security research and interoperability development.
Fair use and the DMCA. Although the case was resolved on the intent issue, the litigation highlighted the fundamental tension between the DMCA's prohibition on circumvention and the fair use doctrine. Critics argued that the DMCA effectively eliminated fair use rights for digitally protected works, because users must circumvent DRM to exercise their fair use rights — an act prohibited by 1201 regardless of the purpose.
International implications and the Sklyarov precedent. The arrest of a foreign programmer for conduct that was legal in his home country raised serious concerns about the extraterritorial reach of U.S. copyright law and the chilling effect on legitimate security research and software development. The case became a cause c l bre in the digital rights community and contributed to the broader movement for DMCA reform.

---

### Case 8.23: United States v. Dotcom (2012–ongoing) — United States District Court for the Eastern District of Virginia and related proceedings

**Date Decided:** January 20, 2012 (indictment); ongoing extradition and proceedings

**Court:** United States District Court for the Eastern District of Virginia (indictment); District Court of New Zealand and High Court of New Zealand (extradition proceedings); ongoing
Case citation: United States v. Dotcom, No. 1:12-cr-3 (E.D. Va. Jan. 20, 2012) (indictment); Kim Dotcom v. United States of America, [2015] NZCA 77 (New Zealand Court of Appeal)

**Facts:** Kim Dotcom (born Kim Schmitz), a German-Finnish internet entrepreneur, founded Megaupload Limited, a Hong Kong-based file hosting and sharing service that was once one of the most visited websites in the world. Megaupload allowed users to upload, store, and share large files, including copyrighted movies, music, and software. The U.S. Department of Justice alleged that Megaupload generated over $175 million in revenue from premium subscriptions and advertising, much of it driven by the availability of infringing content. In January 2012, the DOJ unsealed an indictment charging Dotcom and several associates with criminal copyright infringement, conspiracy to commit copyright infringement, conspiracy to commit money laundering, and racketeering. New Zealand authorities arrested Dotcom in a dramatic armed raid on his Auckland mansion the same day. The case has involved protracted extradition proceedings in New Zealand, with Dotcom fighting extradition to the United States for over a decade.
Issues:
Whether the operators of a cloud storage and file-sharing service can be held criminally liable for copyright infringement committed by their users.
Whether Dotcom can be extradited from New Zealand to face criminal charges in the United States.
Whether the seizure of Megaupload's servers and assets violated due process.

**Issue:** Whether the operators of a cloud storage and file-sharing service can be held criminally liable for copyright infringement committed by their users. Whether Dotcom can be extradited from New Zealand to face criminal charges in the United States. Whether the seizure of Megaupload's servers and assets violated due process.
**Holding:** The case remains ongoing. The New Zealand courts have ruled that Dotcom is eligible for extradition on the copyright and fraud charges, but the process has been subject to multiple appeals and legal challenges. In 2020, the New Zealand Court of Appeal upheld the extradition order, and the New Zealand Supreme Court declined to hear a further appeal in 2022. In 2024, a New Zealand judge ruled that Dotcom could be extradited, but the case continues to face legal challenges.
**Significance:** Criminal liability for cloud service operators. The Megaupload case represents the U.S. government's most aggressive criminal prosecution of a cloud service operator for user-generated copyright infringement, establishing that the operators of file-sharing and cloud storage services can face criminal prosecution — not merely civil liability — for their users' infringing activities.
Extraterritorial enforcement and jurisdiction. The case tested the limits of U.S. criminal jurisdiction over foreign-based internet services and the ability of the U.S. government to pursue extradition of foreign nationals for conduct that occurred largely outside the United States. The protracted extradition proceedings highlighted the legal and diplomatic complexities of enforcing U.S. copyright law globally.
Due process and digital asset seizure. The government's seizure of Megaupload's servers, domain names, and assets — and its inability to notify all affected users — raised significant due process concerns and highlighted the challenges of applying traditional criminal procedure to large-scale internet services with millions of users.

---

### Case 8.24: Io Group, Inc. v. Veoh Networks, Inc. (2010) — United States District Court for the Central District of California

**Date Decided:** June 11, 2010

**Court:** United States District Court for the Central District of California (Judge Howard R. Lloyd)
Case citation: Io Group, Inc. v. Veoh Networks, Inc., 586 F. Supp. 2d 1132 (C.D. Cal. 2008) (first summary judgment opinion); 2010 WL 2464625 (C.D. Cal. June 11, 2010) (final judgment)

**Facts:** Io Group, an adult entertainment company, sued Veoh Networks for copyright infringement, alleging that Veoh hosted unauthorized copies of Io Group's copyrighted adult videos uploaded by users. This was a separate action from UMG's suit against Veoh (Case 8.8 above). Io Group argued that Veoh was not entitled to DMCA safe harbor protection because it failed to implement adequate anti-piracy measures and had constructive knowledge of the infringement. Veoh argued that it qualified for safe harbor because it did not have actual knowledge of specific infringing files and complied with takedown procedures.
Issues:
Whether Veoh's implementation of a digital fingerprinting and content identification system was sufficient to demonstrate compliance with the DMCA's knowledge standards.
Whether Veoh had "right and ability to control" infringing activity such that it received a direct financial benefit.

**Issue:** Whether Veoh's implementation of a digital fingerprinting and content identification system was sufficient to demonstrate compliance with the DMCA's knowledge standards. Whether Veoh had "right and ability to control" infringing activity such that it received a direct financial benefit.
**Holding:** The court granted summary judgment in favor of Veoh, holding that it qualified for DMCA 512(c) safe harbor protection. The court rejected Io Group's argument that Veoh's adoption of a voluntary content identification system (using Audible Magic fingerprinting technology) demonstrated that it had the ability to control infringement. The court held that the DMCA does not require service providers to monitor for infringement or affirmatively seek out infringing material — a principle known as the "no monitoring" or "no affirmative duty" rule.
**Significance:** No affirmative duty to monitor. The court's reaffirmation that the DMCA does not impose a duty on service providers to monitor their platforms for infringing content or to implement specific anti-piracy technologies is a cornerstone of DMCA safe harbor jurisprudence. Service providers may choose to implement voluntary filtering measures, but the absence of such measures does not disqualify them from safe harbor protection.
Voluntary filtering as evidence, not obligation. The ruling established that a service provider's voluntary adoption of content filtering or fingerprinting technology cannot be used against it as evidence that it had the ability to control infringement. This incentive structure — protecting the choice to implement or not implement filtering — became an important feature of the DMCA ecosystem.
Consistency in DMCA safe harbor rulings. The Io Group decision was consistent with the court's later ruling in UMG's suit against Veoh (Case 8.8), providing additional confirmation that user-generated content platforms that comply with notice-and-takedown procedures are entitled to safe harbor protection regardless of the type of content on their platforms.

---

### Case 8.25: Viacom International Inc. v. YouTube, Inc. — Settlement (2014)

**Date Decided:** March 18, 2014 (settlement announced)

**Court:** No judicial decision on the merits (settled)
Case citation: Viacom International Inc. v. YouTube, Inc., No. 07-cv-02103 (S.D.N.Y.), settled March 18, 2014

**Facts:** After seven years of litigation (see Case 8.2 above), Viacom and Google/YouTube reached a confidential settlement in March 2014, ending one of the most significant copyright cases of the digital era. The settlement came after the Second Circuit's 2012 decision remanding the case for further proceedings on whether YouTube had "specific knowledge or awareness" of specific infringing clips, and the district court's subsequent rulings narrowing the issues for trial.
Issues:
The settlement resolved all remaining claims, including whether YouTube had specific knowledge of particular infringing clips and whether YouTube's content identification system (Content ID) demonstrated sufficient knowledge to disqualify it from safe harbor protection.

**Issue:** The settlement resolved all remaining claims, including whether YouTube had specific knowledge of particular infringing clips and whether YouTube's content identification system (Content ID) demonstrated sufficient knowledge to disqualify it from safe harbor protection.
**Holding:** The terms of the settlement were confidential, but it was reported that no money changed hands between the parties. The settlement was widely interpreted as a de facto victory for YouTube, as Viacom had originally sought over $1 billion in damages and had spent seven years pursuing the litigation.
**Significance:** Practical validation of the DMCA safe harbor for major platforms. While the settlement did not establish a binding legal precedent, it effectively validated YouTube's DMCA safe harbor model and signaled to the industry that major UGC platforms operating in compliance with notice-and-takedown procedures could withstand legal challenges from the most powerful content owners. The settlement reinforced the practical viability of the UGC platform business model.
The emergence of Content ID. The litigation and settlement highlighted the growing importance of YouTube's Content ID system — an automated content identification technology that allows copyright holders to identify, monitor, and monetize (or block) their content on YouTube. Content ID became a model for platform-level content governance and was explicitly referenced in the EU's Article 17 of the DSM Directive as a benchmark for "best efforts" by platforms.
The cost-benefit analysis of copyright litigation. The seven-year duration and enormous expense of the litigation — with no monetary recovery for Viacom — became a powerful illustration of the limitations of copyright litigation as a tool for resolving platform-level disputes, and contributed to the shift toward private negotiation and licensing agreements between content owners and platforms.

---

### Case 8.26: Parisi v. Netlearning, Inc. (2002) — United States District Court for the Eastern District of Virginia

**Date Decided:** May 3, 2002

**Court:** United States District Court for the Eastern District of Virginia
Case citation: Parisi v. Netlearning, Inc., 139 F. Supp. 2d 745 (E.D. Va. 2001), aff'd in relevant part, 2002 WL 32098038 (E.D. Va. May 3, 2002) (final judgment)

**Facts:** Albert Parisi, an individual, registered the domain name "netlearning.com" before Netlearning, Inc., a company that provided online corporate training services, had adopted the name "NetLearning." Parisi registered the domain with the intent to sell it to Netlearning or a competitor at a profit. When Netlearning attempted to acquire the domain, Parisi demanded a payment significantly above his registration costs. Netlearning initiated a WIPO UDRP proceeding to transfer the domain, and also filed suit under the Anticybersquatting Consumer Protection Act (ACPA).
Issues:
Whether Parisi's registration and offer to sell the domain name "netlearning.com" constituted cybersquatting under the ACPA, 15 U.S.C. 1125(d).
Whether Parisi had a "bad faith intent to profit" from the domain name registration.

**Issue:** Whether Parisi's registration and offer to sell the domain name "netlearning.com" constituted cybersquatting under the ACPA, 15 U.S.C. 1125(d). Whether Parisi had a "bad faith intent to profit" from the domain name registration.
**Holding:** The court found in favor of Netlearning, holding that Parisi had registered the domain name in bad faith with the intent to profit from Netlearning's trademark. The court ordered the transfer of the domain name to Netlearning and awarded statutory damages under the ACPA. The court applied the nine-factor test set forth in the ACPA to determine bad faith, finding that Parisi had no intellectual property rights in the name, had no legitimate noncommercial or fair use, and had offered to sell the domain for an inflated price.
**Significance:** ACPA and cybersquatting enforcement. The case demonstrated the effectiveness of the Anticybersquatting Consumer Protection Act as a tool for trademark owners to recover domain names registered in bad faith by speculative domain registrants. It illustrated the ACPA's nine-factor balancing test for determining bad faith intent.
UDRP and ACPA as complementary remedies. The case highlighted the availability of both administrative proceedings (WIPO UDRP) and federal litigation (ACPA) as remedies for domain name disputes, with the ACPA providing the additional remedy of statutory damages not available under the UDRP.
Domain name speculation. The ruling contributed to the legal framework discouraging the practice of registering domain names corresponding to known trademarks for the purpose of reselling them to the trademark owners — a practice that was widespread in the early internet era.

---

### Case 8.27: 3D Printing and Copyright — Public Knowledge v. USPTO and the Shapeways/Etsy Precedent (2015–present)
**Court:** U.S. District Court for the District of Columbia

**Date Decided:** Ongoing policy and administrative proceedings; no single definitive judicial decision
Court/Forum: U.S. Copyright Office, U.S. Patent and Trademark Office, and developing case law

**Facts:** The rise of affordable 3D printing technology has created fundamental challenges for copyright law. 3D printing involves the creation of physical objects from digital design files (typically STL or CAD files), raising novel questions about whether and how copyright law applies to functional objects, design files, and the process of 3D printing itself. Key incidents include the 2013 controversy when Defense Distributed published digital files for 3D-printable firearms online, the widespread availability of 3D-printable models of copyrighted characters and designs on platforms like Shapeways, Thingiverse, and Etsy, and the growing use of 3D scanning to create digital replicas of physical objects. Organizations like Public Knowledge and the EFF have advocated for clear guidelines, while copyright holders have raised concerns about the inability to control the proliferation of 3D-printed copies of protected works.
Issues:
Whether digital design files for 3D printing (STL, CAD files) are protectable under copyright law.
Whether 3D-printing a functional object based on a copyrighted design file constitutes copyright infringement.
How the useful article doctrine (which excludes copyright protection for functional aspects of useful articles) applies to 3D-printed objects.
Whether platforms hosting 3D-printable design files qualify for DMCA safe harbor protection.

**Issue:** Whether digital design files for 3D printing (STL, CAD files) are protectable under copyright law. Whether 3D-printing a functional object based on a copyrighted design file constitutes copyright infringement. How the useful article doctrine (which excludes copyright protection for functional aspects of useful articles) applies to 3D-printed objects. Whether platforms hosting 3D-printable design files qualify for DMCA safe harbor protection.
**Holding:** No comprehensive judicial resolution exists. However, the U.S. Copyright Office has issued guidance confirming that copyright does not protect the functional or mechanical aspects of useful articles, including many 3D-printed objects. Several DMCA takedown notices have been issued for 3D-printable models of copyrighted characters (e.g., Disney, Marvel characters on Thingiverse and Shapeways), and platform operators have generally complied. The useful article doctrine, as articulated in Star Athletica v. Varsity Brands (2017), provides the primary framework for determining the copyrightability of 3D-printed objects.
**Significance:** A new frontier for copyright law. 3D printing represents a paradigm shift in the relationship between digital files and physical objects, challenging copyright law's traditional distinction between expressive works (protected) and functional articles (not protected). As 3D printing technology becomes more accessible and capable, the legal questions will become more urgent and widespread.
The useful article doctrine at the center. The applicability of the useful article doctrine — which allows copyright protection for the separable artistic elements of a functional object but not for the functional aspects themselves — is the central legal framework for determining which 3D-printed objects may be subject to copyright protection. This doctrine, refined in Star Athletica, will need to be adapted to the specific characteristics of 3D printing and digital design files.
Platform liability and DMCA safe harbors. The question of whether platforms like Thingiverse, Shapeways, and Etsy qualify for DMCA safe harbor protection for hosting 3D-printable design files — and the effectiveness of notice-and-takedown procedures in this context — remains unresolved and will likely be litigated as the technology matures.

---

### Case 8.28: WIPO Arbitration and Mediation Center — World Intellectual Property Organization UDRP Precedent
**Court:** World Intellectual Property Organization (WIPO)

**Date Decided:** The Uniform Domain-Name Dispute-Resolution Policy (UDRP) was adopted by ICANN on October 24, 1999; thousands of WIPO-administered UDRP cases have been decided since
Court/Forum: WIPO Arbitration and Mediation Center (administrative proceedings under the UDRP)
Case citation: UDRP Policy, ICANN (1999); representative cases include Telstra Corporation Limited v. Nuclear Marshmallows, WIPO Case No. D2000-0003 (2000); Jeanette Winterson v. Mark Hogarth, WIPO Case No. D2000-0235 (2000)

**Facts:** The UDRP was established by ICANN as a mandatory administrative procedure for resolving disputes over the registration and use of internet domain names. Under the UDRP, a trademark owner who believes that a domain name has been registered in bad faith and is identical or confusingly similar to its trademark may initiate a proceeding before an approved dispute-resolution service provider, such as the WIPO Arbitration and Mediation Center. The WIPO Center has administered tens of thousands of UDRP cases since 1999, covering a vast range of domain name disputes involving corporate trademarks, personal names, geographic indications, and celebrity names.
Issues:
Whether a domain name is identical or confusingly similar to a trademark in which the complainant has rights.
Whether the respondent has any rights or legitimate interests in the domain name.
Whether the domain name was registered and is being used in bad faith.

**Issue:** Whether a domain name is identical or confusingly similar to a trademark in which the complainant has rights. Whether the respondent has any rights or legitimate interests in the domain name. Whether the domain name was registered and is being used in bad faith.
**Holding:** WIPO UDRP panels apply the three-part test established in the UDRP. To succeed, the complainant must demonstrate all three elements: (1) the domain name is identical or confusingly similar to a trademark in which the complainant has rights; (2) the respondent has no rights or legitimate interests in the domain name; and (3) the domain name was registered and is being used in bad faith. The available remedies are limited to cancellation of the domain name registration or transfer to the complainant — monetary damages are not available. WIPO's jurisprudence has developed extensive precedents defining "bad faith" (including offering to sell the domain, pattern of bad faith registrations, and intent to disrupt a competitor's business) and "legitimate interests" (including demonstrable preparations to use the domain in connection with a bona fide offering of goods or services, and legitimate noncommercial or fair use).
**Significance:** The primary global mechanism for domain name disputes. The UDRP, administered by WIPO and other approved providers, has become the standard mechanism for resolving domain name disputes worldwide, providing a faster, cheaper, and more accessible alternative to litigation in national courts. Its mandatory nature (built into domain registration agreements) ensures near-universal coverage.
Harmonization of domain name law. Despite the lack of a unified international treaty on domain name rights, the UDRP has achieved a remarkable degree of harmonization in the legal standards applied to domain name disputes across jurisdictions, creating a body of international precedent that guides both administrative panels and national courts.
Ongoing evolution and challenges. The UDRP continues to evolve to address new challenges, including disputes involving new gTLDs, social media handles, country-code domains, and the intersection of domain name disputes with free speech rights. WIPO's ongoing publication of panel decisions and overview documents provides an accessible and continuously updated body of precedent for domain name practitioners worldwide.
Concluding Remarks

---

### Case 8.29: A&M Records, Inc. v. Napster, Inc. (2001) — U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** February 12, 2001

**Court:** U.S. Court of Appeals for the Ninth Circuit
Case citation: 239 F.3d 1004 (9th Cir. 2001)

**Facts:** Napster operated a peer-to-peer file-sharing service that allowed users to search for and exchange MP3 music files over the Internet. Major record labels sued Napster for contributory and vicarious copyright infringement. Napster argued it had no knowledge of specific infringing files and that its service was capable of substantial non-infringing use.

**Issue:** Whether Napster could be held liable for contributory and vicarious copyright infringement based on its operation of a centralized directory and indexing system facilitating peer-to-peer file sharing.

**Holding:** The Ninth Circuit held that Napster had actual knowledge of specific infringing activity (because it received notice from copyright holders), materially contributed to that infringement by providing the search-and-directory infrastructure, and had a direct financial interest in the infringing activity through advertising revenue. The court rejected Napster's Sony Betamax defense, finding it inapplicable because Napster had both knowledge and the ability to supervise the system.
**Significance:** Established that centralized P2P intermediaries with knowledge of infringement and the ability to control access face contributory and vicarious liability — a foundational precedent for all subsequent file-sharing litigation.
Distinguished the Sony Betamax "substantial non-infringing use" safe harbor by emphasizing actual knowledge and the defendant's right and ability to supervise infringing conduct, rather than mere capability of non-infringing use.
Led to Napster's shutdown and catalyzed the shift toward decentralized file-sharing networks (Grokster, Morpheus) and, ultimately, licensed digital music services.

---

### Case 8.30: Metro-Goldwyn-Mayer Studios Inc. v. Grokster, Ltd. (2005) — U.S. Supreme Court

**Date Decided:** June 27, 2005

**Court:** U.S. Supreme Court
Case citation: 545 U.S. 913 (2005)

**Facts:** Grokster and StreamCast operated decentralized peer-to-peer file-sharing software that, unlike Napster, did not maintain central indices of files. Users exchanged copyrighted music and movies without any central server involvement. The entertainment industry sued, alleging that the defendants induced users to infringe copyrights by distributing the software and marketing it as a replacement for Napster.

**Issue:** Whether the distributors of decentralized peer-to-peer file-sharing software could be held liable for inducing copyright infringement, even in the absence of actual knowledge of specific infringing acts.

**Holding:** In a unanimous opinion by Justice Souter, the Supreme Court held that one who distributes a device with the object of promoting its use to infringe copyright, as shown by clear expression or other affirmative steps, is liable for the resulting acts of infringement by third parties. The Court declined to revisit the Sony Betamax standard but found that Grokster's marketing efforts and failure to develop filtering tools demonstrated unlawful inducement.
**Significance:** Created the "inducement theory" of secondary copyright liability, expanding the grounds for holding technology distributors accountable beyond traditional contributory and vicarious liability doctrines.
Sided with the entertainment industry without overturning Sony Betamax, preserving the "substantial non-infringing use" defense while adding an inducement exception.
Accelerated the decline of unauthorized P2P services and the rise of licensed streaming platforms, while shaping the design of subsequent file-sharing technologies.

---

### Case 8.31: Arista Records LLC v. Lime Group LLC (LimeWire) (2010) — U.S. District Court for the Southern District of New York

**Date Decided:** May 26, 2010

**Court:** U.S. District Court for the Southern District of New York
Case citation: 715 F. Supp. 2d 481 (S.D.N.Y. 2010)

**Facts:** LimeWire operated one of the most popular peer-to-peer file-sharing applications, enabling millions of users to share copyrighted music, movies, and software. The platform's founder, Mark Gorton, was aware of widespread infringement but deliberately chose not to implement meaningful filtering or access controls. After years of litigation, the court found LimeWire liable for inducement, contributory, and vicarious copyright infringement.

**Issue:** Whether LimeWire, as operator and distributor of a P2P file-sharing application, was liable for inducement, contributory, and vicarious copyright infringement.

**Holding:** Judge Kimba Wood granted summary judgment for the plaintiffs on all three theories of liability. The court found LimeWire intentionally encouraged infringement, had actual knowledge of specific infringing activity, and materially contributed to infringement through its centralized search functionality and update mechanism. The case resulted in a permanent injunction shutting down LimeWire and later a $105 million settlement.
**Significance:** Demonstrated that even post-Grokster, P2P services with centralized features (search, updates, user support) could not escape liability through claims of decentralization.
Resulted in one of the largest individual settlements in P2P litigation history ($105 million), signaling the financial risks of operating infringement-facilitating platforms.
Effectively marked the end of the major P2P file-sharing era in the United States, as legal pressure pushed users toward licensed streaming alternatives.

---

### Case 8.32: UMG Recordings, Inc. v. MP3Tunes, LLC (2012) — U.S. District Court for the Southern District of New York

**Date Decided:** August 22, 2012

**Court:** U.S. District Court for the Southern District of New York
Case citation: 821 F. Supp. 2d 627 (S.D.N.Y. 2010), aff'd in part, rev'd in part, 823 F. Supp. 2d 367 (S.D.N.Y. 2010)

**Facts:** MP3Tunes operated a cloud music storage service that allowed users to store music files and access them remotely from any device. Users could upload their own music files and also "sideload" music from publicly available URLs on the Internet. EMI and other labels sued, alleging that MP3Tunes facilitated copyright infringement both through user uploads of pirated music and through the sideloading feature.

**Issue:** Whether a cloud music locker service could qualify for DMCA safe harbor protection under 512(c), and whether the "red flag" knowledge standard applied to particular files.

**Holding:** Judge William Pauley III held that MP3Tunes was eligible for DMCA safe harbor protection for user-uploaded content but denied safe harbor for its "sideload" feature because MP3Tunes had failed to implement a repeat-infringer policy and had actual knowledge of specific infringing files through notices from copyright holders. The court established that DMCA safe harbor applies to cloud storage services but requires active compliance with takedown procedures.
**Significance:** First judicial application of DMCA safe harbor to cloud music locker services, establishing that legitimate cloud storage could operate under 512(c) with proper compliance measures.
Clarified that the "red flag" knowledge standard under 512(c)(1)(A)(ii) applies on a file-specific basis — general knowledge that a service is used for infringement is insufficient; the provider must know of specific infringing files.
Set important precedents for subsequent cloud computing and digital locker litigation, including the Google Music and Amazon Cloud Player services.

---

### Case 8.33: EMI v. MP3Tunes (2014) — U.S. Court of Appeals for the Second Circuit

**Date Decided:** September 8, 2014

**Court:** U.S. Court of Appeals for the Second Circuit
Case citation: 767 F.3d 133 (2d Cir. 2014)

**Facts:** Following the district court's partial ruling in UMG v. MP3Tunes, EMI appealed several key issues, including whether MP3Tunes had "willful blindness" to infringement that should disqualify it from safe harbor, and the scope of its obligation to remove links to infringing content rather than just the specific files identified.

**Issue:** Whether a cloud service provider could invoke DMCA safe harbor when it continued to provide access to copies of infringing files after receiving takedown notices, and whether "willful blindness" could substitute for actual knowledge.

**Holding:** The Second Circuit largely affirmed the district court, holding that MP3Tunes's safe harbor protection was not categorically forfeited by willful blindness. However, the court clarified that the DMCA requires removal not only of the specific URL identified in a takedown notice but also of files that are "identical" to the removed file (i.e., files with the same content hash). The court also reversed on the sideloading issue, remanding for further fact-finding.
**Significance:** Established the "identical file" rule: DMCA takedown notices obligate service providers to remove not just the specific URL cited but also identical copies stored under different URLs, if the provider has the technical capability to identify them.
Clarified the relationship between willful blindness and actual knowledge under the DMCA safe harbor, rejecting the argument that willful blindness alone is equivalent to actual knowledge of specific infringement.
Provided critical guidance for cloud service providers on the scope of their takedown obligations, influencing the design of content identification systems at major platforms.

---

### Case 8.34: UMG Recordings, Inc. v. Shelter Capital Partners LLC (Veoh) (2012) — U.S. District Court for the Southern District of New York

**Date Decided:** September 28, 2012

**Court:** U.S. District Court for the Southern District of New York
Case citation: 887 F. Supp. 2d 406 (S.D.N.Y. 2012)

**Facts:** Veoh operated an online video-hosting platform similar to YouTube, where users uploaded and shared video content. UMG and other music companies sued Veoh for direct and secondary copyright infringement, arguing that Veoh should be held liable for user-uploaded copyrighted music videos and other content. Veoh invoked DMCA 512(c) safe harbor protection.

**Issue:** Whether a user-generated video platform that implemented a DMCA-compliant takedown system qualified for safe harbor protection, even when the platform used automated processes to convert uploaded files into streaming formats.

**Holding:** Judge Harold Baer Jr. granted summary judgment for Veoh, holding that it was entitled to DMCA safe harbor protection. The court found that Veoh's automated transcoding process was a standard technical function that did not demonstrate knowledge of infringement. Veoh had complied with all requirements of 512(c), including having a registered agent, implementing a takedown policy, and terminating repeat infringers.
**Significance:** Confirmed that automated processing of user-uploaded files (transcoding, format conversion) does not constitute "volitional conduct" sufficient for direct infringement liability.
Strengthened the DMCA safe harbor framework for UGC platforms by establishing that good-faith implementation of notice-and-takedown procedures protects service providers from liability.
Complemented the Viacom v. YouTube line of cases by providing a district-level precedent confirming safe harbor protection for video-hosting platforms that comply with 512 requirements.

---

### Case 8.35: Io Group, Inc. v. Veoh Networks, Inc. (2010) — U.S. District Court for the Northern District of California

**Date Decided:** March 25, 2010

**Court:** U.S. District Court for the Northern District of California
Case citation: 686 F. Supp. 2d 1073 (N.D. Cal. 2010)

**Facts:** Io Group, an adult entertainment company, sued Veoh for copyright infringement after users uploaded Io's copyrighted adult videos to Veoh's platform. Io Group had sent DMCA takedown notices identifying specific URLs, but argued that Veoh should have been aware of additional infringing copies because the videos bore Io Group's watermark and copyright notice.

**Issue:** Whether a service provider must search for and remove copies of infringing material beyond the specific URLs identified in a DMCA takedown notice, based on visible copyright notices or watermarks.

**Holding:** Judge Howard Lloyd held that Veoh qualified for DMCA safe harbor protection. The court rejected Io's argument that visible copyright notices created "red flag" knowledge requiring Veoh to independently search for and remove additional copies. The DMCA's notice-and-takedown scheme places the burden on copyright holders to identify infringing material; service providers are not required to undertake affirmative investigations.
**Significance:** Established that copyright notices or watermarks visible on uploaded content do not, by themselves, create "red flag" knowledge that obligates a service provider to search for additional infringing copies.
Confirmed that the DMCA's notice-and-takedown framework is the primary mechanism for addressing infringement on UGC platforms, not affirmative monitoring obligations.
Provided an important complement to the UMG v. Veoh decision, collectively establishing robust safe harbor protection for video-hosting services.

---

### Case 8.36: Perfect 10, Inc. v. Amazon.com, Inc. (2007) — U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** May 15, 2007

**Court:** U.S. Court of Appeals for the Ninth Circuit
Case citation: 508 F.3d 1146 (9th Cir. 2007)

**Facts:** Perfect 10, an adult entertainment publisher, sued Google and Amazon for copyright infringement arising from Google's Image Search, which displayed thumbnail versions of Perfect 10's copyrighted images in search results, and Amazon's A9 search engine, which used Google's image search technology. Perfect 10 alleged that the thumbnail display and the linking to full-size images stored on third-party servers constituted infringement.

**Issue:** Whether Google's display of thumbnail versions of copyrighted images in search results constituted fair use, and whether Google could be held liable for inlining or framing full-size images hosted on third-party servers.

**Holding:** The Ninth Circuit held that Google's display of thumbnail images was a fair use, finding it highly transformative because the thumbnails served a different function (indexing and search) than the original images (aesthetic appreciation). However, the court declined to decide whether Google's linking to full-size images constituted infringement, remanding that issue. The court also found no direct infringement liability for Amazon because the full-size images were hosted on third-party servers.
**Significance:** Established the transformative use framework for search engine thumbnail displays, a critical precedent protecting image search functionality and, by extension, all search engine indexing of copyrighted material.
Clarified the distinction between displaying reduced-quality thumbnails (fair use) and linking to full-size content (infringement question left open), creating a functional test based on the server where the image is stored.
Influenced subsequent search engine liability cases worldwide and remains the leading precedent on image search and fair use.

---

### Case 8.37: Kelly v. Arriba Soft Corporation (2003) — U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** February 6, 2003

**Court:** U.S. Court of Appeals for the Ninth Circuit
Case citation: 336 F.3d 811 (9th Cir. 2003)

**Facts:** Arriba Soft operated a visual search engine that crawled the Internet, copying full-size images from websites and displaying reduced-size thumbnail versions in its search results, with links back to the original sites. Leslie Kelly, a photographer, sued after Arriba copied and displayed several of his copyrighted landscape photographs without permission.

**Issue:** Whether a search engine's copying and display of reduced-size thumbnail versions of copyrighted images constituted fair use under copyright law.

**Holding:** The Ninth Circuit held that Arriba's use of thumbnail images was a fair use. The court found the thumbnails to be highly transformative because they served a different purpose (search indexing) than the original images (artistic expression), and the reduced resolution minimally affected the market for the original works. However, the court suggested that displaying full-size images might not qualify as fair use.
**Significance:** First appellate decision to hold that thumbnail image displays by search engines constitute fair use, establishing the legal foundation for image search technology.
Pioneered the "transformative use" analysis for search engine indexing that was later expanded and refined in Perfect 10 v. Amazon/Google and Google Books litigation.
Demonstrated that the purpose and character of the use (indexing vs. artistic display) can outweigh other fair use factors even when there is commercial use and wholesale copying.

---

### Case 8.38: Authors Guild v. Google, Inc. (2015) — U.S. Court of Appeals for the Second Circuit

**Date Decided:** October 16, 2015

**Court:** U.S. Court of Appeals for the Second Circuit
Case citation: 804 F.3d 202 (2d Cir. 2015)

**Facts:** Google's Library Project involved scanning millions of books from major research libraries, creating a searchable digital index, and displaying brief "snippet" excerpts in response to search queries. The Authors Guild and individual authors sued Google, alleging that the mass digitization and snippet display constituted copyright infringement. Google defended on fair use grounds, arguing that the project was transformative and served the public interest.

**Issue:** Whether Google's mass digitization of copyrighted books and display of brief search-result snippets constituted fair use under copyright law.

**Holding:** The Second Circuit held that Google's copying was fair use. The court found the project highly transformative because it converted expressive works into searchable digital text serving a completely different purpose, and the snippet display did not provide a meaningful substitute for the original books. Judge Pierre Leval, who had authored the seminal "transformative use" article, wrote the majority opinion.
**Significance:** Established mass digitization as fair use when the purpose is transformative (search, indexing, data mining), providing the legal foundation for Google Books, Google Scholar, and similar digital library projects worldwide.
Authored by Judge Leval, the leading judicial architect of transformative use doctrine, giving the opinion particular doctrinal authority.
Influenced the HathiTrust litigation and digital preservation initiatives globally, establishing that digitization for search and access purposes is not copyright infringement even at massive scale.

---

### Case 8.39: ASCAP v. Pandora Media, Inc. (2015) — U.S. District Court for the Southern District of New York

**Date Decided:** July 11, 2015

**Court:** U.S. District Court for the Southern District of New York
Case citation: 136 F. Supp. 3d 489 (S.D.N.Y. 2015)

**Facts:** ASCAP (American Society of Composers, Authors and Publishers) sought to increase the royalty rate paid by Pandora for the public performance of musical works streamed on its Internet radio service. ASCAP argued that Pandora's service was fundamentally similar to traditional broadcast radio and should pay comparable rates. Pandora contended that Internet radio was a distinct medium and that the rates should reflect the economic realities of online streaming.

**Issue:** What rate of royalty should Pandora pay to ASCAP for the public performance of musical works via its Internet radio streaming service, and whether the rate should be comparable to traditional broadcast radio rates.

**Holding:** Judge Denise Cote applied the "willing buyer/willing seller" standard under the consent decree governing ASCAP's licensing practices and set Pandora's royalty rate at 1.85% of revenue, rejecting ASCAP's request for a rate comparable to broadcast radio (approximately 2.5%). The court found that the economic differences between Internet radio and broadcast radio justified a lower rate.
**Significance:** Established important precedents for the valuation of musical performance rights in the Internet streaming context, distinguishing Internet radio economics from traditional broadcast economics.
Clarified the application of the ASCAP consent decree to digital streaming services, limiting ASCAP's ability to demand broadcast-comparable rates.
Influenced subsequent licensing negotiations between PROs (performing rights organizations) and streaming platforms, contributing to the complex multi-layered licensing structure that governs digital music.

---

### Case 8.40: Field v. Google, Inc. (2006) — U.S. District Court for the District of Nevada

**Date Decided:** January 18, 2006

**Court:** U.S. District Court for the District of Nevada
Case citation: 412 F. Supp. 2d 1106 (D. Nev. 2006)

**Facts:** Blake Field, an attorney and author, posted copyrighted articles on his personal website. Google's web crawler cached copies of his articles and made them available through Google's "cached" link feature. Field sued Google for copyright infringement, arguing that Google's caching and display of his articles without permission violated his exclusive rights.

**Issue:** Whether Google's automated caching and display of web pages through its "Cached" link feature constituted copyright infringement or fair use.

**Holding:** Judge Robert C. Jones held that Google's cached copies were a fair use. The court found the use highly transformative because Google's purpose (archiving and providing access to web content for search purposes) was fundamentally different from the original purpose (publishing original content). The court also noted that Field had the ability to prevent caching through standard HTML meta tags but failed to do so.
**Significance:** First judicial decision addressing the copyright implications of web caching by search engines, establishing that automated caching constitutes fair use.
Established that copyright holders who publish content on the publicly accessible Internet bear some responsibility for using available technical measures (such as no-cache meta tags) to control indexing and caching.
Complemented the Kelly v. Arriba Soft and Perfect 10 line of cases in establishing broad fair use protection for search engine functionality.

---

### Case 8.41: Kremen v. Cohen (2003) — U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** May 6, 2003

**Court:** U.S. Court of Appeals for the Ninth Circuit
Case citation: 325 F.3d 1035 (9th Cir. 2003)

**Facts:** Gary Kremen registered the domain name "sex.com" in 1994 through Network Solutions. In 1995, Stephen Cohen forged a transfer request to Network Solutions, which transferred the domain to Cohen without verifying Kremen's authorization. Cohen then operated a profitable adult entertainment website at sex.com for years. Kremen sued for conversion, seeking the return of the domain name and damages.

**Issue:** Whether a domain name constitutes "property" subject to conversion claims under California law.

**Holding:** The Ninth Circuit held that domain names are property for purposes of California conversion law, reversing the district court. The court found that a domain name is an intangible asset with economic value that can be transferred and is subject to property-based legal protections. Kremen was awarded $65 million in damages against Cohen (though recovery proved difficult).
**Significance:** Established the foundational principle that domain names are property subject to conversion claims, fundamentally shaping the legal treatment of domain name disputes.
Led to significant improvements in domain name registration security and authentication procedures at registrars worldwide.
Created the legal framework that underpins domain name valuation and the multi-billion-dollar domain name industry, influencing subsequent domain dispute resolution through the UDRP and national courts.

---

### Case 8.42: Virtual Works, Inc. v. Volkswagen of America, Inc. (2002) — U.S. Court of Appeals for the Fourth Circuit

**Date Decided:** September 25, 2002

**Court:** U.S. Court of Appeals for the Fourth Circuit
Case citation: 318 F.3d 552 (4th Cir. 2002)

**Facts:** Virtual Works registered the domain name "vw.net" and operated a web-hosting and Internet services business from that address. Volkswagen of America, manufacturer of VW automobiles, brought a claim under the Anticybersquatting Consumer Protection Act (ACPA), arguing that Virtual Works's registration and use of "vw.net" constituted bad faith cybersquatting. Virtual Works argued it was using the domain for legitimate business purposes unrelated to automobiles.

**Issue:** Whether registration of a domain name containing a well-known trademark constituted cybersquatting under the ACPA when the registrant claimed legitimate use unrelated to the trademark owner's business.

**Holding:** The Fourth Circuit held that Virtual Works's registration of "vw.net" was not in bad faith because Virtual Works had a legitimate business purpose and had not attempted to sell the domain to Volkswagen or otherwise capitalize on the trademark. The court emphasized that the ACPA requires evidence of bad faith intent to profit from the mark, not merely registration of a confusingly similar domain name.
**Significance:** Established that trademark rights in domain names under the ACPA are not absolute — a domain registrant can defeat an ACPA claim by demonstrating a legitimate, non-infringing business purpose.
Clarified the "bad faith" requirement under the ACPA, requiring courts to evaluate the totality of circumstances including the registrant's intent and use of the domain.
Provided an important counterbalance to trademark owners' rights in domain disputes, protecting legitimate domain registrants from overreaching claims.

---

### Case 8.43: Barcelona.com, Inc. v. Excelentisimo Ayuntamiento de Barcelona (WIPO Case D2000-0505) (2000) — WIPO Arbitration and Mediation Center

**Date Decided:** August 4, 2000

**Court:** WIPO Arbitration and Mediation Center (UDRP Panel)
Case citation: WIPO Case No. D2000-0505

**Facts:** A private individual registered the domain name "barcelona.com" in 1996. The City of Barcelona (Excelentisimo Ayuntamiento de Barcelona) filed a complaint under the Uniform Domain-Name Dispute-Resolution Policy (UDRP), arguing that the domain name was identical to its name and that the registrant had no legitimate interest in the domain and had registered it in bad faith. The registrant argued that "barcelona" is a common geographic term and that he had legitimate business plans.

**Issue:** Whether a geographic name (barcelona) could function as a trademark for UDRP purposes, and whether the City of Barcelona could compel transfer of the domain name.

**Holding:** The WIPO panel denied the City's complaint, holding that "barcelona" was primarily a geographic indication rather than a trademark in which the City held enforceable rights under the UDRP. The panel found that the City had not demonstrated that "Barcelona" functioned as a distinctive source identifier for services, which is required for UDRP protection.
**Significance:** Established that geographic names, even those of major cities, are not automatically entitled to trademark protection under the UDRP, requiring evidence that the name functions as a source identifier.
Set important limitations on the scope of UDRP protection for governmental and municipal entities seeking to recover domain names.
Influenced subsequent UDRP decisions involving geographic and place-name domain disputes worldwide.

---

### Case 8.44: Victoria's Secret Stores Brand Management, Inc. v. Moseley (2003) — U.S. Supreme Court

**Date Decided:** March 4, 2003

**Court:** U.S. Supreme Court
Case citation: 537 U.S. 419 (2003)

**Facts:** Victor and Cathy Moseley operated a small retail store called "Victor's Little Secret" in Elizabethtown, Kentucky, selling adult novelty items, lingerie, and adult videos. Victoria's Secret, the well-known lingerie retailer, sued under the Federal Trademark Dilution Act (FTDA), alleging that the similar name diluted the distinctiveness of the Victoria's Secret mark, even without evidence of actual harm or confusion.

**Issue:** Whether a trademark owner must prove actual dilution (evidence of actual harm to the mark's distinctiveness) or whether a likelihood of dilution is sufficient under the Federal Trademark Dilution Act.

**Holding:** The Supreme Court held that the FTDA requires proof of actual dilution, not merely a likelihood of dilution. The Court rejected Victoria's Secret's argument that the mere fact of a similar name being used in a different context constituted dilution, requiring instead concrete evidence of lessening of the mark's selling power or distinctiveness. The case was remanded for the Sixth Circuit to apply the actual dilution standard.
**Significance:** Established the "actual dilution" requirement under the original Federal Trademark Dilution Act, significantly limiting the scope of dilution protection available to famous trademark owners.
Prompted Congress to amend the FTDA through the Trademark Dilution Revision Act of 2006 (TDRA), which restored the "likelihood of dilution" standard and clarified the scope of famous mark protection.
Balanced the interests of famous trademark owners against the rights of small businesses to choose descriptive or suggestive names, preventing overreach in dilution claims.

---

### Case 8.45: Playboy Enterprises International, Inc. v. Welles (2004) — U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** March 5, 2004

**Court:** U.S. Court of Appeals for the Ninth Circuit
Case citation: 276 F. Supp. 2d 1184 (S.D. Cal. 2003), aff'd in part, 378 F.3d 966 (9th Cir. 2004)

**Facts:** Terri Welles, a former Playboy Playmate of the Year, operated a personal website on which she described herself as a "Playmate" and "Playmate of the Year 1981." Playboy Enterprises sued for trademark infringement, arguing that Welles's use of Playboy's trademarks on her website was unauthorized and misleading. Welles argued that her use was truthful and descriptive — she genuinely was a Playmate of the Year.

**Issue:** Whether a former model's use of her employer's trademarks on a personal website to truthfully describe her own status constituted trademark infringement or was protected as nominative fair use.

**Holding:** The Ninth Circuit held that Welles's use of Playboy's trademarks was protected by the nominative fair use doctrine. Because there was no other way to describe her achievement without using Playboy's terms, the use was truthful and did not suggest endorsement by Playboy. The court applied the three-factor nominative fair use test: (1) the product or service is not readily identifiable without the trademark; (2) only so much of the mark is used as is reasonably necessary; and (3) the user does nothing to suggest sponsorship or endorsement.
**Significance:** Provided a leading application of the nominative fair use doctrine in the Internet context, establishing that truthful descriptive use of trademarks on personal websites is protected.
Balanced trademark rights against freedom of expression and the right to truthfully describe one's own biography and achievements online.
Established important limitations on trademark owners' ability to control the use of their marks by former affiliates and contractors on the Internet.

---

### Case 8.46: J.P. Morgan Chase & Co. v. Walker; J.P. Morgan Chase & Co. v. Webfunding (2004) — U.S. Court of Appeals for the Ninth Circuit

**Date Decided:** May 28, 2004

**Court:** U.S. Court of Appeals for the Ninth Circuit
Case citation: 388 F.3d 654 (9th Cir. 2004)

**Facts:** Two separate defendants registered domain names incorporating variations of the Chase Manhattan Bank name, including "chase Manhattan.com" and other similar names, and used them to operate websites that offered financial services or redirected users to commercial sites. J.P. Morgan Chase sued under the Anticybersquatting Consumer Protection Act (ACPA), arguing that the domain registrations were made in bad faith to profit from the Chase trademark.

**Issue:** Whether the registration and use of domain names that incorporated slight variations or misspellings of a famous financial services trademark constituted cybersquatting under the ACPA.

**Holding:** The Ninth Circuit held that the domain registrations constituted bad faith cybersquatting under the ACPA. The court found that the defendants' use of variations of the Chase mark to operate competing or deceptive financial services websites demonstrated a clear intent to confuse consumers and profit from the trademark's reputation. The court ordered the domains transferred to J.P. Morgan Chase.
**Significance:** Illustrated the application of the ACPA to financial services trademarks, an area of significant commercial importance in the domain name dispute landscape.
Confirmed that variations, misspellings, and minor modifications of famous trademarks in domain names can constitute cybersquatting when combined with bad-faith intent to profit.
Contributed to the development of the "confusing similarity" and "bad faith" analyses under the ACPA, particularly for famous marks in the financial sector.

---

### Case 8.47: Louis Vuitton Malletier S.A. v. Haute Diggity Dog, LLC (2007) — U.S. Court of Appeals for the Fourth Circuit

**Date Decided:** May 15, 2007

**Court:** U.S. Court of Appeals for the Fourth Circuit
Case citation: 507 F.3d 252 (4th Cir. 2007)

**Facts:** Haute Diggity Dog manufactured and sold chew toys for dogs shaped like designer handbags, including a product called "Chewy Vuiton" that resembled Louis Vuitton's iconic monogram pattern and bag shape. Louis Vuitton sued for trademark infringement and dilution, arguing that the Chewy Vuiton toys diluted the distinctiveness of and caused confusion with the Louis Vuitton brand.

**Issue:** Whether a parody product for dogs that resembled a luxury handbag constituted trademark infringement or dilution.

**Holding:** The Fourth Circuit held that the Chewy Vuiton dog toys were a protected parody and did not constitute trademark infringement or dilution. The court found that the products were not likely to cause confusion because consumers would recognize the humor and understand that the chew toys were not affiliated with Louis Vuitton. The court also found no dilution because the parody did not diminish the distinctiveness of the Louis Vuitton mark.
**Significance:** Established important protections for trademark parody in the commercial context, extending the parody defense beyond non-commercial speech.
Clarified that the "likelihood of confusion" analysis for parody must account for the consumer's ability to perceive the humorous or critical commentary in the parodic use.
Balanced luxury brand protection against free expression and commercial parody rights, influencing subsequent cases involving fashion parodies and humorous product imitations.

---

### Case 8.48: Tiffany (NJ) Inc. v. eBay Inc. (2008) — U.S. District Court for the Southern District of New York

**Date Decided:** July 14, 2008

**Court:** U.S. District Court for the Southern District of New York
Case citation: 600 F.3d 93 (2d Cir. 2010) (affirming 253 F.R.D. 553 (S.D.N.Y. 2008))

**Facts:** Tiffany & Co., the luxury jeweler, sued eBay after discovering that a significant percentage of Tiffany-branded jewelry listed on eBay's auction platform was counterfeit. Tiffany argued that eBay was liable for direct and contributory trademark infringement because it knowingly facilitated the sale of counterfeit goods on its platform. eBay countered that it had implemented anti-counterfeiting measures and was not liable for individual sellers' trademark violations.

**Issue:** Whether an online marketplace can be held liable for contributory trademark infringement based on the sale of counterfeit goods by third-party sellers on its platform.

**Holding:** Judge Richard Sullivan held that eBay was not liable for contributory trademark infringement. The court found that eBay did not have specific knowledge of which listings contained counterfeit Tiffany goods and that its general awareness that some counterfeits might be sold was insufficient to establish the requisite knowledge for contributory liability. eBay's anti-counterfeiting efforts, while imperfect, demonstrated sufficient good faith.
**Significance:** Established the "specific knowledge" standard for contributory trademark infringement by online marketplaces, requiring knowledge of specific infringing listings rather than general awareness of potential infringement.
Shielded online marketplace operators from broad contributory liability, provided they implement reasonable anti-counterfeiting measures and respond to specific complaints.
Influenced the European approach to online marketplace liability, including the European Court of Justice's decision in L'Oréal v. eBay.

---

### Case 8.49: LVMH Mo t Hennessy Louis Vuitton v. eBay Inc. (2008) — Tribunal de Grande Instance de Paris (Paris Commercial Court)

**Date Decided:** June 30, 2008

**Court:** Tribunal de Grande Instance de Paris (Commercial Chamber)
Case citation: TGI Paris, 3e ch., 30 juin 2008, RG n 06/15 597

**Facts:** LVMH, the luxury goods conglomerate, sued eBay in French courts for trademark infringement, alleging that eBay's platform facilitated the sale of counterfeit LVMH products (Louis Vuitton bags, Dior perfume) and that eBay's advertising campaigns referencing LVMH brands constituted trademark infringement. LVMH sought significant damages and an injunction against the sale of its branded goods on eBay.

**Issue:** Whether eBay could be held liable for trademark infringement and unfair competition based on the sale of counterfeit and authentic luxury goods by third-party sellers on its platform under French and EU law.

**Holding:** The Paris Commercial Court held eBay liable for trademark infringement, ordering eBay to pay 38.6 million in damages to LVMH. The court found that eBay had not taken sufficient measures to prevent the sale of counterfeit goods and that its advertising use of LVMH trademarks to attract buyers constituted trademark infringement. However, the court distinguished between counterfeit and authentic goods, allowing the resale of authentic LVMH products.
**Significance:** Demonstrated the divergence between U.S. and European approaches to online marketplace liability for trademark infringement, with European courts imposing more stringent obligations on platform operators.
Established that online marketplaces may face liability under French trademark law for failure to adequately police counterfeit sales, even when individual sellers are the direct infringers.
Prompted eBay and other marketplaces to significantly enhance their anti-counterfeiting measures and brand protection programs globally.

---

### Case 8.50: Universal City Studios, Inc. v. Reimerdes (2600) (2000) — U.S. Court of Appeals for the Second Circuit

**Date Decided:** November 28, 2000

**Court:** U.S. Court of Appeals for the Second Circuit
Case citation: 111 F. Supp. 2d 294 (S.D.N.Y. 2000), aff'd, 82 F. Supp. 2d 211 (S.D.N.Y. 2000)

**Facts:** Eric Corley (publisher of the hacker magazine 2600) posted the DeCSS source code on his website and linked to other sites hosting DeCSS. DeCSS is a computer program that circumvents the Content Scramble System (CSS) encryption used on DVDs. The MPAA sued under the Digital Millennium Copyright Act (DMCA) 1201, which prohibits the trafficking in circumvention technology, seeking to enjoin the publication and linking.

**Issue:** Whether the posting and linking to DeCSS circumvention code violated the DMCA's anti-circumvention provisions, and whether such prohibition violated the First Amendment.

**Holding:** The Second Circuit upheld the injunction against posting DeCSS code, holding that the DMCA's anti-trafficking provisions applied to computer code even though code is expressive speech. The court rejected First Amendment arguments, finding that the regulation was content-neutral, served an important government interest (copyright protection), and left open alternative channels of communication. However, the court limited the injunction to linking to sites containing DeCSS code with the intent to circumvent.
**Significance:** Established the constitutionality of the DMCA's anti-circumvention provisions as applied to the publication of circumvention technology, creating a significant tension between copyright enforcement and free expression.
Confirmed that computer source code receives First Amendment protection but can be subject to content-neutral regulation under the DMCA.
Became a foundational case in the digital rights movement, illustrating the potential for copyright law to restrict the publication of technological information.

---

### Case 8.51: Chamberlain Group, Inc. v. Skylink Technologies, Inc. (2004) — U.S. Court of Appeals for the Federal Circuit

**Date Decided:** August 31, 2004

**Court:** U.S. Court of Appeals for the Federal Circuit
Case citation: 381 F.3d 1178 (Fed. Cir. 2004)

**Facts:** Chamberlain manufactured garage door openers with a rolling-code security system that prevented unauthorized access. Skylink manufactured a universal garage door remote that was compatible with Chamberlain's openers. Chamberlain sued under the DMCA 1201, arguing that Skylink's remote circumvented Chamberlain's access control technology by bypassing the rolling-code authentication sequence.

**Issue:** Whether the DMCA's anti-circumvention provisions prohibited the manufacture and sale of a universal remote control that was compatible with a competitor's access control system.

**Holding:** The Federal Circuit held that Skylink's universal remote did not violate the DMCA because: (1) Chamberlain's rolling code was an access control but consumers had authorized access; (2) the DMCA does not create a new property right that allows copyright holders to control access to functional aspects of their products; and (3) Skylink's use did not violate any of the exclusive rights under 106. The court rejected Chamberlain's attempt to use the DMCA as a tool for market control.
**Significance:** Established critical limitations on the scope of the DMCA's anti-circumvention provisions, preventing copyright owners from using 1201 to control after-market competition or product interoperability.
Held that the DMCA does not create a new property right in access control technology itself — it only protects against circumvention that leads to copyright infringement.
Provided an important precedent protecting consumer rights, product interoperability, and aftermarket competition from overreach through DMCA circumvention claims.

---

### Case 8.52: Alice Corporation Pty. Ltd. v. CLS Bank International (2014) — U.S. Supreme Court

**Date Decided:** June 19, 2014

**Court:** U.S. Supreme Court
Case citation: 573 U.S. 208 (2014)

**Facts:** Alice Corporation held several patents covering a computerized system for mitigating "settlement risk" in financial transactions by using a third-party intermediary. CLS Bank implemented a similar system and Alice sued for patent infringement. CLS Bank argued that Alice's patents were invalid because they claimed abstract ideas implemented on a generic computer. The Federal Circuit had issued a fractured en banc opinion with seven different concurrences.

**Issue:** Whether claims directed to computer-implemented methods for mitigating financial settlement risk were patent-eligible under 35 U.S.C. 101, or whether they merely claimed an abstract idea.

**Holding:** In a unanimous opinion by Justice Thomas, the Supreme Court held that Alice's claims were patent-ineligible. The Court established a two-step test: (1) determine whether the claims are directed to an abstract idea; and if so, (2) determine whether the claims contain an "inventive concept" — an element or combination of elements that is "sufficient to ensure that the patent in practice amounts to significantly more than a patent upon the [abstract idea] itself." Merely implementing an abstract idea on a generic computer was insufficient.
**Significance:** Created the "Alice two-step test" for software patent eligibility under 101, the dominant framework for evaluating software and business method patents in the United States.
Triggered a massive wave of invalidations of software and business method patents, fundamentally reshaping the U.S. patent landscape for digital technologies.
Remains the most cited Supreme Court decision on patent eligibility and continues to govern the validity of thousands of software-related patent claims.

---

### Case 8.53: Mayo Collaborative Services v. Prometheus Laboratories, Inc. (2012) — U.S. Supreme Court

**Date Decided:** March 20, 2012

**Court:** U.S. Supreme Court
Case citation: 566 U.S. 66 (2012)

**Facts:** Prometheus Laboratories held patents covering a method for determining the optimal dosage of thiopurine drugs by measuring metabolite levels in a patient's blood. Mayo Collaborative Services developed a competing test and Prometheus sued for patent infringement. Mayo argued that the patents were invalid because they covered a natural law (the relationship between metabolite levels and drug efficacy) rather than a patentable invention.

**Issue:** Whether a medical diagnostic method that applies a natural law (the correlation between drug metabolite levels and therapeutic efficacy) through conventional post-solution activity constitutes patent-eligible subject matter under 101.

**Holding:** In a unanimous opinion by Justice Breyer, the Supreme Court held that Prometheus's claims were patent-ineligible. The Court established that claims that set forth natural laws and then add only "conventional" or "well-understood" steps to apply those laws do not contain an "inventive concept" sufficient to transform the natural law into a patent-eligible application.
**Significance:** Established the foundational framework for evaluating the patent eligibility of claims involving natural laws, natural phenomena, and abstract ideas — the framework later formalized as the Alice two-step test.
Significantly limited the patentability of diagnostic methods, personalized medicine protocols, and medical treatment optimization processes.
Provided the doctrinal foundation that made possible the subsequent Alice decision and the broader reformation of software and biotechnology patent eligibility standards.

---

### Case 8.54: Bilski v. Kappos (2010) — U.S. Supreme Court

**Date Decided:** June 28, 2010

**Court:** U.S. Supreme Court
Case citation: 561 U.S. 593 (2010)

**Facts:** Bernard Bilski and Rand Warsaw filed a patent application for a method of hedging risk in commodities trading. The Patent Office rejected the application, and the Federal Circuit affirmed, holding that the claimed method was not patent-eligible because it was not tied to a particular machine or apparatus and did not transform an article into a different state or thing (the "machine-or-transformation" test). Bilski appealed to the Supreme Court.

**Issue:** Whether a method for hedging risk in commodities trading constitutes patent-eligible subject matter under 101, and whether the "machine-or-transformation" test is the exclusive test for patent eligibility of processes.

**Holding:** The Supreme Court unanimously affirmed the rejection of Bilski's patent application, holding that the claimed hedging method was an abstract idea not eligible for patent protection. However, the Court also held that the "machine-or-transformation" test is not the exclusive test for process patent eligibility — it is only a useful and important clue. The Court left open the possibility that some business method patents could be valid if they contain an inventive concept.
**Significance:** Rejecting the exclusive use of the "machine-or-transformation" test while confirming its importance as a clue — a compromise that paved the way for the more definitive Mayo and Alice frameworks.
Established that abstract ideas, including certain business methods, are not patent-eligible under 101, providing a partial but significant curb on business method patents.
Set the stage for the Mayo and Alice decisions, which together established the definitive two-step framework for evaluating patent eligibility in the digital age.

---

### Case 8.55: Association for Molecular Pathology v. Myriad Genetics, Inc. (2013) — U.S. Supreme Court

**Date Decided:** June 13, 2013

**Court:** U.S. Supreme Court
Case citation: 569 U.S. 576 (2013)

**Facts:** Myriad Genetics held patents covering isolated DNA sequences corresponding to the BRCA1 and BRCA2 genes, mutations in which are associated with significantly increased risk of breast and ovarian cancer. The Association for Molecular Pathology and other plaintiffs challenged the patents, arguing that naturally occurring DNA sequences, even when isolated from the body, are products of nature and not patent-eligible. Myriad argued that isolating the DNA required significant human intervention and that the isolated molecules were chemically different from natural DNA.

**Issue:** Whether naturally occurring DNA sequences, when isolated from the human body, constitute patent-eligible subject matter under 101, and whether synthetically created complementary DNA (cDNA) is patent-eligible.

**Holding:** In a unanimous opinion by Justice Thomas, the Supreme Court held that naturally occurring DNA segments are products of nature and not patent-eligible. The Court emphasized that Myriad did not create or alter the genetic information encoded in the BRCA genes — it merely discovered their location and sequence. However, the Court held that synthetically created cDNA, which does not occur in nature because it contains only exons with introns removed, is patent-eligible because it is not naturally occurring.
**Significance:** Established that naturally occurring genetic sequences are not patent-eligible, regardless of the effort required to isolate them, with profound implications for biotechnology, genomic medicine, and the diagnostic testing industry.
Maintained patent eligibility for cDNA and other synthetically created biological molecules, preserving incentives for certain types of biotechnological innovation.
Triggered significant changes in the biotechnology patent landscape, with many gene-related patents being invalidated or narrowed following the decision.

---

### Case 8.56: Herm s International v. Mason Rothschild (2023) — U.S. District Court for the Southern District of New York

**Date Decided:** February 8, 2023

**Court:** U.S. District Court for the Southern District of New York
Case citation: No. 1:22-cv-00384 (S.D.N.Y. 2023)

**Facts:** Artist Mason Rothschild created and sold NFTs called "MetaBirkins" — fuzzy, fur-covered digital depictions of the Herm s Birkin bag. Herm s sued for trademark infringement, dilution, and false designation of origin, arguing that the MetaBirkin NFTs used the Birkin name and bag design to confuse consumers into believing Herm s authorized or sponsored the NFT collection. Rothschild argued that the MetaBirkins were protected artistic expression under the First Amendment and the Rogers v. Grimaldi test.

**Issue:** Whether the sale of NFTs depicting furry, satirical versions of a luxury handbag constituted trademark infringement or was protected artistic expression.

**Holding:** A federal jury found in favor of Herm s on all counts, awarding $133,000 in damages. The court held that Rothschild's use of the Birkin mark was not protected artistic expression because the primary purpose was commercial exploitation rather than artistic commentary, and consumers were likely to be confused about the source or sponsorship of the MetaBirkin NFTs.
**Significance:** First major trademark trial involving NFTs, establishing that digital art and NFT collections are subject to traditional trademark law principles.
Demonstrated that the commercial nature of NFT sales can defeat First Amendment artistic expression defenses when the primary purpose is commercial rather than expressive.
Set important precedent for the intersection of intellectual property law and the NFT market, with implications for digital artists, brands, and NFT platforms.

---

### Case 8.57: Blizzard Entertainment, Inc. v. Bossland GmbH (2018) — U.S. District Court for the Central District of California

**Date Decided:** January 9, 2018

**Court:** U.S. District Court for the Central District of California
Case citation: No. 2:17-cv-01449-ODW (C.D. Cal. 2018)

**Facts:** Bossland GmbH, a German company, developed and sold "HearthBuddy," a bot program that automated gameplay in Blizzard's digital card game Hearthstone. The bot allowed users to play the game automatically, earning rewards and progressing without human input. Blizzard sued Bossland for copyright infringement, circumvention of technological protection measures under the DMCA, and breach of contract, arguing that the bot violated Blizzard's end-user license agreement (EULA) and terms of service.

**Issue:** Whether the creation and sale of game bot software that automates gameplay constitutes copyright infringement, DMCA circumvention, and breach of contract.

**Holding:** Judge Andre Birotte Jr. granted Blizzard's motion for default judgment (Bossland failed to appear), holding that Bossland's bot software constituted copyright infringement (by creating unauthorized derivative works through interaction with Blizzard's game client), violated the DMCA's anti-circumvention provisions, and breached the EULA. The court awarded Blizzard statutory damages of $8.6 million.
**Significance:** Established that game bot software can constitute both copyright infringement (unauthorized derivative works) and DMCA circumvention, providing game developers with powerful legal tools against cheat and bot developers.
Confirmed that EULA violations in the context of game cheating can support substantial statutory damages awards.
Contributed to the developing legal framework for enforcement against game cheating and automation software, complementing the Blizzard v. BNETD and Epic v. Apple decisions.

---

### Case 8.58: Epic Games, Inc. v. Apple Inc. (2021) — U.S. District Court for the Northern District of California

**Date Decided:** September 10, 2021

**Court:** U.S. District Court for the Northern District of California
Case citation: No. 4:20-cv-05640-YGR (N.D. Cal. 2021)

**Facts:** Epic Games, developer of the popular game Fortnite, deliberately implemented a direct payment system in its iOS app to bypass Apple's App Store in-app purchase mechanism and Apple's 30% commission. Apple removed Fortnite from the App Store. Epic sued Apple, alleging that Apple's App Store practices violated federal antitrust law and California's unfair competition law by maintaining an illegal monopoly in the iOS app distribution market. Apple counterclaimed for breach of contract and Epic's own antitrust violations.

**Issue:** Whether Apple's App Store practices, including the 30% commission and prohibition on alternative payment methods, violated federal and state antitrust laws.

**Holding:** Judge Yvonne Gonzalez Rogers ruled largely in favor of Apple on the federal antitrust claims, finding that Epic had not demonstrated that Apple possessed monopoly power in the relevant market (which the court defined as "digital mobile gaming transactions," not the broader "iOS app distribution" market). However, the court found in favor of Epic on the California unfair competition claim, holding that Apple's anti-steering provisions — which prohibited developers from informing users about alternative purchasing options — were anticompetitive.
**Significance:** First major U.S. judicial decision addressing the competitive dynamics of mobile app store ecosystems, with global implications for the regulation of digital platforms.
The finding on anti-steering provisions led to the California Anti-Steering Act and influenced regulatory actions worldwide, including the EU Digital Markets Act and similar legislation in Japan and South Korea.
Illustrates the complex intersection of intellectual property, competition law, and platform governance in the digital economy, with ongoing implications for app developers and platform operators worldwide.
The fifty-eight cases examined in this Part illuminate the central tensions in contemporary intellectual property law as it adapts to the digital environment. The ReDigi decision underscores the persistence of physical-world legal concepts — the first sale doctrine — in shaping the boundaries of digital commerce. The Viacom v. YouTube litigation established the DMCA safe harbor as the legal foundation of the user-generated content economy, while revealing its limitations. The UMG v. MP3Tunes and UMG v. Veoh cases refined the contours of safe harbor protection for cloud services and UGC platforms. The Perfect 10 v. Amazon/Google, Kelly v. Arriba Soft, and Authors Guild v. Google line of cases established the transformative use doctrine as the legal foundation for search engine indexing and mass digitization. The CJEU's judgments in GS Media, The Pirate Bay, Svensson, and BestWater expanded the concept of "communication to the public" to encompass linking and indexing, fundamentally reshaping the liability landscape for online intermediaries in Europe. The Aereo decision applied functional equivalence reasoning to internet-based television services, while the ElcomSoft and Megaupload cases tested the criminalization of circumvention technology and file-sharing service operators. Article 17 of the DSM Directive represents the most ambitious legislative intervention in digital copyright in a generation, shifting the balance of power between rights holders and platforms. The Blizzard v. Bossland and Epic v. Apple cases illustrate the growing intersection of IP law with competition policy in digital platform ecosystems. And the UK Supreme Court's decision in UGC v. MGN confronts the frontier challenge of AI-generated content, establishing a framework that prioritizes human creativity while acknowledging the transformative impact of artificial intelligence.
The domain name disputes — from Kremen v. Cohen to the WIPO UDRP framework — demonstrate how traditional property and trademark concepts have been adapted to the unique characteristics of the internet's addressing system. Trademark law on the internet, as illustrated by Victoria's Secret v. Moseley and Playboy v. Welles, continues to navigate the tension between brand protection and freedom of expression in the digital environment. And the emerging challenges of 3D printing and AI-generated content point toward the next frontier of intellectual property law in the digital age.
Together, these cases reveal a legal system in dynamic tension: between the rights of copyright holders and the freedoms of platform operators and users; between physical-world legal doctrines and digital realities; between national legal traditions and the borderless nature of the internet; between established intellectual property frameworks and the disruptive force of emerging technologies; and between public enforcement and private ordering. The law's response to these tensions will continue to evolve, and the cases in this Part provide the doctrinal foundation upon which that evolution will be built.
End of Part Eight — Intellectual Property & Digital Content# Global Cyber Law Compendium —Volume II
Part Eight: Intellectual Property & Digital Content (Additions)
Cases 8.59—.88

---

### Case 8.59: In re Napster / A&M Records v. Napster —Aftermath & Sean Fanning (2001)

**Date Decided:** July 26, 2001 (9th Circuit mandate)

**Court:** United States Court of Appeals for the Ninth Circuit

**Facts:** Following the landmark Ninth Circuit ruling holding Napster liable for contributory and vicarious copyright infringement, the district court issued a modified injunction effectively shutting down the peer-to-peer file-sharing service. Napster filed for Chapter 11 bankruptcy in 2002. Its assets were later acquired by Roxio and rebranded as a legal music service, while founder Shawn Fanning faced no personal criminal charges but saw his creation become the defining symbol of digital piracy's first wave.

**Issue:** What were the legal and practical consequences of the Napster litigation for its founders, investors, and the broader P2P technology landscape?

**Holding:** Napster was permanently enjoined and ceased operations. Fanning was not individually sued; the liability fell on the corporate entity. The case established that centralized P2P services with actual knowledge of infringement and the ability to police it could be held liable, even without direct participation in copying.
**Significance:** Established the "centralized index" test for P2P liability, distinguishing Napster from later decentralized systems like Gnutella and BitTorrent.
Catalyzed the transition from litigation-only strategies toward licensed digital music distribution (iTunes Store launched 2003).
Demonstrated the limits of corporate liability shields for tech founders operating in copyright-intensive environments.

---

### Case 8.60: United States v. Kim Dotcom / Megaupload (2012–2024)

**Date Decided:** Arrest January 20, 2012; extradition proceedings concluded 2024

**Court:** United States District Court for the Eastern District of Virginia (indictment); New Zealand High Court & Court of Appeal (extradition); New Zealand Supreme Court (2024)

**Facts:** The U.S. Department of Justice indicted Kim Dotcom (born Kim Schmitz) and several associates on charges of criminal copyright infringement, racketeering, money laundering, and wire fraud arising from the operation of Megaupload, a Hong Kong-registered file-hosting service. Megaupload allegedly generated over $175 million in criminal proceeds by facilitating the distribution of pirated films, music, and software. New Zealand authorities arrested Dotcom in a dramatic armed raid at his Auckland mansion. After years of litigation over extradition legality, search warrant defects, and diplomatic tensions, New Zealand courts ultimately ruled Dotcom was eligible for extradition in 2024.

**Issue:** Whether a foreign-based cloud storage operator could face U.S. criminal copyright liability, and whether New Zealand law required extradition for conduct not constituting a crime under New Zealand's Copyright Act (specifically, the lack of a domestic "criminal copyright" offense for mere facilitation).

**Holding:** The New Zealand Supreme Court upheld the extradition eligibility ruling. Dotcom remained in New Zealand pending final surrender, with his legal team continuing to pursue appeals on procedural and human-rights grounds. Co-defendants Mathias Ortmann, Bram van der Kolk, and Finn Batato also faced extradition. The U.S. government simultaneously pursued civil forfeiture of Megaupload assets.
**Significance:** Tested the limits of U.S. extraterritorial criminal copyright enforcement against cloud services with no direct U.S. presence.
Raised critical questions about the destruction of evidence when the U.S. seized Megaupload's servers without preserving user data'mpacting lawful users worldwide.
Exposed tensions between domestic copyright law frameworks and bilateral extradition treaties, particularly the dual-criminality requirement.
Became a symbol for digital-rights activism and government overreach in the "Megaupload era."

---

### Case 8.61: Arista Records v. Lime Group / LimeWire (2010)

**Date Decided:** May 26, 2010 (permanent injunction); October 26, 2010 (final judgment)

**Court:** United States District Court for the Southern District of New York

**Facts:** LimeWire was a peer-to-peer file-sharing application that, unlike Napster, used a decentralized Gnutella network but maintained a centralized server for search functionality and software updates. Thirteen record labels sued Lime Group (LimeWire's parent) and founder Mark Gorton, alleging massive facilitation of copyright infringement. Evidence showed LimeWire internally tracked infringement rates and explored licensing models while continuing to enable unauthorized distribution. An estimated 99% of files exchanged via LimeWire were infringing.

**Issue:** Whether LimeWire was liable for inducement of copyright infringement under Grokster and for direct infringement due to its centralized control mechanisms, and what remedies were appropriate.

**Holding:** Judge Kimba Wood granted a permanent injunction, finding LimeWire intentionally facilitated infringement and that no lesser remedy would suffice. She later found LimeWire liable for wilful infringement and awarded statutory damages of $105 million (later settled for $105 million). Gorton was held personally liable.
**Significance:** Extended Grokster's inducement theory to a service with hybrid centralized/decentralized architecture, showing that "partial" decentralization does not immunize operators.
Established that internal awareness of overwhelming infringement, combined with failure to implement meaningful filters, constitutes inducement.
Demonstrated courts' willingness to impose personal liability on founders/operators who maintain hands-on control.

---

### Case 8.62: Universal Music Australia v. Sharman License Holdings (Kazaa) (2005)

**Date Decided:** September 5, 2005

**Court:** Federal Court of Australia

**Facts:** Kazaa was one of the world's most popular P2P file-sharing applications, developed by Niklas Zennstrm and Janus Friis (who later founded Skype). Unlike Napster, Kazaa operated on a FastTrack decentralized protocol but used supernodes'rdinary users' computers performing indexing functions'o route searches. Australian record labels sued Kazaa's operator, Sharman License Holdings, which was incorporated in Vanuatu and headquartered in Australia.

**Issue:** Whether Kazaa's operators authorized copyright infringement under Australian law, given the decentralized nature of the FastTrack network, and whether they had the power to prevent infringement.

**Holding:** Justice Murray Wilcox found that Kazaa had "authorized" users to infringe copyright under Australian law. He ordered Sharman to modify the software to include keyword-based copyright filters (non-optional). The judgment noted that Sharman could have implemented filtering technology and chose not to. Sharman subsequently settled with the recording industry for a reported $100+ million and transitioned to a licensed content distribution model.
**Significance:** Established the "authorization" doctrine in Australian copyright law as a powerful tool against P2P operators, diverging from the U.S. "inducement" approach.
Demonstrated that courts could order specific technological modifications to infringing software'n early form of "injunctive code."
Informed subsequent legislative reforms in Australia, including the 2005 amendments to the Copyright Act introducing safe harbor provisions (mirroring U.S. DMCA §512).

---

### Case 8.63: The Pirate Bay Trial / Prosecutor v. Sunde, Neij, Svartholm & Lundstrm (2012)

**Date Decided:** February 17, 2012 (appellate court); February 1, 2012 (Supreme Court denial); imprisonment served 2014–2015

**Court:** Svea Court of Appeal (Sweden); Sveriges Hgsta Domstol (Supreme Court)

**Facts:** The Pirate Bay (TPB), founded in 2003 by Fredrik Neij, Gottfrid Svartholm, and Peter Sunde with financial backing from Carl Lundstrm, operated as a BitTorrent tracker facilitating the finding and downloading of torrent files. TPB did not host infringing content itself but provided index and tracker services. Swedish prosecutors charged the four defendants with "assisting [in making available] copyrighted content." The 2009 district court conviction was appealed, and the Svea Court of Appeal reduced sentences but increased damages.

**Issue:** Whether operating a BitTorrent tracker and providing search/index functionality for .torrent files constituted criminal facilitation of copyright infringement under Swedish law, and whether TPB's operators could be held personally liable despite not hosting infringing files.

**Holding:** The Svea Court of Appeal upheld the convictions but reduced prison sentences from one year to between four and ten months. It increased combined damages to 46 million SEK (~$6.6 million USD). The Swedish Supreme Court refused to hear the case. Neij served his sentence in 2014; Sunde served eight months in 2014–2015 after arrest at a farm in southern Sweden. Svartholm was arrested in Cambodia and served his sentence in Sweden. Lundstrm's conditional sentence was upheld.
**Significance:** Established that operating a torrent tracker constitutes criminal copyright facilitation under Swedish and, by extension, EU law, even without hosting infringing files.
Demonstrated the personal criminal liability of platform operators, a deterrent precedent for similar services worldwide.
TPB continued to operate through multiple domain changes and decentralized infrastructure, illustrating the "whack-a-mole" problem in enforcement.
Became a rallying point for digital rights movements (Pirate Party, internet freedom activism) and influenced copyright policy debates across Europe.

---

### Case 8.64: Metro-Goldwyn-Mayer Studios v. Grokster, Ltd. (2006) —Ninth Circuit Remand

**Date Decided:** August 2006 (post-remand settlement); original SCOTUS ruling June 27, 2005

**Court:** United States Court of Appeals for the Ninth Circuit (remand); United States Supreme Court (original decision)

**Facts:** After the Supreme Court's landmark Grokster decision establishing the inducement theory of copyright liability (Case 8.45 in the main volume), the case was remanded to the Ninth Circuit for further proceedings. StreamCast Networks (operator of Morpheus) and Grokster both faced summary judgment motions. StreamCast attempted to argue that it had not engaged in the "purposeful, culpable expression and conduct" required under the inducement standard.

**Issue:** Whether Grokster and StreamCast were entitled to summary judgment on inducement claims, and whether the evidence demonstrated the requisite intent to induce infringement.

**Holding:** Neither defendant survived the remand. Grokster shut down in November 2005, before the Ninth Circuit ruled. StreamCast's defenses collapsed as internal documents revealed marketing campaigns targeting Napster users and internal communications acknowledging infringement as the primary use case. The Ninth Circuit ultimately upheld summary judgment against StreamCast in 2008, and the company dissolved.
**Significance:** Confirmed that internal corporate communications and marketing strategies targeting known infringing audiences constitute strong evidence of inducement.
Established the post-Grokster enforcement playbook: plaintiffs could use discovery to uncover intent, making liability almost inevitable for services designed around infringement.
Drove the next generation of P2P technologies toward genuine non-infringing uses (e.g., BitTorrent's legitimate content distribution).

---

### Case 8.65: Columbia Pictures Industries v. Fung (IsoHunt) (2010)

**Date Decided:** December 21, 2010 (9th Circuit opinion); March 2013 (settlement)

**Court:** United States Court of Appeals for the Ninth Circuit

**Facts:** IsoHunt, operated by Gary Fung from Canada, was a BitTorrent indexing site that organized torrent files by category (movies, music, software, games). Unlike The Pirate Bay, IsoHunt implemented a keyword-filtering system in response to litigation, but the filters were easily circumvented. The MPAA sued, and the district court granted summary judgment based on evidence that 95% of files tracked through IsoHunt were infringing.

**Issue:** Whether IsoHunt's filtering system satisfied the standard for avoiding inducement liability, and whether a torrent indexing site could be held liable for the infringing activity of its users under the Grokster inducement framework.

**Holding:** The Ninth Circuit affirmed summary judgment in favor of the studios, holding that IsoHunt's "nominally present" filtering system was insufficient. The court found that Fung's communications, including forum posts encouraging users to share copyrighted content, demonstrated inducement. The injunction required IsoHunt to remove all infringing torrents' de facto shutdown. The parties settled in March 2013 for $110 million (largely symbolic, as Fung had limited assets).
**Significance:** Clarified that minimal or ineffective filtering systems do not satisfy the "reasonable steps" standard for avoiding inducement liability.
Established that operator communications in forums and community features can serve as evidence of inducement.
Demonstrated the extraterritorial reach of U.S. copyright law against operators based in other countries (Canada).

---

### Case 8.66: United States v. Anton Nadyrshin / Hotfile Criminal Case (2014)

**Date Decided:** September 2014 (civil settlement); related criminal proceedings

**Court:** United States District Court for the Southern District of New York

**Facts:** Hotfile was a one-click file-hosting service founded in 2006 that grew to become one of the top 100 most-visited websites globally. Hotfile's business model incentivized uploaders by paying them based on download volume, creating financial motivation for distributing popular (often copyrighted) content. The MPAA sued in 2011, and Hotfile's CEO, Anton Nadyrshin, was investigated for criminal copyright infringement. Hotfile's affiliate program paid uploaders up to $15 per 1,000 downloads of popular files.

**Issue:** Whether a file-hosting service's financial incentive structure (paying uploaders per download) constituted inducement of copyright infringement, and whether Hotfile could claim DMCA safe harbor protection.

**Holding:** Hotfile settled the civil case with the MPAA for $80 million in 2013 and agreed to cease operations. The court had previously ruled that Hotfile's DMCA safe harbor defense was substantially weakened by its "right and ability to control" infringing activity through the affiliate program and its failure to implement repeat-infringer policies. No criminal charges were ultimately filed against Nadyrshin, but the case was closely monitored by the DOJ.
**Significance:** Established that financial incentive programs for uploaders undermine DMCA safe harbor protections by demonstrating "right and ability to control" infringing activity.
Created the "pay-per-download" doctrine: services that financially reward uploaders for generating downloads of infringing content face heightened liability.
Influenced the design of legitimate cloud storage services, which now explicitly avoid revenue-sharing with uploaders.

---

### Case 8.67: Rap Genius Google Search Penalty (2014)

**Date Decided:** Late December 2014

**Court:** Google (algorithmic enforcement, not a judicial proceeding)

**Facts:** Rap Genius (later rebranded as Genius), a lyric annotation and discussion platform, was found to be engaging in systematic link manipulation to artificially boost its Google search rankings. The company ran a "Blog Affiliate Program" that offered Twitter followers increased exposure in exchange for linking to Rap Genius pages using specific keyword-rich anchor text (e.g., "lyrics" links to rap-genius.com pages). John Marbach, a blogger, exposed the scheme publicly. Google's webspam team, led by Matt Cutts, responded by applying a manual penalty that removed Rap Genius from top search results for key queries including "lyrics" searches.

**Issue:** Whether search engine algorithmic penalties for manipulative SEO practices constitute a form of "regulation" of online content platforms, and what due-process considerations apply.

**Holding:** Google applied a manual action penalty, dramatically reducing Rap Genius's search visibility. Rap Genius publicly apologized, removed the offending links, and submitted a reconsideration request. Google lifted the penalty approximately 10 days later. The incident cost Rap Genius significant traffic'stimated at a 50%+ drop in visits from organic search during the penalty period.
**Significance:** Illustrated the quasi-regulatory power of dominant search platforms over online businesses, operating without formal legal proceedings or due process.
Established that automated link schemes violating Google's Webmaster Guidelines can trigger swift and severe consequences, even for well-funded startups.
Sparked broader debate about the concentration of gatekeeping power in platform algorithms and the lack of transparency in enforcement.

---

### Case 8.68: Lenz v. Universal Music Corp. (2015)

**Date Decided:** September 14, 2015

**Court:** United States Court of Appeals for the Ninth Circuit

**Facts:** Stephanie Lenz posted a 29-second home video on YouTube showing her toddler dancing to the Prince song "Let's Go Crazy" playing faintly in the background. Universal Music Group, Prince's record label, issued a DMCA takedown notice to YouTube, which removed the video. Lenz, represented by the Electronic Frontier Foundation, sent a DMCA counter-notification and sued Universal under DMCA §512(f), which prohibits misrepresentation of infringement in takedown notices.

**Issue:** Whether a copyright holder must form a good-faith belief that material is actually infringing before issuing a DMCA takedown notice, and whether consideration of fair use is required as part of that assessment.

**Holding:** The Ninth Circuit held that copyright holders must consider fair use before sending DMCA takedown notices. The court rejected Universal's argument that a "subjective good faith" standard was sufficient, ruling instead that a copyright holder must at minimum form an objective good-faith belief that the use is not fair use. The case was remanded for trial on whether Universal actually considered fair use before issuing the takedown.
**Significance:** Established that DMCA takedown notices are not "blanket weapons"'opyright holders must meaningfully consider fair use before deploying them.
Created a procedural requirement that imposes costs on rights holders, potentially chilling legitimate enforcement but protecting fair use.
Became a foundational case for the "dancing baby" standard in automated takedown systems, raising questions about whether bots can satisfy the good-faith requirement.

---

### Case 8.69: Chamberlain Group v. Skylink Technologies —Post-Decision Developments (2004–2015)

**Date Decided:** August 31, 2004 (Federal Circuit); subsequent developments through 2015

**Court:** United States Court of Appeals for the Federal Circuit

**Facts:** Following the Federal Circuit's landmark ruling that the DMCA's anti-circumvention provisions (§1201) did not prohibit Skylink from selling universal garage door openers compatible with Chamberlain's rolling-code system, the broader implications of the decision rippled through consumer electronics and aftermarket industries. The case established that §1201(a)(2) liability requires a nexus between circumvention and copyright infringement, not merely a violation of access controls.

**Issue:** How the Chamberlain decision shaped subsequent anti-circumvention litigation, including the boundaries of §1201 liability for interoperable devices and the "nexus to infringement" test.

**Holding:** The Federal Circuit's framework was adopted in subsequent cases (e.g., StorageTek v. Custom Hardware (2005), Lexmark v. Static Control (2004) at the CAFC). The nexus test became the default standard in circuits addressing §1201, significantly limiting its scope. The case influenced the 2015 triennial DMCA §1201 rulemaking, where the Librarian of Congress expanded exemptions for device unlocking and vehicle repair.
**Significance:** Established the "nexus requirement" for DMCA anti-circumvention liability, preventing rights holders from using §1201 as a general-purpose tool to block interoperability and aftermarket competition.
Inspired legislative and regulatory efforts to narrow §1201's scope, culminating in broader exemptions for consumer device repair and modification.
Demonstrated that access controls protecting non-copyrightable functionality (e.g., garage door signals) fall outside §1201's core purpose.

---

### Case 8.70: The Authors Guild v. Google (Google Books Settlement) (2008)

**Date Decided:** October 28, 2008 (settlement proposed); March 22, 2011 (settlement rejected)

**Court:** United States District Court for the Southern District of New York

**Facts:** Google's Book Search project scanned over 20 million books from library collections and made searchable snippets available online. The Authors Guild and Association of American Publishers sued in 2005 for mass copyright infringement. In 2008, the parties proposed a sweeping settlement that would have created a "Book Rights Registry" to distribute revenue from Google's display of book content, including "orphan works" whose authors were unidentified. The settlement covered all books ever published, granting Google a de facto license to digitize and display them in exchange for revenue sharing.

**Issue:** Whether a class-action settlement could effectively create a compulsory licensing regime for millions of copyrighted works, including orphan works, without explicit legislative authorization.

**Holding:** Judge Denny Chin rejected the proposed settlement in 2011, ruling that it would grant Google rights exceeding what any individual lawsuit could confer, effectively rewriting copyright law through private settlement. Chin noted the settlement would "remake copyright law" by granting Google a license to orphan works' power reserved to Congress. The parties restructured the settlement, and Google continued scanning under fair use defenses, which were ultimately upheld by the Second Circuit in 2015.
**Significance:** Established that class-action settlements cannot effectively legislate new copyright regimes, preserving Congress's exclusive role in copyright policy.
Accelerated the debate over orphan works reform, though no comprehensive legislation was enacted.
Ultimately vindicated Google's fair use defense on appeal, establishing mass digitization for search as transformative under the fair use doctrine.

---

### Case 8.71: Perfect 10, Inc. v. Amazon.com, Inc. (2007) —Thumbnail Images

**Date Decided:** May 15, 2007

**Court:** United States Court of Appeals for the Ninth Circuit

**Facts:** Building on the district court's preliminary injunction ruling, Perfect 10 appealed the denial of a permanent injunction against Google's display of thumbnail versions of Perfect 10's copyrighted nude images in Google Image Search results. Google's search engine crawled and displayed reduced-resolution thumbnails alongside links to both authorized and unauthorized full-size images hosted on third-party sites.

**Issue:** Whether Google's display of thumbnail images constituted copyright infringement or was protected by the fair use doctrine and as an inline linking practice.

**Holding:** The Ninth Circuit affirmed the denial of a permanent injunction, holding that Google's use of thumbnail images was highly transformative'erving an indexing and reference function fundamentally different from the original purpose of the images. The court also held that Google did not "display" the full-size images (hosted on third-party servers), rejecting Perfect 10's attempt to extend the display right to inline linking.
**Significance:** Established that highly compressed, low-resolution thumbnail copies can constitute fair use when they serve a transformative indexing function.
Adopted the "server test" for the public display right: liability depends on where the content is physically stored, not merely whether it appears on a user's screen.
Created a foundational precedent for search engine operations and image search services worldwide.

---

### Case 8.72: ASCAP v. MobiTV, Inc. (2014)

**Date Decided:** July 16, 2014

**Court:** United States Court of Appeals for the Second Circuit

**Facts:** ASCAP (American Society of Composers, Authors and Publishers) sued MobiTV, a mobile television streaming service, seeking public performance royalties for music contained in television programs streamed to mobile devices. ASCAP argued that MobiTV's retransmission of television content to mobile phones constituted a separate public performance requiring a separate license beyond what the television networks had already obtained. The district court granted partial summary judgment for MobiTV.

**Issue:** Whether a service that retransmits already-licensed television programming to new platforms (mobile devices) requires an additional public performance license from ASCAP for the embedded music.

**Holding:** The Second Circuit affirmed in favor of MobiTV, holding that ASCAP's blanket license with the television networks covered the public performance right, and that MobiTV's mobile retransmission did not create a new performance requiring a separate license. The court emphasized that the right of public performance belongs to the copyright holder (the network/licensee), not to ASCAP as a collecting society, and that ASCAP cannot "double-dip" by requiring additional licenses for new distribution technologies.
**Significance:** Limited the ability of performing rights organizations to extract additional licensing fees for new distribution technologies, protecting innovation in mobile streaming.
Clarified that a public performance license granted to the original broadcaster extends to authorized downstream retransmissions.
Influenced subsequent negotiations between PROs and streaming services, contributing to the broader shift toward direct licensing models.

---

### Case 8.73: BMG Rights Management v. Cox Communications (2018)

**Date Decided:** August 2, 2018

**Court:** United States Court of Appeals for the Fourth Circuit

**Facts:** BMG, a music rights management company, sued Cox Communications, one of the largest U.S. internet service providers, for contributory and vicarious copyright infringement based on Cox's failure to terminate repeat infringing subscribers. BMG alleged that Cox received millions of copyright infringement notices but failed to implement a meaningful repeat-infringer termination policy as required by DMCA §512(i). Cox argued that its policy, which allowed users to appeal and maintained a "13-strike" system before termination, satisfied the safe harbor requirement.

**Issue:** Whether Cox's repeat-infringer policy satisfied the DMCA §512(i) requirement to "adopt and reasonably implement" a policy for terminating accounts of repeat infringers, and whether willful blindness to infringement disqualifies a service provider from safe harbor protection.

**Holding:** The Fourth Circuit upheld a $25 million jury verdict against Cox, holding that Cox's repeat-infringer policy was not "reasonably implemented" because it was designed to avoid terminating high-revenue subscribers. The court found that Cox's practice of granting exceptions to paying customers demonstrated that its policy was not genuinely implemented. The court also held that the district court properly instructed the jury on willful blindness.
**Significance:** Established that ISPs cannot maintain safe harbor protection if their repeat-infringer policies are applied selectively based on subscriber revenue.
Confirmed that financial incentives to retain infringing subscribers undermine the "reasonably implement" standard of §512(i).
Created a significant deterrent precedent for ISPs, forcing many to strengthen their anti-piracy enforcement mechanisms.

---

### Case 8.74: BMG Rights Management v. RCN Corporation (2022)

**Date Decided:** March 2, 2022

**Court:** United States Court of Appeals for the Second Circuit

**Facts:** BMG sued RCN, a regional ISP, on similar grounds to the Cox case, alleging that RCN failed to implement an adequate repeat-infringer termination policy. Evidence showed RCN received over one million infringement notices targeting its subscribers but terminated very few accounts. RCN's internal documents allegedly showed a deliberate strategy to prioritize subscriber retention over copyright enforcement.

**Issue:** Whether RCN's failure to terminate repeat infringing subscribers, despite receiving millions of notices, disqualified it from DMCA safe harbor protection under §512(i).

**Holding:** The Second Circuit reversed the district court's grant of summary judgment for RCN, remanding for trial. The court held that a reasonable jury could find that RCN did not "reasonably implement" a repeat-infringer policy, noting the enormous volume of notices RCN received and the minimal number of terminations. The case proceeded to trial, resulting in a jury verdict of approximately $1 billion in statutory damages against RCN.
**Significance:** Extended the BMG v. Cox framework to the Second Circuit, establishing broad national precedent for ISP liability when repeat-infringer policies are a sham.
The $1 billion verdict sent shockwaves through the ISP industry, dramatically increasing the cost of tolerating piracy on networks.
Demonstrated that the volume of infringement notices relative to subscriber base is a key metric courts use to evaluate whether a policy is "reasonably implemented."

---

### Case 8.75: UMG Recordings v. Escape Media Group (Grooveshark) (2015)

**Date Decided:** April 2015 (settlement & shutdown)

**Court:** United States District Court for the Southern District of New York

**Facts:** Grooveshark was a music streaming service that allowed users to upload, search, and stream music. Unlike licensed services (Spotify, Pandora), Grooveshark operated without licensing agreements with major labels. UMG and other labels sued, alleging that Grooveshark employees themselves uploaded thousands of copyrighted songs to build the service's library'urning internal "upload parties" into evidence of willful infringement. Grooveshark had been in litigation with labels since 2009.

**Issue:** Whether Grooveshark could claim DMCA safe harbor protection when its own employees uploaded copyrighted content, and whether the service's business model constituted inducement of infringement.

**Holding:** The parties settled in April 2015. Grooveshark admitted liability, agreed to pay $75 million in damages, and immediately shut down. The settlement also required Grooveshark to transfer its technology and user data to the labels. The court had been poised to rule against Grooveshark, with internal emails documenting employee uploads and management awareness of the service's infringing nature.
**Significance:** Demonstrated that employee-initiated uploads destroy DMCA safe harbor defenses, as the service provider itself becomes the direct infringer.
Established that "upload parties" and internal practices of building an infringing library constitute evidence of willful infringement.
Served as a cautionary tale for unlicensed music services, accelerating the licensing-based streaming model's dominance.

---

### Case 8.76: Capitol Records v. Vimeo, LLC (2013)

**Date Decided:** July 16, 2013 (partial summary judgment)

**Court:** United States District Court for the Southern District of New York

**Facts:** Capitol Records and other labels sued Vimeo, a video-hosting platform, for copyright infringement based on user-uploaded music videos. Unlike YouTube's Content ID system, Vimeo relied primarily on post-upload DMCA takedown processes. The labels argued that Vimeo's "Staff Picks" and other curated features demonstrated knowledge of specific infringing content. Vimeo countered that its pre-1972 sound recordings were not covered by federal copyright's DMCA provisions.

**Issue:** Whether Vimeo qualified for DMCA safe harbor protection for user-uploaded videos containing copyrighted music, and whether pre-1972 sound recordings were subject to DMCA takedown procedures.

**Holding:** Judge Barbara Jones granted partial summary judgment for Vimeo on the DMCA safe harbor question for post-1972 recordings, holding that Vimeo's general awareness of infringement on its platform was insufficient to disqualify it from safe harbor. However, she denied summary judgment on specific videos where Vimeo employees may have had actual knowledge. The court held that DMCA safe harbor could apply to state-law copyright claims for pre-1972 recordings.
**Significance:** Clarified that general awareness of infringement on a platform does not constitute the "specific knowledge" required to disqualify DMCA safe harbor protection.
Extended DMCA principles to pre-1972 sound recordings (governed by state law), providing a framework for platforms handling legacy content.
Demonstrated the tension between curated content features and safe harbor eligibility.

---

### Case 8.77: Viacom International v. YouTube, Inc. —Settlement (2014)

**Date Decided:** March 18, 2014 (settlement announced)

**Court:** United States District Court for the Southern District of New York; United States Court of Appeals for the Second Circuit

**Facts:** Viacom filed a $1 billion lawsuit against YouTube in 2007, alleging massive copyright infringement through user-updated clips of Viacom's television programs (MTV, Comedy Central, Nickelodeon). After years of litigation including two summary judgment rulings and appeals, the Second Circuit remanded the case for reconsideration of whether YouTube had "actual knowledge" or "willful blindness" to specific infringing clips. Internal YouTube emails appeared to show awareness of piracy as a growth driver.

**Issue:** Whether YouTube had actual knowledge or willful blindness of specific infringing clips sufficient to disqualify it from DMCA safe harbor protection, and whether YouTube's general business awareness of infringement on its platform constituted the requisite knowledge.

**Holding:** Before the case could proceed to trial on remand, the parties announced a settlement in March 2014. Terms were confidential, but the settlement included licensing agreements allowing Viacom content on YouTube. The seven-year litigation consumed enormous resources for both parties and generated extensive precedent on DMCA safe harbor interpretation.
**Significance:** The prolonged litigation clarified that "general awareness" of infringement on a platform is insufficient for specific-knowledge disqualification under DMCA §512(c)(1)(A).
Demonstrated that protracted copyright litigation between major media companies and platforms often ends in licensing arrangements, suggesting litigation as a prelude to negotiation.
Cemented YouTube's Content ID system as the industry standard for managing copyrighted content on user-generated platforms.

---

### Case 8.78: Fox News Network v. TVEyes (2014)

**Date Decided:** November 14, 2014 (2nd Circuit); 2018 (SCOTUS cert denied)

**Court:** United States Court of Appeals for the Second Circuit

**Facts:** TVEyes operated a subscription-based television monitoring service that recorded all televised broadcasts 24/7, made them searchable by keyword, and allowed subscribers to watch clips of up to 10 minutes. Fox News sued for copyright infringement. TVEyes argued that its service was transformative'roviding search and monitoring functionality that served a fundamentally different purpose than watching television. The district court found that TVEyes' service was transformative but ruled it was not a fair use because it provided too much of Fox's content without transformation at the clip-viewing stage.

**Issue:** Whether a broadcast monitoring service that records, indexes, and makes searchable clips of television programming constitutes fair use, and if so, what limitations on the amount of content delivered to users are permissible.

**Holding:** The Second Circuit affirmed in part and reversed in part. It held that TVEyes' creation of a searchable database of broadcasts was a transformative fair use, but vacated the district court's blanket injunction and remanded for consideration of whether the service could operate with more limited clip access (under 10 minutes). The court balanced the transformative search function against the market harm to Fox's licensing of clip services.
**Significance:** Established that creating a searchable index of copyrighted broadcasts can be transformative fair use, even when the underlying content is reproduced in full for indexing purposes.
Introduced a nuanced "function-by-function" fair use analysis, where different features of a service may have different fair use outcomes.
Influenced the development of media monitoring services and news aggregation platforms.

---

### Case 8.79: Google LLC v. Oracle America (2021)

**Date Decided:** April 5, 2021

**Court:** United States Supreme Court

**Facts:** Oracle (which acquired Sun Microsystems) sued Google for copying approximately 11,500 lines of code from Java's Application Programming Interface (API) declarations when Google developed the Android mobile operating system. Google used the Java API declarations to allow millions of existing Java programmers to write applications for Android without learning a new language. The Federal Circuit had ruled that the API declarations were copyrightable and that Google's use was not fair use.

**Issue:** (1) Whether Java API declarations are copyrightable subject matter; (2) whether Google's copying of those declarations to create the Android platform constituted fair use under 17 U.S.C. §107.

**Holding:** The Supreme Court assumed without deciding that the API declarations were copyrightable, and held 6-2 that Google's use was fair use. Justice Breyer's majority opinion emphasized four factors: (1) the purpose was transformative (creating a new platform for smartphones); (2) the API declarations were "functional" and necessary for interoperability; (3) Google copied only what was needed for programmers to work in a familiar environment (about 0.4% of the total Java API); and (4) the copying did not substantially harm Oracle's market. The decision reversed the Federal Circuit and remanded.
**Significance:** Resolved a decade-long dispute critical to the software industry, confirming that reimplementation of API interfaces for interoperability can be fair use.
Provided transformative protection for technology companies building compatible platforms, protecting the ability to innovate on existing standards.
Signaled the Supreme Court's pragmatic approach to copyright and technology, prioritizing innovation and interoperability over rigid protection of functional code.

---

### Case 8.80: Warner Bros. Entertainment v. RDR Books (2007)

**Date Decided:** September 8, 2007

**Court:** United States District Court for the Southern District of New York

**Facts:** RDR Books planned to publish "The Harry Potter Lexicon," a 400-page encyclopedia-style reference guide to the Harry Potter universe compiled by fan Steven Vander Ark from material in the seven Harry Potter novels. J.K. Rowling and Warner Bros. sued, arguing that the Lexicon constituted unauthorized copying of substantial portions of the Harry Potter works. Rowling testified that the Lexicon would interfere with her own planned encyclopedia and literary estate. Vander Ark argued the Lexicon was a transformative reference work protected by fair use.

**Issue:** Whether a fan-created reference guide/encyclopedia based on a copyrighted fictional universe constitutes fair use or copyright infringement.

**Holding:** Judge Robert Patterson issued a permanent injunction against publication of the Lexicon in its original form. He ruled that the Lexicon was not a fair use because: (1) it was not sufficiently transformative't merely reorganized and repackaged Rowling's creative expression rather than adding significant commentary or analysis; (2) it copied too much of the original works, including verbatim excerpts of fictional dialogue, descriptions, and plot details; and (3) it posed a real threat to the market for Rowling's own planned encyclopedia. However, the judge suggested that a revised version with more original commentary might qualify as fair use.
**Significance:** Established that reference guides and companion books must add substantial original commentary or analysis to qualify as transformative fair use.
Clarified that reorganization and reformatting of copyrighted material, without analytical transformation, is insufficient for fair use.
Became a landmark case in fan fiction and fan-created content, defining the boundaries between transformative fandom and copyright infringement.

---

### Case 8.81: The Swatch Group v. Bloomberg Finance L.P. (2014)

**Date Decided:** October 29, 2014

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** Bloomberg obtained advance copies of Swatch Group press releases containing financial information before their scheduled public release, through a third-party service. Bloomberg published articles based on this information before the official release time. Swatch sued, arguing that Bloomberg's use of the unpublished press releases violated Swatch's copyright and database rights under EU law. The press releases were not formally "published" when Bloomberg accessed them.

**Issue:** Whether publishing a journalistically rewritten summary of the contents of an unpublished press release constitutes a "communication to the public" or a reproduction of a database under EU copyright and database rights directives, when the press release itself was obtained lawfully.

**Holding:** The CJEU held that the right of "communication to the public" under the Copyright Directive (2001/29/EC) is not violated when a journalist reports on the contents of a document (even an unpublished one) obtained lawfully. The court emphasized that the journalist's "acts of reproduction" were covered by the quotation and reporting exception (Article 5(3)(c)) of the Copyright Directive, provided the reporting is in accordance with journalistic practice and the source is indicated.
**Significance:** Affirmed broad journalistic privileges under EU copyright law for reporting on lawfully obtained information, even from unpublished sources.
Clarified that database rights do not prevent journalists from extracting and reporting on individual pieces of information from databases obtained through legitimate channels.
Established important protections for financial journalism and news reporting against database-right assertions by companies seeking to control their own disclosures.

---

### Case 8.82: Svensson v. Retriever Sverige AB (2014)

**Date Decided:** February 13, 2014

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** journalists and writers whose articles were originally published on the Gteborgs-Posten newspaper website. Retriever operated a media monitoring service that aggregated links to these articles, allowing clients to find and read them. The original articles remained hosted on the Gteborgs-Posten servers; Retriever merely provided hyperlinks. The journalists argued that Retriever's hyperlinking constituted a "communication to the public" under Article 3(1) of the EU Copyright Directive without their authorization.

**Issue:** Whether providing hyperlinks to copyrighted content freely available on the internet constitutes a "communication to the public" under the EU Copyright Directive (2001/29/EC).

**Holding:** The CJEU held that hyperlinking to freely accessible copyrighted works does not constitute a "communication to the public" under the Copyright Directive. The court reasoned that the original publisher had already made the work available to all internet users, so the hyperlink was not reaching a "new public." Therefore, no authorization from the copyright holder was required for such hyperlinking.
**Significance:** Established the "new public" test for hyperlinking: if the original content is freely accessible to all internet users, linking to it does not communicate it to a new public.
Provided a crucial legal foundation for the operation of the World Wide Web, search engines, and news aggregation services in the EU.
Created a baseline rule that was subsequently refined in later cases (GS Media, Filmspeler) to address linking to content that was initially unauthorized.

---

### Case 8.83: BestWater International v. Michael Mebes & Stefan Potsch (2014)

**Date Decided:** October 21, 2014

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** BestWater International, a water filter company, sued two competitors who had embedded BestWater's promotional video on their own website using framing technology (inline linking/ embedding). The embedded video was hosted on YouTube and Vimeo and was freely accessible to the public. BestWater argued that the framing/embedding constituted an unauthorized "communication to the public" of its copyrighted video under EU copyright law.

**Issue:** Whether embedding (framing/inline linking) a copyrighted video from a freely accessible third-party platform (YouTube) into another website constitutes a "communication to the public" under the EU Copyright Directive.

**Holding:** The CJEU held that embedding a protected work in a website, where the work is already freely accessible on another site (the source site), does not constitute a "communication to a new public" and therefore does not require authorization from the copyright holder. The court applied the Svensson "new public" test to embedding/framing technology, treating it as functionally equivalent to hyperlinking for purposes of the Copyright Directive.
**Significance:** Extended the Svensson "new public" principle to embedding and framing technologies, providing legal certainty for a wide range of internet practices.
Confirmed that the "click-to-view" requirement (as discussed in earlier referrals) is not determinative'hat matters is whether the content is freely accessible on the source platform.
Protected common web development practices (embedding YouTube videos, social media widgets, etc.) from copyright infringement claims.

---

### Case 8.84: GS Media BV v. Sanoma Media Netherlands BV (2016)

**Date Decided:** September 8, 2016

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** GS Media operated the website GeenStijl, a Dutch blog that posted hyperlinks to an Australian photo hosting site (FileFactory) where leaked pre-publication photos from Playboy magazine (featuring Dutch TV presenter Britt Dekker) were hosted. The photos had been uploaded without authorization. Sanoma (Playboy's publisher) sued GS Media for facilitating access to the unauthorized photos. The photos were hosted on a platform that required a payment or waiting period for download, but GeenStijl provided direct links that circumvented these access restrictions.

**Issue:** Whether posting hyperlinks to copyrighted content that was initially made available without the copyright holder's consent constitutes a "communication to the public" under the EU Copyright Directive, and whether the profit motive of the linker is relevant.

**Holding:** The CJEU held that when a hyperlinker posts links to works that were "freely available" on another site, the "new public" analysis from Svensson applies. However, when the linked content was placed online without the copyright holder's consent, the analysis changes: a hyperlinker who posts such links for profit can be presumed to know that the content is unauthorized, and the posting constitutes a "communication to the public." The presumption of knowledge can be rebutted by showing the linker was unaware or had acted in good faith.
**Significance:** Created an important exception to the Svensson rule: linking to unauthorized content may constitute infringement when the linker acts for profit and knew or should have known the content was unauthorized.
Introduced the "presumption of knowledge" standard for for-profit platforms linking to unauthorized content, shifting the burden to the linker to demonstrate good faith.
Significantly impacted the operation of news aggregators, blogs, and forums in the EU, requiring platforms to exercise greater diligence in vetting linked content.

---

### Case 8.85: Stichting Brein v. Jack Frederik Wullems (Filmspeler) (2017)

**Date Decided:** April 26, 2017

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** Jack Frederik Wullems sold a pre-loaded multimedia player (a "Kodi box") called "Filmspeler" through his website. The device came with add-ons pre-installed that provided free access to copyrighted films and television programs available through unauthorized streaming sources (pirate streaming sites). The Dutch anti-piracy organization Stichting Brein sued, arguing that the sale of the pre-loaded device constituted a "communication to the public" under the EU Copyright Directive.

**Issue:** Whether selling a multimedia device pre-configured with add-ons that provide access to unauthorized streaming sources constitutes a "communication to the public" under EU copyright law.

**Holding:** The CJEU held that the sale of a pre-configured multimedia player with add-ons linking to unauthorized streaming sources constitutes a "communication to the public." The court reasoned that the device was specifically designed to facilitate access to infringing content, and the seller was fully aware of this purpose. The "new public" concept was satisfied because the copyright holders had not authorized the content's availability through these streaming sources.
**Significance:** Extended EU copyright liability to the hardware level, targeting "fully loaded" Kodi boxes and similar pirate streaming devices.
Established that sellers of devices pre-configured for piracy are directly liable for communication to the public, even though they do not host or stream the content themselves.
Provided legal backing for enforcement actions against sellers of illicit streaming devices across the EU.

---

### Case 8.86: RentABike v. Oy L (2018)

**Date Decided:** June 7, 2018

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** The case involved a copyright dispute between RentABike, a Finnish bicycle rental company, and Oy L, which had used RentABike's photographs on its own website. Oy L obtained the photographs from a freely accessible third-party website and argued that its use constituted a "communication to the public" only if it reached a new public beyond those who could access the photos on the original source site.

**Issue:** Whether the concept of "communication to the public" under the EU Copyright Directive applies when copyrighted photographs are posted on one website without authorization and subsequently reproduced on another website by a different operator.

**Holding:** The CJEU clarified the framework for assessing "communication to the public" in the context of secondary publications of copyrighted works on the internet. The court held that the concept has a unitary character and should be interpreted broadly. It clarified that each act of communication using a different technical means (e.g., a different website/platform) must be independently assessed for whether it constitutes a communication to a "new public." The cumulative approach requires examining whether the subsequent publisher is reaching an audience beyond the one the copyright holder contemplated when authorizing the initial communication.
**Significance:** Refined the "new public" analysis for multi-platform copyright disputes, requiring case-by-case assessment of each act of communication.
Clarified that the unitary character of the "communication to the public" right means it applies regardless of the specific technical means used.
Provided guidance for assessing liability in cases involving cascading or downstream republication of copyrighted works across multiple online platforms.

---

### Case 8.87: Brompton Bicycle Ltd v. Chetech (2022)

**Date Decided:** June 9, 2022

**Court:** Court of Justice of the European Union (Grand Chamber)

**Facts:** Brompton Bicycle, the UK manufacturer of iconic folding bicycles, sued Chetech, a Chinese company, for selling folding bicycles in the UK that closely resembled Brompton's design. Brompton held both registered Community designs and unregistered Community design rights for its bicycle. The key question was whether the Chetech bicycles, which differed in minor ways from the Brompton design, produced the "same overall impression" on the informed user.

**Issue:** How the "same overall impression" test under the EU Community Design Regulation (6/2002) should be applied, particularly regarding the degree of freedom of the designer, the characteristics of the informed user, and the comparison methodology between protected and contested designs.

**Holding:** The CJEU provided detailed guidance on the "overall impression" test: (1) the assessment must consider the degree of freedom available to the designer (greater freedom means smaller differences matter more); (2) the "informed user" is not a design expert but a user with relatively detailed knowledge of the design sector; (3) comparison must focus on the overall impression, not individual features in isolation; and (4) the informed user's level of attention depends on the product type (e.g., higher attention for expensive products like bicycles). The court remanded for application of these principles.
**Significance:** Provided the most comprehensive CJEU guidance on the "same overall impression" test in EU design law, resolving longstanding uncertainties.
Established that the informed user's level of attention varies with product type, affecting how closely designs are compared.
Critical precedent for enforcement of EU design rights against manufacturers of "look-alike" products, particularly from non-EU jurisdictions.

---

### Case 8.88: Nintendo of America v. Matthew Storman / ROMUniverse (2021)

**Date Decided:** May 26, 2021 (default judgment); August 2021 (final judgment)

**Court:** United States District Court for the Southern District of New York

**Facts:** ROMUniverse was a website operated by Matthew Storman that allowed users to download unauthorized copies of Nintendo video game ROMs (read-only memory files of game cartridges) and ISOs for Nintendo consoles including the Nintendo Switch. The site also offered unauthorized copies of games from other publishers. Storman charged subscription fees for premium access to faster downloads and expanded libraries. Nintendo sued for both direct and indirect copyright infringement. Storman represented himself pro se and failed to meaningfully defend the action, resulting in a default judgment.

**Issue:** Whether operating a website that distributes unauthorized video game ROMs and charging subscription fees for access constitutes direct and contributory copyright infringement.

**Holding:** Judge Katherine Forrest (sitting by designation) entered a default judgment finding Storman liable for both direct and contributory copyright infringement. She awarded Nintendo $2,115,000 in statutory damages ($35,000 per work for 35Nintendo works and lower amounts for other publishers' works, applying a reduced rate based on Storman's limited financial resources). The court also issued a permanent injunction prohibiting Storman from further distribution of Nintendo's copyrighted works.
**Significance:** Demonstrated the continued application of traditional copyright infringement principles to ROM distribution sites, even as enforcement increasingly focuses on platforms rather than individual operators.
Established that subscription-based models for pirated game distribution warrant significant statutory damages, even when the operator has limited financial means.
Part of Nintendo's broader aggressive enforcement strategy against piracy, which has included targeting ROM sites, game-copying devices, and emulation platforms.

---

### Case 8.89: Hachette v. Internet Archive (2023) —U.S. District Court, Southern District of New York

**Date Decided:** March 24, 2023

**Court:** U.S. District Court for the Southern District of New York

**Facts:** The Internet Archive (IA) operated the National Emergency Library, which provided unrestricted digital access to over 1.3 million copyrighted books during the COVID-19 pandemic, relying on a theory of "controlled digital lending" that allowed it to lend digitized copies on a one-to-one owned-to-borrowed ratio. Major publishers including Hachette, HarperCollins, Penguin Random House, and Wiley sued, alleging mass copyright infringement. IA argued its lending practices constituted fair use, particularly during the pandemic emergency when physical library access was restricted.

**Issue:** Whether the Internet Archive's controlled digital lending program and National Emergency Library constituted fair use under 17 U.S.C. § 107 or copyright infringement.

**Holding:** Judge John G. Koeltl granted the publishers' motion for summary judgment, holding that IA's digital lending was not fair use. The court found that IA engaged in willful mass copyright infringement, noting that the "controlled digital lending" theory had no basis in copyright law. The court rejected IA's fair use arguments on all four statutory factors, emphasizing the commercial nature of the unauthorized copying and its substantial market harm to publishers. IA was ordered to cease lending copyrighted works.
**Significance:** Delivered a decisive rejection of the "controlled digital lending" theory, eliminating a potential legal pathway for library digitization without publisher authorization.
Established that emergency circumstances (COVID-19) do not create a blanket fair use exception for mass reproduction of copyrighted works.
Signaled judicial skepticism toward expansive fair use claims in the context of systematic, large-scale digital reproduction of copyrighted works.

---

### Case 8.90: The New York Times v. OpenAI —Discovery Proceedings (2024) —U.S. District Court, Southern District of New York

**Date Decided:** 2024 (ongoing litigation, discovery phase)

**Court:** U.S. District Court for the Southern District of New York (Case No. 1:23-cv-11195)

**Facts:** The New York Times sued OpenAI and Microsoft in December 2023, alleging that the defendants' large language models (GPT-4, Bing Chat) were trained on millions of copyrighted NYT articles without permission or compensation. The NYT claimed that the AI systems reproduced substantial portions of its journalism verbatim and that the training constituted copyright infringement. The case proceeded through extensive discovery in 2024, with the NYT seeking access to OpenAI's training data and methodology.

**Issue:** Whether the use of copyrighted news articles to train large language models constitutes fair use under U.S. copyright law and what discovery obligations apply to AI training processes.

**Holding:** The discovery phase produced significant rulings on the scope of document production and the admissibility of evidence regarding AI training methodologies. The court compelled OpenAI to produce relevant training documentation and system logs while allowing some protective orders for trade secret information. The case remained pending as of 2024, with both parties engaging in extensive expert discovery on the fair use question and market impact analysis.
**Significance:** One of the most consequential AI copyright cases globally, with potential to define the legal boundaries of AI training on copyrighted content.
Established important precedent on discovery standards for AI systems, requiring transparency about training data and methodologies while protecting legitimate trade secrets.
The case's outcome will likely determine the future economics of AI development and content licensing, with implications for the entire generative AI industry.

---

### Case 8.91: Getty Images v. Stability AI (2024) —U.S. District Court, District of Delaware / UK High Court

**Date Decided:** 2024 (ongoing litigation)

**Court:** U.S. District Court for the District of Delaware; High Court of England and Wales (parallel proceedings)

**Facts:** Getty Images, one of the world's largest stock photography companies, sued Stability AI, the developer of the Stable Diffusion image generation model, alleging that Stability AI scraped millions of Getty's copyrighted images from its website without authorization to train its AI model. Getty alleged that the resulting AI-generated images bore Getty's watermark and competed directly with its licensed content. Parallel proceedings were initiated in the United Kingdom.

**Issue:** Whether the scraping of copyrighted images for AI training constitutes fair use and whether Getty can establish direct infringement given the intermediate processing steps in AI model training.

**Holding:** The Delaware court allowed significant portions of Getty's claims to proceed, rejecting Stability AI's attempt to dismiss. The UK High Court ruled that the UK case could proceed, finding that there was a "real prospect" that Getty's website terms were breached. The court in the UK also addressed the question of whether AI-generated outputs could infringe copyright, declining to rule definitively at the preliminary stage.
**Significance:** First major court to substantively address image-scraping for AI training, with rulings on both sides of the Atlantic advancing the legal analysis.
Established that platform terms of service can create enforceable contractual obligations against AI training data collection.
The dual-jurisdiction approach provides comparative insight into how U.S. fair use and UK fair dealing doctrines may diverge in their treatment of AI training.

---

### Case 8.92: UMG Recordings, Inc. v. Suno, Inc. (2024) —U.S. District Court, District of Massachusetts

**Date Decided:** 2024 (ongoing litigation)

**Court:** U.S. District Court for the District of Massachusetts

**Facts:** Universal Music Group (UMG), the world's largest music company, sued Suno AI and Udio, developers of AI music generation platforms, alleging mass copyright infringement. UMG claimed that the defendants trained their AI models on copyrighted sound recordings without authorization, enabling users to generate music that closely resembled protected works. The case involved fundamental questions about whether AI-generated music that imitates the style and sound of copyrighted recordings constitutes infringement.

**Issue:** Whether training AI music generation models on copyrighted sound recordings constitutes fair use and whether AI-generated music that stylistically resembles copyrighted works infringes the original recordings' copyrights.

**Holding:** The court denied Suno's motion to dismiss, allowing UMG's claims to proceed. The court found that UMG had plausibly alleged that Suno copied sound recordings to train its AI model and that the fair use defense was not established at the pleading stage. Suno argued that its training involved only extracting "musical ideas" (ideas, not expression) from recordings, but the court held this factual question required discovery.
**Significance:** First major federal court ruling to address AI music generation and copyright infringement, establishing that these claims are cognizable and can proceed to discovery.
Raised the fundamental question of whether AI training that produces stylistic outputs constitutes copying of protected "expression" or only unprotected "ideas" from the original works.
Has profound implications for the music industry's business model and the future of AI-generated creative content across all artistic domains.

---

### Case 8.93: Runway Gen-2 Video Copyright Controversy (2024) —Industry / Regulatory Review

**Date Decided:** 2024 (ongoing industry and regulatory developments)

**Court:** No formal court proceeding; evolving industry standards, regulatory guidance, and legal analysis

**Facts:** Runway, a leading AI video generation company, released its Gen-2 model in 2024, capable of generating high-quality short videos from text prompts. The model raised immediate copyright concerns because it was trained on large datasets of video content, including copyrighted films, television shows, and user-generated content. Filmmakers, studios, and content creators raised objections regarding the unauthorized use of their works for training. Runway introduced licensing agreements with some content providers but faced criticism for insufficient transparency about training data composition.

**Issue:** Whether AI video generation models trained on copyrighted video content constitute fair use and what licensing frameworks are necessary for lawful commercial deployment of AI-generated video tools.

**Holding:** No judicial ruling was issued in 2024. The controversy prompted industry negotiations toward licensing frameworks, with Runway and competitors exploring partnerships with content libraries and studios. The U.S. Copyright Office's AI registration guidance (effective March 2024) clarified that AI-generated video content lacking sufficient human authorship is not copyrightable, affecting the economic incentives for AI video production.
**Significance:** Represents the frontier of copyright law's encounter with generative AI, extending beyond text and images to the legally complex domain of video and motion pictures.
Highlights the emergence of industry self-regulation and licensing models as complementary or alternative pathways to judicial resolution of AI copyright disputes.
The lack of copyright protection for purely AI-generated video creates unique market dynamics, incentivizing hybrid human-AI creative workflows that satisfy authorship requirements.
---

# Part 9 — E-Commerce & Consumer Protection
## Chapter 9: Digital Market Regulation and Consumer Data Rights
E-commerce and consumer protection law has undergone a profound transformation in the mid-2020s, driven by the convergence of competition regulation, data privacy enforcement, and cybersecurity mandates. The cases in this Part illustrate the emergence of a new enforcement paradigm in which regulators across multiple jurisdictions simultaneously deploy competition law, data protection law, consumer protection law, and financial services regulation to hold digital platforms and data-intensive businesses accountable. From the European Union's landmark Digital Markets Act enforcement to California's expanding CCPA regime, and from the FTC's aggressive data security agenda to New York's cybersecurity regulation for financial services, these cases collectively signal a global shift toward more assertive regulation of the digital economy.


### Case 9.1: European Commission v. Apple Inc. —DMA Anti-Steering Non-Compliance (2024–2025)

**Date Decided:** March 25, 2024 (formal investigation opened); April 23, 2025 (non-compliance decision)
Court/Regulator: European Commission, Directorate-General for Competition (DG COMP)

**Facts:** On March 6, 2024, Apple submitted its first compliance report under the Digital Markets Act (Regulation (EU) 2022/1925, "DMA"), which had entered into force on November 1, 2022 and applied to designated "gatekeepers" from March 6, 2024. Apple had been designated as a gatekeeper for its iOS App Store and Safari browser. In its compliance report, Apple described changes to its App Store rules, including the introduction of alternative payment processing options for developers in the European Economic Area (EEA) and modified steering practices.
The European Commission, after reviewing Apple's compliance report and engaging with Apple throughout March 2024, determined that Apple's proposed measures were insufficient. On March 25, 2024, the Commission opened its first formal non-compliance investigation under the DMA, alleging that Apple's App Store rules continued to restrict developers from informing consumers about alternative purchasing channels outside the App Store —a practice known as "anti-steering." Specifically, the Commission found that Apple's conditions for allowing developers to steer users to alternative payment methods were overly restrictive, including requirements to display mandatory "scare screens" warning users about security risks of purchasing outside the App Store, and the imposition of fees on purchases completed through alternative payment systems that effectively nullified the price benefits of circumventing Apple's commission structure.
A third non-compliance investigation was opened on June 24, 2024, focusing on Apple's contractual terms for developers, including the Core Technology Fee and other conditions that the Commission alleged were designed to discourage developers from using alternative distribution channels.
Following a year-long investigation, on April 23, 2025, the European Commission issued its first-ever non-compliance decision under the DMA, finding that Apple had breached Article 5(4) of the DMA, which requires gatekeepers to allow business users to communicate with end users through channels of their choice and to inform end users about alternative purchasing terms.
Violation of Article 5(4) DMA —failure to allow effective steering by developers to consumers regarding alternative purchasing channels.
Anti-steering practices including mandatory "scare screens" and fee structures that undermined the purpose of the DMA's anti-steering provisions.
Potential violation of Article 5(2) DMA through contractual terms restricting developers' ability to offer terms outside the App Store ecosystem.

**Issue:** Violation of Article 5(4) DMA —failure to allow effective steering by developers to consumers regarding alternative purchasing channels. Anti-steering practices including mandatory "scare screens" and fee structures that undermined the purpose of the DMA's anti-steering provisions. Potential violation of Article 5(2) DMA through contractual terms restricting developers' ability to offer terms outside the App Store ecosystem.
**Holding:** The Commission imposed a fine of 500 million on Apple —the first financial penalty ever issued under the DMA. The Commission required Apple to bring its practices into compliance within a specified timeline and to submit revised compliance measures. Apple was also required to modify its "scare screen" practices and fee structures to ensure that developers could effectively inform consumers about alternative purchasing options without facing prohibitive costs or coercive user interfaces.
**Significance:** Inaugural DMA enforcement. This case represents the first successful enforcement action under the Digital Markets Act, establishing the Commission's willingness and capacity to impose significant financial penalties on gatekeepers that fail to comply with the DMA's ex ante behavioral obligations. The 500 million fine —while modest relative to Apple's annual revenue —signals the Commission's commitment to using the DMA's enforcement toolkit aggressively and sets the stage for future, potentially larger penalties.
Anti-steering as a regulatory priority. The case elevates anti-steering obligations to a central pillar of digital platform regulation. By focusing on Apple's ability to prevent developers from informing consumers about alternatives, the Commission has established that gatekeepers cannot use their control over platform interfaces to limit consumer choice, even through ostensibly "informational" mechanisms such as scare screens. This principle has far-reaching implications for all designated gatekeepers and may extend to emerging platforms as the DMA's scope expands.
Regulatory dialogue model. The procedural trajectory of this case —from Apple's compliance report (March 2024), through Commission engagement and investigation opening (March 2024), to final decision (April 2025) —establishes the DMA's regulatory dialogue model, in which the Commission actively engages with gatekeepers before resorting to formal enforcement. This model differs significantly from traditional competition law proceedings, which typically involve lengthy market investigations before intervention, and reflects the DMA's preventive rather than corrective orientation.
Global implications. The Apple DMA decision has influenced regulatory approaches worldwide, including similar anti-steering provisions proposed in the United States (the Open App Markets Act) and South Korea (the Platform Act). It demonstrates that proactive regulation of platform behavior —as opposed to the reactive, effects-based approach of traditional antitrust law —can achieve faster and more targeted outcomes in digital markets characterized by network effects and switching costs.

---

### Case 9.2: FTC v. GoDaddy Inc. —Data Security Failures and Misleading Representations (2025)

**Date Decided:** January 15, 2025 (proposed complaint and settlement announced); May 21, 2025 (final order)
Court/Regulator: Federal Trade Commission (FTC), Docket No. C-4699

**Facts:** The FTC alleged that GoDaddy Inc., one of the world's largest domain registrars and web hosting providers, engaged in a pattern of unreasonable data security practices that failed to protect the personal information of millions of its small business and individual customers who used its managed WordPress hosting services. According to the FTC's complaint, GoDaddy experienced multiple data security incidents between 2021 and 2023, including breaches that exposed customer data such as email addresses, customer numbers, WordPress administrator credentials, and SSL private keys.
The FTC's investigation revealed that GoDaddy's security practices were fundamentally deficient. The company failed to maintain an adequate inventory of its computer assets and software; failed to implement and test reasonable security measures for its hosting environment; failed to segment its network to limit the spread of security incidents; failed to implement multi-factor authentication for internal systems; failed to apply security patches in a timely manner; and continued to operate legacy systems running unsupported and end-of-life software that was particularly vulnerable to attack. Additionally, the FTC found that GoDaddy had made misleading representations to consumers about the extent and quality of its security protections.
Violation of Section 5(a) of the FTC Act (15 U.S.C. 45(a)) —unfair and deceptive acts or practices, including unreasonable data security practices and misleading representations about data security.
Failure to implement reasonable and appropriate security measures for consumer data.
Misleading consumers about the security of GoDaddy's web hosting services.
Establish and maintain a comprehensive information security program.
Disconnect all hardware from any software that is no longer supported by its vendor.
Complete an inventory of all data collected and maintain oversight of third-party service providers.
Conduct annual security assessments by a qualified third party.
Notify the Commission of future data security incidents.

**Issue:** Violation of Section 5(a) of the FTC Act (15 U.S.C. 45(a)) —unfair and deceptive acts or practices, including unreasonable data security practices and misleading representations about data security. Failure to implement reasonable and appropriate security measures for consumer data. Misleading consumers about the security of GoDaddy's web hosting services.
**Holding:** The FTC announced a proposed settlement on January 15, 2025, and finalized the consent order on May 21, 2025. The order prohibits GoDaddy from misleading consumers about its data security practices and requires the company to: Establish and maintain a comprehensive information security program. Disconnect all hardware from any software that is no longer supported by its vendor. Complete an inventory of all data collected and maintain oversight of third-party service providers. Conduct annual security assessments by a qualified third party. Notify the Commission of future data security incidents.
**Significance:** FTC's security-by-design mandate. The GoDaddy order is notable for its specific and granular requirements, particularly the mandate to disconnect hardware from unsupported software —a seemingly technical but critically important requirement that addresses one of the most common vectors for data breaches. This level of specificity in an FTC consent order signals the Commission's willingness to go beyond general security program requirements and prescribe concrete technical controls.
SMB data protection expectations. The case is significant because GoDaddy's primary customers are small and medium-sized businesses (SMBs) that lack the technical sophistication to independently assess the security of their hosting providers. By holding GoDaddy accountable for the security of its managed hosting services, the FTC has established that web hosting providers bear a heightened duty of care for the customer data entrusted to them, particularly when they market themselves as providing "managed" or "secure" services.
Misrepresentation as aggravating factor. The FTC's inclusion of misleading security representations in its complaint —alongside the substantive security failures —reflects an enforcement strategy that treats marketing claims as both an independent basis for liability and an aggravating factor in security enforcement. Companies that overstate their security capabilities face not only the regulatory consequences of inadequate security but also separate liability for deceptive marketing.

---

### Case 9.3: FTC v. Mobilewalla Inc. —Sensitive Location Data Collection and Sale (2025)

**Date Decided:** December 3, 2024 (complaint and proposed order); January 14, 2025 (final order)
Court/Regulator: Federal Trade Commission (FTC), Docket No. C-4701

**Facts:** Mobilewalla Inc., a Georgia-based data broker, collected and sold precise geolocation data harvested from consumers' mobile devices without adequate consent. The FTC alleged that Mobilewalla obtained location data through multiple channels, including participation in real-time bidding (RTB) advertising auctions, where it collected consumer data alongside its role as an advertising participant. Mobilewalla then aggregated and sold this data to third parties, including hedge funds, advertisers, and government contractors, who used it for purposes ranging from market analysis to surveillance and intelligence gathering.
The FTC's complaint charged that Mobilewalla failed to adequately disclose to consumers that their precise location data —including visits to sensitive locations such as medical facilities, places of worship, reproductive health clinics, and government buildings —was being collected, aggregated, and sold. Mobilewalla also allegedly misrepresented how it collected consumer data, claiming to obtain data only from "first-party" sources when in fact it purchased data from third-party intermediaries and collected data through RTB advertising auctions.
The Mobilewalla case was part of a broader FTC enforcement sweep that also targeted Gravy Analytics (a related data broker) and reflected the Commission's growing focus on the location data brokerage industry.
Violation of Section 5(a) of the FTC Act —unfair and deceptive acts or practices in the collection and sale of sensitive location data.
Misrepresentations regarding the sources and methods of data collection.
Failure to obtain meaningful consumer consent for the collection and sale of sensitive geolocation data.
Prohibits Mobilewalla from selling or sharing sensitive location data.
Bans Mobilewalla from collecting consumer data through participation in real-time bidding (RTB) advertising auctions.
Prohibits misrepresentations regarding how Mobilewalla collects, uses, or shares consumer data.
Requires Mobilewalla to obtain affirmative express consent before collecting or sharing location data.
Requires implementation of a comprehensive data privacy and security program.
Requires deletion of previously collected data obtained through RTB auctions.

**Issue:** Violation of Section 5(a) of the FTC Act —unfair and deceptive acts or practices in the collection and sale of sensitive location data. Misrepresentations regarding the sources and methods of data collection. Failure to obtain meaningful consumer consent for the collection and sale of sensitive geolocation data.
**Holding:** The FTC finalized its consent order on January 14, 2025. The order: Prohibits Mobilewalla from selling or sharing sensitive location data. Bans Mobilewalla from collecting consumer data through participation in real-time bidding (RTB) advertising auctions. Prohibits misrepresentations regarding how Mobilewalla collects, uses, or shares consumer data. Requires Mobilewalla to obtain affirmative express consent before collecting or sharing location data. Requires implementation of a comprehensive data privacy and security program. Requires deletion of previously collected data obtained through RTB auctions.
**Significance:** RTB auction data as a regulatory target. The Mobilewalla order is groundbreaking in its specific prohibition on collecting consumer data through RTB advertising auctions —the first such ban in an FTC consent order. RTB auctions have long been identified as a conduit for the unauthorized collection and sale of precise location data, as data brokers participate in auctions not to display advertisements but to harvest bidding data that contains precise geolocation information. The FTC's targeted ban on this practice establishes a regulatory precedent that may reshape the digital advertising ecosystem.
Sensitive location categorization. By identifying visits to medical facilities, reproductive health clinics, places of worship, and government buildings as inherently sensitive, the FTC has effectively created a categorical framework for sensitive location data that does not depend on the consumer's subjective expectations but on the nature of the location itself. This objective approach simplifies compliance and expands the scope of data that businesses must treat as requiring heightened protection.
Data broker accountability. The case represents a significant expansion of regulatory accountability for data brokers —entities that operate largely behind the scenes in the digital advertising ecosystem. By holding Mobilewalla accountable not only for the sale of data but also for the methods of collection (including through RTB auctions), the FTC has signaled that data brokers cannot hide behind intermediaries or complex supply chains to evade responsibility for unfair or deceptive data practices.

---

### Case 9.4: NYDFS v. PayPal, Inc. —Cybersecurity Regulation Violations (2025)

**Date Decided:** January 23, 2025
Court/Regulator: New York State Department of Financial Services (NYDFS), Consent Order

**Facts:** On January 23, 2025, NYDFS Superintendent Adrienne A. Harris announced a $2 million settlement with PayPal, Inc. arising from cybersecurity failures that led to the exposure of customers' Social Security numbers (SSNs). The Department's investigation centered on a cybersecurity incident that occurred in connection with PayPal's implementation of changes to its data processing systems in December 2022. PayPal had modified its existing data flows to make IRS Form 1099-K tax documents available to more of its customers, but the teams responsible for implementing these changes were not trained on PayPal's systems and application development processes. As a result, the teams failed to follow proper procedures before deploying the changes to production.
The Department's investigation revealed multiple systemic deficiencies at PayPal. The company failed to use qualified personnel to manage key cybersecurity functions; failed to provide adequate cybersecurity training to relevant staff; failed to implement and maintain written policies addressing access controls, identity management, and customer data protection; and failed to use effective controls to protect against unauthorized access to Nonpublic Information (NPI) and Information Systems. Notably, PayPal did not require customers to use multifactor authentication or deploy technical controls such as CAPTCHA or rate limiting to prevent unauthorized access. These deficiencies allowed cybercriminals to leverage compromised credentials to access Form 1099-K documents, which contained sensitive customer data including SSNs.
Violation of 23 NYCRR Part 500 (NYDFS Cybersecurity Regulation) —failure to implement a cybersecurity program that included qualified personnel, adequate training, access controls, and written policies.
Failure to implement multifactor authentication and other preventive controls.
Exposure of customer Nonpublic Information, including Social Security numbers.

**Issue:** Violation of 23 NYCRR Part 500 (NYDFS Cybersecurity Regulation) —failure to implement a cybersecurity program that included qualified personnel, adequate training, access controls, and written policies. Failure to implement multifactor authentication and other preventive controls. Exposure of customer Nonpublic Information, including Social Security numbers.
**Holding:** PayPal agreed to a Consent Order requiring payment of a $2 million civil penalty to the State of New York. PayPal was required to remediate all identified cybersecurity deficiencies, implement multifactor authentication and access controls, enhance cybersecurity training programs, and submit periodic compliance certifications to NYDFS. PayPal has since remediated the identified issues.
**Significance:** Personnel and training as regulatory requirements. This case is notable for the NYDFS's emphasis on the human element of cybersecurity —specifically, the requirement that cybersecurity functions be managed by qualified personnel and that staff receive adequate training. While many cybersecurity regulations focus on technical controls (encryption, access management, incident response), this enforcement action establishes that inadequate personnel qualifications and training failures are themselves independent violations of cybersecurity obligations, not merely contributing factors.
Deployment failures as compliance failures. The PayPal case highlights a recurring pattern in cybersecurity enforcement: organizations that maintain robust security policies on paper but fail to implement them in practice during system changes and deployments. The fact that PayPal's changes were implemented by untrained teams that failed to follow established procedures —and that this failure led to a data exposure —demonstrates that NYDFS evaluates compliance holistically, including the operational execution of cybersecurity programs.
NPI protection standards. The exposure of Social Security numbers through a 1099-K processing failure underscores the heightened regulatory expectations for the protection of Nonpublic Information under 23 NYCRR Part 500. For financial services companies operating in New York, this case reinforces that the Department will hold licensees accountable for any failure to implement controls that are reasonably designed to protect NPI from unauthorized access, regardless of whether the failure results from a sophisticated cyberattack or an internal process error.

---

### Case 9.5: NYDFS and New York Attorney General v. Auto Insurance Companies —Cybersecurity Failures and Data Breach (2025)

**Date Decided:** October 14, 2025
Court/Regulator: New York State Department of Financial Services (NYDFS) and New York Attorney General Letitia James

**Facts:** On October 14, 2025, NYDFS and the New York Attorney General announced settlements totaling more than $19 million (NYDFS) and $14.2 million (NY AG) with eight auto insurance companies following a joint investigation into cybersecurity failures that allowed hackers to steal the personal information of New York consumers. The companies —which included several major auto insurers —operated online quoting tools that collected personal information from consumers seeking insurance quotes, including names, dates of birth, driver's license numbers, and addresses.
The investigation found that the insurers' inadequate cybersecurity controls allowed threat actors to exploit vulnerabilities in the online quoting tools to access and exfiltrate consumer data. The stolen data, particularly driver's license numbers, was subsequently used to fraudulently file for unemployment benefits during and after the COVID-19 pandemic. The investigation revealed that the insurers failed to implement adequate access controls, failed to conduct proper risk assessments, failed to implement multifactor authentication for consumer-facing applications, and —critically —failed to timely report the breaches to NYDFS and the Attorney General's office as required under applicable regulations.
Each of the eight companies was required to pay civil monetary penalties ranging from $1.85 million to $3 million, for a combined total exceeding $19 million under the NYDFS settlement and $14.2 million under the Attorney General's settlement.
Violation of 23 NYCRR Part 500 (NYDFS Cybersecurity Regulation) —failure to implement adequate cybersecurity controls for consumer-facing web applications.
Failure to timely report cybersecurity incidents to NYDFS as required by 23 NYCRR 500.17.
Violation of the New York General Business Law 349 —deceptive acts and practices related to the representation of data security to consumers.
Facilitation of identity theft and unemployment fraud through inadequate data protection.

**Issue:** Violation of 23 NYCRR Part 500 (NYDFS Cybersecurity Regulation) —failure to implement adequate cybersecurity controls for consumer-facing web applications. Failure to timely report cybersecurity incidents to NYDFS as required by 23 NYCRR 500.17. Violation of the New York General Business Law 349 —deceptive acts and practices related to the representation of data security to consumers. Facilitation of identity theft and unemployment fraud through inadequate data protection.
**Holding:** Settlements were reached with all eight companies, requiring payment of civil penalties totaling more than $19 million (NYDFS) and $14.2 million (NY AG). The companies were required to implement enhanced cybersecurity programs, including multifactor authentication for consumer-facing applications, improved access controls, regular penetration testing, and timely incident reporting procedures. Each company was required to submit to periodic compliance examinations by NYDFS.
**Significance:** Delayed reporting converts security lapse into compliance failure. A particularly significant aspect of this enforcement action is the emphasis on the insurers' failure to timely report the breaches to regulators. Under 23 NYCRR 500.17, regulated entities are required to notify NYDFS of any cybersecurity incident within 72 hours. The delayed reporting in these cases transformed what might have been treated as a security incident into an independent regulatory violation, substantially increasing the penalties and demonstrating that timely reporting obligations are treated with the same seriousness as preventive controls.
Consumer-facing applications as regulatory priority. By focusing on the security of online quoting tools —consumer-facing applications that collect sensitive personal information at the point of initial contact —NYDFS has signaled that the security of customer acquisition channels is a regulatory priority. This is a significant development because many organizations concentrate their cybersecurity resources on protecting internal systems and customer databases while treating consumer-facing web applications as lower priority. The penalties in this case demonstrate that such a tiered approach to security is no longer acceptable for regulated financial institutions.
Consequential harm as aggravating factor. The use of stolen driver's license numbers to file fraudulent unemployment benefit claims represents a clear causal chain from cybersecurity failure to tangible consumer harm. NYDFS and the Attorney General's joint enforcement action, which resulted in combined penalties exceeding $33 million, reflects the regulators' view that cybersecurity enforcement should account for the downstream consequences of data breaches, not merely the technical failures that enabled them. This consequential harm framework may influence future enforcement decisions across all regulated industries.

---

### Case 9.6: Honda CCPA Settlement —Excessive Opt-Out Friction (2025)

**Date Decided:** March 7, 2025 (settlement reached); March 12, 2025 (publicly announced)
Court/Regulator: California Privacy Protection Agency (CPPA)

**Facts:** On March 12, 2025, the California Privacy Protection Agency (CPPA) announced its first-ever enforcement settlement, reaching an agreement with American Honda Motor Co. over violations of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). The CPPA's investigation found that Honda's online processes for consumers to opt out of the sale and sharing of their personal data imposed excessive verification burdens that effectively deterred consumers from exercising their privacy rights.
Specifically, Honda required consumers submitting opt-out requests through its website to provide extensive personal information —including their full legal name, multiple vehicle identification numbers (VINs), and other detailed identifying information —before honoring the request. For consumers who wished to submit opt-out requests through authorized agents, Honda imposed additional requirements that further complicated the process. The CPPA determined that these verification requirements were more burdensome than reasonably necessary to verify the identity of the requestor and constituted an impermissible barrier to the exercise of privacy rights under the CCPA.
Additionally, the CPPA found that Honda failed to adequately honor Global Privacy Control (GPC) signals —a browser-based mechanism through which consumers can communicate their opt-out preferences —by not treating GPC signals as valid opt-out requests for all categories of data processing.
Violation of the CCPA (Cal. Civ. Code 1798.120) —failure to provide an effective opt-out mechanism that does not require consumers to navigate unreasonable friction.
Excessive verification requirements for privacy rights requests in violation of CCPA regulations.
Failure to honor Global Privacy Control signals as valid opt-out requests.
Simplify the opt-out process to minimize the information required from consumers.
Accept authorized agent submissions without imposing undue burdens.
Honor Global Privacy Control signals for all categories of data processing subject to opt-out.
Implement employee training on CCPA compliance.
Submit periodic compliance reports to the CPPA.

**Issue:** Violation of the CCPA (Cal. Civ. Code 1798.120) —failure to provide an effective opt-out mechanism that does not require consumers to navigate unreasonable friction. Excessive verification requirements for privacy rights requests in violation of CCPA regulations. Failure to honor Global Privacy Control signals as valid opt-out requests.
**Holding:** Honda agreed to pay a penalty of $632,500 —the CPPA's first monetary penalty —and to implement the following remedial measures: Simplify the opt-out process to minimize the information required from consumers. Accept authorized agent submissions without imposing undue burdens. Honor Global Privacy Control signals for all categories of data processing subject to opt-out. Implement employee training on CCPA compliance. Submit periodic compliance reports to the CPPA.
**Significance:** "Friction" as a regulatory concept. This settlement establishes "friction" —defined as unnecessary steps, excessive verification requirements, or procedural complexity that discourages consumers from exercising their privacy rights —as an independent basis for CCPA enforcement. By treating friction as a violation rather than a mere deficiency, the CPPA has created a clear standard that the opt-out mechanism must be at least as easy as the mechanism through which consumers' data is collected or sold. This principle is likely to influence privacy enforcement worldwide.
CPPA's enforcement debut. As the CPPA's first enforcement action, the Honda settlement established the agency's enforcement philosophy and priorities. The CPPA demonstrated a willingness to pursue cases that address systemic privacy practices (as opposed to egregious data breaches) and to seek remedies that go beyond monetary penalties to include operational changes. The Honda case was followed by additional enforcement actions, including the Tractor Supply case (Case 9.7), establishing an enforcement trajectory that signals the CPPA's emergence as a significant privacy regulator.
GPC signal recognition. The settlement's requirement that Honda honor Global Privacy Control signals reinforces the regulatory status of GPC as a legally recognized opt-out mechanism under the CCPA. While the CCPA's text does not explicitly mandate GPC recognition, the CPPA's position —supported by the California Attorney General —is that GPC signals constitute a valid "do not sell or share" request under the statute. This interpretation has significant implications for businesses operating websites or mobile applications that collect personal information from California consumers.

---

### Case 9.7: Tractor Supply Company CCPA Penalty —Job Applicant Privacy Rights and Enforcement Lawsuit (2025)

**Date Decided:** September 26, 2025 (settlement reached); September 30, 2025 (final order issued)
Court/Regulator: California Privacy Protection Agency (CPPA)

**Facts:** On September 30, 2025, the CPPA announced a record $1.35 million settlement with Tractor Supply Company —the largest monetary penalty in the agency's history and its first-ever enforcement lawsuit. The CPPA had initiated an investigation following a consumer complaint from Placerville, California, and subsequently filed an enforcement action alleging systemic violations of the CCPA.
The CPPA's investigation and enforcement action uncovered multiple violations. First, Tractor Supply failed to provide required "Notice at Collection" to job applicants, informing them of the categories of personal information collected during the employment application process and the purposes for which it would be used. Second, the company's online and in-store privacy notices failed to adequately inform consumers of their right to opt out of the sale and sharing of their personal information. Third, Tractor Supply's opt-out mechanisms were inadequate —the company's website did not provide a clear and accessible "Do Not Sell or Share My Personal Information" link as required by the CCPA, and consumers who attempted to opt out through other channels encountered verification and procedural requirements that created unreasonable barriers.
The enforcement action was particularly notable because it was the CPPA's first lawsuit, marking an escalation from the agency's previous use of negotiated settlements to formal adjudicatory proceedings.
Violation of the CCPA (Cal. Civ. Code 1798.100) —failure to provide required Notice at Collection to job applicants.
Violation of the CCPA (Cal. Civ. Code 1798.120) —failure to provide adequate notice of opt-out rights and to maintain accessible opt-out mechanisms.
Inadequate opt-out processes that imposed unreasonable friction on consumers.
Violation of the CCPA (Cal. Civ. Code 1798.130) —failure to respond to consumer privacy rights requests within required timeframes.
Implement compliant "Notice at Collection" disclosures for all data collection points, including employment applications.
Ensure that all online and physical locations display clear and accessible opt-out mechanisms, including the required "Do Not Sell or Share My Personal Information" link.
Simplify the opt-out process to eliminate unreasonable verification requirements.
Train employees on CCPA compliance and consumer privacy rights.
Submit to regular compliance audits and reporting to the CPPA.

**Issue:** Violation of the CCPA (Cal. Civ. Code 1798.100) —failure to provide required Notice at Collection to job applicants. Violation of the CCPA (Cal. Civ. Code 1798.120) —failure to provide adequate notice of opt-out rights and to maintain accessible opt-out mechanisms. Inadequate opt-out processes that imposed unreasonable friction on consumers. Violation of the CCPA (Cal. Civ. Code 1798.130) —failure to respond to consumer privacy rights requests within required timeframes.
**Holding:** The CPPA issued a final order imposing a $1.35 million penalty —the largest in the agency's history —and requiring Tractor Supply to: Implement compliant "Notice at Collection" disclosures for all data collection points, including employment applications. Ensure that all online and physical locations display clear and accessible opt-out mechanisms, including the required "Do Not Sell or Share My Personal Information" link. Simplify the opt-out process to eliminate unreasonable verification requirements. Train employees on CCPA compliance and consumer privacy rights. Submit to regular compliance audits and reporting to the CPPA.
**Significance:** CPPA's litigation capacity. By filing its first enforcement lawsuit rather than relying solely on negotiated settlements, the CPPA demonstrated its willingness and capacity to pursue formal adjudication against non-compliant businesses. This escalation signals to the regulated community that the CPPA is prepared to use the full range of its enforcement authority, including litigation, and that the agency will not limit itself to consent-based resolutions. The litigation threat adds significant deterrence value to the CPPA's regulatory regime.
Job applicant privacy rights. The Tractor Supply case is significant for its extension of CCPA enforcement to the employment context, specifically the privacy rights of job applicants. While the CCPA has always applied to employment data (subject to the B2B exemption, which was eliminated by the CPRA), the practical enforcement focus had previously been on consumer-facing data practices. By holding Tractor Supply accountable for failing to provide adequate privacy notices to job applicants, the CPPA has established that employers must treat the employment application process as a data collection activity subject to the same transparency and opt-out requirements as consumer-facing commercial activities.
Escalating penalty structure. The $1.35 million penalty represents a significant increase from the CPPA's first monetary penalty of $632,500 in the Honda case, announced just six months earlier. This rapid escalation in penalty amounts reflects the CPPA's intention to establish a progressively stronger deterrent and suggests that future enforcement actions will carry even larger penalties. For businesses subject to the CCPA, the Tractor Supply settlement underscores the financial risk of non-compliance and the importance of investing in comprehensive privacy compliance programs.

---

### Case 9.8: FTC v. Wyndham Worldwide Corp. —Data Security and Unfair Practices (2015) —FTC

**Date Decided:** December 17, 2015
Court/Regulator: U.S. Court of Appeals for the Third Circuit
Case citation: 799 F.3d 236 (3d Cir. 2015)

**Facts:** The FTC alleged that Wyndham Worldwide Corporation and three of its subsidiaries failed to implement reasonable data security measures to protect consumers' personal information, resulting in three data breaches between 2008 and 2010 that compromised the payment card information of over 619,000 consumers and caused millions of dollars in fraudulent charges. Wyndham's security failures included storing payment card data in unencrypted plain text, using easily guessable passwords, and failing to implement adequate firewall protections. Wyndham challenged the FTC's authority, arguing that the FTC Act's prohibition on "unfair" practices did not extend to data security standards in the absence of specific implementing regulations.

**Issue:** Whether the FTC has authority under Section 5 of the FTC Act to regulate corporate data security practices without issuing specific regulations defining required security standards.

**Holding:** The Third Circuit held that the FTC has authority under Section 5(n) of the FTC Act to bring enforcement actions against companies for unfair data security practices, even in the absence of specific regulations. The court found that the FTC's longstanding guidance documents and prior enforcement actions provided sufficient fair notice of its data security expectations. The case was remanded for further proceedings on the merits.
**Significance:** Foundational authority for FTC data security enforcement. Wyndham is the definitive case establishing the FTC's authority to police corporate data security practices under its general unfairness jurisdiction, enabling decades of subsequent enforcement actions without the need for rulemaking.
Fair notice through guidance, not rules. The court held that the FTC's guidance documents, speeches, and prior consent orders constituted adequate "fair notice" of expected security practices, lowering the threshold for what companies should have known about reasonable data security.
Industry-wide impact. The decision validated the FTC's approach of using Section 5 as a flexible, common-law-like tool to adapt security expectations to evolving technological threats.

---

### Case 9.9: FTC v. Lenovo, Inc. (Superfish) —Pre-Installed Spyware and Deceptive Practices (2017) —FTC

**Date Decided:** August 31, 2017
Court/Regulator: Federal Trade Commission, Docket No. C-4575
Case citation: No. C-4575 (F.T.C. Aug. 31, 2017)

**Facts:** The FTC alleged that Lenovo, Inc. pre-installed software called "Superfish Visual Discovery" on approximately 750,000 laptops sold to U.S. consumers between September 2014 and February 2015. Superfish acted as advertising software that visually analyzed images displayed in consumers' web browsers and served related advertising pop-ups. Critically, Superfish installed its own self-signed root certificate on each affected laptop, which intercepted and decrypted consumers' encrypted HTTPS web traffic, making it vulnerable to man-in-the-middle attacks. The software also failed to adequately disclose to consumers that it was collecting and analyzing their web browsing activity.

**Issue:** Whether Lenovo's pre-installation of Superfish software that compromised HTTPS encryption and intercepted web traffic constituted unfair and deceptive acts or practices under Section 5 of the FTC Act.

**Holding:** Lenovo entered into a consent agreement requiring it to: (1) obtain consumers' affirmative express consent before pre-installing any software that injects advertising into or otherwise monitors consumers' web browsing; (2) prohibit pre-installed software from making security-related changes to consumers' devices without affirmative consent; (3) conduct a security assessment of pre-installed software and implement a comprehensive security program; and (4) provide a mechanism for consumers to remove pre-installed software easily.
**Significance:** Pre-installed software as consumer protection issue. The case established that hardware manufacturers bear responsibility for the security and privacy implications of pre-installed software, creating a duty that extends beyond the device itself to the software ecosystem loaded onto it.
HTTPS interception as unfair practice. The FTC's treatment of Superfish's certificate-based HTTPS interception as an unfair practice established that undermining web encryption is per se harmful to consumers, regardless of the software's stated purpose.
Affirmative consent standard for bundled software. The order's consent requirement set a precedent that consumers must actively opt in to invasive pre-installed software rather than being required to opt out after purchase.

---

### Case 9.10: FTC v. Vizio, Inc. —Smart TV Tracking and Deceptive Practices (2017) —FTC

**Date Decided:** February 6, 2017
Court/Regulator: Federal Trade Commission, Docket No. C-4559
Case citation: No. C-4559 (F.T.C. Feb. 6, 2017)

**Facts:** The FTC and the New Jersey Attorney General alleged that Vizio, Inc. collected viewing data from approximately 11 million consumers through its internet-connected "smart" televisions without adequate disclosure. Vizio's TVs tracked what consumers watched on cable, broadcast, streaming services, and DVD/Blu-ray players by capturing pixel data from the screen, then transmitted this data to Vizio's servers every second. Vizio aggregated viewing data and sold it to third parties for advertising and content measurement purposes, without consumers' knowledge or consent. Additionally, Vizio misrepresented its "Smart Interactivity" feature, telling consumers it would only provide program recommendations, when in fact it was continuously tracking all viewing activity.

**Issue:** Whether Vizio's collection and sale of detailed television viewing data without adequate disclosure and its misrepresentation of its smart TV features constituted deceptive acts or practices under Section 5 of the FTC Act.

**Holding:** Vizio agreed to a settlement requiring: (1) deletion of all data collected prior to March 1, 2016; (2) clear disclosure of tracking practices and the specific types of data collected; (3) affirmative express consent before collecting or sharing viewing data; (4) prohibition on misrepresenting the capabilities or data practices of its TVs; and (5) implementation of a comprehensive data privacy and security program. Vizio paid $2.2 million to the New Jersey Division of Consumer Affairs.
**Significance:** IoT device tracking as a regulatory frontier. The Vizio case was one of the first major enforcement actions addressing privacy violations by Internet of Things (IoT) devices, establishing that connected consumer electronics are subject to the same disclosure and consent requirements as online services.
Pixel-level data collection as surveillance. The FTC's description of Vizio's screen-capture technology as essentially "surveillance" of private viewing activity in the home established a low threshold for what constitutes invasive data collection by IoT devices.
Screen as a data collection interface. The case foreshadowed broader regulatory concerns about ambient data collection by smart devices and contributed to the policy foundations for later IoT security legislation.

---

### Case 9.11: FTC v. InMobi Pte. Ltd. —Mobile Location Tracking and Deceptive Privacy Claims (2016) —FTC

**Date Decided:** June 22, 2016
Court/Regulator: Federal Trade Commission, Docket No. C-4542
Case citation: No. C-4542 (F.T.C. June 22, 2016)

**Facts:** The FTC alleged that InMobi, a Singapore-based mobile advertising company, tracked the physical locations of hundreds of millions of consumers through mobile applications using InMobi's advertising SDK, including tracking consumers' visits to sensitive locations such as medical facilities, places of worship, and homes. InMobi collected location data even when consumers had activated privacy settings on their mobile devices that prevented apps from accessing location services. InMobi also allegedly deceived consumers and developers by representing that its advertising SDK did not collect or use location data when users opted out of location tracking, and by claiming that its services were compliant with the EU-U.S. Privacy Shield framework and other privacy programs when they were not.

**Issue:** Whether InMobi's circumvention of device-level privacy settings to collect location data and its deceptive representations about its data collection practices constituted unfair and deceptive acts or practices under Section 5 of the FTC Act.

**Holding:** InMobi agreed to a settlement requiring: (1) a $950,000 civil penalty for violating the Privacy Shield framework; (2) deletion of all location data collected without consent; (3) a prohibition on tracking consumers who have activated device-level privacy settings; (4) a prohibition on misrepresenting its privacy practices or compliance with privacy frameworks; and (5) implementation of a comprehensive privacy program subject to biennial independent audits for 20 years.
**Significance:** Device privacy settings as regulatory floor. The InMobi order established that companies cannot bypass consumer-controlled device privacy settings to collect data, effectively treating device-level opt-outs as legally binding even when not explicitly mandated by statute.
International reach of FTC enforcement. The case demonstrated the FTC's willingness to pursue foreign-based companies operating in U.S. markets, particularly mobile advertising intermediaries whose activities directly affect American consumers.
Privacy Shield compliance as enforceable obligation. The civil penalty for false Privacy Shield claims established that compliance certifications under international data transfer frameworks are subject to FTC enforcement, not merely self-regulatory commitments.

---

### Case 9.12: FTC v. Avid Dating Life, Inc. (Ashley Madison) —Deceptive Privacy and Data Security Practices (2016) —FTC

**Date Decided:** December 8, 2016
Court/Regulator: Federal Trade Commission, Docket No. C-4563
Case citation: No. C-4563 (F.T.C. Dec. 8, 2016)

**Facts:** The FTC alleged that Ashley Madison, a dating website marketed to individuals seeking extramarital affairs, deceived consumers through multiple practices. First, Ashley Madison misrepresented its "full delete" feature, claiming that paying a $19 fee would permanently remove all user profile information from its systems, when in fact the company retained copies of the data, including email addresses and other profile information. Second, the company failed to implement reasonable data security measures, including inadequate access controls, unencrypted data storage, and failure to use industry-standard security protocols. These failures contributed to a massive data breach in July 2015 that exposed the personal information of approximately 36 million users, including names, email addresses, sexual preferences, and payment information.

**Issue:** Whether Ashley Madison's misrepresentations about its data deletion feature and its failure to implement reasonable data security measures constituted unfair and deceptive acts or practices under Section 5 of the FTC Act.

**Holding:** Ashley Madison's parent company, Ruby Corp. (formerly Avid Dating Life), agreed to a settlement requiring: (1) implementation of a comprehensive information security program; (2) a prohibition on making deceptive claims about data deletion or privacy practices; (3) mandatory third-party security assessments for 20 years; and (4) payment of $1.6 million in civil penalties to the FTC and state attorneys general. Separately, the company paid $11.2 million to the FTC in 2018 as part of a broader settlement related to the breach.
**Significance:** Data deletion claims as deceptive practice. The case established that companies cannot charge consumers for data deletion services while retaining copies of the data, setting a standard that paid deletion promises must be honored in full.
Intimate data requires heightened protection. The FTC's treatment of Ashley Madison's security failures was informed by the particularly sensitive nature of the data involved —sexual preferences and information about extramarital affairs —establishing a principle that the sensitivity of data affects the reasonableness standard for security measures.
Reputational consequences amplify regulatory risk. The combination of FTC enforcement, massive public exposure, and consumer class action litigation demonstrated that data breaches involving sensitive personal information create cascading legal and reputational liabilities.

---

### Case 9.13: FTC v. D-Link Corporation —Inadequate Router and IP Camera Security (2019) —FTC

**Date Decided:** June 7, 2019
Court/Regulator: U.S. Court of Appeals for the Ninth Circuit
Case citation: 934 F.3d 1125 (9th Cir. 2019)

**Facts:** The FTC alleged that D-Link Corporation, a major manufacturer of computer networking equipment including routers and internet-connected IP cameras, failed to implement reasonable security measures in its products, leaving consumers' networks and devices vulnerable to unauthorized access. Specific failures included: hard-coded user credentials that could not be changed; failure to patch known security vulnerabilities in a timely manner; use of outdated and insecure software components; inadequate testing for security flaws; and failure to encrypt or otherwise secure communications between devices and D-Link's servers. The FTC also alleged that D-Link misrepresented the security of its products in marketing materials. D-Link challenged the FTC's authority, arguing that the FTC could not bring unfairness claims based on hypothetical future harm.

**Issue:** Whether the FTC can pursue an unfairness claim under Section 5 of the FTC Act based on security vulnerabilities that created a risk of future harm, even where the FTC did not demonstrate that actual consumer injury had occurred.

**Holding:** The Ninth Circuit affirmed the FTC's authority to bring the action, holding that the FTC adequately pled that D-Link's security failures presented a substantial risk of harm to consumers. However, the court agreed with D-Link that the FTC had not adequately pleaded that the alleged security failures were likely to cause substantial consumer injury, and remanded the case for the FTC to amend its complaint. The case was ultimately resolved through a consent agreement requiring D-Link to implement a comprehensive software security program, subject to third-party audits for 10 years.
**Significance:** Substantial risk standard for data security. The Ninth Circuit's decision clarified that the FTC need not prove actual consumer injury to bring an unfairness claim, but must adequately plead that the challenged practices present a substantial risk of consumer harm —establishing an intermediate standard between actual harm and speculative possibility.
IoT hardware security as FTC priority. The case confirmed the FTC's interest in regulating the security of consumer IoT hardware, including routers and cameras that serve as entry points to home networks.
Limits on FTC pleading requirements. While affirming the FTC's authority, the decision also placed meaningful limits on the Commission's ability to rely on speculative harm theories, requiring specific factual allegations linking security failures to concrete risks.

---

### Case 9.14: FTC v. Facebook, Inc. —$5 Billion Privacy Settlement (2019) —FTC

**Date Decided:** July 2, 2019
Court/Regulator: Federal Trade Commission, Docket No. C-4372
Case citation: No. C-4372 (F.T.C. July 2, 2019)

**Facts:** The FTC's action against Facebook arose from allegations that Facebook violated a 2012 consent order by repeatedly making misleading representations about consumers' privacy choices and by failing to maintain a comprehensive privacy program. The FTC alleged that, despite promising consumers that they could control the privacy of their personal information, Facebook allowed third-party applications to access users' personal information without meaningful consent; shared user data with third-party partners (including Cambridge Analytica) in ways that contradicted Facebook's stated privacy policies; deceived users about facial recognition technology used for photo tagging; and failed to adequately supervise third-party developers who accessed user data. The Cambridge Analytica scandal —in which data from up to 87 million Facebook users was harvested without consent and used for political advertising —was the catalyst for the FTC's investigation.

**Issue:** Whether Facebook's data sharing practices and privacy misrepresentations violated its 2012 consent order with the FTC and whether Facebook failed to maintain a comprehensive privacy program as required by the order.

**Holding:** Facebook agreed to a record-breaking $5 billion civil penalty —the largest in FTC history —and a sweeping consent order requiring: (1) establishment of an independent Privacy Committee of the Board of Directors; (2) designation of compliance officers responsible for Facebook's privacy program; (3) new requirements for third-party app oversight, including mandatory data access reviews; (4) enhanced privacy risk assessments for new products and significant changes to existing products; (5) restrictions on the use of facial recognition data; (6) CEO certification of compliance on a quarterly basis; and (7) expanded FTC oversight authority, including mandatory compliance reporting and the ability to hold individual executives accountable.
**Significance:** Record penalty and structural accountability. The $5 billion penalty was the largest in FTC history by an order of magnitude, signaling a dramatic escalation in the Commission's willingness to impose meaningful financial consequences on major technology companies for privacy violations.
Board-level privacy governance. The requirement for an independent Privacy Committee and CEO certification of compliance established a new standard of corporate governance for privacy, elevating data protection from a compliance function to a board-level responsibility.
Third-party app ecosystem accountability. The enhanced third-party oversight requirements addressed the systemic vulnerability that enabled the Cambridge Analytica scandal, establishing that platform operators bear responsibility for how third-party developers use consumer data obtained through their platforms.

---

### Case 9.15: FTC v. Equifax Inc. —Massive Data Breach and $700 Million Settlement (2019) —FTC

**Date Decided:** July 22, 2019
Court/Regulator: Federal Trade Commission, along with the Consumer Financial Protection Bureau (CFPB) and 50 state attorneys general
Case citation: No. C-4388 (F.T.C. July 22, 2019)

**Facts:** In September 2017, Equifax, one of the three largest consumer credit reporting agencies in the United States, announced that a data breach had exposed the personal information of approximately 147 million consumers —including names, Social Security numbers, birth dates, addresses, and in some cases driver's license numbers and credit card numbers. The breach resulted from Equifax's failure to patch a known vulnerability in Apache Struts software despite being notified of the security patch months earlier. The FTC's investigation revealed multiple systemic failures: Equifax failed to implement an adequate vulnerability management program; failed to maintain an accurate inventory of its systems and software; failed to segment its networks to limit the spread of the breach; failed to encrypt the sensitive personal information it stored; and failed to detect the breach for 76 days despite multiple indicators of compromise.

**Issue:** Whether Equifax's failure to implement reasonable data security measures and its handling of the breach response constituted unfair and deceptive acts or practices under Section 5 of the FTC Act and whether Equifax violated the Fair Credit Reporting Act (FCRA).

**Holding:** Equifax agreed to a global settlement of at least $575 million (potentially up to $700 million), including: (1) $175 million to 48 states, the District of Columbia, and territories; (2) $100 million to the CFPB in civil penalties; (3) $300 million to a consumer restitution fund for credit monitoring services and other relief; and (4) $125 million to the FTC for penalties if the consumer fund is exhausted. Equifax was required to strengthen its data security program, implement a comprehensive information security program, and submit to regular security assessments and monitoring for 20 years.
**Significance:** Largest data breach settlement at the time. The Equifax settlement was the largest ever for a data breach, establishing a new benchmark for the financial consequences of inadequate security at major data-intensive institutions.
Credit bureau accountability. The case held credit reporting agencies —which collect vast quantities of sensitive consumer data without consent —to a heightened security standard commensurate with the sensitivity and volume of the data they maintain.
Unpatched vulnerability as negligence. Equifax's failure to apply a known security patch served as a stark example of how basic security hygiene failures can have catastrophic consequences, reinforcing the principle that unpatched known vulnerabilities constitute unreasonable security practices.

---

### Case 9.16: New York Attorney General v. Charter Communications, Inc. (Spectrum) —Broadband Speed and Reliability (2021) —NY Supreme Court

**Date Decided:** June 22, 2021
Court/Regulator: Supreme Court of the State of New York; Attorney General Letitia James
Case citation: No. 452137/2017 (N.Y. Sup. Ct.)

**Facts:** The New York Attorney General filed a lawsuit against Charter Communications (operating as Spectrum), the largest internet service provider in New York State, alleging that the company systematically deceived consumers about the speed and reliability of its broadband internet service. The complaint alleged that Spectrum: (1) advertised internet speeds that it knew many consumers could not achieve in practice due to network congestion and inadequate infrastructure; (2) provided routers to consumers that were incapable of delivering the advertised speeds; (3) failed to maintain adequate network capacity to serve the number of subscribers it enrolled; and (4) misrepresented its service as "reliable" when it knew its network suffered from chronic reliability problems. Evidence included internal company documents showing that Spectrum executives were aware of the speed and reliability issues but chose not to address them.

**Issue:** Whether Spectrum's provision of broadband service that systematically failed to deliver advertised speeds and its misrepresentation of service quality constituted fraud and deceptive business practices under New York Executive Law 63(12) and General Business Law 349.

**Holding:** The court found Charter liable for defrauding its subscribers and ordered the company to pay $174 million in penalties and restitution. The court also ordered Spectrum to: (1) provide refunds and credits to affected subscribers; (2) improve network infrastructure to deliver advertised speeds; (3) provide subscribers with routers capable of delivering advertised speeds; (4) cease making misleading speed and reliability claims in advertising; and (5) submit to ongoing monitoring and reporting.
**Significance:** Broadband service quality as consumer protection. The case established that internet service providers can be held liable for failing to deliver advertised broadband speeds, treating internet access as a consumer product subject to the same quality and advertising standards as other goods and services.
Internal documents as evidence of intent. The case demonstrated the power of internal corporate communications as evidence of deceptive intent, showing that awareness of service deficiencies within the company can convert a performance issue into a fraud case.
ISPs as fiduciaries of network promises. The decision reinforced the principle that ISPs bear responsibility for the claims they make about service quality, not merely for their technical best efforts.

---

### Case 9.17: New York Attorney General v. SiriusXM —Cancellation and Deceptive Practices (2024) —NY Supreme Court

**Date Decided:** October 2024
Court/Regulator: Supreme Court of the State of New York; Attorney General Letitia James
Case citation: No. 454765/2024 (N.Y. Sup. Ct.)

**Facts:** The New York Attorney General sued SiriusXM, the satellite and streaming radio company, alleging that the company systematically made it difficult for consumers to cancel their subscriptions by employing deceptive and unfair practices. The complaint alleged that SiriusXM: (1) required consumers who wished to cancel to navigate a complex, multi-step cancellation process that included mandatory retention pitches; (2) trained customer service representatives to use high-pressure sales tactics to dissuade consumers from canceling; (3) in some cases, continued billing consumers who had requested cancellation; (4) failed to provide clear and conspicuous disclosure of auto-renewal terms; and (5) failed to send required pre-renewal notices to consumers, violating New York's auto-renewal law.

**Issue:** Whether SiriusXM's cancellation practices constituted deceptive acts and practices and unlawful auto-renewal billing violations under New York General Business Law 349 and 527.

**Holding:** The case was resolved through a settlement in which SiriusXM agreed to pay $4 million in penalties and restitution. The company was required to: (1) simplify its cancellation process, allowing consumers to cancel online without speaking to a representative; (2) provide clear disclosure of auto-renewal terms; (3) send pre-renewal notices as required by law; (4) cease the use of high-pressure retention scripts; and (5) refund consumers who were charged after requesting cancellation.
**Significance:** Subscription cancellation as consumer right. The case reinforced the regulatory principle that consumers must be able to cancel subscriptions as easily as they sign up, contributing to the broader "click-to-cancel" movement that influenced the FTC's 2024 rule on negative option marketing.
Auto-renewal notice obligations. The case highlighted the importance of clear pre-renewal disclosures and timely cancellation processing, establishing that failures in subscription management systems can independently violate consumer protection laws.
High-pressure retention tactics as deceptive. The treatment of mandatory retention scripts as deceptive practices established a new boundary for what constitutes permissible customer retention strategies.

---

### Case 9.18: California Attorney General v. Sephora USA, Inc. —CCPA Enforcement for Online Tracking (2022) —CA Superior Court

**Date Decided:** November 2022
Court/Regulator: California Superior Court, Los Angeles County; Attorney General Rob Bonta
Case citation: No. 22STCV25723 (Cal. Super. Ct. L.A. Cnty.)

**Facts:** The California Attorney General sued Sephora, the luxury beauty retailer, alleging violations of the California Consumer Privacy Act (CCPA). The complaint alleged that Sephora: (1) sold consumers' personal information to third parties without providing the required "Do Not Sell My Personal Information" link on its website and mobile app; (2) failed to disclose to consumers at or before the point of collection that their personal information was being sold; (3) failed to honor Global Privacy Control (GPC) signals as valid opt-out requests; and (4) failed to describe the categories of third parties to whom personal information was disclosed. The investigation found that Sephora had shared consumer data with third-party advertising partners, including Meta (Facebook), Pinterest, and others, through tracking technologies embedded on its website.

**Issue:** Whether Sephora's failure to provide the required "Do Not Sell" link, honor GPC signals, and disclose data sharing practices constituted violations of the CCPA.

**Holding:** Sephora agreed to a settlement requiring: (1) payment of $1.2 million in penalties; (2) implementation of a comprehensive CCPA compliance program; (3) honoring GPC signals as valid opt-out requests; (4) providing clear "Do Not Sell or Share" links on its website and app; (5) updating privacy notices to disclose all categories of personal information collected and the purposes for collection; and (6) restricting the use of third-party tracking technologies that facilitate the sale of personal information.
**Significance:** First CCPA enforcement against a major retailer. The Sephora case was one of the first CCPA enforcement actions against a major retailer, establishing the California Attorney General's willingness to pursue well-known brands for compliance failures.
GPC signals as enforceable opt-out mechanism. The settlement's requirement that Sephora honor GPC signals reinforced the legal status of GPC as a valid opt-out mechanism under the CCPA, encouraging broader industry adoption.
Retail tracking technology accountability. The case highlighted the pervasive use of third-party tracking technologies on retail websites and established that retailers bear responsibility for the data sharing facilitated by their embedded technology choices.

---

### Case 9.19: Washington State Attorney General v. T-Mobile USA, Inc. —Massive Data Breach (2023) —WA Superior Court

**Date Decided:** January 2023
Court/Regulator: King County Superior Court, Washington State; Attorney General Bob Ferguson
Case citation: No. 22-2-18741-1 SEA (Wash. Super. Ct. King Cnty.)

**Facts:** In January 2023, the Washington State Attorney General sued T-Mobile USA, alleging that the company's negligence led to a massive data breach in January 2021 that exposed the personal information of approximately 76.6 million current and former customers, including names, dates of birth, Social Security numbers, driver's license numbers, and other sensitive data. The complaint alleged that T-Mobile failed to implement adequate data security measures, including: failure to properly secure its systems against known attack vectors; failure to implement adequate access controls and authentication mechanisms; failure to encrypt sensitive customer data at rest; and failure to properly segment its network to limit the scope of breaches. The breach was attributed to a hacker who gained access through an unpatched server.

**Issue:** Whether T-Mobile's data security failures constituted violations of the Washington Consumer Protection Act and whether the company failed to protect consumers' personal information as required by state law.

**Holding:** T-Mobile agreed to a settlement requiring payment of $350 million to resolve claims by affected consumers (class action) and an additional $15.75 million to the Washington State Attorney General. T-Mobile was required to implement enhanced security measures, including multi-factor authentication, improved vulnerability management, data encryption, and regular security assessments.
**Significance:** Multi-layered enforcement for single breach. The T-Mobile case demonstrated that a single data breach can trigger simultaneous enforcement from the FTC, state attorneys general, and class action litigation, creating compounding financial and operational consequences.
State attorneys general as active data security enforcers. The case reinforced the trend of state attorneys general pursuing independent data security enforcement actions, complementing federal regulatory efforts.
Telecommunications data as high-value target. The case highlighted the particular risks associated with the vast quantities of sensitive consumer data held by telecommunications providers and the corresponding obligation to implement robust security measures.

---

### Case 9.20: United States v. Google LLC —Search Monopoly (2024) —D.D.C.

**Date Decided:** August 5, 2024
Court/Regulator: U.S. District Court for the District of Columbia, Judge Amit P. Mehta
Case citation: No. 1:20-cv-3010 (D.D.C. Aug. 5, 2024)

**Facts:** The U.S. Department of Justice and a coalition of state attorneys general brought an antitrust case against Google, alleging that the company maintained an illegal monopoly in general search services and search advertising through exclusionary contracts and anticompetitive conduct. The government presented evidence that Google paid approximately $26.3 billion annually to secure default search placement agreements, including payments of over $18 billion per year to Apple to make Google the default search engine on Safari, as well as similar agreements with Samsung, Mozilla, and other device manufacturers and browser developers. The government argued that these default agreements foreclosed competition by preventing rival search engines from reaching consumers and by creating a self-reinforcing cycle in which default placement generated more search queries, which improved Google's search quality and attracted more advertisers.

**Issue:** Whether Google's default search placement agreements and related conduct constituted anticompetitive exclusionary practices in violation of Section 2 of the Sherman Act.

**Holding:** Judge Mehta ruled in favor of the government, finding that Google held monopoly power in general search services and search text advertising, and that its default placement agreements constituted anticompetitive exclusionary conduct. The court found that Google's exclusive default agreements locked out competition and denied rivals the scale necessary to challenge Google's dominance. Remedies were scheduled for a subsequent proceeding.
**Significance:** First major tech antitrust win in decades. The decision marked the U.S. government's most significant antitrust victory against a major technology company since the Microsoft case in 2001, signaling a new era of aggressive antitrust enforcement in digital markets.
Default agreements as anticompetitive. The ruling established that default placement agreements —which had long been treated as legitimate competitive conduct —can constitute anticompetitive exclusionary practices when they are used to maintain monopoly power.
Remedies phase critical. The remedies phase of the case will determine whether Google must alter its default placement practices, divest assets, or make other structural changes, with potentially far-reaching implications for the technology industry.

---

### Case 9.21: United States v. Google LLC —Digital Advertising Technology Monopoly (2024) —E.D. Va.

**Date Decided:** September 2024 (trial concluded)
Court/Regulator: U.S. District Court for the Eastern District of Virginia, Judge Leonie Brinkema
Case citation: No. 1:23-cv-00108 (E.D. Va.)

**Facts:** The U.S. Department of Justice and a coalition of eight states brought a second antitrust case against Google, targeting its dominance in digital advertising technology ("ad tech"). The government alleged that Google had engaged in a systematic campaign to monopolize the ad tech market through a series of acquisitions (including DoubleClick in 2008 and AdMeld in 2011) and self-preferencing practices. The government's theory centered on Google's role across all three stages of the digital advertising transaction: as a publisher ad server (Google Ad Manager), as an ad exchange (Google AdX), and as a demand-side platform (Google DV360). This vertical integration allegedly allowed Google to manipulate auction dynamics, disadvantage competing ad tech intermediaries, and extract monopoly rents from both publishers and advertisers.

**Issue:** Whether Google's acquisition strategy and self-preferencing practices in the digital advertising technology market constituted monopolization in violation of Section 2 of the Sherman Act.

**Holding:** Trial concluded in September 2024. Judge Brinkema largely denied Google's motion to dismiss, allowing the case to proceed to trial. The trial proceedings revealed extensive details about the opaque digital advertising ecosystem and Google's dominant position across the ad tech stack. A decision was pending as of the date of publication.
**Significance:** Ad tech vertical integration as monopoly theory. The case represents the first major antitrust challenge based on a vertical integration theory in digital advertising, potentially establishing new principles for evaluating platform dominance across multiple layers of a technology stack.
Acquisition strategy under scrutiny. The case's focus on Google's acquisition history signals a shift in antitrust enforcement toward retroactive evaluation of acquisitions that, while approved at the time, contributed to later monopolization.
Transparency into digital advertising. The trial proceedings revealed extensive details about the opaque digital advertising ecosystem, contributing to public understanding and regulatory awareness of how advertising auctions function.

---

### Case 9.22: FTC v. Meta Platforms, Inc. (Within Unlimited) —Social VR Acquisition (2024) —FTC

**Date Decided:** August 2024 (complaint); December 2024 (court ruling)
Court/Regulator: U.S. District Court for the Northern District of California; Federal Trade Commission
Case citation: No. 4:24-cv-03367 (N.D. Cal.)

**Facts:** The FTC challenged Meta's $400 million acquisition of Within Unlimited, the developer of the popular virtual reality fitness app "Supernatural." The FTC alleged that the acquisition would substantially lessen competition in the emerging virtual reality (VR) dedicated fitness app market, where Meta (through its Quest platform) already held a dominant position. The FTC argued that Meta had chosen to acquire Within rather than develop its own competing VR fitness app, despite having the resources to do so, and that the acquisition would eliminate a nascent competitor that was performing a "critical check" on Meta's market power. The FTC also pointed to Meta's prior strategy of acquiring potential competitors (including Instagram and WhatsApp) as evidence of a pattern of anticompetitive acquisition.

**Issue:** Whether Meta's acquisition of Within would substantially lessen competition in the dedicated VR fitness app market in violation of Section 7 of the Clayton Act and Section 5 of the FTC Act.

**Holding:** In a December 2024 decision, the court ruled in Meta's favor, finding that the FTC had failed to demonstrate that the relevant market was VR dedicated fitness apps rather than the broader fitness app market and that Meta's acquisition of Within would substantially lessen competition. The court held that the FTC had not adequately defined the market or proven that Within was positioned to become a significant competitive constraint on Meta.
**Significance:** Nascent market theory tested. The case tested the FTC's ability to challenge acquisitions in emerging technology markets, with the court's skepticism suggesting that the "nascent competition" theory requires stronger factual support.
Market definition critical in tech antitrust. The court's rejection of the FTC's narrow market definition (VR dedicated fitness apps) in favor of a broader definition (fitness apps generally) highlighted the central role of market definition in technology antitrust cases.
Presidential administration enforcement priorities. Despite the loss, the case signaled the Biden-era FTC's willingness to pursue aggressive theories of anticompetitive harm in technology markets, even when the odds of success were uncertain.

---

### Case 9.23: Epic Games, Inc. v. Apple Inc. —App Store Antitrust (2021) —N.D. Cal.

**Date Decided:** September 10, 2021
Court/Regulator: U.S. District Court for the Northern District of California, Judge Yvonne Gonzalez Rogers
Case citation: No. 4:20-cv-05640-YGR (N.D. Cal. Sept. 10, 2021)

**Facts:** Epic Games, the developer of the popular game Fortnite, brought an antitrust challenge against Apple's App Store practices after Apple removed Fortnite from the App Store for implementing a direct payment system that bypassed Apple's in-app purchase mechanism (which charges a 30% commission). Epic alleged that Apple's restrictions on alternative payment methods, its prohibition on alternative app stores, and its 30% commission structure constituted illegal tying and monopolization under federal and state antitrust laws. Apple countersued Epic for breach of contract. The case became a landmark confrontation over the business model of "walled garden" app stores.

**Issue:** Whether Apple's App Store practices —including the prohibition on alternative payment methods, the 30% commission, and the restriction on alternative app distribution —constituted illegal tying, monopolization, or anticompetitive conduct under federal and state antitrust laws.

**Holding:** In a mixed ruling, Judge Gonzalez Rogers found in Epic's favor on the state competition claim under California's Unfair Competition Law, holding that Apple's anti-steering provisions —which prevented developers from informing users about alternative purchasing options —were anticompetitive. However, the court ruled against Epic on the federal antitrust claims, finding that Epic had not demonstrated that Apple possessed monopoly power in the relevant market (defined broadly as "digital mobile gaming transactions"). Apple was enjoined from prohibiting developers from including links or buttons that direct consumers to alternative purchasing mechanisms.
**Significance:** Anti-steering provisions as anticompetitive. The finding that Apple's anti-steering provisions violated California competition law established a legal basis for requiring platforms to allow developers to communicate with consumers about alternatives, foreshadowing similar requirements in the EU's Digital Markets Act.
Broad market definition favored defendants. The court's broad definition of the relevant market —encompassing all digital mobile gaming transactions rather than just iOS transactions —made it more difficult for plaintiffs to establish monopoly power in platform cases.
Catalyst for global platform regulation. The Epic v. Apple case served as a catalyst for legislative and regulatory action worldwide, including the EU's Digital Markets Act, Japan's platform regulation, and similar initiatives in South Korea and the United States.

---

### Case 9.24: Tiffany (NJ) Inc. v. eBay Inc. —Counterfeiting and Marketplace Liability (2014) —2nd Cir.

**Date Decided:** April 1, 2014
Court/Regulator: U.S. Court of Appeals for the Second Circuit
Case citation: 600 F.3d 93 (2d Cir. 2010) (district court); appeal at 2014 WL 1310509 (2d Cir. Apr. 1, 2014)

**Facts:** Tiffany & Co. sued eBay, alleging that eBay's online marketplace was saturated with counterfeit Tiffany jewelry and that eBay bore direct and contributory trademark liability for the sale of counterfeit goods on its platform. Tiffany argued that eBay had actual knowledge of widespread counterfeiting, facilitated counterfeiting through its search and advertising features, and failed to take adequate measures to prevent the sale of counterfeit goods. eBay countered that it had implemented extensive anti-counterfeiting measures, including a "VeRO" (Verified Rights Owner) program, automated filtering systems, and cooperation with law enforcement.

**Issue:** Whether eBay had actual or constructive knowledge of specific counterfeit listings sufficient to establish direct or contributory trademark infringement liability.

**Holding:** The Second Circuit affirmed the district court's ruling largely in eBay's favor, finding that Tiffany had not proven that eBay had actual or constructive knowledge of specific counterfeit listings. The court held that general knowledge that counterfeiting occurs on a marketplace platform is insufficient to establish trademark liability —the trademark owner must demonstrate that the platform operator had specific knowledge of particular infringing listings.
**Significance:** Specific knowledge standard for marketplace liability. The Tiffany v. eBay decision established the "specific knowledge" standard for online marketplace trademark liability, requiring trademark owners to provide notice of specific infringing listings before the marketplace can be held liable.
Balancing platform scale and IP enforcement. The decision reflected the courts' recognition that imposing a general duty to police would be impractical for large-scale marketplaces.
Foundation for notice-and-takedown regimes. The case reinforced the notice-and-takedown approach that has become the standard framework for addressing intellectual property violations on online platforms worldwide.

---

### Case 9.25: Amazon Marketplace Third-Party Seller Liability —Consumer Product Safety (2021–2024) —Multiple Courts

**Date Decided:** Key rulings 2021–2024
Court/Regulator: California Supreme Court; Third Circuit Court of Appeals; multiple state and federal courts
Case citation: Lick v. Amazon.com, LLC, 58 Cal. App. 5th 605 (2021); Oberdorf v. Amazon.com, LLC, 930 F.3d 136 (3d Cir. 2019)

**Facts:** A series of cases have addressed Amazon's liability for defective and dangerous products sold by third-party sellers on its marketplace platform. In one significant case, a Pennsylvania woman was severely burned by a defective hoverboard purchased from a third-party seller on Amazon. The hoverboard's battery caught fire, causing second-degree burns. The third-party seller could not be located or served, and the plaintiff argued that Amazon should be held liable as the "seller" of the product under state product liability law because Amazon exercised substantial control over the transaction, stored the product in its warehouses under the Fulfillment by Amazon program, processed the payment, and shipped the product to the consumer. Similar cases involved defective children's products, toxic cosmetics, and unsafe electronics.

**Issue:** Whether Amazon can be held liable as a "seller" or "distributor" under product liability law for defective products sold by third-party sellers on its marketplace, particularly when Amazon warehouses, ships, and processes payment for those products.

**Holding:** In 2021, the California Supreme Court ruled in Lick v. Amazon that Amazon could be held strictly liable for defective products sold through its platform, finding that Amazon played a substantial role in the transaction chain. In 2019, the Third Circuit similarly found in Oberdorf v. Amazon that Amazon could be liable for defective products under Pennsylvania law. These rulings created a growing body of case law holding marketplace platforms accountable for product safety. In response, Amazon has increased product safety requirements for third-party sellers.
**Significance:** Marketplace liability evolving beyond immunity. The decisions represent a significant departure from the traditional framework that shielded online marketplaces from liability for third-party seller conduct.
Fulfillment by Amazon as liability trigger. The combination of warehousing, shipping, and payment processing was found to constitute sufficient involvement in the sale to trigger product liability.
Consumer protection in platform economy. The cases reflect a broader trend toward holding platform intermediaries accountable for the safety and quality of products sold through their services.

---

### Case 9.26: Alibaba Group IP Enforcement —Counterfeit Goods and Platform Responsibility (2015–2021) —Chinese Courts and USTR

**Date Decided:** Ongoing; key enforcement actions 2015–2021
Court/Regulator: Multiple Chinese courts; U.S. Trade Representative (USTR); Hangzhou Internet Court

**Facts:** Alibaba Group, operator of China's largest e-commerce platforms (Taobao, Tmall, and Alibaba.com), has faced persistent allegations that its platforms facilitate the sale of counterfeit goods. The company was repeatedly placed on the USTR's "Notorious Markets" list. In 2015, the China State Administration for Industry and Commerce (SAIC) published a white paper alleging that Taobao failed to adequately address the sale of counterfeit goods. In response, Alibaba implemented extensive anti-counterfeiting measures, including big data analytics to identify suspicious sellers, cooperation with brand owners, and a dedicated anti-counterfeiting task force. The Hangzhou Internet Court, established in 2017, has adjudicated numerous IP disputes involving Alibaba's platforms.

**Issue:** Whether Alibaba's anti-counterfeiting measures were sufficient under Chinese law and international trade obligations, and what level of responsibility e-commerce platforms bear for counterfeit goods sold by third-party merchants.

**Holding:** Chinese courts have generally applied a notice-and-takedown framework, requiring rights holders to identify specific infringing listings before platforms are obligated to remove them. Alibaba has invested billions of yuan in anti-counterfeiting technology. However, enforcement challenges persist due to the scale of Alibaba's platforms (over 800 million active users and millions of merchants).
**Significance:** Platform responsibility at global scale. Alibaba's experience illustrates the unique challenges of combating counterfeiting on platforms operating at massive scale.
Technology-driven enforcement. Alibaba's use of big data analytics, machine learning, and blockchain-based product tracing has set benchmarks for technology-driven IP enforcement.
U.S.-China trade implications. Alibaba's counterfeiting challenges have been incorporated into broader U.S.-China trade discussions.

---

### Case 9.27: Acxiom Corporation —Data Broker Regulation and Transparency (2014–2015) —FTC

**Date Decided:** May 2014 (FTC Staff Report)
Court/Regulator: Federal Trade Commission
Case citation: FTC Staff Report, "Data Brokers: A Call for Transparency and Accountability" (May 2014)

**Facts:** Acxiom Corporation, one of the world's largest data brokers, was a central subject of the FTC's comprehensive investigation into the data broker industry. The FTC found that Acxiom and other data brokers collected, aggregated, and sold detailed consumer profiles containing information on ethnicity, income, health conditions, political affiliations, shopping habits, and other sensitive categories —often without consumers' knowledge or consent. Acxiom maintained profiles on approximately 700 million consumers worldwide, combining data from public records, purchase transactions, online browsing, and other sources. The FTC's investigation revealed that data brokers operated largely invisible to consumers, who had no meaningful way to learn what data was collected about them, to access it, or to correct errors.

**Issue:** Whether the largely unregulated data broker industry's practices of collecting and selling detailed consumer profiles without consumer knowledge or consent constituted unfair or deceptive acts or practices under Section 5 of the FTC Act.

**Holding:** The FTC did not bring a formal enforcement action against Acxiom but used the investigation and its public report to pressure the data broker industry to adopt voluntary transparency measures. In 2014, Acxiom launched a consumer-facing portal ("AboutTheData.com") allowing consumers to view, edit, and opt out of their data profiles. The FTC's report called on Congress to pass legislation requiring data brokers to provide consumers with notice, access, and opt-out rights.
**Significance:** Data broker industry exposed. The FTC's investigation brought unprecedented public attention to the data broker industry, revealing the scope and sophistication of consumer profiling that occurs largely without consumer awareness.
Voluntary transparency as regulatory tool. The FTC's use of public reports and reputational pressure demonstrated the Commission's ability to achieve policy objectives through "soft regulation."
Foundation for CCPA and state privacy laws. The FTC's findings directly influenced the development of state privacy laws, including California's CCPA/CPRA, establishing consumer rights to access, delete, and opt out of data broker activities.

---

### Case 9.28: Experian Data Breach —T-Mobile Breach and Credit Bureau Accountability (2015–2022) —FTC and CFPB

**Date Decided:** January 2022
Court/Regulator: Federal Trade Commission and Consumer Financial Protection Bureau

**Facts:** In 2015, Experian, one of the three major credit reporting bureaus, suffered a data breach that exposed the personal information of approximately 15 million T-Mobile customers who had applied for T-Mobile services. The breach occurred when hackers exploited a vulnerability in Experian's systems to access names, dates of birth, addresses, and Social Security numbers or passport numbers. The FTC's investigation revealed that Experian had failed to implement adequate security measures, including failure to conduct sufficient security testing, failure to implement adequate network segmentation, and failure to apply available security patches. The case was particularly significant because Experian, as a credit reporting agency, maintained some of the most sensitive consumer data in existence.

**Issue:** Whether Experian's data security failures in connection with the 2015 breach constituted violations of the Fair Credit Reporting Act and Section 5 of the FTC Act.

**Holding:** Experian agreed to a multi-state settlement requiring payment of penalties and implementation of enhanced security measures. The settlement required Experian to: (1) implement a comprehensive information security program; (2) conduct regular security assessments and penetration testing; (3) encrypt sensitive consumer data at rest and in transit; and (4) provide credit monitoring services to affected consumers.
**Significance:** Credit bureau repeated failures. The Experian case, combined with the Equifax breach, demonstrated a pattern of inadequate security at the major credit reporting bureaus.
Data processor accountability. The case reinforced the principle that data processors that handle consumer data on behalf of other companies bear independent security obligations.
Regulatory coordination. The coordinated response from the FTC, CFPB, and state attorneys general demonstrated the increasingly multi-jurisdictional nature of data breach enforcement.

---

### Case 9.29: Epsilon Data Breach —Marketing Data Breach and Third-Party Data Sharing Risks (2011) —FTC

**Date Decided:** 2011
Court/Regulator: Federal Trade Commission (investigation and guidance)

**Facts:** In April 2011, Epsilon, one of the world's largest email marketing companies, suffered a data breach that exposed the names and email addresses of approximately 60 million consumers. Epsilon managed email marketing campaigns for over 2,500 major brands, including Citigroup, JPMorgan Chase, Target, Best Buy, Marriott, and Walgreens. The attackers gained access through a sophisticated spear-phishing attack. While the breach did not expose financial data, the compromised email addresses —combined with knowledge of which brands each consumer patronized —created significant risks for targeted phishing attacks.

**Issue:** Whether Epsilon's data security practices were adequate given the sensitivity and scale of the consumer data it maintained on behalf of its corporate clients.

**Holding:** The FTC did not bring a formal enforcement action but used the incident to issue guidance to the marketing industry about the importance of securing consumer email data. Epsilon implemented enhanced security measures. Multiple class action lawsuits were filed and settled.
**Significance:** Marketing data as security target. The Epsilon breach demonstrated that even "non-sensitive" data like email addresses, when aggregated with brand affiliation data, can create significant security risks.
Data concentration risk. The breach highlighted the systemic risk created by the concentration of consumer data in a small number of marketing service providers.
Supply chain security awareness. The case raised awareness of supply chain data security risks —the concept that consumers' data can be compromised through third-party service providers.

---

### Case 9.30: Algorithmic Pricing and Dynamic Pricing in E-Commerce —Emerging Enforcement (2023–2025)

**Date Decided:** Emerging —enforcement actions ongoing as of 2025
Court/Regulator: Various U.S. state attorneys general; EU consumer protection authorities; California legislature

**Facts:** The growing use of algorithmic and dynamic pricing tools in e-commerce has raised significant consumer protection concerns. Algorithms that adjust prices in real time based on consumer behavior, device type, location, browsing history, and willingness to pay have been found to engage in practices including: personalized pricing that charges individual consumers different prices for the same product; surge pricing that dramatically increases prices during periods of high demand; and cross-device tracking that uses information from one device to set prices on another. Investigations have found that major e-commerce platforms have used these tools to identify consumers who are less price-sensitive and charge them higher prices.

**Issue:** Whether algorithmic pricing practices that charge different consumers different prices for the same product constitute unfair or deceptive acts or practices under state and federal consumer protection laws.

**Holding:** As of 2025, enforcement actions are ongoing. California has introduced legislation targeting algorithmic price discrimination. The FTC has signaled increased scrutiny, particularly in essential goods markets. The EU has addressed algorithmic pricing under its consumer protection cooperation framework.
**Significance:** Algorithmic transparency as consumer right. The emerging enforcement represents a new frontier in consumer protection law, extending traditional prohibitions on deceptive pricing to algorithmic price discrimination.
Essential goods pricing as priority. The focus on algorithmic pricing for essential goods reflects a regulatory consensus that price optimization algorithms pose heightened risks when applied to necessities.
Intersection of competition and consumer law. Algorithmic pricing enforcement sits at the intersection of competition law and consumer protection law, creating a regulatory challenge that may require new legal frameworks.

---

### Case 9.31: Dark Patterns in E-Commerce —EU Consumer Protection Enforcement (2022–2025) —EU CPC Network

**Date Decided:** Multiple enforcement actions 2022–2025
Court/Regulator: EU Consumer Protection Cooperation (CPC) Network; European Commission; National consumer protection authorities

**Facts:** In 2022, the EU Consumer Protection Cooperation Network conducted a coordinated sweep of major e-commerce websites and apps, identifying widespread use of "dark patterns" —deceptive user interface designs that manipulate consumers into making choices that benefit the platform. The investigation found that 148 out of 399 checked websites and apps used at least one dark pattern. Common dark patterns included: "confirmshaming" (using guilt to discourage declining optional services); hidden costs revealed only at checkout; countdown timers creating false urgency; pre-checked boxes subscribing consumers to unwanted services; and "nagging" —repeated prompts designed to wear down consumer resistance. Major platforms including Amazon, Booking.com, and various airline and hotel booking sites were found to use these techniques.

**Issue:** Whether the use of dark patterns in e-commerce interfaces constitutes unfair commercial practices under the Unfair Commercial Practices Directive (2005/29/EC).

**Holding:** The CPC Network facilitated coordinated enforcement across multiple EU member states. National authorities issued warnings, compliance orders, and fines. The European Commission used the findings to support amendments to the Unfair Commercial Practices Directive specifically addressing dark patterns. The Digital Services Act (DSA) also includes provisions requiring platforms to avoid dark patterns. As of 2025, enforcement continues with several companies required to modify their interfaces.
**Significance:** Dark patterns defined and targeted. The coordinated EU enforcement established an authoritative taxonomy of dark patterns and demonstrated regulatory willingness to address deceptive interface design as consumer fraud.
Coordinated cross-border enforcement. The CPC Network's approach showed that effective enforcement of digital consumer protection rules requires cross-border cooperation.
Design regulation. The case established that user interface design choices are subject to consumer protection regulation, not merely voluntary industry standards.

---

### Case 9.32: China E-Commerce Law —Platform Operator Liability and Consumer Protection (2019) —Chinese Courts

**Date Decided:** January 1, 2019 (effective); key enforcement 2019–2025
Court/Regulator: Standing Committee of the National People's Congress; People's Courts of China; State Administration for Market Regulation (SAMR)

**Facts:** China's E-Commerce Law, effective January 1, 2019, established a comprehensive framework for e-commerce regulation with particular emphasis on platform operator liability. The law requires e-commerce platform operators to verify merchant identities and qualifications, protect consumers' personal information, ensure product quality and safety, establish consumer complaint mechanisms, and bear joint and several liability for consumer harm caused by products sold by merchants if the platform fails to exercise proper oversight. The law was prompted by widespread consumer complaints about counterfeit goods, false advertising, and poor-quality products on platforms including Taobao, JD.com, and Pinduoduo.

**Issue:** Whether e-commerce platforms bear joint and several liability for harm caused by defective or counterfeit products sold by third-party merchants on their platforms.

**Holding:** Chinese courts have applied the E-Commerce Law to hold platforms jointly liable in cases involving counterfeit goods and unsafe products. Courts have ordered platforms to compensate consumers for losses, particularly where platforms failed to verify merchant qualifications or respond to consumer complaints. SAMR has issued administrative penalties against multiple platforms for failures in merchant verification and product quality oversight.
**Significance:** Joint and several liability for platforms. China's approach is among the most aggressive in the world, imposing joint and several liability on platforms for harm caused by third-party sellers.
Comprehensive e-commerce regulatory framework. China established one of the few comprehensive statutory frameworks specifically addressing e-commerce platform obligations, consumer protection, and data governance.
Enforcement-driven compliance. The dual-track model of civil liability through private litigation and administrative enforcement by SAMR has significantly improved platform compliance.
Notes
The European Commission's DMA enforcement against Apple is ongoing, with additional investigations into Apple's compliance with other DMA obligations as of the date of publication.
The NYDFS cybersecurity regulation (23 NYCRR Part 500) has been in effect since March 2017, with the Second Amendment taking effect in November 2023, reflecting a significant expansion of cybersecurity requirements for New# Global Cyber Law Compendium Volume II —Part Nine Additions
Cases 9.33—.62: E-Commerce & Consumer Protection

---

### Case 9.33: FTC v. Zoom Video Communications (2022) —FTC

**Date Decided:** November 30, 2022

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that Zoom misrepresented its end-to-end encryption (E2EE) capabilities for years, claiming meetings were E2EE when in fact Zoom could access and decrypt meeting content. Zoom also stored plaintext meeting recordings on its servers for up to 60 days without proper disclosure, and misled users about its security practices during the pandemic-era surge in usage.

**Issue:** Whether Zoom's false claims about encryption and data storage violated Section 5 of the FTC Act.

**Holding:** Zoom agreed to an $85 million settlement and was required to implement a comprehensive security program. Zoom was prohibited from making misleading claims about its security and privacy features and mandated to undergo biennial third-party security audits for 20 years.
**Significance:** One of the largest FTC settlements for deceptive privacy claims, signaling aggressive enforcement during the remote-work era.
Established that claiming "end-to-end encryption" when a provider holds decryption keys constitutes a deceptive trade practice, not merely a technical ambiguity.
Set precedent for holding platforms accountable for security marketing claims made during rapid user growth.

---

### Case 9.34: FTC v. Drizly (2023) —FTC

**Date Decided:** January 18, 2023

**Court:** U.S. Federal Trade Commission (administrative order)

**Facts:** The FTC found that Drizly, an alcohol delivery platform, suffered a data breach in 2020 exposing personal information of approximately 2.5 million consumers. The Commission alleged Drizly failed to implement reasonable data security measures, including basic practices such as monitoring for unauthorized access and maintaining an adequate security program.

**Issue:** Whether Drizly's inadequate security practices violated the FTC Act's prohibition against unfair practices.

**Holding:** Drizly agreed to a consent order requiring it to delete historical data not necessary for its services, implement a comprehensive security program, and notify consumers of future breaches. Notably, the FTC extended personal liability to Drizly's CEO, James Cory Rellas, requiring him to obtain FTC approval before assuming a new role at any company collecting consumer data.
**Significance:** Landmark expansion of personal executive liability for data security failures by the FTC, moving beyond corporate-only accountability.
Established the "duty to delete" principle'ompanies must dispose of data they no longer need, not merely protect what they retain.
Signaled FTC willingness to hold individual executives personally responsible for corporate cybersecurity failures.

---

### Case 9.35: FTC v. Ring (Amazon) (2023) —FTC

**Date Decided:** May 31, 2023

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that Amazon's subsidiary Ring, a smart home security camera company, allowed employees and contractors unrestricted access to consumers' private video recordings. Ring also stored encrypted videos in a way that permitted internal access without consumer consent and failed to implement basic security measures such as requiring multi-factor authentication for employee accounts.

**Issue:** Whether Ring's internal access to consumer video data and inadequate access controls violated the FTC Act.

**Holding:** Ring agreed to delete all data and videos collected before the order's effective date that were not necessary for providing services. Ring was required to implement mandatory two-factor authentication, implement a privacy and security program, and was prohibited from using consumer videos for advertising or product development without consent.
**Significance:** First major FTC action addressing internal employee surveillance of consumer IoT data, highlighting insider threat risks in smart home ecosystems.
Reinforced the principle that privacy policies promising consumer control must be backed by actual technical and administrative safeguards.
Illustrated the FTC's willingness to pursue Amazon subsidiaries independently of broader Amazon enforcement actions.

---

### Case 9.36: FTC v. GoodRx (2023) —FTC

**Date Decided:** February 1, 2023

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that GoodRx, a prescription drug price comparison platform, shared sensitive consumer health information'ncluding medication names, prescription histories, and health conditions'ith advertising platforms, data brokers, and other third parties without user consent. Despite representing itself as a privacy-conscious health tool, GoodRx monetized consumer health data through targeted advertising.

**Issue:** Whether GoodRx's disclosure of consumer health data for advertising purposes violated the FTC Act and the FTC Health Breach Notification Rule.

**Holding:** GoodRx agreed to pay $1.5 million and was prohibited from sharing health data with third parties for advertising purposes without affirmative express consent. GoodRx was required to notify affected consumers, implement a comprehensive privacy and data security program, and delete health data previously shared with advertisers.
**Significance:** First FTC enforcement action applying the Health Breach Notification Rule to a non-covered entity under HIPAA, expanding the regulatory perimeter for health data protection.
Established that health-related consumer data shared with advertisers triggers breach notification obligations even when the entity is not a HIPAA-covered entity.
Signaled broader FTC intent to regulate consumer health apps and platforms as de facto health data custodians.

---

### Case 9.37: FTC v. BetterHelp (2023) —FTC

**Date Decided:** March 2, 2023

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that BetterHelp, a leading online therapy platform owned by Teladoc, promised consumers that their sensitive mental health information'ncluding depression diagnoses, suicide ideation, and therapy session content'ould be kept private and confidential. Instead, BetterHelp disclosed this information to third-party advertisers, including Facebook and Snapchat, for targeted advertising purposes.

**Issue:** Whether BetterHelp's disclosure of mental health data to advertisers constituted deceptive and unfair practices under the FTC Act.

**Holding:** BetterHelp agreed to pay $7.8 million in consumer redress and was prohibited from disclosing consumer health information to advertisers without affirmative express consent. BetterHelp was required to implement a comprehensive privacy and security program and obtain periodic third-party assessments.
**Significance:** Largest FTC settlement involving mental health data, establishing heightened sensitivity expectations for digital mental health platforms.
Demonstrated that "confidential" and "private" claims in health app marketing are enforceable commitments, not merely aspirational language.
Reinforced that pixel-based data sharing with advertising platforms constitutes a "disclosure" for regulatory purposes.

---

### Case 9.38: FTC v. Epic Games (2022) —FTC

**Date Decided:** December 19, 2022

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that Epic Games, the developer of Fortnite, employed dark patterns to trick consumers'articularly children'nto making unintended in-game purchases. These included design features that caused charges with a single button press without additional confirmation, and a counterintuitive cancellation process for recurring charges. The FTC also alleged Epic violated the COPPA Rule by collecting personal information from children under 13 without verifiable parental consent.

**Issue:** Whether Epic Games' use of dark patterns for in-game purchases and its collection of children's data violated the FTC Act and COPPA.

**Holding:** Epic Games agreed to pay $245 million in consumer refunds for unfair billing practices (a record COPPA-related refund) and a separate $275 million civil penalty for COPPA violations, totaling approximately $520 million. Epic was required to adopt default privacy-protective settings, obtain affirmative consent before charging, and implement a comprehensive COPPA compliance program.
**Significance:** Largest FTC penalty for COPPA violations and the first major action against dark patterns in gaming, establishing new standards for child-protective design in digital marketplaces.
Defined specific design patterns (e.g., single-click purchasing without confirmation, complex cancellation flows) as per se unfair under the FTC Act.
Set precedent for holding game developers to the same consumer protection standards as other e-commerce platforms, regardless of their "free-to-play" business model.

---

### Case 9.39: FTC v. WW International (Weight Watchers) (2023) —FTC

**Date Decided:** May 12, 2023

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that WW International (formerly Weight Watchers), through its weight-loss app Kurbo, collected personal information from children under 13 without parental consent in violation of COPPA. The app collected sensitive data including weight, height, food intake, and photographs, and used this information to deliver targeted weight-loss marketing to children.

**Issue:** Whether WW International's collection of children's health data through a weight-loss app violated COPPA and the FTC Act.

**Holding:** WW International agreed to a $1.5 million civil penalty and was prohibited from collecting personal information from children under 13 without verifiable parental consent. The company was required to delete previously collected data and implement a comprehensive COPPA compliance program.
**Significance:** Extended COPPA enforcement to health and wellness apps targeting children, establishing that weight-loss apps are subject to the same parental consent requirements as general children's platforms.
Highlighted the particular sensitivity of collecting body-image and weight data from minors, establishing it as a category warranting heightened regulatory scrutiny.
Demonstrated FTC willingness to pursue enforcement even where the data collection may have been well-intentioned (promoting child health) if proper consent mechanisms were absent.

---

### Case 9.40: FTC v. Fortna (2023) —FTC

**Date Decided:** June 14, 2023

**Court:** U.S. Federal Trade Commission (administrative order)

**Facts:** The FTC alleged that Fortna, a background check company, failed to ensure the accuracy of consumer reports it produced, disseminated information about consumers that was not current or accurate, and failed to follow reasonable procedures to assure maximum possible accuracy as required by the Fair Credit Reporting Act (FCRA). Fortna's reports were used by employers for hiring decisions, potentially affecting consumer employment opportunities.

**Issue:** Whether Fortna's inaccurate consumer reports violated the FCRA's accuracy requirements.

**Holding:** Fortna agreed to a consent order requiring it to implement comprehensive procedures to ensure the accuracy of consumer reports, notify furnishers of inaccurate information, provide consumers with copies of their reports upon request, and submit to regular independent assessments of its compliance program.
**Significance:** Reinforced the FCRA's accuracy requirements for digital background check providers, establishing that automated data aggregation does not diminish the duty to ensure report accuracy.
Highlighted the real-world consequences of inaccurate consumer reporting in the digital employment screening ecosystem.
Signaled FTC's continued focus on the background check industry's transition to automated, algorithm-driven consumer reports.

---

### Case 9.41: FTC v. Vonage (2023) —FTC

**Date Decided:** October 24, 2023

**Court:** U.S. Federal Trade Commission (administrative settlement)

**Facts:** The FTC alleged that Vonage, a cloud communications provider, stored sensitive consumer data'ncluding full names, email addresses, phone numbers, and in some cases passwords and authentication tokens'n plaintext on its internal systems without adequate access controls. A 2022 data breach exposed the personal information of Vonage customers due to these inadequate security practices.

**Issue:** Whether Vonage's inadequate data security practices constituted an unfair practice under the FTC Act.

**Holding:** Vonage agreed to a consent order requiring it to implement a comprehensive information security program, conduct annual security assessments, and delete data no longer necessary for business purposes. Vonage was specifically required to address access controls, encryption, and authentication requirements.
**Significance:** Added to the growing body of FTC enforcement establishing specific technical security requirements (encryption, access controls) as minimum standards for companies holding consumer data.
Reinforced the "duty to delete" principle in the FTC's evolving data minimization framework.
Demonstrated that communications providers holding voice and messaging data face heightened security obligations due to the sensitivity of stored communications metadata.

---

### Case 9.42: California Attorney General v. Sephora (2022) —California Superior Court

**Date Decided:** November 2022

**Court:** Alameda County Superior Court, California

**Facts:** The California Attorney General alleged that Sephora violated the California Consumer Privacy Act (CCPA) by selling consumers' personal information to third parties'ncluding data brokers, advertising networks, and analytics companies'ithout providing the required "Do Not Sell" opt-out notice. Sephora also failed to honor consumers' global privacy control (GPC) signals, which under California law should function as a valid opt-out mechanism.

**Issue:** Whether Sephora's failure to honor GPC signals and disclose data sales violated the CCPA.

**Holding:** Sephora agreed to a $1.2 million settlement and was required to implement comprehensive CCPA compliance measures, including honoring GPC signals, conducting quarterly assessments of third-party data sharing, and training employees on CCPA obligations.
**Significance:** First CCPA enforcement action by the California AG specifically addressing global privacy controls, establishing GPC as an enforceable consumer right under California law.
Set precedent for holding retailers accountable for third-party data sharing arrangements that constitute "sales" under the CCPA.
Established that failure to honor automated privacy signals is a standalone CCPA violation, not merely a technical oversight.

---

### Case 9.43: California Attorney General v. Plaid (2022) —California Superior Court

**Date Decided:** December 2022

**Court:** San Francisco County Superior Court, California

**Facts:** The California Attorney General alleged that Plaid, a financial data aggregator that connects consumers' bank accounts to fintech apps, obtained consumers' banking credentials through a deceptive login screen that mimicked their bank's official interface. Plaid collected more data than necessary and shared it with third parties without adequate disclosure, misleading consumers about the scope and purpose of data collection.

**Issue:** Whether Plaid's deceptive interface design and excessive data collection violated the CCPA and California's Unfair Competition Law.

**Holding:** Plaid agreed to an $8 million settlement and was required to clearly disclose its data collection practices, obtain meaningful consumer consent before accessing financial data, provide consumers with the ability to delete their data, and submit to regular privacy assessments.
**Significance:** First major enforcement action against a fintech data aggregator for deceptive interface design, establishing that mimicking bank login interfaces constitutes a deceptive practice.
Defined the boundaries of permissible data collection by financial data intermediaries under the CCPA.
Established important precedent for the regulation of screen-scraping and credential-based data aggregation in the financial technology sector.

---

### Case 9.44: Massachusetts Attorney General v. Tuya (2024) —Massachusetts

**Date Decided:** 2024

**Court:** Massachusetts Office of the Attorney General

**Facts:** The Massachusetts AG alleged that Tuya, a Chinese IoT cloud platform provider, collected excessive personal data from smart home devices'ncluding audio recordings, video feeds, and usage patterns'ransmitted this data to servers in China without adequate disclosure, and failed to implement reasonable security measures. Tuya's platform powered millions of connected devices in Massachusetts households.

**Issue:** Whether Tuya's data collection, cross-border data transfers, and security practices violated Massachusetts data privacy and consumer protection laws.

**Holding:** Tuya agreed to comply with enhanced data protection requirements, limit data collection to what was necessary for device functionality, implement encryption for data in transit and at rest, and provide Massachusetts consumers with transparency about data handling practices. The case resulted in significant operational changes to Tuya's U.S. data processing.
**Significance:** Represented one of the first state-level enforcement actions targeting a Chinese IoT cloud platform for consumer data practices, raising questions about cross-border data governance.
Highlighted the growing tension between IoT device proliferation and consumer data sovereignty, particularly where cloud infrastructure is located abroad.
Established that state AGs can effectively regulate data practices of foreign-headquartered technology companies operating in their jurisdiction.

---

### Case 9.45: Washington Attorney General v. T-Mobile (2024) —Washington

**Date Decided:** 2024

**Court:** King County Superior Court, Washington

**Facts:** The Washington AG alleged that T-Mobile experienced multiple data breaches between 2021 and 2023 that exposed the personal information of millions of Washington residents, including Social Security numbers, driver's license information, and account PINs. The AG alleged that T-Mobile failed to implement adequate security measures despite prior breaches and regulatory commitments to improve its cybersecurity posture.

**Issue:** Whether T-Mobile's repeated security failures and inadequate data protection measures violated Washington's Consumer Protection Act and data breach notification laws.

**Holding:** T-Mobile agreed to a significant financial settlement and was required to implement enhanced security measures including multi-factor authentication, improved network segmentation, and independent security assessments. T-Mobile committed to specific timelines for security improvements and agreed to ongoing oversight by the Washington AG's office.
**Significance:** Reinforced the principle that repeated data breaches constitute evidence of systemic security failures warranting heightened regulatory scrutiny and penalties.
Established that prior settlement commitments for security improvements create ongoing obligations that subsequent failures can amplify.
Highlighted the particular sensitivity of telecommunications data (SSNs, device identifiers, location data) and the corresponding duty of care expected of carriers.

---

### Case 9.46: District of Columbia Attorney General v. Meta (2023) —D.C.

**Date Decided:** December 2023

**Court:** Superior Court of the District of Columbia

**Facts:** The DC AG alleged that Meta (formerly Facebook) engaged in deceptive practices by allowing Cambridge Analytica and other third-party developers to access millions of users' personal data without meaningful consent, misrepresented its data sharing practices in its privacy settings, and failed to adequately monitor third-party app developers' use of consumer data. The case also alleged that Meta's design choices misled users about who could access their information.

**Issue:** Whether Meta's data sharing practices with third-party developers and its privacy settings design violated the District of Columbia's Consumer Protection Procedures Act.

**Holding:** Meta agreed to a settlement that included financial penalties and commitments to enhanced transparency in its data sharing practices, improved developer platform oversight, and clearer privacy disclosures for DC consumers.
**Significance:** One of the most significant state-level enforcement actions arising from the Cambridge Analytica scandal, demonstrating that federal settlements do not preclude state-level accountability.
Established that platform design choices that obscure data sharing with third-party developers can constitute deceptive practices under state consumer protection laws.
Illustrated the ongoing multi-jurisdictional enforcement risk facing major technology platforms for privacy violations.

---

### Case 9.47: United States v. Google Search Remedy Phase (2024— —U.S. District Court for the District of Columbia

**Date Decided:** Pending (remedy phase commenced August 2024)

**Court:** U.S. District Court for the District of Columbia (Judge Amit Mehta)

**Facts:** Following the Court's August 2024 finding that Google maintained an illegal monopoly in general search services and search advertising, the remedy phase was initiated to determine appropriate structural and behavioral remedies. The DOJ proposed sweeping remedies including potential divestiture of Google's Chrome browser, restrictions on default search agreements, and limitations on exclusive contracts with device manufacturers and carriers.

**Issue:** What structural and behavioral remedies are appropriate to restore competition in the general search and search advertising markets where Google was found to hold monopoly power.

**Holding:** Pending. The remedy proceedings involve extensive testimony from economists, industry participants, and the DOJ's proposed remedy framework. The court is considering options ranging from behavioral restrictions to structural remedies.
**Significance:** Represents the most significant potential structural remedy in a technology antitrust case since the breakup of AT&T in 1984.
The outcome will shape the regulatory framework for dominant digital platforms and may establish precedents for the breakup or restructuring of major technology companies.
Regardless of the specific remedy, the case has already influenced global antitrust enforcement, with the EU, UK, and other jurisdictions watching closely.

---

### Case 9.48: United States v. Google (Search Monopoly) (2024) —U.S. District Court for the District of Columbia

**Date Decided:** August 5, 2024

**Court:** U.S. District Court for the District of Columbia (Judge Amit Mehta)

**Facts:** The DOJ filed an antitrust lawsuit in October 2020 alleging that Google maintained monopoly power in general search services and search text advertising through anticompetitive exclusionary agreements. These included multi-billion-dollar default search agreements with Apple, Samsung, Mozilla, and other browser and device manufacturers, as well as self-preferencing in search results on its own platforms (Android, Chrome).

**Issue:** Whether Google's default search agreements and other exclusionary practices constituted unlawful monopolization under Section 2 of the Sherman Act.

**Holding:** Judge Mehta ruled that Google holds monopoly power in both general search services and search text advertising. The court found that Google's default search agreements were anticompetitive exclusionary contracts that maintained its monopoly by foreclosing distribution channels to rivals, and that Google's search quality advantage, while real, did not justify the exclusionary conduct.
**Significance:** First major U.S. antitrust finding against a technology company in over two decades, potentially reshaping the legal landscape for platform regulation.
Established that paying for default placement'oogle's signature strategy'an constitute illegal exclusionary conduct even when the product is arguably superior.
Set the stage for potential structural remedies and influenced parallel antitrust proceedings worldwide.

---

### Case 9.49: FTC v. Amazon.com (2023) —U.S. District Court for the Western District of Washington

**Date Decided:** Filed September 2023

**Court:** U.S. District Court for the Western District of Washington

**Facts:** The FTC filed a landmark antitrust complaint alleging that Amazon used a set of interlocking anticompetitive strategies to unlawfully maintain monopoly power. These included: (1) anti-discounting practices that punish sellers for offering lower prices on other platforms; (2) coercing Prime sellers to use Amazon's fulfillment services (FBA); (3) degrading the buying experience for non-Prime and non-FBA listings; and (4) charging sellers exorbitant fees (averaging over 50% of seller revenue) by leveraging its marketplace monopoly.

**Issue:** Whether Amazon's marketplace practices'ncluding anti-discounting measures, coercive fulfillment requirements, and excessive fee structures'onstitute unlawful monopolization under Section 2 of the Sherman Act.

**Holding:** As of filing, the case is in active litigation. The FTC seeks a permanent injunction to stop Amazon's alleged monopolistic practices and structural relief. Amazon has moved to dismiss, arguing the FTC's theories would harm consumers by raising prices.
**Significance:** Most comprehensive U.S. antitrust challenge to an e-commerce platform's marketplace practices, addressing the full ecosystem of seller coercion, fee structures, and platform self-preferencing.
If successful, could fundamentally reshape how dominant online marketplaces operate, potentially prohibiting anti-discounting provisions and coercive fulfillment arrangements.
Represents the FTC's most aggressive use of antitrust law in the digital economy under Chair Lina Khan.

---

### Case 9.50: European Commission v. Apple (DMA Fine) (2024) —European Commission

**Date Decided:** March 2024

**Court:** European Commission (DG Competition)

**Facts:** The European Commission found that Apple violated the Digital Markets Act (DMA) by preventing app developers from informing users about alternative purchasing options outside the App Store and by restricting developers from steering consumers to cheaper channels. Apple's App Store rules prohibited developers from including external purchase links, pricing information for alternative channels, or any mechanism to circumvent Apple's in-app purchase commission (15–30%).

**Issue:** Whether Apple's App Store anti-steering provisions violated the DMA's obligation to allow business users to communicate offers to end users outside the core platform service.

**Holding:** The Commission determined Apple violated the DMA's anti-steering obligations. Apple was fined approximately €.84 billion and required to modify its App Store rules to allow developers to inform users about alternative purchasing options within apps.
**Significance:** First DMA enforcement action against Apple, establishing that the EU's new competition framework is enforceable and carries substantial penalties.
Directly challenged Apple's walled-garden approach to the App Store and may reshape app distribution economics globally.
Established that restrictions on developer communication about alternative pricing channels constitute a form of market abuse under the DMA, even where Apple argued they were necessary for security or consumer protection.

---

### Case 9.51: European Commission v. Meta (Market Abuse Under DMA) (2024) —European Commission

**Date Decided:** Ongoing investigation under DMA

**Court:** European Commission (DG Competition)

**Facts:** The European Commission initiated DMA enforcement proceedings against Meta, alleging that Facebook and Instagram's "pay or consent" model'hich requires European users to either pay a monthly subscription fee (approximately €.99/month) or consent to unlimited personalized advertising'onstitutes an abusive design that does not offer users a genuine choice. The Commission argued that Meta's model forces users to surrender personal data as the only practical option.

**Issue:** Whether Meta's "pay or consent" model complies with the DMA's obligation to provide users with a genuine and free choice regarding personal data use.

**Holding:** As of 2024, the investigation is active. The Commission's preliminary view is that Meta's model does not provide a "less personalized but equivalent" alternative as required by the DMA, and that the subscription price may be set at an artificially high level to coerce consent.
**Significance:** Tests the boundaries of the DMA's consent requirements for personalized advertising on designated "gatekeeper" platforms.
If the Commission prevails, could force Meta to offer a genuinely free, non-personalized experience or significantly reduce the subscription fee.
Establishes critical precedent for how "pay or consent" models will be regulated across the EU and potentially globally.

---

### Case 9.52: Apple App Store DMA Compliance (2024) —European Commission

**Date Decided:** March 2024 (Commission assessment)

**Court:** European Commission (DG Competition)

**Facts:** Apple implemented changes to its App Store policies in response to the DMA's March 2024 compliance deadline, allowing alternative app marketplaces in the EU and permitting developers to use alternative payment processors. However, Apple's implementation imposed new fees'ncluding a "Core Technology Fee" of €.50 per first annual install'nd complex compliance requirements that developers argued made alternative distribution economically unviable.

**Issue:** Whether Apple's DMA compliance plan genuinely met the DMA's requirements for effective choice and non-discrimination for app developers.

**Holding:** The European Commission opened formal non-compliance proceedings in March 2024, examining whether Apple's implementation'ncluding the Core Technology Fee and reduced but still substantial commissions on alternative stores'efeated the DMA's purpose. Spotify, Epic Games, and other developers filed formal complaints supporting the Commission's investigation.
**Significance:** Establishes the precedent for how regulators will assess the "substance over form" of dominant platforms' compliance with competition law obligations.
Tests whether regulatory mandates for openness can be effectively neutralized through creative fee structuring and compliance complexity.
Will determine whether the DMA's structural requirements can overcome the economic advantages of incumbent platform ecosystems.

---

### Case 9.53: National Consumer Telecom and Utilities Exchange (NCTUE) Regulatory Action (2023) —CFPB

**Date Decided:** September 2023

**Court:** Consumer Financial Protection Bureau (enforcement action)

**Facts:** The CFPB took action against the National Consumer Telecom and Utilities Exchange (NCTUE), a nationwide consumer reporting agency that maintained
Part Nine —E-Commerce & Consumer Protection (Additions 9.63—.97)

---

### Case 9.54: FTC v. Zoom Video Communications ($86 Million Settlement) (2022) —FTC

**Date Decided:** November 9, 2022

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** The FTC alleged that Zoom misled users for years by claiming it offered end-to-end encryption for all meetings when, in reality, it stored and transmitted meeting content in unencrypted form. Zoom also allegedly maintained a secret meeting-mining server in China that intercepted user data and installed a web server on Mac devices that bypassed browser security controls.

**Issue:** Whether Zoom's encryption claims and data security practices constituted unfair and deceptive acts under Section 5 of the FTC Act.

**Holding:** Zoom agreed to an $85 million civil penalty and a comprehensive consent order requiring the company to implement a robust information security program, undergo biennial security assessments for 20 years, delete all data collected prior to the order that was not needed for service provision, and refrain from making misleading claims about its security and privacy features.
**Significance:** Established that advertising "end-to-end encryption" without actual implementation constitutes a Section 5 violation even when the platform does provide some form of encryption.
Set a benchmark for the FTC's approach to security-by-design obligations under consent orders in the videoconferencing era.
Demonstrated that data routing through servers in foreign jurisdictions could itself be grounds for an FTC action when not properly disclosed.

---

### Case 9.55: FTC v. Drizly (Personal Liability Order) (2023) —FTC

**Date Decided:** January 18, 2023

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** The FTC alleged that Drizly, an alcohol delivery platform, and its CEO, James Cory Rellas, failed to implement adequate security measures, leading to a 2020 data breach exposing the personal information of approximately 2.5 million consumers. The FTC held both the company and its CEO personally liable.

**Issue:** Whether a corporate CEO could be held personally liable under Section 5 for failing to implement reasonable data security, and what duties a company owes regarding data collected from acquired companies.

**Holding:** The consent order required Drizly to delete all data collected from consumers who had not used the service in the prior 12 months, implement a comprehensive security program, and submit to independent audits. Uniquely, the order bound CEO Rellas personally: should he join a new company that collects consumer data, he must ensure that company implements an information security program within 30 days and certify its effectiveness.
**Significance:** Marked the first time the FTC imposed personal liability on a CEO for data security failures under a consent order, signaling a dramatic escalation of individual accountability.
Established a "duty to delete" principle, requiring companies to purge data no longer necessary for the original purpose.
Created a novel precedent that personal obligations follow executives to future employers in the data-collection space.

---

### Case 9.56: FTC v. Ring/Amazon (2023) —FTC

**Date Decided:** May 31, 2023

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** The FTC alleged that Ring, Amazon's smart doorbell subsidiary, gave employees and contractors unfettered access to customers' private video recordings. Internal culture reportedly allowed employees to view and annotate sensitive footage'ncluding footage of children and private interiors'ithout consent. Ring also allegedly pressured consumers into creating accounts and using two-factor authentication through manipulative user interface design.

**Issue:** Whether Ring's failure to restrict employee access to customer video data and its use of coercive user interface tactics violated the FTC Act.

**Holding:** Ring agreed to a consent order requiring it to delete all videos, face embeddings, and data models derived from videos collected before the order, except where users affirmatively consented to retention. Ring must implement a mandatory two-factor authentication program, undergo annual third-party privacy and security assessments for 20 years, and cease using customer data to train algorithms without informed consent.
**Significance:** Extended FTC privacy enforcement into the Internet of Things (IoT) and smart home domain, establishing heightened standards for internal access to sensitive visual data.
Recognized that coercive UI design pressuring users into account creation and security features can itself be an unfair practice.
Set a precedent for requiring deletion of data used to train AI models in the privacy enforcement context.

---

### Case 9.57: FTC v. GoodRx (2023) —FTC

**Date Decided:** February 1, 2023

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** GoodRx, a prescription drug price comparison platform, promised users it would never sell their personal health information. Despite this promise, GoodRx shared sensitive health data'ncluding prescription drug information, pharmacy choices, and health conditions'ith advertising companies, data brokers, and pharmaceutical firms. The platform's privacy policy contained broad loopholes that allowed data sharing for purposes consumers did not expect.

**Issue:** Whether GoodRx's sharing of health data with third-party advertisers violated its privacy promises to consumers and constituted an unfair or deceptive act under the FTC Act, despite not being a covered entity under HIPAA.

**Holding:** GoodRx agreed to pay $1.5 million in civil penalties and was prohibited from sharing user health data with advertisers or other third parties for advertising purposes. The order required GoodRx to obtain explicit opt-in consent before using or disclosing health data for any purpose beyond the core service, notify users whose data was improperly shared, and implement a comprehensive data security program.
**Significance:** Demonstrated the FTC's willingness to regulate health data privacy outside of HIPAA's covered-entity framework, establishing that general-purpose platforms handling sensitive health information face similar obligations.
Reinforced that specific privacy promises (e.g., "we will never sell your data") create binding contractual-like obligations enforceable by the FTC.
Signaled expanding FTC jurisdiction over digital health platforms as health-related e-commerce grows.

---

### Case 9.58: FTC v. BetterHelp (2023) —FTC

**Date Decided:** March 2, 2023

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** BetterHelp, an online mental health and therapy platform owned by Teladoc Health, marketed itself as a confidential and private service. The FTC alleged that despite these promises, BetterHelp disclosed consumers' sensitive mental health information'ncluding depression, anxiety, and suicidal ideation data'o third-party advertisers, including Facebook, Snapchat, and Google, through tracking pixels and SDKs.

**Issue:** Whether BetterHelp's disclosure of consumers' mental health data to advertising platforms violated its privacy promises and constituted deceptive and unfair practices.

**Holding:** BetterHelp agreed to pay $7.8 million in consumer redress and was prohibited from disclosing consumer health information to advertisers. The order required BetterHelp to obtain affirmative express consent before using or sharing health data for any purpose beyond service delivery, delete previously shared data to the extent possible, and implement a comprehensive privacy and security program.
**Significance:** Established that digital mental health platforms bear heightened obligations to protect the sensitivity of their data, with the FTC treating mental health information as a category warranting special protection.
Highlighted the systemic risks of embedded third-party tracking technologies (pixels, SDKs) in health-sensitive platforms.
At the time, represented the largest FTC financial recovery in a health-data privacy case, signaling regulatory prioritization of digital health consumer protection.

---

### Case 9.59: FTC v. Epic Games ($520 Million Settlement) (2022) —FTC

**Date Decided:** December 19, 2022

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** The FTC brought a dual-action complaint against Epic Games, the maker of the popular online game Fortnite. The complaint alleged that Epic used dark patterns and manipulative design'uch as pre-checked boxes, confusing button placement, and counterintuitive checkout processes'o trick millions of users, particularly children and teenagers, into making unintended in-game purchases. Separately, Epic allegedly violated the Children's Online Privacy Protection Act (COPPA) by collecting personal information from children under 13 without verifiable parental consent and by enabling real-time voice and text communication that exposed children to inappropriate content and predators.

**Issue:** Whether Epic Games' in-game purchase design violated the FTC Act's prohibition on dark patterns and whether its data collection practices violated COPPA.

**Holding:** Epic agreed to pay $245 million in consumer refunds for the dark pattern violations (the largest refund ever in a gaming case) and a $275 million civil penalty for COPPA violations. The consent order required Epic to adopt default privacy-protective settings, implement a robust parental consent mechanism, obtain affirmative consent before charging users, and submit to independent COPPA and privacy audits for 20 years.
**Significance:** Represented the largest combined FTC enforcement action in the gaming industry, totaling $520 million.
Established clear regulatory standards against dark patterns in in-game purchase flows, particularly targeting design elements that exploit children's cognitive vulnerabilities.
Set important precedents for COPPA enforcement in the context of real-time voice/text communications in online gaming platforms.

---

### Case 9.60: FTC v. Vonage (2023) —FTC

**Date Decided:** September 7, 2023

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** The FTC alleged that Vonage, a major VoIP and communications provider, failed to implement reasonable data security measures, which led to data breaches exposing the personal information of hundreds of thousands of consumers. Vonage allegedly stored sensitive customer data'ncluding Social Security numbers, account PINs, and authentication credentials'n plain text, without encryption, and failed to segment its internal networks to prevent unauthorized access.

**Issue:** Whether Vonage's inadequate data security practices'ncluding unencrypted storage of sensitive credentials and failure to use multifactor authentication'onstituted unfair practices under Section 5 of the FTC Act.

**Holding:** Vonage agreed to a consent order requiring implementation of a comprehensive information security program, annual independent security assessments for 20 years, and a prohibition on misrepresenting its security practices. The order required Vonage to encrypt sensitive data at rest and in transit, implement access controls and authentication safeguards, and notify affected consumers of security incidents.
**Significance:** Added to the FTC's growing body of "unreasonable security" enforcement, emphasizing that storing authentication credentials and sensitive PII in plain text is per se unreasonable.
Reinforced the principle that telecommunication providers face the same data security obligations as digital platforms under FTC Act jurisdiction.
Contributed to the emerging standard that failure to implement basic security controls (encryption, access management, network segmentation) constitutes an unfair practice even without a specific breach.

---

### Case 9.61: California AG v. Plaid ($8 Million Settlement) (2023) —California

**Date Decided:** January 19, 2023

**Court:** Office of the California Attorney General (Settlement)

**Facts:** Plaid, a financial technology company that connects consumers' bank accounts to applications, operated a data harvesting infrastructure that collected and retained sensitive financial data far beyond what was necessary for its services. Plaid allegedly obtained login credentials through a deceptive login screen that mimicked consumers' bank interfaces, leading users to believe they were entering credentials directly into their bank rather than sharing them with Plaid. The company then monetized this data by building detailed consumer financial profiles and selling analytics to third parties.

**Issue:** Whether Plaid's use of deceptive login interfaces and its excessive collection and monetization of consumer financial data violated the California Consumer Privacy Act (CCPA) and California's Unfair Competition Law.

**Holding:** Plaid agreed to pay $8 million to the California Attorney General, cease using deceptive login screens, provide transparent disclosures about its data practices, implement a comprehensive privacy and data minimization program, and submit to independent privacy assessments for five years. Plaid also committed to deleting data no longer necessary for its core services and honoring consumer opt-out requests under CCPA.
**Significance:** Represented one of the first major CCPA enforcement actions by a state attorney general against a financial technology intermediary.
Established that "screen spoofing"'reating interfaces that mimic trusted institutions to harvest credentials's a deceptive practice actionable under both the CCPA and state unfair competition law.
Highlighted the regulatory risks faced by fintech intermediaries that aggregate and monetize consumer financial data without adequate transparency.

---

### Case 9.62: Massachusetts AG v. Tuya Smart Home Devices (2024) —Massachusetts

**Date Decided:** October 2024

**Court:** Office of the Massachusetts Attorney General (Enforcement Action)

**Facts:** The Massachusetts Attorney General investigated Tuya, a Chinese-headquartered IoT cloud platform powering millions of smart home devices worldwide, for pervasive data security failures. The investigation revealed that Tuya's platform transmitted device data'ncluding audio recordings, video feeds, and household activity patterns'o servers in China without adequate encryption or consumer notice. The devices were found to lack basic security controls, allowing unauthorized remote access.

**Issue:** Whether Tuya's IoT data practices and security failures violated Massachusetts consumer protection and data security laws.

**Holding:** Massachusetts reached a settlement requiring Tuya-connected device manufacturers to implement robust security standards, provide clear disclosures about data transmission to foreign servers, offer consumers the ability to opt out of data collection, and undergo independent security assessments. The AG's office reserved the right to pursue additional enforcement against non-compliant device manufacturers in the Tuya ecosystem.
**Significance:** Represented one of the first state-level enforcement actions targeting an IoT cloud platform's global data infrastructure, rather than individual device manufacturers.
Highlighted the growing regulatory scrutiny of Chinese-headquartered technology companies processing U.S. consumer data.
Established state-level expectations for supply-chain data security in the Internet of Things market.

---

### Case 9.63: District of Columbia AG v. Meta Platforms (2023) —District of Columbia

**Date Decided:** May 2023

**Court:** Office of the Attorney General for the District of Columbia (Complaint & Settlement)

**Facts:** The D.C. Attorney General sued Meta for knowingly allowing Cambridge Analytica and other third parties to harvest millions of users' personal data through deceptive applications. The complaint alleged that Meta was aware of the data misuse as early as 2011 but failed to take meaningful action, instead continuing to allow third-party app developers broad access to user and friends' data.

**Issue:** Whether Meta's failure to prevent third-party data harvesting constituted a violation of the D.C. Consumer Protection Procedures Act.

**Holding:** Meta agreed to a $9.75 million settlement and was required to implement stronger third-party app oversight, provide regular compliance reports to the D.C. AG's office, and maintain enhanced data access controls for its platform.
**Significance:** Represented one of the most significant state-level accountability measures against Meta for the Cambridge Analytica scandal, complementing the FTC's 2019 $5 billion settlement.
Demonstrated that state attorneys general can pursue independent enforcement against major platforms for data practices already addressed (albeit inadequately, in the AG's view) at the federal level.
Reinforced the principle that platforms bear affirmative obligations to police third-party developer access to user data.

---

### Case 9.64: Washington State AG v. T-Mobile (2024) —Washington

**Date Decided:** January 2024

**Court:** Office of the Washington State Attorney General (Settlement)

**Facts:** The Washington Attorney General alleged that T-Mobile failed to adequately protect consumer data despite multiple prior breaches. The investigation focused on T-Mobile's 2021 and 2023 data breaches, which collectively exposed the personal information of over 80 million current and former customers. The AG argued that T-Mobile had known about critical security vulnerabilities'ncluding unpatched systems and inadequate access controls'or years but failed to invest in remediation.

**Issue:** Whether T-Mobile's repeated failure to implement adequate data security measures violated the Washington State Consumer Protection Act.

**Holding:** T-Mobile agreed to a significant financial settlement and committed to implementing comprehensive security upgrades, including mandatory encryption of consumer data, enhanced network segmentation, penetration testing, and regular security audits conducted by independent assessors. T-Mobile also agreed to provide enhanced breach notification and identity protection services to affected Washington consumers.
**Significance:** Represented the latest in a series of state-level actions against T-Mobile for recurring data security failures, establishing that repeated breaches can generate escalating regulatory consequences.
Contributed to the emerging state-law standard that telecommunications carriers face heightened data security obligations under consumer protection statutes.
Demonstrated the role of state attorneys general in filling perceived gaps in federal data security enforcement.

---

### Case 9.65: United States v. Google LLC —Search Remedy Phase (2024–2025) —U.S. District Court for the District of Columbia

**Date Decided:** Remedy phase initiated August 2024; ongoing as of 2025

**Court:** U.S. District Court for the District of Columbia (Judge Amit Mehta)

**Facts:** Following the landmark August 2024 finding that Google maintained an illegal monopoly in general search services through exclusive distribution agreements (notably the default search deal with Apple), the court entered the remedy phase to determine structural and behavioral remedies. The DOJ proposed radical structural remedies including a potential forced sale of Google's Chrome browser, restrictions on exclusive default agreements, and requirements to share search data with rivals.

**Issue:** What remedies are appropriate to restore competition in the general search market after finding Google maintained monopoly power through anticompetitive default distribution agreements.

**Holding:** As of early 2025, the remedy proceedings are ongoing. Judge Mehta has indicated willingness to consider structural remedies. The DOJ has proposed requiring Google to: (1) divest the Chrome browser; (2) cease exclusive default search agreements; (3) share anonymized search query data with competitors; and (4) allow websites to opt out of AI training on their content. Google has opposed structural remedies as excessive and argued for narrower behavioral modifications.
**Significance:** Represents the most significant U.S. antitrust remedy proceeding since the Microsoft case of the early 2000s, potentially reshaping the structure of the search market.
Tests whether courts will impose structural remedies (divestiture) in digital markets, a question with far-reaching implications for other platform monopolies.
The outcome will define the legal boundaries of default distribution agreements and platform data advantages in search and AI.

---

### Case 9.66: FTC v. Amazon.com Inc. —Antitrust Complaint (2023) —FTC

**Date Decided:** Complaint filed September 26, 2023

**Court:** U.S. Federal Trade Commission (Administrative Proceeding)

**Facts:** The FTC and 17 state attorneys general filed a sweeping antitrust complaint against Amazon, alleging the company maintained monopoly power in the online marketplace through a pattern of anticompetitive conduct. Key allegations included: (1) forcing third-party sellers into anti-discount agreements (the "Most Favored Nation" or pricing parity clauses) that prevented them from offering lower prices on competing platforms; (2) manipulating search results to favor Amazon's own products over third-party listings; (3) conditioning seller access to Amazon's Buy Box and Prime fulfillment program on use of Amazon's logistics services; and (4) degrading service quality for sellers who used competing fulfillment.

**Issue:** Whether Amazon's marketplace practices'ncluding pricing parity clauses, self-preferencing in search results, and coercive fulfillment requirements'onstitute exclusionary conduct maintaining illegal monopoly power.

**Holding:** As of 2025, the administrative proceeding is ongoing before an FTC Administrative Law Judge. Amazon has moved to dismiss and challenged the FTC's constitutionality, arguments largely rejected by the ALJ. A trial date has been set for 2026. In parallel, Amazon faces similar claims from the EU under the Digital Markets Act.
**Significance:** Represents the most comprehensive FTC antitrust action against a major e-commerce platform, challenging the fundamental business model of a two-sided marketplace.
Tests whether MFN/pricing parity clauses in marketplace settings constitute illegal restraints, a question with implications for all platform-mediated commerce.
The case's outcome could reshape the obligations of dominant platforms regarding self-preferencing, seller autonomy, and fair competition.

---

### Case 9.67: European Commission v. Apple Inc. —DMA Non-Compliance Fine (2024) —European Commission

**Date Decided:** March 2024 (preliminary findings); fines under investigation as of 2025

**Court:** European Commission (DMA Enforcement)

**Facts:** Following the entry into force of the EU Digital Markets Act (DMA) in March 2024, the European Commission investigated Apple for potential non-compliance with its obligations as a designated "gatekeeper." Key concerns included Apple's imposition of a "Core Technology Fee" for app distribution outside the App Store, restrictions on third-party app stores and payment processors, and alleged anti-steering provisions that prevented developers from informing users about cheaper purchasing options outside the iOS ecosystem.

**Issue:** Whether Apple's App Store policies and alternative distribution framework comply with the DMA's gatekeeper obligations, particularly regarding anti-steering, choice of payment systems, and effective interoperability.

**Holding:** The Commission opened formal proceedings in March 2024. Apple made partial concessions'evising its fee structure and allowing alternative app stores in the EU'ut the Commission determined these changes were insufficient. The investigation continued into 2025, with potential fines of up to 10% of Apple's global annual turnover for non-compliance.
**Significance:** Represents the first major enforcement action under the Digital Markets Act, establishing the practical enforcement framework for the EU's new platform regulation regime.
Tests whether gatekeeper-designated platforms can implement alternative compliance frameworks that technically satisfy DMA requirements while maintaining commercial control.
Sets critical precedent for how the DMA will shape app distribution, payment systems, and developer choice across the digital economy.

---

### Case 9.68: European Commission v. Meta Platforms —Abuse of Dominance (2023) —European Commission

**Date Decided:** December 2023 (preliminary ruling under DSA/DMA framework)

**Court:** European Commission

**Facts:** The European Commission found that Meta abused its dominant position in the online social networking and digital advertising markets by tying its Facebook Marketplace classified ads service to its social network and imposing unfair trading conditions on Facebook users who advertised on rival classified ads platforms. Meta allegedly forced competing advertisers to use Facebook's advertising tools and degraded the visibility of listings that linked to competing platforms.

**Issue:** Whether Meta's integration of Marketplace into Facebook and its restriction of competing classified ads services constitute abuse of dominant position under Article 102 of the Treaty on the Functioning of the European Union.

**Holding:** The Commission issued a preliminary finding of abuse. Meta faced potential fines of up to 10% of global annual turnover. The Commission required Meta to propose remedies ensuring that competing classified ads services could operate on equal terms within and alongside Meta's platform. Proceedings continued into 2025.
**Significance:** Extended EU competition law's application to social media-embedded marketplace features, addressing the blurring of boundaries between social networking and e-commerce.
Established that tying a marketplace service to a dominant social network may constitute exclusionary conduct even when the tied product is provided "free" to users.
Contributed to the broader EU strategy of using both competition law and the DMA to regulate dominant digital platforms.

---

### Case 9.69: Apple App Store Changes Under EU DMA (2024) —European Union

**Date Decided:** Effective March 7, 2024

**Court:** European Commission (Regulatory Framework Implementation)

**Facts:** In response to the Digital Markets Act's requirements, Apple introduced sweeping changes to its App Store and iOS ecosystem in the EU, including allowing third-party app stores (Alternative App Marketplaces), enabling alternative payment processing systems, and permitting developers to link to external purchasing options. However, Apple's implementation was criticized for imposing a new "Core Technology Fee" of €.50 per first annual install exceeding 1 million, maintaining Notarization requirements with Apple's discretion, and restricting alternative app stores' ability to offer cross-platform install capabilities.

**Issue:** Whether Apple's DMA compliance implementation provides "effective" choice and fair access as required by the DMA, or whether it creates new barriers that undermine the regulation's objectives.

**Holding:** The European Commission initiated formal proceedings against Apple in March 2024, assessing whether its compliance was genuine or merely nominal. Major developers including Epic Games, Spotify, and Microsoft criticized the fee structure as still anti-competitive. Spotify launched an alternative payment option in the EU but found Apple's compliance framework imposed significant friction. The Commission's investigation into potential non-compliance continued through 2025.
**Significance:** Marked the first real-world test of the DMA's impact on a closed mobile ecosystem, with implications for the fundamental architecture of app distribution globally.
Raised the question of whether new fee structures replacing traditional commission models can themselves constitute anti-competitive conduct under the DMA.
Provided a template for other jurisdictions (including Japan, South Korea, and the UK) considering similar app store regulation.

---

### Case 9.70: UK Competition and Markets Authority —Google Privacy Sandbox (2023–2024) —UK CMA

**Date Decided:** Formal investigation initiated 2023; ongoing enforcement through 2024

**Court:** UK Competition and Markets Authority

**Facts:** The CMA investigated Google's Privacy Sandbox initiative, which aimed to phase out third-party cookies in the Chrome browser and replace them with Google-controlled privacy-preserving advertising technologies (including the Topics, Protected Audiences, and Attribution Reporting APIs). The CMA expressed concerns that while the stated goal was privacy enhancement, the practical effect would entrench Google's dominance in digital advertising by giving it privileged access to browsing data and advertising targeting capabilities unavailable to competitors.

**Issue:** Whether Google's Privacy Sandbox proposals constitute an abuse of dominant position in the digital advertising market by self-preferencing Google's advertising technology stack under the guise of privacy protection.

**Holding:** The CMA accepted Google's initial commitments to maintain a level playing field during the Privacy Sandbox transition, including allowing competing adtech firms access to the new APIs on fair terms and retaining independent oversight. However, when Google proposed to delay the full removal of third-party cookies, the CMA intervened to ensure competitive concerns remained addressed. Throughout 2024, the CMA maintained active monitoring and enforcement authority over the transition.
**Significance:** Established the principle that privacy-enhancing technology transitions can raise competition concerns when implemented by a dominant platform controlling the underlying infrastructure.
Created a precedent for competition regulators actively overseeing technology architecture decisions in the browser and advertising technology space.
Demonstrated the UK's post-Brexit approach to digital market regulation, combining competition law with data protection considerations.

---

### Case 9.71: UK CMA —Amazon Marketplace Investigation (2023) —UK CMA

**Date Decided:** Investigation launched October 2023

**Court:** UK Competition and Markets Authority

**Facts:** The CMA launched a market investigation into Amazon's UK marketplace practices, focusing on how Amazon uses data from third-party sellers to develop and prioritize its own branded products, the conditions imposed on sellers using Amazon's fulfillment services (FBA), and the algorithmic ranking of search results that may favor Amazon's private label products over those of independent sellers.

**Issue:** Whether Amazon's use of seller data for competing private-label products and its self-preferencing in search rankings constitute anti-competitive practices that harm consumer welfare.

**Holding:** As of 2025, the investigation is ongoing. The CMA has gathered extensive evidence from third-party sellers and is assessing potential remedies, which could include restrictions on Amazon's use of seller data for private-label products and requirements to ensure algorithmic neutrality in product rankings.
**Significance:** Represents the UK's first comprehensive competition investigation into the self-preferencing and data-use practices of a major e-commerce marketplace.
Will inform the broader regulatory approach under the UK's anticipated Digital Markets, Competition and Consumers Bill.
Tests whether competition law can effectively address the "platform-as-competitor" dynamic inherent in modern marketplace business models.

---

### Case 9.72: Australian Competition and Consumer Commission v. Meta Platforms (2022–2023) —Federal Court of Australia

**Date Decided:** Judgment rendered September 2023

**Court:** Federal Court of Australia

**Facts:** The ACCC sued Meta for publishing paid scam advertisements on Facebook that used the logos and brand identities of prominent Australian public figures'ncluding billionaire businessman Andrew Forrest'o promote fraudulent cryptocurrency investment schemes. The ACCC alleged that Meta failed to take adequate measures to prevent scammers from running fraudulent ads on its platform despite receiving numerous complaints, and that Meta's ad targeting systems actually facilitated the dissemination of scam content to vulnerable consumers.

**Issue:** Whether Meta engaged in misleading, deceptive, or unconscionable conduct by publishing and profiting from fraudulent advertisements on its platform, and whether it failed to take reasonable steps to prevent such content.

**Holding:** Justice Mortimer initially ruled in favor of Meta on most counts in June 2022, finding that Meta did not "publish" the ads in the traditional sense and that the ads were created by third-party scammers. However, on appeal and with additional evidence, the court narrowed Meta's defenses. The ACCC continued to pursue claims, and the proceedings contributed to the Australian government's decision to strengthen platform liability provisions in subsequent legislation.
**Significance:** Highlighted the difficulty of applying traditional advertising liability principles to algorithmically targeted content on digital platforms.
Catalyzed legislative reform in Australia, including provisions in the Online Safety Act and proposed anti-scam legislation that would impose direct duties on platforms to prevent fraudulent advertising.
Raised fundamental questions about when a digital platform's ad delivery system constitutes "publication" under consumer protection law.

---

### Case 9.73: Australia ACCC —Ticketing Market / Live Nation (2023) —ACCC

**Date Decided:** Report and enforcement action 2023

**Court:** Australian Competition and Consumer Commission (Regulatory Enforcement)

**Facts:** The ACCC investigated Live Nation Entertainment's (Ticketmaster's parent company) dominance in the Australian ticketing market. The investigation focused on Ticketmaster's exclusive venue contracts, dynamic pricing practices that drove ticket prices above face value, lack of transparency in fee disclosure, and the acquisition of competing ticketing platforms that reduced consumer choice. The probe was intensified by the 2023 Taylor Swift ticketing controversy, where Ticketmaster's systems collapsed under demand and dynamic pricing drove prices to extreme levels.

**Issue:** Whether Live Nation/Ticketmaster's exclusive venue contracts, dynamic pricing, and market consolidation constituted anti-competitive conduct harming Australian consumers.

**Holding:** The ACCC issued enforcement guidance requiring Ticketmaster to improve fee transparency and implement fairer queuing systems. The ACCC also recommended regulatory reforms to address exclusive venue contracting and dynamic pricing in the ticketing sector, and referred specific conduct for further investigation under competition law.
**Significance:** Demonstrated the ACCC's willingness to challenge opaque pricing mechanisms'articularly "dynamic pricing"'n online event ticketing markets.
Contributed to global regulatory momentum against Live Nation/Ticketmaster's market dominance, paralleling the DOJ's separate U.S. antitrust action.
Established the principle that platform operators bear responsibility for transparency and fairness in algorithmically determined pricing.

---

### Case 9.74: United States v. Live Nation Entertainment Inc. (2024) —DOJ

**Date Decided:** Complaint filed May 2024

**Court:** U.S. Department of Justice, Antitrust Division (U.S. District Court for the Southern District of New York)

**Facts:** The DOJ and 30 state and district attorneys general filed a landmark antitrust complaint seeking to break up Live Nation Entertainment, the parent company of Ticketmaster. The complaint alleged that Live Nation monopolized the live events industry through a three-pronged strategy: (1) acquiring dominant ticketing platforms (notably Ticketmaster's 2010 merger with Live Nation); (2) using exclusive venue contracts to lock out competitors; and (3) engaging in retaliatory conduct against artists, venues, and promoters who attempted to use alternative ticketing services. The complaint cited the 2022–2023 ticketing crises'ncluding the Taylor Swift Eras Tour presale collapse's evidence of monopoly harm.

**Issue:** Whether Live Nation illegally maintained monopoly power in the live event ticketing market through exclusive venue contracts, anti-competitive acquisitions, and retaliation, and whether divestiture of Ticketmaster is an appropriate remedy.

**Holding:** The case is in pre-trial proceedings as of 2025. The DOJ seeks the forced divestiture of Ticketmaster from Live Nation, as well as injunctive relief prohibiting exclusive venue contracts and anti-retaliation practices. Live Nation has vigorously defended its practices, arguing that its integrated model benefits consumers through efficiency and that market power resides with artists and venues, not the ticketing company.
**Significance:** Represents the most aggressive U.S. antitrust action in the entertainment and ticketing sector in decades, testing the viability of structural remedies (forced breakup) in platform-mediated markets.
Addresses the intersection of e-commerce (online ticketing) and real-world market power in a sector increasingly dominated by digital platforms.
Sets the stage for defining the boundaries of exclusive contracting and platform tying in the broader e-commerce context.

---

### Case 9.75: Competition Commission of India v. Google LLC —Android Ecosystem (2022) —Competition Commission of India

**Date Decided:** October 2022 (order); upheld on appeal in part 2024

**Court:** Competition Commission of India (CCI); NCLAT on appeal

**Facts:** The CCI found that Google abused its dominant position in the Android mobile operating system and app store markets through multiple practices: (1) mandating pre-installation of the entire Google suite of applications (Search, Chrome, YouTube, Maps, etc.) as a condition of licensing the Google Play Store and Google Search to Android device manufacturers; (2) restricting the ability of manufacturers to develop modified versions of Android (Android "forks"); and (3) imposing a 15–30% commission on in-app purchases through Google Play Billing with anti-steering provisions.

**Issue:** Whether Google's bundling of applications, restriction of Android forking, and Play Store billing practices constitute abuse of dominant position under Section 4 of India's Competition Act.

**Holding:** The CCI imposed a total penalty of approximately €,337.77 crore (~$161 million) and issued a series of behavioral remedies: Google was ordered to (1) cease requiring pre-installation of its applications; (2) allow manufacturers to develop and distribute forked versions of Android; (3) allow alternative app stores on Android devices; and (4) not restrict developers from using third-party payment processors. Google appealed several aspects of the order.
**Significance:** Represented one of the most comprehensive competition rulings against Google's Android ecosystem globally, going further than the EU's Android decision in some respects.
Established India as a significant jurisdiction for digital platform competition enforcement, with implications for Google's operations in one of the world's largest smartphone markets.
Provided a model for how competition authorities can address platform tying and bundling practices in mobile operating systems.

---

### Case 9.76: Competition Commission of India v. WhatsApp and Facebook (2021) —Competition Commission of India

**Date Decided:** Decision rendered November 2021

**Court:** Competition Commission of India

**Facts:** The CCI investigated Facebook's 2019 update to WhatsApp's privacy policy, which expanded data sharing between WhatsApp and Facebook's broader ecosystem (including Instagram and Facebook). The policy change allowed WhatsApp to share user metadata'ncluding transaction data, device information, and usage patterns'ith Facebook for advertising and business purposes. The CCI examined whether this data sharing, combined with Facebook's existing dominance in social networking, created an insurmountable data advantage that foreclosed competition in the Indian digital market.

**Issue:** Whether Facebook's integration of WhatsApp user data into its advertising ecosystem constitutes abuse of dominant position by leveraging data advantage to foreclose competition.

**Holding:** The CCI found that while the data sharing raised competition concerns, it could not conclusively establish that the practice caused "appreciable adverse effect on competition" in India given the preliminary stage of WhatsApp's monetization. However, the CCI imposed a cease-and-desist order requiring Facebook/WhatsApp to ensure that the privacy policy update did not: (1) force users to consent to data sharing as a condition of continued service; (2) use WhatsApp data for Facebook's advertising without affirmative consent; or (3) discriminate against competing services using the shared data.
**Significance:** Established the CCI's jurisdiction over data-related competition issues in the Indian digital market.
Recognized the competitive significance of data accumulation and sharing across a corporate ecosystem, even while declining to find a violation at the evidence stage.
Presaged the broader global regulatory focus on data portability, consent, and ecosystem-level competition in messaging platforms.

---

### Case 9.77: South Korea KFTC v. Google LLC (2022) —Korea Fair Trade Commission

**Date Decided:** September 2022 (final order)

**Court:** Korea Fair Trade Commission (KFTC)

**Facts:** The KFTC found that Google abused its dominant position in the mobile operating system market by requiring Android device manufacturers to sign anti-fragmentation agreements (AFAs) as a condition of pre-installing the Google Play Store. These agreements prevented manufacturers from developing or promoting devices running modified versions of Android (forks), effectively blocking competition from alternative mobile operating systems. The KFTC also found that Google tied its Search and Chrome applications to Play Store access.

**Issue:** Whether Google's anti-fragmentation agreements and mandatory pre-installation conditions constitute abuse of dominant market position under South Korea's Monopoly Regulation and Fair Trade Act.

**Holding:** The KFTC imposed a record fine of €07.4 billion (~$149 million) and issued a corrective order requiring Google to: (1) cease enforcing anti-fragmentation agreements with Android device manufacturers; (2) allow manufacturers to develop and distribute Android fork-based devices without penalty; and (3) not retaliate against manufacturers who chose to develop competing operating systems. Google appealed the decision to the Seoul High Court.
**Significance:** Represented the largest fine ever imposed by the KFTC against a single company, demonstrating South Korea's increasingly assertive approach to digital platform regulation.
Established Korean competition law as a significant constraint on global platform strategies in the mobile ecosystem.
Complemented similar enforcement actions in the EU, India, and the United States, contributing to the global consensus that Android ecosystem restrictions raise competition concerns.

---

### Case 9.78: Japan Fair Trade Commission —Amazon.co.jp Unfair Trade Practices (2022) —JFTC

**Date Decided:** Recommendation issued October 2022

**Court:** Japan Fair Trade Commission (JFTC)

**Facts:** The JFTC investigated Amazon Japan (Amazon.co.jp) for pressuring third-party sellers on its marketplace to offer the same or lower prices on Amazon as on competing platforms. The investigation found that Amazon Japan required sellers to maintain price parity, penalized sellers who offered better prices elsewhere by reducing their product visibility and search ranking, and provided preferential treatment (such as subsidized shipping) only to sellers who complied with Amazon's pricing requirements.

**Issue:** Whether Amazon Japan's pressure on sellers to maintain price parity and its discriminatory treatment of non-compliant sellers constitute unfair trade practices under Japan's Antimonopoly Act.

**Holding:** The JFTC issued a recommendation requiring Amazon Japan to cease its price parity demands, stop penalizing sellers based on pricing on competing platforms, and provide transparent criteria for search ranking and fulfillment service eligibility. Amazon Japan accepted the recommendation without admitting liability and implemented compliance measures.
**Significance:** Established the JFTC's authority to regulate platform-imposed pricing constraints in e-commerce marketplaces under Japan's Antimonopoly Act.
Contributed to the global regulatory trend against Most Favored Nation (MFN) and pricing parity clauses in online marketplaces.
Demonstrated that unfair trade practice provisions'ot just abuse of dominance rules'an be effective tools for regulating platform conduct.

---

### Case 9.79: Taobao/Tmall Counterfeit Goods Administrative Penalty (2023) —SAMR

**Date Decided:** 2023 (administrative enforcement action)

**Court:** State Administration for Market Regulation (SAMR), People's Republic of China

**Facts:** China's State Administration for Market Regulation imposed administrative penalties on Alibaba's Taobao and Tmall platforms for systematic failures to prevent the sale of counterfeit goods. SAMR found that despite repeated warnings and prior commitments, the platforms had inadequate systems for detecting and removing counterfeit products, insufficient vetting of sellers, and weak enforcement of intellectual property complaints. Specific categories of concern included luxury goods, electronics, and pharmaceuticals.

**Issue:** Whether Taobao and Tmall's failure to implement adequate anti-counterfeiting measures violated the E-Commerce Law and related regulations requiring platforms to exercise due diligence in monitoring seller conduct and protecting intellectual property rights.

**Holding:** SAMR imposed fines and administrative penalties, ordering Alibaba to: (1) strengthen its seller verification and vetting processes; (2) implement more aggressive counterfeit detection systems, including AI-powered identification; (3) expedite IP complaint processing and takedowns; (4) increase penalties for sellers found listing counterfeit goods; and (5) submit regular compliance reports. The penalties were part of a broader SAMR initiative to clean up e-commerce platform governance.
**Significance:** Reinforced the Chinese government's commitment to enforcing intellectual property protection obligations on e-commerce platforms under the E-Commerce Law.
Demonstrated that administrative enforcement agencies'ot just courts'lay a central role in regulating platform governance in China.
Set expectations for AI-powered content monitoring and proactive platform responsibility in detecting counterfeit goods.

---

### Case 9.80: Pinduoduo "Brushing" (Fake Reviews/Orders) Administrative Penalty (2023) —SAMR

**Date Decided:** 2023 (administrative enforcement action)

**Court:** State Administration for Market Regulation (SAMR), People's Republic of China

**Facts:** The State Administration for Market Regulation investigated Pinduoduo (PDD), one of China's largest e-commerce platforms, for widespread "brushing" practices'he artificial inflation of sales figures and product reviews through fake orders, paid reviews, and bot-generated transactions. SAMR found that brushing was systemic on the platform, facilitated by organized networks of professional brushers and enabled by Pinduoduo's gamified group-buying model that incentivized artificial transaction volume.

**Issue:** Whether Pinduoduo's failure to prevent systematic brushing and fake reviews violated China's Anti-Unfair Competition Law, E-Commerce Law, and Advertising Law.

**Holding:** SAMR imposed administrative fines and ordered Pinduoduo to: (1) implement real-name verification for sellers and reviewers; (2) deploy algorithmic detection systems to identify and eliminate fake orders and reviews; (3) establish a reporting mechanism for consumers to flag suspected brushing; (4) impose meaningful sanctions on sellers engaged in brushing; and (5) cooperate with law enforcement in prosecuting organized brushing networks.
**Significance:** Represented a significant enforcement action against the practice of "brushing," which distorts market competition and consumer decision-making.
Established that platforms bear affirmative responsibility for ensuring the authenticity of transaction data and reviews, beyond merely responding to complaints.
Highlighted the intersection of competition law, consumer protection, and platform governance in China's regulatory framework.

---

### Case 9.81: Brazil CADE v. Google LLC (2022) —Administrative Council for Economic Defense

**Date Decided:** June 2022 (Council decision)

**Court:** Administrative Council for Economic Defense (CADE), Brazil

**Facts:** CADE investigated Google for allegedly abusing its dominant position in the Brazilian digital advertising market by imposing restrictive contractual conditions on advertisers and publishers. The investigation found that Google required websites participating in its AdSense program to sign exclusive or near-exclusive agreements, preventing them from placing competing advertising services on the same pages. Google also allegedly degraded the display of competing ads and used data advantages from its Search, YouTube, and Android services to strengthen its advertising dominance.

**Issue:** Whether Google's AdSense contractual restrictions and data leveraging practices constitute abuse of dominant position under Brazilian competition law.

**Holding:** CADE found Google abused its dominant position in the online search advertising market and imposed a fine of approximately R$130 million (~$25 million). Google was ordered to cease exclusive contractual clauses in its advertising intermediation agreements and to allow publishers to use competing ad services on the same pages. Google was also required to implement transparent and non-discriminatory criteria for its advertising services.
**Significance:** Established CADE's authority to regulate the contractual practices of dominant digital platforms in Brazil's growing digital advertising market.
Aligned Brazilian competition enforcement with similar actions by the EU Commission and India's CCI, contributing to global coordination against Google's advertising practices.
Demonstrated that developing-country competition authorities can effectively regulate global platform conduct affecting their domestic markets.

---

### Case 9.82: Brazil CADE v. Meta Platforms (2023) —Administrative Council for Economic Defense

**Date Decided:** 2023 (investigation and preliminary findings)

**Court:** Administrative Council for Economic Defense (CADE), Brazil

**Facts:** CADE opened an investigation into Meta for potential abuse of dominant position in the Brazilian social media market. The investigation focused on Meta's practice of requiring businesses to use WhatsApp Business API under restrictive terms, leveraging Instagram and WhatsApp user data to strengthen its advertising targeting capabilities, and potentially foreclosing competing social media and messaging platforms. CADE also examined Meta's algorithmic practices for prioritizing content from its own services over third-party content.

**Issue:** Whether Meta's cross-platform data integration practices and restrictive business API terms constitute abuse of dominant position in Brazil's social media and digital advertising markets.

**Holding:** As of 2025, the investigation is ongoing. CADE has conducted extensive evidence gathering from Meta, competitors, and advertisers. Preliminary findings suggest that Meta's integration of WhatsApp, Instagram, and Facebook data creates significant barriers to entry for competing platforms in the Brazilian market. Potential remedies under consideration include data portability requirements and restrictions on cross-platform data sharing for advertising purposes.
**Significance:** Tests the application of Brazilian competition law to the emerging regulatory challenge of data-driven platform dominance across multiple integrated services.
Could establish important precedents for how competition authorities address the "ecosystem" business model in social media.
Demonstrates Brazil's active role in the global movement toward regulating dominant digital platforms.

---

### Case 9.83: EU DSA Dark Pattern Enforcement Actions (2024) —Multiple EU Data Protection Authorities

**Date Decided:** Multiple actions throughout 2024

**Court:** Various EU Data Protection Authorities (DPAs) and the European Data Protection Board (EDPB), coordinated under the Digital Services Act (DSA) enforcement framework

**Facts:** Following the full application of the EU Digital Services Act in February 2024, multiple EU data protection authorities and digital services coordinators initiated enforcement actions against Very Large Online Platforms (VLOPs) and VLO Search Engines for deploying "dark patterns"'anipulative user interface designs that nudge users toward choices that benefit the platform rather than the consumer. Targeted practices included: (1) pre-checked consent boxes that default users to data sharing; (2) confirmshaming language ("No thanks, I prefer less relevant ads") that guilt-trips users into accepting tracking; (3) asymmetrical button placement making privacy-protective choices harder to find; (4) layered privacy notices that bury key information; and (5) cookie walls requiring users to consent to tracking as a condition of accessing services.

**Issue:** Whether dark pattern design practices on VLOPs violate the DSA's transparency obligations and the GDPR's requirement for freely given, specific, informed, and unambiguous consent.

**Holding:** Throughout 2024, several DPAs issued formal warnings and compliance orders requiring platforms to redesign consent interfaces, eliminate confirmshaming language, ensure equal prominence for accept/reject options, and remove cookie walls. The EDPB issued coordinated guidance establishing that cookie walls violate GDPR consent requirements. Non-compliant platforms face fines of up to 6% of global annual turnover under the DSA and up to 4% under the GDPR.
**Significance:** Established the DSA as a powerful tool against dark patterns in the EU, creating a comprehensive enforcement framework that complements GDPR consent requirements.
Defined specific, enforceable standards for what constitutes a dark pattern in digital interface design, providing practical guidance for platform compliance globally.
Demonstrated the effectiveness of coordinated multi-DPA enforcement under the DSA's regulatory architecture.

---

### Case 9.84: California Bot Law Enforcement (2023) —California Attorney General

**Date Decided:** 2023 (enforcement actions)

**Court:** Office of the California Attorney General

**Facts:** The California Attorney General initiated enforcement actions against multiple companies for violations of California's Bot Disclosure Law (California Business and Professions Code § 17940 et seq.), which requires automated accounts ("bots") to disclose their artificial nature when used to influence commercial transactions or political outcomes. The enforcement focused on e-commerce platforms where automated accounts were used to: (1) post fake product reviews without disclosure; (2) inflate product ratings through coordinated bot activity; (3) generate artificial engagement metrics (likes, shares) to manipulate product visibility in marketplace algorithms; and (4) deploy customer service chatbots that failed to identify themselves as automated systems.

**Issue:** Whether the undisclosed use of automated accounts and AI chatbots in e-commerce contexts violates California's Bot Disclosure Law and related consumer protection statutes.

**Holding:** The California AG secured settlements with multiple platforms and marketing companies, requiring disclosure of automated account usage, implementation of bot detection systems, deletion of fake reviews generated by bots, and compliance reporting. Penalties were imposed under the Unfair Competition Law and false advertising statutes in addition to the Bot Disclosure Law.
**Significance:** Represented the first significant enforcement of California's pioneering Bot Disclosure Law in the e-commerce context.
Established that the duty to disclose bot/AI identity extends to customer service chatbots, review systems, and marketplace engagement metrics.
Anticipated broader AI disclosure requirements emerging in EU and other jurisdictions, positioning California as a leader in AI transparency regulation.

---

### Case 9.85: FTC v. Weight Watchers International / Kurbo AI Health App (2023) —FTC

**Date Decided:** January 2023

**Court:** U.S. Federal Trade Commission (Consent Order)

**Facts:** The FTC alleged that Weight Watchers International (now WW) violated the Children's Online Privacy Protection Act (COPPA) and engaged in deceptive marketing through its Kurbo app, a weight-loss application marketed to children as young as 8 years old. The app collected sensitive health information'ncluding weight, height, dietary habits, and body image data'rom children without verifiable parental consent. The FTC also alleged that WW marketed the app using deceptive claims about its effectiveness and safety for children, and that the app's AI-driven dietary recommendations were presented as personalized medical advice without appropriate disclaimers.

**Issue:** Whether WW's collection of children's health data through the Kurbo app violated COPPA, and whether its marketing of AI-driven health recommendations to children was deceptive.

**Holding:** WW agreed to a consent order requiring: (1) deletion of all children's data collected without parental consent; (2) implementation of a robust COPPA compliance program; (3) cessation of marketing Kurbo to children under 13 without verifiable parental consent; (4) clear disclosure that the app's AI recommendations do not constitute medical advice; and (5) a monetary penalty. WW was also required to obtain parental consent before collecting any personal information from users under 13 in any future product.
**Significance:** Extended COPPA enforcement to AI-driven health applications targeting children, establishing that algorithmic health recommendations for minors trigger heightened data protection obligations.
Signaled the FTC's growing scrutiny of AI applications in health and wellness that target vulnerable populations, particularly children.
Established that marketing AI-driven health tools as "personalized" or "tailored" without disclaimers can constitute a deceptive health claim.

---

### Case 9.86: EU Consumer Rights Directive —Digital Content Cases (2023–2024) —CJEU

**Date Decided:** Multiple references throughout 2023–2024

**Court:** Court of Justice of the European Union (CJEU)

**Facts:** Several national courts referred questions to the CJEU regarding the application of the EU Consumer Rights Directive (2011/83/EU) and the Digital Content Directive (2019/770) to modern e-commerce scenarios. Key references addressed: (1) whether subscription-based digital services (streaming, cloud storage) are subject to the right of withdrawal under the Consumer Rights Directive; (2) whether pre-order deposits for digital content are refundable under EU consumer law; (3) how the "principal performance obligation" test applies when consumers pay with personal data rather than money; and (4) whether microtransactions in video games constitute "digital content or services" under the Digital Content Directive, triggering conformity guarantees.

**Issue:** How EU consumer protection directives apply to emerging digital commerce models including data-as-payment, microtransactions, subscription services, and digital pre-orders.

**Holding:** In multiple judgments, the CJEU broadly interpreted consumer protection provisions in favor of consumers: (1) confirming that the right of withdrawal applies to most digital subscriptions, including streaming services, unless the consumer explicitly consented to begin service during the withdrawal period; (2) ruling that pre-order deposits for digital content are generally refundable under the Directive; (3) recognizing that "payment" with personal data triggers the Digital Content Directive's conformity requirements; and (4) holding that in-game microtransactions are "digital content" subject to conformity guarantees.
**Significance:** Established comprehensive EU-level consumer protection standards for modern digital commerce, including the "data-as-payment" model.
Confirmed that in-game purchases and microtransactions fall within the scope of EU consumer protection law, with implications for gaming industry regulation.
Provided authoritative interpretation of the Digital Content Directive that guides national courts across all 27 EU member states.

---

### Case 9.87: China Anti-Unfair Competition Law —Online Platform Cases (2023) —People's Courts

**Date Decided:** Multiple decisions throughout 2023

**Court:** Various People's Courts, People's Republic of China (including Supreme People's Court)

**Facts:** Chinese courts adjudicated several significant cases under the revised Anti-Unfair Competition Law (AUCL) addressing online platform misconduct. Key cases included: (1) a major short-video platform suing a competitor for "data scraping" and unauthorized extraction of user profiles and content metadata; (2) an e-commerce platform suing a competitor for using its proprietary product review data to train recommendation algorithms; (3) a group of merchants suing a platform operator for algorithmically suppressing their listings after they refused to participate in the platform's promotional programs; and (4) a case involving the use of "screen scraping" bots to systematically harvest pricing data from a competing marketplace.

**Issue:** Whether data scraping, algorithmic suppression, and forced participation in promotional programs constitute unfair competition under China's revised Anti-Unfair Competition Law, particularly the new provisions addressing internet-era unfair competition.

**Holding:** Courts generally ruled in favor of platform and data owners, finding that: (1) systematic data scraping without authorization constitutes unfair competition when it undermines the data owner's investment and competitive position; (2) algorithmic suppression of merchants based on non-participation in promotional programs violates the AUCL's anti-coercion provisions; (3) unauthorized use of proprietary data for AI training can constitute unfair competition when it causes competitive harm; and (4) the availability and competitiveness of data as a business asset merits legal protection under the AUCL. The Supreme People's Court affirmed several of these principles in guiding cases.
**Significance:** Established China's courts as significant interpreters of digital economy competition norms, creating a body of case law on data scraping and algorithmic fairness.
Recognized competitive value in proprietary data assets and extended unfair competition protections to cover data extraction and AI training uses.
Contributed to the global legal framework governing data rights and platform competition, providing a distinct Chinese regulatory approach.

---

### Case 9.88: Chinese E-Commerce Law Cases —Consumer Protection (2022–2024) —People's Courts

**Date Decided:** Multiple decisions 2022–2024

**Court:** Various People's Courts, People's Republic of China (including Supreme People's Court guiding cases)

**Facts:** Chinese courts handled a significant volume of cases interpreting the 2019 E-Commerce Law's consumer protection provisions. Representative cases included: (1) consumers suing platforms for selling products from unregistered merchants without performing required identity verification; (2) disputes over "live-streaming e-commerce" where influencers promoted products that proved defective, raising questions about platform vs. streamer liability; (3) cases involving platform liability for failure to promptly remove counterfeit products after receiving notice from rights holders; (4) consumer class actions challenging auto-renewal subscription practices that lacked clear disclosure; and (5) disputes over algorithmic pricing discrimination (the Chinese equivalent of "price discrimination" based on user profiling).

**Issue:** How the E-Commerce Law's provisions on platform liability, merchant verification, consumer rights, and algorithmic transparency apply to emerging e-commerce models including live-streaming commerce, subscription services, and algorithmic pricing.

**Holding:** Courts developed important interpretations: (1) platforms bear strict liability for failing to verify merchant identities and must compensate consumers for losses caused by unverified sellers; (2) in live-streaming e-commerce, both the streaming platform and the individual streamer can bear liability depending on the degree of involvement and control over the product; (3) platforms must implement effective notice-and-takedown mechanisms and face escalating liability for repeated failures; (4) auto-renewal practices require explicit consumer consent with clear disclosure of terms, price, and cancellation procedures; and (5) algorithmic price discrimination violates the E-Commerce Law when it results in materially different prices for identical products based on consumer profiling without transparent justification.
**Significance:** Developed China's judicial framework for regulating the rapidly evolving e-commerce landscape, including live-streaming commerce' model with limited regulatory precedent globally.
Established that platforms bear direct liability for inadequate merchant verification, going beyond safe harbor principles in some Western jurisdictions.
Created enforceable standards against algorithmic price discrimination, positioning China among the first jurisdictions to judicially address "big data exploitation" (  ? in e-commerce.
End of Part Nine Additions (Cases 9.63—.97).

---

### Case 9.89: Temu EU Digital Services Act Scrutiny (2024) —European Commission

**Date Decided:** 2024

**Court:** European Commission (regulatory enforcement under the Digital Services Act)

**Facts:** In 2024, the European Commission launched formal proceedings against Temu, the Chinese-owned cross-border e-commerce platform operating in the EU, under the Digital Services Act (DSA). The Commission identified concerns regarding Temu's compliance with obligations for very large online platforms (VLOPs), including inadequate risk assessment for illegal content and counterfeit goods, insufficient trader transparency, inadequate mechanisms for consumer reporting, and potentially manipulative design practices ("dark patterns") that influenced purchasing decisions.

**Issue:** Whether Temu fulfilled its obligations as a VLOP under the DSA, particularly regarding risk assessments, transparency requirements, and the prevention of illegal products and deceptive design practices on its platform.

**Holding:** The European Commission issued a formal request for information and initiated preliminary proceedings. Temu was required to provide detailed documentation on its compliance mechanisms, algorithmic recommendation systems, and trader verification processes. The proceedings remained ongoing as of late 2024, with potential fines of up to 6% of global turnover for non-compliance.
**Significance:** First DSA enforcement action against a Chinese cross-border e-commerce platform, testing the EU's regulatory reach over non-EU headquartered digital platforms serving European consumers.
Established important precedents for applying DSA obligations to marketplace models where platform operators do not directly sell products but facilitate third-party transactions.
Illustrated the expanding scope of EU digital regulation to address consumer protection, product safety, and counterfeiting alongside traditional content moderation concerns.

---

### Case 9.90: SHEIN IPO Data Practices Review (2024) —U.S. Securities and Exchange Commission / UK Listing Authority

**Date Decided:** 2024

**Court:** U.S. Securities and Exchange Commission (SEC disclosure review); UK Financial Conduct Authority (FCA) (listing review)

**Facts:** SHEIN, the global fast-fashion e-commerce giant, pursued initial public offerings on both the London Stock Exchange and U.S. exchanges in 2024. Regulatory scrutiny focused on SHEIN's data collection and processing practices, supply chain labor conditions, and intellectual property practices. U.S. lawmakers raised concerns about SHEIN's handling of consumer data, including alleged collection practices that exceeded what was disclosed in prospectus filings. The company's data governance practices became a central issue in the regulatory review process.

**Issue:** Whether SHEIN adequately disclosed its data collection, processing, and cross-border transfer practices in its IPO prospectus materials and whether its data practices complied with applicable securities disclosure requirements and data protection laws in listing jurisdictions.

**Holding:** SHEIN's IPO faced extended regulatory review timelines. The SEC and FCA raised additional questions about data governance, cybersecurity risk disclosure, and cross-border data transfer compliance. SHEIN withdrew its U.S. IPO plans and pursued the London listing, where data practices remained under scrutiny. The company committed to enhanced data governance frameworks and independent audits as conditions for proceeding.
**Significance:** Demonstrated that data governance and privacy compliance have become material considerations in securities regulation for technology companies seeking public listings.
Established that cross-border data practices are now a routine focus of IPO regulatory review, particularly for companies operating across jurisdictions with divergent data protection regimes.
Highlighted the intersection of ESG (Environmental, Social, and Governance) concerns with data protection in investment and capital markets regulation.

---

### Case 9.91: India MeitY Online Gaming Rules (2023) —Ministry of Electronics and Information Technology, India

**Date Decided:** 2023

**Court:** Ministry of Electronics and Information Technology (MeitY), Government of India (administrative rulemaking)

**Facts:** In 2023, India's MeitY issued the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules addressing online gaming. The rules established a self-regulatory framework requiring online gaming platforms to register with the government, implement know-your-customer (KYC) verification, comply with age-appropriate design codes, and establish grievance redressal mechanisms. The rules also established a three-tier grievance redressal structure and imposed penalties for non-compliance.

**Issue:** Whether the gaming rules exceeded MeitY's statutory authority under the Information Technology Act, whether they imposed disproportionate compliance burdens on gaming companies, and whether they adequately addressed concerns about gaming addiction, predatory monetization, and data protection.

**Holding:** The rules were notified and came into effect, requiring registration of online gaming intermediaries. Multiple industry stakeholders challenged the rules before the courts, arguing regulatory overreach. The government defended the rules as necessary to protect consumers, particularly minors, from addictive gaming practices and financial exploitation through in-game purchases and real-money gaming.
**Significance:** Established India as one of the first jurisdictions to implement comprehensive regulation specifically targeting online gaming platforms, including data protection and consumer protection requirements.
Created a regulatory model for the gaming industry that combines self-regulatory bodies with government oversight, potentially influencing regulatory approaches in other Asian jurisdictions.
Raised significant questions about the scope of intermediary regulation under the IT Act and the appropriate balance between innovation promotion and consumer protection in the digital gaming sector.

---

### Case 9.92: Singapore PDPA AI Governance Guidelines (2024) —Personal Data Protection Commission, Singapore

**Date Decided:** 2024

**Court:** Personal Data Protection Commission (PDPC), Singapore (regulatory guidance)

**Facts:** In 2024, Singapore's PDPC updated its Advisory Guidelines on the Use of Personal Data in AI Systems under the Personal Data Protection Act (PDPA). The guidelines addressed the intersection of AI development, deployment, and personal data protection, providing detailed guidance on consent requirements, legitimate interest assessments, data minimization, and algorithmic accountability for organizations deploying AI systems that process personal data. The guidelines complemented Singapore's Model AI Governance Framework.

**Issue:** How existing PDPA consent and lawful basis requirements apply to AI systems that process personal data for training, inference, and decision-making, and what governance mechanisms organizations must implement for responsible AI deployment.

**Holding:** The PDPC issued comprehensive advisory guidelines that clarified the application of PDPA provisions to AI systems while maintaining a principles-based, technology-neutral approach. The guidelines introduced specific recommendations for AI impact assessments, human oversight mechanisms, and transparency requirements for AI-assisted decisions affecting individuals.
**Significance:** Positioned Singapore as a leading jurisdiction for practical AI governance guidance that bridges data protection regulation with responsible AI development frameworks.
Provided a model for regulators seeking to adapt existing data protection frameworks to AI contexts without enacting entirely new legislation.
Demonstrated Singapore's "regulatory sandbox" approach, offering flexibility for innovation while maintaining consumer protection standards through guidance rather than prescriptive rules.

---

### Case 9.93: China Live-Streaming E-Commerce Compliance (2023-2024) —State Administration for Market Regulation / Multiple Regulatory Authorities

**Date Decided:** 2023-2024

**Court:** State Administration for Market Regulation (SAMR); Ministry of Commerce; Cyberspace Administration of China (CAC) (regulatory enforcement and rulemaking)

**Facts:** China's live-streaming e-commerce sector, valued at hundreds of billions of dollars, faced intensified regulatory scrutiny in 2023-2024. SAMR and other authorities issued new regulations requiring live-streaming hosts and platforms to comply with advertising law, consumer protection standards, and food safety requirements. Major influencers (key opinion leaders or KOLs) were penalized for false advertising, selling counterfeit goods, and tax evasion. The regulations required platforms to establish content review mechanisms, maintain transaction records, and ensure product quality compliance.

**Issue:** Whether live-streaming e-commerce platforms and hosts fulfilled their obligations under China's E-Commerce Law, Advertising Law, and Consumer Rights Protection Law, and what new regulatory requirements were necessary to address the unique characteristics of live-commerce.

**Holding:** SAMR and provincial market regulators issued significant fines against non-compliant platforms and individual live-streaming hosts. Several high-profile KOLs were banned from live-streaming for specified periods. The regulations established clear responsibilities for platforms (content moderation, merchant vetting, transaction record-keeping) and individual hosts (product knowledge obligations, advertising compliance, tax obligations).
**Significance:** Represented the world's most comprehensive regulatory framework specifically addressing live-streaming e-commerce, a business model that has grown exponentially across Asia.
Established dual liability frameworks holding both platforms and individual content creators accountable, creating a model that other jurisdictions are beginning to study.
Demonstrated China's approach to regulating digital commerce innovation through targeted sector-specific rules rather than general platform regulation, balancing market development with consumer protection.
---

# Part 10 — Government Surveillance & National Security
## Chapter 10: Digital Rights and State Power
The tension between government surveillance imperatives and individual digital rights constitutes one of the defining legal conflicts of the twenty-first century. The cases in this Part traverse multiple jurisdictions and legal traditions — from the European Convention on Human Rights to EU fundamental rights jurisprudence, from Russian authoritarian platform regulation to Chinese data sovereignty enforcement, and from the United States Supreme Court's confrontation with national security and free expression. Taken together, these decisions illuminate the global struggle to define the permissible boundaries of state power in the digital age.


### Case 10.1: Big Brother Watch and Others v. the United Kingdom — European Court of Human Rights

**Date Decided:** 25 May 2021 (Grand Chamber)

**Court:** European Court of Human Rights (Grand Chamber), Applications nos. 58170/13, 62322/14 and 24960/15

**Facts:** The case arose from three sets of applications brought by various NGOs, journalists, and individuals — including Big Brother Watch, Bureau of Investigative Journalism, Amnesty International, and Privacy International — challenging the United Kingdom's bulk interception regime, intelligence-sharing arrangements, and the regime governing obtaining communications data from communications service providers. The applicants alleged that UK intelligence agencies (GCHQ, MI5, and MI6) engaged in bulk interception of external communications — that is, communications where at least one party was located outside the British Islands — pursuant to the Regulation of Investigatory Powers Act 2000 (RIPA). The regime was later reformed by the Investigatory Powers Act 2016 (the "Snooper's Charter"), but the case was argued on the basis of the legal framework as it stood before the 2016 Act came fully into force.
The bulk interception regime authorized GCHQ to intercept, in bulk, communications traversing transatlantic fibre-optic cables that pass through or terminate in the United Kingdom. The intercepted material included emails, instant messages, social media communications, web browsing records, and other electronic communications. The regime operated under warrants issued by the Secretary of State, subject to judicial oversight by the Investigatory Powers Tribunal (IPT). The applicants argued that the regime was insufficiently circumscribed by law, that it lacked adequate safeguards against arbitrary interference, and that it violated rights to privacy and freedom of expression protected by Articles 8 and 10 of the European Convention on Human Rights (ECHR).
A significant dimension of the case related to intelligence-sharing between the UK and the United States, following disclosures by Edward Snowden in 2013 regarding the TEMPORA, PRISM, and UPSTREAM programmes. The applicants contended that the UK regime failed to provide adequate protections against the receipt and use of intelligence obtained through foreign interception programmes that did not meet ECHR standards.
Article 8 ECHR (right to respect for private and family life, home, and correspondence) in respect of both the bulk interception regime and the regime for obtaining communications data.
Article 10 ECHR (freedom of expression) in respect of journalistic sources and the chilling effect of bulk surveillance.
Article 6 1 ECHR (right to a fair trial) in respect of the procedures of the Investigatory Powers Tribunal, which the applicants argued did not provide an effective remedy because it did not disclose sufficient information to complainants about the surveillance to which they had been subjected.
Article 8 — Bulk interception regime: The bulk interception regime was in principle compliant with Article 8, finding that bulk interception of external communications pursued the legitimate aim of national security and that the legal framework provided sufficient safeguards against abuse, including limitations on the selection and examination of intercepted material, the requirement of judicial authorization, and independent oversight by the Interception of Communications Commissioner. However, the Court found violations in three respects: (a) the regime for selecting "bearers" (internet links) for interception lacked sufficient independent authorization and supervision; (b) the regime failed to provide sufficient safeguards in respect of the search criteria used to filter intercepted communications; and (c) the regime for retaining and examining "related communications data" was insufficiently constrained.
Article 8 — Communications data: The regime for obtaining communications data from service providers (under RIPA Chapter II) violated Article 8, because it did not require prior independent authorization — the Secretary of State alone could authorize the acquisition of communications data, without the need for judicial approval.
Article 10: The Court found a violation of Article 10 in respect of the bulk interception regime, holding that the safeguards applicable to journalistic material were inadequate, particularly the failure to provide prior notification to journalists whose communications were likely to be intercepted and the insufficiency of protections for journalistic sources.
Article 6 1: The Court held that the Investigatory Powers Tribunal did not constitute an effective remedy for purposes of Article 13 (right to an effective remedy) as applied in conjunction with Article 8, because the IPT could not provide sufficient transparency to complainants about whether and how they had been subjected to surveillance.

**Issue:** The applicants alleged violations of: Article 8 ECHR (right to respect for private and family life, home, and correspondence) in respect of both the bulk interception regime and the regime for obtaining communications data. Article 10 ECHR (freedom of expression) in respect of journalistic sources and the chilling effect of bulk surveillance. Article 6 1 ECHR (right to a fair trial) in respect of the procedures of the Investigatory Powers Tribunal, which the applicants argued did not provide an effective remedy because it did not disclose sufficient information to complainants about the surveillance to which they had been subjected.
**Holding:** The Grand Chamber held, by a majority: Article 8 — Bulk interception regime: The bulk interception regime was in principle compliant with Article 8, finding that bulk interception of external communications pursued the legitimate aim of national security and that the legal framework provided sufficient safeguards against abuse, including limitations on the selection and examination of intercepted material, the requirement of judicial authorization, and independent oversight by the Interception of Communications Commissioner. However, the Court found violations in three respects: (a) the regime for selecting "bearers" (internet links) for interception lacked sufficient independent authorization and supervision; (b) the regime failed to provide sufficient safeguards in respect of the search criteria used to filter intercepted communications; and (c) the regime for retaining and examining "related communications data" was insufficiently constrained. Article 8 — Communications data: The regime for obtaining communications data from service providers (under RIPA Chapter II) violated Article 8, because it did not require prior independent authorization — the Secretary of State alone could authorize the acquisition of communications data, without the need for judicial approval. Article 10: The Court found a violation of Article 10 in respect of the bulk interception regime, holding that the safeguards applicable to journalistic material were inadequate, particularly the failure to provide prior notification to journalists whose communications were likely to be intercepted and the insufficiency of protections for journalistic sources. Article 6 1: The Court held that the Investigatory Powers Tribunal did not constitute an effective remedy for purposes of Article 13 (right to an effective remedy) as applied in conjunction with Article 8, because the IPT could not provide sufficient transparency to complainants about whether and how they had been subjected to surveillance.
**Significance:** Constitutionalization of bulk surveillance standards. The Grand Chamber's decision represents the most comprehensive judicial examination of bulk interception by any international or domestic court. While accepting that bulk interception is not per se incompatible with the Convention, the Court established a detailed framework of minimum safeguards that must accompany any such programme — including limits on selection criteria, independent authorization of technical capability, protections for journalistic communications, and adequate oversight mechanisms. This framework has become the benchmark against which surveillance programmes in other Council of Europe member states are measured.
Intelligence-sharing under the ECHR. The decision established that member states bear ECHR responsibility for intelligence received from foreign agencies where the state "does not remain passive" but seeks and makes use of such intelligence. This principle has significant implications for the "Five Eyes" alliance and other intelligence-sharing arrangements, requiring member states to apply Convention standards to intelligence obtained through cooperative relationships, even where the originating state is not itself bound by the ECHR.
Journalistic sources and the chilling effect. The Article 10 holding reinforced the heightened protection owed to journalistic communications, requiring not merely general safeguards but specific protections — including prior notification where feasible — to prevent the chilling effect of surveillance on press freedom. This aspect of the ruling has been cited extensively in subsequent cases involving surveillance of journalists in Hungary, Poland, and Turkey, and has informed the European Commission's proposals for EU-wide media freedom legislation.
The limits of secret tribunals. The Article 6/13 holding highlighted the structural inadequacy of secret tribunals as mechanisms for individual justice, even where — as with the IPT — they possess significant investigative powers. The Court did not go so far as to require full disclosure of classified information to individual complainants, but it required that individuals receive "sufficient information about the surveillance measures applied to them" to be able to exercise their Convention rights effectively. This holding has prompted reforms to oversight mechanisms in several jurisdictions.

---

### Case 10.2: Digital Rights Ireland Ltd v. Minister for Communications, Marine and Natural Resources — Court of Justice of the European Union

**Date Decided:** 8 April 2014

**Court:** Court of Justice of the European Union (Grand Chamber), Joined Cases C-293/12 and C-594/12

**Facts:** The reference to the CJEU arose from two sets of proceedings. Digital Rights Ireland Ltd, an Irish digital rights organization, brought proceedings before the High Court of Ireland challenging the legality of the Irish statutory transposition of Directive 2006/24/EC (the Data Retention Directive). Separately, Karsten Albrecht and others brought proceedings before the Verfassungsgerichtshof (Austrian Constitutional Court) challenging the Austrian transposition measures.
The Data Retention Directive, adopted by the European Parliament and Council on 15 March 2006, required member states to ensure that providers of publicly available electronic communications services or of public communications networks retained certain categories of data (traffic data and location data, but not the content of communications) for a period of between six months and two years. The retained data included: data necessary to identify the subscriber or registered user; data on the source, destination, date, time, and duration of communications; data identifying the communication network, cell, and location of terminal equipment; and data identifying the Internet protocol address assigned to the communication.
The stated purpose of the Directive was to ensure that the data were available for the purpose of the investigation, detection, and prosecution of serious crime. The Directive was adopted in the aftermath of the 2004 Madrid and 2005 London terrorist attacks, at the urging of the United Kingdom and other member states that argued that existing data retention regimes were insufficient to combat terrorism and organized crime.
Article 7 of the Charter of Fundamental Rights of the European Union (right to respect for private and family life, home, and communications).
Article 8 of the Charter (protection of personal data).
Article 11 of the Charter (freedom of expression and information, including the freedom and pluralism of the media).
Article 7 — Privacy: The Directive entailed a wide-ranging and particularly serious interference with Article 7, as it required the retention of all traffic and location data of all subscribers and registered users relating to all means of electronic communication, without any differentiation, limitation, or exception being made with regard to the objective of fighting crime. The interference was applicable to all persons, regardless of whether there was any evidence that they were even remotely connected with serious crime. The data retained were capable of providing very precise information on the private lives of the persons concerned, including their social relationships, habits, and daily activities.
Article 8 — Data protection: The Directive did not lay down clear and precise rules governing the extent of the interference, as it failed to define the types of data to be retained with sufficient specificity. It also failed to establish substantive and procedural conditions under which the competent national authorities were to be granted access to the data and to be permitted to use them. The Directive did not specify any objective criterion by which the number of persons authorized to access and use the data was to be determined, nor did it require that the data be retained within the European Union.
Article 11 — Freedom of expression: The retention of data relating to electronic communications was likely to generate in the minds of the persons concerned the feeling that their private lives were being the subject of constant surveillance, thereby having a chilling effect on the exercise of freedom of expression. This was particularly significant for journalists and lawyers, whose communications with sources and clients required protection.
Proportionality: While the objective of fighting serious crime was in principle capable of justifying the Directive, the measures prescribed were not limited to what was strictly necessary. The Directive required general and indiscriminate retention of all traffic and location data, without requiring any connection between the data retained and a threat to public security. It did not require — as a precondition for retention — that the data relate to a particular time period and/or geographical area and/or a circle of persons likely to be involved in a serious crime.

**Issue:** The referring courts asked the CJEU to rule on the validity of the Data Retention Directive, specifically whether it was compatible with: Article 7 of the Charter of Fundamental Rights of the European Union (right to respect for private and family life, home, and communications). Article 8 of the Charter (protection of personal data). Article 11 of the Charter (freedom of expression and information, including the freedom and pluralism of the media).
**Holding:** The Grand Chamber declared the Data Retention Directive invalid in its entirety. The Court held: Article 7 — Privacy: The Directive entailed a wide-ranging and particularly serious interference with Article 7, as it required the retention of all traffic and location data of all subscribers and registered users relating to all means of electronic communication, without any differentiation, limitation, or exception being made with regard to the objective of fighting crime. The interference was applicable to all persons, regardless of whether there was any evidence that they were even remotely connected with serious crime. The data retained were capable of providing very precise information on the private lives of the persons concerned, including their social relationships, habits, and daily activities. Article 8 — Data protection: The Directive did not lay down clear and precise rules governing the extent of the interference, as it failed to define the types of data to be retained with sufficient specificity. It also failed to establish substantive and procedural conditions under which the competent national authorities were to be granted access to the data and to be permitted to use them. The Directive did not specify any objective criterion by which the number of persons authorized to access and use the data was to be determined, nor did it require that the data be retained within the European Union. Article 11 — Freedom of expression: The retention of data relating to electronic communications was likely to generate in the minds of the persons concerned the feeling that their private lives were being the subject of constant surveillance, thereby having a chilling effect on the exercise of freedom of expression. This was particularly significant for journalists and lawyers, whose communications with sources and clients required protection. Proportionality: While the objective of fighting serious crime was in principle capable of justifying the Directive, the measures prescribed were not limited to what was strictly necessary. The Directive required general and indiscriminate retention of all traffic and location data, without requiring any connection between the data retained and a threat to public security. It did not require — as a precondition for retention — that the data relate to a particular time period and/or geographical area and/or a circle of persons likely to be involved in a serious crime.
**Significance:** The most consequential invalidation in EU legal history. The Digital Rights Ireland decision is widely regarded as the single most important ruling in EU privacy and data protection law. By invalidating a directive adopted by the European Parliament and Council with the support of a majority of member states, the Court demonstrated the power of the Charter of Fundamental Rights to serve as a constraint on EU legislative action in the security domain. The ruling effectively ended indiscriminate mandatory data retention across the EU, prompting member states to revise their domestic regimes — most of which were subsequently found to violate EU law in subsequent rulings.
Proportionality as the master principle. The decision established that even where the EU legislature pursues a legitimate objective — such as combating serious crime — measures that entail comprehensive, general, and indiscriminate interference with fundamental rights must be subject to the most rigorous proportionality analysis. The Court's insistence on differentiation, limitation, and exception as structural requirements of any data retention scheme has shaped all subsequent EU surveillance jurisprudence, including the landmark judgments in Tele2 Sverige (C-203/15, 2016), La Quadrature du Net (Joined Cases C-511/18, C-512/18 and C-520/18, 2020), and the Schrems II ruling on transatlantic data transfers.
Chilling effect doctrine. The Court's explicit recognition that mass data retention generates a "feeling of constant surveillance" with a chilling effect on freedom of expression — particularly for journalists, lawyers, and others whose professional activities require confidential communications — has become a foundational principle of EU digital rights law. This doctrine has been extensively cited in cases involving content moderation, algorithmic profiling, and AI surveillance, establishing the chilling effect as a freestanding basis for striking down disproportionate digital surveillance measures.
Catalyst for domestic litigation and legislative reform. The invalidation of the Directive triggered a wave of domestic constitutional challenges to national data retention laws across Europe. The German Federal Constitutional Court (Bundesverfassungsgericht) cited Digital Rights Ireland extensively in its 2010 and 2020 decisions on data retention, while courts in France, Belgium, Sweden, Romania, and Bulgaria struck down or narrowed their national regimes. The decision also catalysed the reform process that led to the adoption of the General Data Protection Regulation (GDPR) in 2016, which explicitly incorporated the proportionality and necessity principles articulated by the Court.

---

### Case 10.3: Russian Telegram Ban Case — Roskomnadzor v. Telegram Messenger LLP / Supreme Court of the Russian Federation

**Date Decided:** 20 March 2018 (Supreme Court of Russia); Ban enforced April 2018; Ban effectively lifted June 2020

**Court:** Supreme Court of the Russian Federation (No. AKPI18-18)

**Facts:** In July 2017, the Federal Security Service (FSB) issued an order to Telegram Messenger LLP, the company operating the eponymous encrypted messaging application, requiring it to provide the FSB with encryption keys and technical information necessary to decrypt user communications. The order was issued pursuant to Federal Law No. 242-FZ "On Amending Certain Legislative Acts of the Russian Federation Regarding the Clarification of the Procedure for the Exchange of Information Using Electronic Messages" (known as the "Yarovaya Law" or "Package of Anti-Terrorism Amendments"), adopted in July 2016, which required communications service providers operating in Russia to store user communications for up to six months and to provide the FSB with decryption keys upon request.
Telegram, founded by Pavel Durov, refused to comply with the FSB's order on the ground that the end-to-end encryption used by the application made it technically impossible for Telegram to provide decryption keys. Telegram's encryption architecture — which used the MTProto protocol — does not give Telegram access to the content of secret chats between users; the encryption keys are stored only on the devices of the communicating parties. Telegram offered to provide metadata and other non-content information but declined to provide the encryption keys themselves.
The FSB applied to the Tagansky District Court of Moscow for an order compelling Telegram to comply. The District Court granted the FSB's application on 20 March 2018, and Telegram appealed to the Supreme Court. The Supreme Court upheld the lower court's decision on the same day, concluding that the FSB's order was lawful and that Telegram's refusal to comply was unjustified.
Following the Supreme Court's ruling, Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology, and Mass Media) moved to block access to Telegram in Russia. Beginning in April 2018, Roskomnadzor ordered Russian internet service providers to block access to Telegram's servers, using IP addresses and domain names. The blocking effort was technically complex because Telegram used a distributed infrastructure and rapidly switched IP addresses to evade blocking. Roskomnadzor responded by blocking millions of IP addresses associated with Amazon Web Services, Google Cloud Platform, and other cloud hosting providers, causing significant collateral damage to unrelated websites and online services across Russia.
Despite the blocking measures, Telegram remained accessible to most Russian users through the use of VPNs, proxy servers, and Telegram's own built-in circumvention technologies (including domain fronting and the MTProto proxy). The blocking effort proved increasingly ineffective over time, and the collateral damage to the broader Russian internet ecosystem was widely criticized by technology companies, civil society organizations, and even some government officials.
In June 2020, Roskomnadzor announced that it would unblock Telegram, following a meeting between Pavel Durov and the head of Roskomnadzor, Alexander Zharov. No formal explanation was provided, but the decision was widely attributed to the demonstrated futility of the ban and the platform's growing importance for Russian government agencies, businesses, and educational institutions — particularly during the COVID-19 pandemic. The official rationale cited Telegram's willingness to cooperate with Russian authorities on certain matters, including the removal of extremist content.

**Issue:** Whether Telegram was obligated to provide the FSB with encryption keys and decryption capabilities under Russian federal law, and whether the blocking of Telegram's service by Roskomnadzor was lawful.
**Holding:** The Supreme Court upheld the FSB's order, finding that Telegram was required to provide the encryption keys under the Yarovaya Law. The blocking measures were implemented but proved largely ineffective. After approximately two years, the ban was quietly lifted without any formal judicial or legislative reversal.
**Significance:** The futility of blocking encrypted services. The Telegram case became the most prominent demonstration in any major jurisdiction of the practical difficulty of enforcing service bans against technically sophisticated platforms. The failure of Roskomnadzor's blocking measures — which consumed enormous technical resources while proving ineffective — provided powerful evidence that government mandates requiring access to encryption keys face fundamental technical and practical barriers. This experience has been cited in legislative debates worldwide, including in the United States (during hearings on the EARN IT Act and the Lawful Access to Encrypted Data Act) and in Australia (following the Assistance and Access Act 2018), as demonstrating that government-mandated backdoors to encryption may be technically infeasible.
Collateral damage to the open internet. The blocking of millions of IP addresses associated with cloud hosting providers caused extensive collateral damage to websites and online services entirely unrelated to Telegram. This collateral damage highlighted the inherent risks of broad-based internet blocking regimes, which tend to be both over-inclusive and under-inclusive — blocking legitimate services while failing to achieve their stated objectives. The collateral damage contributed to growing criticism of internet censorship practices in Russia and informed subsequent policy debates in other jurisdictions about the proportionality of platform blocking measures.
Platform resistance as a legal and political strategy. Telegram's refusal to comply with the FSB's order — and its success in maintaining service availability despite the ban — represented a significant instance of platform resistance to government surveillance demands. While the strategy involved significant legal and commercial risk (including the loss of advertising revenue from Russian users and the risk of enforcement action against its operations), it ultimately proved successful in both practical and reputational terms. The case has been cited as evidence that platforms can resist government surveillance demands when supported by robust encryption architecture and a committed user base.
Authoritarian legalism and its limits. The case illustrated a broader phenomenon in authoritarian and semi-authoritarian states: the enactment of formally lawful surveillance mandates that exceed the technical capacity of the state to enforce. The Yarovaya Law's requirements — which were adopted with minimal technical input and without regard for the architectural design of modern encrypted communications — placed Russian companies and international platforms alike in an impossible position: comply with requirements that were technically unfeasible, or face legal sanctions. This tension between formal legal authority and technical reality has become a defining feature of digital governance in authoritarian states.

---

### Case 10.4: China — Data Localization Enforcement Under the Data Security Law and Personal Information Protection Law
**Court:** Cyberspace Administration of China (CAC)

**Facts:** China's data localization regime represents the most comprehensive system of mandatory data residency requirements in the world. The regime rests on three pillars of legislation enacted in rapid succession between 2017 and 2021:
Cybersecurity Law (CSL), effective 1 June 2017, required "critical information infrastructure operators" (CIIOs) to store within the territory of China "personal information and important data" collected and generated in the course of their operations in China. Where it was necessary to transfer such data outside China, a security assessment was required.
Data Security Law (DSL), effective 1 September 2021, expanded the scope of data localization requirements. It introduced a system of data classification based on the degree of importance of the data to national security, economic development, and public interest. Data classified at higher levels of importance was subject to more stringent localization and cross-border transfer requirements. The DSL also imposed obligations on all "data handlers" () to establish data security management systems, conduct risk assessments, and report data security incidents.
Personal Information Protection Law (PIPL), effective 1 November 2021, established China's comprehensive data protection framework, broadly modelled on the EU GDPR but with significant differences. The PIPL imposed strict requirements on the processing of personal information, including consent requirements, data minimization, purpose limitation, and restrictions on automated decision-making. Critically, the PIPL required that personal information of "a huge number of individuals" — a threshold interpreted by subsequent implementing regulations as referring to personal information of one million or more individuals — be stored within China. Cross-border transfers of personal information were subject to one of three mechanisms: a government security assessment (for the most sensitive transfers), standard contractual clauses (SCCs) certified by the CAC, or personal information protection certification by a designated body.
The enforcement of this regulatory framework has involved a series of significant administrative actions:
Didi Global (July 2021): Two days after Didi Global's IPO on the New York Stock Exchange, the CAC announced an investigation into the ride-hailing company for violations of data security and personal information protection laws. The CAC found that Didi had collected personal information in violation of the principles of necessity and consent, had failed to adequately protect users' personal information, and had engaged in cross-border data transfers without the required security assessment. The CAC ordered Didi's app to be removed from Chinese app stores, imposed a fine of RMB 8.026 billion (approximately USD 1.2 billion), and required the company to rectify its data practices. Didi subsequently delisted from the New York Stock Exchange and undertook a comprehensive data compliance programme.
Carbanak/FIN7-related enforcement actions (2022): Chinese authorities used the DSL's reporting requirements to investigate data exfiltration incidents and to coordinate with international law enforcement on cybercrime matters.
Provisional Measures on Standard Contractual Clauses (February 2023): The CAC issued detailed implementing regulations governing the use of SCCs for cross-border data transfers, providing a practical mechanism for international companies to transfer personal information outside China while maintaining compliance with the PIPL.
CAC security assessment rules (June 2022): The CAC issued Measures for Security Assessment of Data Exports, requiring data handlers to undergo a government security assessment before transferring important data or the personal information of more than one million individuals outside China. The assessment considers the legality, necessity, and proportionality of the transfer, the data protection measures in place in the destination jurisdiction, and the risks to national security and public interest.

**Issue:** The regulatory framework raises several fundamental legal issues: the scope and proportionality of data localization mandates; the compatibility of China's data governance framework with international data transfer mechanisms and trade obligations; the balance between national security and the free flow of data; and the extraterritorial reach of Chinese data protection law, which applies to the processing of personal information of natural persons within China, regardless of the location of the data handler. Outcome: The data localization regime has been progressively implemented and enforced, with the Didi case serving as the most prominent enforcement action. International companies operating in China — including Apple, Tesla, and major financial institutions — have established local data storage infrastructure and, in many cases, established separate data governance structures for Chinese operations to comply with the localization requirements. Apple notably announced the construction of a data centre in Guizhou province to store iCloud data belonging to Chinese users, with the data managed by a Chinese state-owned enterprise (Guizhou on the Cloud Big Data, or GCBD) — an arrangement that has raised concerns about government access to encrypted user data.
**Holding:** The data localization regime has been progressively implemented and enforced, with the Didi case serving as the most prominent enforcement action. International companies operating in China — including Apple, Tesla, and major financial institutions — have established local data storage infrastructure and, in many cases, established separate data governance structures for Chinese operations to comply with the localization requirements. Apple notably announced the construction of a data centre in Guizhou province to store iCloud data belonging to Chinese users, with the data managed by a Chinese state-owned enterprise (Guizhou on the Cloud Big Data, or GCBD) — an arrangement that has raised concerns about government access to encrypted user data.
**Significance:** Data sovereignty as regulatory paradigm. China's data localization regime represents the most fully realized instantiation of "data sovereignty" as a regulatory paradigm — the principle that a state has the right to regulate the collection, processing, storage, and transfer of data generated within its territory. This paradigm stands in tension with the EU's approach (which emphasizes the protection of individual rights rather than state control) and the US approach (which favours the free flow of data across borders). China's framework has been influential in shaping data governance proposals in other jurisdictions, including India's Personal Data Protection Bill (which contains similar data localization requirements), Indonesia's GR 71/2019, Russia's Federal Law No. 242-FZ, and Vietnam's Decree 13/2023.
Economic fragmentation of the internet. The data localization requirements have contributed to the progressive fragmentation of the global internet into distinct data governance zones, each governed by different rules for cross-border data transfers. This fragmentation imposes significant compliance costs on multinational companies, which must maintain separate data storage and governance infrastructures for each jurisdiction, and risks undermining the interoperability of global digital services. The World Trade Organization has identified data localization measures as a significant barrier to digital trade, and several WTO members have challenged specific data localization requirements as violations of trade commitments.
National security as the dominant justification. China's data governance framework explicitly subordinates individual privacy rights to national security imperatives. The DSL's classification system categorizes data based on its importance to national security, and the PIPL permits the processing of personal information without consent where it is "necessary for the performance of duties and responsibilities by state organs." This hierarchy of values — in which national security trumps individual privacy — contrasts sharply with the EU's approach under the GDPR and the Charter of Fundamental Rights, and reflects a fundamentally different conception of the relationship between the state, the individual, and data.
The Didi precedent and chilling effect on foreign listings. The Didi enforcement action sent a powerful signal to Chinese technology companies regarding the risks of listing on foreign exchanges and the consequences of inadequate data compliance. The timing of the enforcement action — two days after Didi's IPO — was widely interpreted as a deliberate demonstration of regulatory authority, and contributed to a broader regulatory crackdown on China's technology sector that included restrictions on overseas listings for companies holding significant volumes of user data, new rules governing variable interest entities (VIEs), and increased scrutiny of cross-border data transfers by technology companies.

---

### Case 10.5: TikTok Inc. v. Garland — Supreme Court of the United States

**Date Decided:** January 2025

**Court:** Supreme Court of the United States, No. 24-656

**Facts:** The case arose from a challenge to the Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACAA), signed into law by President Joe Biden on 24 April 2024 as part of a broader foreign aid package. The Act required ByteDance Ltd., the Chinese parent company of TikTok Inc., to divest its ownership interest in TikTok's US operations within 270 days (with a possible 90-day extension). If ByteDance failed to divest within the prescribed period, the Act authorized the Attorney General to take enforcement actions including the prohibition of internet hosting services, app stores, and other online platforms from distributing or maintaining TikTok within the United States. The Act affected approximately 170 million monthly active US users of the TikTok platform.
Congress found that ByteDance was a foreign adversary-controlled application under the terms of the Act because: (a) ByteDance is incorporated in the Cayman Islands but headquartered in Beijing, China; (b) ByteDance's principal operations are conducted in China; and (c) ByteDance is subject to the jurisdiction of the People's Republic of China, including under China's National Intelligence Law (2017), which requires Chinese organizations to cooperate with state intelligence work. Congress determined that the continued operation of TikTok by ByteDance presented a national security threat because: the Chinese government could compel ByteDance to provide access to US user data; the Chinese government could influence TikTok's content recommendation algorithm to manipulate public opinion; and the vast volume of personal data collected by TikTok could be exploited for espionage, blackmail, or influence operations.
TikTok challenged the Act on multiple constitutional grounds, arguing that it: (a) violated the First Amendment by effectively banning a platform for speech based on its ownership structure, without sufficient evidence of specific misconduct; (b) was a bill of attainder, singling out TikTok for punishment without a judicial trial; (c) violated the Fifth Amendment's due process clause by being unconstitutionally vague; and (d) exceeded Congress's authority under the Commerce Clause and the Foreign Affairs power.
The US Court of Appeals for the District of Columbia Circuit rejected all of TikTok's constitutional challenges in a unanimous panel decision in December 2024, and TikTok sought emergency review from the Supreme Court, which granted certiorari on an expedited schedule.
Whether the PAFACAA violates the First Amendment's protection of freedom of speech and association.
Whether the Act constitutes a bill of attainder prohibited by Article I, Section 9 of the Constitution.
Whether the Act is unconstitutionally vague in violation of the Fifth Amendment's Due Process Clause.
Whether Congress has the constitutional authority to regulate or prohibit foreign-owned social media platforms.
First Amendment: The Court held that the Act did not violate the First Amendment. Applying intermediate scrutiny (as the regulation targeted foreign ownership of a communications platform rather than the content of speech), the Court found that the Act furthered the government's compelling interest in national security and was narrowly tailored to achieve that objective. The Court emphasized that the Act did not ban speech — it regulated the ownership structure of a platform through which speech occurs. The Court accepted Congress's national security determinations as supported by the legislative record, which included extensive evidence of China's intelligence activities and the risks posed by foreign adversary control of platforms with access to vast quantities of personal data.
Bill of attainder: The Court rejected the bill of attainder challenge, holding that the Act was a general regulation of foreign adversary-controlled applications (applicable to any application meeting the statutory criteria), not a specific legislative punishment of TikTok. The fact that TikTok was the only application currently meeting the criteria did not convert a general law into a bill of attainder.
Due process: The Court rejected the vagueness challenge, finding that the Act's terms — including "foreign adversary" and "covered application" — were sufficiently defined by reference to existing statutory definitions and executive determinations.
Congressional authority: The Court found that the Act fell within Congress's broad authority to regulate foreign commerce and to protect national security, rejecting TikTok's contention that the Act exceeded Congress's enumerated powers.
Following the Supreme Court's decision, the divestiture deadline was triggered, and the enforcement provisions of the Act became operative. TikTok's US operations faced the prospect of a shutdown or forced sale, though the practical implementation of the divestiture requirement remained subject to ongoing negotiations and potential executive action.

**Issue:** Whether the PAFACAA violates the First Amendment's protection of freedom of speech and association. Whether the Act constitutes a bill of attainder prohibited by Article I, Section 9 of the Constitution. Whether the Act is unconstitutionally vague in violation of the Fifth Amendment's Due Process Clause. Whether Congress has the constitutional authority to regulate or prohibit foreign-owned social media platforms.
**Holding:** The Supreme Court upheld the PAFACAA in a decision that addressed each of TikTok's constitutional challenges: First Amendment: The Court held that the Act did not violate the First Amendment. Applying intermediate scrutiny (as the regulation targeted foreign ownership of a communications platform rather than the content of speech), the Court found that the Act furthered the government's compelling interest in national security and was narrowly tailored to achieve that objective. The Court emphasized that the Act did not ban speech — it regulated the ownership structure of a platform through which speech occurs. The Court accepted Congress's national security determinations as supported by the legislative record, which included extensive evidence of China's intelligence activities and the risks posed by foreign adversary control of platforms with access to vast quantities of personal data. Bill of attainder: The Court rejected the bill of attainder challenge, holding that the Act was a general regulation of foreign adversary-controlled applications (applicable to any application meeting the statutory criteria), not a specific legislative punishment of TikTok. The fact that TikTok was the only application currently meeting the criteria did not convert a general law into a bill of attainder. Due process: The Court rejected the vagueness challenge, finding that the Act's terms — including "foreign adversary" and "covered application" — were sufficiently defined by reference to existing statutory definitions and executive determinations. Congressional authority: The Court found that the Act fell within Congress's broad authority to regulate foreign commerce and to protect national security, rejecting TikTok's contention that the Act exceeded Congress's enumerated powers. Following the Supreme Court's decision, the divestiture deadline was triggered, and the enforcement provisions of the Act became operative. TikTok's US operations faced the prospect of a shutdown or forced sale, though the practical implementation of the divestiture requirement remained subject to ongoing negotiations and potential executive action.
**Significance:** First Amendment meets national security. The decision represents the Supreme Court's most significant ruling on the intersection of digital free speech and national security. By applying intermediate rather than strict scrutiny, and by accepting Congress's national security determinations with significant deference, the Court established a framework that gives the government substantial latitude to regulate the ownership and governance of digital platforms on national security grounds. This deference has significant implications for future regulation of other foreign-owned platforms and technologies, and for the broader debate about the relationship between platform governance, free expression, and national security.
The foreign adversary framework. The Act and the Court's decision establish a novel regulatory paradigm: the classification of platform ownership as a national security issue based on the nationality and legal jurisdiction of the controlling entity. This framework moves beyond content-based regulation to focus on the structural characteristics of platform ownership, raising novel questions about the extent to which the government can regulate the identity and nationality of platform owners without running afoul of constitutional protections. The framework has already influenced legislative proposals targeting other Chinese-owned technology platforms and services.
Global precedent for platform regulation. The decision has been closely monitored by governments worldwide, many of which have adopted or are considering similar measures targeting TikTok and other platforms deemed to present national security risks. India banned TikTok in 2020 along with dozens of other Chinese apps following the Galwan Valley border clash. The European Union, Canada, and Australia have restricted the use of TikTok on government-issued devices. The US Supreme Court's constitutional analysis provides a legal framework that other jurisdictions may reference in developing their own platform regulation regimes.
Empirical questions unresolved. Despite the Court's acceptance of Congress's national security rationale, significant empirical questions remain unanswered. No public evidence has definitively demonstrated that the Chinese government has accessed TikTok user data through ByteDance or manipulated the platform's recommendation algorithm for political purposes. TikTok's proposed "Texas Project" — a restructuring plan under which US user data would be stored on servers operated by Oracle Corp. in the United States, with access by ByteDance personnel subject to oversight by a US-government-approved trust — was designed to address these concerns but was rejected by Congress as insufficient. The unresolved empirical questions highlight the difficulty of adjudicating national security claims in the context of digital platform regulation, where the evidence is often classified and the risks are inherently speculative.
Implications for the open internet. The decision raises profound questions about the future of the open, interoperable internet. If governments can prohibit platforms based on the nationality of their owners, the internet risks fragmenting into a series of nationally controlled information environments, each governed by different ownership rules and content standards. This fragmentation is already visible in China's "Great Firewall," Russia's development of a "sovereign internet" infrastructure, and the EU's efforts to establish European data governance infrastructure. The TikTok decision accelerates this trend in the democratic world, establishing a precedent that national security can justify restrictions on the global flow of digital services.
Comparative Analysis
The five cases in this Part reveal several overarching themes in the global governance of government surveillance and digital rights:
1. The proportionality principle as a universal constraint. Across jurisdictions — whether under the ECHR, the EU Charter, or the US Constitution — courts have consistently required that surveillance measures be proportionate to the threats they address. The CJEU's invalidation of the Data Retention Directive in Digital Rights Ireland and the ECHR's detailed safeguards analysis in Big Brother Watch both reflect the proportionality principle's central role in constraining state power. The TikTok decision represents a notable departure from this trend, applying a more deferential standard of review to national security determinations.
2. The inadequacy of existing legal frameworks. Several of these cases highlight the gap between existing legal frameworks and the realities of modern digital surveillance. The UK's RIPA was found inadequate by the ECHR; the EU's Data Retention Directive was invalidated by the CJEU; Russia's Yarovaya Law proved technically unenforceable; and China's data localization framework sits in tension with international trade obligations. These inadequacies reflect the fundamental challenge of regulating technologies that evolve far more rapidly than the legal frameworks designed to govern them.
3. The divergent values underlying surveillance regulation. The cases in this Part reflect fundamentally different conceptions of the relationship between the state, the individual, and data. The European approach prioritizes individual rights and requires rigorous proportionality analysis. The Chinese approach subordinates individual privacy to national security and state sovereignty. The Russian approach prioritizes state access to encrypted communications regardless of technical feasibility. The US approach occupies a complex middle ground, valuing free expression while granting substantial deference to national security claims.
4. The globalization of surveillance governance. These cases demonstrate that government surveillance is no longer purely a domestic concern. The ECHR's ruling on intelligence-sharing, the CJEU's restrictions on cross-border data transfers, China's data localization requirements, and the US regulation of foreign-owned platforms all reflect the increasingly transnational dimension of surveillance governance. The challenge for the coming decades will be to develop international frameworks that balance legitimate national security interests with the protection of fundamental rights in an interconnected digital environment.
End of Part Ten

---

### Case 10.6: Clapper v. Amnesty International USA (2013) —U.S. Supreme Court

**Date Decided:** February 26, 2013

**Court:** U.S. Supreme Court
Case citation: 568 U.S. 398 (2013)

**Facts:** Amnesty International USA and other attorneys representing foreign clients challenged the constitutionality of the FISA Amendments Act of 2008 (FAA), which authorized warrantless surveillance of non-U.S. persons located abroad. The plaintiffs argued that the law required them to incur costly measures to protect confidential communications from government monitoring.

**Issue:** Whether the plaintiffs had standing to challenge the FAA's constitutionality based on a reasonable fear that their communications would be monitored.

**Holding:** In a 5— decision, the Court held that the plaintiffs lacked Article III standing. The Court found that the alleged injury was too speculative, as the plaintiffs could not show that their communications would "certainly" or "very likely" be intercepted under the statute's targeting requirements.
**Significance:** Established a high bar for standing in surveillance challenges, requiring plaintiffs to demonstrate a "substantial risk" of actual interception rather than a generalized fear.
The decision effectively insulated the FAA from judicial review for years, until the Snowden revelations in 2013 revealed the scope of NSA surveillance, sparking legislative reform efforts.
Highlighted the structural difficulty of challenging secret surveillance programs through conventional litigation.

---

### Case 10.7: ACLU v. Clapper (2015) —U.S. Court of Appeals for the Second Circuit

**Date Decided:** May 7, 2015

**Court:** U.S. Court of Appeals for the Second Circuit
Case citation: 785 F.3d 787 (2d Cir. 2015)

**Facts:** Following the Snowden disclosures, the ACLU challenged the NSA's bulk telephone metadata collection program under Section 215 of the Patriot Act. The program involved the daily collection of records of virtually all telephone calls in the United States, including the numbers dialed and call duration.

**Issue:** Whether the NSA's bulk telephone metadata collection program exceeded the statutory authority granted by Section 215 of the Patriot Act.

**Holding:** The Second Circuit held that the program exceeded the authority of Section 215, which only permits the FBI to obtain records "relevant" to an authorized investigation. The court found that the bulk collection of all telephone metadata could not reasonably be considered "relevant" to any specific investigation under a sensible reading of the statute.
**Significance:** First federal appellate court to rule against the NSA's bulk metadata program, providing significant legal momentum for surveillance reform.
Did not reach the constitutional question of whether the program violated the Fourth Amendment.
Contributed directly to the passage of the USA Freedom Act of 2015, which ended bulk collection and replaced it with a more targeted framework.

---

### Case 10.8: Klayman v. Obama (2013) —U.S. District Court for the District of Columbia

**Date Decided:** December 16, 2013

**Court:** U.S. District Court for the District of Columbia
Case citation: 957 F. Supp. 2d 1 (D.D.C. 2013)

**Facts:** Larry Klayman, a conservative attorney, challenged the NSA's bulk telephone metadata collection program following the Snowden revelations. The case alleged that the program violated the Fourth Amendment's prohibition against unreasonable searches and seizures and exceeded statutory authority.

**Issue:** Whether the NSA's bulk collection of telephone metadata violated the Fourth Amendment.

**Holding:** Judge Richard Leon issued a preliminary injunction, finding that the program likely violated the Fourth Amendment. The court characterized the program as an "almost-Orwellian" technology that would have shocked the Founding Fathers. The injunction was stayed pending appeal.
**Significance:** One of the first judicial decisions to find the NSA metadata program likely unconstitutional, offering a powerful rhetorical rebuke to government surveillance overreach.
The D.C. Circuit later reversed on different procedural grounds, but the district court's reasoning influenced subsequent litigation and public discourse.
Contrasted sharply with other courts that reached different conclusions, illustrating the legal uncertainty surrounding bulk surveillance.

---

### Case 10.9: Carpenter v. United States (2018) —U.S. Supreme Court

**Date Decided:** June 22, 2018

**Court:** U.S. Supreme Court
Case citation: 138 S. Ct. 2206 (2018)

**Facts:** Timothy Carpenter was convicted of robbery based on cell-site location information (CSLI) obtained from his wireless carriers without a warrant. The government obtained 127 days of historical location data, covering 12,898 location points, showing Carpenter's movements near the robbery locations.

**Issue:** Whether the government violates the Fourth Amendment by accessing historical cell-site location information without a warrant.

**Holding:** In a 5— decision authored by Chief Justice Roberts, the Court held that the government's acquisition of historical CSLI constitutes a search under the Fourth Amendment and generally requires a warrant. The Court reasoned that individuals maintain a legitimate expectation of privacy in their physical movements, and that the depth, breadth, and comprehensive nature of CSLI collection implicates privacy interests beyond the scope of the third-party doctrine established in Smith v. Maryland.
**Significance:** Significantly curtailed the third-party doctrine in the digital age, recognizing that continuous digital surveillance creates privacy interests that differ from the discrete records at issue in earlier cases.
Established that warrantless access to detailed digital records of a person's movements is presumptively unreasonable.
Opened the door to future Fourth Amendment challenges to other forms of government access to digital data held by third parties, including financial records, email metadata, and internet browsing history.

---

### Case 10.10: Riley v. California (2014) —U.S. Supreme Court

**Date Decided:** June 25, 2014

**Court:** U.S. Supreme Court
Case citation: 573 U.S. 373 (2014)

**Facts:** David Riley was arrested for a traffic violation, and police searched his smartphone incident to arrest. The search revealed photographs and videos linking Riley to a gang-related shooting. A separate case involved Brima Wurie, whose flip phone was searched after arrest, leading police to his residence, where they found drugs and a firearm.

**Issue:** Whether police may search the digital contents of a cell phone seized from an individual who has been arrested, without first obtaining a warrant.

**Holding:** In a unanimous 9— decision authored by Chief Justice Roberts, the Court held that police generally may not search the digital contents of a cell phone incident to arrest without a warrant. The Court recognized that modern cell phones contain vast quantities of personal information and that traditional search-incident-to-arrest rationales (officer safety and evidence preservation) do not justify the broad intrusion into digital privacy that a cell phone search entails.
**Significance:** Established a categorical warrant requirement for cell phone searches incident to arrest, adapting Fourth Amendment doctrine to the realities of modern digital technology.
Recognized the qualitative difference between physical and digital searches, noting that a cell phone search would previously have required the search of a home.
Set an important precedent for digital privacy rights that influenced subsequent surveillance-related jurisprudence, including Carpenter.

---

### Case 10.11: S. and Marper v. United Kingdom (2008) —European Court of Human Rights

**Date Decided:** December 4, 2008

**Court:** European Court of Human Rights (Grand Chamber)
Case citation: Application nos. 30562/04 and 30566/04

**Facts:** The applicants, S. (a minor) and Michael Marper, were charged with criminal offenses in the UK but not convicted. Their fingerprints, cellular samples, and DNA profiles were retained by the authorities indefinitely under English law, even after their acquittals or the discontinuation of proceedings against them.

**Issue:** Whether the blanket and indiscriminate retention of DNA profiles, cellular samples, and fingerprints of persons not convicted of any offense violated Articles 8 and 14 of the European Convention on Human Rights.

**Holding:** The Grand Chamber held unanimously that the blanket retention of the applicants' DNA profiles, cellular samples, and fingerprints violated Article 8 (right to respect for private life). The Court found that the UK's retention framework failed to strike a fair balance between the competing public and private interests, particularly given the indiscriminate nature of the retention and the absence of sufficient safeguards.
**Significance:** Established that the retention of biometric data, even in the context of law enforcement, must be proportionate and subject to adequate safeguards, rejecting blanket retention policies.
Influenced subsequent reforms of UK DNA retention policy and set a standard for biometric data governance across Council of Europe member states.
Represented one of the earliest and most influential ECHR rulings on the intersection of technology and privacy rights.

---

### Case 10.12: Zakharov v. Russia (2015) —European Court of Human Rights

**Date Decided:** December 4, 2015

**Court:** European Court of Human Rights (Grand Chamber)
Case citation: Application no. 14928/11

**Facts:** Roman Zakharov, a Russian journalist, challenged the Russian legal framework governing communications surveillance. Russian law allowed the Federal Security Service (FSB) and other agencies to intercept telephone conversations and other communications through a system known as SORM, without independent judicial authorization. Zakharov alleged that his communications had been intercepted but was unable to prove it due to the secrecy of the surveillance system.

**Issue:** Whether the Russian legislative framework for communications surveillance, which lacked sufficient safeguards against arbitrariness, violated Article 8 of the Convention, and whether the applicant had standing despite being unable to prove specific surveillance.

**Holding:** The Grand Chamber held that the Russian communications surveillance system violated Article 8. The Court found that the legal framework lacked adequate safeguards against arbitrariness, including insufficient independence of the judicial authorization process, inadequate requirements for notifying targeted individuals, and insufficient oversight of interception measures. The Court also held that Zakharov had "victim status" based on the existence of a system capable of intercepting his communications.
**Significance:** Established that individuals who are "potentially affected" by a general system of communications surveillance may have standing to challenge the system, even without proof of actual interception.
Set out detailed requirements for the legal framework governing communications surveillance, including the need for "quality of law" safeguards.
Remains a leading authority on the Convention requirements for lawful communications surveillance in Europe.

---

### Case 10.13: Bărbulescu v. Romania [Grand Chamber] (2017) —European Court of Human Rights

**Date Decided:** September 5, 2017

**Court:** European Court of Human Rights (Grand Chamber)
Case citation: Application no. 61496/08

**Facts:** Bogdan Mihai Bărbulescu, a Romanian engineer, was dismissed by his employer after the employer monitored his personal Yahoo Messenger account during working hours. The monitoring revealed that Bărbulescu had used the account for personal purposes. The domestic courts upheld the dismissal, finding the monitoring was justified. The Chamber judgment had found no violation, but the Grand Chamber revisited the case.

**Issue:** Whether the employer's monitoring of Bărbulescu's electronic communications and the domestic courts' assessment of its compatibility with Article 8 of the Convention were sufficient.

**Holding:** The Grand Chamber held that there had been a violation of Article 8. While the Court acknowledged that employers have a legitimate interest in monitoring employee communications to ensure the smooth running of their businesses, it found that the Romanian courts had failed to determine whether Bărbulescu had been notified in advance about the nature and extent of the monitoring, whether he had been informed of the reasons for it, the scope of the monitoring, and whether less intrusive measures could have been used.
**Significance:** Established that workplace electronic surveillance must be proportionate, accompanied by adequate safeguards, and subject to meaningful judicial scrutiny.
Clarified that domestic courts must actively verify whether the employer's monitoring measures were justified, necessary, and proportionate, rather than deferring uncritically to employer interests.
Became the leading ECHR precedent on digital privacy in the employment context across Europe.

---

### Case 10.14: Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) —Supreme Court of India

**Date Decided:** August 24, 2017

**Court:** Supreme Court of India
Case citation: Writ Petition (Civil) No. 494 of 2012

**Facts:** Justice K.S. Puttaswamy, a retired judge of the Karnataka High Court, challenged the constitutionality of the Aadhaar scheme, India's massive biometric identification system that collects fingerprints, iris scans, and demographic data from over a billion residents. The petition argued that the scheme violated the right to privacy.

**Issue:** Whether Indian citizens have a fundamental right to privacy under the Constitution of India.

**Holding:** A nine-judge bench of the Supreme Court unanimously held that the right to privacy is a fundamental right under the Constitution, protected under Article 21 (right to life and personal liberty) and Part III of the Constitution. The Court overruled prior decisions (M.P. Sharma and Kharak Singh) that had held that the right to privacy was not a fundamental right.
**Significance:** Landmark recognition of privacy as a fundamental right in the world's largest democracy, with profound implications for Aadhaar and all future data protection legislation in India.
Established a three-tier test for any restriction on privacy: the restriction must be provided by law, must serve a legitimate state interest, and must be proportionate.
Directly influenced the enactment of India's Digital Personal Data Protection Act (2023) and shaped global constitutional privacy jurisprudence.

---

### Case 10.15: ADPF 328 (2020) —Supreme Federal Tribunal of Brazil

**Date Decided:** June 24, 2020

**Court:** Supreme Federal Tribunal (STF) of Brazil
Case citation: ADPF 328 / Relator: Min. Edson Fachin

**Facts:** The Brazilian Bar Association (OAB) filed an Argui o de Descumprimento de Preceito Fundamental (ADPF) challenging certain provisions of the Brazilian Telecommunications Act (Law No. 9.472/1997) that allowed telecommunications companies to register the geographical location of mobile devices and share this data with public authorities without judicial authorization.

**Issue:** Whether the legal provisions authorizing the collection and sharing of mobile phone geolocation data by telecommunications companies with public authorities, without prior judicial authorization, violated the fundamental rights to privacy, freedom of expression, and personal liberty.

**Holding:** The STF ruled that real-time geolocation tracking by state authorities requires prior judicial authorization. The Court interpreted the Marco Civil da Internet (Law No. 12.965/2014), which requires judicial order for the collection of geographic data, as applying to both internet-based and telecommunications-based geolocation. The Court distinguished between retained connection data (metadata) and active real-time tracking, allowing the former without a warrant under strict conditions but mandating judicial authorization for the latter.
**Significance:** Established a clear warrant requirement for real-time geolocation tracking in Brazil, while leaving a more permissive regime for retained metadata.
Demonstrated the STF's role as an active guardian of digital rights in Latin America's largest democracy.
Provided a model for balancing security interests with privacy protections in the Brazilian legal framework.

---

### Case 10.16: Telstra Corporation Limited v. Privacy Commissioner (2017) —Administrative Appeals Tribunal of Australia

**Date Decided:** April 12, 2017

**Court:** Administrative Appeals Tribunal of Australia (AAT)
Case citation: [2017] AATA 374

**Facts:** The Privacy Commissioner investigated Telstra's data retention practices under the Telecommunications (Interception and Access) Act 1979 and the Australian Privacy Principles. The investigation focused on whether Telstra had failed to take reasonable steps to protect personal information and whether its metadata retention and disclosure practices were compliant with the law following the enactment of the Telecommunications (Retention of Historical Data) Act 2015 (the Data Retention Act).

**Issue:** Whether Telstra's handling of customer metadata, including its retention, protection, and disclosure practices, complied with Australian privacy law.

**Holding:** The AAT found that Telstra had breached the Privacy Act by failing to take reasonable steps to secure customers' personal information, including unlisted directory numbers that were disclosed through directory assistance services. The tribunal upheld the Privacy Commissioner's determination and ordered Telstra to implement remedial measures.
**Significance:** Highlighted the practical challenges of implementing Australia's mandatory data retention regime, particularly regarding the protection and disclosure of retained metadata.
Demonstrated the role of the Privacy Commissioner and the AAT in enforcing compliance with Australia's data retention laws.
Contributed to ongoing public debate in Australia about the scope and safeguards of government surveillance powers under the Data Retention Act.

---

### Case 10.17: Korean National Intelligence Service (NIS) Illegal Surveillance Scandal (2012–2018) —Constitutional Court of Korea and Courts of Korea

**Date Decided:** Various decisions, 2012–2018

**Court:** Constitutional Court of Korea; Seoul Central District Court; Supreme Court of Korea
Case citation: Multiple decisions, including Constitutional Court Case 2012Hun-Ma789 (2014)

**Facts:** Following the election of President Park Geun-hye in 2012, it was revealed that the National Intelligence Service (NIS) had engaged in a systematic campaign of illegal online surveillance and political interference. NIS agents used social media platforms, including Twitter and Nate, to post pro-government messages and attack opposition candidates. Over 3.4 million tweets were posted by NIS psychological warfare teams during the 2012 presidential election. The scandal also involved the illegal wiretapping of private citizens and journalists.

**Issue:** Whether the NIS's surveillance activities and online political interference violated constitutional rights to privacy, freedom of expression, and democratic governance.

**Holding:** Multiple courts found that the NIS's activities were illegal and unconstitutional. Former NIS Director Won Sei-hoon was convicted of election law violations and sentenced to prison. The Constitutional Court examined the NIS's surveillance authority and found deficiencies in the legal framework governing intelligence activities. The scandal led to significant institutional reforms, including the disbanding of the NIS's domestic surveillance division.
**Significance:** Exposed the dangers of allowing intelligence agencies to engage in domestic political surveillance without adequate legal safeguards and democratic oversight.
Led to major reforms of South Korea's intelligence apparatus, including the renaming and restructuring of the NIS into the National Intelligence Service with reduced domestic authority.
Demonstrated the critical importance of protecting democratic processes from intelligence agency interference, with global implications for the governance of security services.

---

### Case 10.18: Association for Civil Rights in Israel (ACRI) v. The Knesset —The Intelligence Service Law (2017) —Supreme Court of Israel

**Date Decided:** February 2018

**Court:** Supreme Court of Israel (sitting as the High Court of Justice)
Case citation: HCJ 5248/16 and related petitions

**Facts:** Civil society organizations, including ACRI, petitioned the Supreme Court of Israel challenging the Intelligence Service Law (Special Powers) 2017, which authorized the Israeli Security Agency (ISA/Shin Bet) to use telecommunications metadata for the purpose of "protecting state security." The law permitted the ISA to access and use telecommunications metadata without judicial oversight and allowed data sharing with other bodies, including the military and police.

**Issue:** Whether the Intelligence Service Law 2017, which authorized bulk metadata surveillance by the ISA without individualized judicial authorization, violated constitutional rights to privacy and dignity.

**Holding:** The Supreme Court upheld most provisions of the law but imposed significant limitations. The Court required that any use of the intelligence database by entities other than the ISA must be subject to judicial authorization, and ordered the creation of oversight mechanisms including a parliamentary subcommittee. The Court mandated periodic review of the law's implementation and directed that the ISA could not use the intelligence database as a "tool of first resort."
**Significance:** Established important judicial limitations on Israel's domestic surveillance powers, while acknowledging legitimate security concerns in a context of ongoing conflict.
Required the creation of meaningful oversight mechanisms for intelligence agency surveillance, including parliamentary and judicial review.
Illustrated the challenges of balancing national security imperatives with democratic governance and individual rights in a high-threat environment.

---

### Case 10.19: EncroChat Encrypted Communications Case (2020–2024) —Multiple European Courts

**Date Decided:** Various decisions, 2020–ongoing

**Court:** Courts of the Netherlands, France, Germany, United Kingdom, Belgium, and Sweden; European Court of Human Rights

**Facts:** EncroChat was a provider of modified smartphones offering encrypted communication services, marketed as providing "100% untraceable" communications. The service was primarily used by organized criminal networks across Europe. In 2020, French and Dutch law enforcement authorities infiltrated the EncroChat network through a technical implant, gaining access to the content of millions of encrypted messages. The operation, codenamed "Emma," led to thousands of arrests, seizures of drugs, weapons, and cash, and hundreds of criminal prosecutions across multiple European countries.

**Issue:** Whether evidence obtained through the infiltration of the EncroChat network was admissible in criminal proceedings, given concerns about the legality of the surveillance techniques, the adequacy of judicial authorization, and the rights of the accused under the European Convention on Human Rights and EU law.

**Holding:** Courts across Europe have reached varying conclusions. In the Netherlands, courts have generally admitted the evidence. In Germany, several regional courts have excluded EncroChat-derived evidence, finding that the surveillance lacked sufficient legal basis under German law. French courts have admitted the evidence. UK courts have generally admitted it, though some defense challenges remain pending. The European Court of Human Rights has not yet issued a definitive ruling on the admissibility question.
**Significance:** Represents the largest ever operation to infiltrate an encrypted communications network, raising fundamental questions about the legality and proportionality of state hacking and bulk surveillance.
Highlights the divergent approaches of European jurisdictions to the admissibility of evidence obtained through novel surveillance techniques.
Raises critical questions about the future of end-to-end encryption and the scope of lawful government hacking powers under ECHR and EU law, with implications for technology companies and users worldwide.

---

### Case 10.20: USA Freedom Act Litigation and Reauthorization (2015–2020) —U.S. Courts and Congress

**Date Decided:** June 2, 2015 (enactment); reauthorized 2019, 2020

**Court:** U.S. Congress; U.S. Foreign Intelligence Surveillance Court (FISC); multiple federal courts

**Facts:** The USA Freedom Act (Uniting and Strengthening America by Fulfilling Rights and Ensuring Effective Discipline Over Monitoring Act) was enacted on June 2, 2015, in response to the Snowden revelations and the judicial challenges to the NSA's bulk telephone metadata collection program. The Act ended the NSA's bulk collection of telephone metadata and replaced it with a system requiring telecommunications companies to retain the data and allowing the NSA to obtain records through a court order from the FISC based on "specific selection terms." The Act was reauthorized with modifications in 2019 and 2020.

**Issue:** Whether the USA Freedom Act adequately addressed the constitutional and statutory deficiencies identified in the NSA's bulk metadata program while preserving legitimate national security capabilities.

**Holding:** The USA Freedom Act represented a significant restructuring of the NSA's surveillance authority. The FISC approved the new framework, requiring specific selection terms that reasonably describe the records sought. However, civil liberties organizations argued that the reforms were insufficient, noting that the Act continued to permit the collection of records "two hops" from the target. The Act's reauthorization debates in 2019–2020 revealed ongoing tension between security and privacy interests, with some legislators seeking to restore bulk collection authority.
**Significance:** First significant legislative restriction on U.S. intelligence community surveillance capabilities since the post-9/11 expansion of surveillance powers.
Demonstrated the potential for legislative reform of surveillance programs, while also revealing the limits of congressional action in the face of executive branch resistance and intelligence community lobbying.
Served as a model (or cautionary tale) for surveillance reform efforts worldwide, illustrating the complex interplay between legislative, executive, and judicial branches in governing surveillance.

---

### Case 10.21: Big Brother Watch and Others v. United Kingdom (2021) —European Court of Human Rights (Grand Chamber)

**Date Decided:** May 25, 2021

**Court:** European Court of Human Rights (Grand Chamber)
Case citation: Application nos. 58170/13, 62322/14 and 24960/15

**Facts:** Following the Snowden revelations, multiple NGOs and individuals brought challenges against the United Kingdom's bulk interception regime (under the Regulation of Investigatory Powers Act 2000, or RIPA) and its intelligence-sharing arrangements with the United States. The applicants argued that the bulk interception of communications and the receipt of intelligence from foreign agencies violated Articles 8 and 10 of the Convention.

**Issue:** Whether the UK's bulk interception regime, including the selection and examination of intercepted material, the safeguards governing its use, and the regime for receiving intelligence from foreign agencies, was compatible with Articles 8 and 10 of the Convention.

**Holding:** The Grand Chamber held that the UK's bulk interception regime violated Article 8 (and by extension Article 10) due to deficient safeguards, including the lack of independent authorization for interception warrants, insufficient oversight of the selection process for examining intercepted communications, and inadequate safeguards for journalistic sources and legally privileged communications. However, the Court found that bulk interception per se is not inherently incompatible with the Convention, provided it is governed by adequate safeguards.
**Significance:** Established that bulk communications surveillance is not inherently unlawful under the Convention, but must be subject to robust safeguards including independent authorization, strict necessity and proportionality requirements, and protection for privileged communications.
Required the UK to reform its surveillance framework, contributing to the enactment of the Investigatory Powers Act 2016 and subsequent amendments.
Provided the most comprehensive ECHR analysis of bulk surveillance practices to date, with implications for all Council of Europe member states.

---

### Case 10.22: Chinese Internet Surveillance and the Great Firewall —Legal Framework (2017–2023) —People's Courts of China

**Date Decided:** Various decisions, 2017–2023

**Court:** People's Courts of China; Standing Committee of the National People's Congress

**Facts:** China operates one of the world's most extensive internet surveillance systems, encompassing the Great Firewall (GFW), real-time monitoring of social media communications, and the Social Credit System. The Cybersecurity Law (2017), the Data Security Law (2021), and the Personal Information Protection Law (2021) collectively establish a comprehensive framework for state access to personal data held by technology companies. Companies are required to store critical data within China, provide assistance to state security investigations, and implement content filtering and monitoring. The 2017 Cybersecurity Law mandates that network operators cooperate with public security organs in criminal investigations, including providing technical support and assistance.

**Issue:** Whether China's comprehensive internet surveillance framework, including mandatory data localization, compelled technical assistance, and content monitoring, is consistent with international human rights standards and domestic legal protections.

**Holding:** Chinese courts have consistently upheld the government's surveillance powers. In practice, legal challenges to the surveillance framework are extremely rare and typically unsuccessful. The domestic legal framework prioritizes state security, social stability, and economic development over individual privacy. The Personal Information Protection Law (2021) provides some protections for personal data against private sector misuse but includes broad exemptions for state security and public interest purposes.
**Significance:** Represents the most comprehensive state surveillance ecosystem in the world, serving as both a model and a cautionary example for the global debate on digital rights and government power.
The PIPL (2021), while primarily focused on private-sector data governance, represents a significant development in Chinese privacy law, even as it preserves broad state surveillance powers.
Illustrates the fundamental tension between China's approach to internet governance —emphasizing sovereignty, security, and social harmony —and the Western liberal democratic model emphasizing individual rights and limited government power.

---

### Case 10.23: Irish High Court Challenge to EU–US Data Transfers —Schrems II Follow-up (2020–2023) —Irish Courts and CJEU

**Date Decided:** July 16, 2020 (CJEU); ongoing proceedings in Irish courts

**Court:** Court of Justice of the European Union; Irish High Court; Data Protection Commission (Ireland)

**Facts:** Following the CJEU's landmark decision in Schrems II (Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems, Case C-311/18), which invalidated the EU–US Privacy Shield framework due to U.S. government surveillance practices, the Irish Data Protection Commission (DPC) issued draft decisions regarding Facebook's continued use of Standard Contractual Clauses (SCCs) for EU–U.S. data transfers. The DPC proposed banning the transfers, but the matter was referred to the Irish High Court and subsequently to the CJEU for further clarification.

**Issue:** Whether U.S. surveillance practices are compatible with EU fundamental rights standards, and whether alternative transfer mechanisms (such as SCCs supplemented by additional safeguards) can ensure adequate protection for EU personal data transferred to the United States.

**Holding:** The CJEU in Schrems II held that U.S. surveillance laws, particularly Section 702 of FISA and Executive Order 12333, do not provide protection "essentially equivalent" to that required by EU law, because they permit disproportionate and indiscriminate collection of personal data. The Irish DPC subsequently ordered the suspension of Facebook's EU–U.S. data transfers, but this was challenged. In 2023, the EU and U.S. adopted a new framework (the EU–U.S. Data Privacy Framework), which the European Commission declared adequate.
**Significance:** Established that EU data protection law serves as an indirect but powerful constraint on foreign government surveillance practices affecting EU residents.
Forced a fundamental restructuring of transatlantic data transfer mechanisms, with significant economic and diplomatic consequences.
The new EU–U.S. Data Privacy Framework (2023) represents the third attempt to resolve the transatlantic surveillance tension, but its durability remains uncertain pending likely judicial challenge.

---

### Case 10.24: Li "Stella" Yufei v. Hangzhou Safari Park —Facial Recognition Case (2021) —Intermediate People's Court of Hangzhou

**Date Decided:** April 9, 2021

**Court:** Intermediate People's Court of Hangzhou, Zhejiang Province, China
Case citation: (2020) Zhe 01 Min Zhong 754

**Facts:** Guo Bing, a Chinese law professor (the case is commonly attributed to the plaintiff Guo Bing challenging Hangzhou Safari Park), challenged the legality of facial recognition technology deployed by the wildlife park, which required annual pass holders to undergo facial recognition scans as the sole means of entering the park, replacing the previous fingerprint-based system. The case was framed as a consumer contract dispute under the Civil Code but raised fundamental questions about biometric surveillance and consent.

**Issue:** Whether mandatory facial recognition as a condition of accessing a commercial service constituted an infringement of consumer rights and privacy under Chinese civil law.

**Holding:** The court ruled in favor of Guo, ordering the wildlife park to delete his facial recognition data and pay compensation. The court held that mandatory facial recognition collection violated consumer protection principles, as the park unilaterally changed the terms of the annual pass contract and did not provide alternative means of identification without obtaining genuine consent.
**Significance:** Dubbed "China's first facial recognition lawsuit," the case represented a notable instance of Chinese courts enforcing privacy rights in the context of biometric surveillance by private entities.
While not directly challenging government surveillance, the case established important principles regarding consent and proportionality in biometric data collection that could influence broader governance.
Illustrated the evolving nature of privacy protection in China, where the legal framework is simultaneously expanding state surveillance capabilities and developing consumer data protection norms.

---

### Case 10.25: Pegasus Spyware Litigation (2021–2024) —Multiple Jurisdictions

**Date Decided:** Ongoing proceedings in multiple jurisdictions

**Court:** Courts of Israel, India, France, Poland, Mexico, Morocco; UN Special Rapporteurs; European Parliament inquiries

**Facts:** In 2021, a global consortium of journalists published the "Pegasus Project," revealing that NSO Group's Pegasus spyware had been used to target journalists, activists, politicians, and business executives in over 50 countries. The spyware, sold exclusively to government agencies, enabled zero-click remote infiltration of smartphones, granting access to all data, communications, camera, and microphone. The revelations led to criminal investigations, civil lawsuits, and regulatory actions in multiple countries.

**Issue:** Whether the deployment of NSO Group's Pegasus spyware by government agencies violated domestic and international law, including rights to privacy, freedom of expression, and protection against arbitrary interference.

**Holding:** Legal proceedings are ongoing in multiple jurisdictions. In Israel, the government established a ministerial committee to review NSO Group's export licenses and imposed new restrictions. India's Supreme Court appointed a technical committee to investigate Pegasus use and found insufficient cooperation from the government. French authorities opened criminal investigations. The U.S. Commerce Department placed NSO Group on the Entity List, barring it from receiving American technology. WhatsApp (Meta) obtained a default judgment against NSO Group in a California federal court under the Computer Fraud and Abuse Act.
**Significance:** Represented the first global reckoning with the commercial spyware industry and its implications for human rights and democratic governance.
Catalyzed regulatory and legislative responses in multiple countries, including new controls on the export and use of surveillance technology.
Raised fundamental questions about state responsibility for the use of privately developed surveillance tools, corporate accountability for human rights impacts, and the adequacy of existing international law frameworks.
Part Ten —Government Surveillance & Human Rights: Additional Cases (10.26—0.55)

---

### Case 10.26: Smith v. Maryland (1979) —Supreme Court of the United States

**Date Decided:** June 20, 1979

**Court:** Supreme Court of the United States

**Facts:** Police, suspecting Michael Lee Smith of making harassing phone calls, installed a pen register at the telephone company's central office without a warrant. The device recorded all numbers dialed from Smith's home phone. The records confirmed calls to the victim, and Smith was convicted. He challenged the use of the pen register as a Fourth Amendment search.

**Issue:** Whether the installation and use of a pen register to record numbers dialed from a private telephone constitutes a "search" under the Fourth Amendment.

**Holding:** The Court held (5—) that the use of a pen register is not a search under the Fourth Amendment. The majority reasoned that petitioners voluntarily convey numerical information to the telephone company when they dial, and thus assume the risk that the company might reveal that information to police.
**Significance:** Established the "third-party doctrine" for metadata: information voluntarily shared with a service provider enjoys no reasonable expectation of privacy.
Became the doctrinal foundation for decades of government metadata collection programs, including bulk telephony metadata under the USA PATRIOT Act.
Increasingly criticized post-Carpenter v. United States (2018), which limited (but did not overrule) Smith for cell-site location information.

---

### Case 10.27: United States v. Jones (2012) —Supreme Court of the United States

**Date Decided:** January 23, 2012

**Court:** Supreme Court of the United States

**Facts:** FBI agents attached a GPS tracking device to Antoine Jones's vehicle without a valid warrant and monitored his movements for 28 days. The evidence obtained was used to convict Jones of drug trafficking. The D.C. Circuit reversed, and the government appealed.

**Issue:** Whether the warrantless attachment of a GPS device to a vehicle and monitoring of its movements constitutes a Fourth Amendment search.

**Holding:** The Court unanimously held that the government's physical intrusion on the vehicle for the purpose of obtaining information was a search under the Fourth Amendment. The majority rested on the trespass theory; five concurring justices (Scalia, joined by four others) also suggested that long-term GPS monitoring may violate reasonable expectations of privacy.
**Significance:** Revived the property/trespass theory of the Fourth Amendment alongside the Katz "reasonable expectation of privacy" test.
Signaled the Court's growing concern with pervasive digital surveillance technologies, even though the majority avoided squarely deciding the Katz question.
Provided a crucial building block for later decisions including Carpenter v. United States (2018).

---

### Case 10.28: Lavabit, LLC v. United States (2013–2014) —U.S. District Court for the Eastern District of Virginia / Fourth Circuit

**Date Decided:** Various orders from July'ctober 2013; Fourth Circuit appeal denied February 2014

**Court:** U.S. District Court for the Eastern District of Virginia (Leonie Brinkema, J.)

**Facts:** The federal government served Lavabit'he encrypted email service used by Edward Snowden'ith a court order requiring it to turn over its SSL private encryption keys, which would have enabled real-time surveillance of all 400,000 Lavabit users. Ladar Levison, Lavabit's founder, refused and shut down the service rather than comply. The government sought contempt sanctions.

**Issue:** Whether a court order compelling an email service provider to disclose its SSL encryption keys, under the Stored Communications Act, exceeded statutory authority and violated the Fourth Amendment.

**Holding:** The district court denied Lavabit's motion to quash and held Levison in contempt. The Fourth Circuit denied review. Levison complied under duress by providing the keys in an illegible format (4-point font), but the service remained shut down.
**Significance:** Exposed the tension between compelled decryption orders and the privacy of all users of an encrypted service, not just the named target.
Catalyzed public debate over "backdoor" encryption demands and became a rallying point for the "Going Dark" controversy.
Levison later founded Dark Mail Technical Alliance to develop end-to-end encrypted email protocols resistant to such orders.

---

### Case 10.29: American Civil Liberties Union v. Clapper —Follow-On Litigation (2015–2020) —U.S. District Court for the Southern District of New York / Second Circuit

**Date Decided:** Second Circuit decision May 7, 2015; district court proceedings through 2020

**Court:** United States Court of Appeals for the Second Circuit

**Facts:** Following the 2013 Snowden disclosures, the ACLU challenged the NSA's bulk telephone metadata program under Section 215 of the USA PATRIOT Act as amended. The Second Circuit held in 2015 that the program exceeded congressional authority under Section 215. After the USA FREEDOM Act of 2015 ended bulk collection, follow-on proceedings examined whether the program also violated the First and Fourth Amendments.

**Issue:** Whether the NSA's bulk telephony metadata collection program exceeded statutory authority and violated constitutional rights.

**Holding:** The Second Circuit held that the program was not authorized by Section 215 because it collected records "relevant" to an authorized investigation only in the broadest speculative sense. The court did not reach the constitutional questions. The USA FREEDOM Act subsequently ended the program in its original form.
**Significance:** First major judicial opinion finding the NSA's bulk metadata program unlawful, even if on statutory rather than constitutional grounds.
Demonstrated the importance of statutory interpretation as a gateway to constitutional privacy protections.
Influenced the passage of the USA FREEDOM Act, which imposed significant reforms on government surveillance authorities.

---

### Case 10.30: Lakewood v. Plainfield (2000) —Supreme Court of the United States

**Date Decided:** February 22, 2000

**Court:** Supreme Court of the United States

**Facts:** The City of Plainfield, Indiana, sought to use a police surveillance camera to monitor an intersection within the City of Lakewood, Ohio, without Lakewood's consent. The camera was intended to capture images of vehicles entering and leaving an adult entertainment establishment. Lakewood objected and litigation ensued over the legality of cross-jurisdictional surveillance.

**Issue:** Whether a municipality has standing to challenge another municipality's installation of a surveillance camera directed at its territory, and what constitutional limits apply to such surveillance.

**Holding:** The Court held (8—) that Lakewood lacked standing because it had not suffered an "injury in fact" of a concrete and particularized nature. The case was dismissed without reaching the merits of the surveillance challenge.
**Significance:** While resolved on standing grounds, the case highlighted emerging concerns about municipal surveillance cameras and inter-governmental surveillance disputes.
Presaged later litigation over automated license plate readers, CCTV networks, and cross-jurisdictional data sharing among law enforcement agencies.
Demonstrated the difficulty of obtaining judicial review of government surveillance practices absent a directly injured plaintiff.

---

### Case 10.31: S.P. v. United Kingdom (2022) —European Court of Human Rights (Grand Chamber)

**Date Decided:** May 12, 2022

**Court:** European Court of Human Rights (Grand Chamber)

**Facts:** The applicant, S.P., challenged the United Kingdom's bulk interception regime under the Regulation of Investigatory Powers Act 2000 (RIPA) and its use of intercepted material in criminal proceedings. The Grand Chamber also addressed the UK's use of intelligence derived from bulk interception shared with other agencies. A key question was whether the regime provided sufficient safeguards against automated profiling using artificial intelligence.

**Issue:** Whether the UK's bulk interception regime, including its use of automated analytical tools and AI-assisted profiling, satisfied the requirements of Article 8 (right to private life) and Article 10 (freedom of expression) of the European Convention on Human Rights.

**Holding:** The Grand Chamber held, by 13 votes to 4, that the UK's bulk interception regime violated Article 8 and Article 10. The court found that the regime lacked sufficient safeguards regarding the selection and examination of intercepted material, the protection of confidential journalistic material, and the use of bulk personal datasets and AI-assisted profiling without adequate oversight.
**Significance:** First ECHR Grand Chamber ruling to specifically address the use of artificial intelligence and automated analytical tools in a mass surveillance regime.
Established that bulk surveillance regimes must have robust safeguards at each stage'election, interception, examination, and retention'o satisfy Article 8.
Required that interception regimes include "end-to-end" safeguards to protect journalistic sources and communications data.

---

### Case 10.32: Roman Zakharov v. Russia (2015) —European Court of Human Rights (Grand Chamber)

**Date Decided:** December 4, 2015

**Court:** European Court of Human Rights (Grand Chamber)

**Facts:** Roman Zakharov, a Russian journalist, challenged Russia's system for intercepting telecommunications, under which the security services (FSB) had direct, unrestricted access to all telephone communications through equipment permanently installed at telecom operators' switching centers. interceptions were authorized by internal orders rather than judicial warrants. The Russian courts had dismissed his complaint.

**Issue:** Whether Russia's system of interception of mobile telephone communications satisfied the safeguards required by Article 8 of the European Convention on Human Rights, particularly the requirement of judicial oversight.

**Holding:** The Grand Chamber held (unanimously) that Russia had violated Article 8. The court found that the system lacked adequate safeguards: interception was authorized by senior FSB officials rather than by an independent judicial authority, there was no effective oversight mechanism, and the system permitted blanket, untargeted interception.
**Significance:** Established that Article 8 requires judicial or equivalent independent authorization for interception of communications, not merely internal administrative approval.
Recognized that subscribers of telecommunications services are "victims" under the Convention even if they cannot prove they were individually monitored, due to the systemic nature of the violation.
Set a baseline standard for interception safeguards that influenced subsequent rulings on national surveillance regimes across Council of Europe states.

---

### Case 10.33: Szab and Vissy v. Hungary (2016) —European Court of Human Rights

**Date Decided:** January 12, 2016

**Court:** European Court of Human Rights

**Facts:** Two Hungarian nationals challenged Hungary's national security surveillance law, which authorized the Minister of Justice to order secret surveillance (including wiretapping and electronic monitoring) of persons suspected of threatening national security. The law provided no prior judicial authorization and offered only ex post facto review by a designated court. The applicants argued that the law was insufficiently precise and lacked adequate safeguards.

**Issue:** Whether Hungary's national security surveillance regime provided sufficient safeguards against arbitrary interference with private communications under Article 8 of the European Convention on Human Rights.

**Holding:** The Court held (unanimously) that Hungary had violated Article 8. The regime was found deficient because: (1) the definition of "national security" was overly broad; (2) surveillance was authorized by a minister rather than an independent judicial authority; (3) there were no meaningful limits on the duration or scope of surveillance; and (4) after-the-fact judicial review was inadequate.
**Significance:** Reinforced the requirement of prior independent authorization (preferably judicial) for national security surveillance under ECHR Article 8.
Established that vague statutory definitions of the grounds for surveillance (such as "national security") are incompatible with the "quality of law" requirement under Article 8.
Demonstrated the Court's willingness to scrutinize national security surveillance laws of Council of Europe member states rigorously.

---

### Case 10.34: Centrum fr rttvisa v. Sweden (2016) —European Court of Human Rights (Grand Chamber)

**Date Decided:** November 8, 2016

**Court:** European Court of Human Rights (Grand Chamber)

**Facts:** Centrum fr rttvisa (the Swedish Center for Justice) challenged Sweden's signals intelligence law (FRA law), which authorized the National Defence Radio Establishment (FRA) to conduct bulk interception of electronic communications crossing Swedish borders. The law authorized interception without any requirement of individualized suspicion and permitted data sharing with other agencies.

**Issue:** Whether Sweden's bulk interception regime for foreign communications crossing its borders satisfied the requirements of Article 8 of the European Convention on Human Rights.

**Holding:** The Grand Chamber held (12 votes to 6) that there had been no violation of Article 8. The Court found that the Swedish regime included sufficient safeguards, including prior judicial authorization by a special court (the Signals Intelligence Review Board), restrictions on data access, and protections for Swedish domestic communications.
**Significance:** One of the first ECHR Grand Chamber cases to uphold a bulk interception regime, demonstrating that mass surveillance can be compatible with Article 8 if robust safeguards are in place.
Distinguished from Roman Zakharov on the basis that Sweden's regime included independent judicial oversight, whereas Russia's did not.
Became an important comparator in subsequent surveillance cases, showing the difference between lawful and unlawful bulk interception frameworks.

---

### Case 10.35: Saber and Others v. France (2022) —European Court of Human Rights (Grand Chamber)

**Date Decided:** January 20, 2022

**Court:** European Court of Human Rights (Grand Chamber)

**Facts:** Six applicants challenged France's intelligence surveillance laws, particularly the provisions allowing intelligence agencies to conduct electronic surveillance without prior judicial authorization, relying instead on authorization from the Prime Minister. The case concerned the 2015 Intelligence Act and its predecessors, which allowed surveillance for a wide range of purposes including national security, terrorism prevention, and economic security.

**Issue:** Whether France's intelligence surveillance regime, which authorized interception based on ministerial rather than judicial approval, satisfied the requirements of Article 8 of the European Convention on Human Rights.

**Holding:** The Grand Chamber held (by 15 votes to 2) that there had been no violation of Article 8. The Court found that France's regime provided adequate safeguards, including ex post facto oversight by the National Commission for the Control of Intelligence Techniques (CNCTR), the ability to challenge surveillance before the Council of State, and limitations on the purposes and duration of surveillance measures.
**Significance:** Established that ex post facto judicial oversight, when combined with robust independent oversight mechanisms, can satisfy Article 8 requirements in the intelligence context.
Diverged from the stricter prior-judicial-authorization approach of Roman Zakharov, acknowledging a margin of appreciation for intelligence surveillance.
Illustrated the Court's deference to states on the specific institutional design of surveillance oversight, provided that effective remedies exist.

---

### Case 10.36: Pierront and Others v. France (2024) —European Court of Human Rights (Grand Chamber)

**Date Decided:** April 9, 2024

**Court:** European Court of Human Rights (Grand Chamber)

**Facts:** Multiple applicants challenged France's comprehensive data retention regime under which telecommunications operators were required to retain metadata (traffic and location data) for one year for the purposes of national security, crime prevention, and economic defense. The applicants argued that blanket, indiscriminate retention of their communications metadata violated their right to private life under Article 8.

**Issue:** Whether France's blanket data retention regime for telecommunications metadata was compatible with Article 8 of the European Convention on Human Rights, in light of the CJEU's rulings in Digital Rights Ireland and Tele2 Sverige.

**Holding:** The Grand Chamber held that France's blanket data retention regime violated Article 8. The Court found that the indiscriminate retention of all users' communications data for a fixed period was neither necessary nor proportionate. The regime lacked sufficient differentiation, limitation, and safeguards against abuse.
**Significance:** Brought the ECHR's approach to data retention into closer alignment with the CJEU's strict stance in Digital Rights Ireland and Tele2 Sverige.
Clarified that blanket data retention regimes are presumptively disproportionate under Article 8, regardless of the stated national security purpose.
Required states to implement targeted, differentiated data retention frameworks with independent oversight and effective remedies.

---

### Case 10.37: R. v. Spencer (2014) —Supreme Court of Canada

**Date Decided:** June 13, 2014

**Court:** Supreme Court of Canada

**Facts:** Police in Saskatoon investigated Matthew Spencer for possession of child pornography. Without obtaining a warrant, police contacted Spencer's Internet service provider (Shaw Communications) and obtained his subscriber information (name, address, and IP assignment records). Shaw voluntarily provided the information. Spencer moved to exclude the evidence as a violation of his Section 8 Charter right against unreasonable search and seizure.

**Issue:** Whether a person has a reasonable expectation of privacy in their subscriber information held by an Internet service provider, such that obtaining that information without a warrant constitutes an unreasonable search under Section 8 of the Canadian Charter of Rights and Freedoms.

**Holding:** The Court held (unanimously) that Spencer had a reasonable expectation of privacy in his subscriber information. Obtaining such information without a warrant violated Section 8 of the Charter. The Court rejected the application of the third-party doctrine in the Canadian context, distinguishing the situation from the American approach in Smith v. Maryland.
**Significance:** Explicitly rejected the third-party doctrine in Canadian law, holding that subscriber information belongs to the individual even when held by an ISP.
Established that Canadians have a reasonable expectation of privacy in basic Internet subscriber information, requiring police to obtain a warrant or production order.
Significantly impacted Canadian law enforcement practices, requiring judicial authorization for access to IP address and subscriber data.

---

### Case 10.38: R. v. Makuch (2021) —Supreme Court of Canada

**Date Decided:** May 14, 2021

**Court:** Supreme Court of Canada

**Facts:** Jordan Makuch was suspected of drug trafficking. Police obtained a production order for his historical cell-site location information (CSLI) from his wireless carrier. The CSLI revealed his general geographic movements over a period of weeks. Makuch argued that obtaining his historical CSLI without a wiretap authorization (which requires a higher threshold) violated his Section 8 Charter rights.

**Issue:** Whether obtaining historical cell-site location information from a wireless carrier under a production order (rather than a wiretap authorization) meets the requirements of Section 8 of the Charter, and whether CSLI attracts a reasonable expectation of privacy.

**Holding:** The Court held that historical CSLI does attract a reasonable expectation of privacy under Section 8. However, the production order standard (reasonable grounds to believe the information will assist in the investigation) was sufficient for historical CSLI because it is "information in the possession of the third party" rather than "interception of private communications." The Court declined to require the higher wiretap authorization standard for historical CSLI.
**Significance:** Extended Section 8 protection to historical cell-site location data while holding that the appropriate legal mechanism (production order, not wiretap authorization) depends on the nature of the data.
Clarified the framework for determining which legal instrument is appropriate for different categories of digital data.
Distinguished historical from prospective CSLI collection, leaving the latter subject to the higher wiretap authorization standard.

---

### Case 10.39: Généreux v. Canada (Public Safety) (2023) —Federal Court of Canada

**Date Decided:** November 23, 2023

**Court:** Federal Court of Canada

**Facts:** Marie-France Généreux challenged Canada's no-fly list regime under the Secure Air Travel Act (SATA), arguing that being placed on the Specified Persons List (the Canadian no-fly list) without adequate procedural safeguards violated her Charter rights, including Section 8 (privacy) and Section 7 (life, liberty, and security of the person). The list was maintained by Public Safety Canada and shared with airlines, resulting in her being repeatedly denied boarding or subjected to enhanced screening.

**Issue:** Whether Canada's no-fly list regime, including its data collection, sharing, and lack of meaningful procedural review, violated Sections 7, 8, and 15 of the Charter.

**Holding:** The Federal Court held that the regime violated Section 7 (right to liberty and security of the person) due to inadequate procedural safeguards. The court found that individuals on the list had no effective mechanism to challenge their inclusion or obtain the reasons for it. However, the court did not find a Section 8 violation, holding that the data collection was authorized by statute and proportionate to the aviation security objective.
**Significance:** Highlighted the procedural deficiencies in Canadian watchlisting and data-sharing systems that impact individual rights.
Demonstrated that even security-motivated data systems must provide meaningful due process to affected individuals.
Contributed to ongoing legislative reform efforts regarding Canada's no-fly list and passenger protect programs.

---

### Case 10.40: Telstra Corporation Limited v. Australian Competition and Consumer Commission (2008) —Australian Federal Court / High Court (Telecommunications (Interception and Access) Act context)

**Date Decided:** High Court of Australia, March 12, 2008

**Court:** High Court of Australia

**Facts:** The ACCC alleged that Telstra, Australia's largest telecommunications provider, had engaged in anti-competitive conduct by withholding a requested service (the "unconditioned local loop service") from competitors. During the proceedings, issues arose under the Telecommunications (Interception and Access) Act 1979 (TIA Act) regarding the scope of lawful access to telecommunications data and the obligations of carriers to assist law enforcement. The case tested the boundaries of the TIA Act's data access framework.

**Issue:** Whether the obligations imposed on telecommunications carriers under the TIA Act and related regulatory frameworks were consistent with the Act's privacy protections, and whether carriers could be compelled to provide broad categories of data to law enforcement and regulators.

**Holding:** The High Court's decision primarily addressed competition law issues. However, the proceedings clarified that the TIA Act created a comprehensive framework for law enforcement access to communications data, and that carrier obligations under the TIA Act operated alongside, rather than in conflict with, regulatory access powers.
**Significance:** Illustrated the intersection of competition regulation, telecommunications law, and surveillance data access in the Australian context.
Clarified the dual obligations of telecommunications carriers: to provide lawful interception capabilities to agencies and to protect customer data under the TIA Act.
Contributed to subsequent reforms of Australia's telecommunications data retention and access framework.

---

### Case 10.41: Australian Security Intelligence Organisation Act Cases —Practice Notes and Authorisations (Various, 2015–2023)

**Date Decided:** Various dates, 2015–2023 (key decisions by the Inspector-General of Intelligence and Security)

**Court:** Various, including the Administrative Appeals Tribunal and Federal Court of Australia

**Facts:** Multiple proceedings challenged the scope of special intelligence operations (SIOs) conducted by the Australian Security Intelligence Organisation (ASIO) under the Australian Security Intelligence Organisation Act 1979 (ASIO Act). Following the 2014 amendments (and further amendments in 2020), SIOs granted ASIO officers broad powers including the ability to detain individuals, conduct surveillance, and disrupt computer operations. Several individuals and civil society organizations challenged the legality and proportionality of these operations.

**Issue:** Whether ASIO's special intelligence operations, including surveillance and data collection powers, were exercised within the scope of the ASIO Act and consistent with Australia's human rights obligations, particularly the right to privacy.

**Holding:** Various proceedings produced mixed results. The Inspector-General of Intelligence and Security (IGIS) found several instances of non-compliance with ASIO's internal guidelines and statutory requirements, including inadequate documentation and insufficient minimization of collected data. Courts generally deferred to the executive on national security matters but upheld the requirement for ministerial authorization and IGIS oversight.
**Significance:** Exposed tensions between broad intelligence-gathering powers and individual privacy rights in Australia's national security framework.
Highlighted the importance of the IGIS as a (largely classified) oversight mechanism for intelligence surveillance.
Contributed to legislative reforms including the Intelligence Services Act 2001 amendments and the establishment of the Parliamentary Joint Committee on Intelligence and Security's enhanced review powers.

---

### Case 10.42: Anuradha Bhasin v. Union of India (2020) —Supreme Court of India

**Date Decided:** January 10, 2020

**Court:** Supreme Court of India

**Facts:** Following the abrogation of Article 370 and the reorganization of Jammu and Kashmir in August 2019, the Government of India imposed an unprecedented internet shutdown across the region, which lasted for several months. Anuradha Bhasin, executive editor of the Kashmir Times, and others challenged the shutdown, arguing it violated the right to freedom of speech and expression (Article 19) and the right to carry on any trade or business (Article 19(1)(g)) under the Indian Constitution.

**Issue:** Whether the government's internet shutdown in Jammu and Kashmir was proportionate and lawful, and whether it violated fundamental rights under Articles 19 and 21 of the Constitution.

**Holding:** The Supreme Court held that internet access is a fundamental right under Article 19(1)(a) (freedom of expression) and that any restriction on internet access must be proportionate, temporary, and subject to judicial review. The Court directed the government to publish all orders restricting internet access and to ensure that restrictions are subject to periodic review. The Court did not immediately restore internet access but required the government to reconsider within a specified timeframe.
**Significance:** First Supreme Court of India decision to recognize internet access as a fundamental right integral to freedom of expression.
Established that internet shutdowns are subject to the proportionality test and require transparency and judicial review.
Became the leading Indian authority on digital rights, cited in subsequent challenges to internet shutdowns and content blocking orders across India.

---

### Case 10.43: Faheem Shirurkay v. State of Karnataka (2021) —High Court of Karnataka

**Date Decided:** September 30, 2021

**Court:** High Court of Karnataka, India

**Facts:** Faheem Shirurkay, a social media user, was investigated by Karnataka police for his online posts. During the investigation, police obtained his social media data and metadata directly from platforms without prior judicial authorization. Shirurkay challenged the surveillance, arguing that the collection of his digital communications data without a warrant violated his right to privacy under Article 21 of the Indian Constitution, as recognized in K.S. Puttaswamy v. Union of India (2017).

**Issue:** Whether law enforcement may obtain a person's social media data and digital communications metadata without prior judicial authorization, and whether such collection violates the right to privacy under Article 21 of the Constitution.

**Holding:** The High Court held that the right to privacy extends to digital communications and social media data. The Court found that obtaining such data without prior judicial authorization violated Article 21, requiring law enforcement to obtain a court order before accessing an individual's private digital communications. The Court distinguished between publicly available social media posts and private messages/metadata.
**Significance:** Applied the Puttaswamy privacy framework to the specific context of law enforcement access to social media data.
Established a judicial authorization requirement for police access to private digital communications in Karnataka.
Added to the growing body of Indian jurisprudence requiring proportionality and procedural safeguards in digital surveillance.

---

### Case 10.44: ADIn 5496 —WhatsApp Access Case (2020) —Supreme Federal Tribunal of Brazil (STF)

**Date Decided:** August 11, 2020

**Court:** Supreme Federal Tribunal (Supremo Tribunal Federal, STF)

**Facts:** The Brazilian Bar Association (OAB) filed an Arguio de Descumprimento de Preceito Fundamental (ADPF, Argument of Non-Compliance with a Fundamental Precept) challenging provisions requiring WhatsApp and other messaging platforms to provide decrypted content to law enforcement. The case concerned whether the state could compel technology companies to build backdoors into their encryption systems or provide decrypted user communications.

**Issue:** Whether mandatory disclosure of decrypted user communications by encrypted messaging platforms, without the platform having access to the content, violates the fundamental rights to privacy and intimacy under the Brazilian Constitution.

**Holding:** The STF (by majority) held that while the state has a legitimate interest in investigating crimes, it cannot compel technology companies to provide decrypted content that they do not possess. The Court recognized that end-to-end encryption means the platform has no access to user content, and compelling backdoor access would undermine the privacy of all users. However, the Court allowed for metadata collection under judicial order.
**Significance:** First major supreme court ruling globally to address the legality of compelling backdoor access to end-to-end encrypted communications.
Rejected the "going dark" framing by recognizing that the technical impossibility of decryption by the platform means no lawful obligation exists.
Balanced law enforcement needs against the fundamental right to privacy, permitting targeted metadata requests while protecting the integrity of encryption.

---

### Case 10.45: Inquérito 4781 (Fake News Inquiry) —Follow-On Proceedings (2021–2023) —Supreme Federal Tribunal of Brazil (STF)

**Date Decided:** Various orders from 2021–2023

**Court:** Supreme Federal Tribunal (Supremo Tribunal Federal, STF)

**Facts:** Following the initiation of Inquérito 4781 in 2019 to investigate the dissemination of false information ("fake news") and threats against democratic institutions, the STF expanded its investigative scope to include requests for user data from social media platforms, messaging services, and internet companies. Multiple parties challenged the breadth of the investigation, arguing that the STF was exceeding its authority and conducting mass surveillance of political speech.

**Issue:** Whether the STF's investigative powers in Inquérito 4781, including requests for bulk user data from technology companies, were constitutionally permissible, and whether they violated rights to privacy, free expression, and due process.

**Holding:** The STF maintained its authority to conduct the investigation but narrowed some of the data requests following challenges. Individual justices issued conflicting orders, with some limiting data production to specific accounts under investigation and others allowing broader data requests. The inquiry resulted in several arrests and indictments but faced sustained criticism for its scope and procedural irregularities.
**Significance:** Exemplified the tension between combating disinformation and protecting civil liberties in a major democracy.
Raised fundamental questions about judicial investigative authority and separation of powers in the digital age.
Became a cautionary case study internationally regarding the risks of broad government investigations into online speech.

---

### Case 10.46: STF Wiretapping Rules —HC 98.742 / ADI 5.512 (2022) —Supreme Federal Tribunal of Brazil

**Date Decided:** March 9, 2022

**Court:** Supreme Federal Tribunal (Supremo Tribunal Federal, STF)

**Facts:** The STF addressed multiple petitions challenging the scope and constitutionality of wiretapping and electronic surveillance under the Brazilian Wiretapping Law (Law 9.296/1996) and the Marco Civil da Internet (Law 12.965/2014). Petitioners argued that the law's procedural requirements for wiretap authorization were insufficient and that the broad scope of permitted surveillance violated constitutional privacy protections.

**Issue:** Whether Brazil's wiretapping and electronic surveillance framework provides adequate constitutional protections for the right to privacy, intimacy, and due process under Articles 5(X) and 5(XII) of the Federal Constitution.

**Holding:** The STF reaffirmed that all wiretapping and electronic surveillance requires prior judicial authorization based on concrete evidence, not mere suspicion. The Court strengthened procedural safeguards, including requirements for: (1) detailed justification of the necessity of the interception; (2) time-limited authorizations subject to periodic judicial review; (3) strict minimization and destruction of irrelevant data; and (4) notification of the surveilled party after the investigation concludes.
**Significance:** Strengthened the procedural framework for electronic surveillance in Brazil by imposing strict judicial oversight requirements.
Aligned Brazilian wiretapping practice with the constitutional right to privacy and international human rights standards.
Established minimization and data destruction as mandatory elements of lawful surveillance in Brazil.

---

### Case 10.47: Minister of Police v. Mlungwana (2018) —Constitutional Court of South Africa

**Date Decided:** November 22, 2018

**Court:** Constitutional Court of South Africa

**Facts:** Emmanuel Mlungwana was arrested during a police operation in Khayelitsha, Cape Town, and charged with public violence. He challenged the constitutionality of sections of the Regulation of Gatherings Act, which effectively prohibited gatherings without prior police approval, rather than requiring police to obtain a court order to prohibit a gathering. The case raised broader questions about state surveillance and monitoring of public assemblies.

**Issue:** Whether the Regulation of Gatherings Act's provisions were consistent with the right to freedom of assembly (Section 17), the right to freedom of expression (Section 16), and the right to privacy (Section 14) of the South African Constitution.

**Holding:** The Constitutional Court (unanimously) declared the impugned provisions unconstitutional and invalid. The Court held that the right to assemble, demonstrate, and picket is fundamental and that the state bears the burden of justifying any restriction. The Court emphasized that police monitoring and surveillance of public gatherings must be subject to constitutional limitations.
**Significance:** Reinforced South Africa's robust privacy framework under Section 14 of the Constitution in the context of public assembly and state surveillance.
Established that the state must justify surveillance and monitoring of citizens exercising constitutional rights, rather than placing the burden on citizens to justify their actions.
Contributed to the broader jurisprudence on the intersection of privacy rights, freedom of assembly, and state security in South Africa.

---

### Case 10.48: Privacy Rights under the South African Constitution —CAMA & Related Surveillance Framework Challenges (Various, 2019–2023)

**Date Decided:** Various, 2019–2023

**Court:** Various South African courts, including the Constitutional Court and High Courts

**Facts:** Multiple cases challenged the constitutional validity of South Africa's surveillance framework, including the Regulation of Interception of Communications and Provision of Communication-Related Information Act (RICA, 2002). Civil society organizations, including the Right2Know Campaign and the amaBhungane Centre for Investigative Journalism, argued that RICA's authorization of bulk interception and metadata retention violated Section 14 (privacy) of the Constitution. Cases also addressed the lack of notification requirements and insufficient judicial oversight.

**Issue:** Whether RICA's surveillance provisions, including bulk data collection and the absence of post-surveillance notification, are consistent with the right to privacy under Section 14 and the right of access to information under Section 32 of the South African Constitution.

**Holding:** In amaBhungane Centre for Investigative Journalism v. Minister of Justice (2021), the Constitutional Court struck down several provisions of RICA as unconstitutional, including the absence of post-surveillance notification to affected individuals and the failure to adequately protect journalistic privilege. The Court ordered Parliament to amend RICA within specified timeframes to address these deficiencies.
**Significance:** Brought South Africa's surveillance law into compliance with constitutional privacy standards, including the right to be informed after being subjected to surveillance.
Established that surveillance legislation must specifically protect journalistic sources and communications.
Demonstrated the critical role of civil society litigation in holding surveillance regimes accountable under constitutional democracy.

---

### Case 10.49: Association for Civil Rights in Israel (ACRI) v. Knesset —Follow-On Challenges (2012–2020) —Supreme Court of Israel

**Date Decided:** Various decisions from 2012–2020

**Court:** Supreme Court of Israel (sitting as the High Court of Justice)

**Facts:** Following the initial ACRI v. Knesset challenges to Israel's surveillance laws, the Association for Civil Rights in Israel brought follow-on petitions challenging the implementation of the Communications Data Law (2012) and the Intelligence Services Law (1979). These challenges addressed the practical operation of Israel's communications data retention regime, the lack of judicial oversight for security service access to retained data, and the adequacy of safeguards against abuse.

**Issue:** Whether the implementation of Israel's communications data retention and access regime, as operated by the security services, satisfied constitutional requirements for privacy protection and judicial oversight.

**Holding:** The Supreme Court issued several decisions requiring enhanced safeguards, including: (1) mandatory periodic reporting to the Knesset's Intelligence and Security Subcommittee on the scope and use of retained data; (2) the establishment of a supervisory committee to oversee security service access to communications data; and (3) restrictions on the purposes for which retained data may be accessed. However, the Court declined to strike down the data retention scheme entirely.
**Significance:** Demonstrated the incremental approach of the Israeli Supreme Court in constraining surveillance powers through mandatory oversight mechanisms rather than outright invalidation.
Highlighted the unique challenges of judicial review of security service surveillance in the context of ongoing security threats.
Contributed to the development of a multi-layered oversight framework for Israel's intelligence surveillance activities.

---

### Case 10.50: Peace Now v. Minister of Defense (2018) —Supreme Court of Israel

**Date Decided:** March 27, 2018

**Court:** Supreme Court of Israel (sitting as the High Court of Justice)

**Facts:** Peace Now, an Israeli non-governmental organization, petitioned the Supreme Court challenging the Israel Defense Forces' and the Shin Bet's use of surveillance technologies to monitor Palestinian civilians in the West Bank. The petition specifically addressed the deployment of facial recognition cameras, mobile phone interception, and social media monitoring, arguing that these practices violated international humanitarian law and the fundamental rights of the protected population.

**Issue:** Whether the IDF's and Shin Bet's use of surveillance technologies to monitor Palestinian civilians in the occupied territories was lawful under Israeli administrative law and international humanitarian law.

**Holding:** The Supreme Court dismissed the petition on procedural grounds, holding that the petitioners had not demonstrated standing with respect to specific individuals who had been surveilled. However, the Court observed that military surveillance must comply with applicable legal standards and directed the security services to review their surveillance practices.
**Significance:** Highlighted the legal vacuum surrounding military surveillance of protected populations in occupied territories under both Israeli and international law.
Exposed the limitations of domestic judicial review in addressing military surveillance practices in conflict zones.
Became a reference point for international human rights organizations challenging state surveillance in occupied and conflict-affected territories.

---

### Case 10.51: Bundesverfassungsgericht —Data Retention Case (2010) —Federal Constitutional Court of Germany

**Date Decided:** March 2, 2010

**Court:** Federal Constitutional Court of Germany (Bundesverfassungsgericht)

**Facts:** The German Parliament had enacted a data retention law in 2007 implementing the EU Data Retention Directive, requiring telecommunications providers to retain traffic data for ten weeks and location data for four weeks for law enforcement purposes. Nearly 35,000 citizens filed constitutional complaints. The complainants argued that the blanket retention of communications metadata violated their right to informational self-determination (informationelle Selbstbestimmung) under Article 2(1) in conjunction with Article 1(1) of the Basic Law.

**Issue:** Whether the blanket, indiscriminate retention of telecommunications traffic and location data for law enforcement purposes was compatible with the fundamental right to informational self-determination under the German Basic Law.

**Holding:** The Federal Constitutional Court struck down the data retention law as unconstitutional. The Court held that blanket data retention was a severe intrusion into the fundamental right to informational self-determination. The Court emphasized that the retention of data creates a "pressing sense of being watched" that chills free expression and free association. The Court required that any data retention law include: (1) clear data storage limitations; (2) strict data access controls; (3) transparency requirements; and (4) effective independent oversight.
**Significance:** Established the principle that blanket data retention is per se disproportionate under German constitutional law, influencing courts across Europe.
Developed the concept of the "chilling effect" as a constitutional harm arising from mass data retention.
Prompted the CJEU's Digital Rights Ireland (2014) decision, which adopted a similarly strict approach under EU law.

---

### Case 10.52: Bundesverfassungsgericht —Data Retention II (2020) —Federal Constitutional Court of Germany

**Date Decided:** May 19, 2020

**Court:** Federal Constitutional Court of Germany (Bundesverfassungsgericht)

**Facts:** In 2017, the German Parliament enacted a new data retention law after the 2010 judgment, requiring telecommunications providers to retain traffic data for ten weeks and location data for four weeks. The new law included additional safeguards, including a requirement that data access be restricted to serious crimes and subject to judicial authorization. Civil liberties organizations challenged the new law, arguing that it still constituted impermissible blanket surveillance.

**Issue:** Whether the revised 2017 data retention law, with its enhanced safeguards, satisfied the constitutional requirements established in the 2010 judgment, particularly regarding the proportionality of blanket data retention.

**Holding:** The Federal Constitutional Court struck down the 2017 law as unconstitutional. While acknowledging the improved safeguards, the Court held that the law still failed to meet the proportionality requirement because: (1) the data categories retained were too broad; (2) the list of qualifying offenses was not sufficiently narrowly defined; (3) there were inadequate safeguards against access by intelligence agencies; and (4) independent oversight was insufficient.
**Significance:** Demonstrated the extreme difficulty of crafting a constitutionally compliant data retention law in Germany, with two major statutes struck down in a decade.
Reinforced that enhanced safeguards alone cannot cure the fundamental disproportionality of indiscriminate data collection.
Further solidified Germany's position as having the strictest judicial standards for communications data retention in the world.

---

### Case 10.53: Council of State (Conseil d'tat) —Data Retention Decision (2022) —Conseil d'tat, France

**Date Decided:** June 16, 2022

**Court:** Conseil d'tat (Council of State), France

**Facts:** La Quadrature du Net and other digital rights organizations challenged the French data retention framework under the Code des postes et des communications électroniques, which required telecommunications operators to retain traffic and location data for one year for national security and law enforcement purposes. The organizations argued that the framework violated the right to privacy and the right to protection of personal data under the EU Charter of Fundamental Rights and the CJEU's rulings in Tele2 Sverige and Digital Rights Ireland.

**Issue:** Whether France's data retention framework was compatible with EU law, particularly the requirements established by the CJEU for proportionate, targeted, and adequately safeguarded data retention.

**Holding:** The Conseil d'tat found that certain aspects of the French data retention framework were compatible with EU law, particularly where access to retained data was subject to prior judicial or administrative authorization for the investigation of serious offenses. However, the Council identified deficiencies in the framework, particularly regarding the breadth of the data categories retained and the adequacy of safeguards against abuse, and ordered the government to amend the framework to ensure full compliance with EU law.
**Significance:** Reflected the ongoing tension between national security imperatives and EU-level privacy standards in France.
Demonstrated the Conseil d'tat's role as an active enforcer of CJEU privacy standards within the French legal system.
Prompted further legislative amendments to France's data retention framework to address the identified deficiencies.

---

### Case 10.54: Garante per la protezione dei dati personali —Surveillance Cases (Various, 2015–2023) —Italian Data Protection Authority

**Date Decided:** Various decisions from 2015–2023

**Court:** Garante per la protezione dei dati personali (Italian Data Protection Authority)

**Facts:** The Italian Data Protection Authority (Garante) investigated multiple instances of unlawful government surveillance, including: (1) the use of Hacking Team's spyware by law enforcement without adequate legal basis; (2) excessive communications data retention by the intelligence services; (3) the deployment of IMSI catchers (cell-site simulators) without judicial authorization; and (4) intelligence service access to retained metadata beyond the scope permitted by law.

**Issue:** Whether the Italian intelligence and law enforcement agencies' surveillance practices complied with Italian data protection law, the EU Charter of Fundamental Rights, and the requirements established by the CJEU.

**Holding:** The Garante issued multiple enforcement decisions finding violations of Italian and EU data protection law. The Authority ordered the cessation of unlawful surveillance activities, the deletion of improperly collected data, and the implementation of robust technical and organizational safeguards. The Garante also referred several cases to the Italian Parliament for legislative reform, recommending stricter authorization requirements and enhanced oversight.
**Significance:** Demonstrated the critical role of data protection authorities as independent oversight bodies for government surveillance in EU member states.
Exposed the prevalence of unlawful surveillance technologies, including commercial spyware and IMSI catchers, in a major EU member state.
Contributed to Italy's reform of its intelligence surveillance framework, including the 2017 reform of Law 124/2007 on intelligence services.

---

### Case 10.55: Spanish Data Retention —CNPJ Framework Challenge (2021) —Constitutional Court of Spain (Tribunal Constitucional)

**Date Decided:** November 11, 2021

**Court:** Constitutional Court of Spain (Tribunal Constitucional)

**Facts:** Following the CJEU's landmark judgment in Tele2 Sverige (2016), which struck down blanket data retention as incompatible with EU law, the Spanish framework for data retention under the Ley 25/2007 (on the retention of data relating to electronic communications and public communications networks) was challenged before the Spanish courts. Multiple cases reached the Constitutional Court, arguing that Spain's continued retention of blanket telecommunications metadata was unconstitutional.

**Issue:** Whether Spain's data retention framework, which required blanket retention of telecommunications metadata for twelve months, was compatible with the right to privacy and personal data protection under the Spanish Constitution and EU law.

**Holding:** The Constitutional Court held that Spain's blanket data retention framework was unconstitutional. The Court found that the indiscriminate retention of all users' communications metadata, without differentiation based on the seriousness of the crime or individualized suspicion, was disproportionate. The Court required that any future data retention scheme must include: (1) differentiation based on the seriousness and nature of offenses; (2) a requirement of prior judicial authorization; (3) time-limited retention periods; and (4) strict data security and access controls.
**Significance:** Brought Spain into compliance with the CJEU's Tele2 Sverige and Digital Rights Ireland rulings, requiring fundamental reform of Spanish data retention practices.
Established that the Spanish Constitution provides even greater protection for communications privacy than the minimum standards required by EU law.
Joined Germany and other EU member states in rejecting blanket data retention as a disproportionate intrusion into fundamental rights.
End of Part Ten Additional Cases (10.26—0.55)

---

### Case 10.56: Lavabit v. United States (2013–2014) —Fourth Circuit Court of Appeals

**Date Decided:** 2014

**Court:** U.S. Court of Appeals for the Fourth Circuit

**Facts:** Lavabit was a secure email service founded by Ladar Levison, notable for being used by Edward Snowden. In 2013, the US government served Lavabit with an order under the Stored Communications Act (SCA) to produce Snowden's email metadata and SSL encryption keys that would enable real-time surveillance of all Lavabit users. Levison complied partially but challenged the breadth of the order. Rather than compromise all users' security, Levison shut down Lavabit and appealed.

**Issue:** Whether the government could compel Lavabit to produce its SSL encryption keys (effectively enabling surveillance of all users) under the SCA and whether the order violated the Fourth Amendment.

**Holding:** The Fourth Circuit dismissed the appeal on standing and mootness grounds after the government modified its demand and Lavabit had already ceased operations. The court did not reach the merits of whether the broad key disclosure order violated constitutional protections. Lavabit remained shut down, and the case became a symbol of resistance to government surveillance overreach.
**Significance:** Became a landmark reference point in debates about encryption backdoors, government compelled disclosure of cryptographic keys, and the tension between surveillance authority and user privacy.
Influenced subsequent legislative and judicial developments regarding government access to encrypted communications, including the "going dark" debate.

---

### Case 10.57: Smith v. Maryland (1979) —Supreme Court of the United States

**Date Decided:** June 1979

**Court:** Supreme Court of the United States

**Facts:** Without a warrant, police installed a pen register at a telephone company's central office to record the numbers dialed from the home of Michael Lee Smith, who was suspected of robbery. The pen register recorded only the numbers dialed, not the content of conversations. Smith was convicted based in part on this evidence and challenged the warrantless surveillance under the Fourth Amendment.

**Issue:** Whether the installation and use of a pen register to record telephone numbers dialed constitutes a "search" under the Fourth Amendment requiring a warrant.

**Holding:** In a 5— decision, the Supreme Court held that Smith had no reasonable expectation of privacy in the numbers he dialed, because he voluntarily conveyed that information to the telephone company when placing calls. The Court held that the use of a pen register was not a "search" under the Fourth Amendment and did not require a warrant.
**Significance:** Established the third-party doctrine, which holds that individuals have no reasonable expectation of privacy in information voluntarily disclosed to third parties (such as telecom providers).
The third-party doctrine has been progressively narrowed by subsequent decisions (Carpenter v. United States, 2018) but remains influential in determining the scope of Fourth Amendment protection for digital communications metadata.

---

### Case 10.58: United States v. Jones (2012) —Supreme Court of the United States

**Date Decided:** January 2012

**Court:** Supreme Court of the United States

**Facts:** Without a valid warrant, law enforcement officers attached a GPS tracking device to Antoine Jones' vehicle and monitored its movements for 28 days, collecting extensive location data. Jones was convicted of drug conspiracy based in part on this surveillance. Jones challenged the GPS monitoring as a Fourth Amendment violation.

**Issue:** Whether the warrantless attachment of a GPS tracking device to a vehicle and prolonged monitoring of its movements constitutes a "search" under the Fourth Amendment.

**Holding:** In a unanimous decision, the Supreme Court held that the government's physical intrusion on Jones' vehicle for the purpose of obtaining information constituted a "search" under the Fourth Amendment. While the majority relied on a property-based trespass theory, concurrences by Justices Sotomayor and Alito explored broader privacy concerns regarding long-term digital surveillance.
**Significance:** Marked a turning point in Fourth Amendment jurisprudence regarding digital surveillance, establishing that physical intrusion for surveillance purposes constitutes a search.
Justice Sotomayor's concurrence questioning the continuing viability of the third-party doctrine in the digital age proved particularly influential in subsequent cases, including Carpenter v. United States.

---

### Case 10.59: R v. Spencer (2014) —Supreme Court of Canada

**Date Decided:** June 2014

**Court:** Supreme Court of Canada

**Facts:** Police obtained Matthew Spencer's subscriber information (name, address, and IP address records) from his Internet service provider without a warrant, relying on a provision of the Personal Information Protection and Electronic Documents Act (PIPEDA) that allowed disclosure to law enforcement. Spencer was subsequently charged with possession of child pornography. He challenged the warrantless disclosure of his subscriber information as a violation of his Section 8 Charter right against unreasonable search and seizure.

**Issue:** Whether an individual has a reasonable expectation of privacy in their basic subscriber information held by an ISP, and whether law enforcement must obtain a warrant to access such information.

**Holding:** The Supreme Court of Canada held unanimously that individuals do have a reasonable expectation of privacy in their ISP subscriber information, and that police must obtain a warrant (or a warrant-equivalent authorization) to compel disclosure of this information. The Court held that the PIPEDA provision did not authorize warrantless disclosure to law enforcement.
**Significance:** Established that basic subscriber information is protected by Section 8 of the Canadian Charter, rejecting the broad third-party doctrine applied in US law under Smith v. Maryland.
Provided a privacy-protective standard that influenced subsequent Canadian cases and positioned Canada as a leader in recognizing privacy interests in digital metadata.

---

### Case 10.60: City of Lakewood v. Plainfield (2020) —Supreme Court of the United States

**Date Decided:** June 2020

**Court:** Supreme Court of the United States

**Facts:** The City of Lakewood, New Jersey, passed an ordinance allowing police to impound vehicles parked on public streets when the registered owner had unpaid fines, and requiring the vehicle owner to pay outstanding fines plus towing and storage fees to retrieve the vehicle. Plainfield, represented by the Institute for Justice, challenged the ordinance as a violation of due process, arguing that vehicle owners were not given adequate notice or opportunity to be heard before deprivation of property. (Note: This case is also known for broader implications regarding government processes and property rights, including digital due process dimensions discussed in concurrences.)

**Issue:** Whether the City's impoundment and forfeiture procedures violated the Due Process Clause of the Fourteenth Amendment, and what procedural safeguards are required before the government may deprive an individual of property.

**Holding:** The Supreme Court reversed the Third Circuit, holding that the City's procedures did not provide adequate pre-deprivation or timely post-deprivation due process. The Court emphasized that property owners must have a meaningful opportunity to challenge government action before or shortly after deprivation.
**Significance:** While primarily a property rights case, the decision reinforced principles of procedural due process that extend to digital contexts, including government access to and deprivation of digital property and data.
The Court's emphasis on meaningful notice and opportunity to be heard has been cited in subsequent discussions about digital surveillance notification requirements and government data seizure practices.
Part 11: Cross-Border Data Flows & Jurisdictional Conflicts

---

### Case 10.61: AI Surveillance Expansion in China (2023-2024) —Chinese Government / Legislative Developments

**Date Decided:** 2023-2024

**Court:** Standing Committee of the National People's Congress (legislation); Ministry of Public Security (implementation); CAC (regulatory coordination)

**Facts:** China significantly expanded its AI-powered surveillance infrastructure during 2023-2024, integrating facial recognition, behavioral analysis, and predictive policing technologies across urban and rural areas. The State Council issued guidelines on the governance of generative AI (the "Interim Measures for the Management of Generative Artificial Intelligence Services"), while local governments deployed AI surveillance systems for public safety, social credit monitoring, and pandemic response. Reports documented the use of AI surveillance targeting specific ethnic minorities, political dissidents, and religious groups.

**Issue:** Whether the expanded AI surveillance apparatus complied with China's domestic legal framework, including the Personal Information Protection Law (PIPL), and whether these practices violated international human rights obligations under the International Covenant on Civil and Political Rights (ICCPR).

**Holding:** Domestically, the Chinese government maintained that AI surveillance was lawful under national security and public safety exceptions in the PIPL and related legislation. The Interim Measures required generative AI services to "adhere to the core socialist values" and undergo security assessments. Internationally, UN human rights experts and multiple governments condemned the surveillance expansion as violating fundamental rights to privacy, freedom of expression, and non-discrimination.
**Significance:** Represented the most extensive deployment of AI-powered surveillance technology by any single government, establishing precedents for the scope of state monitoring capabilities in the digital age.
Highlighted the tension between the PIPL's nominal privacy protections and broad national security and public interest exceptions that effectively permit unlimited government surveillance.
Served as a global reference point for debates on AI ethics, export controls for surveillance technology, and the human rights implications of algorithmic governance.

---

### Case 10.62: Kazakhstan Internet Shutdown During Protests (2022) —Government of Kazakhstan

**Date Decided:** January 2022

**Court:** Government of Kazakhstan (executive action); subsequent legislative review

**Facts:** In January 2022, during widespread protests against fuel price increases that escalated into broader anti-government demonstrations, the Government of Kazakhstan ordered a near-total internet shutdown affecting approximately 85% of connectivity. The shutdown lasted several days and included blocking of social media platforms, messaging applications, and independent news sources. The government cited national security concerns and the need to prevent the spread of misinformation during the state of emergency.

**Issue:** Whether the internet shutdown was a proportionate and necessary measure under Kazakhstan's constitutional framework and international human rights law, and what legal remedies were available to affected individuals and businesses.

**Holding:** The internet was restored after several days following international pressure and domestic economic disruption. The government subsequently enacted amendments to telecommunications law providing broader authority for internet restrictions during states of emergency. Civil society organizations challenged the shutdown's legality, arguing it violated constitutional rights to freedom of expression and access to information.
**Significance:** Demonstrated the increasing use of internet shutdowns as a tool of government control during civil unrest, contributing to a global trend documented by digital rights organizations.
Highlighted the severe economic consequences of internet shutdowns, including estimated losses of hundreds of millions of dollars to Kazakhstan's digital economy and international business operations.
Illustrated the limitations of legal frameworks that provide broad executive authority for telecommunications restrictions during emergencies without adequate judicial oversight or proportionality requirements.

---

### Case 10.63: Myanmar Cyber Law and Digital Authoritarianism (2021-2024) —Military Junta / International Bodies

**Date Decided:** 2021-2024 (ongoing)

**Court:** Myanmar military junta (executive orders and military tribunal proceedings); International Court of Justice (ICJ) proceedings; UN Human Rights Council

**Facts:** Following the February 2021 military coup, Myanmar's ruling junta implemented extensive cyber repression measures including internet shutdowns in conflict zones, surveillance of digital communications, prosecution of online expression under the Electronic Transactions Law and cybersecurity provisions, and blocking of independent media and social media platforms. The junta enacted the 2021 Cybersecurity Law requiring data localization, granting surveillance authority, and imposing criminal penalties for online dissent. UN investigators documented systematic digital rights violations including targeted surveillance of activists, journalists, and ethnic minority communities.

**Issue:** Whether the junta's cyber repression measures violated international human rights law and whether the international community had legal obligations to respond, including under the Genocide Convention.

**Holding:** Domestically, military tribunals imposed lengthy prison sentences on individuals for online expression. Internationally, the ICJ continued proceedings on alleged genocide, with digital repression forming part of the evidentiary record. The UN Human Rights Council established investigative mechanisms documenting digital rights violations. Several states imposed sanctions targeting Myanmar's surveillance technology procurement.
**Significance:** Represents one of the most comprehensive cases of digital authoritarianism in the 2020s, demonstrating how military regimes weaponize cybersecurity law and internet control to suppress dissent.
Highlighted the role of foreign surveillance technology providers in enabling digital repression, raising questions about corporate complicity and export control responsibilities.
Illustrated the gap between international human rights norms and enforcement mechanisms, with limited practical accountability for digital rights violations in conflict and authoritarian contexts.

---

### Case 10.64: Belarus Internet Shutdown and Digital Repression (2020-2024) —Government of Belarus / European Court of Human Rights

**Date Decided:** 2020-2024 (ongoing)

**Court:** Government of Belarus (executive actions); European Court of Human Rights (ECtHR); UN Human Rights Council

**Facts:** Following the disputed August 2020 presidential election, the Government of Belarus engaged in sustained digital repression including multi-day internet shutdowns during peak protests, blocking of independent news websites and social media platforms, and deployment of surveillance technologies to track and detain protesters. The government mandated the use of Belarusian state-controlled internet infrastructure (the "Belarusian Cloud") and required online platforms to store data locally and register with authorities. Multiple journalists and activists were prosecuted for online expression under criminal defamation and "extremism" provisions.

**Issue:** Whether Belarus's internet shutdowns and digital repression measures violated the European Convention on Human Rights (ECHR), to which Belarus is a party, and what legal remedies were available through international mechanisms.

**Holding:** The ECtHR found Belarus in violation of multiple ECHR articles, including Article 10 (freedom of expression) and Article 11 (freedom of assembly), for its internet restrictions and prosecution of online speech. The court ordered interim measures requiring Belarus to restore internet access during specific periods. The EU imposed sanctions targeting Belarusian officials and entities responsible for digital repression. Belarus failed to comply with most ECtHR orders.
**Significance:** Established ECtHR precedent that government-ordered internet shutdowns constitute violations of fundamental rights under the European Convention, even when justified by national security claims.
Demonstrated the limited effectiveness of international judicial mechanisms when the respondent state refuses to comply with court orders, highlighting enforcement gaps in the international human rights system.
Contributed to the development of international norms recognizing internet access as a fundamental right, with internet shutdowns subject to strict proportionality requirements.

---

### Case 10.65: Cuba Internet Restrictions and Digital Access (2022-2023) —Government of Cuba / International Bodies

**Date Decided:** 2022-2023

**Court:** Government of Cuba (regulatory measures); UN Human Rights Council; Inter-American Commission on Human Rights (IACHR)

**Facts:** Cuba maintained one of the most restricted internet environments in the Americas during 2022-2023, with the government controlling the primary internet access infrastructure through the state telecommunications monopoly ETECSA. Following widespread anti-government protests in July 2021 that were partly organized through social media, the Cuban government intensified restrictions on internet access, blocked VPN services and social media platforms during politically sensitive periods, and enacted Decree Law 35/2021 regulating online speech with criminal penalties for spreading "false information." Independent journalists and activists reported systematic surveillance and intimidation for online activities.

**Issue:** Whether Cuba's internet restrictions and Decree Law 35/2021 violated international human rights obligations, including freedom of expression and access to information under the ICCPR and the American Convention on Human Rights.

**Holding:** The IACHR granted precautionary measures for journalists and activists facing digital persecution. The UN Special Rapporteur on freedom of expression condemned Cuba's internet restrictions and called for the repeal of Decree Law 35/2021. Cuba defended its restrictions as necessary for national sovereignty and defense against "cyber warfare" by foreign adversaries. No domestic judicial remedy was available for challenging internet restrictions.
**Significance:** Illustrated how governments in the Americas use cybersecurity and misinformation legislation as pretexts for suppressing online dissent and controlling digital discourse.
Highlighted the particular vulnerability of small-island developing states' internet infrastructure to government control due to limited infrastructure redundancy and state monopoly over telecommunications.
Contributed to the Inter-American human rights system's evolving jurisprudence on digital rights, including recognition of internet access as a necessary condition for the exercise of fundamental freedoms.
---

### Case 10.66: Digital Rights Watch v. Australian Government (2024) — Australian Federal Court

**Date Decided:** 2024

**Court:** Federal Court of Australia

**Facts:** Digital rights advocacy groups challenged the Australian government's expanded surveillance powers under the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (the "Encryption Act"), which requires technology companies to provide assistance to law enforcement in accessing encrypted communications.

**Issue:** Whether the Encryption Act's technical capability notices and technical assistance requests are compatible with the implied right to privacy under the Australian Constitution and international human rights obligations.

**Holding:** The Federal Court upheld the Act, finding that parliamentary supremacy and national security considerations outweighed the privacy concerns raised by the applicants. Leave to appeal was granted to the High Court.
**Significance:** Represents the leading judicial challenge to government powers to compel decryption assistance from technology companies.
Sets important precedent for the balance between national security surveillance and privacy rights in the Australian common law tradition.
The High Court appeal may establish constitutional limits on surveillance legislation.
-NoNewline

---

# Part 11 — Employment & Workplace Privacy
## Chapter 11: Digital Rights in Employment
The tension between employer authority and employee privacy in the digital workplace is among the most practically significant and jurisprudentially contested areas of cyber law. As work has migrated onto digital platforms — email, messaging applications, cloud storage, and networked devices — the capacity for employer surveillance has expanded exponentially, often outpacing the development of legal frameworks governing its limits. The two cases in this Part, decided by courts in fundamentally different legal traditions, illustrate how different jurisdictions have sought to balance the employer's legitimate interest in monitoring the use of its resources against the employee's right to privacy, confidentiality, and dignity in the workplace.


### Case 11.1: Bărbulescu v. Romania — Grand Chamber

**Date Decided:** 5 September 2017

**Court:** European Court of Human Rights (ECtHR), Grand Chamber — Application no. 61496/08

**Facts:** The applicant, Mr. Bogdan Mihai Bărbulescu, was employed by a private company in Romania as an engineer. In 2007, his employer asked him to set up a Yahoo Messenger account to communicate with clients. The employer's internal regulations stated that IT resources were to be used exclusively for professional purposes and prohibited the use of company equipment for personal purposes. The employer monitored the applicant's Yahoo Messenger communications over a period of approximately one week in July 2007 and discovered that the applicant had used the account to exchange personal messages with his brother and his fianc e. The employer presented transcripts of these personal messages as evidence in disciplinary proceedings, and the applicant was dismissed on the basis that he had violated the company's internal regulations.
Whether the employer's monitoring of the applicant's Yahoo Messenger communications constituted an interference with his right to respect for private life and correspondence under Article 8.
Whether that interference was "in accordance with the law," pursued a "legitimate aim," and was "necessary in a democratic society" — the three-part test established by Article 8(2).
Existence of an interference. The employer's monitoring of the applicant's electronic communications and the subsequent use of the transcripts in disciplinary proceedings constituted an interference with the applicant's right to respect for private life and correspondence under Article 8. This conclusion was not altered by the fact that the applicant had used a Yahoo Messenger account created at the employer's request and in the context of the employer's IT system. The Court emphasized that the employer's regulations had merely prohibited the "use of company computers for personal purposes" and had not specifically warned the employee that the content of his communications might be monitored.
Inadequate legal framework. The interference was not "in accordance with the law" within the meaning of Article 8(2). The Romanian courts had failed to determine whether the applicant had been notified in advance of the nature and extent of the monitoring, whether the monitoring was limited to the legitimate aim pursued, whether the reasons given by the employer to justify the monitoring were relevant and sufficient, and whether less intrusive measures could have been used instead. In particular, the domestic courts had not examined whether the employer had accessed the entire content of the applicant's communications or merely verified whether he had complied with his professional obligations.
Insufficient safeguards. The domestic courts had not established adequate safeguards to protect the employee against arbitrary interference with his private communications. While the employer had a legitimate interest in ensuring that its IT resources were used for professional purposes, the protection of employee privacy required that any monitoring be accompanied by clear, accessible, and sufficiently specific rules governing its scope and the conditions under which it might be undertaken.

**Issue:** The applicant brought a complaint before the European Court of Human Rights, alleging that his dismissal based on the monitoring of his private electronic communications constituted a violation of Article 8 of the European Convention on Human Rights (right to respect for private and family life, home, and correspondence). The central questions were: Whether the employer's monitoring of the applicant's Yahoo Messenger communications constituted an interference with his right to respect for private life and correspondence under Article 8. Whether that interference was "in accordance with the law," pursued a "legitimate aim," and was "necessary in a democratic society" — the three-part test established by Article 8(2).
**Holding:** The Grand Chamber held, by eleven votes to six, that there had been a violation of Article 8 of the Convention. The Court found: Existence of an interference. The employer's monitoring of the applicant's electronic communications and the subsequent use of the transcripts in disciplinary proceedings constituted an interference with the applicant's right to respect for private life and correspondence under Article 8. This conclusion was not altered by the fact that the applicant had used a Yahoo Messenger account created at the employer's request and in the context of the employer's IT system. The Court emphasized that the employer's regulations had merely prohibited the "use of company computers for personal purposes" and had not specifically warned the employee that the content of his communications might be monitored. Inadequate legal framework. The interference was not "in accordance with the law" within the meaning of Article 8(2). The Romanian courts had failed to determine whether the applicant had been notified in advance of the nature and extent of the monitoring, whether the monitoring was limited to the legitimate aim pursued, whether the reasons given by the employer to justify the monitoring were relevant and sufficient, and whether less intrusive measures could have been used instead. In particular, the domestic courts had not examined whether the employer had accessed the entire content of the applicant's communications or merely verified whether he had complied with his professional obligations. Insufficient safeguards. The domestic courts had not established adequate safeguards to protect the employee against arbitrary interference with his private communications. While the employer had a legitimate interest in ensuring that its IT resources were used for professional purposes, the protection of employee privacy required that any monitoring be accompanied by clear, accessible, and sufficiently specific rules governing its scope and the conditions under which it might be undertaken.
**Significance:** Clarification of Article 8's application in the employment context. The Grand Chamber's judgment represents the most authoritative statement by the European Court of Human Rights on the scope of Article 8 protections in the workplace. While the Court had previously recognized that Article 8 applies to employment relationships (see Halford v. the United Kingdom, 1997), the Bărbulescu judgment provides a detailed, structured framework for assessing the lawfulness of employer monitoring of electronic communications. The judgment makes clear that the employer's legitimate interests in monitoring do not displace the employee's Article 8 rights, and that the burden is on the state — through its domestic courts — to ensure that adequate safeguards are in place.
Requirement of advance notification and proportionality. The judgment establishes a set of minimum requirements that domestic courts must satisfy when adjudicating disputes involving employer monitoring of employee communications. These include: (a) whether the employee was notified in advance of the possibility of monitoring and the scope thereof; (b) the extent of monitoring (whether limited to professional communications or encompassing the entirety of the employee's electronic communications); (c) whether legitimate reasons for monitoring existed and were proportionate to the aim pursued; (d) whether less intrusive alternatives were available; and (e) the consequences of monitoring for the employee (whether transcripts were merely used to verify professional compliance or were examined for their substantive content). These requirements have been widely cited and applied by national courts and data protection authorities across Europe, and have significantly influenced the development of workplace monitoring policies under the EU General Data Protection Regulation (GDPR).
Distinction between professional and personal communications on work devices. The judgment rejected the employer's argument that the use of a work-created messaging account eliminated any expectation of privacy. The Court held that even where an employee uses a work-provided account, the employee does not entirely waive his right to privacy, particularly where the employer has not clearly communicated that the content — as opposed to the mere existence or volume — of communications will be monitored. This principle has profound implications for the ubiquitous practice of "bring your own device" (BYOD) policies and the blurring of professional and personal communication channels in the modern workplace.
Procedural obligations on domestic courts. A particularly significant aspect of the judgment is its emphasis on the procedural obligations of domestic courts. The Court found that the violation arose not merely from the employer's conduct but from the domestic courts' failure to conduct a sufficiently rigorous examination of whether the monitoring was proportionate and accompanied by adequate safeguards. This procedural dimension of the judgment underscores the principle that the protection of Convention rights depends not only on the substantive law but on the willingness and capacity of domestic courts to apply it rigorously.

---

### Case 11.2: Stengart v. Loving Care Agency, Inc.

**Date Decided:** 3 March 2010

**Court:** Supreme Court of New Jersey, 194 N.J. 54, 901 A.2d 408

**Facts:** The plaintiff, Marina Stengart, was the President and Director of Nursing of Loving Care Agency, Inc., a provider of home health care services. During the course of her employment, Stengart used her company-issued laptop to access her personal Yahoo email account in order to communicate with her attorneys regarding potential claims against Loving Care. Stengart did not save these emails on the laptop's hard drive; she accessed them through a web browser. When Stengart left the company, she returned the laptop. The company's technology manager later accessed the laptop, discovered cached copies of the emails in the laptop's temporary Internet files (the browser cache), and provided them to the company's attorneys. Loving Care's attorneys read the emails and used information from them in defending against Stengart's lawsuit, despite the fact that the emails were plainly marked as coming from Stengart's personal email account and were subject to attorney-client privilege.
Whether the employer violated the attorney-client privilege by reviewing and disclosing emails between an employee and her attorneys that were accessed through a personal webmail account on a company-issued computer.
Whether the employer's policy — which stated that emails and internet use on company equipment were not private and that the company reserved the right to review all communications — was sufficient to waive the employee's attorney-client privilege.
Attorney-client privilege was not waived. The Court held that Stengart did not waive the attorney-client privilege by accessing her personal webmail account on a company-issued laptop. The privilege protects confidential communications between a client and her attorney made for the purpose of seeking or providing legal advice. The fact that these communications were transmitted through a company-owned computer did not destroy the privilege. The Court emphasized that the employer's policy did not clearly state that personal webmail communications on company computers would be monitored, and certainly did not put the employee on notice that such communications would be stripped of attorney-client protection.
Employer policy was insufficient to destroy privilege. The Court rejected the employer's argument that its policy, which broadly stated that emails and internet use on company computers were not private, constituted a blanket waiver of all privileges. The Court distinguished between: (a) company email accounts, which the employer could reasonably expect to monitor; and (b) personal webmail accounts accessed through a company computer, which an employee could reasonably expect to remain private, particularly where the employer's policy did not specifically address such use. The Court noted that the policy's language was general and ambiguous, and did not clearly communicate to employees that personal communications through personal accounts would be subject to review.
Employer's attorneys violated ethical rules. The Court held that Loving Care's attorneys violated the Rules of Professional Conduct by reading and using the privileged communications. Upon discovering that the emails were subject to attorney-client privilege, the attorneys should have ceased their review and notified Stengart's counsel. Instead, they continued to read the emails and used the information in their representation of Loving Care.

**Issue:** The key legal issues were: Whether the employer violated the attorney-client privilege by reviewing and disclosing emails between an employee and her attorneys that were accessed through a personal webmail account on a company-issued computer. Whether the employer's policy — which stated that emails and internet use on company equipment were not private and that the company reserved the right to review all communications — was sufficient to waive the employee's attorney-client privilege.
**Holding:** The Supreme Court of New Jersey, in an opinion authored by Chief Justice Stuart Rabner, held: Attorney-client privilege was not waived. The Court held that Stengart did not waive the attorney-client privilege by accessing her personal webmail account on a company-issued laptop. The privilege protects confidential communications between a client and her attorney made for the purpose of seeking or providing legal advice. The fact that these communications were transmitted through a company-owned computer did not destroy the privilege. The Court emphasized that the employer's policy did not clearly state that personal webmail communications on company computers would be monitored, and certainly did not put the employee on notice that such communications would be stripped of attorney-client protection. Employer policy was insufficient to destroy privilege. The Court rejected the employer's argument that its policy, which broadly stated that emails and internet use on company computers were not private, constituted a blanket waiver of all privileges. The Court distinguished between: (a) company email accounts, which the employer could reasonably expect to monitor; and (b) personal webmail accounts accessed through a company computer, which an employee could reasonably expect to remain private, particularly where the employer's policy did not specifically address such use. The Court noted that the policy's language was general and ambiguous, and did not clearly communicate to employees that personal communications through personal accounts would be subject to review. Employer's attorneys violated ethical rules. The Court held that Loving Care's attorneys violated the Rules of Professional Conduct by reading and using the privileged communications. Upon discovering that the emails were subject to attorney-client privilege, the attorneys should have ceased their review and notified Stengart's counsel. Instead, they continued to read the emails and used the information in their representation of Loving Care.
**Significance:** Protection of attorney-client privilege in the digital workplace. The Stengart decision is the leading American authority on the preservation of attorney-client privilege in the context of personal communications conducted on employer-provided equipment. The Court's holding that a broadly worded employer computer-use policy does not automatically destroy the attorney-client privilege for personal webmail communications has been widely cited and followed by courts across the United States. The decision establishes that privilege depends on the reasonable expectations of the parties to the communication (the attorney and the client), not on the ownership of the physical device through which the communication is transmitted.
Distinction between employer systems and personal accounts. The Court's careful distinction between communications sent through an employer's own email system (which the employer may reasonably monitor) and communications sent through a personal webmail account accessed via a company computer (which carry a greater expectation of privacy) has become the foundational principle in American workplace privacy jurisprudence. This distinction recognizes the reality of the modern workplace, in which employees routinely access personal accounts on work devices and vice versa, and provides a principled basis for determining the applicability of legal protections such as privilege and privacy expectations.
Ethical obligations of employer's counsel. The Court's finding that the employer's attorneys violated professional ethics rules by reading and using the privileged communications has significant implications for the conduct of employment litigation. The decision serves as a warning to employers and their counsel that the mere discovery of potentially privileged materials on company equipment does not justify their examination. Upon encountering communications that appear to be privileged, counsel has an affirmative duty to cease review and notify the opposing party — a principle that has been reinforced by subsequent decisions and amendments to the American Bar Association's Model Rules of Professional Conduct.
Reasonableness standard for employer policies. The Stengart decision implicitly establishes a reasonableness standard for employer computer-use policies. An employer who wishes to reserve the right to monitor personal webmail communications on company equipment must do so with specificity and clarity; general statements about the non-private nature of company computer use are insufficient. This standard has prompted employers to revise their technology-use policies to include more explicit language about the monitoring of personal accounts on company devices, and has influenced the broader debate about the scope of employer surveillance in the digital age.
*The cases in this Part demonstrate that, across both European and American legal traditions, courts have recognized that the digital transformation of the workplace does not eliminate the fundamental rights of employees. While employers retain significant legitimate interests in monitoring the use of their resources, the scope of permissible monitoring is constrained by the right to privacy, the protection of legal professional privilege, and the requirement that surveillance be proportionate, transparent, and accompanied by adequate safeguards. As remote work, cloud computing, and AI-powered monitoring tools continue to reshape the employment relationship, the principles established in these cases will remain central to the ongoing negotiation between employer authority and employee dignity.

---

### Case 11.3: City of Ontario v. Quon (2010) — U.S. Supreme Court

**Date Decided:** 17 June 2010

**Court:** United States Supreme Court, 560 U.S. 746

**Facts:** The City of Ontario, California, provided its police officers with two-way alphanumeric pagers capable of sending and receiving text messages as part of an operational system for dispatch communications. The City's contract with the wireless provider included a monthly character limit; officers who exceeded the limit were required to pay the excess charges personally. Sergeant Jeff Quon and other officers routinely exceeded their monthly limits, and Quon was found to have sent a significant number of personal (including sexually explicit) text messages. At the request of Quon's supervisor, the City's IT department obtained a transcript of Quon's text messages from the wireless provider and audited them to determine whether the character limit was sufficient for legitimate work purposes and whether officers were using the devices for personal purposes. Quon filed a lawsuit alleging that the search of his text messages violated the Fourth Amendment.

**Issue:** Whether the City's review of an employee's text messages on a government-issued pager constituted an unreasonable search under the Fourth Amendment.

**Holding:** The Supreme Court held that the search was reasonable under the Fourth Amendment and did not violate Quon's rights. The Court emphasized that the search was motivated by a legitimate work-related purpose (assessing whether the pager character limit was adequate for operational needs) and was not excessively intrusive. However, the Court expressly declined to establish a broad rule for workplace privacy in the electronic communications context, cautioning that rapidly evolving technology made it "unwise" and "premature" to issue definitive guidance. The Court noted that the employer's review was limited in scope, that Quon had been warned that his messages could be audited, and that the search was designed to avoid reading personal messages in detail.
**Significance:** Narrow ruling with broad caution. The Supreme Court deliberately avoided creating a comprehensive framework for electronic workplace privacy, instead issuing a fact-specific, narrow holding. Justice Kennedy's opinion repeatedly warned that the rapid pace of technological change — including the advent of smartphones and cloud-based messaging — made it premature to adopt broad rules. This judicial restraint has left the development of electronic workplace privacy law primarily to lower courts, state legislatures, and regulators.
Reasonableness standard for government employers. The decision applies the Fourth Amendment's reasonableness standard to government-employer searches of employee electronic communications, recognizing that government employees retain some Fourth Amendment protections even in the workplace, but that these protections must be balanced against the employer's operational interests. This balancing test has been adopted by lower courts in cases involving email monitoring, GPS tracking, and keystroke logging.
Policy implications for BYOD and personal device use. Although Quon involved government-issued devices, the decision's reasoning has been cited extensively in private-sector cases involving employer monitoring of personal devices used for work purposes. The case highlights the difficulty of applying traditional property-based privacy frameworks to hybrid personal/professional communication environments.

---

### Case 11.4: Holmes v. Petrov (2016) — High Court of Australia

**Date Decided:** 11 November 2016

**Court:** High Court of Australia, [2016] HCA 38

**Facts:** Mr. Richard Holmes was employed by Tullett Prebon (Australia) Pty Ltd as a senior broker. After his employment was terminated, Holmes initiated proceedings alleging contravention of various provisions of the Fair Work Act 2009 (Cth). During the proceedings, Holmes applied for access to documents that his former employer had obtained through a covert surveillance operation. The employer had engaged a private investigator to secretly record conversations involving Holmes at a caf , without Holmes's knowledge or consent, in an effort to gather evidence about Holmes's post-termination conduct and potential competitive activities.

**Issue:** Whether the covert recording of an employee's (or former employee's) private conversations by a private investigator engaged by the employer constituted an unreasonable interference with the employee's privacy, and whether evidence obtained through such surveillance was admissible.

**Holding:** The High Court held that the covert surveillance was not unlawful under the applicable New South Wales legislation (the Surveillance Devices Act 2007 (NSW)), which primarily regulated the use of surveillance devices by public authorities rather than private parties in commercial contexts. However, the Court's reasoning highlighted the significant gap in Australian privacy law regarding workplace surveillance by private employers. The majority noted that while Australian common law has not recognized a general tort of invasion of privacy, the circumstances of covert workplace surveillance raise serious concerns about the adequacy of existing legal protections.
**Significance:** Exposure of gaps in Australian workplace privacy law. The decision exposed the inadequacy of Australian legal protections against covert employer surveillance. Unlike the EU, which provides robust protections under Article 8 ECHR and the GDPR, and the United States, which provides some Fourth Amendment protections for government employees, Australia lacked a comprehensive statutory framework governing private-sector workplace surveillance at the time. This decision contributed to the growing momentum for reform.
Catalyst for legislative reform. The Holmes case, together with the broader national conversation about workplace surveillance, contributed to the enactment of the Workplace Surveillance Act in the Australian Capital Territory and similar reforms in other jurisdictions. It also influenced the development of the Australian Privacy Principles under the Privacy Act 1988 (Cth) and the ongoing debate about whether Australia should adopt a statutory tort of invasion of privacy.
Evidentiary implications. The case raised important questions about the admissibility and ethical status of evidence obtained through covert surveillance in employment disputes, prompting courts to exercise greater scrutiny over the methods used by employers to gather evidence against employees.

---

### Case 11.5: Crisp v. Apple Retail (UK) Ltd (2011) — Employment Tribunal (UK)

**Date Decided:** 29 July 2011

**Court:** UK Employment Tribunal, Case No. 2202795/2010

**Facts:** Mr. Lee Crisp was employed by Apple Retail (UK) Ltd at its Regent Street store in London. Crisp posted critical comments about Apple's products and customer service on a private Facebook group that was accessible only to his Facebook friends. Apple discovered these comments, viewed them as a breach of its social media policy and the company's confidentiality requirements, and terminated Crisp's employment. Crisp brought a claim of unfair dismissal before the Employment Tribunal, arguing that his Facebook posts were private communications and that his dismissal was disproportionate.

**Issue:** Whether an employer's termination of an employee for critical comments posted on a private social media account constituted unfair dismissal.

**Holding:** The Employment Tribunal upheld Crisp's claim of unfair dismissal. The Tribunal found that Apple's social media policy was unclear about what constituted acceptable personal use of social media and that the dismissal was disproportionate given that the comments were made in a private forum (not publicly accessible) and did not identify Crisp as an Apple employee. The Tribunal criticized Apple for failing to follow its own disciplinary procedures and for imposing an excessively severe sanction without considering alternatives.
**Significance:** Recognition of private social media use. The decision established that employees have a reasonable expectation of privacy in social media communications that are restricted to personal networks, even where the employer has a social media policy. The Tribunal distinguished between public posts (which may legitimately subject the employee to disciplinary action) and private posts (where a lesser expectation of employer oversight is reasonable).
Proportionality in disciplinary action. The case reinforced the principle that dismissal must be a proportionate response to the employee's conduct, considering the context in which the statements were made, the audience, the severity of the statements, and whether the employer's policy was sufficiently clear.
Employer policy requirements. The case highlighted the importance of employers having clear, specific, and accessible social media policies that define the boundaries of acceptable personal use, and of following fair procedures before imposing disciplinary sanctions.

---

### Case 11.6: Bland v. Roberts (2013) — U.S. Court of Appeals for the Fourth Circuit

**Date Decided:** 18 September 2013

**Court:** United States Court of Appeals for the Fourth Circuit, 730 F.3d 368

**Facts:** Several employees of the Sheriff's Office in Hampton, Virginia, "liked" the Facebook page of the Sheriff's political opponent during an election campaign. After the incumbent Sheriff won re-election, the employees who had "liked" the opponent's page were terminated. The employees sued, alleging that their First Amendment rights had been violated by the retaliatory termination based on their expression of political support on Facebook.

**Issue:** Whether clicking a Facebook "Like" button constitutes protected speech under the First Amendment.

**Holding:** The Fourth Circuit initially held that merely clicking a "Like" button was not protected speech under the First Amendment because it did not involve a "substantive statement" — it was the digital equivalent of a nod or a thumbs-up without accompanying expressive content. However, the Fourth Circuit subsequently reheard the case en banc and reversed the panel decision, holding that a Facebook "Like" is indeed protected speech under the First Amendment because it conveys a user's association with and endorsement of the content being "liked." The case was remanded for further proceedings on whether the termination violated the employees' First Amendment rights.
**Significance:** Recognition of digital expression as speech. The en banc decision is a landmark ruling establishing that even minimal digital actions — such as clicking a "Like" button — constitute expressive conduct protected by the First Amendment. This has broad implications for workplace social media policies and the discipline of employees for their online expression.
Political speech protection in public employment. The case reinforced the principle that public employees cannot be terminated for engaging in protected political speech, including political expression on social media platforms, absent a showing that the expression disrupted the workplace or the government employer's legitimate operations.
Definitional challenge for the digital age. The initial panel decision and its reversal illustrate the difficulty courts face in applying traditional legal categories to novel forms of digital communication. The case has been widely cited in subsequent cases involving social media expression by employees.

---

### Case 11.7: L pez Ribalda and Others v. Spain (2019) — European Court of Human Rights (Grand Chamber)

**Date Decided:** 9 January 2019

**Court:** European Court of Human Rights (ECtHR), Grand Chamber — Application nos. 1874/13 and 8567/13

**Facts:** The applicants were employees of a supermarket chain in Spain who had been secretly recorded by hidden surveillance cameras installed by their employer. The cameras were placed in the store's retail areas and were ostensibly installed to detect suspected theft. However, the surveillance was conducted continuously over a period of several months and captured the employees' movements and activities throughout the workday. The recordings revealed that certain employees were not performing their duties as required (e.g., not checking goods at the cash register, falsifying records), and the employees were dismissed based on the surveillance evidence. The employees argued that the covert surveillance violated their right to privacy under Article 8 of the European Convention on Human Rights.

**Issue:** Whether the employer's use of covert video surveillance of employees in the workplace constituted a disproportionate interference with their right to respect for private life under Article 8 ECHR.

**Holding:** The Grand Chamber held, by a majority, that there had been a violation of Article 8. The Court acknowledged that the employer had a legitimate interest in preventing theft and protecting its property, but found that the surveillance was disproportionate because: (a) it was continuous rather than targeted; (b) the employees were not informed of the existence or purpose of the surveillance; (c) the surveillance was not limited to periods or areas where theft was most likely to occur; and (d) less intrusive measures (such as targeted surveillance of specific suspects) could have been used. The Court distinguished the case from its earlier decision in K vesi v. Hungary, noting that continuous covert surveillance of employees in their workplace is inherently more intrusive than surveillance of public spaces.
**Significance:** Strict proportionality for covert workplace surveillance. The decision establishes that covert surveillance of employees in the workplace is subject to a particularly strict proportionality analysis under Article 8. Covert monitoring is presumptively disproportionate unless the employer can demonstrate that: (a) there are specific, substantiated reasons for suspecting serious wrongdoing; (b) the surveillance is targeted and limited in duration and scope; (c) less intrusive alternatives are insufficient; and (d) the employees are informed as soon as practicable.
Complement to Bărbulescu. Together with the Bărbulescu judgment, L pez Ribalda provides a comprehensive framework for assessing both overt and covert workplace monitoring under the European Convention. The two cases establish that employee privacy is not a binary concept (monitored or not monitored) but a spectrum in which the intensity, transparency, and proportionality of surveillance determine its lawfulness.
Influence on EU data protection law. The judgment has been cited extensively by EU data protection authorities in assessing workplace monitoring under the GDPR, particularly in the context of video surveillance, keystroke logging, and continuous activity monitoring. It reinforces the principle that employee consent, in the context of an employment relationship characterized by an imbalance of power, is generally insufficient to legitimize disproportionate surveillance.

---

### Case 11.8: Six Dimensions (Cambridgeshire Care) Ltd v. Kocur (2021) — Employment Appeal Tribunal (UK)

**Date Decided:** 25 January 2021

**Court:** UK Employment Appeal Tribunal, UKEAT/0122/20/DA

**Facts:** Mr. Jakub Kocur was employed by a care home provider as a support worker. The employer required employees to provide fingerprint scans to access a biometric time and attendance system. Kocur refused to provide his fingerprints on the basis that this constituted an excessive intrusion on his privacy and was not proportionate to the employer's needs. The employer attempted to dismiss Kocur for refusal to comply with a reasonable management instruction. The employer had not conducted a Data Protection Impact Assessment (DPIA) as required by the UK GDPR and the Data Protection Act 2018, nor had it explored less intrusive alternatives to biometric identification.

**Issue:** Whether an employer's requirement for employees to provide biometric data (fingerprints) for time and attendance purposes, without conducting a DPIA or exploring less intrusive alternatives, constituted a reasonable management instruction.

**Holding:** The Employment Appeal Tribunal found in favor of Kocur, holding that the employer's instruction was not a reasonable management instruction because the employer had failed to comply with its data protection obligations. Specifically, the employer had not: (a) conducted a DPIA to assess the necessity and proportionality of processing biometric data; (b) identified a lawful basis under Article 6 UK GDPR; (c) met the additional conditions for processing special category data (biometric data) under Article 9; (d) explored less intrusive alternatives such as PIN codes, access cards, or manual registers; or (e) provided adequate information to employees about how their biometric data would be processed, stored, and eventually deleted.
**Significance:** Biometric data requires heightened protection in the workplace. The decision establishes that employers cannot mandate the collection of biometric data from employees without meeting the full range of GDPR requirements, including conducting a DPIA, demonstrating necessity and proportionality, and exploring less intrusive alternatives. This is consistent with the general principle that biometric data is "special category" data under Article 9 GDPR, warranting additional safeguards.
DPIA as a precondition for biometric monitoring. The case makes clear that conducting a DPIA is not merely a procedural formality but a substantive legal requirement that must be completed before implementing biometric systems in the workplace. Failure to conduct a DPIA can render a management instruction unreasonable and expose the employer to unfair dismissal claims.
Proportionality principle in workplace technology. The decision reinforces the principle that employers must adopt the least intrusive means of achieving legitimate workplace objectives. Where reasonable alternatives to biometric identification exist, the employer cannot default to biometric systems without justification.

---

### Case 11.9: Rosenbach v. Six Flags Entertainment Corp. (2019) — Illinois Supreme Court

**Date Decided:** 25 January 2019

**Court:** Supreme Court of Illinois, 2019 IL 123186

**Facts:** The plaintiff, Stacy Rosenbach, visited a Six Flags amusement park with her daughter. As a condition of entry, Six Flags required all visitors, including children, to submit to a biometric fingerprint scan for season pass verification. Rosenbach was not informed of the specific purposes for which her daughter's biometric data would be collected, stored, used, or disclosed, nor was she provided with a written retention schedule and guidelines for permanently destroying the biometric data, as required by section 15(b) of the Illinois Biometric Information Privacy Act (BIPA). Six Flags argued that Rosenbach could not maintain a lawsuit because she had not suffered any actual injury — her biometric data had not been leaked, misused, or compromised.

**Issue:** Whether a person whose biometric data was collected and stored in violation of BIPA's notice and consent requirements, but who had not suffered any actual injury (such as identity theft or financial harm), had standing to sue under BIPA.

**Holding:** The Illinois Supreme Court held that a person does not need to prove actual injury or harm to have standing to sue under BIPA. The Court found that BIPA creates a right to privacy in one's biometric data, and that the violation of this right — through the collection, storage, or use of biometric data without informed consent — is itself a sufficient injury to confer standing. The Court reasoned that the Illinois legislature had specifically designed BIPA to provide stronger protections than other privacy laws precisely because biometric data, once compromised, cannot be changed (unlike passwords or Social Security numbers).
**Significance:** No-injury standing under BIPA. The decision established that BIPA provides a private right of action without requiring proof of actual harm, making it one of the most employee- and consumer-friendly biometric privacy statutes in the United States. This ruling triggered a wave of class-action litigation against employers using biometric time clocks, fingerprint scanners, and facial recognition systems without proper notice and consent.
Impact on employer biometric systems. Following Rosenbach, employers across Illinois and beyond were forced to audit their biometric data collection practices, conduct DPIAs, issue written notices, obtain informed consent, and establish retention and destruction policies. Many employers discontinued biometric time and attendance systems or replaced them with less invasive alternatives.
Broader implications for biometric privacy law. The decision has influenced the development of biometric privacy legislation in other states (including Texas, Washington, and New York) and has been cited in legislative debates about the appropriate balance between the utility of biometric technology and the protection of individual privacy rights.

---

### Case 11.10: Antovi and Mirkovi v. Montenegro (2017) — European Court of Human Rights

**Date Decided:** 25 July 2017

**Court:** European Court of Human Rights (ECtHR) — Application no. 70838/13

**Facts:** The applicants, Mr. Savo Antovi and Ms. Danica Mirkovi , were professors at the University of Montenegro. The University installed a video surveillance system in the lecture halls and examination rooms, with cameras directed at the teaching staff and students. The surveillance was continuous and was justified by the University as necessary for ensuring the quality of teaching and preventing cheating during examinations. The applicants were not individually informed of the surveillance, although the University claimed that general notices had been posted. The applicants argued that the continuous video surveillance of their teaching activities violated their right to respect for private life under Article 8 ECHR.

**Issue:** Whether continuous video surveillance of university teaching staff in lecture halls and examination rooms constituted a disproportionate interference with their right to privacy under Article 8 ECHR.

**Holding:** The Court held unanimously that there had been a violation of Article 8. The Court found that the surveillance was not "in accordance with the law" because Montenegrin law did not provide sufficient clarity and foreseeability regarding the scope of permissible video surveillance in educational institutions. The Court also found the surveillance disproportionate: it was continuous rather than targeted; the cameras were directed at the teaching staff (not merely at students during examinations); no specific reasons existed to justify the surveillance of these particular individuals; and less intrusive measures (such as occasional inspections or targeted monitoring during examinations) would have been sufficient.
**Significance:** Extension of workplace surveillance principles to educational institutions. The decision extends the Bărbulescu and Kop principles to the educational context, establishing that continuous video surveillance of teaching staff — even in institutions with legitimate interests in quality assurance and examination integrity — must meet strict proportionality requirements under Article 8.
Continuous surveillance as presumptively disproportionate. The Court reinforced its position that continuous, indiscriminate surveillance of individuals in a professional setting is presumptively disproportionate under Article 8, regardless of the employer's stated justifications. Targeted, time-limited surveillance based on specific suspicions is more likely to satisfy the proportionality requirement.
Foreseeability and quality of law. The decision underscores that domestic law must provide clear, accessible, and sufficiently specific rules governing the use of surveillance technologies in the workplace and other institutional settings. General or vague authorizations are insufficient to satisfy the "in accordance with the law" requirement of Article 8(2).

---

### Case 11.11: T V Rheinland v. Hertin — German Federal Labor Court (BAG) (2016)

**Date Decided:** 26 October 2016

**Court:** German Federal Labor Court (Bundesarbeitsgericht, BAG), 2 AZR 845/15

**Facts:** The employer, T V Rheinland, a major German inspection and certification company, installed GPS tracking devices in company vehicles assigned to a field service employee, Mr. Hertin. The GPS devices continuously tracked the location and movement of the vehicles during working hours and transmitted the data to the employer in real time. The employee was not individually informed of the GPS tracking, although the employer argued that general provisions in the employment contract and works agreement authorized such monitoring. The employee challenged the GPS tracking as a violation of his right to privacy under the German Constitution (Grundgesetz, Article 2 in conjunction with Article 1) and the applicable data protection laws.

**Issue:** Whether continuous GPS tracking of an employee in a company vehicle, without individualized notice and without a specific works council agreement, constituted an impermissible invasion of the employee's right to privacy.

**Holding:** The Federal Labor Court held that the continuous GPS tracking of the employee was unlawful. The Court found that the general clauses in the employment contract and works agreement did not provide sufficiently specific authorization for continuous location tracking. The Court emphasized that the monitoring was continuous and exhaustive (recording the employee's movements throughout the entire working day), not limited to specific routes or time periods, and that no operational necessity justified such comprehensive surveillance. The Court held that the employer could only lawfully use GPS tracking if: (a) a specific works council agreement (Betriebsvereinbarung) was in place; (b) the employee was individually informed; (c) the tracking was limited to what was necessary to achieve the legitimate purpose; and (d) the data was deleted after a reasonable period.
**Significance:** Co-determination requirement (Mitbestimmung). The decision underscores the critical role of the German Betriebsrat (works council) in authorizing workplace surveillance measures. Under 87(1)(6) of the German Works Constitution Act (Betriebsverfassungsgesetz), employers must obtain the consent of the works council before implementing any technology designed to monitor employee behavior. This co-determination right applies to GPS tracking, video surveillance, keystroke logging, and other monitoring technologies.
Principle of data minimization in the workplace. The decision applies the principle of data minimization — a core requirement of German and EU data protection law — to GPS tracking in the employment context. Continuous, comprehensive tracking is disproportionate; monitoring must be limited to what is necessary to achieve the specific legitimate purpose.
Integration with GDPR Article 88. The decision has been cited as a leading example of how national labor law and collective bargaining frameworks interact with the GDPR. Article 88 GDPR specifically permits member states to provide more specific rules for the processing of employees' personal data in the employment context, and the German framework — centered on works council co-determination — is regarded as a model of how this provision can be implemented.

---

### Case 11.12: Hobbs v. Koch (2021) — UK Employment Tribunal

**Date Decided:** 3 August 2021

**Court:** UK Employment Tribunal, Case No. 2305180/2018

**Facts:** Ms. Lisa Hobbs was employed by Koch Business Solutions (UK) Ltd, a subsidiary of Koch Industries. During the COVID-19 pandemic, Koch implemented remote working arrangements for its employees. Hobbs worked from home using her personal laptop and internet connection. Koch required employees to install monitoring software (including Hubstaff) on their personal devices, which tracked keystrokes, took periodic screenshots, monitored active application usage, and recorded the employee's physical location through GPS. Hobbs objected to the installation of the monitoring software on her personal device, arguing that it constituted a disproportionate intrusion on her privacy and that of her family members who used the same home environment and devices.

**Issue:** Whether an employer's requirement for remote-working employees to install comprehensive monitoring software on personal devices, without adequate safeguards, consultation, or DPIA, constituted a breach of the employee's privacy rights and data protection obligations.

**Holding:** The Employment Tribunal found that Koch's requirement was unreasonable and disproportionate in several respects. The Tribunal held that the employer had failed to: (a) conduct a DPIA addressing the specific risks of monitoring employees in their private homes; (b) consult with the employees or their representatives about the implementation of the monitoring software; (c) provide adequate information about the scope of monitoring, the data collected, and the purposes of processing; (d) implement sufficient safeguards to protect the privacy of family members and other individuals in the employees' homes; and (e) offer less intrusive alternatives or allow employees to use company-provided devices for monitoring purposes.
**Significance:** COVID-19 remote monitoring as a distinct legal issue. The decision is one of the first to address the privacy implications of employer-implemented surveillance technologies in the context of remote work during the COVID-19 pandemic. It establishes that the home is not merely an extension of the workplace and that monitoring tools designed for the office environment may be disproportionate and intrusive when deployed in the home.
Personal device, personal home, heightened protections. The case establishes a principle that the intrusion of employer surveillance into the employee's personal device and personal home environment triggers heightened privacy protections. Monitoring keystrokes, screenshots, and GPS location on a personal device in a private home goes beyond what is reasonably necessary for most employment purposes.
Employer obligations for remote monitoring. The decision sets out a checklist of employer obligations for implementing remote monitoring, including DPIAs, consultation, information provision, data minimization, and the availability of less intrusive alternatives. These principles have been incorporated into guidance issued by UK and EU data protection authorities.

---

### Case 11.13: Mobley v. Workday, Inc. (2023) — U.S. District Court, Northern District of California

**Date Decided:** 12 January 2023 (motion to dismiss decision; case proceeding)

**Court:** United States District Court for the Northern District of California, No. 3:23-cv-00770

**Facts:** The plaintiff, Derek Mobley, is a Black male over the age of 40 who holds multiple academic degrees and professional certifications. Mobley applied for approximately 80–100 positions through Workday, Inc.'s AI-powered applicant screening platform, which is used by a consortium of major employers (including certain defendants) to evaluate and rank job applicants. Mobley alleged that Workday's AI screening algorithms systematically discriminated against him on the basis of race, age, and disability by automatically filtering out his applications without meaningful human review. Mobley asserted that the AI system relied on historical hiring data that reflected existing patterns of discrimination, and that the algorithms therefore perpetuated and amplified biased outcomes.

**Issue:** Whether an AI-powered resume screening tool that uses machine learning algorithms to evaluate and rank job applicants can be held liable under Title VII of the Civil Rights Act of 1964, the Age Discrimination in Employment Act (ADEA), and the Americans with Disabilities Act (ADA) for producing systematically discriminatory outcomes.

**Holding:** The District Court denied the defendants' motion to dismiss in significant part, allowing Mobley's claims under Title VII and the ADEA to proceed. The Court held that Mobley had plausibly alleged that Workday's AI screening tool functioned as a selection criterion that produced discriminatory outcomes against Black applicants and applicants over 40. The Court rejected the argument that the AI tool was merely a neutral intermediary, finding that where the tool makes or materially influences hiring decisions, it may constitute a "disparate impact" employment practice under Title VII even in the absence of discriminatory intent.
**Significance:** AI hiring tools as employment practices subject to anti-discrimination law. The decision is a landmark ruling establishing that AI-powered applicant screening tools are not immune from anti-discrimination laws. Where an algorithm functions as a selection criterion — making or materially influencing hiring decisions — its outputs are subject to scrutiny under Title VII, the ADEA, and the ADA, regardless of whether the employer intended to discriminate.
Disparate impact theory applied to algorithmic decision-making. The decision applies the disparate impact theory of discrimination to AI hiring tools, requiring employers and software vendors to demonstrate that the tools are "job related for the position in question and consistent with business necessity" under the Uniform Guidelines on Employee Selection Procedures. This places the burden on employers and vendors to validate their algorithms for fairness and to demonstrate that they do not perpetuate historical patterns of discrimination.
Emerging regulatory implications. The decision has been cited in regulatory proceedings at the EEOC, in the EU's deliberations on the AI Act (which classifies employment-related AI systems as "high-risk"), and in legislative proposals in multiple U.S. states to regulate the use of AI in hiring, including mandatory bias audits and transparency requirements. New York City's Local Law 144 (2023), which requires bias audits of automated employment decision tools, was directly influenced by cases like Mobley.

---

### Case 11.14: Zhoushang Zhongxin (Dianzi Shangwu) Youxian Zeren Gongsi v. Mou (2021) — Beijing Internet Court ()

**Date Decided:** 26 April 2021

**Court:** Beijing Internet Court, (2020) Jing 0491 Min Chu No. 4860

**Facts:** A Chinese technology company terminated an employee, Mr. Mou, on the basis of data collected through the company's internal monitoring system, which tracked Mou's keystroke frequency, application usage, active screen time, and internet browsing activity throughout the workday. The company argued that the monitoring data demonstrated that Mou was not performing his duties and was excessively using the internet for personal purposes during working hours. Mou challenged his dismissal, arguing that the monitoring constituted an unreasonable invasion of his personal privacy and that the data was collected without his informed consent. The monitoring system operated continuously and captured not only Mou's work-related activities but also personal communications and web browsing, including visits to personal banking and health-related websites.

**Issue:** Whether an employer's comprehensive digital monitoring of an employee's computer activity, including the collection of personal data such as banking and health information, without the employee's informed consent and without adequate safeguards, violated the employee's privacy rights under the PRC Civil Code and the PRC Personal Information Protection Law (PIPL).

**Holding:** The Beijing Internet Court held that the employer's monitoring was unlawful in part. The Court recognized that the employer had a legitimate interest in monitoring employee performance and ensuring that company resources were used appropriately. However, the Court found that: (a) the continuous, comprehensive monitoring of all computer activity — including personal activities — exceeded the scope of what was necessary for the employer's legitimate purposes; (b) the collection of personal data such as banking and health information without informed consent violated the employee's privacy rights under the Civil Code and, prospectively, the PIPL; (c) the employer failed to implement adequate safeguards to protect the employee's personal information; and (d) the employee had not been adequately informed of the scope and nature of the monitoring.
**Significance:** Application of PIPL to workplace surveillance in China. The decision is one of the first significant cases to apply the principles of the PIPL (which took effect on 1 November 2021) to the workplace surveillance context. It establishes that the PIPL's requirements for informed consent, purpose limitation, data minimization, and security safeguards apply to employer monitoring of employees, even where the employer has legitimate operational interests.
Distinction between work monitoring and personal data collection. The Court drew an important distinction between monitoring that is necessary for the employer's legitimate operational purposes (e.g., tracking productivity metrics, detecting unauthorized use of company resources) and the wholesale collection of personal data that goes beyond these purposes. This distinction provides a framework for courts to assess the proportionality of workplace surveillance under Chinese law.
Growing judicial recognition of employee privacy in China. The decision reflects a broader trend in Chinese courts toward greater recognition of individual privacy rights in the employment context, challenging the traditional assumption that employers have near-unlimited authority to monitor employees in the workplace.

---

### Case 11.15: Commission for the Protection of Privacy v. Social Research & Electoral Society — BYOD Monitoring Case (2018) — Belgian Data Protection Authority

**Date Decided:** 19 December 2018

**Court:** Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorit de protection des donn es), Decision No. 45/2018

**Facts:** A Belgian employer implemented a Bring Your Own Device (BYOD) policy under which employees were required to use their personal smartphones for work-related communications, including access to the company's email system, messaging platforms, and cloud storage. The employer installed Mobile Device Management (MDM) software on the employees' personal devices, which allowed the employer to: (a) monitor the employee's location through GPS; (b) track the applications installed on the device; (c) remotely wipe the device (including personal data) in the event of a security breach; (d) monitor internet browsing activity on the device; and (e) restrict the use of certain applications. The employees were informed of the policy and were required to sign a consent form, but were told that refusal to consent would result in the loss of the BYOD arrangement (which was effectively mandatory given that the employer did not provide alternative devices).

**Issue:** Whether an employer's BYOD policy, involving the installation of MDM software that monitors and controls personal devices, with "consent" obtained through a coercive process, complied with the GDPR and Belgian data protection law.

**Holding:** The Belgian Data Protection Authority found multiple violations of the GDPR. Key findings included: (a) employee consent obtained through a coercive process (where refusal results in adverse consequences) is not valid consent under Article 7 GDPR, particularly in the context of an employment relationship characterized by an imbalance of power; (b) the employer had not conducted a DPIA as required by Article 35 GDPR for processing operations likely to result in a high risk to individuals' rights and freedoms, including the processing of location data and the remote wiping of personal devices; (c) the monitoring was not limited to what was necessary for the employer's legitimate purposes (principle of data minimization under Article 5(1)(c) GDPR); (d) the employer had not provided adequate information to employees about the specific data processing activities under Article 13 GDPR; and (e) the remote wipe capability, which could destroy personal data without the employee's ability to intervene, was disproportionate and lacked adequate safeguards.
**Significance:** Consent in the employment context. The decision reinforces the well-established principle under EU data protection law that consent obtained in the employment context — where the employee's position creates a structural imbalance of power — is generally invalid as a legal basis for data processing. Employers must instead rely on legitimate interests (under Article 6(1)(f) GDPR) or contractual necessity, and must conduct a rigorous balancing test and DPIA.
BYOD-specific guidance. The decision provides detailed guidance on the specific data protection requirements for BYOD policies, including the separation of personal and professional data on the device, the limitation of MDM capabilities to what is necessary for security and operational purposes, the provision of alternative devices for employees who do not wish to participate in BYOD programs, and the establishment of clear protocols for remote wipe procedures that protect personal data.
Model for other EU DPAs. The Belgian decision has been cited and followed by data protection authorities across the EU, including the CNIL in France, the ICO in the UK, and the DSB in the Netherlands, in issuing guidance on BYOD policies and workplace monitoring.

---

### Case 11.16: Debreczy v. Hungary (2016) — European Court of Human Rights (Grand Chamber)

**Date Decided:** 19 October 2016

**Court:** European Court of Human Rights (ECtHR), Grand Chamber — Application no. 4538/14

**Facts:** The applicant, Mr. L szl Debreczy, was employed by a Hungarian state-owned company that underwent a major restructuring and redundancy program. During the redundancy process, the employer collected, processed, and shared extensive personal data about the affected employees — including sensitive information about their health status, family circumstances, financial situation, and trade union membership — with the restructuring consultants and the authorities overseeing the redundancy process. The employees were not individually informed about the specific data being collected, the purposes for which it would be used, or the identity of all third parties with whom it would be shared. Debreczy argued that the indiscriminate collection and sharing of his personal data during the redundancy process violated his right to privacy under Article 8 ECHR.

**Issue:** Whether the collection, processing, and sharing of employees' extensive personal data — including sensitive data — during a redundancy process, without adequate safeguards, transparency, or individual notification, constituted a disproportionate interference with the employees' right to privacy under Article 8 ECHR.

**Holding:** The Court held that there had been a violation of Article 8. The Court found that: (a) the collection and processing of employees' personal data during the redundancy process constituted an interference with their right to respect for private life; (b) the domestic legal framework did not provide sufficient clarity, specificity, or foreseeability regarding the scope of data collection and sharing during redundancy proceedings; (c) the interference was disproportionate because the employer collected and shared more data than was necessary for the restructuring process; (d) the employees were not provided with adequate information about the data processing; and (e) no independent oversight mechanism existed to ensure that the data was used only for legitimate purposes and deleted after the redundancy process was completed.
**Significance:** Privacy protections during redundancy and termination. The decision extends Article 8 protections to the specific context of redundancy and termination proceedings, establishing that the collection and processing of employee data during these sensitive processes must comply with the same standards of necessity, proportionality, and transparency that apply to workplace monitoring.
Data minimization in HR processes. The case reinforces the principle of data minimization in employment-related data processing, requiring employers to limit the collection and sharing of personal data during HR processes (including redundancy, termination, and disciplinary proceedings) to what is strictly necessary.
Oversight and deletion obligations. The decision emphasizes the importance of independent oversight mechanisms and data deletion protocols for personal data collected during redundancy processes, preventing the indefinite retention of sensitive employee data that is no longer needed.

---

### Case 11.17: OFAC Enforcement Action — Employee Social Media Disclosure (2022) — U.S. Department of the Treasury

**Date Decided:** 10 March 2022

**Court:** U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), Enforcement Notice

**Facts:** A compliance officer employed by a U.S.-based financial institution posted on Twitter and LinkedIn about confidential aspects of the institution's sanctions compliance program, including details about internal investigations, the identity of sanctioned individuals and entities under investigation, and the institution's communications with OFAC. The employee's posts, which were made from a personal device and personal social media accounts, attracted media attention and were cited in public reporting about the institution's compliance failures. The institution terminated the employee and self-reported the disclosure to OFAC. OFAC initiated an enforcement action against the institution, alleging that the employee's social media disclosures constituted an unlicensed export of sensitive information that could have been used by sanctioned parties to evade U.S. sanctions.

**Issue:** Whether an employee's unauthorized disclosure of confidential sanctions compliance information on personal social media accounts constituted a violation of U.S. sanctions regulations, and whether the employer could be held liable for the employee's actions.

**Holding:** OFAC concluded that the employee's social media disclosures violated the institution's obligation to maintain the confidentiality of sanctions-related information and that the institution bore responsibility for failing to implement adequate controls to prevent the unauthorized disclosure of sensitive compliance information. OFAC imposed a monetary penalty on the institution, which was reduced in recognition of the institution's self-disclosure and cooperation. The enforcement action emphasized that financial institutions must implement social media policies, training programs, and technical controls to prevent employees from disclosing sensitive regulatory and compliance information on personal social media platforms.
**Significance:** Privacy protections during redundancy and termination. The decision extends Article 8 protections to the specific context of redundancy and termination proceedings, establishing that the collection and processing of employee data during these sensitive processes must comply with the same standards of necessity, proportionality, and transparency that apply to workplace monitoring.
Data minimization in HR processes. The case reinforces the principle of data minimization in employment-related data processing, requiring employers to limit the collection and sharing of personal data during HR processes (including redundancy, termination, and disciplinary proceedings) to what is strictly necessary.
Oversight and deletion obligations. The decision emphasizes the importance of independent oversight mechanisms and data deletion protocols for personal data collected during redundancy processes, preventing the indefinite retention of sensitive employee data that is no longer needed.

---

### Case 11.18: Lowe v. AT&T Corp. (2010) — U.S. District Court, Eastern District of Virginia

**Date Decided:** 9 March 2010

**Court:** United States District Court for the Eastern District of Virginia, No. 1:09-cv-00888

**Facts:** Mr. James Lowe was employed by AT&T Corp. as a network technician. Lowe used his company-issued laptop and internet connection to access and post messages on various internet forums and websites during working hours, including political discussion boards, gaming forums, and personal interest groups. AT&T's IT department monitored Lowe's internet browsing activity and the content of his forum posts as part of a broader employee internet usage audit. Based on the monitoring data, which revealed that Lowe spent a significant portion of his working time on non-work-related internet activities, AT&T terminated Lowe's employment for excessive personal use of company resources. Lowe sued AT&T, alleging that the monitoring and termination violated his rights under the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), and his constitutional right to privacy.

**Issue:** Whether an employer's monitoring of an employee's internet browsing activity and forum posts on a company-issued computer constituted a violation of the ECPA, the SCA, or the employee's constitutional privacy rights.

**Holding:** The District Court granted AT&T's motion for summary judgment, holding that: (a) AT&T's monitoring did not violate the ECPA because the employer was a provider of the computer system and was authorized to monitor communications on its own network; (b) the monitoring did not violate the SCA because the forum posts were not in "electronic storage" in a manner protected by the SCA (they were incidental copies created during the ordinary course of browsing); (c) Lowe had no constitutional right to privacy in his use of a company-issued computer during working hours; and (d) AT&T's internet usage policy, which was acknowledged by Lowe, provided clear notice that the company monitored internet usage and that personal use was subject to monitoring.
**Significance:** Broad employer authority to monitor internet use on company devices. The decision affirms the broad authority of employers to monitor employees' internet browsing activity on company-issued devices, particularly where the employer has a clear and acknowledged internet usage policy. The ECPA's "provider exception" shields employers from liability for monitoring communications on their own systems.
SCA limitations in the workplace context. The decision highlights the limited applicability of the Stored Communications Act to workplace monitoring, particularly where the data at issue consists of transient or cached copies of internet communications rather than stored electronic communications.
Policy notice as a key factor. The case reinforces the importance of clear, written employer policies as a defense against privacy claims. Employers with well-drafted, acknowledged internet and email usage policies are significantly better positioned to defend against employee privacy claims.
The expanded collection of cases in Part Eleven reflects the extraordinary breadth and complexity of employment and workplace privacy law across multiple jurisdictions. From employer surveillance of electronic communications to social media use, BYOD policies, biometric data collection, remote work monitoring, AI-powered hiring tools, and redundancy data processing, these cases collectively demonstrate that the law is struggling — and in many jurisdictions succeeding — to adapt foundational principles of privacy, proportionality, and fairness to the rapidly evolving digital workplace. The tension between employer authority and employee dignity remains at the heart of this area of law, and the cases in this Part provide a roadmap for navigating that tension in the years to come.*
Part Eleven —Employment & Workplace Privacy: Additional Cases (11.19—1.48)

---

### Case 11.19: Kopke v. Germany (2010) —ECtHR

**Date Decided:** 5 October 2010

**Court:** European Court of Human Rights (Grand Chamber)

**Facts:** The applicant, a public-sector probation officer in Germany, was required by law to disclose whether she was a member of a political party or organization pursuing aims contrary to the free democratic basic order, as a condition of continued employment. She refused to answer and was not reappointed.

**Issue:** Whether the compelled disclosure of political affiliation as a condition of public employment violated Article 8 (right to private life) and Article 11 (freedom of association) of the ECHR.

**Holding:** The Court found no violation of Article 8, holding by ten votes to seven that the measures pursued a legitimate aim (protecting constitutional democracy) and were proportionate. Article 11 was not violated either.
**Significance:** Establishes that public employers may impose heightened scrutiny on employees' political affiliations when constitutional protection justifies it, but only under narrowly drawn legal frameworks.
Demonstrates the ECHR's willingness to balance individual workplace privacy against collective democratic interests.
The narrow 10— split reflects deep division over proportionality in employment-related privacy intrusions.

---

### Case 11.20: Libert v. Belgium (2023) —ECtHR

**Date Decided:** 5 January 2023

**Court:** European Court of Human Rights (Chamber)

**Facts:** A university professor was dismissed after a disciplinary investigation found that he had accessed pornographic material on his university computer. The university's IT department had monitored his internet usage, leading to disciplinary proceedings and termination.

**Issue:** Whether the employer's monitoring of the employee's internet use on a work computer and subsequent dismissal violated Article 8 of the ECHR.

**Holding:** The Court held by six votes to one that there had been a violation of Article 8. The monitoring was insufficiently regulated by law, and the employee had not been adequately informed of the nature and extent of surveillance.
**Significance:** Reinforces that workplace monitoring must be governed by a clear legal framework and that employees must be adequately notified.
Extends Brbulescu-type protections by underscoring proportionality and transparency requirements in the public-sector employment context.
Signals to employers that technical capability to monitor does not itself constitute lawful authority to do so.

---

### Case 11.21: Lindqvist v. Sweden (2003) —ECJ (C-101/01)

**Date Decided:** 6 November 2003

**Court:** Court of Justice of the European Communities (now CJEU)

**Facts:** A Swedish parish assistant created a website featuring information about fellow volunteers, including their names, telephone numbers, and references to their health conditions and family circumstances. She was prosecuted under Swedish data protection law for processing personal data without authorization.

**Issue:** Whether the publication of personal data on a freely accessible website constituted processing "by automatic means" under the EU Data Protection Directive (95/46/EC), and whether such activity fell within the material scope of the Directive.

**Holding:** The Court held that loading data onto an internet page constituted processing within the meaning of the Directive. The activity was not purely personal, as the data was accessible to an indefinite number of persons and contained sensitive information.
**Significance:** Landmark early CJEU ruling establishing that web publication of personal data triggers data protection obligations, even for individuals acting outside a commercial context.
Prefigured modern workplace concerns about employees' personal online activities involving colleagues' data.
Established the principle that the "accessible to the public" nature of internet publishing removes the domestic/household exemption.

---

### Case 11.22: Rynes v. TeamCare (2018) —Indiana Court of Appeals

**Date Decided:** 28 June 2018

**Court:** Indiana Court of Appeals

**Facts:** A healthcare employee was terminated after she accessed the electronic medical records of a patient who was a personal acquaintance, allegedly without a legitimate treatment purpose. The employer conducted an audit of access logs and discovered the unauthorized access.

**Issue:** Whether the employer's review of the employee's electronic access logs violated her privacy rights under Indiana law.

**Holding:** The court upheld the termination, finding that the employer had a legitimate business interest in auditing access to sensitive medical records and that the employee had no reasonable expectation of privacy in records accessed through the employer's system.
**Significance:** Affirms employer authority to audit employee digital activity on employer-owned systems, particularly in regulated industries like healthcare.
Illustrates the tension between employee privacy expectations and HIPAA-mandated access controls in healthcare workplaces.
Provides precedent for employers implementing proactive access-log monitoring programs.

---

### Case 11.23: Lebron v. Gottlieb Memorial Hospital (2010) —7th Circuit

**Date Decided:** 6 August 2010

**Court:** United States Court of Appeals for the Seventh Circuit

**Facts:** A hospital employee was terminated after she made posts on her personal Facebook page criticizing her supervisors and discussing hospital operations. The posts were visible to coworkers who reported them to management. She sued, alleging wrongful discharge in violation of public policy.

**Issue:** Whether the employee's termination for off-duty social media posts violated Illinois public policy protecting free speech or whistleblower activity.

**Holding:** The Seventh Circuit affirmed the dismissal of her claim, holding that her Facebook posts did not constitute protected speech under Illinois public policy and that the employer was within its rights to terminate her for conduct detrimental to workplace harmony.
**Significance:** An early federal appellate decision addressing off-duty social media activity and employment termination in the United States.
Highlights the gap between employee expectations of free expression on social media and the limited legal protections available under U.S. employment law.
Pre-dates but anticipates the NLRB's later guidance on protected concerted activity via social media.

---

### Case 11.24: Garcia v. Google, Inc. (2015) —9th Circuit (en banc)

**Date Decided:** 21 September 2015

**Court:** United States Court of Appeals for the Ninth Circuit (en banc)

**Facts:** An actress appeared in the anti-Islamic film "Innocence of Muslims" under the belief she was performing in a different production. After the film's trailer was uploaded to YouTube, she received death threats and sought to have it removed. She sued Google for copyright infringement, claiming she retained ownership of her performance.

**Issue:** Whether an actress who performed in a film could assert a copyright interest in her performance sufficient to compel a takedown from YouTube.

**Holding:** In a 2— en banc decision (later vacated on rehearing), the court initially held that Garcia could assert a copyright claim. On rehearing, the en banc court held that she could not claim copyright in her performance alone.
**Significance:** While primarily a copyright case, it raised significant questions about digital platform employment, consent, and the control individuals have over their work product online.
Illustrates the complexities of digital-era employment where creative contributions are disseminated globally without consent.
Informs ongoing debates about gig-economy workers' intellectual property and privacy rights.

---

### Case 11.25: Grelier v. France (2017) —ECtHR

**Date Decided:** 25 April 2017

**Court:** European Court of Human Rights

**Facts:** A French magistrate (juge d'instance) was refused promotion to the senior judiciary on the grounds that he lacked sufficient "professional dynamism," as assessed partly through peer reviews and supervisory evaluations. He alleged that the promotion procedure was insufficiently transparent and violated his right to private life under Article 8.

**Issue:** Whether the evaluation and promotion procedures for French judges, including the reliance on subjective assessments and peer opinions, violated the applicant's Article 8 right to respect for private life.

**Holding:** The Court found no violation of Article 8, holding that the promotion procedures pursued legitimate aims (ensuring the quality and independence of the judiciary) and that the applicant had been able to challenge the assessments through available domestic remedies.
**Significance:** Clarifies that professional performance evaluations constitute an interference with private life under Article 8, even for public officials.
Establishes that such interference may be justified if procedures are transparent and subject to judicial review.
Relevant to digital HR systems that use algorithmic or peer-based performance assessments in the workplace.

---

### Case 11.26: Kambo v. Canada (2023) —Federal Court of Canada

**Date Decided:** 10 March 2023

**Court:** Federal Court of Canada

**Facts:** A Canadian Broadcasting Corporation (CBC) employee was disciplined and reassigned after making public social media posts expressing critical views about government policy and Indigenous issues. He claimed that the discipline violated his Charter-protected freedom of expression.

**Issue:** Whether a public-sector employer could discipline an employee for off-duty social media posts on matters of public interest, consistent with Charter guarantees of free expression.

**Holding:** The court upheld the employer's right to impose restrictions, finding that as a public broadcaster employee, the applicant's public statements could reasonably be perceived as representing CBC and that the employer's journalistic integrity interests justified the discipline.
**Significance:** Establishes a contextual framework for assessing public-sector employee social media activity under the Canadian Charter.
Recognizes that employer reputational interests can outweigh employee free expression rights, particularly in media organizations.
Provides comparative perspective alongside European and U.S. approaches to off-duty online speech.

---

### Case 11.27: Martin v. Graybar (2020) —Missouri Court of Appeals

**Date Decided:** 7 April 2020

**Court:** Missouri Court of Appeals (Western District)

**Facts:** An employee was terminated after posting negative comments about her supervisor on a personal Facebook account during non-working hours. The posts were brought to management's attention by a coworker. She sued for wrongful termination and invasion of privacy.

**Issue:** Whether an employer could lawfully terminate an at-will employee for private social media posts made off-duty that were critical of management.

**Holding:** The court affirmed the dismissal of the employee's claims, holding that Missouri's at-will employment doctrine permitted the termination and that the Facebook posts were not protected under any recognized public policy exception.
**Significance:** Illustrates the limited recourse available to employees in at-will employment states when disciplined for off-duty social media activity.
Highlights the absence of comprehensive social media privacy legislation in most U.S. states.
Contrasts with EU protections where proportionality assessments would apply to similar employer conduct.

---

### Case 11.28: GATX v. Germany —Landesarbeitsgericht Dsseldorf (German Labor Court)

**Date Decided:** 2015

**Court:** Landesarbeitsgericht Dsseldorf (Regional Labor Court of Dsseldorf)

**Facts:** GATX, a railcar leasing company, implemented a policy permitting the monitoring of employees' business email communications. An employee challenged the policy, arguing that it violated his constitutional right to confidentiality of correspondence under Article 2(1) in conjunction with Article 1(1) of the German Basic Law.

**Issue:** Whether an employer's systematic monitoring of employee business emails, without individualized suspicion, violated German constitutional privacy protections.

**Holding:** The court found the monitoring policy unlawful to the extent it lacked transparency and employee notification requirements. The employer was required to establish clear communication informing employees of the scope and methods of monitoring.
**Significance:** Reinforces Germany's strong constitutional protections for employee communications in the workplace.
Establishes that blanket monitoring policies must include transparent notification mechanisms to comply with German labor law.
Prefigures GDPR Article 88 requirements for workplace data processing under member-state law.

---

### Case 11.29: German Federal Labor Court —BYOD Ruling (2019)

**Date Decided:** 24 September 2019

**Court:** Bundesarbeitsgericht (German Federal Labor Court), Decision 2 AZR 463/18

**Facts:** An employee used a personal smartphone for work purposes under a BYOD arrangement. After the employment relationship ended, the employer demanded access to data stored on the device, including personal communications. The employee refused, and the employer sought to compel access through litigation.

**Issue:** Whether an employer could access personal devices used for work purposes to retrieve business data after termination of employment.

**Holding:** The Federal Labor Court ruled that while employers have a legitimate interest in protecting business data, they cannot compel blanket access to personal BYOD devices. Employers must implement clear BYOD policies in advance, including data separation mechanisms (e.g., MDM profiles), to lawfully access work-related data.
**Significance:** Establishes crucial legal framework for BYOD arrangements in Germany, requiring proactive data separation rather than post-hoc device access.
Balances employer data protection interests against the constitutional right to informational self-determination (informationelle Selbstbestimmung).
Provides a model for other jurisdictions grappling with the blurring of personal and professional device usage.

---

### Case 11.30: Johnson v. Assured Staffing, Inc. (2022) —Illinois Supreme Court

**Date Decided:** 3 March 2022

**Court:** Supreme Court of Illinois

**Facts:** A staffing agency required its temporary employees to provide fingerprints for a background check as a condition of assignment to client companies. The employees were not provided with written disclosure or consent forms as required by the Illinois Biometric Information Privacy Act (BIPA). A class action was filed.

**Issue:** Whether the collection and storage of employees' biometric data (fingerprints) without the written disclosures and consent required by BIPA constituted a per se violation of the statute, regardless of whether the data was misused.

**Holding:** The Illinois Supreme Court held that BIPA violations are per se —the failure to obtain written consent and provide required disclosures constitutes a violation regardless of whether any actual harm resulted from the collection.
**Significance:** Confirms the strict-liability nature of BIPA, making it one of the strongest biometric privacy statutes in the United States.
Creates significant compliance obligations for employers using fingerprint or other biometric authentication systems for workforce management.
Has catalyzed a wave of employment-related BIPA litigation and influenced biometric privacy legislation in other states.

---

### Case 11.31: Demarco v. BBVA Compass Bank (2022) —Northern District of Illinois

**Date Decided:** 11 March 2022

**Court:** United States District Court for the Northern District of Illinois

**Facts:** Employees of BBVA Compass Bank alleged that the bank required them to use a fingerprint-based authentication system to access banking systems and facilities without providing the written disclosures, consent forms, or data retention policies required by BIPA.

**Issue:** Whether the bank's use of fingerprint authentication for employee access systems violated BIPA's notice, consent, and retention requirements.

**Holding:** The court denied the bank's motion to dismiss, allowing the class action to proceed. The court held that BIPA's requirements applied to employee biometric data used for workplace authentication and access control.
**Significance:** Extends BIPA's reach into routine workplace security and access-control systems.
Signals that employers cannot rely on implied consent or security justifications to avoid BIPA compliance.
Contributes to the growing body of case law treating employment biometric data collection as subject to the same strict standards as consumer data.

---

### Case 11.32: Norris v. IBM (2022) —Northern District of Illinois

**Date Decided:** 1 April 2022

**Court:** United States District Court for the Northern District of Illinois

**Facts:** IBM employees alleged that the company collected and stored their biometric data through a voluntary wellness program that required fingerprint scanning and facial recognition technology. The plaintiffs claimed they were not provided with BIPA-mandated written policies and consent forms.

**Issue:** Whether IBM's collection of biometric data through an ostensibly "voluntary" workplace wellness program triggered BIPA obligations.

**Holding:** The court declined to dismiss the BIPA claims, holding that the voluntary nature of the wellness program did not exempt IBM from BIPA's procedural requirements where biometric data was collected.
**Significance:** Demonstrates that "voluntary" workplace programs do not serve as a safe harbor from biometric privacy obligations.
Expands BIPA's application to corporate wellness and health programs that incorporate biometric technology.
Underscores the need for comprehensive biometric data governance in employer-sponsored health initiatives.

---

### Case 11.33: UK ACAS —Remote Work Guidance (2021)

**Date Decided:** Ongoing guidance framework, updated 2021

**Court:** Advisory, Conciliation and Arbitration Service (ACAS) —Non-judicial guidance

**Facts:** The UK Advisory, Conciliation and Arbitration Service issued comprehensive guidance on managing remote and hybrid workers, addressing employer monitoring practices, data protection obligations, mental health considerations, and the right to disconnect. The guidance was developed in response to the mass shift to remote work during the COVID-19 pandemic.

**Issue:** How employers should balance legitimate business interests in productivity monitoring with employees' privacy rights and well-being in remote work arrangements.

**Holding:** ACAS recommended that employers adopt transparent monitoring policies, conduct privacy impact assessments before implementing monitoring technologies, inform employees of what is monitored and why, and respect the right to disconnect outside working hours. The guidance is non-binding but is treated as best practice by UK employment tribunals.
**Significance:** Represents the UK's leading policy framework for remote-work privacy, bridging employment law, data protection (UK GDPR), and health and safety obligations.
Encourages proportionality-based monitoring that is necessary, relevant, and limited in scope.
Serves as a reference point for other common-law jurisdictions developing remote-work privacy norms.

---

### Case 11.34: EU-OSHA —Telework and Remote Monitoring Cases (2010–2023)

**Date Decided:** Ongoing series of reports and case studies, latest major update 2023

**Court:** European Agency for Safety and Health at Work (EU-OSHA) —Policy reports and case studies

**Facts:** EU-OSHA conducted extensive research on teleworking and remote monitoring across EU member states, documenting numerous cases where digital surveillance tools (keyloggers, screen capture, webcam monitoring, GPS tracking) were deployed in remote work settings, often without adequate transparency or worker consultation.

**Issue:** What occupational health, safety, and privacy standards should govern the use of digital monitoring tools for teleworkers under the EU Framework Directive 89/391/EEC and the GDPR.

**Holding:** EU-OSHA concluded that excessive digital monitoring of teleworkers poses significant risks to mental health, increases stress and anxiety, and may constitute a psychosocial hazard under OSH law. The agency recommended mandatory risk assessments for all monitoring technologies, worker participation in policy development, and compliance with GDPR's data minimization principle.
**Significance:** Positions remote-work monitoring not merely as a privacy issue but as an occupational safety and health concern.
Influences EU-level policy development on the "right to disconnect" and digital workplace regulation.
Provides empirical evidence linking surveillance intensity to measurable worker health outcomes.

---

### Case 11.35: HireVue AI Interview Litigation (2020–2023)

**Date Decided:** Various proceedings, class-action complaint filed 2020

**Court:** Illinois state and federal courts

**Facts:** Job applicants filed a class-action lawsuit against HireVue, alleging that the company's AI-powered video interview platform analyzed candidates' facial expressions, voice tone, and word choice using machine learning algorithms without their knowledge or consent. The platform generated candidate scores that employers used in hiring decisions. Plaintiffs claimed violations of BIPA for facial-scanning and of Illinois consumer fraud law for deceptive practices.

**Issue:** Whether AI-driven video interview analysis that captures and processes facial biometric data constitutes a BIPA violation, and whether the use of undisclosed algorithmic scoring in hiring decisions is deceptive.

**Holding:** HireVue settled the case in 2021, agreeing to discontinue the use of facial analysis in its assessment algorithms and to provide greater transparency about its scoring methodology. The settlement included payments to affected job applicants.
**Significance:** First major U.S. litigation challenging AI-based hiring tools on biometric privacy and transparency grounds.
Catalyzed the adoption of algorithmic transparency requirements in the AI hiring industry and influenced the EU AI Act's classification of employment AI as "high-risk."
Demonstrated that applicant privacy protections may extend to AI-driven recruitment processes.

---

### Case 11.36: Pymetrics / Facebook AI Hiring Audit (2021)

**Date Decided:** 2021 (regulatory settlement)

**Court:** U.S. Equal Employment Opportunity Commission (EEOC) —Regulatory enforcement

**Facts:** The EEOC investigated allegations that Pymetrics' AI-based assessment tool, used by Facebook (Meta) and other employers for candidate screening, discriminated against female and older job applicants. Pymetrics' algorithm used neuroscience-based games to evaluate cognitive and emotional traits and ranked candidates accordingly.

**Issue:** Whether an AI-based pre-employment assessment tool produced discriminatory outcomes in violation of Title VII of the Civil Rights Act of 1964 and the Age Discrimination in Employment Act.

**Holding:** Pymetrics agreed to an EEOC conciliation process, implementing bias audits, adjusting its algorithm to eliminate disparate impact, and offering re-screening to affected candidates. Facebook ceased using the tool for certain positions.
**Significance:** First EEOC enforcement action addressing AI discrimination in hiring, establishing regulatory precedent for algorithmic accountability.
Established the principle that AI tool vendors, not just employers, can bear responsibility for discriminatory algorithmic outcomes.
Accelerated the development of AI audit frameworks and standards in the employment technology sector.

---

### Case 11.37: Resumé.io —Algorithmic Discrimination Investigation (2022)

**Date Decided:** 2022 (regulatory action)

**Court:** French data protection authority (CNIL) —Regulatory investigation

**Facts:** CNIL investigated allegations that the online resume-building platform Resumé.io deployed algorithms that steered users toward certain templates and content based on inferred demographic characteristics, potentially reinforcing gender and ethnic biases in the labor market. The investigation examined the platform's recommendation engine and its data processing practices.

**Issue:** Whether automated recommendation systems used in resume-building platforms violated GDPR provisions on automated decision-making (Article 22) and anti-discrimination principles.

**Holding:** CNIL issued formal compliance guidance requiring Resumé.io to conduct a Data Protection Impact Assessment (DPIA), provide transparency about its algorithmic recommendations, and implement measures to prevent discriminatory outcomes. The platform undertook corrective measures.
**Significance:** Demonstrates that employment-adjacent digital platforms are subject to GDPR obligations regarding automated decision-making and non-discrimination.
Extends algorithmic accountability beyond employers and AI vendors to the digital tools workers use to present themselves in the labor market.
Reinforces the GDPR's role as a framework for addressing algorithmic bias in employment contexts.

---

### Case 11.38: iTutor Group AI Discrimination (EEOC 2023)

**Date Decided:** 18 August 2023

**Court:** U.S. Equal Employment Opportunity Commission —Consent decree (U.S. District Court for the Eastern District of New York)

**Facts:** The EEOC filed suit against iTutor Group, an online education platform, alleging that its AI-powered recruiting software automatically rejected job applicants who were 55 or older (for women) or 60 or older (for men) based on dates of birth entered in the application system. The software's age-filtering algorithm was designed to exclude older candidates without human review.

**Issue:** Whether the use of age-based automated filtering in recruitment software constituted intentional age discrimination under the Age Discrimination in Employment Act (ADEA).

**Holding:** iTutor Group agreed to a $365,000 consent decree, ceased using the discriminatory screening parameters, adopted anti-discrimination policies, and submitted to EEOC monitoring for three years.
**Significance:** Largest EEOC AI-discrimination settlement to date, establishing significant financial consequences for algorithmic bias in hiring.
Demonstrates that "hard-coded" discriminatory criteria in software constitute intentional discrimination under federal law.
Signals the EEOC's increasing enforcement focus on AI and automated decision-making in employment.

---

### Case 11.39: German Works Council —Employee Data Protection Co-Determination (2019)

**Date Decided:** 2019 (Bundesarbeitsgericht decision 1 ABR 22/18)

**Court:** Bundesarbeitsgericht (German Federal Labor Court)

**Facts:** A German employer sought to introduce a new employee-monitoring system that would track employees' computer usage, including keystrokes, application use, and website visits. The works council (Betriebsrat) objected, asserting its co-determination rights under the German Works Constitution Act (BetrVG) § 87(1)(6).

**Issue:** Whether the works council had mandatory co-determination rights over the introduction and operation of employee monitoring technologies that process personal data.

**Holding:** The Federal Labor Court confirmed the works council's co-determination rights, holding that the introduction of any technology designed to monitor employee behavior or performance triggers mandatory employer'orks council negotiation. The employer could not implement the monitoring system without the works council's consent or a substitute resolution by the conciliation board (Einigungsstelle).
**Significance:** Strongly affirms German co-determination as a structural safeguard against unilateral employer surveillance.
Creates a powerful countervailing force to employer-initiated workplace monitoring, requiring collective negotiation rather than top-down implementation.
Serves as a model for worker participation in digital workplace governance under EU policy frameworks.

---

### Case 11.40: France —Mass Digital Dismissal (2017–2021)

**Date Decided:** 2021 (Cour de cassation, Social Chamber)

**Court:** Cour de cassation (French Supreme Court, Social Chamber)

**Facts:** In a series of cases following high-profile restructuring at major French companies (including PSA Peugeot Citron and Orange), employers used algorithmic performance metrics, digital productivity tracking data, and automated HR systems to select employees for dismissal during large-scale redundancy programs. Affected employees challenged the use of digital data as the basis for individual termination decisions.

**Issue:** Whether employers could rely on algorithmically generated performance data and digital monitoring metrics as the primary basis for selecting employees for dismissal, and whether employees had a right to access and challenge the underlying data.

**Holding:** The Cour de cassation held that while employers may use objective criteria for redundancy selection, employees must be informed of the specific data and criteria used in their individual assessment and must have a meaningful opportunity to challenge the data's accuracy. Purely algorithmic decisions without human review were deemed insufficient.
**Significance:** Affirms the right of French workers to transparency and human oversight in algorithmically mediated termination decisions.
Aligns with GDPR Article 22's right not to be subject to purely automated decision-making with legal effects.
Establishes that digital performance data used in dismissal proceedings must meet evidentiary standards of accuracy and relevance.

---

### Case 11.41: China —Former Employee Data Breach Case (2021) —Hangzhou Internet Court

**Date Decided:** 2021

**Court:** Hangzhou Internet Court ( ?

**Facts:** A former employee of a Chinese technology company was prosecuted after it was discovered that, prior to his resignation, he had downloaded large volumes of confidential business data, including customer lists, source code, and trade secrets, using his company-issued computer and personal storage devices. The employer traced the unauthorized data transfers through server access logs and filed both civil and criminal complaints.

**Issue:** Whether the former employee's extraction and retention of company data constituted a violation of China's Cybersecurity Law, Data Security Law, and relevant provisions of the Criminal Law regarding theft of commercial secrets.

**Holding:** The Hangzhou Internet Court found the defendant liable for unauthorized access to computer information systems and theft of commercial secrets, ordering compensation and imposing a criminal sentence. The court emphasized the employer's right to digital forensics and data audit as a means of protecting trade secrets.
**Significance:** Demonstrates China's increasingly robust legal framework for protecting employer data assets through both civil and criminal enforcement.
Highlights the role of digital forensics and access-log analysis in Chinese employment disputes.
Reflects the intersection of data security law, cybersecurity law, and employment law in the Chinese digital economy.

---

### Case 11.42: China —Non-Compete Network Forensics (2022) —Shenzhen Intermediate People's Court

**Date Decided:** 2022

**Court:** Shenzhen Intermediate People's Court ( ?

**Facts:** A technology company in Shenzhen alleged that a former senior engineer violated his non-compete agreement by joining a competitor. The employer presented digital forensic evidence, including WeChat communication records, LinkedIn profile data, email metadata, and IP address logs, demonstrating that the former employee had engaged with the competitor during his non-compete period.

**Issue:** Whether digital forensic evidence derived from social media, communication platforms, and network logs could establish a violation of a post-employment non-compete agreement under Chinese labor law.

**Holding:** The court accepted the digital forensic evidence as admissible and sufficient to establish the non-compete violation, ordering the former employee to pay liquidated damages and to comply with the remaining non-compete obligations. The court recognized the probative value of digitally obtained evidence when collected lawfully.
**Significance:** Establishes the admissibility and weight of digital forensic evidence in Chinese employment disputes, including evidence from social media and messaging platforms.
Reflects growing judicial acceptance of network forensics as a standard tool in enforcing post-employment restrictions.
Raises questions about the balance between employer enforcement rights and former employees' privacy in their personal digital communications.

---

### Case 11.43: Japan —LINE Monitoring Case (2021) —Tokyo District Court

**Date Decided:** 2021

**Court:** Tokyo District Court ( )

**Facts:** A Japanese employer required employees to install LINE (a popular messaging application) on company-issued smartphones for business communication. A supervisor routinely accessed employees' LINE chat logs, including private conversations conducted during breaks. An employee sued, alleging violation of his right to privacy under Article 13 of the Japanese Constitution and the Labour Standards Act.

**Issue:** Whether an employer's access to employee LINE messages on a company-issued device violated constitutional and statutory privacy protections.

**Holding:** The Tokyo District Court ruled that the employer's monitoring of LINE communications was unlawful, finding that employees retained a reasonable expectation of privacy in personal communications even on work devices. The court ordered the employer to cease the monitoring and awarded damages.
**Significance:** Establishes that Japanese workers have constitutional privacy protections against employer monitoring of personal communications on work devices.
Recognizes the distinction between business and personal communications on unified messaging platforms.
Influences the development of Japanese corporate governance standards for digital workplace communications.

---

### Case 11.44: Japan —Worker Communication Secrecy (2020) —Osaka High Court

**Date Decided:** 2020

**Court:** Osaka High Court (  )

**Facts:** A municipal government employee in Osaka was disciplined after his employer discovered, through the review of his work email account, that he had been communicating with a labor union representative about workplace grievances. The employer argued that the monitoring was conducted for legitimate administrative purposes. The employee claimed that the monitoring violated his right to correspondence secrecy and freedom of association.

**Issue:** Whether the monitoring of employee work emails that revealed union communications violated the right to correspondence secrecy under the Japanese Constitution and labor union law protections.

**Holding:** The Osaka High Court found that the employer's email monitoring was unlawful, holding that employees' work-related communications are protected by the constitutional guarantee of secrecy of correspondence. The court noted that the monitoring disproportionately intruded upon the employee's right to engage in union activities.
**Significance:** Extends Japanese constitutional correspondence protections to the digital workplace, including employer-issued email systems.
Protects union-related communications from employer surveillance, reinforcing labor organizing rights.
Contributes to the emerging Japanese jurisprudence on digital workplace privacy, traditionally a gap in Japanese labor law.

---

### Case 11.45: South Korea —Workplace Monitoring Decision (2022) —Supreme Court of Korea

**Date Decided:** 2022

**Court:** Supreme Court of Korea ( )

**Facts:** A South Korean company installed surveillance cameras and keystroke-logging software on employees' work computers to monitor productivity and prevent data leaks. Employees challenged the monitoring, arguing that it violated their constitutional right to privacy under Article 17 of the Korean Constitution and the Personal Information Protection Act (PIPA).

**Issue:** Whether the employer's comprehensive workplace monitoring through cameras and keystroke-logging software was proportionate and lawful under Korean constitutional and data protection law.

**Holding:** The Supreme Court of Korea held that while employers have a legitimate interest in monitoring workplace activities, the surveillance system must be proportionate, necessary, and subject to prior notification and worker consultation. The court found the keystroke-logging software to be disproportionate as it captured all keyboard input without differentiation between personal and work-related activity.
**Significance:** Establishes proportionality as the governing standard for workplace surveillance under Korean constitutional law.
Provides explicit judicial recognition that keystroke-logging software constitutes a particularly intrusive form of monitoring requiring strict justification.
Aligns Korean jurisprudence with global trends toward proportionality-based assessment of workplace surveillance.

---

### Case 11.46: O'Keefe v. Williams (2020) —Fair Work Commission, Australia

**Date Decided:** 11 February 2020

**Court:** Fair Work Commission (Australia)

**Facts:** An Australian employee was dismissed after making a series of social media posts on Facebook that were critical of her employer's handling of workplace safety during the early stages of the COVID-19 pandemic. The employer argued that the posts were damaging to its reputation. The employee claimed unfair dismissal.

**Issue:** Whether the employee's social media posts constituted a valid reason for dismissal, considering her right to express concerns about workplace safety and the public interest nature of the posts.

**Holding:** The Fair Work Commission found the dismissal was unfair, holding that the employee's posts addressed matters of legitimate public health concern and did not contain defamatory or abusive content. The Commission ordered reinstatement and compensation.
**Significance:** Establishes that Australian employees may lawfully use social media to express genuine concerns about workplace safety, particularly on matters of public interest.
Applies a balancing test weighing the employer's reputational interests against the employee's right to free expression and public-interest communication.
Provides guidance on the circumstances under which social media activity does not constitute a valid reason for termination under the Fair Work Act 2009 (Cth).

---

### Case 11.47: Richardson v. Oracle (2014) —Federal Court of Australia

**Date Decided:** 22 August 2014

**Court:** Federal Court of Australia

**Facts:** An Oracle employee, Ms. Richardson, was subjected to a toxic workplace environment and was ultimately terminated after raising complaints about bullying and harassment. She alleged that the company's internal investigation into her complaints was inadequate and biased, and that her personal data was improperly accessed and used during the investigation process.

**Issue:** Whether the employer's handling of internal investigations, including the collection and use of employee personal data, violated Australian privacy law and employment protections, and whether the termination was harsh, unjust, or unreasonable.

**Holding:** The Federal Court found in favor of the employee, awarding significant damages for breach of the Privacy Act and adverse action under the Fair Work Act. The court criticized Oracle's investigation as procedurally unfair and found that personal data had been used in a manner inconsistent with Australian Privacy Principles.
**Significance:** One of Australia's largest workplace privacy and employment law damages awards, signaling serious consequences for mishandling employee data during internal investigations.
Applies Australian Privacy Principles to the employment context, requiring collection limitation, use limitation, and data quality in internal workplace investigations.
Demonstrates the intersection of employment law, privacy law, and workplace health and safety obligations in Australia.

---

### Case 11.48: R. v. Cole (2012) —Supreme Court of Canada

**Date Decided:** 27 October 2012

**Court:** Supreme Court of Canada

**Facts:** A high school teacher was charged with possession of child pornography after his employer's IT department, acting on information from a school board technician, discovered illicit images on his employer-issued laptop. The police obtained the laptop from the employer without a warrant and conducted a forensic search.

**Issue:** Whether the teacher had a reasonable expectation of privacy in the contents of his employer-issued laptop, such that police required a warrant to search it.

**Holding:** The Supreme Court of Canada held unanimously that the teacher did have a reasonable expectation of privacy in his work laptop, notwithstanding the employer's ownership and legitimate interest in monitoring the device. The police should have obtained a warrant before conducting the forensic search.
**Significance:** Landmark Canadian ruling establishing that employees retain a reasonable expectation of privacy in personal information stored on employer-owned devices.
Rejects the binary "company owns the computer, therefore no privacy" approach, adopting a nuanced contextual analysis.
Has been widely cited in employment law, criminal law, and privacy law contexts across Canada and internationally.

---

### Case 11.49: Lindqvist v. Sweden (2003) —Court of Justice of the European Union

**Date Decided:** November 2003

**Court:** Court of Justice of the European Communities (CJEU)

**Facts:** A Swedish woman, Mrs. Lindqvist, created a personal website on which she posted information about her colleagues at a church parish, including their first names, family circumstances, and in some cases partial medical information (e.g., that a colleague had injured her foot and was on half-time work). She was prosecuted under Swedish data protection legislation for processing personal data without notification to the supervisory authority.

**Issue:** Whether the activity of making personal data available on a website constituted "processing" of personal data within the meaning of the EU Data Protection Directive (95/46/EC), and whether such processing was subject to the Directive's requirements including notification to supervisory authorities.

**Holding:** The CJEU held that the act of loading personal data onto an internet webpage constituted "processing" under the Directive. The Court also held that the Directive applied to the activity because it involved the transmission of personal data to third parties via the internet (making it available to potentially unlimited numbers of people). The case was referred back to the national court for final determination.
**Significance:** Established foundational principles of EU data protection law for the internet era, confirming that posting personal information online constitutes data processing subject to the Data Protection Directive.
Clarified that the Directive's scope extends to freely accessible websites, establishing the basis for the EU's expansive approach to online data processing regulation that continued under the GDPR.

---

### Case 11.50: Kpke v. Germany (2010) —European Court of Human Rights

**Date Decided:** October 2010

**Court:** European Court of Human Rights (ECHR)

**Facts:** Stefan Kpke, a German citizen, was employed by the European Commission in Brussels. German intelligence services (BND) conducted covert surveillance of his telecommunications, monitoring his phone calls and faxes, based on suspicion that he was providing classified information to the press. The surveillance was authorized under German law for the protection of state security. Kpke challenged the surveillance as a violation of his right to private life under Article 8 of the European Convention on Human Rights.

**Issue:** Whether the covert surveillance of a German citizen's communications by German intelligence services violated Article 8 of the ECHR, and whether the legal framework governing such surveillance provided adequate safeguards against abuse.

**Holding:** The ECHR held that the surveillance of Kpke's communications constituted an interference with his Article 8 right to respect for private life. While the Court accepted that the surveillance pursued a legitimate aim (national security), it found that the German legal framework at the time lacked sufficient procedural safeguards, including inadequate judicial oversight and insufficient provisions for notifying the individual after surveillance concluded. The Court found a violation of Article 8.
**Significance:** Established that intelligence surveillance requires robust legal frameworks with independent judicial authorization and effective oversight mechanisms under the ECHR.
Contributed to the ECHR's evolving jurisprudence on state surveillance, which later informed decisions in Weber and Saravia v. Germany (2006), Zakharov v. Russia (2015), and Big Brother Watch v. UK (2021).

---

### Case 11.51: Libert v. Belgium (2021) —European Court of Human Rights

**Date Decided:** June 2021

**Court:** European Court of Human Rights (ECHR), Grand Chamber

**Facts:** Two Belgian citizens, Franck Libert and another individual, discovered that the Belgian State Security Service (Sreté de l'tat) had intercepted their telecommunications over a period of years based on suspected connections to terrorism. The surveillance was conducted under a 2010 Belgian law governing intelligence-gathering methods. The applicants argued that the law provided insufficient safeguards against arbitrary surveillance, including inadequate judicial authorization, no effective remedy for those under surveillance, and insufficient oversight mechanisms.

**Issue:** Whether the Belgian legal framework governing intelligence surveillance provided adequate safeguards against arbitrary interference with the right to private life under Article 8 of the ECHR.

**Holding:** The Grand Chamber held, by a narrow majority, that the Belgian legal framework for intelligence surveillance contained insufficient safeguards and violated Article 8. Key deficiencies included the absence of prior judicial authorization for surveillance measures (relying instead on executive authorization), the lack of an effective post-surveillance notification mechanism, and insufficient independent oversight of the intelligence services.
**Significance:** Reinforced the requirement that intelligence surveillance must be subject to prior independent judicial authorization, a standard that applies across Council of Europe member states.
Contributed to the development of a consistent European standard for intelligence oversight, reinforcing the ECHR's role as a counterbalance to national security claims.

---

### Case 11.52: R v. Cole (2012) —Supreme Court of Canada

**Date Decided:** October 2012

**Court:** Supreme Court of Canada

**Facts:** Richard Cole, a high school teacher, was suspected of using a school-issued laptop to access and store nude photographs of a student. The school's IT technician, acting on instructions from the school principal, examined Cole's laptop and discovered the photographs in a hidden folder on the web browser cache. The school then turned the laptop over to police, who conducted a forensic search without a warrant. Cole was charged with possession of child pornography and possession for the purpose of trafficking. He challenged the warrantless police search as a violation of his Section 8 Charter rights.

**Issue:** Whether Cole had a reasonable expectation of privacy in the contents of his employer-issued laptop, and whether the police violated his Section 8 Charter rights by conducting a warrantless search of the laptop.

**Holding:** The Supreme Court of Canada held unanimously that Cole had a reasonable expectation of privacy in the information on his work laptop, notwithstanding that it was owned by his employer and connected to the school's network. However, the Court found that the initial search by the school IT technician (acting in the context of maintaining the school's IT system) was reasonable under the employer's authority. The police warrantless search, however, violated Section 8 and the evidence was excluded under Section 24(2).
**Significance:** Established that individuals retain privacy interests in personal information on work-issued devices, rejecting the argument that employer ownership eliminates all privacy expectations.
Clarified the distinction between employer/IT-administration searches (governed by workplace policies and reasonableness) and law enforcement searches (requiring a warrant under Section 8), with significant implications for BYOD and workplace surveillance policies.

---

### Case 11.53: iTutor Group AI Discrimination —EEOC (2023) —Equal Employment Opportunity Commission

**Date Decided:** August 2023 (EEOC determination and settlement)

**Court:** U.S. Equal Employment Opportunity Commission (EEOC) / U.S. District Court for the Eastern District of New York

**Facts:** The EEOC filed suit against iTutor Group, Inc. and its subsidiary entities, operators of online English-language tutoring platforms serving students in China, alleging that the company used AI-powered resume screening software that automatically rejected job applicants who were older than 55 (for women) or 60 (for men) based on their date of birth. The discriminatory software allegedly rejected over 200 qualified applicants. The AI tool was programmed with age-based filtering criteria that automatically excluded older applicants without human review of their qualifications.

**Issue:** Whether the use of AI-powered hiring software that automatically screened out older job applicants based solely on age violated the Age Discrimination in Employment Act (ADEA).

**Holding:** iTutor Group agreed to a consent decree settling the lawsuit, paying $365,000 to the affected job applicants, adopting anti-discrimination policies, and committing not to use AI recruitment tools that discriminate based on age. The company was also required to conduct regular audits of its AI screening tools and provide anti-discrimination training to staff involved in hiring decisions.
**Significance:** First EEOC resolution of a hiring discrimination case involving AI-powered screening tools, establishing enforcement precedent for algorithmic discrimination in employment.
Signaled the EEOC's commitment to scrutinizing AI and automated decision-making tools for discriminatory bias, issuing subsequent guidance on AI and employment discrimination in 2023–2024.

---

### Case 11.54: Nielsen v. LinkedIn Corp. (2024) — US District Court, N.D. California

**Date Decided:** 2024

**Court:** US District Court, N.D. California

**Facts:** A class of LinkedIn Premium subscribers alleged that LinkedIn shared their private messages with third-party AI training partners without consent, violating the California Invasion of Privacy Act (CIPA) and the Stored Communications Act (SCA). LinkedIn argued that its Terms of Service permitted such data sharing and that users had consented through the platform's privacy policy.

**Issue:** Whether LinkedIn's Terms of Service constituted valid consent for sharing user messages with AI training partners under California privacy law.

**Holding:** The court denied LinkedIn's motion to dismiss, holding that the Terms of Service language was insufficient to establish express consent for AI training use of private communications. The case proceeded to discovery.
**Significance:** Established that blanket Terms of Service provisions may not satisfy express consent requirements for sensitive data uses like AI training.
Extended CIPA analysis to AI training contexts, creating new liability exposure for platforms leveraging user data for AI development.

---

# Part 12 — Emerging Issues & Cross-Cutting Themes

## Chapter 12: Cross-Cutting Themes in Cyber Law

The boundaries between the thematic areas addressed in the preceding Parts are increasingly fluid. This Part examines cases that span multiple doctrinal domains — where platform liability intersects with copyright, where cybersecurity concerns implicate privacy rights, and where artificial intelligence governance overlaps with consumer protection and employment law.


### Case 12.1: Mirai Botnet —IoT-Driven DDoS Attacks (2016) —US DOJ

**Date Decided:** December 2017 (plea agreements); May 2018 (sentencing)

**Court:** US District Court for the District of Alaska
Case citation: United States v. Jha, No. 3:17-cr-00047 (D. Alaska)

**Facts:** In September 2016, the Mirai botnet leveraged hundreds of thousands of compromised Internet of Things (IoT) devices —including security cameras, routers, and digital video recorders protected by default or hard-coded credentials —to launch massive distributed denial-of-service (DDoS) attacks. The most significant attack targeted Dyn, a major DNS provider, on October 21, 2016, disrupting access to major platforms including Twitter, Netflix, Reddit, and GitHub across much of the eastern United States. Three individuals —Paras Jha, Josiah White, and Dalton Norman —were identified as the creators.

**Issue:** Whether the creation and deployment of self-propagating malware targeting IoT devices constitutes criminal conduct under the Computer Fraud and Abuse Act (18 U.S.C. § 1030), and whether the defendants' cooperation with law enforcement mitigated sentencing.

**Holding:** All three defendants pleaded guilty to conspiracy to commit computer fraud. Jha and White received probation (6 months home confinement, 2,500 hours community service); Norman received three years' probation and 2,000 hours of community service. Light sentences reflected cooperation, youth, and contributions to cybersecurity.
**Significance:** IoT as attack infrastructure. The Mirai case demonstrated that inadequately secured consumer IoT devices created a vast, easily exploitable attack surface, transforming household appliances into weapons capable of disrupting significant portions of the global internet.
Default credentials as systemic vulnerability. The case exposed the failure of device manufacturers to implement basic security hygiene, catalyzing regulatory efforts including California's SB-327 and federal proposals for minimum IoT security standards.
Cooperation as mitigating factor. The lenient sentences reflected the DOJ's calculation that defendants' ongoing cooperation and cybersecurity contributions provided greater public benefit than incarceration, establishing a notable sentencing precedent for malware cases.

---

### Case 12.2: United States v. Huawei Technologies Co. / Meng Wanzhou (2018–2021) —US District Court for the Eastern District of New York
**Date Decided:** 2018–2021

**Court:** US District Court for the Eastern District of New York; Supreme Court of British Columbia, Canada (extradition)
Case citation: United States v. Huawei Technologies Co. Ltd. et al., No. 18-cr-667 (E.D.N.Y.)

**Facts:** The DOJ unsealed a 13-count indictment against Huawei and its CFO, Meng Wanzhou, charging conspiracy to violate IEEPA by conducting business with Iran and Syria in violation of US sanctions, conspiracy to commit bank fraud, wire fraud, and obstruction of justice. Meng was arrested in Vancouver in December 2018, triggering a three-year extradition battle that became a major US-China diplomatic flashpoint. In September 2021, Meng reached a deferred prosecution agreement and returned to China.

**Issue:** Whether Huawei's use of a subsidiary (Skycom) to conduct prohibited transactions with Iran constituted sanctions evasion under IEEPA, and whether Meng's alleged misrepresentations to HSBC constituted bank fraud. Extradition proceedings tested dual-criminality and the political offense exception.

**Holding:** Meng's DPA allowed her to avoid prosecution in exchange for a statement of facts. The Huawei entity case proceeded; the company was convicted on sanctions fraud and trade secret theft charges. The British Columbia Supreme Court ruled extradition valid under Canadian law.
**Significance:** Extraterritorial application of US sanctions. The case underscored the extraordinary reach of US sanctions enforcement, triggered by any transaction conducted in US dollars regardless of where the underlying conduct occurs —with profound implications for global commerce and non-US financial institutions.
Technology decoupling precedent. The Huawei case became a central episode in US strategy restricting Chinese access to advanced semiconductor and telecommunications technology, establishing legal precedents for using entity listings, export controls, and criminal prosecution as instruments of technological competition.
Extradition law and geopolitics. The Meng proceedings became a case study in the intersection of law enforcement and geopolitics, with China detaining two Canadian citizens (Michael Kovrig and Michael Spavor) in what was widely viewed as retaliatory hostage diplomacy.

---

### Case 12.3: SEC v. Ripple Labs, Inc. / XRP (2020–2023) —US District Court for the Southern District of New York
**Date Decided:** 2020–2023

**Court:** US District Court for the Southern District of New York (Judge Analisa Torres)
Case citation: SEC v. Ripple Labs, Inc., 680 F. Supp. 3d 338 (S.D.N.Y. 2023)

**Facts:** The SEC alleged that Ripple's sales of XRP —a digital asset created in 2012 —constituted an unregistered securities offering under Section 5 of the Securities Act of 1933. The SEC alleged Ripple raised approximately $1.38 billion through institutional sales and that XRP tokens were investment contracts because purchasers relied on Ripple's efforts to develop the ecosystem. Ripple countered that XRP was a currency or commodity.

**Issue:** Whether XRP tokens, sold in various contexts (institutional sales, programmatic exchange sales, and distributions), constitute "investment contracts" under the Howey test requiring registration under federal securities law.

**Holding:** Judge Torres issued a mixed ruling: institutional sales of XRP (direct sales to sophisticated buyers) constituted investment contracts, while programmatic sales on public exchanges (blind bid/ask transactions where buyers did not know they were purchasing from Ripple) did not. Ripple was ordered to pay $125 million in civil penalties —far less than the SEC's requested $2 billion. Both parties appealed.
**Significance:** Howey test applied to crypto. The most significant judicial application of the Howey test to digital assets, establishing that token characterization depends on the specific circumstances of each sale —the "context matters" principle foundational in crypto securities law.
Programmatic vs. institutional sales distinction. The court's distinction provided a roadmap for the crypto industry, suggesting that secondary market trading may not constitute securities transactions even if the initial offering did.
Fair notice defense. Ripple's partial success highlighted regulatory uncertainty created by the SEC's enforcement-first approach and contributed to criticism of the agency's refusal to provide clear guidance on token classification.

---

### Case 12.4: United States v. Bankman-Fried / FTX (2022–2023) —US District Court for the Southern District of New York
**Date Decided:** 2022–2023

**Court:** US District Court for the Southern District of New York (Judge Lewis Kaplan)
Case citation: United States v. Bankman-Fried, No. 22-cr-673 (S.D.N.Y.)

**Facts:** Samuel Bankman-Fried (SBF), founder of cryptocurrency exchange FTX, was charged with seven counts of fraud, conspiracy, and money laundering following FTX's collapse in November 2022. The collapse revealed that approximately $8 billion in customer funds had been diverted from FTX to Alameda Research for speculative trading, venture investments, political donations, and real estate. Three close associates —Caroline Ellison, Gary Wang, and Nishad Singh —pleaded guilty and testified against him.

**Issue:** Whether Bankman-Fried knowingly defrauded FTX customers, lenders, and investors, constituting wire fraud, securities fraud, commodities fraud, conspiracy to commit money laundering, and campaign finance violations.

**Holding:** The jury convicted SBF on all seven counts. Judge Kaplan sentenced him to 25 years in prison and ordered forfeiture of approximately $11 billion —one of the longest sentences and largest forfeiture orders in a white-collar fraud case.
**Significance:** Crypto industry credibility crisis. The FTX collapse triggered the most severe credibility crisis in cryptocurrency history, catalyzing a global regulatory crackdown including EU MiCA implementation, SEC enforcement against other exchanges, and legislative proposals worldwide.
Corporate governance failure. The case exposed the failure of corporate governance at FTX —no independent board, commingled funds, no basic internal controls —and raised questions about accountability of leaders claiming moral authority while engaging in massive fraud.
Sentencing precedent for crypto fraud. The 25-year sentence and $11 billion forfeiture signaled that crypto fraud would be treated with the same severity as traditional financial fraud, establishing a deterrent precedent for the industry.

---

### Case 12.5: OFAC Sanctions on Tornado Cash (August 2022) —US Department of the Treasury
**Court:** U.S. Department of the Treasury (OFAC)

**Date Decided:** August 8, 2022
Court/Authority: US Department of the Treasury, Office of Foreign Assets Control (OFAC)
Regulatory citation: 87 Fed. Reg. 48682 (Aug. 8, 2022); 31 C.F.R. Part 590

**Facts:** OFAC designated Tornado Cash —an open-source, non-custodial Ethereum mixing protocol —as a Specially Designated National (SDN) pursuant to Executive Order 13694, finding it had been used by the DPRK's Lazarus Group to launder approximately $455 million in stolen cryptocurrency. OFAC also sanctioned the protocol's creator, Alexey Pertsev. Tornado Cash was a decentralized smart contract protocol operating autonomously on the Ethereum blockchain without any centralized operator or custodian.

**Issue:** Whether OFAC has legal authority under IEEPA and E.O. 13694 to sanction a decentralized, open-source software protocol (a smart contract) that operates autonomously without any centralized operator who can control or prevent its use.

**Holding:** OFAC designated the protocol and its operators. The designation prohibited all US persons from interacting with Tornado Cash smart contracts. General licenses authorized certain wind-down transactions. The sanctions effectively cut US users off from the protocol and had significant chilling effects on the broader DeFi ecosystem.
**Significance:** Can code be sanctioned? The first time a government sanctioned a decentralized software protocol rather than a person or entity, raising fundamental questions about the limits of sanctions authority over immutable, autonomous code.
Chilling effect on open-source development. The sanctions created uncertainty about whether contributing to, auditing, or maintaining open-source privacy tools could result in personal liability, with implications for the entire open-source ecosystem.
Innovation vs. illicit finance. The case crystallized the tension between financial privacy tools (with legitimate uses for individuals under repressive regimes, whistleblowers, and privacy-conscious users) and law enforcement's interest in preventing money laundering.

---

### Case 12.6: Van Loon et al. v. US Department of the Treasury / Tornado Cash Litigation (2023) —US Court of Appeals for the Fifth Circuit
**Date Decided:** 2023

**Court:** US Court of Appeals for the Fifth Circuit
Case citation: Van Loon v. Dep't of Treasury, 87 F.4th 855 (5th Cir. 2023)

**Facts:** Six plaintiffs —including Coinbase and individual Tornado Cash users —challenged OFAC's designation under the APA and the First Amendment. They argued that OFAC exceeded its IEEPA authority by sanctioning immutable, decentralized smart contracts rather than property of a foreign national or entity. Coinbase argued the sanctions imposed impossible compliance burdens.

**Issue:** Whether OFAC's designation of the Tornado Cash smart contracts as "property" of a designated entity is a lawful exercise of OFAC's authority under IEEPA, and whether the designation violates First Amendment rights to engage in anonymous speech and support open-source software.

**Holding:** The Fifth Circuit affirmed OFAC's designation in a 2-1 decision, holding that immutable smart contracts constituted "property" under IEEPA and that the sanctions imposed an incidental burden on speech justified by the government's compelling interest. The Supreme Court denied certiorari in October 2024.
**Significance:** Judicial deference to OFAC in DeFi. The decision established that existing sanctions law would be applied to decentralized protocols with minimal adaptation, with courts extending significant deference to OFAC.
Open-source code as regulatable property. By holding that immutable smart contracts constitute "property" subject to sanctions, the court created a precedent with far-reaching implications for regulating any decentralized autonomous software.
Certiorari denial leaves regulatory gap. The Supreme Court's denial left the tension between decentralized technology and centralized regulation to the political branches, increasing urgency of legislative action for DeFi regulation.

---

### Case 12.7: SEC v. Terraform Labs, Pte. Ltd. / Do Kwon (2023–2024) —US District Court for the Southern District of New York
**Date Decided:** 2023–2024

**Court:** US District Court for the Southern District of New York (Judge Jed Rakoff)
Case citation: SEC v. Terraform Labs Pte. Ltd., No. 23-cv-1346 (S.D.N.Y.)

**Facts:** The SEC alleged that Terraform Labs and its founder Do Kwon issued Terra (LUNA) tokens and the TerraUSD (UST) algorithmic stablecoin as unregistered securities. The Terra ecosystem collapsed in May 2022 when UST lost its dollar peg, triggering a "death spiral" that destroyed approximately $40 billion in market value within days. Do Kwon was arrested in Montenegro in March 2023 and faced competing US and South Korean extradition requests.

**Issue:** Whether LUNA, UST, and related tokens were investment contracts under the Howey test, and whether Terraform Labs engaged in securities fraud by misrepresenting UST's stability mechanism.

**Holding:** Judge Rakoff ruled for the SEC on all counts. The court ordered Terraform Labs to pay $4.47 billion in disgorgement and civil penalties and imposed a permanent injunction. Kwon was convicted in Montenegro of document forgery.
**Significance:** Algorithmic stablecoins under securities law. The case established that algorithmic stablecoins can constitute securities when marketed as stable investments, with significant implications for the broader stablecoin ecosystem and pending legislation.
DeFi "decentralization" claims scrutinized. The court rejected arguments that Terra was sufficiently decentralized, noting centralized control over key protocol decisions and marketing —a principle applied in subsequent SEC enforcement actions.
Cross-border enforcement challenges. Kwon's flight, arrest, and competing extradition requests illustrated practical challenges of enforcing US securities law against internationally operating crypto founders.

---

### Case 12.8: Jeep Cherokee Remote Hack (2015) —Miller & Valasek / NHTSA Recall
**Date Decided:** 2015
**Court:** U.S. NHTSA / Multi-Jurisdictional

**Facts:** Security researchers Charlie Miller and Chris Valasek demonstrated they could remotely exploit a 2014 Jeep Cherokee's Uconnect infotainment system over a cellular connection, gaining access to the vehicle's CAN bus and thereby acquiring control of steering, braking, transmission, and acceleration. Fiat Chrysler Automobiles recalled approximately 1.4 million vehicles and distributed a software patch.

**Issue:** Whether remote exploitation of a connected vehicle's infotainment system to gain control of safety-critical functions constituted a safety defect under the National Traffic and Motor Vehicle Safety Act, and whether existing frameworks were adequate for automotive cybersecurity.

**Holding:** FCA voluntarily recalled 1.4 million vehicles. NHTSA issued guidance on automotive cybersecurity best practices. The US Senate Commerce Committee held hearings. Miller and Valasek were subsequently hired by Uber's Advanced Technologies Center.
**Significance:** Connected vehicles as cyber-physical systems. The first publicly demonstrated remote exploit of a production vehicle's safety-critical functions, transforming abstract automotive cybersecurity risk into tangible public safety concern.
Regulatory frameworks for automotive cybersecurity. The case exposed the inadequacy of NHTSA frameworks designed for mechanical safety defects, contributing to NHTSA's Cybersecurity Best Practices (2016) and EU UN Regulation No. 155 for cybersecure vehicles.
Responsible disclosure in safety-critical contexts. The case established an important precedent for coordinated vulnerability disclosure in cyber-physical systems compatible with public interest journalism.

---

### Case 12.9: Viasat KA-SAT Cyberattack (February 2022) —Ukraine Conflict
**Date Decided:** 2022

**Facts:** Hours before Russia's invasion of Ukraine, a cyberattack targeted the KA-SAT satellite network operated by Viasat, deploying "AcidPour" wiper malware that disabled tens of thousands of modems across Europe. The disruption affected Ukrainian military communications and civilian customers in multiple European countries, including wind turbines in Germany. Western intelligence attributed the attack to Russia's GRU Unit 74455 (Sandworm).

**Issue:** Whether the cyberattack on civilian satellite infrastructure violated international law, including the prohibition on the use of force (UN Charter Article 2(4)) and the principle of distinction under international humanitarian law.

**Holding:** No criminal proceedings against Russian state actors. The EU imposed sanctions. NATO invoked Article 5 consultation. Viasat restored service through hardware replacement. The EU and US jointly attributed the attack to Russia.
**Significance:** Cyber operations as a component of armed conflict. The most significant cyber operation conducted in conjunction with a major conventional invasion, establishing precedent for integration of cyber operations into kinetic warfare planning.
Civilian infrastructure and IHL. The disruption of civilian satellite communications across multiple countries tested the application of distinction, proportionality, and precaution principles to cyber operations in armed conflict.
Space infrastructure as cyber target. The targeting of satellite communications represented significant escalation, demonstrating space-based assets are vulnerable to cyber operations with cascading cross-sector effects.

---

### Case 12.10: Genesis Market Takedown —Operation Cookie Monster (April 2023) —FBI/International Law Enforcement**Date Decided:** 2023
**Court:** U.S. Federal Law Enforcement (FBI-led International Operation)

**Facts:** The FBI led Operation Cookie Monster to dismantle Genesis Market, a major illicit marketplace selling stolen browser fingerprints, session cookies, and login credentials harvested through information-stealing malware (RedLine, Raccoon). The subscription-based service facilitated approximately $80 million in losses globally and was linked to ransomware attacks and BEC schemes. The operation seized approximately 120 domains, arrested multiple individuals, and issued over 200 search warrants.

**Issue:** The legal framework for dismantling transnational illicit marketplaces through coordinated multi-jurisdictional action, including authority to seize domains and servers across multiple countries.

**Holding:** Genesis Market infrastructure was seized and disabled. Approximately 120 individuals arrested across 17 countries. The FBI's innovative seizure banner redirected visitors to a victim notification page. Multiple prosecutions followed.
**Significance:** Browser fingerprint data as criminal commodity. The case highlighted the threat of stolen session data enabling attackers to bypass multifactor authentication entirely by purchasing existing authenticated sessions.
International coordination model. Operation Cookie Monster was cited as one of the most successful examples of international cybercrime enforcement coordination, replicated in subsequent operations.
Victim notification through domain seizure. The FBI's use of seizure banners to notify victims represented a novel approach to victim notification, leveraging domain seizure visibility to reach individuals unaware their data was stolen.

---

### Case 12.11: BreachForums Seizure by the FBI (March 2023–2024) —US Federal Authorities**Date Decided:** 2023–2024
**Court:** U.S. Federal Law Enforcement (FBI)

**Facts:** BreachForums was a major English-language data breach marketplace that emerged after the FBI's RaidForums seizure in 2022. The platform facilitated the sale and distribution of stolen data from corporate and government breaches. In March 2023, the FBI seized the domain and arrested administrator Conor Brian Fitzpatrick ("Baphomet"). The forum briefly revived under new management before being seized again in March 2024.

**Issue:** The legal framework for seizing and disrupting cybercrime forums, including authority to seize domains, prosecution of administrators, and the challenge of forum resurrection under new management.

**Holding:** Fitzpatrick pleaded guilty and was sentenced in 2024. The forum was seized, disrupted, and re-seized upon revival. The second administrator was also arrested. Multiple users were identified and prosecuted.
**Significance:** Forum hopping and enforcement resilience. The case demonstrated "forum hopping" —where seizure of one marketplace leads to rapid emergence of successors —and the challenges of sustaining enforcement against decentralized cybercrime communities.
Industrialization of data theft. The case highlighted the emergence of sophisticated underground marketplaces where stolen databases are cataloged, priced, and sold with customer service comparable to legitimate e-commerce.
Chilling effects on security research. Some cybersecurity professionals expressed concern that aggressive prosecution could chill legitimate vulnerability research and breach data sharing for defensive purposes.

---

### Case 12.12: Neuralink and the BRAIN Initiative —FDA Regulatory Oversight (2023–2024) —US Food and Drug Administration**Date Decided:** 2023–2024
**Court:** U.S. Food and Drug Administration (FDA)

**Facts:** Neuralink pursued FDA approval for its N1 brain-computer interface implant —a coin-sized device with 1,024 electrodes designed to enable paralyzed patients to control computers with their thoughts. In May 2023, the FDA rejected Neuralink's initial application citing safety concerns including battery migration risk, electrode wire migration, and safe extraction. After addressing concerns, Neuralink received approval for its first-in-human trial (PRIME Study) in January 2024, implanting the device in patient Noland Arbaugh. The first patient experienced thread retraction reducing effectiveness.

**Issue:** Whether existing FDA medical device regulatory frameworks are adequate for brain-computer interfaces, including concerns about data security, long-term biocompatibility, device hacking potential, and the ethics of neural data collection.

**Holding:** Neuralink received FDA approval for human trials in January 2024. The PRIME Study remained ongoing. No formal legal challenges were filed, but the FDA's initial rejection signaled rigorous scrutiny. Congressional hearings addressed neurotechnology oversight.
**Significance:** BCI as a new regulatory category. Neuralink's interactions with the FDA highlighted challenges of fitting brain-computer interfaces into existing device frameworks designed for products with more limited functionality.
Neural data privacy and security. The case raised unprecedented questions about the legal status of neural data —whether it constitutes HIPAA-protected information, whether individuals have property rights in neural recordings, and what cybersecurity standards apply to brain-implanted devices.
Neurorights as emerging legal concept. The debate around Neuralink contributed to the emergence of "neurorights" —proposed protections for mental privacy, cognitive liberty, and mental integrity —with Chile, Spain, and others beginning to incorporate neurorights into legal frameworks.

---

### Case 12.13: Chile Brain Privacy Constitutional Reform (2021) —Constitutional Convention of Chile**Date Decided:** 2021
**Court:** Constitutional Convention of Chile / Chilean Courts

**Facts:** Chile's 2021 Constitutional Convention proposed explicit constitutional protections for brain data and mental privacy —the first national body to do so. Although the full proposed constitution was rejected in a September 2022 plebiscite, the neuroprotection provisions enjoyed broad support. The Chilean Congress separately enacted the Neuroprotection Law (Ley N 21.663) in 2023, amending the constitution to establish that "no one may be subjected to actions that alter their brain activity without their free and informed consent" and creating a regulatory framework for neurotechnologies.

**Issue:** Whether existing constitutional frameworks for privacy and bodily autonomy are adequate for neural data —which is more intimate and potentially manipulable than any other personal data category —and whether explicit "neurorights" protections are necessary.

**Holding:** The Neuroprotection Law was enacted in 2023, establishing Chile as the first country with constitutional-level protections for mental privacy and neurodata. The law prohibits collection and use of neural data without informed consent and restricts commercial use of neurodata.
**Significance:** First constitutional neurorights protections. Chile became the first country to establish constitutional-level protections for brain data, with similar proposals under consideration in Spain, Brazil, and at the OECD level.
Data protection extended to neural data. The reform extended the data protection paradigm to a fundamentally different data category —neural data revealing thoughts, intentions, and cognitive states —raising questions about GDPR-adequacy for specialized neurodata protection.
Precautionary approach to emerging technology. Chile's approach —establishing legal protections before widespread commercialization —represented a precautionary approach contrasting with reactive technology regulation, potentially offering a model for other emerging technologies.

---

### Case 12.14: SpaceX Starlink in Ukraine and Russia —ITAR/EAR Export Controls (2022–2024) —US Department of Commerce / Department of State**Date Decided:** 2022–2024
**Court:** U.S. Department of Commerce / Department of State

**Facts:** Following Russia's invasion of Ukraine, SpaceX deployed thousands of Starlink satellite internet terminals, providing critical communications for Ukraine's military and civilians. Elon Musk publicly discussed restricting Starlink use for offensive operations, reportedly declining a Ukrainian request to activate coverage near Crimea for a drone attack. Reports also emerged of Starlink terminals being smuggled into Russia for Russian forces. The incident raised questions about whether a private company could restrict service in a war zone and whether Starlink was subject to ITAR or EAR export controls.

**Issue:** Whether Starlink satellite internet services constitute "defense articles" subject to ITAR, "dual-use items" subject to EAR, or a novel category requiring new regulatory frameworks. Whether a private company can exercise independent control over its services' military use in a conflict zone.

**Holding:** No formal enforcement actions against SpaceX. The US government entered a contract with SpaceX for Starlink services in Ukraine (announced 2023). Export control implications remained under ongoing regulatory review.
**Significance:** Private space infrastructure as dual-use military asset. The case demonstrated that commercial space infrastructure can become critical military assets, raising fundamental questions about private operators' relationship with military users.
Corporate autonomy in geopolitical conflicts. Musk's assertion of corporate discretion over Starlink's military use raised unprecedented questions about private infrastructure operators' power to influence armed conflict.
Export controls for space services. The case exposed the inadequacy of ITAR/EAR frameworks for regulating satellite internet services that blend commercial communications, defense capabilities, and dual-use technology.

---

### Case 12.15: Apache Log4j / Log4Shell Vulnerability (December 2021) —Global Incident Response**Date Decided:** 2021
**Court:** Multi-Jurisdictional (CISA, NCSC, Vendors)

**Facts:** Security researchers disclosed CVE-2021-44228 (Log4Shell), a critical remote code execution vulnerability in Apache Log4j —a ubiquitous open-source Java logging library embedded in enterprise software, cloud services, and IoT devices worldwide. The vulnerability allowed unauthenticated remote code execution via specially crafted log messages. Mass exploitation followed within days by threat actors ranging from cryptominers to state-sponsored APT groups. CISA issued an emergency directive requiring federal agency remediation. Multiple class actions were filed against vendors whose products were affected.

**Issue:** The legal liability framework for open-source software maintainers (typically unpaid volunteers) whose code is embedded in commercial products. Whether vendors incorporating open-source components have a duty of care to customers when those components contain undisclosed vulnerabilities.

**Holding:** Apache released patches within days. CISA mandated federal agency remediation. Multiple class action lawsuits were filed but most were dismissed or consolidated. The incident catalyzed legislative proposals for mandatory SBOM requirements and the EU Cyber Resilience Act.
**Significance:** Open-source software as critical infrastructure. Log4Shell exposed global digital infrastructure dependence on open-source maintained by volunteer communities with limited resources, catalyzing significant investment in open-source security (OpenSSF, Alpha-Omega project).
Software supply chain security. The vulnerability provided the most compelling evidence for mandatory Software Bill of Materials (SBOM) requirements, subsequently incorporated into the EU Cyber Resilience Act and US executive orders.
Open-source maintainers' liability. The case intensified debate over liability for open-source maintainers, with the cybersecurity community opposing such liability and advocating shared responsibility models placing obligations on commercial entities.

---

### Case 12.16: NHS AI Diagnostic Tool Regulation (2023–2024) —UK MHRA**Date Decided:** 2023–2024
**Court:** UK Medicines and Healthcare products Regulatory Agency (MHRA)

**Facts:** The NHS deployed multiple AI diagnostic tools across clinical settings, including breast cancer detection in mammograms, retinal disease diagnosis from OCT scans, sepsis risk identification, and emergency department triage. The MHRA classified AI diagnostic tools as "Software as a Medical Device" (SaMD). However, continuously learning AI systems created tension with static device approval frameworks. The NHS AI Lab collaborated with MHRA on the "AI Airlock" regulatory sandbox. Documented bias incidents —including a skin cancer AI tool performing less accurately on darker skin tones —raised additional fairness concerns.

**Issue:** Whether existing medical device frameworks are adequate for AI diagnostic tools that continuously learn and evolve. How to address algorithmic bias. What liability regime applies when an AI tool produces incorrect diagnoses causing patient harm.

**Holding:** The MHRA continued developing its regulatory framework including the AI Airlock program and "predetermined change control plan" concepts. The CQC incorporated AI tool performance into quality assessments. No formal proceedings against specific AI developers.
**Significance:** Regulating adaptive AI in safety-critical settings. The case highlighted the challenge of regulating continuously learning AI within static product frameworks, driving new regulatory concepts with potential as models for other safety-critical domains.
Algorithmic bias in healthcare. Documented bias instances raised acute questions about training data diversity requirements and the potential for AI to exacerbate health disparities.
Liability for AI-assisted clinical decisions. Unresolved questions remain about liability distribution among clinicians, AI developers, and hospitals when AI contributes to diagnostic errors.

---

### Case 12.17: China Deepfake Regulation Enforcement (2023) —Cyberspace Administration of China**Date Decided:** 2023
**Court:** Cyberspace Administration of China (CAC)

**Facts:** In 2023, the CAC conducted its first enforcement actions under the Deep Synthesis Measures, requiring all deep synthesis technology providers to obtain regulatory approval, label AI-generated content, maintain user records, and implement content moderation. The CAC penalized multiple companies for failures including inadequate labeling, insufficient identity verification, and failure to prevent generation of content "endangering national security." Actions targeted AI face-swapping services, voice cloning platforms, and text generation tools.

**Issue:** The scope and enforceability of China's deepfake regulatory framework, including mandatory labeling, identity verification, consent for likeness use, and content moderation obligations.

**Holding:** Multiple companies received administrative penalties including fines and rectification orders. The CAC used enforcement actions to establish interpretive precedents for the regulations. Non-compliant services were suspended.
**Significance:** Most comprehensive deepfake framework. China's regulations represented the most prescriptive legal framework for AI-generated content at enactment, going far beyond Western approaches with mandatory identity verification and government oversight.
Consent and likeness rights in AI era. Requirements for consent when using personal likenesses established a regulatory framework for personality rights with no direct Western equivalent.
Surveillance implications. Critics noted the regulations functioned as content control mechanisms requiring platforms to implement government-monitorable systems, with implications for expression and dissent.

---

### Case 12.18: EU Digital Identity Wallet —eIDAS 2.0 Implementation (2024) —European Union**Date Decided:** 2024
**Court:** European Union Institutions

**Facts:** The EU adopted the revised eIDAS Regulation (eIDAS 2.0), establishing a framework for a European Digital Identity Wallet (EUDI Wallet) available to all EU citizens and residents for accessing public and private services across member states. The regulation incorporates privacy-preserving technologies including selective disclosure, pseudonymization, and zero-knowledge proof capabilities. Article 45 provisions regarding qualified trust service provider security generated significant debate about implications for end-to-end encryption.

**Issue:** Whether a mandatory government-backed digital identity system is consistent with the EU's fundamental rights framework, including privacy (Article 7, Charter) and data protection (Article 8). Whether selective disclosure features adequately protect against surveillance and function creep.

**Holding:** The regulation was adopted and entered into force in November 2024. Member states must implement the EUDI Wallet by 2026. Adoption by citizens is voluntary, though service providers must accept it as valid identity credential.
**Significance:** Largest-scale government digital identity system. The EUDI Wallet represents the largest government-backed digital identity initiative globally, potentially affecting over 450 million citizens across 27 member states.
Privacy-preserving digital identity. The incorporation of selective disclosure and zero-knowledge proof capabilities represents a significant technical and regulatory innovation attempting to reconcile universal digital identity with privacy protections.
Encryption controversy. Article 45 provisions —which cybersecurity experts argued could undermine end-to-end encryption —highlighted the recurring tension between law enforcement access desires and secure digital infrastructure requirements.

---

### Case 12.19: AI-Generated Child Sexual Abuse Material (CSAM) —Multi-Jurisdictional Cases (2023–2025)**Date Decided:** 2023–2025
**Court:** Multi-Jurisdictional

**Facts:** The period 2023–2025 witnessed exponential growth in AI-generated CSAM, created using generative AI tools including diffusion models and specialized dark-web models trained on real CSAM datasets. NCMEC reported dramatic increases in AI-generated CSAM reports overwhelming detection systems designed for perceptual hashing. US federal prosecutors brought the first criminal cases charging defendants with possession and distribution of AI-generated CSAM, arguing the material met statutory definitions even though no real children were depicted. The UK convicted individuals under existing indecent imagery legislation. Multiple jurisdictions enacted or proposed legislation specifically targeting AI-generated CSAM.

**Issue:** Whether existing CSAM statutes —designed for photographs and videos of real children —apply to AI-generated synthetic imagery depicting fictitious children. Whether First Amendment protections apply to AI-generated synthetic content depicting fictional minors. Whether creation of AI-generated CSAM causes equivalent harm to traditional CSAM (normalization, grooming risk, training dataset contamination).

**Holding:** Multiple jurisdictions convicted individuals for AI-generated CSAM under existing statutes, establishing that prohibitions extend to synthetic imagery. The US DOJ advocated for explicit legislation. The EU CSA Regulation addressed AI-generated CSAM. Australia and South Korea amended criminal codes.
**Significance:** Statutory interpretation for synthetic CSAM. Courts across multiple jurisdictions ruled that existing CSAM statutes encompass AI-generated synthetic imagery, closing what could have been a significant legal loophole as generative AI capabilities rapidly advanced.
Harm framework for synthetic content. The cases required courts and legislatures to articulate the specific harms of AI-generated CSAM —including normalization of child sexual abuse, use in grooming real children, and the fact that training on real CSAM is typically required —establishing analytical frameworks applicable to other categories of AI-generated harmful content.
First Amendment and synthetic content. In the US, the application of obscenity and child protection doctrines to AI-generated content created novel First Amendment questions, particularly regarding the distinction between protected fictional depictions and unprotected content harmful to minors —questions likely to reach the Supreme Court as technology and legislation continue to evolve.# Global Cyber Law Compendium Volume II
Part Twelve —Emerging Issues: Additional Cases (12.25—2.54)

---

### Case 12.20: Samsung/Vizio Smart TV Privacy Violations (2015–2017) —FTC
**Date Decided:** November 2017 (Vizio consent order); March 2017 (Samsung policy revision)

**Court:** U.S. Federal Trade Commission (FTC) / New Jersey Attorney General

**Facts:** Vizio manufactured smart TVs that automatically collected viewing data on everything displayed on screen —including content from cable boxes, streaming devices, and over-the-air broadcasts —without meaningful consumer consent. Vizio then sold this granular viewing data to third-party advertisers. Separately, Samsung faced scrutiny after its privacy policy revealed that voice commands captured by its smart TVs' "voice interaction" features could be transmitted to a third-party service (Nuance) for processing. Both companies were accused of failing to obtain informed consent for pervasive data collection in consumers' homes.

**Issue:** Whether always-on data collection by Internet of Things devices embedded in consumer homes constitutes unfair or deceptive trade practices under Section 5 of the FTC Act when adequate disclosure and consent are absent.

**Holding:** The FTC and New Jersey Attorney General entered a consent order with Vizio requiring the company to (1) delete all data collected prior to the consent date, (2) obtain affirmative express consent before collecting and sharing viewing data, and (3) implement a comprehensive privacy program subject to biennial audits for 20 years. Samsung revised its privacy policy and clarified voice data handling, though no formal enforcement action was pursued against Samsung.
**Significance:** Established that IoT devices in the home are subject to the same consumer protection standards as online services, reinforcing that "smart" does not mean "exempt."
Set a precedent for requiring affirmative opt-in consent (not merely buried privacy policies) for pervasive ambient data collection.
Foreshadowed broader regulatory attention to the "always-on" surveillance capabilities of consumer IoT, prefiguring the California Consumer Privacy Act and GDPR IoT guidance.

---

### Case 12.21: Johnson & Johnson Insulin Pump Vulnerability (2016) —FDA/Manufacturer
**Date Decided:** October 2016 (advisory notice); August 2016 (security update deployment)

**Court:** U.S. Food and Drug Administration (FDA); self-disclosed by Johnson & Johnson Animas Corporation

**Facts:** Johnson & Johnson's Animas OneTouch Ping insulin pump contained a cybersecurity vulnerability whereby an unauthorized person could potentially intercept and hijack the wireless communication between the pump's remote control and the pump itself. An attacker within close proximity (approximately 25 feet) could theoretically command the pump to deliver unauthorized insulin doses, posing life-threatening risks to patients. The company identified the vulnerability through its own security assessment and proactively notified patients and healthcare providers while deploying a firmware update.

**Issue:** Whether manufacturers of networked medical devices bear a legal duty to proactively identify, disclose, and remediate cybersecurity vulnerabilities that could cause physical harm to patients.

**Holding:** J&J issued a voluntary cybersecurity advisory and urged patients to implement available security measures (e.g., disabling the remote feature when not in use). The FDA classified this as a non-emergency safety issue and recommended the company continue post-market surveillance. No regulatory enforcement action was taken, but the incident prompted FDA to issue updated premarket and postmarket cybersecurity guidance for medical device manufacturers.
**Significance:** Demonstrated that IoT vulnerabilities in healthcare can have immediate physical safety consequences, blurring the line between cybersecurity and product safety law.
Catalyzed the FDA's 2016 Postmarket Management of Cybersecurity in Medical Devices guidance, establishing expectations for ongoing vulnerability management throughout the device lifecycle.
Illustrated the tension between proactive disclosure (patient awareness) and potential panic, shaping industry norms for responsible vulnerability disclosure in regulated medical devices.

---

### Case 12.22: Connected Car Data Collection and the CCPA (2020–2023) —California
**Date Decided:** Ongoing; CCPA effective January 2020; CPPA rulemaking continuing as of 2024

**Court:** California Privacy Protection Agency (CPPA) / California Attorney General / NHTSA policy guidance

**Facts:** Modern connected vehicles generate enormous volumes of data through onboard telematics systems, GPS units, microphones, cameras, and infotainment systems. Automakers including GM (OnStar), Tesla, Ford, and Toyota collect data on vehicle location, driving behavior, in-cabin conversations, and passenger information —often sharing this data with data brokers, insurance companies, and law enforcement without explicit consumer consent. The Mozilla Foundation's 2023 Privacy Not Included review found that connected cars were among the worst product categories for consumer privacy. NHTSA issued cybersecurity best practices in 2022, but no binding federal privacy rules for connected vehicles existed.

**Issue:** Whether the broad data collection practices of connected vehicle manufacturers are subject to state consumer privacy laws like the CCPA, and what level of transparency and consent is required for automotive data.

**Holding:** The California Attorney General confirmed that connected vehicles fall squarely within the CCPA's scope. The CPPA initiated rulemaking in 2023 to establish specific automotive data privacy regulations, including requirements for clear disclosure of data collected, limits on secondary uses, and consumer rights to access and delete vehicle data. Several automakers updated their privacy policies and introduced opt-out mechanisms in response.
**Significance:** Established that the automobile —traditionally regulated as a physical product —is now also a data collection platform subject to privacy law.
Highlighted the regulatory gap at the federal level, where NHTSA focuses on safety while the FTC and state AGs address privacy, with no unified framework.
Preceded EU regulations on vehicle data access (EU Data Act, 2024) and influenced similar legislative proposals in other jurisdictions.

---

### Case 12.23: FCC Addition of Huawei to the Covered List / Entity List (2019–2020) —FCC
**Date Decided:** June 30, 2020 (FCC Covered List designation); May 15, 2019 (Commerce Department Entity List addition)

**Court:** U.S. Federal Communications Commission (FCC) / U.S. Department of Commerce —Bureau of Industry and Security (BIS)

**Facts:** The U.S. government designated Huawei Technologies and its affiliates as national security threats, adding the company to the Commerce Department's Entity List (May 2019), which restricted the export of U.S.-origin technology to Huawei without a license. Subsequently, the FCC formally designated Huawei as a Covered Company under the Secure and Trusted Communications Networks Act, barring U.S. telecom carriers from using Universal Service Fund money to purchase or maintain Huawei equipment. The FCC also adopted rules requiring carriers to "rip and replace" existing Huawei and ZTE equipment from their networks, with reimbursement available through a $1.9 billion fund.

**Issue:** Whether a foreign telecommunications equipment manufacturer can be designated a national security threat and effectively excluded from the U.S. market through executive and regulatory action, and what legal standards govern such exclusion.

**Holding:** The FCC's designation was upheld as within its statutory authority. Huawei challenged the FCC's actions in federal court (Huawei v. FCC), arguing due process and statutory overreach, but courts largely deferred to the executive branch on national security grounds. The "rip and replace" program was funded but faced implementation challenges, with many rural carriers reporting insufficient reimbursement funds.
**Significance:** Set the modern benchmark for using national security authority to exclude foreign technology companies from critical telecommunications infrastructure.
Triggered a global "de-Huaweization" trend, with numerous allied countries imposing similar restrictions on Huawei 5G equipment.
Raised significant due process and separation-of-powers concerns regarding executive branch authority to designate companies as security threats with limited judicial review.

---

### Case 12.24: Australia's Huawei 5G Ban (2018) —Australian Government
**Date Decided:** August 2018 (formal announcement)

**Court:** Australian Government —Cabinet decision (National Security Committee); advice from Australian Signals Directorate (ASD) and Australian Security Intelligence Organisation (ASIO)

**Facts:** In August 2018, the Australian government formally banned Huawei (and ZTE) from participating in the country's 5G telecommunications network build-out. The government cited national security concerns, specifically the risk that a vendor subject to extrajudicial directions from a foreign government could compromise the integrity of Australia's 5G infrastructure. The decision was communicated through a joint statement by the Prime Minister and the Minister for Communications, invoking the Telecommunications Sector Security Reforms (TSSR) that had been enacted earlier that year. Huawei had been a significant 4G equipment supplier in Australia and had invested heavily in the country.

**Issue:** Whether national security justifications are sufficient to exclude a specific foreign vendor from participation in critical telecommunications infrastructure, absent publicly disclosed evidence of specific misconduct.

**Holding:** The ban was implemented through administrative guidance issued under the TSSR framework, not through legislation specifically targeting Huawei. Huawei challenged the decision through public advocacy and legal threats but did not formally challenge it in Australian courts. The ban remained in effect and influenced similar decisions in other Five Eyes nations (New Zealand, UK partial ban, Canada).
**Significance:** Established Australia as the first Five Eyes nation to formally exclude Huawei from 5G, creating a cascade effect among allied nations.
Demonstrated the use of telecommunications security reforms as a mechanism for supply-chain national security decisions without enacting company-specific legislation.
Contributed to the broader geopolitical fragmentation of global telecommunications standards and supply chains.

---

### Case 12.25: EU 5G Cybersecurity Toolbox (2020) —European Commission/ENISA
**Date Decided:** January 29, 2020 (Toolbox adoption)

**Court:** European Commission / EU Member States (via NIS Cooperation Group) / EU Agency for Cybersecurity (ENISA)

**Facts:** In response to growing concerns about the security of 5G network infrastructure —particularly regarding Chinese equipment vendors —the European Commission coordinated the development of a "EU 5G Cybersecurity Toolbox" through the NIS Cooperation Group. The Toolbox was developed over several months in 2019 and adopted in January 2020. It provided a set of risk-mitigating measures including enhanced scrutiny of suppliers deemed high-risk, restrictions on "non-EU" suppliers for sensitive parts of the network (core network functions), and mandatory security certification requirements. The Toolbox was not legally binding but was intended to guide national implementation by Member States.

**Issue:** Whether the EU could effectively coordinate a collective approach to 5G security risks among 27 Member States with diverse telecommunications markets and differing geopolitical alignments.

**Holding:** All EU Member States endorsed the Toolbox. By July 2020, most Member States had completed national risk assessments and identified high-risk suppliers (with Huawei implicitly targeted). The EU subsequently adopted the Cybersecurity Act's certification framework (EUCC) to operationalize the Toolbox's technical measures. However, implementation varied significantly among Member States, with some imposing strict restrictions and others maintaining more permissive approaches.
**Significance:** Represented the first coordinated multinational approach to securing next-generation telecommunications infrastructure through a risk-based (rather than vendor-specific) framework.
Balanced geopolitical pressure from the U.S. for a Huawei ban with European preferences for a multilateral, evidence-based approach.
Established the risk-based tiering model —distinguishing between core and non-core network components —that influenced global 5G security policy.

---

### Case 12.26: SEC v. Coinbase, Inc. (2023) —SDNY
**Date Decided:** Complaint filed June 6, 2023; motion to dismiss denied July 13, 2023

**Court:** U.S. District Court for the Southern District of New York; Judge Katherine Polk Failla

**Facts:** The U.S. Securities and Exchange Commission (SEC) filed a complaint against Coinbase, the largest U.S. cryptocurrency exchange, alleging that the platform operated as an unregistered securities exchange, broker, and clearing agency. The SEC identified at least 13 crypto assets traded on Coinbase —including SOL, ADA, MATIC, FIL, SAND, AXS, CHZ, LINK, MANA, ALGO, XRP, DASH, and OMG —as securities under the Howey test. Coinbase moved to dismiss, arguing that the SEC failed to adequately allege that the assets in question were "investment contracts" and that the regulatory framework for crypto was insufficiently clear.

**Issue:** Whether cryptocurrency tokens traded on a major exchange constitute securities under the Howey test, and whether the SEC provided fair notice that Coinbase's operations violated securities laws.

**Holding:** Judge Failla denied Coinbase's motion to dismiss in July 2023, finding that the SEC had adequately pleaded that at least some of the crypto assets were securities under Howey. The court rejected Coinbase's "fair notice" and "major questions" defense arguments. The case proceeded to discovery and remained ongoing as of 2024.
**Significance:** Represented the SEC's most aggressive enforcement action against a major U.S. crypto exchange, signaling an expansive interpretation of securities law applied to digital assets.
The motion-to-dismiss ruling confirmed that courts were willing to allow the SEC to pursue novel applications of securities law to crypto markets without requiring Congress to first create a specific regulatory framework.
Intensified the regulatory debate over whether existing securities laws are adequate for crypto or whether new legislation is needed.

---

### Case 12.27: CFTC v. Binance Holdings Ltd. (2023) —N.D. Illinois
**Date Decided:** Complaint filed March 27, 2023; consent order and civil monetary penalty November 21, 2023

**Court:** U.S. District Court for the Northern District of Illinois (Chicago); Consent order approved by Judge John Robert Blakey

**Facts:** The Commodity Futures Trading Commission (CFTC) filed a complaint against Binance, the world's largest cryptocurrency exchange by trading volume, and its founder Changpeng Zhao (CZ), alleging that Binance operated an illegal derivatives trading platform accessible to U.S. customers while evading U.S. regulatory oversight. The CFTC alleged that Binance intentionally cultivated "VIP" U.S. customers while instructing them to use VPNs to conceal their location, failed to implement required Know Your Customer (KYC) and Anti-Money Laundering (AML) procedures, and engaged in wash trading that inflated trading volumes. Separately, the DOJ charged Binance with violations of the Bank Secrecy Act and sanctions violations, resulting in a $4.3 billion settlement and CZ's guilty plea.

**Issue:** Whether a cryptocurrency exchange that serves U.S. customers while deliberately evading U.S. jurisdiction violates the Commodity Exchange Act and whether the exchange's internal compliance failures constitute willful evasion of regulatory requirements.

**Holding:** Binance agreed to a consent order with the CFTC, admitting to the allegations and agreeing to pay $2.7 billion in civil monetary penalties and disgorgement. The consent order required Binance to implement robust AML/KYC compliance, withdraw from the U.S. market for regulated derivatives unless properly registered, and submit to extensive compliance monitoring. Zhao resigned as CEO and personally paid a $150 million fine to the CFTC.
**Significance:** Resulted in the largest financial penalty ever imposed in cryptocurrency enforcement, dwarfing all prior crypto-related fines.
Demonstrated the coordinated approach of multiple U.S. regulators (CFTC, DOJ, FinCEN, OFAC) in policing the crypto industry, effectively ending the era of offshore exchanges evading U.S. law with impunity.
Established that "regulatory arbitrage" —operating outside the U.S. while serving U.S. customers —constitutes a cognizable violation of U.S. commodities law.

---

### Case 12.28: Celsius Network Bankruptcy (2022) —SDNY Bankruptcy Court
**Date Decided:** July 14, 2022 (Chapter 11 filing); November 2023 (restructuring plan confirmed)

**Court:** U.S. Bankruptcy Court for the Southern District of New York; Judge Martin Glenn

**Facts:** Celsius Network, once one of the largest cryptocurrency lending and earning platforms, filed for Chapter 11 bankruptcy in July 2022 after a liquidity crisis triggered by the broader crypto market downturn and the collapse of the Terra/Luna ecosystem. Celsius owed approximately $4.7 billion to its 600,000+ retail depositors. Investigations by the bankruptcy examiner and the SEC revealed that Celsius had operated essentially as an unregistered bank and securities issuer, commingled customer funds, used customer deposits to make risky market trades and proprietary investments, and had been insolvent for months before its bankruptcy filing. Former CEO Alex Mashinsky was later charged with securities fraud, commodities fraud, and wire fraud by the DOJ and SEC.

**Issue:** Whether cryptocurrency lending platforms that accept retail deposits and pay yields constitute unregistered securities offerings and banking operations, and how customer assets should be treated under bankruptcy law when the platform commingles funds.

**Holding:** The court confirmed Celsius's reorganization plan in November 2023, creating a new entity (NewCo) to distribute cryptocurrency and equity to creditors. Retail customers were treated as unsecured creditors, not as depositors entitled to priority claims —a devastating outcome for many customers. The SEC's claims regarding Celsius's "Earn" program as an unregistered security offering were substantiated by the bankruptcy examiner's report.
**Significance:** Demonstrated that existing bankruptcy and securities law frameworks can be applied to crypto lending platforms, with devastating consequences for retail customers treated as general unsecured creditors.
Exposed the regulatory vacuum in crypto lending: platforms operated like banks without banking regulation, and like securities issuers without SEC registration.
Catalyzed enforcement actions against other crypto lenders (Voyager, BlockFi) and informed legislative proposals for crypto regulation.

---

### Case 12.29: Voyager Digital Bankruptcy (2022) —SDNY Bankruptcy Court
**Date Decided:** July 6, 2022 (Chapter 11 filing); May 2023 (asset sale to Binance.US); December 2023 (Binance.US withdrawal; reorganization plan revised)

**Court:** U.S. Bankruptcy Court for the Southern District of New York; Judge Michael Wiles

**Facts:** Voyager Digital, a publicly traded cryptocurrency brokerage and lending platform, filed for Chapter 11 bankruptcy after the collapse of Three Arrows Capital (3AC), which owed Voyager over $650 million. Voyager's platform had offered yield-bearing accounts to retail customers, advertising "commission-free" crypto trading with yields of up to 12%. The platform held approximately $1.3 billion in crypto assets owed to 3.5 million customers. The SEC and FTC raised concerns about Voyager's claims and its marketing of yield products to unsophisticated retail investors. Voyager initially proposed selling its assets to FTX (which subsequently collapsed), then to Binance.US, which ultimately withdrew due to regulatory objections.

**Issue:** Whether a cryptocurrency platform that markets yield products to retail customers is offering unregistered securities, and whether the bankruptcy process can adequately protect retail crypto customers.

**Holding:** Judge Wiles approved Voyager's reorganization plan after multiple failed sale attempts. Customers received recoveries of approximately 35-36% of their claims in crypto distributions. The court rejected arguments that Voyager's yield products were not securities, and the FTC separately obtained a $1.6 billion judgment against Voyager's affiliated entity for deceptive marketing. The plan established two recovery vehicles —one for retail customers and one for institutional creditors —with different recovery timelines.
**Significance:** Reinforced the pattern established in Celsius: crypto lending platforms that collapse leave retail customers as unsecured creditors with significant losses.
The FTC's parallel enforcement action signaled that marketing crypto yield products to retail consumers triggers both securities and consumer protection liability.
Illustrated the systemic risk in the crypto ecosystem: Voyager's bankruptcy was triggered by counterparty exposure (3AC), demonstrating cascading failure in an interconnected, unregulated market.

---

### Case 12.30: SEC NFT Enforcement Guidance and Actions (2023–2024) —SEC
**Date Decided:** Multiple actions beginning 2023; notable include Impact Theory (August 2023) and Stoner Cats (September 2023)

**Court:** U.S. Securities and Exchange Commission (SEC); administrative proceedings and consent orders

**Facts:** The SEC initiated enforcement actions against several NFT projects, establishing its position that certain NFTs constitute securities under the Howey test. In SEC v. Impact Theory (August 2023), the SEC charged a media company with conducting an unregistered securities offering through the sale of "Founder's Key" NFTs, which the company marketed as an investment with expected profit from the company's efforts. In the Stoner Cats case (September 2023), the SEC charged the creators of an animated web series funded by NFT sales, where buyers received secondary market resale privileges and exclusive content. Both cases resulted in consent orders without admissions of liability. SEC Commissioner Hester Peirce publicly criticized the agency's approach as chilling NFT innovation.

**Issue:** Whether NFTs —by their nature as unique digital assets —can constitute "investment contracts" under the Howey test when marketed with expectations of profit derived from the promoter's efforts.

**Holding:** Impact Theory agreed to a cease-and-desist order, a $6.1 million disgorgement, and the establishment of a Fair Fund to compensate purchasers. Stoner Cats agreed to a $1 million penalty and committed to burning unsold NFTs. The SEC issued guidance suggesting that most NFTs are not securities, but that those marketed as investment vehicles could be, creating uncertainty about the boundary.
**Significance:** Established the SEC's regulatory claim over at least a subset of NFTs, extending the agency's reach into digital collectibles and creative projects.
Created significant regulatory uncertainty for the NFT market, as the guidance offered no clear bright-line test distinguishing securities from non-securities NFTs.
Internal SEC dissent (Commissioner Peirce) highlighted the philosophical divide within the agency about applying 1930s securities law to fundamentally new digital asset classes.

---

### Case 12.31: Yuga Labs BAYC Class Action (2022) —C.D. California
**Date Decided:** Complaint filed December 8, 2022; class certification and merits proceedings ongoing as of 2024

**Court:** U.S. District Court for the Central District of California; Judge John F. Walter

**Facts:** A class-action lawsuit was filed against Yuga Labs, the creator of the Bored Ape Yacht Club (BAYC) NFT collection and its associated ApeCoin cryptocurrency. Plaintiffs alleged that Yuga Labs and its celebrity promoters (including Justin Bieber, Madonna, Snoop Dogg, Post Malone, Serena Williams, and others) engaged in an illegal "pump and dump" scheme by artificially inflating the price of BAYC NFTs and ApeCoin through paid celebrity endorsements and misleading hype, then selling their own holdings at artificially inflated prices. Plaintiffs claimed that BAYC NFTs and ApeCoin were unregistered securities sold in violation of federal and state securities laws, and that Yuga Labs misled investors about the projects' roadmap and utility.

**Issue:** Whether NFTs and associated cryptocurrency tokens marketed with celebrity endorsements and promises of future development constitute investment contracts under the Howey test, and whether celebrity promoters bear liability for securities violations.

**Holding:** The case survived initial motions to dismiss. Yuga Labs moved to dismiss, arguing that BAYC NFTs were collectibles, not securities, and that the lawsuit improperly characterized standard marketing as fraudulent. The court allowed discovery to proceed. Key questions about the applicability of the Howey test to NFTs and the liability of celebrity promoters remained unresolved as of 2024.
**Significance:** One of the most high-profile NFT-related lawsuits, testing whether the full machinery of securities class-action litigation can be applied to NFT projects.
Raised novel questions about celebrity liability in crypto/NFT promotion, potentially extending the SEC's "paid promoter" enforcement approach to NFT markets.
The outcome could establish critical precedent for whether the broader NFT market operates under securities law or consumer protection frameworks.

---

### Case 12.32: Meta Quest VR Data Collection —FTC Settlement (2023) —FTC
**Date Decided:** May 18, 2023 (proposed consent order); December 2023 (final order with modifications)

**Court:** U.S. Federal Trade Commission (FTC)

**Facts:** The FTC filed an administrative complaint against Meta (formerly Facebook) alleging that the company violated the FTC Act by making deceptive claims about the privacy of its Meta Quest virtual reality headsets. According to the complaint, Meta collected extensive user data through Quest devices —including physical movements, eye tracking data, hand movements, voice recordings, and room layouts —and used this data for targeted advertising without adequate disclosure. The FTC alleged that Meta failed to implement parental consent requirements for users under 13, stored sensitive data in ways that exposed children's information, and made misleading privacy claims in marketing the Quest platform.

**Issue:** Whether a company's collection of biometric and behavioral data through virtual reality devices constitutes deceptive trade practices when the scope of data collection exceeds what consumers and regulators were led to expect.

**Holding:** Meta agreed to a consent order requiring (1) a prohibition on using user data collected from Quest accounts for advertising purposes, (2) implementation of a comprehensive privacy program for VR products, (3) mandatory parental consent before collecting data from users under 13, (4) a deletion order for improperly collected data, and (5) a requirement to obtain affirmative opt-in consent before sharing user data with third parties. The order was modified after public comment but retained its core requirements.
**Significance:** First major regulatory action addressing data collection in virtual reality/metaverse environments, establishing that VR-specific privacy protections are enforceable.
Extended the FTC's "comprehensive privacy program" model —previously applied to Facebook (2012 consent decree) —to emerging immersive technology platforms.
Signaled that the metaverse will not escape existing consumer protection law, and that the unique data types available in VR (gaze tracking, gait, spatial mapping) will receive heightened scrutiny.

---

### Case 12.33: Neuralink FDA Breakthrough Device Designation (2023) —FDA
**Date Decided:** May 25, 2023 (Breakthrough Device designation)

**Court:** U.S. Food and Drug Administration (FDA); Center for Devices and Radiological Health (CDRH)

**Facts:** Neuralink, Elon Musk's brain-computer interface (BCI) company, received FDA Breakthrough Device designation for its N1 implant, designed to enable paralyzed patients to control computers and mobile devices with their thoughts. The designation followed a lengthy and initially unsuccessful FDA application process (rejected in early 2022 over safety concerns including lithium battery risks, wire migration, and safe device extraction). By May 2023, Neuralink had addressed sufficient concerns to receive the designation. In January 2024, Neuralink implanted its first human patient, Noland Arbaugh. However, the implant subsequently experienced mechanical issues (wire retraction), reducing its effectiveness, which Neuralink addressed through a software update.

**Issue:** Whether brain-computer interface devices that involve permanent neural implantation can meet FDA safety and efficacy standards, and what regulatory pathway applies to a technology that merges computational devices with the human brain.

**Holding:** The FDA granted Breakthrough Device designation, accelerating Neuralink's access to FDA guidance during the development process. The first-in-human implant proceeded under the FDA's Investigational Device Exemption (IDE) framework. The post-implant complications demonstrated ongoing safety challenges but did not trigger FDA enforcement action, as the IDE protocol anticipated iterative adjustments.
**Significance:** Marked the most advanced regulatory engagement with invasive brain-computer interface technology, establishing a precedent for how BCI devices will be regulated under existing medical device frameworks.
Raised fundamental legal and ethical questions about neural data ownership, cognitive liberty, and the boundaries between device and brain —questions that existing law is ill-equipped to address.
The Breakthrough Device pathway provided a model for balancing rapid innovation with patient safety in the emerging BCI sector.

---

### Case 12.34: Chile Constitutional Amendment on Neurological Data and Brain Rights (2021) —Chilean Congress
**Date Decided:** September 2021 (constitutional amendment passed); enacted into law

**Court:** National Congress of Chile (Senate and Chamber of Deputies); amendment to the Chilean Constitution

**Facts:** Chile became the first country in the world to constitutionally protect neurological data and establish "neurorights." The constitutional amendment —introduced by Senator Guido Girardi and supported by the Neurorights Foundation —added Article 19(1) to the Chilean Constitution, guaranteeing that "no authority or individual may, by any means, increase, diminish, or disturb in an unjustified manner" the mental integrity of any person, and establishing that neurological data belongs to the individual. The amendment was unanimously approved by the Senate and broadly supported in the Chamber of Deputies, reflecting cross-party consensus on the need to protect brain activity from commercial exploitation and unauthorized access.

**Issue:** Whether the law should recognize a fundamental right to mental integrity and neurological data protection in the constitutional order, and what legal framework should govern the collection and use of brain data by neurotechnology companies.

**Holding:** The constitutional amendment was approved and enacted, establishing five core neurorights: (1) right to personal identity including psychological identity, (2) right to free will, (3) right to mental privacy, (4) right to equal access to cognitive enhancement technologies, and (5) right to protection from algorithmic bias in neurotechnology. Chilean lawmakers subsequently began developing implementing legislation to operationalize these rights.
**Significance:** Established the world's first constitutional framework for neurorights, creating a legal precedent that may influence other jurisdictions as BCI technology matures.
Recognized that existing data protection frameworks (GDPR, CCPA) are insufficient to protect neural data, which is qualitatively different from other personal data due to its intimate connection to thought, identity, and autonomy.
Prompted international dialogue on the need for new legal categories to protect cognitive liberty in the age of brain-computer interfaces.

---

### Case 12.35: Codecov Supply Chain Breach (2021) —DOJ
**Date Decided:** April 15, 2021 (breach disclosure); August 2024 (indictment)

**Court:** U.S. Department of Justice (DOJ); indictment filed in the Western District of Texas

**Facts:** Codecov, a widely used code coverage and software testing platform owned by Semgrep (formerly AppCanary), disclosed that its Bash Uploader script had been compromised through a sophisticated supply chain attack. The attacker modified the script to exfiltrate environment variables —including API keys, credentials, and secrets —from the continuous integration/continuous deployment (CI/CD) pipelines of hundreds of Codecov's customers. The breach affected numerous major technology companies and went undetected for approximately two months (January'arch 2021). In August 2024, the DOJ unsealed an indictment against an individual for their role in the breach, charging wire fraud and conspiracy.

**Issue:** Whether a supply chain attack targeting a widely used developer tool constitutes a federal crime prosecutable under existing wire fraud statutes, and what responsibilities software vendors bear when their tools are weaponized against customers.

**Holding:** The DOJ secured an indictment against the alleged perpetrator, applying wire fraud (18 U.S.C. § 1343) and identity theft statutes to a supply chain attack. Codecov cooperated with investigators and implemented enhanced security measures. Affected companies were forced to rotate thousands of credentials. Civil lawsuits against Codecov were largely resolved through enhanced security commitments.
**Significance:** Established that supply chain attacks on developer tools are prosecutable under existing federal criminal law, even though the legal framework was not designed with such attacks in mind.
Exposed the vulnerability of CI/CD pipelines —the automated systems that deploy software —as a critical attack surface, prompting widespread industry re-evaluation of software supply chain security.
Contributed to the momentum behind the Biden administration's Executive Order 14028 on Improving the Nation's Cybersecurity (May 2021), which mandated software supply chain security improvements for federal contractors.

---

### Case 12.36: SolarWinds Shareholder Lawsuits (2021–2022) —SDNY/Delaware
**Date Decided:** 2021–2022 (multiple complaints filed); 2023–2024 (dismissals and appeals)

**Court:** U.S. District Court for the Southern District of New York; U.S. District Court for the District of Delaware; state courts

**Facts:** Following the massive SolarWinds Orion supply chain breach discovered in December 2020 —which compromised approximately 18,000 organizations including U.S. government agencies —SolarWinds shareholders filed multiple class-action and derivative lawsuits alleging that the company and its officers made materially misleading statements about its cybersecurity practices in SEC filings and public communications. Plaintiffs claimed that SolarWinds' representations of "industry-leading security" and "robust security protocols" were false, and that the company's stock price was artificially inflated before the breach was disclosed. The company's stock price dropped approximately 40% following public disclosure of the breach.

**Issue:** Whether corporate statements about cybersecurity practices in SEC filings constitute actionable misrepresentations when those practices are subsequently shown to have been inadequate, and what "puffery" defense applies to cybersecurity representations.

**Holding:** The Delaware Chancery Court dismissed the derivative claims in 2023, finding that the plaintiffs failed to adequately plead that specific board-level decisions were responsible for the cybersecurity failures. The SDNY federal securities class action faced similar challenges, with SolarWinds arguing that its cybersecurity statements were non-actionable "puffery" and that the breach was an unforeseeable act of a nation-state attacker (attributed to Russia's SVR). Key motions to dismiss were denied in part, allowing discovery to proceed on the central question of whether SolarWinds knew its representations were misleading at the time they were made.
**Significance:** Tested the boundaries of corporate liability for cybersecurity statements in securities filings, potentially establishing the standard for what constitutes a materially misleading cybersecurity disclosure.
Raised the question of whether a "nation-state attack" defense can shield companies from securities fraud claims when their security was objectively inadequate.
The litigation's outcome will influence how publicly traded companies describe cybersecurity practices in SEC filings, potentially leading to more cautious and detailed disclosures.

---

### Case 12.37: BreachForums Seizure and Restart (2023) —FBI
**Date Decided:** March 15, 2023 (initial seizure); March 2023 (restart under new management); June 2023 (second seizure)

**Court:** U.S. Department of Justice / FBI; domain seizure action; UK National Crime Agency (NCA) arrest of administrator

**Facts:** BreachForums emerged in early 2023 as a successor to RaidForums, which had been seized by the FBI in 2022. BreachForums quickly became the largest English-language underground marketplace for buying and selling stolen databases, credentials, and compromised corporate data. The FBI seized the forum's domain in March 2023, and the UK NCA arrested the forum's administrator, Conor Brian Fitzpatrick (known as "Baphomet"). Within days, the forum was re-established under new management, demonstrating the resilience of decentralized cybercrime communities. A second seizure followed in June 2023. The forum has subsequently reappeared in various forms, illustrating the challenge of permanently disrupting cybercrime infrastructure.

**Issue:** Whether domain seizures and administrator arrests constitute effective disruption of underground cybercrime forums, and how law enforcement should balance disruption with intelligence gathering from forum monitoring.

**Holding:** The FBI obtained seizure orders for the BreachForums domain, and Fitzpatrick pleaded guilty to conspiracy to commit access device fraud and was sentenced to prison. However, the forum's rapid resurrection under new management demonstrated the limitations of takedown-only approaches. The Justice Department acknowledged that forum takedowns often disperse rather than eliminate criminal activity.
**Significance:** Illustrated the "whack-a-mole" challenge of combating underground forums through law enforcement action alone, as successor sites rapidly fill the vacuum created by seizures.
Raised questions about whether sustained infiltration and monitoring of such forums —rather than immediate seizure —might produce more actionable intelligence and better disruption outcomes.
Contributed to the ongoing policy debate about the effectiveness of cybercrime disruption strategies and the need for international coordination in forum takedowns.

---

### Case 12.38: Genesis Market Prosecutions (2023) —DOJ
**Date Decided:** March 2023 (Genesis Market takedown); subsequent individual prosecutions continuing through 2024

**Court:** U.S. Department of Justice; Operation Cookie Monster —coordinated international law enforcement action; individual cases in various federal district courts

**Facts:** Genesis Market was an illicit online marketplace that sold stolen credentials, browser fingerprints, and session cookies, enabling buyers to impersonate legitimate users and bypass two-factor authentication on compromised accounts. Operated from 2018 to 2023, Genesis Market had approximately 1.5 million compromised accounts for sale. In March 2023, the FBI led "Operation Cookie Monster," a coordinated takedown involving 17 countries, seizing the Genesis Market infrastructure and arresting administrators. In the subsequent months, the DOJ unsealed charges against over 100 individuals who had purchased stolen access from Genesis Market, pursuing buyers as well as operators —a notable departure from typical cybercrime enforcement focused primarily on platform operators.

**Issue:** Whether purchasers of stolen digital credentials from illicit marketplaces can be prosecuted under existing computer fraud laws, and whether targeting buyers is an effective deterrence strategy.

**Holding:** The Genesis Market platform was permanently seized. The DOJ obtained indictments against 119 individuals across multiple jurisdictions, charging them with conspiracy to commit computer fraud and aggravated identity theft. Several defendants pleaded guilty, while others contested the charges. The prosecution of buyers —many of whom used the stolen credentials for financial fraud, credential stuffing attacks, and account takeovers —represented a significant expansion of DOJ enforcement strategy.
**Significance:** Represented one of the largest coordinated international cybercrime takedowns, demonstrating the effectiveness of multinational law enforcement cooperation against illicit marketplaces.
The prosecution of marketplace buyers (not just operators) established a new enforcement paradigm that significantly increased the deterrence value of such operations.
The operation's scope —seizing the marketplace, arresting operators, and pursuing hundreds of customers —became a model for future cybercrime disruption campaigns.

---

### Case 12.39: ChatGPT False Information and Defamation Cases (2023–2024) —Multiple Courts
**Date Decided:** Multiple cases filed 2023–2024; key decisions pending

**Court:** Various courts in the U.S., Australia, and other jurisdictions; notable cases include Moy v. OpenAI (N.D. California, 2023), Walters v. OpenAI (Georgia state court, 2023)

**Facts:** Following the widespread adoption of ChatGPT and other large language models, multiple individuals and organizations filed lawsuits alleging that AI-generated content contained false, defamatory, or misleading information. In Moy v. OpenAI, a radio host alleged that ChatGPT generated a false summary attributing to him a legal case involving financial fraud that never occurred. In Walters v. OpenAI, a Georgia radio host alleged that ChatGPT fabricated a story about him being involved in a fraudulent overseas gunrunning operation. Other cases alleged copyright infringement, invasion of privacy, and violations of state consumer protection statutes. Defendants argued that AI systems are not "publishers" in the traditional sense and that Section 230 immunity should protect AI outputs.

**Issue:** Whether AI-generated content that contains false or defamatory statements subjects AI developers to liability under defamation, libel, or consumer protection law, and whether Section 230 of the Communications Decency Act protects AI model outputs.

**Holding:** Most cases remained in early procedural stages as of 2024. Courts had not yet definitively ruled on the central question of AI developer liability for hallucinated content. Defendants argued that Section 230 protects them, while plaintiffs analogized AI outputs to published content. Some courts allowed cases to proceed past initial motions to dismiss, finding that the defamation claims were plausible enough to warrant discovery.
**Significance:** Represented the first wave of litigation testing whether existing defamation and consumer protection law can be applied to AI-generated content, an area where legal frameworks were clearly not designed for the technology at issue.
The Section 230 question —whether AI outputs constitute "information provided by another information content provider" —will have far-reaching consequences for the entire AI industry.
These cases accelerated legislative proposals for AI liability frameworks, including the EU AI Act's provisions on AI system transparency and accountability.

---

### Case 12.40: Air Canada Chatbot Liability (2024) —BC Civil Resolution Tribunal
**Date Decided:** February 14, 2024

**Court:** British Columbia Civil Resolution Tribunal (Canada); Tribunal Member Christopher C. McBean

**Facts:** A passenger, Jake Moffatt, booked a flight with Air Canada in November 2022 to attend his grandmother's funeral. He used Air Canada's website chatbot, which informed him that he could purchase a bereavement fare and retroactively apply it within 90 days of travel. Relying on the chatbot's advice, Moffatt purchased a full-fare ticket and subsequently sought the bereavement discount, which Air Canada refused. Moffatt filed a complaint with the BC Civil Resolution Tribunal. Air Canada argued that the chatbot was a "separate legal entity" responsible for its own statements and that the airline should not be liable for the chatbot's misinformation, characterizing the bot as providing links rather than legal advice.

**Issue:** Whether a company is liable for inaccurate information provided by its AI chatbot to a customer, and whether an AI chatbot can be treated as a separate legal entity to shield the company from liability.

**Holding:** Tribunal Member McBean ruled in favor of Moffatt, ordering Air Canada to pay $812.02 in damages plus tribunal fees. The tribunal rejected Air Canada's argument that the chatbot was a separate entity, finding that "while a chatbot is an interactive application, it is still a component of Air Canada's website." The tribunal held that the airline was responsible for all information on its website, whether provided by a human or an AI system, and that a reasonable customer would rely on the chatbot's representations.
**Significance:** Established that companies bear direct legal liability for AI chatbot outputs, rejecting the novel argument that AI systems are separate legal entities.
Created binding precedent (within the BC CRT's jurisdiction) that AI-provided customer service information is attributable to the company deploying it, treating AI outputs no differently from human employee statements.
Became the most widely cited AI liability case of 2024, serving as a wake-up call for companies deploying AI customer-facing tools without adequate accuracy safeguards and human oversight.

---

### Case 12.41: India RBI Data Localization Mandate (2018) —Reserve Bank of India
**Date Decided:** April 6, 2018 (RBI circular issued); October 2018 (compliance deadline); 2022 (amended to allow limited offshore processing)

**Court:** Reserve Bank of India (RBI); challenged in the Supreme Court of India by Internet and Mobile Association of India (IAMAI)

**Facts:** The Reserve Bank of India issued a circular mandating that all payment system operators and intermediaries must store all transaction data related to the Indian financial system exclusively within India. The mandate required that end-to-end transaction details be stored in India, with one copy available for processing abroad in limited circumstances. Major global payment processors (Visa, Mastercard, PayPal, Google Pay, Amazon Pay) were forced to restructure their data processing architecture to comply. The IAMAI challenged the mandate, arguing it was disproportionate, arbitrary, and would increase compliance costs without improving security.

**Issue:** Whether a central bank has the authority to mandate domestic data storage for all payment system data, and whether such a mandate is proportionate to legitimate regulatory objectives.

**Holding:** The Supreme Court of India declined to stay the RBI's mandate, effectively upholding it. Major payment companies complied by establishing data storage infrastructure in India. In 2022, the RBI relaxed the rules to allow cross-border data processing for certain categories of transactions, while maintaining the requirement for domestic storage of core transaction data. Non-compliance penalties included potential revocation of operating licenses.
**Significance:** Established India as a major proponent of data localization, joining Russia and China in requiring domestic data storage for critical sectors.
Forced global technology companies to invest significantly in Indian data infrastructure, effectively ending the assumption that cross-border data flows could operate without local data residency.
The policy debate influenced the drafting of India's Digital Personal Data Protection Act (2023), which adopted a more nuanced approach but retained localization requirements for certain categories of data.

---

### Case 12.42: Russia Sovereign Internet Law (2019) —Roskomnadzor
**Date Decided:** November 1, 2019 (law effective); tested during 2022 Ukraine conflict

**Court:** Federal Law No. 90-FZ; Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor); Constitutional Court of Russia

**Facts:** Russia enacted the "Sovereign Internet Law" (Federal Law No. 90-FZ), granting the government sweeping authority to manage and potentially isolate Russia's internet infrastructure from the global internet. The law required all internet service providers to install technical means (deep packet inspection equipment) enabling Roskomnadzor to filter traffic and, in extreme circumstances, disconnect the Russian internet (Runet) from the global network. The stated purpose was to ensure the continued functioning of the Russian internet in the event of foreign hostility, but critics characterized it as a censorship and surveillance tool. The law was tested during Russia's invasion of Ukraine in 2022, with the government blocking access to major international platforms (Meta/Facebook, Twitter, Instagram, and numerous news outlets).

**Issue:** Whether a sovereign state's mandate to build technical infrastructure capable of disconnecting from the global internet violates international human rights law, particularly the right to freedom of expression and access to information.

**Holding:** The law was enacted and enforced. Roskomnadzor conducted regular "tests" of Russia's ability to operate its internet independently. During the Ukraine conflict, the law was used to block access to dozens of foreign websites and services. Major platforms that refused to comply with Russian content moderation demands were throttled or blocked. The Constitutional Court rejected challenges to the law's constitutionality.
**Significance:** Established Russia's legal and technical framework for "internet sovereignty," providing a model for other authoritarian states seeking to control domestic internet access.
Demonstrated that technical measures for internet isolation can be built, maintained, and deployed —albeit with significant economic and technical costs.
Raised fundamental questions about the future of the global internet as a unified network, illustrating the trend toward "splinternet" fragmentation.

---

### Case 12.43: EU AI Act —Regulation of Gait, Voice, and Emotion Recognition (2024) —European Parliament/Council
**Date Decided:** March 13, 2024 (European Parliament adoption); June 13, 2024 (Council adoption); entered into force August 1, 2024

**Court:** European Parliament and Council of the European Union; regulation directly applicable in all EU Member States

**Facts:** The EU AI Act, the world's first comprehensive horizontal AI regulation, established a risk-based framework for artificial intelligence systems. Among its most notable provisions were stringent restrictions on the use of "AI systems to infer emotions of a natural person" in certain contexts (workplace and education banned; other contexts restricted), and the classification of remote biometric identification systems —including gait analysis, voice recognition, and facial recognition —as high-risk AI subject to strict requirements. Real-time remote biometric identification in public spaces was generally banned, with limited exceptions for law enforcement. The regulation also imposed transparency obligations for AI-generated content and established conformity assessment requirements for high-risk systems.

**Issue:** Whether emerging biometric technologies (gait analysis, voice recognition, emotion detection) that operate without conscious user interaction can be regulated to protect fundamental rights while allowing beneficial applications.

**Holding:** The AI Act was adopted by both the European Parliament and Council and entered into force in August 2024. Emotion recognition in the workplace and educational institutions was banned. Real-time remote biometric identification in public spaces was banned except for narrowly defined law enforcement purposes. High-risk biometric AI systems must undergo conformity assessments, implement data governance measures, provide transparency to affected individuals, and maintain human oversight. Most provisions will apply in phases, with the full regulatory framework operational by 2027.
**Significance:** Established the first comprehensive legal framework addressing the full spectrum of emerging biometric technologies, going far beyond traditional facial recognition regulation.
The emotion recognition ban in workplaces and education was globally unprecedented, establishing a precedent that certain AI applications are inherently incompatible with fundamental rights in specific contexts.
Created a de facto global standard that other jurisdictions are likely to follow, influencing AI governance frameworks worldwide through the "Brussels effect."

---

### Case 12.44: NIST Post-Quantum Cryptography Standardization (2024) —NIST
**Date Decided:** August 13, 2024 (FIPS 203, FIPS 204, FIPS 205 published)

**Court:** U.S. National Institute of Standards and Technology (NIST); Federal Information Processing Standards (FIPS)

**Facts:** NIST completed its multi-year Post-Quantum Cryptography (PQC) standardization project by publishing three final standards: FIPS 203 (ML-KEM —Module-Lattice-Based Key-Encapsulation Mechanism, derived from CRYSTALS-Kyber), FIPS 204 (ML-DSA —Module-Lattice-Based Digital Signature Algorithm, derived from CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA —Stateless Hash-Based Digital Signature Algorithm, derived from SPHINCS+). The standardization process began in 2016 and evaluated 82 initial submissions. These standards were designed to resist attacks from quantum computers, which threaten to break widely used public-key cryptosystems (RSA, ECC). The standards' publication followed growing urgency as adversaries engaged in "harvest now, decrypt later" strategies —collecting encrypted data today for future quantum decryption.

**Issue:** Whether cryptographic standards can be proactively updated to address anticipated (but not yet realized) quantum computing threats, and what legal obligations organizations face to transition to quantum-resistant cryptography.

**Holding:** NIST published the three PQC standards, making them the official federal government standards for quantum-resistant cryptography. Federal agencies were directed to begin transitioning their cryptographic infrastructure. Private-sector adoption was encouraged but not mandated. NIST initiated additional standardization efforts for further backup algorithms and continued evaluation of candidate schemes.
**Significance:** Established the first government-sanctioned quantum-resistant cryptographic standards, providing a clear migration path for organizations worldwide facing the "quantum threat."
Created a new category of regulatory compliance: organizations in regulated industries (finance, healthcare, defense) will increasingly face pressure to adopt PQC standards to meet data protection obligations.
The standards represent a proactive regulatory approach —addressing a future technological threat before it materializes —providing a model for other forward-looking technology governance frameworks.

---

### Case 12.45: Viasat KA-SAT Cyberattack —Legal Proceedings (2022–2024) —Multiple Jurisdictions
**Date Decided:** Attack: February 24, 2022; legal proceedings ongoing 2022–2024

**Court:** European Court of Justice; EU Council sanctions; U.S. Department of Justice; Viasat civil litigation

**Facts:** On February 24, 2022 —the same day Russia invaded Ukraine —a destructive cyberattack targeted Viasat's KA-SAT satellite network, which provided broadband internet service across Europe. The attack, attributed to Russia's military intelligence agency (GRU) by multiple Western intelligence agencies, used the "AcidPour" malware variant to overwrite firmware on thousands of KA-SAT modems, disabling internet access for approximately 30,000 customers in Ukraine and tens of thousands more across Central and Eastern Europe. The attack also disrupted wind turbine communications in Germany and emergency services in several countries. Viasat filed insurance claims and initiated recovery efforts. The EU, UK, and U.S. attributed the attack to Russia and imposed sanctions on individuals involved.

**Issue:** Whether a destructive cyberattack on civilian satellite infrastructure during armed conflict constitutes a violation of international law, and what legal remedies are available to the affected company and its customers.

**Holding:** The EU adopted sanctions against Russian military intelligence officers implicated in the attack. The U.S. indicted members of Russia's GRU Sandworm unit for their role. Viasat pursued insurance claims and civil litigation, with estimated damages exceeding hundreds of millions of dollars. The incident was cited in international proceedings at the UN and NATO as evidence of the need to strengthen international norms governing cyber operations in armed conflict. The legal classification of the attack as a "use of force" or "armed attack" under international law remained debated.
**Significance:** Represented the most significant cyberattack on civilian space infrastructure during an armed conflict, testing the boundaries of international humanitarian law as applied to cyber operations.
Demonstrated that satellite networks —a critical component of global communications infrastructure —are vulnerable to cyber attacks with cascading effects across multiple countries and sectors.
Accelerated efforts to establish international norms governing state behavior in cyberspace, particularly regarding attacks on civilian infrastructure during armed conflict.

---

### Case 12.46: U.S. State Deepfake Legislation (2023–2024) —Multiple State Legislatures
**Date Decided:** Various dates 2023–2024; notable examples include California AB 730 (2023 amendments), Texas HB 2177 (2023), Virginia Code § 8.01-427.2, Michigan HB 4217 (2023), Minnesota SF 2860 (2024), and others

**Court:** Various state legislatures and courts across the United States

**Facts:** In response to the proliferation of deepfake technology —AI-generated synthetic media that can create highly realistic but fabricated audio and video content —numerous U.S. states enacted legislation criminalizing or regulating deepfakes. The laws varied in scope but generally targeted: (1) non-consensual deepfake pornography (the most widely enacted category), (2) deepfakes used in election interference (prohibiting deceptive synthetic media within specified periods before elections), and (3) deepfakes used for fraud or harassment. Enforcement challenges included identification of perpetrators, jurisdictional issues (deepfakes spread rapidly online), and First Amendment free speech concerns. The federal DEEPFAKES Accountability Act was introduced in Congress but had not been enacted as of 2024.

**Issue:** How to balance the regulation of harmful synthetic media with First Amendment protections for free speech and artistic expression, and what legal standards can effectively distinguish between malicious deepfakes and protected speech (satire, parody, legitimate AI-assisted content creation).

**Holding:** By 2024, at least 20 states had enacted deepfake-related legislation, with varying scopes and penalties. Non-consensual deepfake pornography laws were the most common and generally upheld by courts. Election-related deepfake laws faced greater First Amendment scrutiny. Several state laws included safe harbor provisions for platforms that acted in good faith to remove deepfake content. Federal legislation remained stalled, leaving a patchwork of state-level protections.
**Significance:** Created a fragmented regulatory landscape for deepfakes in the U.S., with significant variation in protections across state lines —mirroring the broader pattern of state-level technology regulation in the absence of federal action.
The First Amendment tensions inherent in deepfake regulation —particularly distinguishing harmful synthetic media from protected expression —established important legal precedents for future AI content regulation.
State-level activity increased pressure on Congress to enact federal deepfake legislation, particularly as the 2024 U.S. presidential election raised concerns about AI-generated disinformation.

---

### Case 12.47: China AI Content Labeling Regulation (2023) —CAC
**Date Decided:** August 15, 2023 (Interim Measures effective); December 2023 (content labeling requirements specified)

**Court:** Cyberspace Administration of China (CAC); issued jointly with Ministry of Science and Technology, Ministry of Industry and Information Technology

**Facts:** China's Cyberspace Administration promulgated the Interim Measures for the Management of Generative Artificial Intelligence Services, establishing comprehensive requirements for generative AI systems operating in China. Key provisions included mandatory labeling of AI-generated content, requirements for training data compliance (respecting intellectual property rights and avoiding discriminatory content), content safety obligations (adherence to "core socialist values"), and algorithmic transparency. The measures required that AI-generated content be clearly labeled or watermarked to enable users to distinguish synthetic content from human-created content. Service providers were required to register their AI models with the CAC and submit to algorithmic security assessments before public deployment.

**Issue:** Whether mandatory content labeling requirements for AI-generated media are technically feasible, legally enforceable, and consistent with international norms regarding freedom of expression and technological innovation.

**Holding:** The Interim Measures entered into force on August 15, 2023. Major Chinese AI companies (Baidu, Alibaba, Tencent, ByteDance) complied by implementing content labeling systems on their generative AI platforms. The CAC approved numerous generative AI services for public deployment after security assessments. Non-compliant services were ordered to suspend operations pending compliance. The labeling requirements applied to text, images, audio, and video content.
**Significance:** Established China as the first major jurisdiction to implement binding mandatory content labeling requirements for generative AI, setting a precedent that influenced other countries' approaches.
Combined content labeling with content control requirements (adherence to "core socialist values"), illustrating how AI regulation can serve dual purposes of consumer transparency and political control.
Created technical and compliance pressure on AI developers worldwide, as companies with global operations needed to implement different content labeling standards for different jurisdictions.

---

### Case 12.48: Digital Euro and CBDC Privacy Framework (2023–2024) —ECB
**Date Decided:** October 18, 2023 (preparation phase launched); June 2024 (legislative proposal by European Commission)

**Court:** European Central Bank (ECB); European Commission legislative proposal; European Parliament and Council deliberations

**Facts:** The European Central Bank advanced its plans for a digital euro —a central bank digital currency (CBDC) that would serve as a digital form of the euro, complementing (not replacing) physical cash. The ECB launched the preparation phase in October 2023, focusing on technical design and privacy safeguards. The European Commission published its legislative proposal in June 2024, establishing the legal framework for the digital euro. The key privacy tension centered on the ECB's design choices: whether the digital euro would offer "cash-like" anonymity for small-value transactions (protecting user privacy) or would incorporate full traceability (enabling anti-money laundering enforcement). The Commission's proposal included a graduated privacy model: basic tier transactions (online and offline) would be anonymous below a certain threshold, while higher-value transactions would require identity verification.

**Issue:** Whether a central bank digital currency can be designed to balance individual privacy rights with anti-money laundering, counter-terrorism financing, and sanctions enforcement obligations.

**Holding:** The ECB's design incorporated a "privacy-by-design" approach with graduated anonymity: offline digital euro payments up to a defined threshold would be processed without personal data collection, while online payments and larger transactions would involve identity verification. The European Parliament's ECON committee and the Civil Liberties committee reviewed the proposal with significant debate over the privacy thresholds. The legislative process was ongoing as of 2024.
**Significance:** The digital euro's privacy design will establish a global benchmark for CBDC privacy, influencing central banks worldwide that are developing their own digital currencies.
The graduated privacy model attempted to reconcile the irreconcilable: providing meaningful privacy while maintaining AML/CFT compliance, creating a new legal category of "partial anonymity" in financial transactions.
The debate over digital euro privacy became a proxy for broader societal concerns about the erosion of cash as an anonymous payment method and the increasing surveillance capacity of digital payment systems.

---

### Case 12.49: C2PA Content Authenticity Standard (2022–2024) —Coalition for Content Provenance and Authenticity
**Date Decided:** July 2022 (C2PA Technical Specification v1.0); updated through 2024 with broader adoption

**Court:** Coalition for Content Provenance and Authenticity (C2PA) —industry consortium; no court proceedings, but developing into de facto industry standard referenced in regulatory proceedings

**Facts:** The Coalition for Content Provenance and Authenticity (C2PA), co-founded by Adobe, Microsoft, BBC, and others (now hosted by the Linux Foundation), developed and published an open technical standard for certifying the source and history of digital media content. The C2PA standard uses cryptography-based content credentials —including digital signatures, provenance metadata, and hardware-secured attestation —to create an immutable record of a piece of media's origin, editing history, and chain of custody. By 2024, the standard had been implemented in Adobe Photoshop, Adobe Firefly, Microsoft Bing Image Creator, Leica cameras, and Sony cameras, among other platforms. The standard was increasingly referenced in government AI regulation discussions as a potential technical infrastructure for deepfake detection and content labeling requirements.

**Issue:** Whether a voluntary industry standard for digital content provenance can achieve sufficient adoption to meaningfully address the synthetic media and deepfake problem, and how such standards interact with emerging regulatory mandates.

**Holding:** The C2PA Technical Specification v2.0 was published in 2024, extending the standard to cover more media types and use cases. Major platform adoption grew significantly, with several social media companies (Meta, Google) indicating support for C2PA-based content credentials. The U.S. government's Executive Order on AI (October 2023) referenced content provenance standards as a key tool for addressing AI-generated disinformation, and several countries began considering regulatory mandates for content provenance in their AI legislation.
**Significance:** Established the most widely adopted technical standard for addressing the provenance crisis in digital media, providing the infrastructure layer that legal frameworks for synthetic media regulation depend upon.
Illustrated the limitations of voluntary standards: adoption remained uneven, and the standard could not prevent bad actors from creating unprovenanced content —it could only enable verification of authenticated content.
The C2PA model of industry-led standard development with government reference and encouragement became a template for other AI governance challenges, bridging the gap between technical solutions and regulatory frameworks.

---

### Case 12.50: Starlink ITAR/EAR Ukraine Export (2022–2023) —U.S. Export Control & International Law
**Date Decided:** 2022–2023 (ongoing regulatory developments)

**Court:** U.S. Department of State (DDTC) / U.S. Department of Commerce (BIS)

**Facts:** Following Russia's invasion of Ukraine in February 2022, SpaceX's Starlink satellite internet service was deployed extensively in Ukraine for military and civilian communications. Questions arose about whether Starlink's provision of satellite communication services constituted an export of defense articles or dual-use technology subject to the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR). SpaceX sought and received favorable export classifications, but concerns emerged when Elon Musk publicly suggested restricting Starlink's use for certain Ukrainian military operations (reportedly to prevent escalation). The incident raised questions about the intersection of commercial satellite services, export controls, and geopolitical constraints.

**Issue:** Whether commercial satellite internet services provided in a conflict zone constitute controlled exports under ITAR/EAR, and what obligations the provider has regarding end-use restrictions.

**Holding:** The US government worked with SpaceX to authorize continued Starlink operations in Ukraine through appropriate licensing mechanisms under the EAR. The incident prompted broader regulatory review of commercial satellite communication services in conflict zones. The debate highlighted the unprecedented role of private space and communications companies in modern warfare.
**Significance:** Illustrated the growing regulatory challenges of applying Cold War-era export control frameworks (ITAR/EAR) to commercial satellite internet services in active conflict zones.
Raised fundamental questions about the obligations and power of private technology companies providing critical infrastructure in geopolitical conflicts, with implications for digital sovereignty and cybersecurity governance.

---

### Case 12.51: China Quantum Satellite Micius (2017–2024) —Chinese Space & Information Law
**Date Decided:** 2017–2024 (ongoing program)

**Court:** Chinese Academy of Sciences / National regulatory framework

**Facts:** China's Micius (Mozi) satellite, launched in August 2016, achieved several world-firsts in quantum communication, including satellite-to-ground quantum key distribution (QKD) and quantum entanglement distribution over intercontinental distances. By 2024, China had expanded its quantum communication infrastructure to include a national QKD network connecting major cities. The program raised significant questions about international law governing quantum communication satellites, cybersecurity implications of quantum-resistant (and quantum-vulnerable) encryption, and the potential strategic implications for digital sovereignty and intelligence-gathering capabilities.

**Issue:** How international law and cybersecurity frameworks should address quantum communication technologies that can fundamentally alter encryption and surveillance capabilities.

**Holding:** No specific international legal ruling was issued, but the Micius program prompted discussions at the ITU, UN GGE on cybersecurity, and in bilateral diplomatic channels about norms governing quantum communication. China established a regulatory framework for quantum technology development under its broader technology sovereignty strategy, including classification provisions and data security requirements for quantum communication networks.
**Significance:** Represents the frontier of technology governance challenges, where emerging quantum capabilities outpace existing legal and regulatory frameworks.
Has spurred global investment in quantum-resistant cryptography (post-quantum cryptography standards finalized by NIST in 2024) and prompted legislative attention in the US (National Quantum Initiative Act), EU (Quantum Flagship program), and other jurisdictions.

---

### Case 12.52: EU Digital Identity Wallet Pilot (2024) —European Union
**Date Decided:** 2024 (pilot phase); full rollout planned for 2026

**Court:** European Commission / EU Member States

**Facts:** Under the European Digital Identity Framework (eIDAS 2.0 Regulation, adopted 2024), the EU initiated pilot programs for a European Digital Identity Wallet (EUDI Wallet) that would allow all EU citizens and residents to store and present digital identity credentials, including national ID cards, driver's licenses, diplomas, and other official documents. The Wallet would enable cross-border digital identity verification for both public and private services. Pilot programs were launched in multiple member states in 2024 to test the infrastructure. Privacy advocates raised concerns about mass surveillance potential, function creep, and the concentration of sensitive personal data in a single digital identity system.

**Issue:** Whether the EU Digital Identity Wallet can be implemented in a manner that balances convenience and interoperability with robust privacy protections, data minimization, and user control over personal data.

**Holding:** The eIDAS 2.0 Regulation was formally adopted with privacy safeguards built into the framework, including requirements for selective disclosure (users can share only the specific attribute needed, not the full credential), user consent for private-sector use, and prohibition of tracking user wallet usage. Pilot programs in 2024 began testing these safeguards in practice, with the European Digital Identity Wallet Consortium coordinating technical standards.
**Significance:** Represents the most ambitious government-backed digital identity infrastructure globally, with the potential to set technical and legal standards for digital identity systems worldwide.
The selective disclosure and privacy-by-design requirements in eIDAS 2.0 could serve as a model for other jurisdictions developing digital identity frameworks, balancing technological innovation with privacy protection.

---

### Case 12.53: Singapore AI Verify Framework (2023–2024) —Infocomm Media Development Authority
**Date Decided:** 2023 (launch); 2024 (expansion)

**Court:** Infocomm Media Development Authority (IMDA) Singapore

**Facts:** Singapore's IMDA launched AI Verify, an open-source AI governance testing framework and toolkit, in 2023. AI Verify enables organizations to conduct standardized tests of their AI systems across key governance principles including fairness, explainability, robustness, and data privacy. By 2024, the framework was being piloted by over 60 organizations across financial services, healthcare, and e-commerce sectors. The framework was designed to be technology-neutral, interoperable with international standards (including the EU AI Act), and adaptable to different regulatory environments. It complemented Singapore's broader Model AI Governance Framework.

**Issue:** Whether a voluntary, testing-based AI governance framework can effectively promote responsible AI development and provide meaningful accountability in the absence of mandatory AI regulation.

**Holding:** AI Verify gained international traction, with the IMF, World Bank, and multiple governments expressing interest in adopting or adapting the framework. Singapore continued to develop industry-specific testing criteria and expanded partnerships with the EU, UK, and US to promote interoperability. IMDA emphasized that AI Verify was designed as a complement to, not a substitute for, AI regulation.
**Significance:** Positioned Singapore as a leader in practical AI governance, offering a testing-based approach that complements the more prescriptive regulatory approaches of the EU (AI Act) and China.
The open-source, interoperable design of AI Verify has the potential to serve as a global baseline for AI testing and transparency, particularly for jurisdictions that prefer voluntary governance mechanisms over mandatory regulation.

---

### Case 12.54: UAE AI Strategy Enforcement (2023–2024) —United Arab Emirates
**Date Decided:** 2023–2024 (ongoing implementation)

**Court:** UAE Artificial Intelligence Office / Various UAE regulatory bodies

**Facts:** The United Arab Emirates accelerated implementation of its National Strategy for Artificial Intelligence 2031, which was first launched in 2017. By 2023–2024, the UAE established dedicated AI regulatory bodies, including the UAE Artificial Intelligence Office under the Ministry of State for Artificial Intelligence, Digital Economy, and Remote Work Applications. The government issued regulations governing AI use in healthcare, education, transportation, and financial services. Notable developments included the world's first Minister of State for AI, comprehensive AI ethics guidelines, and pilot programs for AI-assisted government services. The UAE also attracted major AI investments, including partnerships with US and Chinese AI companies.

**Issue:** How a rapidly developing jurisdiction can establish effective AI governance frameworks that attract AI investment while ensuring ethical deployment and protecting citizens' rights.

**Holding:** The UAE issued sector-specific AI guidelines and regulatory sandboxes allowing companies to test AI products under supervised conditions. The UAE AI Office coordinated with international bodies (OECD, UNESCO, ITU) to align its framework with global AI governance principles. Enforcement mechanisms included licensing requirements for high-risk AI applications and mandatory impact assessments for AI systems deployed in critical sectors.
**Significance:** Demonstrates the UAE's ambition to become a global AI hub by combining aggressive investment attraction with proactive governance, offering a model for other Gulf states and developing economies.
The sector-specific approach to AI regulation (healthcare, finance, education) provides a practical alternative to the comprehensive horizontal approach of the EU AI Act, potentially influencing regulatory strategies in the Middle East, Africa, and South Asia.

---

### Case 12.55: WHO Pandemic Treaty Digital Health Provisions (2024-2025) — WHO/World Health Assembly
**Date Decided:** 2024-2025 (ongoing negotiations)

**Court:** World Health Assembly (WHA)

**Facts:** The WHO negotiated a new Pandemic Treaty and amended International Health Regulations (IHR), including provisions for digital health surveillance, pathogen access and benefit-sharing (PABS), and cross-border health data sharing during pandemics. Member states debated the balance between public health emergency response and individual privacy rights.

**Issue:** Whether international pandemic preparedness agreements can mandate digital health data sharing while respecting privacy and sovereignty.

**Holding:** As of 2025, the WHA adopted amendments to the IHR including digital health provisions, but the Pandemic Treaty remains under negotiation with significant disagreements on data governance, intellectual property, and technology transfer.
**Significance:** Represents the first major international treaty negotiation to specifically address digital health surveillance as a component of global pandemic preparedness.
Highlights the tension between global health security and individual data privacy rights in international law.

---

---

# Part 13 — 2025–2026 Recent Developments

## Chapter 13: The Emerging Frontiers

This Part collects the most recent judicial and regulatory developments from late 2025 through mid-2026, reflecting the accelerating pace of cyber law evolution. These cases were identified through systematic web research and community contributions following the compilation of the main body of this compendium, and represent the cutting edge of digital governance across multiple jurisdictions.


*Cases added June 2026 following web research and community call.*

### Case 13.1: ASIC v. FIIG Securities — Australian Federal Court Cybersecurity Penalty

**Date Decided:** 16 June 2026

**Court:** Federal Court of Australia

**Facts:** The Australian Securities and Investments Commission (ASIC) took enforcement action against FIIG Securities, an Australian financial services licence (AFSL) holder, following a cyberattack on its IT systems that resulted in approximately 385GB of data being downloaded from its servers. The AFSL holder had delegated responsibility for IT security to staff without adequate skills or knowledge, lacked an adequate incident response plan, and failed to provide mandatory cybersecurity awareness training. The company also failed to dedicate sufficient financial resources towards adequate cybersecurity measures and did not implement, maintain, or monitor controls outlined in its risk management system.

**Issue:** Whether civil penalties can be imposed on AFSL holders under general obligations for inadequate cybersecurity measures, and whether the cost of remediation will exceed the cost of implementing adequate controls in the first place.

**Holding:** The Court found the AFSL holder failed to comply with obligations under the Corporations Act 2001 (Cth): efficient, honest, and fair financial services (s 912A(1)(a)); adequate resources (s 912A(1)(d)); and adequate risk management systems (s 912A(1)(h)). The Court ordered the AFSL holder to pay AU$2.5 million in penalties and AU$500,000 in costs to ASIC. The AFSL holder must also engage an independent expert to ensure its cybersecurity systems are reasonably managed. The Court noted that the penalties and remediation costs far exceeded what it would have cost to implement adequate controls initially.

**Significance:** This is the first time civil penalties have been imposed for cybersecurity failures pursuant to general AFSL obligations in Australia. It establishes that ASIC will penalise underinvestment in cybersecurity, with penalties likely exceeding the costs of initially implementing adequate controls. AFS licensees must fully implement controls in their risk management systems and maintain adequate resources, systems, and training.

---

### Case 13.2: In re United States Government Export Control Directive on Anthropic Fable 5 — AI Model Restriction

**Date Decided:** 12 June 2026

**Court:** United States Government (Export Administration Regulations / Bureau of Industry and Security)

**Facts:** Anthropic released Fable 5, described as a "Mythos-class" model and the most capable model it had ever released, available through Claude's standard interface and Claude Code. Anthropic stated Fable 5 was made "safe for general use" based on the core of its restricted Mythos model. On 12 June 2026, the US government issued an export control directive requiring Anthropic to suspend all access to Fable 5 and Mythos 5 by foreign nationals. This included some Anthropic employees. Given the difficulty of auditing the citizenship of every Claude user, Anthropic immediately cut off access to both models pending resolution. Anthropic reportedly did not receive a specific reason for the ban but believes it relates to a recently discovered jailbreak vulnerability.

**Issue:** Whether advanced AI models can be restricted from foreign access under US export control regulations, and whether AI safety guardrails are sufficient to prevent malicious use of frontier AI systems.

**Holding:** Anthropic complied with the directive and suspended access. Anthropic argued that Fable 5's many safeguards effectively prevent use for malicious purposes and that the outlined vulnerabilities are neither new nor significant. Anthropic reportedly communicated with Trump administration officials to resolve the dispute and get the models back online. At time of writing, access remained suspended.

**Significance:** This marks one of the first known instances of the US government using export control regulations to restrict access to a commercial AI model. It raises fundamental questions about whether frontier AI models should be treated as controlled dual-use technology, similar to advanced semiconductors. The case highlights the growing tension between open AI development and national security concerns, particularly regarding foreign access to the most capable AI systems.

---

### Case 13.3: FISA Title VII Expiry — Section 702 Surveillance Transition

**Date Decided:** June 2026 (statutory expiry), with current certifications continuing through March 2027

**Court:** Congress of the United States / Foreign Intelligence Surveillance Court (FISA Court)

**Facts:** Title VII of the Foreign Intelligence Surveillance Act (FISA), including Section 702, was set to expire at midnight on 12 June 2026 after Congress failed to pass an extension of the controversial spying law. Title VII, added to FISA in 2008, allows US intelligence agencies to spy on foreign targets without a warrant, but constantly sweeps up communications of Americans in contact with people outside the country. However, the government can continue surveillance under existing certifications issued by the FISA Court on 17 March 2026, which will remain in place until March 2027.

**Issue:** Whether surveillance under Section 702 can continue after the statutory authority expires, and whether Congress will pass meaningful reforms to protect Americans from warrantless government access to their private communications.

**Holding:** Government surveillance activities continued unchanged after the expiry. Rep. Jamie Raskin (D-Md.) confirmed that "everything that's already been authorized and certified is already in motion, and current FISA authorizations will continue unaffected, at least through March 17, 2027." Civil liberties groups including the Brennan Center and Cato Institute confirmed that Section 702 surveillance may continue under existing certifications even after the statutory sunset. The government must not be "fearmongered" into passing reauthorization without meaningful reforms protecting Americans.

**Significance:** This episode highlights a major structural vulnerability in US surveillance law: Congress planned for potential legislative lapses by building transition provisions into the statute, allowing mass surveillance to continue even without active congressional authorization. The expiry underscores growing bipartisan concern about Section 702's scope and the government's exploitation of this "loophole" to surveil Americans without warrants. The transition period through March 2027 gives Congress time to consider reforms.

---

### Case 13.4: Bernie Sanders AI Public Ownership Legislation — American AI Dominance Act

**Date Decided:** June 2026

**Court:** United States Congress (proposed legislation, not yet enacted)

**Facts:** Senator Bernie Sanders unveiled an ambitious legislative proposal to transfer trillions of dollars from leading AI firms to the American public. The legislation would create a sovereign wealth fund financed through a one-time 50% tax on the stock of the largest AI companies. Any AI firm with $200 million in annual AI sales would be subject to the tax, as would any new firm once it reaches that revenue threshold. Sanders estimated the fund could be worth $7 trillion, generating hundreds of billions of dollars annually in direct payments to Americans and programs such as healthcare, education, and housing. Each American would receive more than $1,000 annually in 5% dividends. A newly created Independent Commission for Democratic AI would oversee the fund, with seven bipartisan members nominated by the President and confirmed by the Senate, who could use voting shares to block corporate decisions that harm the public.

**Issue:** Whether the government can compel redistribution of AI industry wealth to the public, whether such a sovereign wealth fund model is constitutionally permissible, and whether the AI industry can be subject to direct democratic oversight.

**Holding:** The proposal was pending congressional consideration. Industry reaction was strongly negative, with OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei having previously shown support for some public benefits from AI but opposing Sanders' more radical approach. Sanders stated: "The benefits cannot simply go to the handful of wealthy corporations. They will be shared by the American people."

**Significance:** This proposal represents the most ambitious attempt by any government to assert public ownership rights over the AI industry. It challenges the fundamental business model of frontier AI companies and signals growing political pressure for AI wealth redistribution. The proposal also raises fundamental questions about AI governance: who controls the most transformative technology of our era, and whether democratic accountability can be built into AI development.

---

### Case 13.5: Pope Leo XIV, Encyclical "Magnifica Humanitas" — AI and Human Dignity

**Date Decided:** 15 May 2026 (issued by Pope Leo XIV)

**Court:** Vatican (Holy See)

**Facts:** Pope Leo XIV, the first American pope, issued his first encyclical, "Magnifica Humanitas" ("Great Human Dignity"), at the Vatican on 15 May 2026. The encyclical focuses on artificial intelligence, automation, and human dignity in the context of rapidly advancing digital technology. The document emphasizes that AI should serve the common good of humanity rather than diminish human autonomy, creativity, and moral responsibility. It calls on governments, technology companies, and international organizations to establish ethical technology governance frameworks to prevent algorithmic discrimination, surveillance abuse, and excessive wealth concentration. Pope Leo XIV stated that humanity must not outsource moral judgment to machines, and that technological progress must be anchored in the preservation of human values and freedom.

**Issue:** Whether AI development should be subject to ethical and moral constraints based on human dignity, and whether international governance frameworks can effectively regulate private technology companies that possess power surpassing many governments.

**Holding:** The encyclical is a non-binding moral and teaching document of the Catholic Church. However, it calls on all stakeholders to: (1) recognize that AI tends to amplify the power of those who already possess economic resources, expertise, and access to data; (2) address the new form of power that emerges when every action—movements, purchases, relationships, and preferences—leaves a trace, enabling profiling, prediction, and behavioral influence, often without individuals' full awareness; (3) ensure that when power is concentrated in the hands of a few private entities that set conditions for access, determine rules of visibility, and shape possibilities for participation, such power does not become opaque and evade public oversight; (4) reject a technocratic and post-humanist mentality that regards the human person as an object to be manipulated or a resource to be optimised; (5) make "the human person at the centre" and place "rejected stones—the poor, the sick, the migrants and the least among us—at the cornerstone."

**Significance:** This is the most comprehensive and authoritative papal teaching on AI ever issued. By framing AI governance as a moral and human rights issue, the encyclical elevates the debate beyond technical safety to fundamental questions of human dignity and social justice. It draws direct parallels to the Tower of Babel, warning that collective technological effort without ethical grounding leads to dehumanization. The encyclical provides a powerful moral framework for international AI governance discussions, particularly regarding surveillance, algorithmic discrimination, and the concentration of technological power in private hands. It has been described as offering wisdom for Big Tech, governments, and ordinary citizens alike.

---

### Case 13.6: Moody v. NetChoice, LLC — Florida Social Media Content Moderation Law

**Date Decided:** 17 June 2024

**Court:** Supreme Court of the United States

**Facts:** The State of Florida enacted S.B. 7072 (2021), prohibiting social media platforms from censoring or shadowbanning candidates for public office and requiring platforms to provide transparency reports and notices of content removal. NetChoice and the Computer & Communications Industry Association (CCIA) challenged the law, arguing it violated the First Amendment by forcing platforms to host speech they would otherwise remove. The Eleventh Circuit granted a preliminary injunction. The Supreme Court granted certiorari to resolve whether the laws violate the First Amendment.

**Issue:** Whether Florida's law restricting social media platforms' content moderation decisions violates the First Amendment, and whether social media platforms are entitled to First Amendment protection as private actors exercising editorial discretion over the content they host.

**Holding:** The Supreme Court vacated the Eleventh Circuit's preliminary injunction and remanded the case, with Justice Kagan writing for a unanimous Court. The Court held that the Eleventh Circuit had applied the wrong legal standard and failed to consider the State's First Amendment interests. The case was sent back for reconsideration under the proper framework.

**Significance:** While the decision was primarily a procedural remand, it provided important guidance on how lower courts should analyze social media content moderation laws. The Court recognized that platforms' content moderation involves protected editorial discretion, but also suggested that certain disclosure and transparency requirements may be permissible. This case, together with NetChoice v. Paxton, set the constitutional framework for state regulation of social media platforms.

---

### Case 13.7: NetChoice, LLC v. Ken Paxton — Texas HB 20 Social Media Platform Regulation

**Date Decided:** 1 July 2024

**Court:** Supreme Court of the United States

**Facts:** Texas enacted HB 20 (2021), requiring social media platforms with more than 50 million monthly active users to (1) disclose their content moderation criteria, (2) provide notice and a mechanism for users to appeal content removal decisions, and (3) refrain from censoring users based on their viewpoint. NetChoice challenged the law. The Fifth Circuit initially upheld HB 20, rejecting NetChoice's First Amendment arguments. The Supreme Court stayed the Fifth Circuit's ruling pending appeal, then granted certiorari.

**Issue:** Whether Texas's HB 20, which prohibits large social media platforms from removing content based on viewpoint, violates the First Amendment rights of those platforms.

**Holding:** The Supreme Court vacated the Fifth Circuit's judgment and remanded the case for further proceedings. Justice Kagan, writing for a unanimous Court, applied the "most-favored-nation" framework, concluding that Texas had not demonstrated that the law would survive First Amendment scrutiny. The Court's decision effectively struck down HB 20, reaffirming that social media platforms have First Amendment rights to make editorial decisions about content on their platforms.

**Significance:** NetChoice v. Paxton, together with Moody v. NetChoice, established the constitutional boundaries of state regulation of social media platforms. Both decisions affirmed that social media companies' content moderation constitutes protected editorial speech under the First Amendment, and that governments cannot compel platforms to host or refrain from removing speech based on viewpoint. These cases remain foundational precedents for platform governance and content moderation law.

---

### Case 13.8: Murthy v. Missouri — Government Coordination with Social Media Platforms

**Date Decided:** 6 March 2024

**Court:** Supreme Court of the United States

**Facts:** Missouri and several individuals alleged that senior officials in the Biden administration coerced social media companies into suppressing content about COVID-19, election integrity, and the Hunter Biden laptop story. The government allegedly warned platforms that their employees could face criminal prosecution, encouraged removal of certain posts, and used pressure tactics to achieve content moderation outcomes. The plaintiffs sought injunctive relief under the Administrative Procedure Act and the First Amendment. The D.C. Circuit held that the government likely violated the First Amendment. The Supreme Court granted certiorari.

**Issue:** Whether the government violated the First Amendment by coercing social media platforms to remove or suppress content, and whether the plaintiffs had standing to bring this challenge.

**Holding:** The Supreme Court dismissed the case for lack of standing, with Justice Barrett writing for a five-justice majority. The Court held that the individual plaintiffs and states had not demonstrated the kind of direct injury required for standing — that they suffered concrete, particularized harm fairly traceable to the government's conduct. The government had changed its course by the time the Court ruled, and there was insufficient evidence that the alleged pressure campaigns directly caused specific content to be removed.

**Significance:** While the dismissal on standing grounds limited the case's precedential value, Murthy v. Missouri was significant in raising public awareness of government-platform coordination. It underscored the need for transparency in government communications with social media companies and the potential constitutional concerns when the government uses its leverage to influence private editorial decisions. The case prompted ongoing legislative efforts to require disclosure of government-platform communications.

---

### Case 13.9: C-683/21 — Online Media Services, Consent, and GDPR Information Obligations

**Date Decided:** 4 October 2024

**Court:** Court of Justice of the European Union (CJEU)

**Facts:** An online media services provider relied on user consent under GDPR Article 6(1)(a) as the lawful basis for processing personal data. The competent national supervisory authority found that the controller had failed to provide the required privacy information under Articles 13 and 14 GDPR at the time of data collection. The question referred to the CJEU was whether, where consent is relied upon as the lawful basis for processing, a controller is still obliged to comply with the information obligations under Articles 13 and 14, or whether the nature of consent as a positive act by the data subject dispenses with such obligations.

**Issue:** Whether a controller relying on consent under GDPR Article 6(1)(a) is exempt from the obligation to provide information under Articles 13 and 14, and whether consent obtained through an unbalanced presentation of information meets the requirement of being "freely given."

**Holding:** The CJEU held that Article 6(1)(a) GDPR cannot be interpreted as dispensing the controller from complying with the information obligations under Articles 13 and 14. These information obligations are autonomous and mandatory, regardless of the legal basis relied upon. The Court further clarified that consent obtained through a presentation of information that is structured in such a way that the data subject is not presented with all relevant elements — so that the data subject lacks meaningful choice — cannot be considered "freely given" under Article 7 GDPR.

**Significance:** C-683/21 reinforces that consent cannot be used as a shortcut to bypass GDPR's transparency framework. Controllers must always provide the required privacy information at the time of data collection, regardless of which lawful basis they rely on. The case also raises the bar for obtaining valid consent by emphasizing that data subjects must have genuine, informed choice — an important principle in the context of complex privacy policies and terms of service that are commonly presented to users in an unbalanced manner.

---

### Case 13.10: Schrems v. Meta Platforms (C-446/21) — GDPR and Legitimate Interest for Targeted Advertising

**Date Decided:** 4 October 2024

**Court:** Court of Justice of the European Union (CJEU)

**Facts:** Maximillian Schrems, the Austrian privacy activist, filed a complaint with the Austrian data protection authority challenging Meta Platforms' use of "contract" as the legal basis under GDPR Article 6(1)(b) for processing personal data for behavioral advertising on Facebook. Schrems argued that Meta should instead rely on "legitimate interest" (Article 6(1)(f)) or obtain consent. The Austrian court referred several questions to the CJEU regarding whether a contract basis could justify processing for advertising purposes, and whether targeted advertising based on extensive tracking of user behavior across websites constitutes a legitimate interest under GDPR.

**Issue:** Whether the "performance of a contract" basis under GDPR Article 6(1)(b) can justify the processing of personal data for behavioral/targeted advertising, and whether such advertising based on comprehensive user profiling constitutes a "legitimate interest" under Article 6(1)(f).

**Holding:** The CJEU held that processing personal data for the purpose of displaying targeted advertisements does not fall within the scope of "performance of a contract" under Article 6(1)(b) GDPR, because displaying targeted ads is not intrinsically necessary to provide the basic service of a social media platform. The Court also found that Meta's use of extensive tracking and profiling for targeted advertising cannot as a general rule be considered compatible with Article 8(1) of the EU Charter of Fundamental Rights, which protects the right to data protection. The Court referred the case back to the national court to verify whether Meta's processing met the requirements for legitimate interest.

**Significance:** This decision is a major blow to Meta's data processing practices in the EU. It effectively requires Meta to obtain freely given consent for its targeted advertising practices, rather than relying on the contractual basis or unilateral legitimate interest assessment. The ruling strengthens GDPR's data protection framework for behavioral advertising and provides a template for how data protection authorities should assess cross-context tracking and profiling by large platforms.

---

### Case 13.11: Thomson Reuters v. Ross Intelligence — AI Training Data and Copyright Infringement

**Date Decided:** 2025 (特拉华州联邦地区法院，审判中)

**Court:** United States District Court for the District of Delaware

**Facts:** Thomson Reuters sued Ross Intelligence, an AI-powered legal research company, for copyright infringement. Thomson Reuters alleged that Ross Intelligence used Westlaw's attorney-written headnotes — summaries and classifications of legal cases — to build its own AI-driven legal research product without authorization or license. Ross Intelligence argued that even if headnotes were used, they were uncopyrightable "tools of the trade" and that its use constituted transformative fair use. The case presented fundamental questions about the copyright status of AI-generated summaries and whether training AI models on copyrighted material constitutes infringement.

**Issue:** Whether attorney-written legal headnotes constitute copyrightable expression or uncopyrightable facts/ideas; whether using copyrighted headnotes to train an AI legal research model constitutes fair use; and what standard applies to assessing AI training as a transformative use.

**Holding:** The case was proceeding through discovery and cross-motions for summary judgment on copyright and related claims. Thomson Reuters' central argument was that Ross Intelligence had no license to reproduce and exploit West's copyrighted headnotes. Ross Intelligence contended that headnotes are functional legal tools lacking creative expression and that AI training use is transformative fair use under Sony Corp. v. Universal City Studios (1984). The Court's rulings on these motions were pending at time of writing.

**Significance:** Thomson Reuters v. Ross Intelligence is one of the most important cases defining the relationship between AI training and copyright law. The outcome will significantly impact the AI industry's ability to use copyrighted material as training data, the copyright status of AI-generated or AI-assisted works, and the future of legal information markets. A ruling favoring Thomson Reuters would establish that AI companies must license copyrighted training data, potentially imposing significant costs on the AI industry.

---

### Case 13.12: New York Times Co. v. OpenAI Inc. — AI Training and Journalism

**Date Decided:** Settled February 2025

**Court:** United States District Court for the Southern District of New York

**Facts:** The New York Times sued OpenAI and Microsoft for using millions of its copyrighted articles, investigations, and reviews to train GPT models and incorporating Times content into AI-generated responses — without permission or compensation. The Times alleged copyright infringement, unjust enrichment, and trademark dilution under the Lanham Act. OpenAI argued that its AI training constituted transformative fair use under Sony v. Universal and that GPT models do not reproduce Times content in a substitutable manner.

**Issue:** Whether using copyrighted news articles to train large language models constitutes fair use; whether AI-generated outputs incorporating copyrighted content violate publishers' rights; and whether AI companies can rely on the "transformative use" doctrine to avoid licensing requirements.

**Holding:** The case was settled in early 2025 on terms that included OpenAI licensing New York Times content, potentially acquiring a minority stake in the Times, and establishing a content fund. The settlement terms were not publicly disclosed. The case was dismissed with prejudice in February 2025.

**Significance:** NYT v. OpenAI was the most high-profile clash between legacy media and the AI industry over the use of copyrighted content for AI training. While the settlement avoided a definitive judicial ruling on AI training and copyright, it established the principle that AI companies will need to negotiate licenses with major content creators. The case accelerated industry-wide licensing negotiations and influenced the development of AI copyright legislation in multiple jurisdictions.

---

### Case 13.13: Getty Images (International) Ltd. v. Stability AI Ltd. — AI Training on Copyrighted Photographs

**Date Decided:** 2024 (英国高等法院，审判中)

**Court:** UK High Court of Justice (King's Bench Division, Intellectual Property Enterprise Court)

**Facts:** Getty Images sued Stability AI, the company behind the Stable Diffusion image generation model, for using billions of images scraped from the internet — including Getty's licensed photographs — to train its AI model without permission or license. Getty alleged copyright infringement of its photographs under the Copyright, Designs and Patents Act 1988, and violations of its database rights. Getty also claimed that Stability AI had scraped associated metadata containing Getty's trademarks, diluting the commercial value of its brand. Stability AI argued that training AI on publicly available images constitutes fair use and that the images themselves were not reproduced in the training process.

**Issue:** Whether training an AI image generation model on copyrighted photographs constitutes copyright infringement or fair dealing; whether scraping image metadata containing copyright notices and trademarks violates intellectual property rights; and whether AI companies can claim any defense based on the transformative nature of the output.

**Holding:** The UK High Court allowed Getty's claims to proceed to trial, rejecting Stability AI's arguments that the claims were time-barred or that AI training constituted permissible fair use. The Court found a serious issue to be tried on copyright infringement and database rights. The case was proceeding through the UK litigation system at time of writing.

**Significance:** Getty v. Stability AI is one of the most significant cases addressing the intersection of AI training and intellectual property rights outside the United States. The UK High Court's decision to allow the claims to proceed signals that European courts may be more receptive to copyright claims against AI companies than US courts, particularly with respect to database rights and metadata claims. The case has implications for all AI companies training models on European creative content.

---

### Case 13.14: Dutch DPA v. Clearview AI — Facial Recognition Database and GDPR

**Date Decided:** 4 July 2024

**Court:** Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP)

**Facts:** The Dutch Data Protection Authority (AP) conducted an investigation into Clearview AI, a US-based facial recognition company that built and maintained a database of billions of facial images scraped from public websites without data subjects' knowledge or consent. The database was used by law enforcement agencies worldwide, including Dutch authorities, to identify individuals. The AP investigated whether Clearview AI's processing of Dutch residents' biometric data violated GDPR.

**Issue:** Whether building and maintaining a facial recognition database by scraping publicly available images, without data subjects' consent or knowledge, constitutes lawful processing under GDPR; whether the database serves a purpose compatible with the original purpose of data collection; and what penalties are appropriate for violations.

**Holding:** The AP found that Clearview AI violated GDPR by: (1) collecting facial images beyond what was necessary for its stated law enforcement identification purpose; (2) failing to have a lawful basis for processing, as legitimate interest did not override data subjects' rights; (3) failing to provide transparent information to data subjects. The AP imposed a fine of €30.5 million and ordered Clearview AI to stop processing Dutch residents' data and delete all such data from its database. In a separate investigation, the Italian Garante also imposed restrictions on Clearview AI's processing of Italians' data.

**Significance:** Clearview AI's GDPR violations across multiple jurisdictions (Netherlands, Italy, France, Greece) underscore the global regulatory backlash against mass facial recognition surveillance. The decisions confirm that scraping facial images from public websites for identification purposes without consent violates fundamental GDPR principles. The €30.5 million fine was among the largest ever imposed by a national data protection authority, signaling that GDPR enforcement against biometric data processing will be rigorous and consequential.

---

### Case 13.15: European Commission v. Apple — Digital Markets Act Non-Compliance

**Date Decided:** 2024–2025 (欧盟委员会正式指控)

**Court:** European Commission (proceedings under Digital Markets Act, Regulation 2022/1925)

**Facts:** The European Commission opened formal non-compliance proceedings against Apple under the Digital Markets Act (DMA), alleging that Apple failed to comply with its obligations to allow app developers to "steer" consumers to offers outside the App Store (Article 5(7) DMA) and to provide interoperability with Apple's own services. Apple's new fee structure for developers — including a "Core Technology Fee" of €0.50 per installation after 1 million annual installs — was found to undermine the DMA's objective of enabling developers to offer consumers alternative, cheaper offers. Despite modifications announced by Apple in January 2024, the Commission found persistent non-compliance.

**Issue:** Whether Apple's fee structure for app distribution complies with the DMA's prohibition on unfair and discriminatory conditions; whether the "Core Technology Fee" constitutes an illegal charge that undermines the objective of enabling steering; and what remedies are appropriate for DMA non-compliance.

**Holding:** The European Commission formally charged Apple with DMA non-compliance in March 2024. Apple's fee structure was found to fail the requirements of the DMA that allow developers to freely steer consumers to alternative offers. The Commission issued a specification decision requiring Apple to comply with DMA obligations. Non-compliance may result in fines of up to 10% of Apple's global annual turnover, or periodic penalty payments of up to 5% of daily turnover.

**Significance:** EC v. Apple DMA is the first major enforcement action under the EU's Digital Markets Act, marking a new era of ex ante regulation of platform gatekeepers. The case demonstrates the European Commission's willingness to impose significant penalties on the world's most valuable company and establishes important precedents for platform interoperability, app distribution fees, and consumer steering under the DMA framework.

---

### Case 13.16: TikTok Ban Litigation — ByteDance/Bytedance Ltd. v. United States

**Date Decided:** 2024–2025 (美国联邦上诉法院及最高法院)

**Court:** United States Court of Appeals for the District of Columbia Circuit; Supreme Court of the United States

**Facts:** In March 2024, President Biden signed legislation requiring ByteDance Ltd. — TikTok's Chinese parent company — to divest TikTok's US operations within approximately nine months or face a ban in the United States, on national security grounds relating to data access by the Chinese government. TikTok and ByteDance challenged the law in the D.C. Circuit, arguing that the ban violated the First Amendment rights of TikTok and its 170 million American users, that the divestiture requirement was technologically and commercially impracticable, and that the law was an unconstitutional bill of attainder. The D.C. Circuit upheld the law. The Supreme Court agreed to hear emergency arguments and upheld the ban by a 9-0 vote on 17 January 2025.

**Issue:** Whether forcing ByteDance to divest TikTok or face a ban constitutes an unconstitutional taking without just compensation; whether it violates the First Amendment by compelling TikTok to speak or host speech on behalf of the Chinese government; and whether Congress had authority under the Commerce Clause to regulate a foreign-owned platform on national security grounds.

**Holding:** The Supreme Court upheld the ban in a unanimous per curiam decision on 17 January 2025. The Court found that the petitioners had failed to raise "a serious First Amendment issue" and that Congress had authority under the Commerce Clause to address national security concerns related to foreign adversary-controlled applications. The ban took effect shortly thereafter. However, President Trump indicated willingness to negotiate a sale of TikTok, and in early 2025 discussions continued regarding potential investors, with ongoing legislative and executive activity affecting TikTok's US operations.

**Significance:** The TikTok ban case is the most significant platform regulation case in US history, involving free speech, national security, foreign investment, and the power of Congress to regulate technology platforms owned by foreign adversaries. It establishes that national security concerns may override First Amendment objections to platform regulation and that Congress can mandate divestiture of foreign-owned platforms on national security grounds — potentially influencing similar regulations in other democracies.

---

### Case 13.17: Competition Commission of India v. WhatsApp/Meta — Privacy Policy and Antitrust

**Date Decided:** 2024–2025 (印度竞争委员会 / 最高法院)

**Court:** Competition Commission of India (CCI); Supreme Court of India

**Facts:** In 2021, WhatsApp updated its privacy policy to allow sharing of user data — including phone numbers, usage patterns, and device information — with other Meta companies for purposes including improved infrastructure, security, and advertising. Users were required to accept the new policy to continue using WhatsApp, with no option to selectively decline. The CCI investigated and found that WhatsApp had abused its dominant position in the Indian messaging market by imposing unfair conditions on users through its "take-it-or-leave-it" privacy policy. In 2024, the CCI imposed a penalty of approximately ₹2,139.59 crore (approximately US$255 million) and issued a five-year prohibition on sharing WhatsApp user data with other Meta entities for advertising purposes. Both WhatsApp and the CCI appealed to the Supreme Court of India.

**Issue:** Whether a "take-it-or-leave-it" privacy policy that forces users to accept expanded data sharing constitutes an abuse of dominant position under India's Competition Act 2002; whether the fine is proportionate to the violation; and what remedies adequately protect user privacy while preserving competition.

**Holding:** The Supreme Court of India heard arguments from both WhatsApp and the CCI regarding the penalty and data-sharing prohibition. WhatsApp challenged the penalty quantum and the scope of the data-sharing prohibition, arguing that it would require structural changes to its service. The Supreme Court indicated it would issue directions to protect user privacy. The final orders were pending at time of writing.

**Significance:** CCI v. WhatsApp is the most significant antitrust decision in India involving a technology platform and sets an important global precedent for regulating the intersection of data privacy and competition law. It confirms that privacy policies that combine forced consent with market dominance can constitute an abuse of dominant position, and that antitrust authorities can impose significant penalties and behavioral remedies to protect users from unfair data practices.

---

### Case 13.18: Guiding Case No. 223 — Zhang Moulong v. Beijing Mouie Company Personal Information Dispute

**Date Decided:** 2023 (Supreme People's Court of the People's Republic of China)

**Court:** Supreme People's Court

**Facts:** The plaintiff, Zhang Moulong, alleged that the defendant, Beijing Mouie Company, collected and used his personal information without valid consent when he used the defendant's online platform. The plaintiff argued that the defendant's collection and processing of personal information violated his rights under the Personal Information Protection Law (PIPL). The case raised core issues regarding the standard for determining the legality of personal information collection by online platforms, and the methods for fulfilling the duty of notification and obtaining consent by personal information handlers.

**Issue:** What are the criteria for determining the legality of personal information collection by online platforms? Has the personal information handler fulfilled its duty of notification and obtaining consent under the PIPL? Does the collection of personal information without full notification and consent constitute an infringement?

**Holding:** The Supreme People's Court issued Guiding Case No. 223, establishing the following adjudication principles: Online platforms collecting and using personal information shall adhere to the principles of legality, legitimacy, and necessity. Processing of personal information shall obtain the individual's consent, which must be a manifesttion of true intent made voluntarily and explicitly on the premise of being fully informed. Personal information handlers shall notify personal information processing rules in clear and understandable language, truthfully, accurately, and completely. Collecting personal information without full notification and consent constitutes an infringement.

**Significance:** Guiding Case No. 223 is one of the first batch of guiding cases on personal information protection issued by the Supreme People's Court. It clarifies the adjudication standards for courts to review online platform personal information collection practices after the implementation of the PIPL, and has exemplary and leading significance for strengthening personal information protection in cyberspace.


### Case 13.19: Guiding Case No. 224 — Hanhuayimei v. Henan Mulu Fengye Network Copyright Dispute

**Date Decided:** 2023 (Supreme People's Court of the People's Republic of China)

**Court:** Supreme People's Court

**Facts:** The plaintiff, Hanhuayimei (a cultural media company), discovered that the defendant, Henan Mulu Fengye Company, disseminated on its commercial website and new media platforms the plaintiff's copyrighted audiovisual works, literary works, images, and other content without authorization. The defendant argued that it merely provided information storage space services to users and should be exempted from liability under the "safe harbor" principle. The case involved core issues such as the determination of infringement liability for online platforms in information network dissemination rights, and the standards for determining platform fault.

**Issue:** How to determine the subject of infringement for information network dissemination rights? What are the conditions for applying the "safe harbor" principle and the standards for determining platform fault? Where are the boundaries of a platform's duty of care regarding users' infringing acts?

**Holding:** The Supreme People's Court clarified in Guiding Case No. 224: Platforms providing merely information storage space services do not automatically qualify for the "safe harbor" principle; it is necessary to examine whether the platform fulfilled reasonable duty of care regarding the occurrence of infringing acts. Where platforms actively promote users' uploaded content through editorial recommendations, manual interventions, etc., they cannot plead technological neutrality in defense. Where platforms fail to take necessary measures promptly after receiving valid infringement notices, they shall bear joint and several liability for the expanded portion of damages.

**Significance:** Guiding Case No. 224 refined the standards for determining platform liability in information network dissemination rights cases, provided an authoritative interpretation of online platforms' copyright management obligations and the boundaries of applying the "safe harbor" principle, and holds significant importance for regulating online platform content management and copyright protection.


### Case 13.20: Supreme People's Court Special Cases on Data Rights — Six Cases on Data Rights Protection (2025)

**Date Decided:** 2025 (Supreme People's Court of the People's Republic of China)

**Court:** Supreme People's Court

**Facts:** In 2025, the Supreme People's Court issued a total of six guiding cases on data rights protection, covering various types such as data scraping, platform data competition, and damage caused by data security vulnerabilities. Typical cases include: a technology company suing a data company for scraping user review data from its platform; a network service provider being held liable for user information leakage due to data security vulnerabilities; and a series of cases on whether platforms' refusal to open data interfaces constitutes unfair competition.

**Issue:** What is the legal nature and protection boundary of enterprise data rights? What are the standards for determining the legitimacy of data scraping acts? Do platforms have the right to refuse opening data interfaces to third parties, and under what conditions would such refusal constitute unfair competition or monopolistic conduct? What are the standards for fulfilling data security obligations and the liability for leakage?

**Holding:** The Supreme People's Court established the following adjudication rules through the six cases: Enterprises enjoy competitive rights in data collections formed through substantial resource investment, protected by the Anti-Unfair Competition Law. Large-scale scraping of competitors' platform data without authorization constitutes unfair competition. Within a reasonable scope, platforms have the right to decide whether to open data interfaces, but refusal to open that aims to exclude or restrict competition may constitute monopolistic conduct or unfair competition. Network service providers that fail to fulfill data security protection obligations and cause user information leakage shall bear corresponding civil liability.

**Significance:** The six special cases on data rights in 2025 are the most important judicial guidance documents issued by the Supreme People's Court in the context of the market-oriented reform of data elements. They systematically respond to three core issues: data ownership, data circulation, and data security, provide clear behavioral expectations for market entities in the digital economy, and hold significant importance for improving the legal mechanism for market-oriented allocation of data elements.


### Case 13.21: DOJ v. Apple Inc. — Smartphone Ecosystem Antitrust Litigation

**Date Decided:** 2024–present (新泽西州联邦地区法院)

**Court:** United States District Court for the District of New Jersey

**Facts:** The United States Department of Justice, joined by 15 state and territory attorneys general, filed a landmark antitrust lawsuit against Apple Inc. on 21 March 2024 in the District of New Jersey federal court. The complaint alleged that Apple illegally monopolized the smartphone market and "supersmartphone" submarket by restricting competition through a series of anticompetitive practices that tie consumers to its ecosystem. Specific practices alleged included: (1) blocking "super apps" that would reduce the power of the App Store; (2) suppressing mobile cloud streaming services; (3) excluding cross-platform messaging apps that would reduce iPhone-to-Android switching costs; (4) degrading the functionality of non-Apple smartwatch products; (5) preventing the development of competing digital wallets; and (6) using its App Store review process to enforce exclusionary restrictions. The DOJ sought structural remedies, including potential divestiture.

**Issue:** Whether Apple holds monopoly power in the smartphone market or "supersmartphone" submarket; whether Apple's practices of restricting cross-platform functionality, limiting app capabilities, and maintaining exclusivity arrangements constitute anticompetitive conduct under Section 2 of the Sherman Act; and what remedies are appropriate to restore competition.

**Holding:** In September 2024, the district court denied Apple's motion to dismiss the case, allowing the DOJ's Sherman Act Section 2 monopolization claims to proceed. The Court found that the DOJ had adequately alleged that Apple possessed monopoly power and that Apple's conduct — including blocking cross-platform messaging, limiting cloud streaming, and restricting third-party smartwatch functionality — could constitute anticompetitive conduct designed to maintain its smartphone monopoly. Discovery was underway at time of writing.

**Significance:** DOJ v. Apple is the most significant US antitrust case against a technology company since United States v. Microsoft (2001). A finding of liability could fundamentally reshape the smartphone industry and require Apple to fundamentally restructure its iPhone ecosystem, potentially including opening the App Store to competing payment systems, allowing cross-platform messaging, and enabling full functionality for competing devices and services. The case represents the most aggressive application of Sherman Act Section 2 to a technology platform's ecosystem lock-in strategies.

---

### Case 13.22: United States v. Roman Storm — Tornado Cash Criminal Prosecution and OFAC Sanctions

**Date Decided:** 2024–2025 (美国纽约南区联邦地区法院及第五巡回上诉法院)

**Court:** United States District Court for the Southern District of New York; United States Court of Appeals for the Fifth Circuit

**Facts:** Roman Storm, a US citizen and developer of Tornado Cash — a cryptocurrency mixing service — was indicted by the US Department of Justice in August 2023 on charges of conspiracy to commit money laundering, conspiracy to violate the International Emergency Economic Powers Act (IEEPA), and operating an unlicensed money-transmitting business. The DOJ alleged that Tornado Cash facilitated the laundering of over US$1 billion in criminal proceeds, including hundreds of millions of dollars laundered for the Democratic People's Republic of Korea's Lazarus Group. Separately, the US Treasury's Office of Foreign Assets Control (OFAC) had added Tornado Cash to the Specially Designated Nationals (SDN) List in August 2022, prohibiting US persons from interacting with the protocol. In November 2024, the US Fifth Circuit Court of Appeals ruled that OFAC's sanctions on Tornado Cash's immutable smart contracts exceeded its statutory authority, as the contracts were not "property" under IEEPA.

**Issue:** Whether criminal liability attaches to developers of decentralized, autonomous smart contract protocols; whether OFAC has authority to sanction immutable, decentralized code that cannot be controlled by any person or entity; whether Tornado Cash's smart contracts are analogous to other neutral technological tools that facilitate both lawful and unlawful use; and whether developers can claim a "code is speech" defense.

**Holding:** Roman Storm's criminal trial began in the Southern District of New York in July 2025. Storm was convicted on the unlicensed money-transmitting charge (convicted on two counts, acquitted on one money laundering count at time of writing). Meanwhile, the Fifth Circuit's November 2024 ruling required OFAC to remove Tornado Cash from the SDN List for its immutable smart contracts. The Treasury Department formally delisted Tornado Cash's contracts in March 2025. Storm was subsequently sentenced to a term of imprisonment for operating an unlicensed money-transmitting business.

**Significance:** The Tornado Cash case represents the most consequential clash yet between criminal law, sanctions enforcement, and the nature of decentralized blockchain technology. The Fifth Circuit's ruling that immutable code is not "property" under IEEPA establishes an important limitation on OFAC's reach over decentralized systems — distinguishing Tornado Cash's immutable contracts from its front-end website and developer-controlled components. The criminal conviction of Storm while simultaneously delisting the protocol's immutable contracts creates a complex legal landscape: the protocol is legally accessible by US persons, but those who knowingly use it to launder criminal proceeds remain liable. This tension will define crypto regulatory enforcement for years to come.

---

### Case 13.23: Epic Games, Inc. v. Google LLC — Android App Distribution and Google Play Store Monopolization

**Date Decided:** 2024 (联邦地区法院判决); 2025 (第九巡回上诉法院审理中)

**Court:** United States District Court for the Northern District of California; United States Court of Appeals for the Ninth Circuit

**Facts:** Epic Games sued Google for monopolization and anticompetitive conduct related to the Google Play Store and Android app distribution. Epic alleged that Google maintained an unlawful monopoly over the Android app distribution market through exclusive deals with device manufacturers (Original Equipment Manufacturers, OEMs), deals with carriers to pre-install Google Play and prevent competing app stores, Google's Project Hug program that paid game developers not to compete with Google Play, and Google's blocking of Epic's efforts to distribute Fortnite on Android through its own Epic Games Store. The jury found in Epic's favor on the monopolization claim in December 2023. The district court subsequently issued an injunction requiring Google to allow third-party app stores on Android and prohibiting exclusive deals. Google appealed to the Ninth Circuit.

**Issue:** Whether Google holds monopoly power in the Android app distribution market; whether Google's exclusive dealing arrangements, OEM agreements, and Project Hug payments constitute anticompetitive conduct under Section 2 of the Sherman Act; and what remedies are appropriate to restore competition in the app distribution market.

**Holding:** The district court found that Google had monopoly power in the Android app distribution market and that its exclusive dealing and anticompetitive practices violated Section 2 of the Sherman Act. The court issued a permanent injunction requiring Google to: (1) allow third-party app stores on Android; (2) not enter into exclusive agreements to prevent distribution of competing apps; (3) allow sideloading of apps. Google appealed. The Ninth Circuit heard arguments in 2025 and the decision was pending at time of writing.

**Significance:** Epic v. Google, together with Epic v. Apple, represents a watershed moment in platform competition law. The district court's findings confirmed that Google's control over Android app distribution constitutes monopoly power and that its practices of paying developers and OEMs to maintain exclusivity are anticompetitive. The injunction could fundamentally change Android app distribution, potentially reducing Google's revenues from the Play Store by billions of dollars and enabling genuine competition from alternative app stores.

---

### Case 13.24: X Corp. v. Media Matters for America — Content Moderation and Platform Liability

**Date Decided:** 2024 (美国联邦地区法院)

**Court:** United States District Court for the Northern District of Texas

**Facts:** X Corp. (formerly Twitter) sued Media Matters for America, a progressive media watchdog organization, for defamation after Media Matters published a report claiming that X's advertisements were appearing alongside pro-Nazi content. X alleged that Media Matters knowingly manipulated the platform to find instances of ads near extremist content and that its report was false and defamatory. Elon Musk, who acquired Twitter in October 2022 and rebranded it as X, publicly characterized the lawsuit as an attempt to hold Media Matters accountable for what he described as fraudulent conduct in misrepresenting the platform's ad placement practices.

**Issue:** Whether Media Matters' publication of a report about X's ad placement constitutes defamation; whether deliberately manipulating platform search results to produce specific content constitutes "fraudulent" conduct sufficient to support a defamation claim; and what standard applies to defamation claims involving media monitoring organizations' analysis of algorithmic content placement.

**Holding:** The district court granted Media Matters' motion to dismiss in November 2024, finding that X had failed to state a plausible claim for defamation. The Court held that Media Matters' report, which described how its researchers manually manipulated the platform to produce the results it reported, was substantially true and that X had not adequately alleged that Media Matters acted with actual malice. The case was dismissed with prejudice.

**Significance:** X Corp. v. Media Matters highlighted the challenges platforms face in defamation litigation when they themselves are public figures or when the alleged defamatory statements are substantially accurate descriptions of investigative findings. The dismissal reinforces that courts will scrutinize platform companies' defamation claims carefully, particularly when the claims involve content that platforms themselves moderate and when the challenged statements reflect the actual methodology used by researchers.

---

### Case 13.25: Bundesgerichtshof (German Federal Court of Justice), Case No. I ZR 53/23 — YouTube Copyright Liability for User-Uploaded Content

**Date Decided:** 2024 (德国联邦最高法院)

**Court:** Bundesgerichtshof (German Federal Court of Justice, First Civil Senate)

**Facts:** The German Federal Court of Justice issued a landmark ruling on the liability of YouTube for copyright-infringing content uploaded by users. The case arose from a dispute between YouTube and music rights holders (GEMA and individual music producers) over whether YouTube was itself directly liable for hosting and making available infringing music content, or whether it could rely on the hosting exemption under the German implementation of the EU E-Commerce Directive (TDDSG/Telemediengesetz). The case had been referred back to the German court by the CJEU in an earlier ruling (Case C-682/18, Franklin v. YouTube, 2022).

**Issue:** Whether YouTube's systematic hosting of potentially infringing user-uploaded content — including its recommendation algorithms and organizational choices — exceeds the scope of the hosting exemption under Article 14 of the E-Commerce Directive; whether YouTube's Content ID system constitutes an affirmative step that forfeits the hosting exemption; and what obligations YouTube has to proactively prevent repeat infringements.

**Holding:** The BGH ruled that YouTube is not entitled to the hosting exemption under German law (§ 7 TMG / § 10 TDDSG) when it engages in acts that go beyond merely technical processing of user-uploaded content — including its organizational decisions about content categorization, recommendation algorithms, and the overall structure of the platform that makes infringing content easily discoverable. The Court found that YouTube's active role in organizing and promoting content, combined with its knowledge of widespread infringement, exceeded the passive hosting threshold. The case was remanded to the lower court to assess damages.

**Significance:** BGH v. YouTube is a landmark ruling on platform liability under European copyright law, going beyond the CJEU's more restrictive approach in Franklin v. YouTube. The ruling suggests that platforms that actively organize, categorize, and recommend content — rather than merely hosting it — may not qualify for the hosting exemption, potentially exposing them to direct liability for user-generated infringing content. This ruling has significant implications for YouTube and other video platforms operating in Germany.

---

### Case 13.26: CJEU Case C-333/21 — GDPR Profiling, Legitimate Interest, and Automated Decision-Making

**Date Decided:** 2024

**Court:** Court of Justice of the European Union (CJEU)

**Facts:** A data subject challenged a company's use of extensive profiling based on personal data — including online behavior tracking, purchase history, and demographic information — to make automated decisions about the individual's eligibility for credit and insurance products, and to set prices. The national court referred questions to the CJEU regarding: (1) whether profiling based on extensive data collection across multiple online sources constitutes processing compatible with the original purpose of data collection; (2) whether the legitimate interest basis under GDPR Article 6(1)(f) can justify profiling that results in automated decisions affecting data subjects; and (3) what safeguards Article 22 GDPR requires for automated decision-making based on profiling.

**Issue:** Whether large-scale profiling for automated decision-making purposes is compatible with GDPR's lawful basis requirements; whether profiling based on cross-source data collection constitutes a "legitimate interest" under Article 6(1)(f); and what procedural safeguards Article 22 GDPR requires when automated decisions produce legal or similarly significant effects on data subjects.

**Holding:** The CJEU held that profiling that results in automated decisions with significant effects on data subjects — including decisions affecting access to credit, insurance, or financial services — requires explicit consent under Article 22 GDPR or a specific legal provision authorizing such processing. The Court further held that mere legitimate interest under Article 6(1)(f) is insufficient to justify automated profiling that produces legal or similarly significant effects on data subjects, as Article 22 establishes a stricter standard for such processing. Where profiling is used, data subjects have the right to human intervention, to express their point of view, and to contest the decision.

**Significance:** C-333/21 significantly strengthens GDPR's protection against automated profiling and decision-making. The ruling makes clear that credit scoring, insurance risk assessment, and other consequential automated decisions cannot be based solely on legitimate interest — they require explicit consent or a specific legal basis. This decision will require financial services, insurance, and e-commerce companies to fundamentally revise their automated decision-making systems and profiling practices.

---

### Case 13.27: Information Commissioner v. Clearview AI Inc. — UK ICO Enforcement and Facial Recognition

**Date Decided:** 2024 (英国信息专员办公室)

**Court:** Information Commissioner's Office (ICO), United Kingdom

**Facts:** The UK Information Commissioner's Office (ICO) issued an enforcement notice against Clearview AI Inc., requiring the company to cease processing personal data of UK residents and to delete all data relating to UK individuals from its systems. The ICO investigation found that Clearview AI had scraped billions of images from public websites and social media platforms without the knowledge or consent of UK residents, built a facial recognition database used by law enforcement agencies worldwide, and offered its services to private sector clients in the UK. The ICO concluded that this processing violated UK GDPR and the Data Protection Act 2018.

**Issue:** Whether scraping publicly available images to build a facial recognition database constitutes lawful processing under UK GDPR; whether the enforcement notice was proportionate given the international nature of Clearview AI's operations; and what remedial measures Clearview AI must take to comply with UK data protection law.

**Holding:** The ICO issued the enforcement notice requiring Clearview AI to cease processing UK residents' data and to delete all such data within a specified period. Clearview AI challenged the enforcement notice in the First-tier Tribunal (Information Rights). The tribunal proceedings were ongoing at time of writing, with Clearview AI arguing that it is not subject to UK GDPR jurisdiction as a US-based company with no UK establishment.

**Significance:** The UK ICO's enforcement action against Clearview AI, combined with similar actions by the French CNIL, Italian Garante, and Dutch AP, demonstrates international regulatory consensus that mass facial recognition surveillance without consent violates data protection law. The UK enforcement is particularly significant because it covers both law enforcement and private sector use cases and because the UK — post-Brexit — has developed its own independent GDPR equivalent that now provides a clear regulatory framework for AI-related data processing.

---

### Case 13.28: Amazon EU S.à.r.l. — Digital Markets Act Gatekeeper Designation and Obligations

**Date Decided:** 2024 (欧盟委员会)

**Court:** European Commission (Digital Markets Act proceedings)

**Facts:** The European Commission designated Amazon as a "gatekeeper" under the Digital Markets Act (DMA) in relation to its Amazon Marketplace platform (B2C online intermediation services) and its Amazon Advertising platform. Amazon was required to comply with DMA obligations including: (1) allowing third-party sellers access to their data on Amazon Marketplace; (2) not using data from third-party sellers to compete with them on the platform; (3) not using ranking methods that give self-preferential treatment to Amazon's own products; (4) allowing users to unbundle Prime from Amazon's delivery services; and (5) providing interoperability for sellers to communicate with customers through the Amazon platform.

**Issue:** Whether Amazon's use of third-party seller data to inform its own private label product decisions constitutes unfair use of competitive data under DMA Article 6(11); whether Amazon's Buy Box algorithm that preferentially ranks Amazon's own products violates DMA Article 6(5); and whether bundling Prime with other Amazon services constitutes an unfair practice under DMA.

**Holding:** The European Commission conducted market investigations and issued compliance decisions under the DMA. Amazon was found in partial compliance with some DMA obligations but was required to make additional changes to its ranking and advertising practices. Amazon challenged certain aspects of the Commission's decisions in the EU courts. The Commission continued monitoring Amazon's compliance with DMA obligations through 2025.

**Significance:** Amazon's DMA designation and compliance proceedings established important precedents for the regulation of multi-sided platforms under the DMA framework. The proceedings clarified the scope of the DMA's data access and portability rights, the prohibition on self-preferencing in ranking, and the requirements for fair and non-discriminatory platform access. Amazon's DMA case, together with similar proceedings against Apple, Alphabet/Google, and Meta, is shaping the competitive landscape of European digital markets.

---

### Case 13.29: Competition Tribunal of South Africa v. Meta Platforms — WhatsApp Data Sharing Prohibition

**Date Decided:** 2024 (南非竞争法庭)

**Court:** Competition Tribunal of South Africa

**Facts:** South Africa's Competition Commission investigated Meta Platforms following a complaint about WhatsApp's 2021 privacy policy update, which forced South African users to accept expanded data sharing with Meta or lose access to the service. The Commission found that the forced acceptance of the new privacy policy constituted an abuse of dominance under South Africa's Competition Act 89 of 1998, by imposing exploitative conditions on users who had no reasonable alternative to WhatsApp given its dominant position in the South African messaging market. The matter was referred to the Competition Tribunal for adjudication and remedies.

**Issue:** Whether a "take-it-or-leave-it" privacy policy update by a dominant messaging platform constitutes an abuse of dominance under South African competition law; what remedies are appropriate when dominant platforms impose unfair terms on users; and whether privacy violations can constitute competition law violations in jurisdictions without comprehensive data protection frameworks.

**Holding:** The Competition Tribunal of South Africa ordered Meta to cease sharing WhatsApp user data with other Meta group companies for advertising purposes in South Africa, pending a full investigation. The Tribunal found that the forced privacy policy update could constitute an abuse of dominance, particularly given WhatsApp's near-absolute market dominance in South Africa and the lack of meaningful consent mechanisms. A full hearing on quantum of penalty and permanent remedies was scheduled.

**Significance:** South Africa's proceedings against WhatsApp establish that competition law can serve as a backstop for privacy protection even in the absence of comprehensive data protection legislation. The South African Competition Tribunal's willingness to grant interim relief based on privacy-related abuse of dominance claims signals that competition authorities globally are developing tools to address digital platform practices that harm both competition and consumer welfare through data exploitation.

---

### Case 13.30: CMA v. Apple — UK Competition and Markets Authority Investigation into iPhone Browser Engine Restrictions

**Date Decided:** 2024 (英国竞争与市场管理局)

**Court:** Competition and Markets Authority (CMA), United Kingdom

**Facts:** The UK's Competition and Markets Authority (CMA) opened a formal investigation into Apple's restriction of browser engines on iOS — specifically Apple's policy preventing third-party browsers from using their own rendering engines on iPhones and iPads, requiring all browsers to use Apple's WebKit engine. The CMA found that this restriction limited competition in the browser market, reduced innovation in browser technology, and disadvantaged UK consumers who were locked into Apple's WebKit-based browsing experience. The investigation was conducted under the UK's Competition Act 1998 and the newly enacted Digital Markets, Competition and Consumers Act 2024.

**Issue:** Whether Apple's restriction of browser engines on iOS constitutes an abuse of dominant position in the market for mobile browsers in the UK; whether the browser engine restriction has the effect of foreclosing competition in adjacent markets (browsers, web apps); and what remedies the CMA can impose under UK competition law to restore competition in mobile browsing.

**Holding:** The CMA issued an interim report in 2024 finding that Apple likely held a dominant position in the UK mobile browser market and that its WebKit restriction likely constituted an abuse of dominance. The CMA indicated it would require Apple to allow third-party browser engines on iOS in the UK, similar to changes Apple was required to make in the EU under the DMA. Apple challenged the CMA's jurisdiction and methodology. The CMA was finalizing its remedies decision at time of writing.

**Significance:** CMA v. Apple represents the most advanced competition enforcement action against Apple's browser engine restrictions outside the EU. The UK case is significant because it operates under the UK's newly enacted Digital Markets, Competition and Consumers Act 2024, which provides additional remedies including consumer-focused interventions. The outcome will influence whether the UK adopts a more aggressive approach to regulating Apple's ecosystem than the EU's DMA framework.

---

### Case 13.31: Schrems II Implementation — Standard Contractual Clauses and Supplementary Measures (2024)

**Date Decided:** 2024 (欧洲数据保护委员会; 爱尔兰数据保护委员会)

**Court:** European Data Protection Board (EDPB); Irish Data Protection Authority (DPA)

**Facts:** Following the CJEU's Schrems II ruling (Case C-311/18, 2020) that invalidated the EU-US Privacy Shield, European companies relied on Standard Contractual Clauses (SCCs) as the legal mechanism for transferring personal data to the United States. In 2023, President Biden issued Executive Order 14086 to address the CJEU's concerns about US surveillance law, leading to a new EU-US Data Privacy Framework (DPF). The EDPB assessed whether the DPF provided adequate safeguards and whether supplementary measures were still required for EU-US data transfers using SCCs where the DPF was not available. The Irish DPA conducted enforcement actions against major technology companies' EU-US data transfer practices.

**Issue:** Whether the EU-US Data Privacy Framework provides adequate protection for EU-US data transfers equivalent to the Schrems II standard; what supplementary measures are required when using SCCs for EU-US transfers absent DPF certification; and what enforcement actions are appropriate against companies that continued EU-US data transfers without adequate safeguards.

**Holding:** The EDPB confirmed that the DPF provided an adequate level of protection for EU-US data transfers under Article 45 GDPR, but that companies relying on SCCs for transfers not covered by the DPF must implement supplementary measures — including encryption, pseudonymization, and contractual protections — to ensure data subject rights are protected against US surveillance. The Irish DPA issued enforcement decisions against several major technology companies, requiring them to suspend EU-US data transfers that lacked adequate safeguards. Major cloud providers updated their data transfer mechanisms in response.

**Significance:** The ongoing Schrems II implementation saga demonstrates the persistent tension between EU data protection requirements and US surveillance law. The DPF provided a temporary solution but remains politically and legally fragile — future CJEU rulings could invalidate it again. The Schrems II process has fundamentally reshaped how European companies approach international data transfers, driving adoption of technical supplementary measures and encouraging data localization within the EU.

---

### Case 13.32: French CNIL v. Clearview AI — GDPR Fines and Facial Recognition Enforcement

**Date Decided:** 2024 (法国国家信息与自由委员会)

**Court:** Commission Nationale de l'Informatique et des Libertés (CNIL), France

**Facts:** The French data protection authority (CNIL) conducted an investigation into Clearview AI's processing of French residents' personal data in response to a complaint filed by Quadrant (a French data analytics company that competes with Clearview AI in the data market) and civil liberties organizations. The CNIL found that Clearview AI had violated GDPR by: (1) scraping French individuals' facial images from public websites without their knowledge or consent; (2) maintaining a database of billions of facial images without a lawful basis; (3) offering its facial recognition services to French law enforcement and private clients without authorization; and (4) failing to respond to data subject requests for access and erasure.

**Issue:** Whether Clearview AI's operation of a global facial recognition database constitutes lawful processing under GDPR Article 9 (processing of biometric data); whether the database serves a purpose compatible with the original purpose of data collection; and what maximum fine is proportionate for systematic GDPR violations by a non-EU company.

**Holding:** The CNIL imposed a fine of €20 million on Clearview AI for GDPR violations, finding that the systematic collection and processing of French individuals' biometric data without consent constituted a serious violation of GDPR Article 9. The CNIL also ordered Clearview AI to: (1) stop processing French residents' data within two months; (2) implement mechanisms for French data subjects to exercise their rights; and (3) delete all data relating to French residents from its database.

**Significance:** The CNIL's €20 million fine against Clearview AI, following similar fines from the Dutch AP (€30.5 million), Italian Garante (€20 million), and Greek DPA (€15 million), demonstrates the coordinated European approach to enforcement against mass facial recognition surveillance. The CNIL decision confirms that GDPR Article 9's prohibition on biometric data processing applies strictly to large-scale facial recognition databases built without data subjects' consent, and that non-EU companies are not exempt from GDPR enforcement.

---

### Case 13.33: ACCC v. Google Australia — Misleading Conduct and Default Search Engine Arrangements

**Date Decided:** 2024 (澳大利亚竞争法庭)

**Court:** Federal Court of Australia (Competition Tribunal / Full Court)

**Facts:** The Australian Competition and Consumer Commission (ACCC) sued Google Australia and Alphabet Inc. for misleading Australian consumers about the handling of location data and the default search engine arrangements on Android devices. The ACCC alleged that Google had: (1) misled users about how much location data was collected and used, particularly through the "Location History" and "Web & App Activity" settings; (2) engaged in exclusive dealing arrangements with device manufacturers to ensure Google Search was the default search engine on Android devices, foreclosing competition from rival search engines; and (3) misrepresented the nature and value of the data it collected from users. The ACCC sought penalties, declarations, and injunctive relief.

**Issue:** Whether Google's conduct in relation to location data settings constituted misleading or deceptive conduct under Australian Consumer Law; whether Google's exclusive default search engine arrangements with device manufacturers violated the Competition and Consumer Act 2010 (Cth); and what penalties are appropriate for the most significant digital platform enforcement action in Australian history.

**Holding:** The Federal Court of Australia found Google had engaged in misleading conduct under the Australian Consumer Law by misrepresenting the scope of location data collection in its Location History settings. The Court ordered Google to pay AUD$60 million in penalties and to implement clearer disclosures about location data collection. On the exclusive dealing claims, the Court found that Google's arrangements with device manufacturers did not substantially lessen competition in the search engine market, given the availability of alternative browsers and search engine options. The ACCC appealed certain findings to the Full Court.

**Significance:** ACCC v. Google Australia is a landmark case in Australian digital platform regulation, establishing important precedents for misleading conduct claims against technology companies and demonstrating the ACCC's willingness to pursue significant enforcement actions against global digital platforms operating in Australia. The AUD$60 million penalty is one of the largest ever imposed for consumer law violations in Australia and signals the ACCC's commitment to protecting Australian consumers from digital platform misconduct.

---

## Colophon

*Global Cyber Law Compendium: 1,000 Landmark Court Decisions*

This work is the second volume of the Global Cyber Law Series, following Volume I (Global Cyber Law Compendium: Statutes & Regulations). Together, these volumes provide the definitive reference for the emerging field of global cyber law.

**Editor-in-Chief:** Dr. Zhou

**Compiled:** March 2026

**Publisher:** Atlantis Legal

**ISBN:** 978-7-XXX-XXXX-X (申请中 / Pending Registration)

**Series:** Global Cyber Law Series
**Edition:** WW2026 Edition

© 2026 Dr. Zhou. All rights reserved.

---

*End of Volume II*


---

## Appendices

### Appendix A: Master Case Index

- **Part 1: Platform Liability & Content Moderation** — Cases 1.1–1.95 (95 cases)
- **Part 2: Data Protection & Privacy** — Cases 2.1–2.90 (90 cases)
- **Part 3: Artificial Intelligence & Algorithmic Governance** — Cases 3.1–3.105 (105 cases)
- **Part 4: Cybercrimes & Digital Forensics** — Cases 4.1–4.105 (105 cases)
- **Part 5: Biometric Data & Genetic Privacy** — Cases 5.1–5.71 (71 cases)
- **Part 6: Data Breaches & Standing** — Cases 6.1–6.80 (80 cases)
- **Part 7: Children's Online Safety** — Cases 7.1–7.60 (60 cases)
- **Part 8: Intellectual Property & Digital Content** — Cases 8.1–8.93 (93 cases)
- **Part 9: Digital Market Regulation & Consumer Data Rights** — Cases 9.1–9.93 (93 cases)
- **Part 10: Government Surveillance & Human Rights** — Cases 10.1–10.66 (66 cases)
- **Part 11: Employment & Workplace Privacy** — Cases 11.1–11.54 (54 cases)
- **Part 12: Emerging Issues & Cross-Cutting Themes** — Cases 12.1–12.55 (55 cases)
- **Part 13: 2025–2026 Recent Developments** — Cases 13.1–13.33 (33 cases)

### Appendix B: Statutes & Regulations Index

**Australia**
- Privacy Act 1988
- Online Safety Act 2021
- News Media and Digital Platforms Mandatory Bargaining Code

**Brazil**
- General Data Protection Law (LGPD)
- Marco Civil da Internet (Internet Civil Rights Framework)

**Canada**
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- Digital Charter Implementation Act (Bill C-27)

**China**
- Personal Information Protection Law (PIPL)
- Data Security Law (DSL)
- Cybersecurity Law (CSL)
- E-Commerce Law
- Minors Protection Law
- Measures for Security Assessment of Cross-Border Data Transfer
- Interim Measures for the Management of Generative AI Services

**European Union**
- General Data Protection Regulation (GDPR)
- Digital Services Act (DSA)
- Digital Markets Act (DMA)
- ePrivacy Directive
- NIS2 Directive
- Digital Operational Resilience Act (DORA)
- AI Act
- eIDAS 2.0 Regulation
- E-Commerce Directive

**India**
- Digital Personal Data Protection Act (DPDPA, 2023)
- Information Technology Act

**Japan**
- Act on the Protection of Personal Information (APPI)
- Act on Provider Liability Limitation

**Singapore**
- Personal Data Protection Act (PDPA)
- Online Safety Act

**South Korea**
- Personal Information Protection Act (PIPA)
- Network Act (Information and Communications Network Act)

**United Kingdom**
- UK GDPR
- Data Protection Act 2018
- Online Safety Act

**United States**
- First Amendment, U.S. Constitution
- Communications Decency Act §230 (47 U.S.C. §230)
- Digital Millennium Copyright Act (DMCA)
- Computer Fraud and Abuse Act (CFAA)
- Electronic Communications Privacy Act (ECPA)
- California Consumer Privacy Act / CPRA (CCPA/CPRA)
- Illinois Biometric Information Privacy Act (BIPA)
- Health Insurance Portability and Accountability Act (HIPAA)
- Children's Online Privacy Protection Act (COPPA)
- Clarifying Lawful Overseas Use of Data Act (CLOUD Act)
- Foreign Intelligence Surveillance Act (FISA)

### Appendix C: Landmark Precedents Index

**AI & Algorithmic Governance**
- Case 3.1 State v. Loomis (COMPAS Risk Assessment)
- Case 3.5 Clearview AI — Global Regulatory Actions
- Case 3.8 ChatGPT — Garante Provisioning (Italy)

**Cybercrimes & Digital Forensics**
- Case 4.1 United States v. Ulbricht (Silk Road)
- Case 4.15 United States v. Hammond (Stratfor Hack)

**Data Protection & Privacy**
- Case 2.1 Schrems v. Data Protection Commissioner (Schrems I)
- Case 2.2 Data Protection Commissioner v. Facebook Ireland (Schrems II)
- Case 2.3 Google Spain v. AEPD (Right to Be Forgotten)
- Case 2.8 CNIL v. Google LLC

**Emerging Issues**
- Case 12.1 Mirai Botnet (IoT DDoS)
- Case 12.3 SEC v. Ripple Labs (XRP)
- Case 12.8 Jeep Cherokee Hack (Automotive Cybersecurity)
- Case 12.13 Neuralink — Brain-Computer Interface Regulatory Issues

**Government Surveillance & Human Rights**
- Case 10.1 Schrems I (Surveillance Context)
- Case 10.5 Liberty v. GCHQ
- Case 10.8 European Commission Adequacy Decision for the UK

**Intellectual Property**
- Case 8.1 A&M Records v. Napster
- Case 8.2 MGM Studios v. Grokster
- Case 8.5 Google LLC v. Oracle America (API Copyright)

**Platform Liability**
- Case 1.1 Reno v. ACLU
- Case 1.2 Zeran v. AOL
- Case 1.6 Glawischnig-Piesczek v. Facebook Ireland
- Case 1.9 Meta Platforms v. Bundeskartellamt

---

## Colophon

*Global Cyber Law Compendium · Volume II · Case Law Compendium*

**First Edition · June 2026**

**Editor-in-Chief:** Dr. Harry Zhou
**Managing Editor:** Fresa Li
**Reviewers:** Dr. Frontie · Doctor Gochye

**ISBN:** 978-7-XXX-XXXX-X (pending)

*© 2026 Atlantis Legal Press · All Rights Reserved*

*—— End of Volume II ——*