Happy New Year! 2025 was a busy year for the Insider authors—we published 271 posts throughout 2025. To kick-off 2026, in case you missed them last year, we are providing the articles from 2025 that were the most interesting to our readers across various categories.

We hope you enjoy them and look forward to another productive year of keeping our readers informed on the rapidly changing and dynamic areas of data privacy, cybersecurity, information governance, artificial intelligence, and of course—the weekly Privacy Tip!

CYBERSECURITY

FBI Warns of Account Takeover Fraud

Insider Threats Climb + Are Costly

ENFORCEMENT + LITIGATION

EdTech and Privacy of Student Information: A Case Study

Breaches Within Breaches: Contractual Obligations After a Security Incident

DATA PRIVACY

Privacy Under Pressure: What the NYT v. OpenAI Teaches Us About Data Governance

New State Privacy Laws Expand Consumer Data Control in 2026

INFORMATION GOVERNANCE

Why Dumping Sensitive Data on Network Shares is a Liability

ARTIFICAL INTELLIGENCE

When AI Notetakers Take the Stand: The Legal Risks Lurking in Your Virtual Meetings

PRIVACY TIPS

Privacy Tip #431 – DOGE Has Access to Our Personal Information: What You Need to Know

Privacy Tip #7 – Who is listening to your conversations through your smartphone microphone?

A new class action in the U.S. District Court for the Northern District of California alleges that Ace Hardware tracked users’ online activity through third-party tools before users could make meaningful choices through cookie consent tools, and that it continued even after users took steps to opt out. The plaintiffs claim that the Ace Hardware website intercepted browsing data before consent choices could be made, promised opt-out control but did not honor it, and used multiple third-party tools to collect detailed activity. Specifically, the complaint alleges tools from Google Analytics, Bazaarvoice, and other companies were used to collect information such as search terms, product views, and device identifiers.

In plain terms, the lawsuit frames the issue as a mismatch between what users were told about their privacy choices and what allegedly happened behind the scenes. While the lawsuit focuses on Ace Hardware’s website practices, it also reflects on the broader scrutiny of third-party analytics and marketing tools, especially where consent mechanisms are alleged to be ineffective or misleading.

Even when companies believe they have implemented standard consent banners, plaintiffs increasingly focus on what the underlying scripts actually do in real time. This case is a reminder that privacy risk often turns on implementation details, not policy language. Companies should pressure-test consent flows against what tags and pixels actually transmit, including on first page load and after opt-out selections. Aligning disclosures, consent settings, and real-time script behavior is increasingly where litigation exposure is won or lost.

Carfax, Inc. faced an early loss in a closely-watched privacy case under the federal Driver’s Privacy Protection Act (DPPA), after a judge in Maryland refused to throw out a proposed class action alleging the company sold drivers’ personal information sourced from crash and vehicle records. The plaintiff alleges that Carfax obtained his DPPA-protected personal information from a crash report tied to a 2023 auto accident and then sold that data to third parties. He claims this happened without his consent and without Carfax ensuring that downstream recipients were entitled to receive the information under the DPPA.

On Monday, Judge Julie R. Rubin of the U.S. District Court for the District of Maryland denied Carfax’s motion to dismiss. The court held that the plaintiff plausibly alleged Carfax obtained and sold his DPPA-protected information for an impermissible purpose under the statute. Importantly, Judge Rubin signaled that this is not the final word on the merits. She denied the motion to dismiss without foreclosing Carfax from reasserting its arguments later. The company can renew its legal challenges at summary judgment, once there is a “full record” showing how the crash report was actually prepared and handled.

Carfax argued that the crash report at issue was not covered by the DPPA because it was obtained from a police department, not from a department of motor vehicles. The plaintiff responded that the report should still qualify as a covered “motor vehicle record” because it was generated by the Maryland Motor Vehicle Administration before being provided to police. Judge Rubin acknowledged that the case law is mixed on this issue, and she described Carfax’s argument as “well-taken” and raising “serious questions (if not doubts)” about the plaintiff’s ability to ultimately prevail. Still, she concluded the uncertainty in the law did not justify dismissal at the pleading stage, especially without a developed factual record clarifying the report’s creation and flow. Carfax also argued that the plaintiff’s claim that Carfax lacked a permissible purpose was too conclusory. Judge Rubin agreed the allegations “could certainly be more robust,” but found them sufficient when considered alongside the allegations about Carfax’s business model and practices. The complaint, as described, alleges Carfax collects and sells vehicle history and accident data from thousands of sources and markets access to a database of more than 1.5 million police reports. At this stage, that context helped bridge the gap between “possible” and “plausible.”

This ruling is a reminder of a practical reality in privacy class actions. Motions to dismiss often fail when the dispute turns on how data was sourced, processed, and sold, since those details frequently sit with the defendant and emerge in discovery. For companies that traffic in large-scale driver and crash datasets, the opinion also highlights two recurring DPPA pressure points: (1) whether a document is a covered “motor vehicle record” can depend on provenance and process, not just where a defendant says it got the record; and (2) even if a company claims a DPPA-compliant use, plaintiffs may survive early dismissal by alleging the seller did not verify that purchasers were entitled to receive the data.

California resident Nathaniel Bee filed a lawsuit this week alleging that the ATP Tour’s website used third-party tracking technology that captured details on how visitors interacted with the site, including what content they viewed; how they navigated the website; and what type of device they used, without user consent in violation of the California Invasion of Privacy Act. According to the complaint, that information was transmitted to third parties, including Google and Comscore Inc., and was used for targeted advertising and analytics.

The lawsuit centers on what users were told and what the website allegedly did anyway. The plaintiff alleges that users first visiting the ATP Tour website are presented with two options: accept “essential cookies only” or accept “cookies.” The plaintiff argues that the “essential cookies only” option gives visitors the impression that they can opt out of tracking that shares information with “social media, advertising and analytics partners.” However, even after a user selects “essential cookies only,” the ATP Tour allegedly continued transmitting non-essential information that could be used for targeted advertising. The complaint states that “even when users attempted to limit tracking by rejecting nonessential cookies, ATP Tour failed to prevent third parties from receiving information generated by users’ website communications.”

Even at the allegation stage, the case highlights a pressure point for many consumer-facing websites where consent interfaces are only as reliable as the technical controls behind them.

If a website offers an “essential cookies only” option, the expectation is that third-party tags, pixels, and scripts tied to advertising and analytics are actually disabled or prevented from transmitting data when a user opts out.

Regardless of how the claims ultimately shake out, the complaint underscores a simple but increasingly litigated reality: privacy disclosures and consent banners are only as defensible as the engineering behind them. If a site presents an “essential cookies only” option, users reasonably expect that advertising and analytics tags, pixels, and scripts are actually blocked from firing and from transmitting data to third parties. For consumer-facing organizations, this case is a reminder to align what the interface promises with what the site does in practice, and to validate that opt-out choices are enforced consistently across all third-party tools and integrations.

Anyone who has purchased a car in the past decade is familiar with the dazzling wave of technology that greets them: giant touchscreens, voice controls, remote start apps. But behind the gleaming infotainment systems and driver-assist cameras, a subtler, more powerful feature has crept into the modern automobile, the ability to observe, record, and report on virtually every aspect of its use and its users.

For years, consumers have worried about smartphone privacy, Alexa eavesdropping, or social media tracking. However, while attention was directed elsewhere, auto manufacturers quietly built an ecosystem that rivals Big Tech in its reach, and, according to a blistering Mozilla Foundation study reported by AP News, completely fails at protecting consumer privacy. Not even one of the 25 major car brands reviewed earned a passing grade.

Why? Because car companies aren’t just making money off vehicle sales anymore. They’re monetizing your data, and the information they scoop up goes well beyond GPS locations or your driving speed. Think:

  • Biological metrics: Weight, heart rate, even facial expressions via sensors and cameras;
  • Personal details: Information from your tethered phone, call logs, text messages, sometimes even biometric or demographic data; and
  • Highly sensitive information: According to some vehicle manufacturers’ own policies, data on “sexual activity” and “intelligence” can be collected.

Unlike a smartphone app, which must explicitly ask for permissions, car makers hide their consent models deep in paperwork signed under pressure in a dealership. Few read these documents and even fewer realize that 84% of cars reviewed by Mozilla share personal data with brokers and service providers, and 76% claim the right to sell your data.

This has transformed cars into ongoing surveillance devices whose output is not for your benefit, but to be shopped around in a shadowy secondary data market, sold to insurers, marketers, and sometimes even government agencies.

What was once private (e.g., how you drive, where you go, who rides with you) can now raise your costs or be used for purposes you never anticipated. The auto industry claims this is about safety or innovation. While crash detection or predictive maintenance require some data, that argument fails when it comes to collecting genetic or intimate personal information.

In the United States, where state-level rules like the California Consumer Privacy Act are only just beginning to probe this problem, most drivers are exposed by default. Federal lawmakers are only now starting to see the domestic, and even national security dangers. Issues range from stalkers misusing connected apps to fears of foreign adversaries accessing U.S. driver data. But for now, self-regulation prevails—and as Mozilla’s findings make clear, it doesn’t work. Consent screens for cars, buried in sales documents and 50-page privacy policies, simply don’t provide real choice or transparency, particularly when a car is used by multiple drivers or passengers.

In an age when car sensors can identify individual drivers, or capture pedestrians in external footage, the question of whose privacy is being violated gets murky. Passengers (who never agreed to anything), can have their images, voices, and even biometrics swept up by default, an uncharted legal territory, with serious implications for consent and wiretapping laws.

The Alliance for Automotive Innovation touts voluntary, non-binding “consumer privacy principles.” In practice, opting out often means disabling mission-critical functions or navigating a maze of settings and customer service calls—hardly a meaningful choice, and often creating a “take it or leave it” arrangement where convenience trumps privacy.

As cars increasingly become platforms for subscriptions and software updates, the industry must realize that trust is everything. Already, lawsuits are hitting data-sharing arrangements. If automakers don’t fix their practices, a harsh regulatory reckoning is inevitable—one that could curtail the very innovation they celebrate.

Today’s car dealerships are not just selling you a car, they’re enrolling you, and everyone who travels with you, into a sprawling, often poorly regulated data marketplace. As drivers and passengers wake up to this reality, demands for transparency, meaningful consent, and real privacy choices will only grow. The road to the future, it turns out, is paved with data. The question is, do we still control the dashboard, or has the car quietly taken the wheel?

In August, the Office for Civil Rights (OCR) published guidance relating to individuals’ rights to access their protected health information (PHI) under HIPAA. As we covered in our earlier blog post about the August guidance, the new FAQs came amidst OCR’s continued enforcement focus on its Right of Access initiative, under which the OCR has brought over fifty enforcement actions to date.

On September 3, 2025, the U.S. Department of Health and Human Services (HHS) announced Secretary Robert F. Kennedy, Jr.’s crackdown on health data blocking, noting that HHS “will take an active enforcement stance against health care entities that restrict patients’ engagement in their care by blocking the access, exchange, and use of electronic health information.” This announcement signals the agency’s continued focus on patient access rights and healthcare interoperability.

HHS’s September 3rd press release references the 21st Century Cures Act, which was signed into law in 2016 and prohibits information blocking by requiring that patient information stored in electronic health record systems can be “accessed, exchanged, and used without special effort through the use of application programming interfaces.” This is a broad definition of information blocking and could include a provider’s refusal to share patient health records, unreasonable delays in providing requested records, or charging excessive fees for patient access.

The Cures Act imposes requirements on health ecosystem entities beyond providers, too. Health IT developers, for example, may engage in information blocking by executing restrictive contractual terms related to data sharing or disabling interoperability functions on their platforms. Health information exchanges and health information networks are also covered under the Cures Act, and could be found to engage in information blocking by imposing unfair fees to join an exchange or blocking certain organizations without valid justification.

Under the Cures Act, the Office of Inspector General (OIG) and the Office of the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC) are authorized to take enforcement action against information blocking in healthcare. In a September 4, 2025, Enforcement Alert following the HHS press release, ASTP warned that individuals found to have engaged in information blocking could face several types of enforcement actions, including civil monetary penalties of up to $1 million per violation against certain health IT developers, entities offering certified health IT, health information exchanges, and health information networks. CMS may also impose disincentives on providers if OIG refers information blocking cases to HHS. Notably, OIG has stated that it will prioritize enforcement where information blocking causes patient harm or significantly impairs a provider’s ability to deliver care.

Proponents of information blocking enforcement assert that these measures will increase patient access to information, promote interoperability, and enhance care coordination. On the other hand, critics note that broad data sharing raises security and privacy concerns. Greater access could increase the risk of breaches or misuse of sensitive health information. While there are exceptions to what constitutes information blocking, aggressive enforcement could pressure organizations into unnecessary disclosure, which runs counter to principles of data minimization and need-to-know sharing. Still, with HHS putting the healthcare ecosystem on alert, now is the time for providers, IT developers, and exchanges to take a look at their data practices. Organizations should not wait for an HHS inquiry to conduct internal audits, assess interoperability capabilities, and ensure any exceptions are well-documented. Overall, data sharing practices should balance appropriate information access with safeguards that prevent patient harm and minimize risk of information being misused. If your organization touches health information in any way, preparation for this increased regulatory focus now could prevent OCR scrutiny later.

On February 21, 2025, a federal district court judge from the Southern District of New York issued a preliminary injunction against the Department of Government Efficiency’s (DOGE), access to Treasury Department payment systems, stating access was provided in a “chaotic and haphazard manner.” The order resulted from a suit filed by 19 state Attorneys General against DOGE for unauthorized access to Americans’ data. It prevents anyone affiliated with DOGE from accessing federal payment systems until further order.

According to the 64-page opinion, the judge was critical of the “‘rushed’ process by DOGE to access Bureau of Fiscal Service’s payment systems, which stores the names, Social Security numbers, birth dates, birth places, home addresses and telephone numbers, email addresses, and bank account information of Americans who have transacted with the federal government.”

The District Court also noted that “[t]he record is silent as to what vetting or security clearance process they went through prior to their appointment” and reported being “troubled by the fact that Elez [a DOGE associate] was apparently granted full access to [Bureau of Fiscal Service] systems rather than read-only access, writing that that process was ‘rushed and undertaken under political pressure.’” We have made a similar observation.

The Court requested that the Treasury Department provide a report by March 24, 2025: (1) certifying that the DOGE associates have been vetted, have obtained proper security clearances, and have been properly trained; and (2) setting forth the mitigation measures which have been taken to minimize threats associated with the access, including the reporting chains for DOGE within the Treasury Department. 

The ruling stated that “[t]he process by which the Treasury DOGE Team was appointed, brought on board, and provided with access to [Bureau of the Fiscal Service] payment systems could have been implemented in a measured, reasonable, and thoughtful way. To date, based on the record currently before the Court, it does not appear that this has been the case.”