Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR

52 minutes 35 seconds ago

Law enforcement agencies across the country are increasingly relying on spying technologies—automated license plate readers (ALPR), cell-site simulators, and facial recognition, to name a few--causing an outcry in many communities where people are rightly concerned about the threat to civil rights and civil liberties these tools present.

Some authorities are responding to these concerns by trying to hide what they’re doing. Police departments are telling officers not to mention ALPRs when stopping vehicles and concealing their use of ALPRs to avoid citizens’ public records requests. Concealing the use of unpopular spying tools isn’t anything particularly new for law enforcement—cops have been doing it for years—but it’s just as wrong now as it was 20 years ago.

These practices prevent the public from knowing about and questioning how agencies are spending taxpayer dollars on spying technologies and holding them accountable. This is especially troubling when many towns are signing contracts with Flock and other ALPR vendors with little to no public oversight. The practice also violates disclosure obligations, allows cops and prosecutors to hide their tactics from judges, and cheats defendants from being able to challenge the use of evidence gathered by spy tech from being used against them.

404 Media recently revealed that in its usage policy for Flock ALPR cameras, one county in Iowa tells police to keep them a secret when detaining people: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” If writing a report about an incident, police are told to say they used “county resources” in making a stop instead of acknowledging use of ALPRs.

In Houston, police officers are likewise instructed to “be as vague as permissible” about why they are using Flock because the searches they run on Flock’s surveillance system could be obtained via public records requests.

There is growing public alarm about the threat to civil liberties posed by ALPR cameras and reports of police abusing the tech by using it to spy on their exes. Some cities have the cameras covered up, and others are cancelling their use of ALPR networks. Two states have recently stepped back from ALPRs. This trend is certainly not lost on law enforcement agencies. Hiding the fact that they’re using ALPRs from Flock and other vendors is one way of avoiding scrutiny and bad PR.

But law enforcement and their spy tech vendors keeping people in the dark about the surveillance technologies trained on them predates the Flock backlash by decades. For example, AT&T built a powerful phone surveillance tool for police, called Hemisphere, in the mid 2000s, and the company required agencies not to use evidence gathered by Hemisphere in court unless there was no other admissible evidence. If evidence obtained through Hemisphere was used, police were required to recreate it through a traditional subpoena, a process they called “parallel construction.” We called it “evidence laundering.”

Likewise, police and prosecutors have taken far-reaching steps to hide from the public and courts their use of cell site simulators, also known as stingrays. Police have used these devices, which trick cell phones into connecting to them instead of phone towers to try locating suspects, to obtain people’s location data without a warrant by deceptively obtaining basic pen register orders from courts. Pen register orders are for obtaining call log data and police don’t need to prove they have probable cause to get one.

In Baltimore, for example, a judge concluded that law enforcement had used a standard pen register order to intentionally hide its use of a Stingray from the court in violation of its legal disclosure obligations, leading to a landmark 2015 privacy ruling that cops need a warrant to use the device.

That didn’t stop police from continuing to try to pull the wool over the eyes of courts and defense attorneys when they used stingrays, however. Prosecutors have accepted plea deals to hide their use of cell-site simulators and have even dropped cases rather than reveal information about their use of the technology. U.S. Marshalls have driven files hundreds of miles to thwart public records requests.

Fortunately, our commitment to shining a light on the use of surveillance tech is just as strong, if not stronger, than law enforcement’s quest to hide it. We’re working with privacy advocates and community groups to bring awareness about existing and emerging spy tools that threaten civil liberties and we’re encouraging policymakers and lawmakers to do more to restrain warrantless mass surveillance and stop it before it ever takes hold.  

If you're curious about whether your local police have contracts for ALPRS or other surveillance technologies, you can search EFF's Atlas of Surveillance.

 

Karen Gullo

Digital Sovereignty: What It Is, What It Could Be

2 hours 57 minutes ago

The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI, semiconductors, and platform regulation. Governments throughout the global majority use it to argue for greater control over data and communications infrastructure and boost their economies. Companies market “sovereign cloud” products designed to reassure their customers that their information stays under local jurisdiction. But digital sovereignty could be something more: an opportunity for users around the world to build more resilient, open  systems and the skills and infrastructure to maintain them.

There is no singular definition of digital sovereignty, nor is there a single coherent position in the digital rights space. Despite its growing popularity, the term remains frustratingly vague. Policymakers, regulators, civil society groups, and others can mean very different things when they use the term. But to start simply with a broad definition, we can say that it means having the capacity to control one’s digital destiny—though the implications of that will obviously differ considerably whether you’re talking about an individual or a country.

We can start by developing  a shared understanding of what digital sovereignty actually means. We’ve also included a glossary of terms at the bottom of this post. 

In Europe and other places where digital sovereignty has become a topic of policy, discussions focus on reducing dependency: on foreign (and particularly American) cloud infrastructure, chips, platforms, and at times, foreign political priorities. The concern is both economic and geopolitical. If essential infrastructure is controlled by companies elsewhere—and thus subject to the laws of another jurisdiction—then what control does a country actually have over its own digital future?

In global majority countries in particular, wars, sanctions, and the growing fragmentation of the internet have demonstrated for many that the physical infrastructure that underlies digital life is neither neutral nor invulnerable. 

Amidst this increasing geopolitical instability governments and civil society should consider whether digital sovereignty can help shore up that infrastructure. 

What are we talking about when we talk about digital sovereignty? 

A recent Franco-German joint paper on digital sovereignty defines it as the “capability and capacity to develop, provide, use, adapt and control digital technologies including hardware in an independent, self-determined and secure manner” and puts forward a framework to operationalize Europe’s capacity to act in the digital domain. 

Some governments, such as Germany’s, have started to put funding behind sovereignty efforts through initiatives like the Sovereign Tech Agency, which “invest[s] globally in the open software components that underpin Germany's and Europe's competitiveness and ability to innovate.” 

Positions on digital sovereignty among EFF’s allies across Europe vary. Open Rights Group have defined digital sovereignty as “the ability of a country to have control over its digital infrastructure, data, and technology” and states it to be “critical for the UK’s economic and national security.” 

Similarly, the European Partnership for Democracy has expressed concern that “a few Big Tech corporations decide our collective destiny,” and argue that the EU should explore “alternative ownership models for tech companies and clearly [define] their purpose and mission.” And our friends at EDRi (of which EFF is a member) have stated clearly that “Europe’s digital sovereignty starts with open source.” Some initiatives, such as DI.DAY, consider digital sovereignty an opportunity to free users from Big Tech dependencies.

Elsewhere in the world, conversations about digital sovereignty often take a different shape. Indigenous discussions of the topic have been ongoing for more than a decade and focus on the inherent right of Native nations to govern their own digital ecosystems. In Southeast Asia, the desire for digital sovereignty has created growth in the sovereign cloud industry, but the conversation isn’t purely economic: Concerns about jurisdiction for where data is held are driving much of the conversation. 

In Latin America, digital public infrastructure is often a key aspect of debates. Across Africa, leaders speak of a desire to shift the continent from being consumers of technology to becoming architects of their own digital infrastructure and data ecosystems. And in the Middle East and North Africa, concerns about reliance on U.S. technology companies—which have engaged in conflict and disproportionate censorship (particularly of Palestinian voices) in the region—are often paramount.

Reem Almasri, a senior researcher based in Jordan, recently spoke to EFF about digital sovereignty, which she sees as “the ability of people and communities to choose, control, and use technology that serves their needs and values,” particularly in light of the role that U.S. companies have played in regional conflicts.

In a January article, Almasri pointed to growing concerns about granting greater sovereignty and influence to governments over citizens’ data, communications, and websites, writing: “This is particularly worrisome in countries that impose high levels of internet and media censorship and run unaccountable surveillance programs on their citizens’ data.”

Indeed, while pushing for greater sovereignty from Big Tech has benefits, there is an inherent risk that some states will pursue digital sovereignty as a means of cutting off or splintering access—as we’ve already seen in Iran, Russia, and elsewhere.

For that reason, it’s no surprise that some, such as Iranian professor Azadeh Akbari, believe that “the current wave pushing digital sovereignty as the key to ending dependency on American and Chinese technology is negligent of its Eurocentric bias.” 

What does EFF believe?

In a world where people have digital sovereignty, civil society should be able to communicate freely, privately, and anonymously if they wish. People should be able to easily understand where their data lives and who has access to it. That data should be easily portable between platforms and services.

At EFF, we view digital sovereignty not as a walled garden, but as an opportunity for resilience and development of industries and skills. We believe that governments can and should take a role in crafting digital sovereignty that centers the autonomy of users rather than just re-creating a state of digital dependency with a new set of companies. Governments should support and use free and open source tools and projects built using principles of interoperability and data portability. This support should include employing full-time developers, UX designers, and community managers. Government policy and legislation should grant users control of their own data and a clear understanding of who can lawfully access it. Digital sovereignty should foster users’ ability to choose how they use digital products and services, free from unfair lock-ins, coercive terms and manipulative defaults. It should also foster the broader public interest internet, the part of the web that provides public goods and useful services without requiring the scale or the business practices of the tech giants.

Encryption backdoors are fundamentally incompatible with a vision of data sovereignty that centers user control. Governments should support the development and normalization of reputable end-to-end encrypted communications as well as strong encryption for data at rest. This support should include employing cryptographers and contributing to strong, peer-reviewed encryption standards strengthened by data minimization as a fundamental design principle, as well as refraining from legislating mandates for “lawful access” or any other reason.  

As technologists, we don’t have to wait for governments to act in order to create the digital sovereignty we want. We get the internet that we build. We can contribute to open source, decentralized, and end-to-end encrypted projects. We can build standards that make interoperability and data portability a feature from the very beginning. We can resist the call of proprietary solutions, user lock-in, and encryption backdoors.

And finally, while digital sovereignty is often framed as a response to the dominance of Big Tech, that does not mean that there is no role for private companies to play. There is no point in replacing the influence of a few mostly US-based tech companies with a handful of giants based elsewhere. Companies can and should build platforms and services on top of open source, decentralized protocols and contribute to the ecosystem. Companies should also minimize processing a person’s data except as strictly necessary to provide them what they asked for, and only with opt-in consent that makes it clear to users what data they are gathering, where it is stored, and who has access to it. And companies should build their tools and platforms in a way that allows interoperability and that makes it easy for users to leave with their data. Some of these practices are already required by law in some jurisdictions, but companies don’t have to merely do the bare minimum the law demands: they should respect their users and support data sovereignty right now.

A glossary of terms

The following terms are useful for understanding this blog post as well as the broader conversation about Digital Sovereignty:

Intermediary liability: the legal responsibility of online service providers (ISPs, websites, social media platforms) for unlawful activities by their users, such as defamation, copyright infringement, or illegal hate speech.

The stack: a secure, open-source technology framework, often focusing on European alternatives, designed to break dependencies on (mostly) US-based technology providers. It comprises interoperable, vendor-neutral, and transparent digital infrastructures designed to regain control over data, infrastructure, and technology.

Digital sovereignty: the ability of people, as nations, organizations, and individuals, to control their own digital destiny by retaining authority over their own data, technology, and infrastructure.

Data sovereignty: the principle that digital information is subject to the laws and governance frameworks of the country or region where it is physically collected, stored, or processed. It dictates that data remains bound by the specific privacy protections and regulations of its originating jurisdiction, regardless of where the collecting organization is located.

Digital commons: a shared, online resource, such as knowledge, software, and data, that is collectively produced, governed, and maintained by a community, intended for public access. Examples include Wikipedia, open source operating systems such as Linux, and Creative Commons licensed content.

Data portability/interoperability: the ability to easily transfer personal data from one service provider to another, or to a personal system, in a structured, machine-readable format. It empowers users to move away from "walled gardens," reducing vendor lock-in and enhancing user autonomy.

Digital dependency: the opposite of digital sovereignty. The inability of people as nations, organizations, and individuals to control their own digital destiny through control over their own data, technology, and infrastructure. 

Decentralization: a shift away from relying on centralized, often US-based, corporate platforms toward a distributed, user-centric internet where individuals, communities, and nations maintain control over their data, digital identity, and infrastructure.

End-to-end encryption (e2ee): a secure communication process where only the sender and intended recipient can access, read, or decrypt messages or data.

Fairness (à la the Digital Fairness Act): the absence of deceptive, manipulative, or addictive design practices that distort consumer choice and exploit vulnerabilities. 

User sovereignty: the concept that individuals possess absolute control over their personal data, digital identity, and online privacy, rejecting the centralization of power by large technology platforms. It emphasizes user consent, decentralization, and the ability to manage personal data using secure and independent tools.

Jillian C. York

2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights

5 hours 1 minute ago

EFF is pleased to announce that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights have received 2026 EFF Awards for their vital work in ensuring that technology supports freedom, justice, and innovation for all people. 

The EFF Awards recognize specific and substantial technical, social, economic, or cultural contributions in diverse fields including journalism, art, digital access, legislation, technology development, and law. 

For the past 30 years, the EFF Awards—previously known as the Pioneer Awards—have recognized and honored key leaders in the fight for freedom and innovation online. Started when the internet was new, the Awards now reflect the fact that the online world has become both a necessity in modern life and a continually evolving set of tools for communication, organizing, creativity, and increasing human potential.  

Supporting a global community advancing digital rights, defending digital access in crisis zones, empowering communities to take action against surveillance, and providing free legal assistance for creators and consumers to fight back against digital threats are high callings that help bring about a better tech future for all. We are pleased to honor these organizations with 2026 EFF Awards. 

Access Now – Fostering Change in Human Rights and Technology

Access Now, founded in 2009 as an emergency response team helping Iranian activists get back online and communicate safely, has grown into one of the world’s foremost organizations defending and extending the digital rights of people and communities at risk and supporting the global fight against technological repression.  

Its 24/7 Digital Security Helpline offers real-time, direct technical assistance and advice to civil society groups and activists, media organizations, journalists and bloggers, and human rights defenders. It provides grants to frontline organizations working with people and communities most impacted by digital rights violations. It educates decision makers and pressures the powerful. And it organizes RightsCon, a leading annual summit on human rights in the digital age, where activists, technologists, policymakers, business leaders, journalists, philanthropists, researchers, and artists can connect, collaborate, and drive change at the intersection of human rights and technology. 

7amleh – The Arab Center for the Advancement of Social Media – Defending and Advancing Digital Access and Rights Across the MENA Region

7amleh - The Arab Center for the Advancement of Social Media protects and expands digital access and rights for Palestinians and across the MENA region. The nonprofit investigates and monitors challenges to digital rights, focusing on internet access, privacy, freedom of expression and association online. It builds the capacity of activists, human rights defenders, and civil society organizations to provide training about digital rights, gender sensitive digital security, and effective online advocacy.  

7amleh also advocates for changes to the digital rights policies and practices of governments, corporations and other influential institutions and individuals locally, regionally and internationally. It plans and manages advocacy and awareness-raising campaigns and builds networks and coalitions to promote access to safe, fair and free online spaces. For example, 7amleh has led the #ReconnectGaza campaign, supported by dozens of international NGOs including EFF, to restore full internet access in Gaza – a crucial lifeline for residents, journalists, activists, and first responders.  

DeFlock – Exposing the ALPR Surveillance Network

DeFlock is an open-source, volunteer-powered project that maps surveillance devices across the world, helping communities hold their governments and surveillance vendors accountable and understand where and how they're being watched. Founded in 2024 by software engineer and privacy advocate Will Freeman, DeFlock shines a light on the widespread use of automated license plate reader (ALPR) technology and the threats it poses to personal privacy and civil liberties.  

DeFlock resources help people request public records, speak to local lawmakers, and take action against ALPR surveillance. Its work has helped foster a national grassroots community of anti-surveillance activists fighting back against this dangerous surveillance technology. 

New Media Rights – Helping Creators Fight Back Against IP Bullies

New Media Rights (NMR) is a San Diego-based nonprofit program of California Western School of Law dedicated to defending digital rights through legal services, education, and public policy advocacy. Since its inception, NMR has been at the forefront of protecting creators, entrepreneurs, and internet users from digital threats such as copyright abuse, online harassment, and privacy violations. 

In addition to providing free legal assistance, NMR has produced hundreds of freely available video and written legal education guides for creators and consumers, including the Fair Use App for filmmakers and video creators. It has participated in regulatory proceedings on net neutrality, Digital Millennium Copyright Act anti-circumvention, and copyright reform. Its work has also helped support access to public information and greater business and government accountability. 

Josh Richman

New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment

1 day 1 hour ago

EFF sued the government back in March for information about the Wasteful and Inappropriate Service Reduction (WISeR) model, a new Medicare program that uses AI to evaluate prior authorization requests for certain medical services. Today, we’re releasing approximately 1,000 pages of records obtained from the Centers for Medicare & Medicaid Services (CMS) through this litigation, including contracts with tech companies, internal status reports and providers’ complaints about the program. The documents (available here) show that WISeR has resulted in widespread delays and denials of care, operational chaos, and reports of patient harm.

Why We Sued for Records about WISeR

EFF filed the FOIA lawsuit to gain badly needed transparency into an experimental AI program that could jeopardize Medicare beneficiaries' access to care. In January 2026, CMS launched the WISeR model, subjecting seniors in six states to AI-driven prior authorization decisions. Medical providers must now request permission before delivering certain medical treatments if they want assurance that Medicare will cover them. Private companies contracted by CMS evaluate the requests using AI. In the absence of rigorous safeguards, AI-driven prior authorization determinations can lead to unwarranted—and even discriminatory—delays or denials of necessary medical care. 

Little is known about the AI systems that WISeR vendors are using to process prior authorization requests. Although CMS says that a qualified human clinician must review all denials, research has shown that AI-generated recommendations often influence human decisions. And the design of the WISeR program creates a financial incentive for vendors to deny care, since they are paid for averted expenditures. Just months after the program launched, medical providers reported improper denials, administrative friction, and lengthy delays that have left patients waiting in pain.

EFF’s FOIA request sought records pertaining to the CMS contracts with WISeR software vendors; any tests for accuracy, bias, or hallucinations in vendors' technology; and any audits, monitoring, or evaluation of WISeR and participating vendors.

CMS Documents Highlight Issues with the WISeR Model

CMS records obtained by EFF echo issues that medical providers, patient advocates, and lawmakers have warned about since WISeR began. This includes long wait times, rampant technical failures, inappropriate denials, and harm to patients.

Delayed Responses to Prior Authorization Requests

CMS publicly states that WISeR vendors should respond to prior authorization requests within 72 hours, but records received by EFF show widespread delays. Internal status reports from the first few months of the program show that WISeR vendors failed to respond within 72 hours for a significant number of requests. One status report cites a prior authorization request that went unanswered for 83 days ("WISeR FOIA Response - Combined Records," page 234). These delayed responses can have serious consequences for patients. Medical providers reported that WISeR has delayed medically necessary care and left patients in pain as they waited for approvals.

Timeliness data for two WISeR vendors in January 2026 show that a significant number of requests did not receive a response within 72 hours (WISeR FOIA Response - Combined Records, page 410)

Payment Methodology Provides Financial Incentive to Deny Care 

The released records confirm that WISeR’s payment methodology creates a financial incentive to deny care. Specifically, WISeR vendors are paid for requests that they deny (though not for denials reversed on appeal). This profit motive aggravates the risk that AI-assisted decision-making may unfairly deprive people of the services they need.

CMS publicly claims that it safeguards against inappropriate denials by tying vendors’ payment rates to “quality scores,” which reflect the timeliness and accuracy of vendors’ decisions. However, the recently released WISeR Data Reporting Guide shows that low quality scores reduce payments by only 5-10%.

Impact of low quality scores on payment rates described in the WISeR Data Reporting Guide (WISeR FOIA Response - Combined Records, page 99)

WISeR Vendors Have Denied Thousands of Prior Authorization Requests

Documents obtained by EFF appear to support reports that WISeR vendors may be denying claims at unusually high rates. Two companies alone denied over 20,000 prior authorization requests in the first 3 months of the program. One company, Virtix, the vendor that CMS required to submit a Corrective Action Plan, denied more requests than it approved during this time period.

Prior authorization decision data for two vendors in a March 30th, 2026 status report (WISeR FOIA Response - Combined Records, page 322)

Medical Provider Feedback Ties WISeR Delays to Patient Harm

Feedback from medical providers emphasize that WISeR delays have harmed patients. The released records include March 2026 responses to a feedback form about Innovaccer, the WISeR vendor processing requests for Ohio. Medical providers complained about a lack of communication, administrative issues, and long response times. Several responses emphasize that long response times from the WISeR vendor harmed patients ("WISeR FOIA Response - Feedback Survey Responses"):

“We have patients calling our offices crying in pain because their procedures are being delayed while awaiting approvals or guidance tied to this model. A 3–4 day delay for necessary pain procedures is already difficult for vulnerable patients, but when providers cannot obtain answers for weeks, the situation becomes unacceptable.”

“I HAVE HAD TO WATCH 3 PATIENTS CRY AT BEDSIDE FOR NOT HEARING BACK ON THEIR PRIOR AUTH FOR KYPHOPLASTY/VERTABRAL AUGMENTIATION PROCEDURE. THESE PATIENTS ARE IN DEEP PAIN.”

“I have had cases submitted and waiting over 1 1/2 months for a UTN to be generated… In the meantime patients are having to be cancelled for surgeries they need. This is not acceptable they are severely hindering patient care.”

Rushed Rollout Amidst Widespread Technical Failures 

CMS WISeR launched in January 2026, just six months after it was announced. Despite warnings from both medical providers and a vendor about insufficient preparation time, CMS chose not to delay the launch. 

Approximately a month before the launch, one of the vendors, Innovaccer, alerted CMS that it intended to go live with a version of its software that lacked full functionality and had not been fully tested. It cited several barriers to going live with full functionality, including changing requirements and expectations, unclear governance processes, and lack of time for end-to-end testing with the provider community ("WISeR FOIA Response - Combined Records,", page 216-217). Innovaccer said it would auto-affirm all prior authorization requests until it could develop full functionality and explained that “Given CMS's decision not to delay the model start date, auto-affirming is the only path available” ("WISeR FOIA Response - Combined Records," page 217).

Innovaccer had not yet finished developing or testing some features several months into the program, according to an April 2026 status report. Innovaccer was not the only vendor who faced technical challenges before and after WISeR launched. Weekly status reports and provider feedback in the released records show widespread challenges associated with WISeR’s rushed rollout (for example, "WISeR FOIA Response - Combined Records," pages 238 and 383).

A status report from April 6th, 2026 describes issues with incomplete solutions from Innovaccer (WISeR FOIA Response - Combined Records, page 200)

More Urgent Medical Services Considered for Inclusion in Future Years of WISeR Model

In its first year, the WISeR model introduced prior authorization requirements for a set of 13 medical services. The June 2025 Innovation Center Investment Plan for WISeR lists medical services that could be added to the program in future years. This planning document considers the possibility of adding services “where prior authorization would have to be done on a more urgent or emergent basis,” including air ambulance transport, cancer treatment, MRI scans, and medications without publicly available coverage criteria.

A planning document from June 2025 lists ideas for the expansion of WISeR to additional medical services (WISeR FOIA Response - Combined Records, page 22)

More Transparency is Needed About Medicare’s AI Experiment

CMS continues to produce records in response to EFF’s lawsuit. Records released thus far echo concerns that providers have raised since WISeR launched, including long delays, financial incentives to deny care, and technical problems. But important questions remain about the AI systems private companies are using to inform decisions about whether to provide people with Medicare benefits. As CMS continues to produce documents, we will continue to make them available to the public. The public deserves to know how AI is driving decisions that affect patients’ access to care.

Related Cases: EFF v. CMS
Lena Cohen

Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal

6 days 1 hour ago

A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was brought by our client, Channel 781 News, after takedown notices temporarily shut down the citizen journalism group's YouTube channel. We think the court set the bar far too low for copyright takedowns, and we plan to appeal.

Channel 781 is a group of independent, volunteer journalists who report on local affairs in Waltham, Massachusetts. That includes posting short, newsworthy excerpts from recordings of city government meetings produced by Waltham Community Access Corporation (WCAC), the city's public access television station.

In September 2023, WCAC sent three copyright takedown notices to YouTube targeting fifteen of Channel 781's videos. YouTube removed the videos and, under its three-strikes policy, temporarily disabled Channel 781's entire account—just days before a local election.

Represented by EFF and Brown Rudnick LLP, Channel 781 sued WCAC under Section 512(f) of the Digital Millennium Copyright Act (DMCA), which provides a remedy when a copyright holder knowingly makes material misrepresentations in a takedown notice.

When Is a Copyright Holder Responsible for a Wrongful Takedown?

Fair use is the legal right to use copyrighted material without permission, when doing so serves purposes like criticism, commentary, or creating something new. Fair use is not copyright infringement, and courts have recognized that copyright holders must consider fair use before using the DMCA's powerful notice-and-takedown process.

In this case, Channel 781 argued that WCAC accused it of copyright infringement without making a good-faith assessment of whether its videos were fair use.

The evidence showed that WCAC's analysis was seriously deficient. The court noted that Chris Wangler, the WCAC employee who sent the notices, didn’t consider several facts relevant to fair use. For instance, Channel 781 used relatively small portions of WCAC's recordings, and the underlying recordings were factual public meetings, not a creative work. WCAC also gave little or no weight to whether Channel 781's use harmed any market for the recordings.

There’s also strong evidence that WCAC had motivations unrelated to copyright. WCAC objected to its footage being used to criticize local officials and advance political viewpoints. And WCAC sent the takedown notices during a local election, shortly after Channel 781 posted a campaign statement by Waltham's mayor that WCAC had mistakenly made available online.

Despite this evidence, the court concluded that WCAC had a subjective good-faith belief that Channel 781's videos were infringing. We disagree.

A Subjective Belief Should Not Be a Free Pass

Channel 781 argued that a copyright holder’s belief that material is infringing must be both genuinely held and objectively reasonable. WCAC argued that a subjective good-faith belief is good enough. Unfortunately, the court agreed with WCAC.

The court emphasized that Wangler had read up on fair use, watched a short YouTube video explaining the doctrine, and distinguished between videos he thought might qualify as fair use and those he believed did not. That was enough, the court concluded, to establish subjective good faith—even though Wangler’s analysis ignored important facts relevant to fair use. As the court put it, Section 512(f) does not require “a perfect or even reasonable fair use analysis.”

That is an alarmingly low bar for copyright holders seeking to remove someone else’s speech from the internet. A DMCA takedown can cause lawful speech to disappear almost immediately. As Channel 781 experienced, multiple notices can even result in an entire channel being disabled.

If a copyright holder can avoid liability despite a cursory, incomplete, and objectively unreasonable analysis that ignores important facts—even when there’s evidence that the copyright holder wanted to suppress critical speech—the obligation to consider fair use risks becoming little more than a box-checking exercise. That interpretation threatens to strip Section 512(f) of much of its force.

Even Under a Subjective Standard, WCAC Fell Short

Even accepting the court’s subjective standard, WCAC's cursory consideration of fair use should not have been enough. WCAC disregarded important fair use considerations, and the record included statements suggesting that it believed people generally needed permission to reuse its footage—an understanding at odds with fair use. There was also evidence that WCAC objected to Channel 781's political use of its footage, and had motivations for the takedowns unrelated to copyright.

Taken together, these facts raise serious questions about whether WCAC genuinely considered fair use, rather than using copyright as a rationale for removing material it did not like.

The Court Did Not Find That Channel 781's Videos Infringed

Importantly, the court's analysis recognized Channel 781’s strong fair use argument: the group used short excerpts from factual recordings of public government proceedings, selecting clips for their newsworthiness, and making them easier for the public and journalists to find, share, and discuss.

The opinion even states that WCAC's fair use analysis “may have been deficient.” But under the purely subjective standard it adopted, the court concluded that it could not reject WCAC's professed belief—even if the court itself “would have reached the opposite conclusion” on fair use.

We plan to appeal this decision to the First Circuit Court of Appeals. Copyright law should not allow a rightsholder to suppress critical reporting or political speech through the DMCA and escape accountability simply by claiming it believed the speech was infringing. Section 512(f) is supposed to provide protection against wrongful takedowns. We will keep fighting to ensure that safeguard actually protects people. 

Betty Gedlu

Texas and Florida Step Back from ALPRs

1 week ago

Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After years of successful grassroots battles to pull these cameras from local streets, bipartisan momentum is sweeping the country.

On August 28, Texas Governor Greg Abbott banned state agencies from spending public funds on Flock cameras. The order dropped just as The Texas Tribune prepared to publish an investigation revealing that a state agency had quietly funneled at least $30 million into building a sprawling surveillance network. 

Then on August 31, the Florida Department of Transportation (FDOT) issued a memo, announced by Governor Ron DeSantis, ordering the removal of all ALPRs from the right-of-way on state highways within 30 days. The order revokes all previously approved permits to install ALPRs, and bars transportation officials from issuing future permits. 

FDOT officials stated that “the recent exponential increase in deployments along our roadways, coupled with concerning reports of misuse, data privacy concerns, and surveillance schemes merit immediate action to preserve Floridians’ sovereignty and quality of life.” FDOT’s action has been followed by a surge of local governments in Florida canceling or pausing their vendor contracts.

Much more work remains. Many ALPRs in Florida are not on state highways, but sit on city streets, county roads, residential driveways, and shopping center parking lots—and FDOT's order doesn't touch any of them. Likewise, the Texas directive leaves local agencies free to use city, county, federal, and private funds to install cameras.

This week’s good news follows years of pushback from local advocates that has seen dozens of cities sever ties with surveillance companies. According to some metrics, during the last 30 days, an average of three localities per day has halted contracts with Flock. Other advocates have been resisting ALPRs in statehouses and court houses, and by blowing the whistle with investigative activism.

The moves in Florida and Texas also illustrate the power that the executive branch can wield to curtail mass surveillance with almost immediate results. We hope that the California Governor Gavin Newsom and the California Department of Transportation will take notice and initiate steps to curb this technology, starting with removing the ALPRs that U.S. Border Patrol and the Drug Enforcement Administration have installed on California highways.

EFF’s position remains: ALPR mass surveillance – the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion – should not exist. This past week’s actions in Texas and Florida are good steps forward, but we are still far from the finish line. We will continue working alongside community groups to keep cameras off local streets, while urging judges and state lawmakers to impose enforceable restraints on this warrantless mass surveillance.

Rindala Alajaji

Judge Rules DOD Unlawfully Retaliated Against Anthropic

1 week ago

A federal judge has sided with Anthropic on its claims that the Department of Defense illegally retaliated against Anthropic’s protected speech by labeling the AI company a “supply chain risk.” The judge found that designation, intended to penalize Anthropic for telling the U.S. military it would not allow their technology to be used for mass surveillance of U.S. persons, “constituted unlawful retaliation in violation of the First Amendment.” EFF joined a coalition of organizations in filing multiple amicus briefs (here, here) arguing that the Pentagon had trampled on Anthropics First Amendment rights. We agree with the court’s decision and applaud the judge for slapping down such an obvious act of illegal and unconstitutional retribution by the Pentagon—even as the court left open the broader question of whether a company’s choices about how its technology may be used are protected speech in their own right. 

From the start of this conflict, EFF argued that companies should not be penalized for not wanting to conduct mass surveillance of US persons. Nor do we want to live in a legal system where our susceptibility to surveillance is hashed out and decided in closed-door contract negotiations between a few powerful people at the military and an AI company. Unfortunately, this ruling does little to address the bigger problem: that Congress has abdicated its responsibility to adopt statutory safeguards to protect our privacy, and instead left us reliant on the whims of private companies to decide when they are and are not willing to help the government conduct mass surveillance. 

In February 2026, the government began threatening to penalize Anthropic unless it backed off its position that it did not want the U.S. military using its AI product Claude for mass surveillance of Americans or to power autonomous weapons systems. Ultimately, the Department of Defense, deciding that it did not want military contractors dictating what its products could or could not be used for, declared the company a “supply chain risk.” This national security designation means the government and companies that do business with it cannot use the company’s products for government projects. It was, in essence, an attempted blacklisting of Anthropic for setting boundaries and articulating unacceptable use cases for its products. 

None of this is to say that Anthropic is a morally unimpeachable company, or that it and other companies would never permit their products to be used under specific conditions to aid in surveillance or analysis of collected data that could affect U.S. persons—but the facts remain: the government cannot punish a company for having preferences regarding unconstitutional uses of its technology. 

Unsupported claims that a company poses a national security risk should never be an excuse for government retaliation. This ruling correctly recognizes the dangerous implications of allowing the government to punish a company for its critical speech and for refusing to allow its technology to be used for mass surveillance. While we applaud the court's decision, we continue to urge lawmakers to take the protection of our privacy seriously. We shouldn't have to rely on private companies to protect us from the surveillance state. It's past time for Congress to act.

Matthew Guariglia

Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users

1 week 1 day ago

Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.

In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:

  • The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
  • The Settlement places severe restrictions on Teens that can largely only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
  • The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
  • The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism. And the Settlement in no way limits the attorneys general from seeking the user information for their own law enforcement purposes.

Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.

Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.

Age Gates Reinforced By Age Estimation Technology

In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And further, Meta will now enforce these age gates with age assurance technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The technology also just adds a layer of creepiness into the use of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]

1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) or age assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.

Those methods might include commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.

This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.

For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.

Those estimated to be 13-17 years old will be limited to Teen User accounts.

Those estimated to be under-13 will lose their accounts altogether.

Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]

(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.

What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement, and that seems to require a formal assessment of accuracy.

How accurate does the age assurance process need to be?

The Settlement sets maximum false-positive rates for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more than 10% for ages 16-17 and no more than 3% for ages 13-15. 

6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: 
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.

Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement generally shows little concern for those falsely placed in its Teen User category. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]

9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.

Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).

(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and 

Any age assurance process Meta uses must be tested annually.

Data minimization

The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” The “reasonable period of time” is not defined. And the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information ... where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.

8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.

Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)

Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to those estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.

Time restrictions

Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits, and that some teens may need to work at the restricted times to support their families and themselves:

  • Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
  • School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
  • Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
  • “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be momentarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:

exhibit_g_meta.jpg

To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such user controls would have recognized that teens have human rights, agency, and autonomy.

But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.

Feature restrictions (§II.C-D)

Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service. 

Again, these would be useful user controls that should be offered to users of all ages. And while a Teen User potentially has control over these features, they cede that control to their parent once they enroll in Parental Supervision, part of the Parental Supervision Tradeoff discussed below.

Also, by default, teens will not see the number of likes or other reactions to their posts.

Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques.”

X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.

Meta has had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. 

Content restrictions (P.1, §II.E, as defined by §I.C, E, F)

For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.

C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.

The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity standard, Meta blocks teens from “real world art of visible genitalia ... where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous women, breast cancer awareness postseducational posts about ovulation, and posts about testicular and breast self-exams. And it has disproportionately applied the standard negatively to gay and lesbian content as compared to straight content.  

And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressures Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions. 

C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.

The Parental Supervision Tradeoff 

All of these Teen User restrictions can be modified – but only if the Teen User enrolls in Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).

Parental Supervision comes with huge tradeoffs. There is a huge privacy tradeoff: in exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with the Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G] And there are huge autonomy tradeoffs: once enrolled in Parental Supervision, the ability to control features like recommendations and autoplay, discussed above, transfer from the Teen user over to their parent.

Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.

Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8] 

This may be ultimately workable for young people with healthy and safe relationships with their parent or guardian. But obviously it is not good at all for a Teen User lacking such a safe relationship. 

More Surveillance, Not Less

Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users' use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.  

For example: 

  • Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)] 
  • Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)] 
  • Meta pledges to utilize and improve its existing “soft matching models” that track signals such as “device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)] 
  • Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3] 
  • Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4] 
  • The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E] 

Moreover, one of the chief threats of Meta’s surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain. 

Meta Has To Pay The States And Pays To Establish Norms Beyond Meta

The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten-year life of the Settlement, these annual payments will total over $11 billion. And the states then get an additional $5 billion if Meta competitors adopt the same measures. 

This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get the additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance, age-gating, and the ceding of teen autonomy as the norm across online services. 

1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).

2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:

(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.

3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment

The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance, and does nothing to protect access to such data by the states. 

David Greene

EFF to Governor Newsom: Veto California’s AB 1709

1 week 1 day ago

The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a sweeping ban on social media use for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cuts young people off from essential information and experiences, particularly harming vulnerable youth and marginalized groups who often find safety in supportive online communities they can't access offline. That’s why we’re urging Governor Gavin Newsom to veto the measure

Should the law go into effect in January, platforms would be prohibited from offering virtually every functional recommendation algorithm and basic input, such as who a user follows or what posts they like, to anyone under 16. These so-called "addictive features," are in reality the basic tools that online services use to identify what other user-generated content a particular user might want to see. Users also rely on these features to find audiences for their own speech, as well as community. By labeling these basic tools as "addictive," the bill relies on sweeping generalizations regarding the unsettled science of youth social media use. Because nearly every major service relies on automated feeds, the ultimate result is that young people under 16 will still be locked out of major digital services as they currently exist.  

A.B. 1709 is a massive privacy and free speech nightmare.

A.B. 1709 is a massive privacy and free speech nightmare. Denying young people access to digital forums (or stripping out the basic tools needed to navigate them) does nothing to make young people safer or healthier. Research shows that social media bans are ineffectual, and can be harmful when they deny young people opportunities to develop their own voices and perspectives, whether that means sharing art, practicing religion, or engaging in politics. 

Far from protecting children, the bill will also severely restrict access to constitutionally protected speech and push platforms to implement invasive age-verification methods, such as requiring government IDs or biometric scanning. Age-gating requirements will force everyone to give big tech companies even more personal information. To verify who can pass through online gates, companies will collect even more data, concentrating power in corporate hands rather than protecting users. This creates massive honeypots of sensitive personal data, severely damages online anonymity, and exposes users of all ages to heightened data breach risks

Finally, A.B. 1709 introduces legal confusion by creating provisions that conflict with already enacted legislation like A.B. 1043 and S.B. 976. Rather than offering regulatory clarity on already-passed laws, California will only end up spending valuable resources to defend a law bound to be tied up in court.  

For more details, you can read our full letter to the Governor here

Rindala Alajaji

EFF to Courts: Don’t Rewrite Copyright Over AI Hype

1 week 2 days ago

The history of technology is rife with copyright panics.  In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public as the Boston strangler is to the woman home alone.” Then, the Supreme Court declined to embrace the hype, noting that the VTR was capable of all kinds of non-infringing uses, like time-shifting and cautioning courts to avoid rewriting copyright law in response to new technologies. We believe that courts now should be similarly wary about the hype surrounding AI.

Hollywood’s hyperbole has echoed that of composer John Phillip Sousa, who claimed in 1906 that the player piano and the gramophone would destroy music composition; portrait artists who feared the camera would replace the paintbrush. None of these things happened. Cameras, for example, sparked a resurgence of portraiture and, by making it possible for more people to create images, led to unexpected developments—like the rise of photojournalism.

New markets, new ideas, and new creators are actually what copyright is supposed to promote, not restrict. Using copyright to lock in existing gatekeepers and massive rightsholders’ profits helps neither the public nor individual artists.

Generative AI has sparked the latest wave of anxiety and with it a massive wave of litigation. In multiple cases around the U.S. and the world, rightsholders are asking courts to do precisely what the Supreme Court warned against: dramatically expand copyright protections based in substantial part on hyperbole and speculation. They should decline to do so.

Copyright owners claim that unless courts abandon 300-year-old copyright principles—and give rightsholders the power to control non-infringing works created by others—an imagined flood of AI-generated works will devastate creative markets. Under this “market dilution” theory, building generative AI tools cannot be fair use because those tools might be encourage the proliferation of competing works.

As EFF has explained to the courts in multiple amicus briefs in Concord Music Group, Inc. v. Anthropic PBC and In re Mosaic LLM Litigation, that’s not how copyright works. In fact, accepting this theory would undermine copyright’s constitutional purpose: promoting the creation of expressive works for the public’s benefit. Because copyright law is designed to encourage others to build freely on existing works, it punishes infringement, not competition. The “market dilution” theory would eviscerate not only the fair use doctrine, but also other limits on copyright that work specifically to prevent rightsholders from unfairly suppressing competition by claiming broad ownership over tropes, genres, styles, and so on. In other words, publishers would wield unchecked veto power over any expression that might conceivably compete with a work they own.

The result? Art doesn’t get created, ideas are never expressed, and we’re all worse off. Copyright shouldn’t be a tool to silence future creative competitors—whether or not they use AI in their work.

And the plaintiffs in these cases get at least two other things wrong. First, research shows that large generative AI models are unlikely to produce infringing works because the more data on which a model is trained, the less any individual training example matters to any particular output.

Second, AI tools aren’t necessarily displacing human creativity. To take a just a few examples:

  • Boston-based artist Nettrice Gaskins uses AI to create Afro-futurist art, including a portrait of Octavia Butler displayed at the San Francisco Airport
  • Indian artists Prateek Arora and Varun Gupta use generative AI to reimagine Western science fiction.
  • Philadelphia-based artist Alex Smith uses generative AI to reimagine Afrofuturism with queer, plus-sized Black superheroes.
  • Ana Miljački, a professor of architecture at MIT, used generative AI to create a “non-liner documentary” film on Yugoslav World War II memorials and the values they embodied.
  • A research-creation project used AI generated visual art to both amplify the voices of activists in the Iran Woman Life Freedom Movement and evaluate AI’s role in sociopolitical advocacy through art.
  • AI company Bronze works with musicians like Disclosure and Jai Paul to create songs that never sound the same when played back twice, challenging audience conceptions of what music could be.

It is not the place of courts to say these people are not artists or that AI cannot augment human creativity in a positive way.

Given this range of experimentation, courts should be reluctant to decide in advance what tools do and do not foster “human creativity.” Like the VTR, large language models are general purpose tools, used by humans to do a broad variety of things far beyond generating lyrics. The effects of this particular technological innovation will doubtless be far-reaching, disruptive, and potentially harmful for some—but distorting copyright law is not the way to address those harms.

Tori Noble

Doxxing Safety Part II: Incident Response

1 week 2 days ago

Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse. 

This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.

Incident Log

An incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful. 

The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:

Assign Team Roles

Remember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).

Monitoring Hate Forums

So often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.

Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.

Set Up Search Alerts

Google alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.

For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.

Hardening Your Public Facing Accounts

For accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.

Shut Down Affected Accounts

If a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.

Revisit Your Data Broker Removal Strategies

Although this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.

Revisit Public Records

As covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.

Consider Contacting Law Enforcement

For many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.

Revisit PACE Documents, Enact Those Steps

If you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.

This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.

Put A Lock on Your Bank Accounts and Cell Subscriptions

One of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques. 

Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).

Regulate Your Nervous System

It’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process. 

Flexibility and Resiliency

The reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security. 

Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.

Daly Barnett

Doxxing Safety Pt I: Prevention and Footprint Management

1 week 2 days ago

Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there's a lot you can do to reduce your digital footprint and take control of your data.

This post is part one of a two-part series discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. The second focuses on incident response, as in, steps to take if you're in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it's worth reading each and gaining familiarity with the steps well ahead of time.

OSINT

Open source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.

There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different OSINT resource lists that index together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful. 

Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:

Breach Databases

When a company gets hacked and their customer data is leaked, that information often ends up in “breach databases,” that is, troves of peoples' data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like haveibeenpwned, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like DeHashed, offer a similar sort of tracking, but for a fee. 

You may not have control over a company's digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.

Open Records

Public records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences. 

Instead of requiring a formal request through the courts, mirroring sites make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.

Some states have programs called “Address Confidentiality Programs” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.

Social Media

Going through and tightening the security and privacy settings of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.

To get a quick overview of the various accounts you have registered online, especially if you've been online for a long time, use a username search engine like What's My Name or Namechk to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.

Data Brokers and Removals

Data brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry is no more, it's up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. Yael Grauer's BADBOOL project compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. Though they've been found to be less effective than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more easily opt out through the new and exciting DROP tool.

Reverse Image Searching and FR Services

Services like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They contribute to law enforcement investigations and predictive policing systems, as well as providing commercial services to abusers and stalkers. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out. 

Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you're under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.

Extra Monitoring, Automated

This section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you're in the Google ecosystem of products, consider enrolling in their Advanced Protection Program, which offers a number of different features to keep you and your account safe. 

If you're the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like Open Measures is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.

Get Others Involved

Coordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers. 

A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using secure technology like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.

It's a Process; Keep Yourself Apace for the Marathon, Not the Race

The process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don't underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you're first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the Surveillance Self-Defense project

Daly Barnett

Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

1 week 2 days ago

Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut, Maryland, New Jersey, Oregon, and Virginia enacting new consumer privacy restraints on an industry that profits off our physical movements.

Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.

Why Location Privacy Is Important

Imagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.

This is the reality of geofence warrants for location data, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in Chatrie v. United States. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court's ruling in Chatrie established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by commercial data brokers operating in a largely unregulated market. These brokers regularly harvest, aggregate, and sell physical location data to anyone with a credit card (including government agencies, which are among their regular clients). Especially for individuals seeking reproductive or gender-affirming care, attending a protest, or visiting an immigration law clinic, this pervasive commercial location surveillance represents an immediate threat.

In Part 1 of this series, we urged lawmakers to protect people from the growing harms of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars buying app location data to track priests across multiple dioceses and used app-harvested location data to “out” a priest after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to Locate X, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like Near Intelligence have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to locate U.S. military personnel in war zones. Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from real-time bidding ad networks to track individuals attending demonstrations.

The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, a recent EFF investigation identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users' location data whenever app-level location permissions are granted. These advertising libraries automatically feed users' location data into ad systems that location data brokers have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.

State Legislative Progress

Last year, we outlined six essential core principles that any meaningful location privacy law must contain:

  • Strong definitions,
  • Clear rules,
  • Affirmation that all precise geolocation data is sensitive,
  • Empowerment of consumers through a strong private right of action,
  • Prohibition of “pay-for-privacy” schemes, and
  • Transparency through clear privacy policies.

While the bills we highlighted from California, Illinois, and Massachusetts are yet to pass into law, a new wave of state location privacy legislation has taken effect across Connecticut, Maryland, New Jersey, Oregon, and Virginia.

These five laws represent progress, and share two strong features.  First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (BIPA), which bans the sale of biometric information such as face scans.

Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from California’s A.B. 45 of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.

These five laws vary regarding whether, on top of the ban on sale, they require consent and/or minimization for other kinds of processing of precise geolocation data. Maryland’s Online Data Privacy Act (MODPA) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “strictly necessary to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.

Connecticut requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.

New Jersey requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).

Virginia protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”

Beyond its ban on sale, Oregon does not limit the processing of precise geolocation data.

Gaps in Current Legislation

While these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.

The Enforcement Void: Why Every Law Needs a Private Right of Action

A privacy law without a Private Right of Action is a law "without teeth”.

None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.

The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (UDAP). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.

Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against mandatory arbitration. This ensures that compliance isn't optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.

The "Pay-for-Privacy" Trap

Privacy is a fundamental right, not a luxury tier. So EFF opposes pay-for-privacy schemes, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.

Unfortunately, all three of these states that require consent to process precise geolocation information (Connecticut, New Jersey, and Virginia) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to eschew this loophole, as in the ban on pay-for-privacy in last year’s location data privacy bills in Illinois and Massachusetts.

These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements in exchange for essential discounts or services.

Dark Patterns

Any law that requires consent also needs to ban company techniques that subvert consent. These are often called dark patterns, predatory design, and manipulative user interface (UI/UX) practices.

Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.

Conclusion

The recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.

To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult EFF's Surveillance Self-Defense Guide to learn practical steps for reducing location tracking on their personal devices.

Rindala Alajaji

LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?

1 week 2 days ago

This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch! 

EFF answers all the queer digital rights questions you submit to us through our LGBT Q&A. You asked us: What’s one thing I can do today to improve my safety and security online as an LGBTQ+ person? 

And for this question, we’ve brought in our friends from the Trevor Project to answer together:

Hi, I’m Tommy from the Trevor Project! The Trevor Project’s mission is to end suicide among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ+) young people. Our vision is to create a world where all LGBTQ+ young people see a bright future for themselves.

EFF and the Trevor Project know that digital security and online safety can feel overwhelming, especially because we all have different levels of concern for different parts of our online lives. Some might be focused on the dangers of doxxing, another might only want to ensure they're not outed. And queer people can be particularly vulnerable to these kinds of online threats. 

This might seem like a big task, but the one way you can do today to protect yourself is to revise the information you’ve shared with services and platforms to ensure you’re as in control of your information and data as possible:

Protect Your Personal Information

Be cautious about sharing sensitive details like your full name, address, school, phone number, and personal photos as it might expose identifying information you want to keep private. Consider using an avatar as your profile picture to avoid sharing your personal photos if that makes you more comfortable. Keep it lowkey when talking about work stuff or sharing details about where you’re studying.

If you do share personal photos, don’t accompany them with information that identifies your location or frequent whereabouts, and make sure EXIF data in photos is turned off (which could inadvertently include your location); the easiest way to do this is to take a screenshot of the photo and share that instead. Don’t post pictures with obvious spots in the background, like your front door or porch. 

Understand the Importance of Login Information

When you create an account on websites and platforms, you can often use your phone number or a third party account, such as Facebook, Google, or Apple. These external accounts might share data with the apps you're logging into, but they can be helpful if you struggle with managing a lot of logins. Deciding if that trade-off is worth it is up to you but, when you can, use strong, unique passwords for your accounts, and be sure to enable two-factor authentication when offered. 

Review Permissions with Social Media Apps

Review which apps have access to things like your location and camera roll, and possibly change those permissions in line with what information you would like to keep private. Location is particularly important. For example, some apps might need some location information to function. But you can typically at least deny access to your device's "precise location" or enter in a city or zip code manually.

Consider What You Share When Speaking with Others Online

It’s important to be mindful of what you share with others when you post online or speak with people. Avoid disclosing sensitive information like financial details, and trust your gut if something feels off. It’s also useful to review your profile’s privacy settings and information now and again to make sure you’re still comfortable sharing what you’ve listed there.

Good privacy decisions begin with proper knowledge about your situation and a community-oriented approach. To dig in deeper, read EFF’s blog post on Building a Community Privacy Plan and the Trevor Project’s Guide to Online Safety for LGBTQ+ Young People.

Paige Collings

EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity

1 week 5 days ago

EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil's elections. The recommendations stress the close relationship between violations of personal data protection and challenges to the integrity of electoral processes. They underscore how privacy and data protection guarantees are a crucial tool for curbing the targeted spread of false or manipulative content and other problematic strategies used by political actors that are amplified by digital technologies such as artificial intelligence systems. 

The recommendations are part of a broader regional initiative and build on the legal and institutional safeguards already in place in Brazil. They seek to promote greater coordination among oversight institutions, civil society, and digital platforms, and encourage the solid implementation of privacy and data protection guarantees as drivers of electoral integrity. Read the full document below. 

The Link Between the Integrity of the Electoral Process and Privacy 

Protecting the integrity of the electoral process in the face of internet and social media use is a challenge that many policymakers are addressing or are willing to address. Online, content that can affect the integrity of the electoral process is increasingly personalized. This phenomenon is so concerning that it has been identified as one of the main global short- and medium-term risks

In an era of generative AI, the economic cost and technical difficulty of producing and spreading false or synthetic content to deceive, manipulate, or simulate authenticity have been considerably reduced. That intensifies concern over the integrity of the electoral process. Meanwhile, online privacy and personal data protection remain unfinished business in Latin America. 

There is an intrinsic connection between the ability to collect and process large amounts of personal data and the way false or manipulative content is created and distributed—on social media and messaging apps in particular, and on the internet in general. For this reason, applying strict laws and policies on personal data protection and privacy makes it possible to reduce the impact of false or manipulative content. This is especially important in electoral contexts, where such content affects and impoverishes public debate, directly affecting political and electoral rights and the integrity of the electoral process. 

This phenomenon predates the emergence of the internet. However, the rise of new technologies accelerates the generation and spread of false and manipulative content. This is supported by the very economic model that sustains the platforms, amplifying its effectiveness and reach. On the one hand, social media platforms have content recommendation algorithms that use personal data to generate profiles to which they can then serve targeted advertising content, including explicitly political propaganda. This technique is known as "microtargeting." 

Political microtargeting seeks to have a direct or indirect impact on democracy. It is used to persuade voters, to encourage or discourage turnout at the polls, or to raise funds using information that is deliberately taken out of context, inaccurate, or erroneous. 

The control exercised by these companies raises serious concerns about people's rights. By having access to massive amounts of personal information, these companies have the ability to shape the content that users see and interact with. This happens through the construction of profiles that can reveal habits, social relationships, political preferences, and opinions, to mention a few examples. Personal data is the fuel that amplifies risks to the integrity of the electoral process. That’s true whether it’s provided by the users themselves or generated by the platforms from their interactions online. 

For disinformation actors, access to sophisticated tools—such as those used to create "deepfakes" through generative AI, or "bots" programmed to spread content and seek to manipulate public opinion—boosts the effectiveness of this microtargeting in terms of quality and scalability, making it harder to detect as false or manipulative content. AI-generated avatars and synthetic characters that simulate voters, influencers, hosts, commentators, or community leaders can produce footage that appears spontaneous, fabricate the voices of artificial political actors, and make it harder for users to identify if a given public statement was created or mediated by technology. 

In this context, paid promotion with nanotargeting seeks to reach increasingly specific profiles with customized content, and AI-based tools are used to assess and map its impact on social networks. Drawing on the personal data of groups of voters, profiles of "synthetic voters" are created to test messages or strategies in search of the most efficient way to influence real voters. 

This rapid expansion of AI systems and hyper-personalization with data can lead to a problem of "epistemic erosion" for democratic societies, as pointed out by the UN's Independent Scientific Panel on AI Governance in 2026. 

At Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation, we point to the enforcement of personal data protection laws and public privacy policies as an efficient mechanism for improving the quality of our democracies and reducing the manipulation of public discourse in digital environments and its impact in electoral contexts. Measures to broaden access to information for electoral decision-making, and to ensure transparency about campaigns' and political parties' use of digital technologies built on the massive processing of personal data, also play a relevant role in guaranteeing the integrity of the electoral process. 

Recommendations for Safeguarding the Integrity of Electoral Processes in Brazil in the Face of New Technologies 

Concern about the effects of spreading false, manipulative, or deliberately decontextualized content is particularly heightened in electoral contexts. From Argentina to Mexico, many countries in Latin America, including Brazil, are holding or will hold significant electoral processes in the coming period. 

Providing the public with quality information from a range of sources is an essential element for the exercise of political rights. In order to safeguard the electoral process, these countries must enforce their privacy and personal data protection laws through their competent authorities, in coordination with their judiciaries and electoral courts. 

Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation propose the following recommendations to protect the integrity of the electoral process by guaranteeing privacy and data protection during electoral contexts: 

1. Strengthen personal data protection guarantees and policies as a key element for the integrity of the electoral process, in particular the principles of necessity, purpose, and proportionality:

  • Prohibit the processing of sensitive personal data (such as philosophical beliefs and the labeling of ideological leanings), including inferred data, that reveals or could reveal people's political preferences for the purpose of targeting political content. In electoral contexts, the processing of sensitive personal data is only legitimate when the person has given their consent in advance, explicitly, and with strictly limited and clearly disclosed purposes of use and transfer. 
  • Processing must be carried out only on personal data that is strictly necessary for the purpose being pursued. 
  • Prohibit adding users to instant messaging groups for political outreach purposes, except in exceptional cases involving lists of political party members or where prior and informed consent has been given by the data subject. 
  • Free, specific, and informed consent means that the person is able to make a real choice, set apart from other choices, and does not run any risk of deception, intimidation, coercion, denial of access to products or services, or other significant negative consequences if they do not give their consent. 

2. Political parties, federations, and coalitions must improve the information made available to the general public about their personal data processing activities in electoral contexts, including: 

  • The personal data processing policy adopted, in compliance with data protection legislation and electoral legislation, including the measures adopted to prevent breaches of the general protection principles, to record personal data processing operations, to obtain consent appropriately, and to ensure technical and administrative security in data processing; 
  • Communication channels where the data subject can obtain information about the processing of their personal data, exercise the rights provided by law, and request to opt out of receiving electronic and instant messages. 
  • Information about the profiling they carry out for electoral purposes and about the procurement and use of data-based digital technologies in this context, including for purposes of paid promotion, microtargeting, network analysis, and prediction of voters' reactions or behavior. 

3. Strengthen cooperation mechanisms between the National Data Protection Authority (ANPD) and the Superior Electoral Court in order to: 

  • Improve communication channels and strengthen joint initiatives to oversee compliance with data protection guarantees in the electoral context, with the publication of periodic enforcement reports. 
  • Identify and dismantle coordinated strategies that compromise the integrity of the electoral process and carry out online activities that pretend to be "organic" and citizen-based when they are in fact funded or coordinated by a party, government, or company, such as bot farms, fake personal accounts managed by a single entity, AI avatars and synthetic characters that simulate real voters in order to manipulate public opinion, among others. 
  • Within the scope of their powers, require the preparation and publication of a data protection impact assessment in cases involving the use of sensitive personal data or emerging technologies for voter profiling. 

4. Authorities, political parties, communicators, and social media platforms must ensure, as far as possible, that the population has access to adequate and relevant information for electoral decision-making. 

  • Political parties, electoral authorities, and data protection authorities must allocate a percentage of their communications budget to warning about the consequences of microtargeting in electoral contexts; and about the use of AI avatars or synthetic voters to simulate support, rejection, outrage, or spontaneous political mobilization. 
  • Strengthen alliances with fact-checkers and other relevant communicators, such as civil society organizations, influencers, and others, to identify campaigns that compromise the integrity of the electoral process and to inform the public about such alliances through different channels, including official government channels.
  • Systematize the electoral proposals developed by candidates and their electoral platforms according to thematic areas to facilitate comparison between political parties. 
  • Agree on strategies between authorities and online platform companies, including social media platforms and chatbots, at the start of electoral periods, so that priority is given to content developed by electoral authorities. 
  • Every body, protocol, or policy created that involves authorities or public entities must be communicated in accordance with proactive transparency standards. 

5. Platforms must disable microtargeting tools for political and electoral content during previously established periods. 

6. Authorities, technical actors, academics, civil society, and/or social media platforms must collaborate in creating an algorithmic impact analysis lab that makes it possible to oversee compliance with these recommendations. 

  • Produce reports on the results achieved, in particular those that document the existence of microtargeting, the use of personal data for targeting, and exposure to varied content in electoral contexts. 
  • Establish strict cybersecurity protocols so that the labs prevent access to real users' private information. 

7. The authorities responsible for overseeing personal data protection and electoral matters must have sufficient functional, economic, and technical autonomy and independence to guarantee the proper exercise of their powers. 

Veridiana Alimonti

A List of ICE Subpoenas to Tech Companies

1 week 6 days ago

Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.

A favored tool in these speech chilling investigations are administrative subpoenas sent to technology companies, requesting basic subscriber data about their users. For example, from 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter (now X), according to documents obtained by Just Futures Law. In just the second half of 2025, the Department of Homeland Security (DHS) sent 21 administrative subpoenas to Reddit, according to its Transparency Report.

While some subpoenas are routine, ICE has been forced to withdraw others after users challenged them in court or companies pushed back. These challenged subpoenas exceeded the agency's statutory authority and violated users' First Amendment rights.

Below is a non-comprehensive list of DHS subpoenas that we gathered going back to 2025, looking at public reporting and court cases. This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report (so far, only Reddit appears to break out specific numbers on DHS subpoenas). In addition, DHS has been slow to respond to our Freedom of Information Act requests and lawsuits seeking records that would show how many administrative subpoenas ICE has sent to social media companies since 2025.

If you know of other subpoenas that are not on this list, please reach out to info@eff.org. While the government has abused the subpoena process in other areas, particularly to hospitals, this list focuses on DHS and ICE subpoenas to technology companies for user data. 

DATE ISSUED

(and link to subpoena)

TARGETED COMPANY INDIVIDUAL USER TARGETED  OUTCOME  3/17/25 Facebook  Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 3/23/25 Google  Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 4/1/25 Google  Amandla Thomas-Johnson, international student who attended pro-Palestinian protest Google disclosed data to ICE on 5/8/25 9/4/25 Meta  6 accounts in Southern California that documented immigration activity, including LB_Protest, Long Beach Rapid Response Network, and Stopice.net Withdrawn after court challenge on 11/24/25 9/11/25* Meta (Instagram) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 9/11/25* Meta (Facebook) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 10/30/25 Google  Retired Philadelphia user who emailed criticism to U.S. prosecutor   Withdrawn after court challenge on 2/5/26 2/4/26* Google Social media user who regularly posts criticism of the President Subpoena challenged in Court 2/19/26* Reddit "Tired_Thumb," user who posted about ICE officer Withdraw after court challenge on 3/27/26; replaced with grand jury subpoena 2/27/26* X "podslurp,” who posted publicly available address information about ICE officer Withdrawn May 2026; replaced with grand jury subpoena 3/7/26 PayPal/Venmo "Voices of Racial Justice," a racial justice organization in Minnesota  PayPal/Venmo disclosed data 3/20/26 4/3/26* Google (YouTube) @TheDonLemonShow, GeorgiaFort, @DemocracyNow, and seven other accounts that reported on protest at Minnesota church Google Objected 4/7/26 4/12/26* T-Mobile Minnesota journalist Georgia Fort and others T-Mobile disclosed data on 4/12/26 First half of 2025 Reddit  Reddit account Subpoena withdrawn after questions from Reddit Second half of 2025 Reddit  11 Reddit accounts that posted content "critical of ICE actions" 3 subpoenas withdrawn after Reddit objected

* = denotes summonses issued under 19 U.S.C. 1509, an authority that has been abused in the past, according to DHS's inspector general.

Mario Trujillo

EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms

2 weeks ago

Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool that can be made safe with the right policy or feature update—they are irredeemably harmful.

EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines.

EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines. EFF applies every tool available to eliminate ALPR surveillance and the harm it enacts.

The Case Against ALPRs

A note about scope: This post addresses ALPR mass surveillance. It does not address the wider universe of automated traffic enforcement (ATE) such as conventional red light and speed cameras that solely ticket a specific violation, without retaining or networking data on uninvolved drivers. But lawmakers and purchasers should guard against efforts by vendors to piggyback on ATE contracts to market ALPR mass surveillance systems.

ALPRs are frequently marketed as a narrow tool for specific purposes, such as recovering stolen vehicles. But in practice, these sensors sweep up data on every driver who passes a camera, and store it in searchable databases. That indiscriminate collection and retention is precisely why ALPR-fed surveillance systems can be easily weaponized against immigrants, political dissidents, and other targeted communities as ICE and other federal agencies escalate their assault on civil liberties. There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it.

Of course, ALPRs cause other predictable harms. Innocent drivers are recurringly arrested and menaced by police because of ALPR errors. Officers regularly abuse ALPR systems to stalk past and potential romantic partners. Creating any database of personal information—including ALPR surveillance databases—inherently creates risk of data theft and subsequent harm to data subjects. And ALPR surveillance of protests and targeting of activists chill participation in First Amendment-protected dissent. But even if these downstream harms could all be prevented (and they likely can’t), ALPRs would remain an intolerable form of mass surveillance.

Fighting on Every Front to Eliminate ALPR Surveillance

At the city level, EFF works with community members and decision makers to outright refuse ALPR purchasing. ALPRs are not inevitable. The same decision mechanisms used to facilitate runaway surveillance purchasing in U.S. localities can be turned against these systems to dismantle them.

EFF also pushes state legislatures to establish strict state-level limits on ALPR surveillance, such as data-deletion rules and use restrictions. Building such constraints into statute can mitigate the harms of existing ALPR systems.

In courts across the country, EFF files amicus briefs arguing that warrantless police searches of ALPR databases violate the Fourth Amendment. In California state court, EFF and the ACLU of Northern California are suing on behalf of two community groups, SIREN and CAIR-CA, arguing that the San Jose Police Department's practice of letting officers search stored plate data—to the tune of over 100,000 times a year—without a warrant violates the California Constitution. We’ve also sued to block California law enforcement from sharing ALPR data with federal and out-of-state agencies, in violation of a California statute.

A big part of EFF’s work is exposing the harms of ALPR surveillance. Our investigative team tirelessly collects information about how law enforcement uses ALPRs with public records requests, sues to enforce such requests, and publishes reports about them. We’ve also successfully lobbied for a State Auditor investigation of law enforcement’s use of ALPRs.

Coordinated Action Against Mass Surveillance

EFF practices integrated advocacy because all of these tools work best together. City refusals, statehouse restrictions, impact litigation, and investigative activism are different levers EFF pulls toward the same end: eliminating ALPR surveillance, and building the durable public power needed to keep it off our streets. A council vote against a Flock contract and a warrant argument in Santa Clara County Superior Court are both, at their core, the same fight: rejecting mass surveillance infrastructure outright, and using every venue available to eliminate its harmful presence and consequences.

Sarah Hamid

EFF Statement on Meta Settlement

2 weeks ago

Under this settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta's harmful surveillance into law, and it will compromise users' privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care. 

David Greene

French Top Court Gets It Right, Strikes Down Social Media Ban For Youths

2 weeks ago

Earlier this month, France’s top court struck down the country’s legislation that banned social media use for people under 15 years old, which had been scheduled to take effect in January 2027. This is a welcome win for free expression, as we face a wave of countries and U.S. states seeking to pass similar laws banning young people from social media. 

In particular, the Constitutional Council’s decision focused on two components:

Infringement on Free Expression

The Council ruled that the legislation banning under-15s from social media infringed on freedom of expression and communication in a manner that is not appropriate, necessary, or proportionate, which is required by Article 34 of the French Constitution. In particular, it stressed that the ban did not distinguish between different types of online services, and ignored the circumstances of individual users, such as their exact age, level of maturity, and family situation.

The evidence is clear: these are reckless and harmful laws that negatively impact all people, not just those under 15. These measures chill all users’ exercise of the right to free speech and expression online by imposing obstacles on sites or by wrongfully blocking people’s access outright.

By forcing young people into digital isolation, these bans curtail vital access to news and resources for health and development; especially for LGBTQ+ and marginalized youth as social media can often be the only place to find community, explore their identity, or access life-saving resources. They also completely ignore the calls of young people themselves who favor digital literacy and education over surveillance and government control. 

These bans also destroy the right to online anonymity—a cornerstone of our right to free expression that in particular protects whistleblowers, journalists, activists, and immigrants.

Infringement on the Right to Private Life 

The Council’s second objection noted that the law requiring every person, even adults, to prove their age before accessing social media platforms impedes the right to private life, and thus infringes on Article 2 of the Déclaration de 1789.

The French Council gets a lot right in this decision: it highlights that bans like this impact not just young people, but everyone online. They force people of all ages to hand over government IDs, face scans, and other sensitive information into a growing surveillance ecosystem. Further, when parental consent is required, companies must collect even more verification data on the parents.

We know that when people are forced to hand over this information, age verification systems frequently misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their appearance; adding to the privacy concerns around these bans.

Next Steps 

As all bills in France are subject to scrutiny by the Constitutional Council to ensure compliance with the French Constitution, French President Emmanuel Macron has tasked Prime Minister Sébastien Lecornu to re-work the legislation with a goal to adopt a ‘legally robust’ version of the social media ban. 

Public policy must be effective, proportionate, and respectful of fundamental rights; and the ruling by the Constitutional Council has ramifications beyond France. It sends a message of caution to Brussels, where the EU Commission is working on an EU-wide bill on access restrictions. These legal restrictions would likely require problematic age verification of users. The prominent EU digital identity wallet and the “mini” age verification app, presented as privacy-robust options, instead raise serious privacy and security concerns.

Young people deserve better than a policy built on panic, and all internet users deserve a safe and free internet that includes measures to empower all people with the knowledge they need to navigate online spaces safely. A social media ban generates headlines, but it will not solve the problem. 

Paige Collings

EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition

2 weeks 5 days ago

This week, EFF, along with Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch, and Stopwatch, wrote to Nottinghamshire Police Force in the UK raising concern about the proposed roll-out of live facial recognition technology (LFR), and called for its immediate halt.

In particular, the letter highlights six concerns:

LFR Is Not "Just Another Tool"

Nottinghamshire Police has stated that “facial recognition is just another tool to fight crime.” But LFR used in public spaces is an incredibly intrusive biometric mass surveillance technology that scans the faces of everyone who walks past the camera and takes biometric face prints. This is not just another tool, but a major escalation of surveillance that treats everyone as a suspect by default.

People Having "Nothing to Worry About" Does Not Hold to Scrutiny 

According to Nottinghamshire Police, “if you aren’t entering the city or county to commit crime then you have nothing to worry about.” However, many people have legitimate concerns about the normalisation of invasive technologies. So a public that cannot move around their towns and cities without being subjected to a biometric identity check may be less willing to seek medical care or legal advice, speak with journalists, act in a union, vote, protest, or express their gender, sexual or religious identity. 

Disproportionate Targeting With LFR

We are particularly concerned to learn that Nottinghamshire Police could deploy LFR to tackle low level crimes, such as youth behavior deemed anti-social, as part of Operation View. Reporting suggests that the force already possesses “a watchlist of young people believed to be causing the most problems,” including children as young as 11 years old. It would be highly disproportionate to deploy live facial recognition to tackle this behaviour. Many of these children are reportedly known to the police, and it is highly likely that there are more proportionate means for locating them. 

LFR Could Increase Social Problems

We are also concerned that Nottinghamshire Police has not adequately examined the distinct risks of using LFR to target children, including negative impacts on their behaviour and outcomes, risk of recidivism, and relationship with the police. Use of LFR could exacerbate behavioural problems in children and create an adversarial, rather than trusting, relationship with the police from a young age. 

Lack of Public Support 

Recent polling commissioned by Liberty indicated that 48% of people oppose scanning the faces of those walking on high streets when there is no suspected imminent threat. Furthermore, Opinium found that the majority of people oppose the use of facial recognition in schools. Likewise, a report by the London Policing Ethics Panel found that Londoners aged 16-24 were most likely to find the Metropolitan Police Service’s use of LFR unacceptable and most likely to stay away from events where LFR was in use.

On these grounds, Nottinghamshire Police must immediately halt their plans to use live facial recognition surveillance any further.

Read our full letter here

Paige Collings
Checked
1 hour 56 minutes ago
EFF's Deeplinks Blog: Noteworthy news from around the internet
Subscribe to EFF update feed