Doxxing Safety Part II: Incident Response

3 hours 56 minutes ago

Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse. 

This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.

Incident Log

An incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful. 

The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:

Assign Team Roles

Remember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).

Monitoring Hate Forums

So often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.

Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.

Set Up Search Alerts

Google alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.

For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.

Hardening Your Public Facing Accounts

For accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.

Shut Down Affected Accounts

If a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.

Revisit Your Data Broker Removal Strategies

Although this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.

Revisit Public Records

As covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.

Consider Contacting Law Enforcement

For many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.

Revisit PACE Documents, Enact Those Steps

If you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.

This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.

Put A Lock on Your Bank Accounts and Cell Subscriptions

One of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques. 

Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).

Regulate Your Nervous System

It’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process. 

Flexibility and Resiliency

The reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security. 

Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.

Daly Barnett

Doxxing Safety Pt I: Prevention and Footprint Management

4 hours 6 minutes ago

Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there's a lot you can do to reduce your digital footprint and take control of your data.

This post is part one of a two-part series discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. The second focuses on incident response, as in, steps to take if you're in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it's worth reading each and gaining familiarity with the steps well ahead of time.

OSINT

Open source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.

There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different OSINT resource lists that index together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful. 

Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:

Breach Databases

When a company gets hacked and their customer data is leaked, that information often ends up in “breach databases,” that is, troves of peoples' data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like haveibeenpwned, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like DeHashed, offer a similar sort of tracking, but for a fee. 

You may not have control over a company's digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.

Open Records

Public records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences. 

Instead of requiring a formal request through the courts, mirroring sites make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.

Some states have programs called “Address Confidentiality Programs” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.

Social Media

Going through and tightening the security and privacy settings of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.

To get a quick overview of the various accounts you have registered online, especially if you've been online for a long time, use a username search engine like What's My Name or Namechk to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.

Data Brokers and Removals

Data brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry is no more, it's up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. Yael Grauer's BADBOOL project compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. Though they've been found to be less effective than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more easily opt out through the new and exciting DROP tool.

Reverse Image Searching and FR Services

Services like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They contribute to law enforcement investigations and predictive policing systems, as well as providing commercial services to abusers and stalkers. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out. 

Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you're under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.

Extra Monitoring, Automated

This section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you're in the Google ecosystem of products, consider enrolling in their Advanced Protection Program, which offers a number of different features to keep you and your account safe. 

If you're the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like Open Measures is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.

Get Others Involved

Coordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers. 

A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using secure technology like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.

It's a Process; Keep Yourself Apace for the Marathon, Not the Race

The process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don't underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you're first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the Surveillance Self-Defense project

Daly Barnett

Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

6 hours 9 minutes ago

Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut, Maryland, New Jersey, Oregon, and Virginia enacting new consumer privacy restraints on an industry that profits off our physical movements.

Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.

Why Location Privacy Is Important

Imagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.

This is the reality of geofence warrants for location data, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in Chatrie v. United States. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court's ruling in Chatrie established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by commercial data brokers operating in a largely unregulated market. These brokers regularly harvest, aggregate, and sell physical location data to anyone with a credit card (including government agencies, which are among their regular clients). Especially for individuals seeking reproductive or gender-affirming care, attending a protest, or visiting an immigration law clinic, this pervasive commercial location surveillance represents an immediate threat.

In Part 1 of this series, we urged lawmakers to protect people from the growing harms of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars buying app location data to track priests across multiple dioceses and used app-harvested location data to “out” a priest after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to Locate X, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like Near Intelligence have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to locate U.S. military personnel in war zones. Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from real-time bidding ad networks to track individuals attending demonstrations.

The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, a recent EFF investigation identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users' location data whenever app-level location permissions are granted. These advertising libraries automatically feed users' location data into ad systems that location data brokers have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.

State Legislative Progress

Last year, we outlined six essential core principles that any meaningful location privacy law must contain:

  • Strong definitions,
  • Clear rules,
  • Affirmation that all precise geolocation data is sensitive,
  • Empowerment of consumers through a strong private right of action,
  • Prohibition of “pay-for-privacy” schemes, and
  • Transparency through clear privacy policies.

While the bills we highlighted from California, Illinois, and Massachusetts are yet to pass into law, a new wave of state location privacy legislation has taken effect across Connecticut, Maryland, New Jersey, Oregon, and Virginia.

These five laws represent progress, and share two strong features.  First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (BIPA), which bans the sale of biometric information such as face scans.

Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from California’s A.B. 45 of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.

These five laws vary regarding whether, on top of the ban on sale, they require consent and/or minimization for other kinds of processing of precise geolocation data. Maryland’s Online Data Privacy Act (MODPA) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “strictly necessary to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.

Connecticut requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.

New Jersey requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).

Virginia protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”

Beyond its ban on sale, Oregon does not limit the processing of precise geolocation data.

Gaps in Current Legislation

While these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.

The Enforcement Void: Why Every Law Needs a Private Right of Action

A privacy law without a Private Right of Action is a law "without teeth”.

None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.

The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (UDAP). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.

Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against mandatory arbitration. This ensures that compliance isn't optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.

The "Pay-for-Privacy" Trap

Privacy is a fundamental right, not a luxury tier. So EFF opposes pay-for-privacy schemes, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.

Unfortunately, all three of these states that require consent to process precise geolocation information (Connecticut, New Jersey, and Virginia) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to eschew this loophole, as in the ban on pay-for-privacy in last year’s location data privacy bills in Illinois and Massachusetts.

These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements in exchange for essential discounts or services.

Dark Patterns

Any law that requires consent also needs to ban company techniques that subvert consent. These are often called dark patterns, predatory design, and manipulative user interface (UI/UX) practices.

Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.

Conclusion

The recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.

To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult EFF's Surveillance Self-Defense Guide to learn practical steps for reducing location tracking on their personal devices.

Rindala Alajaji

LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?

7 hours 1 minute ago

This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch! 

EFF answers all the queer digital rights questions you submit to us through our LGBT Q&A. You asked us: What’s one thing I can do today to improve my safety and security online as an LGBTQ+ person? 

And for this question, we’ve brought in our friends from the Trevor Project to answer together:

Hi, I’m Tommy from the Trevor Project! The Trevor Project’s mission is to end suicide among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ+) young people. Our vision is to create a world where all LGBTQ+ young people see a bright future for themselves.

EFF and the Trevor Project know that digital security and online safety can feel overwhelming, especially because we all have different levels of concern for different parts of our online lives. Some might be focused on the dangers of doxxing, another might only want to ensure they're not outed. And queer people can be particularly vulnerable to these kinds of online threats. 

This might seem like a big task, but the one way you can do today to protect yourself is to revise the information you’ve shared with services and platforms to ensure you’re as in control of your information and data as possible:

Protect Your Personal Information

Be cautious about sharing sensitive details like your full name, address, school, phone number, and personal photos as it might expose identifying information you want to keep private. Consider using an avatar as your profile picture to avoid sharing your personal photos if that makes you more comfortable. Keep it lowkey when talking about work stuff or sharing details about where you’re studying.

If you do share personal photos, don’t accompany them with information that identifies your location or frequent whereabouts, and make sure EXIF data in photos is turned off (which could inadvertently include your location); the easiest way to do this is to take a screenshot of the photo and share that instead. Don’t post pictures with obvious spots in the background, like your front door or porch. 

Understand the Importance of Login Information

When you create an account on websites and platforms, you can often use your phone number or a third party account, such as Facebook, Google, or Apple. These external accounts might share data with the apps you're logging into, but they can be helpful if you struggle with managing a lot of logins. Deciding if that trade-off is worth it is up to you but, when you can, use strong, unique passwords for your accounts, and be sure to enable two-factor authentication when offered. 

Review Permissions with Social Media Apps

Review which apps have access to things like your location and camera roll, and possibly change those permissions in line with what information you would like to keep private. Location is particularly important. For example, some apps might need some location information to function. But you can typically at least deny access to your device's "precise location" or enter in a city or zip code manually.

Consider What You Share When Speaking with Others Online

It’s important to be mindful of what you share with others when you post online or speak with people. Avoid disclosing sensitive information like financial details, and trust your gut if something feels off. It’s also useful to review your profile’s privacy settings and information now and again to make sure you’re still comfortable sharing what you’ve listed there.

Good privacy decisions begin with proper knowledge about your situation and a community-oriented approach. To dig in deeper, read EFF’s blog post on Building a Community Privacy Plan and the Trevor Project’s Guide to Online Safety for LGBTQ+ Young People.

Paige Collings

EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity

3 days 19 hours ago

EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil's elections. The recommendations stress the close relationship between violations of personal data protection and challenges to the integrity of electoral processes. They underscore how privacy and data protection guarantees are a crucial tool for curbing the targeted spread of false or manipulative content and other problematic strategies used by political actors that are amplified by digital technologies such as artificial intelligence systems. 

The recommendations are part of a broader regional initiative and build on the legal and institutional safeguards already in place in Brazil. They seek to promote greater coordination among oversight institutions, civil society, and digital platforms, and encourage the solid implementation of privacy and data protection guarantees as drivers of electoral integrity. Read the full document below. 

The Link Between the Integrity of the Electoral Process and Privacy 

Protecting the integrity of the electoral process in the face of internet and social media use is a challenge that many policymakers are addressing or are willing to address. Online, content that can affect the integrity of the electoral process is increasingly personalized. This phenomenon is so concerning that it has been identified as one of the main global short- and medium-term risks

In an era of generative AI, the economic cost and technical difficulty of producing and spreading false or synthetic content to deceive, manipulate, or simulate authenticity have been considerably reduced. That intensifies concern over the integrity of the electoral process. Meanwhile, online privacy and personal data protection remain unfinished business in Latin America. 

There is an intrinsic connection between the ability to collect and process large amounts of personal data and the way false or manipulative content is created and distributed—on social media and messaging apps in particular, and on the internet in general. For this reason, applying strict laws and policies on personal data protection and privacy makes it possible to reduce the impact of false or manipulative content. This is especially important in electoral contexts, where such content affects and impoverishes public debate, directly affecting political and electoral rights and the integrity of the electoral process. 

This phenomenon predates the emergence of the internet. However, the rise of new technologies accelerates the generation and spread of false and manipulative content. This is supported by the very economic model that sustains the platforms, amplifying its effectiveness and reach. On the one hand, social media platforms have content recommendation algorithms that use personal data to generate profiles to which they can then serve targeted advertising content, including explicitly political propaganda. This technique is known as "microtargeting." 

Political microtargeting seeks to have a direct or indirect impact on democracy. It is used to persuade voters, to encourage or discourage turnout at the polls, or to raise funds using information that is deliberately taken out of context, inaccurate, or erroneous. 

The control exercised by these companies raises serious concerns about people's rights. By having access to massive amounts of personal information, these companies have the ability to shape the content that users see and interact with. This happens through the construction of profiles that can reveal habits, social relationships, political preferences, and opinions, to mention a few examples. Personal data is the fuel that amplifies risks to the integrity of the electoral process. That’s true whether it’s provided by the users themselves or generated by the platforms from their interactions online. 

For disinformation actors, access to sophisticated tools—such as those used to create "deepfakes" through generative AI, or "bots" programmed to spread content and seek to manipulate public opinion—boosts the effectiveness of this microtargeting in terms of quality and scalability, making it harder to detect as false or manipulative content. AI-generated avatars and synthetic characters that simulate voters, influencers, hosts, commentators, or community leaders can produce footage that appears spontaneous, fabricate the voices of artificial political actors, and make it harder for users to identify if a given public statement was created or mediated by technology. 

In this context, paid promotion with nanotargeting seeks to reach increasingly specific profiles with customized content, and AI-based tools are used to assess and map its impact on social networks. Drawing on the personal data of groups of voters, profiles of "synthetic voters" are created to test messages or strategies in search of the most efficient way to influence real voters. 

This rapid expansion of AI systems and hyper-personalization with data can lead to a problem of "epistemic erosion" for democratic societies, as pointed out by the UN's Independent Scientific Panel on AI Governance in 2026. 

At Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation, we point to the enforcement of personal data protection laws and public privacy policies as an efficient mechanism for improving the quality of our democracies and reducing the manipulation of public discourse in digital environments and its impact in electoral contexts. Measures to broaden access to information for electoral decision-making, and to ensure transparency about campaigns' and political parties' use of digital technologies built on the massive processing of personal data, also play a relevant role in guaranteeing the integrity of the electoral process. 

Recommendations for Safeguarding the Integrity of Electoral Processes in Brazil in the Face of New Technologies 

Concern about the effects of spreading false, manipulative, or deliberately decontextualized content is particularly heightened in electoral contexts. From Argentina to Mexico, many countries in Latin America, including Brazil, are holding or will hold significant electoral processes in the coming period. 

Providing the public with quality information from a range of sources is an essential element for the exercise of political rights. In order to safeguard the electoral process, these countries must enforce their privacy and personal data protection laws through their competent authorities, in coordination with their judiciaries and electoral courts. 

Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation propose the following recommendations to protect the integrity of the electoral process by guaranteeing privacy and data protection during electoral contexts: 

1. Strengthen personal data protection guarantees and policies as a key element for the integrity of the electoral process, in particular the principles of necessity, purpose, and proportionality:

  • Prohibit the processing of sensitive personal data (such as philosophical beliefs and the labeling of ideological leanings), including inferred data, that reveals or could reveal people's political preferences for the purpose of targeting political content. In electoral contexts, the processing of sensitive personal data is only legitimate when the person has given their consent in advance, explicitly, and with strictly limited and clearly disclosed purposes of use and transfer. 
  • Processing must be carried out only on personal data that is strictly necessary for the purpose being pursued. 
  • Prohibit adding users to instant messaging groups for political outreach purposes, except in exceptional cases involving lists of political party members or where prior and informed consent has been given by the data subject. 
  • Free, specific, and informed consent means that the person is able to make a real choice, set apart from other choices, and does not run any risk of deception, intimidation, coercion, denial of access to products or services, or other significant negative consequences if they do not give their consent. 

2. Political parties, federations, and coalitions must improve the information made available to the general public about their personal data processing activities in electoral contexts, including: 

  • The personal data processing policy adopted, in compliance with data protection legislation and electoral legislation, including the measures adopted to prevent breaches of the general protection principles, to record personal data processing operations, to obtain consent appropriately, and to ensure technical and administrative security in data processing; 
  • Communication channels where the data subject can obtain information about the processing of their personal data, exercise the rights provided by law, and request to opt out of receiving electronic and instant messages. 
  • Information about the profiling they carry out for electoral purposes and about the procurement and use of data-based digital technologies in this context, including for purposes of paid promotion, microtargeting, network analysis, and prediction of voters' reactions or behavior. 

3. Strengthen cooperation mechanisms between the National Data Protection Authority (ANPD) and the Superior Electoral Court in order to: 

  • Improve communication channels and strengthen joint initiatives to oversee compliance with data protection guarantees in the electoral context, with the publication of periodic enforcement reports. 
  • Identify and dismantle coordinated strategies that compromise the integrity of the electoral process and carry out online activities that pretend to be "organic" and citizen-based when they are in fact funded or coordinated by a party, government, or company, such as bot farms, fake personal accounts managed by a single entity, AI avatars and synthetic characters that simulate real voters in order to manipulate public opinion, among others. 
  • Within the scope of their powers, require the preparation and publication of a data protection impact assessment in cases involving the use of sensitive personal data or emerging technologies for voter profiling. 

4. Authorities, political parties, communicators, and social media platforms must ensure, as far as possible, that the population has access to adequate and relevant information for electoral decision-making. 

  • Political parties, electoral authorities, and data protection authorities must allocate a percentage of their communications budget to warning about the consequences of microtargeting in electoral contexts; and about the use of AI avatars or synthetic voters to simulate support, rejection, outrage, or spontaneous political mobilization. 
  • Strengthen alliances with fact-checkers and other relevant communicators, such as civil society organizations, influencers, and others, to identify campaigns that compromise the integrity of the electoral process and to inform the public about such alliances through different channels, including official government channels.
  • Systematize the electoral proposals developed by candidates and their electoral platforms according to thematic areas to facilitate comparison between political parties. 
  • Agree on strategies between authorities and online platform companies, including social media platforms and chatbots, at the start of electoral periods, so that priority is given to content developed by electoral authorities. 
  • Every body, protocol, or policy created that involves authorities or public entities must be communicated in accordance with proactive transparency standards. 

5. Platforms must disable microtargeting tools for political and electoral content during previously established periods. 

6. Authorities, technical actors, academics, civil society, and/or social media platforms must collaborate in creating an algorithmic impact analysis lab that makes it possible to oversee compliance with these recommendations. 

  • Produce reports on the results achieved, in particular those that document the existence of microtargeting, the use of personal data for targeting, and exposure to varied content in electoral contexts. 
  • Establish strict cybersecurity protocols so that the labs prevent access to real users' private information. 

7. The authorities responsible for overseeing personal data protection and electoral matters must have sufficient functional, economic, and technical autonomy and independence to guarantee the proper exercise of their powers. 

Veridiana Alimonti

A List of ICE Subpoenas to Tech Companies

5 days 1 hour ago

Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.

A favored tool in these speech chilling investigations are administrative subpoenas sent to technology companies, requesting basic subscriber data about their users. For example, from 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter (now X), according to documents obtained by Just Futures Law. In just the second half of 2025, the Department of Homeland Security (DHS) sent 21 administrative subpoenas to Reddit, according to its Transparency Report.

While some subpoenas are routine, ICE has been forced to withdraw others after users challenged them in court or companies pushed back. These challenged subpoenas exceeded the agency's statutory authority and violated users' First Amendment rights.

Below is a non-comprehensive list of DHS subpoenas that we gathered going back to 2025, looking at public reporting and court cases. This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report (so far, only Reddit appears to break out specific numbers on DHS subpoenas). In addition, DHS has been slow to respond to our Freedom of Information Act requests and lawsuits seeking records that would show how many administrative subpoenas ICE has sent to social media companies since 2025.

If you know of other subpoenas that are not on this list, please reach out to info@eff.org. While the government has abused the subpoena process in other areas, particularly to hospitals, this list focuses on DHS and ICE subpoenas to technology companies for user data. 

DATE ISSUED

(and link to subpoena)

TARGETED COMPANY INDIVIDUAL USER TARGETED  OUTCOME  3/17/25 Facebook  Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 3/23/25 Google  Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 4/1/25 Google  Amandla Thomas-Johnson, international student who attended pro-Palestinian protest Google disclosed data to ICE on 5/8/25 9/4/25 Meta  6 accounts in Southern California that documented immigration activity, including LB_Protest, Long Beach Rapid Response Network, and Stopice.net Withdrawn after court challenge on 11/24/25 9/11/25* Meta (Instagram) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 9/11/25* Meta (Facebook) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 10/30/25 Google  Retired Philadelphia user who emailed criticism to U.S. prosecutor   Withdrawn after court challenge on 2/5/26 2/4/26* Google Social media user who regularly posts criticism of the President Subpoena challenged in Court 2/19/26* Reddit "Tired_Thumb," user who posted about ICE officer Withdraw after court challenge on 3/27/26; replaced with grand jury subpoena 2/27/26* X "podslurp,” who posted publicly available address information about ICE officer Withdrawn May 2026; replaced with grand jury subpoena 3/7/26 PayPal/Venmo "Voices of Racial Justice," a racial justice organization in Minnesota  PayPal/Venmo disclosed data 3/20/26 4/3/26* Google (YouTube) @TheDonLemonShow, GeorgiaFort, @DemocracyNow, and seven other accounts that reported on protest at Minnesota church Google Objected 4/7/26 4/12/26* T-Mobile Minnesota journalist Georgia Fort and others T-Mobile disclosed data on 4/12/26 First half of 2025 Reddit  Reddit account Subpoena withdrawn after questions from Reddit Second half of 2025 Reddit  11 Reddit accounts that posted content "critical of ICE actions" 3 subpoenas withdrawn after Reddit objected

* = denotes summonses issued under 19 U.S.C. 1509, an authority that has been abused in the past, according to DHS's inspector general.

Mario Trujillo

EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms

5 days 5 hours ago

Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool that can be made safe with the right policy or feature update—they are irredeemably harmful.

EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines.

EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines. EFF applies every tool available to eliminate ALPR surveillance and the harm it enacts.

The Case Against ALPRs

A note about scope: This post addresses ALPR mass surveillance. It does not address the wider universe of automated traffic enforcement (ATE) such as conventional red light and speed cameras that solely ticket a specific violation, without retaining or networking data on uninvolved drivers. But lawmakers and purchasers should guard against efforts by vendors to piggyback on ATE contracts to market ALPR mass surveillance systems.

ALPRs are frequently marketed as a narrow tool for specific purposes, such as recovering stolen vehicles. But in practice, these sensors sweep up data on every driver who passes a camera, and store it in searchable databases. That indiscriminate collection and retention is precisely why ALPR-fed surveillance systems can be easily weaponized against immigrants, political dissidents, and other targeted communities as ICE and other federal agencies escalate their assault on civil liberties. There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it.

Of course, ALPRs cause other predictable harms. Innocent drivers are recurringly arrested and menaced by police because of ALPR errors. Officers regularly abuse ALPR systems to stalk past and potential romantic partners. Creating any database of personal information—including ALPR surveillance databases—inherently creates risk of data theft and subsequent harm to data subjects. And ALPR surveillance of protests and targeting of activists chill participation in First Amendment-protected dissent. But even if these downstream harms could all be prevented (and they likely can’t), ALPRs would remain an intolerable form of mass surveillance.

Fighting on Every Front to Eliminate ALPR Surveillance

At the city level, EFF works with community members and decision makers to outright refuse ALPR purchasing. ALPRs are not inevitable. The same decision mechanisms used to facilitate runaway surveillance purchasing in U.S. localities can be turned against these systems to dismantle them.

EFF also pushes state legislatures to establish strict state-level limits on ALPR surveillance, such as data-deletion rules and use restrictions. Building such constraints into statute can mitigate the harms of existing ALPR systems.

In courts across the country, EFF files amicus briefs arguing that warrantless police searches of ALPR databases violate the Fourth Amendment. In California state court, EFF and the ACLU of Northern California are suing on behalf of two community groups, SIREN and CAIR-CA, arguing that the San Jose Police Department's practice of letting officers search stored plate data—to the tune of over 100,000 times a year—without a warrant violates the California Constitution. We’ve also sued to block California law enforcement from sharing ALPR data with federal and out-of-state agencies, in violation of a California statute.

A big part of EFF’s work is exposing the harms of ALPR surveillance. Our investigative team tirelessly collects information about how law enforcement uses ALPRs with public records requests, sues to enforce such requests, and publishes reports about them. We’ve also successfully lobbied for a State Auditor investigation of law enforcement’s use of ALPRs.

Coordinated Action Against Mass Surveillance

EFF practices integrated advocacy because all of these tools work best together. City refusals, statehouse restrictions, impact litigation, and investigative activism are different levers EFF pulls toward the same end: eliminating ALPR surveillance, and building the durable public power needed to keep it off our streets. A council vote against a Flock contract and a warrant argument in Santa Clara County Superior Court are both, at their core, the same fight: rejecting mass surveillance infrastructure outright, and using every venue available to eliminate its harmful presence and consequences.

Sarah Hamid

EFF Statement on Meta Settlement

5 days 6 hours ago

Under this settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta's harmful surveillance into law, and it will compromise users' privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care. 

David Greene

French Top Court Gets It Right, Strikes Down Social Media Ban For Youths

5 days 8 hours ago

Earlier this month, France’s top court struck down the country’s legislation that banned social media use for people under 15 years old, which had been scheduled to take effect in January 2027. This is a welcome win for free expression, as we face a wave of countries and U.S. states seeking to pass similar laws banning young people from social media. 

In particular, the Constitutional Council’s decision focused on two components:

Infringement on Free Expression

The Council ruled that the legislation banning under-15s from social media infringed on freedom of expression and communication in a manner that is not appropriate, necessary, or proportionate, which is required by Article 34 of the French Constitution. In particular, it stressed that the ban did not distinguish between different types of online services, and ignored the circumstances of individual users, such as their exact age, level of maturity, and family situation.

The evidence is clear: these are reckless and harmful laws that negatively impact all people, not just those under 15. These measures chill all users’ exercise of the right to free speech and expression online by imposing obstacles on sites or by wrongfully blocking people’s access outright.

By forcing young people into digital isolation, these bans curtail vital access to news and resources for health and development; especially for LGBTQ+ and marginalized youth as social media can often be the only place to find community, explore their identity, or access life-saving resources. They also completely ignore the calls of young people themselves who favor digital literacy and education over surveillance and government control. 

These bans also destroy the right to online anonymity—a cornerstone of our right to free expression that in particular protects whistleblowers, journalists, activists, and immigrants.

Infringement on the Right to Private Life 

The Council’s second objection noted that the law requiring every person, even adults, to prove their age before accessing social media platforms impedes the right to private life, and thus infringes on Article 2 of the Déclaration de 1789.

The French Council gets a lot right in this decision: it highlights that bans like this impact not just young people, but everyone online. They force people of all ages to hand over government IDs, face scans, and other sensitive information into a growing surveillance ecosystem. Further, when parental consent is required, companies must collect even more verification data on the parents.

We know that when people are forced to hand over this information, age verification systems frequently misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their appearance; adding to the privacy concerns around these bans.

Next Steps 

As all bills in France are subject to scrutiny by the Constitutional Council to ensure compliance with the French Constitution, French President Emmanuel Macron has tasked Prime Minister Sébastien Lecornu to re-work the legislation with a goal to adopt a ‘legally robust’ version of the social media ban. 

Public policy must be effective, proportionate, and respectful of fundamental rights; and the ruling by the Constitutional Council has ramifications beyond France. It sends a message of caution to Brussels, where the EU Commission is working on an EU-wide bill on access restrictions. These legal restrictions would likely require problematic age verification of users. The prominent EU digital identity wallet and the “mini” age verification app, presented as privacy-robust options, instead raise serious privacy and security concerns.

Young people deserve better than a policy built on panic, and all internet users deserve a safe and free internet that includes measures to empower all people with the knowledge they need to navigate online spaces safely. A social media ban generates headlines, but it will not solve the problem. 

Paige Collings

EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition

1 week 3 days ago

This week, EFF, along with Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch, and Stopwatch, wrote to Nottinghamshire Police Force in the UK raising concern about the proposed roll-out of live facial recognition technology (LFR), and called for its immediate halt.

In particular, the letter highlights six concerns:

LFR Is Not "Just Another Tool"

Nottinghamshire Police has stated that “facial recognition is just another tool to fight crime.” But LFR used in public spaces is an incredibly intrusive biometric mass surveillance technology that scans the faces of everyone who walks past the camera and takes biometric face prints. This is not just another tool, but a major escalation of surveillance that treats everyone as a suspect by default.

People Having "Nothing to Worry About" Does Not Hold to Scrutiny 

According to Nottinghamshire Police, “if you aren’t entering the city or county to commit crime then you have nothing to worry about.” However, many people have legitimate concerns about the normalisation of invasive technologies. So a public that cannot move around their towns and cities without being subjected to a biometric identity check may be less willing to seek medical care or legal advice, speak with journalists, act in a union, vote, protest, or express their gender, sexual or religious identity. 

Disproportionate Targeting With LFR

We are particularly concerned to learn that Nottinghamshire Police could deploy LFR to tackle low level crimes, such as youth behavior deemed anti-social, as part of Operation View. Reporting suggests that the force already possesses “a watchlist of young people believed to be causing the most problems,” including children as young as 11 years old. It would be highly disproportionate to deploy live facial recognition to tackle this behaviour. Many of these children are reportedly known to the police, and it is highly likely that there are more proportionate means for locating them. 

LFR Could Increase Social Problems

We are also concerned that Nottinghamshire Police has not adequately examined the distinct risks of using LFR to target children, including negative impacts on their behaviour and outcomes, risk of recidivism, and relationship with the police. Use of LFR could exacerbate behavioural problems in children and create an adversarial, rather than trusting, relationship with the police from a young age. 

Lack of Public Support 

Recent polling commissioned by Liberty indicated that 48% of people oppose scanning the faces of those walking on high streets when there is no suspected imminent threat. Furthermore, Opinium found that the majority of people oppose the use of facial recognition in schools. Likewise, a report by the London Policing Ethics Panel found that Londoners aged 16-24 were most likely to find the Metropolitan Police Service’s use of LFR unacceptable and most likely to stay away from events where LFR was in use.

On these grounds, Nottinghamshire Police must immediately halt their plans to use live facial recognition surveillance any further.

Read our full letter here

Paige Collings

Intermediary Liability in Brazil: The Intricate Path Ahead

1 week 3 days ago

Brazil's new internet intermediary liability regime is underway. The implementation of changes established by the Supreme Court includes notice and takedown mechanisms and duty of care obligations. Caution is crucial as these measures can create problematic incentives for enforcement overreach and over censorship of protected speech.  

The court in June issued a new decision clarifying elements of its 2025 finding that the previous liability regime was partially unconstitutional. The government also published in late May two presidential decrees that detail how the new rules apply. 

Under the new regime, social media platforms and other internet applications that curate or interfere with posts can be held liable for third-party content if they don’t remove it after being notified by the user seeking take down unless there's a reasonable doubt that the content is unlawful. For certain specific cases, like crimes against honor (e.g. defamation), platform liability still depends on failing to comply with a judicial order.  

For some serious crimes, like human trafficking and crimes against women, applications have a duty of care to remove related content immediately and can be held liable when systemically failing to do so. The precise limits of what constitutes a systemic failure are still unclear. There are also stricter rules for paid ads, boosted content, and bots. 

The previous regime, set by Article 19 of the law known as the Brazilian Civil Rights Framework for the Internet (“Marco Civil da Internet” in Portuguese), sought to protect freedom of expression online by holding internet application providers liable for user content if they failed to comply with a judicial order to remove it. There were specific, limited exceptions to this rule, like the unauthorized disclosure of nude or private sexual images. This was meant to prevent providers from over-removal of user content to avoid legal action. Yet, the court found that this provision failed to sufficiently safeguard democracy and fundamental rights. 

We outlined the thorny context leading to this shift in Brazil’s intermediary liability rules, including Big Tech’s alignment with the far right and hurdles to approve platform regulation in Congress, through a proper legislative process. 

Brazil’s shift is part of broader discussions and changes in response to growing concerns over online harms and digital platforms’ abuses. However, responses focused on platforms’ liability of user-generated content carry important traps and risks—from entrenching dominant platforms’ power over the information flow to escalating arbitrary online surveillance and censorship. The path ahead must prevent this to the extent possible, and the new presidential decrees provide a mixed contribution towards this task. 

New Decrees: Strengths and Flaws  

The government published two decrees regulating the new regime set by the Supreme Court. One introduces changes to its previous regulation, the Decree 8.771/2016, detailing elements of the decision, including additional duties that the court only briefly addressed (Decree 12.975). The other regulates measures to tackle violence against women online (Decree 12.976). 

The Supreme Court's decision didn't establish guidelines to protect users' due process rights when facing content take down and removal demands. Instead, it relies on providers to self regulate, which could lead to over censorship.  

The decrees’ provisions on user notification systems are helpful in this sense. They stipulate that providers must inform users (both the notifier and the content author) about the decision to remove or keep the content up, why, and the means to appeal. The guidance makes explicit that a platform may reconsider and reinstate content after an appeal and must explain its reasons to the party requesting removal and content author. The decrees also address concerns with the weaponization of notification systems, establishing that internet applications must adopt measures to prevent abuses. 

Decree 12.795 reinforces that applications can keep content up after notification when there’s reasonable doubt that the post is unlawful, stating that the analysis should consider the context of the publications, freedom of religion and belief, and any informational, educational, or critical, satirical, or parodic purpose with the aim of ensuring freedom of expression. With these guidelines, it aims to mirror the Digital Services Act's "notice-and-action" approach. Moreover, for sexual related, intimate content, platforms will provide a specific and easily accessible notice channel where victims or their representatives can follow the case. 

One of the most concerning provisions requires applications to proactively report content related to criminal conduct on their platforms to government authorities. Applications must send the post along with information that can identify the user. The Ministry of Justice will regulate this provision, something the Supreme Court didn't touch on in its decision. While it seems to apply just to those providers already required to comply with new content-related obligations (exempting email and videoconference providers, for example), it takes a disastrous step beyond. It’s not only about preventing the spread of unlawful content online; it gets platforms to police and report users to authorities by handing identification information apparently without a court order. 

Decree 12.795 also details the definition of messaging applications that are exempt from notice and duty of care obligations. It excludes features for public dissemination of content and open groups so that the exemption doesn't apply. It's still unclear what exactly open groups mean. Especially regarding end-to-end encrypted applications, it's crucial that duties to monitor and take down don't affect conversations that are under this security architecture. Perhaps more troubling, the Supreme Court stated in its clarification ruling that a judicial order can determine email, voice and video conference, and messaging providers to take down content of private communications. Any measure must respect privacy and free expression safeguards and refrain from undermining end-to-end encryption. 

Furthermore, decree 12.976 importantly addresses the protection of women online, but it contains a broad definition of online violence against women that will guide how platforms handle takedown notices they receive. This definition involves "any act, conduct, or omission that causes (...) psychological, political, or economic suffering (…) in any aspect of their lives, committed, instigated, facilitated, or aggravated, in whole or in part, by the use of digital technologies." Its breadth could unfortunately result in censoring legitimate criticism and other protected speech, which platforms and authorities must avoid. 

The decrees also establish powers to the Brazilian Data Protection Agency (ANPD) to oversee and regulate the new regime. Among controversies, the decrees give ANPD the power to apply penalties for breaches of content-related obligations. These obligations go beyond agency competencies set in the Data Protection Law and the Law 15.211/2025, focused on the online protection of children and adolescents. They are also not clearly covered by Article 12 of Marco Civil as it stipulates administrative penalties for violations of its data privacy provisions.  

We appreciate that ANPD has been open to civil society's demands and concerns. While it’s crucial that the agency conducts its oversight role preserving a proportionality commitment and keeping solid participation channels, sanction powers must be prescribed by law. 

Alerts for the Path Ahead 

It’s true that there are critical platform accountability problems we must address, especially regarding the big players. And yes, platforms should align their policies and practices with human rights standards, including by dealing diligently with the dissemination of unlawful, toxic content. But accountability efforts should look at platforms’ systems and processes and promote measures to put checks on the power of tech giants, instead of having a prevalent focus on policing and reporting user behavior.  

Key digital competition measures to regulate gatekeeper platforms are under discussion in bill 4675/2025, but the proposal is pending in Congress with no clear timeline for approval.  

One important measure is to ensure accountability of take-down requests, including by the government. The Supreme Court’s decision stipulated that internet applications should publish transparency reports of the removal notices they receive. Government institutions should follow suit by periodically disclosing aggregate data of their own requests to online platforms, covering various types of user data and demands for content and account restrictions. Back in 2016, Marco Civil’s regulation decree established that all federal bodies must annually publish statistical reports on their requests of subscriber data to providers. To the best of our knowledge, federal bodies generally fail to meet this provision. ANPD can play a crucial role in stepping up transparency in the implementation of the new rules. 

Ultimately, platform accountability under the new liability regime hinges on how accountable its application will be by platforms and state institutions, and on the regime's commitment to protecting fundamental rights, including freedom of expression and privacy.  

  

 

Veridiana Alimonti

Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.

1 week 5 days ago

In a handful of known cases, large social media companies have privately pushed back against Immigration and Customs Enforcement (ICE) subpoenas when the agency tried to unmask anonymous users who tracked immigration activities or criticized the government.

As ICE engages in a pattern of illegal and chilling investigations, any resistance is welcome. But social media companies can do more. When companies receive these unlawful subpoenas, they should be clear with the public that they will not hand over the data unless a court compels them to do so. In addition, companies themselves can take the government to court to challenge these unlawful subpoenas on behalf of their users.

ICE has sent hundreds of subpoenas to large technology companies like Google, Meta, and Reddit.

Publicly challenging these unlawful subpoenas in court has the dual purpose of protecting individual users who may lack the resources or know-how to challenge a subpoena on their own, while also discouraging ICE from issuing similarly unlawful subpoenas in the future.

Companies have a responsibility to protect the privacy of their users. That responsibility does not end simply because companies wish to avoid the ire of this administration—which has sought to chill other powerful institutions like news outlets, law firms, universities, and non-profits.

ICE Has Issued Many Unlawful Subpoenas

ICE has sent hundreds of subpoenas to large technology companies like Google, Meta, and Reddit seeking basic subscriber information like name, email address, IP address, and session times.

Some of these subpoenas have targeted people who engaged in protected activity—like tracking immigration actions, criticizing the government, or attending a protest. People have a First Amendment right to document law enforcement activities and criticize the government online, without retaliatory government investigations. This right has become more important as immigration agents have engaged in invasive, unconstitutional, and sometimes violent conduct.

In a handful of cases, users themselves have successfully pushed back. After receiving notice of these subpoenas, users have challenged them in court, relying on pro-bono lawyers from groups like the ACLU or Civil Liberties Defense Center. Companies have been largely absent from these court proceedings.

Private Pushback from Meta and Reddit

While not appearing in court, companies like Meta and Reddit have sometimes pushed back behind the scenes.

For example, on September 11, 2025, ICE sent administrative subpoenas to Meta seeking to unmask users who ran Instagram and Facebook accounts that tracked immigration activity in Pennsylvania. On September 19, 2025, Meta’s Law Enforcement Response Team told ICE that the agency did not have the “statutory authorization” to seek the records. It asked for more detail about the investigation and said “Meta will take no further action with respect to this summons until it receives this information.” Later, Meta informed ICE that it planned to notify the users about the subpoenas, since no gag order had been obtained. The government disclosed this information in one of EFF’s Freedom of Information Act lawsuits against ICE and other agencies.

On October 3, 2025, Meta notified the user about the subpoena. Despite its private pushback, Meta told the users it would comply with the subpoenas unless they mounted a court challenge within 10 days—which they did with the help of the ACLU. Ultimately, ICE withdrew the subpoenas when it became likely that ICE would lose the case in court.

In another example, Reddit documented its pushback in a transparency report released a few months ago. Reddit reported that in the second half of 2025, the company received three Department of Homeland Security (DHS) subpoenas seeking account information from 11 users who posted content critical of ICE. In the report, the company stated that “Reddit objected to these legal demands because the users appeared to be engaged in protected activity under the First Amendment, and law enforcement withdrew their requests.” The company reported that most other DHS subpoenas it received appeared to be routine.

A Tech Company Model for Public Resistance

EFF’s demand that technology companies do more to protect their users is not unprecedented. Twitter (now X) did so successfully in the first Trump administration.

On April 6 2017, Twitter went to court to challenge a DHS subpoena that sought to unmask a Twitter account named “@ALT_USCIS,” which frequently criticized the administration’s immigration policies. Twitter challenged the subpoena on both statutory and First Amendment grounds. A day later, DHS withdrew the subpoena and Twitter dismissed the case. The incident led to an inspector general investigation, which criticized a tactic that DHS is still engaged in.

In other circumstances, companies have also gone to court to protect their users and shield themselves from burdensome legal process. In 2013, Microsoft challenged a search warrant for the content of emails stored on servers outside the United States. In 2015, Apple challenged a court order to break the security of its iPhone during an investigation into the San Bernardino shootings. And in 2007, Yahoo challenged the constitutionality of government requests at the Foreign Intelligence Surveillance Court.

Mario Trujillo

📍 The Sneaky Code Tracking App Users | EFFector 38.15

1 week 5 days ago

Your location isn't just a pin on a map—it can expose some of the most intimate details about your life. The value of this information to advertisers and others has turned the location data business into a multi-billion dollar industry. In our latest EFFector newsletter, we're covering a new EFF report on how ad libraries encourage apps to leak user location data—potentially without app developers themselves even realizing it.

JOIN OUR NEWSLETTER

For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers what recently announced Flock reforms actually do, privacy-invasive legislation advancing in the Senate, and an EFF investigation into mobile ad software.

Prefer to listen in? EFFector is now available on all major podcast platforms. This time, we're covering EFF's new report on mobile ad libraries and chatting with EFF Executive Director Nicole Ozer about how digital rights have become fundamental to our lives. You can find the episode and subscribe on your podcast platform of choice:

%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2Fbaf87477-9c26-4b51-8f00-b0465a2606d1%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E Privacy info. This embed will serve content from simplecast.com

   

Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!

Hudson Hongo

Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230

1 week 5 days ago

A federal appeals court just made it harder for online services, big and small, to get lawsuits over user speech dismissed early. In California v. Meta, a Ninth Circuit three-judge panel held that the lower court’s denial of Section 230 immunity to Meta is not immediately appealable. The misguided ruling has the potential to have widespread impact and to threaten the free speech of all internet users.

The ruling is bigger than a loss for Meta, which has the resources to defend itself against these lawsuits. The court’s ruling signals that all online services (and internet users) that host others’ speech—including those without Meta’s deep pockets—must bear the burden and expense of fighting lawsuits that Section 230 ultimately precludes. This will have real consequences, incentivizing online services to take down users’ speech in response to spurious legal threats, filter speech preemptively, or simply stop offering a place for people to speak online. So even though some may think that Meta is not a sympathetic company, the ruling should raise concerns for anyone who cares about an open and free internet.

Immunities from Suit Advance Important Public Interests

A little procedural background is necessary to understand the implications of the Ninth Circuit’s ruling.

Meta had moved to dismiss a group of social media addiction cases brought by state attorneys general, school districts, and local governments. Meta argued that Section 230(c)(1) immunity applies because the plaintiffs’ claims, framed as seeking to hold Meta liable for allegedly harmful platform features, really seek to hold the company liable for publishing decisions related to third-party content. Section 230 is one of the most important laws supporting online free speech, because its protections for online services enable them to distribute users’ speech at an unprecedented scale.

The district court ruled that Section 230 does not apply to certain features (and does apply to others) and so denied the motion to dismiss on the claims related to those features. Meta immediately appealed invoking appellate jurisdiction under 28 U.S.C. § 1291, but the question before the Ninth Circuit was whether the appeal was legally appropriate.

Under Section 1291, U.S. circuit courts generally only have jurisdiction to hear appeals of “final decisions” from the district courts. Final decisions are trial court orders ending a case, or come after a trial on the merits. Section 230 appellate cases often arise from a district court’s grant of a defendant platform’s motion to dismiss the plaintiff’s case based on Section 230. Typically, a district court’s denial of a defendant’s motion to dismiss is not a final order—it simply means that the case may continue to discovery and summary judgment or trial, after which time an appeal would be appropriate.

However, federal law allows for “interlocutory appeals,” which are appeals of orders that do not end a case but nonetheless are allowed because they involve important legal issues. For example, there is an exception to Section 1291 called the “collateral order doctrine”—at issue in this case—allowing for immediate appeal if, as the Ninth Circuit explained here, “holding a trial would imperil a substantial public interest.”

Inherent in the collateral order doctrine is the consideration of whether an immunity like Section 230 provides mere “immunity from liability” or a more robust “immunity from suit.”

An immunity from liability does not require an immediate appeal and so demands that Section 1291’s final order rule be followed. That’s because waiting until the end of a case before an appellate court can consider the trial court’s denial of immunity does not prejudice the defendant. The appellate court may overturn the trial court and grant the immunity, and thus the defendant’s right to be immune from liability would be vindicated on appeal.

Immunity from suit is different. It means that the public interest demands that a defendant be able to get out of a case as early as possible and avoid having to litigate the case to the end. The U.S. Supreme Court has held, for example, that qualified immunity is such an immunity, and that a district court’s denial of qualified immunity for a government official is immediately appealable under Section 1291, notwithstanding the lack of a final order. The idea is that the public interest is served when government officials are free to act without fear of consequences when established rights are not implicated, and so determining as soon as possible whether their acts are immune serves that public interest.

Here, the Ninth Circuit held that the district court’s denial of Section 230 immunity for Meta was not immediately appealable under Section 1291’s collateral order doctrine because the immunity is not from suit, but rather from ultimate liability. The panel’s absurd result contravenes the text of Section 230, the statute’s policy goals, and the court’s own prior rulings.

Treating Section 230 as an Immunity from Suit Protects Online Free Speech

Meta rightly argued that Section 230(e)(3) plainly states, “No cause of action may be brought and no liability may be imposed under any State or local law that is inconsistent with this section.” The panel dismissed this argument, stating that this language likely amounts to “redundancy” reflecting only immunity from liability. The court failed to side with the more reasonable position that statutory language should generally not be interpreted as superfluous.

Meta also reminded the panel that the Ninth Circuit has many times over the past two decades framed Section 230 as both an immunity from liability and an immunity from suit. The panel also dismissed this argument, stating, “It is true that we have used the phrase ‘immunity’ somewhat loosely in our section 230 jurisprudence.”

But “loosely” is a gross mischaracterization—the panel did not discuss a seminal prior ruling, Fair Housing Council of San Fernando Valley v. Roommates.com (2008), in which the entire Ninth Circuit, not just a three-judge panel, explicitly ruled that Section 230 is also an immunity from suit. That court rightly explained that Section 230 “must be interpreted to protect websites not merely from ultimate liability, but from having to fight costly and protracted legal battles.”

Why is it important that social media platforms and other internet intermediaries (and their users) have immunity from suit for engaging in publishing activities related to third-party content—and thus a right to immediately appeal when Section 230 immunity is denied?

The Ninth Circuit panel here, using their own words, failed to “evaluate the interests that would be lost through rigorous application of a final judgment requirement” and failed to consider the “substantial public interest” served by treating Section 230 as an immunity from suit.

Section 230 immunity, contrary to what some argue, is not a gift to Big Tech—it applies to all internet intermediaries, big and small, from the large social media companies to smaller entities like community message boards and local ISPs. It even protects internet users who forward others’ emails or host comments on their blogs. In turn, the law supports the free speech of all internet users.

While it is helpful when an internet intermediary can ultimately benefit from Section 230 immunity, if a trial court’s early denial is not immediately appealable, that means the intermediary must bear the extended logistical and financial burdens of defending itself. Under the Ninth Circuit’s logic, anyone hosting others’ speech online would have to endure the pain and expense of discovery, summary judgment, or trial, before they ultimately can be protected by Section 230.

Congress crafted Section 230 to give internet intermediaries legal breathing room, so that they will be incentivized to facilitate online communication and commerce, allowing the rest of us to go online with minimal barriers to entry, without needing to have loads of money or to know how to code. Congress acknowledged in Section 230 itself, “Increasingly Americans are relying on interactive media for a variety of political, educational, cultural, and entertainment services.”

Yet if platforms, especially smaller platforms, know that they will have to defend themselves for years in court before they can ultimately benefit from Section 230 immunity, this alone will create a perverse incentive, as we have explained, to censor user speech, in order to reduce the platforms’ legal exposure. And this incentive is only exacerbated at scale, where the sheer volume of user-generated content hosted by modern platforms makes legal risk astronomical.

Unfortunately, this opinion seems to be part of larger trend reflecting the Ninth Circuit’s increasing disdain for Section 230, and apparently for free speech rights more broadly. The court similarly held last year in Gopher Media v. Melone (2025)—overruling itself—that a trial court’s denial of a defendant’s anti-SLAPP motion also is not immediately appealable under the collateral order doctrine. This is despite the fact that, similar to Section 230, California’s anti-SLAPP law is intended to allow defendants to get harassing lawsuits meant to silence them dismissed early, lest they be chilled from engaging in lawful speech on public issues due to the risk of being mired in litigation, even if they ultimately win a delayed appeal.

Sophia Cope

Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets

1 week 6 days ago

Age verification (laws and regulations requiring platforms and websites to assure or estimate that a user seeking to use an online service is of a certain age) is everywhere. At the time of writing, about half the states in the US have some internet age verification law in place, and dangerous proposals, from the KIDS Act to the Kids Online Safety Act (KOSA), have been advancing at the federal level. European Union member states are moving toward having age verification in a centralized app by the end of this year. Australia famously now has one extremely broad restriction in place.

Most age verification laws tend to fail at their primary goal of barring kids from being online or from entering only specially designated zones, not to mention they pose a significant threat to everyone’s privacy. Some proponents of these age-based internet restrictions think they've found the silver bullet: Zero-Knowledge Proofs (ZKPs). We wrote about ZKP’s when they were first rolled out in the age verification context last year. However, more recent examples show our concerns weren’t just conjecture; ZKP-focused AV schemes are gameable, hackable, and not the cure-all some may claim.

ZKPs in Age Verification Would Only Centralize Power and Create More Harms

Before we jump into how these systems work, it must be said: creating a single point of failure for internet access contradicts the very idea of a free and open internet. 

The mechanisms underlying ZKPs pose an existential threat to everyone’s digital rights, not just kids. The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user's access to a service, essentially removing that person’s access to the internet entirely. Without oversight of who has authority to implement and operate these systems, this approach centralizes critical internet infrastructure in the hands of very few actors. 

How ZKPs Work

ZKPs are mathematically impressive cryptographic tools—but they weren’t developed with age verification in mind. Essentially, they let a computer quickly attest to the validity of a given question asked by another computer without divulging any underlying private data. 

Computer A (such as the device operated by a person trying to access a website) is able to prove to Computer B (such as the server for the website that person is trying to access) that something is true without actually sharing the contents of that information itself. Computer A locks in a "commitment" to the information it needs to convey. Computer B, which wants to verify that information, generates mathematical "challenges" that can be answered correctly only if the information is true. Traditionally, this happens over many different “challenges" until there is no room for doubt that Computer A’s "commitment" is true.

Since that kind of lengthy back-and-forth process would drastically slow things down over the internet, there's a shortened version of this exchange that's "non-interactive.” In that case, the ZKP is verified instantly. The answer itself is hashed (mathematically converted into a fixed, shorter string of characters), and the resulting hash is theoretically unpredictable and tamper-resistant. This shortened version of the ZKP exchange is called "zk-SNARK," which is the current preferred method for age verification.

In the ideal scenario, this means that ZKP’s are able to attest to a person’s status as an adult or a child without actually giving away any other private information about that person. In other words, only one entity would collect that private information, typically on the user’s device, instead of every website or app that needs the user’s age attested to. Unfortunately, recent real-world testing of these systems prove that ZKP’s aren’t the silver bullet that proponents of AV laws were hoping for.

EU’s AV Rollout Reveals How Broken It Is

By the end of 2026, the 27 states within the European Union are expected to have infrastructure in place to do age verification within a "mini-wallet" app that will live inside the EUDI (European Digital Identity) Wallet. This is being met with plenty of warranted criticism from digital rights experts. The "mini-wallet" version is already being rolled out, with promises that the ZKPs are in working order. But recent insights show that the ZKP features aren't yet turned on except for the closed demo/prototype build (not the version of the app people are using “out of the box”), which the vast majority of everyday users can’t access. 

Worse still, a security researcher found they could bypass the app's system using a quickly built Chrome extension that tricked the app into repeatedly accepting the same "over-18" token. It did so without ever asking for fresh verification. 

Over 400 security researchers signed an open letter stating that age assurance checkpoints, even if implemented with privacy in mind, would cause more harm than good. A primary focus of their concern, which we share, is the fact that a centralized identity verification system creates a single point of failure that is extremely vulnerable to both cyberattack and authoritarian overreach.

Once the "mini-wallet" version of this is fully integrated into the EUDI Wallet, it will replicate these same failures, perhaps more, but at a much larger scale. At that point, the failures will involve many more pieces of sensitive information that the EUDI Wallet contains: passports, driver's licenses, travel information, financial information, to name a few.

ZKP’s Aren’t The Magic Bullet

As we’ve said time and time again, no method of online age verification is privacy-protective, fully accurate, and capable of guaranteeing universal coverage without introducing severe security risks. 

Lawmakers concerned about the privacy failures of age verification mandates must understand that ZKPs are not a magic bullet. They do not solve the age verification paradox; they simply push the burden of trust down the road, relying on technical ignorance and magical thinking about how the internet actually functions.  

Mandatory online age verification of any kind is a dangerously flawed idea. Tell your lawmakers we said so.

Daly Barnett

Too Little, Too Late: Flock Admits Their Technology Needs Reforms

2 weeks 4 days ago

Flock Safety, the embattled vendor of mass surveillance technology, has rolled out a handful of new reforms intended to appease the justified nationwide anger that has seen scores of towns cancel or suspend their contracts with the company for automated license plate readers (ALPRs). The reforms are a combination of long overdue changes along with some cosmetic fixes that fail to address the fundamental dangers of this technology.  

We should not be letting companies decide how much privacy we deserve.

So, what do these reforms actually do?  

The most consequential is Flock’s default setting of an optional 7-day retention period for ALPR data, down from its original default optional 30-day retention period. This means if police want to retain data beyond the duration of their retention setting, they need to access “Evidence Mode,” i.e., when the desired data is associated with an active investigation and not just a fishing expedition. This is significant because, in at least some circumstances, Flock has previously charged its customers to extend their retention period. So, while towns can likely easily flip the switch to longer retention periods, it might come with a price tag some cities will be unwilling to pay.  

Flock also has two other, likely easier-to-bypass reforms. The first is offense filtering so that cities can enable other departments to access their ALPR data only if they are investigating certain crimes, e.g., murder or robbery but not immigration-related investigations. The second is supposedly beefing up their audit feature and proactively locking out officers who file suspicious requests for data. The major problem here is the fact that Flock’s enhanced audit and transparency tools help to address a problem that Flock itself has created—an abusable mass surveillance system that tracks all cars all the time.  

In addition to these reforms, there is also a tone shift coming from Flock’s CEO, Garrett Langley. Langley went from calling the DeFlock movement “terrorists” (which he has since apologized for) and saying that the wave of anti-surveillance anger was more about the current federal administration than it was specifically about his company, to a more conciliatory tone that acknowledges some of the problems of dangerous surveillance, mission creep, and police abuse.  Just look at this report from the BBC:  

“Historically, my point of view as a chief executive of a private company was, I don't know if I should be making these decisions. I don't know if it's my job to say how long data should be retained,” Langley said. 

He added that he has come to agree with groups like the American Civil Liberties Union and the Electronic Frontier Foundation that police should need an active case number to search Flock's data. 

“They're right. I think it should be required.” 

To be clear, our position has long been that police, at a minimum, need to get a warrant, signed by a judge, in order to search for historic ALPR data regarding specific vehicles. For us, it’s common sense: if police want to dip into historic ALPR data like they were going back in time to retroactively follow your comings and goings, they need a warrant.  

Fundamentally, these reforms leave us wondering: what is stopping Flock from reversing course on them if their law enforcement customers respond by defecting to another ALPR vendor? Nothing.  

This all leads to the bigger and more important issue: We should not be letting companies decide how much privacy we deserve. If our privacy is determined by how much surveillance technology vendors decide is too much surveillance, then we’re really out of luck. It shouldn’t be up to Flock or any other ALPR vendor to decide how long police can collect and retain data on millions, if not hundreds of millions, of innocent people. We need lawmakers to step up and pass laws that restrict police’s use of surveillance technology. After all, the surveillance business model is the problem, and a few company-imposed slapdash reforms aren’t going to change that.

Related Cases: SIREN and CAIR-CA v. San Jose
Matthew Guariglia

Who (or What) Generates Images for EFF?

2 weeks 6 days ago

We’ve had a few questions from EFF supporters lately, asking whether the images we use on our blog posts, or on donation and shop items, have been created with AI image generators. We’d like to answer these questions and clarify our internal policy regarding image creation. 

EFF images are all made by human beings, not by automated image generators, with very rare exceptions. This is an internal decision made by our small design team, for the following reasons: 
  

  1. Our designers bring knowledge and expertise to the images we create, informed by years of consultation with EFF’s lawyers, technologists and activists. We find that this informed perspective helps make the issues we cover more clear, and more engaging, for our supporters. 
  2. The content on our sites is written by human beings, not by bots, and we feel that the images illustrating these posts should be human-made as well. Our supporters come to EFF for honest, trustworthy information from expert human beings, and we want our images to communicate that authenticity as well. 
  3. Aesthetic preference: our designers prefer the look, as well as the process, of images made “by hand.” It also gives us more control over the images, including producing multiple versions for different posts. While it can sometimes take a bit longer, we feel the results are more satisfactory and long-lasting.  
  4. While it is rare, it is possible for image generators to create images that are under copyright, or understood by some to be under copyright. This could conflict with our use of a Creative Commons Attribution license for all our images. By generating our own images, we avoid any risk of a dispute about copyright infringement, so that we can continue our work promoting digital rights (including the right to fair use of copyrighted materials) without fear of a lawsuit. 

An example of EFF artwork process: sketch and final art

To be as clear as possible, we are now adding a small credit in the lower righthand area of each banner image that will read “Image created by EFF.” As mentioned earlier, there may be rare exceptions, when an EFF designer uses an automatically generated image as a small element in a larger illustration. In these cases, we will indicate that use with additional text, specifying the elements involved, and naming the image generator used.  

We hope that by describing our internal design thinking, we are answering the questions we are getting without confusing anyone about EFF's various and nuanced positions on the issues raised by image generators. As with past technological developments, we continue to defend the rights of technologists to develop these powerful tools, as well as the right of the public to make legal and legitimate use of them. Ultimately, EFF's design team has made a choice we feel is consistent with EFF's brand and look, and it's a decision we think every user gets to make for themselves. 

And don't forget: because all of our images are CC-By, you are free to use, share or remix any image we create (we ask that you include a credit to EFF). If you need hi-res versions, you can find some on our Flickr page, or you can email us directly with any requests. And you can enjoy some of the art we create on gifts you receive when you donate to EFF!

Donate to EFF

Get awesome human-generated art as a thank you gift!

Hugh D'Andrade

Dismiss Church’s Trademark Lawsuit Against “Mormon Stories” Podcast, EFF Urges Court

2 weeks 6 days ago

Imagine if McDonald’s could use trademark law to control how you use the term “fast food.” Or if the Canadian government could stop you from using the word “Canada” in the title of a book about the country and its people. That wouldn’t just be absurd; it would be an unacceptable obstacle to criticism of and commentary about those institutions. Yet the Church of Jesus Christ of Latter-day Saints (the “LDS Church”) has a track record of claiming exactly that kind of authority over the word “Mormon,” using the threat of expensive litigation to pressure speakers into compliance.

We at EFF have opposed the LDS Church’s abuse of trademark law for over a decade. In 2014, we filed an amicus brief when the church sued an online dating service for church members called Mormon Match. In 2016, it threatened legal action against our client the Mormon Mental Health Association, a nonprofit association for mental health professionals who work with members of Mormon faiths. In 2025, the church tried to pressure our client Burke Sorenson into changing the name of his Mormon News Roundup podcast. Now, the LDS Church has brought a lawsuit over a podcast called Mormon Stories that examines Mormonism and Mormon culture. With the help of attorneys at Ballard Spahr, EFF has filed an amicus brief in the case.

Our brief urges the district court to dismiss the case as soon as possible. Trademark is supposed to be about helping consumers identify the sources of the products they buy, not controlling criticism. That’s why our brief asks the court to use a test that’s more protective of speech than what’s applied in most trademark cases. This test, known as the Rogers test, has been adopted by many courts (but not yet this one) for cases where someone is using a trademark as part of an expressive work, rather than just as a brand name. We explain to the court that the Rogers test is an important First Amendment safeguard in part because it makes it easier to throw out meritless trademark claims before the most expensive parts of litigation, allowing more speakers to confidently stand up for their rights.

Our brief goes on to explain that First Amendment safeguards are especially important in cases like this one, where a plaintiff is seeking to control the use of a common term for its common meaning. Trademark law isn’t even supposed to extend to generic terms, and for good reason. Otherwise, we risk giving trademark owners power to control discussion and debate over entire topics.

It’s about time that a court shut down the LDS Church’s trademark bullying. We hope the court will do so here, while also taking the opportunity to endorse the Rogers test.

Cara Gagliano

Meta Must Stop Silencing Reproductive Health Information

3 weeks ago

Access to accurate information about reproductive and maternal health can be critical. But on Meta's platforms, simply talking about prescription medication, abortion care, or one's own medical experiences can be enough to trigger content removals and account restrictions.

That's why EFF recently submitted a public comment to the Meta Oversight Board in its consideration of a case involving an Instagram post about prescription drugs during pregnancy and childbirth. The case touches upon a topic we’ve been documenting for some time; last year we collected stories from individuals who had experienced censorship of reproductive health information on various platforms. Meta in particular stood out: Its moderation systems routinely fail to distinguish between prohibited drug transactions and legitimate discussion of medications, including educational information and people's firsthand experiences with healthcare.

Through our Stop Censoring Abortion project, EFF collected nearly 100 submissions from healthcare providers, clinics, educators, advocates, researchers, and others whose reproductive health content had been removed or suppressed by social media platforms. What we found was alarming: systemic over-enforcement, confusing policies, arbitrary takedowns, sudden account bans, de-ranking, and appeals that too often went nowhere.

Talking About Medication Isn't the Same as Selling It

In almost every case we reviewed, the censored posts and accounts did not actually violate the platforms' stated rules. Meta frequently cited its Restricted Goods and Services policy, which prohibits attempts to buy, sell, trade, donate, gift, or request pharmaceutical drugs. But the content EFF documented overwhelmingly consisted of factual or educational information—not attempts to sell or distribute drugs.

The consequences were significant. For example, the Miscarriage+Abortion Hotline had its Instagram account restricted and posts removed even though it was providing information about legally obtaining medication rather than offering pharmaceuticals for sale. Red River Women's Clinic and the RISE reproductive health research center at Emory University had accounts locked after posting about mifepristone.

Other users reported having their content quietly de-ranked or “shadowbanned,” limiting its reach without giving them meaningful notice or recourse. We believe educational content and people's experiences involving reproductive healthcare and medication should not be suppressed in this way.

And when Meta gets these decisions wrong, the appeals process too often fails to fix them. In several cases EFF documented, accounts were restored only after journalists drew attention to the problem or someone with a personal connection inside Meta intervened. A moderation system shouldn't require knowing the right person to get an erroneous decision reversed.

Meta Can—and Must—Do Better

Our submission calls on Meta to make five changes—the same five changes we asked for last year.

First, Meta should publish clear, understandable policies so users can know what content is permitted and what might result in removal, downranking, or account suspension. Second, those rules must be enforced consistently and fairly. Third, Meta must provide meaningful explanations for enforcement decisions, including what rule was violated and how users can appeal. Fourth, users need a functional appeals system that doesn't depend on insider access.

Finally, Meta should expand human review. Reproductive healthcare is precisely the sort of nuanced and context-dependent subject that automated moderation systems struggle to understand. As our research shows, automated systems can mistake education for drug sales, misinterpret terminology, overlook cultural and political context, and even classify legitimate advocacy as dangerous content. Human moderators should therefore play a greater role when automated systems flag sensitive healthcare information or political expression.

Meta has chosen to allow discussion of reproductive healthcare, including abortion, on its platforms. That commitment means little if its moderation systems nevertheless prevent people from accessing or sharing that information.

At a moment when reproductive rights are under attack around the world, the stakes are particularly high. Restricting access to essential healthcare information can have profound consequences, especially for people who already face barriers to reproductive care.

Users deserve a system in which rules aren't applied arbitrarily, appeals actually work, and vital health information isn't silenced because an automated system failed to understand its context. Meta can—and must—do better.

You can read our comment in full below.

Jennifer Pinsof

Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction

3 weeks 5 days ago

The Senate Commerce Committee will vote this week on several censorious and privacy invasive bills: KOSA, the SCREEN Act, Youth AI Privacy Act, and CHATBOT Act. While we appreciate that the Committee is taking the time to look at these bills separately, it’s still impossible to ignore the message Congress is sending to the world: Age-gate the internet and block young people from speaking and accessing lawful speech online. Or else. 

Take action

Tell Congress: don't age-gate the internet

Each of these bills claims to be trying to protect children and teenagers from dangerous situations on and offline—certainly a worthy goal. But the proposed solutions in these bills are unlikely to make children and teenagers safer at all. Rather, they would create sweeping new privacy and data security problems, and force platforms to adopt unconstitutional restrictions on the content they host, for both adults and teenagers. 

There is a better way. Instead of considering these bills, the Senate Commerce Committee should be focusing on a national consumer privacy bill that would protect ALL internet users, or on banning behavioral advertising that tracks us across the web—again, for users of all ages. 

But the bills being considered this week move in the other direction—more information being collected, more surveillance, and less privacy for internet users of all ages. 

Take action

help eff oppose these bills

EFF sent a letter to the Committee with our concerns about these bills. We look forward to continuing to work with them to find a way forward that protects all users. 

India McKinney
Checked
4 hours 55 minutes ago
EFF's Deeplinks Blog: Noteworthy news from around the internet
Subscribe to EFF update feed