Normal view

The CHATBOT Act Forces One Parenting Model On Every Family

31 July 2026 at 21:06

Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced CHATBOT Act answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems. 

The Bill Requires AI Companies To Build Family Monitoring Systems 

Parents are approaching AI in different ways. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life. 

The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system. 

As part of the required parental-consent process for teens, AI companies must offer parents a "family account" that provides access to a "full record of the conversations and activity" of teen users and tools to "monitor, analyze, and understand, at scale" those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls. 

This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI. 

The CHATBOT Act Creates New Privacy Risks For Families 

Parents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages. 

And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures. 

The vast archives of conversations created by the government-mandated family accounts won't be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks. 

Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system. 

The CHATBOT Act Applies A Children’s Law To Teenagers 

The CHATBOT Act takes the basic structure of COPPA, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers. 

That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. Facebook, Instagram, TikTok, X, YouTube, Snapchat, Discord, Spotify, and blogging platforms like WordPress all keep out users under 13. Children under 13 are also not allowed to use Microsoft Co-Pilot, Google Gemini, or ChatGPT. Anthropic does not allow users under 18 to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are creating those accounts with parental consent.  

In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting more information about young users. 

But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires. 

The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student. 

Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI systemthe bill’s only option is to create a family account.

Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, uses Wikipedia, types search terms into Google, or reads a newspaper online. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant. 

The CHATBOT Act Will Pressure AI Companies To Check Users’ Ages 

The bill says it doesn’t require age verification. But like many recent “kids online safety” bills, it imposes obligations that depend on a company knowing whether a user is under 18. 

Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification.  Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes. 

Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law. 

A Better Way Forward

Congress doesn't have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children's privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families. 

Lawmakers have urged the FTC to crack down on AI-enabled toys that make unsubstantiated educational claims or illegally collect children's data. Those are regulatory actions that can be taken right now. 

Finally, the FTC is currently investigating how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues. 

Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.

San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing

28 July 2026 at 23:55

The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, collate, and store as much of our personal data as possible, and then monetize it through use and sale. When it comes to surveillance pricing, that looks like corporations offering the same product to two different people at two different prices, based on harvested personal information. That's why EFF supports A.B. 2654, authored by Assemblymember Chris Ward, which bans this harmful practice. 

As an organization based in San Francisco, EFF was proud to learn that the San Francisco Board of Supervisors had also introduced a resolution to similarly support the legislation. However,  we were disappointed to learn the San Francisco Board of Supervisors has since stalled a vote on the resolution stating their own support for A.B. 2654 after receiving an email from the San Francisco Chamber of Commerce criticizing the bill using well-worn and debunked concerns. We’ve sent the Supervisors a letter asking them to reconsider.

Banning surveillance pricing would be good for consumers. The FTC has found that companies will set higher prices based on personal information. “For instance,” the FTC found last year, “if a consumer is profiled as a new parent, the consumer may intentionally be shown higher-priced baby thermometers on the first page of their in-app search results, based on their residential zip code and time of purchase.” Let's say that again: the U.S. government has found that companies may seek to use surveillance pricing to charge parents searching for a thermometer in the middle of the night more money in a time of need.

Privacy is a human right, not something that people should understand as a currency to give away or protect based on how it will impact the price of groceries. EFF has long opposed pay-for-privacy schemes, in which a company charges a higher price to a customer who refuses to submit to processing of their personal data. Surveillance pricing is another version of that practice. You should never have to worry that your privacy rights depend on how much you make.

At a time when prices for everyday goods continue to climb, some surveillance pricing defenders note that using personal information could lead to lower prices for some consumers. Yet some recent studies indicate there will be losers and winners  based on factors such as whether a consumer is willing or able to switch products. Who loses or wins also will turn on the accuracy of the underlying data – yet surveillance pricing is often based on false information.

That said, even if surveillance pricing has the capability to lead to lower prices (which it often doesn't) we oppose it as just another way that corporations try to make customers pay for their privacy.

The San Francisco Chamber of Commerce’s concerns are fully addressed in the text of A.B. 2654. The Chamber raises questions about how businesses will comply with the law. But the bill is quite clear: “a retailer shall not engage in surveillance pricing.” It also has a clear definition of what “surveillance pricing” is. The banned practice is defined as: “[i] a customized price for a good for a specific consumer or group of consumers, [ii] based, in whole or in part, on personally identifiable information collected through electronic surveillance,” including if that information is “acquired from a third party.” In other words, “surveillance pricing” is a customized price based on personal information.

The SF  Chamber’s letter also asks about the bill's “treatment of discounts and loyalty programs.” In this way, too, A.B. 2654 is quite clear. The bill includes three broad carveouts that ensure it doesn't disrupt loyalty programs and discounts:

  • First, for price differences “based solely on costs associated with providing the good to different consumers.”
  • Second, for a discount offered to a consumer who is taking steps to terminate a service.
  • Third, for a discount, conspicuously posted on a retailer’s website, that is uniformly available based on (1) criteria anyone can meet, such as signing up for a mailing list, (2) membership in a broadly defined group, such as seniors, or (3) participation in a loyalty program.

An opt-in senior discount to the movies is not the problem. The systematic collection of all of our personal information to determine whether someone is a senior and if so whether they should pay more or less for that matinee is. 

As we said in our blog post outlining our support for this bill:

Surveillance pricing is very similar to online behavioral advertising, a business practice that EFF urges governments to ban. Both practices incentivize all businesses to collect as much of our personal data as possible, in order to later monetize it. Both practices lead some businesses to collate and store our data into dossiers about us for later use. Both practices use these surveillance-based dossiers to manipulate and limit our economic choices, by altering the advertisements and prices we see online.

We urge the San Francisco Board of Supervisors to join the coalition of groups that support A.B. 2564, and stand against companies mining our personal information to charge us different prices for the same thing. 

You can read our letter to the Supervisors here.

Why Are Gay Bars Building Databases of Their Patrons?

28 July 2026 at 18:19

Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether those images are used for facial recognition.

A broader privacy concern also deserves scrutiny. For years, PatronScan has marketed itself not just as an ID-verification tool, but as a system that allows bars and clubs to identify patrons, keep records about them, and share information across venues. As one news article published in 2019 documented, PatronScan built a network that allowed participating bars to flag patrons and share information about them with other establishments. 

And in California, it’s not at all clear how PatronScan’s business model of scanning IDs and sharing the information from those scans with other bars comports with the law. California’s ID privacy law, which was amended in 2018 to add ID “scans,” states that no businesses shall “retain or use” any information from a scanned ID card except for limited purposes such as to verify age, comply with a legal requirement, or prevent fraud. 

A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database.

Californians should be deeply concerned about businesses that collect information from government-issued IDs and use it to build databases about where people go, whom they associate with, and whether they should be allowed into other public gathering places. That concern is especially strong in LGBTQ+ spaces, which have long served as refuges for people to go without being tracked, monitored, or put on lists. 

We reached out to Patronscan with questions regarding their practices and their views on California ID law. They referred us to their published FAQ question “Is Patronscan privacy compliant in California?” which claims that the use of Patronscan kiosks is legal in California. They also said “Patronscan does not do facial recognition in North America, or any kind of automated analysis of the ID or the live photo image.” 

The California Legislature Has Investigated PatronScan’s Business Model 

In 2018, the California Legislature published bill analyses (on that year's AB 2769) that went into detail about PatronScan’s business. Reviewing PatronScan's own materials, the California Senate Judiciary Committee found that the company had collected and retained information on 561,087 customers in Sacramento alone during the first five months of 2018—a remarkable figure for a city whose population had only recently topped 500,000.

Lawmakers also found that at that time, PatronScan retained information for at least 90 days or longer in some cases, shared information among participating bars, and maintained bans that lasted an average of more than 19 years. A PatronScan “Public Safety Report” used 10,000 scans collected on a single day to report on “where customers live, how far they have traveled, and how many different venues the customers patronized.” 

This was not simply checking IDs at the door. PatronScan was building a database. 

An immigrants’ rights group, the Coalition for Human Immigrant Rights (CHIRLA), wrote about its concern at the time with these growing ID databases, saying that “placing individuals on a database that labels them a "threat to public safety" has “significant immigration consequences that could lead to deportation, revoking of current status, or denial of future immigration relief.” 

Today, Patronscan states that it retains personal information about all customers for 21 days, and about flagged customers for up to five years. This includes the customer’s name, date of birth, photograph, gender, and zip code. It also includes the dates and times that the customer entered particular bars. Such databases are a grave privacy threat. Personal data is routinely stolen by thieves, misused by a company’s employees, seized by government agencies, and diverted to new purposes by a company’s executives. 

California Law Still Bans ID-Scan Databases, And Bars Should Follow That Law

In 2018, California lawmakers closed what they viewed as a loophole. Existing law already prohibited businesses from retaining or using information obtained when they “swiped” a driver's license, except for the narrow purposes of legal requirements (like a judicial warrant) or “preventing fraud, abuse, or material misrepresentation.” 

After reviewing companies like PatronScan, the Legislature amended the law to make clear that the same restrictions that apply to businesses that “swipe” ID cards also apply when those IDs are “scanned.” PatronScan opposed that change, arguing it wanted to preserve the ability to share information among bars so participating venues could decide whether to admit patrons.

The bill became law anyway. Yet PatronScan continues to market and sell a system that apparently retains information from scanned IDs, and allows participating venues to flag patrons and share information across its network. 

At a minimum, that raises serious questions about how those practices fit with California's existing ID privacy law. Bar and nightlife venue owners who utilize PatronScan should think twice about its effects on their customers, and consider going back to standard, visual ID checks. These physical checks have been effective at keeping underage patrons out of 21-and-over venues for decades, and don’t present the serious privacy dangers of creating a private database of bar patrons. 

For venues serving vulnerable communities like immigrants or the LGBTQ+ community, the stakes of using this technology are even higher. It’s disappointing and alarming to see some of California’s more well-known LGBTQ+ nightlife spots instead lining up as PatronScan’s early adopters. A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database. These businesses should reject PatronScan, return to the standard ID checks that every other bar has been able to utilize, and prove to their customers that their privacy and security still matters. 

Protect Your Privacy with California's DROP Tool

20 July 2026 at 23:55

Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy. 

It's called a DROP request. (That's Delete Request and Opt-out Platform, if you're fancy). This one bit of paperwork lets you tell every data broker registered in the state of California that you'd like them to delete your information from their databases and request they stop selling and sharing your information. 

Here are some things to know about DROP. 

(Don’t want all the details and want to just learn how to file a request? Skip to this section.)

What does a request do?

Filing a request on the DROP will send a request to delete and opt-out of sale to all the data brokers in California's registry. Data brokers are companies that collect information about people, repackage that information, and sell it. As of time of writing, a single DROP request reaches 614 brokers.

After August 1, once data brokers receive a request, they will have 45 days to address the request. 

DROP officially launched on Jan. 1 of this year, but companies have until Aug. 1 to begin complying with requests. That means if you file a request now, you'll be in on the ground floor.

Didn't I hear about this before?

If you pay attention to EFF, you sure did. With your help, we advocated for the law creating the DROP tool, the Delete Act. As we said then, we needed the DROP because Californians have a right to request that companies delete information collected about them, and a right to opt-out of having businesses sell information about them. Yet, in reality, making those requests is an incredibly time-consuming and tedious process. Filing each request is hard. Plus, because data brokers buy, sell, and exchange information with so many companies (and each other) people may not even know who to file a request with. By linking a request to California's data broker registry, DROP cuts this process down considerably.

We advocated for DROP and the Delete Act because it makes our privacy law more user-friendly, which gives us better control over our data and reduces the risks that the uncontrolled collection and sale of personal information creates in our everyday lives. 

What's in it for me?

Filing a request benefits you in a few ways. For one, data brokers are often how spammers (or companies that act like spammers) get your email address, phone number, and other ways of contacting you. Removing yourself from data broker lists could lead to a decrease in these kinds of messages. Second, reducing the number of companies that have your personal information also improves your personal cybersecurity, as it decreases the number of firms with your information who could be hacked. Third and finally, it gives you an opportunity to exert more control over how your personal information is collected and used—an important element of privacy. Unless you opt out, data brokers can sell your private information to predatory companies, scammers, stalkers, insurance companies, and law enforcement.

What kinds of information will (and won't) be deleted?

The California Privacy Protection Agency, which administers the DROP, has a great resource explaining what data are and are not included in a request. But in summary, a request will often deal with identifying information such as: social security number, precise geolocation, browsing history, email address, and phone numbers. It will also enter a request to delete guesses that data brokers may have made about you based on identifying information, such as political views, inferences about your health—inferences about pregnancy or chronic illness, for example, that may be based on purchases or browsing history.

Not all information will be deleted. Some information, such as vehicle or real estate ownership, contains information that is a matter of public record. 

If there is a specific data broker you'd like to be able to retain and continue selling your data, the system also gives you a way to remove them from the list of brokers that get any given request. 

How do I file?

Head to the California Privacy Protection Agency's DROP website to start your request. Before you start, there are a few pieces of information you may want to gather for your request, such as your advertising ID or your VIN number, if you want this information to be deleted from data broker databases. 

The agency does ask to collect some personal information—name, address, phone number, email address, etc.—in order to fulfill a request. (Yes, there is an irony to this.) This is to verify that you're the right person asking for your deletion and opt-out request in any given database, and the agency itself is bound to its terms of service that say they won't sell or share it for other purposes.  

If you're interested in filing a request for someone else, such as an elderly relative drowning in junk mail, you can also do that but will need to attest that you're filing for someone else who is a resident of California. 

Once you've filed, you will get a DROP ID, which you can use to check in on your request. If you lose this ID, you can contact the agency to recover it, but keep it in a safe place if you want to check in on the status of your request.  

If I file once, am I done forever?

Unfortunately, no. While the opt-out of sale request should last indefinitely, California's privacy law still allows companies to collect information without asking for permission first in most cases. That means data brokers are likely to continue to collect information for profiles of you—but they will will have less data and be limited in how they use it after an opt-out request. New data brokers may also register with the state after you file your request. And DROP won't stop companies who aren't registered data brokers, like Google, from collecting and sharing your personal information.

Two things can be true. DROP is a fantastic tool to help more people exercise their California privacy rights. We also still need even stronger privacy laws to make things more fair for everyday people. 

That fact shouldn't undercut the power of this tool, but it does mean that you may want to make updating your request a regular part of a broader plan to manage your digital footprint. For example, might we suggest doing it as a part of Opt-Out Octobera thing we totally made up but also totally stand behind?

What if I'm not in California?

Also unfortunately for those who don't live in California, this tool only works for California residents. But it's not all bad news. Versions of the Delete Act have been introduced around the country, and many regulators are monitoring how California's system works to see whether a similar system might work in their own states. Residents of all states can use EFF’s Opt-Out October guide to bolster their online privacy and limit the ways that data brokers harvest their personal data

How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues

17 July 2026 at 17:01

When Ubisoft's Watch Dogs 2 was released in 2016, it was a headtrip for those of us working on digital-rights issues in the Bay Area. During the day, I'd fight tech-authoritarianism from EFF's San Francisco offices and then, at night, I'd fight tech-authoritarianism in an uncanny simulation of San Francisco from my home gaming console.  

Watch Dogs 2 is an open-world video game that follows a hacktivist collective called Dedsec as they take on surveillance tech and discriminatory AI systems that are being controlled by tech bros, government contractors, and corrupt cops. The game's missions often felt like they were ripped from the pages of EFF's Deeplinks blog.  

EFF’s mission is defending civil liberties in the digital world, and we do that with activists, technologists, and lawyers. If you've ever dreamt of joining Dedsec, you should definitely join us as a member.  

 Join the movement to Take Back CTRL.  

In fact, we've even got the same merch aesthetic. I cosplayed as the lead character, Marcus, at Dragon Con, and no one even knew I was in costume. 

Dave (left) as Marcus takes a selfie with a Wrench cosplayer at Dragon Con 2018.

To commemorate Watch Dog 2's 10th anniversary, I'll be speaking on a panel at San Diego Comic-Con reflecting on how the game predicted tech issues we're facing today. Organized by Mia Ginae of The Mighty Hostess and Black in Gaming, we've got voice actors Ruffin Prentiss lll and Shawn Baichoo, cinematic producer Timmy Fisher, and music producer Hudson Mohawke, who did the soundtrack, with Mia Ginae moderating. That's at 3:15 PM on Friday, July 24 in room 6BCF. 

Watch Dogs 2 panel at San Diego Comic-Con

But not everyone can get to Comic-Con and I certainly have more to say that can fit in. So here are a few ways where Watch Dogs 2 mirrored our work back then and foresaw what we're facing today.

Check out our full San Diego Comic Schedule, including panels and a meet-up. 

Insecure Surveillance Cameras 

One of the signature gameplay elements of the Watch Dogs series is the ability for your character to hack into nearby security cameras from your phone and use that to gain a strategic advantage over hostile adversaries. 

About a year before, that's exactly the issue that we were working on. EFF Technologist Cooper Quintin and I used the service Shodan to identify a slew of automated license plate readers (ALPRs) that Louisiana police had left unprotected on the internet. We found that the controls were open to anyone to manipulate and, just like in the game, you could watch the live video feeds.

Shodan screencap of unprotected ALPR feeds

We didn't use the data to acquire a skill point or collectible outfit. Instead, we forced police agencies to lock down their equipment and then used what we learned to persuade then Gov. Bobby Jindal to veto a bill that would have created a new statewide surveillance dragnet.  

This issue still persists today. Most recently, security researchers Benn Jordan and Jon “GainSec” Gaines, and the award-winning journalists at 404 Media, uncovered how at least 60 pan-tilt-zoom cameras from the vendor Flock Safety were left exposed online.

Cell-Site Simulators 

In Watch Dogs 2 there's a mission called "Stolen Signals," in which Marcus and his best friend Wrench are trying to locate "stingrays," police devices that gather nearby cell-phone data by masquerading as legit cellular towers. We call these "cell-site simulators" (CSSs) and they're are an extremely alarming mass surveillance technology that allows police to track individual users through their phone identifiers. We've long advocated that this should require a search warrant.   

Like Dedsec, we also had initiated a project to do the exact same thing. And in true Dedsec fashion, we also gave it a pop-culture name: Crocodile Hunter, an homage to wildlife expert Steve Irwin, who had famously died after a stingray attack.  

But while Marcus was running around Telegraph Hill, staff technologist Cooper Quintin and I were running around downtown San Francisco, testing out our own device for detecting suspicious cell phone towers during Salesforce's annual Dreamforce conference. And while we didn't find a CSS that day, we did find a mobile surveillance tower that a start-up had set up for the event.

Cooper Quintin, EFF's own "Wrench," testing out Crocodile Hunter at Dreamforce

Cooper Quintin, EFF's own 'Wrench,' testing out Crocodile Hunter at Dreamforce

Today, that project has evolved into Rayhunter, which allows anyone to use a cheap mobile hotspot to detect the type of cellular anomalies associated with CSSs. We're proud to say that now there's a whole international Dedsec-style network of researchers using this technology to look for surveillance at protests, at the border, and in metropolitan areas 

Security Robots 

Throughout the game, Marcus encounters a number of autonomous pickle-shaped security robots wandering the city. At one point, Wrench reprograms one to become "Wrench Jr," a bona fide member of the Dedsec team.  

In real life, these robots are made by a company called Knightscope, and EFF started shining light on them in 2020-2021, when they were first being deployed by companies and government agencies.

A Knightscope robot patrols a casino parking lot in Reno, Nevada.

Today, law enforcement is pursuing weaponized robots and drones, and EFF is at the forefront to stop this dystopian reality. In fact, in December 2022, we successfully fought for San Francisco to ban the police department from weaponizing drones. In 2024, New York Police Department also retired its subway robot.

A Citywide Surveillance "Operating System" 

In the Watch Dog series, one of the ominous developments is CTOS 2.0 (Central Operating System 2.0). Through this system, Blume, a government contractor, tries to collect a massive amount of data through citywide sensors and infrastructure, and to combine all that data into one unifiedand totally insecureanalytics system.  

At the time we'd only just begun to see this idea floated, with a limited number of cities trying tools like Palantir's Gotham to manage data.  

Today, it is a frighteningly competitive market, particularly when it comes to law enforcement surveillance. For example, both Axon and Flock Safety are trying to offer products that integrate with every function of policing that sound like CTOs. In fact, Flock Safety product is literally titled, "Flock OS."

Fusus demonstrated at a police chief's conference.

Meanwhile, Axon's camera networking product, "Fusus," sounds like it came straight from the Watch Dogs' writers room. Fusus allows for central live-streaming of all types of surveillance cameras in a city, including body-worn cameras, which was another prediction from the Watch Dog series that came true.  

EFF has been part of many local battles to reject Flock and Axon surveillance systems, and we've also advocated against recent efforts at the federal level to consolidate government data.  

Join the Fight Against Authoritarian Tech 

Watch Dogs 2's protagonists aren't just the merry band of core hackers: It's a distributed movement spread across the region and social media. The sequel, Watch Dogs Legion, is even designed so that every single person in the city of London is a potential playable Dedsec member, ready to take on tech tyranny with whatever skills they have.  

That's also our philosophy: If you use tech, if you're affected by tech, this is your fight. And it's time to take back control. 

There are a lot of ways to do this. You can become a member by donating. You can contact public officials through our Action Center. You can join the thousands of volunteers who are helping gather data on surveillance through our Atlas of Surveillance project. You can also hunt cell-site simulators with usand help improve our codethrough the Rayhunter project.  

And just like Watch Dogs 2, this is a game we can win if we work together.

Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features

15 July 2026 at 21:56

Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. It’s time they step up and start providing transparency reports and stronger encryption options.

Surveys suggest that around 40 percent of people in the United States own some sort of commercially available wearable health device. Despite being marketed as health devices, they have no special health-related privacy protections that one might hope for. The companies who make these devices can and do collect an abundance of data, and many of them share that data with third-parties for marketing or to influence insurance rates, or use it for their own purposes, like training artificial intelligence models.

Health data is increasingly an important part of law enforcement or government investigations. Wearable data has been critical in a number of cases, where information about heart rate and steps was used to determine the whereabouts of individuals. And the surveillance company Penlink calls fitness trackers and wearables an “overlooked source” for law enforcement since they tend to show movement patterns and changes in heart rates. Law enforcement can try to get access to this data through subpoenas or warrants. 

There are many potential privacy issues with these sorts of devices, including whether the companies who make them share or sell information to third-parties. But here we are choosing to focus on two facets we’re concerned with around health data itself: 1) whether the company shares information with law enforcement and governments and 2) if they offer end-to-end encryption, which means the company itself can’t access that health data to begin with.

Reading through dozens of product review sites we narrowed our research in on ten companies that seem to make the majority of recommended consumer health products on the market:

  • Amazfit
  • Apple
  • Coros
  • Garmin
  • Google (including Fitbit)
  • Hume
  • Oura
  • Polar
  • Suunto
  • Whoop 

We reviewed each company’s public facing policies, then emailed them to confirm those findings. Here’s what we found.

Transparency Reports Are Few and Far Between

Companies should provide transparency reports of how often they provide data to the government, including information about whether it’s an official demand or an unofficial request. We have been calling on tech companies to publish transparency reports for a long time, but the practice is still rare across the industry. That’s especially true with fitness gadgets. 

Only two of the companies we surveyed, Apple and Google (which also owns Fitbit), currently publish transparency reports. Apple, Google, and Whoop promise to notify users of law enforcement requests in publicly available documentation. 

Oura now does too, after an update to their privacy policy in June 2026 that was perhaps prompted by a series of requests from journalist Zack Whittaker. In that same update and in an email to us, Oura promises that it is “actively evaluating ways to provide greater visibility into how we handle these requests, like through a transparency report.” This is promising, and we hope the company agrees that transparency reports are the best option moving forward. 

Any company that handles data that’s of interest to law enforcement and governments owes it to their users to publish transparency reports and, when legally possible, notify users when that data is requested.

Similarly, Suunto does not currently publish transparency reports, but in an email reply to our questions the company did express an openness to potentially doing so, stating, “We continuously evaluate our transparency practices and may publish additional information, such as a transparency report, in the future if we believe it would provide meaningful value for users and support our data protection efforts.” We hope they do, as these sorts of reports are a useful metric for all of us to better understand if and when our data can potentially be accessed by law enforcement.

We could not find instances where the other companies publicly state a policy around notification or transparency reports, and no others replied to our email questions.

Any company that handles data that’s of interest to law enforcement and governments owes it to their users to publish transparency reports and, when legally possible, notify users when that data is requested. This is especially true of personal health data, which can reveal our movements, and be used to infer details about what we’re doing at any given moment.

End-to-End Encrypted Data Is Far Too Rare of a Feature

End-to-end encryption is a method to ensure that your personal data is only accessible by you, and not the company who makes the device and manages the cloud storage. End-to-end encryption is usually used to refer to message encryption in communication apps, like Signal or WhatsApp, but can also refer to data storage. For example, many password managers use end-to-end encryption, and Ring implemented it for its cameras after we pushed for it. There’s no reason it can’t be offered for wearables too.

In the case of health data from wearable devices, it’s a way to store data in the cloud so that information can be synced and backed up between your device and an app on your phone in a way where only your devices can access it. 

Support for end-to-end encryption is more rare than transparency reports. 

The Apple Watch, at least with data that’s stored in the Health app, is the only popular fitness wearable that supports end-to-end encryption, and it’s enabled by default for all users (you are required to have two-factor authentication enabled as well, but that is also on by default for most accounts).

However, Apple Watch owners should remember that this protection is only for data stored in the Apple Health app. If you use other apps on your watch, or choose to share data with third-parties, like Strava, or if you’re sharing data with other wearables, like an Oura ring, that data is likely not end-to-end encrypted by the third-party company. 

Support for end-to-end encryption is more rare than transparency reports. 

And that’s it. Apple is the only one. No other popular consumer health wearable offers end-to-end encryption for the data it collects and stores online. Not Google. Not Garmin. Not Oura. Most of these companies instead offer encryption in transit and at rest, but this means those companies can still see and use your data. This is the industry standard, but it doesn’t have to be.

Another option would be more robust local-storage options. Some devices we looked at, like a handful of Garmin and Polar watches, can operate on the watch itself without syncing data to the cloud, but some models are limited in capability and cannot sync to an app without storing data online. More robust options for limiting the data to just the wearable and the phone app it's synced to would be a privacy improvement. For example, the Apple Watch has the option to disable iCloud sharing in Apple Health, which will keep the data only on your phone. It’s the only wearable we found that offers this feature without using a third-party app like Gadgetbridge or by physically connecting the wearable to a computer with a USB cable and transferring activity files over manually.

The general lack of local-only options or end-to-end encryption is a major privacy oversight, especially when you consider these devices collect heart rate, track sleep, and can log your location while also calculating a variety of health metrics supposedly intuiting everything from anxiety to your fitness “age.”

We understand that it’s technically more difficult to implement end-to-end encryption than other sorts of cloud storage, and comes with some limitations that may affect a user’s experience with a product. It also makes certain types of AI-related features harder to implement, since they’d typically need to work on-device (either in the app or the wearable device itself). Because of that, we believe an option for end-to-end encryption or local-only storage of the data collected by a wearable is the least companies can do. This way, those who want to use these devices can do so with the choice to either accept some privacy risks, or choose a more locked down option.

What’s Next

If you’re a user of a fitness wearable from any of the companies we’ve reached out to, or any other one, don’t be shy in asking for these sorts of features. In the rare cases a company offers a feature request page, use it—like for Garmin, Polar, Suunto, and Whoop. And when those types of outlets aren’t offered, don’t shy away from general contact pages, like those offered by Amazfit and Oura, or on community subreddits.

The companies that make these wearables, whether they’re designed for fitness or health, need to improve. At the bare minimum, companies need to publish transparency reports detailing how often they receive requests from law enforcement and commit to notifying users whenever that happens. 

It’s also well past the time for more companies to offer end-to-end encryption for the health data they’re storing. We acknowledge that this may be a trade-off for some features, like social networking features, but it should be up to users to decide if they’re willing to make those trade-offs. This level of privacy is an appealing feature that benefits users in myriad ways and more companies can set themselves apart by committing to this level of privacy.

Health data is some of the most personal data we produce, and most wearables companies are behind the times when it comes to basic privacy practices and transparency. Now’s the time to improve those practices.

Don’t Repeat NY’s 3D Printing Blunder

14 July 2026 at 21:52

This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect every artist, researcher, engineer, and hobbyist in the state, but there is a real risk of other states thoughtlessly following suit—prior to the New York rules even taking effect.

We, along with many other experts, already warned about this bill buried in the state’s crowded budget process. Hundreds of our supporters and 3D printing enthusiasts in New York reached out to their representatives hoping to kill this farcical bill. While there were some welcome amendments in response to the outcry, Albany passed it anyway.

It might be well-intentioned, but bills like these sell a fantasy that can only have an untold negative impact on the privacy, free expression, and consumer rights of anyone using these general purpose devices. Behind the banner of reducing gun violence, which is nearly always committed with commercial firearms, New York lawmakers have passed draconian legislation that will let manufacturers lock in users and collect their data.

Now that the bill has passed and been signed by Governor Hochul, let’s look at two important ways the final legislation changed since we last wrote about it, and why states like California shouldn’t make the same mistake.

Reduced Risk for Lawful File Sharing 

The New York bill includes language that criminalizes access to firearm print files, a proposal correctly dropped by states like Colorado due to First Amendment concerns. While this made it through to the passed legislation, a few wins were still gained.

Originally the legislation threatened felony charges for the storing and sharing of files, potentially impacting researchers, artists, and journalists with no intention of printing a firearm component. These charges were downgraded to a Class A misdemeanor.

Two provisions criminalized file sharing. The first of the two provisions criminalizing this file sharing, which pertains to the sale or distribution of files in the state, gained an important exception for when a sender has a reasonable belief that the recipient won’t illegally print these components. However the second provision, pertaining to criminalizing file possession, complicates this. Under 2.12 of the subpart, people who possess the file with intent to share the files do not clearly get this same reasonable belief exception.

In other words, if you share one of these files the actual sharing is covered by the exception, but the law makes it ambiguous whether possessing those same files is covered when you intend to share them.

While this exception could have created some breathing room for researchers and journalists operating in good faith, this slapdash bill language leaves plenty of ambiguity and potential speech-chilling effects. However, these changes do offer a modicum of harm reduction in this unconstitutional law.

Saving Face by Preserving Online Sale

Originally the bill had a strange requirement for all 3D printers and Computer Numerical Control, or CNC, machines to be sold and delivered face-to-face, with no exception. That would have meant a major barrier to access, particularly for people in agricultural and rural areas of the state who uniquely benefit from in-home fabrication and repair. It also would have meant a major inconvenience for businesses using these devices. For everyone though, it meant fewer retailers to choose from and facing more stigma for using these devices. 

Fortunately this was dropped from the bill entirely. 

Next Step: We Find Out What Was Actually Passed

In addition to being buried in the complicated legislative process of the NY budget and avoiding proper scrutiny, this bill also kicked the can down the road in determining what exactly is being mandated. In many respects, legislators passed a vibe. We’ll see how the actual law be developed over the next year by a working group with no mandated transparency to the public. Further, they have no obligation to ensure consumer safeguards in developing this state-mandated censorware.

We are still concerned by the possibility of a biased working group acting in the interest of manufacturers or facing pressure to accept consumer harms in the standards they produce. Our remaining hope is this working group convened by the Department of State and the state university system is composed of actual experts who are aware of how unfeasible and harmful this mandate is, and prevent it from being realized.

The Fight Continues

New York is the first to go down this path of state-mandated censorship and surveillance software on 3D printers, but it’s far from the only one to entertain it. It is now more urgent that we fiercely oppose this trend in other states, like California,  as they attempt to join the bandwagon—before even seeing the real-world impacts. 

Take action

Don’t Let California Repeat NY’s Mistake

We cannot allow this to be the foundation for future restrictions on speech and design, or serve as a playbook for the state and corporations to wrest control over our tools.

The House Passed The KIDS Act—The Senate Should Reject It 

9 July 2026 at 22:58

Last week, the House voted on the KIDS Act, a disjointed package of legislation that seeks to control Americans’ web browsing and private messaging. The package combines a revised version of the Kids Online Safety Act (KOSA), with several other internet bills, study bills, reporting requirements, and new regulations. Different parts of the bill pressure online services to impose different age-gating schemes, using different standards. EFF opposed this bill, along with many of our members and supporters.

Take action

Tell Congress: no internet age-gates

The bill passed the House, 267-117. It now heads to the Senate, where its fate remains uncertain. But this fight is not over. Even if you took our earlier action to contact the House, we need you to reach out to your Senators today. 

The KIDS Act Will Lead to Mandatory Age Checks 

Many of the bills in the KIDS Act share the same premise: that children and teenagers should have different experiences online than adults. In practice, that requires websites and apps to determine who is under 18—and who isn’t. That’s where the problems with the KIDS Act start. 

EFF certainly supports giving all users better privacy and safety tools online. But those protections should not, and do not need to, come at the expense of privacy or free expression. Unfortunately, that’s exactly the tradeoff the KIDS Act makes.

There is no way to determine a user’s age online that is both privacy protective and accurate. Some age verification processes may rely on collecting government-issued ID, while others may use biometric scans. Others will use algorithms to guess a user’s age based on facial images or online behavior. But no matter the method, every system demands users hand over sensitive personal information that links their offline identity to their online activity. And then, once that valuable data is collected, it can be leaked, hacked, or misused. In fact, we’ve already seen several breaches of age verification providers.

The Bill Still Regulates Online Speech

The revised KOSA language within the KIDS Act still pressures companies to police lawful speech online. Platforms must “establish, implement, maintain, and enforce” policies that address content like gambling or the use of alcohol or cannabis. This encourages platforms to broadly restrict speech on these topics, which could include a teen seeking advice on a parent’s gambling problem or searching for substance abuse recovery resources. When platforms are required to create and enforce content moderation policies that regulators can sue them over, they will often err on the side of deleting speech. 

Protect Privacy For Everyone

There is a better way to protect young people online. Instead of encouraging a complicated system of age checks, more monitoring, and more restrictions on access to information, Congress could finally pass a strong, comprehensive privacy law that benefits all users. A great place to start would be to ban behavioral advertising that tracks us across the web—again, for users of all ages. 

We urge the Senate to oppose the KIDS Act and instead focus on a strong, bipartisan privacy package for all users. 

Take action

Tell the senate to reject the kids act

LGBT Q&A: How Can I Wipe Online Data That Points To My Queer Identity?

2 July 2026 at 17:52

This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q&A

You Asked: Is there a way for me to wipe data about me online that could point to my queer identity?

EFF’s Answer: You cannot protect everything all the time, but there are ways to wipe information about yourself online. 

Most information available about you online will typically be found in two places:

  1. The site where you voluntarily posted the data, such as your pictures and videos on social media, comments in user reviews and forums, and even classified postings for items you’ve sold.
  2. A data broker. These companies collect personal information, repackage it, and sell it to the highest bidders. This information often includes your address, phone number, details about your family members, and more. 

So you might not want this information out there, especially if it points to your queer identity. 

The best time to take steps to protect yourself is before anything bad happens, because once this information is in the hands of bad actors you have fewer options.

To see what information people might find about you online, you can look for it for yourself. This is as simple as opening up a search engine and entering your name, nickname, handle, avatar and seeing what comes up. It can also be worth searching for your address, phone number, and email addresses to check what's out there.

Do this in a private browsing window or a separate browser than the one you normally use to ensure you’re not logged into any accounts that might skew the results, like a Google account. 

It’s also best to try to make a lot of your information hard to find in the first place—and we’ve got you covered on how to do this. 

  1. Establish a strong security baseline: use unique passwords (a password manager helps simplify this) and set up two-factor authentication for your online accounts to add an extra layer of protection when logging into your accounts.
  2. Add our install-and-forget tracker blocking tool, Privacy Badger, which lets you browse in peace and stops the sorts of web trackers that compile information about your habits for advertising purposes and for data brokers.
  3. Remove your advertising ID on your phone to help prevent some tracking there, too (directions for Android or iPhone). This way less information about you is available for purchase, making it harder for corporations to profit from your online activities.
  4. Ask data brokers to delete your personal data. You might spend the time doing it yourself. If you’re in California, you can use the Privacy Protection Agency’s tool for this. You also might use professional services like EasyOptOuts and Optery to help minimize the information available about you online from data brokers and similar sources.
  5. You can remove yourself from Google results by heading to the “Results about you” page, then entering your information. Once set up, you’ll get notifications if some new types of information about you appear in Google Search. Just remember that this will not remove the information from the internet, it just won’t show up in Google’s search.

You also should consider auditing your digital footprint on public-facing social media and forums. Different people have different tolerance for risk when it comes to announcing who we are and what we are doing in these online spaces. You can make a list of every social media or forum account you’ve had over the years, and review the public-facing content about you, including your name, contact information like email addresses or phone numbers, and pictures that might show your home or workplace. You can also review the account settings to ensure you’re comfortable with the privacy options and that you’ve got strong login credentials.

For more in depth advice check out our Surveillance Self Defense guide on managing your digital footprint.

LGBT Q&A: What Data Are Companies in the UK Collecting When Verifying My Age?

30 June 2026 at 10:08

This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q&A

You Asked: I live in the UK, and we have age verification now on a bunch of websites (including Reddit) and now on iPhones. Can you explain what sort of data companies are actually collecting when they check for age and whether there are any real threats to my safety? 

EFF’s Answer: Age verification is a process where a website or service checks your age to determine whether a user is over a certain age, in the UK this age is 18. 

As of July 2025, all platforms in the UK that host content considered by the UK government and the country’s telecommunications regulator Ofcom to be harmful are legally obligated to check that their users are over the age of 18. If not, users cannot access the content. 

There are various privacy implications for data sharing with age verification. Unfortunately, because services may use different methods to verify users’ ages, you’ll usually have to do a little digging to learn how each provider you have verifies their users, and consider what information might be harmful to your personal safety: 

  • The data itself: What info does each method require users to disclose?
  • Access: Who can see the data during the course of the verification process? Does anything other than the age result leave your phone or device? Is the provider told your date of birth, or just if you’re over 18? Which third party services see the information you send?
  • Retention: Who will hold onto that data after the verification process, and for how long? Sometimes it’s deleted immediately. Sometimes it hangs around forever, waiting for a data breach.
  • Audits: How sure are we that the provider’s stated claims around data access and retention will happen in practice? For example, are there external audits confirming that data is not accidentally leaked to another site along the way? Ideally these will be in-depth, security-focused audits by specialized auditors like NCC Group or Trail of Bits, instead of audits that merely certify adherence to standards. 
  • Visibility: Who will be aware that you’re attempting to verify your age, and will a third party provider know which platform you’re trying to verify for? Will they hang onto that data to build a profile of you?

Last year, Ofcom outlined a number of methods for online services and platforms to check users' ages. Let's look at some methods in more detail. 

Facial Age Estimation 

First up we have facial age estimation, where you show your face via photo or video, and a technology provided by a company like Yoti or Persona analyses it to estimate your age. Most of these third-party verification services upload your photo to their servers during this process. Yoti claims that “as soon as an age has been estimated, the facial image is immediately and permanently deleted.” 

You might not want to use facial age estimation if you’re worried about a current picture of your face accidentally leaking—for example, if elements in the background of your selfie might reveal your current location. Some services like k-ID and Private ID will analyse your face directly on the device, so only the age result will leave your phone. 

If you do choose (or are forced to) use the face check system, be sure to snap your selfie without anything in the background that you'd be concerned with identifying your location or embarrassing you, in case the image leaks. 

Photo-ID Matching

Photo-ID matching checks whether your photo matches a document that confirms your identity, such as a driving license or passport. This is usually considered the most sensitive, since your ID has quite a bit of information on you. For example, if you upload an image of a document that shows your face and age, and an image of yourself at the same time, these are compared to confirm they match. Like with facial age estimation services, you’ll usually be sent to a third-party provider, such as Yoti or Incode. You’d hope that they’d delete the data immediately, but that’s not always the case. Incode for example doesn’t automatically delete the data you give it once the process is complete; though if you’re reaching them through TikTok, TikTok does claim to “start the process to delete the information you submitted,” which should include telling Incode to delete your data once the process is done. 

If you want to be sure, you can ask Incode to delete that data yourself. But you’re relying on a service you don’t generally have a choice about doing the right thing, and we’ve already seen how that can fail. A previous system that Discord used to verify age had you send a picture to their general help forum, where all of the IDs sat around forever, until they got exposed in a massive data breach. Discord no longer uses that system to verify users’ ages. So, it might be fine, but unless you look into the exact company and all their practices, it’s hard to know. You can check out EFF’s guide for a few of the major platforms

Open Banking

Next is open banking, where you give permission for the age-check service to securely access information from your bank about whether you are over 18. The age-check service then confirms this with the online service. The user's full date of birth is not shared. Credit card age checks are also used for pornography services, where you provide your credit card details and a payment processor checks if the card is valid. As you must be over 18 to obtain a credit card in the UK, this shows you are over 18 and can therefore access a service.

Email Verification 

Email-based age estimation is also quite prevalent, where users provide an email address, and a third party technology analyses other online services where it has been used—such as banking or utility providers—to estimate your age. That third party will aggregate some data on you in the process, but the only new information they’ll find out is that you want to verify your age using a particular email address.  

Mobile Operator Checks

Mobile network operator age checks give your permission for an age-check service to confirm whether or not your mobile phone number has age filters applied to it. If there are no restrictions, this confirms you are over 18. 

There is no perfect, privacy protecting verification service

Unfortunately, none of these verification options are perfect in terms of protecting information, especially when this is compounded by the additional risks that LGBTQ+ people face with data sharing. The data can reveal someone’s sexual orientation, gender identity, or HIV status that can be used by employers, governments, family members, scammers, or bad actors to inflict harassment, discrimination, arrest, or violence. 

There is still no widely available way to verify age online without compromising privacy—but even if there were, broad restrictions on social media will inevitably limit access to lawful speech, and valuable online communities, and arts and culture. These are just a few of the reasons that EFF is against age-gating mandates and is working to stop and overturn them in the UK and around the world.

Victory! Supreme Court Says Constitution Protects People’s Location Data

29 June 2026 at 19:25

You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, the U.S. Supreme Court ruled today in Chatrie v. United States 

The case involved geofence warrants, a form of dragnet surveillance police have used to vacuum up location data from electronic devices of people who happen to be in the vicinity of a crime. EFF had joined the American Civil Liberties Union, the ACLU of Virginia, and the Center on Privacy & Technology at Georgetown Law in filing an amicus brief in the case. 

JOIN EFF

The decision in Chatrie is important: It is the first digital surveillance decision by the Court since its landmark 2018 ruling Carpenter v. United States, which involved prolonged tracking of people’s movements using cell phone location data. The new case expands that ruling by confirming that even shorter-term surveillance of location data can constitute a search because it can still reveal “private matters,” including “a wealth of detail about a person’s familial, political, professional, religious, and sexual associations.”  

The case is also important because the Court also recognized the records generated by the apps on a user’s phone—records we necessarily share with third-party tech company—are a user’s “own” and require Fourth Amendment protection. This is true, regardless of whether those records are “emails, documents, photographs, [ ] calendars” or location data. This will likely have broad implications for data generated by other apps on our phones, even if we click “agree” to sharing that data with third-party tech companies.  

Geofence warrants don’t name a suspect or a specific individual or device the way typical warrants do. Instead, they compel companies—almost always Google—to provide information on every electronic device in a given area during a given time period. This creates a high risk of suspicion falling on innocent people and can reveal sensitive and private information about where individuals have traveled in the past. 

Geofence warrants are the digital equivalent of police going person to person, home to home, without suspicion that any device holder has a connection to a crime. This turns innocent bystanders into suspects, just for being in the wrong place at the wrong time.  

In Chatrie, a 2019 geofence warrant compelled Google to search the accounts of all its hundreds of millions of users to see if any one of them was within a radius police drew around a Northern Virginia crime scene. This area amounted to several football fields in size and encompassed numerous homes, businesses, and a church. 

A federal district court in Virginia in 2022 held that the geofence warrant plainly violated  the Fourth Amendment. If the police want to get information on every device in the area, they must also establish probable cause to search every person in the area, the court said. The judge noted the government lacked particularized probable cause as to every individual within the geofence, which swept up innocent people and covered over 70,000 square meters in a busy area. 

The decision set an important precedent in finding the warrant overbroad and unconstitutional and was later followed by a 2024 federal Fifth Circuit Court of Appeals ruling holding that geofence warrants are “categorically prohibited by the Fourth Amendment.” However, the Chatrie lower court allowed the government to use the evidence it obtained because it relied on the warrant in “good faith.” A much divided en banc panel of the U.S. Court of Appeals for the Fourth Circuit in 2025 affirmed this “good faith” finding in the lower court’s opinion. 

Google in 2023 announced changes to how it stores location data, with the effect of eventually making it impossible for the company to respond to geofence warrants. Since July 2025, mass geofence searches of Google users’ location data have not been possible.  

However, Google is not the only company collecting location data, nor the only way for police to access mass amounts of data on people with no connection to a crime. As we’ve written about extensively, data brokers collect and aggregate location data from many different apps on our phones and provide that data to police. And police can use “cell tower dump” warrants to get access to data on everyone within range of specific cell towers. Suspicionless searches like these drag a net through vast swaths of information in hopes of identifying previously unknown suspects—ensnaring innocent bystanders along the way. 

Chatrie could have wide-ranging implications beyond location data as well. The Supreme Court affirmed that app data is subject to the Fourth Amendment, because users “reasonably view” it as their own and reasonably expect it “to be shielded from the ‘inquisitive eyes’ of the government.” Justice Gorsuch, in an opinion concurring in the judgment, called location data a user’s “personal property,” no different from myriad other “effects” explicitly protected by the text of the Fourth Amendment.  As the Court concluded, “the point of carrying smartphones is to use what is on them,” so the Fourth Amendment has to protect more than just location data generated by the act of carrying the phone itself. 

The Court ultimately did not decide whether the particular warrant at issue in Chatrie was “reasonable” or whether the “good faith” doctrine applied. The case now heads back to the Fourth Circuit Court of Appeals to address these questions.  

But regardless of how the Fourth Circuit rules on remand, this Chatrie opinion will shape how lower courts address police access to location and other data going forward. We look forward to citing Chatrie to press future courts to recognize broad Fourth Amendment protections for user data.

EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits

26 June 2026 at 18:18

This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers or training AI on private information without users’ opt-in consent.

Grindr is a dating app for the LGBTQ+ community; and for queer people, privacy violations can have life-altering consequences. Information that reveals someone’s sexual orientation, gender identity, or HIV status can be used by employers, governments, family members, scammers, or bad actors to inflict harassment, discrimination, arrest, or violence. For example, data from Grindr and other gay dating apps was sold by data brokers and used to 'out' (the act of disclosing someone's sexual orientation without permission) a gay priest in 2021. 

Despite being the world's most popular gay dating app, Grindr has repeatedly mishandled users' sensitive data. Grindr has been caught sharing users' HIV status and precise location with advertisers without obtaining valid consent, resulting in reprimands and fines in several countries. Its former Chief Privacy Officer even sued, alleging the company fired him for raising concerns about Grindr prioritizing “profit over privacy."

Grindr ended several of its most egregious data sharing practices after they were exposed. But more changes are needed if Grindr wants to earn back trust and prove its commitment to users’ privacy and safety. This Pride month, we’re calling on Grindr to make privacy the default and ensure the immediate implementation of two changes to better protect its users:

Opt Users Out of Behavioral Advertising by Default

Grindr currently allows users to opt out of behavioral advertising, but that protection is not enabled automatically (except in some unspecified regions). As we’ve long warned, behavioral advertising relies on the collection and sharing of personal data across a vast network of advertisers, intermediaries, and data brokers. Once information enters this ecosystem, users have little control over where it goes or how it is used: people’s most private and intimate information can be aggregated, sold, and combined with information from other sources to create detailed personal profiles.

By default, Grindr appears to share data with numerous advertising and tracking companies. Using TrackerControl, an app developed by privacy researcher Konrad Kollnig, we recorded Grindr contacting 20 third-party tracking domains during 15 minutes of app activity (see Grindr_TrackerControl_06-23-2026.csv for exported results). TrackerControl observed Grindr contacting Big Tech companies and ad-tech intermediaries, many of which have faced significant legal scrutiny for privacy violations. Several of these companies auction off ad space through a process called “real-time bidding,” which can expose user data to hundreds of additional companies and be exploited by data brokers

The dangers of Grindr’s default settings exposing users’ personal data to this ecosystem are not hypothetical. Between approximately 2017 to 2020, a location data broker collected the precise movements of millions of Grindr users from digital advertising networks and made them available for sale. The commercially available data was allegedly so detailed that, in some cases, it could be used to infer romantic encounters between specific Grindr users. 

Although Grindr has stated that it no longer shares precise location data or profile information with advertisers, it acknowledges sharing other personal data, including mobile advertising identifiers (MAIDs)—unique, persistent device IDs that allow advertising companies and data brokers to connect data about the same individual across different sources. MAIDs are not anonymous, and an entire industry exists to link them to more directly identifying information, like emails and phone numbers. According to Grindr’s privacy policy, companies receiving users’ MAIDs “are aware that such data is being transmitted from Grindr,” which could expose a users’ sexuality to the advertising and data broker ecosystem.

Opt Users Out of AI Training on Personal Data by Default

Grindr should stop training its AI models on users’ personal data without opt-in consent. 

Grindr has been investing heavily in AI features as its CEO strives to make Grindr an “AI-first business.” New AI features include a wingman chatbot, profile recommendations based on users’ inferred “type”, summaries of previous interactions with other users, and AI-generated insights about other profiles (like responsiveness, typical online hours, and engagement patterns). By default, Grindr uses its users’ personal data to train the AI models behind these features.

Grindr claims to never use sensitive health information for AI training and requires users to opt-in to AI training on “special-category” data, which includes chat content and precise location. But Grindr automatically enrolls users in AI training on other private information, including profile photos, age, taps, and display names. Users must navigate several levels of Grindr settings to prevent these personal details from being used to train Grindr’s AI.

AI systems trained on personal data create new privacy risks, including the possibility that personal information may be retained, reproduced, or exposed in unexpected ways. For example, researchers have been able to extract training data from AI systems like ChatGPT.

Beyond AI training, Grindr enables AI-powered features by default and allows both “special-category” data and other personal information to be processed by those features. Even users without access to premium-subscription AI features could have their data automatically used to power those features for other users. “Behavior-based profile insights” (pictured below) could expose information that users would never choose to share publicly, like the types of people they interact with on Grindr, their typical online hours, and how often they initiate conversation with other users.

AI-powered profile insight stating that a Grindr user is "most likely to interact with Tops, ages 22-43, and tribes Discreet and Jock." Insight also displays the user's response rate, initiation rate, and when they're most active on Grindr.

Image of the “Profile Insights” feature from a Grindr blogpost promoting its premium, AI-first subscription

Regardless of whether new AI features leak private information, users deserve meaningful control over how their personal data is used and by whom. Grindr notifies users that their personal information may be used to train AI and that they can opt out on a separate settings page, but this notice does not specify the type of data used (i.e. profile photos, taps) and it is unlikely that people carefully read or understand it. Closing the notice or clicking its only button (which is “Proceed”) maintains Grindr’s default of using personal information for AI training. To respect users’ autonomy, Grindr should require opt-in consent before training AI models on personal data.

Notice entitled "AI for Personalization & Connection" describes the use of personal data for AI features. The only prominent button is "Proceed"

Notice displayed in the Grindr app about the use of personal data for new AI features

Celebrate Pride by Demanding Better Privacy

Grindr must immediately stop prioritizing profits over users’ safety. The ability to opt-out is not an acceptable substitute for opt-in consent, especially given the added risks of data sharing for LGBTQ+ users. Defaults matter—studies show that most people cannot or do not change the default settings of technologies they use.

If Grindr wants to back up its claim that it “takes user privacy very seriously,” it should make privacy the default across its platform, rather than something users need to go through complicated processes to opt in to. 

Hate “The Algorithm?” RSS Is One of the Tools You’ve Been Looking For

26 June 2026 at 18:06

Poke your head into just about any online social network—or any general conversations about internet culture—and you’ll likely find a boogieman: the algorithm. Since at least the moment Facebook introduced (and apologized for) its News Feed, “the algorithm” has been shorthand for the ways the tech giants control what we see and when we see it. In the age of enshittification, there is a push to reclaim our feeds and networks. Good news: there’s a tool that’s been around for decades that can help wrangle many of your feeds into something manageable: Really Simple Syndication, more commonly known as RSS.

What’s RSS and How Do I Use It?

RSS has been around since 1999, but its real publicity glow-up came from Google Reader, a newsreader service that Google offered between 2005 and 2013. Despite the alarm bells people rang at the time, the death of Google Reader wasn’t the death of RSS, and many replacements have come and gone over the years.

RSS may seem complicated, but it boils down to one general concept: when websites publish new content, like news articles, blog entries, webcomics, videos, or podcasts, that content gets added to an RSS feed, where your RSS reader (aka newsreader, feed reader, or aggregator) will show you that content in chronological order. If you’ve ever used a podcast player like Apple Podcasts or Spotify to follow different podcasts, you’ve used RSS. You can think of it like an internet-wide “follow” button, where you can track the contents of websites, users, and more.

People talk about RSS like it’s a power user’s secret trick to making the internet more usable, but the real secret is that it’s not that hard to set up and use. Here’s what you need to do:

  • Find an RSS reader: RSS readers come in many forms. Feedly, NewsBlur, or The Old Reader, are web-based, but have their own apps (though they also support third-party apps). Others, like NetNewsWire, are app-based, and support either using a web-based RSS reader like Feedly, or a local file. Some live in browsers or web extensions. There’s an abundance of choice in RSS readers, and part of the fun is finding one that best accomplishes what you want to do. But don’t worry about finding the right RSS reader right away. One of the many magic tricks of RSS is that it is platform agnostic, and nearly every RSS reader—whether it's a website or an app, supports importing and exporting a list of the sites you subscribe to. This means you can change RSS readers in a couple minutes. If you need some help finding an RSS reader, Wired, The Verge, and Privacy Guides all have useful roundups. 
  • Collect your feeds: As for adding websites to your feeds, the process is straightforward. Most RSS readers are designed to help find the feed for a site for you, so you don’t need to go hunting down a special link. Just drop the URL of what you want to follow in your reader, and if an RSS feed exists, it should be able to find it. If not, some sites, including ours (and our current podcast, EFFector as well as our last series, How to Fix the Internet), provide direct links to our RSS feeds.
  • Sort, filter, and build your feed: Adding a bunch of new feeds can be overwhelming, particularly for news sites. RSS readers typically include folders, which let you group similar feeds together and can be great for lifting up low-traffic updates you don’t want to miss. Your reader may also have different filters, like the option to block any article that contains “sponsored post.” 

RSS Is the Best Way to Follow the News

It can be very difficult to follow the news, whether that means politics, tech policy, or your hobbies. Solutions like Google News or Apple News have tried to make this simpler, but many find that their algorithmic feeds are as often a source of frustration and annoyance as they are genuinely useful. And no matter how often you tap on news stories that matter to you from publications you respect, there may always be stories that refuse to bubble up.

RSS can make reading the news much easier, reliable, and more private. The vast majority of news sites have RSS feeds you can subscribe to, and many, including CNN, The New York Times, BBC, Wired, Politico, and many others, offer RSS for specific sections or special feeds that include the full text of articles for subscribers, so you aren’t just pummeled with a firehose of news all day long (we’ll get to a tip below in the next section that tackles this problem if they don’t have separate feeds, though). In many cases, you can read articles right in your RSS reader, never being forced to engage with wonky comments sections or poor design choices on websites.

Of course, the news isn’t just general news sites, it also includes hobbyist or more niche sites, local news offerings, and blogs. Most of these sorts of websites also offer RSS feeds, as do newsletter platforms like Substack or Ghost. 

RSS Offers One Way to Fix Some Social Feeds

Decentralized social media like Mastodon, Bluesky, and Threads, use RSS for user feeds, so you can follow your friend’s posts on Bluesky or Mastodon without actually having an account on either. This can be especially helpful for news sources, too—where you likely wouldn’t want to subscribe to a feed of everything a national news organization publishes because that would include dozens if not hundreds of stories a day, you can instead subscribe to their social media posts, which often get you the most breaking or important news.

The internet is more than just Facebook.

Some legacy social media works with RSS, too, including YouTube, Reddit (though that is currently at risk), and Tumblr. But others, like Facebook, LinkedIn, and Instagram, wall off posts behind account requirements that seem to pop up if you simply look at an account page for too long, let alone come in from an RSS feed. These walled gardens prevent information from getting out there, which ranges from annoying, like when your favorite local brewery only posts their food truck schedule on Instagram, to dangerous, like when local public services only post to a Facebook page.

The internet is more than just Facebook. It’s more than Mastodon or Bluesky, too. It’s a decentralized smorgasbord of websites, tools, feeds, newsletters, social profiles, and more, and treating it as such will help us wrangle the information we want and trust. 

Other Surprising Places You’ll Find RSS Feeds

When in doubt, try copying and pasting the URL for a site into your RSS reader of choice, you might be surprised to find a feed that proves useful to you. Many places on the internet may offer RSS feeds without you even realizing it. For example, if you want to keep an eye on an artist’s prints that you like, but you don’t have Instagram where they usually post, you might be able to subscribe to their webstore, as some shopping platforms, like Big Cartel, create XML feeds that some RSS readers can read. And for something even more tweakable, even Google Alerts can be turned into RSS feeds.

RSS is one of the best examples we have of the open web, where we can design and customize how we experience the internet, not the other way around.

If you prefer to track policy over products, then you’ll be happy to know that government sites often support RSS, including most U.S. government sites, many of which break them into different sections like the U.S. Department of State’s various feeds. Many local governments or other public services, like fire departments may offer the same. Some universities (and university newspapers) also sometimes offer some RSS feeds. 

And even if a website doesn’t have an RSS feed, there are workarounds from tools like RSSHub, RSS-Bridge, and RSS.app that require varying levels of technical expertise or a willingness to pay subscription fees.

RSS is one of the best examples we have of the open web, where we can design and customize how we experience the internet, not the other way around. RSS has come in and out of fashion, been declared dead, and has come back, every time. Open systems are the best way forward to a free, equitable internet, and the resilience and continued reinvention of RSS has shown just how creative the web community can be with open protocols.

Correction: clarified that Big Cartel creates an XML file, not an RSS feed.

We Can Still Stop California’s 3D Printer Surveillance Scheme

26 June 2026 at 17:05

Ignoring EFF’s warnings about the dangers and impossibility of implementing a new mandate for 3D print surveillance software, the California State Assembly has signed off on legislation to do just that. In the process, legislators amended the bill to make it even more confusing, while failing to address the risks to privacy, speech, and consumer rights. We must renew our call on legislators to drop this bill as it heads to the state senate, and protect the tools of creators in the state.

Take action

Tell CA Senators to stand with creators

What’s changed about the bill?

Since we first wrote about AB  2047, a bill targeting 3D printers for the rare, impractical, and already outlawed practice of manufacturing firearms without a license, it has picked up several amendments. Some are welcome changes, but most have only highlighted the technocratic absurdity of the proposed scheme. Our core concernsthat this mandate censors lawful speech, builds out corporate surveillance, and criminalizes open source experimentationhave not been remedied. 

Removes criminalization of resale

Starting with one silver lining, the current bill includes a carveout for the private resale of devices. The original bill would have made it a criminal offense for an individual to resell 3D printers purchased before this mandated censorship and surveillance software. This is a clear win for the 3D-printing community, but it is unfortunately not enough.

Ineffective carveouts for open source

One of the most dangerous aspects of the bill is that it criminalizes individual users for common practices, like creating and using alternative open source programs with their 3D printer. New amendments provide a carveout for the use of an open source tool, but only if it includes compliant censorship software. The bill burdens open source developers with ambiguous and unrealistic standards for print blocking, and continues to create a chilling effect for open source users.

Removes any actual requirement to work

To reiteratethere is no world where the mandated technology actually works as intended. It will both block lawful use of 3D printers, and allow firearms to be printed by anyone determined to do so. There is no amendment that can change this reality.

Instead, the current bill simply drops the pretense that this mandate is expected to work. The performance standard of algorithms changed from “effectively prevent[ing] a technically skilled user from evading [the algorithm]” to “substantially reduce the likelihood of foreseeable circumvention attempts…” The bill will still require all prints to be surveilled, but instead of testing efficacy against a skilled user, it just plays whack-a-mole with the (literally) infinite number of circumventions that any user can employ. 

Further, the bill now leaves us with an unclear process that relies on non-governmental third parties to define standards, and now relies on manufacturers and resellers to self-police.

Hollywood gets a cut

The bill includes yet another carve out for commercial users. This time for the entertainment industry, which makes extensive use of 3D printers for props and costumes. 

That’s fine for big studios, but it leaves out indie filmmakers, cosplayers, and many other small creators. 

This is simply a defensive edit to limit corporate opposition. There isn’t a clear division in 3D-printing between consumer and commercial tools. These are general purpose tools which might be picked up by a prop department of a big studio, or an artist getting ready for Comic Con. Indeed consumer level products are not only used by amateur artists and engineers developing their skills. Commercial 3D printers, like their traditional 2D equivalents, are frequently used in workplaces, as well as by professionals honing their skills or just trying to get some work done at home. 

Commercial carveouts hands printer manufacturers the ability to sell a more expensive tier of printers, locking-in and up-charging their commercial customers. Some of those customers will choose to buy general retail versions, but that carries its own price: increased risk of IP theft as all printed files are surveilled the same way they are for hobbyists. That means a real risk of businesses leaking any prototypes or new designs to not only the printer manufacturer, but potentially snooping governments and/or the general public through data breaches.

Demand  your senator oppose AB 2047

This updated version of AB 2047 downgrades performance standards and removes oversight while still threatening privacy and choice for users of 3D printers. A printer surveillance system won’t work for its intended purpose, and will only harm law abiding users. 

Act now to demand your senators to vote no on this ineffective and invasive bill.

Take action

Tell CA Senators to stand with creators

EFF, TEDIC and CEJIL Challenge Secrecy in the Use of Face Recognition in Paraguay

25 June 2026 at 23:15

Seeking transparency and accountability in Paraguay’s use of facial recognition, EFF, the Association of Technology, Education, Development, Research, Communication (TEDIC), and the Centre for Justice and International Law (CEJIL) filed a complaint with the Inter-American Commission on Human Rights against the state for arbitrarily denying access to information about its implementation and use of the technology as a tool for mass surveillance that erodes people’s privacy rights. 

The case involves the Ministry of the Interior and National Police’s installation in 2019 of surveillance cameras with facial recognition technology in Asunción. Maricarmen Sequera, a lawyer and executive director of TEDIC, filed an information request with the ministry seeking details and protocols about the implementation and use of facial recognition systems and the personal data processing involved. 

The request sought information about, among other things, whether the state had conducted human rights or data protection impact assessments, as well as if it had developed measures and protocols for avoiding abuses, illicit uses of personal data, and other risks in the deployment of the facial recognition system.

The state denied most of the information requested, arguing that implementation details, protocols, and the processing of individuals' personal data were confidential security information. TEDIC contested the secrecy in courts, but the analyses lagged and ultimately sustained the denial of information. 

The petition filed last Friday (19) cites Inter-American standards upholding the public’s right to access information, particularly in relation to national security, that the Paraguayan authorities disregarded in denying TEDIC’s information request. The petition also argues that the refusal of information violated privacy and the right to informational self-determination.

The petition asks the Commission to recognize a violation of those rights and require the state to deliver the information requested. Further, the petition seeks an order compelling the state to adopt mandatory permanent mechanisms of active transparency regarding the acquisition, contracting, implementation, financing, functioning, and use of surveillance technologies by public bodies, especially those that incorporate processing of biometric data or artificial intelligence systems. 

It also asks the Commission to order the state to mandatory procedures for human rights impact assessments prior to acquiring and using surveillance technologies, particularly those that collect biometric data or use artificial intelligence.

The state’s lack of transparency in this case is not an isolated incident, both in Paraguay and in Latin America, where opacity in matters of security and surveillance is the unsettling rule. The situation gets worse with the increasing normalization of intrusive surveillance technologies by states in the region.

The Special Rapporteur for Freedom of Expression of the Inter-American Commission emphasized that states should disclose surveillance capabilities and contracts, and acknowledge state use of surveillance technologies at a meaningful level of detail, to facilitate essential public debate on the necessary limitations of surveillance in democratic societies and ensure compliance with international human rights law.

We hope that the Inter-American Commission upholds the robust safeguards in the Inter-American System and advances access to information and privacy rights in a case that can set a crucial precedent for the region.

The FCC’s Spam Call Proposal Is Just a Data Collection Scheme

25 June 2026 at 19:28

The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting scam and spam calls. This plan will fail to combat the deluge of unwanted calls people in the United States receive every day while giving untrustworthy companies a gold mine of information that would harm everyday consumer’s privacy, access to communications, and ability to speak freely. 

The requirement to provide ID and an address would completely cut off the ability to have an anonymous phone line, which would mean many people in the most precarious situations imaginable: domestic violence and human trafficking survivors, unhoused people, and children without stable homes, would not be able to gain access to a crucial lifeline. EFF, along with ACLU, has submitted comments advising the FCC to abandon this proposal entirely

This Rule Will Not Decrease Spam Calls 

Requiring phone providers to collect consumers’ information will not appreciably decrease or eliminate unwanted calls. The FCC knows this because it confesses in its own rulemaking that “the most effective way to prevent unwanted calls from reaching American consumers is by ensuring they never enter the network.” Further, the Federal Trade Commission found that “a significant proportion, if not the majority, of unwanted robocalls originate from overseas.” Collecting the personal information of everyone who wants to make a phone call will not put a dent in fraudulent calls. 

What will address unwanted calls is the FCC’s STIR/SHAKEN technical standards, which already exist. While STIR/SHAKEN is not perfect, it is actually a technical solution to the problem of spam calls. And where less than 50% of American telecommunication providers have fully implemented the protocol, the FCC should put its energy toward 100% compliance to reduce the scale of unwanted calls, instead of collecting consumer’s private information. 

The FCC gives away the true reason for this proposal in their own comments: this is a move to shut down the very existence of anonymous phones, aka burner phones. FCC says in their comments: 

“Enhanced KYC information can assist law enforcement to more easily identify callers that use the network to perpetuate crimes by ensuring that voice providers have accurate and complete customer information. The KYC information gathered and verified would help ensure that law enforcement gets accurate information in response to subpoenas when investigating crimes. For example, can enhanced KYC rules assist law enforcement in investigating organized criminal groups that use the network to facilitate illegal activities? Can they be used to deter or detect trafficking operations that use communication networks to buy and sell illicit goods?”

Anonymous phones are not just used by people to break the law, they are also used by activists who wish to remain anonymous, privacy conscious consumers, people escaping domestic violence, people escaping human trafficking, journalists who need to reach out to confidential sources, and other people in desperate situations. Anonymous phone lines are a lifeline to many, one which this proposal would cut off without any alternative. 

Mass Data Collection Makes Us All Less Safe

Mass data collection of individuals does not address unwanted calls, but it does make us all less safe online. The telecommunications industry has proven time and again that they’re poor stewards of personal information. They’ve been at the center of several large-scale data breaches in recent years and their data practices leave much to be desired.

In 2024, AT&T disclosed two large data breaches. One in which 7.6 million existing account holders and more than 65 million former customers had their information leaked onto the dark web, and another in which more than 100 million customer account call and text logs were downloaded. Another large provider, Comcast, suffered a data breach in 2023 where nearly 36 million account holder’s information was stolen, including the last four digits of their Social Security Number and date of birth. 

In 2024, the nation’s CALEA infrastructure, which law enforcement uses to tap and trace calls, was breached in the Salt Typhoon attacks. Experts maintain that U.S. communications networks remain vulnerable, and even this administration acknowledges these attacks as an ongoing threat. 

If telecoms can’t even protect the most sensitive communications infrastructure in the nation how can we expect that they will protect our identities?

In addition to their poor cybersecurity practice, these providers themselves abuse the information in their possession. In Scott v AT&T, AT&T, among others, made consumer information available to hundreds of third parties without the consumer’s express consent. Though the case was dismissed because AT&T forces its consumers to sign arbitration agreements, it shows the complete lack of care for their consumers' privacy. 

A Lack of Anonymity Silences People 

Mass data collection of individuals just to have a phone number will also harm and silence people. Anonymity in calls provides people the safety they may require to organize themselves, speak freely, and seek services. Anonymous phone calls give people the courage to participate in politics, organize themselves, reach out to a suicide or sexual-assault hotline, an addiction-recovery sponsor, seek medical care, seek escape from a violent and coercive situation, and do much more. Without this anonymity, people may otherwise not do any of these things. 

It will prevent many from obtaining phone numbers at all. 

Not everyone has all the information the FCC wants to require. The FCC wants people’s physical addresses, defined so narrowly that it’s essentially a home address. Not everyone has a stable home address, so those individuals would be not able to get phone service. 

FCC suggests that a government-issued identification should be required for any phone service. About 15 million adult U.S. citizens do not have a driver’s license, while about 2.6 million do not have any form of government-issued photo ID. Others don’t have access to their identifying documents, they may be controlled by an abusive spouse or parent, human trafficker, cult, or someone else from whom a secondary phone line could help a person escape. Estimates show another 21 million adult U.S. citizens do not have a non-expired driver’s license, and over 34.5 million adult citizens have neither a driver’s license nor a state ID card with their current name or address. 

These numbers do not include non-U.S. citizens who do not have current government-issued identification, including undocumented immigrants who cannot obtain a state ID or driver’s license. Black American and Hispanic Americans are disproportionately less likely to have current drivers’ licenses, and Americans with disabilities and Americans with lower annual incomes are also less likely to have current driver’s licenses. 

The FCC’s proposal will not decrease the amount of unwanted calls. All it will do is set up a data collection regime that harms everyday, law abiding Americans. This proposal makes us less secure online, strips away our right to anonymous speech in calls, and actively disconnects those Americans who are already at the margins. EFF recommends the FCC discard this proposal in its entirety. 

The window for reply comments can still be filed until July 26th. Express comments, which are appropriate for most individuals, can be filed on the FCC website. See the suggested language below to help you get started. 

The KIDS Act Would Require Age Checks To Get Online

25 June 2026 at 08:40

Within the next week, Congress is preparing to vote on the KIDS Act, a sprawling package of legislation that seeks to control Americans’ web browsing and private messaging. The package includes a revised version of the Kids Online Safety Act, or KOSA, combined with a collection of other internet bills, study bills, reporting requirements, and new regulations. Instead of debating any of these proposals on their merits, lawmakers are attempting to move them all at once under an ultra-expedited process. 

The package of cobbled-together bills is a mess, with different age-gating schemes for different services, using different standards. It’s a lot of complexity, and a lot of legal risk. Faced with that, many companies will conclude that the safest option is restrictive age-checking practices across their entire platforms.

Buried inside the KIDS Act are provisions that will push online services to verify all users’ ages, require government-directed moderation policies for online speech, and even create new rules about private and encrypted communications. While supporters continue to claim this bill protects minors online, its requirements come at the expense of privacy, free expression, and the ability of people of all ages to use the internet without revealing sensitive data. 

Take action

Tell Congress to reject this age-gating bill

The KIDS Act Pressures Platforms to Check Everyone's Age

Supporters of KOSA have said the bill doesn’t require age verification. And technically, the KOSA section of the bill does say that KOSA shouldn’t be read to require age verification. 

But if you read the rest of the bill, that disclaimer starts to look hollow. 

Throughout the KOSA section of the legislation, special protections, controls, messaging settings, and parental tools are required whenever a website or app “knows or should have known” a user is a child (defined in the bill as anyone under 13) or a teen (defined as anyone between 13 and 16 years old). 

The problem is a website operator doesn’t need actual knowledge that a user is a minor to get in legal trouble. It applies when a platform “knows or should have known” a user’s age—a low, negligence-style standard of knowledge. If an online service gets it wrong, it’s going to be up to courts and regulators to decide, after the fact, if an online service “should” have known a user was 16. 

To try to avoid liability, services will have to determine which users are teenagers and which are not. Most won’t be able to simply trust their users. They’ll have to collect more information about age, before any lawsuit or government action arises. Some companies may respond by requesting driver's licenses or passports. Others will rely on age-estimation systems that attempt to guess users' ages by looking at existing activity or doing facial scans. Existing estimation systems make mistakes when estimating children’s ages correctly, which is a big problem when that is the population KOSA is trying to protect. And the systems fail more frequently for people of color, people with disabilities, and trans and nonbinary people.

The bill’s authors seem to know this is a problem. On the one hand, the new KOSA section says age verification is not required. On the other, it repeatedly imposes obligations that depend on knowing whether a user is under 17. But a disclaimer doesn’t magically eliminate legal risk, especially for smaller services and startups that can’t afford to defend lawsuits or fight regulators.  

Take action

The "KIDS Act" Is an Age Surveillance Bill

KOSA is not the only part of this package that creates age-verification pressure. The SAFE BOTS Act, like KOSA, goes back to the standard that if a service “knows or should have known” that a user is a minor it can’t offer certain chatbot features. 

The SCREEN Act requires services that host sexually explicit content to determine whether users are “more likely than not” under the relevant age limit, before allowing access to certain content. 

The consequences of this liability will not be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. The result is a less private internet for everyone.

The KIDS Act Pressures Platforms To Police Lawful Speech 

The new version of KOSA removes the bill’s infamous "duty of care" provision, a significant change. The revised KOSA requires covered platforms to "establish, implement, maintain, and enforce" policies and procedures addressing several categories of content and conduct. 

Some categories, such as true threats and sexual exploitation, involve unlawful activity. Others are much broader. The bill specifically requires policies addressing the "sale or use" of narcotic drugs, tobacco products, cannabis products, gambling, and alcohol. It also restricts discussions around financial fraud.

Sounds straightforward enough. Then you remember how people actually talk—online and off. Can teens discuss addiction and recovery? Can a 15-year-old post that she’s worried she has a friend who is drinking too much? Can they seek advice about a parent’s gambling problem, or get help if they or a family member have been scammed? Can they participate in harm-reduction communities or discuss substance abuse treatment? All of these young people would be engaging in lawful speech when discussing topics covered by KOSA’s enumerated harms. 

The bill does not directly ban those conversations. But it places platforms under huge pressure to create and enforce moderation policies around broad categories of lawful speech. Faced with legal risk, many services will inevitably choose to remove that speech or restrict those discussions to spaces where they know only adults can participate. We’ve seen this movie before. When legal risk goes up, platforms will take down more speech. 

The KIDS Act Regulates Private Messages, Too 

Several provisions of the bill create new rules around direct messages, disappearing or “ephemeral” messages, and AI chat services. 

The bill includes language stating that certain KOSA requirements should not be construed to override strong encryption. But the protection is incomplete. The carve-out applies to certain features and messaging controls, but doesn’t apply to KOSA’s separate requirement that platforms "address" a list of harms to minors. 

The KIDS Act never answers an obvious question: how exactly is a platform supposed to address those activities if they’re inside encrypted communications that it can’t read? That will create pressure for providers to weaken private communications or limit features on encrypted private services. 

That approach is especially troubling when it comes to ephemeral messaging. Disappearing messages are not a “loophole” or a dangerous design trick. They are a useful privacy feature that allows online conversations to function more like ordinary real-world conversations, which are not preserved forever in a permanent database.

Like many other parts of the KIDS Act, these private messaging provisions also depend on websites and apps knowing who is a minor and who is not. The result is more age checks, more restrictions, and less privacy online.

Take action

Tell congress: no online age checkpoints

The UK’s New Under-16 Social Media Ban Will Cause More Harm Than It Prevents

19 June 2026 at 11:45

This week, politicians in the UK pushed forward with plans to eviscerate privacy and free speech on the internet by announcing a ban on social media for users under 16 that is set to take effect in Spring 2027. 

The UK government continues to falsely characterize this policy as a necessary response to growing concerns about online harms for young people. In reality, much like the Online Safety Act, it will cause more harm than it will prevent. 

Users of all ages are burdened with proving their age before accessing content, with social media platforms such as Snapchat, TikTok, YouTube, Instagram, Facebook, and X included in the ban. There remains no reliable, privacy-preserving method of verifying the age of every internet user and methods vary from one platform to the next.

Young people will not simply be protected from being contacted by adults or endlessly scrolling—they’ll also lose access to educational videos on YouTube, local events on Facebook, and potentially cut off from distant friends and family. 

Public policy must be effective, proportionate and respectful of fundamental rights. Young people deserve better than a policy built on panic, and all internet users deserve a safe and free internet. A social media ban generates headlines, but it will not solve the problem. 

A Brief History of Age-Gating in the UK

Age restriction proposals in the UK date back to a decade ago, when the proposed Digital Economy Bill was put forth to (among other things) restrict young people from accessing pornographic websites. While the Digital Economy Act of 2017 passed without age-based restrictions, it laid the groundwork for later age verification measures.

Over the next few years, age checks for porn websites were announced then delayed several times. But it wasn’t until a consultation under the 2016-2019 May government and the 2020 publication of the Online Harms Whitepaper that age verification became a broader idea.

In 2023, the UK passed the controversial Online Safety Act, establishing powers that could weaken privacy protections and freedom of expression for internet users worldwide. In July 2025, the government implemented age assurance measures on sites hosting “harmful” content. 

And despite politicians affirming repeatedly that the Online Safety Act would solve all of the problems with online safety, this year they decided it in fact did not go far enough. American social psychologist and The Anxious Generation author Jonathan Haidt—who has called for age-related social media bans around the world, despite significant scientific doubt about his research—met with the UK Health Secretary in February to push for the ban.

In March, politicians introduced plans for a social media ban into the Children’s Wellbeing and Schools Bill to “prevent children under the age of 16 from becoming or being users” of “all regulated user-to-user services,” to be implemented by “highly-effective age assurance measures”—effectively banning under-16s from social media. 

When this proposal came before the House of Commons, MPs defeated and proposed their own amendment: enabling the Secretary of State to introduce provisions “requiring providers of specified internet services” to prevent access by children, under age 18 rather than 16, to specified internet services or to specified features; and to restrict access by children to specified internet services which ministers provide. 

But the social media ban does not stop there. The provision also requires internet service providers to limit the time kids spend online, and has rules about who can contact them online. These extreme rules will take decisions about using technology away from families and put them in the hands of government regulators. 

The history of this proposal shows that the UK government has repeatedly returned to the same flawed idea: restricting access to online services by requiring age checks for everyone. But the fundamental problems have not changed. There is still no widely available way to verify age online without compromising privacy—but even if there were, broad restrictions on social media will inevitably limit access to lawful speech, and valuable online communities, and arts and culture.

❌