Reading view

There are new articles available, click to refresh the page.

EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices

With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. 

Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public's security.

When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else's computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test environment, disconnected from other systems, and be monitored and logged. Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.

That said, any proposal must be flexible enough to evolve with changing technology. Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time. Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.

Strong legislation should also mandate and fund independent third-party investigations into any serious security incidents that may occur during AI labs’ tests of new tools, and make reports of these investigations available to the public. This important transparency measure would go a long way toward providing public oversight of the industry.

As with any technology regulation, those targeting cybersecurity practices at AI labs must be careful, precise, and practical.

California’s “Addictive Feeds” Law Violates Teens’ First Amendment Rights

A California law that prohibits teens from receiving recommended social media content from other social media users violates their First Amendment rights, EFF argued this week.

The case, Meta v. Bonta, challenges SB 976, which requires that teen social media users get their parents’ permission before seeing other users’ recommended speech on their social media feeds. The legal challenge to SB 976 has largely centered on how the law violates social media services’ First Amendment rights to curate user-generated content and present it as they see fit.

But the friend-of-of the-court brief EFF filed along with the Center for Democracy & Technology and the Wikimedia Foundation shows that the law violates teen users’ First Amendment rights, too.

“SB 976 frustrates young people’s ability to use the internet to its full potential, prohibiting them from relying on tools that disseminate their speech and help them view and interact with other users’ speech,” the brief argues.

Recommendation systems have a dual purpose on social media: they help all users discover speech and content by other users, and to get their own speech in front of a wider audience.

“SB 976 creates significant, constitutionally violative, burdens on young users’ ability to read and comment on the news, discuss politics, find and share art, share their religious beliefs, or even practice their religion with fellow members of their faith,” the brief argues. “There is simply too much content on services for users to sift through manually, and young users may not know what to search for or even how to find content.”

Because SB 976 creates such broad burdens on teens’ ability to distribute and receive speech, it should be struck down on First Amendment grounds. But as EFF’s brief argues, the First Amendment doesn’t stop California and other states from passing laws that help all users, regardless of age, avoid major social media services’ harmful surveillance business models.

“One could imagine a law that required services to minimize the amount of data they collect, or limit using more invasive data analysis practices, such as tracking users across multiple services, analyzing keystrokes, and other surveillance-intensive practices,” the brief argues. “Such restrictions likely would serve the state’s aim of protecting all internet users—including minors—and would be more narrowly tailored to addressing the harms those practices cause than SB 976.”

Victory! Appeals Court Rejects Expansive New Copyright Claim

 The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyright liability.  

The case involves Section 1202 of the DMCA, which prohibits intentionally removing copyright management information (CMI) like an author’s name or a copyright notice, from a copyrighted work. Open AI and Microsoft used code from Github as part of the training data for their LLMs, along with billions of other works. A group of anonymous Github contributors sued, alleging the new code coming out of these LLMs was similar to theirs—but with the CMI stripped out.  

The Ninth Circuit correctly agreed with what we said in our briefremoving copyright information from a copyrighted work is fundamentally different from creating a new work that didn't have CMI in the first place. Section 1202 of the Digital Millennium Copyright Act was intended to serve as a backstop for traditional copyrights in the digital age—not to create a new, more expansive right to inhibit otherwise non-infringing uses. 

As we also explained, accepting the Does’ theory would have created a brand-new source of liability for otherwise perfectly lawful activities, undermining creativity and innovation far beyond the specific context of AI development. Copyright holders would be able to file costly lawsuits against all kinds of legitimate users, such as artists making remixes based on older works, teachers adapting works for a classroom presentation, engineers reverse engineering code to understand it better, and search engines that help us all navigate the web. The risks would have fallen especially hard on independent software developers and other small creators. Large companies can afford to litigate these claims in federal court for years, if necessary. But an independent programmer facing massive statutory damages may simply have to settle, even when their underlying use is completely lawful. That’s why EFF fights to make sure courts don’t expand copyright beyond what Congress authorized.  

Copyright law still protects programmers when their work is unlawfully copied. They can still bring copyright infringement claims if someone uses a model to reproduce their code. Additionally, the plaintiffs’ contract claims against the AI companies are still in play. The specific holding here was narrow but important: that the absence of copyright information from a new work does not mean, by itself, that someone illegally removed it.  

That’s the correct result. New technologies will keep raising hard questions about copyright. Courts should answer those questions by applying the rights that Congress actually authorized, not by inventing new rights that could harm expression and lawful use for everyone.  

Additional Reading:  

Victory: Court, Using a New Test, Rules Embedding Links is Legal

Courts have for two decades found that linking and embedding someone else’s web content, be it a photo, music, or an article, doesn’t violate copyright law–the entity that controls the server that hosts a copyrighted work, not the user or website that merely directs others to it, is directly liable if the content turns out to be infringing.

News publisher Emmerich Newspapers sought to convince the Fifth Circuit Court of Appeals to chart a new and dangerous course, arguing that an aggregator website that published links to its copyrighted articles was in effect “displaying” them and can be directly liable for infringement. EFF, along with several other public interest organizations and trade associations, filed a brief urging the court to follow multiple other circuits and reject that theory.

Fortunately, the Fifth Circuit Court of Appeals did just that. While it rejected the server test–the rule courts have used to determine copyright liability rests with whoever serves up the content–the court came to the same practical conclusion by focusing on who is responsible for transmitting content. 

Applying that test, the court found that pointing or directing a user’s browser to request and receive the copyright owner’s own copy residing on its computers does not involve transmitting or communicating the content. “Although we take different routes to get there, both the server test and the test we announce end up in a similar place: a website cannot transmit a work that it does not have,” the court said

We told the court that accepting Emmerich's theory would make the common act of embedding links a legally fraught activity, one that many websites might be unwilling to risk, which would seriously damage the internet as a tool for creating and disseminating ideas and knowledge,

We applaud the court’s decision–even though it applied a different test, it correctly concluded that a user linking pictures, video, or articles isn’t in charge of transmitting that content to the world. The user doesn’t control what’s located on the other end of the link—that’s up to the person who controls the server.

Emmerich also claimed linking violates the Digital Millennium Copyright Act (DMCA), arguing its URLs were copyright management information (CMI) and when the aggregator displayed Emmerich’s articles under its own URL, it tampered with Emmerich’s CMI, which violates the DMCA. 

Under that logic, unsuspecting internet users could face ruinous legal risk for doing something as simple as using a link shortener, particularly given potential statutory penalties of up to $25,000 per violation.  

In our brief, we told the court that URLs don’t necessarily equate to a copyrighted work or provide sufficient information about the nature of the underlying content, making it highly unlikely that anyone would expect a URL to contain CMI. Quoting EFF’s brief, the court concluded that URLs are first and foremost a locational reference tool and while it may be possible for a URL to contain CMI, the bar to that conclusion is high.

Overall, this was a good and sensible decision that will protect ordinary online expression, communication, and access to knowledge. Hopefully this issue is laid to rest at last.

EFF Welcomes Alexander Macgillivray to its Board of Directors

The Electronic Frontier Foundation (EFF) is honored to announce today that Alexander amac Macgillivray — a former White House official who also served in top legal capacities at Twitter and Google — has joined EFF’s Board of Directors. 

Macgillivray served in the Biden Administration as Deputy Assistant to the President and Principal Deputy U.S. Chief Technology Officer in the Office of Science and Technology Policy, and earlier had held a similar position in the Obama Administration. Macgillivray was one of the co-authors of the Biden Administration’s Blueprint for an AI Bill of Rights and oversaw many of the Administration’s AI initiatives, such as organizing its AI CEO convening, leading its working group on federal AI policy, and overseeing the creation of the National AI Research and Development Strategic Plan and National AI Research Resource. 

He was Twitter's General Counsel from 2009 to 2013, leading the Corporate Development, Public Policy, Communications, and Trust & Safety teams. Before that he was Deputy General Counsel at Google from 2003 to 2009, where he created the Product Counsel team.  

“One of the things I am currently focused on is positively impacting AI development,” Macgillivray said. “The EFF is uniquely situated for that purpose because it combines top-notch legal, technical and advocacy staff with a long history of fighting for people’s rights while encouraging the positive development of technology. I’m thrilled to be joining the board.”

Macgillivray joins a dynamic EFF Board led by Board Chair Gigi Sohn and Vice Chair Brian Behlendorf, and including fellow Board Members Erica Astrella, Anil Dash, Sarah Deutsch, Tadayoshi Kohno, Pamela Samuelson, Bruce Schneier, James Vasile, Tarah Wheeler, and Jonathan Zittrain.

“The EFF Board is thrilled to have Alex join our ranks, Sohn said. I’ve worked with Alex for over two decades and have always been impressed not only with his intelligence and grace, but also his ability to think outside the box. His deep experience with non-profit boards will be invaluable as EFF enters a new and exciting chapter.”

Macgillivray currently also serves on the boards of The Trust & Safety FoundationThe Trust & Safety Professional Association and Public Resource. He is an affiliate at the Berkman Klein Center for Internet & Society at Harvard University. Macgillivray earned a law degree from Harvarda bachelor’s degree in Reasoning & Decision Making from Princeton University, and a New Jersey Teaching Certificate

“The vanguard leadership of EFF Board members to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical, EFF Executive Director Nicole Ozer said. Many of the threats that once seemed hypothetical are now reality and the work of our EFF community is fundamental to the future of our countries, our livelihoods, and literally our lives. I feel fortunate to have amac join as a Board member as I begin my tenure as Executive Director. His diverse expertise will be invaluable to make sure that EFF is stronger than ever to meet this moment.” 

Members of the Board of Directors ensure the managerial and financial health of the organization.  EFF is the leading nonprofit organization defending civil liberties in the digital world. Learn more about our cutting-edge work on AI issues, and please donate today to help keep us fighting for a brighter digital future.

Donate to EFF

👮 Flock Searches for the LOLs | EFFector 38.16

Mass surveillance isn't a joke. But police are treating it like one when using automated license plate reader (ALPR) networks. In our latest EFFector newsletter, we're covering a new EFF report on how officers across the country are routinely logging completely nonsensical "reasons" for their Flock searches, including "LOL," "LMAO," and even (yuck) "Sexy."

JOIN OUR NEWSLETTER

For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers a settlement enshrining Meta's harmful surveillance into law, states pushing back against ALPR, and how police are turning our privacy into a punchline.

Prefer to listen in? EFFector is now available on all major podcast platforms. This time we're asking EFF's Adam Schwartz what has united people against Flock cameras — and how we can make sure that today's backlash leads to lasting change. You can find the episode and subscribe on your podcast platform of choice:

play
Privacy info. This embed will serve content from simplecast.com

Listen on Spotify Podcasts Badge Listen on Apple Podcasts Badge  Subscribe via RSS badge

Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!

How the Meta Settlement Silences Youth Activism

Since its integration into our digital world, social media has played a pivotal role in youth organizing and social mobilization. Yet, people’s access to these platforms is increasingly coming under threat from courts and legislatures under the guise of protecting young people online—presenting a significant hindrance to youth organizing.  

In a major recent example, Meta settled in a lawsuit with 52 states and territories regarding the use of Instagram and Facebook by young people. The settlement will require Meta, and pressure other non-Meta owned platforms like TikTok and YouTube, to embed age gating practices into every product while also requiring restrictions on the accounts of people under-18, such as a two-hour daily time limit and content restrictions.   

Youth Power on Social Media 

Young people have been using social media for political advocacy and community organizing for more than a decade. From organizing protests speaking out against police brutality, to organizing nationwide school walkouts demanding safety in schools from gun violence, and striking to demand lawmakers take action to protect the climate, social media has become an instrumental tool for youth to both speak out and connect with other young activists.  

Instagram has become especially useful for activism online by young people. The features on the app make it a helpful tool for being able to efficiently and quickly spread awareness, which is especially important when people need to share real-time information. For example, 17-year-old Darnella Frazier’s video on Facebook showed the world the murder of George Floyd. 

The impact of youth activism online is also evident on non-Meta owned platforms, with services like TikTok and YouTube being particularly prevalent spaces for young people to share their stories, build movements, and amplify collective engagement.

However, in a digital world operating under the settlement’s new guidelines, young people risk not being able to read crucial news due to the content being labeled as “age-inappropriate,” which has already happened for teenagers in Australia under its social media ban.  

A two-hour daily time limit and a block on Meta’s apps between midnight and 6am leaves little room for young activists to organize rapid response efforts. Being unable to see likes on a post will make it difficult to gauge the effectiveness of their campaigns.   

Add to this what we already know about Meta’s content policies which claim to “protect children” and keep sites “family-friendly” but instead label content like LGBTQ+ content as “adult” or “harmful,” youth will be left with no choice in what content they see once the ‘age-appropriate’ content filter is turned on by default. One recent report noted that Meta had hidden posts that reference LGBTQ+ hashtags like #lesbian, #bisexual, #gay, #trans, and #queer for users with the sensitive content filter on. This would specifically curtail the efforts of young activists doing work on comprehensive sex education.   

Global Trends 

Measures like this are being discussed across the globe, but not all courts have taken such a short-sighted approach. In August, the French Constitutional Council got a lot right in its decision to strike down the country’s legislation banning under-15s from social media for infringing free expression and communication for everyone online, not just young people.  

The French Court also called attention to its infringement on privacy as the legislation would have forced people of all ages to hand over government IDsface scans, and other sensitive information to prove their age and access online content.  

Requiring this much data from users puts activists in danger of even more surveillance. Meta has already previously complied with demands from law enforcement to hand over the messages of users. The amount of personal information that will be logged and that could be demanded via a warrant from police to stifle or investigate activists’ actions or plans could cause a chilling effect, forcing advocates to pause or terminate their work.  

This is egregious because these systems misidentify or lock out people of colorpeople with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their chosen name or align with what the system expects them to look like upon verification. And it’s often these communities that benefit from online organizing the most, especially for marginalized youth as social media can often be the only place to organize and build community. 

What Young People Deserve 

The settlement generates headlines, but it will not solve the core problem. Instead of tackling Meta’s surveillance capitalism business model that turns all online content into potential profit and centers lining the company’s pockets over protecting the speech and privacy of users, this settlement gives the tech giant an opportunity to carve out a new digital world that prioritizes its own needs, not those of young people.  

As we’ve been calling attention to in other contexts, this will force young people into digital isolation—curtailing vital access to news and resources for health and development. It also completely ignores the calls of youths themselves who favor digital literacy and education over surveillance and government control.   

Young people deserve a better internet than one regulated through panic. They deserve better than the government or Big Tech getting to decide how they use social media and what they can or cannot be exposed to or learn about. They deserve better than having their right to free expression minimized. This must not be lost in the pursuit of building a better and safer online ecosystem and environment.   

Who’s buying your personal data: Disney, GM, your insurer and bank. Here’s what they get

Consumers asked a major data broker for their files. What they got back shows interest in how fat they are, how much they drink, and how likely they are to get a mammogram, among many other characteristics.

An illustration of a cartoon figure with a star-shaped head as they walk throw a row of trees, where unidentified hands hold up post-it notes with personal information about the star-shaped figure.

This story is coreported with Consumer Reports

The Arkansas-based data broker Acxiom claims it has data on billions of people around the world, including where they live and how they might spend their money. It says it can even deduce their political leanings, weight, and interest in medical procedures.

But what exactly does the company know?

For Tracey Reed, a nonprofit worker in Oregon, it knew enough to compile a 58-page dossier charting the purported history of her income, employment, and education, not to mention her spending, including everything from her online shopping to charitable giving. Although much of the information was incorrect, she said, the company attempted to log where she lived, complete with latitude and longitude coordinates. And it listed dozens of companies to which it had sold data or inferences about her.

“I think it’s pretty gross that people are treated like sources of wealth to be mined,” she said. “And that’s what these data profiles are, like, ‘Here’s a guide for how to squeeze this person and get money out of them.’”

I think it’s pretty gross.

Tracey Reed, Oregon resident who obtained her data broker file

Reed obtained her data as part of a project by Consumer Reports’ consumer advocacy team to encourage consumers to request their personal information from companies like Acxiom to see how well new state privacy laws are working. By examining the dossiers that come back — more than 100 so far — the nonprofit hopes to better understand what information data brokers are able to collect and to whom they sell it. (Consumer Reports said that its membership arm uses information derived from data brokers, including Acxiom, to understand consumer interests, including the likelihood of becoming a Consumer Reports member, but does not use the information to set prices for its products or share the information with the brokers.)

Consumer Reports shared its data requests with CalMatters and The Markup. Acxiom is notable among the various brokers in the requests for its size, leading industry role — and because it provided detailed data back to consumers.

Acxiom and its connections to other companies have been subjects of press accounts for years, but the records obtained by Consumer Reports offer granular new details about its practices, including the many particular inferences it makes, some of them remarkably specific.

Across the reports CalMatters and The Markup reviewed, Acxiom uses the data it had collected to make predictions in more than 3,000 distinct categories about people’s financial lives and behavior, from the ages and genders of their children, to their estimated “alcohol usage,” to how likely they were, on a scale of 1 to 100, to be in the market for a new Tesla Cyber Truck.

The project was enabled by new laws enacted in a handful of states in recent years that allow consumers to get a look at what brokers have on them.

In each of the profiles, Acxiom made detailed — sometimes to the point of bizarre — ”inferences” about consumers, attempting to chart the likelihood they’d be associated with various characteristics.

Some of those inferences would clearly be valuable to retailers looking to sell products to new or repeat customers. The data broker estimated for consumers, on a zero to 100 point scale, the likelihood that they would spend money at businesses from Nike to Buffalo Wild Wings to PlayStation, or the likelihood that they owned any of dozens of different car models. 

Other inferences went so far as to estimate how likely the person would be to respond to an offer to consolidate a student loan, how likely they’d be to give to charity, or what body mass index percentile they might fall into. Also rated were the chances the person was experiencing food insecurity, had a primary care physician, would get a mammogram, could pay for medical expenses, or showed online interest in the Army. (For more on what’s in Acxiom’s files and how it impacts you, see our accompanying visual explainer.)

The most revelatory finding in the Acxiom reports, according to the privacy experts we interviewed, is the list of specific companies that bought consumer data — more than 100 in total. Several relatively new state privacy laws, including those in Minnesota and Oregon, require companies to disclose not only the types of consumer information they collect but also the other companies to which they are ultimately sold.

Among those in the Acxiom files: several of the nation’s largest insurers, banks, and pharmaceutical companies, including GEICO, State Farm, Citi, JPMorgan Chase, US Bank, and Janssen Pharmaceuticals. Big online sellers were frequent customers, too, including General Motors, Hilton, Kohl’s, MLB.com, Southwest Airlines, T-Mobile, and the Walt Disney Corporation. And several smaller companies repeatedly fined and sued by federal and state regulators, including several direct-mail companies, showed up in the Acxiom files, including Affinion Benefits Group (now called CXLoyalty/Tenerity), Endurance Warranty Services, and Mailers Haven. 

Who’s buying your data from Axciom?

Consumer Reports volunteers requested their personal data from data broker Acxiom. These are the companies the reports identified as buyers of their data.
Chart: Derek Kravitz, Consumer Reports,&nbsp;<span class="block-byline datawrapper-1Mz9g-1nrs9uk">Ryan Tate, CalMatters and The Markup</span>

Of the more than 100 businesses we found that used Acxiom, only a few large companies responded to requests for comment. Those few responses broadly defended their use of the data as an important marketing tool. CalMatters and The Markup are publishing the remaining responses here.

“We leverage consumer data to help improve the efficiency and effectiveness of our marketing outreach,” said Farmers Insurance spokesperson ​​​​​Luis Sahagun, “and are committed to responsible use of any consumer information we may obtain from third parties.”

Marketing lists, loan offers, and patient risk scores

Companies often use personal data like Acxiom reports to identify potential new customers and find out about their household finances and key life events, such as the birth of a child or the death of a spouse. In turn, banks, insurers, and pharmaceutical companies can group, or “segment,” customers into small buckets — a new parent or widower, for example — and tailor advertisements or offers down to just a handful of people. 

Case in point: HealthVerity, a Philadelphia-based venture capital-backed startup that markets itself as the nation’s “largest healthcare data ecosystem,” was listed as a buyer in every Acxiom report we reviewed. It sells deidentified patient data to companies and government agencies, including the Centers for Disease Control and Prevention and, in several case studies posted on its website, insurers and pharmaceutical companies buy HealthVerity’s patient data to find medical research participants, build marketing lists, and link patient health records across different data sources.

But HealthVerity also markets an insurance underwriting product that helps produce “risk scores” and predictions for health, life, disability, and workers’ compensation insurers. And as part of its product list, HealthVerity offers another marketing product with more than “1,000 attributes from providers typically not available, such as Acxiom, Epsilon, Adstra and others. With these sources, you gain more granular demographics, including race data, consumer behavior, online activity, socio-economic profiles, lifestyle and digital media preferences.”

Acxiom’s privacy disclosures clearly state that its data can’t be used for insurance underwriting under the federal Fair Credit Reporting Act but HealthVerity’s products could fall outside that legal definition, as it’s billed as a “healthcare analytics” company, not a credit reporting agency, experts say. HealthVerity didn’t respond to a request for comment.

“There are a lot of holes in this Swiss cheese of privacy law,” said Ari Ezra Waldman, a professor of law at the University of California, Irvine, who studies the data economy.

U.S. privacy law can protect personal data in some contexts — say, when your FICO score and current debts are used for a credit check. But for certain kinds of health data, those laws can fall short. For example, while the federal Health Insurance Portability and Accountability Act of 1996, or HIPAA, protects most kinds of patient health information, daily measurements of someone’s heart rate, step count, and sleep held by a tech company like Apple or Garmin don’t have the same restrictions.

Other companies with spotty track records in handling consumer data show up repeatedly in the Acxiom and Epsilon files. OneMain Financial, a subprime personal lender, shows up as a buyer in several reports; in March, OneMain was sued by 13 state attorneys general for allegedly packing its loans with an estimated $826 in hidden fees and interest per borrower. 

Centene Corporation, the largest Medicaid managed care company in the world, has been sued by California and several other states for allegedly inflating its pharmacy costs and then overcharging state Medicaid plans. 

Janssen Pharmaceuticals, the Johnson & Johnson subsidiary listed in every Acxiom report we reviewed, has paid out billions of dollars in settlements for allegedly violating federal laws regarding off-label drug marketing and physician kickbacks. 

When personal data is used to market costly financial products, the effects on vulnerable consumers can be disastrous, such as when personal, home, or auto loans are targeted to those in financial trouble, often with onerous terms, said Lena Cohen, a staff technologist at the nonprofit Electronic Frontier Foundation who has studied the data broker industry. 

“The extremely personal data we see in these files doesn’t appear out of nowhere,” Cohen said. “There is a network of companies and tech that have to share this data for a data broker to collect it. And it can have real harms.”

The personal data reports also contain dozens of examples of inaccurate info that data brokers glean from public records. Those errors “poke a hole in the argument that we need these surveillance systems for advertising to work,” Cohen said. 

There are a lot of holes in this Swiss cheese of privacy law.

Ari Ezra Waldman, University of California, Irvine School of Law

Many of the early participants in the Consumer Reports effort are particularly mindful about protecting their privacy, and Reed, the Oregon consumer, is no exception. She is so aware of her personal data that she still uses a flip phone. “I hate marketing and advertising,” she said. “I always have ad-block and I try to be conscious of my own data privacy.”

That didn’t stop Acxiom from attempting to catalog her habits. Some information was wrong, and some was right. Her listed addresses seemed to mix her up with her parents, for one. But the company was correct about her spending habits.

The Acxiom reports also include what critics say are artful examples of the company employing coded language to otherwise describe racial, ethnic, and health information that would otherwise be protected from disclosure and use by federal and state laws. One report scores a consumer’s “assimilation level” as “3+ generations in the US.” Others rate “health conscientiousness,” the “likelihood to be a smoker,” and “social setting behavior.”

“We don’t actually know what goes into these kind of vague terms,” Waldman said. The assimilation score is likely “getting at things like race, ethnicity, immigration status, things that we don’t normally like to discriminate on.” But the vague terms used by data brokers “are there to hide the true nature of what’s going on — and to sanitize it, to legitimize it.”

Sherry Hamilton, a spokesperson for Acxiom, said in an emailed statement that the company works to ensure “all data is sourced ethically, used responsibly, and protected securely.” She said the company works with “data suppliers” credentialed by Acxiom to ensure users are given “appropriate notice and choice” in how their data is collected.

The reports collected by Consumer Reports and viewed by CalMatters and The Markup were furnished to provide unfiltered transparency, she said, while clients the company works with are given a more refined, and accurate, data set. 

She added that health-related categories in the data do not indicate a person has an illness but only that they “may be interested in information about a condition, treatment, or product” and that assimilation level is “a household-level score and does not indicate an individual’s race, ethnicity, or immigration status.” Under the law, she said, companies that purchase Acxiom data may not use it to determine qualification or the price of credit and insurance. 

“Acxiom is fundamentally committed to ethical data practices,” Hamilton said.

A multi-billion-dollar industry

Acxiom dates its start back to the 1960s, as an American analytics company called Demographics Inc. According to the New York Times, the company in its early years mined telephone directories to help the Democratic Party find voters’ addresses and mail them campaign material. Since then, the company has ballooned into a data-gathering behemoth. 

Acxiom’s massive data stockpile translates to massive revenue. According to its latest quarterly report, Acxiom’s parent company, Interpublic, took in $2.5 billion in one quarter this year.

But Acxiom is just one part of an even-more-sprawling industry harvesting consumer data with little oversight, and one that few people even know about.

The sale of personal information has become common enough that many companies legally qualify as data brokers even if they are not known as such and focus on other activities. They are part of a sector generally valued at hundreds of billions of dollars and expected to grow. Data brokers are now major political players, too, spending big money on lobbying to influence legislation. 

To build their databases, data brokers broadly rely on three types of data, according to Justin Sherman, a scholar-in-residence at the Electronic Privacy Information Center who formerly ran a research program on data brokers at Duke University. Those ways are data obtained directly, indirectly, and through inference.

Companies may get data directly by, say, gathering it through an app that they offer their customers, or buying a smaller company and integrating that data into their systems. Some of these companies may resell that data to brokers for their databases as well.

Public information, like property records, marriage certificates, and court filings are some of the means data brokers can use to gather data indirectly. Acxiom itself has acknowledged getting data through these means. 

Inferences are the ways a data point might lead a broker to determine something else about a person, Sherman points out. Those inferences can be especially invasive. If a person has a Christian news app, the company might infer their religion, or a gay dating app might lead them to infer a person’s sexual orientation. Companies might not be able to collect data on children legally, but they can infer which households might have a toddler.

If a data broker has a person’s geolocation data, they might see them visit a military base, or a school, or a medical specialist.

“From that I can derive all kinds of information about other characteristics: finance, health, demographics, religion,” Sherman said.

The data a broker obtains can be accurate or not, and may cause problems for the person being profiled either way. If it’s accurate, the data can give companies an unsettlingly detailed window into someone’s life.

But if it’s not accurate, the person might face harmful consequences, too. Faulty data on their driving practices, for example, could lead to unfairly increased insurance rates

And most consumers have little recourse to stop companies from collecting their data.

Data brokers and the law

Absent a comprehensive federal privacy law, some states have taken measures into their own hands. 

Four states — California, Oregon, Vermont, and Texas — have passed transparency laws that require companies to register as data brokers if they meet certain requirements. Some laws, like in California, require data brokers to provide consumers with a way to access and delete their information. California this year rolled out a new website enabling residents to tell hundreds of brokers to stop tracking them and selling their information; CalMatters and The Markup have a guide for how to file that request.

Lawmakers are increasingly worried that personal information collected by brokers and others will fuel discriminatory pricing; at least 30 states this year, including California, have considered bills regulating how companies offer multiple prices for the same product. 

But compliance with the regulations is uneven: a report this year by Privacy Rights Clearinghouse and the Electronic Frontier Foundation found that hundreds of companies appeared in one state’s database but not others’, despite similar registration requirements. 

It’s not clear how many companies that qualify as data brokers under these laws fail to register in a database at all. “The data broker industry is way underregulated,” Sherman said. 

The companies’ practices, he points out, raise serious questions about the boundaries of privacy rights and civil liberties.

There’s little to stop brokers from amassing profiles through more and more invasive means, then passing that data to whoever they see fit. Government agencies, meanwhile, have been known to purchase data from brokers as well. With this method, agencies like the National Security Agency have reportedly been able to bypass getting a warrant for information on a person. 

In response to criticism, data brokers argue that their practices are legal, and that they get consent to transfer and sell consumers’ data. If you sign up for a store’s loyalty program, for example, the fine print might include allowing the company to give your data to outside parties. But as Sherman points out, few people have ever heard of these companies, or could remember agreeing to having their data sold. 

“The notion that a data broker gets consent to sell someone’s data to clients flies in the face of years of academic peer-reviewed research, polling, news reporting, and people’s personal experiences,” Sherman said. “People are not actually consenting to this, so that notion is fanciful.”

Data brokers have detailed files on you. Here’s what’s in them — and how it impacts you

Data brokers collect thousands of details about your finances, health and habits. See what’s in your profile, who buys it and how companies use it.

Two purple hands: one holds a phone reading “COVERAGE: REJECTED. HAVE A NICE DAY!,” the other holds a cereal box labeled “CEREAL, PRIZE INSIDE!” with a sticky note reading “BMI 31” circled in red.
Catherine Twomey for Consumer Reports/CalMatters

This story is coreported with Consumer Reports

In several states, new privacy laws are forcing brokers to disclose the companies that bought your data. So we asked for volunteers to request their personal data reports from the world’s largest data brokers. Hundreds of people responded.

Each report typically contained a detailed profile: names, addresses, Social Security numbers — along with more than a thousand educated guesses and predictions about your traits and habits.

 Your data isn’t just sitting there. These reports show that it’s constantly accumulating, endlessly analyzed, and routinely sold off — to more than 100 of the largest companies in the U.S., among many others.

What’s in your data report?

A lot. These profiles show the last time you logged into your computer and how much you’ve spent on clothes, furniture, and dining out over the past several years.

Data brokers like Acxiom, Epsilon and others routinely sweep up the digital trail you leave behind and turn it into thousands of predictions about you and your purported traits, including things like: 

  • How many children you have, and their ages and genders
  • Whether you’re “blue collar” or “white collar”
  • If you’ve ever been a victim of fraud

But much of the data is wrong. One report listed six different guesses about someone’s age.

Your profile starts with who you are.

Data brokers maintain files on almost everyone. Acxiom says it has profiles of roughly 95% of U.S. adults. Epsilon claims to have data on “virtually every marketable U.S. household.”

Data brokers source data from public records, commercial databases, and other brokers.

They compile those records into a file that follows you throughout your life — and even after you die.

Your devices give you away.

Your phone’s “advertising ID,” your smart TV’s tracking identifier, your home’s IP address, and your car’s vehicle ID number — data brokers can have them all. 

These identifiers let their clients match you to your online behavior — across every phone, tablet, computer, car, and television you own.

You’re assigned an economic value.

While data brokers typically don’t have access to your bank account, they can guess what you earn, what you’ve saved, and what you’re worth.

This is all “modeled” behavior based on where you live, your previous purchases, and what similar consumers to you are worth.

Your identity and health are inferred.

Without access to your medical records, data brokers infer how well you sleep, if you smoke, your body mass index, and if you have health insurance.

They can also guess your religion, ethnicity, political leanings, and even the exact ages of your children.

These inferences are then sold to pharmaceutical companies, healthcare firms, and insurers.

What you’ll do next is already predicted.

Data brokers score your likelihood to buy things from hundreds of brands. They predict what car you’ll buy next, where you like to eat, and whether you’re in the market for cryptocurrencies.

You’re assigned a ‘lifetime value score’ and a ‘profit margin’ label

Your data is valuable to companies. 

A bank can use it to send you a credit card offer — with a better (or worse) sign-up bonus based on your profile. A home insurer can target you for new add-on coverage. Your favorite clothing store can use it to personalize the price of a sweater just for you.

To this end, Epsilon predicts your income, investments and “life cycle,” grouping people into one of 26 “NICHES” codes, such as “Easy Street,” “Mid Life Munchkins” and “Big Spender Parents.” It also categorizes people into how profitable they are to companies, using labels like “Best Profit Margin.”

Acxiom calculates a “lifetime value score” estimating your profitability as a customer. 

For auto, home, and health insurers, this score ranges from 0 to 200,000, with higher scores suggesting you’re more profitable. 

Acxiom then attaches dozens of labels to you, such as “Seniors ages 64+ years, with a medium ability to pay for medical expenses,” “3+ Generations in the US,” and “Completed High School.”

Here’s who’s buying your data.

The reports don’t just show what was collected. They name every company that purchased your profile.

Across the reports we reviewed, we identified hundreds of buyers.

Who’s buying your data?

Consumer Reports volunteers requested their personal data from data brokers Acxiom and Epsilon. These are the companies the reports identified as buyers of their data.
Chart: Derek Kravitz, Consumer Reports

Here’s what buyers do with your data.

Once your profile reaches corporate buyers, it becomes the raw material for decisions that directly affect your day-to-day financial life.

Insurers use it to gauge the health of your company’s employees and then prepare health insurance quotes and premiums. 

Personal lenders use it to identify you as someone who may need a financial lifeline or is in the market for a car. But these loans may have bad terms and high interest rates.

Banks use it to market financial add-on products you may not need, like identity protection and credit monitoring.

Opting out is harder than you think.

Data brokers get most of their data from other companies, not directly from you. 

You never signed up. 

It’s debatable whether you even meaningfully consented.

And opting out only removes your data from one broker — it doesn’t erase the copies that have already been sold to dozens of others.

For more on who’s buying your personal information from data brokers, and what they’re getting, see our full investigation.

California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety

The federal government has inserted a provision into a funding deal with the state of California that would make the state abandon its gold standard net neutrality law, broadband affordability laws, and public safety protections. Doing so would be a huge step back for California, and would actually end up being more expensive for Californians in the long run. Tell the governor to reject this provision before accepting these funds from the federal government.

Take Action

Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety

On August 31, the National Telecommunications and Information Administration announced it would be awarding California $1.4 billion to expand broadband connectivity in the state. In that deal is a provision that says that California agrees to not enforce any law, order, or policy that imposes any sort of restriction on internet service providers (ISPs). These ISPs will get awarded the funding in order to connect Californians they have neglected for years. The ban on enforcing our laws would last 14 years. This is disastrous for a lot of reasons. 

First, California is one of the only states with a strong state net neutrality law. Recreating much of the FCC’s Open Internet Order, the law prevents ISPs from blocking, throttling, zero rating, and instituting paid prioritization on internet service. Put another way, the law ensures that users, not companies, decide how they can see on the internet. If California is not allowed to enforce our gold standard law, there will be little stopping ISPs from controlling how everyone experiences the internet. 

Second, California has a number of affordability protections that would also fall under this agreement. For example, when the state approved the merger of Verizon and Frontier earlier this year, it required the new merged company to offer a $20 internet plan to low-income Californians—saving Californians billions of dollars over the next decade. Just this year the California Public Utilities Commission found that the average cost of broadband across four major urban markets (San Mateo, Oakland, Los Angeles, and San Diego) was $51 per month. In 2023, Consumer Reports found that 84% of American consumers pay at least $50 per month, with many paying more. That $30 difference per month—which is likely to actually be more—makes all the difference for low-income Californians. It is how Californians will save billions from this merger requirement. In contrast, $1.4 billion in new connectivity and infrastructure doesn't matter if the most vulnerable Californians cannot afford it. Eviscerations of this and the net neutrality protections will, ultimately, cost Californians more than they will get. 

Third, this deal will impact public safety. The same California net neutrality law which protects consumers also ensures reliable service for first responders during emergencies by banning throttling. In 2018, Verizon throttled, or slowed down, the service of firefighters as they were battling what was, at the time, the largest wildfire in California history. In reaction, fire departments came out in support of what would become California’s net neutrality law. If California cannot enforce its net neutrality law it will leave its first responders in a weaker position as natural disasters only become more intense. 

Most people do not have a choice in ISP as it is. California’s net neutrality law is one of the few things protecting Californians from the whims of these monopolistic giants. Californians should not give up our few hard-won protections in return for a hand out to these behemoths. Tell Governor Newsom to reject this provision before he accepts these funds from the federal government. 

Take Action

Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety

The High Crime of “LMAO”: How Cops Are Treating Mass Surveillance As a Joke

Here's a riddle: Why did a Goshen Police Department officer search 6,474 automated license plate reader (ALPR) networks, representing data from 82,413 cameras, on May 7, 2025? 

If your answer is "I don't know," it turns out you're 100% correct. The officer left the letters "idk" in the search field where cops are supposed to document the reason for the search.

When law enforcement and tech salespeople pitch ALPRs to city councils, they stick to a familiar script. They trumpet the technology, which is often provided by private companies like Flock Safety, Motorola Solutions, or Axon, as an essential tool for solving high-stakes crimes, such as car jacking, kidnapping, or murder.

But when you strip away the carefully curated talking points, the data continues to reveal a different (and frankly, ridiculous) story. An EFF analysis of ALPR search logs from Flock Safety systems shows that officers across the country are spying on drivers for completely nonsensical "reasons." Police are routinely searching the Flock database without providing any legitimate justification, making a mockery of our civil liberties by logging reasons like "LOL" (short for “laugh out loud”), "LMAO" (short for "laughing my ass off"), "sexy," and "idk" (short for “I don’t know”) to access sensitive ALPR location data.

And in some cases, officers are just mashing keyboard buttons rather than articulating the nature of their searches.

Flock Safety claims it has improved its system by requiring officers to select from a dropdown list of crimes before running a search–but that only makes it easier for officers to hide improper searches behind the veneer of uniformity. The system does not require proof that the dropdown reason actually matches the true purpose of the search. 

With no warrant requirements, limited guardrails, and deficient audit processes, ALPR databases have fostered a culture of unrestricted access to everyone’s location information. This culture of abuse has allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for low-level complaints, personal whims, and sometimes, seemingly, for the lols.

A Documented Culture of Abuse

ALPR misuse isn’t a new phenomenon; it has dominated headlines for more than a year. We already know that officers regularly abuse these systems to stalk past and potential romantic partners. We’ve seen ALPRs used to surveil protests, which can chill First Amendment-protected dissent, and seen officers try to use an ALPR system to track down a woman seeking an abortion.

Typically, we learn about these uses from documents called "network audits," which are long spreadsheets that document all the searches that run through an agency's system. It is not unusual for even a small agency to have a record of millions of searches from thousands of external agencies across the United States.

We’ve also uncovered horrific systemic profiling, with more than 80 law enforcement agencies using terms like "roma" and "g*psy" to target ethnic Romani people—often without any mention of a suspected crime. And when police aren’t using ALPRs for stalking or profiling, they routinely use them for extreme low-level investigations: verifying whether a student lives in a specific school zone, running employment background checks, following up on loud music complaints, or targeting a motorcyclist simply for holding a cell phone.

But somehow, it gets worse.

The Absurdity of Documented Search Reasons

EFF’s analysis of Flock Safety’s ALPR search data obtained through public records requests has uncovered a disturbing trend. In the absence of judicial oversight, officers are inputting ridiculously unserious terms to justify their searches. Here is just a snapshot of what police consider a "reason" to track someone’s vehicle:

Surveillance as a Joke

Audit logs sample

  • Barberton Police Department (Ohio) employees ran numerous searches between March 2024 and May 2026, listing “LOL” or “lol” as the reason.
  • Harris County Sheriff's Office (Texas) employees ran several searches between April and May 2026 listing “LOL” or “lol” as the case number.
  • Lake County Sheriff's Department (Ind.) employees ran searches in July 2025 for “LMAO.”
  • Richmond Police Department (Calif.) employees ran over multiple searches in November 2024 for “Hehe.”
  • Riverside County Sheriff's Department (Calif.) employees ran searches in 2024 for “Haha.”

"Don’t Know, Don’t Care" Approach

  • Kankakee County, Sheriff's Office (Ill.) employees ran searches (2023–2025) for “idk” or “idk lol.”
  • Goshen Police Department (Ind.) ran searches (May–June 2025) for “idk.”
  • Fishers Police Department (Ind.) ran searches in May 2025 for “blah.”
  • A Pasco Police Department (Wash.) employee searched for at least four different license plates, leaving "robbery i don't remember the case number leave me alone" in the reason field.
  • The San Diego Sheriff's Department (Calif.) ran searches in May 2025 with "idk" in the reason field. 
  • More than 30 agencies ran more than 6,300 searches with "TBD" (short for "To Be Determined") as the "reason." These included the Arizona Department of Public Safety, the Manteca Police Department (Calif.), and the Baton Rouge Police Department (La.). The Priceville Police Department (Ala.) alone ran 1,954 searches with reasons "TBD." 

Insults and Inappropriate Searches

  • Belton Police Department (Mo.) ran searches (Aug–Sept 2024) for “d*ckhead.”  (asterisk/redaction our own)
  • A Manteca Police Department (Ill.) employee ran searches in June 2024 for “sh*thead”  (asterisk/redaction our own)
  • A Norton Police Department (Mass.) employee ran searches in December 2024 for “Sexy.”
  • Corona Police Department (Calif.) employees ran searches (2023–2025) for “weird” or “WEIRD KID.”
  • Thornton Police Department (Colo.) employees ran several searches in October 2025 for “driving around being weird.”
  • A Columbus Police Department (Ohio) officer ran searches in 2023 for “idiot.”
  • A Michigan City Police Department Officer (Ind.) ran searches in June 2025 listing “f*ck this new search engine.” (asterisk/redaction our own)

Button Mashing 

Button mashing audit logs sample

One of the more alarming discoveries we found in the network audit data is a large number of "reasons" that appear to be nothing more than an officer mashing buttons. These typically involve a nonsensical long string of characters from the same line or area of the keyboard.

For example: 

  • An Eatonton Police Department (Ga.) employee ran searches with reasons such as HJKNUILH, uiokjk.kuj, GJLHBNMN, hjhbnmg, and iuohjk.
  • An Atlanta Police Department (Ga.) employee ran searches with asdfga as the reason. 
  • Bay County Sheriff's Office (Fla.) employees ran searches with reasons such as  ;'lkjh, /lkjh and lkjhg.
  • A Brown County Sheriff's Office (Wis.) employee ran searches with reasons such as gyghkkghghjkghjk, ggyjgyujdsrdghdfhjkghjghk, HJHJKLHLKHJK, hjjkjkhjkljk and JHLJKHHJKL.
  • A Lake County Sheriff's Office (Ohio) employee ran searches with reasons such as asdfg and ghjkl, and a second officer ran a series of searches that started off with "investigation" but then devolved into button mashing, including: 
    • Investigatafy, Investigatafyd, Investigatafydl, Investigatafydlh, investigatafydlhj, investigatafydlhji, investigatafyfdlhji, investigatafyfdlhjigkfgty, investigatafyfdlhjigkfgtyy, investigatafyfdlhjij, investigatafyfdlhjik, investigatafyfdlhjikf, investigatafyfdlhjikfg, investigatafyfdlhjikfgty, investigatafyfdlhjikfgy and investigatafyfdlhjiy.
  • A Moore Police Department (Okla.) ran searches with reasons such as jhjhjkhj, jhjkhjh, jhjkhjkh, jkhhkjhjk, Jkhjkhj, Jkhjkhjk, Jkhjkhjkh, jkhjkhkjh, jkjkhjkh, kjjkhjk, loiuiou, ukjhjkh and ulkuiou.
  • A Westlake Police Department (Ohio) employee ran searches with reasons such as fghjkl, ghjkl, and lkjhg.
  • A Kentucky State Police employee ran searches with reasons such as mhghjk, mhgnhjkj, nbvcxcvbn, nmbvcbnm, and sdfghj

It's hard to imagine a situation where these characters add up to a legitimate police code. However, it's easy to imagine an officer cutting corners with a text field they know no one is checking, especially if they are accessing the Flock Safety app from their phones while driving. 

How Police Departments Are Responding

When confronted with these flagrantly unserious searches, police departments offered a mix of bureaucratic deflections and excuses. 

In response to EFF’s request for comment, Thornton Police Department (Colo.) claimed the system didn't require officers to select from a defined list at the time, but it does today. They also audited the “driving around being weird” searches, claiming they were all actually for "legitimate public safety purposes." 

Other police departments we reached out to for comment shared the following: 

  • Richmond Police Department (Calif.) stated that the officers involved with the "Hehe" and "idk" searches were "counseled."
  • Corona Police Department (Calif.) noted that the employees searching for "WEIRD KID" are no longer employed by the city for unrelated reasons.
  • Columbus Police Department (Ohio) pointed to their union contract, stating their Inspector General only has jurisdiction to investigate incidents within the last 90 days, giving the officer who searched for "idiot" in 2023 a free pass.
  • Belton Police Department (Mo.) promised a "thorough investigation" of the "d*ckhead" searches through existing union and personnel policies.
  • Manteno Police Department (Ill.) said it will "review the searches and the circumstances surrounding them thoroughly" and "take whatever action is determined to be appropriate based on the facts and circumstances.”
  • Manteca Police Department (Calif.) said: "Since the beginning of 2026, our personnel have been directed that the reason field for ALPR searches must identify the law enforcement purpose for the search and that 'TBD' is not an acceptable entry." The spokesperson added: "The presence of 'TBD' in the reason field in prior searches should not, by itself, be interpreted to mean that the associated search was conducted without a legitimate law enforcement purpose or that reasonable suspicion was required." EFF has asked the agency to clarify whether it verified the hundreds of "TBD" searches were legitimate, and we will update this post with a response if we receive one. 
  • Fishers Police Department (Ind.) said that the detective that searched for “blah” has done so “when he has issues with the technology” and that the term “is used when he is actively using the technology to solve a criminal case, and the technology is not moving fast enough for him.” The department shared that “he has been told to use “test” in the future.”
  • The Cobb County Police Department (Ga.) acknowledged that "TBD" stood for "To Be Determined" and is no longer an acceptable search reason: "We have instituted a new policy that took place after the dates listed in your audit that now require, in addition to a criminal offense and a reason, a case number for any search conducted on FLOCK." 
  • The San Diego County Sheriff's Department says that it checked the cases where "idk" was used and determined "there was an active investigation associated with the searches." The department said that this was due to the reason field being optional at the time (which was true on a software level) but California law has required officers to document a purpose for accessing ALPR data since 2015. The sheriff's spokesperson says the reason field is now mandatory, and involves a dropdown menu. 

Other agencies did not respond to EFF’s requests for comment. We will update with responses as they are received.

The Cop Out of the Drop-Down Menu “Feature Update”

Under the guise of streamlining audit logs, in late 2025, Flock safety announced that they will be replacing the required, free-text search “reasons” with a pre-populated dropdown menu of generic offense categories. Since this update, officers are no longer required to type out why they are digging through a driver's movement history, and instead can select a pre-packaged option like "Traffic infraction" or “Other” in half a second. 

Replacing the requirement to articulate the reason for the search with one-click searches is a loss for transparency, but also may explain why audit logs including the searches we highlight in this piece significantly decreased since early 2026. 

The Punchline is Our Privacy

Two Flock cameras and a solar panel on a light pole.

Entries like these defeat transparency, undermine accountability, and entirely fail to satisfy what many jurisdictions require by law or policy: an actual reason for the search. And this keeps happening because police use ALPRs as a convenient shortcut around constitutional privacy safeguards. 

In other contexts, such as searches of cell phone location information, police have to go to a judge, demonstrate probable cause, and get a search warrant. But because laws and courts have not caught up with the pace of ALPR technology, police do not do the same before searching ALPR databases. Instead, they are given free rein to track a person’s movements without a sliver of judicial oversight.

As we mention in our piece about the use of ALPR surveillance for low-level investigations, if a police chief stood in front of a city council and asked for permission to install hundreds of cameras just so his officers could investigate the high crime of "haha," they would be laughed out of the room. The same could be said if an officer asked a judge to sign a warrant to track someone down for "LOL."

The fact that these searches were not only missed by the agency supervising the officer, but by the often thousands of other agencies whose systems were searched, demonstrates how agencies cannot be trusted to oversee themselves. 

Mass surveillance is incompatible with a free society, and especially so when the people with access to this data are treating it like a joke. This ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. But because it does, EFF continues to urge courts and state legislatures to immediately step in and impose strict, enforceable restrictions to rein in this abuse. At an absolute minimum, this means mandating rigid data deletion deadlines and an ironclad warrant requirement. 

If police want the power to track a person's movements, they must be required to convince a judge with evidence and probable cause. They should not be able to bypass the Constitution with a search for "haha."

How TikTok and Google ended up with information about doctors’ appointments around the world

Doctoralia sent information about specialists and appointment dates to social media companies.

An illustration in green, blue and white tones that depicts a medical appointment webpage with fill-out boxes, including a "enviar" button, surrounded by several pixels.
Illustration by Adriana Heldiz, The Markup

Healthcare appointment site Doctoralia, which serves millions of people in Latin America and Europe, sent sensitive information about their medical appointments, including the specialties and names of doctors, to social media companies including TikTok, Google, and LinkedIn, according to a review of its websites. 

The Markup and Agência Pública, an investigative journalism nonprofit in Brazil, reviewed multiple website domains operated by the company, which provides services similar to those ZocDoc offers in the United States, letting people looking for healthcare easily search for a variety of providers in the area, then book appointments. As part of a series on web tracking, the review looked at network traffic between Doctoralia domains in multiple countries and popular social media sites.

According to the traffic logs, embedded online trackers followed visitors in Brazil, Colombia, Mexico, and other countries from nearly the second they started to search for care, then sent that data to the tech industry for advertising purposes. 

If a visitor searched for a gynecologist based in Sao Paolo, Brazil, for example, the website sent searches for provider specialties and other information to Google through its marketing platform. If a visitor continued through to book an appointment, name and other information on the doctor, as well as the date and time of the appointment, was sent to the company.

The path taken in seeking medical care can itself provide clues about health issues that should remain private.

Brazilian gynecologist

Similar data was shared across other countries with other tech giants as well, according to the review. As in Brazil, searches for specialists in Colombia were sent to social media companies. If a user in Cartagena, for example, booked an appointment with a dermatologist, the provider’s name, as well as the data and time of the appointment, were sent to LinkedIn. The same happened with searches for any other specialists. 

If a web user in Bogotá booked an appointment with a doctor through Doctoralia, whether a psychologist, dermatologist, or other care provider, information on that appointment was also shared with TikTok. The same happened for users in Mexico. 

Doctoralia said it would conduct a detailed review of its online practices but noted it does not monetize patient data.

Still, experts said the information sharing violates privacy expectations and possibly Brazilian law.

“Even without a stated diagnosis, the path taken in seeking medical care can itself provide clues about health issues that should remain private to the patient,” said a Brazilian gynecologist who uses Doctoralia and spoke to Pública and The Markup on condition of anonymity.

For example, a search for gynecology, obstetrics or reproductive care may be related to trying to conceive, a possible pregnancy, infertility, choosing a contraceptive method or concern after a risky sexual encounter, the gynecologist added. In the doctor’s view, even though inference is not the same as diagnosis, the expectation of confidentiality in the relationship between patient and professional should also apply in the digital environment.

“When someone looks for a doctor, a test or a clinic, they are looking for care, guidance, help,” he said. “So there is a legitimate expectation of privacy.”

Was it illegal? Doctoralia promises a “detailed” review

The tracking on Doctoralia started before any personal information such as email addresses or names was entered, but the trackers often tied users to unique IDs. Social media companies say they can tie users’ social media profiles to browsing behavior through such identifiers. 

The tracking also happened across providers and borders in Latin America, with some experts telling The Markup and Pública that government agencies may want to scrutinize the practices. 

In Brazil, for example, a law provides for stringent privacy rights, especially for healthcare data. 

“Obviously there is a risk here of permanent tracking based on unique IDs and building profiles that people are not aware of,” said Rafael Zanatta, co-director of Data Privacy Brazil, an advocacy organization. “There could be a massive violation of those fundamental rights.”

Chiara de Teffé, a professor of digital law at the Federal University of Rio de Janeiro, said the protections provided by Brazil’s General Data Protection Law are not limited to diagnoses and medical records. “Behavioral information may receive enhanced protection when, because of its context and the way it is processed, it reveals or allows inferences about aspects of someone’s health,” she says.

Brazil’s Federal Council of Medicine, the agency in charge of regulating and licensing medical professionals, meanwhile, told Pública and The Markup that “booking an appointment does not involve medical confidentiality” and “there is no sensitive data of any kind when a patient seeks a specialist.”

But the country’s National Supplementary Health Agency, which regulates private insurance, said “the medical specialty sought and other appointment-booking information may reveal aspects of a person’s health.”

Arsenia Nikolaeva, a spokesperson for Doctoralia parent company Docplanner, said in a statement that the trackers were used to monitor the company’s own social media campaigns and that Doctoralia “does not use these tools to sell personal data or to operate a commercial data product” and isn’t paid by social media companies for data. But the company said it would review its practices.

“We take the questions raised very seriously and are conducting a detailed technical and legal review of the matters described, including the relevant technical configurations,” Nikolaeva said in an email. “We remain committed to protecting personal data across all the markets in which we operate, and to acting appropriately based on the outcome of that review.”

The social media companies say they have rules against sending sensitive information, including health data, through their trackers. In practice, however, businesses have frequently been caught sending such information. 

Sofie Diskin, a spokesperson for Google, said the company has “strict, long-standing policies against collecting private health information or advertising based on sensitive information” and provides customers with tools to help them avoid collecting health data.

A spokesperson for LinkedIn, Brionna Ruff, said the company’s policies “prohibit installation” of its signature tracker, the Insight Tag, on pages that collect sensitive data, and that the company doesn’t want such data. 

TikTok didn’t respond to a request for comment.

Despite the tech companies’ policies, however, healthcare businesses have frequently been caught transmitting sensitive data, leading to regulatory scrutiny and a wave of lawsuits in the United States

A close-up view of a unidentifiable doctor holding a stylus to tap on a tablet next to patient during a consultation.
Photo via iStock

Pixel tracking

Since 2022, The Markup has been reporting on the pervasive use of “pixels,” tracking technology that social media companies use to follow web users.

Across the internet, invisible trackers embedded on websites report information on web users to major social media companies. 

Companies like Meta, Facebook and Instagram’s parent company, freely offer the code for pixels to businesses and organizations, who place it on their sites. That code can then log data on visitors and transmit it back to the companies. 

Those businesses can then target social media ads to customers who interacted with their site. If a person visited the page for a product but didn’t purchase it, for example, a business can send that visitor ads on Facebook for similar products they might be interested in instead. Meta takes payment from the business for the targeted ads. 

The use of pixels is widespread, underpinning the economy of the internet by letting businesses target people who they want to reach, including those who might be the most interested in their products. 

But tech companies and businesses that rely on pixels have been hammered with criticism e for tracking sensitive personal data. The practice has sparked lawsuits, demands from lawmakers, and regulatory scrutiny. 

While social media companies say they don’t want to receive information on health or finances, for example, in practice it happens frequently. 

In previous articles, The Markup has found pixel tracking in several potentially sensitive areas, including education, finances, and healthcare. Among other instances, the reviews have found pixels transmitting information from tax filing companies and the Department of Education’s financial aid service. 

It isn’t the first time that companies have been in hot water for tracking health data. In 2022, a review by The Markup showed that Facebook was receiving sensitive medical information on appointments for major hospitals. The investigation led to lawsuits and several hospitals quickly changing their practices. 

In separate investigations, The Markup found trackers sending information from abortion pill providers and major drug store chains to Meta and other social media companies. (Doctoralia appeared to use Facebook trackers but sent less sensitive information to the company than to others in cases The Markup reviewed.)

Meta and other social media companies have said in the past that they do not want sensitive information sent to them through tools like the pixel. They also say they use tools to automatically identify and filter out potentially confidential information.

But ultimately, the companies are operating inside a black box. While it’s not clear in any particular case what happens after the data is sent, companies can use it to target ads and power their algorithms in the future. 

Privacy in Latin America

Doctoralia’s parent company, Docplanner Group, founded in Poland in 2012, says it operates a sprawling platform across 13 countries, from Turkey to Chile, letting 100 million people book 25 million appointments per month across countries, cultures, and languages. 

The countries where Doctoralia operates have a patchwork of laws that provide varying protections for web users. In Mexico versus Colombia, for example, different laws and regulatory agencies govern how data is shared and protected.

Not all of the Doctoralia domains that The Markup and Pública tested sent data to social media companies, either. If a visitor to the Spanish version of Doctoralia searched for an appointment, for example, the search was not sent to outside companies in our testing. Doctoralia is based in Spain, where data is protected under the European Union’s General Data Protection Regulation.

In Germany, where Docplanner offers a similar platform, a pop-up allows visitors to turn off any tracking cookies. In the Latin American countries, by contrast, a pop-up informs readers of cookies but doesn’t immediately offer them a way to turn them off. 

Unlike the unified law in the European Union, the most stringent privacy protections in Latin America comes from one country, Brazil, which has a comprehensive national privacy law, the General Data Protection Law. 

Under the law, companies that process data are required to do so with full transparency on how the data will be used, and users must be given an ability to opt out.

The law also gives special protections to “sensitive” types of data, including demographic and health-related information. If a company handles that data, they must ask for it conspicuously and prominently. Failure to comply with the law can result in action from Brazil’s regulatory body, the National Data Protection Authority. 

Zanatta, who works with the Authority as part of a government advisory board, said the tracking highlighted by The Markup and Pública would be something for regulators to examine. “There could be many legal problems here for sure,” he said.

Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans

Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was AB 1709, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, AB 2071 and AB 2298, which require that children learn critical digital literacy and cybersecurity topics. The bills are an affirmative and constitutional way for the state to address valid concerns about young people’s internet use without violating their First Amendment rights.

Unlike blanket bans, A.B. 2071 and A.B. 2298 address online safety through education rather than prohibition. Young people rely on the internet not just for entertainment, but for civic engagement, education, self-expression, and community—especially vulnerable youth who may lack support in their physical surroundings. This is why real digital safety comes from preparation, not isolation. Research consistently shows that open, honest conversations about digital literacy and privacy with trusted adults are far more effective at protecting youth than restrictive censorship laws. Young people themselves recognize this need; in fact, A.B. 2071 was co-authored by a group of students actively seeking better resources to navigate their digital lives safely.

Education vs. Censorship 

A.B. 2071 and A.B. 2298 fill critical gaps in California’s school curricula by equipping students with actionable skills. A.B. 2071 integrates digital wellness into middle and high school health classes, teaching students how to identify unhealthy tech habits, protect their personal safety, and evaluate digital content—including AI-generated media—for credibility and bias. Meanwhile, A.B. 2298 adds cybersecurity concepts to recommended school curricula, teaching young people how to safeguard their personal data from online threats.

While the state’s turn toward social media bans remains a harmful and misguided policy direction, the passage and signing of A.B. 2071 and A.B. 2298 show there is a better way. Lawmakers must stop treating censorship as a quick fix and instead focus on constitutional, empowering solutions that give youth the tools they need to thrive online. 

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn’t deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.

TAKE introduces a new way for Ring to manage encryption keys, where the user’s device has its key, then the company holds encryption keys temporarily within its own cloud infrastructure. Ring’s servers receive the keys temporarily so it can offer a variety of the features it says it can’t offer when a user chooses to use end-to-end encryption, like video descriptions, smart alerts, video search, and more, then deletes the key after 24 hours. 

This differs from how it works now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features. 

Comparatively, this is an improvement to the default settings Ring has now, because it at least puts some restrictions on historical footage, but it has some serious holes worth exploring.

Ring Gets Access to Unencrypted Video for a Short Period

Ring has designed its service so many of its camera features, including smart alerts and video search, need cloud processing to work. That means to provide those features, Ring needs to decrypt the footage while it’s stored in Ring’s cloud servers. 

With TAKE, in order to decrypt footage to offer these features, Ring gets access to footage stored in the cloud for 24 hours. TAKE adds some small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, the cloud processing does its thing and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server. 

In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys. The client device essentially takes the place of a hardware security module (HSM), including making those keys available to the server whenever they’re needed. The end result is an improvement from the status quo, but still not even close to the privacy protections of end-to-end encryption

The company says it does not keep backups of the keys and there’s no way for a Ring employee to access footage. It also claims that any decrypted content is deleted from its servers. 

But that doesn’t mean much when user actions send the keys back to the server. And making features like “Video Search” and “Smart Video Descriptions” available to the device owner means that while the footage can’t be seen by Ring, descriptions are readily available to the company. In response to a question about capability, Ring responded to us that, “As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included.”

Plus, account recovery keys are stored in the camera itself by default. When that’s paired with the fact that currently, indices of video contents are available to the company, it means that TAKE isn’t even a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest from the device-owner, decrypting account backups, and using that information to decrypt encrypted videos. 

Law Enforcement May Still Seek to Compel Access to Footage

Because of the ways the access and key rotations work, it’s technically still possible for Ring to alter its current practice if compelled to do so by law enforcement, in much the same way as other existing encryption-at-rest systems where the company holds the keys. For example, Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they’d retain some level of access. 

In an email to EFF, Ring stated, “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests.” EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it.

End-to-end encryption works to maintain trust by its user base because the company that employs it never has access to the keys at any point, making it impossible for itself to access the encrypted contents. This also means law enforcement can’t demand the service retain keys or choose not to rotate them. As described, this level of protection isn’t offered with TAKE.

Ultimately, Ring is the one managing this software and its implementation, and beyond a white paper, “trust us” is the only level of verification they’re offering outside observers. While it doesn’t fix the issues, at the bare minimum, the company needs to open the entire infrastructure up to third-party auditors to verify its claims. Ring seems to agree, as they told us that, “Ring conducts rigorous security reviews of all products before launch and critical components of TAKE’s infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review.”

TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn’t claim it as such. Ring already offers the option for end-to-end encryption, and turning that on by default would offer the real sorts of privacy improvements we all want from video doorbells. 

We All Deserve a Better Internet, Not A Smaller One

Bans Like California’s Don’t Fix What’s Wrong With Social Media Companies

SAN FRANCISCO - Technology and the laws that regulate it should support and empower young people. California’s AB 1709 - signed into law today by Gov. Gavin Newsom - falls far short of this goal, say the Electronic Frontier Foundation (EFF) and its allies.   

Using technology is how we learn and build community in today’s world. Laws such as AB 1709, a functional ban on social media use for people under the age of 16, instead cut young people off from essential information and experiences. That particularly harms those already facing increased challenges, who often find safety in supportive online communities that they can’t always access in the physical world.  

"California should be passing laws to ensure that technology really works for people of all ages, not enacting social media bans that cut young people off from digital lifelines, communities, and speech," said EFF Associate Director of State Affairs Rindala Alajaji. "Denying minors access to digital forums - or stripping out basic tools needed to navigate them - is not going to help make young people safer or healthier in the AI age."  

Research shows social media bans are ineffectual, while also denying young people opportunities to develop their own voices and perspectives—to share their art, practice religion or engage in politics.   

Age-gating requirements also force everyone to give up more personal information. To verify who can pass through their online gates, companies will collect even more data, and this further concentrates power in the hands of companies, rather than protecting people.  

AB 1709 is also inconsistent with rights to free expression and California will be spending resources to defend a law tied up in court. Instead, we should redouble our efforts to get technology laws right—and support the passage of new robust privacy laws that target surveillance business models. That’s how we protect everyone in the AI age.   

Young people should be able to use technology in safe and healthy ways. The Golden State should model the gold standard laws that ensure technology works for everyone, rather than shut down access to digital forums in ways that do more harm than good. 

"Social media bans like AB1709 make kids less safe, while undermining privacy and freedom of expression for everyone,” said Evan Greer, Director of Fight for the Future. “Young people have been on the forefront of every social movement throughout history that has led to positive social change. We need policies that empower young people rather than silencing them. These kid-focused bans are a gift to Big Tech giants, allowing them to continue operating their harmful business model while incentivizing them to collect even more data. California lawmakers should be ashamed. They didn't do anything to protect the kids, they just used kids as pawns to make good headlines."  

“In a world of increasing stigma and marginalization for LGBTQ+ families, AB 1709 continues that trend by stripping people with LGBTQ+ parents of the ability to meet and build community with one another on the internet” said Jordan Wilson, Executive Director of COLAGE. “Beyond obstructing the right of youth with LGBTQ+ parents to access information, this bill places an undue burden on all Californians by forcing age verification at a time when digital privacy rights are being eroded globally. We cannot ‘protect children’ by stripping them of their primary avenue for connection.” 

Contact: 
Rindala
Alajaji
Associate Director of State Affairs

Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR

Law enforcement agencies across the country are increasingly relying on spying technologies—automated license plate readers (ALPR), cell-site simulators, and facial recognition, to name a few--causing an outcry in many communities where people are rightly concerned about the threat to civil rights and civil liberties these tools present.

Some authorities are responding to these concerns by trying to hide what they’re doing. Police departments are telling officers not to mention ALPRs when stopping vehicles and concealing their use of ALPRs to avoid citizens’ public records requests. Concealing the use of unpopular spying tools isn’t anything particularly new for law enforcement—cops have been doing it for years—but it’s just as wrong now as it was 20 years ago.

These practices prevent the public from knowing about and questioning how agencies are spending taxpayer dollars on spying technologies and holding them accountable. This is especially troubling when many towns are signing contracts with Flock and other ALPR vendors with little to no public oversight. The practice also violates disclosure obligations, allows cops and prosecutors to hide their tactics from judges, and cheats defendants from being able to challenge the use of evidence gathered by spy tech from being used against them.

404 Media recently revealed that in its usage policy for Flock ALPR cameras, one county in Iowa tells police to keep them a secret when detaining people: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” If writing a report about an incident, police are told to say they used “county resources” in making a stop instead of acknowledging use of ALPRs.

In Houston, police officers are likewise instructed to “be as vague as permissible” about why they are using Flock because the searches they run on Flock’s surveillance system could be obtained via public records requests.

There is growing public alarm about the threat to civil liberties posed by ALPR cameras and reports of police abusing the tech by using it to spy on their exes. Some cities have the cameras covered up, and others are cancelling their use of ALPR networks. Two states have recently stepped back from ALPRs. This trend is certainly not lost on law enforcement agencies. Hiding the fact that they’re using ALPRs from Flock and other vendors is one way of avoiding scrutiny and bad PR.

But law enforcement and their spy tech vendors keeping people in the dark about the surveillance technologies trained on them predates the Flock backlash by decades. For example, AT&T built a powerful phone surveillance tool for police, called Hemisphere, in the mid 2000s, and the company required agencies not to use evidence gathered by Hemisphere in court unless there was no other admissible evidence. If evidence obtained through Hemisphere was used, police were required to recreate it through a traditional subpoena, a process they called “parallel construction.” We called it “evidence laundering.”

Likewise, police and prosecutors have taken far-reaching steps to hide from the public and courts their use of cell site simulators, also known as stingrays. Police have used these devices, which trick cell phones into connecting to them instead of phone towers to try locating suspects, to obtain people’s location data without a warrant by deceptively obtaining basic pen register orders from courts. Pen register orders are for obtaining call log data and police don’t need to prove they have probable cause to get one.

In Baltimore, for example, a judge concluded that law enforcement had used a standard pen register order to intentionally hide its use of a Stingray from the court in violation of its legal disclosure obligations, leading to a landmark 2015 privacy ruling that cops need a warrant to use the device.

That didn’t stop police from continuing to try to pull the wool over the eyes of courts and defense attorneys when they used stingrays, however. Prosecutors have accepted plea deals to hide their use of cell-site simulators and have even dropped cases rather than reveal information about their use of the technology. U.S. Marshalls have driven files hundreds of miles to thwart public records requests.

Fortunately, our commitment to shining a light on the use of surveillance tech is just as strong, if not stronger, than law enforcement’s quest to hide it. We’re working with privacy advocates and community groups to bring awareness about existing and emerging spy tools that threaten civil liberties and we’re encouraging policymakers and lawmakers to do more to restrain warrantless mass surveillance and stop it before it ever takes hold.  

If you're curious about whether your local police have contracts for ALPRS or other surveillance technologies, you can search EFF's Atlas of Surveillance.

 

Digital Sovereignty: What It Is, What It Could Be

The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI, semiconductors, and platform regulation. Governments throughout the global majority use it to argue for greater control over data and communications infrastructure and boost their economies. Companies market “sovereign cloud” products designed to reassure their customers that their information stays under local jurisdiction. But digital sovereignty could be something more: an opportunity for users around the world to build more resilient, open  systems and the skills and infrastructure to maintain them.

There is no singular definition of digital sovereignty, nor is there a single coherent position in the digital rights space. Despite its growing popularity, the term remains frustratingly vague. Policymakers, regulators, civil society groups, and others can mean very different things when they use the term. But to start simply with a broad definition, we can say that it means having the capacity to control one’s digital destiny—though the implications of that will obviously differ considerably whether you’re talking about an individual or a country.

We can start by developing  a shared understanding of what digital sovereignty actually means. We’ve also included a glossary of terms at the bottom of this post. 

In Europe and other places where digital sovereignty has become a topic of policy, discussions focus on reducing dependency: on foreign (and particularly American) cloud infrastructure, chips, platforms, and at times, foreign political priorities. The concern is both economic and geopolitical. If essential infrastructure is controlled by companies elsewhere—and thus subject to the laws of another jurisdiction—then what control does a country actually have over its own digital future?

In global majority countries in particular, wars, sanctions, and the growing fragmentation of the internet have demonstrated for many that the physical infrastructure that underlies digital life is neither neutral nor invulnerable. 

Amidst this increasing geopolitical instability governments and civil society should consider whether digital sovereignty can help shore up that infrastructure. 

What are we talking about when we talk about digital sovereignty? 

A recent Franco-German joint paper on digital sovereignty defines it as the “capability and capacity to develop, provide, use, adapt and control digital technologies including hardware in an independent, self-determined and secure manner” and puts forward a framework to operationalize Europe’s capacity to act in the digital domain. 

Some governments, such as Germany’s, have started to put funding behind sovereignty efforts through initiatives like the Sovereign Tech Agency, which “invest[s] globally in the open software components that underpin Germany's and Europe's competitiveness and ability to innovate.” 

Positions on digital sovereignty among EFF’s allies across Europe vary. Open Rights Group have defined digital sovereignty as “the ability of a country to have control over its digital infrastructure, data, and technology” and states it to be “critical for the UK’s economic and national security.” 

Similarly, the European Partnership for Democracy has expressed concern that “a few Big Tech corporations decide our collective destiny,” and argue that the EU should explore “alternative ownership models for tech companies and clearly [define] their purpose and mission.” And our friends at EDRi (of which EFF is a member) have stated clearly that “Europe’s digital sovereignty starts with open source.” Some initiatives, such as DI.DAY, consider digital sovereignty an opportunity to free users from Big Tech dependencies.

Elsewhere in the world, conversations about digital sovereignty often take a different shape. Indigenous discussions of the topic have been ongoing for more than a decade and focus on the inherent right of Native nations to govern their own digital ecosystems. In Southeast Asia, the desire for digital sovereignty has created growth in the sovereign cloud industry, but the conversation isn’t purely economic: Concerns about jurisdiction for where data is held are driving much of the conversation. 

In Latin America, digital public infrastructure is often a key aspect of debates. Across Africa, leaders speak of a desire to shift the continent from being consumers of technology to becoming architects of their own digital infrastructure and data ecosystems. And in the Middle East and North Africa, concerns about reliance on U.S. technology companies—which have engaged in conflict and disproportionate censorship (particularly of Palestinian voices) in the region—are often paramount.

Reem Almasri, a senior researcher based in Jordan, recently spoke to EFF about digital sovereignty, which she sees as “the ability of people and communities to choose, control, and use technology that serves their needs and values,” particularly in light of the role that U.S. companies have played in regional conflicts.

In a January article, Almasri pointed to growing concerns about granting greater sovereignty and influence to governments over citizens’ data, communications, and websites, writing: “This is particularly worrisome in countries that impose high levels of internet and media censorship and run unaccountable surveillance programs on their citizens’ data.”

Indeed, while pushing for greater sovereignty from Big Tech has benefits, there is an inherent risk that some states will pursue digital sovereignty as a means of cutting off or splintering access—as we’ve already seen in Iran, Russia, and elsewhere.

For that reason, it’s no surprise that some, such as Iranian professor Azadeh Akbari, believe that “the current wave pushing digital sovereignty as the key to ending dependency on American and Chinese technology is negligent of its Eurocentric bias.” 

What does EFF believe?

In a world where people have digital sovereignty, civil society should be able to communicate freely, privately, and anonymously if they wish. People should be able to easily understand where their data lives and who has access to it. That data should be easily portable between platforms and services.

At EFF, we view digital sovereignty not as a walled garden, but as an opportunity for resilience and development of industries and skills. We believe that governments can and should take a role in crafting digital sovereignty that centers the autonomy of users rather than just re-creating a state of digital dependency with a new set of companies. Governments should support and use free and open source tools and projects built using principles of interoperability and data portability. This support should include employing full-time developers, UX designers, and community managers. Government policy and legislation should grant users control of their own data and a clear understanding of who can lawfully access it. Digital sovereignty should foster users’ ability to choose how they use digital products and services, free from unfair lock-ins, coercive terms and manipulative defaults. It should also foster the broader public interest internet, the part of the web that provides public goods and useful services without requiring the scale or the business practices of the tech giants.

Encryption backdoors are fundamentally incompatible with a vision of data sovereignty that centers user control. Governments should support the development and normalization of reputable end-to-end encrypted communications as well as strong encryption for data at rest. This support should include employing cryptographers and contributing to strong, peer-reviewed encryption standards strengthened by data minimization as a fundamental design principle, as well as refraining from legislating mandates for “lawful access” or any other reason.  

As technologists, we don’t have to wait for governments to act in order to create the digital sovereignty we want. We get the internet that we build. We can contribute to open source, decentralized, and end-to-end encrypted projects. We can build standards that make interoperability and data portability a feature from the very beginning. We can resist the call of proprietary solutions, user lock-in, and encryption backdoors.

And finally, while digital sovereignty is often framed as a response to the dominance of Big Tech, that does not mean that there is no role for private companies to play. There is no point in replacing the influence of a few mostly US-based tech companies with a handful of giants based elsewhere. Companies can and should build platforms and services on top of open source, decentralized protocols and contribute to the ecosystem. Companies should also minimize processing a person’s data except as strictly necessary to provide them what they asked for, and only with opt-in consent that makes it clear to users what data they are gathering, where it is stored, and who has access to it. And companies should build their tools and platforms in a way that allows interoperability and that makes it easy for users to leave with their data. Some of these practices are already required by law in some jurisdictions, but companies don’t have to merely do the bare minimum the law demands: they should respect their users and support data sovereignty right now.

A glossary of terms

The following terms are useful for understanding this blog post as well as the broader conversation about Digital Sovereignty:

Intermediary liability: the legal responsibility of online service providers (ISPs, websites, social media platforms) for unlawful activities by their users, such as defamation, copyright infringement, or illegal hate speech.

The stack: a secure, open-source technology framework, often focusing on European alternatives, designed to break dependencies on (mostly) US-based technology providers. It comprises interoperable, vendor-neutral, and transparent digital infrastructures designed to regain control over data, infrastructure, and technology.

Digital sovereignty: the ability of people, as nations, organizations, and individuals, to control their own digital destiny by retaining authority over their own data, technology, and infrastructure.

Data sovereignty: the principle that digital information is subject to the laws and governance frameworks of the country or region where it is physically collected, stored, or processed. It dictates that data remains bound by the specific privacy protections and regulations of its originating jurisdiction, regardless of where the collecting organization is located.

Digital commons: a shared, online resource, such as knowledge, software, and data, that is collectively produced, governed, and maintained by a community, intended for public access. Examples include Wikipedia, open source operating systems such as Linux, and Creative Commons licensed content.

Data portability/interoperability: the ability to easily transfer personal data from one service provider to another, or to a personal system, in a structured, machine-readable format. It empowers users to move away from "walled gardens," reducing vendor lock-in and enhancing user autonomy.

Digital dependency: the opposite of digital sovereignty. The inability of people as nations, organizations, and individuals to control their own digital destiny through control over their own data, technology, and infrastructure. 

Decentralization: a shift away from relying on centralized, often US-based, corporate platforms toward a distributed, user-centric internet where individuals, communities, and nations maintain control over their data, digital identity, and infrastructure.

End-to-end encryption (e2ee): a secure communication process where only the sender and intended recipient can access, read, or decrypt messages or data.

Fairness (à la the Digital Fairness Act): the absence of deceptive, manipulative, or addictive design practices that distort consumer choice and exploit vulnerabilities. 

User sovereignty: the concept that individuals possess absolute control over their personal data, digital identity, and online privacy, rejecting the centralization of power by large technology platforms. It emphasizes user consent, decentralization, and the ability to manage personal data using secure and independent tools.

2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights

EFF is pleased to announce that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights have received 2026 EFF Awards for their vital work in ensuring that technology supports freedom, justice, and innovation for all people. 

The EFF Awards recognize specific and substantial technical, social, economic, or cultural contributions in diverse fields including journalism, art, digital access, legislation, technology development, and law. 

For the past 30 years, the EFF Awards—previously known as the Pioneer Awards—have recognized and honored key leaders in the fight for freedom and innovation online. Started when the internet was new, the Awards now reflect the fact that the online world has become both a necessity in modern life and a continually evolving set of tools for communication, organizing, creativity, and increasing human potential.  

Supporting a global community advancing digital rights, defending digital access in crisis zones, empowering communities to take action against surveillance, and providing free legal assistance for creators and consumers to fight back against digital threats are high callings that help bring about a better tech future for all. We are pleased to honor these organizations with 2026 EFF Awards. 

Access Now – Fostering Change in Human Rights and Technology

Access Now logo

Access Now, founded in 2009 as an emergency response team helping Iranian activists get back online and communicate safely, has grown into one of the world’s foremost organizations defending and extending the digital rights of people and communities at risk and supporting the global fight against technological repression.  

Its 24/7 Digital Security Helpline offers real-time, direct technical assistance and advice to civil society groups and activists, media organizations, journalists and bloggers, and human rights defenders. It provides grants to frontline organizations working with people and communities most impacted by digital rights violations. It educates decision makers and pressures the powerful. And it organizes RightsCon, a leading annual summit on human rights in the digital age, where activists, technologists, policymakers, business leaders, journalists, philanthropists, researchers, and artists can connect, collaborate, and drive change at the intersection of human rights and technology. 

7amleh – The Arab Center for the Advancement of Social Media – Defending and Advancing Digital Access and Rights Across the MENA Region

7amleh logo7amleh - The Arab Center for the Advancement of Social Media protects and expands digital access and rights for Palestinians and across the MENA region. The nonprofit investigates and monitors challenges to digital rights, focusing on internet access, privacy, freedom of expression and association online. It builds the capacity of activists, human rights defenders, and civil society organizations to provide training about digital rights, gender sensitive digital security, and effective online advocacy.  

7amleh also advocates for changes to the digital rights policies and practices of governments, corporations and other influential institutions and individuals locally, regionally and internationally. It plans and manages advocacy and awareness-raising campaigns and builds networks and coalitions to promote access to safe, fair and free online spaces. For example, 7amleh has led the #ReconnectGaza campaign, supported by dozens of international NGOs including EFF, to restore full internet access in Gaza – a crucial lifeline for residents, journalists, activists, and first responders.  

DeFlock – Exposing the ALPR Surveillance Network

DeFlock logo

DeFlock is an open-source, volunteer-powered project that maps surveillance devices across the world, helping communities hold their governments and surveillance vendors accountable and understand where and how they're being watched. Founded in 2024 by software engineer and privacy advocate Will Freeman, DeFlock shines a light on the widespread use of automated license plate reader (ALPR) technology and the threats it poses to personal privacy and civil liberties.  

DeFlock resources help people request public records, speak to local lawmakers, and take action against ALPR surveillance. Its work has helped foster a national grassroots community of anti-surveillance activists fighting back against this dangerous surveillance technology. 

New Media Rights – Helping Creators Fight Back Against IP Bullies

New Media Rights logo

New Media Rights (NMR) is a San Diego-based nonprofit program of California Western School of Law dedicated to defending digital rights through legal services, education, and public policy advocacy. Since its inception, NMR has been at the forefront of protecting creators, entrepreneurs, and internet users from digital threats such as copyright abuse, online harassment, and privacy violations. 

In addition to providing free legal assistance, NMR has produced hundreds of freely available video and written legal education guides for creators and consumers, including the Fair Use App for filmmakers and video creators. It has participated in regulatory proceedings on net neutrality, Digital Millennium Copyright Act anti-circumvention, and copyright reform. Its work has also helped support access to public information and greater business and government accountability. 

New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment

EFF sued the government back in March for information about the Wasteful and Inappropriate Service Reduction (WISeR) model, a new Medicare program that uses AI to evaluate prior authorization requests for certain medical services. Today, we’re releasing approximately 1,000 pages of records obtained from the Centers for Medicare & Medicaid Services (CMS) through this litigation, including contracts with tech companies, internal status reports and providers’ complaints about the program. The documents (available here) show that WISeR has resulted in widespread delays and denials of care, operational chaos, and reports of patient harm.

Why We Sued for Records about WISeR

EFF filed the FOIA lawsuit to gain badly needed transparency into an experimental AI program that could jeopardize Medicare beneficiaries' access to care. In January 2026, CMS launched the WISeR model, subjecting seniors in six states to AI-driven prior authorization decisions. Medical providers must now request permission before delivering certain medical treatments if they want assurance that Medicare will cover them. Private companies contracted by CMS evaluate the requests using AI. In the absence of rigorous safeguards, AI-driven prior authorization determinations can lead to unwarranted—and even discriminatory—delays or denials of necessary medical care. 

Little is known about the AI systems that WISeR vendors are using to process prior authorization requests. Although CMS says that a qualified human clinician must review all denials, research has shown that AI-generated recommendations often influence human decisions. And the design of the WISeR program creates a financial incentive for vendors to deny care, since they are paid for averted expenditures. Just months after the program launched, medical providers reported improper denials, administrative friction, and lengthy delays that have left patients waiting in pain.

EFF’s FOIA request sought records pertaining to the CMS contracts with WISeR software vendors; any tests for accuracy, bias, or hallucinations in vendors' technology; and any audits, monitoring, or evaluation of WISeR and participating vendors.

CMS Documents Highlight Issues with the WISeR Model

CMS records obtained by EFF echo issues that medical providers, patient advocates, and lawmakers have warned about since WISeR began. This includes long wait times, rampant technical failures, inappropriate denials, and harm to patients.

Delayed Responses to Prior Authorization Requests

CMS publicly states that WISeR vendors should respond to prior authorization requests within 72 hours, but records received by EFF show widespread delays. Internal status reports from the first few months of the program show that a significant number of prior authorization requests took far longer than 72 hours to resolve. One status report cites a prior authorization request that went unanswered for 83 days ("WISeR FOIA Response - Combined Records," page 234). These delayed responses can have serious consequences for patients. Medical providers reported that WISeR has delayed medically necessary care and left patients in pain as they waited for approvals.

Timeliness data for two WISeR vendors in January 2026 show that a significant number of requests did not receive a response within 72 hours (WISeR FOIA Response - Combined Records, page 410)

Payment Methodology Provides Financial Incentive to Deny Care 

The released records confirm that WISeR’s payment methodology creates a financial incentive to deny care. Specifically, WISeR vendors are paid for requests that they deny (though not for denials reversed on appeal). This profit motive aggravates the risk that AI-assisted decision-making may unfairly deprive people of the services they need.

CMS publicly claims that it safeguards against inappropriate denials by tying vendors’ payment rates to “quality scores,” which reflect the timeliness and accuracy of vendors’ decisions. However, the recently released WISeR Data Reporting Guide shows that low quality scores reduce payments by only 5-10%.

Impact of low quality scores on payment rates described in the WISeR Data Reporting Guide (WISeR FOIA Response - Combined Records, page 99)

WISeR Vendors Have Denied Thousands of Prior Authorization Requests

Documents obtained by EFF appear to support reports that WISeR vendors may be denying claims at unusually high rates. Two companies alone denied 5,944 prior authorization requests in the first 3 months of the program. One company, Virtix, the vendor that CMS required to submit a Corrective Action Plan, denied more requests than it approved during this time period.

Prior authorization decision data for two vendors in a March 30th, 2026 status report (WISeR FOIA Response - Combined Records, page 322)

Medical Provider Feedback Ties WISeR Delays to Patient Harm

Feedback from medical providers emphasize that WISeR delays have harmed patients. The released records include March 2026 responses to a feedback form about Innovaccer, the WISeR vendor processing requests for Ohio. Medical providers complained about a lack of communication, administrative issues, and long response times. Several responses emphasize that long response times from the WISeR vendor harmed patients ("WISeR FOIA Response - Feedback Survey Responses"):

“We have patients calling our offices crying in pain because their procedures are being delayed while awaiting approvals or guidance tied to this model. A 3–4 day delay for necessary pain procedures is already difficult for vulnerable patients, but when providers cannot obtain answers for weeks, the situation becomes unacceptable.”

“I HAVE HAD TO WATCH 3 PATIENTS CRY AT BEDSIDE FOR NOT HEARING BACK ON THEIR PRIOR AUTH FOR KYPHOPLASTY/VERTABRAL AUGMENTIATION PROCEDURE. THESE PATIENTS ARE IN DEEP PAIN.”

“I have had cases submitted and waiting over 1 1/2 months for a UTN to be generated… In the meantime patients are having to be cancelled for surgeries they need. This is not acceptable they are severely hindering patient care.”

Rushed Rollout Amidst Widespread Technical Failures 

CMS WISeR launched in January 2026, just six months after it was announced. Despite warnings from both medical providers and a vendor about insufficient preparation time, CMS chose not to delay the launch. 

Approximately a month before the launch, one of the vendors, Innovaccer, alerted CMS that it intended to go live with a version of its software that lacked full functionality and had not been fully tested. It cited several barriers to going live with full functionality, including changing requirements and expectations, unclear governance processes, and lack of time for end-to-end testing with the provider community ("WISeR FOIA Response - Combined Records,", page 216-217). Innovaccer said it would auto-affirm all prior authorization requests until it could develop full functionality and explained that “Given CMS's decision not to delay the model start date, auto-affirming is the only path available” ("WISeR FOIA Response - Combined Records," page 217).

Innovaccer had not yet finished developing or testing some features several months into the program, according to an April 2026 status report. Innovaccer was not the only vendor who faced technical challenges before and after WISeR launched. Weekly status reports and provider feedback in the released records show widespread challenges associated with WISeR’s rushed rollout (for example, "WISeR FOIA Response - Combined Records," pages 238 and 383).

A status report from April 6th, 2026 describes issues with incomplete solutions from Innovaccer (WISeR FOIA Response - Combined Records, page 200)

More Urgent Medical Services Considered for Inclusion in Future Years of WISeR Model

In its first year, the WISeR model introduced prior authorization requirements for a set of 13 medical services. The June 2025 Innovation Center Investment Plan for WISeR lists medical services that could be added to the program in future years. This planning document considers the possibility of adding services “where prior authorization would have to be done on a more urgent or emergent basis,” including air ambulance transport, cancer treatment, MRI scans, and medications without publicly available coverage criteria.

A planning document from June 2025 lists ideas for the expansion of WISeR to additional medical services (WISeR FOIA Response - Combined Records, page 22)

More Transparency is Needed About Medicare’s AI Experiment

CMS continues to produce records in response to EFF’s lawsuit. Records released thus far echo concerns that providers have raised since WISeR launched, including long delays, financial incentives to deny care, and technical problems. But important questions remain about the AI systems private companies are using to inform decisions about whether to provide people with Medicare benefits. As CMS continues to produce documents, we will continue to make them available to the public. The public deserves to know how AI is driving decisions that affect patients’ access to care.

Correction: An earlier version of this post misstated the number of prior authorization requests that had been denied by two WISeR vendors in the first three months of the program. This version has been corrected to reflect that the number of denials was 5,944. The post has also been updated to clarify that reported turnaround times reflect the full request pathway and are not solely controlled by WISeR vendors.

Related Cases: 

❌