EFF: Updates
Resisting the Menace of Federal Data Consolidation
In the past two years, the federal government has unlawfully consolidated data exposing our private information.
This consolidation has been chaotic but generally came in three rolling waves: It started with DOGE, moved to agency-to-agency data sharing with ICE, and then attempted data-driven purges of state voter rolls.
We all deserve to live in a world where the data we use to pay our taxes, receive benefits, and vote is not combined and weaponized against us. The amalgamation of data leads to mistakes, abuses, and a lack of trust in institutions meant to protect us. Overall, it can chill our participation in society. This is particularly true for groups disfavored by this administration—especially immigrants and protesters.
Congress highlighted similar abuses—including the creation of enemies lists and snooping on activists and federal employees—following the McCarthy and Watergate eras. And the increasing use of computers to magnify those harms led Congress to pass a slate of protections like the federal Privacy Act of 1974.
The good news is that many people have stepped forward to resist the federal government’s unprecedented and unlawful data consolidations. Many groups, including EFF, have filed lawsuits to enforce our data privacy laws, and many states have, too. Legislators at the federal and state levels have worked to expose and oppose these surveillance programs. And many people have protested for their right to data privacy.
Existing data privacy protections have been essential in the past two years, but they can be improved. This should include: narrowing loopholes and increasing enforcement in existing laws, limiting the government’s purchase of data on the commercial market, and passing a comprehensive consumer privacy law.
Data Consolidation by DOGEStarting on January 20, 2025, President Trump created DOGE—essentially renaming an existing agency originally meant to modernize government technology. Rather than engage in modernization, DOGE quickly obtained high-level access to sensitive databases across the government that store millions of people’s personal records—including at the Office of Personnel Management (OPM), the Social Security Administration, and the Treasury Department.
DOGE was staffed with people with little government or cybersecurity knowledge and who often had conflicts of interest. DOGE’s early aim was not always clear, aside from gaining “prompt access to all unclassified agency records” and the “sharing and consolidation” of those records.
The result? The indiscriminate firing of government employees and the decimation of important agencies that focused on consumer protection and foreign aid. It also resulted in clear misuses of data. For example, while working with DOGE at the Social Security Administration, one individual signed an outside agreement with an advocacy group with the aim of using SSA data to find evidence of alleged voter fraud and “overturn election results in certain States.”
DOGE’s data access and consolidation violated the federal Privacy Act, which limits the sharing and consolidation of government databases. Many groups stepped in to sue. For example, EFF and our co-counsel at Lex Lumina LLC and Democracy Defenders Fund, on behalf of two public employee unions (AFGE and AALJ), sued the OPM for unlawfully disclosing federal workers’ information to DOGE. After EFF and others secured early victories, the government sought to end the lawsuits by firing many DOGE agents and removing their access to records. A great deal of damage remains in need of a judicial remedy.
Data Consolidation by the Department of Homeland Security (DHS)Even as DOGE’s influence diminished, federal agencies have attempted to share, compare, and seize large databases, in order to target immigrants. In some cases, they have succeeded. This happened with tax records at the IRS, Medicaid data from the Department of Health and Human Services (HHS), and public housing data from the Department of Housing and Urban Development. The Department of Agriculture also sought to collect databases regarding Supplemental Nutrition Assistance Programs (SNAP) from states.
Many groups have filed lawsuits to block this anti-immigrant-motivated data consolidation, alleging it violates privacy protection laws. EFF filed amicus briefs in support of two of these lawsuits: Centro de Trabajadores v. Bessent, which concerns IRS data; and California v. HHS, which concerns Medicaid data (and where we teamed up with EPIC and Protect Democracy). Most recently, states have stepped up to challenge the federal government’s attempted seizure, for immigration enforcement purposes, of state commercial driver’s license data held by the American Association of Motor Vehicle Administrators, a non-profit organization.
This data consolidation for immigration enforcement has also included government purchase of commercial products. This includes ICE’s purchase of commercial location data without a warrant, and its interest in “Big Data and Ad Tech providers.” ICE also has contracts with companies like Palantir, which help organize all the datasets the agency collects.
Data Consolidation for Voter PurgesThe right to vote is fundamental to every democracy. That’s why EFF has long advocated for cybersecurity in voting systems, to make sure every vote is properly counted.
Voter purges are a longstanding threat to the right to vote. State and local officials regularly delete people from the voter registration rolls, often for bad reasons and without adequate notice. This has a disparate impact against people of color.
Now the federal government is trying to purge voters, too. To do so, it has consolidated our data in three ways. First, it is using an old data system called SAVE for a new purpose: checking voter eligibility. Second, it has seized voter information from states. Third, it has created a federal list of eligible voters.
As a direct result, people with a right to vote will be purged from voter rolls because of erroneous data. Others will be intimidated from voting or registering. And all registered voters suffer a violation of their data privacy rights: information collected for one purpose is being used against them for another purpose.
Expansion of SAVESince 1986, the federal government has operated SAVE, which stands for Systematic Alien Verification for Entitlements. It is not a database, but it facilitates easy access to databases. It is used to determine whether immigrants and naturalized citizens are eligible for various government benefits, such as food stamps.
In 2025, the federal government started using SAVE for a new purpose: checking voters’ eligibility. Further, SAVE now provides access to new databases and allows bulk searches. More than 60 million voters have been run through SAVE, and 21,000 were flagged as potential noncitizens who are ineligible to vote. Erroneous flags have caused purges of lawful voters – such as Anthony Nell.
A case called League of Women Voters v. DHS challenges this expansion of SAVE. The plaintiffs are represented by CREW, Democracy Forward, the Fair Elections Center, and EPIC. A federal judge held this program unlawful and set it aside. DHS appealed and asked for a stay of this order, and a federal appellate court denied the stay. Unfortunately, the U.S. Supreme Court granted the stay, exercising its controversial “shadow docket” authority by a six-to-three vote.
Federal employees in DHS’s “Fraud Detection and National Security Unit,” which ordinarily investigates alleged immigration fraud, have been re-assigned to examine voter eligibility. A whistleblower alleges that employees have been directed to go to state election agency websites, enter some of a voter’s personal information, and thereby access more of it. This may violate state laws requiring a person, before accessing a voter’s information, to attest they are that voter or have that voter’s authorization.
Federal Seizure of States’ Voter InformationSince 2025, the federal government has demanded that at least 48 states hand over their voter information. At least 16 states have complied. The federal government is running this information through SAVE, searching for voters to purge.
The federal government has sued 30 states for refusing to comply. So far, courts have dismissed 25 of these suits. There’s also a lawsuit against this data grab, titled Common Cause v. DOJ, brought by CREW, Protect Democracy, and the ACLU.
The New Federal Voter Eligibility ListIn March 2026, President Trump issued an executive order requiring DHS to create a list of people who are U.S. citizens, aged 18 or older, and residents of the state. The order also requires DOJ to prosecute anyone, including state and local officials, who provides a ballot to a person who is not eligible to vote in federal elections.
In California v. Trump, 24 states allege that this executive order violates the Constitution’s separation of powers. A federal judge enjoined this program, and an appellate court denied a stay. But the U.S. Supreme Court by a six-to-three vote granted a stay, which allows the program to move forward. (By a seven-to-two vote, the Court denied a stay of an injunction against a different part of the same executive order, which concerned mail-in ballots.) Another legal challenge, titled EPIC v. USCIS, alleges that the new federal voter eligibility list violates the Privacy Act as well as the separation of powers.
Next StepsIt is encouraging to see so many people, groups, and states step forward to protect our data privacy from these unlawful waves of federal data consolidations. Still, more work remains. For example:
- The Privacy Act of 1974 has proven a critical bulwark. But after a half century, it could use a refresh. For example, Congress should close its loopholes and expand its enforceability.
- Law enforcement agencies must be prohibited from avoiding the Constitution’s warrant requirement by buying our personal data from brokers. For example, Congress should pass the “Fourth Amendment Is Not For Sale Act.”
- We need a comprehensive consumer data privacy law, among other reasons to reduce the flood of our personal data that corporations provide to law enforcement agencies. Legislators should check out EFF’s “privacy first” framework.
In the meantime, there’s no time like the present to practice surveillance self-defense, like using strong passwords and disabling your phone’s ad identification.
Related Cases: American Federation of Government Employees v. U.S. Office of Personnel Management
Organizing in the Town at Oakland Tech Week
EFF was thrilled to join organizers, advocates, and activists in the East Bay for the second annual Oakland Tech Week last week. We are grateful to our friends at MediaJustice and Upturn for inviting us co-present this all-day event, “Building Beyond Big Tech: Organizing Oakland’s Future”, on Sept. 30. The event, hosted by the Kapor Center in downtown Oakland, offered a unique chance to spend time with people across The Town and the Bay Area working to create a better future for everyone.
“We’re at this truly consequential moment,” said EFF executive director Nicole Ozer, in her speech kicking off the day’s events. “We know that in this community’s work—and communities across the country—our ability to ensure that technology empowers rather than oppresses is fundamental to the future of countries, our livelihoods, and, literally, our lives.”
We also participated in a panel on the state of play in California, moderated by MediaJustice executive director Steven Renderos. Director of State Affairs Hayley Tsukayama joined reporter Khari Johnson of CalMatters and Crystal Zemero of People Over Billionaires to talk about the landscape at the state level. The day also included smaller conversations focused on building better tech and fine-tuning messaging, facilitated by our colleagues at MediaJustice.
Seeing the people—our neighbors—who are fighting back against surveillance in their communities was inspiring. They’re casting doubt on the claims large technology companies make about what’s happening in their neighborhoods. They’re speaking up at council meetings and rallies. They’re seeking changes that would give their workplaces and neighborhoods a better, safer relationship with technology. It was so important to come together in solidarity to compare notes, spend time together, find opportunities to support each other, and scheme together.
We can work together to build a future that works for everyday people. A better world is possible—and Oakland Tech Week was a great reminder that, all around us, folks are working together to tackle huge challenges.
“There are formidable forces,” Ozer said. “But we can pierce the other side’s narrative of inevitability with our power of indignation. The future of AI and other technology is not written and we can work together to get it right.”
Whether you’re in Oakland or Aukland, consider this a renewed invitation to join us.
Become an EFF Member Today
Turkish Crackdown On LGBTQ+ Organizations Threatens Freedom of Expression and Association
EFF strongly condemns Turkey’s state-led discriminatory, oppressive attacks on feminist and LGBTQ+ organisations, media platforms, student groups, and rights defenders and activists within the country.
Since mid-September, access to the websites and social media accounts of a dozen organizations have been blocked by court order, while over 60 members and activists have been detained, their offices and homes raided, mobile phones, laptops and other digital devices seized, and judicial proceedings launched against them.
These actions threaten the very existence of the LGBTQ+ organizations targeted, limiting their ability to carry out legitimate human rights work, deterring participation and support, and chilling the free speech rights of not just these groups, but any organization that even reports on LGBTQ+ oppression.
A little over a week ago, an Istanbul court shut down the website and social media accounts of T24, Turkey’s longest running independent digital news organization—which has covered government-backed campaigns against and earlier crackdowns on gay rights groups—alleging it had aired “LGBT propaganda” over the past year.
It’s all part of Turkey’s efforts to portray LGBTQ+ groups and support networks for those living with HIV as criminal organizations that must be suppressed, purportedly to protect family values. Homosexuality is not illegal in Turkey (unlike Uganda, Nigeria, and Egypt, where it is criminalized), but LGBTQ+ organizations and activists have in recent years faced increased government oppression, including criminal proceedings on allegations related to obscenity and violations of Turkey’s Law on Associations, which regulates the activities of nonprofits.
In its new crackdown, the government is targeting LGBTQ+ groups’ websites and social media channels for alleged obscene posts accessible to children. Kaos GL, Turkey’s oldest gay rights organization, said investigations are being led by the Cyber Crimes Bureau of the Ankara Chief Public Prosecutor’s Office, which took members of its Board of Directors into custody, raided their homes, and searched the organization’s offices, where electronic devices were seized.
According to Human Rights Watch, prosecutors in Istanbul said those targeted were suspected of “founding, leading, or being a member of a criminal organization,” as well as sex work and drug-related offenses. Publicly available law enforcement and judicial documents about the investigation reportedly don’t say which publications or posts are alleged to be obscene.
The prosecutor’s office launched an investigation of the organization and others under Article 226 of the Turkish Penal Code, which regulates the offense of “obscenity” (without clearly defining it), while the overall operation, dubbed “My Family is Safe” and launched as part of President Recep Tayyip Erdoğan’s “Decade of the Family” program, is being brought under Article 220 of the code. Justifying the crackdown by invoking family values and child safety suggests that the government is trying to enforce a moral code on society based on intolerance of and discrimination against LGBTQ+ people.
New Low for TurkeyFraming the activities of LGBTQ+ rights organizations as violations of organized crime provisions is a new low for Turkey, where free speech and press freedoms have long been under attack. The implication from these raids and investigations is that the organizations’ legitimate civil society work advocating for the rights of queer people—monitoring human rights violations, offering legal aid, running news portals, sponsoring cultural events such as symposiums and film screenings, publishing an online magazine and supporting LGBTQ+ refugees—is suspected of being criminal threatens the basic human rights of the LGBTQ+ community in Turkey.
These actions send a dangerous message to people and organizations exercising freedom of speech and association in support of queer people. Under the penal code, directing a criminal organization is punishable by five to ten years in prison, while merely being a member carries a sentence of two to five years.
EFF joins hundreds of human, civil, LGBTQ+, and digital rights organizations around the world in calling for the immediate release of all those detained for exercising their rights to freedom of expression, association and legitimate human rights work, and the unblocking of all websites and social media accounts of affected organizations.
For many LGBTQ+ individuals the world over, the internet can be a safer space for exploring identity, finding community, and seeking support. The anti-LGBTQ+ crackdown in Turkey is not happening in a vacuum—unfortunately we are seeing anti-LGBTQ+ bills restricting free expression and privacy, content moderation decisions that disproportionately impact LGBTQ+ users, and other forms of intolerance around the world.
We urge international civil society and diplomatic partners to raise awareness of and to speak out against the crackdown, and to publicly show support for the legitimacy of Turkey’s LGBTQ+ organizations and the important work they do to ensure that queer people are safe and free.
When No ID Means No Internet: Age Verification and the Right to Access Information
This post was co-authored by Sheila B. Lalwani, a doctorate student and recent COMPASS Fellow hosted by EFF.
Age verification proposals are often presented as a simple tradeoff: sacrifice a little privacy to better safeguard children online. But that framing overlooks a more fundamental question. What happens to people who cannot verify their age at all? This is particularly a problem when users are required to prove their age with identity documents.
Age-related restrictions are developing quickly around the world. While they differ radically across jurisdictions, in the past year, we’ve witnessed a sharp uptick toward mandatory age assurance for social media access but also for other high-risk digital services.
For example:
- In late 2025, Australia became the first country to implement a minimum age requirement for prohibiting children under age 16 from creating or holding social media accounts.
- India passed the Digital Personal Data Protection (DPDP) Act that includes mandatory verifiable parental consent and has undertaken ongoing discussions for social media restriction.
- The United Kingdom passed the Online Safety Act requiring age verification across a swath of services hosting content considered harmful to users under 18. More than half the states across the U.S. have enacted age verification laws.
- An EU Commission’s expert report recommends a ban on social media access for users under 13. It also recommends mandatory age verification for platforms to ensure that users are ‘age appropriate.’
Age verification laws that are predicated on the necessity of users possessing a current passport, driver’s license, credit card, or similar documents proving their identity exclude critical sections of populations. And this problem is global in nature: Millions of people lack government-issued identification or encounter regular challenges to obtaining or updating it.
Roughly 15 million adult U.S. citizens lack a driver’s license, and a further 2.6 million lack any government photo ID; leaving large groups blocked from online content or services. The UK has a similar predicament: proof-of-age checks are often reliant on passports, driver’s licenses, or other recognized alternatives, which can pose unique challenges to people without these documents.
Much of the advocacy around age verification discusses the privacy harms of age verification. Yet these measures also threaten something more fundamental: equal access to information and the ability to exercise the right to freedom of expression.
Unfortunately, age verification systems foster unequal access to information and provide an asymmetric solution to find essential information, build community, and weigh in on public discourse. As governments and companies increasingly require users to prove their age before accessing online services, these individuals risk being excluded from large parts of the internet altogether.
Effects on Global Majority CountriesAge verification laws reshape who can speak, who can access information, and who gets excluded from the digital public sphere. In other words, age verification is not a neutral safety measure: it presents a structural barrier to disproportionately exclude certain groups—particularly those in the global majority—and alters the architecture of global online expression. Some of these groups are already marginalized offline, and age verification extends that exclusion into digital spaces.
For instance, 850 million people globally do not have ID. Most of these individuals exist in primarily low and middle income countries in Sub-Saharan Africa and South Asia. The World Bank points out that many are members of marginalized groups and more than half of those lacking access to identity documentation also have children whose births have not been registered. Women are particularly vulnerable and are 8% less likely than men to have an ID. Other vulnerable groups, such as adults in low income countries, are less likely to have an ID when they fall below 25 years, as are those with a primary school education or less or those in rural areas.
A policy paper from EDRi points out that age verification laws provide quick tech solutions but overlook longstanding structural challenges and undermine the universality of the internet. The analysis finds that age verification laws have serious human rights implications and ironically harm the very individuals they deem to protect. Moreover, these laws depend on the collection of harmful mass data that human rights organizations, including EFF, is fighting against—and has for decades.
For example:
- In Morocco, a push to restrict children’s access would ban under-13s from creating accounts on gaming platforms. This could potentially create challenges for those with IDs that have incomplete information concerning the year of birth. In addition, this push would also impact those who attempt to leave Morocco.
- In Egypt, the lack of ID cards has created challenges for minority groups such as the Baha’i.
- Stateless individuals would also struggle under age verification laws. The Rohingya, the world’s largest population of stateless people, often lack IDs.
- Kuwait’s Bidoon population also lacks proper identification materials. According to Amnesty International, this leads many to rely on standard civil identity cards, which can be restrictive.
- Nigeria launched a national program to provide ID cards to its population in 2007. Since then, 64.4 million have registered, but that represents just over 30% of the national population.
- The Kafala system, a practice in several countries across the Middle East, also introduces challenges for age verification laws. Under this legal framework, migrant workers’ legal residency and employment status are bound to a specific employer. This potentially leaves stateless persons or migrant workers vulnerable to forced labor and restricted movements.
Age verification laws are less about confirming the age of a user and more about creating barriers to online participation that many people cannot reliably scale. The net result is reduced access, more data collection, and an increased chance of unequal or mistaken exclusion from accessing information online.
Nobody doubts the importance of protecting children online. While proponents assert that age verification laws protect minors from harmful material, online harassment, and digital addiction, these laws are not the solution. They subvert fundamental freedom of expression rights and pose significant privacy risks.
EFF has long warned against age-gating the internet. Age verification technology itself is often inaccurate and privacy-invasive, and as more countries considering implementing ID-based checks, the risks move beyond censorship and surveillance toward excluding some people entirely. That’s why we’re working with groups in the U.S. and around the world to push back against these laws, and why we hope you join our effort.
For more information on how to fight back against dangerous age verification laws, visit our resource hub at eff.org/age
It's DAF Day! Wait...What's a DAF?
Today is DAF Day! This event highlights the millions of donor-advised funds (DAFs) people have set up to make charitable donations and change the world. If you have a DAF, consider supporting EFF today.
Decisions about your privacy, encryption, artificial intelligence, online speech, and digital security will determine whether technology empowers people or concentrates power in the hands of a few. A grant from your DAF to EFF supports our mission to ensure that technology remains a force for freedom, innovation, and human rights.
If you’ve never heard of a DAF, just think of it as a bank account for your giving with some special benefits.
Grants from DAFs allow you to:
- Simplify your taxes by receiving an upfront single deduction for your multiple charitable donations
- Receive immediate tax benefits of multi-year gifts
- Avoid capital gains tax on long-term appreciated assets like stocks
- Boost your giving by investing your DAF funds
While allowing EFF to:
- Defend encryption, privacy, and security that protect users and developers
- Challenge unlawful surveillance and censorship that threaten democracy
- Shape technology policy to safeguards civil liberties while enabling innovation
- Build free privacy-preserving tools that strengthen digital autonomy
- Protect the rights of creators, researchers, and builders in the digital ecosystem
Your support helps ensure that the next generation of technology will strengthen our freedom. Consider a DAF gift today.
Site-Blocking Will Not Defend IP, No Matter the Bill’s Name
There has been a raft of site-blocking bills in the latest Congress, and the latest is called the “Deterring Extraterritorial Foreign Exploitation of Networks Damaging Intellectual Property” aka the “DEFEND IP Act.” The problem is that instead of “defending IP,” this bill will incentivize censorship, overblocking, and bad faith attempts to block access to a website. DEFEND IP Act, and all of these site-blocking proposals, threaten the open web.
We keep seeing attempts to pass site-blocking legislation–from SOPA/PIPA in 2012 to Block BEARD, FADPA, and ACPA this year. Every one of them has at its core the rotten idea that enforcing copyrights requires building a censorship machine for websites into the architecture of the internet. This is, of course, a disaster for a free and open web. There is no way to create a mechanism for blocking access to an entire website that does not invite both deliberate abuse and lots of collateral harm to free and lawful speech.
DEFEND IP deputizes every service provider into a copyright cop, so long as a rightsholder has accused a website of copyright infringement. Let’s be clear: this isn’t about removing access to an infringing work–that already exists via the DMCA. This isn’t about getting damages from the website or the uploader. It is about making an entire website inaccessible for everyone trying to visit it.
DEFEND IP lets any rightsholder go to a court and get an order requiring service providers to block access to an entire website after alleging copyright infringement. What DEFEND IP does not have is any deterrent for someone seeking to block a website in bad faith. There are no punishments for getting a website blocked for protected speech. There are no meaningful remedies for those whose speech is vanished from the internet due to an entire website being disappeared. It creates a one-stop shop for getting an entire website–again, not an instance of infringement but an entire site hosting all sorts of user content–removed. But for those whose business, speech, or access to information is affected, there is no easy way to get the site restored.
DEFEND IP scales up the extraordinary legal structures that already exist for copyright enforcement. In doing so, it likewise scales up the problems those regimes pose to protected speech.
We see this with DMCA takedowns all the time. We see it with bad faith takedowns used to silence criticism or commentary. We see it with the voluntary use of copyright filters by sites like YouTube, where seconds of sound matching seconds of sound in another video can prevent an entire work from reaching its audience. In these existing systems, there are at least some mechanisms of challenge available to the targeted creator. DEFEND IP has none. Instead, site owners, users, or readers will have to find a lawyer and go to court and hope to challenge the order, a slow, expensive, and daunting process
Those existing systems are already frustrating for the targeted creators and users, but under DEFEND IP a whole class of people doing protected speech will find themselves deplatformed because of the actions of others
This bill is not a defense of creativity or creators. It is a way to reshape the internet by building a vast new infrastructure of censorship. Congress should put aside DEFEND IP and the failed idea of site-blocking laws, for good.
Congress Has Another Site-Blocking Bill, And This One Targets VPNs
Congress is taking another run at site-blocking, a deeply flawed concept that would undermine basic internet infrastructure. Rep. Darrell Issa (R-CA) has introduced the American Copyright Protection Act (ACPA), H.R. 10364, a bill that would give copyright owners a new legal tool to block Americans’ access to foreign websites accused of copyright infringement.
The basic idea is all too familiar, and it’s still dangerous. A copyright owner first asks a court to label a foreign website a “foreign piracy site.” Once that happens, the copyright owner could seek orders requiring internet service providers, DNS providers, and—new and explicit in this bill—VPN providers to take “commercially reasonable steps” to stop their users in the United States from accessing those sites. The decision to label a website as a “foreign piracy site” can happen without the accused site even showing up in court to defend itself.
ACPA Goes Further Than Other Site-Blocking ProposalsIn some ways, the ACPA is even worse than a site-blocking legislation introduced last year, the Foreign Anti-Digital Piracy Act (FADPA), which EFF also opposed. That bill at least excluded companies that provide only VPN services, as well as providers that offer DNS resolution exclusively through encrypted DNS protocols. The ACPA drops those protections. In fact, the bill explicitly includes VPNs among the service providers that can be ordered to block access to a website.
The bill also broadens the definition of a “piracy site.” Last year’s site blocking bill covered sites with “no commercially significant purpose or use” other than infringement. ACPA changes that to sites with “only limited commercially significant purpose or use” beyond infringement. In other words, under ACPA, even a website with legitimate commerce going on could still be labeled a “foreign piracy site” and ultimately blocked for all Americans.
Better Process Still Doesn’t Fix The ProblemThe ACPA includes some procedural protections, such as requiring service providers that could be subject to a blocking order to receive legal notice and an opportunity to respond. The bill also requires courts to consider the potential harm to other websites and internet users before ordering intermediaries to block websites. It further requires the copyright owner to post a bond, in an amount determined by the court, sufficient to cover the costs and damages incurred by any service provider found to have been wrongfully enjoined. The bill also provides a mechanism for operators or users of third-party online services affected by erroneous blocking to seek compensation after the fact in certain circumstances. Finally, a site operator can ask a court to rescind its designation as a “foreign piracy site.”
These safeguards are significant and positive changes, but they don’t solve the basic, and severe, due process problem. The initial decision to label a website a “foreign piracy site” can still be made without the site operator appearing to defend itself. The court can appoint a “special master,” which is an independent expert who helps the judge evaluate evidence, to review the copyright owner’s case—but that step is not required. In any case, a special master is not a lawyer who actually represents the accused website, nor the users whose access to information and speech may be affected.
We know what site-blocking looks like when it’s put into practice. Supporters of site-blocking like to point to its use in other countries. But what we’re seeing in other countries is serious collateral damage to lawful websites. In Italy, 510 benign, non-streaming websites, including a Catholic convent and a telehealth platform, were blocked by the country’s “Piracy Shield” program. In Spain, a site-blocking system blocked more than 550,000 domains during soccer broadcasts, including sites belonging to Greenpeace and Harvard University.
Congress Should Reject Site-Blocking ProposalsMore than a decade ago, Congress abandoned SOPA and PIPA after internet users pushed back against site-blocking and other threats to the open internet. We shouldn't start building that infrastructure now.
ACPA adds some safeguards, but those don’t fundamentally change what Congress is being asked to create: a system for blocking Americans’ access to entire websites at the request of copyright owners. By explicitly bringing VPNs into that system, the bill also reaches into basic tools that people use to access the internet safely and privately. Adding somewhat better procedures to a bad idea doesn’t turn it into a good idea.
Victory! Court Rejects Government Effort to Dismiss Social Media Surveillance Lawsuit
NEW YORK — A lawsuit filed by three labor unions against the Departments of State and Homeland Security for their viewpoint-based surveillance and suppression of protected expression online can move forward, a federal judge ruled yesterday.
On October 1, 2026, Judge Alvin K. Hellerstein of the U.S. District Court for the Southern District of New York rejected the government’s motion to dismiss the lawsuit. The case was filed in October 2025 on behalf of the United Automobile Workers (UAW), Communications Workers of America (CWA), and American Federation of Teachers (AFT). The Electronic Frontier Foundation (EFF), Muslim Advocates (MA), and the Media Freedom & Information Access Clinic (MFIA) represent the labor unions.
This decision is a victory: The Court held that claims that the government’s social media surveillance program is harming the unions’ members, as well as hampering the ability of the unions to associate with their members and potential members, can move forward.
The Court ruled that: "This threat of adverse immigration consequences, under a government whose harsh immigration crackdowns has been heavily publicized and reported on, is certainly enough to 'deter a person of ordinary firmness from the exercise of First Amendment rights.' It is objectively reasonable that noncitizens would limit their expression of disfavored viewpoints under the [Challenged Surveillance Program] given the credible threat of adverse immigration action from the Government."
"The freedom of Plaintiffs' members to speak, associate, and appear publicly is not incidental to union work, but rather is the mechanism through which unions recruit, organize, communicate, and bargain," the Court further explained. "A program alleged to silence members and drive them from the unions' rolls therefore strikes at the unions' representational function itself, which is the 'grounds that bring [their] membership together.'"
Since taking power, the Trump administration has created a mass surveillance program to monitor constitutionally protected speech by noncitizens lawfully present in the U.S. Using AI and other automated technologies, the program surveils the social media accounts of visa and green card holders with the goal of identifying and punishing those who express viewpoints the government disfavors. The surveillance program has been paired with a public intimidation campaign—silencing not just noncitizens with immigration status, but also the families, coworkers, and friends with whom their lives are integrated.
In October 2025, UAW, CWA, and AFT sued the Departments of State and Homeland Security, alleging that this viewpoint-based surveillance program violates the First Amendment and the Administrative Procedure Act.
"No one should have to fear government surveillance or retaliation against their immigration status for expressing their views or participating in their union. We're pleased the Court has allowed this challenge to move forward and will continue fighting to protect the rights of everyone to speak, organize, and advocate without fear," said UAW President Shawn Fain.
"This is a victory for working people, for the labor movement, and for our democracy," said CWA President Claude Cummings Jr. "Our very freedom is under attack by the Trump administration's online surveillance program, and today's decision is a critical first step toward affirming our freedom to speak, to protest, to organize without fear of government retaliation. These essential freedoms underpin our union rights to join together and fight to improve our working conditions. CWA is a fighting union, and our members remain ready to stand together to protect our rights and our freedoms."
"Today’s decision is a critical step toward vindicating our Constitutional right to freedom of speech and rejecting the Trump Administration’s cynical attempts to criminalize and punish those who disagree with them," said AFT President Randi Weingarten. "Government surveillance to monitor the 'opposition' is a tool of dictators that erodes the democratic principles this country was founded on. We will continue to remain vigilant in defending our 250-year-old rights—not just for our members, but for all Americans."
"Our plaintiff-unions have members that have wholly changed the way they interact with social media—including limiting their engagement with union content—because of the government's social media surveillance program," said EFF Senior Staff Attorney Lisa Femia. "Many have stopped posting online together, and have even stopped engaging in offline activities, for fear of being scrutinized or targeted related to immigration benefits. We are pleased that the Court has agreed to let the case proceed, and allow unions and their members to seek justice for infringement of their rights."
"Today’s ruling is an important step forward in holding the government accountable for its ever-expansive online surveillance program that silenced non-citizens, stoking fear that exercise of their protected First Amendment rights could result in unfavorable treatment on their immigration applications or worse." said Sadaf Hasan, Staff Attorney at Muslim Advocates. "We will keep fighting until all non-citizens are able to freely associate, organize, and speak out without the looming threat of visa revocation and immigration enforcement simply because the government dislikes their views."
"Defendants' attempt to evade accountability on specious jurisdictional grounds was rightly rejected by the Court," said Nick Jones, a student in the Media Freedom & Information Access Clinic. "We are excited to see the case now proceed to the merits, where we expect to prevail as well.”
For the ruling: https://www.eff.org/document/uaw-v-dos-opinion-order-denying-motion-dismiss
For more about the litigation: https://eff.org/cases/united-auto-workers-v-us-department-state
Contacts:
Electronic Frontier Foundation: press@eff.org
Muslim Advocates: melissa@muslimadvocates.org
Ola Bini Ordered to Leave Ecuador Under Obscure Accusations
In a new blow to Ola Bini’s legal guarantees, Ecuadorean authorities retained the free software developer and security expert yesterday in Quito and ordered his immediate deportation from the country. He is barred from returning to Ecuador for 10 years.
According to information released by his lawyer, Bini was intercepted by a car with four people who identified themselves as immigration agents. He was then taken to an immigration office without further information or a formal order from a competent authority. There, officials told Bini that his visa had been revoked but didn’t show any supporting document.
Bini's defense filed a habeas corpus to safeguard his freedom and prevent his deportation. Yet, Ecuadorian authorities affirmed that the developer represents a threat or risk to public security and the state structure, and must leave the country. The ground for deportation is a secret report which allegedly asserts that Bini committed acts against the security of Ecuador. The defense could not access its contents.
The deportation hearing started yesterday at 5pm Quito time. Human rights organizations tried to attend the hearing but were denied entry. The hearing was suspended but later reinstalled establishing his immediate deportation. Ola Bini was relocated to Quito's airport and must stay there until fly back to Sweden.
The case that led to Bini's unfounded criminal conviction has expired (the statute of limitations ran out) and the court had already formally lifted all precautionary measures against him. Yesterday's events open a new chapter in the nefarious persecution of Ola Bini by Ecuadorean authorities.
Since Bini’s arbitrary arrest in 2019, EFF has reported about his criminal prosecution fraught with misconceptions and rights violations. The script of what happened yesterday follows the same patterns we saw in the entire case, from its outset with unjustified allegations that Bini was a national security risk. The Observation Mission of Ola Bini’s case, joined by EFF and other digital and human rights organizations, has published reports and raised international awarenness about the perils of this case to the protection of rights online and the beneficial work of security experts.
In a case surrounded by political interests, Ola Bini’s unanimous acquittal by the lower court in 2023 was overturned after the prosecution’s appeal. The majority of the appeals court convicted Bini for attempted unauthorized access of a telecommunications system without actual evidence to corroborate the accusation claims.
Now, once again we must sound the alarm. Ecuadorean authorities must explain the accusations against the security expert. We will remain vigilant and ensure that at least this time his rights are respected.
We Demand More Information on How Marin Cops Illegally Shared Flock ALPR Data
The Marin County Sheriff’s Office is the latest California law enforcement agency to get caught sharing automated license plate reader (ALPR) data from their Flock Safety system with out-of-state and federal agencies. EFF and the ACLU of Northern California are calling them out for this direct violation of California law, which has put every driver in the county at risk and is especially dangerous for immigrants, abortion seekers, and other targets of the federal government.
Today, we sent the Marin County Sheriff’s Office (MCSO) a demand letter and request for records under the California Public Records Act following the Point Reyes Light’s recent report that MCSO provided non-California agencies access to its ALPR database. This directly violates California law and the terms of the 2022 Settlement Agreement in our case Lagleva v. Marin County Sheriff.
ALPRs are cameras that capture images of vehicles and upload their location to a searchable, shareable database. They are a mass surveillance technology that collects data indiscriminately on every vehicle on the road.
Sharing ALPR data with out-of-state or federal agencies—for any reason—violates California law (SB 34). If this data is shared for the purpose of assisting with immigration enforcement, agencies violate an additional California law (SB 54).
But network audit logs obtained by Point Reyes Light show that during the final months of 2024, Marin County Sheriff’s Office shared ALPR data with multiple out-of-state and federal agencies, including 254,131 times in November 2024 alone. Many of these searches were conducted by law enforcement in states that impose severe restrictions on reproductive care and have a history of assisting ICE, including Alabama, Indiana, Kentucky, Florida, and Texas.
This sharing violated state law and “exposed sensitive driver location information to misuse by the federal government and by states that lack California’s robust privacy protections,” the letter explains.
This is not the first time MCSO has shared Marin County ALPR information with federal and out-of-state agencies in violation of California law.
Back in 2021, on behalf of community activists, EFF and ACLU sued the Marin County Sheriff for illegally sharing millions of local drivers’ license plate numbers and location data with hundreds of federal and out-of-state agencies, including ICE and Border Patrol.
The parties eventually reached a settlement, under which the Sheriff agreed to stop sharing license plate and location information with agencies outside of California to comply with state laws SB 34 and SB 54.
“MCSO’s November 2024 audit report shows that your office has violated not only SB 34, but the terms of the Lagleva Settlement Agreement as well,” the letter explains.
EFF and ACLU are urging MCSO to launch a thorough audit of its ALPR database, institute new protocols for compliance, and assess penalties for any employee found to be sharing ALPR information out of state.
“While your office claims that it took deliberate steps to disable nationwide data-access capabilities and ensure your system operated within strict privacy safeguards, you have not explained how outside agencies nonetheless obtained access, how you plan to prevent future violations of SB 34 and the Lagleva Settlement Agreement, or why you did not take steps to inform the public and the Marin County Inspector General once you learned about the breach,” the letter explains.
As we’ve demonstrated over and over again, many California agencies continue to ignore these laws, exposing sensitive location information to misuse and putting entire communities at risk. As federal agencies continue to carry out violent ICE raids, and many states enforce harsh, draconian restrictions on abortion, ALPR technology is already being used to target and surveil immigrants and abortion seekers. These incidents have made it clear that having ALPR programs are incompatible with the protection of residents. California agencies, including Marin County Sheriff’s Office, have an obligation to protect the rights of Californians, even when those rights are not recognized by other states or the federal government.
See the full letter here: https://www.eff.org/document/20261001-letter-aclu-norcal-and-eff-marin-sheriff
Challengers Approach: Third Party App Stores Arrive to Google Play
If you are an Android user, you may have noticed it already: Google has begun allowing rival, third-party app stores to be distributed through the Google Play Store. And if you are a developer, you may have noticed new options for billing and distributing your apps.
For years, Epic Games, maker of games such as Fortnite, has been suing Google, alleging violations of antitrust law. Specifically at issue were Google's restrictions on the distribution of alternate app stores through the Play Store, restrictions on app developers who have little practical choice but to distribute their apps through the Play Store, and Google’s rules governing in-app payments and the fees associated with them.
Epic’s challenge ultimately resulted in a court order requiring significant changes to Google’s practices. Among other changes, rival, third-party Android app stores are now allowed to access the Play Store’s catalog and to be distributed through the Google Play Store. Developers also have greater freedom to direct users to alternative payment and distribution options.
These changes give users and developers more choices and create new opportunities for competition in the Android ecosystem, breaking the power Google once had over many facets of the app ecosystem. This is a win for competition and antitrust enforcement. But the benefits can extend beyond competition itself—more meaningful choice can also create opportunities for greater freedom of online expression, privacy, and security.
With alternate app stores able to compete for Android users, Google no longer has the first and last say on what apps can reach users and on what terms. Developers have more options for reaching their audiences, rather than having a single company’s rules determine the terms of access.
More importantly, Android users are no longer trapped in an arrangement of feudal security with Google, where users must depend on the goodwill of a monopolist to protect them and guarantee their safety. If Google does not adequately protect their data or security, Android users can now switch to a competitor that does a better job. And if that competitor fails them, they can choose another.
Competition in the app store market therefore means competition not only over which apps are offered, the user experience, and developer fees, but also over privacy and security. Users and developers gain something fundamental in the process: the ability to choose.
As we’ve previously written, antitrust has never been just about prices—it’s also about power. It is about who gets to control and shape the future of the internet. A world in which a handful of dominant platforms can dictate how users access apps or programs, how developers reach them, and what rules govern those interactions is one in which users have fewer meaningful choices. Without Epic’s successful antitrust challenge and the changes that followed, users would have remained in a world of feudal security, where they would have been left begging their feudal tech lord for more.
The arrival of competitor app stores on Google Play does not solve every problem with the Android ecosystem. But it opens the door to something that dominant platforms have spent years trying to keep out: meaningful competition. And each new competitor gives users another opportunity to choose something better.
Related Cases: Epic Games v. GoogleCourt Agrees with EFF: Utah’s VPN Law Demands a Technical Impossibility
When state lawmakers attempt to rewrite how the internet works, users rely on courts to recognize that laws can’t make technical impossibilities a reality. That’s why we were happy to see that a court has blocked Utah’s attempt to outlaw the privacy protections of Virtual Private Networks (VPNs).
In a win for digital rights, a federal judge has issued a preliminary injunction blocking Utah’s SB 73, the state’s draconian anti-VPN age verification law. The decision comes as EFF submitted our comments to the Utah Department of Commerce, detailing how forcing platforms to detect and block privacy-preserving tools undermines user privacy and security worldwide while demanding the impossible.
What SB 73 DoesSigned into law earlier this year, SB 73 attempted to regulate adult websites by requiring them to block VPN users or to identify the physical location of visitors using them or similar tools that mask their network traffic. It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks. This made Utah, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates.
The Utah federal court halted enforcement of the law's VPN provisions last week, ruling that the law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.
SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah. The law’s “actual-location provision in practice requires an entity to perform age verification services for every user visiting its site from any location because the entity would violate the law if even one of those users happened to be obfuscating,” the court wrote. The court essentially ruled that Utah has less-burdensome ways to prevent Utah minors from accessing adult websites than requiring all users in the world to comply with SB 73.
Aylo’s lawsuit does not challenge SB 73’s provision prohibiting the websites covered by the law from sharing information about VPNs.
The Legal ChallengeThis court order follows months of legal maneuvering.
Initially set to go into effect in May 2026, SB 73 sparked an immediate constitutional challenge from Aylo, the parent company of major online adult platforms like Pornhub. In response to the lawsuit, Utah and Aylo initially agreed that the state would pause enforcement while the court considered the preliminary injunction request or until administrative rules setting specific compliance terms were finalized. Those proposed compliance rules (R152-78B, see Utah State Bulletin, page 6) were published by the Utah Department of Commerce’s Division of Consumer Protection on September 1st, and EFF submitted formal comments to the Department in opposition. According to the notice, the proposed rules could be effective as soon as October 8, 2026. However, Judge Barlow’s decision means that it cannot be enforced pending further action by the court.
The RulingEFF welcomes Judge Barlow’s ruling, which recognizes the fundamental disconnect between state legislation of the internet and how technology works. In his ruling, Judge Barlow noted that the statute requires a technical impossibility on pain of legal liability. “Aylo is correct that the statute, as amended, now essentially imposes strict liability for entities like it when it comes to determining the location of its websites’ users.”
The court recognized that the problem is that SB 73 “requires entities like Aylo to geolocate its website users with perfection to avoid liability.” But, at the same time, the court acknowledged “that geolocation perfection is not presently possible.”
EFF explained this technical impossibility in our comment to the Department of Commerce. VPNs protect user privacy by routing web traffic through intermediary servers. Because destination websites only see the IP address of the VPN server, they have no reliable mechanism to tell whether a connection originates from Salt Lake City, Seattle, or Shanghai. So, under Utah's current statutory framework, platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely. Judge Barlow agreed, asserting:
Because the law requires perfection in the absence of perfect geolocation tools, Aylo would need to verify those 28 million users—whether located in Salt Lake City, Boston, New Orleans, Anchorage, or Honolulu—to ensure compliance and avoid liability.
The RulemakingThe administrative rules drafted by the state compelled commercial entities to implement "commercially reasonable geolocation obfuscation detection systems", which is a directive, we argue, that demands a technical impossibility.
In our submission to the Utah Department of Commerce, EFF also detailed how these rules force an invasive data collection regime onto internet users everywhere. So, in response to internet users trying to avoid invasive data collection required by age-verification requirements, SB 73 requires even greater surveillance of internet users’ online activities. The Department’s suggested detection heuristics (like monitoring connection latency or device time zones) are notoriously unreliable and easily skewed by normal network conditions. This active surveillance inevitably leads to widespread misclassification, unwarranted access blocks, and severe impacts on users’ privacy far beyond Utah's borders.
You can read EFF’s full comments to the Department of Commerce here.
What Now?As we’ve said time and time again: the internet will always route around censorship.
Mandating invasive tracking and punishing the use of essential security tools turns genuine privacy concerns into mere compliance theater and requires more state-mandated surveillance of internet users who rely on VPNs. As is the case in heavily censored regions, VPN services and obfuscation tools will simply adapt, making this framework fundamentally unsustainable.
As we’ve said time and time again: the internet will always route around censorship.
While Utah legislators have indicated they may attempt to revise the law during the next legislative session, the court's preliminary injunction sets an important precedent: state lawmakers should not weaponize age verification to force dragnet tracking or undermine essential security tools.
As other states consider similar anti-VPN proposals, EFF will continue pushing back against these technically impossible mandates and defending users’ privacy and anonymity. Thus, we urge legislators and regulators to reject anti-privacy rules, prioritize real user security, and safeguard constitutional protections for all users.
Happy Opt Out October! Let’s Find Real Alternatives to the Tech Giants
Over the years, the major tech companies have found all sorts of ways to embed themselves into our lives. We often use their software, their AI tools, their social media, and their operating systems by default without even thinking about potential alternatives. It’s time to rethink that relationship.
Last year, we created Opt Out October to help remind ourselves of the variety of ways we can take back control of our data through small steps inside apps, operating systems, and other various forms. This year, we highlight the idea that sometimes the best way to control your data is to leave a platform, app, or operating system altogether.
To do so, we’ve created a hub of resources sharing ways to find new software that isn’t made by the tech giants, take advantage of the growing universe of new social media options, install a whole new operating system, and better control how various popular tools and software use your data for AI training.
As an incentive, we’ve made merit badges like the one below to help you track your own wins and share them with others. Complete any of these tasks and let the world know by sharing that accomplishment on social media or changing your profile image! Better, more privacy-respecting, and less-enshittified tools are out there. We just have to find and use them.
Head over to our Opt Out October landing page and start taking the first steps to regaining control of the tools and software you use.
Victory! California Appeals Court Refuses to Revive Surveillance Tech CEO’s Meritless Lawsuit Against Journalist
When the rich and powerful try to use the court to silence negative reporting about themselves, it’s worth calling out that behavior for what it is: an attack on free speech. This is why EFF is happy to stand up for reporters who find themselves in that situation.
The California Court of Appeals upheld a lower court’s decision to strike a former Premise Data CEO’s meritless lawsuit against a journalist who exposed the CEO’s secret arrest for felony domestic violence. Jack Poulson, the writer and publisher of All Source Intelligence, reported details from the San Francisco Police Department’s report of the arrest and posted a copy of the report after receiving the document from a confidential source. Poulson later learned the arrest record had been sealed. The CEO, Maury Blackman, sued Poulson, Substack, AWS, and another organization for damages to try and force the removal of Poulson’s reporting from the internet.
The trial court tossed the entire case under California’s anti-SLAPP statute—SLAPP stands for “strategic lawsuit against public participation” and describes cases where the goal isn’t vindication in court so much as it is costing someone time, money, and peace of mind fighting the lawsuit. To fight SLAPP cases, states like California have passed anti-SLAPP laws, which are invaluable tools for protecting the First Amendment. California’s law provides an avenue for early dismissals of these baseless lawsuits, which curtails their intended effect on the target. Blackman appealed the court’s decision, arguing that a court order sealing the arrest overrides Poulson’s right to report the news.
The Court of Appeals correctly rejected Blackman’s appeal and affirmed the decision to throw out the case. The court held that the First Amendment protects Poulson’s publications. As the court explained in its decision, “the First Amendment protects the lawfully obtained truthful publication of the information at issue absent ‘a need to further a state interest of the highest order,’” a standard that Blackman’s privacy interests do not satisfy. The Court also found that Poulson, as the publisher of the All Source Intelligence newsletter, was protected by California’s Shield Law, relying on precedent established by EFF in 2006. The Court also affirmed that Substack and the other website, which had merely temporarily hosted a copy of the arrest record, were immunized from liability by Section 230.
This decision is a win for free speech, for Jack Poulson, and for everybody.
Related Cases: Blackman v. Substack, et al.📱 Hey Siri, How Do I Limit AI Data Access? | EFFector 38.17
With the launch of iOS 27, Apple is rolling out a variety of new AI features to its familiar voice assistant, Siri. But how are AI tools like these handling our data? In our latest EFFector newsletter, we're talking about the privacy complications of AI phone features.
For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers drones and our right to record the law enforcement, video doorbell footage privacy, and how to limit what data Apple's new Siri AI can access.
Prefer to listen in? EFFector is now available on all major podcast platforms. This time we're asking EFF's Thorin Klosowski about the difference between AI phone features that are computed on-device and ones that are computed on external servers—and what that means for data protection. You can find the episode and subscribe on your podcast platform of choice:
%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2Ff5abca72-7d82-4e94-9c0b-0d9f991891f0%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E
Privacy info.
This embed will serve content from simplecast.com
Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!
While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards
San Francisco's decision to retain its use of Automated License Plate Reader (ALPR) surveillance cameras belies what we know about this spying technology tool: it endangers residents and threatens the privacy and civil liberties of our community. Based on what's in the city's press release and announcement, this policy will do nothing to stop actual harms.
We know innocent drivers will be stopped and menaced by officers because of erroneous matches. We know officers use Flock to stalk potential and past romantic partners. Data will be accessed by Immigration and Customs Enforcement (ICE) and used to deport immigrants. Promising greater penalties for such abuse will not end this. These are not isolated mistakes that another policy can fix. They are consequences of building a system that records everyone’s movements and makes them searchable by police. This is also not unique to a single vendor. From Flock Safety to Motorola to Axon—San Francisco must end its use of ALPRs.
We ultimately cannot rely on new protocols from city officials, and the City’s new policy is woefully inadequate. There is no warrant requirement to search stored ALPR data. An incident or computer-aided dispatch (CAD) number is not judicial authorization. Without a warrant requirement, officers can search stored location data without showing probable cause to a judge, and will. Without judicial control, officers will continue to search the data for abusive reasons. But a warrant requirement alone would not justify retaining the ALPR network: the community is demanding an end to the collection itself.
Additionally, the announced policies include no deadline to delete ALPR data, there is only a 30-day deadline to move data from the vendor’s servers to the city’s servers. City officials must understand that moving data is not deleting it. Whether Flock or SFPD stores the data, it remains a permanent record of where people drive, worship, work, organize, seek care, and spend time with others. Thus, the best practice is deletion. New Hampshire requires deletion in three minutes, and Flock itself has reduced the default retention time to seven days. San Francisco can and should do better.
Lastly, while transparency and documentation are important concepts, better audit logs are not the answer. They can expose abuse only after a search has occurred. They cannot undo the disclosure of someone’s movements or justify collecting everyone’s location data in the first place; especially when we are talking about people’s lives and civil liberties. The city's announced policy does not even require officers to state, in their own words, why they are searching the stored ALPR data—an accountability rule that has exposed abusive searches across the country.
San Francisco is behind many communities that have considered the tradeoffs of ALPR surveillance and made the right choice by ending their contracts. San Francisco must do the same.
Privacy’s Defenders Podcast: Cowboys, Cypherpunks and Visionaries
People are increasingly concerned about the ways in which mass surveillance is tracking our every move: from Flock license plate readers to face recognition to creepy ads that – based on what we see and do online – seem to know everything we’re thinking and planning. It didn’t have to be this way, and since the early days of the internet, a dedicated band of activists, lawyers and technologists have fought for a better, more secure and private digital future – a future that’s still attainable.
Cindy Cohn, who just finished a 26-year run with the Electronic Frontier Foundation including 11 years as its executive director, has lived this fight. She says privacy isn’t just about secrecy: It's ultimately about power – who has it, and who has the ability to protect themselves from it.
Welcome to the first episode of “Privacy’s Defenders,” a podcast about the people – lawyers, journalists, hackers, and others – who’ve fought to secure your digital liberties since before most people even knew what the internet was.
%3Ciframe%20height%3D%2252px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F2f955342-7675-4c8c-bb40-fa364d9a569d%3Fdark%3Dtrue%26amp%3Bcolor%3D000000%22%20allow%3D%22autoplay%22%3E%C2%A0%3C%2Fiframe%3E
Privacy info.
This embed will serve content from simplecast.com
(You can also find this episode on the Internet Archive and on YouTube.)
In this episode, Cindy talks with EFF cofounder John Gilmore about how he – an early employee at Sun Microsystems – came together with Lotus Development cofounder Mitch Kapor and cattle rancher, philosopher and Grateful Dead lyricist John Perry Barlow to create EFF as a bulwark against government investigation and prosecution of early internet users.
It’s a story of the Secret Service’s “Operation Sundevil,” jet-setting tech titans, tie-dyed cypherpunks, and a fateful house party in San Francisco’s Haight-Ashbury district amid the earliest days of online communications, setting the stage for the battles that created the internet as we know it and issues we still grapple with today.
The “Privacy’s Defenders” podcast is a follow-up to Cindy’s book, “Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance,” bringing to life pivotal moments in the voices of those who fought for your rights. Sales of “Privacy’s Defender” benefit EFF, so pick up your copy today!
Joanne Elgart Jennings co-produced and created this podcast.
Jarod Sport co-produced, mixed, and mastered it.
Corinne Ruff is our story editor.
We had additional help from Rachel Estabrook and Alison Broverman.
The original music was composed and performed by Nat Keefe of Hot Buttered Rum with Ben Andrews on the fiddle.
And other archival sound came from the Internet Archive's amazing collection, including the snippet of the Grateful Dead song “Cassidy” that John Perry Barlow co-wrote.
EFF to San Francisco Police: Drones are Powerful Surveillance Tools That Require a Robust Policy
The San Francisco Police Department (SFPD) began regularly deploying drones two years ago and has since expanded their use in a way that has outpaced its documented policy and evaded existing local and state oversight of these devices.
The department has a new proposed policy, which continues to be grossly inadequate in protecting privacy and civil liberties. At best, the draft policy continues the SFPD’s pattern of putting vague guardrails on a powerful surveillance tool, but at worst, if implemented, the policy could effectively usher in sweeping, non-targeted, and unspecified general surveillance over the city with few guardrails.
EFF has repeatedly opposed the unaccountable development of the SFPD’s drone program and recently sent a comment to the Police Commission, the local civilian oversight body, about the SFPD’s new proposed policy.
The SFPD has been sidestepping oversight of its drones since 2024. In March 2024, San Francisco voters approved a heavily-funded, billionaire-backed measure, Proposition E, which sought to expand police access to surveillance technology. Among its impacts, Prop E removed drones from oversight required by the 2019 Surveillance Technology Ordinance. Nonetheless, in its haste to purchase drones after Prop E passed, the SFPD knowingly violated California’s AB 481, a state statute requiring law enforcement agencies to get approval from their local elected governing body before purchasing military equipment, including drones. Eventually the SFPD sought retroactive approval from the Board of Supervisors and, soon after, announced that it would be launching a drone-as-first-responder (DFR) program.
Now, San Francisco finally has an opportunity to update the SFPD’s guidance in a way that won’t quickly become stale, as has happened while the SFPD steadily increases the purposes for drone use. Though drones were initially identified as tools to use for specific actions such as vehicle pursuits and active criminal investigations, within a year, the SFPD expanded use cases to include patrol, i.e. unrelated to a specific incident. Along with this mission creep, the SFPD has also steadily and exponentially increased the number of drone flights, from roughly 350 deployments in 2024, to over 1,100 from January to August 2025, to over 3,500 in just the first five months of 2026.
The original draft of an updated policy brought by the SFPD to the local Police Commission, a civilian oversight body, earlier this month provided limited details and proposed allowing police to treat drone flights as an extension of their patrol abilities, paving the way for general surveillance, including of First Amendment-protected activity. The proposal received significant community pushback, and the San Francisco Public Defender’s Office authored a letter describing the policy’s shortcomings. That letter was signed by over a dozen local, state, and national groups, including EFF.
Based on these concerns, the Police Commission deferred taking action until the SFPD addressed them. The SFPD then revised its proposed policy, but this, too, falls short of providing practical guidance to officers and protecting civil liberties, as the Public Defender’s Office identified in a follow-up letter signed by over 40 organizations, including EFF.
EFF’s additional comment to the Police Commission, in part, calls out the incredible gap in oversight of these ballooning drone flights and the immense data collection they facilitate:
The revised policy states that “[unmanned aerial vehicles] may be used as an asset in any situation in which a member may be deployed for a public safety response or when a member onviews criminal activity” but fails to define what is meant by a “public safety response.” The revised policy also provides a definition of “Drone as First Responders,” but it fails to provide any more detail about appropriate DFR deployment. Without appropriate safeguards around deployment and use, drones could be deployed to every call for service, even in situations that are ultimately deemed nonincidents, collecting data along the way that is then stored for 30 days. This type of general patrol could effectively become general surveillance, which SFPD acknowledges is an inappropriate use of their drones and yet is still possible under the vague terms of the current DGO.
The Police Commission is set to consider the matter on October 14. You can read EFF’s full comment here.
EFF to Court: Trump's Use of Truth Social's Pay-To-See-Posts-First Scheme Violates Americans' 1st Amendment Equal Access Rights
EFF legal intern Simar Kaur also contributed to this article.
Americans’ First Amendment right to equal access to official government statements is violated by the Trump administration’s use of Truth Social’s preferential treatment scheme, which blocks people who won’t pay Trump’s company up to $100,000 a month early access to government news, EFF told a federal court.
The First Amendment guarantees that members of the public have equal access to public officials’ public comments, we reminded the court.
EFF filed an amicus brief in support of a motion for a preliminary injunction in the lawsuit filed by The Intercept Media and the Freedom of the Press Foundation against President Trump and other administration officials. The lawsuit challenges their use of Truth Social as their primary social media method of making official announcements when that platform provides people who pay a fee for early access to such posts.
Trump uses his Truth Social account as his primary means of communicating with the public, including to announce military operations and ceasefires, foreign and domestic policy, and the removal and appointment of heads of federal agencies. Earlier in the year, Trump Media, which owns Truth Social, announced “Truth API,” a service that provides investors early access to “market-moving” messages from the president and other high-ranking officials for a fee of up to $100,000 per month.
The plaintiffs, the Freedom of the Press Foundation and The Intercept, contend that the president and other officials’ preferred use of Truth Social with this service violates the First and Fifth Amendments of the Constitution. The plaintiffs are asking the court to immediately prevent the president from posting on Truth Social in a manner that allows him to profit from selling early access to government information.
EFF’s amicus makes two main points.
First, the brief establishes that social media is pervasively used by government officials and agencies as a medium for official communication with the public, including to disseminate critical public safety information and make official announcements.
Second, the brief explains that the challenged practice violates the First Amendment, which guarantees a right to access public officials’ public comments on equal terms with other members of the press and public. Giving some people preferential access must at a minimum be reasonably justified to satisfy First Amendment scrutiny, a test the administration does not meet.
Lining the president and his company's pockets is not a legitimate government interest for restricting timely access to the government's statements. Further, the fact that the public could ultimately access the information from other, less direct channels does not eliminate the need for First Amendment scrutiny; mere delays in timely access still trigger First Amendment scrutiny.
EFF has been advancing the First Amendment right of equal access to government’s public social media posts since at least 2018. We’ve argued that the right of equal access, which is well established in offline contexts, must apply to official government social media posts as well. This case presents an excellent opportunity for a court to directly adopt that position.
DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising
Online sports betting company DraftKings is using AI to target customers who are most likely to place losing bets and respond to gambling promotions. This kind of targeting is a form of online behavioral advertising, which is when companies personalize the ads they show you based on the data they’ve collected about you. The more data a company has, the more personalized the ad can be. While DraftKings is using AI to supercharge the harmful effects of online behavioral advertising, EFF has long argued that all behavioral advertising should be banned.
According to the New York Times, DraftKings is using its customers’ betting records to train a machine learning model to find losing gamblers. Once found, DraftKings sends these customers targeted advertising designed to lure them back to the site to place more bets—bets that DraftKings thinks will be losing ones. DraftKings has a business incentive to keep losing gamblers coming back to their site, because these are the users actually making DraftKings money. Unfortunately, those considered “problem gamblers” (people who repeatedly gamble despite harm to themselves, their finances, and their relationships) are highly likely to be targeted by this model. By re-engaging these individuals through targeted promotions aimed at keeping them on the platform, DraftKings is capitalizing on their vulnerability for profit instead of mitigating their risk.
Predatory online behavioral advertising isn’t new, but companies’ use of AI to process data and target customers has magnified its harms. Online behavioral advertising incentivizes the collection of vast quantities of data to power ad tech. Adding AI into the mix means that even more data is collected to train and refine models. Because AI operates as a black box, the humans building the models can rarely predict which data points are the most useful to the AI, driving them to continuously collect more data. AI also allows companies to process enormous data sets much faster, and, as a result, supercharges the harms of online behavioral advertising.
A direct consequence of online behavioral advertising is that it provides the data the surveillance industry needs to run. Data collected for targeted placement of ads is being sold to insurance companies, banks, and state and federal government law enforcement agencies such as CBP. ICE is also taking an interest in the data fueling ad tech: earlier this year, ICE published a Request for Information “seeking information to better understand how the industry’s commercial Big Data and Ad Tech providers can directly support investigations activities.”
DraftKings seems to be using solely “first party data” to target their ads, meaning that they’re using only the data they collect directly from their users and are not buying any additional data from third parties to fuel their machine learning model. This highlights how policy solutions that only limit third-party data sharing and selling would not be enough to prevent these predatory advertisements. Rather, policymakers must ban online behavioral ads.
What DraftKings is doing with their targeted promotions is just one example of how online behavioral advertising causes real harm to real people. But there are ways to take back control over your own data: EFF offers resources such as our Surveillance Self Defense project, along with other tips for how you can protect yourself on mobile apps and on websites.
DraftKings’ use of AI to target losing gamblers illustrates how ad tech evolves and how companies find new ways to use our data against us. This is why EFF believes that all behavioral advertising should be banned. If companies can’t send personalized ads, they’ll have less incentive to collect the behavioral data powering them.
