I spent an embarrassing amount of time this week thinking about my driver's license. Not because I lost it: more than 150 million of them (including yours and mine, for all I know) just showed up for sale on the dark web after a breach at IDScan, the identity-verification vendor that bars, dispensaries, and event venues use to scan your ID at the door. The FBI is investigating. So is the Pentagon, because the Secretary of Defense's license reportedly turned up in the stolen data too.
It got me thinking about how much more of this we're about to sign up for.
California just signed 13 new child-safety bills for chatbots and social media, anchored by "Adam's Law," and the EU's leaked Kids Act draft would require every new social media account to pass age verification, keeping anyone under 15 out without a parent's approval. Arguably, both are good, overdue ideas. Both also mean handing more sensitive documents to more companies.
Itâs not always the case that better security technology is the key to protecting sensitive data. Itâs not like we can manage the proliferation of data if we just invent better locks. Humans are always going to be part of the process, and humans are easy to mislead. Another story this week features fintech Revolut, which just disclosed that a scammer posing as a government agency talked its way into customer passports and IDs.
So, whatâs easier: endless vigilance or collecting a little less data?
Best,
Arlo
Highlights From Osano
Events
Speaking Session: Take a CIPA This: What It Takes to Really Reduce Your CIPA Risk
Attending IAPPâs Privacy. Security. Risk. + AI Governance Global 2026 conference this year? Donât miss Osanoâs Amar Ramakrishnan and Husch Blackwellâs Anokhy Desai as they break down how to *really* reduce CIPA risk. Come say hi to the Osano team at booth #107! Learn more and register below.
In Case You Missed ItâŠ
Release Notes: September
Whatâs new in Osano this month? Check out our release notes to find out the latest.
Top Privacy Stories of the Week
California Signs Sweeping Child-Safety Law Package for Chatbots and Social Media
Governor Gavin Newsom signed 13 bills this week that California is billing as the nation's strongest child-safety rules for chatbots and social media. The centerpiece, "Adam's Law," requires companion-chatbot makers to build in crisis protocols, parental controls, and independent child-safety audits, the first mandate of its kind in the country. The package also bars addictive features like autoplay and algorithmic feeds for anyone under 16, and expands child exploitation statutes to cover AI-generated material. Most of the new requirements phase in over the coming months, with several enforcement deadlines landing in 2027.
150 Million Drivers' Licenses Exposed in IDScan Hack
Identity-verification company IDScan confirmed that hackers stole more than 150 million driver's licenses and other government ID numbers from its cloud systems. The confirmation came days after security journalist Brian Krebs found a dark web site that let anyone search the stolen records, photos included. IDScan's technology sits behind ID checks at bars, cannabis dispensaries, and entertainment venues across the U.S. and Canada. The FBI and the Pentagon, whose own defense secretary reportedly turned up in the data, are now investigating.
Leaked Draft Shows EU "Kids Act" Would Bar Under-15s From Social Media Without Parental OK
A leaked draft obtained by Euronews shows the European Commission preparing to bar children under 15 from opening social media, video-sharing, or AI chatbot accounts without a parent's approval. Kids under three would be locked out of these services entirely, and those three to 13 could use only child-friendly versions under adult supervision. Platforms like Meta and Google would have to verify every new account's age, using an EU-wide verification app or an equivalent national tool.
Social Engineering Hack Exposes 80 Million Revolut Customersâ Data
Fintech company Revolut confirmed that a scammer impersonating a government agency, using a legitimate-looking government email domain, tricked the company into handing over sensitive customer data. The exposed information may include passports, driver's licenses, birth dates, and identity-verification selfies. Revolut says a "limited" number of its more than 80 million customers were affected and that it has alerted law enforcement and regulators, though it hasn't said how many people were hit or which agency was impersonated.
Meta's Smart Glasses Have a Privacy Blind Spot: AI Camera Use Doesn't Trigger the Recording Light
Meta has defended its AI glasses by pointing to a small recording light, going so far as to disable the cameras on thousands of devices where users tried to cover or damage it. But Meta's own documentation shows that light doesn't turn on when someone uses the glasses' camera-based AI features, meaning the device can analyze a bystander's surroundings without giving them any visible signal at all.
Like What You See in the Privacy Insider newsletter?
There's more to explore:
đ ïž The Osano Engineering Blog
Learn what we're building, why, and how! New posts released monthly here.
đ± The Osano Subreddit
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
đ The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If youâre interested in working at Osano, check out our Careers page!
Arlo Gilbert
Arlo Gilbert
Arlo Gilbert is the CIO & co-founder of Osano. A native of Austin, Texas, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
