In this article

Sign up for our newsletter

Share this article

I spent an embarrassing amount of time this week thinking about my driver's license. Not because I lost it: more than 150 million of them (including yours and mine, for all I know) just showed up for sale on the dark web after a breach at IDScan, the identity-verification vendor that bars, dispensaries, and event venues use to scan your ID at the door. The FBI is investigating. So is the Pentagon, because the Secretary of Defense's license reportedly turned up in the stolen data too.

It got me thinking about how much more of this we're about to sign up for.

California just signed 13 new child-safety bills for chatbots and social media, anchored by "Adam's Law," and the EU's leaked Kids Act draft would require every new social media account to pass age verification, keeping anyone under 15 out without a parent's approval. Arguably, both are good, overdue ideas. Both also mean handing more sensitive documents to more companies.

It’s not always the case that better security technology is the key to protecting sensitive data. It’s not like we can manage the proliferation of data if we just invent better locks. Humans are always going to be part of the process, and humans are easy to mislead. Another story this week features fintech Revolut, which just disclosed that a scammer posing as a government agency talked its way into customer passports and IDs.

So, what’s easier: endless vigilance or collecting a little less data?

Best,

Arlo

 

PSR Banner

Highlights From Osano

Events

Speaking Session: Take a CIPA This: What It Takes to Really Reduce Your CIPA Risk

Attending IAPP’s Privacy. Security. Risk. + AI Governance Global 2026 conference this year? Don’t miss Osano’s Amar Ramakrishnan and Husch Blackwell’s Anokhy Desai as they break down how to *really* reduce CIPA risk. Come say hi to the Osano team at booth #107! Learn more and register below.

Learn more

In Case You Missed It


Release Notes: September

What’s new in Osano this month? Check out our release notes to find out the latest.

Read more



Top Privacy Stories of the Week

California Signs Sweeping Child-Safety Law Package for Chatbots and Social Media

Governor Gavin Newsom signed 13 bills this week that California is billing as the nation's strongest child-safety rules for chatbots and social media. The centerpiece, "Adam's Law," requires companion-chatbot makers to build in crisis protocols, parental controls, and independent child-safety audits, the first mandate of its kind in the country. The package also bars addictive features like autoplay and algorithmic feeds for anyone under 16, and expands child exploitation statutes to cover AI-generated material. Most of the new requirements phase in over the coming months, with several enforcement deadlines landing in 2027.

Read more

150 Million Drivers' Licenses Exposed in IDScan Hack

Identity-verification company IDScan confirmed that hackers stole more than 150 million driver's licenses and other government ID numbers from its cloud systems. The confirmation came days after security journalist Brian Krebs found a dark web site that let anyone search the stolen records, photos included. IDScan's technology sits behind ID checks at bars, cannabis dispensaries, and entertainment venues across the U.S. and Canada. The FBI and the Pentagon, whose own defense secretary reportedly turned up in the data, are now investigating.

Read more

Leaked Draft Shows EU "Kids Act" Would Bar Under-15s From Social Media Without Parental OK

A leaked draft obtained by Euronews shows the European Commission preparing to bar children under 15 from opening social media, video-sharing, or AI chatbot accounts without a parent's approval. Kids under three would be locked out of these services entirely, and those three to 13 could use only child-friendly versions under adult supervision. Platforms like Meta and Google would have to verify every new account's age, using an EU-wide verification app or an equivalent national tool.

Read more

Social Engineering Hack Exposes 80 Million Revolut Customers’ Data

Fintech company Revolut confirmed that a scammer impersonating a government agency, using a legitimate-looking government email domain, tricked the company into handing over sensitive customer data. The exposed information may include passports, driver's licenses, birth dates, and identity-verification selfies. Revolut says a "limited" number of its more than 80 million customers were affected and that it has alerted law enforcement and regulators, though it hasn't said how many people were hit or which agency was impersonated.

Read more

Meta's Smart Glasses Have a Privacy Blind Spot: AI Camera Use Doesn't Trigger the Recording Light

Meta has defended its AI glasses by pointing to a small recording light, going so far as to disable the cameras on thousands of devices where users tried to cover or damage it. But Meta's own documentation shows that light doesn't turn on when someone uses the glasses' camera-based AI features, meaning the device can analyze a bystander's surroundings without giving them any visible signal at all.

Read more

Like What You See in the Privacy Insider newsletter?

There's more to explore:

đŸ› ïž The Osano Engineering Blog

Learn what we're building, why, and how! New posts released monthly here.

đŸ“± The Osano Subreddit

Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!

📖 The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands

The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.

If you’re interested in working at Osano, check out our Careers page! 

Get a demo of Osano today
Share this article