Insight Tag Ruling, Singapore GenAI Rules & Minors' Privacy (08/02/2026)
- › A federal judge dismissed most claims against LinkedIn over its Insight Tag, holding the health marketplace consented to the data sharing as a party to the communication.
- › Singapore's PDPC finalized its generative AI guidelines, confirming organizations can lean on the publicly available exception to train on scraped personal data without consent.
- › Eight states passed social media laws and nine passed AI companion laws in 2026, with South Carolina requiring annual independent audits posted publicly.
- › California's 1967 wiretap statute keeps driving a wave of demand letters and class actions over ordinary website tracking technology.
A federal judge threw out most of the LinkedIn Insight Tag case because the health insurance website consented to the tracking on the user’s behalf. Singapore finalized guidance the same month saying you can train a model on scraped personal data when that data was publicly available. Both rulings move the consent decision further from the person the data describes, and neither one asked them.
Top 4 Critical Privacy Alerts
1. A Judge Gutted the Insight Tag Case Because the Website Consented for You
Senior U.S. District Judge Edward Davila in the Northern District of California mostly granted LinkedIn’s motion to dismiss two class actions over the LinkedIn Insight Tag, which links activity on third-party advertiser sites back to specific LinkedIn profiles. He dismissed the federal wiretap claim on the ground that the health marketplace, as a party to the communication, consented to sharing the data with LinkedIn. Claims from two California residents over data from Covered California were dismissed without prejudice, and only an intrusion upon seclusion claim survived. Courthouse News Service
Operator Note: The person shopping for health insurance never agreed to anything. The site did, on their behalf, by installing a tag. If your organization runs marketing pixels on any page where people disclose health, financial, or employment information, you are the party doing the consenting, and that is the exposure.
2. Singapore Says Scraped Personal Data Can Train Your Model
The Personal Data Protection Commission published the final Advisory Guidelines on Use of Personal Data in Generative AI on 20 July 2026, after the consultation closed on 1 July. The guidelines confirm organizations may rely on the publicly available exception under the Personal Data Protection Act to collect and use personal data for model development, including through web scraping, without consent, provided they assess whether the data is genuinely publicly accessible and whether the use is reasonable. They cover accountability across the AI supply chain, legal bases for training, output risks including hallucination and bias, and transparency toward individuals. The guidance is not legally binding. PogoWasRight
Operator Note: This is a workable rule and it beats the alternative of pretending model training can be consented to one record at a time. The word doing the work is reasonable, and nobody has defined it yet, so document your assessment now while it is cheap.
3. Minors’ Privacy Law Multiplied Across the States in 2026
Covington’s mid-year recap counts eight states passing new social media laws with parental consent, age verification, and limits on engagement features such as infinite scroll, plus nine states enacting AI companion laws requiring disclosure that the service is artificial. South Carolina passed the first age-appropriate design code demanding annual independent audits posted publicly to the Attorney General. Texas’s app store age law stayed in effect after the Supreme Court declined to block it on July 6, and Colorado’s operating system age-signal requirement takes effect July 1, 2028. Inside Privacy
Operator Note: Age verification means collecting identity documents from minors at scale to prove you are protecting minors. That is Shadow Risk, a control that creates a richer target than the harm it was written to prevent, and it is the same trap we described in the data you keep is a liability someone else can claim.
4. A 1967 Wiretap Statute Is Still Repricing Website Analytics
The California Invasion of Privacy Act, written in 1967 to stop phone tapping, continues to drive a surge of demand letters and class actions aimed at ordinary web tracking technology. Plaintiffs’ firms have built a repeatable practice around it, and the LinkedIn ruling above shows courts are still working out where party consent lands. PogoWasRight
Additional Privacy Alerts
Privacy Laws & Regulations
- EU AI Act transparency obligations apply from today: The European Commission’s guidelines took effect August 2, requiring chatbots and other interactive AI systems to identify themselves and deepfake content to be labeled. Global Privacy Watch
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.