Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

The Federal Trade Commission (FTC) and several states have taken action against Hims & Hers for deceptive and unlawful privacy practices. This enforcement targets the company's handling of consumer data, highlighting the FTC's commitment to protecting privacy in the digital health sector. The action underscores the importance of transparent and lawful data practices for businesses operating in sensitive areas like health information.

Today's question

Following the FTC's action against Hims & Hers for deceptive privacy practices, what is a critical area for privacy professionals in the digital health sector to review?

  1. Ensuring all data processing activities are explicitly covered by HIPAA, regardless of the data type.
  2. Verifying that public privacy policies accurately reflect actual data processing and sharing practices.
  3. Implementing a new data retention policy that deletes all user data after 30 days.
  4. Obtaining explicit consent for all data collection, even for strictly necessary operational purposes.

Answer this question on the site

Worth knowing

  1. EDPB Publishes Web Scraping Guidelines for Generative AI

    The European Data Protection Board (EDPB) adopted Guidelines 03/2026 on web scraping in the context of generative AI for public consultation on July 7, 2026. These guidelines acknowledge the epistemic, technical, and institutional limitations of regulating AI, such as the difficulty in knowing what data a model has collected and the irreversibility of model learning. The document provides guidance on how GDPR principles apply to web scraping for AI training, despite these challenges.

  2. Italian Garante Sanctions Piaggio & C. Spa and Altroconsumo Edizioni

    The Italian Garante privacy issued a fine of EUR 460,000 to Piaggio & C. Spa and EUR 280,000 to Altroconsumo Edizioni. The sanctions were imposed for marketing related violations. The Garante also provided a conditional approval for the AI Act's legislative decree, requesting stronger guarantees, particularly for biometric data.

  3. King's College London Issued Enforcement Notice by ICO for FOI Failures

    King's College London (KCL) received an Enforcement Notice from the Information Commissioner's Office (ICO) on July 10, 2026, due to its poor performance under the Freedom of Information Act. KCL reported a significant backlog of overdue requests and declining compliance with statutory timescales during 2025/26. The ICO requires KCL to publish an action plan, respond to overdue requests, and improve its compliance rate.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.