#User Privacy

Every story tagged User Privacy, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

12 stories · open in the command center

  • Security & PrivacyTechCrunchZack Whittaker2m

    Android app developers may be unwittingly sharing their users’ location data with advertisers

    Android app developers are unknowingly sharing users' location data with advertisers and data brokers through third-party SDKs that inherit app permissions by default, creating significant privacy, security, and regulatory risks for organizations. This widespread practice—affecting apps downloaded hundreds of millions of times—exposes sensitive location data to unauthorized third parties including government agencies and intelligence services, creating liability exposure and potential compliance violations under data protection regulations. IT and security leaders must establish vendor management protocols and SDK auditing practices to prevent unauthorized data sharing and mitigate organizational risk.

  • Security & PrivacyTechMemeJuro Osawa2m

    Anthropic says it is rolling back a covert Claude Code tracking feature to identify users based in China or affiliated with Chinese AI labs, after backlash (Juro Osawa/The Information)

    Anthropic is rolling back a covert tracking feature in Claude Code that identified users based in China or affiliated with Chinese AI labs, following public backlash. This incident highlights critical risks around hidden telemetry, user trust, and compliance violations that can damage enterprise relationships and expose organizations to regulatory and reputational harm. Technology leaders must now reassess their vendor risk management practices and establish stronger oversight mechanisms for AI tool transparency and data collection practices.

  • Security & PrivacyWiredReece Rogers2m

    How to Opt Out of Google Search’s New AI Data Training Feature

    Google is automatically enrolling users' search data—including images, audio, and video—into AI model training via a new default-enabled Search Services History feature, requiring manual opt-out through account settings. This represents a significant expansion of data collection practices across Google's integrated services ecosystem, with trained data persisting for up to 4 years even after deletion, creating potential privacy and compliance risks for enterprise users and their organizations. IT leaders must evaluate the implications for employee data privacy policies, contractual obligations with Google, and the growing pattern of tech vendors shifting from opt-in to opt-out models for AI training, which may necessitate updated corporate technology governance frameworks.

  • Security & PrivacyTechMeme2m

    A look at Roblox's biometric age-checking tool, which will help place users into age-based accounts starting this month, amid controversy over user privacy (NBC News)

    Roblox is implementing a biometric age-verification system to segment users into age-appropriate accounts, addressing regulatory compliance and child safety concerns but introducing privacy trade-offs that may impact user trust and retention. This development signals the industry's shift toward biometric identity verification for digital platforms, creating both compliance opportunities and privacy liability risks that IT leaders must evaluate for their own organizations. Technology leaders should anticipate increasing regulatory pressure for age verification mechanisms and prepare their systems and policies to balance safety mandates with consumer privacy expectations.

  • Security & PrivacyThe VergeEmma Roth2m

    Google will save your Lens photos, Search Live recordings, and Translate audio for AI training

    Google is expanding its data collection practices by automatically saving user interactions across Google Lens, Search Live, voice searches, and Translate for AI model training and personalization, creating significant privacy and compliance implications for enterprises managing corporate data use. This change separates from existing privacy controls, requiring IT organizations to reassess data governance policies and employee awareness programs, particularly regarding how user-generated content feeds AI development. CIOs must understand the new 'Search Services History' setting and its business implications, as this represents a broader industry trend of leveraging user interactions for AI advancement that may conflict with organizational data retention and privacy policies.

  • Security & Privacy9to5MacZac Hall2m

    macOS 27 Golden Gate makes it clear when apps are sneakily running in background

    macOS 27 Golden Gate introduces enhanced visibility into background app activity, making it immediately apparent when applications continue running after being closed—a capability that will improve IT security posture and user awareness of resource consumption. This change directly addresses security and compliance concerns around unauthorized background processes, requiring IT organizations to prepare for user education and potential policy updates around which applications should be permitted background execution. The new Background App Activity controls in System Settings provide IT departments with clearer management and enforcement capabilities, reducing the risk of performance degradation and security vulnerabilities from rogue processes.

  • Security & PrivacyAndroid PoliceRajesh Pandey2m

    Your Motorola phone might be secretly monetizing your Amazon clicks

    Motorola devices are secretly intercepting Amazon links and rerouting them through third-party domains with affiliate codes attached, potentially monetizing user clicks without consent—a serious breach of user trust and data integrity that raises critical questions about supply chain security and vendor accountability. This incident demonstrates the risks of pre-installed bloatware and highlights how device manufacturers may be incentivized to compromise user experience for revenue, requiring IT organizations to implement stricter mobile device management policies and vendor audits. For enterprises deploying Motorola devices, this vulnerability exposes organizations to potential brand reputation damage, regulatory compliance issues, and user trust erosion if employees' browsing activity is being monetized without proper disclosure.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite: Tired of app tracking pop-ups? Here’s how to auto-deny them

    Apple's App Tracking Transparency framework enables users to automatically deny app tracking requests at the OS level, reducing privacy risks from data collection and targeted advertising that had previously cost ad-tech companies billions in lost revenue. For IT organizations managing Apple device fleets, this setting represents an important privacy and security control that can be deployed enterprise-wide to protect user data and reduce organizational exposure to tracking-related compliance risks. Organizations should evaluate enabling this default-deny posture across their iOS/iPadOS deployments to strengthen privacy controls and demonstrate commitment to user data protection.

  • Enterprise TechTechCrunch2m

    Meta will now allow parents to see the topics their child discussed with Meta AI

    Meta is expanding parental controls by allowing parents to view topics their teens discuss with Meta AI across its platforms, representing a significant shift toward transparency and liability mitigation in response to child safety lawsuits and regulatory pressure. This initiative signals Meta's strategic pivot to position itself as a responsible AI provider for minors while establishing new governance through an AI Wellbeing Expert Council, creating both compliance obligations and market expectations for parental monitoring features across enterprise social platforms. For IT organizations, this underscores the growing need to implement robust content monitoring, data governance, and age-gating controls in AI-integrated platforms, particularly as legal liability for child safety becomes an established precedent.

  • Security & PrivacyHacker News3m

    Google, Microsoft, Meta All Tracking You Even When You Opt Out

    An independent audit found that Google, Microsoft, and Meta may be violating California privacy regulations by setting ad tracking cookies even when users opt out, potentially exposing these companies to billions in fines. This represents a significant compliance and regulatory risk for enterprise technology partnerships, as organizations using these platforms could face indirect liability and reputational damage. IT leaders must reassess their vendor relationships and data governance frameworks, particularly as privacy regulations expand and enforcement intensifies across jurisdictions.

  • Mobile & AppsTechCrunch2m

    PSA: If you use the Meta AI app, your friends will find out and it will be embarrassing

    Meta's AI app expansion raises critical privacy and data governance concerns for IT leaders, as the platform automatically notifies users' contacts about app usage and interconnects data across Meta's ecosystem for targeted advertising without explicit consent. The incident reveals significant design flaws in data sharing controls and user consent mechanisms, exemplified by previous security incidents where users inadvertently shared sensitive personal information including medical details and home addresses. IT organizations must evaluate their data governance frameworks and employee monitoring policies, particularly regarding third-party app integrations and the implicit consent embedded in terms of service agreements.

  • Security & PrivacyArs Technica2m

    LinkedIn scanning users' browser extensions sparks controversy and two lawsuits

    LinkedIn faces two class action lawsuits alleging it covertly scans users' browser extensions without adequate disclosure, potentially collecting sensitive data about religious beliefs, political affiliations, and health conditions—raising significant privacy compliance risks under US and EU regulations. The disputes stem from LinkedIn's stated goal of detecting abusive extensions but are being challenged as excessive surveillance that exceeds user consent and may involve undisclosed third-party data sharing. For IT leaders, this case underscores the critical importance of transparent data collection practices, privacy policy clarity, and the legal exposure of tracking technologies that could be interpreted as invasive surveillance.

Browse all tags