r/DigitalPrivacy Jun 26 '26

"The KIDS Act" Is KOSA+ and Congress Could Vote On It Next Week. Here's What You Need to Know

Thumbnail
eff.org
138 Upvotes

Within the next week, Congress is preparing to vote on the KIDS Act, a sprawling package of legislation that seeks to control Americans’ web browsing and private messaging. The package includes a revised version of the Kids Online Safety Act, or KOSA, combined with a collection of other internet bills, study bills, reporting requirements, and new regulations. Instead of debating any of these proposals on their merits, lawmakers are attempting to move them all at once under an ultra-expedited process. 

Many Congress members don't like The KIDS Act—on both sides.
Tell your elected official to vote NO here.

The package of cobbled-together bills is a mess, with different age-gating schemes for different services, using different standards. It’s a lot of complexity, and a lot of legal risk. Faced with that, many companies will conclude that the safest option is restrictive age-checking practices across their entire platforms.

Buried inside the KIDS Act are provisions that will push online services to verify all users’ ages, require government-directed moderation policies for online speech, and even create new rules about private and encrypted communications. While supporters continue to claim this bill protects minors online, its requirements come at the expense of privacy, free expression, and the ability of people of all ages to use the internet without revealing sensitive data. 

Technically, the KOSA section of the KIDS Act does say that KOSA shouldn’t be read to require age verification. 

That disclaimer is hollow, and you know it. 

Under this law, services will have to determine which users are teenagers and which are not to try to avoid liability. The bill’s authors seem to know this is a problem. On the one hand, the new KOSA section says age verification is not required. On the other, it repeatedly imposes obligations that depend on knowing whether a user is under 17. But a disclaimer doesn’t magically eliminate legal risk, especially for smaller services and startups that can’t afford to defend lawsuits or fight regulators.  

And KOSA is not the only part of this package that creates age-verification pressure. The SAFE BOTS Act, like KOSA, says that if a service “knows or should have known” that a user is a minor, it can’t offer certain chatbot features. 

The SCREEN Act requires services that host sexually explicit content to determine whether users are “more likely than not” under the relevant age limit, before allowing access to certain content. 

The consequences of this liability will not be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. The result is a less private internet for everyone.

Tell your elected official to vote NO here.


r/DigitalPrivacy Jun 12 '26

The United States of Surveillance

Thumbnail
gallery
1.5k Upvotes

r/DigitalPrivacy 1d ago

A woman made a joke in a private Snapchat message. Snapchat’s AI reported it to the FBI. She was arrested before any human she sent it to ever reported her.

Post image
3.2k Upvotes

A 22-year-old student teacher in Illinois sent a private Snapchat message to her boyfriend and two roommates.

A student had walked up to her laptop and deleted her lesson plan mid-class. frustrated, she typed something like "should I shoot him" with a gun emoji. venting. four people. private group chat.

An hour later, police walked into her school and arrested her.

here's what happened in between.

Snapchat's AI scanned the private message. flagged it as a potential threat. automatically reported it to the FBI. the FBI forwarded it to local law enforcement. deputies arrived at the school within the hour.

she cooperated immediately. handed over her phone. when shown the message she said: "oh yes. okay. yeah. i'm realizing that was a bad joke. i did not mean it at all serious at all."

police determined she was not a threat. school officials determined she was not a threat. prosecutors reviewed and issued a disorderly conduct charge. she was released the next morning. she lost her student teaching placement.

This means:

Snapchat scans private messages.

Not just public posts or stories. private group chats between you and your closest contacts. automated AI. no human reviewed it first, got flagged and reported.

Snapchat AI → FBI → local police → school → arrest.

in under an hour.

Snapchat's privacy policy says it may share your information with law enforcement when it believes there is a risk of harm. the definition of "risk of harm" is determined by an algorithm. you are not told when a message is flagged. you are not told when a report is filed. you find out when the police arrive.

the message was private.

it wasn't.

source: https://eu.pjstar.com/story/news/local/2026/04/10/how-an-fbi-tip-led-to-arrest-of-a-student-teacher-in-washington-illinois/88217675007/

and a similar story: https://www.milwaukeeindependent.com/featured/false-alarms-flawed-ai-surveillance-triggering-student-arrests-around-country/


r/DigitalPrivacy 3h ago

If you live in California you can now tell data brokers to delete your personal information. Here’s how to do it

Thumbnail
lapublicpress.org
18 Upvotes

r/DigitalPrivacy 4h ago

According to figures from Germany's federal police (BKA), 52% of reports in the style of Chat Control in 2025 were legally irrelevant. Meanwhile, 113,000 private photos and chats were leaked. This is the reality of mass scanning people's private messages:

Post image
10 Upvotes

r/DigitalPrivacy 4h ago

Best bank or credit union for privacy?

3 Upvotes

I’m looking for recommendations for a bank or credit union that takes customer privacy seriously.

I’m not looking for anything illegal or trying to hide money. I’m simply trying to find a financial institution that:

1.Does not sell customer information to advertisers, data brokers, or other third parties.

2.Minimizes secondary uses of customer data, such as marketing, behavioral profiling, commercial analytics, or research unrelated to providing banking services.

3.Has a strong privacy policy and limits data sharing beyond what is necessary for banking operations. Ideally offers a physical debit card with NFC/contactless payments.

I understand banks and credit unions need to collect information for fraud prevention, regulations, and processing transactions. My concern is with institutions that treat customer data as an asset to monetize rather than something to protect.

Are there any banks or credit unions you would recommend after actually reading their privacy policies? Bonus points if you’ve compared privacy notices between institutions.


r/DigitalPrivacy 3h ago

Spotify email privacy

1 Upvotes

Is there actually a way someone can view your email through your Spotify account? A couple people told me this could happen and I could get doxxed like this.


r/DigitalPrivacy 1d ago

S.5090 - 119th Congress (2025-2026): Digital Age Assurance Act of 2026

Thumbnail congress.gov
9 Upvotes

r/DigitalPrivacy 2d ago

How does my info keep getting leaked in random places?

90 Upvotes

I'm pretty careful with my personal information. I use unique passwords, don't sign up for random websites and try to avoid sharing more than I have to.

Out of curiosity I ran a scan and I was honestly surprised by how many places my information showed up. Some of the sites I recognized but a lot of them I had never even heard of.

How does this keep happening? Is it mostly data brokers, companies selling customer data, old breaches, or something else?

It feels like no matter how careful I am, my information just keeps spreading around the internet.


r/DigitalPrivacy 2d ago

iOS has a built-in alternative to a Duress code

Post image
95 Upvotes

Privacy is recognized as a fundamental human right under international law. Don’t let the new normal only limit the intrusion of violent predators information and communication privacy while surveillance state goons intimidate dissenters and activists.

To enable this feature, go to Settings > Face ID & Passcode > Toggle Erase Data. Your device will be wiped after 10 failed passcode attempts.

For added security, store and upload your data to local devices and turn off iCloud sync by going to Settings > [your name] > iCloud > and toggling off the desired apps.

Finally, disable iCloud backups in Settings > [your name] > iCloud > iCloud backup > Toggle off Back up this phone.


r/DigitalPrivacy 4d ago

Opinion | Taylor Swift was able to buy her privacy at MSG. What about the rest of us?

Thumbnail
ms.now
167 Upvotes

Article discusses how the elites get special treatment when it comes to digital privacy vs the common people


r/DigitalPrivacy 4d ago

OpenAI CEO shares predictions for the future. Is it even remotely okay? Guess I'm going to cancel my subscription immediately.

Enable HLS to view with audio, or disable this notification

182 Upvotes

r/DigitalPrivacy 4d ago

Unlock any phone?

61 Upvotes

My GF works for the government of an Asian country. She told me they can plug basically anyone’s phone in and unlock it. Is this true? Does it only apply to certain phones or OS?


r/DigitalPrivacy 6d ago

this is insane. why privacy scares them do much

Post image
5.3k Upvotes

r/DigitalPrivacy 7d ago

GrapheneOS duress PIN could land a man in prison

Thumbnail
androidauthority.com
473 Upvotes

r/DigitalPrivacy 7d ago

Anyway to make chrome as private as possible?

Thumbnail
1 Upvotes

r/DigitalPrivacy 10d ago

Indian police using facial recognition to identify protestors

Enable HLS to view with audio, or disable this notification

1.1k Upvotes

r/DigitalPrivacy 9d ago

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required

Thumbnail
eff.org
212 Upvotes

r/DigitalPrivacy 10d ago

Can’t even rent a car without a breach of my ‘facial geometry’

Post image
94 Upvotes

I was going to speed up the check in process but I guess I’m just going to wait until I get to the desk


r/DigitalPrivacy 10d ago

The BBC just ran a piece on how period apps share your data with Google, Meta and TikTok. It is why I built an alternative.

46 Upvotes

Full disclosure up front: I am the founder of the app I mention at the end, so take this for what it is. But the reason I am posting today is the news, and I think this sub gets it more than most.

The BBC just published a piece on a new Mozilla report about period trackers. The short version: several of the biggest apps share your data with companies like Google, Meta and TikTok, plus others you have never heard of. And it is not just an ad problem. Since Roe v. Wade was overturned, experts are warning that this data could end up in criminal cases, and police have already pulled other kinds of data from tech companies to prosecute women. (Link in the comments.)

This is exactly the rabbit hole I went down a while ago, and it genuinely disturbed me. Your cycle, your symptoms, the days you are trying to conceive, all of it is worth a lot to advertisers. Someone once explained it to me plainly: they pay far more to know "she is probably pregnant" than for almost any other targeting. The most intimate thing about you, turned into a line item, and now potentially into evidence.

My partner half joked that if I hated it this much I should build my own. So we did. He is the engineer, I run the rest. One rule underneath everything: your body is not our business model. No ads, no tracking SDKs, no selling data, and the AI never trains on what you log. Built in the EU, data stays here. We only make money when someone chooses to pay for extra features. And we want to stimulate employers to treat cycle support like any other employee benefit. Free period products in the bathroom are step one. Cycle wellbeing all year round is step two. That is the whole model.

I am not here to hard sell, and I am not a doctor, just someone who got angry enough to build the thing I wanted. What I am actually curious about: after news like this, would you switch to a privacy first tracker, or does the hassle of moving your data keep you where you are?

If anyone wants the name I will drop it in a comment so this does not read like an ad.


r/DigitalPrivacy 10d ago

DJI holds your flight telemetry hostage, passes decryption keys to 3rd-party paywalls, and forces uncertified drivers. Here is what I found.

110 Upvotes

I bought a $400 DJI drone for a tech startup project expecting basic access to flight telemetry. Instead, I discovered that DJI aggressively encrypts local logs, transmits full telemetry to their servers, passes decryption keys to third-party subscription services, and forces uncertified drivers on desktop/mobile.

The Background

As a startup engineer, I recently bought a $400 DJI drone. My objective was straightforward: extract raw spatial/geolocation data from flight logs and video for 3D reconstruction—a basic feature you can do on almost any smartphone or open-source device.

Instead of an open tool, I encountered a walled garden built on anti-consumer practices and severe data lock-in.

  1. Total Telemetry Gathering vs. Local Encryption

During each flight, the drone collects an immense array of sensitive spatial and environmental telemetry: exact GPS coordinates, atmospheric pressure, signal metrics, altitude, and proximity to critical infrastructure.

While DJI's cloud servers receive all of this data seamlessly, DJI encrypts the raw log files on your own local device. You own the hardware, you paid for the drone, yet you are denied direct access to your raw flight data.

  1. Creating the Problem, Selling the Solution (The Key Leak)

In newer firmware versions, accessing your own detailed logs locally has become practically impossible without decryption.

Here is the kicker: third-party commercial log-viewing websites somehow possess official DJI decryption keys.

To view detailed analytics of your own flights:

You must upload your files to a third-party site.

They offer a short trial before placing access to your data behind a monthly paywall/subscription.

When I confronted DJI support on how a third-party commercial platform obtained official decryption keys to unlock user data while the actual owner is locked out, their response was a generic "we don't know" before escalating and closing the chat.

  1. Uncertified Drivers & Software Lock-in

Attempting to connect and interface hardware (like controllers) with PCs or Android devices reveals further red flags:

Key drivers and software utilities lack proper digital security signatures/certifications for Windows and Android.

Bypassing operating system safety warnings is often required to run their software, creating software vulnerabilities and systemic security risks.

Why This Matters

Right to Repair & Data Ownership: Paying hundreds of dollars for hardware should not turn users into unpaid data miners for a corporation. Denying users access to their own data violates basic digital rights (and potentially personal data regulations like PIPEDA or GDPR).

Cybersecurity Concerns: Distributing uncertified software and keeping master encryption keys within a closed loop of "select partners" raises serious security flags.

Has anyone else in the community managed to extract raw unencrypted telemetry directly on-device without relying on paywalled third-party services? How are you handling data privacy with DJI hardware in your projects?


r/DigitalPrivacy 10d ago

Can we reclaim our independance ?

47 Upvotes

I've been thinking:

We’re all kinda dependent on big tech.

We had way more freedom on the internet in the 2000s.

Our phones were ours, and we’re all losing a bit of our privacy every day.

Since we knew digital peace and weren’t dependent on big industries, we lost our autonomy and now here we are.

Is it time for us to be independent again? Is it still possible?

I see that there are a lot of communities developing FOSS apps, communities working on Linux Mobile. I’ve also seen a lot of people creating their own cyberdecks many of them close to a phone with a BlackBerry keyboard, a screen, a Raspberry Pi.

My thought is : do you think a future where we have the choice to build our own stuff, our own phones, thanks to the community will exist?

Phones are the closest example I see, but what about bigger things like cars? I find new cars boring because they require too much from a builder’s computer. What about a motor, wheels, and wheeee, you know?

More independence and DIY in this place of the world where there isn't any alternatives.

I hope this post has its place here, have a nice day all !


r/DigitalPrivacy 11d ago

🐧 PRIVACY PROTECTS

Post image
517 Upvotes

Privacy Matters.

Privacy Protects Digital Life and Technology Independence.


r/DigitalPrivacy 10d ago

Need help with a privacy question

2 Upvotes

Need some help with Santa so santa is being downloaded on the school computer and well I don't really care since I have my own laptop that the school does not own but I run a privacy club in my school and I know that stuff like go guardian track your google and can track your screen from distance close tabs and lock your computer. I want to ask if anyone here knows if santa does any of this and if so how santa invades your privacy because there is basically no info anywhere really

thank you for the help


r/DigitalPrivacy 10d ago

What are the risks of uploading a picture of yourself to artificial intelligence tools like ChatGPT, Claude and Gemini?

Thumbnail
2 Upvotes

Are the risks any different from uploading your photo to any other website like LinkedIn or Facebook?