Error message

  • Warning: date_timezone_set() expects parameter 1 to be DateTime, bool given in format_date() (line 2133 of includes/common.inc).
  • Warning: date_format() expects parameter 1 to be DateTimeInterface, bool given in format_date() (line 2143 of includes/common.inc).

Electronic Freedom Foundation

EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity

EFF - Thu, 08/27/2026 - 11:46pm

EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil's elections. The recommendations stress the close relationship between violations of personal data protection and challenges to the integrity of electoral processes. They underscore how privacy and data protection guarantees are a crucial tool for curbing the targeted spread of false or manipulative content and other problematic strategies used by political actors that are amplified by digital technologies such as artificial intelligence systems. 

The recommendations are part of a broader regional initiative and build on the legal and institutional safeguards already in place in Brazil. They seek to promote greater coordination among oversight institutions, civil society, and digital platforms, and encourage the solid implementation of privacy and data protection guarantees as drivers of electoral integrity. Read the full document below. 

The Link Between the Integrity of the Electoral Process and Privacy 

Protecting the integrity of the electoral process in the face of internet and social media use is a challenge that many policymakers are addressing or are willing to address. Online, content that can affect the integrity of the electoral process is increasingly personalized. This phenomenon is so concerning that it has been identified as one of the main global short- and medium-term risks. 

In an era of generative AI, the economic cost and technical difficulty of producing and spreading false or synthetic content to deceive, manipulate, or simulate authenticity have been considerably reduced. That intensifies concern over the integrity of the electoral process. Meanwhile, online privacy and personal data protection remain unfinished business in Latin America. 

There is an intrinsic connection between the ability to collect and process large amounts of personal data and the way false or manipulative content is created and distributed—on social media and messaging apps in particular, and on the internet in general. For this reason, applying strict laws and policies on personal data protection and privacy makes it possible to reduce the impact of false or manipulative content. This is especially important in electoral contexts, where such content affects and impoverishes public debate, directly affecting political and electoral rights and the integrity of the electoral process. 

This phenomenon predates the emergence of the internet. However, the rise of new technologies accelerates the generation and spread of false and manipulative content. This is supported by the very economic model that sustains the platforms, amplifying its effectiveness and reach. On the one hand, social media platforms have content recommendation algorithms that use personal data to generate profiles to which they can then serve targeted advertising content, including explicitly political propaganda. This technique is known as "microtargeting." 

Political microtargeting seeks to have a direct or indirect impact on democracy. It is used to persuade voters, to encourage or discourage turnout at the polls, or to raise funds using information that is deliberately taken out of context, inaccurate, or erroneous. 

The control exercised by these companies raises serious concerns about people's rights. By having access to massive amounts of personal information, these companies have the ability to shape the content that users see and interact with. This happens through the construction of profiles that can reveal habits, social relationships, political preferences, and opinions, to mention a few examples. Personal data is the fuel that amplifies risks to the integrity of the electoral process. That’s true whether it’s provided by the users themselves or generated by the platforms from their interactions online. 

For disinformation actors, access to sophisticated tools—such as those used to create "deepfakes" through generative AI, or "bots" programmed to spread content and seek to manipulate public opinion—boosts the effectiveness of this microtargeting in terms of quality and scalability, making it harder to detect as false or manipulative content. AI-generated avatars and synthetic characters that simulate voters, influencers, hosts, commentators, or community leaders can produce footage that appears spontaneous, fabricate the voices of artificial political actors, and make it harder for users to identify if a given public statement was created or mediated by technology. 

In this context, paid promotion with nanotargeting seeks to reach increasingly specific profiles with customized content, and AI-based tools are used to assess and map its impact on social networks. Drawing on the personal data of groups of voters, profiles of "synthetic voters" are created to test messages or strategies in search of the most efficient way to influence real voters. 

This rapid expansion of AI systems and hyper-personalization with data can lead to a problem of "epistemic erosion" for democratic societies, as pointed out by the UN's Independent Scientific Panel on AI Governance in 2026. 

At Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation, we point to the enforcement of personal data protection laws and public privacy policies as an efficient mechanism for improving the quality of our democracies and reducing the manipulation of public discourse in digital environments and its impact in electoral contexts. Measures to broaden access to information for electoral decision-making, and to ensure transparency about campaigns' and political parties' use of digital technologies built on the massive processing of personal data, also play a relevant role in guaranteeing the integrity of the electoral process. 

Recommendations for Safeguarding the Integrity of Electoral Processes in Brazil in the Face of New Technologies 

Concern about the effects of spreading false, manipulative, or deliberately decontextualized content is particularly heightened in electoral contexts. From Argentina to Mexico, many countries in Latin America, including Brazil, are holding or will hold significant electoral processes in the coming period. 

Providing the public with quality information from a range of sources is an essential element for the exercise of political rights. In order to safeguard the electoral process, these countries must enforce their privacy and personal data protection laws through their competent authorities, in coordination with their judiciaries and electoral courts. 

Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation propose the following recommendations to protect the integrity of the electoral process by guaranteeing privacy and data protection during electoral contexts: 

1. Strengthen personal data protection guarantees and policies as a key element for the integrity of the electoral process, in particular the principles of necessity, purpose, and proportionality:

  • Prohibit the processing of sensitive personal data (such as philosophical beliefs and the labeling of ideological leanings), including inferred data, that reveals or could reveal people's political preferences for the purpose of targeting political content. In electoral contexts, the processing of sensitive personal data is only legitimate when the person has given their consent in advance, explicitly, and with strictly limited and clearly disclosed purposes of use and transfer. 
  • Processing must be carried out only on personal data that is strictly necessary for the purpose being pursued. 
  • Prohibit adding users to instant messaging groups for political outreach purposes, except in exceptional cases involving lists of political party members or where prior and informed consent has been given by the data subject. 
  • Free, specific, and informed consent means that the person is able to make a real choice, set apart from other choices, and does not run any risk of deception, intimidation, coercion, denial of access to products or services, or other significant negative consequences if they do not give their consent. 

2. Political parties, federations, and coalitions must improve the information made available to the general public about their personal data processing activities in electoral contexts, including: 

  • The personal data processing policy adopted, in compliance with data protection legislation and electoral legislation, including the measures adopted to prevent breaches of the general protection principles, to record personal data processing operations, to obtain consent appropriately, and to ensure technical and administrative security in data processing; 
  • Communication channels where the data subject can obtain information about the processing of their personal data, exercise the rights provided by law, and request to opt out of receiving electronic and instant messages. 
  • Information about the profiling they carry out for electoral purposes and about the procurement and use of data-based digital technologies in this context, including for purposes of paid promotion, microtargeting, network analysis, and prediction of voters' reactions or behavior. 

3. Strengthen cooperation mechanisms between the National Data Protection Authority (ANPD) and the Superior Electoral Court in order to: 

  • Improve communication channels and strengthen joint initiatives to oversee compliance with data protection guarantees in the electoral context, with the publication of periodic enforcement reports. 
  • Identify and dismantle coordinated strategies that compromise the integrity of the electoral process and carry out online activities that pretend to be "organic" and citizen-based when they are in fact funded or coordinated by a party, government, or company, such as bot farms, fake personal accounts managed by a single entity, AI avatars and synthetic characters that simulate real voters in order to manipulate public opinion, among others. 
  • Within the scope of their powers, require the preparation and publication of a data protection impact assessment in cases involving the use of sensitive personal data or emerging technologies for voter profiling. 

4. Authorities, political parties, communicators, and social media platforms must ensure, as far as possible, that the population has access to adequate and relevant information for electoral decision-making. 

  • Political parties, electoral authorities, and data protection authorities must allocate a percentage of their communications budget to warning about the consequences of microtargeting in electoral contexts; and about the use of AI avatars or synthetic voters to simulate support, rejection, outrage, or spontaneous political mobilization. 
  • Strengthen alliances with fact-checkers and other relevant communicators, such as civil society organizations, influencers, and others, to identify campaigns that compromise the integrity of the electoral process and to inform the public about such alliances through different channels, including official government channels.
  • Systematize the electoral proposals developed by candidates and their electoral platforms according to thematic areas to facilitate comparison between political parties. 
  • Agree on strategies between authorities and online platform companies, including social media platforms and chatbots, at the start of electoral periods, so that priority is given to content developed by electoral authorities. 
  • Every body, protocol, or policy created that involves authorities or public entities must be communicated in accordance with proactive transparency standards. 

5. Platforms must disable microtargeting tools for political and electoral content during previously established periods. 

6. Authorities, technical actors, academics, civil society, and/or social media platforms must collaborate in creating an algorithmic impact analysis lab that makes it possible to oversee compliance with these recommendations. 

  • Produce reports on the results achieved, in particular those that document the existence of microtargeting, the use of personal data for targeting, and exposure to varied content in electoral contexts. 
  • Establish strict cybersecurity protocols so that the labs prevent access to real users' private information. 

7. The authorities responsible for overseeing personal data protection and electoral matters must have sufficient functional, economic, and technical autonomy and independence to guarantee the proper exercise of their powers. 

A List of ICE Subpoenas to Tech Companies

EFF - Wed, 08/26/2026 - 5:31pm

Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.

A favored tool in these speech chilling investigations are administrative subpoenas sent to technology companies, requesting basic subscriber data about their users. For example, from 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter (now X), according to documents obtained by Just Futures Law. In just the second half of 2025, the Department of Homeland Security (DHS) sent 21 administrative subpoenas to Reddit, according to its Transparency Report.

While some subpoenas are routine, ICE has been forced to withdraw others after users challenged them in court or companies pushed back. These challenged subpoenas exceeded the agency's statutory authority and violated users' First Amendment rights.

Below is a non-comprehensive list of DHS subpoenas that we gathered going back to 2025, looking at public reporting and court cases. This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report (so far, only Reddit appears to break out specific numbers on DHS subpoenas). In addition, DHS has been slow to respond to our Freedom of Information Act requests and lawsuits seeking records that would show how many administrative subpoenas ICE has sent to social media companies since 2025.

If you know of other subpoenas that are not on this list, please reach out to info@eff.org. While the government has abused the subpoena process in other areas, particularly to hospitals, this list focuses on DHS and ICE subpoenas to technology companies for user data. 

DATE ISSUED

(and link to subpoena)

TARGETED COMPANY INDIVIDUAL USER TARGETED  OUTCOME  3/17/25 Facebook  Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 3/23/25 Google  Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 4/1/25 Google  Amandla Thomas-Johnson, international student who attended pro-Palestinian protest Google disclosed data to ICE on 5/8/25 9/4/25 Meta  6 accounts in Southern California that documented immigration activity, including LB_Protest, Long Beach Rapid Response Network, and Stopice.net Withdrawn after court challenge on 11/24/25 9/11/25* Meta (Instagram) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 9/11/25* Meta (Facebook) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 10/30/25 Google  Retired Philadelphia user who emailed criticism to U.S. prosecutor   Withdrawn after court challenge on 2/5/26 2/4/26* Google Social media user who regularly posts criticism of the President Subpoena challenged in Court 2/19/26* Reddit "Tired_Thumb," user who posted about ICE officer Withdraw after court challenge on 3/27/26; replaced with grand jury subpoena 2/27/26* X "podslurp,” who posted publicly available address information about ICE officer Withdrawn May 2026; replaced with grand jury subpoena 3/7/26 PayPal/Venmo "Voices of Racial Justice," a racial justice organization in Minnesota  PayPal/Venmo disclosed data 3/20/26 4/3/26* Google (YouTube) @TheDonLemonShow, GeorgiaFort, @DemocracyNow, and seven other accounts that reported on protest at Minnesota church Google Objected 4/7/26 4/12/26* T-Mobile Minnesota journalist Georgia Fort and others T-Mobile disclosed data on 4/12/26 First half of 2025 Reddit  Reddit account Subpoena withdrawn after questions from Reddit Second half of 2025 Reddit  11 Reddit accounts that posted content "critical of ICE actions" 3 subpoenas withdrawn after Reddit objected

* = denotes summonses issued under 19 U.S.C. 1509, an authority that has been abused in the past, according to DHS's inspector general.

EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms

EFF - Wed, 08/26/2026 - 1:44pm

Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool that can be made safe with the right policy or feature update—they are irredeemably harmful.

EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines.

EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines. EFF applies every tool available to eliminate ALPR surveillance and the harm it enacts.

The Case Against ALPRs

A note about scope: This post addresses ALPR mass surveillance. It does not address the wider universe of automated traffic enforcement (ATE) such as conventional red light and speed cameras that solely ticket a specific violation, without retaining or networking data on uninvolved drivers. But lawmakers and purchasers should guard against efforts by vendors to piggyback on ATE contracts to market ALPR mass surveillance systems.

ALPRs are frequently marketed as a narrow tool for specific purposes, such as recovering stolen vehicles. But in practice, these sensors sweep up data on every driver who passes a camera, and store it in searchable databases. That indiscriminate collection and retention is precisely why ALPR-fed surveillance systems can be easily weaponized against immigrants, political dissidents, and other targeted communities as ICE and other federal agencies escalate their assault on civil liberties. There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it.

Of course, ALPRs cause other predictable harms. Innocent drivers are recurringly arrested and menaced by police because of ALPR errors. Officers regularly abuse ALPR systems to stalk past and potential romantic partners. Creating any database of personal information—including ALPR surveillance databases—inherently creates risk of data theft and subsequent harm to data subjects. And ALPR surveillance of protests and targeting of activists chill participation in First Amendment-protected dissent. But even if these downstream harms could all be prevented (and they likely can’t), ALPRs would remain an intolerable form of mass surveillance.

Fighting on Every Front to Eliminate ALPR Surveillance

At the city level, EFF works with community members and decision makers to outright refuse ALPR purchasing. ALPRs are not inevitable. The same decision mechanisms used to facilitate runaway surveillance purchasing in U.S. localities can be turned against these systems to dismantle them.

EFF also pushes state legislatures to establish strict state-level limits on ALPR surveillance, such as data-deletion rules and use restrictions. Building such constraints into statute can mitigate the harms of existing ALPR systems.

In courts across the country, EFF files amicus briefs arguing that warrantless police searches of ALPR databases violate the Fourth Amendment. In California state court, EFF and the ACLU of Northern California are suing on behalf of two community groups, SIREN and CAIR-CA, arguing that the San Jose Police Department's practice of letting officers search stored plate data—to the tune of over 100,000 times a year—without a warrant violates the California Constitution. We’ve also sued to block California law enforcement from sharing ALPR data with federal and out-of-state agencies, in violation of a California statute.

A big part of EFF’s work is exposing the harms of ALPR surveillance. Our investigative team tirelessly collects information about how law enforcement uses ALPRs with public records requests, sues to enforce such requests, and publishes reports about them. We’ve also successfully lobbied for a State Auditor investigation of law enforcement’s use of ALPRs.

Coordinated Action Against Mass Surveillance

EFF practices integrated advocacy because all of these tools work best together. City refusals, statehouse restrictions, impact litigation, and investigative activism are different levers EFF pulls toward the same end: eliminating ALPR surveillance, and building the durable public power needed to keep it off our streets. A council vote against a Flock contract and a warrant argument in Santa Clara County Superior Court are both, at their core, the same fight: rejecting mass surveillance infrastructure outright, and using every venue available to eliminate its harmful presence and consequences.

EFF Statement on Meta Settlement

EFF - Wed, 08/26/2026 - 12:34pm

Under this settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta's harmful surveillance into law, and it will compromise users' privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care. 

Pages