Statescoop Massachusetts Settles Lawsuit Over COVID-19 Contact-Tracing App Data Privacy Violations
Article Content
- •Massachusetts settled a lawsuit over the automatic installation of a COVID-19 app on Android devices.
- •The state will delete all data collected by the MassNotify app as part of the settlement.
- •The case raises significant privacy concerns regarding government surveillance and data handling.
The Massachusetts Department of Public Health settled a class-action lawsuit regarding the automatic installation of the COVID-19 contact-tracing app, MassNotify, on Android devices. Users alleged that the app tracked their locations and transmitted personal information without consent. The settlement includes the destruction of all collected data and a five-year ban on similar app installations. The New Civil Liberties Alliance, which filed the lawsuit, described the app as 'insidious spyware' and claimed it was installed without user knowledge or consent. The app was reportedly installed on over one million devices, including those of non-residents. The state argued that the app's features were optional and anonymous, disputing claims of Fourth Amendment violations. The case highlights ongoing concerns about government surveillance and data privacy. The settlement is viewed as a significant legal precedent for privacy rights.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…