Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
The 1994 Driver Privacy Law Has Three New Holes: Private Trackers, Hackers and Washington
Rebecca Schaeffer was murdered in 1989 by a stalker who paid a private investigator to pull her home address out of California's motor-vehicle records. Congress responded five years later with the Driver's Privacy Protection Act, a law built on one idea: the government holding your personal data doesn't mean anyone can buy it, sell it, or hand it out. Three separate stories from the past few weeks show how much ground it has lost.
Private companies don't need your DMV record anymore
An op-ed carried by both The Hill and Yahoo News lays out the first gap. Companies like Flock Safety run automated license-plate-reader networks that log plates, vehicle details, timestamps and camera locations off public roads. They never touch a state DMV database to do it. The DPPA regulates personal information contained in state motor-vehicle records. It says nothing about a private company building its own tracking database around the same license plate, independently observed. The op-ed argues that gap doesn't erase the privacy concern Congress was trying to kill in 1994, it just moves it outside the statute's reach.
There's a real public-safety case for plate readers: recovering stolen vehicles, investigating crimes, responding to public-safety threats. Nobody serious argues police should be blind. The unresolved question, as the op-ed frames it, is what happens after a vehicle is recorded — how long the information is retained, who can access it, and whether it can be shared or reused for other purposes. Flock has said it reduced its recommended default retention period from 30 days to seven days and added misuse-detection and accountability measures, though the op-ed notes that's a recommended default, not a universal limit, since actual retention can vary by contract and local law.
A stolen password on a personal phone
The second gap opened in Florida this month, and it wasn't a design flaw in the state's system. Florida's Department of Highway Safety and Motor Vehicles confirmed on September 11, 2026, that its Driver and Vehicle Information Database, known as DAVID, was accessed using login credentials belonging to a single Plant City Police Department employee, according to Shattered.io. Those credentials had reportedly been stored on the employee's personal device.
FLHSMV says it learned of the intrusion on September 4, 2026, called it the work of an international cybercriminal organization, and reported it to the Florida Attorney General's office, working with the Florida Digital Service and the Florida Department of Law Enforcement on the investigation. The hacking group ShinyHunters claims it pulled more than 200,000 driver records; FLHSMV has not confirmed that figure, and outlets covering the claim say they could not independently verify it either.
What's confirmed is the access method: a credential-hygiene failure at a local police department, not a break in DAVID's core architecture. That distinction matters for accountability. A statewide database didn't fail. A cop's password habits did. Florida already has a breach-notification law, Florida Statute 501.171, and privacy advocates and some state lawmakers are now pointing to the incident as reason to update the state's driver-data rules.
Washington wanted the whole list at once
The third gap is federal, and it just lost in court. The U.S. District Court for the Eastern District of Virginia granted a preliminary injunction on September 18, 2026, blocking the Federal Motor Carrier Safety Administration from obtaining bulk commercial driver data, according to a statement from California Attorney General Rob Bonta's office.
The background: the American Association of Motor Vehicle Administrators runs the Commercial Driver's License Information System, or CDLIS, which states use to check individual applicants for commercial licenses on people applying to drive large, heavy or hazardous commercial vehicles. States have historically searched it one driver at a time. In August 2026, FMCSA threatened to withhold funding from AAMVA and terminate its cooperative agreement unless AAMVA handed over records on millions of people at once, according to Bonta's office. A multistate coalition sued, calling the demand unconstitutional, beyond the agency's authority, and in violation of both the federal Driver's Privacy Protection Act and the federal Privacy Act. A temporary restraining order came first; the preliminary injunction followed, and it bars FMCSA from obtaining the data while litigation continues.
Bonta called it a win for privacy and the rule of law, saying the ruling protects Americans' privacy rights as the case continues. That's the state coalition's framing, and it's the only framing in the available record, since no public FMCSA statement defending the bulk-data demand appears in these materials.
Verifying that only qualified people hold commercial licenses to drive semi-trucks and buses is a legitimate federal interest, and CDLIS exists precisely to let states confirm an applicant doesn't already hold a license elsewhere. What's harder to defend, on the facts as reported, is using a funding cutoff as leverage to obtain bulk records on millions of people at once rather than working through CDLIS's individual-search design.
Three gaps, one 1994 statute
None of these three problems is what the DPPA was written to stop. Flock Safety isn't reselling DMV records, it's building parallel ones. Florida's breach wasn't a database leak, it was a stolen login. FMCSA wasn't buying records from a broker, it was leaning on a state-run cooperative system directly.
The litigation over FMCSA's data demand continues in the Eastern District of Virginia. Florida's breach has renewed a push for updated privacy rules there. And nobody has answered the question the 1994 Congress never had to ask: what happens when a private company can build the same map of your life the DPPA was written to keep out of reach, without ever touching the record the law actually protects.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.