News

July privacy news: EU court on VPN legality, Smart TV proxies and the Suno breach

Three stories from the past few days that directly affect ordinary users' privacy: the EU's highest court confirmed the legal status of VPNs, almost half of the apps in LG's Smart TV store were quietly selling TV owners' IP addresses, and the popular AI service Suno leaked the data of 55 million people.

EU Court of Justice: a VPN is a lawful technical tool

The Court of Justice of the European Union ruled on an unusual case — about Anne Frank's diary. In most of Europe the diary has long been in the public domain, but in the Netherlands copyright on part of the text runs until 2037. The publisher hosting the diary online duly blocked access for Dutch IP addresses. The rights-holding foundation sued anyway: Dutch readers could still open the text through a VPN, so — by the foundation's logic — the publisher was infringing copyright.

The EU Court rejected that argument and set out an important principle: a VPN is a lawful technical tool, and a publisher is not liable when some readers use one to get around geographic restrictions. For users this is a significant precedent: the legal status of VPNs as a privacy tool has been confirmed at the level of the EU's highest court.

LG will ban Smart TV apps from selling your IP address

Researchers at Spur discovered that 42% of the games and apps in the LG webOS store contain so-called residential-proxy SDKs — meaning they quietly sell the TV owner's home IP address as an exit node for other people's traffic. On Samsung Tizen, more than a quarter of apps did the same. After the research was published, LG announced it would remove such apps from its store and ban residential proxies on the platform going forward.

Why this matters: someone else's traffic — of any kind — flows through your IP address, and from the outside it is indistinguishable from your own. That is the exact opposite of an honest encrypted tunnel, where you consciously choose a service, read its logging policy and know who the operator is. Free proxies and "free VPNs" often make money exactly this way — by reselling your resources and data. We covered how to tell a trustworthy service from one like that in "5 signs of an unreliable VPN service".

Practical advice for Smart TV owners: install as few third-party apps on the TV as possible, remove the ones you don't use, and keep the firmware updated.

The Suno breach: 55 million records

The breach-notification service Have I Been Pwned confirmed the scale of last year's hack of the AI music generator Suno: data of more than 55.3 million users was stolen — names, physical and email addresses, phone numbers, purchase history and some payment information (including partial card numbers and expiry dates).

What's worth doing even if you have never used Suno:

  • Check your email addresses on haveibeenpwned.com — it shows which known breaches they appear in.
  • Use a unique password for every service — if one site leaks, your other accounts stay safe. The easiest way is a password manager.
  • Enable two-factor authentication on your email and key accounts — a stolen password is useless without the second factor.

What it adds up to

Three unrelated stories form a single picture: in 2026, privacy is not an abstraction but a practical matter. The EU Court confirmed that encrypting your traffic is a legal, normal practice; the LG story is a reminder that "free" services often get paid with your data; and the Suno breach shows that even large services lose entire databases. Basic hygiene remains the same: unique passwords, a second factor, and an encrypted connection from a trusted source.