A class action lawsuit filed Tuesday accuses Lenovo of violating fresh Justice Department regulations designed to prevent the bulk transfer of sensitive American citizen data to foreign adversaries, specifically China. The suit, brought by Almeida Law Group on behalf of San Francisco resident Spencer Christy, alleges that Lenovo’s website collects and shares user data in a way that runs afoul of the DOJ’s Data Security Program, implemented last year.
The core of the complaint centers on concerns that Lenovo is allowing access to, or transferring, large quantities of personal data to entities linked to the Chinese government. This comes amid growing scrutiny of data security and the potential for foreign governments to exploit personal information for surveillance or other purposes. The lawsuit alleges that Lenovo’s practices expose Americans’ behavioral data to these potential risks, raising significant privacy concerns.
The Justice Department’s Data Security Program, established in response to national security threats, aims to safeguard Americans’ data from being acquired and misused by adversarial nations. According to the lawsuit, the regulations “create clear that sending American consumers’ information to Chinese entities through automated advertising systems and associated databases with the requisite controls is prohibited.” The program focuses on preventing the mass collection and transfer of data that could be used to profile and analyze American citizens.
What Data is at Risk?
The lawsuit outlines a broad range of “covered personal identifiers” that could be compromised, if Lenovo’s alleged practices are confirmed. The threshold for triggering the DOJ rule is data relating to 100,000 or more U.S. Persons. These identifiers include not only traditional personal information like government and financial account numbers, but also technical identifiers such as IMEIs, MAC addresses, and SIM numbers. Demographic data and advertising IDs are also included in the list of potentially vulnerable information. The suit claims Lenovo’s website uses trackers that expose this data.
According to the complaint, when a user visits Lenovo’s homepage, numerous first and third-party tracking implementations are activated, collecting and recording user data. These trackers reportedly include those associated with major tech companies like TikTok, Facebook, Microsoft, and Google. The lawsuit alleges that this data collection allows Lenovo to amass a substantial amount of personal information and potentially share it with entities connected to the Chinese government, including its parent company, Lenovo Group.
Broader Concerns About Chinese Data Access
This lawsuit arrives against a backdrop of increasing concern regarding Chinese access to sensitive data, particularly within critical infrastructure and technology sectors. The United States, Australia, and Vietnam have already banned Chinese companies from providing 5G equipment due to security concerns, as detailed in a Wikipedia entry on the topic. Concerns over Chinese involvement in 5G wireless networks stem from allegations that equipment from vendors in China may contain backdoors for surveillance by the Chinese government.
These concerns are rooted in Chinese laws, such as the Cybersecurity Law of the People’s Republic of China, which compel companies and individuals to cooperate with state intelligence agencies in collecting information when requested. The allegations have led to the formation of “The Clean Network,” a US government-led initiative aimed at establishing international digital trust standards and countering what it describes as threats from authoritarian actors.
Lenovo’s Response and Next Steps
Lenovo has publicly dismissed the allegations as “false.” The Register reports Lenovo stating the claim is “false.” However, the lawsuit is proceeding, and the case is now before the courts. The complaint [PDF] is available for review and provides a detailed account of the allegations against Lenovo.
The lawsuit seeks to represent a class of individuals whose data may have been improperly transferred. The next step in the legal process will likely involve Lenovo filing a response to the complaint, followed by a period of discovery where both sides gather evidence. A hearing date has not yet been set. Individuals concerned about their data privacy can stay informed about the case’s progress through the Almeida Law Group’s website and court filings.
This case highlights the growing tension between data privacy, national security, and the global reach of technology companies. As concerns about data security continue to escalate, We see likely that we will see increased scrutiny of data practices and stricter regulations aimed at protecting sensitive information from falling into the wrong hands.
Do you have thoughts on this developing story? Share your comments below, and please share this article with your network.
Worth a look
