< ciso
brief />
Tag Banner

All news with #gdpr tag

73 articles

Denmark: Massive CPR Register Access Exposes Millions

🔒 Unauthorized parties accessed names, addresses, and personal identification numbers for about 8.8 million people in Denmark's Central Person Register (CPR), the digitalization ministry reported on October 5. The breach leveraged a private company's legal lookup rights and persisted for around 10 days in September before unusual activity was detected. The register's administration has suspended the company's access, reported the incident to Datatilsynet, and police are investigating. Authorities urge vigilance against phishing, recommend credit warnings, and have launched a security review while Datatilsynet examines responsibility and impact.
read more →

Italy fines IQVIA €7M for inadequate data anonymization

🔒 Italy's Data Protection Authority fined IQVIA €7 million over insufficient anonymization and data-processing practices affecting about one million patient records. The GPDP found that pseudonymous codes plus detailed health and location data could enable re-identification, and that some records included full personal identifiers. Authorities also cited lack of legal basis, failure to inform patients, and missing retention policies, ordering compliance within 120 days.
read more →

Denmark CPR breach exposes records of 8.8M people

🔒 The Danish Central Population Register (CPR) disclosed a data breach that exposed personal information for approximately 8.8 million registered individuals, including residents, expatriates, and deceased persons. Threat actors abused a private company's legitimate access and used brute-force enumeration of CPR numbers to extract names, addresses, dates of birth, marital status, and CPR identification numbers. The breach occurred in September 2026, was discovered on October 2, and affected about 80% of records held in the CPR system. Authorities have blocked the third party's access, launched a police investigation, and enacted extra security measures while urging citizens to remain vigilant.
read more →

DTU Breach Exposes Data of Up to 200,000 People

🔒 The Technical University of Denmark (DTU) reports that hackers used compromised credentials to access its identity and access management system, DTUBasen, potentially exposing information of up to 200,000 people. The breach may include Danish civil registration numbers (CPR), names, addresses, profile pictures, work emails, job titles, and next-of-kin contact details for active users. DTU is notifying affected current and former employees via e-Boks and urging caution against phishing and identity fraud.
read more →

Sweden fines Miljödata over municipal data breach

🔒 IMY, Sweden’s data protection authority, fined IT provider Miljödata SEK 1.8 million ($183,000) after an August 2025 cyberattack exposed personal data of 2.2 million people across municipal systems. The regulator found the company failed to perform adequate checks on newly installed software and lacked automated real-time monitoring to detect intrusions, violating GDPR Article 32(1). The attack disrupted services in over 200 regions and saw stolen data published by the threat actor “Datacarry.”
read more →

EU fines Google €403M for mishandling location data

📌 The Irish Data Protection Commission fined Google €403 million for GDPR breaches in how three features handled location data between May 2018 and February 2020. The DPC found issues with Web & App Activity, Location History and the Location Accuracy feature, citing failures in lawful processing, transparency and accountability, and excessive data retention. Google says the case concerns historical policies and notes it has updated practices, including introducing auto-delete controls and changing defaults since 2019.
read more →

DPC fines Google €403M for location data breaches

📌 Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches tied to processing users’ location data. The investigation, opened in February 2020, reviewed three features — Web & App Activity, Location History, and Location Accuracy — active during May 25, 2018 to February 4, 2020. The DPC found failures in transparency, lawful processing, and retention practices, and ordered compliance within six months. Google says it has since updated policies and added user controls for location data.
read more →

Irish DPC Fines Google €403M Over Location Data

📍The Irish Data Protection Commission has fined Google €403m for GDPR breaches related to its handling of users' location data across features such as Web & App Activity, Location History and Location Accuracy. The inquiry, covering May 25, 2018 to February 4, 2020, found failures in lawfulness, transparency, accountability and retention practices. The DPC said Google must rectify its processing within six months, while Google contends policies have since changed and tools improved.
read more →

16 Tools for Governing and Securing Enterprise AI

🛡️ This article surveys 16 vendors offering governance, guardrails, and security platforms for production LLMs and agent fleets. It outlines each vendor’s primary capabilities, standout features, pricing model, and the types of organizations best suited to their offerings. The piece emphasizes themes such as data protection, automated red teaming, compliance with regulations like the EU AI Act and GDPR, and integrations with cloud or data ecosystems. Readers get a comparative, vendor-focused guide to building control planes for AI risk management.
read more →

Twenty-Five Years of Mass Surveillance Is Enough

📝 This essay, coauthored with Cindy Cohn and first published in Lawfare, traces the post-9/11 shift from targeted warrants to widespread mass surveillance by government and private actors. It outlines how data brokers, corporate tracking, and programs like the NSA’s Upstream and Section 702 collections have expanded governmental access to Americans’ communications. The authors argue these practices undermine Fourth and First Amendment protections and call for reassessment.
read more →

French hospital fined €500k after data breach

🔒 France’s data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a 2025 breach exposed sensitive records for 727,113 people, including 524,867 patients and 202,246 trusted third parties. The investigation found failures including lack of VPN/MFA for external users, weak access controls, and absent real-time monitoring, enabling extensive data exfiltration. The hospital informed affected patients but did not directly notify all third parties; a teen hacker claiming responsibility sold the data attempt reportedly failed.
read more →

EU extends controversial message scanning through 2028

🔎 Members of the European Parliament failed to block an interim measure that extends mass scanning of private communications through 2028. The motion to reject and an amendment requiring warrants both secured more votes in favor than against, but neither reached the necessary absolute majority due to many absences. The extension permits service providers to scan DMs and emails on platforms like Discord, Instagram, Gmail and iCloud without warrants, while end-to-end encrypted services remain unaffected. Supporters argue it combats child sexual abuse; critics warn it threatens privacy and could lead to false positives affecting enterprises.
read more →

Google Cloud cleared for Dutch public sector use

🔒 Google Cloud announced completion of a Dutch data protection impact assessment (DPIA) by SLM Rijk, confirming there are no known high data protection risks when recommended measures are applied. The outcome enables the Dutch central public sector to adopt Google Cloud from a privacy-assessment perspective and builds on earlier DPIA work for Google Workspace. Google emphasizes continued investment in privacy-enhancing technologies and support resources for customers.
read more →

CMC analysis of Canvas incident impacts education

🔍 The UK Cyber Monitoring Centre (CMC) has published its review of the Canvas incident affecting Instructure’s Learning Management System, finding ~160 UK higher education institutions impacted and around 9,000 worldwide. The analysis highlights that financial losses arose mainly from response, recovery and risk management rather than prolonged outage. The CMC reinforced best-practice recommendations for the sector, including MFA enforcement, separation of application and data layers, careful third‑party control and clearer vendor communication.
read more →

Ten years of the GDPR: mixed outcomes and lessons

📄 Ten years after the GDPR came into force, data protection is far more established across Europe and beyond, raising consumer awareness and making privacy a competitive factor for businesses. Record fines against major tech firms underline enforcement seriousness, even as many penalties remain disputed. Companies increasingly view the regulation as burdensome and legally uncertain, complicating innovation, notably in AI development.
read more →

Google to use IPs for ad personalization in EEA, UK

🔒 Google has notified advertisers it will begin using IP addresses to identify devices for ad measurement and personalization across the EEA, UK and Switzerland on or shortly after August 3, 2026. The change repurposes IPs — already transmitted to route traffic and deliver ads — for purposes that trigger consent requirements under UK and EU law. Google will register for IAB Europe TCF Feature 3 and says it will rely on privacy-enhancing technologies while offering later user choices on its properties. Advertisers remain responsible for obtaining valid consent under Google’s EU User Consent Policy.
read more →

GDPR’s legacy and the coming AI regulatory battles

📰 Over eight years GDPR set global data-protection norms, notably the 72-hour breach notification standard, but nearly 40% of announced EU fines by value are annulled or under appeal. Experts say large tech firms contesting fines isn’t surprising and that rulings provide practical guidance for compliance teams. As the EU’s AI Act and proposed GDPR reforms arrive, regulators must shore up procedural robustness while organisations adapt governance to evolving AI risks.
read more →

Most CISOs Would Consider Paying Ransoms to Recover

🔒 A new report from Absolute Security finds that 58% of CISOs would realistically consider paying a ransom to restore systems after a ransomware attack. US respondents were likelier to consider payment (63%) than UK peers (47%), with legal guidance, GDPR and doubts over recovery cited as reasons. Operational downtime was viewed as the most damaging impact. The report warns organizations to invest in resilience, infrastructure and governance to reduce reliance on ransom payments.
read more →

NOYB Sues LinkedIn Over Paywalled 'Who Viewed' Data

⚖️ NOYB has filed a complaint in an Austrian court arguing that LinkedIn’s paywalled "Who’s Viewed Your Profile" feature violates GDPR Article 15 by denying EU users free access to profile-visitor data. The group says LinkedIn refuses Data Subject Access Requests (DSARs) from non-paying users while providing the same information to Premium subscribers. LinkedIn rejects the claim, saying it discloses the information via its Privacy Policy and that users can control visibility settings. NOYB seeks regulatory enforcement and potential fines to stop what it calls illegal monetization of access rights.
read more →

Ten Years of GDPR: Achievements, Gaps, and Next Steps

🔒 Ten years after the EU adopted the General Data Protection Regulation (GDPR), experts say it fundamentally reshaped corporate privacy culture but left important gaps. Analysts credit the GDPR with embedding privacy into daily operations, raising standards, and creating accountability by forcing organizations to know and document their processing. Yet enforcement inconsistencies, international transfer disputes, widespread consent fatigue and the rise of generative AI expose legal and practical tensions that require clarification and coordination with newer digital rules.
read more →