Back to Feed

Tag

Compliance

GDPR, NIS2, SEC rules, regulatory frameworks

58 items tagged #compliance

Articles

APD/GBA (Belgium) - 101/2026

Belgian DPA fines tech company €176,946.61 for unlawfully retaining contractor's email account after departure.

The Next Cybersecurity Challenge May Be Verifying AI Agents

Industry develops verification standards for autonomous AI agents operating in enterprise systems.

NAIH (Hungary) - NAIH-3344-1/2026

Hungarian DPA fines university HUF 1.5M for excessive data processing in dormitory admissions.

AP (The Netherlands) - Decision of 11 December 2023 imposing administrative fine on Uber

Dutch DPA fines Uber €10M for lacking transparency and failing data subject rights access.

BVwG - W171 2303402-1/7E

Austrian court upholds DPA order requiring ORF to redesign cookie banner for equal consent options.

AP (The Netherlands) - 2025-005323

Dutch DPA finds Yango app unlawfully transferred EEA user data to Russia without proper safeguards

CE - N. 433539

French Supreme Administrative Court strikes down ARCOM copyright enforcement decree for lacking GDPR safeguards on

AEPD (Spain) - EXP202408867

Spain's AEPD fined sports retailer €120K for data breach affecting 300K+ people

BVwG - W171 2303402-1/7E

Austrian court upholds DPA order requiring ORF to redesign cookie banner with equivalent consent options.

Microsoft and Adobe Patch Tuesday, May 2026 Security Update Review

Microsoft patches 137 vulnerabilities including 30 critical; Adobe addresses 52 vulnerabilities with 27 critical in May

BVwG - W171 2303402-1/7E

Austrian court upholds DPA order requiring ORF to redesign cookie banner with balanced consent options.

‼️🇧🇷 MBet allegedly breached exposing 200,000+ KYC documents and 300,000+ PII records from the...

MBet Brazilian betting platform allegedly breached exposing 200K+ KYC docs and 300K+ PII records

AP (The Netherlands) - 2025-005323

Netherlands DPA finds GDPR violations in data transfers to Russia via inadequate safeguards

OLG Stuttgart - 4 U 353/24

German appeals court partially upholds GDPR data subject rights against social media company tracking via third-party

AP (The Netherlands) - 2025-005323

Netherlands DPA fines Yandex €100M for unlawful data transfers to Russia without adequate safeguards.

AP (The Netherlands) - 2025-005323

Dutch DPA fines Yango €100M for unlawful data transfers to Russia without safeguards.

GM agrees to $12.75M California settlement over sale of drivers’ data

GM settles $12.75M California CCPA violation over illegal sale of drivers' location and behavior data.

Why Changing Passwords Doesn’t End an Active Directory Breach

Password resets alone don't remove attackers from AD; cached credentials and Kerberos tickets enable persistence.

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room

Purple team security model fails due to process friction, tool fragmentation, and inability to match AI-powered

AEPD (Spain) - EXP202408867

AEPD fines Spanish sports retailer €120K for data breach affecting 300K+ customers

Google Chrome Accused of Silently Installing 4GB AI Model on User Devices

Google Chrome silently installs 4GB Gemini Nano AI model without user consent.

Before the Breach, There Was a Test Environment

QA and test environments pose production-grade security risks through misconfigurations and excessive permissions.

BVwG - W298 2323263-1/11E

Austrian court rules company violated GDPR by recording client conversation without prior informed consent.

FTC to ban data broker Kochava from selling Americans’ location data

FTC bans data broker Kochava from selling location data without explicit consumer consent.

The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.

SCA tools miss vulnerabilities in EOL software; 5.4M EOL package versions lack CVE coverage.

TS - 1590/2026

Spanish Supreme Court upholds GDPR data minimisation ruling against penitentiary authority over excessive medical data

LinkedIn locks your GDPR rights behind a paywall

LinkedIn paywalls GDPR Article 15 access to profile visitor data despite monetizing it.

Disneyland Now Uses Face Recognition on Visitors

Disney deploys face recognition at Disneyland; NSA tests Anthropic's Mythos AI tool; Scattered Spider member arrested.

‼️🇨🇦 Questrade, a Canadian financial services company offering online investing and trading pla...

Questrade breach exposes 186,515 investor records offered for sale by ijpys.

Tietosuojavaltuutetun toimisto (Finland) - TSV/5875/2024

Finland DPA reprimands insurance company for e-invoice system lacking check digit verification, exposing customer data

No action taken against PimEyes: noyb lawsuit against Hamburg DPA

noyb sues Hamburg DPA for inaction against PimEyes facial recognition engine collecting billions of biometric data.

AEPD (Spain) - EXP202404507

Spanish DPA fines bank €400K for CCTV access via shared credentials violating GDPR Article 32.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Poste Italiane and PostePay €12.5M for unlawful malware detection data collection.

APD/GBA (Belgium) - 86/2026

Belgian DPA fines employer €8,500 for unlawfully retaining former employee email and accessing private communications.

CE - 482872

French court upholds €40M GDPR fine against Criteo for cookie consent violations.

CNIL (France) - SAN-2025-014

CNIL fines Mobius Solutions €1M for data retention, unauthorized processing, and record-keeping failures.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Poste Italiane and PostePay €12.5M for unlawful malware detection data processing.

AEPD (Spain) - EXP202406208

Spain's AEPD fined EVO Banco €240K for API vulnerability causing 1.27M data breach.

Cyber Insurance Data Gives CISOs New Ammo for Budget Talks

Cyber insurance data links security failures to financial losses, helping CISOs justify budgets to boards.

CNIL (France) - SAN-2025-011

CNIL fines American Express Carte France €1.5M for cookie consent violations.

VG Wiesbaden - 6 K 996/22.WI

German court rules payment service illegally processed sensitive health and sexual data without lawful basis.

AEPD (Spain) - EXP202406208

Spain's AEPD fines EVO Banco €240K for API vulnerability exposing 1.27M customers' data.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Italian Post and PostePay for unlawful device data access via Bancaposta and PostePay apps.

82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected

82 Chrome extensions found selling user data to third parties, affecting 6.5M users.

Garante per la protezione dei dati personali (Italy) - 9870014

Italian DPA fines Ediscom €300K for GDPR violations in marketing data collection.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Poste Italiane and PostePay €12.5M for GDPR violations in device data collection.

AEPD (Spain) - EXP202404507

Spanish DPA fines bank €400K for CCTV system shared credentials violating GDPR Article 32.

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator

US launches crackdown on Southeast Asian cyberscam operations, sanctions Cambodian senator and 28 others.

Microsoft to roll out Entra passkeys on Windows in late April

Microsoft rolls out Entra passkeys on Windows in late April for phishing-resistant authentication.

DORA and operational resilience: Credential management as a financial risk control

DORA Article 9 mandates credential management and MFA for EU financial institutions.

Events

Tips & tricks