GRC Report Staff

EU Supervisors Warn External Dependencies, AI & Private Credit Are Testing Financial Resilience

Europe’s financial system has spent much of 2026 absorbing shocks without looking particularly shaken by them. Markets have lurched with geopolitical events and energy prices. Cyber threats have persisted. New technologies have developed faster than the institutions charged with overseeing them can comfortably digest. Through it all, European banks, insurers and investment funds have remained remarkably sturdy.

New Zealand Privacy Commissioner Orders Security Fixes After Manage My Health Cyberattack

New Zealand’s Privacy Commissioner has ordered Manage My Health and Health New Zealand to strengthen their handling of patient data, nine months after a cyberattack exposed weaknesses in the systems meant to protect some of the country’s most sensitive personal information. Commissioner Michael Webster issued separate compliance notices to the two organizations on September 23, following the first phase of his investigation into the December 2025 Manage My Health cyber incident. The inquiry found that, at the time of the attack, both organizations had failed to comply with security requirements under Rule 5 of the Health Information Privacy Code.

EU’s Simplified Sustainability Reporting Standards Become Final

More than a year after Brussels set out to make its sustainability reporting regime less burdensome, the revised European Sustainability Reporting Standards have made their way into the Official Journal. Commission Delegated Regulation (EU) 2026/1563 was published on September 21, replacing the existing ESRS annexes under Delegated Regulation (EU) 2023/2772. The regulation enters into force on November 10, 2026, and the revised standards will apply to financial years beginning on or after January 1, 2027.

Biedronka & Transport Companies Fined $150 Million Over Labor Market Collusion

For nearly seven years, transport companies serving the Polish supermarket chain agreed not to compete with one another for drivers, according to Poland’s Office of Competition and Consumer Protection, or UOKiK. Moving from one participating carrier to another could require the permission of the employer the driver was trying to leave. Without it, the driver could be kept out of the distribution center for months.

ENISA Warns Digital Dependencies Are Widening Europe’s Cyber Attack Surface

More than half of the cyber incidents recorded by the European Union’s cybersecurity agency last year were distributed denial-of-service attacks. Most were not especially damaging, but they were, however, remarkably easy to summon. A political statement, an election, a protest or another turn in the war in Ukraine could be enough. Hacktivist groups claimed 4,709 attacks against EU Member States during 2025, according to ENISA’s latest Threat Landscape report, and more than 89% involved DDoS attacks. Public administrations bore much of it.

Spanish Boards Under the Microscope in CNMV’s 2025 Governance Review

The Spanish National Securities Market Commission (CNMV) published its annual reports on corporate governance and board remuneration on September 21, drawing together disclosures submitted by listed companies for the 2025 financial year. Spain’s listed companies reported greater adherence to the country’s Good Governance Code in 2025, even as the largest companies lost some ground on a measure the code is meant to encourage: independent oversight in the boardroom.

AI Is Expanding the DPO’s Role Faster Than Organizations Are Preparing for It

A study released Tuesday by France’s data protection authority, the CNIL, alongside the French Ministry of Labour and Solidarity and the French Association of Data Protection Officers (AFCDP), found that 55% of DPOs already consider the EU AI Act part of their responsibilities. Seventy-one percent would like their role formally extended to include compliance with the regulation.