GRC Report Staff

EDPB Sets Five-Step Method for GDPR Fines & Finalizes DSA Privacy Guidelines

Europe’s data protection authorities have never lacked ways to punish a GDPR violation. They can warn an organization, reprimand it, order it to change what it is doing, restrict its processing or stop that processing altogether. And, of course, they can fine it. What has been less settled is how an authority should decide among those choices.

ASIC Finds Climate Disclosures Improving Under Australia’s New Sustainability Reporting Rules

ASIC has found an improvement in climate-related financial disclosures under Australia’s new mandatory sustainability reporting regime, although the regulator says companies still have work to do on some of the disclosures that demand the most judgment. The Australian Securities and Investments Commission reviewed a sample of 40 sustainability reports lodged for financial years ending Dec. 31, 2025. Its findings provide an early picture of what mandatory reporting has changed after years in which companies largely disclosed climate information voluntarily.

Amway, Affiliates Agree to $225 Million Settlement Over FTC, Washington Deception Allegations

Amway and two of its largest affiliates have agreed to a $225 million judgment to resolve allegations that they used unfair and deceptive practices to recruit people into Amway's multilevel marketing business and keep them buying products once they were there. Nearly all of the money would go to participants who lost money after being recruited by the two affiliates, World Wide Group LLC and Leadership Team Development Inc.

KPMG Survey Finds Cyberattacks Rising as CISOs Grapple With AI & Complexity

Cyberattacks increased at 83% of large U.S. organizations over the past year, according to a recent KPMG survey, even as companies poured more money into artificial intelligence and expanded the responsibilities of the executives charged with keeping their systems secure.

Irish DPC Fines Google €403 Million Over Location Data Processing

Ireland’s Data Protection Commission has fined Google €403 million over its processing of location data, concluding an investigation that began in 2020 and reached back to the first day the GDPR took effect.

DOJ Revises False Claims Act Enforcement Policies

The Justice Department has revised its enforcement policies under the False Claims Act, restoring restrictions on the use of agency guidance in litigation and instructing government attorneys to consider whether whistleblower lawsuits should be dismissed when DOJ declines to join them.

EBA Finalizes Third-Party Risk Guidelines With Focus on Critical Functions

The European Banking Authority has finalized its Guidelines on third-party risk management, concentrating the new framework on the outside relationships that matter most when something goes wrong.