GRC Report Staff

Texas Investigates Hundreds of Data Center Developments Over Water Reporting

Texas Attorney General Ken Paxton has announced an investigation into data center developments that have not responded to the Texas Water Development Board’s Water Use Survey. His office said the investigation is ongoing and is intended to ensure data centers provide accurate, current information about their water use.

EBA Calls for MiCA Changes on Stablecoins, Crypto Lending & Classification

The European Banking Authority has urged the European Commission to use its review of the Markets in Crypto-Assets Regulation to strengthen safeguards around certain stablecoin arrangements, clarify which crypto-assets fall within the law and consider bringing crypto lending under regulatory rules. The recommendations amount to an early accounting of where Europe’s landmark crypto regime is holding and where experience has begun to expose uncertainty.

TikTok Drops Appeals and Accepts £12.7 Million UK Children’s Privacy Fine

TikTok has agreed to pay a £12.7 million fine imposed by the Information Commissioner’s Office in 2023 after the company dropped two appeals against the UK’s data protection regulator, bringing one long-running children’s privacy case to an end and allowing another to move forward.. TikTok has separately abandoned its challenge to an information notice seeking documents and details about how it processes teenagers’ personal information through its recommender systems. The first case reaches back to TikTok’s handling of children under 13, who were not supposed to be on the platform in the first place.

Czech Pet Food Distributor Fined $1.7 Million Over Retail Price Controls

For nearly a decade, retailers buying pet food and supplies from Plaček Pet Products were not entirely free to decide what those products would cost when they reached the shelf. The Czech Office for the Protection of Competition said the distributor set minimum retail prices for dog and cat food and other pet supplies from Jan. 17, 2013, through March 3, 2022, requiring its customers to follow them. The conduct has now resulted in a fine of about $1.7 million (CZK 36.438 million).

EU Supervisors Warn External Dependencies, AI & Private Credit Are Testing Financial Resilience

Europe’s financial system has spent much of 2026 absorbing shocks without looking particularly shaken by them. Markets have lurched with geopolitical events and energy prices. Cyber threats have persisted. New technologies have developed faster than the institutions charged with overseeing them can comfortably digest. Through it all, European banks, insurers and investment funds have remained remarkably sturdy.

New Zealand Privacy Commissioner Orders Security Fixes After Manage My Health Cyberattack

New Zealand’s Privacy Commissioner has ordered Manage My Health and Health New Zealand to strengthen their handling of patient data, nine months after a cyberattack exposed weaknesses in the systems meant to protect some of the country’s most sensitive personal information. Commissioner Michael Webster issued separate compliance notices to the two organizations on September 23, following the first phase of his investigation into the December 2025 Manage My Health cyber incident. The inquiry found that, at the time of the attack, both organizations had failed to comply with security requirements under Rule 5 of the Health Information Privacy Code.

EU’s Simplified Sustainability Reporting Standards Become Final

More than a year after Brussels set out to make its sustainability reporting regime less burdensome, the revised European Sustainability Reporting Standards have made their way into the Official Journal. Commission Delegated Regulation (EU) 2026/1563 was published on September 21, replacing the existing ESRS annexes under Delegated Regulation (EU) 2023/2772. The regulation enters into force on November 10, 2026, and the revised standards will apply to financial years beginning on or after January 1, 2027.