GRC Report Staff

Disney to Pay $10 Million After DOJ Alleges COPPA Violations in YouTube Content

A federal judge has approved a $10 million settlement requiring Disney to resolve allegations that the company enabled the unlawful collection of children’s personal data through kid-directed content on YouTube, marking the latest escalation in U.S. enforcement of children’s online privacy rules.

Judge Warns CFPB Defunding Would Breach Court Order as Funding Deadline Looms

A federal judge has ruled that the Trump administration’s failure to fund the Consumer Financial Protection Bureau would violate an existing court order, according to the Economic Times, rejecting the administration’s argument that no lawful funding mechanism remains available to keep the agency operating.

Germany Warns Public Authorities Not to Treat AI Privacy as an Afterthought

The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has published new guidance aimed squarely at federal public authorities developing or using AI systems, particularly large language models (LLMs). The guide, “AI in Public Authorities – Considering Data Protection from the Outset,” is intended to help officials spot data protection issues early and take a more structured, practical approach to AI projects.

Promises of Easy Wealth Put Two U.S. Firms in Poland’s Regulatory Crosshairs

For years, pyramid schemes were thought of as a relic of the 1990s. According to Poland’s competition authority, they never really went away. They just learned new language, new platforms, and new disguises. On December 30, 2025, the President of UOKiK announced more than $6 million (over PLN 24 million) in combined fines against two U.S.-based companies, iGenius and International Markets Live, concluding that both operated prohibited pyramid-type incentive schemes.

French Regulator Hits Nexpublica With €1.7 Million Fine Over Security Failures in Social Services Software

France’s data protection authority has fined Nexpublica €1.7 million after finding that the company failed to properly secure software used to manage highly sensitive personal data in the social services sector.

Basel Committee Resets Expectations for Bank Third-Party Risk in a Digital Era

As banks lean ever more heavily on cloud providers, fintech partners, data vendors, and other external service firms, global regulators are making it clear that third-party risk can no longer be treated as a side issue. Against that backdrop, the Basel Committee on Banking Supervision has published a new set of principles aimed at reshaping how banks manage third-party risk in an increasingly digital financial system.

South Korea Launches AML Taskforce Ahead of 2028 FATF Review

The Korea Financial Intelligence Unit (Korea Financial Intelligence Unit) recently held the first meeting of a new taskforce tasked with revisiting the Act on Reporting and Using Specified Financial Transaction Information. While the meeting itself was procedural, the mandate behind it is anything but. The taskforce is meant to modernize Korea’s AML framework, sharpen responses to cross-border crime and large-scale financial fraud, and prepare the ground for South Korea’s next mutual evaluation by the Financial Action Task Force in 2028.