GRC Report Staff

FCA Censures CACEIS UK Over WealthTek Failures, Secures £31.7 Million for Clients

Three times, CACEIS UK checked the Financial Services Register. Three times, it was presented with information showing that WealthTek lacked permission to hold certain client assets. Nothing happened that altered the course of the relationship. According to an enforcement action the UK's Financial Conduct Authority published Thursday, concluding that the asset servicing bank failed to respond appropriately to repeated warning signs while acting as WealthTek's sub-custodian.

Greek Privacy Regulator Orders Hotels to Stop Copying Guest IDs & Payment Cards

Hotels have always occupied an awkward place in the privacy conversation. They are, by necessity, temporary custodians of strangers. Every day, people hand over names, identification, payment details, travel plans, and, for a night or a week, a remarkable amount of trust. The transaction has always depended on a simple understanding that you collect what you need, protect it while you have it, and let it go when you no longer do. Somewhere along the way, some establishments decided that making copies of passports, identity cards, and even both sides of customers' credit cards was simply part of doing business.

Italy Fines Deghi €2 Million Over Misleading Countdown Discounts

A clock counting down to the end of a sale carries an implicit promise—buy now or the opportunity disappears. The Italian Competition Authority says Deghi made that promise over and over again without ever intending to keep it. The regulator has fined the Italian home furnishings and e-commerce retailer €2.0 million ($2.3 million) after concluding that the company systematically misled consumers by presenting discounts as fleeting when they were anything but.

Europe Signals Its Cloud Crackdown May Be About to Get Much Bigger

The European Commission has taken a step that would have seemed improbable when the Digital Markets Act first came into force. It has told Amazon and Microsoft that it preliminarily believes their cloud businesses (Amazon Web Services and Microsoft Azure) should be designated as gatekeepers under the DMA, even though neither service meets the law's standard quantitative thresholds.

UK Auditors Face New Controls Disclosure Requirements Under Revised FRC Standards

Auditor's reports have a habit of growing the way old rulebooks do. Every new requirement leaves its mark. Every reform adds another paragraph. Every perceived gap is filled with another disclaimer, another explanation, another carefully calibrated sentence until the document intended to illuminate a company's financial statements begins to obscure them instead. By the time investors reach the end, they often know they have read a great deal without feeling they have learned very much.

Chemours Agrees to $450 Million PFAS Settlement Across Three States

For more than a decade, federal regulators say, PFAS left Chemours facilities in West Virginia, North Carolina, and New Jersey and entered three of the country's major rivers. On Wednesday, that alleged history of contamination produced one of the most consequential enforcement actions yet against a manufacturer of the so-called "forever chemicals."

European Insurers Hold Firm as EIOPA Warns Next Risks May Be Harder to Measure

European insurers and occupational pension funds entered 2026 from a position most financial regulators would envy. Markets lurched in response to geopolitical shocks. Trade relationships continued to shift. Investors repriced risk. Yet the core indicators supervisors watch most closely (capital, liquidity and solvency) held up remarkably well. That is what the European Insurance and Occupational Pensions Authority's latest Financial Stability Report, published Wednesday. It is also, in many ways, the easy part of the story.