GRC Report Staff

Italian Data Protection Authority Fines Acea Energia €2 Million Over Unauthorized Energy Contracts

Italy’s data protection authority has fined energy supplier Acea Energia €2 million after an investigation found that contracts for electricity and gas services were activated without customers’ knowledge, following failures in how the company and its sales partners handled personal data.

EU Markets Enter 2026 Under Elevated Risk Pressure, ESMA Warns

A new risk monitoring report from the European Securities and Markets Authority suggests that despite resilient market performance in the latter half of last year, the conditions that could trigger market stress have not disappeared. If anything, they are becoming more complex.

Aetna to Pay $117.7 Million to Settle U.S. Allegations of Inflated Medicare Advantage Claims

Aetna has agreed to pay $117.7 million to resolve allegations that it improperly inflated payments from the federal government by submitting inaccurate diagnosis codes for certain Medicare Advantage enrollees, the U.S. Department of Justice announced Wednesday.

Lululemon Pays Penalty After ACMA Finds Hundreds of Thousands of Emails Breached Spam Rules

Athletic apparel retailer Lululemon has paid a $455,000 (AUD $702,900) penalty after Australian regulators found the company sent hundreds of thousands of emails containing marketing content without providing recipients with a way to unsubscribe.

PRA Fines UK Insurance Limited £10.6M Over Solvency II Reporting Error

The Prudential Regulation Authority has fined UK Insurance Limited £10.625 million after errors in the insurer’s Solvency II balance sheet caused it to overstate its solvency position in regulatory reporting and market disclosures.

EU Parliament Moves to Rein in AI Training on Copyrighted Content

The European Parliament has voted overwhelmingly to strengthen protections for copyrighted works used in artificial intelligence systems, signaling growing concern among lawmakers that generative AI is reshaping the economics of creative industries without clear rules for compensation or consent.

Ericsson Discloses Third-Party Data Incident After Vendor System Breach

Ericsson has begun notifying individuals that their personal information may have been exposed in a data security incident involving one of the company’s service providers.