GRC Report Staff

TikTok Under Fire Again as Irish Regulator Probes China Data Storage

TikTok is once again in the crosshairs of Ireland’s privacy watchdog after it admitted to storing some European user data on servers in China, contradicting what it had previously told regulators.

EBA Targets Greenwashing in Retail Banking With Overhaul of Product Governance Guidelines

The European Banking Authority (EBA) has recently announced that it is launching a public consultation to revise its long-standing Guidelines on Product Oversight and Governance (POG). The revisions would, for the first time, formally incorporate ESG-related risks into how financial products are designed, marketed, and reviewed without, the EBA insists, adding unnecessary red tape.

CVS Hit with Nearly $950 Million Judgment in False Claims Case Over Omnicare Drug Billing

A federal judge has ordered CVS Health to pay nearly $950 million in penalties and damages after its Omnicare unit was found to have illegally billed government healthcare programs for prescription drugs that weren’t properly authorized. The massive award stems from a whistleblower case that uncovered years of fraudulent dispensing practices tied to more than 3.3 million false claims.

Harman Hit with $1.45 Million Penalty Over Iran Sanctions Breaches Tied to Overseas Sales Team

Harman International Industries, the U.S.-based electronics company behind well-known audio brands, has agreed to pay $1.45 million to settle apparent violations of U.S. sanctions on Iran—violations that, according to regulators, were knowingly enabled by the company’s overseas staff and overlooked due to a lack of internal controls.

Qantas Data Breach Hits Millions as OAIC Confirms Notification Requirement

Qantas is investigating a cyber incident that exposed the personal information of customers stored on a third-party platform used by one of its contact centres. The breach, first detected earlier this week, has affected records tied to up to 6 million customers.

Bank of England Fines Vocalink £11.9 Million in First-Ever Enforcement Action Against a Market Infrastructure Firm

The Bank of England has recently fined Vocalink Limited £11.9 million for failing to comply with a formal direction aimed at strengthening its risk and control framework, marking the first time the central bank has levied a fine against a financial market infrastructure firm under the Banking Act 2009.

DOJ Unveils Whistleblower Rewards Program to Tackle Antitrust Fraud

The U.S. Department of Justice’s Antitrust Division recently announced a new Whistleblower Rewards Program in partnership with the United States Postal Service. The initiative marks the first time the Antitrust Division will offer financial incentives to individuals who report antitrust crimes and related offenses — with potential rewards reaching up to 30% of the criminal fines recovered in applicable cases.