GRC Report Staff

Terry Grafenstine Takes Helm of IIA Global Board, Puts Spotlight on Tech-Driven Risk Management

The Institute of Internal Auditors (IIA) has appointed Terry Grafenstine as the new Chair of its global board of directors, a decision announced during the organization's annual business meeting and 2024 International Conference held in Washington, DC last week. Grafenstine will serve a two-year term, bringing a wealth of experience to the role.

Massive Australian Health Data Breach: 12.9 Million Records Sold on Dark Web

In one of the largest data breaches in Australian history, cybersecurity experts confirm that highly sensitive health data of 12.9 million Australians, stolen from eScripts provider MediSecure, has been sold on the dark web and is now being offered for resale.

Australian Regulator Issues $10.7 Million Fine to OnePath Custodians for Compliance Breaches

The Australian Prudential Regulation Authority (APRA) has taken action against OnePath Custodians Pty Limited (OPC), a major player in Australia's superannuation industry, for alleged breaches of the Superannuation Industry (Supervision) Act 1993 (SIS Act).

South Korea Issues Detailed Guidelines for Foreign Companies on Data Protection Compliance

The Personal Information Protection Commission (PIPC) of South Korea has released comprehensive guidelines titled "Guidelines on Applying the Personal Information Protection Act to Foreign Business Operators." These guidelines aim to help foreign companies navigate and comply with South Korea's Personal Information Protection Act (PIPA), particularly in light of major amendments made to the law in 2023.

European Data Protection Authorities Crack Down: Dutch Pharmacy Chain and Telecom Giant Face GDPR Sanctions

Data protection authorities across Europe continue to enforce GDPR regulations, with recent actions targeting both a major Dutch retailer and a telecommunications company in Spain.

Verizon Subsidiary Hit with $16M FCC Fine Over API Security Lapses

TracFone Wireless has agreed to pay $16 million to settle Federal Communications Commission (FCC) investigations into a series of data breaches that exposed customer information. The settlement, announced on July 22, 2024, highlights growing concerns over API security in the telecommunications industry.

Global Regulators Outline Vision for Competitive AI Landscape

Competition authorities from the European Union, United Kingdom, and United States have recently issued a joint statement outlining their commitment to ensuring fair competition in the rapidly evolving field of generative AI. The statement, signed by top officials from the European Commission, UK Competition and Markets Authority, US Department of Justice, and US Federal Trade Commission, signals a coordinated approach to tackling potential risks in the AI ecosystem.