GRC Report Staff

Clorox Faces $5.2 Million Penalty Over Misleading 'Ocean Plastic' Claims

Clorox Australia has recently been hit with an AUD $8.25 million ($5.2 million USD) penalty for making false statements about the composition of its GLAD products. The Federal Court’s ruling marks the end of a legal battle that began after the Australian Competition and Consumer Commission (ACCC) uncovered misleading claims about GLAD Kitchen Tidy Bags and Garbage Bags being made from recycled ‘ocean plastic.’

OCC Email Breach Prompts JPMorgan & BNY Mellon to Curb Data Sharing

It’s not every day that major banks start treating a federal regulator like a cybersecurity risk. But after a quiet email breach inside the Office of the Comptroller of the Currency (OCC) stretched on for more than a year undetected, JPMorgan Chase and Bank of New York Mellon have decided to pump the brakes on how much sensitive information they’re sending.

U.S. Organizations Struggle to Manage Growing Risk and Resilience Challenges, According to Recent KPMG Survey

A recent survey from KPMG last month paints a sobering picture of the state of risk management in U.S. organizations. Despite heightened awareness of increasing risks and disruptions, more than half of U.S. organizations are still struggling to integrate proper risk and resilience capabilities. The survey, which gathered insights from 208 C-suite leaders, reveals that 52% of companies have not yet built the necessary organizational structures to effectively manage risk and resilience.

CNIL Strengthens Global Personal Data Protection Framework & Strategy for 2025-2028

The Commission Nationale de l'Informatique et des Libertés (CNIL) has just rolled out an ambitious strategy aimed at tackling the increasingly complex world of personal data protection. As digital spaces grow, data flows faster, and technology advances at a breakneck pace, the CNIL’s new plan for 2025-2028 aims to take the lead—not just in France or Europe, but globally—in safeguarding personal data.

Europe Faces Rising Financial Crime Threats, Reports Show

The shadow of financial crime looms larger than ever over Europe, as a new special edition of the 2024 Global Financial Crime Report sheds light on the vast scale of illicit activity across the region. This report dives deep into the financial crime landscape of Europe, with a specific focus on the European Union (EU), the United Kingdom (UK), and the Nordic countries. The findings paint a sobering picture of the challenges ahead, with billions of dollars flowing through illicit channels that pose a significant threat to both financial institutions and society as a whole.

Ireland Opens Probe into X’s Use of Public Posts to Train AI Chatbot Grok

Ireland’s privacy watchdog has questions, and they’re pointed squarely at Elon Musk’s X. On Thursday, the Irish Data Protection Commission (DPC) announced the launch of a formal inquiry into X Internet Unlimited Company (XIUC), the newly named data controller for X’s EU user base. The central issue? Whether publicly accessible posts by European users have been quietly fed into the company’s generative AI system, Grok, without proper legal basis.

Italian Data Protection Authority Investigates Lusha Over Alleged Privacy Breaches

Italy’s Personal Data Protection Authority (Garante) has launched an investigation into Lusha Systems, a US-based company that’s no stranger to controversy in the world of online data. Known for selling “enriched” contact details, including email addresses and phone numbers, Lusha’s services are accessible to users in Italy, though it seems some of the data within its platform might not be as straightforward as one would hope.