GRC Report Staff

APRA Maps Out a Tougher Test for Financial Resilience

APRA’s 2026-27 Corporate Plan puts cyberattacks, artificial intelligence, geopolitical tensions and dependence on common technology providers among the risks demanding closer attention from banks, insurers and superannuation trustees. The plan sets the regulator’s strategic direction for the next four years and, more immediately, its policy and supervisory agenda for the coming 12 to 18 months.

Uber Faces €825 Million Fine Over Automated Driver Deactivations in French-Dutch GDPR Case

Uber’s software could cut a driver off from the platform for suspected fraud or poor customer ratings. What it did not necessarily do first was ask a person. That has now cost the company €824.99 million.

South Korea Rethinks Privacy Rules as AI Strains the Logic of Consent

The Personal Information Protection Commission has opened a public consultation on an overhaul of the country’s privacy protection framework, a review prompted in part by the widening distance between rules built around consent and forms of data processing that have become considerably harder to explain, much less reduce to a series of yes-or-no decisions.

ACCC Takes Subaru Australia to Court Over Repair Information Access

The Australian Competition and Consumer Commission filed proceedings in the Federal Court on Friday against Subaru, accusing the company of breaching Australia’s Motor Vehicle Service and Repair Information Sharing Scheme, or MVIS.

New Zealand Passes Bill Blocking Climate Tort Claims

New Zealand’s Parliament has passed legislation barring civil tort claims over climate-change effects arising from greenhouse gas emissions, closing a potential avenue of liability for companies and other emitters.

Pokémon Center Customer Data Exposed in CEVA Logistics Cyberattack

Pokémon Center is notifying customers in the United Kingdom and Germany that personal and order information may have been exposed in a cyberattack on CEVA Logistics, the third-party provider it uses to fulfill and ship orders in those markets.

Privacy Has a Hoarding Problem

For a long time, deleting data could feel strangely reckless. Storage was cheap, and information was potentially valuable. The cost of keeping another year of customer records, internal correspondence, transaction histories or old documents was difficult to see, while the cost of deleting the wrong thing was easy to imagine. So companies kept it. Some of it was retained for legal or operational reasons, some because nobody was quite sure whether it could safely be destroyed, and some because of the most durable retention policy in corporate life: we might need it someday.