GRC Report Staff

Poland's Data Management Act Takes Effect, Reshaping Oversight of Data Sharing

Poland's Data Management Act took effect Thursday, completing a piece of legal architecture that has been waiting for its final support. The European Union's Data Governance Act has applied across the bloc since 2023. What entered into force now is the national legislation that gives the regulation a fully functioning home inside Poland's legal system.

Google Hit With €890 Million DMA Fine as EU Targets Search Bias & Play Store Restrictions

In two decisions under the European Union's Digital Markets Act (DMA), the Commission fined Google a combined €890 million, finding that the company unlawfully favored its own services in Google Search while also preventing app developers from freely steering customers toward alternative purchasing channels outside Google Play. The penalties amount to €460 million for Google's search practices and €430 million for its Play Store policies.

Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

A Chick-fil-A One account contains more than reward points. It can also hold payment methods, gift card balances, and enough personal information to make it worth trying a password that worked somewhere else. That, according to breach notification letters first reported by BleepingComputer, is what happened in June, when attackers used credentials stolen from an unrelated source to gain access to a limited number of customer loyalty accounts. The campaign did not depend on breaking into Chick-fil-A's systems. It depended on customers reusing passwords.

TAB Pays $1.76 Million After Australian Regulator Finds Widespread Telemarketing & Spam Breaches

The Australian Communications and Media Authority found that Tabcorp Holdings' wagering business repeatedly breached Australia's telemarketing rules while marketing to VIP customers. The regulator identified 351 calls made to numbers listed on the Do Not Call Register without consent, 82 calls placed outside legally permitted hours, and nearly 4,000 calls in which TAB failed to properly identify itself, the purpose of the call, or both.

Poland's Privacy Regulator Says Cybersecurity & Data Protection Can No Longer Be Treated Separately

Poland recorded roughly 270,000 cybersecurity incidents last year, according to the country's Personal Data Protection Office. That was a 150% increase over 2024. The agency says it is seeing the same trajectory in reports of personal data breaches.

ASIC Warns Auditors as It Expands Oversight of Australia's Largest Audit Firms

On Wednesday, the Australian Securities and Investments Commission wrote to every registered company auditor in the country with a reminder that reads less like routine regulatory housekeeping than a response to a profession under unusual scrutiny. Trust, ASIC told auditors, has become part of the story. That alone explains why the regulator felt compelled to restate obligations that already exist in law.

Japan Rewrites Its Corporate Governance Code With Boards, Not Box-Ticking, in Mind

Japan has revised the rulebook that shapes corporate governance for its listed companies, but the changes are less about adding new obligations than about changing how companies think about the ones they already have.