Samuel Rasmussen

Unraveling Third-Party Risks & IT Security Challenges: Lessons from Toyota's Third-Party Data Breach

In an era where data is often described as the new oil, Toyota, one of the world's largest automakers, finds itself again grappling with the consequences of a significant data leak. The incident, involving the exposure of 240GB of sensitive information, brings to the forefront the complex challenges of managing cybersecurity in a digitally interconnected business ecosystem.

Uber Fined €290 Million by Dutch DPA for Data Transfers to the U.S.

The Dutch Data Protection Authority (DPA), in cooperation with the French data protection authority CNIL, has imposed a colossal €290 million fine on Uber B.V. and Uber Technologies Inc. The penalty, announced on August 26, 2024, stems from Uber's unauthorized transfer of European drivers' personal data to the United States without implementing sufficient safeguards—a violation of the General Data Protection Regulation (GDPR).

Texas AG Sues GM Over Alleged Unlawful Collection & Sale of Driver Data, Raising Compliance Concerns

Texas Attorney General Ken Paxton has filed a lawsuit against industry titan General Motors (GM) over the company's alleged unlawful collection and sale of driver data. This action comes as part of a broader data privacy and security initiative launched by Paxton to aggressively enforce Texas privacy laws.

Survey Reveals Compensation Trends for Chief Compliance Officers Across Various Sectors

The latest survey conducted by BarkerGilmore provides a revealing look into the compensation trends for Chief Compliance Officers (CCOs) across public companies, private companies, and non-profit organizations. As compliance professionals navigate an increasingly complex regulatory environment, understanding these compensation patterns offers valuable insight into the evolving priorities of organizations across various sectors.

The European Union AI Act Has Come Into Effect: A New Regulatory Landscape for Organizations

In a landmark development, the European Artificial Intelligence Act (AI Act), the world's first comprehensive AI regulation, has come into force this past Thursday. This legislation marks a pivotal shift in how artificial intelligence is governed, not only within the European Union but also on the global stage. For compliance professionals, the AI Act introduces a robust framework that necessitates a proactive and strategic approach to AI governance, risk management, and ethical considerations.

Compliance Revolution: Labour's Ambitious Regulatory Agenda

The recent King's Speech, delivered by King Charles III on behalf of Sir Keir Starmer's newly elected Labour government, heralds a transformative period for UK businesses and compliance professionals. This ambitious legislative program, reminiscent of Labour's sweeping reforms in 1997, promises to reshape the regulatory landscape across multiple sectors, demanding a strategic overhaul of compliance practices nationwide.

Massive Global IT Outage Highlights Fragility of Digital Infrastructure

A global technology outage caused by a faulty software update grounded flights, knocked media outlets offline, and disrupted hospitals, small businesses, and government offices on Friday. This incident highlighted the fragility of a digitized world dependent on a few key providers. At the heart of the massive disruption was CrowdStrike, a cybersecurity firm that provides software to thousands of companies worldwide.