IT Security & Privacy

California Establishes Strike Force to Police Data Brokers

California’s privacy regulator is sharpening its focus on the data broker industry, creating a new enforcement strike force to investigate how companies collect, sell, and manage personal information across the state. The effort marks one of the agency’s most concentrated pushes yet to bring more visibility, and accountability, to a sector often operating out of public sight.

DoorDash Confirms Data Breach After Employee Falls for Social Engineering Scam

DoorDash has disclosed a data breach after a social engineering scam tricked one of its employees, allowing an unauthorized party to access user information across its platform. The company says the exposed data included names, email addresses, phone numbers, and physical addresses, though it declined to say how many people were affected.

California Advances Delete Act Regulation to Bring One-Click Data Deletion to Millions

Californians are about to gain one of the most sweeping digital privacy tools in the country. The California Privacy Protection Agency (CalPrivacy) confirmed at last week’s Board meeting that the state’s Office of Administrative Law has approved regulations to implement the Delete Act, a move that paves the way for a single-click mechanism allowing residents to wipe their personal information from hundreds of data brokers.

New Zealand Faces Rising Privacy Risks as Regulator Pushes for a Modern Privacy Act

‍New Zealand’s privacy regulator is sounding the alarm as privacy complaints and serious breach notifications surge across the country. In its latest Annual Report, the Office of the Privacy Commissioner warned that New Zealanders’ rising anxiety about personal data isn’t just theoretical anymore, it reflects a real increase in harm.

UK Tightens Cyber Defenses with New Bill Targeting Critical Infrastructure & Supply Chains

After a bruising year of cyber incidents that exposed the fragility of the UK’s digital defenses, the government has presented its long-awaited Cyber Security and Resilience Bill to Parliament, a huge step intended to move the country from guidance to enforcement in its approach to cyber risk.

Washington Post Confirms Data Breach Linked to Oracle E-Business Hacks

The Washington Post has confirmed that it was among the organizations affected in a broader hacking campaign exploiting vulnerabilities in Oracle’s E-Business Suite, a set of corporate software tools widely used to manage HR systems, business operations, and sensitive internal data.

Australia’s Information Commissioner Highlights Progress on Privacy & Access Rights

Australia’s privacy and information rights regulator says it made meaningful strides in enforcement, transparency, and public trust over the past year, according to the Office of the Australian Information Commissioner’s (OAIC) newly released Annual Report for 2024–25.