IT Security & Privacy

EPA Gives Water Utilities New Tools to Confront Cybersecurity Risks

As cyber threats continue to test the resilience of U.S. water systems, the Environmental Protection Agency is rolling out new resources to help utilities strengthen digital defenses and keep safe water flowing.

Norwegian Court Upholds Fine Against Adult Dating App Over Data Privacy Violations

Norway's Borgarting Court of Appeal has upheld the $6 million (NOK 65 million) fine against Grindr, ruling that the company unlawfully shared users’ personal data with advertisers without valid consent. The decision, handed down on Tuesday, confirms earlier findings by the Norwegian Data Protection Authority (Datatilsynet) and the Oslo District Court that Grindr breached EU data protection law.

Capita Fined £14 Million for 2023 Data Breach Affecting 6.6 Million People

The UK Information Commissioner’s Office (ICO) has fined outsourcing giant Capita and its pensions subsidiary a combined £14 million for failing to protect personal data in a 2023 cyberattack that exposed the information of 6.6 million people.

EDPB Turns to Transparency for Its 2026 GDPR Enforcement Push

Europe’s data regulators are turning the spotlight on transparency, one of the GDPR’s most fundamental principles. During its October plenary, the European Data Protection Board (EDPB) agreed that its 2026 Coordinated Enforcement Framework (CEF) action will focus on how well organizations are informing people about the use of their personal data under Articles 12, 13, and 14 of the regulation.

Auto Insurers Hit with $19 Million in Penalties After DFS Cybersecurity Probe

Eight major auto insurance companies have agreed to pay more than $19 million in penalties to New York State following a sweeping cybersecurity investigation by the Department of Financial Services (DFS). The enforcement action, announced Tuesday by Superintendent Adrienne A. Harris, revealed failures in data security controls that exposed the personal information of New Yorkers through online insurance quoting systems.

Australian Privacy Commissioner Puts Social Media Platforms on Notice with New Guidance

Australia’s privacy regulator has reminded social media companies that privacy must remain front and center as new age restrictions come into force later this year. The Office of the Australian Information Commissioner (OAIC) on Friday published regulatory guidance for age-restricted social media platforms and age assurance providers under the forthcoming Social Media Minimum Age (SMMA) scheme, which begins on December 10.

Australian Clinical Labs Ordered to Pay $3.8 Million Over Medlab Data Breach

Australia just crossed a major privacy enforcement milestone. The Federal Court has ordered Australian Clinical Labs (ACL) to pay $3.8 million (AUD $5.8 million) in penalties after a cyberattack on its Medlab Pathology business exposed the personal information of more than 223,000 individuals.