IT Security & Privacy

French Regulator Hits Nexpublica With €1.7 Million Fine Over Security Failures in Social Services Software

France’s data protection authority has fined Nexpublica €1.7 million after finding that the company failed to properly secure software used to manage highly sensitive personal data in the social services sector.

Coupang Offers $1.18 Billion in Vouchers After Data Breach

South Korean e-commerce giant Coupang has announced a compensation package worth $1.18 billion (SKW 1.69 trillion), according to Reuters, for users affected by one of the country’s largest data breaches, but the plan has quickly become the latest flashpoint in an escalating political and regulatory backlash.

University of Phoenix Breach Tied to Oracle Zero-Day Exposes Data of Nearly 3.5 Million People

The University of Phoenix has confirmed that a cyberattack linked to a previously unknown software flaw has compromised the personal and financial data of nearly 3.5 million individuals, marking one of the largest education-sector breaches disclosed this year.

When Data Becomes a Product: Privacy, Cybersecurity, & the Economics of Information

Data is a constant subject of discussion in the context of security. Custody of personal data is heavily regulated, and systems are designed to protect anonymity, even though it can never be fully guaranteed. Security breaches are costly, not only because of the breach itself, but because of the scrutiny and liability that follow. As a result, privacy has increasingly become a value proposition for products and services that collect and retain personal information.

CNIL Fines Mobius Solutions €1 Million Over Deezer Data Breach

France’s data protection authority has fined Mobius Solutions €1 million after finding that the company, acting as a processor for music-streaming platform Deezer, failed to comply with core GDPR obligations tied to subcontracting and data handling.

Croatia’s Data Protection Authority Fines Bank €1.5 Million Over Mobile Banking Privacy Violations

Croatia’s Personal Data Protection Agency has imposed an administrative fine of €1.5 million on a bank for multiple violations of the General Data Protection Regulation, following findings that the institution unlawfully collected extensive personal data from users of its mobile banking application.

Data Brokers Face Renewed Scrutiny from California Before Registration Deadline

California’s privacy regulator is sharpening its focus on data brokers that may be obscuring their identities or relying on corporate affiliations to sidestep registration requirements, as a new consumer deletion platform prepares to go live in 2026.