IT Security & Privacy

EDPB Tackles Blockchain Privacy Challenges & Prepares to Weigh In on AI Act

The European Data Protection Board (EDPB) is stepping into the blockchain arena with new guidance aimed at helping organizations navigate the thorny intersection of distributed ledger technology and EU privacy law. In its April plenary, the Board officially adopted guidelines on the processing of personal data via blockchain, and signaled it’s ready to collaborate with the newly established EU AI Office on upcoming guidance around the AI Act.

CNIL Strengthens Global Personal Data Protection Framework & Strategy for 2025-2028

The Commission Nationale de l'Informatique et des Libertés (CNIL) has just rolled out an ambitious strategy aimed at tackling the increasingly complex world of personal data protection. As digital spaces grow, data flows faster, and technology advances at a breakneck pace, the CNIL’s new plan for 2025-2028 aims to take the lead—not just in France or Europe, but globally—in safeguarding personal data.

Italian Data Protection Authority Investigates Lusha Over Alleged Privacy Breaches

Italy’s Personal Data Protection Authority (Garante) has launched an investigation into Lusha Systems, a US-based company that’s no stranger to controversy in the world of online data. Known for selling “enriched” contact details, including email addresses and phone numbers, Lusha’s services are accessible to users in Italy, though it seems some of the data within its platform might not be as straightforward as one would hope.

Legacy Vulnerabilities & the Consequences of the Oracle Breach

In March 2025, Oracle faced two major breaches, with its Cloud system exposing millions of records and its Health platform compromising patient data due to unpatched legacy servers exploited since January. The company’s delayed notifications and lack of transparency, despite allegedly knowing about the issues by February, have drawn sharp criticism and fueled distrust. The breaches have sparked widespread concern, prompting heightened oversight and discussions among key regulatory bodies.

Diving into the X Data Breach: Over 200 Million User Records Exposed

X, the social media platform formerly known as Twitter, has always been a breeding ground for debates, discussions, and, lately, a fair amount of drama. Elon Musk, ever the spokesperson for the platform, recently warned about hackers trying to infiltrate the site. But it’s one thing to worry about abstract threats and quite another to find out that your personal data might be at risk because of a real and massive breach.

Apple Fined €150 Million for Abusing Dominant Position with App Tracking Transparency Framework

The Autorité de la concurrence, France’s competition watchdog, has slapped Apple with a hefty €150 million fine. The reason? Apple’s handling of its App Tracking Transparency (ATT) framework, which the French authority argues unfairly tipped the scales in favor of Apple, harming smaller players in the digital ecosystem.

PIPC Slaps Woori Card with Over $9.1 Million Fine for Data Breach

South Korea’s Personal Information Protection Commission (PIPC) has hit Woori Card with a massive fine of KRW 13.45 billion (roughly $9.1 million) following a major data breach. This decision comes alongside a set of corrective measures designed to overhaul the company’s data management practices, including stricter access controls, better employee training, and tighter oversight of personal information handling.