IT Security & Privacy

Croatia’s Data Protection Authority Fines Bank €1.5 Million Over Mobile Banking Privacy Violations

Croatia’s Personal Data Protection Agency has imposed an administrative fine of €1.5 million on a bank for multiple violations of the General Data Protection Regulation, following findings that the institution unlawfully collected extensive personal data from users of its mobile banking application.

Data Brokers Face Renewed Scrutiny from California Before Registration Deadline

California’s privacy regulator is sharpening its focus on data brokers that may be obscuring their identities or relying on corporate affiliations to sidestep registration requirements, as a new consumer deletion platform prepares to go live in 2026.

Privacy Concerns Persist as TikTok Continues EU Data Transfers to China

The Netherlands’ data protection authority has warned users and organizations to think carefully before continuing to use TikTok, after confirming that the platform is still transferring personal data of European users to China despite a joint finding by EU privacy regulators that such transfers are unlawful under the GDPR.

Why Governance Tools Miss What Hackers Exploit

SAP systems store sensitive business data, run mission-critical processes, and ensure that operations continue uninterrupted. However, having the SAP GRC product suite or similar governance, risk, and compliance tools does not cover all aspects of system security. Relying on them to keep you safe is a recipe for infiltration.

SoundCloud Data Breach Triggers Service Disruptions & Raises Questions About Incident Response Controls

SoundCloud has confirmed with Bleeping Computer that a recent wave of service outages and access issues stemmed from a security incident that exposed a subset of user data, as the company moved to contain unauthorized access to parts of its infrastructure.

LastPass Fined £1.2 Million After UK Data Breach Exposes 1.6 Million Users

The UK Information Commissioner’s Office (ICO) has fined password manager provider LastPass £1.2 million following a 2022 data breach that exposed the personal information of up to 1.6 million UK users, concluding that the company failed to implement sufficiently robust security measures despite offering a service designed to improve online security.

DORA Reshapes Cyber Testing as Italy Updates TIBER-IT Guide

Italy’s financial regulators are updating the rulebook on how banks, insurers, and other financial institutions stress-test their cyber defenses, as the EU’s Digital Operational Resilience Act moves from theory to day-to-day supervision.