IT Security & Privacy

Finnish DPA Fines Online Retailer €856K Over Indefinite Data Storage

Finland's data protection authority has imposed an €856,000 fine on e-commerce company Verkkokauppa.com for violating the GDPR by failing to define retention periods for customer account data and requiring users to register accounts to make online purchases.

Hellenic Post Services S.A. Faces GDPR Fine for Data Breaches

Hellenic Post Services S.A. (ELTA S.A.), a prominent postal service provider in Greece, has been fined by the Hellenic Supervisory Authority (SA) for failing to implement adequate technical and organizational measures, leading to unauthorized access by third parties and subsequent data breaches. The final decision, issued on February 28, 2024, highlights critical lapses in compliance with GDPR principles regarding the integrity and confidentiality of personal data and the security of processing.

Staffing Company Agrees to $2.7M Settlement for Alleged Cybersecurity Lapses in COVID-19 Contact Tracing

Insight Global LLC, a prominent staffing firm headquartered in Atlanta, has reached a $2.7 million settlement to resolve allegations of violating the False Claims Act due to inadequate cybersecurity measures during COVID-19 contact tracing efforts. The settlement, announced by the Department of Justice (DOJ), marks a significant step in ensuring government contractors fulfill their cybersecurity obligations, particularly in handling sensitive health information.

Kaiser Permanente Reports Major Data Breach Affecting 13.4 Million Patients

Kaiser Permanente, one of the nation's largest not-for-profit health plans, has disclosed a major data breach impacting the personal information of 13.4 million members.

ChatGPT Faces Privacy Complaint in Austria Over Alleged GDPR Violations

OpenAI, the company behind the wildly popular AI chatbot ChatGPT, is facing a privacy complaint in Austria over alleged violations of the European Union's General Data Protection Regulation (GDPR).

Fortifying Cyber Defenses: A Mandate for State & Local Governments

The cybersecurity landscape is a battleground, and state and local governments find themselves on the frontlines. Cyber threats loom larger than ever, escalating in frequency and sophistication as we progress through 2024. While high-profile breaches often dominate headlines, state and local agencies are not exempt from the relentless barrage of attacks aimed at compromising sensitive citizen data and disrupting critical operations. This pivotal moment demands decisive action to fortify data privacy and security measures.

Czech DPA Slaps Avast with $15M Fine for GDPR Violations

The Czech data protection authority imposed a whopping 351 million CZK fine on Avast Software, a cybersecurity firm, for unlawfully sharing personal data of millions of its antivirus users with a subsidiary company.