The UK Information Commissioner's Office (ICO) has fined the service provider Capita £14 million. The reason: inadequate security measures, which led to a massive hacker attack in March 2023.
The importance of complying with cookie consent requirements under the GDPR and ePrivacy Directive was also emphasized upon by other national authorities. On September 1st 2025, France’s data protection authority (CNIL) fined...
The UK’s Information Commissioner’s Office (ICO) has fined Advanced, a leading IT services provider, £3.07 million for failing to protect sensitive data, following a major ransomware attack in 2022. The breach...
The Irish Data Protection Commission (DPC) has issued a staggering €310 million fine to LinkedIn Ireland, marking the highest GDPR penalty of the year, issued in October. This penalty resulted...
The Advanced Computer Software Group Ltd has failed to implement measures to protect personal data of almost 83’000 individuals, which also included sensitive data. It is assumed that this was possible through a hacker attack in August 2022...
Following complaints lodged by 170 French Uber drivers with the French human rights organization Ligue des droits de l'Homme et du citoyen (LDH), the LDH lodged a class action complaint with the French Data Protection Authority...
It is now less than three months before the Digital Services Act (DSA) becomes effective on February 17, 2024, which was originally introduced to keep tech giants like Meta and Google...
The technical aspect of data protection is often overlooked by Data Controllers who are most likely to focus on the legal aspects of the issue and fail...
Topic of a previous newsletter was the New EU – US Data Privacy Framework (“DPF”) which would act as remedy for the abolition of the “Privacy Shield” in 2020 and facilitate data transfers from and to the United States....