Privacy Headlines
14 headlines in the database.
DataBreaches.net · 10/3/2026
The following is a machine translation of a press release by Italy’s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a... Source
DataBreaches.net · 9/26/2026
Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Agency breach. A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for a $2.3 million fine and a promise of sweeping data security reforms in the wake of a 2019 data... Source
The Record · 9/25/2026
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
EDPB News · 9/23/2026
Background information Date of final decision: 21 September 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) and Article 13 (Information to be provided where personal data are collected from the data subject) Decision: Administrative fine, compliance order Key words: GDPR enforcement, technology, accountability, data subjects rights Summary of the Decision Origin of the case The Irish Data Protection Commission (DPC) has announced its final decision following an inquiry into Google Ireland Limited (Google). This own-volition Inquiry was launched by the DPC, in its role as the Lead Supervisory Authority for Google, in February 2020, following receipt of complaints from several European consumer rights organisations, including BEUC, regarding Google’s processing of location data in
BleepingComputer · 9/22/2026
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
EDPB News · 9/22/2026
Background information Date of final decision: 1 February 2023 National case Controller: SECURITAS DIRECT, S.A. Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) Decision: Administrative fine, Compliance order Key words: Data subject rights Summary of the Decision Origin of the case A consumer association lodged a complaint against Securitas Direct concerning video surveillance notices that directed data subjects to a chargeable 902 telephone number to exercise their rights of access and objection. This was considered to impose a cost on data subjects and to hinder the exercise of their rights. Key Findings The use of a chargeable telephone number for the exercise of data subject rights was contrary to the GDPR requirement that such rights be exercisable free of charge and could discourage data subjects from exercising them. The availability of other free channels on the website did not remedy the i
EDPB News · 9/21/2026
Brussels, 21 September – During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on interplay between the Digital Service Act (DSA) and the GDPR . The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe. EDPB Deputy Chair, Jelena Virant Burnik Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine: the DPA checks if the infringement can lead
Data Protection Report · 9/15/2026
Anyone who contracts for internet or social-media-based advertising may have overlooked two recent actions by the California Privacy Protection Agency (CalPrivacy) and the proposed draft AI regulations from Colorado, but there are some important takeaways that should not be missed. California fines data broker over $100,000 for broker and privacy law issues California’s new data broker deletion requirements (known as the Delete Act) went into effect on August 1, 2026. On August 10, CalPrivacy announced an order against an Iowa data broker, LocateSmarter, LLC, alleging that the company violated both California’s data broker law and the California Consumer Privacy Act (CCPA). According to the order, LocateSmarter required consumers wishing to opt out of the sale or sharing of their personal data to submit not only their mailing addresses but also the last four digits of their Social Security numbers. The order found that this conduct violated CCPA because LocateSmarter: requi
EDPB News · 9/11/2026
Background information Date of final decision: 21 July 2026 National case Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 17 (Right to erasure ‘right to be forgotten’) Decision: Administrative fine Key words: Data subject rights Summary of the Decision Origin of the case EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies. In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified
EDPB News · 9/9/2026
Background information Date of final decision: 3 September 2026 National case Controller: Hôpital Privé de la Loire Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fine Keywords: Cybersecurity, Personal data breaches, Health and research Summary of the Decision Origin of the case In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR). Key findings Fai
EDPB News · 9/3/2026
Background information Date of final decision: 28 August 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Compliance order, Communication order personal data breach Key words: GDPR enforcement, Data subjects rights, Fines, Health and research Summary of the Decision Origin of the case This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the Data Protection Commission (DPC) in October 2023 and November 2023. In both cases, individuals gained unauthorised access to paper records stored and retained in both St. Loman’s Hospital (Mullingar, County Westmeath) and St Conal’s Hospital (Letterkenny, County Donegal). Both locations are former disused psychiatric hospitals.Videos uploa
Data Protection Report · 8/18/2026
On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation , NYDFS found that the company violated the regulation’s applicable requirements in three ways: (1) failure to “conduct a risk assessment sufficient to inform the design of its cybersecurity program”; (2) as a result of the risk assessment’s deficiencies, failure “to design a cybersecurity program based on the Company’s risk assessment and sufficient to identify and assess risks to NPI”; and (3) failure “to implement and maintain written cybersecurity policies addressing systems and network security.” Order Express agreed to pay $250,000. Although this consent order pertains to a limited exemption licensee, it remains relevant to larger covered entities not exempted from t
FTC Press Releases · 6/30/2026
Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commission allegations that the online retail giant knowingly violated the Fair Credit Reporting Act (FCRA) by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud. The complaint , filed by the Department of Justice upon notification and referral from the FTC, alleged that in numerous instances, Amazon.com Inc. failed to comply with Section 609(e) of the FCRA, which requires companies to, within 30 days of a consumer’s request, provide victims of identity theft with application and business transaction records about fraudulent transactions made in their names. According to the complaint, Amazon had no written policy to respond to Section 609(e) requests until early 2025, after it learned of the FTC’s investigation, despite prior outreach from FTC staff advising the company to review its compliance with Section 609(e). “Amazon often put identit
Data Protection Report · 6/15/2026
Spain’s data protection agency, the Agencia Española de Protección de Datos ( AEPD ), has fined Amadeus IT Group, S.A. ( Amadeus ) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026, has found breaches of Article 14 and Article 6 REGULATION (EU) 2016/679 ( GDPR ). Amadeus has made a €14.4 million voluntary payment, representing a 20% reduction from the proposed total fine, and has stated that they intend to appeal the ruling. Background Amadeus is a major Global Distribution System ( GDS ) provider and is one of the largest travel booking networks used by airlines and travel agencies, responsible for processing the personal data of millions of individuals for bookings in the travel industry. Following an anonymous complaint on 26 September 2023, the AEPD initiated proceedings against Amadeus to investigate possible GDPR breaches in relation to a pilot scheme called ‘PLATAFORMA.1’ (the
Showing 1 - 14 of 14 results