The UK’s Information Commissioner’s Office has reprimanded ACRO, the Criminal Records Office, following cybersecurity failures involving a website compromise that potentially affected up to 10,000 people. The case highlights the relationship between cybersecurity controls and data protection compliance. Organizations processing sensitive personal information are expected to maintain appropriate technical and organizational measures to protect that...Read More
The European cybersecurity certification ecosystem is continuing to develop as organizations face growing pressure to demonstrate that their products and services meet security requirements. ENISA’s European Cybersecurity Certification platform recently highlighted developments concerning the market for cybersecurity assessments, reflecting the growing need for independent security evaluation and assurance. Cybersecurity assessments are increasingly relevant to organizations...Read More
The UK’s Information Commissioner’s Office has reprimanded ACRO, the Criminal Records Office, following cybersecurity failures involving a website compromise that potentially affected up to 10,000 people. The case highlights the relationship between cybersecurity controls and data protection compliance. Organizations processing sensitive personal information are expected to maintain appropriate technical and organizational measures to protect that...Read More
The European cybersecurity certification ecosystem is continuing to develop as organizations face growing pressure to demonstrate that their products and services meet security requirements. ENISA’s European Cybersecurity Certification platform recently highlighted developments concerning the market for cybersecurity assessments, reflecting the growing need for independent security evaluation and assurance. Cybersecurity assessments are increasingly relevant to organizations...Read More
The European Union Agency for Cybersecurity (ENISA) announced that it is expanding its role within the Common Vulnerabilities and Exposures (CVE) ecosystem. The development involves additional organizations joining the network of CVE Numbering Authorities under ENISA’s coordination. The CVE system plays a critical role in identifying and communicating publicly known cybersecurity vulnerabilities. A stronger European...Read More
The UK Information Commissioner’s Office has highlighted the growing importance of strong data protection governance when police forces use facial recognition technology (FRT). The ICO says that the rapid development and increasing use of facial recognition creates significant challenges around personal data, transparency, accountability and public trust. Its latest work focuses on how police forces...Read More
The European Union Agency for Cybersecurity (ENISA) announced that it is expanding its role within the Common Vulnerabilities and Exposures (CVE) ecosystem. The development involves additional organizations joining the network of CVE Numbering Authorities under ENISA’s coordination. The CVE system plays a critical role in identifying and communicating publicly known cybersecurity vulnerabilities. A stronger European...Read More
The UK Information Commissioner’s Office has highlighted the growing importance of strong data protection governance when police forces use facial recognition technology (FRT). The ICO says that the rapid development and increasing use of facial recognition creates significant challenges around personal data, transparency, accountability and public trust. Its latest work focuses on how police forces...Read More
Privacy regulators from several U.S. states are increasing cooperation to enforce consumer privacy rights, particularly concerning Global Privacy Control (GPC) compliance. The coordinated approach reflects a broader trend toward joint investigations and consistent enforcement of state privacy laws. Businesses operating across multiple states should ensure their websites, consent management systems, and privacy practices properly recognize...Read More
Legal experts are warning that the growing adoption of autonomous AI Agents presents significant privacy and compliance challenges. Unlike traditional AI tools, AI agents can independently access emails, documents, enterprise systems, and customer information to perform complex business tasks. Privacy professionals caution that organizations deploying these technologies should conduct Data Protection Impact Assessments (DPIAs), review...Read More