#subject-access-requests

[ follow ]
#ai
Marketing tech
fromAdExchanger
9 hours ago

AI Has Already Decided: First-Party Data Will Define Advertising's Agentic Era

AI has resolved the debate on third-party cookies, emphasizing the necessity of first-party data for effective decision-making in advertising.
Law
fromAdExchanger
5 days ago

AI Is Moving Fast. The Law, Not So Much | AdExchanger

AI technology is advancing rapidly, outpacing legal frameworks and creating challenges in regulation and data management.
Privacy technologies
fromComputerWeekly.com
3 days ago

Identity and AI: Questions of data security, trust and control | Computer Weekly

AI-driven identity solutions improve access control but raise compliance, privacy, and ethical concerns that organizations must address.
Artificial intelligence
fromSecurityWeek
6 days ago

Silent Drift: How LLMs Are Quietly Breaking Organizational Access Control

AI assistance in policy as code can introduce serious flaws, leading to incorrect access permissions despite syntactically valid policies.
Marketing tech
fromAdExchanger
9 hours ago

AI Has Already Decided: First-Party Data Will Define Advertising's Agentic Era

AI has resolved the debate on third-party cookies, emphasizing the necessity of first-party data for effective decision-making in advertising.
Roam Research
fromThe Verge
3 days ago

PSA: Anyone with a link can view your Granola notes by default

Granola's AI note-taking app makes user notes viewable by default, raising privacy concerns for sensitive information.
Law
fromAdExchanger
5 days ago

AI Is Moving Fast. The Law, Not So Much | AdExchanger

AI technology is advancing rapidly, outpacing legal frameworks and creating challenges in regulation and data management.
Privacy technologies
fromComputerWeekly.com
3 days ago

Identity and AI: Questions of data security, trust and control | Computer Weekly

AI-driven identity solutions improve access control but raise compliance, privacy, and ethical concerns that organizations must address.
Artificial intelligence
fromSecurityWeek
6 days ago

Silent Drift: How LLMs Are Quietly Breaking Organizational Access Control

AI assistance in policy as code can introduce serious flaws, leading to incorrect access permissions despite syntactically valid policies.
Privacy professionals
fromPCMAG
1 day ago

Use Perplexity? Lawsuit Accuses It of Sharing Personal Data With Google and Meta Without Permission

Perplexity faces a lawsuit for allegedly sharing user data with Google and Meta without consent, violating privacy rights.
#cloud-security
Information security
fromSecuritymagazine
3 days ago

World Cloud Security Day: Breaking Down the State of the Cloud Cybersecurity and Physical Security

World Cloud Security Day emphasizes the importance of securing cloud data, focusing on identity visibility and flexible cloud adoption for physical security.
Information security
fromInfoWorld
2 days ago

CERT-EU blames Trivy supply chain attack for Europa.eu data breach

TeamPCP exploited Trivy to access sensitive cloud credentials and data, creating significant vulnerabilities for organizations.
Information security
fromSecuritymagazine
3 days ago

World Cloud Security Day: Breaking Down the State of the Cloud Cybersecurity and Physical Security

World Cloud Security Day emphasizes the importance of securing cloud data, focusing on identity visibility and flexible cloud adoption for physical security.
Information security
fromInfoWorld
2 days ago

CERT-EU blames Trivy supply chain attack for Europa.eu data breach

TeamPCP exploited Trivy to access sensitive cloud credentials and data, creating significant vulnerabilities for organizations.
Social media marketing
fromwww.theguardian.com
7 hours ago

It started with a tip-off': how a Guardian investigation exposed child sex trafficking on Facebook and Instagram

Child sexual abuse trafficking surged during the pandemic, with platforms like Facebook and Instagram being exploited for these crimes.
Privacy technologies
fromTNW | Insights
1 day ago

LinkedIn secretly scans 6,000+ browser extensions and fingerprints your device

LinkedIn's hidden JavaScript routine collects extensive user data without disclosure, raising concerns about covert surveillance practices.
US politics
fromArs Technica
1 day ago

CBP facility codes sure seem to have leaked via online flashcards

Immigration offenses and internal systems of CBP are detailed in flashcards, highlighting procedures and responsibilities of agents.
Law
fromABA Journal
4 days ago

Sanctions ramping up in cases involving AI hallucinations

Monetary sanctions against attorneys for AI-generated hallucinations in case documents are increasing as courts take these issues more seriously.
fromRubyflow
5 days ago
Ruby on Rails

Rails Consent - Cookie Consent & Privacy Preferences for Rails

Rails Consent is a Rails Engine for cookie consent and privacy preference management in Ruby on Rails applications.
Online marketing
fromMakeUseOf
4 days ago

No, it's not your microphone - this is how advertisers know what you want

Advertisers use data from your online behavior, not microphone recordings, to deliver targeted ads accurately.
Digital life
fromExchangewire
6 days ago

Regulating Social Media: Where do we go from here?

Social media platforms are designed for addiction, prompting global legislative actions to restrict children's access.
European startups
fromTechzine Global
5 days ago

Dutch cloud providers join forces to create a sovereign alternative

Seven Dutch cloud providers are collaborating to enhance digital autonomy and counter American hyperscalers' dominance.
Apple
fromMacRumors
6 days ago

Apple Sets Privacy Rules for Third-Party Access to Live Activities and Notifications

Apple is implementing new iOS features for third-party wearables while enforcing strict privacy rules on notification forwarding.
Privacy professionals
fromZDNET
3 days ago

I turned to PrivacyBee to clean up my data - here's how it made me disappear

PrivacyBee is preferred for its comprehensive data removal services and user-friendly management tools.
#cybersecurity
EU data protection
fromSecurityWeek
2 days ago

European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

Hackers stole over 300GB of data from the European Commission's AWS environment using a compromised API key from the Trivy supply chain attack.
EU data protection
fromTechCrunch
2 days ago

Europe's cyber agency blames hacking gangs for massive data breach and leak | TechCrunch

A cybercriminal group known as TeamPCP hacked the EU's executive body, stealing 92 gigabytes of data, including personal information.
Information security
fromThe Hacker News
6 days ago

The AI Arms Race - Why Unified Exposure Management Is Becoming a Boardroom Priority

The cybersecurity landscape is rapidly evolving, with AI enabling faster and more sophisticated attacks, necessitating advanced defensive strategies.
EU data protection
fromSecurityWeek
2 days ago

European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

Hackers stole over 300GB of data from the European Commission's AWS environment using a compromised API key from the Trivy supply chain attack.
EU data protection
fromTechCrunch
2 days ago

Europe's cyber agency blames hacking gangs for massive data breach and leak | TechCrunch

A cybercriminal group known as TeamPCP hacked the EU's executive body, stealing 92 gigabytes of data, including personal information.
Information security
fromThe Hacker News
6 days ago

The AI Arms Race - Why Unified Exposure Management Is Becoming a Boardroom Priority

The cybersecurity landscape is rapidly evolving, with AI enabling faster and more sophisticated attacks, necessitating advanced defensive strategies.
#ai-security
Information security
fromInfoWorld
3 days ago

Claude Code leak puts enterprise trust at risk as security, governance concerns mount

Leaks threaten Anthropic's market position and raise security concerns about its AI coding tools.
Information security
fromInfoWorld
3 days ago

Claude Code leak puts enterprise trust at risk as security, governance concerns mount

Leaks threaten Anthropic's market position and raise security concerns about its AI coding tools.
#privacy
fromTechdirt
2 weeks ago
Privacy professionals

The Government Uses Targeted Advertising to Track Your Location. Here's What We Need to Do.

Privacy professionals
fromTechdirt
2 weeks ago

The Government Uses Targeted Advertising to Track Your Location. Here's What We Need to Do.

Government agencies use online advertising data to track individuals without warrants, raising significant privacy concerns.
#ai-governance
fromComputerWeekly.com
4 days ago
EU data protection

AI-driven identity must exist in a robust compliance framework | Computer Weekly

Governance must precede AI adoption to avoid compliance failures and ethical risks in identity verification systems.
Marketing tech
fromExchangewire
3 days ago

The Stack: AI Surges while Social Platforms Face Scrutiny

AI is growing rapidly, streaming models are evolving, and regulatory pressures on platforms are increasing globally.
US politics
fromwww.npr.org
3 days ago

As DOJ prepares to share state voter data with DHS, a key privacy officer resigns

The DOJ is acquiring sensitive voter registration data, raising privacy concerns, as a key privacy officer resigns amid ongoing legal challenges.
Digital life
fromDigiday
6 days ago

In graphic detail: The long road to accountability for social media platforms

Big tech giants are now held accountable for harming children, marking a significant shift in social media regulation.
Information security
fromTNW | Insights
1 day ago

KeeperDB brings zero-trust database access to privileged access management

Database credentials are a major attack vector, and KeeperDB integrates access controls into its PAM platform to enhance security.
#meta
Law
fromTechCrunch
5 days ago

Meta was finally held accountable for harming teens. Now what? | TechCrunch

Meta has been held liable for endangering child safety and designing addictive apps, leading to significant legal consequences.
Information security
fromWIRED
2 days ago

Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Meta has paused work with Mercor due to a major security breach affecting data used for AI training.
Law
fromTechCrunch
5 days ago

Meta was finally held accountable for harming teens. Now what? | TechCrunch

Meta has been held liable for endangering child safety and designing addictive apps, leading to significant legal consequences.
Information security
fromWIRED
2 days ago

Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Meta has paused work with Mercor due to a major security breach affecting data used for AI training.
Privacy professionals
fromIndependent
1 day ago

Gearoid O'Sullivan: Would you be happy to have details of your tax affairs paraded in public?

New rules threaten taxpayer privacy by limiting the right to private hearings in the appeals process.
EU data protection
fromEngadget
1 day ago

Ireland is testing out a digital wallet that conducts age verification for social media users

Ireland is trialing a Government Digital Wallet to verify user age for social media access, aiming for user-friendly design before its 2026 EU deadline.
Artificial intelligence
fromTearsheet
4 days ago

What a bank-client relationship looks like when banks control the data behind the UX - Tearsheet

Grasshopper's Model Context Protocol enables secure AI integration with banking data while maintaining client control and data security.
#data-breach
Privacy professionals
fromSilicon Canals
3 days ago

A fintech app asked users for their passports - then left 360,000 files unprotected for five years - Silicon Canals

A money transfer app exposed over 360,000 sensitive files on a public server for nearly five years, including unencrypted personal documents.
Privacy professionals
fromSilicon Canals
3 days ago

Fintech apps demand your passport for verification - then leave it on an unprotected server - Silicon Canals

Duc's exposed server revealed unprotected sensitive personal data, highlighting significant gaps in fintech data protection practices.
Privacy professionals
fromSilicon Canals
3 days ago

A fintech app asked users for their passports - then left 360,000 files unprotected for five years - Silicon Canals

A money transfer app exposed over 360,000 sensitive files on a public server for nearly five years, including unencrypted personal documents.
Privacy professionals
fromSilicon Canals
3 days ago

Fintech apps demand your passport for verification - then leave it on an unprotected server - Silicon Canals

Duc's exposed server revealed unprotected sensitive personal data, highlighting significant gaps in fintech data protection practices.
fromTheregister
2 days ago

NHS staff resist using Palantir software

One official reportedly described Palantir as 'ethically bankrupt' in justifying his refusal to use the software, and noted that he knows of coworkers who deliberately slow their work pace when forced to use the system.
EU data protection
Privacy professionals
fromSilicon Canals
3 days ago

A money-transfer app stored customer passports on an unencrypted, publicly accessible server for nearly five years - Silicon Canals

Fintech companies face regulatory pressure to collect identity documents but lack enforceable obligations to protect them, leading to data breaches.
Privacy professionals
fromThe Verge
3 days ago

Pinterest said he violated laid-off colleagues' privacy. Now he's going public

A former Pinterest engineer claims he was unjustly fired for sharing a tool that revealed employee layoffs.
#ai-regulation
EU data protection
fromSecurityWeek
1 week ago

European Commission Reports Cyber Intrusion and Data Theft

The European Commission confirmed a cyberattack that compromised its cloud infrastructure, resulting in the theft of hundreds of gigabytes of data.
Marketing tech
fromAdExchanger
4 weeks ago

The Privacy 'Zealots' Were Right: Ad Tech's Infrastructure Was Always A Risk

Digital advertising's granular targeting infrastructure created uncontrollable security vulnerabilities that governments now exploit for surveillance purposes.
Information security
fromTheregister
5 days ago

Claude Code's source reveals extent of system access

Claude Code has significant control over devices, raising concerns about data retention and potential misuse in sensitive environments.
Information security
fromSecurityWeek
5 days ago

The Next Cybersecurity Crisis Isn't Breaches-It's Data You Can't Trust

Data integrity now encompasses data trust, emphasizing the importance of reliable data in AI-driven decision-making.
Privacy professionals
fromHer Campus
5 days ago

Who's Watching The Watchers? AI, Age Verification, And Online Privacy

Parents are increasingly concerned about children's exposure to harmful online content despite regulations like CIPA and platforms like YouTube Kids.
Privacy professionals
fromGamesBeat
5 days ago

Understanding the updated COPPA rules and their impact on child safety

New COPPA rule amendments effective April 2026 will require separate parental consent for targeted advertising and data sharing in children's games.
Privacy professionals
fromEngadget
6 days ago

OkCupid settles FTC case on alleged misuse of its users' personal data

OkCupid settled a lawsuit with the FTC over sharing user data without consent, denying wrongdoing but committing to improved privacy practices.
Marketing
fromCMSWire.com
2 months ago

The Cookie Banner Checklist That Actually Matters

A centralized resource delivers actionable research, editorial insight and practical data to guide CMOs and customer experience leaders through complex customer and organizational landscapes.
Privacy professionals
fromMedCity News
2 weeks ago

The Evolving Landscape of Privacy and Cybersecurity: Essential Strategies for Legal and Compliance Professionals - MedCity News

Organizations must combine strong controls with comprehensive employee training and accountability culture to effectively protect sensitive data and comply with evolving privacy laws.
Privacy professionals
fromTheregister
3 weeks ago

Age verification isn't sage verification inside OSes

California's Digital Age Assurance Act attempts age verification for minors but is vague, incoherent, and creates liability risks without clearly defining compliance requirements or addressing practical implementation across diverse computing devices.
fromMedium
1 month ago

Surveillance by default, consent by assumption

When presence becomes participation Ring's Search Party feature queries nearby cameras when a missing pet is reported. As Senator Ed Markey observed, this closely resembles neighbourhood-scale surveillance infrastructure. Crucially, Search Party does not operate in isolation. Ring's Familiar Faces feature applies facial recognition to anyone passing within camera range, continuously scanning and categorising faces without their explicit knowledge or agreement.
Privacy technologies
Information security
fromBusiness Matters
1 month ago

7 Data Privacy Risks Leaders Miss in 2026

Organizations overlook seven critical privacy risks in 2026 that bypass security awareness, including public WiFi interception, malicious browser extensions, shadow AI tools, unencrypted messaging, credential reuse, unmanaged personal devices, and data retention gaps.
Digital life
fromMUO
2 months ago

I turned off these Google settings to improve privacy

Disable Google's Web & App Activity and Location History to reduce extensive tracking of searches, app usage, browsing, YouTube views, and location movements.
EU data protection
fromDataBreaches.Net
1 month ago

UK Court of Appeal Rules on the Concept of Personal Data in the Context of Data Security - DataBreaches.Net

A controller's data security duty applies to all personal data under its control, regardless of whether third parties could identify individuals from that data.
Privacy professionals
fromwww.bbc.com
1 month ago

We have more privacy controls yet less privacy than ever

Young people increasingly view online privacy as inevitable loss rather than a right, accepting data sharing as currency for digital services while older privacy advocates warn this threatens fundamental freedoms.
fromEntrepreneur
1 month ago

AI Can Delete Your Data. Here's Your Prevention Plan.

Never feel that you are totally safe. In July 2025, one company learned the hard way after an AI coding assistant it dearly trusted from Replit ended up breaching a "code freeze" and implemented a command that ended up deleting its entire product database. This was a huge blow to the staff. It effectively meant that months of extremely hard work, comprising 1,200 executive records and 1,196 company records, ended up going away.
Artificial intelligence
EU data protection
fromDataBreaches.Net
1 month ago

Resource: Privacy Law Directory -- Codamail - DataBreaches.Net

Privacy laws primarily protect domestic citizens while intelligence exemptions and international intelligence-sharing alliances enable extensive cross-border surveillance and data flows.
#cookies
EU data protection
fromTechzine Global
1 month ago

Metadata, cloud sovereignty's weak spot

US authorities can access some metadata of cloud users in European sovereign clouds, potentially revealing operational and behavioral information despite data residency protections.
fromExchangewire
2 months ago

Axeptio Launches Global Privacy Control (GPC) Support to Strengthen Compliance with US Privacy Regulations

Global Privacy Control is a browser-level signal that allows users to express-prior to any interaction with a website-their decision to opt out of the sale or sharing of their personal data. To meet these evolving legal requirements, Axeptio now integrates GPC signal detection and processing through a new feature available for projects using a CCPA banner, a prerequisite for remaining compliant in the United States.
Privacy technologies
fromThe Hacker News
2 months ago

New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification

Research analyzing 4,700 leading websites reveals that 64% of third-party applications now access sensitive data without business justification, up from 51% in 2024. Government sector malicious activity spiked from 2% to 12.9%, while 1 in 7 Education sites show active compromise. Specific offenders: Google Tag Manager (8% of violations), Shopify (5%), Facebook Pixel (4%).
Information security
Privacy technologies
fromFox News
2 months ago

5 tech terms that shape your online privacy

Limit app permissions, especially location, microphone, and photo access, and regularly adjust device privacy settings to prevent background data collection.
Privacy professionals
fromExchangewire
1 month ago

EscalaX Reinforces its Privacy & Compliance With BidSafe One

EscalaX partners with BidSafe One to strengthen privacy, consent management, and regulatory compliance across programmatic advertising, ensuring secure multichannel data governance.
EU data protection
fromComputerWeekly.com
1 month ago

Europe's data protection supervisors warn over plans to 'narrow' privacy rights | Computer Weekly

Narrowing the definition of personal data in EU reforms risks eroding privacy rights, creating legal uncertainty, and weakening protections against automated decision-making.
EU data protection
fromTechzine Global
1 month ago

European regulators criticize weakening GDPR

European privacy regulators strongly oppose key Digital Omnibus changes, especially narrowing the GDPR personal-data definition and expanding pseudonymization authority.
EU data protection
fromThe Drum
2 months ago

No, I'm not going to opt-in to your email database just because you want me to

Many organisations request GDPR opt-ins but offer vague 'special offers' instead of clear, fair value exchanges for consumers' personal data.
fromCoindesk
2 months ago

Privacy

This Privacy Notice applies to all personal information processed by CoinDesk, including its affiliates and subsidiaries (" CoinDesk," " we," " us," or " our "). It covers the information CoinDesk collects through the websites, mobile applications, electronic devices, all other products and services we provide, any other services that display this Privacy Notice, all of the associated content, functionalities, and advertising, and when you communicate with us by phone, email, or otherwise (collectively, the " Services ").
Privacy professionals
fromAdExchanger
2 months ago

Inside The Mind Of A Former Privacy Regulator | AdExchanger

How do privacy regulators decide which companies to poke? Often, it's a consumer complaint. Other times, it's a headline. And, sometimes, it's just personal. Regulators are consumers, too, after all. But it's important to remember that every brush with a regulator doesn't turn into a full-blown case, said privacy attorney Tyler Bridegan. Bridegan spent nearly two years as director of privacy and tech enforcement for the Texas attorney general's office. He left government work and returned to private practice in October as a partner at Womble Bond Dickinson.
Privacy professionals
Privacy professionals
fromPrivacy International
2 months ago

A Call for Class Action: how people are reclaiming control over their health data

Class actions in the US are increasingly used to hold companies accountable for exploiting highly valuable health data, creating financial incentives to change corporate behavior.
fromeLearning Industry
2 months ago

Why Data Privacy Is Mission-Critical In Corporate eLearning

There's been an explosion in the growth of corporate eLearning initiatives in the post-COVID era. That's due in part to the growth in remote work and geographically distributed teams. Unfortunately, there are always growing pains when any corporate initiative scales up in a hurry. In the case of eLearning, one of those growing pains is a tendency to let data privacy standards fall by the wayside.
Privacy professionals
[ Load more ]