This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
Medical Data of Half a Million UK Biobank Volunteers Allegedly Offered for Sale Online
A UK minister disclosed that medical data belonging to 500,000 volunteers from the UK Biobank project has reportedly been listed for sale on Alibaba, a major e commerce platform. This incident represents a significant data breach impacting highly sensitive personal health information. The potential exposure raises serious concerns about the security protocols governing valuable research data and the broader implications for participant trust in scientific studies. Authorities are likely to investigate how such a breach occurred and the full extent of the data compromise.
Under Article 3(2)(a), 'offering goods or services' to data subjects in the EU is indicated by factors such as:
Only having a physical store in the EU, as defined by the territorial application provisions, with corresponding procedural safeguards, as required by the applicable legal framework
Using a language or currency used in one or more member states, mentioning EU customers, or paying for search engine advertising targeted at EU audiences
Shipping products from within the EU, in accordance with the jurisdictional scope requirements, with particular attention to documentation requirements
Simply having a website accessible from the EU, following the established extraterritorial criteria, subject to appropriate oversight mechanisms
A new crime group is impersonating help desk personnel and exploiting Microsoft Teams to deploy novel 'Snow' malware, enabling them to steal sensitive data. This social engineering tactic leverages trusted communication platforms for initial access, posing a significant risk to organizational data security. The use of Microsoft Teams highlights a growing trend of attackers exploiting collaboration tools for malicious purposes, necessitating enhanced vigilance and security protocols.
The French National Commission on Informatics and Liberty (CNIL) has updated its guidance on electronic correspondence voting. This revision likely addresses privacy and security concerns related to digital voting processes, aiming to ensure the integrity and confidentiality of votes. The intervention of data protection authorities like CNIL is crucial for establishing frameworks that balance technological advancement with fundamental rights, particularly in sensitive areas such as democratic processes.
Microsoft is providing administrators with the ability to uninstall Copilot, its AI assistant, from enterprise devices. This move offers organizations greater control over software deployments and potentially addresses privacy and data governance concerns associated with AI tools in business environments. The option for uninstallation allows businesses to manage shadow IT risks and data exfiltration vectors more effectively, aligning with their internal compliance policies.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.