Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Healthcare and Utility Sector Face Significant Data Breaches

Major organizations Medtronic and Itron, operating in critical infrastructure sectors like medical technology and utilities, have confirmed data breaches. Medtronic acknowledged a cybersecurity incident following claims by hackers of a 9 million record theft, while Itron, a utility giant, disclosed a breach of its internal IT networks. These incidents highlight the severe vulnerabilities present in sectors handling highly sensitive personal and operational data, posing risks to patient privacy and essential services.

Today's question

A public sector organisation in the EU plans to deploy a new AI system for processing citizen applications, which is classified as high risk under the AI Act. What is a mandatory step this organisation must take before deploying the system, starting December 2027?

  1. Conduct a Data Protection Impact Assessment (DPIA) under GDPR Article 35.
  2. Perform a Fundamental Rights Impact Assessment (FRIA) as per the AI Act.
  3. Obtain prior authorisation from the European Data Protection Board (EDPB).
  4. Implement a 'privacy by design' approach and document it internally.

Answer this question on the site

Worth knowing

  1. Home Security Provider ADT Confirms Cyber Intrusion Affecting Millions

    ADT, a prominent home security company, confirmed a cyber intrusion after an extortion attempt by the ShinyHunters group. The incident has reportedly impacted 5.5 million individuals, raising significant concerns about the security of personal and potentially sensitive home security data. This breach underscores the vulnerability of even security oriented businesses to sophisticated cyberattacks.

  2. ICO Chief John Edwards Under Workplace Investigation Amidst Silence

    John Edwards, the head of the UK's Information Commissioner's Office (ICO), has stepped back from his role while a workplace investigation quietly unfolds. The lack of detailed information surrounding the probe raises questions about transparency and governance within the key data protection authority. This situation could have implications for the ICO's credibility and its ongoing enforcement activities.

  3. FBI Extradites Alleged Chinese State Sponsored Hacker to US

    An alleged hacker, linked to cyberattacks carried out for China, has been extradited to the United States. This extradition underscores ongoing international efforts to combat state sponsored cyberespionage and intellectual property theft. The case highlights the complex legal and geopolitical challenges in prosecuting cybercrimes that cross national borders and involve state actors.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.