Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

US Lawmakers Demand Answers Following Persistent Data Breaches of Educational Platform Canvas

US lawmakers are actively seeking clarification and accountability from Instructure, the company behind the Canvas learning management system, after multiple confirmed data breaches. These incidents have potentially compromised sensitive student and educator data, raising serious concerns about the platform's security posture and its responsibility to protect personal information. The congressional inquiry underscores the increasing scrutiny facing organizations that handle large volumes of personal data, particularly in sectors such as education.

Today's question

The breach of an MEP's phone by Pegasus spyware raises significant concerns under GDPR, particularly regarding which of the following aspects?

  1. The right to data portability
  2. The right to restriction of processing
  3. The security of processing and data breach notification obligations
  4. The requirement for a Data Protection Officer

Answer this question on the site

Worth knowing

  1. Emergence of AI in Vulnerability Discovery Leads to 'Vulnpocalypse' and Rapid Patch Proliferation

    Vendors are increasingly utilizing artificial intelligence to identify software vulnerabilities, leading to an unprecedented surge in discovered bugs and subsequent patches. This period of rapid vulnerability exposure and remediation is being termed the 'vulnpocalypse,' reflecting the scale and speed at which security flaws are being uncovered. The integration of AI tools is transforming the landscape of cybersecurity, forcing organizations to adapt their patching and security management strategies.

  2. CNIL Highlights Privacy Concerns with Connected Wearable Devices

    The French data protection authority CNIL has issued a strong warning regarding the privacy implications of connected glasses and other wearable technology. This advisory emphasizes the potential for these devices to surreptitiously collect personal data, including sensitive information, without adequate transparency or user control. CNIL's call for vigilance underscores the ongoing challenge of regulating emerging technologies to protect individual privacy rights.

  3. Apple and Google Collaborate to Enhance Cross Platform Texting Encryption

    In a significant development for digital privacy, Apple and Google are working together to bring enhanced encryption to cross platform text messaging. This collaboration aims to provide a more secure communication environment for users across different operating systems, addressing long standing concerns about the confidentiality of text messages. The move signifies a growing industry commitment to end to end encryption for widely used consumer services.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.