Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

UK Visa Portal Exposes Thousands of Applicants' Sensitive Personal Data, Remains Unpatched

A significant data breach affecting the UK visa portal has publicly exposed thousands of applicants' passports and selfies. This vulnerability has been persistent and reportedly remains unaddressed, raising serious questions about data security protocols. The exposed information is highly sensitive, including biometric data and official identification documents. The failure to promptly fix such a critical leak endangers individuals and undermines trust in government online services.

Today's question

Which of the following best describes the primary privacy concern raised by OpenAI's GPT-5.6 deleting user files?

  1. Violation of data minimization principles under GDPR Article 5(1)(c)
  2. Breach of data integrity and confidentiality under GDPR Article 5(1)(f)
  3. Failure to obtain explicit consent for data processing under GDPR Article 6(1)(a)
  4. Non-compliance with data portability rights under GDPR Article 20

Answer this question on the site

Worth knowing

  1. Anthropic to Release Advanced AI Models to the Public, Raising AI Governance Questions

    AI research company Anthropic plans to make its 'Mythos class' models publicly available. This move could significantly advance AI capabilities but also introduces new challenges for AI governance and responsible deployment. The increased accessibility of sophisticated AI models necessitates careful consideration of their ethical implications and potential misuse.

  2. MyPillow Faces Ransomware Demand After Data Breach

    MyPillow's data has appeared on a ransomware leak site, indicating a successful attack by cybercriminals. The company must now decide whether to pay the ransom to prevent the public release of potentially sensitive information. This incident highlights the growing threat of ransomware and the difficult choices organizations face when their data is compromised and held hostage.

  3. CNIL Updates and Expands Reference Methodologies for Health Research Data Processing

    France's data protection authority, CNIL, has updated and broadened the scope of its reference methodologies 001 and 003, which concern the processing of health data for research purposes. This update aims to provide clearer guidelines and facilitate compliance for health researchers. It reflects an ongoing effort to balance scientific progress with robust data protection for sensitive medical information.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.