Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

California Attorney General Sues 23andMe Over 2023 Data Breach Exposing Genetic and Health Information

The California Attorney General has initiated a lawsuit against 23andMe's new owners following a 2023 data breach that compromised highly sensitive genetic and health data of millions of users. The lawsuit alleges negligence in securing personal information and seeks to hold the company accountable for the extensive exposure. This legal action emphasizes the critical importance of robust data protection measures particularly for organizations handling sensitive health and genetic data. It also highlights the far reaching consequences of data breaches for affected individuals and the potential for regulatory enforcement.

Today's question

Genetic data under GDPR Article 9 is considered "special category" data because:

  1. Standard administrative procedures fulfill the relevant obligations
  2. Genetic data is not classified as sensitive under GDPR Article 9
  3. Standard lawful basis processing applies without additional restrictions
  4. It reveals biological and hereditary traits unique to individuals

Answer this question on the site

Worth knowing

  1. ICE Contracts Biometric Scanners Raising Concerns Over Surveillance Capabilities

    Immigration and Customs Enforcement ICE has awarded a $25 million contract for biometric scanners, enabling enhanced surveillance capabilities. This development raises significant privacy concerns regarding the collection and use of individuals' biometric data by government agencies. The deployment of advanced biometric technology by law enforcement often sparks debate about individual rights and potential for misuse.

  2. ChatGPT and Generative AI Exploited to Create Malicious Payloads and Phishing Lures

    Recent reports indicate that malicious actors are exploiting generative AI models like ChatGPT to create highly convincing phishing lures and malicious payloads. This sophisticated use of AI significantly enhances the capabilities of attackers in crafting deceptive content that appears legitimate. The ease with which such tools can be misused presents a substantial challenge for cybersecurity and privacy protection.

  3. CNIL Fines IQVIA 5 Million Euros for Health Data Processing Violations

    The French data protection authority CNIL issued a 5 million euro fine against IQVIA for non compliance related to health data processing. This sanction underscores the strict regulatory environment surrounding sensitive health information and the serious consequences of failing to adhere to data protection principles. The case highlights the emphasis on lawful basis consent and data minimization when handling health data.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.