Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

California Seeks Accountability for 23andMe Data Breach Following Ownership Change

The California Attorney General is pursuing legal action against the new owners of 23andMe regarding a 2023 data breach that exposed sensitive genetic and health information of millions of users. This lawsuit highlights the continuing legal ramifications and accountability challenges associated with data breaches, particularly when company ownership transitions. The action underscores the long term liability for organizations holding vast amounts of personal and health data. It also emphasizes the importance of robust data security practices and transparent breach notification protocols.

Today's question

The GDPR relationship with sector-specific EU data protection laws (like the ePrivacy Directive) is that:

  1. The GDPR substantially replaces all other EU laws on data
  2. Specific EU sectoral laws remain applicable as lex specialis
  3. All sector-specific laws are automatically invalid under GDPR
  4. Organizations can freely choose which law to follow

Answer this question on the site

Worth knowing

  1. Microsoft Accused of Threatening Security Researcher with Criminal Investigation

    Microsoft is facing criticism for allegedly threatening a security researcher with a criminal investigation. This incident raises serious concerns about the responsible disclosure process and the potential chilling effect on legitimate security research. It highlights the delicate balance between protecting proprietary information and encouraging vulnerability discovery.

  2. ICE Awards $25 Million Contract for Biometric Scanners, Expanding Surveillance Capabilities

    Immigration and Customs Enforcement (ICE) has awarded a significant $25 million contract for biometric scanners, indicating an expansion of its surveillance capabilities. This development raises substantial privacy concerns regarding the collection, storage, and utilization of sensitive biometric data by government agencies. It underscores the growing debate about civil liberties and government oversight in the context of advanced surveillance technologies.

  3. AI Language Models Exploited for Malicious Purposes, Raising AI Governance Concerns

    Recent reports indicate that AI language models like ChatGPT are being exploited for prompt injection attacks and to create malicious payloads, turning web pages into phishing lures. These incidents highlight the evolving threat landscape where AI tools are weaponized for cybercriminal activities. This necessitates urgent attention to AI governance frameworks and responsible AI development to mitigate potential misuse.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.