Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Novo Nordisk Reports Cyberattack Leading to Theft of Clinical Trial Data

Pharmaceutical giant Novo Nordisk has disclosed a cyberattack resulting in the unauthorized access and exfiltration of sensitive clinical trial data. The incident comes as the UK approves its Wegovy pill, highlighting the increasing vulnerability of healthcare and pharmaceutical sectors to sophisticated cyber threats. The breach of clinical trial data could have significant implications for patient privacy, intellectual property, and regulatory approvals. Organizations must reinforce their cybersecurity posture to protect highly sensitive health information.

Today's question

Health research under GDPR may rely on:

  1. Explicit consent or public interest grounds as specified by GDPR
  2. A contract with the research subject is the lawful basis allowed, subject to proportionate compliance measures
  3. Any legal basis available to the controller can justify health research, under the applicable procedural safeguards
  4. Legitimate interest is the permissible basis for health research, under the conditions specified by applicable law

Answer this question on the site

Worth knowing

  1. Google Sues Chinese Phishing Group Using AI for Fraudulent Operations

    Google has initiated legal action against a Chinese cybercrime organization for allegedly leveraging artificial intelligence to conduct extensive phishing and fraudulent activities. This lawsuit highlights the increasing use of advanced AI technologies by threat actors to scale and refine their malicious campaigns, posing new challenges for cybersecurity defenses and consumer protection. It underscores the broader implications of AI in cybercrime remediation and the need for proactive legal and technical measures.

  2. UK Digital ID Initiative Establishes Brain Trust for Policy Scrutiny

    The UK's digital identity program has formed an advisory 'brain trust' to critically evaluate and challenge government policy decisions related to its implementation. This move aims to ensure robust oversight and address concerns about privacy, security, and the ethical implications of a centralized digital identity system. The formation of such a body is crucial for fostering public trust and ensuring that digital identification schemes are developed with comprehensive data protection safeguards.

  3. Belfast City Council Exposes Hundreds in Latest Local Government Email Gaffe

    Belfast City Council has inadvertently exposed the personal data of hundreds of individuals through an email error, adding to a growing list of data breaches in local government. This incident highlights persistent human error and inadequate training as primary causes of data spills, emphasizing the critical need for stricter protocols and employee education. Such breaches can lead to significant reputational damage, regulatory fines, and erosion of public confidence in data handling by public sector entities.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.