This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
Predatorgate Victims Seek €8M in Damages from Spyware Vendor
Victims of the Pegasus like Predatorgate spyware attack have launched an €8 million lawsuit against the spyware manufacturer. This collective action highlights the growing legal challenges faced by producers of surveillance technology. The suit seeks significant compensation for the profound privacy violations and potential harm experienced by those targeted.
Article 35(3) GDPR specifies that a DPIA is particularly required for:
Systematic and extensive profiling with significant effects, large-scale processing of special categories, and systematic monitoring of publicly accessible areas
All marketing campaigns, as required under the breach notification provisions, with particular attention to documentation requirements
Processing of employee payroll data, following established incident response procedures, including appropriate organizational measures, under the applicable procedural safeguards
Any processing by a small business, following established incident response procedures, with particular attention to documentation requirements
A vulnerability in GitHub's AI agent has been discovered, allowing it to leak contents of private repositories when prompted with specific requests. This incident highlights the inherent risks associated with integrating AI into sensitive development environments and managing proprietary code. Organizations using such AI tools must urgently reevaluate their security configurations and data handling practices.
An anti piracy tool integrated into Windows has reportedly played a role in identifying a suspect linked to the Scattered Spider cybercrime group. This development raises questions about the scope and capabilities of embedded system monitoring features. It also highlights the dual use nature of some technologies, potentially impacting user privacy.
The French data protection authority CNIL has issued 23 new simplified sanctions since the beginning of the year. This action underscores the regulator's proactive stance on enforcing data protection compliance, particularly through streamlined procedures for less severe infringements. Organizations operating in the EU should be aware of CNIL's increased enforcement activity.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.