Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Predatorgate Victims Seek €8M in Damages from Spyware Vendor

Victims of the Pegasus like Predatorgate spyware attack have launched an €8 million lawsuit against the spyware manufacturer. This collective action highlights the growing legal challenges faced by producers of surveillance technology. The suit seeks significant compensation for the profound privacy violations and potential harm experienced by those targeted.

Today's question

Article 35(3) GDPR specifies that a DPIA is particularly required for:

  1. Systematic and extensive profiling with significant effects, large-scale processing of special categories, and systematic monitoring of publicly accessible areas
  2. All marketing campaigns, as required under the breach notification provisions, with particular attention to documentation requirements
  3. Processing of employee payroll data, following established incident response procedures, including appropriate organizational measures, under the applicable procedural safeguards
  4. Any processing by a small business, following established incident response procedures, with particular attention to documentation requirements

Answer this question on the site

Worth knowing

  1. GitHub AI Agent Leaks Private Repositories on Request

    A vulnerability in GitHub's AI agent has been discovered, allowing it to leak contents of private repositories when prompted with specific requests. This incident highlights the inherent risks associated with integrating AI into sensitive development environments and managing proprietary code. Organizations using such AI tools must urgently reevaluate their security configurations and data handling practices.

  2. Windows Anti Piracy Tool Allegedly Identifies Cybercrime Suspect

    An anti piracy tool integrated into Windows has reportedly played a role in identifying a suspect linked to the Scattered Spider cybercrime group. This development raises questions about the scope and capabilities of embedded system monitoring features. It also highlights the dual use nature of some technologies, potentially impacting user privacy.

  3. CNIL Imposes 23 Simplified Sanctions Since January

    The French data protection authority CNIL has issued 23 new simplified sanctions since the beginning of the year. This action underscores the regulator's proactive stance on enforcing data protection compliance, particularly through streamlined procedures for less severe infringements. Organizations operating in the EU should be aware of CNIL's increased enforcement activity.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.