This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
23andMe Fined $18 Million by NY Attorney General for Genetic Data Breach
Fine: $18 million
New York Attorney General James has secured an $18 million settlement from 23andMe following a significant data breach that compromised customers' genetic data. The settlement mandates new security measures for the genetic testing company, highlighting the severe consequences of failing to protect sensitive health information. This action underscores the increasing regulatory scrutiny on companies handling genetic and other health related personal data.
A genetic testing company experiences a data breach exposing sensitive health information of its customers. Following an investigation, a state Attorney General imposes a significant fine and mandates new security measures. What is the primary compliance challenge highlighted by this scenario for organizations handling genetic data?
Ensuring compliance with general data retention policies for non sensitive data.
Implementing robust security safeguards specifically tailored for highly sensitive personal data and managing the legal implications of a breach.
Obtaining explicit consent for marketing communications unrelated to health services.
Adhering to cross border data transfer mechanisms for aggregated, anonymized data.
The Italian data protection authority has imposed a €1.7 million fine on telecommunications company WINDTRE for multiple data breaches. This enforcement action highlights the ongoing regulatory focus on telecommunications providers and their obligations to protect customer data. Organizations must ensure robust security measures and prompt incident response to avoid significant penalties.
Mozilla research indicates that the period tracking app Stardust is sharing users' health data with an analytics firm. This raises significant privacy concerns regarding the handling of sensitive health information by consumer applications. Companies must be transparent about data sharing practices and obtain explicit consent for processing sensitive personal data.
Researchers have found that AI powered spam filters are being circumvented by 'text salting,' a decades old email trick. This highlights a critical vulnerability in AI driven security systems, demonstrating that sophisticated AI models can still be fooled by simple, established attack methods. Organizations relying on AI for security should be aware of these limitations and implement multi layered defenses.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.