Garante fines Emirates €180,000 over assisted-travel health data
Italy's Garante fined Emirates €180,000 over MEDIF health-data transparency and retention. Practical lessons for accessibility and assisted-travel data.
Italy's Garante fined Emirates €180,000 over MEDIF health-data transparency and retention. Practical lessons for accessibility and assisted-travel data.
The ICO has issued a formal caution to a former healthcare professional after concluding a criminal investigation linked to medical…
The Irish Data Protection Commission has fined the Health Service Executive €300,000 after a ransomware attack on the laboratory information…
Yes. Employee data is personal data, so GDPR applies whenever an employer collects, stores, shares, searches, or deletes it. The…
In practice, people often say “GDPR risk assessment”, but the legal test under the UK GDPR is whether you need…
The ICO has fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 after a phishing-led cyber attack led to…
NHS staff rarely face dismissal for data breaches. Analysis of the Southport and Nottingham record access scandals and what they…
California says 23andMe failed to protect genetic data and misled consumers after the 2023 breach. Here is why the lawsuit…
On 4 June 2026, the Information Commissioner’s Office said it had secured £118,852.32 in confiscation orders against two former RAC…
Two NHS record-access scandals now sit side by side in the public record. On 21 May 2026, Nottingham University Hospitals…
On 29 May 2026, the Information Commissioner’s Office said its 2026/27 AI work will include an AI code of practice,…
On 26 May 2026, the French data protection authority CNIL fined IQVIA Operations France €5 million over failures in two…
California’s 11 February 2026 settlement with Disney is one of the clearest CCPA warnings yet for teams that run the…
On 21 May 2026, the ICO said it had secured a £355,880.10 confiscation order against former motor-insurance worker Rizwan Manjra.…
A templated privacy policy can look reassuring while hiding gaps in complaints handling, SAR workflow, consent records, and breach response.…
On 20 May 2026, the Information Commissioner’s Office said it had fined Energy Prices Direct Limited £160,000 after the company…
California’s settlement with General Motors shows how CCPA data minimisation is now an enforcement risk. Here’s what the case says…
Why some UK publishers can now use consent-or-pay banners, what the ICO changed on 23 January 2025, and what managers…
Irish DPC fined Permanent TSB €277,500 after phone-based impersonation attacks exposed weak contact-centre controls and late GDPR breach reporting.
From 19 June 2026, UK organisations must have a process for handling data protection complaints. This requirement needs a live…