When confidential information appears in the media, reaches a competitor, or surfaces anonymously online, many organizations assume the source will never be identified. Yet while today’s workplace is more complex than ever, it is also more heavily documented.
Data Privacy
New California law expands personal data deletion mandate for businesses
Businesses will soon have to honor requests by California residents to delete personal data no matter who collected the information originally.
Future GDPR fines set to be more equal across EU
The EU’s main data regulator has issued new guidelines so that fines under the General Data Protection Regulation are in line from one EU country to the next.
Grindr agrees $35 million settlement for U.K. complaint over serious data breaches
The tech company behind gay dating app Grindr has agreed to make a $35.2 million settlement over allegations that it shared sensitive personal medical informationโincluding whether people were HIV positiveโwith third parties.
Uber’s driver-blocking algorithm draws nearly $1 billion Dutch privacy penalty
The Dutch data protection authority has fined Uber $959.2 million for using automatic decision-making tech to deactivate driversโ accounts if they received poor customer reviews.
New U.K. data law takes full effect: What compliance officers need to know
The U.K. has amended its data protection rules with a sweeping law that aims to simplify compliance with existing privacy legislation, including the GDPR. However, compliance officers should be aware that the need to protect personal data remains paramount.
Meta reaches $18B settlement with states over child safety violations
Meta has agreed to pay up to $18 billion and overhaul teen safety features on Facebook and Instagram as part of a settlement with 47 states, the District of Columbia, and U.S. territories.
Data regulator issues privacy guidance over smart devices
Companies that manufacture smart devices are set to face increased scrutiny from data regulators following concerns that most consumers are unaware of how they collect, use and sell their personal information.
Beyond breaching privacy: The compliance risks of workplace surveillance
When organizations implement workplace surveillance tools, the conversation often begins with privacy. Questions about employee consent, data collection, retention periods, and legal compliance are essential. But as workplace monitoring technologies become more sophisticated, focusing exclusively on privacy risks often overlooks a much larger challenge.
India’s data privacy rules entering enforcement phases, raising compliance stakes for U.S. financial firms
Indiaโs Digital Personal Data Protection Act soft enforcement period will end in November. With more active enforcement to follow, financial institutions that failed to comply could face penalties of up to $26.2 million.


