In 18 daystakes effect
Modernization of the Nation's Alerting Systems; Protecting the Nation's Communications Systems From Cybersecurity Threats
2026-09-29 · Federal Communications Commission
What organisations are now required to do about security and personal data, when each obligation starts, and what has happened to the ones that did not. Every entry is the issuing body’s own publication, linked to the original.
In 18 daystakes effect
2026-09-29 · Federal Communications Commission
Background information Date of final decision: 28 August 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Compliance order, Communication order personal data breach Key words: GDPR enforcement, Data subjects rights, Fines, Health and research Summary of the Decision Origin of the case This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the Data Protection Commission (DPC) in October 2023 and November 2023. In both cases, individuals gained unauthorised access to paper records stored and retained in both St. Loman’s Hospital (Mullingar, County Westmeath) and St Conal’s Hospital (Letterkenny, County Donegal). Both locations are former disused psychiatric hospitals.Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities. Key Findings The Data Protection Commission (DPC) has announced its final decision
Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commission allegations that the online retail giant knowingly violated the Fair Credit Reporting Act (FCRA) by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud. The complaint , filed by the Department of Justice upon notification and referral from the FTC, alleged that in numerous instances, Amazon.com Inc. failed to comply with Section 609(e) of the FCRA, which requires companies to, within 30 days of a consumer’s request, provide victims of identity theft with application and business transaction records about fraudulent transactions made in their names. According to the complaint, Amazon had no written policy to respond to Section 609(e) requests until early 2025, after it learned of the FTC’s investigation, despite prior outreach from FTC staff advising the company to review its compliance with Section 609(e). “Amazon often put identity theft victims through a Kafkaesque ordeal by demanding they identify the thief who stole their information before Amazon would release the records the law entitles them to—records that could help vi
Sources: the US Federal Register, the Securities and Exchange Commission, the Federal Trade Commission, the European Data Protection Board and the UK National Cyber Security Centre. Dates are as published and are shown in UTC. This is a tracker, not legal advice, and an obligation that applies to you is a question for your own counsel.