{"id":5404,"date":"2020-11-11T07:34:00","date_gmt":"2020-11-11T07:34:00","guid":{"rendered":"https:\/\/seersco.com\/blogs\/?p=5404"},"modified":"2024-07-29T07:46:24","modified_gmt":"2024-07-29T07:46:24","slug":"weekly-privacy-updates-11-nov","status":"publish","type":"post","link":"https:\/\/seersco.com\/blogs\/weekly-privacy-updates-11-nov\/","title":{"rendered":"Privacy Updates This Week"},"content":{"rendered":"<p>Fines and more fines everywhere! It has been a week of fine related news. This is why to help you go through a list of the recent fines, we have summarized all of the key fines that have been imposed under the GDPR law in the past few years together for you. You can find more information in the <a href=\"https:\/\/seersco.com\/\">Seers<\/a> fine tracker here.<\/p>\n<p>To mitigate against all of these fines and penalties, it is imperative that you should reduce the possibility of a data breach for implementing the best practice in terms of policies, procedures and processes in your organisation. As well as to train your staff members on fulfilling their obligations under the GDPR by handling and processes personal data correctly through the use of this innovative <a href=\"https:\/\/seersco.com\/gdpr-staff-e-training\">GDPR Staff eTraining Solution<\/a>.<\/p>\n<p>Meanwhile, here are the top privacy headlines.<\/p>\n<h2>Top privacy headlines this week:<\/h2>\n<h3>Most expensive data breach ever!<\/h3>\n<p>JM Bullion, a dealer for gold, silver, copper, platinum and palladium, recently became a victim of a cyber-attack. The cyber-attack took place somewhere in February this year. However, due to a lack of security checks in place, the attack was not discovered until July this year. This attack allowed the hackers to fetch information of the dealer and the clients and harbor it for a long period of time before revealing it to the public.<\/p>\n<p>Read more <a href=\"https:\/\/seersco.com\/blogs\/jm-bullion-most-expensive-data-breach\/\">here<\/a><\/p>\n<h3>Oracle and Salesforce could face multi-billion-dollar GDPR lawsuit<\/h3>\n<p>Two of the biggest tech companies are sued by privacy campaigner and data protection specialist Rebecca Rumbul. According to Rumbul they \u201cunlawfully\u201d gathered user data and used it to \u201cfollow\u201d people around the internet with ads. This is unethical and unlawful in several countries of the world. The data violation is considered a strictly penalisable offence under the GDPR and the PECR. In the Netherlands, upon trial the two firms were found guilty, they could be looking at a fine of anywhere between $13 and $19.5 billion. The lawsuit can emerge in other countries in a similar context at any time.<\/p>\n<p>Read more <a href=\"https:\/\/www.itproportal.com\/news\/oracle-and-salesforce-could-face-dollar13bn-gdpr-lawsuit\/\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>Zoom has settled with the FTC over \u201cdeceptive\u201d security practices<\/h3>\n<p>The Federal Trade Commission announced a settlement with videoconferencing platform Zoom over \u201cmisleading claims\u201d about its security. The agency said in a statement that when Zoom incorrectly claimed its video calls were protected by end-to-end encryption, the company engaged in \u201cdeceptive and unfair practices that undermined the security of its users.\u201d<\/p>\n<p>Read more <a href=\"https:\/\/www.theverge.com\/2020\/11\/9\/21557074\/zoom-security-ftc-settlement-encryption?\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>Experian given final chance after breaking GDPR<\/h3>\n<p>The ICO has warned Experian to comply with an enforcement notice or face a potentially huge GDPR fine for illegally using customer data for marketing purposes. The final notice asks for immediate changes and clarifications on its policy for dealing with the matter. This notice is among the steps taken post the investigation of the top three credit organisations operating in the UK including Experian, Equifax and TransUnion.<\/p>\n<p>Read more <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/experian-threatened-with-massive\/\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>Data Protection Commission finds prison security system in breach of GDPR<\/h3>\n<p>The Irish DPC found problems within the prison security system. The Irish prisons are found to be in breach of the General Data Protection Regulation (GDPR) after investigating a complaint by a prison officer. According to the findings the security system involves scanning prison officers&#8217; thumbprints in order to admit them through security gates.<\/p>\n<p>Read more <a href=\"https:\/\/www.williamfry.com\/newsandinsights\/news-article\/2020\/11\/03\/data-protection-commission-finds-prison-security-system-in-breach-of-gdpr\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>Why is the ICO reducing fines?<\/h3>\n<p>ICO reduced GDPR fines to \u00a320m for BA and \u00a318.4m for Marriott. There are several mitigating factors at play here. Due to the initial severity of the breach, the ICO initially proposed a \u00a330m fine as an appropriate starting point for BA, and \u00a328m for Marriott. Later, only a month ago, the fines were reduced and revised.<\/p>\n<p>The ICO considered the remedial measures proposed by BA and Marriott as mitigation factors, including the following:<\/p>\n<ul>\n<li>They had each cooperated with the ICO\u2019s investigation<\/li>\n<li>They had each swiftly notified the affected data subjects and appropriate regulatory bodies<\/li>\n<li>The breaches had a negative impact on brand and reputation with or without the fines<\/li>\n<li>Neither BA nor Marriott received any financial gain as a result of the breach<\/li>\n<li>Marriott acted quickly to mitigate the risk of damage suffered by its customers, including: (i) deploying real-time monitoring and forensic tools on 70,000 devices on the network; (ii) implementing password resets; (iii) disabling known compromised accounts; and (iv) implementing enhanced detection tools<\/li>\n<\/ul>\n<p>Read more <a href=\"https:\/\/www.jdsupra.com\/legalnews\/ico-gdpr-fines-reduced-to-20m-and-18-4m-32087\/\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>Hotel reservation platform leaves millions of people exposed in massive data breach<\/h3>\n<p>Hotel reservation platform, Prestige Software, based in Spain has been exposing highly sensitive data from millions of hotel guests worldwide, dating as far back as 2013 and including credit card details for 100,000s of people. It sells a channel management platform called Cloud Hospitality to hotels that automates their availability on online booking websites like Expedia and Booking.com.<\/p>\n<p>Read more <a href=\"https:\/\/www.websiteplanet.com\/blog\/prestige-soft-breach-report\/?\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>New draft EU advice for financial institutions<\/h3>\n<p>At the start of the initial lockdown,ATM transaction volumes in the UK fell by 62%. People instantly switched to contactless payments. This resulted in a rise in the potential for financial crimes and data associated with the transactions. The EU has drafted advice for finance institutions to help in managing such data safely.<\/p>\n<p>Read more <a href=\"https:\/\/www.jdsupra.com\/legalnews\/privacy-and-payments-new-draft-eu-89021\/\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a><\/p>\n<h3>Surprise Suprise!<\/h3>\n<p>Did you know that you can avoid several lawsuits just by training your workforce on GDPR? It takes only 40 minutes to prove compliance. Find out where you stand with the GDPR, train your workforce and stay cyber-safe during the lockdown with ease. More on this in the video below:<\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=v307T6QTQVQ\" rel=\"nofollow noopener\" target=\"_blank\">How to reduce the liability on your business as your employees work from home.<\/a><\/p>\n<h3>GDPR Staff eTraining Solution<\/h3>\n<p>Help your staff to help your organisation stay safe during these challenging times by training them on complying with the GDPR.<\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":3,"featured_media":5102,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[26,1],"tags":[],"class_list":["post-5404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-message","category-uncategorized","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","no-featured-image-padding"],"_links":{"self":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts\/5404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/comments?post=5404"}],"version-history":[{"count":0,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts\/5404\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/media\/5102"}],"wp:attachment":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/media?parent=5404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/categories?post=5404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/tags?post=5404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}