Skip to content

menu

Data Protection Report logo
HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseCurrent Page:Data breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

Data breach

Subscribe to Data breach via RSS

Changes to EU and UK data protection law – a tale of two GDPRs?

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on November 12, 2025

The EU Commission recently held a call for evidence on “simplification” of legislation in the data, cybersecurity, and AI space, ahead of a “Digital Omnibus” Act.  These changes look to make the EU’s digital rulebook more innovation-friendly, supporting the Commission’s…

California tightens data breach notification timelines, imposes 30-day notice requirement

Photo of Annmarie Giblin (US)Photo of Susana Medeiros (US)
By Annmarie Giblin (US) & Susana Medeiros (US) on November 5, 2025

California recently signed into law Senate Bill No. 446, which amends its data breach notification law, Section 1798.82 of the Civil Code, to require covered companies to notify affected California residents within 30 calendar days of discovery of the data…

Subscribe to Data Protection Report

Subscribe to this publication

Dutch DPA publishes report on personal data breaches

Photo of Naomi SchuitemaPhoto of Jurriaan JansenPhoto of Alexander McGuirePhoto of Tim Jones
By Naomi Schuitema, Jurriaan Jansen, Alexander McGuire & Tim Jones on September 3, 2025

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (Dutch DPA) recently published a report on personal data breaches, which provides valuable insights into the Dutch DPA’s views on incident response. It also contains some helpful statistics.

Increase…

The differences between non-disclosure, exfiltration and notice – a court’s view

Photo of David Kessler (US)Photo of Susan Ross (US)
By David Kessler (US) & Susan Ross (US) on March 19, 2025

By David Kessler and Sue Ross

Although there is scant case law on the question, it is generally accepted that it is not a violation of one’s duty not to disclose information if it is stolen from you.  Put another…

New York changes data breach law—in December and February

Photo of Annmarie Giblin (US)Photo of Susan Ross (US)Photo of Gerar Mazarakis (US)Photo of Phillip Pang (US)
By Annmarie Giblin (US), Susan Ross (US), Gerar Mazarakis (US) & Phillip Pang (US) on February 19, 2025

New York just finished a series of adjustments to its data breach notification requirements. Effective immediately, organizations must notify impacted individuals of a data breach within 30 days of its discovery instead of “in the most expedient time possible and…

FTC settlement requires disconnection of hardware from all no longer supported software

Photo of David Kessler (US)Photo of Susan Ross (US)
By David Kessler (US) & Susan Ross (US) on February 18, 2025

On January 16, 2025, the FTC announced a proposed complaint and consent agreement with one of the largest hosting companies in the world:  GoDaddy.  According to the complaint, the FTC found GoDaddy’s security practices “unreasonable for a company of its…

TR v Land Hessen – DPA not obliged to fine under the GDPR

Photo of Shan Nanayakkara
By Shan Nanayakkara on December 3, 2024

By Shan Nanayakkara

In TR v Land Hessen (C‑768/21) the European Court of Justice (“ECJ”) found that following a personal data breach, a supervisory authority is under no obligation to exercise its corrective powers, specifically the power to…

SEC issues $7 million in disclosure fines to SolarWinds victims

Photo of Chris Cwalina (US)Photo of Will Daugherty (US)Photo of Susan Ross (US)Photo of Gerar Mazarakis (US)
By Chris Cwalina (US), Will Daugherty (US), Susan Ross (US) & Gerar Mazarakis (US) on October 27, 2024

On October 22, 2024, the U.S. Securities and Exchange Commission (“SEC” or “Commission”) issued a series of orders imposing almost $7 million in disclosure fines against four global digital service providers impacted by the 2020 SolarWinds compromise. The SEC accused…

Security cameras, CAN-SPAM, and “reasonable or appropriate security”

Photo of David Kessler (US)Photo of Susan Ross (US)
By David Kessler (US) & Susan Ross (US) on September 9, 2024

On August 30, 2024, the Federal Trade Commission (FTC) announced a proposed settlement with security camera manufacturer Verkada Inc., claiming Verkada committed a variety of unfair or deceptive acts or practices in violation of § 5 of the Federal Trade…

California Attorney General and data security, access and retention

Photo of David Kessler (US)Photo of Susan Ross (US)Photo of Alyssa Saenz (US)
By David Kessler (US), Susan Ross (US) & Alyssa Saenz (US) on August 28, 2024

On June 13, 2024, the California Attorney General announced a $6.75 million judgment against Blackbaud regarding its data breach from 2020.  (We had previously covered the FTC’s settlement in February here.)  In the judgment with the California Attorney General…

Post navigation

Older Posts 

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2026, Norton Rose Fulbright LLP. All rights reserved.