<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/data-privacy" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Data-privacy ]]></title>
                <link>https://www.itpro.com/tag/data-privacy</link>
        <description><![CDATA[ All the latest data-privacy content from the ITPro team ]]></description>
                                    <lastBuildDate>Tue, 27 Jan 2026 11:45:37 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ AI is “forcing a fundamental shift” in data privacy and governance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/ai-is-forcing-a-fundamental-shift-in-data-privacy-and-governance</link>
                                                                            <description>
                            <![CDATA[ Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j2ts9qHpTFsYN7yTaFKsU9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Jan 2026 11:45:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:description>                                                            <media:text><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:text>
                                <media:title type="plain"><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprises are shaking up their approach to data privacy and governance, new research shows, largely due to added risk factors created by <a href="https://www.itpro.com/technology/artificial-intelligence/large-enterprises-could-be-wavering-on-ai-adoption">AI adoption</a>.</p><p>According to Cisco's 2026 <em>Data and Privacy Benchmark Study</em>, nearly all companies are expanding privacy programs and governance frameworks to protect their data. </p><p>AI is the main reason for 90%, with 93% saying they planned further investment to keep up with the complexity of AI systems and the expectations of customers and regulators. </p><p>The survey found that 38% spent at least $5 million on their privacy programs in the past year – marking a dramatic increase from just 14% who spent over that threshold in 2024. </p><p>Notably, these programs appear to be working well. An overwhelming 96% of organizations reported that robust privacy frameworks were helping unlock AI agility and innovation, and 95% said privacy was essential for building customer trust in AI-powered services.</p><p>One interesting change spotted by the researchers is that trust is no longer just a question of meeting regulatory requirements. </p><p><a href="https://www.itpro.com/security/data-protection/fears-over-ai-model-collapse-are-fueling-a-shift-to-zero-trust-data-governance-strategies">Data governance</a> is now seen as a strategic business enabler, with 99% of organizations reporting at least one tangible benefit from their privacy initiatives, such as enhanced agility, innovation, and greater customer loyalty. </p><p>Almost half said that clear communication about how data is collected and used is the most effective way to build customer confidence.</p><p>As a result, governance is evolving – although many organizations are still working to define and establish the structures they need to manage AI responsibly.</p><p>While three-quarters report having a dedicated AI governance body in place, only 12% describe it as mature. Meanwhile, 65% of organizations struggle to access relevant, high-quality data efficiently.</p><p>"<a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>is forcing a fundamental shift in the data landscape, calling for holistic governance of all data – both personal and non-personal,” said Jen Yokoyama, senior vice president, legal innovation and strategy, at Cisco. </p><p>“Organizations must deeply understand and structure their data to ensure every automated decision is explainable. It’s not just for compliance, but a necessary scaling engine for AI innovation.”</p><h2 id="data-requirements-are-causing-headaches">Data requirements are causing headaches</h2><p>While 72% of respondents were generally positive about data privacy laws, there is a growing push to streamline and update data requirements, Cisco found.</p><p>Just over eight-in-ten organizations surveyed face heightened demand for data localization and global data complexity - and 85% said this adds cost, complexity, and risk to cross-border service delivery. #</p><p>Similarly, 77% report these requirements limit their ability to offer seamless 24/7 service across markets.</p><p>On top of this, the assumption that locally stored data is inherently more secure is gradually eroding, from 90% in 2025 to 86% in 2026.</p><p>“To capture the potential of AI, organizations (83%) are advocating for a shift toward harmonized international standards,” said Harvey Jang, Cisco vice president and chief privacy officer. </p><p>“They recognize that global consistency is an economic necessity to ensure data can flow securely while maintaining the high standards of protection required for trust.”</p><p>Cisco said enterprises should invest in robust data infrastructure, prioritizing transparency, and embedding security and privacy throughout AI initiatives. </p><p>Elsewhere, they should make sure they're making informed decisions about data localization, establish strong <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">AI governance</a>, and kit out their teams with comprehensive training and safeguards. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 26% of privacy professionals expect a “material privacy breach” in 2026 as budget cuts and staff shortages stretch teams to the limit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/26-percent-of-privacy-professionals-expect-a-material-privacy-breach-in-2026-as-budget-cuts-and-staff-shortages-stretch-teams-to-the-limit</link>
                                                                            <description>
                            <![CDATA[ Overworked, underfunded privacy teams are being left hung out to dry by executives ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GhEZMSNNwfTA7nEPTVe6dh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z965G2Zb9Pp5avc9gVoTx9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Jan 2026 17:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z965G2Zb9Pp5avc9gVoTx9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male and female data privacy professionals looking at a desktop computer monitor in an office space, with charts and figures pictured on wall behind.]]></media:description>                                                            <media:text><![CDATA[Male and female data privacy professionals looking at a desktop computer monitor in an office space, with charts and figures pictured on wall behind.]]></media:text>
                                <media:title type="plain"><![CDATA[Male and female data privacy professionals looking at a desktop computer monitor in an office space, with charts and figures pictured on wall behind.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z965G2Zb9Pp5avc9gVoTx9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In January 2025, research from ISACA warned that <a href="https://www.itpro.com/security/privacy/data-privacy-professionals-are-severely-underfunded-and-its-only-going-to-get-worse"><u>organizations were deprioritizing privacy budgets and cutting funds</u></a> for teams. One year on and the situation has deteriorated further, the association claims. </p><p>A confluence of challenges, including funding cuts, staff shortages, and growing regulatory compliance pressures are pushing teams to their limits. </p><p>Nearly half (44%) of European-based survey respondents told ISACA their teams are already underfunded while 54% expect budgets to be cut further across 2026. </p><p>Around four-in-ten (39%) legal privacy workers and over half (51%) of technical privacy workers also reported staff shortages across their teams. </p><p>These funding cuts could have severe consequences further down the line, the association warned, especially as organizations continue ramping up adoption of AI tools.</p><p>Nearly half (49%) of respondents revealed that managing risks associated with emerging technologies is now a major obstacle to their long-term strategies. The pace of technological change is also having a marked impact on morale and workloads, with more than one-third (68%) highlighting this as a key challenge. </p><p>Adding insult to injury, 64% identified compliance-related challenges off the back of new technologies as a key stress driver, with teams forced to pivot rapidly to accommodate for regulations. </p><p>Chris Dimitriadis, global chief strategy officer at ISACA, said the study shows privacy teams are now being asked to “manage more risk with fewer resources” – and the impact is beginning to show across Europe. </p><p>“As organizations adopt new technologies at speed, the volume and complexity of privacy obligations grow in parallel – yet many teams are still operating without the staffing, funding or training they need to keep pace,” he commented. </p><h2 id="privacy-teams-are-bracing-for-impact">Privacy teams are bracing for impact</h2><p>Privacy teams are frightfully aware of the potential risks associated with understaffing and budget cuts – it’s a trend they’ve contended with for several years now, the study noted.</p><p>Notably, many teams are bracing for impact as the effects of these trends come to fruition. More than one-quarter (26%) of respondents told ISACA their organization is “likely to experience a material privacy breach” within the next year.</p><p>“Together, this highlights a growing contradiction for European organizations: privacy risk and regulatory expectations continue to rise, while investment in people and resources is being scaled back,” ISACA said in a statement.</p><h2 id="boards-still-aren-t-tuned-in">Boards still aren’t tuned in</h2><p>Despite repeated calls for heightened support, privacy professionals still feel board-level attention is “inconsistent”. Just over one quarter (26%) of respondents said their board is “failing to adequately prioritize privacy” regardless of intensified risks.</p><p>“When boards underestimate privacy, they underestimate a fundamental pillar of digital trust,” Dimitriadis said. “A single privacy breach can erode years of brand equity, damage customer relationships and trigger significant regulatory consequences. </p><p>“Prioritizing privacy is not simply a compliance requirement; it is a business imperative.”</p><p>There are positives with regard to privacy awareness, however. The potential monetary penalties associated with regulatory compliance failures mean executives are beginning to pay attention. </p><p>More than three quarters (79%) of respondents in Europe said they now use a framework or regulation such as GDPR to “guide their privacy program”. </p><p>64% now have a formal <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response plan</a> embedded within their broader privacy strategies, a figure which ISACA said could be improved upon. </p><p>However, nearly half (44%) of respondents said the board views their privacy programs as merely “compliance-driven” and not from a holistic perspective. </p><p>ISACA warned this is a “narrow focus” which fails to fully address privacy-related risks, thereby leaving organizations exposed. </p><p>“These gaps underline a critical truth: privacy cannot be strengthened solely through controls or checklists,” Dimitriadis commented.  “It demands sustained investment in people, governance and culture – and that begins at the top.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU lawmakers want to limit the use of ‘algorithmic management’ systems at work ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/eu-lawmakers-want-to-limit-the-use-of-algorithmic-management-systems-at-work</link>
                                                                            <description>
                            <![CDATA[ All workplace decisions should have human oversight and be transparent, fair, and safe, MEPs insist ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wmC5cfiUeRywWwRyUaNThT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 10:32:17 +0000</pubDate>                                                                                                                                <updated>Thu, 18 Dec 2025 10:33:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:description>                                                            <media:text><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:text>
                                <media:title type="plain"><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MEPs are calling on the European Commission to establish more robust rules on the use of algorithms in recruitment and staff management amidst concerns over privacy and discrimination.</p><p>According to recent <a href="https://www.europarl.europa.eu/RegData/etudes/STUD/2025/774670/EPRS_STU(2025)774670_EN.pdf" target="_blank"><u>EU research</u></a>, 42% of EU workers are currently subject to algorithmic management in the workplace, a figure expected to rise to 55.5% within the next five years.</p><p>There's already legislation on artificial intelligence and data protection at EU level, including the <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">EU AI Act</a> and <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, while rules focusing more specifically on the use of AI at work are laid out in the Platform Work Directive.</p><p>However, the EU lawmakers believe that more specific legislation is required. It has now proposed a series of recommendations aimed at ensuring that the use of automated monitoring and decision-making systems in the workplace is transparent, fair, and safe.</p><p>The main thrust of the proposals is that there must be human oversight of all decisions taken or supported by algorithmic management systems.</p><p>Workers should have the right to request explanations of any decisions taken or supported by such systems - and, if a worker believes his or her rights to have been infringed, they should have the right to ask for a review. </p><p>If successful, the system in question could be modified or discontinued.</p><p>Decisions on the offer or termination of employment, the renewal or non-renewal of a contract, changes in pay, or disciplinary action should always be taken by a human and be subject to human review.</p><p>"This topic affects both employers and 200 million workers in the EU. A human-centered approach is key, and the rights, safety, and dignity of employers and employees must be strictly respected," said MEP Andrzej Buła. </p><p>"This sends a strong signal: Europe can combine competitiveness with social responsibility. It can support innovative enterprises without sacrificing high standards and employee protection."</p><h2 id="cracking-down-on-algorithmic-management">Cracking down on ‘algorithmic management’</h2><p>A key focus of the crackdown centers on the fact that workers should be informed about how algorithmic management systems impact working conditions, when they're used to take automated decisions, what type of data they collect or process, and how human oversight is ensured. </p><p>MEPs believe workers should be consulted when these systems are used to make decisions affecting pay, evaluation, task allocation or working time. </p><p>Similarly, the use of these systems should respect wellbeing and not put workers' safety or physical or mental health at risk.</p><p>To protect workers’ privacy and data, the proposed rules would ban the processing of data relating to the emotional, psychological or neurological states of employees, as well as their private communications or geolocation outside working hours. </p><p>Elsewhere, the guidelines aim to limit the use of employee data while off-duty, as well as the use of data relating to freedom of association and collective bargaining. </p><p>There were 451 votes in favour of the recommendations and 45 against, with 153 abstentions. The European Commission now has three months to respond, by either informing Parliament on the steps it plans to take, or by giving reasons for a refusal.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mistral AI wants businesses to make new memories with Le Chat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/mistral-ai-wants-businesses-to-make-new-memories-with-le-chat</link>
                                                                            <description>
                            <![CDATA[ The company hopes new functionality and Connection Partners will broaden business appeal ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7eLsirFGiMb8rxc6DWLrAV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KAT4t6nJZ86ZbXRGw2oPr4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Sep 2025 09:51:47 +0000</pubDate>                                                                                                                                <updated>Tue, 28 Oct 2025 11:50:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KAT4t6nJZ86ZbXRGw2oPr4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mistral AI logo and branding pictured on a computer screen, with company logo pictured on smartphone in foreground.]]></media:description>                                                            <media:text><![CDATA[Mistral AI logo and branding pictured on a computer screen, with company logo pictured on smartphone in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Mistral AI logo and branding pictured on a computer screen, with company logo pictured on smartphone in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KAT4t6nJZ86ZbXRGw2oPr4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Mistral AI, the French competitor to generative AI firms like OpenAI and Anthropic, has unveiled a new set of capabilities and partners for its AI assistant, Le Chat. </p><p>The first of these enhancements is Memories, which allows Le Chat to learn from previous interactions and refer back to previous insights, decisions and references. According to Mistral AI, this will help to “ensure continuity and deeper understanding over time”.</p><p>“Users stay in full control of their data as Le Chat allows anyone to add, edit, update, or remove any entry at any time, with clear privacy settings,” the company said, going on to claim that its memory capacity is “10 times higher than competitors for paying users and five times for free users”.</p><p>In addition to Memories, the company has also added over 20 Connection Partners to Le Chat, including Atlassian, Box, Stripe, GitHub, and Cloudflare, with Salesforce, Snowflake, and Databricks joining the line-up “soon”.</p><p>The integration of these Connection Partners gives Le Chat access to all relevant internal documentation. </p><p>Mistral added that both the new features, Memories and Connection Partners, are consistent with its commitment to building “privacy-first AI products”, adding they are “designed to ensure users have full control over their data”.</p><p>“This release makes Le Chat stand out as enterprise's most well-connected AI assistant,” the company said. “Users can now get a personalized experience, and build workflow automations across commonly used enterprise platforms.”</p><p>Commenting on the announcement, Ben Kus, CTO of Box, said: “AI delivers the highest ROI for enterprises when it adapts to their needs and is enriched by their unique business content and data.”</p><p>"Our integration with Mistral's Le Chat, together with the Box <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-model-context-protocol-mcp">MCP server</a>, brings powerful conversational AI directly to global customers' content in Box,” Kus added.</p><h2 id="mistral-has-a-penchant-for-privacy">Mistral has a penchant for privacy</h2><p>While Mistral AI’s claim to make “privacy-first AI products” is clearly its own marketing line in action, there’s nevertheless a grounding in truth.</p><p><a href="https://blog.incogni.com/ai-llm-privacy-ranking-2025/" target="_blank"><u>Research from Incogni</u></a> carried out in May 2025 ranked Le Chat as the least privacy-invasive platform, with ChatGPT and Grok coming in second and third respectively. At the other end of the scale were <a href="http://meta.ai"><u>Meta.ai</u></a> and Gemini.</p><iframe allow="" height="800" width="1080" id="" style="border:none;" data-lazy-priority="high" data-lazy-src="https://e.infogram.com/523927c4-85fe-48bd-bad7-9f4b4f6f5bc4?src=embed"></iframe><p>This reputation has also helped the company make a name for itself in the growing field of sovereign AI. In June 2025, <a href="https://www.aivancity.ai/blog/en/vivatech-2025-mistral-ai-unveils-a-sovereign-hpc-infrastructure-in-partnership-with-nvidia/"><u>at VivaTech</u></a>, the company announced a collaboration with Nvidia to create sovereign AI services in Europe. </p><p>Similarly, in July of the same year it launched AI for Citizens which saw the company working “in close partnership with governments and local entities to build solutions to local needs and goals”, with an emphasis on data sovereignty. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/is-the-future-of-business-ai-specialized-services"><u>Is the future of business AI specialized services? | IT Pro</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/new-dell-ai-factory-partners-debuted-at-dell-technologies-world-2025"><u>New Dell AI Factory partners debuted at Dell Technologies World 2025 | IT Pro</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/microsofts-mistral-ai-partnership-has-eu-regulators-concerned-heres-why"><u>Microsoft’s Mistral AI partnership has EU regulators concerned - here’s why | IT Pro</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/nvidia-deutsche-telekom-team-up-for-sovereign-industrial-ai-cloud"><u>Nvidia, Deutsche Telekom team up for "sovereign" industrial AI cloud | IT Pro</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SAP wants to take data sovereignty to the next level with new 'on-site' infrastructure options ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-management/sap-wants-to-take-data-sovereignty-to-the-next-level-with-new-on-site-infrastructure-options</link>
                                                                            <description>
                            <![CDATA[ The cloud computing giant will allow customers to host SAP-managed infrastructure directly within their own facilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2JvnfpX8e96UaZzWxP9WMS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cEu47UXj4cDoew3xyTtJfG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Sep 2025 14:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Management]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cEu47UXj4cDoew3xyTtJfG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SAP logo is seen on an office building in Budapest, Hungary on July 28, 2022. ]]></media:description>                                                            <media:text><![CDATA[SAP logo is seen on an office building in Budapest, Hungary on July 28, 2022. ]]></media:text>
                                <media:title type="plain"><![CDATA[SAP logo is seen on an office building in Budapest, Hungary on July 28, 2022. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cEu47UXj4cDoew3xyTtJfG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SAP has announced a significant expansion of its sovereign cloud offering with a new “On-Site” solution. </p><p>The launch of the On-Site model will give customers the ability to host managed cloud infrastructure within their own facilities in a move the tech firm said provides the “ultimate level of physical control and data residency”.</p><p>Thomas Saueressig, member of the executive board of SAP SE for customer services and delivery, said the expansion is in direct response to growing enterprise calls for heightened data sovereignty controls. </p><p>“Organizations around the world are seeking greater control over their digital environments,” Saueressig said. </p><p>“With Sovereign Cloud On-Site, SAP empowers customers to define their own sovereignty boundaries while leveraging our global infrastructure expertise and partnerships.”</p><p>The new On-site option aims to offer “flexible sovereignty models” that meet the needs of organizations operating across various areas, SAP said, particularly governments and businesses in regulated sectors. </p><p>Varied deployment options mean organizations can choose between SAP-hosted infrastructure, hyperscaler-based models, or customer-site hosted options. </p><p>“With SAP Sovereign Cloud On-Site, we are redefining what sovereignty means for our customers,” said Martin Merz, president of SAP’s sovereign cloud division. </p><p>“By placing SAP-managed infrastructure directly within customers’ own facilities, we offer unmatched control, compliance, and operational assurance without compromising innovation.”</p><h2 id="what-to-expect-from-sap-s-sovereign-cloud">What to expect from SAP’s sovereign cloud</h2><p>SAP said its sovereign cloud initiative centers around a series of “core capabilities”, which naturally includes a strong focus on data sovereignty. </p><p>Under the scheme, organizations retain full ownership and control of sensitive data, based on local regulatory requirements. </p><p>“Operational sovereignty” features allow enterprises to manage environments with SAP resources while “technical sovereignty” enables customers to run SAP workloads using deployment options based on their individual needs - this applies to those operating in regulated industries, for example. </p><h2 id="sovereign-cloud-in-the-spotlight">Sovereign cloud in the spotlight</h2><p>Data sovereignty has become a recurring talking point on both sides of the Atlantic in recent years. In May 2024, industry analysts told <em>ITPro </em>that sovereign cloud services are now <a href="https://www.itpro.com/cloud/cloud-computing/sovereign-cloud-services-are-now-the-bare-minimum-expected-by-customers-and-hyperscalers-are-scrambling-to-meet-demand"><u>the “bare minimum” expected from European customers</u></a>. </p><p>A key factor behind this growing demand is the array of stringent regulatory requirements introduced - or currently being introduced - in Europe. Naturally, providers have acted swiftly to meet this demand. </p><p>A host of industry heavyweights, including Google Cloud, Amazon Web Services (AWS), Microsoft, and Oracle, have all since launched dedicated sovereign cloud services for European customers. </p><p>Recent months have seen new concerns arise about data sovereignty, with research showing enterprises in the UK and EU both <a href="https://www.itpro.com/security/data-protection/data-sovereignty-a-growing-priority-for-uk-enterprises"><u>cited worries about US interference</u></a>. </p><p>These concerns came after the Trump administration issued a memorandum in early 2025 pledging to defend American tech companies from “overseas extortion”. </p><p>In the wake of the move, Microsoft president Brad Smith said the tech giant would <a href="https://www.itpro.com/cloud/cloud-computing/microsoft-says-itll-protect-eu-cloud-customers-from-shutdown-demands"><u>resort to legal action to protect EU customers</u></a> from US demands to shut down services.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/leadership/sap-names-augusta-spinelli-as-new-emea-president">SAP names Augusta Spinelli as new EMEA president</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/capgemini-and-sap-are-teaming-up-with-mistral-heres-why">Capgemini and SAP are teaming up with Mistral – here’s why</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/sap-rolls-out-joule-for-developers">SAP rolls out ‘Joule for Developers’ AI coding assistant</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data (Use and Access) Act comes into force ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/data-use-and-access-act-comes-into-force</link>
                                                                            <description>
                            <![CDATA[ Organizations will be required to have an effective data protection complaints procedure and fulfil new requirements for online services that children are likely to use ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YrhjXAqUoDhXLdoonRPJBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xCYoySEaBmvVjAaicHQGX8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Jun 2025 10:20:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xCYoySEaBmvVjAaicHQGX8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A side-on shot of someone&#039;s hands using a laptop and holding a phone, overlaid with text and information blocks representing online payments, delivery, and payment APIs.]]></media:description>                                                            <media:text><![CDATA[A side-on shot of someone&#039;s hands using a laptop and holding a phone, overlaid with text and information blocks representing online payments, delivery, and payment APIs.]]></media:text>
                                <media:title type="plain"><![CDATA[A side-on shot of someone&#039;s hands using a laptop and holding a phone, overlaid with text and information blocks representing online payments, delivery, and payment APIs.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xCYoySEaBmvVjAaicHQGX8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Data (Use and Access) Act has received royal assent and has now become law, with its various provisions coming into force over the next 12 months.</p><p>Updating the UK <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulation</a> (UK GDPR), the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a> (DPA), and the Privacy and Electronic Communications Regulations (PECR), it sets out how personal information can be used for research. </p><p>It loosens restrictions on some automated decision making, makes provisions for using some cookies without consent, and allows charities to send people electronic mail marketing without consent in certain circumstances. It also requires organisations to have a data protection complaints procedure and introduces a new lawful basis of recognised legitimate interests.</p><p>"For too long, previous governments have been sitting on a goldmine of data, wasting a powerful resource which can be used to help families juggle food costs, slash tedious life admin, and make our NHS and police work smarter," said technology secretary Peter Kyle.</p><p>"These new laws will finally unleash that power for hardworking people – putting cash back in pockets and boosting vital public services, all part of our Plan for Change."</p><p>The government is pushing the benefits to the NHS, saying it will ensure that healthcare information, such as a patient's pre-existing conditions, appointments, and tests, can easily be accessed in real time across all NHS trusts, GP surgeries, and ambulance services, no matter what IT system they're using. </p><p>Enabling data sharing across platforms, it said, will save NHS staff 140,000 hours a year in admin tasks.  </p><p>"No longer will patients be left waiting needlessly for treatment as NHS staff battle 'computer says no' bureaucracy," said secretary of state for health and social care Wes Streeting.</p><p>"We're making it easier for GPs, nurses, and paramedics to access the information they need, when they need it, safely, securely, and at speed."</p><p>The Act gives the Information Commissioner's Office (ICO) new powers, including the ability to compel witnesses to attend interviews, request technical reports, and issue fines of up to £17.5 million or 4% of global turnover under Privacy and Electronic Communications Regulations (PECR). </p><p>The ICO has published a catalogue of resources to help explain what this new legislation means for businesses.</p><p>"Over the coming months we will launch new guidance, open consultations, and provide practical tools to help embed the Act's principles into everyday operations," said <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">information commissioner</a> John Edwards. </p><p>"Our goal is to ensure that data can be used confidently and responsibly to deliver better services, drive economic growth, and uphold public trust."</p><p>Organizations, said the ICO, should prepare by familiarizing themselves with the changes, making sure they're doing enough to satisfy the new explicit requirements for online services that children are likely to use and, if necessary, overhauling their complaints procedures. </p><p>There's more information from the government <a href="https://www.gov.uk/government/publications/data-use-and-access-bill-factsheets">here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Data Use and Access Bill? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/data-use-and-access-bill-explained</link>
                                                                            <description>
                            <![CDATA[ Aimed at boosting efficiency in the UK, the Data Use and Access Bill is designed to cut red tape around data use. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KymztDpbaTtgK28HCwdGxn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Feb 2025 13:04:32 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Feb 2025 09:06:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:description>                                                            <media:text><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:text>
                                <media:title type="plain"><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/business/public-sector/government-says-new-data-bill-will-free-up-millions-of-hours-of-public-sector-time">Data Use and Access Bill</a> is a piece of legislation introduced by the UK government to allow for a greater level of <a href="https://www.itpro.com/business/policy-legislation/361798/uk-and-us-agree-on-deeper-data-sharing-partnership">data sharing</a> and data exchange within both public and private sector organizations. </p><p>Introduced to parliament <a href="https://www.itpro.com/business/public-sector/government-says-new-data-bill-will-free-up-millions-of-hours-of-public-sector-time"><u>towards the end of 2024</u></a>, the government says this bill could save millions of hours for many public sector workers as well as add an estimated £10 billion to the UK economy over a period of 10 years. The bill can be divided into seven sections <a href="https://commonslibrary.parliament.uk/research-briefings/cbp-10186/#:~:text=According%20to%20the%20government%2C%20the,pressures%20to%20the%20country's%20finances%E2%80%9D." target="_blank"><u>according to the government</u></a>, with the first centered on the enablement of “smart data” use outside the finance sector.</p><p>It would regulate the provision of digital verification services, digitalize birth and death registrations, make changes to the UK’s data protection regime, and transfer the function of the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> to a new Information Commission.</p><p>The bill would also make further provisions about the use of or access to data in areas such as health and social care, smart meter communication services, public service delivery, and online safety. </p><p> "With laws that help us to use data securely and effectively, this Bill will help us boost the UK’s economy, free up vital time for our front-line workers, and relieve people from unnecessary admin so that they can get on with their lives," technology secretary <a href="https://www.itpro.com/business/policy-and-legislation/who-is-peter-kyle-the-uks-new-technology-secretary-and-what-are-his-plans-for-the-future-of-the-sector"><u>Peter Kyle</u></a> said at the time of the bill’s announcement.</p><p>Experts from the tech sector have broadly welcomed the legislation, commending its focus on improving efficiency. Alex Laurie, senior vice president at Ping Identity, said that any legislation of this kind is a positive step.</p><p>“From my perspective, anything that makes it easier for us to do business as a citizen is massively important,” Laurie tells <em>ITPro</em>. “If it takes time out of people's working day I think it's an important thing.”</p><h2 id="how-will-the-data-use-and-access-bill-affect-the-public-sector">How will the Data Use and Access Bill affect the public sector?</h2><p>This legislation has the public sector at its core, with many of the bill’s benefits noted by the government relating to heightening efficiencies in the UK’s police force or the National Health Service (NHS).</p><p>Within the NHS, for example, administrative processes can be very lengthy and time consuming, having a negative impact on the organization and the customer. Laurie expressed his own understanding of this, referring to a study his firm undertook regarding disabled parking permits. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=62749338&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“We did an analysis a few years ago on how many agencies and individual units were involved in getting a blue badge for someone, and it was like 35 different steps, which all needed identification, verification, proof,” Laurie says. </p><p>This bill will likely hone in on a set concept of data portability, Laurie adds, which is an important step forward in speeding up these sorts of processes. Lauren Wills-Dixon, solicitor at Gordons, tells <em>ITPro </em>the bill will also lay out a more coherent, straightforward idea of what data can be used and for what purposes.</p><p>“The bill introduces this concept of recognized <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-training-in-the-crosshairs-as-ico-set-to-examine-legality-of-personal-data-use">legitimate interest</a> to give organizations certainty,” she says.</p><p>Wills-Dixon explains that it will recognize several legitimate interests including national security processing, emergency response, and safeguarding efforts.  </p><p>It will also cut red tape in the public sector, according to Richard Fayers, data and analytics practice lead at Slalom, reducing the lengths that workers have to go to in recording personal data use.</p><h2 id="how-will-the-data-use-and-access-bill-affect-the-private-sector">How will the Data Use and Access Bill affect the private sector?</h2><p>While there’s a huge opportunity in the public sector space, Fayers is keen to point out how elements of the bill – such as the smart data schemes – will likely drive innovation across the private sector landscape. </p><p>For example, he suggests the bill could introduce a greater level of openness for UK businesses and turn attention towards open standards akin to what has been seen in the finance sector with <a href="https://www.itpro.com/policy-legislation/30661/what-is-open-banking"><u>open banking</u></a>. Fayers sees massive opportunities across sectors by building on this interoperability of data. </p><p>There may also be better forecasting of public demand through a pooling of company information, Fayers adds, as well as the potential for businesses to share data to offer collaborative schemes or experiences to customers. Businesses could then give customers a unified profile that works from company to company.   </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LjWdHEMBU3LCLK4bVET7Rg" name="Understanding Least Privileges.jpg" caption="" alt="Understanding Least Privileges" src="https://cdn.mos.cms.futurecdn.net/LjWdHEMBU3LCLK4bVET7Rg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/understanding-least-privileges"><em>Protect your company from ransomware attacks</em></a></p></div></div><p>Bill Wright, global head of government affairs at Elastic, echoes some of these predictions for potential advantages to the private sector. The bill will allow firms in every sector to access and analyze consumer data more effectively, Wright tells <em>ITPro</em>. </p><p>“Simplifying the data sharing rules are going to, maybe, break down some of those silos between industries and create some opportunities for startups to compete with some of the more established players,” Wright says. </p><p>It may even increase foreign investment into the UK, Wright says finally, by showing those outside the UK that the country has a data processing environment both predictable and innovative. </p><h2 id="what-do-it-leaders-need-to-know-about-compliance">What do IT leaders need to know about compliance?</h2><p>As with any new piece of legislation, the data use and access bill will require some degree of reorganization from firms when it comes to ensuring compliance. That being said, Wills-Dixon predicts companies that are already compliant with <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> don't face serious challenges to becoming compliant with the Data Use and Access Bill.</p><p>“If you're carrying out research, statistical use of data, or processing in the public interest and things like that, then it will help, but for most commercial organizations, your obligations are going to be very similar as drafted,” Wills-Dixon adds. </p><p>That said, Fayers warns the new Information Commission will have enhanced enforcement powers and businesses will also need to ensure they can demonstrate robust security and data governance. This will demand a greater focus on compliance certification and accountability frameworks, Fayers says. </p><p>“If you're seen to be transparent – if you're providing customers with assurance and visibility of how you're managing this risk as well – that could also be seen as a benefit, whilst there's a cost,” Fayers concludes.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/what-is-chaos-engineering-and-how-can-it-benefit-businesses">What is chaos engineering and how can it benefit businesses?</a></li><li><a href="https://www.itpro.com/business/business-strategy/what-is-quiet-firing">What is quiet firing?</a></li><li><a href="https://www.itpro.com/security/i-love-magic-links-why-arent-more-services-using-them">Why magic links should be the default password replacement</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK businesses patchy at complying with data privacy rules ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/uk-businesses-patchy-at-complying-with-data-privacy-rules</link>
                                                                            <description>
                            <![CDATA[ Companies need clear and well-defined data privacy strategies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hHWXdLaLbPPrkzDi2wHQ65</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E6CWYG29ZoytTeEWF72mcS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jan 2025 12:53:32 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Jan 2025 16:14:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/E6CWYG29ZoytTeEWF72mcS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electronic network data security, data protection and electronic technology, financial network security]]></media:description>                                                            <media:text><![CDATA[Electronic network data security, data protection and electronic technology, financial network security]]></media:text>
                                <media:title type="plain"><![CDATA[Electronic network data security, data protection and electronic technology, financial network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E6CWYG29ZoytTeEWF72mcS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Only half of UK businesses are fully complying with all data privacy regulations and industry guidelines - an improvement, but not much of one.</p><p>Research from Zoho Digital found that the figure has risen from 2023's 42%, but that many businesses still need to improve their data practices.</p><p>On the plus side, transparency of data practices emerged as a growing strength, with 50% of respondents saying that their data privacy policies are clear, simple, and transparent, up from just 33% in 2023. </p><p>"According to Zoho’s Digital Health survey, businesses must improve transparency around data usage as a clear step toward ethical behaviour," said Sachin Agrawal, Zoho managing director. </p><p>“This will play an important role in improving customer experience, strengthening customer relationships."</p><p>The survey revealed that 47% of businesses now view data privacy as a critical part of their success, and that 46% conduct regular data privacy training for employees.</p><p>However, it also identified serious gaps where businesses are falling behind. Only three-in-ten businesses reported going beyond requirements to provide additional protection for customer and employee data.</p><p>This, Zoho noted, suggests that while businesses are meeting their compliance requirements, few are taking proactive steps to enhance data protection.</p><p>"In an increasingly data-driven world, organisations must prioritize data privacy throughout their operations. It is encouraging to see the growing recognition of data privacy’s role in driving business policies, but there is still a lot of progress to be made," said Agrawal. </p><p>"To unlock the full transformative potential of technologies like AI, businesses must have clear and well-defined data strategies which both protect customer and employee data but enable flexibility of use in the right way."</p><p>The report comes hot on the heels of research from ISACA, which found only a third of <a href="https://www.itpro.com/security/privacy/data-privacy-professionals-are-severely-underfunded-and-its-only-going-to-get-worse">data privacy professionals are confident in their organization’s ability to safeguard sensitive data</a>, and just a quarter follow Privacy by Design best practices.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4FaxkYpuDpkr6ksE4TzLvU" name="Integrating Copilot With CDW" caption="" alt="Integrating Copilot With CDW" src="https://cdn.mos.cms.futurecdn.net/4FaxkYpuDpkr6ksE4TzLvU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/integrating-copilot-with-cdw"><em>Seamlessly embed AI into your business processes</em></a></p></div></div><p>Their teams underfunded, they said, and more than half told ISACA they expect budgets to decline this year.</p><p>ISACA warned that many organizations risk falling foul of <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and new legal frameworks such as the Digital Services Act and <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>. </p><p>Recently, Charlie Bromley-Griffiths, senior legal counsel at legal document management software form Conga, told <em>ITPro </em>that UK businesses had made substantial strides in aligning with privacy legislation. </p><p>"Companies have implemented stronger data governance policies, enhanced security protocols and prioritized the rights of data subjects," she said. "However, challenges still remain, particularly for small and medium-sized enterprises struggling with the complexity and cost of full compliance."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data privacy professionals are severely underfunded – and it’s only going to get worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/data-privacy-professionals-are-severely-underfunded-and-its-only-going-to-get-worse</link>
                                                                            <description>
                            <![CDATA[ European data privacy professionals say they're short of cash, short of skilled staff, and stressed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QR65poDAWBH9rMCbkvqafC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vJxqmUk7XiBNcAeFAyAHXT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jan 2025 10:55:55 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Jan 2025 14:50:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vJxqmUk7XiBNcAeFAyAHXT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female data privacy professional working on a desktop computer in an office space.]]></media:description>                                                            <media:text><![CDATA[Female data privacy professional working on a desktop computer in an office space.]]></media:text>
                                <media:title type="plain"><![CDATA[Female data privacy professional working on a desktop computer in an office space.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vJxqmUk7XiBNcAeFAyAHXT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/data-protection/data-privacy-will-be-a-critical-enterprise-focus-in-2024-and-generative-ai-has-torn-up-the-rulebook">Data privacy</a> professionals think their organizations are underfunding their work, and there's no light on the horizon as budgets are set to be squeezed further in 2025.</p><p>In a recent survey, more than half told ISACA they expect budgets to decline this year, up from 41% last year. Meanwhile, only a third said they were confident in their organization’s ability to safeguard sensitive data, with just a quarter always practicing Privacy by Design. </p><p>As a result, ISACA warned many organizations risk falling short of compliance with <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and new legal frameworks such as the <a href="https://www.itpro.com/business/policy-and-legislation/how-will-the-digital-services-act-affect-businesses">Digital Services Act</a> and <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>. </p><p>“As the threat landscape continues to evolve in complexity, privacy is becoming a sector which is increasingly difficult to operate in, but also more critical," said Chris Dimitriadis, global chief strategy officer at ISACA. </p><p>"Two-thirds of the European professionals working in privacy roles who we spoke to said their job is more stressful now compared to five years ago. This is only being exacerbated by continued underfunding. While companies may be making a short-term financial gain, they are putting themselves at long-term risk."</p><p>Half of technical data privacy teams in Europe remain understaffed, the survey found, much the same as last year, while a third struggle to retain qualified privacy professionals.</p><p>Those that do always practice Privacy by Design do rather better, with 43% saying their technical data privacy teams are appropriately staffed. Six-in-ten said they were highly confident in their technical privacy teams as a result.</p><p>"Practicing <a href="https://www.itpro.com/security/privacy/368750/brave-pushes-the-boundaries-of-how-to-bake-in-user-privacy">Privacy by Design</a> and embedding privacy across an entire enterprise is key to long-term data protection," Dimitriadis said.</p><p>"Such a comprehensive approach fosters trust with stakeholders and safeguards against ever-evolving threats – but this isn’t possible without skilled privacy teams who feel prepared and able to drive privacy practices from a technology, business and compliance point of view."</p><h2 id="the-data-privacy-skills-gap-is-growing">The data privacy skills gap is growing</h2><p><a href="https://www.itpro.com/business/careers-and-training/the-uk-is-dealing-with-a-chronic-data-skills-shortage-and-its-costing-the-economy-billions-each-year">Skills gaps</a> were also highlighted as a key issue for data privacy professionals, ISACA found. The biggest reported skills gaps were experience with different types of technologies and/or applications, cited by 63% of respondents. </p><p>A lack of technical expertise and IT operations knowledge and skills were also flagged as major concerns. As a result of this shortfall, nearly half of organizations said they offer training to allow staff from non-privacy backgrounds to move into roles in this domain. </p><p>However, it’s experience that’s key to plugging this skills gap, the study noted. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YRwEK7F48t5uqGuzdTnavF" name="SANS™ Institute Product Overview_ Safeguard Your Business-Critical Web Apps and APIs with a WAF" caption="" alt="SANS™ Institute Product Overview: Safeguard Your Business-Critical Web Apps and APIs with a WAF" src="https://cdn.mos.cms.futurecdn.net/YRwEK7F48t5uqGuzdTnavF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/sanstm-institute-product-overview-safeguard-your-business-critical-web-apps-and-apis-with-a-waf"><em>Protect on-premises and cloud application workloads</em></a></p></div></div><p>Nearly all respondents said they consider compliance and legal experience an important factor in determining if a privacy candidate is qualified. Nine-in-ten also consider industry credentials as important, while only 54% said the same about a university degree. </p><p>"There are several ways to <a href="https://www.itpro.com/business-strategy/careers-training/369682/hiring-from-overseas-tech-skills-gap">plug the skills gap</a>," said Dimitriadis. </p><p>"Providing training and continuous support for privacy staff on emerging technologies, privacy-enhancing technologies, and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> and <a href="https://www.itpro.com/security/data-protection">data protection</a> architectures on top of legal compliance knowledge is essential for managing their stress and maintaining organizational resilience."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Four years on, how's UK GDPR holding up? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/gdpr/four-years-on-hows-uk-gdpr-holding-up</link>
                                                                            <description>
                            <![CDATA[ While some SMBs are struggling, most have stepped up to the mark in terms of data governance policies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PCUFe9zbJJEQSsBpg9nG7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jan 2025 12:05:55 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jan 2025 17:24:42 +0000</updated>
                                                                                                                                            <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:description>                                                            <media:text><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:text>
                                <media:title type="plain"><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's been four years since the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">UK General Data Protection Regulation (GDPR) </a>came into force after the UK left the European Union (EU). </p><p>However, while the UK legislation remains aligned with that of the EU, it gives the UK the independence to keep the framework under review.</p><p>Like the EU GDPR, the UK version places requirements on organizations that process personal data, based on seven principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality and accountability. </p><p>Charlie Bromley-Griffiths, senior legal counsel at legal document management software form Conga, said that while the legislation has delivered marked benefits, lingering issues remain.</p><p>"Over the last four years, UK businesses have made substantial strides in aligning with UK GDPR requirements. Companies have implemented stronger data governance policies, enhanced security protocols and prioritized the rights of data subjects," Bromley-Griffiths said.</p><p>"However, challenges still remain, particularly for small and medium-sized enterprises struggling with the complexity and cost of full compliance. GDPR mandates stringent measures to safeguard consumer data, which includes data storage, processing and transfer practices, all of which impacts organizations’ data strategies and operational costs."</p><p>Brexit has also caused issues with regard to the transfer of personal data between the UK and the European Economic Area (EEA), along with UK controllers who have an establishment or customers in the EEA, or who monitor individuals in the area. </p><p>While the EU GDPR still applies to this processing, the way organizations interact with European data protection authorities has changed.</p><p>"The international data landscape is now rather complex. UK businesses handling data from the European Union (EU) must also comply with the EU GDPR," said Bromley-Griffiths. </p><p>"Then, of course, there is the <a href="https://www.itpro.com/business/policy-and-legislation/us-uk-data-bridge-everything-you-need-to-know">US-UK data bridge</a>, which forms part of the <a href="https://www.itpro.com/business/policy-and-legislation/eu-us-data-transfer-framework-will-be-overturned-within-five-years-says-expert">EU-US Data Privacy Framework</a> and permits the flow of EU-based data to the United States under certain conditions." </p><p>All this, she said, highlights the importance of maintaining two or more compliance strategies to make sure operations across borders go smoothly – and, ultimately, keep the trust of customers, reassuring them that their data is safe.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="69vPgVDk9D2V2RrxrY7DjV" name="The Business Value of Dell PowerFlex_listing.jpg" caption="" alt="A whitepaper from Dell and Intel on the business value of Dell Powerflex, with image of data  in a funnel shape" src="https://cdn.mos.cms.futurecdn.net/69vPgVDk9D2V2RrxrY7DjV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell | Intel)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/the-business-value-of-dell-powerstore"><em>Dell PowerStore could improve your business performance</em></a></p></div></div><p>Looking ahead, Bromley-Griffiths expects regulatory bodies to look at cracking down harder on repeat offenders or businesses that have suffered significant data breaches. </p><p>Meanwhile, the UK GDPR is likely to be amended, with the introduction last October of the Data Use and Access Bill in the House of Lords. With this bill, and in future, the UK is unlikely to diverge significantly from EU legislation. </p><p>It currently enjoys 'data adequacy' with the EU, meaning that personal data can be transferred freely between the two. If this were lost, it could be an economic disaster.</p><p>However, more minor changes, said Bromley-Griffiths, could be on the cards.</p><p>"Given how quickly cyber threats are evolving, the UK GDPR standards may be updated. Businesses need to have the appropriate tools and measures in place to ensure that they are ready to adapt to any legislative changes," she said. </p><p>"Organizations must remain committed to investing in their employee’s ongoing education but also in the right technology to safeguard personal data."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why The Matrix offers valuable lessons on data sovereignty for channel partners ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/why-the-matrix-offers-valuable-lessons-on-data-sovereignty-for-channel-partners</link>
                                                                            <description>
                            <![CDATA[ Two decades on, there's much that the Matrix series can teach channel partners about data sovereignty ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YtgysLxX8XoywSV4FApP3h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XegarHTRJ8d3dP2u3UkF7g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Aug 2023 10:30:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:39:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Devine ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/xPW3RfDgVX9VKjFBybnMoK.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XegarHTRJ8d3dP2u3UkF7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up of computer screen displaying green zeroes and ones]]></media:description>                                                            <media:text><![CDATA[Close-up of computer screen displaying green zeroes and ones]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up of computer screen displaying green zeroes and ones]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XegarHTRJ8d3dP2u3UkF7g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just over 20 years ago, in <em>The Matrix: Reloaded</em>, Keanu Reeves taught us an important lesson about technological sovereignty. Mid-way through the film, he arrives back in the last remaining human city, Zion, deep underground, and stands on a balcony with Anthony Zerbe, looking out over a field of servers. </p><p>Together, facing an impending machine invasion, they speculate on the nature of control. Reeves – with his usual gravelly brevity – neatly sums it up: if we wanted to, he says, we could shut the machines down. </p><p>Over the last few years, especially in the wake of Brexit, the issue of control and sovereignty has become increasingly pertinent. The networking and cloud market has seen a raft of challenges when it comes to control, freedom, and transparency, making life more complex and, at times, difficult for channel partners. </p><p>From vendor lock-in to rising prices, threats of international surveillance, and <a href="https://www.itpro.com/cloud/370382/microsoft-aws-face-cma-probe-amid-competition-concerns"><u>scrutiny from Ofcom into bundling and competition</u></a>, there is more and more to track today, with each consideration taking up valuable time for channel partners and increasing the overall length of the sales cycle.</p><p>And with respect to Mr Reeves – particularly as he does make an important point about the nature of control – the discussion is somewhat more nuanced than the ability to simply shut servers down. </p><h2 id="what-is-data-sovereignty">What is data sovereignty?</h2><p>Data sovereignty is about both control and freedom: it’s the ability to control all aspects of your data, and allowing customers the ability to do the same, practically, politically and economically. </p><p>If you don’t have the freedom to move your data, you aren’t in control. For this reason, sovereignty is often associated with residency (where your data is stored) which closely influences how it is handled. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5bgDiwE8NhRmYj2TybQ4Dk" name="workplace_diversity_GettyImages-1396315043 (1).jpg" caption="" alt="Female business colleagues in meeting discussing project" src="https://cdn.mos.cms.futurecdn.net/5bgDiwE8NhRmYj2TybQ4Dk.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/addressing-the-gender-divide-in-the-channel">Addressing the gender divide in the channel</a></p></div></div><p>Many people associate data sovereignty with <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>General Data Protection Regulation</u></a> (GDPR). UK GDPR applies to personal data, and states that data must be stored within the EU or in a country outside the EU that can offer an ‘adequate’ level of <a href="https://www.itpro.com/data-protection/28020/data-protection-principles"><u>data protection</u></a>, and that data is used ‘fairly, lawfully and transparently’. </p><p>However, local country laws also apply, adding a layer of complexity. In particular, the location of the head office of a data center owner intersects with these regulations, making it crucial that organizations understand the nuance and impact of where they choose to locate their data. </p><p>There is plenty of non-personal data that requires good governance, which is why we also need international standards for data and cloud security. As most channel partners know, we also have standards for this, including the likes of ISO 27001, and ISO 27018 for cloud environments specifically. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zqJ5igWTeX9R9eFaNKdzme" name="Sustainability at scale, accelerated by data_listing.jpg" caption="" alt="Whitepaper cover with cityscape at sunset image in background" src="https://cdn.mos.cms.futurecdn.net/zqJ5igWTeX9R9eFaNKdzme.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn how GPT delivered winning sustainability outcomes and better business resiliency.<br><br></em><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-operations/370384/sustainability-at-scale-accelerated-by-data">DOWNLOAD FOR FREE</a></p></div></div><p>From a regulatory perspective, data from specific industries needs to be stored in an appropriate environment and handled according to best practice. For example, in the UK we have PCI-DSS, which governs how payment data is handled, and so on. </p><p>Channel partners that can find a cloud provider with infrastructure that is already compliant with these regulations can make life much easier.</p><p><a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>Cyber security </u></a>is also an important component of good sovereignty: knowing where customer data is and how it will be handled means it won’t be exposed to potentially adverse situations, like being processed for national intelligence purposes.  </p><h2 id="moving-beyond-residency">Moving beyond residency</h2><p>Responsible data sovereignty is about more than just residency and handling. For example, it’s important to consider freedom of (or control over) choice in terms of hardware – and therefore where equipment was manufactured, for example. </p><p>Clearly, it’s also no good knowing where customer data is, and having it in a well-established location if you can’t move it when things change. Portability is a key part of sovereignty, but has a number of components, including both standards and commercial arrangements. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EXeL4hPNVaTQPuTt2HGWAF" name="Brain_Evolution_Stock_GettyImages-1436010616.jpg" caption="" alt="Digital generated image of multi coloured gear wheels connected together in shape of brain on grey background" src="https://cdn.mos.cms.futurecdn.net/EXeL4hPNVaTQPuTt2HGWAF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-to-bring-your-people-on-your-digital-evolution-journey">How to bring your people on your digital evolution journey</a></p></div></div><p>To start with, non-proprietary or open-source software, such as <a href="https://www.itpro.com/infrastructure-as-a-service-iaas/31700/what-is-openstack"><u>OpenStack </u></a>or Docker, can help to create standardized environments which are easy for customers to move data in and out of. </p><p>Furthermore, it’s also important to consider other aspects of portability, such as choosing a provider that allows you as a channel organization to move data when needed – including fair ingress and egress fees. This gives both you and your customers greater freedom and sovereignty. </p><p>This may have been exactly what Keanu was talking about, making sure that the human resistance could turn its servers on and off when needed – or scale them up and down to meet the growing (or perilously shrinking) population of the underground city. </p><p>It’s also what Ofcom has been looking into, ensuring that competition in the cloud market is good for the UK market, and that ingress/egress fees are not unfair, for example. </p><p>With all this in mind, it should be easy to understand why a broad definition of sovereignty is important. Digital freedom is intrinsically valuable, and channel and end-user organizations alike should be able to control and manage their data how they wish and have a free choice of vendors. </p><p>However, it goes well beyond this: being able to store and handle data in the way that is right for your company and your customers allows you to move it when it’s beneficial for you to do so. </p><h2 id="risks-and-rewards">Risks and rewards</h2><p>Like the seemingly doomed population of Zion in the Matrix, it’d be easy to sum up by looking at the negative side of the debate. For example, one risk of not considering data sovereignty includes data being subject to country-specific rules that are in conflict with best practice in your region.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8TbsahzKZ53F2B5cCVYakE" name="Dark_web_Stock_GettyImages-1417398548.jpg" caption="" alt="A web structure imposed on a black background" src="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-mssps-can-leverage-dark-web-intelligence-to-counter-emerging-threats">How MSSPs can leverage dark web intelligence</a></p></div></div><p>This might mean data being processed for economic intelligence reasons, which in some cases could constitute a data breach – and no-one has to be reminded about the crushing fines and reputation damage that come with a personal data breach under GDPR.</p><p>It’s far better to look on the positive side. Channel companies that do consider data sovereignty from the outset will tend to have a more consultative relationship with customers. </p><p>Channel partners with a good grasp of data sovereignty will have an inherently orderly, flexible, secure, and compliant infrastructure where data is well-governed and appropriate rules are set for your customers’ business, sector, and region. </p><p>Or to take another Keanu-related piece of advice, as Ian McShane advises us in the John Wick series, without rules, we live with the animals. </p><p>20 years on, Keanu’s movies are still teaching us about best practice in data handling and sovereignty. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom rejects claims AI training policy is mandatory after users vent confusion ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/zoom-rejects-claims-ai-training-policy-is-mandatory-after-users-vent-confusion</link>
                                                                            <description>
                            <![CDATA[ The video conferencing firm has denied customers’ data will be used to train AI without consent ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hhhvbLU2XPgmFSyUSpmZoB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Qw3hw5A9SBXEGXrTAm2dgJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Aug 2023 16:12:32 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Aug 2023 08:31:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Qw3hw5A9SBXEGXrTAm2dgJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom logo on a big blue board]]></media:description>                                                            <media:text><![CDATA[Zoom logo on a big blue board]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom logo on a big blue board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Qw3hw5A9SBXEGXrTAm2dgJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zoom has issued a clarification over items in its terms of service that relate to the use of user data for AI training after a series of LinkedIn posts criticized the firm for allegedly not giving users any way to opt-out.</p><p>Users had objected to several clauses that stated Zoom could use customer content, such as uploaded files and data or transcripts and analytics that result from Zoom calls, to train and tune algorithms and models for artificial intelligence (AI) and machine learning (ML).</p><p>Points 10.2 and 10.4 in the terms of service had drawn particular concern, as they stated Zoom could use the content for the purposes of “machine learning, artificial intelligence, training, testing, improvement of the Services, Software, or Zoom’s other products, services, and software, or any combination thereof”.</p><p>Zoom has rejected criticisms of its terms, and restated that customers have a choice over what their data is used for.</p><p>“Zoom customers decide whether to enable generative AI features, and separately whether to share customer content with Zoom for product improvement purposes,” a Zoom spokesperson told <em>ITPro</em>.</p><p>Alongside its well-known video conferencing software, the firm has released Zoom IQ, an AI assistant that can summarize meetings and action items from conference calls.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nkJY2faZ4P9fjuCkSx3EiA" name="nkJY2faZ4P9fjuCkSx3EiA.jpg" caption="" alt="Whitepaper cover with image of female working remotely at a laptop on her sofa" src="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Unified Endpoint Management and Security in a work-from-anywhere world</strong></p><p class="fancy-box__body-text"><em>Understand what&apos;s influencing security strategies today.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Within businesses that adopt Zoom IQ, administrators have control over whether information is shared with Zoom for training purposes, and can revoke consent they may grant to Zoom for these purposes at any later date.</p><p>Users can continue to use Zoom IQ&apos;s generative Ai features regardless of whether they opt-in to data sharing or not.</p><p>Zoom also collects ‘Service Generated Data’ (SGD), the phrase it uses for diagnostic and telemetry data alongside any other data that Zoom collects or generates as a result of customer use of its services and software.</p><p>The terms agreement states that Zoom users grant the firm a “perpetual, worldwide, non-exclusive, royalty-free, sublicensable, and transferable license” to handle SGD as the firm deems appropriate within the boundaries it has set out.</p><p>Greg Wilson, ​​senior software engineering manager at Deep Genomics, wrote a <a href="https://www.linkedin.com/feed/update/urn:li:activity:7094182563463761920/"><u>post</u></a> on LinkedIn urging businesses to drop Zoom as a platform while the practice remained in place.</p><p>Zoom COO Aparna Bawa <a href="https://www.linkedin.com/feed/update/urn:li:activity:7094063360693989377?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A7094063360693989377%2C7094182559240093696%29"><u>replied</u></a> to the post, explaining that the terms were intended to improve transparency rather than cause concern.</p><p>Separately the company published a <a href="https://blog.zoom.us/zooms-term-service-ai/"><u>blog post</u></a> in which it addressed the new terms of service, which came into effect in March 2023.</p><p>“In Section 10.4, our intention was to make sure that if we provided value-added services, such as a meeting recording, we would have the ability to do so without questions of usage rights,” wrote Smita Hashim, chief product officer at Zoom.</p><p>“An example of a machine learning service for which we need license and usage rights is our automated scanning of webinar invites/reminders to make sure that we aren’t unwittingly being used to spam or defraud participants. </p><p>“The customer owns the underlying webinar invite, and we are licensed to provide the service on top of that content. For AI, we do not use audio, video, or chat content for training our models without customer consent.”</p><p>Some LinkedIn users compared the changes to recent moves by Google.</p><p>In July, the search giant changed its terms of service to explicitly allow the company to train its AI models on publicly-available data.</p><p>A passage in its privacy policy, which had referenced the use of publicly-available information such as text from open-access websites for training Google’s language models was amended to include reference to Google AI products such as Bard.</p><p>Google specifically stated that firms with business information on a website could have this indexed for use in Google services.</p><p>The change drew criticism from some in the industry, who pointed out that it could give the firm an unfair advantage over competitors. It has also been compared to OpenAI, which is widely believed to have used a large amount of public data to train models such as GPT-4.</p><p>OpenAI <a href="https://www.itpro.com/technology/artificial-intelligence/openai-quietly-unveils-gptbot-dedicated-web-crawler"><u>quietly released GPTBot configuration</u></a> on 7 August, which will allow admins to prevent their web data from being scraped for inclusion in future models trained by the firm. </p><p>Other companies are facing similar questions as the AI race heats up, with productivity tools such as <a href="https://www.itpro.com/technology/artificial-intelligence/duet-ai-vs-copilot-all-the-similarities-and-differences"><u>Google Duet AI and Microsoft 365 Copilot</u></a> facing scrutiny.</p><p>In a post on Mastodon, security researcher Kevin Beaumont suggested that changes such as automatically generating transcripts with generative AI could give individuals insight into private corporate meetings through <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> mechanisms.</p><p>“Probably my favorite unconsidered vector with AI is MS Copilot plans to do meeting summaries and transcriptions... so if you want to find out what a company is saying about you in meetings, wait a year and get in that GDPR subject access request,” wrote Beaumont.</p><p><em>ITPro</em> has reached out to Google for more information.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data breach costs: Businesses lose 73% of their income in the year following an incident ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/data-breach-costs-businesses-lose-73-of-their-income-in-the-year-following-an-incident</link>
                                                                            <description>
                            <![CDATA[ Erosion of trust, remediation costs, and potential regulatory fines create a confluence of financial burdens for businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uN7QPGW2fGKcoUfUrRJ79N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5TwUgdWivXfZZjJxeWEgiM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Aug 2023 15:08:25 +0000</pubDate>                                                                                                                                <updated>Thu, 03 Aug 2023 13:06:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5TwUgdWivXfZZjJxeWEgiM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach image: Digital cloud and network security. 3D computer hardware illustration.]]></media:description>                                                            <media:text><![CDATA[Data breach image: Digital cloud and network security. 3D computer hardware illustration.]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach image: Digital cloud and network security. 3D computer hardware illustration.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5TwUgdWivXfZZjJxeWEgiM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies that suffer data breaches face a significant drop in income on top of the typical associated remediation costs, new research has suggested. </p><p>A report from ExtraHop found that public companies experience an average net income drop of 73% within the first year of a data breach’s disclosure, highlighting the painful financial repercussions of security incidents. </p><p>The company’s analysis focused on the overall costs associated with data breaches at six unnamed organizations, taking into account potential regulatory fines, legal settlements, and <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance">cyber insurance</a> costs on top of any impact to earnings.</p><p>“Nearly all” organizations experienced a decline in quarterly earnings in the wake of a data breach, the report found, while stock prices were often found to drop significantly. </p><p>In one example, a company’s stock price dipped nearly 21% the day after a breach was disclosed. In this same incident, net income dropped 27% year-over-year in the quarter that the breach occurred.</p><p>These income-related losses are compounded by the fact that companies also encounter a domino effect of costs in the wake of a breach, ExtraHop said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bFYESi8rNxainGminykfoR" name="Six myths of SIEM_listing.jpg" caption="" alt="Whitepaper cover with black & white birds eye view of a cityscape" src="https://cdn.mos.cms.futurecdn.net/bFYESi8rNxainGminykfoR.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Six myths of SIEM</strong></p><p class="fancy-box__body-text"><em>Understand what to expect from an SIEM solution today, and how to tackle the top six myths.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/367048/six-myths-of-siem"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Losses incurred in the aforementioned example from ExtraHop were in addition to over $1 billion in reported costs, which included regulatory penalties, legal fees, and “multiple settlements with consumers, businesses, and individual states”.</p><p>“Net income for five of the organizations we studied sank an average of 73% within nine to 12 months of each organization announcing a breach. </p><p>“In addition, in nearly all cases, quarterly earnings declined and stock prices dropped significantly after data breaches.”</p><p>The study noted that while “economic and other business factors” may also have contributed to sluggish financial performances, there is “no question” that the breaches impacted company performance.</p><p>Patrick Dennis, CEO at ExtraHop, said the research highlights the “ripple effect” that a security incident could have on company finances due to reputational damage and a loss of consumer or client trust. </p><p>“When a data breach hits, real people lose real money - it goes way past the upfront costs that accompany stolen records and the number of people affected,” he said. </p><p>“Both investors and customers lose faith in the business, which has a ripple effect on the organization for years to come. It’s important that corporate leaders take a hard look at their budget and make the cyber security investments they need to more effectively manage risk.”</p><h2 id="high-stakes-for-businesses">High stakes for businesses</h2><p>Data breach costs can become a significant burden for organizations in the wake of an incident. Research from IBM showed that UK businesses pay an average of £3.4 million in overall costs following an incident. </p><p>Although the report emphasized the potential financial repercussions of a data breach, the 2023 figures <a href="https://www.itpro.com/security/ransomware/ibm-law-enforcement-helped-save-ransomware-victims-dollar470k-in-2023"><u>published last month</u></a> mark a decrease compared to 2022, which saw the average cost stand at £3.8 million. </p><p>The report noted, however, that this is still a 9% increase on 2020 figures, underlining the rising costs associated with data breaches over the last three years. </p><p>Stronger regulatory standards have been introduced in recent years to protect consumers and businesses in the wake of a data breach, most notably with the EU’s <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR legislation</a>. </p><p>Last week the US Securities and Exchange Commission (SEC) also introduced far stricter reporting standards for public companies that encounter security incidents. </p><p>New rules outlined by the commission will require companies to <a href="https://www.itpro.com/business/policy-and-legislation/sec-passes-rules-compelling-us-public-companies-to-report-data-breaches-within-four-days"><u>disclose a data breach or security incident within four days</u></a> of the event unfolding. </p><p>The new ‘Form 8-K’ rules will mean firms are required to provide information on the timing of the incident, as well as its scope and potential impact on customers or clients. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU-US Data Transfer Framework will be overturned within five years, says expert ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eu-us-data-transfer-framework-will-be-overturned-within-five-years-says-expert</link>
                                                                            <description>
                            <![CDATA[ Gartner VP analyst dubs the adequacy ruling “Déjà EU”, citing lack of transparency over remediation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vGtszAeCbgUiawRKKMdAmj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jul 2023 11:52:17 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Jul 2023 13:58:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:description>                                                            <media:text><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:text>
                                <media:title type="plain"><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has adopted the adequacy decision for the EU-US Data Privacy Framework after years of talks, but experts have indicated it will struggle to uphold it in court.</p><p>In its decision announced on 10 July, the Commission found that the US upholds a level of protection comparable to that of the EU when it comes to the transfer of personal data. </p><p>Companies that comply with the extensive requirements of the framework can access a streamlined path for transferring data from the EU to the US without the need for extra data protection measures.</p><p>The framework is likely to face legal action and be overturned, according to Nader Henein, research VP of privacy and data protection at Gartner.</p><p>“It takes one step closer to what the European Court of Justice needs, but it takes one where the Court of Justice needs it to take five, or ten steps,” Henein told <em>ITPro</em>.</p><p>“Maximilian Schrems already said he was going to do it, and if not him someone else will like the EFF or multiple privacy groups. What we’re telling our clients is two to five years, depending on who raises the request, when they raise it, and who they use.”</p><p>A potential legal challenge could move more swiftly if the individual complaint was made against a known entity such as Facebook, which was the subject of the Schrems II verdict that took down the old framework known as <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield"><u>Privacy Shield</u></a>.</p><p>Schrems has posted a series of tweets comparing the new adequacy agreement to Privacy Shield, and vowed to fight it in the courts.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">The "new" EU-US Data Privacy Framework is sooo much a 1:1 copy of the #PrivacyShield -- they even forgot to rename the link in the footer: https://t.co/SyamOFdpSq https://t.co/K68gkM3XTz pic.twitter.com/yB90jbtPix<a href="https://twitter.com/maxschrems/status/1678038200391016449">July 9, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>Henein said businesses are being advised to use the next two years to set up plans that are not dependent on the EU-US Data Privacy Framework, and noted that many firms will be approaching suppliers to demand they protect against more expensive disruption.</p><p>The European Commission has stated the framework will be subjected to regular reviews, with a check that the US side of the framework is operating as intended expected within 12 months.</p><p>Unlike the EU, which has the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a>, the US has no federal data protection scheme. It often leans on the fourth amendment, which protects US citizens from “unreasonable searches and seizures” as a precedent for the conduct of law enforcement, but this does not apply to EU citizens.</p><p>While the framework is in effect, compliant companies will be able to transfer data without the need for costly additional assessments, which could prove especially beneficial for cross-Atlantic collaboration.</p><p>“The EU-US Data Privacy Framework is a positive development in the mission to protect individuals and organizations on both sides of the Atlantic against cyber threats,” said Drew Bagley, VP and counsel, privacy and cyber policy at CrowdStrike.</p><p>“Modern IT infrastructure, cyber security, and privacy compliance programs are dependent upon global data flows.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7Ho3MxBjFHBxdW56QCzrmU" name="Creating a proactive, risk-aware defence in today's dynamic risk environment_listing.jpg" caption="" alt="Whitepaper cover with green title over image of a glasses-wearing businessman looking at the camera holding a laptop" src="https://cdn.mos.cms.futurecdn.net/7Ho3MxBjFHBxdW56QCzrmU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Creating a proactive, risk-aware defence in today&apos;s dynamic risk environment</strong></p><p class="fancy-box__body-text"><em>Learn how a common risk management language can improve enterprise resilience</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk-management/370019/creating-a-proactive-risk-aware-defence-in-todays-dynamic"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Data localization is not a substitute for data protection, and the new Framework stands in sharp contrast to some policy and certification proposals that mistakenly prioritize localizing data over protecting would-be victims from breaches. </p><p>“This marks an opportunity to accelerate the G7’s Data Free Flow with Trust initiative and ensure defenders have the tools they need to defend against cyber attacks.”</p><p>From 2016 to 2020, transfers between the EU and US had been covered by the regulatory framework Privacy Shield. This worked as an adequacy agreement between the EU and US, with the US having promised to oversee the deletion of unneeded data.</p><p>In July 2020 the <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism"><u>European Court of Justice invalidated Privacy Shield</u></a>, having ruled that it was not compatible with the rights afforded to non-US citizens regarding surveillance and data collection in the name of national security.</p><p>The EU-US Data Privacy Framework seeks to address these concerns with new safeguards in place for EU citizens. </p><p>President Biden signed an <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/10/07/fact-sheet-president-biden-signs-executive-order-to-implement-the-european-union-u-s-data-privacy-framework/" target="_blank"><u>executive order</u></a> in October 2022 which brought in new restrictions and measures of redress for intelligence service activities.</p><p>One of the foremost concerns with transferring EU data to the US has historically been that US intelligence services would be able to access and use sensitive data belonging to EU citizens.</p><p>Under the new agreement, intelligence entities will only be able to access data in a manner proportionate to protecting national security. </p><p>Under the framework, EU citizens will also be given access to an impartial, independent mechanism for redress over the use of data by US intelligence agencies overseen by a new Data Protection Review Court (DPRC).</p><p>Complaints will be free to make, and citizens will not be required to produce evidence that their data was collected by an intelligence agency in order for the complaint to be looked into.</p><p>Ursula von der Leyen, President of the European Commission praised the “unprecedented commitments to establish the new framework” taken by the US.</p><p>But Henein argued that there is nowhere near enough transparency, and argued that as the surveillance redress process appears to happen behind closed doors it is unlikely to satisfy privacy concerns.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU regulators are digging their heels in despite big tech’s Data Act pushback  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/eu-regulators-are-digging-their-heels-in-despite-big-techs-data-act-pushback</link>
                                                                            <description>
                            <![CDATA[ EU regulators are no strangers to big tech regulatory push back, so why do companies still persist? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nPMZQpRtxGJq9npkSu5zZh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Jun 2023 12:20:47 +0000</pubDate>                                                                                                                                <updated>Mon, 26 Jun 2023 14:36:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg">
                                                            <media:credit><![CDATA[Santiago Urquijo/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:description>                                                            <media:text><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:text>
                                <media:title type="plain"><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>EU regulators have once again hit back at big tech criticism of regulatory changes in what marks the latest tit-for-tat battle ahead of the pending Data Act. </p><p>Amid concerns the legislation could harm tech companies, Thierry Breton, European commissioner for internal markets, will say it’s expected to do the exact opposite. </p><p>Lawmakers won’t shift their stance either despite the mounting opposition from big tech, according to the draft text of a speech set to be delivered in San Francisco this week. </p><p>“Our European data strategy is to unlock a wealth of big data and set out how that data should be shared, stored, and processed. This will benefit all businesses – European, American, and others alike,” he is expected to say, and will add: “Assertiveness is not protectionism.”</p><h2 id="why-tech-companies-are-fighting-the-data-act">Why tech companies are fighting the Data Act</h2><p>The Data Act aims to prevent non-EU governments from accessing data processed by firms operating within the union. Rules outlined in the act will apply to both corporate and consumer data, and are applicable to a range of services and products, such as smart technologies and industrial machinery. </p><p>Some US companies, however, warn the legislation could have a negative impact on international data transfers and create additional cost burdens for companies that operate across borders. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j9SfGKiJe4VP7Gb4Ycon6D" name="Top data security trends_listing.jpg" caption="" alt="Whitepaper cover with cartoon character wearing digital armour stood in front of a bar/line graph with mobile phone featuring image of female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/j9SfGKiJe4VP7Gb4Ycon6D.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Salesforce)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Top data security trends</strong></p><p class="fancy-box__body-text"><em>Must-have tools for your data security toolkit</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/top-data-security-trends"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>US firms aren’t alone in leveling criticism. Last month, Siemens and SAP suggested the act could <a href="https://www.reuters.com/technology/siemens-sap-say-eu-draft-data-act-puts-trade-secrets-risk-2023-05-07/"><u>compromise “trade secrets”</u></a> due to provisions requiring companies to collaborate with third parties to ensure regulatory compliance. </p><p>In an open letter to Breton, EU antitrust chief Margrethe Vestager, and Commission president Ursula von der Leyen, German companies opposed to the act said it “risks undermining European competitiveness by mandating data sharing”. </p><p>"Effectively, this could mean that EU companies will have to disclose data to third-country competitors, notably those not operating in Europe and against which the Data Act&apos;s safeguards would be ineffective," the letter read.</p><h2 id="pushing-back-against-regulation">Pushing back against regulation</h2><p>This criticism marks the latest in a long-running trend of big tech companies across the world pushing back against pending EU legislative changes.</p><p>Earlier this year, a number of industry stakeholders, most notably OpenAI, slammed the EU’s long-awaiting AI Act, branding it too restrictive and potentially inhibiting operations within the union. </p><p>OpenAI CEO Sam Altman sparked controversy after suggesting the firm could be forced to “leave Europe” if the act was approved as it stood. While Altman <a href="https://www.itpro.com/technology/artificial-intelligence/sam-altman-reverses-threat-to-leave-europe-over-ai-regulations"><u>swiftly reneged on the threat</u></a> and clarified OpenAI’s commitment to Europe, the comments drew harsh criticism from Breton. </p><p>Breton told <em>Reuters </em>at the time the AI rules are aimed specifically to safeguard the “security and well-being of our citizens” and insisted that changes “cannot be bargained”. He stressed the EU has been ahead of the curve in “designing a solid and balanced regulatory framework” in the interests of safety but also so Europe can “become a frontrunner in trustworth AI”.  </p><p><a href="https://www.itpro.com/cloud/367052/data-sovereignty-a-boon-for-msps"><u>Data sovereignty</u></a> rules in the EU have also been in the crosshairs for non-EU firms, with the cyber security labeling rules <a href="https://www.itpro.com/cloud/370204/eu-cloud-proposals-discriminatory-reatliatory-tariffs"><u>described as “discriminatory”</u></a> against international firms in recent months. </p><h2 id="big-tech-resistance-is-futile">Big tech resistance is futile</h2><p>Such pushback has a common theme: time and time again they fall flat. </p><p>The first real acid test for this was prior to the implementation of GDPR, which received a significant degree of resistance from firms within the union and internationally. </p><p>Similarly, cookie legislation and data-sharing rules in the wake of the Schrems cases, which saw companies such as Facebook hint they’d back out of the EU, fizzled out with a whimper. </p><p>It appears tech companies haven’t learned their lesson. EU lawmakers are steadfast in their position and unrelenting in their attempts to implement regulations that benefit member states and citizens. </p><p>For regulators to suddenly u-turn at the slightest hint of pushback would be disastrous from a political perspective. Companies, too, with even the slightest bone to pick would smell blood and pounce on future proposals. </p><p>This raises questions over why organizations continue to try so hard to water down legislation. There are <a href="https://www.itpro.com/technology/artificial-intelligence/why-are-ai-innovators-pushing-so-hard-for-regulation"><u>two differing tactics</u></a> at play – playing tough and cozying up – both of which aim to temper potential regulatory crackdowns.</p><p>Altman’s hardline approach backfired. But around the same time Microsoft president Brad Smith outlined how the organization planned to develop a responsible framework for <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> development. This approach showed a more measured approach that could curry favor with regulators. </p><p>With the draft Data Act pending, organizations pushing back will likely find their criticism – which sometimes seems more like spitting out the dummy than offering constructive input – will come to no avail. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta to fight “unjustified” record $1.3 billion GDPR fine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/meta-to-fight-unjustified-record-dollar13-billion-gdpr-fine</link>
                                                                            <description>
                            <![CDATA[ The company has been ordered to cease EU-US data transfers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SuTvpTQ4t3gyGVUJbxwLtR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e6CFxEsXUqTnbivAyTKz99-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 May 2023 11:19:30 +0000</pubDate>                                                                                                                                <updated>Wed, 24 May 2023 10:08:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e6CFxEsXUqTnbivAyTKz99-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta logo outside its HQ offices at 1 Hacker Way, San Francisco]]></media:description>                                                            <media:text><![CDATA[Meta logo outside its HQ offices at 1 Hacker Way, San Francisco]]></media:text>
                                <media:title type="plain"><![CDATA[Meta logo outside its HQ offices at 1 Hacker Way, San Francisco]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e6CFxEsXUqTnbivAyTKz99-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has confirmed it will be appealing a €1.2 billion ($1.3 billion) GDPR fine imposed on it this week for the unlawful transfer of Europeans’ data to the US.</p><p>The Irish Data Protection Commission’s (DPC) decision was published on Monday morning and forces the company to suspend data transfers between the EU and US due to concerns over EU citizens’ data privacy. </p><p>The DPC said that current data transfer practices at Facebook “did not address the risks to the fundamental rights and freedoms of data subjects” and were in breach of the GDPR.</p><p>The ruling follows a long-running question over citizens’ data privacy and how Meta-owned Facebook conducts data transfers between the EU and US. </p><p>Data transfers were previously protected by the transatlantic <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield"><u>‘Privacy Shield’</u></a>, which was originally created to allow secure data transfers between the EU and US, which operate in different data protection jurisdictions. </p><p>This was later invalidated after a lawsuit between Meta (then called Facebook) and Max Schrems concluded that the standard offered too much leniency to US surveillance laws.</p><p>The DPC noted that Meta used updated <a href="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal"><u>standard contractual clauses (SCCs)</u></a> that were adopted by the European Commission in 2021 with the transfers in question, along with “additional supplementary measures”. </p><p>However, these were still deemed to have not safeguarded the rights and freedoms of European data subjects.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aWdFz5f4uyXMEphjuW8u2e" name="SOC modernisation and and the role of XDR_thumb.png" caption="" alt="Whitepaper cover with image of male colleague at workstation" src="https://cdn.mos.cms.futurecdn.net/aWdFz5f4uyXMEphjuW8u2e.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>SOC modernization and the role of XDR</strong></p><p class="fancy-box__body-text"><em>Security operations remain challenging</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Ever since Privacy Shield was rendered invalid, businesses large and small have been left without clear guidance regarding cross-continent data transfers.</p><p>The EU is still yet to finalize a clear mechanism for safe and secure data transfers between it and the US, although one is expected before the end of the year.</p><p>Meta described the ruling as “unjustified and unnecessary” in a scathing response.</p><p>Nick Clegg, president for global affairs at Meta, criticized the DPC’s decision in a <a href="https://about.fb.com/news/2023/05/our-response-to-the-decision-on-facebooks-eu-us-data-transfers/"><u>blog post</u></a>, saying there is a “fundamental conflict of law between the US government’s rules on access to data and European privacy rights”. </p><p>“We are appealing these decisions and will immediately seek a stay with the courts who can pause the implementation deadlines, given the harm that these orders would cause, including to the millions of people who use Facebook every day,” Clegg wrote alongside chief legal officer Jennifer Newstead.</p><p>The Computer & Communications Industry Association (CCIA) warned that the ruling will exacerbate confusion over current data transfer protocols for US-based firms. </p><p>“Since an EU Court invalidated the previous EU-US data framework back in 2020, European and US organizations and companies of all sizes have been left without clear guidelines for transatlantic data transfers,” the non-profit said in a statement. </p><p>“To this day, that uncertainty continues to affect not only companies, but also non-profits, charities, governments, and others. Data flows between the EU and US make up the busiest internet route in the world, and are vital to transatlantic trade. Yet, today’s decision to suspend data transfers from the EU to the US ignores that reality.”</p><p>Last year, the Biden administration signed an executive order introducing new data protection safeguards for European citizens. The CCIA said these should “pave the way for a new and strengthened EU-US data privacy framework”. </p><p>However, lawmakers on both sides of the Atlantic “still need to finalize the framework before it can come into force”.</p><p>“Today’s legal uncertainty will continue to persist as long as this new data transfer mechanism has not been formally approved by EU member states. We call on the 27 EU national governments to approve the Commission’s adequacy decision without delay,” said Alexandre Roure, public policy director at CCIA Europe. </p><p>The fine issued to Meta is the largest ever handed out since the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> was enacted in 2018.</p><p>It also comes the day before the landmark regulation’s fifth anniversary.</p><p>The previous record <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go"><u>GDPR fine</u></a> was <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine"><u>handed to Amazon in 2021 by Luxembourg’s data protection regulator</u></a>.</p><p>The tech giant was ordered to pay €746 million ($807 million) and the details of the case were never revealed in any great detail.</p><p>At the time the fine was nearly 15 times larger than the then-current record fine <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/32811/france-issues-google-with-the-heaviest-gdpr-fine-to"><u>issued to Google in 2019 by the French data protection regulator CNIL</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ChatGPT needs ‘right to be forgotten’ tools to survive, Italian regulators demand ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/chatgpt-needs-right-to-be-forgotten-tools-to-survive-italian-regulators-demand</link>
                                                                            <description>
                            <![CDATA[ ChatGPT users in Italy could be granted tools to have false information changed under new rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n3uUqT8dx2b8mxedgbkvMG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QhkfY7sLHAggauPQgNd36B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Apr 2023 11:29:27 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 12:22:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QhkfY7sLHAggauPQgNd36B-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT website displayed on a laptop screen]]></media:description>                                                            <media:text><![CDATA[ChatGPT website displayed on a laptop screen]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT website displayed on a laptop screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QhkfY7sLHAggauPQgNd36B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ChatGPT&apos;s developer OpenAI has been ordered to implement a ‘right to be forgotten’-style policy in the chatbot by the Italian data protection regulator (SA).</p><p>Data subject rights were among the most important considerations made by the Italian regulator in deciding ChatGPT’s long-term presence in the country, which has recently been in doubt.</p><p>The additional measures that must be implemented, per the Italian SA’s recent address, include the capability for users and non-users to request their personal information be changed if generated in <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> user prompts. </p><p>“OpenAI will have to make available easily accessible tools to allow non-users to exercise their right to object to the processing of their personal data as relied upon for the operation of the algorithms,” the regulator said. </p><p>“The same right will have to be afforded to users if legitimate interest is chosen as the legal basis for processing their data,” it added. </p><p>The measures echo the so-called ‘<a href="https://www.itpro.com/data-protection/22378/what-is-googles-right-to-be-forgotten"><u>right to be forgotten</u></a><u>&apos;</u> - the data privacy rule that preceded GDPR and was ultimately included in the EU-wide regulations in 2018.</p><p>Since Italy banned the use of ChatGPT in the country earlier this month, a move that was <a href="https://www.itpro.com/business/policy-legislation/370377/italys-chatgpt-ban-branded-an-overreaction-by-experts"><u>branded ‘an overreaction’ by experts</u></a>, talks have been ongoing between it and OpenAI - ChatGPT’s developer.</p><p>The result of these talks has led the California-based firm being given a ‘to-do’ list of changes before it can resume operating in the country. </p><p>OpenAI has been given a deadline of 30 April to comply with the numerous measures set out by the Italian SA. </p><p>These include changes to data processing transparency, the rights of data subjects, the legal basis of <a href="https://www.itpro.com/business-operations/31681/what-is-data-processing"><u>data processing</u></a> for algorithmic training, and safeguards for minors. </p><h2 id="gdpr-and-data-subject-rights">GDPR and data subject rights</h2><p>Data subject rights outlined under <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready"><u>GDPR</u></a> include eight fundamental tenets, including the right to withdraw consent for the use and processing of personal data. </p><p>Under GDPR, citizens are also entitled to the right to rectification under Article 16 of the legislation, meaning that data subjects can request “inaccurate or outdated personal information be updated or corrected”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6EUeCWHrpCmJLv2E2X7Jxg" name="Innovation to boost productivity and provide better data insights_thumb.png" caption="" alt="Whitepaper cover with title and logo over image of female worker with a tablet in a warehouse" src="https://cdn.mos.cms.futurecdn.net/6EUeCWHrpCmJLv2E2X7Jxg.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Innovation to boost productivity and provide better data insights</strong></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/370148/innovation-to-boost-productivity-and-provider-better-data-insights"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Similarly, data subjects have the right to be forgotten, or the ‘right to erasure’, which enables them to request that their personal data be deleted.</p><p>In this context, the Italian data protection regulator appears concerned that given the potential for personal information to be disclosed via ChatGPT, this poses a risk to Italian citizens and is in breach of GDPR. </p><p>Large language models (LLMs) such as ChatGPT rely on huge volumes of information drawn from the internet to train AI models.</p><p>This has posed questions recently over how platforms such as ChatGPT may pose privacy risks - and the generation of incorrect information has been thrust firmly into the spotlight in this regard.</p><p>Last week, an Australian mayor mulled the prospect of legal action when ChatGPT generated false information which stated he was imprisoned for bribery.</p><p>In reality, Brian Hood, Mayor of Hepburn Shire Council, was a whistleblower and was neither arrested nor convicted on criminal charges.</p><h2 id="regulatory-crackdown">Regulatory crackdown</h2><p>Discussions around regulatory safeguards to mitigate the potential dangers of generative AI have raged since the launch of ChatGPT in November last year.</p><p> Earlier this week, US authorities launched a public consultation to <a href="https://www.itpro.com/technology/artificial-intelligence/us-starts-exploring-accountability-measures-to-keep-ai-companies-in-check"><u>explore potential “accountability measures”</u></a> for companies developing AI systems such as ChatGPT. </p><p>The consultation could guide the development of future US legislation on AI safeguards to ensure responsible use.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US starts exploring “accountability measures” to keep AI companies in check ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/us-starts-exploring-accountability-measures-to-keep-ai-companies-in-check</link>
                                                                            <description>
                            <![CDATA[ The move follows Italy’s recent ban on ChatGPT due to data privacy concerns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">66NL2fujeLLPv7eWtwbYGP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ECqSLRa3EpxwcRcj9aZnqX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 15:14:42 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 10:55:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ECqSLRa3EpxwcRcj9aZnqX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[neon blue human head (right-side profile) with particle overlay to denote AI]]></media:description>                                                            <media:text><![CDATA[neon blue human head (right-side profile) with particle overlay to denote AI]]></media:text>
                                <media:title type="plain"><![CDATA[neon blue human head (right-side profile) with particle overlay to denote AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ECqSLRa3EpxwcRcj9aZnqX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Lawmakers in the US are set to explore potential “accountability measures” for companies developing artificial intelligence (AI) systems such as ChatGPT amid concerns over economic and societal impacts. </p><p>The National Telecommunications and Information Administration (NTIA), the US agency which provides advice to the government on technology policies, said it will launch a public consultation on AI products and services. </p><p>According to the NTIA, insights gathered from this consultation will help inform the Biden administration to develop a “cohesive and comprehensive federal government approach to AI-related risks and opportunities”. </p><p>“NTIA’s <em>‘AI Accountability Policy Request for Comment’ </em>seeks feedback on what policies can support the development of AI audits, assessments, certifications, and other mechanisms to create earned trust in AI systems that they work as claimed,” the department said in a statement on Tuesday. </p><p>In its statement, the NTIA said that potential audits of AI systems could work in a similar fashion to those conducted in the financial services industry to “provide assurance that an AI system is trustworthy”.</p><p>NTIA administrator Alan Davidson said the consultation will help inform the US administration’s long-term approach to AI products and prevent or mitigate any adverse effects. </p><p>“Responsible AI systems could bring enormous benefits, but only if we address their potential consequences and harms. For these systems to reach their full potential, companies and consumers need to be able to trust them,” he said. </p><p>“Our inquiry will inform policies to support AI audits, risk and safety assessments, certifications, and other tools that can create earned trust in AI systems.”</p><h2 id="concerns-over-ai-apos-s-growth">Concerns over AI&apos;s growth</h2><p>The move from the NTIA follows mounting concerns about the potential impact of generative AI systems such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a>. </p><p>The rapid advent of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> products has prompted a degree of hesitancy among lawmakers on both sides of the Atlantic. </p><p>In late March, Italy announced a shock ‘ban’ on ChatGPT amid data privacy concerns. </p><p>The Italian data protection authority voiced serious concerns about the generative AI model and said it plans to investigate OpenAI “with immediate effect”. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCES</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4VvxrVfmo9wnMrMfPV42mD" name="The three keys to successful AI and ML outcomes_thumb.png" caption="" alt="Whitepaper cover with image of female colleague using a tablet" src="https://cdn.mos.cms.futurecdn.net/4VvxrVfmo9wnMrMfPV42mD.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The three keys to successful AI and ML outcomes</strong></p><p class="fancy-box__body-text">Leverage the full power of artificial intelligence</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/technology/artificial-intelligence-ai/369912/the-three-keys-to-successful-ai-and-ml-outcomes"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Lawmakers elsewhere in Europe are also thought to be exploring a potential crackdown on AI systems, with German authorities among those cited as having serious concerns. </p><p>While lingering worries over generative AI products such as ChatGPT continue, some industry analysts <a href="https://www.itpro.com/business/policy-legislation/370377/italys-chatgpt-ban-branded-an-overreaction-by-experts"><u>described the Italian decision as an “overreaction”</u></a>, saying that such crackdowns could have negative long-term implications for companies in the country exploring the use of AI. </p><p>Andy Patel, researcher at WithSecure, told <em>ITPro</em> that Italy’s decision had essentially “cut off” one of the most transformative tools currently available to businesses and individuals. </p><p>Industry stakeholders have also voiced a growing discontent over the speed of generative AI development. </p><p>Around the time of Italy’s ChatGPT decision, an open letter penned by tech industry figures including Elon Musk <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370345/tech-pioneers-call-for-six-month-pause-ai-development-out-of-control"><u>called for an immediate halt</u></a> to “out of control” AI development. </p><p>The controversial letter demanded a six-month pause be imposed on companies building generative AI models and argued that there is a concerning lack of corporate and regulatory safeguards currently in place to moderate generative AI development. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TikTok's two new European data centres to address data protection concerns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/370099/tiktoks-two-new-european-data-centres-wont-solve-problems</link>
                                                                            <description>
                            <![CDATA[ The company is under pressure to prove its user data isn’t being accessed by the Chinese state ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9QpBjCVCdjnPDbGJcdif79</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hV2kMBGWfiYtex4X5MG7Fj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Feb 2023 12:11:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hV2kMBGWfiYtex4X5MG7Fj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man walking in front of a neon TikTok sign on an office wall]]></media:description>                                                            <media:text><![CDATA[A man walking in front of a neon TikTok sign on an office wall]]></media:text>
                                <media:title type="plain"><![CDATA[A man walking in front of a neon TikTok sign on an office wall]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hV2kMBGWfiYtex4X5MG7Fj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>TikTok is set to establish two new data centres in Europe as the Chinese social media platform looks to comply with local data laws.</p><p>The company, which has more than 150 million users across Europe, said that it’s finalising a plan for a second data centre in Ireland with a third-party service provider.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok" data-original-url="/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok">FCC commissioner urges Apple and Google to remove TikTok from app stores</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368974/tiktok-reportedly-suffers-data-breach" data-original-url="/security/data-breaches/368974/tiktok-reportedly-suffers-data-breach">TikTok reportedly suffers data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/information-commissioner/369164/tiktok-could-be-hit-with-ps27m-fine-for-failing" data-original-url="/policy-legislation/information-commissioner/369164/tiktok-could-be-hit-with-ps27m-fine-for-failing">TikTok could be hit with £27m fine for failing to protect children's privacy</a></p></div></div><p>It's also in talks to secure a third data centre in Europe. It didn’t specify where, though it said it will complement its Ireland operations.</p><p>European TikTok user data is set to begin migrating this year and continue into 2024.</p><p>“We also remain focused on building trust with our community by demonstrating to them that their data is secure,” said Rich Waterworth, general manager of operations, Europe, at TikTok.</p><p>“We're continuing to deliver against the data governance strategy we set out for Europe last year, which includes further reducing employee access to European user data, minimising data flows outside of Europe, and storing European user data locally.”</p><h2 id="tiktok-tightens-data-protection">TikTok tightens data protection</h2><p>TikTok announced in April 2020 that it would establish a <a href="https://www.itpro.com/strategy/29134/what-is-a-datacentre" target="_blank" data-original-url="https://www.itpro.com/strategy/29134/what-is-a-datacentre">data centre</a> in Ireland, its first in Europe, with the intent to store European user data at the facility.</p><p>The following year, the company also revealed its data governance strategy, underlining that it was committed to Europe’s <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> regulations.</p><p>In April 2022, TikTok gave an update on this data governance strategy for Europe and revealed that it had finally signed a contract for a data centre in Dublin to store UK and EEA user data through a third-party service.</p><p>Operations at this site were expected to commence in early 2023. A spokesperson from TikTok told <em>IT Pro</em> that it plans to start the migration of Europe user data beginning in Q2.</p><p>TikTok has stored global user data overseas, in locations like Singapore or the US. However, it said it wanted to provide a localised solution which would help it to comply with European data sovereignty laws.</p><p>“Chinese-owned TikTok is under pressure to assure its international customers that the user data it holds is secure and safe from being accessed by the Chinese state,” said John Abbott, infrastructure analyst at 451 Research, part of S&P Global Market Intelligence.</p><p>“It’s part of a broader <a href="https://www.itpro.com/policy-legislation/data-governance/369834/building-a-data-governance-strategy" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-governance/369834/building-a-data-governance-strategy">data governance</a> plan set out by TikTok intended to reduce the flow of European user data outside of Europe.”</p><p>Abbott said that Ireland has been chosen as a location for data centres as it’s popular with hyperscalers, like AWS, Google, and Microsoft, as well as colocation providers like Digital Reality and Equinix.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cUJsxGTZgXXXWAzhLzmAED" name="cUJsxGTZgXXXWAzhLzmAED.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/cUJsxGTZgXXXWAzhLzmAED.png" mos="https://cdn.mos.cms.futurecdn.net/cUJsxGTZgXXXWAzhLzmAED.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why technology, cyber and privacy risk management are critical for digital transformation</strong></p><p class="fancy-box__body-text">How ServiceNow Integrated Risk Management helps you embrace the digital future</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/370022/why-technology-cyber-and-privacy-risk-management" data-original-url="/business-strategy/digital-transformation/370022/why-technology-cyber-and-privacy-risk-management">FREE DOWNLOAD</a></p></div></div><p>“Opening data centres nearer customers has two benefits: It can help reduce lag by allowing access to data locally rather than thousands of miles away in China,” said Frank Jennings, partner and head of commercial at Teacher Stern LLP.</p><p>“It can also help assuage concerns over the transfer of <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">personal data</a> to China, a regime that doesn’t have a strong human rights record, let alone data protection laws comparable to <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>.”</p><p>Jennings said that keeping data in the EU won’t fix all the problems facing the company on this issue.</p><p>“It wasn’t that long ago that a New York District Court forced Microsoft to hand over customer data it was holding in its Dublin data centre under the aptly named “Clarifying Lawful Overseas Use of Data” – aka the <a href="https://www.itpro.com/security/privacy/361221/could-the-us-cloud-act-force-uk-channel-companies-to-break-gdpr" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361221/could-the-us-cloud-act-force-uk-channel-companies-to-break-gdpr">Cloud Act</a>,” he said. “No doubt the Chinese government will have such powers too.”</p><p>The new data centres are a good start, said Jennings, but won’t be enough to address the underlying issue.</p><p>In June 2022, the head of the FCC in the US <a href="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok">urged Apple and Google</a> to remove TikTok from their app stores due to the way it handled data.</p><p>FCC commissioner Brendan Carr said the app collects vast troves of sensitive data on its users. He pointed to a report which stated that ByteDance officials, the company which owns TikTok, had accessed the app’s sensitive data which had been collected from US citizens.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2023 Strategic roadmap for data security platform convergence ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/369387/2022-strategic-roadmap-for-data-security-platform</link>
                                                                            <description>
                            <![CDATA[ Capitalise on your data and share it securely using consolidated platforms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x8okfbb48uvDrhXHQwsLUH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zbznc4Mrpga7h7asrJ7Pz3-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Oct 2022 11:12:43 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Jan 2023 11:12:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Zbznc4Mrpga7h7asrJ7Pz3-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper with title and text]]></media:description>                                                            <media:text><![CDATA[Whitepaper with title and text]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper with title and text]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zbznc4Mrpga7h7asrJ7Pz3-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Is your data security team working with siloed security tools and processes? Is this standing in the way of enabling secure data usage and sharing for your organisation?</p><p>Gartner recommends a modern data security platform that supports on-premises and cloud data, AI and machine learning use cases, and high levels of integration capability.</p><p>Download this Gartner report to learn how you can enable simpler, more consistent data security that can help your organisation to realise new value and new data opportunities.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49900/ibm-q1-2023-strategic-roadmap-for-data-security-platform-convergence?locale=1&p=false&wp=10687"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data governance and privacy for data leaders ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/data-insights/369356/data-governance-and-privacy-for-data-leaders</link>
                                                                            <description>
                            <![CDATA[ Create your ideal governance and privacy solution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gBVipNJyLkSDUNP8VZ4NBC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Oct 2022 12:26:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper library with title and logo and man cycling over a bridge]]></media:description>                                                            <media:text><![CDATA[Whitepaper library with title and logo and man cycling over a bridge]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper library with title and logo and man cycling over a bridge]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Few things are more important than having quality data that is easy to use, but simultaneously secure and compliant. Being unable to fulfil this need can result in erroneous insights and reduced customer trust. </p><p>This whitepaper analyses several topics related to data governance and privacy such as scalability, establishing and implementing organisation-wide standards, and data lineage and traceability. Building blocks like data cataloguing, automated metadata generation, and reporting are also covered alongside a discussion of how governance and privacy are related to a data fabric.</p><p>Download now to learn more from real-world examples featuring ING.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49813/ibm-q4-2022-en?locale=1&p=false&wp=10353"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Home Office to collect foreign offenders' biometric data using smartwatch scheme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368748/biometrics-of-foreign-offenders-to-be-collected-using-smartwatch-scheme</link>
                                                                            <description>
                            <![CDATA[ Facial recognition and geolocation data will be matched against Home Office, Ministry of Justice and police databases ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nXyWNSL8V9feToAfzjrt5q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oLLNuKXrTvg5kkya7jH8f4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Aug 2022 11:35:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oLLNuKXrTvg5kkya7jH8f4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A smartwatch on someone&amp;#039;s arm, lit in red]]></media:description>                                                            <media:text><![CDATA[A smartwatch on someone&amp;#039;s arm, lit in red]]></media:text>
                                <media:title type="plain"><![CDATA[A smartwatch on someone&amp;#039;s arm, lit in red]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oLLNuKXrTvg5kkya7jH8f4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Home Office is planning to fit migrants who have committed a crime with smartwatches containing facial recognition technology, with which they will be required to scan their faces up to five times per day.</p><p>Migrants fitted with the devices will be expected to complete regular checks, such as taking a photo of themselves for <a href="https://www.itpro.com/business-operations/31681/what-is-data-processing" target="_blank" data-original-url="https://www.itpro.com/business-operations/31681/what-is-data-processing">data processing</a> at points throughout each day. </p><p>Their names, date of birth, nationality, and <a href="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology" target="_blank" data-original-url="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology">facial recognition</a> data will be stored, and checked against a Home Office database, for use in determining whether or not a manual check is required. Location data of those wearing the smartwatches will also be constantly recorded.</p><p>Collected data will be stored for up to six years, and during this time will be shared between the Home Office and the Ministry of Justice and the police. </p><p>Use of a database to cross-check daily photos of migrants to facial recognition data was not expanded upon, but the Metropolitan Police Service has a controversial history of using facial recognition databases, having been discovered <a href="https://www.itpro.com/information-commissioner/34202/sadiq-khan-concerned-over-facial-recognition-at-kings-cross" data-original-url="https://www.itpro.com/information-commissioner/34202/sadiq-khan-concerned-over-facial-recognition-at-kings-cross">surveiling passengers at King’s Cross in 2019</a> for that purpose.</p><p>According to a letter seen by <em>The Guardian</em>, the Home Office pressed ahead with plans for “daily monitoring of individuals subject to immigration control” after completing a data protection impact assessment (DPIA) in August 2021.</p><p>Under the General Data Protection Regulation (GDPR), organisations seeking to implement new systems that could infringe upon the rights of subjects must run a DPIA, in which the <a href="https://www.itpro.com/strategy/29856/data-controllers-responsibilities" data-original-url="https://www.itpro.com/strategy/29856/data-controllers-responsibilities">data controller</a> assesses the risks of processing data on subjects.</p><p>Rights groups have been vocal about their objection to the collection of facial recognition data, both in regards to the invasion of privacy that they see it as representing and also in doubt of the degree to which the technology can be relied on. Big Brother Watch state that between 2016 and 2022, facial recognition used by the Metropolitan Police Service was <a href="https://bigbrotherwatch.org.uk/campaigns/stop-facial-recognition" target="_blank">87% inaccurate</a>.</p><p>The scale of the operation is not currently public knowledge, though the contract signed between the Ministry of Justice and Buddi Limited is valued at up to £6 million by 30 December 2023. </p><p>Home Office data for the year ending June 2021 shows that 2,809 foreign national offenders (FNOs) were returned from the UK that year, a number that would prove sizeable to track if all FNOs were chosen for the smartwatch programme.</p><p>In June, an independent legal review by the Ada Lovelace Institute <a href="https://www.itpro.com/business/policy-legislation/368400/review-calls-for-urgent-new-biometrics-legislation" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368400/review-calls-for-urgent-new-biometrics-legislation">urgently called for new legislation</a> to regulate the use of biometric data, as well as recommending the creation of a biometric ethics board.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-processing/368720/legal-challenge-for-sadiq-khan-over-anpr-expansion-met-access" data-original-url="/data-insights/data-processing/368720/legal-challenge-for-sadiq-khan-over-anpr-expansion-met-access">Legal challenge for Sadiq Khan over ANPR expansion, Met access to data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology" data-original-url="/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology">The pros and cons of facial recognition technology</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/368685/tim-hortons-offers-free-coffee-and-donut-to-app-users-to-settle-data-lawsuit" data-original-url="/security/privacy/368685/tim-hortons-offers-free-coffee-and-donut-to-app-users-to-settle-data-lawsuit">Tim Hortons 'offers free coffee and donut' to app users to settle data lawsuit</a></p></div></div><p>In contrast, the government’s proposed <a href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">Data Reform Bill</a>, which ministers have credited with cutting down the “red tape and pointless paperwork” of GDPR, seeks to reduce the need to seek user consent in certain circumstances, including data processing by criminal justice organisations and police forces.</p><p>“The Home Office is still not clear how long individuals will remain on monitoring,” Dr Monish Bhatia, a lecturer in criminology at Birkbeck, University of London, told <em>the Guardian</em>. </p><p>“They have not provided any evidence to show why electronic monitoring is necessary or demonstrated that tags make individuals comply with immigration rules better. What we need is humane, non-degrading, community-based solutions.”</p><p><em>IT Pro</em> reached out to the Home Office for a statement. Buddi Limited declined to provide comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK safety tech sees another year of growth, amidst backlash ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/business-transformation/368712/uk-safety-tech-sees-another-year-of-growth</link>
                                                                            <description>
                            <![CDATA[ Record investment in the sector has led to widespread implementation of safety measures, but rights groups and some experts still aren't convinced ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uZybb1spqWvMeZaGwnMcZ5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eMQuoqqyAsijwMr7Mrh6pM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Aug 2022 14:55:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eMQuoqqyAsijwMr7Mrh6pM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI padlock with many two-dimensional projections of itself projecting out from it towards the camera, with code streaming across their surfaces]]></media:description>                                                            <media:text><![CDATA[A CGI padlock with many two-dimensional projections of itself projecting out from it towards the camera, with code streaming across their surfaces]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI padlock with many two-dimensional projections of itself projecting out from it towards the camera, with code streaming across their surfaces]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eMQuoqqyAsijwMr7Mrh6pM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK safety tech sector revenues hit £381 million last year, the government has announced, an increase of 21% across the ‘world-leading’ industry. </p><p>This was matched by the creation of jobs within the sector, with a total number of 2,850 now available marking a 30% increase from the previous year.</p><p>Additionally, 57% of safety tech firms <a href="https://www.itpro.com/business-strategy/34625/the-best-uk-cities-to-live-and-work-in" data-original-url="https://www.itpro.com/business-strategy/34625/the-best-uk-cities-to-live-and-work-in">were based outside of London and the South East</a>, a sizeable increase from the 48% based outside of these regions just two years prior. In total, 117 firms have been identified as currently offering safety tech solutions.</p><p>In a blog post, the government specifically championed safety tech such as tools used to detect and remove child sexual exploitation and abuse (CSEA) content. These systems have been put in the spotlight by the government’s <a href="https://www.itpro.com/marketing-comms/social-media/362045/online-safety-bill-missed-opportunity-child-abuse-dcms" data-original-url="https://www.itpro.com/marketing-comms/social-media/362045/online-safety-bill-missed-opportunity-child-abuse-dcms">Online Safety Bill</a>, which seeks to <a href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" data-original-url="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">compel companies to use or develop such tools</a> to even work on messages currently protected by <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption (E2EE)</a>.</p><p>The bill has drawn criticism from rights organisations such as The Open Rights Group, which <a href="https://www.openrightsgroup.org/press-releases/governments-online-safety-bill-is-an-orwellian-censorship-machine">has described</a> the measures as “an Orwellian censorship machine.” A recent survey of industry experts also revealed that <a href="https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it" data-original-url="https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it">66% thought ending E2EE would have a negative impact on protecting society</a>, while Meta <a href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023" data-original-url="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">plans rollout of E2EE across Messenger and Instagram</a> in 2023.</p><p>Last year, the government set up the <a href="https://www.gov.uk/government/news/government-funds-new-tech-in-the-fight-against-online-child-abuse">Safety Tech Challenge Fund</a>, a £555,000 competition to find novel solutions for combatting CSEA content without impacting people’s rights to privacy. These include artificial intelligence (AI) and facial recognition solutions for detecting child abuse images before upload.</p><p>At the time, it was announced that the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> would offer advice to the winners, to protect privacy throughout the development process.</p><p>However, doubts have been raised over the feasibility of regulation of direct messaging that also retains privacy measures. Last year several rights organisations signed <a href="https://bigbrotherwatch.org.uk/2021/06/big-brother-watch-signs-joint-letter-to-mps-to-protect-end-to-end-encryption">an open letter to MPs</a>, stating that the tech being sought by the government would be bad for business as well as individual privacy.</p><p>“End-to-end encryption means that your constituents’ family photographs, messages to friends and family, financial information, and the commercially sensitive data of businesses up and down the country, can all be kept safe from harm’s way,” the letter stated.</p><p>“It also keeps us safer in a world where connected devices have physical effect: end-to-end encryption secures connected homes, cars and children’s toys. The government should not be making those more vulnerable to attack.”</p><p>At the time of writing, the Online Safety Bill <a href="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn" data-original-url="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn">has been put ‘on ice’</a> amidst Conservative Party restructuring, leaving the timeline for when these changes can be expected to be passed into law unclear.</p><p>When the house returns in September the bill could be redrafted, or scrapped entirely under the leadership of either Liz Truss or Rishi Sunak.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech" data-original-url="/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech">Why the UK is dragging its feet on regulating big tech</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms" data-original-url="/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms">Zoom adds end-to-end encryption to Zoom Phone and Breakout Rooms</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28115/the-pros-and-cons-of-net-neutrality" data-original-url="/strategy/28115/the-pros-and-cons-of-net-neutrality">The pros and cons of net neutrality</a></p></div></div><p>For now, safety tech sees no signs of slowing, as <a href="https://www.gov.uk/government/publications/safer-technology-safer-users-the-uk-as-a-world-leader-in-safety-tech/uk-safety-tech-sector-2022-analysis#supporting-the-safety-tech-sector">67% of firms within the sector</a> predict a customer base increase of 50% or more within the next 12 months. </p><p>“Making the online world safer is not only the right thing to do, it’s good for business,” said digital minister Damien Collins</p><p>“UK tech firms are at the cutting-edge developing practical solutions to the risks posed by the internet so that it continues to be a benefit not a detriment to people’s lives.</p><p>“They have blazed a trail of growth, innovation and job creation to become world leaders in their field and we are committed to maintaining their upward trajectory.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tim Hortons 'offers free coffee and donut' to app users to settle data lawsuit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368685/tim-hortons-offers-free-coffee-and-donut-to-app-users-to-settle-data-lawsuit</link>
                                                                            <description>
                            <![CDATA[ Canadian privacy commissioners found that the coffee giant had tracked and recorded the movements of its app users every few minutes of the day, even when the app wasn’t open ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uSbGi3cx2Kuz6p5iVJGZJH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wUiJhB3msEFZ8BsKRqR4Uc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Aug 2022 10:14:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wUiJhB3msEFZ8BsKRqR4Uc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Photo of a large, red Tim Hortons sign on a storefront, topped with recently fallen snow]]></media:description>                                                            <media:text><![CDATA[Photo of a large, red Tim Hortons sign on a storefront, topped with recently fallen snow]]></media:text>
                                <media:title type="plain"><![CDATA[Photo of a large, red Tim Hortons sign on a storefront, topped with recently fallen snow]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wUiJhB3msEFZ8BsKRqR4Uc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tim Hortons has reached a proposed settlement of a national class action lawsuit involving its app and the collection of geolocation data.</p><p>The Canadian coffee giant had been found to have tracked and recorded the movements of its app users every few minutes of the day, Canadian privacy commissioners found in June 2022. This happened even when the app wasn’t open, in violation of the country’s <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">privacy</a> laws, and occurred between 1 April, 2019 and 30 September, 2020.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/361898/morgan-stanley-agrees-60-million-settlement-data-breach-lawsuit" data-original-url="/policy-legislation/data-protection/361898/morgan-stanley-agrees-60-million-settlement-data-breach-lawsuit">Morgan Stanley agrees $60 million settlement in data breach lawsuit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368645/t-mobile-to-pay-350m-to-settle-class-action-lawsuit" data-original-url="/security/data-breaches/368645/t-mobile-to-pay-350m-to-settle-class-action-lawsuit">T-Mobile to pay $350m to settle class action lawsuit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/368577/google-fined-971k-for-litigation-misconduct-in-privacy-suit" data-original-url="/security/privacy/368577/google-fined-971k-for-litigation-misconduct-in-privacy-suit">Google fined $971k for litigation misconduct in privacy suit</a></p></div></div><p>Tim Hortons sent an <a href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" target="_blank" data-original-url="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services">email</a> to customers on 29 July detailing that as part of the proposed settlement agreement, eligible app users will receive a free hot beverage and baked good, as shared by James McLeod <a href="https://pbs.twimg.com/media/FY1-QSdXkAAtPyV?format=jpg&name=medium" target="_blank">on Twitter.</a> The company is set to share the details of the distribution of this settlement once it is approved by the court.</p><p>Tim Hortons has offered to compensate group members in two areas, without any admission of liability, for the purpose of avoiding trial and the additional costs and expenses related thereto, it said. </p><p>The first is granting each eligible member one credit to be used to purchase one free hot beverage, at the value of $6.19 CAD plus taxes, and one free baked good, at the value of $2.39 plus taxes, from any participating Tim Hortons store in Canada.</p><p>The second is that the company said it would take appropriate measures to permanently delete any geolocation <a href="https://www.itpro.com/strategy/28185/what-is-data-mining" target="_blank" data-original-url="https://www.itpro.com/strategy/28185/what-is-data-mining">data</a> about group members that may be in its possession, and instruct its third-party vendor, Radar Labs, to do the same.</p><p><em>IT Pro</em> has contacted Tim Hortons for comment.</p><h2 id="what-did-the-investigation-find">What did the investigation find?</h2><p>At the start of June, an investigation into Tim Hortons from various privacy commissioners in Canada found that its continual and vast <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">collection of location information</a> was not proportional to the benefits the store may have hoped to gain from better-targeted promotion of its coffee and other products.</p><p>The Office of the Privacy Commissioner of Canada, Commission d’accès à l’information du Québec, Office of the Information and Privacy Commissioner for British Columbia, and Office of the Information and Privacy Commissioner of Alberta carried out the investigation.</p><p>“The Tim Hortons app asked for permission to access the mobile device’s geolocation functions but misled many users to believe information would only be accessed when the app was in use. In reality, the app tracked users as long as the device was on, continually <a href="https://www.itpro.com/business-operations/31681/what-is-data-processing" target="_blank" data-original-url="https://www.itpro.com/business-operations/31681/what-is-data-processing">collecting their location data</a>,” the commissioners said.</p><p>They also found the app used location data to infer where users lived, where they worked, and whether they were travelling. It generated an “event” every time users entered or left a Tim Hortons competitor, a major sports venue, or their home or workplace.</p><p>The investigation discovered that Tim Hortons continued to collect vast amounts of location data for a year after shelving plans to use it for targeted advertising, even though it had no legitimate need to do so.</p><p>The company said it only used aggregated location data in a limited way, like analysing user trends, whether users switched to other coffee chains, and how users’ movements changed as the pandemic took hold.</p><p>The investigation launched in 2020, and while the store stopped continually tracking users’ locations in the same year, the commissioners said that this didn’t eliminate the risk of <a href="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security">surveillance</a>. They added that Tim Hortons’ contract with a US third-party location services supplier contained language that was vague and permissive, which would have allowed the company to sell “de-identified” location data for its own purposes.</p><p>“There is a real risk that de-identified geolocation data could be re-identified,” warned the commissioners.</p><p>“Location data is highly sensitive because it can be used to infer where people live and work, reveal trips to medical clinics. It can be used to make deductions about religious beliefs, sexual preferences, social political affiliations and more,” they underlined.</p><p>Lastly, the investigation revealed that Tim Hortons lacked a robust <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">privacy management</a> programme for the app, which would have allowed the company to identify and address many of the privacy contraventions the investigation found.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TikTok to give researchers new API for insight, greater transparency ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-operations/368667/tiktok-to-give-researchers-new-api-for-insight-greater-transparency</link>
                                                                            <description>
                            <![CDATA[ Trends identified by independent analysts could inform business decisions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWdaf7g8eGi2nKVRgCKurF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Jul 2022 11:12:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:description>                                                            <media:text><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>TikTok has announced new initiatives aimed at improving transparency around the company’s data use, measurement of trends and moderation systems. </p><p>In a <a href="https://newsroom.tiktok.com/en-us/strengthening-our-commitment-to-transparency">blog post</a>, chief operating officer Vanessa Pappas laid out a series of plans in detail to involve researchers, industry experts and academics to test and advise on TikTok’s platform.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WvTN5p4tPpqD7o7rbLAShY" name="WvTN5p4tPpqD7o7rbLAShY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/WvTN5p4tPpqD7o7rbLAShY.jpg" mos="https://cdn.mos.cms.futurecdn.net/WvTN5p4tPpqD7o7rbLAShY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 Gartner critical capabilities for data integration tools</strong></p><p class="fancy-box__body-text">How to identify the right tool in support of your data management solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/368471/2021-gartner-critical-capabilities-for-data-integration-tools" data-original-url="/technology/machine-learning/368471/2021-gartner-critical-capabilities-for-data-integration-tools">FREE DOWNLOAD</a></p></div></div><p>Researchers will be given access to an application programming interface (API) through which they will be able to study public and anonymised data about content on the platform. This will be made available later this year. </p><p>The short-form video hosting service and editing app is extremely popular, with an active base of over one billion users. If research led by the data is made publicly available, insight into the trends and data analysis of TikTok’s vast dataset could prove highly valuable to the tech sector.</p><p>Businesses could benefit from knowledge of the factors that drive content to do well on the platform, as well as an understanding of how trends grow in popularity to release videos before or during them. Often, by the time businesses engage with a viral trend, much of the user interest in it has waned.</p><p>This month, Ofcom <a href="https://www.ofcom.org.uk/news-centre/2022/instagram,-tiktok-and-youtube-teenagers-top-three-news-sources#:~:text=TikTok%20clocks%20up%20millions%20more,adults%20in%202022%20(7%25).">published a report</a> stating that TikTok is the second most popular news source for teenagers with 28% using it to inform themselves, just one percent behind Instagram’s 29% of teens. </p><p>This marks it as a vital frontier in the battle against <a href="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation" data-original-url="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation">disinformation</a>, and the moves announced today will allow greater oversight into this ongoing issue. In the same announcement, the company pledged to publish information on covert influence operations in all further quarterly Community Guidelines Enforcement Reports.</p><p>Select researchers will be given a similar API focused on TikTok's moderation system, to probe existing content moderation systems and the current state of content on the platform. The API will also have the functionality to let researchers upload their own content, to see what is permitted, rejected, or passed on to moderators.</p><p>In addition, select independent experts will be given access to TikTok’s list of filter keywords, which it uses to identify content as harmful and asked to offer advice based on this.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media-marketing/368526/tiktok-launches-programme-to-help-smbs-with-social" data-original-url="/marketing-comms/social-media-marketing/368526/tiktok-launches-programme-to-help-smbs-with-social">TikTok launches programme to help SMBs with social media marketing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" data-original-url="/data-protection/34415/how-to-maintain-your-privacy-on-social-media">How to maintain your privacy on social media</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics" data-original-url="/business-strategy/28163/what-is-big-data-analytics">What is big data analytics?</a></p></div></div><p>Those chosen will include members of TikTok’s US Content Advisory Council, which was set up in 2020 to give industry experts a say in the company’s safety strategies and content policies. The expert members of TikTok’s regional Safety Advisory Councils, namely Europe, the Middle East and North Africa, Asia Pacific, Brazil and Latin America will also be included.</p><p>“We've been listening to feedback from different communities of researchers, academics, and experts, and are today sharing new initiatives to strengthen transparency and accountability of our platform,” wrote Pappas in the post.</p><p>TikTok and its parent company ByteDance have faced harsh criticism in recent months, with FCC commissioner Brendan Carr last month <a href="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok">urging Apple and Google to remove TikTok from their respective app stores</a>. This was prompted by growing concerns over the security risk posed by the app's data harvesting.</p><p><em>IT Pro</em> has approached TikTok for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FTC fires warning against sensitive data misuse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/368525/ftc-strikes-harsh-tone-against-potential-sensitive-data-misuse</link>
                                                                            <description>
                            <![CDATA[ The agency has responded to fears around biometric data breaches, including those relating to abortion services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tUyYgg2au1QXZDWbkFzdcc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Tz9sVz9riEYWkuzJEVtsq5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Jul 2022 09:15:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Tz9sVz9riEYWkuzJEVtsq5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A point-of-view shot of a pregnant woman, holding a phone with an app that shows she is 22 weeks pregnant]]></media:description>                                                            <media:text><![CDATA[A point-of-view shot of a pregnant woman, holding a phone with an app that shows she is 22 weeks pregnant]]></media:text>
                                <media:title type="plain"><![CDATA[A point-of-view shot of a pregnant woman, holding a phone with an app that shows she is 22 weeks pregnant]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Tz9sVz9riEYWkuzJEVtsq5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a clear message to all companies collecting individual data, the Federal Trade Commission (FTC) has reaffirmed its commitment to harshly enforce illegal breaches of sensitive information.</p><p>The FTC notes in a <a href="https://www.ftc.gov/business-guidance/blog/2022/07/location-health-other-sensitive-information-ftc-committed-fully-enforcing-law-against-illegal-use">blog post</a> there's a litany of information that can be collected to categorise and identify people’s medical histories, which has potential for dangerous exploitation particularly in the case of consumers seeking abortions.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WvTN5p4tPpqD7o7rbLAShY" name="WvTN5p4tPpqD7o7rbLAShY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/WvTN5p4tPpqD7o7rbLAShY.jpg" mos="https://cdn.mos.cms.futurecdn.net/WvTN5p4tPpqD7o7rbLAShY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 Gartner critical capabilities for data integration tools</strong></p><p class="fancy-box__body-text">How to identify the right tool in support of your data management solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/368471/2021-gartner-critical-capabilities-for-data-integration-tools" data-original-url="/technology/machine-learning/368471/2021-gartner-critical-capabilities-for-data-integration-tools">FREE DOWNLOAD</a></p></div></div><p>In light of the recent ruling by the Supreme Court to overrule Roe v Wade, the decision which had protected the right to choose to have an abortion, misuse of sensitive data is a point of fierce discussion. </p><p>The regulator cited cases such as that of Copley Advertising LLC as early examples of what could be a growing trend. The company had been utilizing location data to identify people entering within a certain range of clinics offering abortion in several states, and then targeting them with anti-abortion advertising.</p><p>It has since <a href="https://www.mass.gov/news/ag-reaches-settlement-with-advertising-company-prohibiting-geofencing-around-massachusetts-healthcare-facilities">reached a settlement with the Massachusetts Attorney General</a> for misuse of geofencing for advertising purposes.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">New health data strategy to consult public on NHS data use <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">UK unveils Data Reform Bill, scrapping parts of GDPR and promising £1 billion in savings</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361907/ftc-threatens-legal-action-companies-failing-to-patch-log4shell" data-original-url="/security/cyber-security/361907/ftc-threatens-legal-action-companies-failing-to-patch-log4shell">FTC threatens legal action against companies failing to patch Log4Shell</a></p></div></div><p>Striking a tough tone against potentially unethical firms, the FTC further outlined its powers to not only fine companies in breach of data protection legislation, but also require them to delete data they have collected as well as any models made with the data.</p><p>People’s information can be collected and misused in more ways than one, and the post is careful to focus on the potential for information that <a href="https://www.itpro.com/policy-legislation/data-protection/359768/almost-half-of-workers-would-share-health-data-to-get" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359768/almost-half-of-workers-would-share-health-data-to-get">consumers willingly track</a> — such as blood sugar level, menstrual cycle, sleep patterns and contraceptive use — in addition to less flagged data points such as location.</p><p>Unlike the EU and UK, the US has no central data protection legislation, nor is there an explicit right to privacy within the US constitution. Instead, a range of laws and constitutional rulings cover consumers’ right to privacy, making up a complex tradition of protections that vary state-by-state.</p><p>Currently, some of the widest such legislation includes rules that the FTC enforces such as the Health Breach Notifications Rule, which states that “vendors of personal health records and related entities to notify consumers following a breach involving unsecured information”. Violation of the rule can result in a fine if up to $46,517 per violation per day. </p><p>Many rights groups argue these rules are inadequate and subject to loopholes such as legitimate sale of information to third-party brokers. The non-profit organisation Planned Parenthood has called for a federal data protection law to codify regulation of such data into law and prevent misuse by advertisers. <a href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">Biometric data</a> law is a particularly contentious issue, with <a href="https://www.itpro.com/business/policy-legislation/368400/review-calls-for-urgent-new-biometrics-legislation" data-original-url="https://www.itpro.com/business/policy-legislation/368400/review-calls-for-urgent-new-biometrics-legislation">similar calls within the UK</a> right now for more transparent consumer protections around what data companies can track, and why.</p><p>In the post, the FTC specifically warns against misleading claims of ‘anonymization’ by companies, pointing out that such data can frequently be re-identified. Knowingly making such false claims to placate customer concerns around privacy will trigger FTC intervention, it asserts.</p><p>“The Commission is committed to using the full scope of its legal authorities to protect consumers’ privacy. We will vigorously enforce the law if we uncover illegal conduct that exploits Americans’ location, health, or other sensitive data,” stated the agency in the blog post.</p><p>“The FTC’s past enforcement actions provide a roadmap for firms seeking to comply with the law.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Review calls for urgent new laws over use of biometric technology ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/368400/review-calls-for-urgent-new-biometrics-legislation</link>
                                                                            <description>
                            <![CDATA[ Report also calls for the creation of a biometrics ethics board and greater scrutiny of data sharing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sWuk5PbWcRFYrDp4NYA4qF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rQcLB4WXQzk2zpYRtPpw89-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Jun 2022 11:30:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rQcLB4WXQzk2zpYRtPpw89-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital render of a thumbprint, which glows blue and has strands of energy emanating from it]]></media:description>                                                            <media:text><![CDATA[A digital render of a thumbprint, which glows blue and has strands of energy emanating from it]]></media:text>
                                <media:title type="plain"><![CDATA[A digital render of a thumbprint, which glows blue and has strands of energy emanating from it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rQcLB4WXQzk2zpYRtPpw89-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An independent legal review has concluded that new laws regulating the use of biometric data in the public and private sector are urgently needed.</p><p>The report, commissioned by The Ada Lovelace Institute and undertaken by Matthew Ryder QC, aimed to highlight the uncertain level of biometric technology regulation provided by existing laws such as the EU's General Data Protection Regulation (GDPR).</p><p>Among the review’s recommendations are a new statutory framework to set out the use of <a href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">biometric</a> data by private and public organisations for both identification and classification, and the establishment of a national Biometrics Ethics Board. This, it says, is necessary given the rights-intrusive potential of new technologies such as live facial recognition and gait recognition.</p><p>Further investigation into the private sector’s use of biometrics, as well as the sharing of information between private and public sector entities, was also highlighted as a matter of importance.</p><p>The review gives the example of the <a href="https://www.itpro.com/information-commissioner/34202/sadiq-khan-concerned-over-facial-recognition-at-kings-cross" data-original-url="https://www.itpro.com/information-commissioner/34202/sadiq-khan-concerned-over-facial-recognition-at-kings-cross">use of facial recognition technology at the King’s Cross site</a> in 2019, which was later found to have included a data sharing agreement with the Metropolitan Police and British Transport Police, to “prevent and detect crime in the neighbourhood”, according to the site's owners.</p><p>Recommendations in this area include stricter regulation of Live Facial Recognition (LFR) and a complete moratorium on all LFR in both the public and private sector until the new framework is in place.</p><p>Additional concern was raised around the use of <a href="https://www.itpro.com/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring" data-original-url="https://www.itpro.com/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring">remote monitoring</a> and video processing to collect biometric data in the private sector, enabled by the rise of remote working throughout the pandemic.</p><p>Under current protections provided by GDPR, biometric data is only classified as special category data when it is collected for ‘the purpose of uniquely identifying a natural person'. The Ada Lovelace Institute, in their policy report supplemental to the review, notes that this leaves biometric data used to determine a person’s “gender, race, or emotional state” subject to less stringent legal oversight.</p><p>Proposed legislation would cover use of biometric data for identification and classification. It would also require biometric technology earmarked for public use to first undergo a series of impact assessments to determine its potential impact on privacy and equality, as well as scrutinise the necessity and proportionality of the technology.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">UK unveils Data Reform Bill, scrapping parts of GDPR and promising £1 billion in savings</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="/security/29705/what-are-biometrics">What are biometrics?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go" data-original-url="/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go">GDPR fines: Where does the money go?</a></p></div></div><p>Public bodies would then have to refer any such technology to a newly proposed Biometric Ethics Board, the creation of which would provide ethical oversight in a public advisory capacity. It was also suggested that the advice of the board should be made publicly available, with public bodies required to publish explanations for any decisions made contrary to this advice within 14 days of any such decision.</p><p>Having begun in 2020, the review makes no reference to the proposed <a href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">Data Reform Bill</a>, which has been specifically highlighted by government ministers as relaxing certain restrictions imposed by GDPR that they dubbed “red tape and pointless paperwork”. These include aims by the government to cut down on the need to seek user consent for the processing of data in certain circumstances.</p><p>As part of the review, the Ada Lovelace council convened a Citizens’ Biometrics Council, composed of a diverse group of 50 members of the public asked to learn about and offer views on the use of biometric technology in legislation. A common view in their recommendations was the need for consent and transparency regarding the use of biometric data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A third of UK workers are surveilled by employers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/361472/one-in-three-uk-workers-now-surveilled-by-employers-at-home</link>
                                                                            <description>
                            <![CDATA[ The sharp rise in surveillance comes as it's revealed webcam monitoring has more than doubled ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3aEkAjwhMm2Y2PEhd2UtJr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QunLauaetsmuM23MuxM4x7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Nov 2021 11:07:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QunLauaetsmuM23MuxM4x7-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of a CCTV camera observing anonymous people in a crowd]]></media:description>                                                            <media:text><![CDATA[Graphic of a CCTV camera observing anonymous people in a crowd]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of a CCTV camera observing anonymous people in a crowd]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QunLauaetsmuM23MuxM4x7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A third (32%) of UK workers are now being monitored at work using technology like tracking software and remotely controlled webcams.</p><p>The issue has worsened over the past six months, when workers being monitored stood at a quarter (24%) of those <a href="https://prospect.org.uk/news/new-protections-needed-to-stop-employer-surveillance-of-remote-workers">polled by Prospect</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring" data-original-url="/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring">What has the move to remote working meant for employee monitoring?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358350/it-retailer-handed-eu104m-gdpr" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/358350/it-retailer-handed-eu104m-gdpr">IT retailer faces €10.4m GDPR fine for employee surveillance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/machine-learning/33884/is-ai-workplace-monitoring-helpful-or-harmful" data-original-url="/machine-learning/33884/is-ai-workplace-monitoring-helpful-or-harmful">Is AI workplace monitoring helpful or harmful?</a></p></div></div><p>The sharp increase comes amid a huge jump in webcam monitoring, with 13% of homeworkers currently being surveilled by their employer through their work-issued device. The figures have more than doubled in the past six months as just 5% of workers were monitored via video in April 2021.</p><p>The vast majority of those questioned thought the use of webcam monitoring by employers should either be banned (52%) or regulated (28%). Just 8% of employees reported feeling that employers should be able to monitor their webcam's image at will.</p><p>Younger workers are thought to be particularly at risk of higher rates of monitoring by employers. Defined by an 18-34 age bracket, 48% of younger workers are believed to be monitored at home by employers, including 20% of those being monitored using a camera.</p><p>The latest findings have prompted Prospect to launch a campaign to help drive unionisation in the tech sector as it is affected by the recent upward home surveillance trend due to high levels of remote working and low levels of trade union membership.</p><p>Home surveillance will be investigated alongside other issues affecting the industry such as a culture of working long hours, workplace discrimination, and pay.</p><p>"We are used to the idea of employers checking up on workers, but when people are working in their own homes this assumes a whole new dimension," said Mike Clancy, general secretary at Prospect. "New technology allows employers to have a constant window into their employees homes, and the use of the technology is largely unregulated by government.</p><p>"We think that we need to upgrade the law to protect the privacy of workers and set reasonable limits on the use of this snooping technology, and the public overwhelmingly agree with us. Prospect’s new tech workers sector will be campaigning on this issue and other issues affecting tech workers, and I encourage any workers who are worried about monitoring to join Prospect and support our campaign."</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> is currently reviewing guidance for employers on the use of technologies such as employee monitoring.</p><p>“People expect that they can keep their personal lives private and that they are also entitled to a degree of privacy in the workplace," said an ICO spokesperson to <em>IT Pro</em>. "If organisations wish to monitor their employees, they should be clear about its purpose and that it brings real benefits. Organisations also need to make employees aware of the nature, extent and reasons for any monitoring.</p><p>“We are currently working on updating our employment practices guidance to address the changes in data protection law and to reflect the new ways employers use technology and interact with staff.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yndc9iKve3RcuTCcj4ARhF" name="yndc9iKve3RcuTCcj4ARhF.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/yndc9iKve3RcuTCcj4ARhF.png" mos="https://cdn.mos.cms.futurecdn.net/yndc9iKve3RcuTCcj4ARhF.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Three tips for leading hybrid teams effectively</strong></p><p class="fancy-box__body-text">A guide to employee motivation and engagement for business leaders</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/business-communications/361126/three-tips-for-leading-hybrid-teams-effectively" data-original-url="/marketing-comms/business-communications/361126/three-tips-for-leading-hybrid-teams-effectively">FREE DOWNLOAD</a></p></div></div><p>Workplace monitoring saw a steep rise over the course of the pandemic which saw the nations' workforce largely adopt a work from home policy.</p><p>Some business managers report using the technology to 'feel closer to their workforce' and <a href="https://www.itpro.com/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring" data-original-url="https://www.itpro.com/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring">have reported</a> using the tools for good, offering bonuses and promotions for demonstrably good work.</p><p>Questions around the privacy and ethical issues of the technology's use remain, however. Jim Killock, executive director at Open Rights Group, said to <em>IT Pro</em>: "employers think they have a free pass to monitor as they like, but they do not. They have to consider and consult about the impacts on workers, whose dignity and interests must be preserved. Employers are required to be transparent and accountable.</p><p>“The government plans to scrap such restraints in their current GDPR consultation, but people should get on and use their rights," he added.</p><p>The sentiment is echoed by Chi Onwurah, MP and shadow digital minister, who said: “This deeply worrying research shows just how anxious many people are about the use of <a href="https://www.itpro.com/staffing/surveillance/27912/workplace-monitoring-would-you-let-your-boss-track-your-mood" data-original-url="https://www.itpro.com/staffing/surveillance/27912/workplace-monitoring-would-you-let-your-boss-track-your-mood">invasive surveillance whilst they work</a>. Ministers must urgently provide better regulatory oversight of online surveillance software to ensure people have the right to privacy whether in their workplace or home.</p><p>“The bottom line is that workers should not be subject to <a href="https://www.itpro.com/machine-learning/33884/is-ai-workplace-monitoring-helpful-or-harmful" data-original-url="https://www.itpro.com/machine-learning/33884/is-ai-workplace-monitoring-helpful-or-harmful">digital surveillance</a> without their informed consent, and there should be clear rules, rights and expectations for both businesses and workers,” she added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Senators urge FTC to enforce child privacy laws  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/361179/senators-urge-ftc-to-enforce-child-privacy-laws</link>
                                                                            <description>
                            <![CDATA[ Lawmakers wrote to the FTC Commissioner, asking her to enforce new child protection measures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8n2A9zzDHkgieLkac8Vi5v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mSUZh7mjxZb3ikPEyeV6mb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Oct 2021 18:38:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mSUZh7mjxZb3ikPEyeV6mb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The FTC crest on a building]]></media:description>                                                            <media:text><![CDATA[The FTC crest on a building]]></media:text>
                                <media:title type="plain"><![CDATA[The FTC crest on a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mSUZh7mjxZb3ikPEyeV6mb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Senator Edward J. Markey (D-Mass.) and Representatives Kathy Castor (FL-14) and Lori Trahan (MA-03) today wrote to the Federal Trade Commission (FTC) to ask it to use its powers to ensure that large online platform operators handle children's privacy more responsibly. </p><p>The Senators want the FTC to enforce policies outlined in the UK's Age Appropriate Design Code (AADC). The Code, released by the Information Commissioner's Office (ICO) in September 2020, came into effect last month. It dictates 15 principles that online services firms need to follow in order to better protect children's privacy on the web. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/360756/ftc-bans-spyfone-and-orders-company-to-quit-surveillance-app" data-original-url="/business/policy-legislation/360756/ftc-bans-spyfone-and-orders-company-to-quit-surveillance-app">FTC bans SpyFone and orders company to quit surveillance app business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/360513/ftc-scolds-facebook-for-citing-it-in-researcher-ban" data-original-url="/marketing-comms/social-media/360513/ftc-scolds-facebook-for-citing-it-in-researcher-ban">FTC scolds Facebook for citing it in researcher ban</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/360441/civil-rights-groups-ask-the-ftc-to-stop-amazon-surveillance" data-original-url="/business/policy-legislation/360441/civil-rights-groups-ask-the-ftc-to-stop-amazon-surveillance">Civil rights groups ask the FTC to stop Amazon surveillance</a></p></div></div><p>The AADC states that providers of online services to children should work in the child’s best interests and offer privacy policy information in language suited to the child's age. It forbids service providers from using data in ways that are detrimental to their wellbeing and bans the use of “nudge” techniques that encourage children to give up their privacy. It also enforces default high privacy settings and disabling of geolocation functions. </p><p>The Code, which also applies to connected toys and devices, is not a law. Still, the ICO takes it into account when evaluating companies' compliance with regulations such as GDPR. Violation of those regulations, which the UK government is pressing to reform, can carry financial penalties. </p><p>The letter highlighted several steps that technology companies took in response to the code. Instagram introduced private accounts for young people by default to provide more protection from predators and some advertising, the senators pointed out. YouTube defaulted to making uploads private and turning off location history for users under 18. TikTok disabled messaging for users under 16. </p><p>"We write to urge the <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc" data-original-url="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">Federal Trade Commission (FTC)</a> to use all its authority to ensure that these powerful companies comply with their new policies, to hold them accountable if they fail to do so, and to prioritize the protection of children’s and teen’s privacy," the letter said. The senators suggested using Section Five of the FTC Act, which forbids deceptive practices, to enforce the commitments. </p><p>"These policy changes are no substitute for congressional action on children’s privacy, but they are important steps towards making the internet safer for young users, the letter added. </p><p>The letter follows a ground-breaking <a href="https://www.itpro.com/business-operations/business-management/361100/facebook-algorithm-put-profit-before-public-safety" data-original-url="https://www.itpro.com/business-operations/business-management/361100/facebook-algorithm-put-profit-before-public-safety">testimony by whistleblower Frances Haugen</a> before Congress this week. Haugen accused Instagram owner Facebook of disregarding teens' mental health and putting profit before people. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are you over-sharing online? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/social-media/360575/are-you-over-sharing-online</link>
                                                                            <description>
                            <![CDATA[ You’re almost certainly leaking more information online than you realise. We explore the steps you can take to downsize your online footprint ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rjt8cpXRPC5knV1Y6gS4Uw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jBCmkmU2juhscBjHpeAMsZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Sep 2021 08:00:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nik Rawlinson ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jBCmkmU2juhscBjHpeAMsZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Illustration - digital footprints]]></media:description>                                                            <media:text><![CDATA[Illustration - digital footprints]]></media:text>
                                <media:title type="plain"><![CDATA[Illustration - digital footprints]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jBCmkmU2juhscBjHpeAMsZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You might think you're being careful about what post on Facebook, Twitter and LinkedIn – but over time your accumulated posts will inevitably build up a picture of who you are. That could include where you reside, what you do for a living, your childhood, your family composition, your birthday and more. All of which would be valuable information to a potential identity thief.</p><p>As an example, let’s say you post a picture of your child blowing out candles on a cake. Unless the metadata has been stripped first, you’ve probably also shared the date on which the picture was taken. If your child is young, it’s unlikely they waited until the weekend to celebrate, so there’s a good chance the date it was taken was their birthday itself, even if you didn’t post it until a few days later. If there are three candles on the cake, or a card with a number on it, that’s the other half of the equation: anyone seeing your post now knows exactly when your child was born. If you’ve used their birthday – or part of it – in a password or security question, that’s a chink in your digital armour right there, ripe for exploitation.</p><p>That’s not the worst of it. If you took the picture on your phone, the <a href="https://www.itpro.com/security/33980/more-than-1000-android-apps-deceptively-harvest-personal-data" data-original-url="https://www.itpro.com/security/33980/more-than-1000-android-apps-deceptively-harvest-personal-data">exact GPS coordinates of the place where it was taken</a> could be embedded into the image file. That’s probably your home address, so anyone who sees the picture now knows exactly where to find that nice painting hanging in the background. If you’re a married woman and your friends list includes family members, it won’t be hard to deduce your maiden name – another common security question.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/29259/what-is-your-digital-footprint" data-original-url="/strategy/29259/what-is-your-digital-footprint">What is your digital footprint?</a></p></div></div><p>The list goes on. Photos of your first car, connections to school friends… every seemingly innocuous detail makes you more vulnerable to exploits and scams. And now consider the data you’ve scattered outside of social networks – CVs uploaded to job sites, links stored in a cloud-based bookmarking tool, ads you’ve clicked on, the emails you’ve received in a webmail inbox and the places you’ve been with your phone in your pocket.</p><p>Whether this data has escaped through over-sharing or been collected without your noticing, you can never get rid of it all. But you can shrink it down – and the obvious place to start is social media.</p><h3 class="article-body__section" id="section-shrink-your-facebook-footprint"><span>Shrink your Facebook footprint</span></h3><p>Facebook is currently involved in a <a href="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war" data-original-url="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war">dispute with Apple over what information it's able to collect about users</a> – but if you've ever used the platform then there's no doubt that it already knows plenty about you.</p><p>To find out what information Facebook is holding, log in through a browser and click the down arrow in the top-right corner. Click “Settings & privacy”, followed by Settings. Select “Your Facebook information” in the sidebar, then “Download your information”. Leave the default settings as they are and click “Create file”. It will take a short while for Facebook to collect the relevant information. When it’s finished, you’ll be able to download a ZIP file, whose contents you can peruse to see what’s stored against your name on Facebook’s servers. Armed with this data, you can decide what stays – and what should be removed.</p><p>Deleting content from Facebook is surprisingly easy, especially if you use the Manage Activity tool; this lets you remove batches of information at a time, rather than just individual items. The catch is, it’s currently only available in the Facebook mobile app. To access it, tap the menu button on the toolbar, then hit “Settings & privacy”, followed by Settings. Now select “Activity log”; to remove individual entries, tap the three dots on the right of the screen beside each one. To delete several entries at once, tap “Manage activity” and pick whether you want to manage posts, activity you’re tagged in or interactions such as likes, reactions and comments.</p><p>Whichever you choose, Facebook will pull up a list of the ten most recent data points, and scrolling down the screen will extend the list. Tap the box beside each item you want to remove, or tap the box at the top of the list to select everything that’s shown on the page (you might want to scroll down to extend the list a few times). Finally, tap the remove or recycle button – depending on what you’re deleting – at the bottom of the screen.</p><p>You can also delete content through a browser – it’s just more time consuming. Log in and click the down arrow at the top of the screen, followed by “Settings and privacy” and Settings. Click “Your Facebook information”, followed by “Activity log”. As you hover over each item in the sidebar, three dots will appear on top of it, allowing you to unlike things you have liked or move content you’ve posted to the archive or recycle bin.</p><p>While these functions let you manage your publicly accessible content, you should be aware that Facebook also collects data to make internal decisions about what to show you. To review this, select “Privacy shortcuts” from the “Settings & privacy” menu and then “Review your ad preferences” (in the “Ad preferences” box) or “Manage your information” (in the “Your Facebook information” box).</p><p>If you’re reviewing your ad preferences, click “Ad settings” in the sidebar and work your way through each of the sections in the “Manage data used to show you ads” section. Some of the settings you’ll find here let you prevent advertisers from reaching you on third-party websites based on your Facebook data, while others let you see the content categories Facebook thinks you’re interested in.</p><p>This latter information can be quite eye-opening. It’s not always spot-on: I discovered that I was being targeted for content related to Assassin’s Creed, yet I haven’t played a computer game in more than 20 years (not even for <a href="https://www.itpro.com/business-strategy/careers-training/358460/game-on-how-playing-video-games-could-level-up-your" data-original-url="https://www.itpro.com/business-strategy/careers-training/358460/game-on-how-playing-video-games-could-level-up-your">career development</a>). For the most part, though, the list was scarily accurate – it even knew the brand of watch I wear. There are links on the page that let you remove any categories that don’t apply, or which you’d simply prefer Facebook not to use for targeting.</p><p>If you want to get off Facebook altogether, the “Manage your information” section provides links to delete your data and close your account. If you’re hesitant about leaving the platform because you don’t want to lose touch with friends or family members who are using Facebook Messenger, there’s good news; it is possible to <a href="https://www.facebook.com/help/messenger-app/1526848634305688">continue using Messenger for instant messages even after deactivating your main Facebook account</a>.</p><p>If you decide to take the plunge, point your browser at <a href="https://facebook.com/deactivate">Facebook's account deactivation page</a>, enter your password, complete the form and click Deactivate.</p><h3 class="article-body__section" id="section-instagram"><span>Instagram</span></h3><p>You might imagine that Facebook-owned Instagram would offer similar levels of control over your content. Sadly, that’s not the case: you can discover a lot about the metrics that are used to determine what you’re shown in the app, but you can’t always correct or delete any incorrect inferences.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28013/what-is-private-browsing-and-how-can-it-keep-you-safe-online" data-original-url="/security/28013/what-is-private-browsing-and-how-can-it-keep-you-safe-online">What is private browsing and how can it keep you safe online?</a></p></div></div><p>To see what Instagram thinks of you, open the app and tap your icon at the end of the toolbar, followed by the three lines at the top of the next page. Tap Settings followed by “Ads | Ad topics” and untick subjects that don’t interest you. If you tap into Security, rather than Ads, and hit “Access data”, you can see your apparent interests in blocks by selecting “View all” under “Ad interests” – but you can’t delete items recorded here.</p><p>What you can do is flag unwanted adverts individually. Tap the three dots above them in your feed then tap “Hide ad”. You can specify whether the ad is irrelevant, shown too often or inappropriate.</p><h3 class="article-body__section" id="section-shrink-your-twitter-footprint"><span>Shrink your Twitter footprint</span></h3><p>Last year Twitter was hit by <a href="https://www.itpro.com/marketing-comms/social-media/357308/twitter-hires-new-cyber-security-chief" data-original-url="https://www.itpro.com/marketing-comms/social-media/357308/twitter-hires-new-cyber-security-chief">an embarrassing security breach that gave hackers access to numerous high-profile accounts</a>, exposing all sorts of personal information associated with those accounts.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JwSoyQgoyuGSpPdZKLFeqQ" name="JwSoyQgoyuGSpPdZKLFeqQ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" mos="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 state of email security report: Ransomware on the rise</strong></p><p class="fancy-box__body-text">Securing the enterprise in the COVID world</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise" data-original-url="/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise">FREE DOWNLOAD</a></p></div></div><p>What information is Twitter keeping about you? To find out, log in through a browser and click More in the sidebar, followed by “Settings and privacy”. As with Facebook, the information is provided as a bulk download: with “Your account” selected in the second sidebar, click “Download an archive of your data” in the third, and enter your password. Click the “Request archive” button and Twitter will compile a Zip file. It will send you an email when it’s ready for collection.</p><p>Once you know what kind of information is in the database, you can make more informed decisions going forward. There are also some specific settings that it’s worth looking at (all of the menu options mentioned below are found under the “Privacy and safety” section of Twitter’s settings).</p><p>If you want to restrict your tweets so they can be read only by people who actively follow you, click “Audience and tagging” and click the box beside “Protect your tweets”. While you’re in this section, you can optionally disable photo tagging too, which stops people identifying you in photos they post to their own profiles. Once you’ve protected your tweets, you’ll be asked to authorise any future follower requests, rather than allowing anyone who wishes to follow you do so.</p><p>A specific privacy issue that we mentioned earlier is the possibility of giving away your whereabouts. To prevent Twitter from reporting your location, click “Your tweets”, then “Add location information to your tweets”. Untick the box and, optionally, click the link to wipe location data from tweets you’ve posted in the past.</p><p>Again, like Facebook, Twitter builds up an internal profile of you that’s used to select ads and suggest content. You can review this and remove specific interests from your record as you wish. To do so, click “Content you see | Interests” and untick the box for each subject you’d rather not hear about.</p><p>As for items you’ve actively shared, it’s easy to delete individual tweets by clicking the three dots icon on each one and selecting “Delete tweet”. Twitter doesn’t provide any way to remove whole batches of posts, but a number of third-party services have sprung up to plug the gap – check out <a href="https://tweetdeleter.com">tweetdeleter.com</a>, <a href="https://twitwipe.com">twitwipe.com</a>, or <a href="https://www.tweeteraser.com">tweeteraser.com</a>. If that’s not good enough, you may choose to go the whole hog and <a href="https://twitter.com/settings/deactivate">delete your Twitter account</a>.</p><h3 class="article-body__section" id="section-shrink-your-google-footprint"><span>Shrink your Google footprint</span></h3><p>Google offers an extraordinary range of products and services, many of which collect a whole lot of personal information – either for publication or for internal usage. Fortunately, the company also provides a single centralised dashboard from which you can keep track of everything that’s being stored about you across Google’s numerous sites and apps. To access it, start by navigating to myaccount.google.com and logging in.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31330/how-to-reclaim-your-data-from-google-facebook" data-original-url="/general-data-protection-regulation-gdpr/31330/how-to-reclaim-your-data-from-google-facebook">How to reclaim your data from Google, Facebook, Microsoft, Apple under GDPR</a></p></div></div><p>Once you’re authenticated, a good place to begin is <a href="https://myactivity.google.com/activitycontrols?pli=1">Google’s Activity controls page</a>. Here you’ll find options to turn off whole categories of data collection, including location data, data gathered by Google-owned websites and Chrome, and data collected by devices such as your phone and tablet.</p><p>You can also limit what information is collected and used by YouTube: this will probably cause you to receive less relevant video recommendations, but you may not consider that a great price to pay for enhanced privacy.</p><p>At the bottom of the page there’s a link to the <a href="https://adssettings.google.com/authenticated">advertising settings page</a>. If you want to see random ads, rather than ones based on your behaviour, just click off the switch labelled “Ad personalisation”. This only affects advertising on Google sites, but if you visit the <a href="https://www.youronlinechoices.com/uk/your-ad-choices">Your Online Choices website</a> you can similarly turn off advert personalisation for dozens of different companies.</p><p>If you want to remove your own content from your Google account – such as contacts, calendars, Drive data, ebooks, Play store purchases and so forth – it’s a good idea to download an archive of your content in advance, just as with Facebook and Twitter, which you can do from the <a href="https://myaccount.google.com/dashboard?pli=1">Account Dashboard</a>. When you visit this page you’ll see a long list of all the Google services that your identity is connected to; to download data for any of these individual services, click the down arrow to expand it, then click the three dots at the bottom of its card, followed by “Download data”. Clicking the main “Download your data” link at the top of the page will download a complete archive of content from all the various services.</p><p>Bear in mind that this page only shows information for the currently logged-in Google account. If you have multiple accounts – one for work and a personal account, for instance – you’ll need to repeat this process for each one. You can keep track of which identity you’re using by checking the account image at the top right of the dashboard pages.</p><h3 class="article-body__section" id="section-shrink-your-microsoft-footprint"><span>Shrink your Microsoft footprint</span></h3><p>Like Google, Microsoft has helpfully centralised a lot of its privacy settings in <a href="https://account.microsoft.com/account/privacy?ru=https%3A%2F%2Faccount.microsoft.com%2Fprivacy&destrt=privacy-dashboard">a unified dashboard</a>. You can download a copy of your activity by clicking “Download your data”, followed by “Create new archive”. The file that’s delivered will include things like your search and location history and other personal information, but it won’t include data generated in applications such as Office Online or the Outlook calendar. To download those items, you’ll need to go into each product and manually make a copy of whatever you want to keep.</p><p>One information repository that’s of particular interest is what’s known as Cortana’s Notebook. <a href="https://www.itpro.com/technology/voice-assistant/359096/microsoft-retires-cortana-mobile-app" data-original-url="https://www.itpro.com/technology/voice-assistant/359096/microsoft-retires-cortana-mobile-app">Microsoft is scaling back Cortana as a general-purpose voice assistant</a>, but since its introduction </p><p>which is where Cortana keeps track of things it’s learned about you, to help it provide relevant answers to any questions. You’ll find a link to this at the top of the Privacy page, with the data broken into sections covering topics such as your commute, weather preferences, news stories that interest you, stocks you’re tracking and so on. The more information Cortana has squirrelled away, the more effective it will be – but, if you’d rather wipe what it knows, click “Clear Cortana data” in the right-hand sidebar.</p><p>Like Facebook and Google, Microsoft also provides an easy way to opt out of so-called behavioural advertising, which by default serves up content based on what it knows about you. To do so, visit <a href="http://account.microsoft.com/privacy/ad-settings">Microsoft’s Ad settings page</a> and turn off all of the switches for personalisation.</p><p>Don’t forget to also check your privacy settings in Windows itself. Press Windows+I to open the Settings app and click Privacy, then use the switches to manage what the operating system can and can’t do. The standard settings allow the OS to show ads based on your interests and websites to access your language lists to provide locally relevant content, but these can be turned off at the flick of a switch. You can use the App permissions link at the left to block third-party apps from accessing information such as your location and account settings too.</p><h3 class="article-body__section" id="section-prevention-is-better-than-cure"><span>Prevention is better than cure</span></h3><p>The companies we’ve focused on above have huge databases of personal information, but don’t think your digital footprint stops there. It also extends to, for instance, <a href="https://www.itpro.com/policy-legislation/data-protection/357008/how-well-does-your-supermarket-know-you-mr-blair" data-original-url="https://www.itpro.com/policy-legislation/data-protection/357008/how-well-does-your-supermarket-know-you-mr-blair">the online supermarket that brings your groceries</a>, the public library you use to download ebooks, your favourite digital magazine stores and anywhere you’ve ever saved your credit card details.</p><p>To audit and curate exactly what all of these services know about you can be a time-consuming business. However, it’s made a lot easier by services such as <a href="https://www.rightly.co.uk">Rightly</a>, which provides direct links to all manner of companies, with options to see what information they hold about you, to opt out of marketing or to request deletion.</p><p>It’s also important to realise that even if you take direct action, close your accounts and ask companies to scrub you from their databases, your information may still be out there somewhere. The things you publish online can find their way into an incalculable number of third-party services, without your ever knowing about it.</p><p>The only truly safe course of action, therefore, is never to publish anything that you might regret sharing in the future. If that’s not realistic, the next best option is to lock down any services you actively use from the very start, to prevent them from gathering personally identifiable information in the first place.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pearson fined $1 million for downplaying severity of 2018 breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/360605/pearson-fined-1-million-for-downplaying-the-severity-of-2018-breach</link>
                                                                            <description>
                            <![CDATA[ The SEC found the London-based firm made “misleading statements and omissions” about the intrusion ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">stDj1kqDXVkDukAcpECLT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UahVFYX8a3cgJavFQrXDrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Aug 2021 13:51:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UahVFYX8a3cgJavFQrXDrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pearson sign and logo on a building]]></media:description>                                                            <media:text><![CDATA[Pearson sign and logo on a building]]></media:text>
                                <media:title type="plain"><![CDATA[Pearson sign and logo on a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UahVFYX8a3cgJavFQrXDrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Securities and Exchange Commission (SEC) has ordered UK-based Pearson Education to pay $1 million to settle charges it misled investors about a 2018 data breach that resulted in millions of stolen student records.</p><p><a href="https://www.sec.gov/news/press-release/2021-154">The SEC announced the settlement</a> after it found Pearson made “misleading statements and omissions” about the intrusion that involved the theft of student data and administrator log-in credentials of 13,000 school, district, and university customer accounts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360581/t-mobile-confirms-data-breach" data-original-url="/security/data-breaches/360581/t-mobile-confirms-data-breach">T-Mobile confirms it was hit by a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors" data-original-url="/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors">Data breach exposes millions of seniors' data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021" data-original-url="/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021">Data breach costs surge to record high in 2021</a></p></div></div><p>In its semi-annual report filed in July 2019, the SEC said Pearson referred to a <a href="https://www.itpro.com/tag/data-privacy" data-original-url="https://www.itpro.com/tags/data-privacy">data privacy</a> incident as a hypothetical risk, despite the fact the breach had already occurred. In a <a href="https://www.pearson.com/news-and-research/announcements/2019/07/pearson-customer-notification.html">statement published that same month</a>, Pearson said the breach may include dates of birth and email addresses, but it already knew such records were stolen.</p><p>The SEC also said Pearson had "strict protections" in place, “when, in fact, it failed to patch the critical vulnerability for six months after it was notified.” </p><p>“As the order finds, Pearson opted not to disclose this breach to investors until it was contacted by the media, and even then, Pearson understated the nature and scope of the incident, and overstated the company’s data protections,” said Kristina Littman, chief of the SEC Enforcement Division’s Cyber Unit. “As public companies face the growing threat of cyber intrusions, they must provide accurate information to investors about material cyber incidents.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>Dominic Trott, UK product manager at Orange Cyberdefense, told <em>IT Pro</em> the $1 million settlement agreed between Pearson and the SEC comes as the education sector faces increasing hostility from malicious actors. </p><p>“As the threat landscape evolves and while education remains firmly in the crosshairs, it is more important than ever to maintain an open dialogue. Only through collaboration and transparency can cyber researchers and technologists begin to turn the tide against cybercriminals intent on wreaking havoc in the sector,” Trott said. </p><p>“As Pearson has learned, failure to properly disclose a breach can also be far more damaging to an organization’s reputation and can incur severe legal penalties, particularly when customer data is involved.</p><p>"Breach disclosure processes should form part of an organization’s blended approach to cyber <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a>, layering a combination of people, process and enabling technologies to reduce the risk, minimize the impact of a breach should one occur, and demonstrate diligence and best practice to both customers and governing bodies.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ESign Genie adds fraud detection to its digital signature software ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/360594/esign-genie-adds-fraud-detection-to-its-digital-signature-software</link>
                                                                            <description>
                            <![CDATA[ New identity verification solution mandates Social Security number for signing digital forms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2YmHDbYMQfazvkA84btZ1E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZhCZqVKFo3W9gQebcFVZzc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Aug 2021 16:32:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZhCZqVKFo3W9gQebcFVZzc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[stack of Social Security cards]]></media:description>                                                            <media:text><![CDATA[stack of Social Security cards]]></media:text>
                                <media:title type="plain"><![CDATA[stack of Social Security cards]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZhCZqVKFo3W9gQebcFVZzc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ESign Genie has announced that its digital signature platform now supports knowledge-based authentication (KBA).</p><p>Developed in collaboration with LexisNexis Risk Solutions, the new solution improves the <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> of sensitive, private, or protected documents by mandating a Social Security number.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/359710/docusign-acquires-smart-agreements-startup-clause" data-original-url="/business-strategy/mergers-and-acquisitions/359710/docusign-acquires-smart-agreements-startup-clause">DocuSign acquires ‘smart agreements’ startup Clause</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/document-management-systems-dms/360373/box-launches-free-e-signature-feature-for-its-cloud" data-original-url="/software/document-management-systems-dms/360373/box-launches-free-e-signature-feature-for-its-cloud">Box launches free e-signature tool for all customers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/358247/moving-beyond-e-signature" data-original-url="/business-strategy/digital-transformation/358247/moving-beyond-e-signature">Moving beyond E-signature</a></p></div></div><p>“Dynamic security is at the forefront of eSign Genie's electronic signature technology. Providing essential security options, such as KBA, was a feature that the <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> company felt was an important step in its continued development and improvement of safe, reliable, and secure eSigning software. eSign Genie has developed this fraud prevention solution using industry-leading LexisNexis Risk Solutions that authenticate signers using an automated, query-based identity verification system,” explained eSign Genie.</p><p>Notably, eSign Genie helps businesses create reusable document templates they can fill out and have different recipients sign as needed. Forms can be embedded on websites, applications, or sent via email. Enterprises also may enable email authentication for signing online forms.</p><p>KBA by eSign Genie adds an extra layer of security by authenticating document recipients’ identities before issuing viewing or editing rights. The feature is exclusive to eSign Genie’s Enterprise Plan subscribers.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6cKW9vLBKCuXhDgHjvtV2g" name="6cKW9vLBKCuXhDgHjvtV2g.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/6cKW9vLBKCuXhDgHjvtV2g.png" mos="https://cdn.mos.cms.futurecdn.net/6cKW9vLBKCuXhDgHjvtV2g.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The future of CIAM</strong></p><p class="fancy-box__body-text">Four trends shaping identity and access management</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/358831/the-future-of-ciam" data-original-url="/security/identity-and-access-management-iam/358831/the-future-of-ciam">FREE DOWNLOAD</a></p></div></div><p>"We are excited to release our new KBA security feature as it further enables our Enterprise Plan users to stay compliant by utilizing all forms of identity checks while also maintaining signature certificate authentications and obtaining eSignatures on important digital documents," said Mahender Bist, founder and <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> of eSign Genie. </p><p>Bist added, "We understand that security and <a href="https://www.itpro.com/policy-legislation/compliance/354495/testing-for-compliance-just-became-easier" data-original-url="https://www.itpro.com/policy-legislation/compliance/354495/testing-for-compliance-just-became-easier">compliance</a> are of utmost importance to our clients. We strive to provide security and fraud prevention improvements to meet the KYC compliance, such as the new KBA feature, so that we may continue to supply the highest level of safe and secure electronic signature technology available."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Senators quiz Amazon on palm scanning tech  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/biometrics/360580/senators-quiz-amazon-on-palm-scanning-tech</link>
                                                                            <description>
                            <![CDATA[ Lawmakers fret about the privacy implications of Amazon One ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3U8RMgFzVWW7vm5eVnL8Wx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YhqD8gMopde2hGcuVhaMfD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Aug 2021 16:10:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YhqD8gMopde2hGcuVhaMfD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon sign on a brick building]]></media:description>                                                            <media:text><![CDATA[Amazon sign on a brick building]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon sign on a brick building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YhqD8gMopde2hGcuVhaMfD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three senators have written to Amazon with questions about the company's Amazon One palm scanning technology.</p><p>The bipartisan group expressed concerns about the <a href="https://www.itpro.com/632776/biometric-authentication-the-key-to-keeping-businesses-and-users-happy" data-original-url="https://www.itpro.com/632776/biometric-authentication-the-key-to-keeping-businesses-and-users-happy">biometric</a> system's effect on privacy and its potential to bolster Amazon's market position. The <a href="https://www.klobuchar.senate.gov/public/_cache/files/5/e/5ebfd9e0-b230-4a86-8db4-09cacd0c25a6/0DA3E8409AD9EB20E056BC005E5858B1.8.12.21-letter-to-amazon.pdf">letter</a>, from senators Amy Klobuchar (D-Minn.), Bill Cassidy (R-La.) and Jon Ossoff (D-Ga.) to Amazon CEO Andy Jassy, queries the company's handling of biometric data gathered using the service. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine">Amazon faces £637 million fine over GDPR violations</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/360441/civil-rights-groups-ask-the-ftc-to-stop-amazon-surveillance" data-original-url="/business/policy-legislation/360441/civil-rights-groups-ask-the-ftc-to-stop-amazon-surveillance">Civil rights groups ask the FTC to stop Amazon surveillance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/360427/it-pro-news-in-review-record-profits-in-tech-hackers-turn-to-new" data-original-url="/business/business-strategy/360427/it-pro-news-in-review-record-profits-in-tech-hackers-turn-to-new">IT Pro News in Review: Record profits in tech, hackers turn to new languages for malware, Amazon's Bitcoin plans</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/components/360362/intel-four-year-roadmap-starts-qualcomm-amazon-deals" data-original-url="/hardware/components/360362/intel-four-year-roadmap-starts-qualcomm-amazon-deals">Intel's four-year roadmap kicks off with Amazon, Qualcomm chip deals</a></p></div></div><p>"Amazon’s expansion of biometric data collection through Amazon One raises serious questions about Amazon’s plans for this data and its respect for user privacy, including about how Amazon may use the data for advertising and tracking purposes," the letter said. </p><p>Unveiled in September 2020, Amazon One is a contactless payment system that uses palm scanning for applications, including making payments, granting access to locations, presenting loyalty cards, or clocking into work. </p><p>The company began rolling it out at its automated Amazon Go stores, which already used technologies like computer vision to replace traditional checkout operators. It has since arrived at some <a href="https://www.itpro.com/security/29583/whole-foods-is-hacked-exposing-credit-card-details" data-original-url="https://www.itpro.com/security/29583/whole-foods-is-hacked-exposing-credit-card-details">Whole Foods</a> locations, which Amazon acquired in 2017. </p><p>Amazon said the service would be an optional entry method at its stores, which would still allow customers to enter using the Amazon app. At launch, the e-commerce giant also vowed to offer customers the devices, including retailers, stadiums, and office buildings. </p><p>"Our concerns about user privacy are heightened by evidence that Amazon shared voice data with third-party contractors and allegations that Amazon has violated biometric privacy laws," said the letter, referring to reports the company violated facial recognition privacy law in Illinois by using residents' faces to train its algorithms.</p><p>It also cited a class-action lawsuit filed this month against Amazon for allegedly violating the Illinois Biometric Information Privacy Act (BIPA) with its Alexa system. </p><p>"We are also concerned that Amazon may use data from Amazon One, including data from third-party customers that may purchase and use Amazon One devices, to further cement its competitive power and suppress competition across various markets," the senators said. </p><p>Amazon recently offered consumers a $10 credit to enroll themselves on Amazon One. To do so, customers must present their credit cards and scan their palms with the Amazon One device. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>Rather than storing scans locally, the devices send them back to Amazon's cloud. This was an area of concern for the senators, who compared it with biometric scanning technology from Apple and Samsung, which store information locally on the device. </p><p>The letter asked Amazon several questions, including when the company plans to expand its use of Amazon One; how many third-party customers has it sold its technology to; how many users have signed up for the service; and whether the company pairs the scans with data from biometric systems. </p><p>The senators also asked the company to describe how it uses data from the service, with a special focus on whether it uses the data to <a href="https://www.itpro.com/data-insights/data-processing/359895/lack-of-action-by-gdpr-enforcers-fuels-real-time-bidding" data-original-url="https://www.itpro.com/data-insights/data-processing/359895/lack-of-action-by-gdpr-enforcers-fuels-real-time-bidding">personalize advertisements</a> or product recommendations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DataCamp and Degreed partner to offer free data literacy courses  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-insights/big-data/360536/datacamp-and-degreed-partner-to-offer-free-data-literacy-courses</link>
                                                                            <description>
                            <![CDATA[ DataCamp’s custom training courses facilitate enterprises’ digital transformation goals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f8QwYDek2FjQjE4hhNj9vb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MeYZmiFsXvwHbGYEMMED6E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Aug 2021 14:49:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MeYZmiFsXvwHbGYEMMED6E-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data-related terms in the shape of a cloud]]></media:description>                                                            <media:text><![CDATA[Data-related terms in the shape of a cloud]]></media:text>
                                <media:title type="plain"><![CDATA[Data-related terms in the shape of a cloud]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MeYZmiFsXvwHbGYEMMED6E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>DataCamp has begun to offer free data literacy courses to all Degreed users. </p><p>DataCamp and Degreed develop comprehensive learning programs tailored to enterprises’ needs. Extending their partnership, DataCamp is offering free access to three interactive online courses: Data Science for Everyone, <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">Machine Learning</a> for Everyone, and Data Engineering for Everyone. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/business-intelligence-bi/359541/data-literacy-problem-financial-services" data-original-url="/data-insights/business-intelligence-bi/359541/data-literacy-problem-financial-services">Addressing the data literacy problem in the financial services sector</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors" data-original-url="/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors">Data breach exposes millions of seniors' data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/acquisition/360477/deloitte-canada-acquires-applied-ai-firm-dataperformers" data-original-url="/business-strategy/acquisition/360477/deloitte-canada-acquires-applied-ai-firm-dataperformers">Deloitte Canada acquires Applied AI firm Dataperformers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/360439/systools-makes-cloud-email-data-migration-frictionless" data-original-url="/cloud/cloud-computing/360439/systools-makes-cloud-email-data-migration-frictionless">SysTools makes cloud email data migration frictionless</a></p></div></div><p>The courses require no prior <a href="https://www.itpro.com/business-strategy/careers-training/357247/should-you-learn-to-code" data-original-url="https://www.itpro.com/business-strategy/careers-training/357247/should-you-learn-to-code">coding</a> experience, making them an ideal choice for organizations undergoing or planning an enterprise-wide <a href="https://www.itpro.com/strategy/28047/what-is-digital-transformation" data-original-url="https://www.itpro.com/strategy/28047/what-is-digital-transformation">digital transformation</a>. Essentially, the courses are suitable for all skill levels and roles. </p><p>Degreed clients with Edit Settings permission can access DataCamp’s free courses through the Provider's tab or by contacting their Client Experience partner. There’s also the option to upgrade for full DataCamp access.</p><p>The “Data Science for Everyone” course includes 15 videos and 48 exercises on data science, data collection and storage, time series analysis, and A/B testing. </p><p>“Machine Learning for Everyone” lets users discover intelligent technologies behind self-driving cars and always-on customer experience tools. </p><p>Lastly, “Data Engineering for Everyone” explains data engineers’ core responsibilities via Spotflix, a fictional music-streaming firm. Each course takes two hours to complete.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UAvesFwfavgcUBtoUKWL7C" name="UAvesFwfavgcUBtoUKWL7C.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UAvesFwfavgcUBtoUKWL7C.png" mos="https://cdn.mos.cms.futurecdn.net/UAvesFwfavgcUBtoUKWL7C.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The new leadership mindset for data and analytics</strong></p><p class="fancy-box__body-text">How to grow your data and analytics talent, empowering a data culture from the inside out, and more</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/360416/the-new-leadership-mindset-for-data-and-analytics" data-original-url="/data-insights/big-data/360416/the-new-leadership-mindset-for-data-and-analytics">FREE DOWNLOAD</a></p></div></div><p>DataCamp <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> and co-founder Jonathan Cornelissen said, "There is incredible power in data—but only if you know what to do with it. All departments and roles must have the skills to analyze that data to extract meaningful insights. Through our renewed partnership with Degreed, we are proud to provide their clients with free access to the powerful data skills they need to make better decisions, better serve their customers, and drive business growth."</p><p>"Data is core to every organization and that means everyone must have a baseline understanding of data. We're excited to offer all Degreed clients the DataCamp training, to empower their people ready for the data-driven future and ensure everyone knows how to use data effectively in their work," commented Rob Wellington, director of experience partnerships at Degreed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data breach exposes millions of seniors' data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors</link>
                                                                            <description>
                            <![CDATA[ Misconfigured S3 bucket had exposed personal information on three million people ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cgSPviDz9MyPZBaPKeqjEw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Aug 2021 17:43:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach]]></media:description>                                                            <media:text><![CDATA[Data breach]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have found a major breach that exposed the details of over three million US seniors.</p><p><a href="https://www.wizcase.com/blog/senioradvisor-breach-report">According to WizCase</a>, the data breach affected SeniorAdvisor, “one of the largest consumer ratings and reviews websites for senior care and services across the US and Canada.” Among the exposed details were users’ names, surnames, phone numbers, and more.</p><p>Researchers at WizCase discovered a misconfigured Amazon S3 bucket belonging to the website containing over 1 million files and 182GB of data. Contact dates from the files suggest they are from 2002 to 2013, though the files had a 2017 timestamp.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021" data-original-url="/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021">Data breach costs surge to record high in 2021</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360338/gun-owners-urged-to-be-vigilant-following-data-breach" data-original-url="/security/data-breaches/360338/gun-owners-urged-to-be-vigilant-following-data-breach">UK gun owners urged to be ‘vigilant’ after Guntrader data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360126/british-airways-settles-2018-data-breach-case-on-confidential-terms" data-original-url="/security/data-breaches/360126/british-airways-settles-2018-data-breach-case-on-confidential-terms">British Airways settles with 2018 data breach victims</a></p></div></div><p>“The majority of data exposed was in the form of leads, a list of potential customers whose details were collected by SeniorAdvisor presumably via their email or phone call campaigns,” said researchers.</p><p>Researchers also unearthed 2,000 “scrubbed” reviews. These are reviews where the user’s sensitive information has been wiped or redacted.</p><p>“However, this scrubbing process is useless if you have the corresponding information. The scrubbed reviews had a lead id which could be used to trace the review back to who originally wrote it,” researchers said. As both lead data and these scrubbed reviews were in the same database, supposedly anonymous reviewers could have their identity revealed with a simple search operation.</p><p>WizCase researchers said since the breach contained data from a section of the public more vulnerable to scams, the risks were higher. In a <a href="https://www.ftc.gov/reports/protecting-older-consumers-2018-2019-report-federal-trade-commission">2018-2019 report</a>, the <a href="https://www.itpro.com/tag/ftc" data-original-url="https://www.itpro.com/tags/ftc">Federal Trade Commission (FTC)</a> noted that people who filed a fraud complaint between 60 and 69 years old lost $600 per scam on average. The amount rose in older groups, culminating in $1700 on average per scam for people between 80 and 89.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="46MS25Ne58gQYeTNcHoXhW" name="46MS25Ne58gQYeTNcHoXhW.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" mos="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>From zero to hero: The path to CIAM maturity</strong></p><p class="fancy-box__body-text">Your guide to the CIAM journey</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity" data-original-url="/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity">FREE DOWNLOAD</a></p></div></div><p>“In particular, the report found senior citizens were more likely to fall for digital scams such as tech support scams, prize/sweepstakes scams, online shopping scams, and especially phone scams,” said researchers. “As shown, senior citizens are at greater risk for online fraud than the rest of the population, and therefore should be even more careful in their online behavior.”</p><p>Researchers urged people using such services to input the bare minimum of information when making a purchase or setting up an online account.</p><p>“The less information hackers have to work with, the less vulnerable you are,” warned researchers. Researchers have since contacted the company, and the bucket has since been secured.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Senator reintroduces federal data protection bill ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359924/senator-reintroduces-federal-data-protection-bill</link>
                                                                            <description>
                            <![CDATA[ Revised law includes oversight for big tech mergers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gNCrQXj6pi5M9T22piSPc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F7YrremUm66fSNUhUCskz9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Jun 2021 18:08:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F7YrremUm66fSNUhUCskz9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Senator Kirsten Gillibrand giving a speech]]></media:description>                                                            <media:text><![CDATA[Senator Kirsten Gillibrand giving a speech]]></media:text>
                                <media:title type="plain"><![CDATA[Senator Kirsten Gillibrand giving a speech]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F7YrremUm66fSNUhUCskz9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Senator Kirsten Gillibrand is back with a revised bill that would create a federal data protection agency in the US to oversee consumer privacy. This time, it includes powers to review big tech company mergers.</p><p>The Democratic senator from New York introduced the Data Protection Act of 2021 today, a revised and expanded version of an original bill introduced in February 2020. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/358808/dell-and-faction-debut-multi-cloud-backup-and-data-protection-solutions" data-original-url="/cloud/cloud-storage/358808/dell-and-faction-debut-multi-cloud-backup-and-data-protection-solutions">Dell and Faction debut multi-cloud backup and data protection solutions</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/358769/virginia-passes-consumer-data-protection-law" data-original-url="/policy-legislation/data-protection/358769/virginia-passes-consumer-data-protection-law">Virginia passes consumer data protection law</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/358763/google-rejects-charge-that-workspace-is-embedded-with" data-original-url="/policy-legislation/data-protection/358763/google-rejects-charge-that-workspace-is-embedded-with">Google rebuffs claims that Workspace is embedded with data protection risks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/356815/the-state-of-data-protection-and-cloud" data-original-url="/policy-legislation/data-protection/356815/the-state-of-data-protection-and-cloud">The state of data protection and cloud</a></p></div></div><p>At its core lies something the US has lacked to date: a federal regulator dedicated to overseeing data privacy. The bill proposes developing an agency that would make its own data privacy rules or enforce those made by Congress across the government and private companies. It would be an executive agency with a director appointed by the president for a five-year term.</p><p>Alongside enforcing data protection rules, the agency would also develop model privacy frameworks for businesses, watch for discrimination in the use of automated algorithms, and advise the government on emerging threats like deep fakes.</p><p>The proposed law goes beyond its predecessor with several additions. The most notable is the supervision of mergers that involve data aggregators or any merger that involves transferring over 50,000 peoples' data.</p><p>The new bill would also include a civil rights office within the data protection agency, which would protect people from discrimination and clearly define terms such as privacy harm and high-risk data practices.</p><p>Under the new law, the data protection agency would have more enforcement powers, including the power to issue penalties and fines for violators.</p><p>Gillibrand targeted big tech companies in her remarks. They represent a direct threat to privacy and civil rights, she said, describing them as bad actors at the center of a "data privacy crisis."</p><p>Today, there are two main routes to hold companies accountable for privacy infractions in the US. The first is via states with strong consumer protection laws, such as <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California</a>. The second is via the <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc" data-original-url="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">Federal Trade Commission</a>, which Gillibrand called out for failing to act in dozens of cases and enforce its own orders.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to reduce your online footprint ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/359788/how-to-reduce-your-online-footprint</link>
                                                                            <description>
                            <![CDATA[ Tips and tricks to maintain online anonymity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">64ffuxmZfYF7yr6X6vkYfd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BWHsSN9LFrjipxtTerHfyk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Jun 2021 12:04:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BWHsSN9LFrjipxtTerHfyk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Footprint set on binary code]]></media:description>                                                            <media:text><![CDATA[Footprint set on binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Footprint set on binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BWHsSN9LFrjipxtTerHfyk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ads on the internet have become increasingly targeted, customized, and persistent. Flash sales by Amazon feature products you'll likely order. A phone model you searched for earlier in the day appears in your Facebook feed. Even Gmail and YouTube tailor their ads to your exact interests. </p><p>The uncanny precision in ads makes one wonder if they're being watched all the time. However, upon close inspection, you'll find that we let ads find us. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/359700/hacktivist-breaches-private-security-app-citizen" data-original-url="/security/hacking/359700/hacktivist-breaches-private-security-app-citizen">Hacktivist breaches private security app Citizen</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359750/new-study-shows-global-privacy-investments-increasing" data-original-url="/policy-legislation/data-protection/359750/new-study-shows-global-privacy-investments-increasing">New study shows global privacy investments increasing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/31407/hp-3d-printing-can-cut-its-supply-chain-carbon-footprint" data-original-url="/business-operations/31407/hp-3d-printing-can-cut-its-supply-chain-carbon-footprint">HP: 3D printing can cut IT's supply chain carbon footprint</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data" data-original-url="/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data">Senators introduce a new bill to protect consumer data privacy</a></p></div></div><p>Each time we access online services, we create a trail. In time, the trail takes shape as a <a href="https://www.itpro.com/strategy/29259/what-is-your-digital-footprint" data-original-url="https://www.itpro.com/strategy/29259/what-is-your-digital-footprint">digital footprint</a>. This includes the websites you visit and the information you submit to online forums, public accounts, and more. </p><p>Unparalleled insights about a user's identity, online activities, and purchase history can be pieced from a digital footprint. There's no statutory limit to when or how such information may be accessed, collected, or used.</p><p>But that's not all. Hackers and cyberpunks can use digital footprints to create counterfeit digital identities. Several crimes can be committed under a false identity, including cyber espionage, <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, and crypto-jacking.</p><p>While all this is cause for concern, there are several things you can do to protect your data. Here is a guide on how to shield your identity on the web.</p><h2 id="how-to-be-anonymous-on-the-internet">How to be anonymous on the internet</h2><p>Before we jump into the specifics, it helps to know that digital footprints can take two distinct forms.</p><p>When you tweet, blog, or post a photo on social media, you leave an active footprint. Browser cookies and <a href="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference" data-original-url="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference">IP addresses</a> create what is called a passive digital footprint. Unlike active digital tracks, you unwittingly leave behind passive digital during website visits, searches, purchases, and online reviews.</p><p>Active and passive footprints carry great value to marketers. A potential employer or creditor may also examine your online presence. </p><p>Here are seven simple steps you can take to minimize your visibility online. </p><h3 class="article-body__section" id="section-1-use-virtual-private-network"><span>1. Use Virtual Private Network</span></h3><p><a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">Virtual Private Networks</a> (VPNs) circumvent geo-restrictions on websites and multimedia content. But the real appeal lies in <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a>. </p><p>A VPN hides your IP address, obscuring your digital footprint. VPNs also keep your online communications anonymous through <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a>. Additionally, VPNs keep third parties from viewing, selling, or collecting your search history.</p><h3 class="article-body__section" id="section-2-deactivate-old-accounts"><span>2. Deactivate old accounts</span></h3><p>Service providers are far more likely to retain account data despite inactivity. Your personally identifiable information, such as name, phone number, and email address, could linger in a marketing database for years.</p><p>Therefore, it's worthwhile to deactivate inactive social media and email accounts.</p><h3 class="article-body__section" id="section-3-beware-of-34-free-34-wi-fi-connections"><span>3. Beware of "free" Wi-Fi connections</span></h3><p>Free is an enticing word, but there are repercussions you should consider. Using a public Wi-Fi network for online transactions invites theft. This includes WiFis in restaurants, coffee shops, libraries, and even grocery stores. </p><p>Most public Wi-Fi doesn't promise security and lacks encryption. When equipped with the right tools, hackers can intercept unencrypted data, eavesdrop on conversations, steal passwords, and more. </p><p>Consider limiting your online activities to just browsing and streaming when on public Wi-Fi. Switch to your mobile data plan for transactions. You may also use a VPN to create a private network within the free Wi-Fi network.</p><h3 class="article-body__section" id="section-4-re-check-privacy-settings"><span>4. Re-check privacy settings</span></h3><p>Look into the privacy settings of websites you use most often, particularly social media sites. It also helps to be cautious when installing new apps on your smartphone. You may grant apps access to your contacts, messages, camera, and microphone, but gaming apps that solicit your contact list require extra caution. Scams like this are all too common and can have serious consequences.</p><h3 class="article-body__section" id="section-5-avoid-unsafe-websites"><span>5. Avoid unsafe websites</span></h3><p>The URL gives it away. When visiting a website, be sure to look for "https" in the URL. Websites with <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">hypertext transfer protocol secure (HTTPS)</a> encrypt the exchanged data to prevent third-party snooping and interception. </p><p>HTTP lacks encryption, making it less secure than HTTPS. Therefore, it's wise to steer clear of URLS beginning with "http." </p><p>Avoid giving out your personally identifiable information (PII) on unsecured sites at all times. It contributes greatly to ensuring security and a small footprint.</p><h3 class="article-body__section" id="section-6-unsubscribe-from-mailing-lists"><span>6. Unsubscribe from mailing lists</span></h3><p>Unsubscribing from an email is not the same as blocking it, as a blocked email can still end up in your spam box. So long as the service provider holds your email address, it will add to your digital footprint.</p><p>For example, you may have accidentally consented to receive additional promotional emails from a company after purchasing something online. Luckily, it takes only a few clicks to unsubscribe.</p><p>Begin by examining the body of an email. A lot of marketing emails and subscription newsletters have an unsubscribe link at the bottom. In a select few instances, you may be instructed to send an email with the subject line, "unsubscribe" to opt out. </p><h3 class="article-body__section" id="section-7-go-incognito"><span>7. Go incognito </span></h3><p>Google Chrome, Safari, and <a href="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge" data-original-url="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge">Edge</a> all offer anonymous browsing via private or incognito mode. Using a browser's private mode will wipe its cache, browsing history, and cookies, reducing third-party tracking.</p><p>Nevertheless, your internet provider will still have access to a portion of your web activities. Opt for privacy tools or browser extensions to maximize shielding. Additionally, you may also choose to browse on private search engines such as Tor and <a href="https://www.itpro.com/marketing-comms/search-engine-optimization-seo/355585/duckduckgo-vs-google-privacy-or-popularity" data-original-url="https://www.itpro.com/marketing-comms/search-engine-optimization-seo/355585/duckduckgo-vs-google-privacy-or-popularity">DuckDuckGo</a>. </p><h2 id="a-final-word">A final word </h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HuVkXKYxS9nVFkEwoBk7MR" name="HuVkXKYxS9nVFkEwoBk7MR.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" mos="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Don’t just educate: Create cyber-safe behaviour</strong></p><p class="fancy-box__body-text">Designing effective security awareness and training programmes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour" data-original-url="/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour">FREE DOWNLOAD</a></p></div></div><p>Tens of thousands of pages are added to the internet every day. And because security is never absolute, it is near impossible to reduce digital footprints to zero. Therefore, the myth of a "zero digital footprint" is just that: a myth.</p><p>"It used to be expensive to make things public and cheap to make them private. Now it's expensive to make things private and cheap to make them public," recalls Clay Shirky, vice provost of educational technologies at New York University.</p><p>Making small yet decisive changes to your devices and accounts can go a long way toward ensuring digital privacy. Start by "googling" or searching for yourself online. If the results show an extensive digital footprint, consider readjusting your privacy settings. Be sure to read the terms and conditions associated with any new online services you sign up for. It's also a good practice to review privacy policies periodically for any changes that may have occurred. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TikTok implies it’s collecting users' faceprints and voiceprints ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/359774/tiktok-implies-its-collecting-faceprints-and-voiceprints</link>
                                                                            <description>
                            <![CDATA[ New privacy policy gives the app permission to collect biometric data from users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9AoJdrqkdkHRqXUHeS4g8B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fAkfHKrTEYNpRuDEBSEgpm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Jun 2021 14:44:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fAkfHKrTEYNpRuDEBSEgpm-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TikTok app on a smartphone]]></media:description>                                                            <media:text><![CDATA[TikTok app on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[TikTok app on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fAkfHKrTEYNpRuDEBSEgpm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>TikTok has informed US-based users that it's now harvesting more personal information from them, likely including "faceprints and voiceprints." </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359282/tiktok-faces-billion-pound-class-action-for-alleged-data" data-original-url="/policy-legislation/data-protection/359282/tiktok-faces-billion-pound-class-action-for-alleged-data">TikTok faces billion-pound legal battle over "illegal" data collection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/video-conferencing/358964/google-threadit-is-a-tiktok-like-short-video-platform-for" data-original-url="/software/video-conferencing/358964/google-threadit-is-a-tiktok-like-short-video-platform-for">Google Threadit is a TikTok-like short video platform for professionals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358722/tiktok-settles-for-92m-after-being-accused-of-harvesting-biometric-data" data-original-url="/security/privacy/358722/tiktok-settles-for-92m-after-being-accused-of-harvesting-biometric-data">TikTok settles for $92m after being accused of harvesting biometric data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358592/white-house-suspends-action-against-tiktok" data-original-url="/business/policy-legislation/358592/white-house-suspends-action-against-tiktok">White House suspends action against TikTok</a></p></div></div><p>"We may collect biometric identifiers and biometric information as defined under US laws, such as faceprints and voiceprints, from your User Content, the company's new privacy policy states. "Where required by law, we will seek any required permissions from you prior to any such collection."</p><p>This potentially important change was first spotted by <a href="https://techcrunch.com/2021/06/03/tiktok-just-gave-itself-permission-to-collect-biometric-data-on-u-s-users-including-faceprints-and-voiceprints"><em>TechCrunch</em></a>, which noticed a few intriguing updates to TikTok's privacy policy.</p><p>Under the new policy, TikTok may collect information about images and audio in users' content, the policy says, "such as identifying the objects and scenery that appear, the existence and location within an image of face and body features and attributes, the nature of the audio, and the text of the words spoken in your User Content." </p><p>This type of language may sound invasive, but this kind of legal language is fairly common for photo and video apps.</p><p>More important is the statement about collecting "biometric identifiers." It doesn't specify what TikTok plans to do with this data or whether it's taking into account federal or state laws or both.</p><p>This comes only a few months after TikTok <a href="https://www.itpro.com/security/privacy/358722/tiktok-settles-for-92m-after-being-accused-of-harvesting-biometric-data" data-original-url="https://www.itpro.com/security/privacy/358722/tiktok-settles-for-92m-after-being-accused-of-harvesting-biometric-data">settled a $92 million lawsuit</a> where it was accused of collecting biometric data from users without their consent.</p><p>The lawsuit accused the social media platform of deploying a complex artificial intelligence (AI) system to scan for facial features in users' videos, alongside algorithms to identify a user's age, gender and ethnicity. </p><p>The accusers claimed that TikTok's app extracted a broad array of such data without consent and shared personal and private viewing histories with third parties, such as Facebook and Google. </p><p>Also of concern was the potential for this data to be shared with companies based in China, as the lawsuit claims TikTok doesn't adequately disclose how it shares user data with entities outside the US.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon’s Ring now requires police to request doorbell videos publicly ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/359763/amazons-ring-now-requires-police-to-request-doorbell-videos-publicly</link>
                                                                            <description>
                            <![CDATA[ Previously, Ring owners got private messages from police looking for user videos ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qVwPDCXDPEbyXtvvxWMiK6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZHxyN3Axi5CJxLUoBRP4G8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Jun 2021 16:24:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZHxyN3Axi5CJxLUoBRP4G8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ring doorbell camera mounted on a door frame]]></media:description>                                                            <media:text><![CDATA[Ring doorbell camera mounted on a door frame]]></media:text>
                                <media:title type="plain"><![CDATA[Ring doorbell camera mounted on a door frame]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZHxyN3Axi5CJxLUoBRP4G8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon's Ring announced Thursday that police departments must now publicly request user videos from Ring's smart doorbells and cameras instead of doing so privately.</p><p>Until now, Ring device owners would get private messages from the app on behalf of law enforcement agencies looking for videos that may have captured footage of certain individuals, traffic accidents, or crimes in progress. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/internet-of-things-iot/34786/ring-doorbells-leak-users-wi-fi-passwords-in-clear-text" data-original-url="/internet-of-things-iot/34786/ring-doorbells-leak-users-wi-fi-passwords-in-clear-text">Ring doorbells leak users' Wi-Fi passwords in clear text</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359750/new-study-shows-global-privacy-investments-increasing" data-original-url="/policy-legislation/data-protection/359750/new-study-shows-global-privacy-investments-increasing">New study shows global privacy investments increasing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/web-browser/359741/mozilla-moderinses-firefox-ui-design-changes" data-original-url="/network-internet/web-browser/359741/mozilla-moderinses-firefox-ui-design-changes">Mozilla modernises Firefox UI with design overhaul, privacy protections</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359670/whatsapp-sues-indian-government-over-new-privacy-laws" data-original-url="/policy-legislation/data-protection/359670/whatsapp-sues-indian-government-over-new-privacy-laws">WhatsApp sues Indian government over new privacy laws</a></p></div></div><p>Ring is likely taking this action because its partnerships with law enforcement agencies have sparked privacy, surveillance, and racial profiling concerns. According to Ring's active agency tracker, thousands of American police and fire departments in the U.S. have partnered with Ring by joining the Neighbors app.</p><p>"Beginning next week, public safety agencies will only be able to request information or video from their communities through a new, publicly viewable post category on Neighbors called 'Request for Assistance,'" Ring said <a href="https://blog.ring.com/products-innovation/ring-launches-request-for-assistance-posts-on-the-neighbors-app">in a blog post</a>. "Public safety agencies can use these posts to notify residents of an incident and ask their communities for help related to an investigation.</p><p>"All 'Request for Assistance' posts will be publicly viewable in the Neighbors feed, and logged on the agency's public profile. This way, anyone interested in knowing more about how their police agency is using Request for Assistance posts can simply visit the agency's profile and see the post history."</p><p>Ring said it would roll out the new "Request for Assistance" feature in the Neighbors app starting next week.</p><p>The company reiterated that users can always choose what they share with law enforcement agencies.</p><p>Social media apps focused on neighborhood safety have recently come under increased scrutiny. For example, the crime-tracking app Citizen <a href="https://www.itpro.com/security/hacking/359700/hacktivist-breaches-private-security-app-citizen" data-original-url="https://www.itpro.com/security/hacking/359700/hacktivist-breaches-private-security-app-citizen">was in the news last month</a> after a live stream from the app with over a million views sparked a search in California. The app showed the name and photo of a man believed to have started a wildfire, but he turned out to be innocent. </p><p>Also in May, it came out that Citizen had been testing the idea of a private security force after vehicles branded with the Citizen logo were photographed in Los Angeles.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New study shows global privacy investments increasing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359750/new-study-shows-global-privacy-investments-increasing</link>
                                                                            <description>
                            <![CDATA[ Companies must still try harder on cookie consent ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dp72fVhi1tMRRoXix6k65Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MFxmQeu22N4RBhNyMShNZk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jun 2021 15:08:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MFxmQeu22N4RBhNyMShNZk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of a digital padlock on a tablet to symbolise user privacy]]></media:description>                                                            <media:text><![CDATA[Abstract image of a digital padlock on a tablet to symbolise user privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of a digital padlock on a tablet to symbolise user privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MFxmQeu22N4RBhNyMShNZk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are investing more in privacy protection globally, according to research published today by privacy management software company TrustArc. Nevertheless, it still found significant room for improvement in key areas, including cookie consent management.</p><p>The company surveyed people worldwide for its <a href="https://info.trustarc.com/Web-Resource-2021-05-26-Global-Benchmarking-Report_LP.html">2021 Global Privacy Benchmarks Report</a>, including executives, managers, full-time non-managerial employees, and members of the privacy team. It found performance improving on the privacy front and that companies were eager to do more. The proportion of companies planning big-ticket privacy investments of $1 million or more grew to 48% in 2021. This is up from 28% in 2020.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data" data-original-url="/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data">Senators introduce a new bill to protect consumer data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns" data-original-url="/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns">Avast shutters Jumpshot unit in wake of data privacy concerns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/33374/mps-form-data-privacy-taskforce-to-keep-pressure-on-big-tech" data-original-url="/policy-legislation/33374/mps-form-data-privacy-taskforce-to-keep-pressure-on-big-tech">MPs form data privacy taskforce to keep pressure on big tech</a></p></div></div><p>This increased focus on privacy showed up in internal programs. The number of companies with dedicated privacy offices jumped 17 percentage points to 83%. More companies also said that privacy was now a core part of their business strategy. That proportion increased 7 percentage points from 37% to 44%.</p><p>TrustArc also noted a marked improvement in attitudes to privacy on its privacy index, which it compiles based on respondents' answers to core privacy questions. These include whether their board of directors regularly reviewed privacy matters and whether they sufficiently trained employees in privacy issues. It also assessed confidence in key privacy outcomes among their customers, employees, and partners. </p><p>The median score on the privacy index jumped from 62% to 70% during the last year, while the 75th percentile score — the average score for companies getting an "A" grade — jumped from 79% to 85%.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>Organizations in the US are more confident in protecting employee and customer data, at 82% compared to 74% in Europe. This could be a sign that stateside companies have upped their game following the imposition of the wide-ranging <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California Consumer Privacy Act</a>, which came into force on January 1, 2020.</p><p>Companies might be paying more attention to privacy, but there is still work to be done. Over a third of respondents said they had suffered a breach in the last three years, while 27% reported their company suffered a large-scale cyber security attack.</p><p>One area where companies must try harder is cookie consent. This <a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">regulatory requirement</a> mandates that companies <a href="https://www.itpro.com/security/privacy/358080/google-and-amazon-fined-ps122m-for-insufficient-cookie-consent" data-original-url="https://www.itpro.com/security/privacy/358080/google-and-amazon-fined-ps122m-for-insufficient-cookie-consent">collect visitor consent</a> when serving cookies via a website. Only 23% of companies work with stakeholders across all departments to ensure that their consent solution meets regulatory requirements and business objectives. Just 46% of respondents said their cookie consent solution was "fully done."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google now allows you to password-protect your activity page ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359666/google-now-allows-you-to-password-protect-your-activity</link>
                                                                            <description>
                            <![CDATA[ The page shows your Google searches, locations, and YouTube views ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nQiaK2YkBsqN2VbkWfn9gx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CL8Qmv58AHZZ4V5rNiYGy6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 May 2021 15:42:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CL8Qmv58AHZZ4V5rNiYGy6-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand using the Google search bar on a tablet computer]]></media:description>                                                            <media:text><![CDATA[A hand using the Google search bar on a tablet computer]]></media:text>
                                <media:title type="plain"><![CDATA[A hand using the Google search bar on a tablet computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CL8Qmv58AHZZ4V5rNiYGy6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You can now keep prying eyes away from your Google search history and more, as the tech giant has just added password protection to these sensitive screens. </p><p><a href="https://myactivity.google.com/myactivity">Google's My Activity page</a> displays all of your Google searches, every location you've looked up on Google Maps, and every video you've watched on YouTube. Anyone who has access to your phone, tablet, or PC could view all that information and learn <em>a</em> lot about you.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data" data-original-url="/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data">Senators introduce a new bill to protect consumer data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns" data-original-url="/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns">Avast shutters Jumpshot unit in wake of data privacy concerns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite" data-original-url="/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite">Microsoft simplifies data privacy for 365 suite</a></p></div></div><p>Google is now introducing a way to <a href="https://support.google.com/accounts/answer/7028918">put a password</a> on your My Activity page. To add password protection, navigate to your My Activity page and click on the link that reads, "Manage My Activity verification." From there, click the "Require Extra Verification" button. At that point, Google will have you sign in again and complete your <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a>, if it's turned on.</p><p>While you're on that page, it's not a bad idea to check out the settings it has for your Google ID. Here, you can turn off and on the three things: your web and app activity tracker, location history, and YouTube history.</p><p>It's handy to have a password protecting this information, but you should also consider whether you really want Google tracking and displaying this information in the first place.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>Google has long grappled with issues of tracking versus privacy. Two years ago, the search giant first offered its users <a href="https://www.itpro.com/data-protection/33563/google-to-offer-auto-delete-for-web-tracking-history" data-original-url="https://www.itpro.com/data-protection/33563/google-to-offer-auto-delete-for-web-tracking-history">the option to automatically delete</a> their search and location history after three months.</p><p>Users can increase the time range to 18 months, and Google automatically deletes any data older than that from their accounts. </p><p>That data management tool came right after <a href="https://www.itpro.com/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite" data-original-url="https://www.itpro.com/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite">Microsoft and Facebook</a> announced features for users to have greater control over their personal data. </p><p>These measures highlight a continuing trend of companies making an effort to show responsibility for data privacy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Misconfigured cloud services exposed 100 million Android users' data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data</link>
                                                                            <description>
                            <![CDATA[ Mobile apps reveal user data, including emails, chat messages, location, and passwords ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kvKnNupYhdUky5n3ne8u18</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jeU6Bb4BZDZw2w88Gir7Aj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 May 2021 14:36:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jeU6Bb4BZDZw2w88Gir7Aj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Thumb touching a phone&amp;#039;s screen within the Android App store]]></media:description>                                                            <media:text><![CDATA[Thumb touching a phone&amp;#039;s screen within the Android App store]]></media:text>
                                <media:title type="plain"><![CDATA[Thumb touching a phone&amp;#039;s screen within the Android App store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jeU6Bb4BZDZw2w88Gir7Aj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have discovered 23 Android applications that potentially exposed over 100 million users’ personal data through various misconfigurations of third-party <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a> services.</p><p>According to <a href="https://blog.checkpoint.com/2021/05/20/misconfiguration-of-third-party-cloud-services-exposed-data-of-over-100-million-users">Check Point Research</a>, the data exposed from these apps included emails, chat messages, location, passwords, and photos. This left users exposed to fraud, identity theft, and service swipes (using the same username-password combination on other services).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak" data-original-url="/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak">Misconfigured Git servers lead to Nissan data leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357514/government-agencies-see-misconfigured-cloud-services-as-top-security-threat" data-original-url="/security/357514/government-agencies-see-misconfigured-cloud-services-as-top-security-threat">Government agencies see misconfigured cloud services as top security threat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/354611/misconfigured-security-command-exposes-250-million-microsoft-customer" data-original-url="/security/data-breaches/354611/misconfigured-security-command-exposes-250-million-microsoft-customer">Misconfigured security command exposes 250 million Microsoft customer records</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32732/nasa-employee-data-exposed-for-at-least-three-weeks-due-to-misconfigured-web-app" data-original-url="/security/32732/nasa-employee-data-exposed-for-at-least-three-weeks-due-to-misconfigured-web-app">NASA employee data exposed for at least three weeks due to misconfigured web app</a></p></div></div><p>Researchers said, “there was nothing in place to stop the unauthorized access from happening.”</p><p>“Modern cloud-based solutions have become the new standard in the mobile application development world,” researchers said. “Services such as cloud-based storage, real-time databases, notification management, analytics, and more are simply a click away from being integrated into applications. Yet, developers often overlook the security aspect of these services, their configuration, and of course, their content.”</p><p>The first problem researchers discovered was the misconfiguration of real-time databases developers used to store data in the cloud and synchronize with connected clients.</p><p>In 13 Android apps, which saw download numbers range from 10,000 to 10 million, no authentication was in place to prevent hackers from accessing these databases containing email addresses, passwords, private chats, device location, user identifiers, and more.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bKtjyXWcdfnqeGjgXiLXeC" name="bKtjyXWcdfnqeGjgXiLXeC.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bKtjyXWcdfnqeGjgXiLXeC.jpg" mos="https://cdn.mos.cms.futurecdn.net/bKtjyXWcdfnqeGjgXiLXeC.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a data-driven enterprise of the future</strong></p><p class="fancy-box__body-text">Top five trends that will shape the future of organisational resiliency and effectiveness</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/359617/building-a-data-driven-enterprise-of-the-future" data-original-url="/data-insights/data-management/359617/building-a-data-driven-enterprise-of-the-future">FREE DOWNLOAD</a></p></div></div><p>In one app, T’Leva, a taxi app with over 50,000 downloads, researchers could access chat messages between drivers and passengers. They could also access users’ full names, phone numbers, and locations (destination and pick-up) – all by sending one request to the database.</p><p>A second issue was with push notifications. “Most push notification services require a key (sometimes, more than one) to recognize the identity of the request submitter,” said researchers. “When those keys are just embedded into the application file itself, it is very easy for hackers to take control and gain the ability to send notifications which might contain malicious links or content to all users on behalf of the developer.”</p><p>The third problem occurred in cloud storage. In one app, researchers could access cloud storage keys embedded into the app and all stored fax transmissions.</p><p>“With just analyzing the app, a malicious actor could gain access to any and all documents sent by the 500,000 users who downloaded this application,” said researchers.</p><p>Researchers said they approached Google and each app developer before publishing its research to share their findings. Researchers said only a few of the apps have since changed their configurations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Senators introduce a new bill to protect consumer data privacy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359620/senators-introduce-a-new-bill-to-protect-consumer-data</link>
                                                                            <description>
                            <![CDATA[ Bipartisan bill would force Facebook and Google to follow Apple’s lead on tracking transparency ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">upbjDcMy48rzUVsnnwUJwf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8SuLXUhiNMduwkTFWrnkAe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 May 2021 17:44:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8SuLXUhiNMduwkTFWrnkAe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Large eye staring out from the screen]]></media:description>                                                            <media:text><![CDATA[Large eye staring out from the screen]]></media:text>
                                <media:title type="plain"><![CDATA[Large eye staring out from the screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8SuLXUhiNMduwkTFWrnkAe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With Apple now allowing users to opt out of third-party app and website tracking, a bipartisan group of US senators is seeking to force other tech giants, like Facebook and Google, to do the same thing.</p><p>The <a href="https://www.congress.gov/bill/116th-congress/senate-bill/189">Social Media Privacy Protection and Consumer Rights Act</a> would allow users to opt out of data tracking and force tech companies to be more transparent about how they use consumers’ data. </p><p>Senators backing the bill include Amy Klobuchar (D-MN), Richard Burr (R-NC), John Kennedy (R-LA) and Joe Manchin (D-WV). Klobuchar originally introduced the bill in 2019 in the wake of <a href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">Facebook’s Cambridge Analytica scandal</a>, but the bill didn’t move forward due to lack of bipartisan support. It now has that support.</p><p>In addition to allowing users to opt out of data tracking, the bill would also force online platforms to post their terms of service agreements in plain language and notify users within 72 hours of any data breach.</p><p>The Senate bill essentially calls for a national version of data privacy laws already in effect in some states. The most high-profile of these laws is the <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California Consumer Privacy Act (CCPA)</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns" data-original-url="/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns">Avast shutters Jumpshot unit in wake of data privacy concerns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite" data-original-url="/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite">Microsoft simplifies data privacy for 365 suite</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/33374/mps-form-data-privacy-taskforce-to-keep-pressure-on-big-tech" data-original-url="/policy-legislation/33374/mps-form-data-privacy-taskforce-to-keep-pressure-on-big-tech">MPs form data privacy taskforce to keep pressure on big tech</a></p></div></div><p>Some tech companies, such as Microsoft, <a href="https://www.itpro.com/policy-legislation/34797/microsoft-commits-to-honouring-california-consumer-privacy-act-nationwide" data-original-url="https://www.itpro.com/policy-legislation/34797/microsoft-commits-to-honouring-california-consumer-privacy-act-nationwide">have already pledged to honor the CCPA’s rules nationwide</a>. But Klobuchar and other senators want to put a national privacy data law in place that’s similar to Europe’s <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulation (GDPR)</a>. </p><p>The Senate bill would essentially force other US tech giants to follow Apple’s lead on data tracking transparency.</p><p>Last month, Apple released its <a href="https://www.itpro.com/security/privacy/359341/apples-ios-145-released-tracking-update" data-original-url="https://www.itpro.com/security/privacy/359341/apples-ios-145-released-tracking-update">App Tracking Transparency (ATT)</a> tool. It was introduced with iOS 14.5 to explicitly tell users what data will be collected and which apps would track them as part of IDFA. Apps also have to ask for users’ permission upfront, in the form of an opt-in, before being able to track them. </p><p>Since then, <a href="https://www.itpro.com/security/privacy/359467/just-13-of-ios-users-opt-into-being-tracked-by-third-party-apps" data-original-url="https://www.itpro.com/security/privacy/359467/just-13-of-ios-users-opt-into-being-tracked-by-third-party-apps">only a fraction of iOS users have agreed to be tracked</a> by third-party applications such as Facebook. Just 13% of users worldwide have granted permission for tracking by any apps, according to data compiled by Flurry, and 5% of users set themselves to “restricted,” meaning apps won’t even be able to ask them to opt in. </p><p>Facebook led a chorus of voices railing against the rollout of ATT, fearing the expected drop-off in users being tracked would hurt it and its partners’ revenues. </p><p>The social media network publicly campaigned against ATT, forcing Apple to delay the move several times to allow developers and companies to prepare for the changes. </p><p>After the first Senate data privacy bill fell short in 2019, it remains to be seen how far it will get this time.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook bans Signal's crafty anti-tracking ad campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359428/facebook-bans-signals-anti-tracking-ad-campaign</link>
                                                                            <description>
                            <![CDATA[ Signal exposed Facebook’s data collection practices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">irrvcHf5uVqpaAk18VT7yj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Qqecr3tC8nxqyzY3BfLSj7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 May 2021 17:11:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Qqecr3tC8nxqyzY3BfLSj7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook logo surrounded by money]]></media:description>                                                            <media:text><![CDATA[Facebook logo surrounded by money]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook logo surrounded by money]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Qqecr3tC8nxqyzY3BfLSj7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Secure messaging application firm Signal just highlighted how much data Facebook collects about its users in a clever piece of media hacking.</p><p>Signal, which prides itself on not tracking its users, set out to demonstrate to Facebook users how much data they're giving up.</p><p>The company created an ad campaign on Instagram using the Facebook-owned photo and messaging app's multi-variant ad targeting system. This uses the detailed profiles Facebook builds about its users to deliver them appropriate advertisements. Instead of using this targeted demographic data to sell products to a carefully segmented demographic, Signal designed the advertisements to tell recipients what Facebook knew about it explicitly.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/359341/apples-ios-145-released-tracking-update" data-original-url="/security/privacy/359341/apples-ios-145-released-tracking-update">iOS 14.5 privacy changes could have “major impact” on SMBs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359069/government-loses-lawsuit-over-nhs-data-deal-with-palantir" data-original-url="/business/policy-legislation/359069/government-loses-lawsuit-over-nhs-data-deal-with-palantir">Gov 'forced into major U-turn' on NHS deal with Palantir, privacy group claims</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358933/google-privacy-sandbox-added-to-us-antitrust-compaint" data-original-url="/security/privacy/358933/google-privacy-sandbox-added-to-us-antitrust-compaint">Google Privacy Sandbox added to US antitrust compaint</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358822/apple-faces-another-ios-privacy-lawsuit-in-europe" data-original-url="/security/privacy/358822/apple-faces-another-ios-privacy-lawsuit-in-europe">Apple faces another iOS privacy lawsuit in Europe</a></p></div></div><p>"The way most of the internet works today would be considered intolerable if translated into comprehensible real world analogs, but it endures because it is invisible," <a href="https://signal.org/blog/the-instagram-ads-you-will-never-see">the company said</a> when explaining the project.</p><p>Examples of the ads included: "You got this ad because you're a K-pop-loving chemical engineer. This ad used your location to see you're in Berlin. And you have a new baby. And just moved. And you're really feeling those pregnancy exercises lately."</p><p>Other examples Signal posted identified users’ marital status, including a recent divorce, and more nuanced situations like being in an open relationship. Ads also relayed recent purchases and new hobbies. They also called out the kinds of content that specific Instagram users like to read online.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="J25mqBaRCYz3nhkyfHahge" name="J25mqBaRCYz3nhkyfHahge.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/J25mqBaRCYz3nhkyfHahge.jpg" mos="https://cdn.mos.cms.futurecdn.net/J25mqBaRCYz3nhkyfHahge.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Transforming business operations with AI, IoT data, and edge computing</strong></p><p class="fancy-box__body-text">A Pathfinder report on the ROI of AI, IoT, and edge computing</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/internet-of-things-iot/359412/transforming-business-operations-with-ai-iot-data" data-original-url="/network-internet/internet-of-things-iot/359412/transforming-business-operations-with-ai-iot-data">FREE DOWNLOAD</a></p></div></div><p>According to Signal, Facebook disallowed the ad campaign. "Being transparent about how ads use people's data is apparently enough to get banned; in Facebook's world, the only acceptable usage is to hide what you're doing from your audience," it continued.</p><p>This media hack is another small blow in Facebook's ongoing battle against privacy advocates. In March, the US Supreme Court rejected Facebook’s appeal to scale back a $15 billion class-action lawsuit accusing it of illegally tracking its users' activity. </p><p>Facebook is also involved in an ongoing spat with Apple, which has introduced privacy changes in iOS 14 that give users an opt-in prompt to enable in-app tracking. Facebook <a href="https://www.itpro.com/security/privacy/358486/facebook-tries-to-gazump-apple-with-its-own-privacy-notice" data-original-url="https://www.itpro.com/security/privacy/358486/facebook-tries-to-gazump-apple-with-its-own-privacy-notice">responded</a> by inserting messages in its app that guide users to opt in.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Acuant acquires identity verification provider Hello Soda  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/mergers-and-acquisitions/359416/acuant-acquires-identity-verification-provider</link>
                                                                            <description>
                            <![CDATA[ Hello Soda’s dark web solution scans over 600 million records for signs of data theft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bzyPjVJYQisQSBAiWLN27o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AgdEPrR2JpSqErsmPFFQu5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 May 2021 15:14:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AgdEPrR2JpSqErsmPFFQu5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[HelloSoda logo on a white backgorund]]></media:description>                                                            <media:text><![CDATA[HelloSoda logo on a white backgorund]]></media:text>
                                <media:title type="plain"><![CDATA[HelloSoda logo on a white backgorund]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AgdEPrR2JpSqErsmPFFQu5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Acuant has acquired Hello Soda, a global identity verification provider, know your customer (KYC), and anti-money laundering (AML) solutions.</p><p>According to Acuant, the acquisition will fortify its position in the digital identity market and strengthen its Trusted Identity Platform.</p><p>The Acuant-Hello Soda merger will also bring together powerful technologies in data science modeling and advanced <a href="https://www.itpro.com/tag/analytics" data-original-url="https://www.itpro.com/analytics">analytics</a> to enhance trust in digital identities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/microsoft-azure/359122/acuant-joins-microsoft-to-enable-seamless-identity-verification-on" data-original-url="/cloud/microsoft-azure/359122/acuant-joins-microsoft-to-enable-seamless-identity-verification-on">Acuant joins Microsoft to enable seamless identity verification on Azure AD</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/358838/five-critical-questions-to-ask-your-identity" data-original-url="/security/identity-and-access-management-iam/358838/five-critical-questions-to-ask-your-identity">Five critical questions to ask your identity provider</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/358827/what-is-customer-identity-and-access-management" data-original-url="/security/identity-and-access-management-iam/358827/what-is-customer-identity-and-access-management">What is customer identity and access management? </a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/358611/post-office-to-launch-new-biometrics-fueled-app" data-original-url="/business-strategy/digital-transformation/358611/post-office-to-launch-new-biometrics-fueled-app">Post Office embraces biometrics for new digital identity app</a></p></div></div><p>“Our goal has always been to power trust for all, a vision we share with Hello Soda whom we are excited to welcome to the Acuant family,” said Yossi Zekri, president and <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> of Acuant.</p><p>“This is truly the most exhilarating time in our company’s history, coinciding with the disruption of traditional financial markets, the rapid digitalization of the world and the need for business and governments to help safeguard identity more than ever before. Adding Hello Soda to our Trusted Identity Platform will reach more people today and position us even stronger for the future of digital identity.”</p><p>With its proprietary analytics <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a>, data science modeling, and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning (ML)</a> algorithms, Hello Soda helps organizations make informed business decisions by delivering actionable insights.</p><p>The Hello Soda dark web solution reduces fraud risk by scanning over 600 million dark web records for signs of compromised personally identifiable information. Hello Soda’s other interesting solutions include ProfileiD and iDocufy.</p><p>ProfileiD analyzes customers’ digital footprint to automate user authentication “in sub-5 seconds.” iDocufy, on the other hand, verifies over 6,000 forms of government-issued identity documents.</p><p>“We could not be happier to join Acuant, bringing our talent, technology, network and expertise to strengthen all we have accomplished and to take our mutual vision further as a team,” stated James Blake, founder and CEO of Hello Soda.</p><p>“Our combined technology will serve us well in our joint mission to democratize trust and provide solutions to reach every sector of the global population, allowing every individual to conduct trusted transactions when and where they wish.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BigID launches freemium privacy management tool for SMBs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359339/bigid-launches-freemium-privacy-management-tool-for-small</link>
                                                                            <description>
                            <![CDATA[ Portal offers self-service privacy management for customers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vegXu3hpVMh3ker6STaPZd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VEmLoUaMYNiDp3gtGJkRng-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Apr 2021 17:23:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VEmLoUaMYNiDp3gtGJkRng-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Faces in binary code to represent privacy]]></media:description>                                                            <media:text><![CDATA[Faces in binary code to represent privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Faces in binary code to represent privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VEmLoUaMYNiDp3gtGJkRng-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy management company <a href="https://bigid.com">BigID</a> has created a freemium platform to manage customer privacy requests.</p><p>Called <a href="https://www.bigid.me">BigID.me</a>, the tool allows small- to medium-sized enterprises to automate customer privacy management without operating their own dedicated privacy office.</p><p>The service allows companies to manage customers’ data privacy preferences and consent for handling data, including <a href="https://www.itpro.com/security/privacy/358637/what-are-supercookies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/358637/what-are-supercookies">cookies</a> and privacy requests. They can create their own branded customer-facing self-service privacy portals with custom forms to submit data requests. and customers and employees can track the progress of data access requests, managing them against regulatory deadlines.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns" data-original-url="/data-insights/data-processing/354670/avast-shutters-jumpshot-unit-in-wake-of-data-privacy-concerns">Avast shutters Jumpshot unit in wake of data privacy concerns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite" data-original-url="/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite">Microsoft simplifies data privacy for 365 suite</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/privacy/32638/google-wins-biometric-data-privacy-case" data-original-url="/privacy/32638/google-wins-biometric-data-privacy-case">Google wins biometric data privacy case</a></p></div></div><p>The General Data Protection Regulation (GDPR), which apply to US companies holding data on European residents, and other US consumer data protection laws like the <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California Consumer Privacy Act</a> allow individuals to request access to the data companies hold about them. People can ask for that data to be updated and request its deletion at any time, withdrawing consent for companies to hold data about them.</p><p>Internal teams can use the portal to organize consistent workflows for handling privacy requests and can trigger automatic emails to customers to inform them of status changes. It generates reports for managers that show data-request trends according to data points like status and regulation type.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jfMfftdRc8Sostbdck8Fqk" name="jfMfftdRc8Sostbdck8Fqk.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/jfMfftdRc8Sostbdck8Fqk.png" mos="https://cdn.mos.cms.futurecdn.net/jfMfftdRc8Sostbdck8Fqk.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>NETSCOUT threat intelligence report</strong></p><p class="fancy-box__body-text">Cyber crime: Exploiting a pandemic</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/359329/netscout-threat-intelligence-report" data-original-url="/security/cyber-crime/359329/netscout-threat-intelligence-report">FREE DOWNLOAD</a></p></div></div><p>The freemium service allows teams of up to three members to handle up to five data access and deletion requests per month. There are two other paid tiers for handing unlimited general data privacy-related requests. The Standard package costs $750 per month, allows up to 10 members, and includes custom branding. The Growth package costs $1,500 per month, allows up to 20 members to handle unlimited general data requests and up to a million consent requests, and offers branded PDF reports. There is also an enterprise version that offers a range of additional features.</p><p>BigID, which opened in 2016, built its business offering a more full-featured privacy data intelligence platform that offers customers data discovery services and applications to help protect and manage data. It offers customers a range of privacy functions, including data flow mapping, <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a>-based classification of personal information, data inventory, and consent governance practices.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple launches its privacy-label database ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/ios/358883/apple-launches-its-privacy-label-database</link>
                                                                            <description>
                            <![CDATA[ The labels reveal what type of data Apple apps collect when you use them ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mV2hozPFHQ7FNTkGQkVpNT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lf5tVNMLrtzubvq3F5AhRk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Mar 2021 15:55:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lf5tVNMLrtzubvq3F5AhRk-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple logo on a glass storefront in Ireland]]></media:description>                                                            <media:text><![CDATA[The Apple logo on a glass storefront in Ireland]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple logo on a glass storefront in Ireland]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lf5tVNMLrtzubvq3F5AhRk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has announced <a href="https://www.apple.com/privacy/labels">a searchable privacy-label database</a>, bringing privacy labels for iOS, iPadOS, macOS, watchOS, and tvOS apps together in one place.</p><p>Starting late last year, Apple required <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer" data-original-url="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">developers</a> to detail app privacy information on the App store. The details, which Apple calls “<a href="https://www.itpro.com/security/privacy/357690/apple-will-require-developers-to-add-privacy-nutrition-labels-to-apps" data-original-url="https://www.itpro.com/security/privacy/357690/apple-will-require-developers-to-add-privacy-nutrition-labels-to-apps">privacy nutrition labels</a>,” better informed users about what data apps collect and if that data is linked to them or used for tracking. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358133/apple-ios-143-launch-brings-privacy-labels-for-all-apps" data-original-url="/security/privacy/358133/apple-ios-143-launch-brings-privacy-labels-for-all-apps">Apple iOS 14.3 launch brings privacy labels for all apps</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358822/apple-faces-another-ios-privacy-lawsuit-in-europe" data-original-url="/security/privacy/358822/apple-faces-another-ios-privacy-lawsuit-in-europe">Apple faces another iOS privacy lawsuit in Europe</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war" data-original-url="/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war">Apple and Facebook's privacy dispute could lead to legal war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/358809/apple-discontinues-the-imac-pro-after-a-series-of-imac-upgrades" data-original-url="/hardware/358809/apple-discontinues-the-imac-pro-after-a-series-of-imac-upgrades">Apple discontinues the iMac Pro</a></p></div></div><p>"Our privacy labels are designed to help you understand how apps handle your data, including apps we develop," said Apple.</p><p>The database, which you can find under the “Labels” section in <a href="https://www.apple.com/privacy">Apple’s privacy webpage</a>, offers details on Apple apps across iOS, iPadOS, macOS, watchOS, and tvOS. For convenience, Apple arranges the apps alphabetically, and users can learn what data apps are gathering and if that data is linked to their identity.</p><p>For example, Apple Maps collects your location, search history, and usage data, but that data isn't linked to your identity. The App Store collects your contact and purchase info, search history, and other identifiers related to your identity. Airport Utility, on the other hand, collects no data at all.</p><p>According to Apple’s privacy policy, “collected data may depend on the features you use, whether you only use a paid version of an app, or whether you’re a child.” App developers may choose not to list data in the App Privacy section if the data collected from users is “covered by a privacy law under relevant financial services or data protection laws or regulations.” </p><p>The update is a welcome addition for users looking to view and manage their privacy settings in one place. </p><p>For more information about Apple’s data-collection policies, head to <a href="https://developer.apple.com/app-store/app-privacy-details">Apple’s developer support page</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is customer identity and access management? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/identity-and-access-management-iam/358827/what-is-customer-identity-and-access-management</link>
                                                                            <description>
                            <![CDATA[ We answer five top questions about CIAM and its importance to customer relationships and business success ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gSj2HDkwcRMWEahSxaKLtt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/s8ZNyJyFhqrQh2Sz2AR9YE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Mar 2021 15:57:44 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Aug 2021 13:52:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gabriella Buckner ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/s8ZNyJyFhqrQh2Sz2AR9YE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands holding up a sign saying &amp;#039;know your customer&amp;#039; in red letters]]></media:description>                                                            <media:text><![CDATA[Hands holding up a sign saying &amp;#039;know your customer&amp;#039; in red letters]]></media:text>
                                <media:title type="plain"><![CDATA[Hands holding up a sign saying &amp;#039;know your customer&amp;#039; in red letters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/s8ZNyJyFhqrQh2Sz2AR9YE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Improving customer experience is the driving force behind many an organisation’s digital transformation, as any savvy business knows that in our <a href="https://www.itpro.com/marketing-comms/customer-experience-cx/358446/why-digital-experience-is-vital-for-success" data-original-url="https://www.itpro.com/marketing-comms/customer-experience-cx/358446/why-digital-experience-is-vital-for-success">experience economy</a>, how a customer perceives every interaction with your business is integral to its success.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="46MS25Ne58gQYeTNcHoXhW" name="46MS25Ne58gQYeTNcHoXhW.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" mos="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>From zero to hero: The path to CIAM maturity</strong></p><p class="fancy-box__body-text">Your guide to the CIAM journey</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity" data-original-url="/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity">FREE DOWNLOAD</a></p></div></div><p>With 85% of respondents to a <a href="https://www.itpro.com/marketing-comms/customer-experience-cx/358446/why-digital-experience-is-vital-for-success" data-original-url="https://www.itpro.com/marketing-comms/customer-experience-cx/358446/why-digital-experience-is-vital-for-success">survey</a> saying a personalised experience is key to earning their business and 67% saying they would pay more for these experiences, it’s clear that you need to deliver multi-channel, seamless interactions that make your customers feel seen. </p><p>How you manage and protect customer data is a big part of this, as it helps gain trust and adds to the overall experience. How do you do this, though, with the proliferation of extra devices like connected cars and smartwatches complicating secure, multi-channel interactions? </p><p>And since in the past, more data security has often been tied to having less visibility, how can you juggle protecting their information with using it to offer the best experiences? </p><p>This is where customer identity and access management (CIAM) comes in. </p><h3 class="article-body__section" id="section-what-is-the-difference-between-iam-and-ciam"><span>What is the difference between IAM and CIAM? </span></h3><p>Traditional <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy" data-original-url="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity and access management</a> (IAM) is designed for authentication and access within an organisation. It is used for controlling an employee’s access when they join, leave, or change roles and doesn’t cover requirements that are specific to customers, like how they prefer their data to be managed when they sign up to a website. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home" data-original-url="/security/357935/top-security-tips-for-employees-working-from-home">Top security tips for employees working from home</a></p></div></div><p>On the other hand, in addition to securing a customer’s information, CIAM is also geared towards creating better experiences through data collection. It benefits businesses as well, allowing them to build customer profiles with the data collected and better target customers for higher conversions. </p><h3 class="article-body__section" id="section-why-do-you-need-ciam"><span>Why do you need CIAM?</span></h3><p>Customers have high expectations and they can quickly get impatient when those expectations aren’t being met. It doesn’t take too many mistakes, inconveniences, or pages that won’t load before they share their bad experiences with others, so the stakes of CIAM are high. </p><p>When we look at traditional methods of managing customer data without a CIAM platform, there are many pitfalls. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="/security/29982/what-is-two-factor-authentication">What is two-factor authentication?</a></p></div></div><p>Normally, authentication is built into the website and credentials are stored in back-end databases, which don’t transfer sign-in information or social logins across multiple web applications and create more friction for customers.</p><p>This method also doesn’t update automatically, meaning you miss out on new features like multi-factor authentication or the latest security offerings.</p><p>If customers can’t easily access services with a single sign-on and their data is at risk, they’re likely to desert your business in favour of a competitor. </p><h3 class="article-body__section" id="section-what-benefits-can-my-organisation-get-from-ciam"><span>What benefits can my organisation get from CIAM?</span></h3><p>As we’ve already touched on, a good CIAM platform will offer your organisation more visibility into customer behaviour, from their purchase histories to usage trends. </p><p>This customer profile informs sales forecasting, personalised marketing, and new product development, which shows your customers you understand them and their needs. Specially built for consumer applications, CIAM platforms can also be scaled to handle millions of interactions. </p><h3 class="article-body__section" id="section-what-benefits-can-my-customers-get-from-ciam"><span>What benefits can my customers get from CIAM?</span></h3><p>As a direct result of the increased visibility for businesses, customers will, of course, have interactions that are more relevant to them and actually serve their specific needs. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/356003/customer-experience-top-opportunity-for-growth" data-original-url="/marketing-comms/customer-experience-cx/356003/customer-experience-top-opportunity-for-growth">Why customer experience is a top opportunity for growth</a></p></div></div><p>They also get frictionless access across any device using single sign-on or social login. </p><p>Through a CIAM platform, their data is better protected through multi-factor authentication (MFA), threat detection, and password backlists, and it’s easy for them to manage consent for how their data can be used or ask to be removed from systems. </p><h3 class="article-body__section" id="section-how-do-i-choose-a-ciam-solution"><span>How do I choose a CIAM solution? </span></h3><p>Given the complexity of managing customer identity, most businesses choose to use a Identity-as-a-Service provider instead of developing a platform in-house. Choosing the right platform is key to achieving the full breadth of benefits of CIAM, so here are several things to keep in mind when you begin your search. </p><p>First of all, the platform must operate consistently across all applications and devices and it should integrate with existing <a href="https://www.itpro.com/desktop-software/28214/what-is-crm" data-original-url="https://www.itpro.com/desktop-software/28214/what-is-crm">CRM</a> systems, marketing platforms, <a href="https://www.itpro.com/marketing-comms/e-commerce/360194/over-two-thirds-of-b2b-sellers-plan-to-adopt-self-service-tools" data-original-url="https://www.itpro.com/marketing-comms/e-commerce/360194/over-two-thirds-of-b2b-sellers-plan-to-adopt-self-service-tools">e-commerce</a> platforms, <a href="https://www.itpro.com/marketing-comms/content-management-system-cms/355086/how-to-deploy-a-modern-cms-quickly" data-original-url="https://www.itpro.com/marketing-comms/content-management-system-cms/355086/how-to-deploy-a-modern-cms-quickly">content management systems</a>, data management platforms, and more. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="46MS25Ne58gQYeTNcHoXhW" name="46MS25Ne58gQYeTNcHoXhW.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" mos="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>From zero to hero: The path to CIAM maturity</strong></p><p class="fancy-box__body-text">Your guide to the CIAM journey</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity" data-original-url="/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity">FREE DOWNLOAD</a></p></div></div><p>It also needs to bring together the data collected from these touchpoints into one unified database, but with flexibility that allows you to collect what’s most relevant to your brand.</p><p>Without these two points, you won’t be able to get the comprehensive view of your customers that’s so vital to delivering great experiences and growing revenue. </p><p>And, of course, you’ll want to make sure your chosen platform has built-in features for data regulation compliance and data breaches to keep customers’ personal information secure. It must be built to withstand all types of attacks, from denial-of-service attacks (DoS) to fraudsters using stolen identities, and also encrypt data on the back end to keep data safe in the event of an attack getting through. It also needs to meet government regulations like GDPR and CCPA. </p><p>Many CIAM platforms are cloud-based, which offers scalability and reliability and cost savings compared to on-premises, but you’ll still need to integrate this platform with other systems that are on-premises, so a hybrid architecture may be the best option. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Virginia passes consumer data protection law ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/358769/virginia-passes-consumer-data-protection-law</link>
                                                                            <description>
                            <![CDATA[ Eastern state follows California in offering consumers opt-out for data processing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9sezFEwxTxvMLPn8Tzm6Pn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hYu3dGUgStwJ5RUxqJcdhG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Mar 2021 17:51:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hYu3dGUgStwJ5RUxqJcdhG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Virginia Capitol Building]]></media:description>                                                            <media:text><![CDATA[Virginia Capitol Building]]></media:text>
                                <media:title type="plain"><![CDATA[Virginia Capitol Building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hYu3dGUgStwJ5RUxqJcdhG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Yesterday, Virginia became the second state to pass a consumer data protection law, forcing companies to give consumers the right to opt out of data collection. Governor Ralph Northam signed the <a href="https://lis.virginia.gov/cgi-bin/legp604.exe?ses=212&typ=bil&val=HB2307">Consumer Data Protection Act</a> into law on Tuesday. </p><p>The law, which Virginia's General Assembly passed last month, allows consumers to confirm whether a company is holding their data and access it using an automated system. The system allows them to retrieve it in a portable format, making it possible to send it to another company. </p><p>Users can amend inaccuracies in the data or force the company to delete it altogether. They can also prevent companies from using the data for marketing or other purposes.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">What is the California Consumer Privacy Act (CCPA)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/34797/microsoft-commits-to-honouring-california-consumer-privacy-act-nationwide" data-original-url="/policy-legislation/34797/microsoft-commits-to-honouring-california-consumer-privacy-act-nationwide">Microsoft commits to honouring California Consumer Privacy Act nationwide</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite" data-original-url="/data-management/33555/microsoft-simplifies-data-privacy-for-365-suite">Microsoft simplifies data privacy for 365 suite</a></p></div></div><p>Companies must respond to consumer requests within 45 days but may extend that period by an additional 45 days based on request complexity, as long as they inform the individual and explain the delay. The company must fulfill up to two free annual requests from an individual, but they may charge for additional requests.</p><p>Organizations must disclose what they'll use an individual's data for and must limit their personal data collection to those purposes. They must also explain which third parties they'll share the data with and what they'll do with it.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TB3FVQbc9CYRryV2rhU7R" name="TB3FVQbc9CYRryV2rhU7R.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TB3FVQbc9CYRryV2rhU7R.jpg" mos="https://cdn.mos.cms.futurecdn.net/TB3FVQbc9CYRryV2rhU7R.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Edge-enabled mobility of the future</strong></p><p class="fancy-box__body-text">Turning vehicle data into value</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/358699/edge-enabled-mobility-of-the-future" data-original-url="/business-strategy/data-insights/358699/edge-enabled-mobility-of-the-future">FREE DOWNLOAD</a></p></div></div><p>Consumers can opt out of personal data collection and the sale of data to third parties. However, the company can choose not to offer consumers goods or services if it needs the opted-out data to provide the service.</p><p>The law, which goes into effect on January 1, 2023, affects companies holding personal data for at least 100,000 consumers or those holding at least 25,000 individuals’ personal data and make more than half their income selling that data. </p><p>Companies violating the law face civil penalties of up to $7,500 per affected individual, but they can escape those penalties if they fix the problem within 30 days of Virginia notifying them. All penalties collected will go to a Consumer Privacy Fund established by Virginia, which will support enforcement of the Act.</p><p>The Act doesn’t define new data breach notification rules, instead referring to <a href="http://law.lis.virginia.gov/vacode/18.2-186.6">existing rules</a> in the state's legal code.</p><p>The legislation now goes to Virginia's Joint Commission on Technology and Science to evaluate how to implement it and release a study by November.</p><p>This is the second such law to pass in the US. California's approval of the <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California Consumer Protection Act (CCPA)</a> went into effect last year. There’s still no cohesive federal consumer data protection law, which <a href="https://www.itpro.com/policy-legislation/data-protection/354642/majority-of-americans-now-want-a-national-data-protection" data-original-url="https://www.itpro.com/policy-legislation/data-protection/354642/majority-of-americans-now-want-a-national-data-protection">four in five Americans want</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers steal 70GB of data from far-right social network Gab ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/social-media/358744/hackers-steal-70-gb-of-data-from-far-right-social-network-gab</link>
                                                                            <description>
                            <![CDATA[ The stolen data contains nearly 100,000 private messages from Gab users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c1dNbh1juNjsJQttNDJWdt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rxGK4GLxQkwSGVMNcznV9X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Mar 2021 17:35:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rxGK4GLxQkwSGVMNcznV9X-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gab splash screen on a smartphone]]></media:description>                                                            <media:text><![CDATA[Gab splash screen on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Gab splash screen on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rxGK4GLxQkwSGVMNcznV9X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Far-right social network Gab is investigating the alleged theft of 70GB of data containing over 40 million posts from its website.</p><p>The hacking group Distributed Denial of Secrets (DDoSecrets) <a href="https://ddosecrets.com/wiki/GabLeaks">reported</a> the incident on Sunday. The person said to have taken the information goes by JaXpArO and the My Little Anonymous Revival Project. According to DDoSecrets, the data contains public and private posts, along with hashed user passwords, direct messages, and plain text passwords for groups. It also contains over 70,000 messages from over 19,000 chats.</p><p>DDoSecrets claimed no responsibility for the hack and said it’s merely reporting it and distributing information to the appropriate parties. It’s also limiting its distribution to journalists and researchers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts" data-original-url="/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts">Social media firms clamp down on hacked accounts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358326/the-fate-of-parler-exposes-reality-of-deregulated-social-media" data-original-url="/business/policy-legislation/358326/the-fate-of-parler-exposes-reality-of-deregulated-social-media">The fate of Parler exposes the reality of deregulated social media</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/355846/president-trump-signs-executive-order-targeting-social-media" data-original-url="/marketing-comms/social-media/355846/president-trump-signs-executive-order-targeting-social-media">President Trump signs executive order targeting social media companies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357437/new-york-twitter-hack-social-media-regulator" data-original-url="/security/357437/new-york-twitter-hack-social-media-regulator">New York finance watchdog says Twitter hack proves social media should be regulated</a></p></div></div><p>The hacker retrieved the information via a <a href="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work" data-original-url="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work">SQL injection attack</a>, in which an attacker enters commands in the SQL injection language to an online form or via URL parameters. These attacks, which are part of a general injection attack class <a href="https://owasp.org/www-project-top-ten">listed</a> as the No. 1 form of web application attack by the Open Source Web Application Security Project (OWASP), and attackers have been exploiting them for over a decade.</p><p>"We were aware of a vulnerability in this area and patched it last week. We are also proceeding to undertake a full security audit," said Gab CEO Andrew Terba in a <a href="https://web.archive.org/web/20210227011738/https:/news.gab.com/2021/02/26/alleged-data-breach-26-february-2021" data-original-url="https://web.archive.org/web/20210227011738/https://news.gab.com/2021/02/26/alleged-data-breach-26-february-2021">blog post</a> about the incident. "We do not currently have independent confirmation that such a breach has actually taken place and are investigating."</p><p>Terba added that while the company hashes passwords, it doesn't encrypt them in groups, where passwords "are meant to be shared for users to join with.” The site no longer supports direct messaging functionality, he said.</p><p>Gab is an extreme far-right <a href="https://www.itpro.com/technology/social-media" data-original-url="https://www.itpro.com/tags/social-media">social network</a> launched in May 2017. Paypal, GoDaddy, and Medium all banned Gab after one of its members posted an antisemitic message on the site before killing 11 people at a synagogue in October. Its hosting provider Joyent also booted the site from its servers. Gab later found a home with hosting service Epik.</p><p>DDoSecrets posted some analysis of the Gab data and found a marked rise in new Gab users just after Amazon kicked conservative social network Parler off its servers. New users jumped from a little under 50,000 on January 8 to around 450,000 on January 10, the figures show. Parler also suffered a <a href="https://www.itpro.com/marketing-comms/social-media/358294/parler-suffers-data-leak-before-being-taken-offline" data-original-url="https://www.itpro.com/marketing-comms/social-media/358294/parler-suffers-data-leak-before-being-taken-offline">hack</a> in January, and the lone attacker exfiltrated 70 TB of data.</p><p>DDoSecrets is a successor to the secrets-leaking site Wikileaks. Active since 2018, DDoSecrets gained notoriety last June for <a href="https://www.itpro.com/security/data-breaches/356169/blueleaks-activists-publish-269gb-of-hacked-us-police-force-data" data-original-url="https://www.itpro.com/security/data-breaches/356169/blueleaks-activists-publish-269gb-of-hacked-us-police-force-data">BlueLeaks</a>, the publication of US law enforcement officers’ data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>