<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/privacy" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Privacy ]]></title>
                <link>https://www.itpro.com/security/privacy</link>
        <description><![CDATA[ All the latest privacy content from the ITPro team ]]></description>
                                    <lastBuildDate>Tue, 27 Jan 2026 11:45:37 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ AI is “forcing a fundamental shift” in data privacy and governance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/ai-is-forcing-a-fundamental-shift-in-data-privacy-and-governance</link>
                                                                            <description>
                            <![CDATA[ Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j2ts9qHpTFsYN7yTaFKsU9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Jan 2026 11:45:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:description>                                                            <media:text><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:text>
                                <media:title type="plain"><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprises are shaking up their approach to data privacy and governance, new research shows, largely due to added risk factors created by <a href="https://www.itpro.com/technology/artificial-intelligence/large-enterprises-could-be-wavering-on-ai-adoption">AI adoption</a>.</p><p>According to Cisco's 2026 <em>Data and Privacy Benchmark Study</em>, nearly all companies are expanding privacy programs and governance frameworks to protect their data. </p><p>AI is the main reason for 90%, with 93% saying they planned further investment to keep up with the complexity of AI systems and the expectations of customers and regulators. </p><p>The survey found that 38% spent at least $5 million on their privacy programs in the past year – marking a dramatic increase from just 14% who spent over that threshold in 2024. </p><p>Notably, these programs appear to be working well. An overwhelming 96% of organizations reported that robust privacy frameworks were helping unlock AI agility and innovation, and 95% said privacy was essential for building customer trust in AI-powered services.</p><p>One interesting change spotted by the researchers is that trust is no longer just a question of meeting regulatory requirements. </p><p><a href="https://www.itpro.com/security/data-protection/fears-over-ai-model-collapse-are-fueling-a-shift-to-zero-trust-data-governance-strategies">Data governance</a> is now seen as a strategic business enabler, with 99% of organizations reporting at least one tangible benefit from their privacy initiatives, such as enhanced agility, innovation, and greater customer loyalty. </p><p>Almost half said that clear communication about how data is collected and used is the most effective way to build customer confidence.</p><p>As a result, governance is evolving – although many organizations are still working to define and establish the structures they need to manage AI responsibly.</p><p>While three-quarters report having a dedicated AI governance body in place, only 12% describe it as mature. Meanwhile, 65% of organizations struggle to access relevant, high-quality data efficiently.</p><p>"<a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>is forcing a fundamental shift in the data landscape, calling for holistic governance of all data – both personal and non-personal,” said Jen Yokoyama, senior vice president, legal innovation and strategy, at Cisco. </p><p>“Organizations must deeply understand and structure their data to ensure every automated decision is explainable. It’s not just for compliance, but a necessary scaling engine for AI innovation.”</p><h2 id="data-requirements-are-causing-headaches">Data requirements are causing headaches</h2><p>While 72% of respondents were generally positive about data privacy laws, there is a growing push to streamline and update data requirements, Cisco found.</p><p>Just over eight-in-ten organizations surveyed face heightened demand for data localization and global data complexity - and 85% said this adds cost, complexity, and risk to cross-border service delivery. #</p><p>Similarly, 77% report these requirements limit their ability to offer seamless 24/7 service across markets.</p><p>On top of this, the assumption that locally stored data is inherently more secure is gradually eroding, from 90% in 2025 to 86% in 2026.</p><p>“To capture the potential of AI, organizations (83%) are advocating for a shift toward harmonized international standards,” said Harvey Jang, Cisco vice president and chief privacy officer. </p><p>“They recognize that global consistency is an economic necessity to ensure data can flow securely while maintaining the high standards of protection required for trust.”</p><p>Cisco said enterprises should invest in robust data infrastructure, prioritizing transparency, and embedding security and privacy throughout AI initiatives. </p><p>Elsewhere, they should make sure they're making informed decisions about data localization, establish strong <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">AI governance</a>, and kit out their teams with comprehensive training and safeguards. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 26% of privacy professionals expect a “material privacy breach” in 2026 as budget cuts and staff shortages stretch teams to the limit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/26-percent-of-privacy-professionals-expect-a-material-privacy-breach-in-2026-as-budget-cuts-and-staff-shortages-stretch-teams-to-the-limit</link>
                                                                            <description>
                            <![CDATA[ Overworked, underfunded privacy teams are being left hung out to dry by executives ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GhEZMSNNwfTA7nEPTVe6dh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z965G2Zb9Pp5avc9gVoTx9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Jan 2026 17:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z965G2Zb9Pp5avc9gVoTx9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male and female data privacy professionals looking at a desktop computer monitor in an office space, with charts and figures pictured on wall behind.]]></media:description>                                                            <media:text><![CDATA[Male and female data privacy professionals looking at a desktop computer monitor in an office space, with charts and figures pictured on wall behind.]]></media:text>
                                <media:title type="plain"><![CDATA[Male and female data privacy professionals looking at a desktop computer monitor in an office space, with charts and figures pictured on wall behind.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z965G2Zb9Pp5avc9gVoTx9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In January 2025, research from ISACA warned that <a href="https://www.itpro.com/security/privacy/data-privacy-professionals-are-severely-underfunded-and-its-only-going-to-get-worse"><u>organizations were deprioritizing privacy budgets and cutting funds</u></a> for teams. One year on and the situation has deteriorated further, the association claims. </p><p>A confluence of challenges, including funding cuts, staff shortages, and growing regulatory compliance pressures are pushing teams to their limits. </p><p>Nearly half (44%) of European-based survey respondents told ISACA their teams are already underfunded while 54% expect budgets to be cut further across 2026. </p><p>Around four-in-ten (39%) legal privacy workers and over half (51%) of technical privacy workers also reported staff shortages across their teams. </p><p>These funding cuts could have severe consequences further down the line, the association warned, especially as organizations continue ramping up adoption of AI tools.</p><p>Nearly half (49%) of respondents revealed that managing risks associated with emerging technologies is now a major obstacle to their long-term strategies. The pace of technological change is also having a marked impact on morale and workloads, with more than one-third (68%) highlighting this as a key challenge. </p><p>Adding insult to injury, 64% identified compliance-related challenges off the back of new technologies as a key stress driver, with teams forced to pivot rapidly to accommodate for regulations. </p><p>Chris Dimitriadis, global chief strategy officer at ISACA, said the study shows privacy teams are now being asked to “manage more risk with fewer resources” – and the impact is beginning to show across Europe. </p><p>“As organizations adopt new technologies at speed, the volume and complexity of privacy obligations grow in parallel – yet many teams are still operating without the staffing, funding or training they need to keep pace,” he commented. </p><h2 id="privacy-teams-are-bracing-for-impact">Privacy teams are bracing for impact</h2><p>Privacy teams are frightfully aware of the potential risks associated with understaffing and budget cuts – it’s a trend they’ve contended with for several years now, the study noted.</p><p>Notably, many teams are bracing for impact as the effects of these trends come to fruition. More than one-quarter (26%) of respondents told ISACA their organization is “likely to experience a material privacy breach” within the next year.</p><p>“Together, this highlights a growing contradiction for European organizations: privacy risk and regulatory expectations continue to rise, while investment in people and resources is being scaled back,” ISACA said in a statement.</p><h2 id="boards-still-aren-t-tuned-in">Boards still aren’t tuned in</h2><p>Despite repeated calls for heightened support, privacy professionals still feel board-level attention is “inconsistent”. Just over one quarter (26%) of respondents said their board is “failing to adequately prioritize privacy” regardless of intensified risks.</p><p>“When boards underestimate privacy, they underestimate a fundamental pillar of digital trust,” Dimitriadis said. “A single privacy breach can erode years of brand equity, damage customer relationships and trigger significant regulatory consequences. </p><p>“Prioritizing privacy is not simply a compliance requirement; it is a business imperative.”</p><p>There are positives with regard to privacy awareness, however. The potential monetary penalties associated with regulatory compliance failures mean executives are beginning to pay attention. </p><p>More than three quarters (79%) of respondents in Europe said they now use a framework or regulation such as GDPR to “guide their privacy program”. </p><p>64% now have a formal <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response plan</a> embedded within their broader privacy strategies, a figure which ISACA said could be improved upon. </p><p>However, nearly half (44%) of respondents said the board views their privacy programs as merely “compliance-driven” and not from a holistic perspective. </p><p>ISACA warned this is a “narrow focus” which fails to fully address privacy-related risks, thereby leaving organizations exposed. </p><p>“These gaps underline a critical truth: privacy cannot be strengthened solely through controls or checklists,” Dimitriadis commented.  “It demands sustained investment in people, governance and culture – and that begins at the top.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU lawmakers want to limit the use of ‘algorithmic management’ systems at work ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/eu-lawmakers-want-to-limit-the-use-of-algorithmic-management-systems-at-work</link>
                                                                            <description>
                            <![CDATA[ All workplace decisions should have human oversight and be transparent, fair, and safe, MEPs insist ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wmC5cfiUeRywWwRyUaNThT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 10:32:17 +0000</pubDate>                                                                                                                                <updated>Thu, 18 Dec 2025 10:33:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:description>                                                            <media:text><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:text>
                                <media:title type="plain"><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MEPs are calling on the European Commission to establish more robust rules on the use of algorithms in recruitment and staff management amidst concerns over privacy and discrimination.</p><p>According to recent <a href="https://www.europarl.europa.eu/RegData/etudes/STUD/2025/774670/EPRS_STU(2025)774670_EN.pdf" target="_blank"><u>EU research</u></a>, 42% of EU workers are currently subject to algorithmic management in the workplace, a figure expected to rise to 55.5% within the next five years.</p><p>There's already legislation on artificial intelligence and data protection at EU level, including the <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">EU AI Act</a> and <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, while rules focusing more specifically on the use of AI at work are laid out in the Platform Work Directive.</p><p>However, the EU lawmakers believe that more specific legislation is required. It has now proposed a series of recommendations aimed at ensuring that the use of automated monitoring and decision-making systems in the workplace is transparent, fair, and safe.</p><p>The main thrust of the proposals is that there must be human oversight of all decisions taken or supported by algorithmic management systems.</p><p>Workers should have the right to request explanations of any decisions taken or supported by such systems - and, if a worker believes his or her rights to have been infringed, they should have the right to ask for a review. </p><p>If successful, the system in question could be modified or discontinued.</p><p>Decisions on the offer or termination of employment, the renewal or non-renewal of a contract, changes in pay, or disciplinary action should always be taken by a human and be subject to human review.</p><p>"This topic affects both employers and 200 million workers in the EU. A human-centered approach is key, and the rights, safety, and dignity of employers and employees must be strictly respected," said MEP Andrzej Buła. </p><p>"This sends a strong signal: Europe can combine competitiveness with social responsibility. It can support innovative enterprises without sacrificing high standards and employee protection."</p><h2 id="cracking-down-on-algorithmic-management">Cracking down on ‘algorithmic management’</h2><p>A key focus of the crackdown centers on the fact that workers should be informed about how algorithmic management systems impact working conditions, when they're used to take automated decisions, what type of data they collect or process, and how human oversight is ensured. </p><p>MEPs believe workers should be consulted when these systems are used to make decisions affecting pay, evaluation, task allocation or working time. </p><p>Similarly, the use of these systems should respect wellbeing and not put workers' safety or physical or mental health at risk.</p><p>To protect workers’ privacy and data, the proposed rules would ban the processing of data relating to the emotional, psychological or neurological states of employees, as well as their private communications or geolocation outside working hours. </p><p>Elsewhere, the guidelines aim to limit the use of employee data while off-duty, as well as the use of data relating to freedom of association and collective bargaining. </p><p>There were 451 votes in favour of the recommendations and 45 against, with 153 abstentions. The European Commission now has three months to respond, by either informing Parliament on the steps it plans to take, or by giving reasons for a refusal.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Teams is getting a new location tracking feature that lets bosses snoop on staff – research shows it could cause workforce pushback ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/microsoft-teams-is-getting-a-new-location-tracking-feature-that-lets-bosses-snoop-on-staff-research-shows-it-could-cause-workforce-pushback</link>
                                                                            <description>
                            <![CDATA[ A new location tracking feature in Microsoft Teams will make it easier to keep tabs on your colleague's activities – and for your boss to know exactly where you are. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fToMygSPWbzwFtXayzgkdS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Dec 2025 09:45:00 +0000</pubDate>                                                                                                                                <updated>Wed, 10 Dec 2025 12:20:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:description>                                                            <media:text><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new location tracking feature in <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Microsoft Teams</a> will make it easier to keep tabs on your colleague's activities – and for your boss to know exactly where you are. </p><p>Microsoft revealed in September that it was developing a system in Teams to automatically update work locations using <a href="https://www.itpro.com/mobile/28299/how-to-use-chromecast-without-wi-fi">Wi-Fi</a>, as well as noting when a laptop is plugged into a configured desk peripheral such as a monitor. </p><p>The system is designed to help tackle some of the challenges of <a href="https://www.itpro.com/business/careers-and-training/employees-are-dead-set-on-flexible-working-arrangements-three-quarters-would-turn-down-a-role-that-didnt-offer-hybrid-options-as-work-life-balance-becomes-more-important-than-pay">hybrid working</a>, when co-workers might be in the office or working from home at different times. </p><p>Once this update rolls out, Teams will automatically display location information, rather than leaving colleagues guessing as to whether their coworker's status has been updated and forcing employees to constantly check in with each other. </p><p>"When users connect to their organization's Wi-Fi, Teams will soon be able to automatically update their work location to reflect the building they're working from," Microsoft said in a <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?searchterms=when+users+connect+to+their+organization%27s+Wi-Fi" target="_blank"><u>support document</u></a>.</p><p>That means when you're in the office, Teams will know and share that information, making it easier for fellow workers to track you down for some vital in-person collaboration business leaders have been <a href="https://www.itpro.com/business/business-strategy/pushing-staff-back-to-the-office-you-may-want-to-reconsider-return-to-office-mandates-harm-employee-productivity-and-retention">pushing for over the last three years</a>.</p><p>However, it'll also be clear when you're not in the office – though the company hasn't revealed details beyond that – and make it harder to dodge interruptions when you are in the office. </p><h2 id="how-microsoft-teams-location-tracking-works">How Microsoft Teams location tracking works</h2><p>The full system is expected to start rolling out in February next year, an apparent delay to earlier plans to begin pushing the feature out this month. </p><p>"Automatic detection of work location by plugging into peripherals at a desk is available now," Microsoft noted in a <a href="https://learn.microsoft.com/en-us/microsoft-365/places/configure-auto-detect-work-location"><u>support document</u></a>. "Automatic detection of work location using a wireless network connection is currently in preview and will be widely available in the near future."</p><p>The system will either display that the user is "in the office" or list a specific building, depending on how it's configured and what users have consented to. </p><p>Microsoft has clearly recognized that this feature will raise concerns of workplace surveillance. Indeed, the auto-updating location system has to be actively turned on. </p><p>"This feature will be off by default," the company said in an explainer document. "Tenant admins will decide whether to enable it and require end-users to opt-in."</p><p>Of course, if your manager requires you to turn it on, most employees will feel pressured to comply, but Microsoft stressed "it is not possible for admins to consent on users' behalf."</p><p>With an eye on privacy and work-life balance, Microsoft added that the system only operates during working hours.</p><p>"The detected work location lasts until the end of a user's working hours. If users connect after their set work hours, their work locations are not set."</p><h2 id="workplace-monitoring">Workplace monitoring</h2><p>The shift to hybrid working has <a href="https://www.itpro.com/business/business-strategy/bossware-employee-monitoring-workforce-morale-impact">sparked a rise in workplace monitoring</a> as managers seek to maintain some sense of oversight of employees and their work efforts, as well as to track when they're in the office. </p><p>Research suggests about a <a href="https://www.itpro.com/business/business-strategy/bossware-employee-monitoring-workforce-morale-impact">third of companies are using "bossware" of some sort</a> to monitor staff working in the office or remotely. The issue has become a flashpoint for workers in recent years, and research shows that it’s reaching boiling point.</p><p>A survey in late 2024 found these practices are harming workforce morale, with three-quarters of respondents <a href="https://www.itpro.com/security/privacy/workplace-monitoring-is-still-out-of-control-but-some-staff-are-fighting-back">claiming they stopped trusting their employer</a> after monitoring tools were introduced. </p><p>Last year, <a href="https://www.itpro.com/security/privacy/your-office-is-now-absolutely-riddled-with-surveillance-equipment"><u>research revealed that wireless networking equipment</u></a> was being used to track employees throughout office buildings by making use of Bluetooth enabled badges, cameras, and even video conferencing systems.</p><p>Intriguingly, the <a href="https://www.itpro.com/business/business-strategy/microsoft-could-be-preparing-for-a-crackdown-on-remote-work"><u>feature is set to arrive as Microsoft</u></a> is apparently planning to tighten up its own hybrid working policies, requiring staff to come into the office more. </p><p>As <em>ITPro </em>reported in August, per reports from <a href="https://www.businessinsider.com/microsoft-considering-stricter-rto-policy-2025-8" target="_blank"><u><em>Business Insider</em></u></a>, the tech giant will introduce stricter rules for office attendance in the new year. </p><p>The move comes amidst a sharpened focus on workforce productivity at the company, although the crackdown won’t represent a complete <a href="https://www.itpro.com/business/business-strategy/what-are-return-to-office-mandates-rto">return to office (RTO) mandate</a>. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/salesforce-says-microsofts-anticompetitive-tying-of-teams-harmed-business-in-triumphant-response-to-eu-concessions-agreement">Salesforce says ‘Microsoft’s anticompetitive tying of Teams' harmed business</a></li><li><a href="https://www.itpro.com/security/cyber-crime/hackers-have-been-posing-as-it-support-on-microsoft-teams">Hackers have been posing as IT support on Microsoft Teams</a></li><li><a href="https://www.itpro.com/software/microsoft-teams-users-have-been-begging-for-this-convenient-slack-feature-now-the-company-has-answered">Microsoft Teams just added a convenient new feature you can find in Slack</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Hugely significant’: Experts welcome UK government plans to back down in Apple encryption battle – but it’s not quite over yet  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/hugely-significant-experts-welcome-uk-government-plans-to-back-down-in-apple-encryption-battle-but-its-not-quite-over-yet</link>
                                                                            <description>
                            <![CDATA[ Tulsi Gabbard, US director of national intelligence, has confirmed the UK plans to back down on plans that would see Apple forced to create a "back door" for authorities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FYhPpfoJ4SVj8qTspUMHmH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Aug 2025 10:22:27 +0000</pubDate>                                                                                                                                <updated>Tue, 19 Aug 2025 10:24:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:description>                                                            <media:text><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government is reportedly planning to back down on plans to force Apple to share user data. </p><p>Tulsi Gabbard, US director of national intelligence, confirmed the move in a <a href="https://x.com/DNIGabbard/status/1957623737232007638" target="_blank"><u>post on X,</u></a> revealing that Downing Street will withdraw plans which would see Apple required to provide a “back door” to access user data. </p><p>“Over the past few months, I’ve been working closely with our partners in the UK, alongside @POTUS and @VP, to ensure Americans’ private data remains private and our Constitutional rights and civil liberties are protected,” Gabbard wrote. </p><p>“As a result, the UK has agreed to drop its mandate for Apple to provide a “back door” that would have enabled access to the protected encrypted data of American citizens and encroached on our civil liberties.”</p><p>The decision to back down follows a months-long war of words between Apple and the UK government over the tech giant’s Advanced Data Protection (ADP) tool, a feature that uses end-to-end encryption and allows users to protect personal data. </p><p>The feature even prevents Apple from accessing personal information. </p><p>In December last year, the government filed a format notice <a href="https://www.itpro.com/business/policy-and-legislation/uk-governments-attempt-to-strongarm-apple-into-backdoor-adp-is-a-travesty"><u>demanding that Apple grant authorities the right to access encrypted data</u></a>. This was applicable to users globally, and not specifically in the UK. </p><p>The order sparked widespread criticism at the time from privacy experts and industry stakeholders. Legal experts warned that the move could harm industry perception of the UK, noting that the country would “no longer be seen as a safe destination for personal data”. </p><p>In response, Apple refused to comply and announced plans to remove access to ADP for UK users. The tech giant began legal proceedings to challenge the demand. </p><p>“As we have said many times before, we have never built a backdoor or master key to any of our products or services and we never will,” the company said in a <a href="https://support.apple.com/en-gb/122234" target="_blank"><u>statement </u></a>at the time.</p><h2 id="apple-u-turn-hugely-significant-for-uk-government">Apple u-turn “hugely significant” for UK government</h2><p>The UK government is yet to confirm the decision to back down, however, the rumored decision has been welcomed by security experts. </p><p>Charlotte Wilson, head of enterprise at Check Point Software, said the decision to withdraw the demand is “hugely significant”. </p><p>“Once you create a master key to encrypted data, it is not just governments that can use it,” she said. “Criminal groups and hostile states will try to exploit it too.”</p><p>Wilson added that breaking encryption “not only weakens privacy, but also weakens security for everyone.”</p><p>The Apple order was issued under the Investigatory Powers Act, which means orders issued to other companies are essentially shrouded in secrecy. </p><p>Wilson said there are still concerns that these powers “remain on the statute books”, meaning that future governments may attempt a similar move in the future. </p><p>“Even if this particular demand has been withdrawn, the Investigatory Powers Act still allows future governments to try again,” she said. </p><p>“That leaves citizens, campaigners, and businesses in a state of uncertainty about whether the tools that protect their data could be undermined at any point.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy">NCSC expert urges businesses to follow geopolitics as defensive strategy</a></li><li><a href="https://www.itpro.com/security/encryption/the-encryption-stand-off-is-getting-weirder">The encryption stand-off is getting weirder</a></li><li><a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Perplexity hits back at Cloudflare amid claims of website 'stealth crawling' to dodge AI blocks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/perplexity-hits-back-at-cloudflare-amid-claims-of-website-stealth-crawling-to-dodge-ai-blocks</link>
                                                                            <description>
                            <![CDATA[ Perplexity has hit back at claims by Cloudflare that it's been stealthily crawling websites, suggesting recent research was a "sales pitch" for a new blocking product. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vFQj9Y9afqoHddNfyQfn7A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fQWXQDcyzua2pePWLh4PUZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Aug 2025 08:21:39 +0000</pubDate>                                                                                                                                <updated>Wed, 06 Aug 2025 11:53:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fQWXQDcyzua2pePWLh4PUZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Perplexity AI, developer of the Perplexity Labs, Deep Research, and AI-powered browser tools, pictured on a smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Logo of Perplexity AI, developer of the Perplexity Labs, Deep Research, and AI-powered browser tools, pictured on a smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Perplexity AI, developer of the Perplexity Labs, Deep Research, and AI-powered browser tools, pictured on a smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fQWXQDcyzua2pePWLh4PUZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloudflare has accused Perplexity of failing to honour requests from websites to opt out of content scraping by AI companies. </p><p>Last month, the web infrastructure company <a href="https://www.itpro.com/technology/artificial-intelligence/cloudflare-says-ai-companies-have-been-scraping-content-without-limits-now-its-letting-website-owners-block-crawlers-by-default"><u>announced a system to block AI companies</u></a> from accessing websites without permission or compensation. The move came as part of a push back against AI companies hoovering up the entire internet to use as training data — a tactic that has sparked lawsuits. </p><p>Cloudflare's system lets online publishers and other website owners block AI crawlers from seeing their content, with future plans to only allow those who have paid to scrape. </p><p>Several weeks into the blocking system, Cloudflare has reported that AI company Perplexity is using evasive techniques to access that content regardless. In a <a href="https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/"><u>blog post</u></a> this week, the firm said Perplexity changes how it presents itself to a website when it spots a block. </p><p>"Although Perplexity initially crawls from their declared user agent, when they are presented with a network block, they appear to obscure their crawling identity in an attempt to circumvent the website’s preferences," the post noted. </p><p><em>ITPro </em>contacted Perplexity for a statement, but had received no response at time of publication. A spokesperson for the firm told <a href="https://techcrunch.com/2025/08/04/perplexity-accused-of-scraping-websites-that-explicitly-blocked-ai-scraping/" target="_blank"><u><em>TechCrunch</em></u></a><em> </em>that the Cloudflare research was a "sales pitch" for the blocking product and said that the bot discussed "isn't even ours." </p><p>In a separate statement to <a href="https://www.theverge.com/news/718319/perplexity-stealth-crawling-cloudflare-ai-bots-report" target="_blank"><u><em>The Verge</em></u></a>, the company said Cloudflare's report was a "publicity stunt" and that there were "a lot of misunderstandings in the blog post". </p><p>It's not the first time Perplexity has been accused of letting its bots crawl where they're not wanted. Reports from <a href="https://www.wired.com/story/aws-perplexity-bot-scraping-investigation/"><u>Wired</u></a> spotted such behavior last year while <a href="https://www.niemanlab.org/reading/forbes-threatens-perplexity-ai-with-legal-action-over-copyright-infringement/"><u>Forbes</u></a>, the <a href="https://techcrunch.com/2024/10/15/new-york-times-sends-perplexity-cease-and-desist-letter-demands-it-stops-using-its-content-in-ai-summaries/"><u>New York Times</u></a>, and the <a href="https://www.ft.com/content/b743d401-dc5d-44b8-9987-825a4ffcf4ca"><u>BBC</u></a> accused the company of scraping and reproducing their content without permission.</p><p>Perplexity has denied the accusations. </p><h2 id="what-cloudflare-claims">What Cloudflare claims</h2><p>Cloudflare said it saw "continued evidence" that Perplexity's user agent is changing their user agent and the source where it's coming from to hide this activity, and even ignoring or failing to view the "robot.txt" files — these are a list of instructions for bots telling them what to access and not, used for search crawlers and now AI agents. </p><p>After hearing complaints from customers who had tried to block AI crawlers, Cloudflare set up a series of experiments using brand-new test websites that were not publicly accessible, with a robots.txt file directing "respectful bots from accessing any part of a website." </p><p>Cloudflare then asked Perplexity AI questions about the domains, and found it was able to access detailed information from the restricted test sites. </p><p>"This response was unexpected, as we had taken all necessary precautions to prevent this data from being retrievable by their crawlers," the post noted. </p><p>Cloudflare said Perplexity is not only using a declared user agent, but also a generic browser that impersonates Chrome on macOS when the declared agent is blocked. </p><p>For comparison, Cloudflare ran similar tests with OpenAI's ChatGPT, finding it fetched the robots.txt file and stopped crawling when told not to access a page; when there were no instructions in the robots.txt file but there was a block page, ChatGPT again stopped crawling. </p><p>"Both of these demonstrate the appropriate response to website owner preferences," Cloudflare said. </p><h2 id="danger-to-the-internet">Danger to the internet?</h2><p>Cloudflare said that this behavior risks the network of trust that holds up the internet. </p><p>"There are clear preferences that crawlers should be transparent, serve a clear purpose, perform a specific activity, and, most importantly, follow website directives and preferences," the post said. </p><p>The company added that it would now block the AI company from websites using its service. </p><p>"Based on Perplexity’s observed behavior, which is incompatible with those preferences, we have de-listed them as a verified bot and added heuristics to our managed rules that block this stealth crawling," the post added. </p><p>Calling on AI companies to behave better, Cloudflare said "well-intentioned crawlers acting in good faith" should be transparent and identify the agent honestly, and not attempt to dodge detection by sites attempting to block such access. </p><p>For sites that do allow access, AI crawlers should behave fairly and not flood sites with too much traffic or scrape sensitive data, and serve a "clear purpose" — such as checking a price or powering a voice assistant.</p><p>Cloudflare also suggested AI companies use separate web crawlers for each activity, letting website owners more easily allow some crawler activity but not others. "Don’t force site owners to make an all-or-nothing decision," the post said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/a-threat-to-googles-dominance-the-ai-browser-wars-have-begun-here-are-the-top-contenders-vying-for-the-crown">A threat to Google’s dominance? The AI browser wars have begun – here are the top contenders vying for the crown</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/perplexity-labs-ai-automation-tools">Sick and tired of spreadsheets? Perplexity’s new tools can help with that</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/perplexity-ai-a-startup-that-just-raised-dollar736-million-from-nvidia-and-databricks-wants-to-take-on-googles-search-engine-dominance">Perplexity AI, a startup that just raised $73.6 million from Nvidia and Databricks, wants to take on Google's search engine</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of 23andMe users’ genetic data could be up for grabs – and experts worry it’s a looming privacy nightmare ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/23andme-bankruptcy-privacy-concerns</link>
                                                                            <description>
                            <![CDATA[ DNA testing company 23andMe has filed for bankruptcy protection, raising questions about the future of the company and the personal data it holds. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QDezX5xy3G6ZsmSMBHtdnS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KrtqKby2JR8CUvUxgvTFQ4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Mar 2025 11:20:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KrtqKby2JR8CUvUxgvTFQ4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[23andMe logo and branding pictured on a sign outside the company headquarters in Sunnyvale, California.]]></media:description>                                                            <media:text><![CDATA[23andMe logo and branding pictured on a sign outside the company headquarters in Sunnyvale, California.]]></media:text>
                                <media:title type="plain"><![CDATA[23andMe logo and branding pictured on a sign outside the company headquarters in Sunnyvale, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KrtqKby2JR8CUvUxgvTFQ4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>DNA testing company <a href="https://www.itpro.com/security/data-breaches/23andme-risks-public-relations-disaster-as-it-blames-customers-for-data-breach">23andMe</a> has filed for bankruptcy protection, raising questions about the future of the company and the personal data it holds.</p><p>The company says it's looking for a sale and hopes to continue as a going concern during the process.</p><p>The announcement follows the resignation of CEO and co-founder Anne Wojcicki after pushing for a buyout that was rejected by the board. She said she now hopes to bid for the company independently.</p><p>"After a thorough evaluation of strategic alternatives, we have determined that a court-supervised sale process is the best path forward to maximize the value of the business," said Mark Jensen, chair and member of the Special Committee of the Board of Directors. </p><p>"We expect the court-supervised process will advance our efforts to address the operational and financial challenges we face, including further cost reductions and the resolution of legal and leasehold liabilities."</p><p>But there's uncertainty about the data that the company holds - the company currently has around 15 million customers, who have mailed in saliva kits to have their genetic makeup analyzed. Many are concerned that the data could be sold off to data brokers or for targeted advertising.</p><p>"The data itself is one of the core assets, and technically that would be of interest to a buyer. However, the terms of use in which that data was provided remain, so it would be up to the bankruptcy court and associated trustees to ensure that those rights are maintained and controlled," commented Jack Berkowitz, chief data officer at Securiti. </p><p>"Ideally, the court appointed trustee has a view and understanding of the sensitivity of the data, the corporate and legal constraints, and the regulatory implications. We have seen such sensitivity around high profile bankruptcies before, such as when FTX went into receivership."</p><h2 id="23andme-facing-intense-data-protection-scrutiny">23andMe facing intense data protection scrutiny</h2><p>The company's handling of personal data is already under investigation by the UK <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> and the Office of the Privacy Commissioner of Canada, <a href="https://www.itpro.com/security/data-breaches/23andmes-disastrous-data-breach-just-landed-it-a-regulatory-probe">following a data breach</a> that was reported in October 2023.</p><p>Earlier this month, the ICO issued a notice of intent to fine the company £4.59 million ($5.94m) along with a preliminary enforcement notice.  </p><p>"We are aware that 23andMe has filed for Chapter 11 bankruptcy in the US to facilitate a sale process. We are monitoring the situation closely and are in contact with the company," said ICO deputy commissioner - regulatory supervision Stephen Bonner. </p><p>"As a matter of UK law, the protections and restrictions of the UK GDPR continue to apply and 23andMe remains under an obligation to protect the personal information of its customers."</p><p>In many parts of the world, users have the right to request the removal of their personal data, and California attorney general Rob Bonta is urging them to do just that. </p><p>"California has robust privacy laws that allow consumers to take control and request that a company delete their genetic data," he said. </p><p>"Given 23andMe’s reported financial distress, I remind Californians to consider invoking their rights and directing 23andMe to delete their data and destroy any samples of genetic material held by the company."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li>INSERT STORY LINK</li><li>INSERT STORY LINK</li><li>INSERT STORY LINK</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ So long, Defender VPN: Microsoft is scrapping the free-to-use privacy tool over low uptake ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/microsoft-defender-vpn-end-of-life</link>
                                                                            <description>
                            <![CDATA[ Defender VPN, Microsoft's free virtual private network, is set for the scrapheap, so you might want to think about alternative services. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">atEDHmd7ppw5Mjwevvadwi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Tb9cfTmBmbFKyZMZsVc9en-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Feb 2025 14:05:00 +0000</pubDate>                                                                                                                                <updated>Sat, 01 Mar 2025 09:47:11 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Tb9cfTmBmbFKyZMZsVc9en-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[VPN concept image showing a desktop computer connected to a VPN with interlinked data points.]]></media:description>                                                            <media:text><![CDATA[VPN concept image showing a desktop computer connected to a VPN with interlinked data points.]]></media:text>
                                <media:title type="plain"><![CDATA[VPN concept image showing a desktop computer connected to a VPN with interlinked data points.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Tb9cfTmBmbFKyZMZsVc9en-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/microsoft-defender-antivirus-review-defender-does-the-job-as-well-as-anything-else">Defender VPN</a>, Microsoft's free <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">virtual private network</a>, is set for the scrapheap – so you might want to think about alternative services.</p><p>As of 28 February, Microsoft will no longer support the free <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN service</a> that had been included in its Defender security app since 2023. </p><p>When the move was announced at the beginning of the month, Microsoft said new installations and reinstallations would not feature the tool. </p><p>Microsoft suggested the removal of the "privacy protection feature" was because the tool wasn't very well used. </p><p>"We routinely evaluate the usage and effectiveness of our features," Microsoft said in a support post. "As such, we are removing the privacy protection feature and will invest in new areas that will better align to customer needs."</p><p>The move follows Google killing off its One VPN last year, also citing low demand. </p><p>Microsoft said it wasn't planning on ending any other Microsoft Defender features, with device protection, identity theft and, in the US, credit monitoring set to continue. </p><h2 id="did-microsoft-do-enough-to-promote-defender-vpn">Did Microsoft do enough to promote Defender VPN?</h2><p>Some commenters online have suggested that the limited take-up was because no-one knew about the VPN — or because the service was seriously limited. </p><p>It wasn't available outside the UK or US, had a strict 50GB monthly data cap, excluded certain apps, and users couldn't choose the server location, meaning it didn't help with accessing geo-restricted content or dodging censors. </p><p>Instead it was pushed as a way to protect privacy when online, such as against man-in-the-middle attacks when using public <a href="https://www.itpro.com/infrastructure/network-internet/369978/ethernet-vs-wifi-why-ethernet-is-better">Wi-Fi</a>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ECLBQyr97xeXJDuEw2TCmN" name="Gaining observability_listing.jpg" caption="" alt="IBM whitepaper Gaining observability in cloud native applications" src="https://cdn.mos.cms.futurecdn.net/ECLBQyr97xeXJDuEw2TCmN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/gaining-observability-in-cloud-native-applications"><em>Create exceptional customer experiences</em></a></p></div></div><p>Anyone who was using the limited VPN will need to find an <a href="https://www.itpro.com/security/27098/best-vpn-services"><u>alternative VPN</u></a>, likely via a paid-for service, but any will come with a wider range of features that Defender's version lacked. </p><p>Microsoft will continue to offer a VPN in one instance, however, mainly for phishing protection on iPhones. </p><p>"Defender for iOS users, please note, web protection (anti-phishing) on iOS uses a VPN to help keep you safer from harmful links," the support document said. </p><p>"You will continue to see a VPN used for the purposes of web protection and this local (loop-back) VPN is different from the privacy protection feature."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dUrfSc4uecJeyngJguAfUU" name="Ransomware Missteps that Can Cost You" caption="" alt="Ransomware Missteps that Can Cost You" src="https://cdn.mos.cms.futurecdn.net/dUrfSc4uecJeyngJguAfUU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: N-Able)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/uk/technology/artificial-intelligence"><em>Discover a four-step approach for responding to ransomware</em></a></p></div></div><p>Anyone with the VPN on Windows, <a href="https://www.itpro.com/software/apple/ios">iOS</a>, and MacOS won't have to take any action, but Android users will need to remove the tool from their VPN settings if they want it to stop being listed as an option. </p><p>"Not removing the Defender VPN profile on your Android device will not cause any impact to your device but it’s recommended to remove it as it won’t be used by Defender to provide protection," the support post noted. </p><h2 id="what-is-the-defender-app">What is the Defender app?</h2><p>Microsoft included the privacy protection VPN for free in the Defender app that comes with <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> Personal or Family subscriptions. </p><p>The Defender app is available across Windows, Android, iOS, and MacOS, and also features a web portal for managing phone and PC protection. </p><p>The app includes antivirus, alerts about malicious websites or suspicious activity, and more, though what's available differs by platform and region. </p><p>This is separate from Windows Security, a set of security tools built directly into Windows, that is formerly known as Windows Defender Security Centre. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">Everything you need to know about VPNs</a></li><li><a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/355071/does-your-business-need-its-own-vpn">Does your business need a VPN?</a></li><li><a href="https://www.itpro.com/software/microsoft-defender-antivirus-review-defender-does-the-job-as-well-as-anything-else">Everything you need to know about Microsoft Defender</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK businesses patchy at complying with data privacy rules ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/uk-businesses-patchy-at-complying-with-data-privacy-rules</link>
                                                                            <description>
                            <![CDATA[ Companies need clear and well-defined data privacy strategies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hHWXdLaLbPPrkzDi2wHQ65</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E6CWYG29ZoytTeEWF72mcS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jan 2025 12:53:32 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Jan 2025 16:14:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/E6CWYG29ZoytTeEWF72mcS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electronic network data security, data protection and electronic technology, financial network security]]></media:description>                                                            <media:text><![CDATA[Electronic network data security, data protection and electronic technology, financial network security]]></media:text>
                                <media:title type="plain"><![CDATA[Electronic network data security, data protection and electronic technology, financial network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E6CWYG29ZoytTeEWF72mcS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Only half of UK businesses are fully complying with all data privacy regulations and industry guidelines - an improvement, but not much of one.</p><p>Research from Zoho Digital found that the figure has risen from 2023's 42%, but that many businesses still need to improve their data practices.</p><p>On the plus side, transparency of data practices emerged as a growing strength, with 50% of respondents saying that their data privacy policies are clear, simple, and transparent, up from just 33% in 2023. </p><p>"According to Zoho’s Digital Health survey, businesses must improve transparency around data usage as a clear step toward ethical behaviour," said Sachin Agrawal, Zoho managing director. </p><p>“This will play an important role in improving customer experience, strengthening customer relationships."</p><p>The survey revealed that 47% of businesses now view data privacy as a critical part of their success, and that 46% conduct regular data privacy training for employees.</p><p>However, it also identified serious gaps where businesses are falling behind. Only three-in-ten businesses reported going beyond requirements to provide additional protection for customer and employee data.</p><p>This, Zoho noted, suggests that while businesses are meeting their compliance requirements, few are taking proactive steps to enhance data protection.</p><p>"In an increasingly data-driven world, organisations must prioritize data privacy throughout their operations. It is encouraging to see the growing recognition of data privacy’s role in driving business policies, but there is still a lot of progress to be made," said Agrawal. </p><p>"To unlock the full transformative potential of technologies like AI, businesses must have clear and well-defined data strategies which both protect customer and employee data but enable flexibility of use in the right way."</p><p>The report comes hot on the heels of research from ISACA, which found only a third of <a href="https://www.itpro.com/security/privacy/data-privacy-professionals-are-severely-underfunded-and-its-only-going-to-get-worse">data privacy professionals are confident in their organization’s ability to safeguard sensitive data</a>, and just a quarter follow Privacy by Design best practices.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4FaxkYpuDpkr6ksE4TzLvU" name="Integrating Copilot With CDW" caption="" alt="Integrating Copilot With CDW" src="https://cdn.mos.cms.futurecdn.net/4FaxkYpuDpkr6ksE4TzLvU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/integrating-copilot-with-cdw"><em>Seamlessly embed AI into your business processes</em></a></p></div></div><p>Their teams underfunded, they said, and more than half told ISACA they expect budgets to decline this year.</p><p>ISACA warned that many organizations risk falling foul of <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and new legal frameworks such as the Digital Services Act and <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>. </p><p>Recently, Charlie Bromley-Griffiths, senior legal counsel at legal document management software form Conga, told <em>ITPro </em>that UK businesses had made substantial strides in aligning with privacy legislation. </p><p>"Companies have implemented stronger data governance policies, enhanced security protocols and prioritized the rights of data subjects," she said. "However, challenges still remain, particularly for small and medium-sized enterprises struggling with the complexity and cost of full compliance."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LinkedIn faces lawsuit amid claims it shared users' private messages to train AI models ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/linkedin-faces-lawsuit-amid-claims-it-shared-users-private-messages-to-train-ai-models</link>
                                                                            <description>
                            <![CDATA[ LinkedIn faces a lawsuit in the US amid allegations that it shared Premium members' private messages to train AI models. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wJswnyirioDyJesUtfqiWM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VTrjsLqC6hEUVUyhWJyB6b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jan 2025 11:47:04 +0000</pubDate>                                                                                                                                <updated>Thu, 23 Jan 2025 15:22:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VTrjsLqC6hEUVUyhWJyB6b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LinkedIn log an branding pictured at the company office in Singapore on Thursday, Oct. 17, 2024]]></media:description>                                                            <media:text><![CDATA[LinkedIn log an branding pictured at the company office in Singapore on Thursday, Oct. 17, 2024]]></media:text>
                                <media:title type="plain"><![CDATA[LinkedIn log an branding pictured at the company office in Singapore on Thursday, Oct. 17, 2024]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VTrjsLqC6hEUVUyhWJyB6b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a US lawsuit filed on behalf of LinkedIn Premium users, the professional networking app has been accused of using members' private messages to train AI models.</p><p>Filed in a California federal court, the <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.443088/gov.uscourts.cand.443088.1.0.pdf" target="_blank"><u>lawsuit</u></a>, on behalf of LinkedIn user Alessandro De La Torre, accuses the company of breaching its contractual promises by disclosing Premium customers' private messages to third parties to train generative AI models.</p><p>"Given its role as a professional social media network, these communications include incredibly sensitive and potentially life-altering information about employment, intellectual property, compensation, and other personal matters," the filing reads.</p><p>"Microsoft is the parent company of LinkedIn, and Defendant claims it disclosed its users’ data to third-party 'affiliates' within its corporate structure, and in a separate instance, more cryptically to 'another provider'. LinkedIn did not have its Premium customers’ permission to do so."</p><p>In a statement given to <em>ITPro</em>, a spokesperson for LinkedIn said: “These are false claims with no merit.”</p><h2 id="the-story-behind-the-linkedin-lawsuit">The story behind the LinkedIn lawsuit</h2><p>The case hinges on the introduction of a <a href="https://www.itpro.com/security/data-protection/linkedin-backtracks-on-controversial-ai-training-rules-after-user-backlash">change to LinkedIn's privacy practices last year</a>, whereby users were opted in by default to allow third parties to use their personal data to <a href="https://www.itpro.com/technology/artificial-intelligence/who-owns-the-data-used-to-train-ai">train AI</a>.</p><p>To start with, according to the lawsuit, this was done on the quiet, with the change only appearing in the company's privacy policy in September following a backlash from users and privacy campaigners.</p><p>The company exempted customers in Canada, the EU, EEA, the UK, Switzerland, Hong Kong, and Mainland China from the data sharing - but not those in the US.</p><p>"Like other features on LinkedIn, when you engage with <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> powered features we process your interactions with the feature, which may include personal data (e.g., your inputs and resulting outputs, your usage information, your language preference, and any feedback you provide)," the company said in its FAQs.</p><p>The change wasn't universally welcomed, however, with the UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> noting that the opt-out approach wasn’t sufficient to protect user privacy. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d2ymnusFNtdbqndKQ6dbrZ" name="Future proof your infrastructure for a competitive advantage" caption="" alt="Future proof your infrastructure for a competitive advantage" src="https://cdn.mos.cms.futurecdn.net/d2ymnusFNtdbqndKQ6dbrZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/future-proof-your-infrastructure-for-a-competitive-advantage"><em>Get a competitive edge in today’s fast-paced landscape</em></a></p></div></div><p>Digital rights campaigners Open Rights Group also complained the opt-out model “proves once again to be wholly inadequate” to protect user rights.</p><p>The lawsuit is asking for compensation of $1,000 per Premium user for alleged violations of the US federal Stored Communications Act, along with an unspecified additional sum for breach of contract and the breach of California's Unfair Competition Law (UCL). </p><p>It also calls for the company to delete all AI models trained using improperly collected data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data privacy professionals are severely underfunded – and it’s only going to get worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/data-privacy-professionals-are-severely-underfunded-and-its-only-going-to-get-worse</link>
                                                                            <description>
                            <![CDATA[ European data privacy professionals say they're short of cash, short of skilled staff, and stressed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QR65poDAWBH9rMCbkvqafC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vJxqmUk7XiBNcAeFAyAHXT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jan 2025 10:55:55 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Jan 2025 14:50:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vJxqmUk7XiBNcAeFAyAHXT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female data privacy professional working on a desktop computer in an office space.]]></media:description>                                                            <media:text><![CDATA[Female data privacy professional working on a desktop computer in an office space.]]></media:text>
                                <media:title type="plain"><![CDATA[Female data privacy professional working on a desktop computer in an office space.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vJxqmUk7XiBNcAeFAyAHXT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/data-protection/data-privacy-will-be-a-critical-enterprise-focus-in-2024-and-generative-ai-has-torn-up-the-rulebook">Data privacy</a> professionals think their organizations are underfunding their work, and there's no light on the horizon as budgets are set to be squeezed further in 2025.</p><p>In a recent survey, more than half told ISACA they expect budgets to decline this year, up from 41% last year. Meanwhile, only a third said they were confident in their organization’s ability to safeguard sensitive data, with just a quarter always practicing Privacy by Design. </p><p>As a result, ISACA warned many organizations risk falling short of compliance with <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and new legal frameworks such as the <a href="https://www.itpro.com/business/policy-and-legislation/how-will-the-digital-services-act-affect-businesses">Digital Services Act</a> and <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>. </p><p>“As the threat landscape continues to evolve in complexity, privacy is becoming a sector which is increasingly difficult to operate in, but also more critical," said Chris Dimitriadis, global chief strategy officer at ISACA. </p><p>"Two-thirds of the European professionals working in privacy roles who we spoke to said their job is more stressful now compared to five years ago. This is only being exacerbated by continued underfunding. While companies may be making a short-term financial gain, they are putting themselves at long-term risk."</p><p>Half of technical data privacy teams in Europe remain understaffed, the survey found, much the same as last year, while a third struggle to retain qualified privacy professionals.</p><p>Those that do always practice Privacy by Design do rather better, with 43% saying their technical data privacy teams are appropriately staffed. Six-in-ten said they were highly confident in their technical privacy teams as a result.</p><p>"Practicing <a href="https://www.itpro.com/security/privacy/368750/brave-pushes-the-boundaries-of-how-to-bake-in-user-privacy">Privacy by Design</a> and embedding privacy across an entire enterprise is key to long-term data protection," Dimitriadis said.</p><p>"Such a comprehensive approach fosters trust with stakeholders and safeguards against ever-evolving threats – but this isn’t possible without skilled privacy teams who feel prepared and able to drive privacy practices from a technology, business and compliance point of view."</p><h2 id="the-data-privacy-skills-gap-is-growing">The data privacy skills gap is growing</h2><p><a href="https://www.itpro.com/business/careers-and-training/the-uk-is-dealing-with-a-chronic-data-skills-shortage-and-its-costing-the-economy-billions-each-year">Skills gaps</a> were also highlighted as a key issue for data privacy professionals, ISACA found. The biggest reported skills gaps were experience with different types of technologies and/or applications, cited by 63% of respondents. </p><p>A lack of technical expertise and IT operations knowledge and skills were also flagged as major concerns. As a result of this shortfall, nearly half of organizations said they offer training to allow staff from non-privacy backgrounds to move into roles in this domain. </p><p>However, it’s experience that’s key to plugging this skills gap, the study noted. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YRwEK7F48t5uqGuzdTnavF" name="SANS™ Institute Product Overview_ Safeguard Your Business-Critical Web Apps and APIs with a WAF" caption="" alt="SANS™ Institute Product Overview: Safeguard Your Business-Critical Web Apps and APIs with a WAF" src="https://cdn.mos.cms.futurecdn.net/YRwEK7F48t5uqGuzdTnavF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/sanstm-institute-product-overview-safeguard-your-business-critical-web-apps-and-apis-with-a-waf"><em>Protect on-premises and cloud application workloads</em></a></p></div></div><p>Nearly all respondents said they consider compliance and legal experience an important factor in determining if a privacy candidate is qualified. Nine-in-ten also consider industry credentials as important, while only 54% said the same about a university degree. </p><p>"There are several ways to <a href="https://www.itpro.com/business-strategy/careers-training/369682/hiring-from-overseas-tech-skills-gap">plug the skills gap</a>," said Dimitriadis. </p><p>"Providing training and continuous support for privacy staff on emerging technologies, privacy-enhancing technologies, and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> and <a href="https://www.itpro.com/security/data-protection">data protection</a> architectures on top of legal compliance knowledge is essential for managing their stress and maintaining organizational resilience."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Your office is now absolutely riddled with surveillance equipment ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/your-office-is-now-absolutely-riddled-with-surveillance-equipment</link>
                                                                            <description>
                            <![CDATA[ While workplace monitoring is shown to have a detrimental effect on morale, many firms are still charging ahead ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eB3vRmHwucSHTwBpyHDgUH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oTUSyyqsAmvPoYy7uLn7w8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Dec 2024 12:17:58 +0000</pubDate>                                                                                                                                <updated>Mon, 02 Dec 2024 14:21:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oTUSyyqsAmvPoYy7uLn7w8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Workplace surveillance and monitoring concept image showing a CCTV camera with an open place office space in the background.]]></media:description>                                                            <media:text><![CDATA[Workplace surveillance and monitoring concept image showing a CCTV camera with an open place office space in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[Workplace surveillance and monitoring concept image showing a CCTV camera with an open place office space in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oTUSyyqsAmvPoYy7uLn7w8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An ever-increasing and concerning array of wireless networking equipment is now being used to track employees around the office, according to new research.</p><p>A <a href="https://crackedlabs.org/en/data-work/project" target="_blank"><u>study from Cracked Labs</u></a> found that technology vendors are using wireless networking infrastructure to pinpoint the location of devices such as smartphones, laptops and so on, in order to track their location. </p><p>That is paired with Bluetooth beacons linked to access badges, security cameras, <a href="https://www.itpro.com/software/video-conferencing/362328/best-video-conferencing-services">video conferencing</a> systems, and even environmental sensors to understand employee behaviour, alongside more obvious tools such as motion sensors under desks.  </p><p>The report specifically highlighted the monitoring activities of networking giants Cisco and <a href="https://www.itpro.com/infrastructure/networking/our-cloud-works-juniper-networks-exec-fires-shots-at-ciscos-networking-architecture-and-explains-hpes-acquisition-strategy-in-detail">Juniper Networks</a>, as well as Swiss firm Locatee and European company Spacewell.</p><p>Cisco, for example, offers a product that makes use of <a href="https://www.itpro.com/infrastructure/network-internet/369978/ethernet-vs-wifi-why-ethernet-is-better">Wi-Fi </a>access points and other existing IT infrastructure to understand how people move throughout a building. </p><p>The report pointed to Cisco marketing material on the product, which claims it can enable companies to ”gain insights into how people and things move throughout their physical spaces” and “understand the behavior and location of people (visitors, employees) and things (assets, sensors)”. </p><p>“Companies can get a 'real time view of the behavior of employees, guests, customers and visitors' and 'profile' them based on their indoor movements in order to 'get a detailed picture of their behavior',” the report added. </p><p> <a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco</a> hadn't replied to a request for comment at the time of publication. </p><h2 id="big-brother-is-watching">Big Brother is watching</h2><p>In one Cisco example, tracking 138 people via 11 Wi-Fi access points generated several million location records, the report said. That allows the company to track where each device is in the building — as well as the employees who carry them. </p><p>Beyond Wi-Fi, researchers said Cisco's systems also tap into security cameras, <a href="https://www.itpro.com/business-strategy/collaboration/363923/cisco-webex-review">WebEx video conferencing</a>, and make use of linked apps.</p><p>According to the report, the purpose depends on the nature of the company. Retailers or restaurants, for example, can use the tools for behavioral profiling to offer personalized recommendations, or merely to understand where and when to clean. </p><p>In offices, companies can better understand desk usage — <a href="https://www.itpro.com/business/digital-transformation/do-we-really-need-smart-buildings-anymore-in-a-hybrid-world-of-work"><u>helpful during the shift to hybrid working</u></a> —  but also track IT assets to ensure they don't leave the building. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=56365576&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>While those use cases may feel innocuous, the systems are also promoted as being able to measure "behaviour metrics" to aid internal campaigns to change employee behaviour and to understand "employee behaviour that affects performance." </p><p>In one example using technology from Juniper Networks, it was possible to see how long employees spent in break areas and kitchens. </p><h2 id="function-creep">Function creep </h2><p>Even if the aim is useful, researchers warned such systems come with risks. </p><p>"Tracking and analyzing employees’ desk presence, indoor location and movements represents intrusive behavioral monitoring and profiling," the study said. </p><p>"Even if employers analyze the data only at the aggregate level, they process extensive personal data on employee behavior.</p><p>"Once deployed in the name of 'good', whether for worker safety, energy efficiency or just improved convenience, these technologies normalize far-reaching digital surveillance, which may quickly creep into other purposes." </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7jCo7bCRjf7Ev2wpdNzvBn" name="Reinventing procurement_ From cost center to innovation driver (1).jpg" caption="" alt="Man working at his desk with a monitor" src="https://cdn.mos.cms.futurecdn.net/7jCo7bCRjf7Ev2wpdNzvBn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Amazon Business)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/reinventing-procurement"><em>How AI and machine learning are influencing procurement</em></a></p></div></div><p>The report is part of <a href="https://crackedlabs.org/en/data-work/project"><u>wider work into surveillance in the workplace</u></a>, run by a team of researchers at Cracked Labs alongside partners at AlgorithmWatch, academics at the University of Oxford, and EU and Austrian trade unions. </p><p>The report marks the latest batch of research into the rise of workplace monitoring, which has been growing in frequency across a range of industries. </p><p>A study in November revealed <a href="https://www.itpro.com/security/privacy/workplace-monitoring-is-still-out-of-control-but-some-staff-are-fighting-back"><u>one-in-five workers is now being monitored by an activity tracker</u></a> of some kind, and it’s having a significant negative impact on employee morale. </p><p>Tracked employees are 73% more likely to distrust their employer, and twice as likely to be job-hunting as those who aren’t tracked in their workplace, the study noted.  </p><p>The issue reached such an extent that the UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> issued <a href="https://www.itpro.com/security/privacy/surge-in-workplace-monitoring-prompts-new-ico-guidelines-on-employee-privacy"><u>fresh guidance on the practices</u></a> last year. The data watchdog urged businesses to “consider workers’ rights” when introducing workplace monitoring tools. </p><p>This advisory was issued alongside a survey conducted by the ICO which found seven-in-ten respondents found workplace monitoring practices to be “intrusive”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Workplace monitoring is still out of control – but some staff are fighting back ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/workplace-monitoring-is-still-out-of-control-but-some-staff-are-fighting-back</link>
                                                                            <description>
                            <![CDATA[ Workers say they dislike being tracked, yet employers are still ramping up surveillance practices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i5UCipj3gRfMpwurB3QsWj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AxAgZGvaRwq6gCsjBhAnEH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Nov 2024 11:23:53 +0000</pubDate>                                                                                                                                <updated>Wed, 13 Nov 2024 15:16:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AxAgZGvaRwq6gCsjBhAnEH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Workplace monitoring concept image showing office workers sitting at desk during video call in a glass box.]]></media:description>                                                            <media:text><![CDATA[Workplace monitoring concept image showing office workers sitting at desk during video call in a glass box.]]></media:text>
                                <media:title type="plain"><![CDATA[Workplace monitoring concept image showing office workers sitting at desk during video call in a glass box.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AxAgZGvaRwq6gCsjBhAnEH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>One-in-five workers is now being monitored by an activity tracker, new research shows, and it's not doing much for employee morale.</p><p>Tracked employees are 73% more likely to distrust their employer and twice as likely to be job-hunting as those who aren’t tracked, according to analysis from Software Finder. </p><p>Meanwhile, three-quarters of workers whose location isn't tracked say they'd be unwilling to share that information with the boss.</p><p>"As these tools become more widespread — from activity monitors to location trackers — concerns about their impact are growing," the firm said..  </p><p>"With privacy and mental health at the forefront, many workers are questioning if the trade-off is worth it."</p><p>Tech staff are the most likely to be monitored, with one-in-three being tracked during their daily activities, followed by finance, where it's 30%. Similarly,  21% of retail employees are being actively monitored throughout their working week, along with 20% of people working in healthcare, and 17% in the education sector.</p><p>The study noted that activity tracking “does not seem to make employees more productive” and in fact has an adverse impact on team morale. </p><p>“Tracked and untracked employees report equal productivity levels,” the firm said. </p><p>“Tracked employees report higher stress levels, worse <a href="https://www.itpro.com/business/business-strategy/boosting-mental-health-support-in-the-workplace">mental health</a>, and less job satisfaction than untracked employees."</p><p>Despite this, half of managers currently using tracking tools plan to expand their surveillance over the next year, and 13% of those that aren't tracking staff plan to start.</p><p>A third of workers are now sharing their computer's location with their employer, and one-in-seven share their phone's location. </p><p>Notably, the study found the bigger the company, the more likely it is to be using surveillance tools. Only 8% of workers at micro companies being tracked compared to 18% of those at small companies, 23% of those at medium companies and a quarter of staff at large firms.</p><p>Remote and <a href="https://www.itpro.com/business/business-strategy/hybrid-workers-aren-t-disconnected-from-office-colleagues-they-re-happier-more-productive-and-have-better-workplace-relationships">hybrid workers</a> are more likely to be tracked, with a quarter under surveillance, compared with 18% of those working in the office.</p><p>Just over three-in-ten managers say they check up on their employees every day, with 35% doing it a few times a week and 23% once a week. Four in five believe it makes their staff more productive.</p><h2 id="staff-are-pushing-back-on-workplace-monitoring">Staff are pushing back on workplace monitoring</h2><p>Many workers are rebelling against this growing trend, the study found.  One-in-six revealed they’re using a mouse jiggler - a device that mimics movement - to disguise periods of inactivity. Another 12% say they want to start.</p><p>However, using a mouse jiggler carries its risks and these controversial devices can be detected. Earlier this year, for example, <a href="https://www.itpro.com/security/privacy/wells-fargo-firing-staff-for-using-mouse-jiggler-tools-raises-questions-over-employee-privacy-wellbeing"><u>Wells Fargo fired more than a dozen employees over their use</u></a>.</p><p>The financial services firm said the actions of the employees amounted to gross misconduct and therefore warranted dismissal.</p><p>Experts told <em>ITPro </em>at the time that although the firm may have been justified in its response, the incident highlighted the now-pervasive culture of surveillance across a range of industries. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LjWdHEMBU3LCLK4bVET7Rg" name="Understanding Least Privileges.jpg" caption="" alt="Understanding Least Privileges" src="https://cdn.mos.cms.futurecdn.net/LjWdHEMBU3LCLK4bVET7Rg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/reduce-cyber-risk-stay-in-business"><em>The guide to cyber insurance</em></a></p></div></div><p>While worker surveillance is perfectly legal, the UK’s Information Commissioner’s Office (ICO) has <a href="https://www.itpro.com/security/privacy/surge-in-workplace-monitoring-prompts-new-ico-guidelines-on-employee-privacy"><u>previously warned employers</u></a> that it has to be carried out in a fair and responsible manner.</p><p>Guidance issued by the data protection watchdog called on employers to make it clear to staff exactly what they're doing, and have either the worker's consent or a legal obligation for the monitoring. </p><p>Similarly, the guidance warned enterprises they must also carry out data protection impact assessments to ensure safe and responsible use. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/ai-recruitment-tools-are-still-a-privacy-nightmare-heres-how-the-ico-plans-to-crack-down-on-misuse</link>
                                                                            <description>
                            <![CDATA[ The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wQJFVT8dEwvNj6DLkTQ87i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BoxspQRwTLu8HAXk5Pnrd8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Nov 2024 10:42:22 +0000</pubDate>                                                                                                                                <updated>Fri, 08 Nov 2024 10:43:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BoxspQRwTLu8HAXk5Pnrd8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image showing a robotic hand dropping a man in a suit into the garbage, signifying AI recruitment tools.]]></media:description>                                                            <media:text><![CDATA[Concept image showing a robotic hand dropping a man in a suit into the garbage, signifying AI recruitment tools.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image showing a robotic hand dropping a man in a suit into the garbage, signifying AI recruitment tools.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BoxspQRwTLu8HAXk5Pnrd8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> has issued guidance on the use of AI recruitment tools following a wide-ranging review.</p><p>With AI increasingly being used to source potential candidates, <a href="https://www.itpro.com/business-strategy/careers-training/355955/tips-for-writing-a-cover-letter-thatll-help-land-the-job">summarize CVs</a>, and score applicants, the ICO said it's become concerned that their use can cause problems for job applicants in terms of their privacy and information rights. </p><p>Some <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> were not processing personal information fairly, for example, by allowing recruiters to filter out candidates with certain protected characteristics. </p><p>Others were even inferring characteristics such as gender and ethnicity from a candidate’s name, rather than asking for the information. </p><p>Meanwhile, some AI recruitment tools collected far more personal information than necessary and retained it indefinitely to build large databases of potential candidates without their knowledge.</p><p>The ICO has now made nearly 300 recommendations, such as ensuring personal information is processed fairly and kept to a minimum, and clearly explaining to candidates how their information will be used by the AI tool. </p><p>"<a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> can bring real benefits to the hiring process, but it also introduces new risks that may cause harm to jobseekers if it is not used lawfully and fairly. Our intervention has led to positive changes by the providers of these AI tools to ensure they are respecting people’s information rights," said Ian Hulme, ICO director of assurance.</p><p>"Our report signals our expectations for the use of AI in recruitment, and we're calling on other developers and providers to also action our recommendations as a priority. That’s so they can innovate responsibly while building trust in their tools from both recruiters and jobseekers."  </p><p>Some of the most important measures, said the ICO, include completing a <a href="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr">Data Protection Impact Assessment (DPIA)</a>, to understand, address and mitigate any potential privacy risks or harms.</p><p>Organizations must also identify an appropriate lawful basis for collecting data, such as consent or legitimate interests. Special category data, such as racial, ethnic origin or health data involves extra conditions.</p><p>Recruiters must identify who is the controller and processor of personal information and set explicit and comprehensive written instructions for providers to follow, and check that the provider has mitigated bias. </p><p>Candidates should be told how an AI tool will process their personal information, and recruiters must ensure that the tool collects only the minimum amount of personal information required to achieve its purpose, and that it won't be used in any other ways.</p><p>The developers concerned have all accepted or partially accepted all the ICO's recommendations.</p><p>“We are actively working to implement the specific actions agreed with the ICO in our audit plan," said one. "For example, we are making sure to provide the relevant information regarding the use of AI in our privacy policies and evaluating the steps taken to minimize bias when training and testing our <a href="https://www.itpro.com/technology/artificial-intelligence/workers-are-using-generative-ai-tools-on-the-sly-and-it-needs-to-stop">AI tools</a>."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Peloton faces lawsuit amid claims it allowed marketing firm to train AI on user chat data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/peloton-faces-lawsuit-amid-claims-it-allowed-marketing-firm-to-train-ai-on-user-chat-data</link>
                                                                            <description>
                            <![CDATA[ Peloton is accused of allowing marketing firm Drift to read and process data without user consent ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FH5dDSGLmT3DnjJqWbrs2N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ERVjqwAYf2wWHhr2GCZs34-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jul 2024 12:16:35 +0000</pubDate>                                                                                                                                <updated>Tue, 09 Jul 2024 13:50:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ERVjqwAYf2wWHhr2GCZs34-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up shot of the Peloton branding and logo pictured on a bicycle. ]]></media:description>                                                            <media:text><![CDATA[Close-up shot of the Peloton branding and logo pictured on a bicycle. ]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up shot of the Peloton branding and logo pictured on a bicycle. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ERVjqwAYf2wWHhr2GCZs34-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Peloton could face court in California over accusations that it allowed a third party to process user chat data, including for <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-training-in-the-crosshairs-as-ico-set-to-examine-legality-of-personal-data-use">training AI</a>, after twice attempting to have the lawsuit dismissed. </p><p>The case highlights the legal uncertainty surrounding how companies can gather the huge swathes of data necessary to train <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> systems.</p><p>In June 2023, legal firm Consumer Advocates filed a class-action lawsuit alleging that chat data between Peloton users and company representatives was processed without permission by AI-powered <a href="https://www.itpro.com/business/marketing-and-comms">marketing</a> firm Drift.</p><p>Both companies, Peloton and Drift, are accused in the filing as violating the anti-wiretapping California Invasion of Privacy Act (CIPA); though Drift is named, it is not targeted in the lawsuit.</p><p>According to one of the filings, Peloton&apos;s website has a chat function, allowing current and would-be customers to ask questions to the connected tech workout company.</p><p>Those people were not told that chat content was automatically captured by Drift to be stored and analysed. The transcripts were also used to train Drift&apos;s AI systems, as it also offers AI-powered <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbots</a>. Beyond the chat text, the Drift system also captured the website visitor&apos;s <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP address</a>, device type, and other data.</p><p>Though Peloton&apos;s attempt to have the case thrown out was unsuccessful, the class-action was narrowed from its initial wording to focus on how it allowed Drift to violate the act. Peloton is, of course, allowed to see the content of the chats as one party to the communication, but the complaint is that they were shared without consent.</p><p>As the filing notes, the complaint arises from Peloton&apos;s "secret integration of third parties’ software to secretly wiretap and eavesdrop on the private conversations of users of the chat features on the website," adding that the intent was to allow Drift to " harvest data for financial gain."</p><h2 id="peloton-incident-highlights-lingering-ai-trust-issues">Peloton incident highlights lingering AI trust issues</h2><p>Acquired by Salesloft in February this year, Drift uses <a href="https://www.itpro.com/machine-learning/32201/the-ethical-implications-of-conversational-ai">conversational AI</a> for customer service and consumer marketing, using AI to help clients "deliver curated, personalized experiences to every unique buyer in real-time", according to a product announcement from last year. </p><p>A report by the company in 2022 predicted trust and perception would be serious challenges for AI in the coming years, while also suggesting companies shouldn&apos;t continue to over-rely on declining marketing tools like <a href="https://www.itpro.com/software/google/googles-third-party-cookies-phase-out-will-force-firms-to-rely-on-first-party-data">third-party cookies</a>.</p><p>"Companies that don&apos;t prioritize a strong first-party data collection strategy are setting themselves back for the near term," Kimen Warner, VP of Product Management at Drift, was quoted as saying at the time.</p><p>Warner later added that conversational AI can help build trust with data collection by "empowering customers to willingly &apos;opt in&apos; and consent to sharing more information about themselves."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zPqJCyEu6wpL7hmyg2RA3f" name="The security awareness handbook 2.jpg" caption="" alt="Cartoon of two people looking at a pocketwatch" src="https://cdn.mos.cms.futurecdn.net/zPqJCyEu6wpL7hmyg2RA3f.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-security-awareness-handbook"><em>Get insight into the common risks users face</em></a></p></div></div><p>Whether the court agrees that Peloton customers were "empowered" to make a choice about how their data was processed remains to be seen, but Drift is not part of the legal complaint. </p><p>The second motion to dismiss has been denied, but questions remain over whether Peloton will file further motions or when the case may proceed.</p><p>Peloton has had a rough ride after pandemic lockdowns sent sales soaring. Its share price has fallen from $160 at the end of 2020 to around $3.50 today.</p><p>Last year, the fitness-at-home company paid a $19 million fine after safety issues with its treadmills were tied to injuries and the death of a child, while in May, CEO Barry McCarthy stepped down amid job losses.</p><p>Peloton and Drift have yet to respond to requests for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Meta could face a hefty EU fine over its 'pay or consent' ad model ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/why-metas-pay-or-consent-ad-model-has-landed-it-in-hot-water-with-eu-regulators</link>
                                                                            <description>
                            <![CDATA[ The European Commission said Meta is failing to offer users a valid option for equivalent services that doesn't involve tracking and targeting ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MwZxavCDMi7q8cNj76r9WN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Fvu8vCPHUjMXrnPhGThgRk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jul 2024 09:10:39 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Jul 2024 12:04:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Fvu8vCPHUjMXrnPhGThgRk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta logo pictured at Menlo Park, California.]]></media:description>                                                            <media:text><![CDATA[Meta logo pictured at Menlo Park, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Meta logo pictured at Menlo Park, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Fvu8vCPHUjMXrnPhGThgRk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has told Meta its ‘pay or consent’ model for personalized ads is in breach of the <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">Digital Markets Act (DMA)</a>.</p><p>Under the DMA, users should be given a choice on whether their data can be collected and used for targeted ads. </p><p>Since November last year, the company has attempted to claim it is compliant by offering Facebook and Instagram users in the EU the choice of agreeing to accept tracking and targeting, or of paying a monthly subscription for an ad-free version of the platforms.</p><p>However, following an investigation, the Commission said its preliminary view is that giving users this binary choice forces them to accept the data collection, by failing to give them an equivalent service if they decline.</p><p>"Today we make another important step to ensure full compliance with the DMA by Meta. Our preliminary view is that Meta’s Pay or Consent business model is in breach of the DMA," said Thierry Breton, commissioner for internal market.</p><p>"The DMA is there to give back to the users the power to decide how their data is used and ensure innovative companies can compete on equal footing with tech giants on data access."</p><p>Meta has been classified under the DMA as one of a number of &apos;<a href="https://www.itpro.com/business/policy-and-legislation/european-firms-say-theyre-being-left-in-the-dark-by-big-tech-gatekeepers-ahead-of-digital-markets-act">gatekeepers</a>&apos;, meaning it’s subject to more stringent rules. These gatekeepers, according to the Commission, have been able to impose terms of services on their user base that allows them to collect vast amounts of personal data.</p><p>This has given them potential advantages compared to competitors, making it hard to compete in terms of providing online advertising and social network services.</p><p>As such, firms such as Meta are required to gain users&apos; consent for combining their personal data between designated core platform services and other services; and if a user refuses consent, they should have access to a less personalized but equivalent alternative.</p><p>Gatekeepers can&apos;t make use of the service or certain functionalities conditional on users&apos; consent.</p><p>Meta&apos;s policy, the Commission said, fails to allow users to opt for a service that uses less of their personal data but is otherwise equivalent to the personalized ads-based service. Nor does it give users a free choice when it comes to consenting to the combination of their personal data.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wKEy4KeUWJrRMLAHryHep5" name="Maximize your data insights with AI.jpg" caption="" alt="Maximize your data insights with AI" src="https://cdn.mos.cms.futurecdn.net/wKEy4KeUWJrRMLAHryHep5.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/maximize-your-data-insights-with-ai"><em>Unlock the power of your data</em></a></p></div></div><p>"Our investigation aims to ensure contestability in markets where gatekeepers like Meta have been accumulating personal data of millions of EU citizens over many years," said Margrethe Vestager, executive vice-president in charge of competition policy.</p><p>"We want to empower citizens to be able to take control over their own data and choose a less personalized ads experience."</p><h2 id="meta-ruling-has-been-welcomed-by-industry-stakeholders">Meta ruling has been welcomed by industry stakeholders</h2><p>The Commission&apos;s verdict has been welcomed by the European Consumer Organisation (BEUC), which late last year submitted a formal complaint to European consumer protection authorities.</p><p>"It’s good news that the Commission is taking enforcement action based on the Digital Markets Act against Meta’s pay-or-consent model," said BEUC director general Agustin Reyna.</p><p>"It comes on top of the complaints against Meta’s model for breaches of consumer law and data protection law which consumer organizations have raised in the last few months. We now urge Meta to comply with laws meant to protect consumers."</p><p>Meta can now reply to the findings, and the Commission is expected to complete its investigation by the end of March next year. </p><p>If the preliminary view is confirmed, the company could, in theory, be subject to fines up to 10% of the company&apos;s total worldwide turnover - or even 20% in the case of repeated infringement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wells Fargo firing staff for using 'mouse jiggler' tools raises questions over employee privacy, wellbeing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/wells-fargo-firing-staff-for-using-mouse-jiggler-tools-raises-questions-over-employee-privacy-wellbeing</link>
                                                                            <description>
                            <![CDATA[ Wells Fargo is by no means the first company to crack down on mouse jigglers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rmt48T4z7EdsFNEA4koBMX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uPHcA2SXR4uphAKjU98Zvg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Jun 2024 13:08:53 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jun 2024 11:31:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uPHcA2SXR4uphAKjU98Zvg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wells Fargo bank branch in New York, US, on Wednesday, Dec. 27, 2023.]]></media:description>                                                            <media:text><![CDATA[Wells Fargo bank branch in New York, US, on Wednesday, Dec. 27, 2023.]]></media:text>
                                <media:title type="plain"><![CDATA[Wells Fargo bank branch in New York, US, on Wednesday, Dec. 27, 2023.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uPHcA2SXR4uphAKjU98Zvg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wells Fargo’s decision to fire staff for using “mouse jiggler” tools highlights a pervasive culture of workplace surveillance – and there’s little staff can do to stop the trend in the age of hybrid work.</p><p>The financial services firm fired more than a dozen employees in May over what it described as a “simulation of keyboard activity” that created the “impression of active work”.</p><p>The aforementioned employees are believed to have been using devices or software used to imitate activity on their work devices. These are commonly referred to as “mouse jigglers” or “mouse movers”.</p><p>Devices such as these have grown in popularity since the onset of the Covid pandemic and the shift to remote and <a href="https://www.itpro.com/business/the-future-of-business/hybrid-work-means-were-burning-out-harder-and-faster-than-ever">hybrid working</a>.</p><p>According to reports from <a href="https://www.bloomberg.com/news/articles/2024-06-13/wells-fires-over-a-dozen-for-simulation-of-keyboard-activity?srnd=homepage-americas&embedded-checkout=true"><em>Bloomberg</em></a>, it remains unclear whether the fired employees were using these devices at home or in the office. However, Wells Fargo said the actions of the dismissed employees amounted to gross misconduct.</p><p>“Wells Fargo holds employees to the highest standards and does not tolerate unethical behavior,” a company spokesperson said in a statement.</p><p>While the company may have been justified in this regard, the incident highlights a larger trend of workplace monitoring that has surged in recent years, according to Ellen Goodland, associate in the employment team at UK-based law firm, Burges Salmon.</p><p>“Prompted, no doubt, by the growth in home working since the pandemic, the monitoring, by employers, of their employees is becoming increasingly common,” she said.</p><p>Goodland added that this trend has given rise to a slew of new technologies and tools aimed at enabling employers to monitor staff during their daily activities.</p><p>“The tech market has been quick to catch on to this trend and, alongside the tried and tested methods of CCTV, attendance logs and email and telephone monitoring. numerous new monitoring technologies are now available including keystroke-logging, browser monitoring, and social media tracking.”</p><p>The use of monitoring technologies appears to be negatively impacting some employees and is placing workers at odds with their organizations.</p><p>A recent study from <a href="https://www.forbes.com/advisor/business/software/internet-surveillance-workplace/"><em>Forbes</em></a>, for example, found that 43% of employees have their online activity monitored by employees. The issue has reached such an extent that some are even using <a href="https://www.itpro.com/security/27098/best-vpn-services">virtual private networks (VPNs)</a> to circumvent surveillance practices.</p><p>Hybrid employees in particular were found to experience far more scrutiny in this regard, according to Forbes. Nearly half (48%) of workers reported monitoring practices compared to 37% of fully remote employees.</p><p>Notably, 39% said workplace monitoring practices have a negative impact on their relationship with employers, and 43% said it negatively impacts company morale.</p><h2 id="workplace-monitoring-raises-ethical-and-legal-questions">Workplace monitoring raises ethical and legal questions</h2><p>There are serious considerations – and potential penalties – for employers employing invasive workplace monitoring practices. </p><p>Last year, the UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> issued fresh guidance urging organizations <a href="https://www.itpro.com/security/privacy/surge-in-workplace-monitoring-prompts-new-ico-guidelines-on-employee-privacy">to “consider workers’ rights” when introducing such tools</a>.</p><p>The warning from the data protection watchdog followed the publication of a report which found 70% of the public would find workplace monitoring practices “intrusive”.</p><p>Nearly one-in-five (19%) also told the ICO they believe they had been monitored by their employer at some stage.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LLknV3zUwteEHmrfX7EWDN" name="Modern adversaries and evasion techniques.jpg" caption="" alt="Modern adversaries and evasion techniques" src="https://cdn.mos.cms.futurecdn.net/LLknV3zUwteEHmrfX7EWDN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Crowdstrike)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/modern-adversaries-and-evasion-techniques"><em>Modern endpoint security is the only way to stop breaches</em></a></p></div></div><p>The watchdog warned that excessive monitoring can “easily intrude into people’s private lives” and undermine privacy.</p><p>Ellen Goodland said employers must ensure any employee monitoring is undertaken lawfully as the “potential consequences of getting it wrong can be extensive”.</p><p>“The ICO has the powers to investigate monitoring off their own initiative or an employee may complain to the ICO about the (mis)use of their personal data, which could also result in an ICO investigation,” Goodland told <em>ITPro</em>.</p><p>“If the ICO finds there have been data breaches then it can take enforcement action, including through information notices (requiring certain information being provided to the ICO), enforcement notices (requiring action to be taken or not taken) and imposing (sometimes heavy) financial penalties.”</p><p>Crucially, Goodland said that communication with employees on the subject is key to ensure that staff can voice concerns and understand the rules being put in place.</p><p>“Transparency is a fundamental principle of data protection compliance, and organizations will be required to demonstrate they have been transparent with employees about what monitoring is taking place.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Euro police chiefs rekindle end-to-end encryption battle amid continued rollouts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/euro-police-chiefs-rekindle-end-to-end-encryption-battle-amid-continued-rollouts</link>
                                                                            <description>
                            <![CDATA[ End-to-end encryption plans are putting users in danger and making it harder to fight crime, police claim, but tech industry stakeholders disagree ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nBBwdoFN7Jtf6A2XxGsjUQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8jaVZpQM96Y2PNRsWdgpLd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Apr 2024 07:30:20 +0000</pubDate>                                                                                                                                <updated>Wed, 24 Apr 2024 15:06:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8jaVZpQM96Y2PNRsWdgpLd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[End-to-end encryption concept image showing a series of locked digitized padlocks on a circuit board.]]></media:description>                                                            <media:text><![CDATA[End-to-end encryption concept image showing a series of locked digitized padlocks on a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[End-to-end encryption concept image showing a series of locked digitized padlocks on a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8jaVZpQM96Y2PNRsWdgpLd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>European police chiefs have warned the increasing use of end-to-end encryption (E2EE) is making it harder for them to investigate crime and keep people safe.</p><p>Graeme Biggar, director general of the UK’s National Crime Agency said that encryption can be hugely beneficial, protecting users from a range of crimes.</p><p>However, the “blunt and increasingly widespread rollout” by major tech companies is putting users in danger due to a lack of sufficient consideration for public safety, he argued.</p><p>“These changes are also making it harder for us to investigate serious crime and protect the public, as the companies are less able to act on a warrant and provide us with the data of suspected criminals,” Biggar said.</p><p>The statement was issued by international policing agency Europol and backed by 32 European police chiefs.</p><p>E2EE means that a message is encrypted when it is sent, and only unscrambled when it arrives at the recipient’s device. It cannot be read by anyone in between.</p><p>While this means that sensitive messages can be securely sent over the internet, it also means that neither the tech companies themselves, nor police and other law enforcement agencies, are able to intercept these messages and – for example – uncover a criminal plot.</p><p>“Our homes are becoming more dangerous than our streets as crime is moving online. To keep our society and people safe, we need this digital environment to be secured,” said Europol executive director Catherine de Bole.</p><p>The authorities argue that moves like this will mean their ability to tackle serious crime threats will be hampered, as tech companies cannot respond to a warrant because the information has been encrypted.</p><p>The NCA pointed out that “one stream of data” provided by tech companies in response to warrants led to 327 arrests, the seizure of 3.5 tonnes of Class A drugs, the recovery of £4.8m, the identification of 29 previously unknown threats to life, and a further 100 threats to harm, between January and March this year.</p><p>For their part, the tech companies argue that by providing E2EE they are delivering the security that their customers want - and need - to keep them protected from crooks and scammers. They say the net result of strong encryption is to make most people more safe.</p><p>Europol noted that its declaration comes as Meta has started to roll out E2EE across its Messenger platform.</p><p>Meta told <em>ITPro</em> the overwhelming majority of Brits already rely on apps that use encryption to keep them safe from hackers, fraudsters, and criminals.</p><p>“We don’t think people want us reading their private messages so have spent the last five years developing robust safety measures to prevent, detect and combat abuse while maintaining online <a href="https://www.itpro.com/security">security</a>,” a spokesperson said.</p><p>“As we roll out end-to-end encryption, we expect to continue providing more reports to law enforcement than our peers due to our industry leading work on keeping people safe.”</p><h2 id="end-to-end-encryption-goals-still-unclear">End-to-end encryption goals still unclear</h2><p>While the police chiefs said industry and governments should “take action against <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption</a> roll-out” it’s not entirely clear what they want done instead.</p><p>“We do not accept that there need be a binary choice between cyber security or privacy on the one hand and public safety on the other. Absolutism on either side is not helpful,” the statement said.</p><p>“Our view is that technical solutions do exist; they simply require flexibility from industry as well as from governments. We recognize that the solutions will be different for each capability, and also differ between platforms,” it added.</p><p>But finding those technical solutions may be hard. Governments and tech companies have consistently struggled to find some form of compromise when it comes to E2EE. It’s a standoff that is unresolved and probably unresolvable. Data is either encrypted end-to-end or it is not.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZhfDScDRLze3CZL24fjUo" name="The Total Economic Impact™ Of IBM Security MaaS360 With Watson.jpg" caption="" alt="The Total Economic Impact™ Of IBM Security MaaS360 With Watson whitepaper" src="https://cdn.mos.cms.futurecdn.net/ZhfDScDRLze3CZL24fjUo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/367053/the-total-economic-impacttm-of-ibm-security-maas360-with-watson"><em>Distribute security measures bette with</em></a><em> </em><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/367053/the-total-economic-impacttm-of-ibm-security-maas360-with-watson"><em>Maas360 </em></a></p></div></div><p>Governments can ban E2EE but the most likely impact would be that <a href="https://www.itpro.com/business/policy-and-legislation/uk-competition-watchdog-says-it-has-very-real-concerns-over-a-big-tech-concentration-of-power-in-the-ai-market">big tech companies</a> would simply stop offering services in any countries that did so. That would make the average user there much less secure, while crooks would just buy their encryption tools on the black market.</p><p>The UK government’s recent Online Safety Bill illustrated the bind that governments find themselves in. While the legislation theoretically gives the government the power to ask for encrypted messages, it also acknowledges that – at least for now – there is no technical way of doing it.</p><p>Pam Cowburn, head of communications and campaigns at The Open Rights Group, said E2EE keeps messages safe and secure, and helps to protect users from fraud, scams, and other criminal behaviour.</p><p>“Preventing Meta from following out end-to-end encryption could deny billions of users this security,” she told <em>ITPro</em>.</p><p>"While the UK government adopted powers that could allow the private messages of everyone in the UK to be scanned, it did concede that this could not be put into practice without jeopardizing people’s security and privacy.</p><p>"Open Rights Group has called for Ofcom to publish regulations that make clear that there is no available technology that can allow for scanning of user data to co-exist with strong encryption and privacy. “</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google forced to delete billions of incognito browsing records after privacy controversy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/google-forced-to-delete-billions-of-incognito-browsing-records-after-privacy-controversy</link>
                                                                            <description>
                            <![CDATA[ Google has agreed to delete data it gained improperly through its private browsing function ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FANeKpjtWhsevDdxZJLcbH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Nha23juDci28B2ZtUsP37H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Apr 2024 12:22:47 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Apr 2024 14:38:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Nha23juDci28B2ZtUsP37H-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The exterior of the new headquarters of Google is seen at 550 Washington Street in Hudson Square on January 09, 2024 in New York City]]></media:description>                                                            <media:text><![CDATA[The exterior of the new headquarters of Google is seen at 550 Washington Street in Hudson Square on January 09, 2024 in New York City]]></media:text>
                                <media:title type="plain"><![CDATA[The exterior of the new headquarters of Google is seen at 550 Washington Street in Hudson Square on January 09, 2024 in New York City]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Nha23juDci28B2ZtUsP37H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/google">Google</a> has announced it will destroy billions of data records to settle an ongoing lawsuit in which plaintiffs accused the tech firm of tracking search activity improperly. </p><p>The move follows allegations that Google tracked the search data of users operating in Chrome’s private browsing - or ‘incognito’ - mode without clearly stating that it would be doing so in privacy disclosures. </p><p>Google tried unsuccessfully to have the case dismissed in the summer of 2023 following the lawsuit’s inception in 2020, claiming that users were adequately informed of data collection.</p><p>In the most recent development of the case, however, a settlement has been passed that will see Google forced to delete data and update its privacy policies. </p><p>Google will destroy the billions of ill-gotten records it secured while also updating disclosures for its private browsing capabilities to clearly describe what data it collects. It will now also give users the option to disable third-party cookies within this function. </p><p>These latest terms which hold Google to account, filed in a California federal court, now await approval from US district judge Yvonne Gonzalez Rogers. </p><h2 id="google-penalties-are-part-of-a-wider-wake-up-call-for-businesses">Google penalties are part of a wider wake-up call for businesses</h2><p>In this case, Google was found to have been unclear about its data access and usage, leaving it open to a level of legal action that helps establish an important precedent for enterprises. </p><p>With consumers increasingly aware of their privacy rights, businesses can ill afford to shirk responsibilities, according to Stephanie Liu, senior analyst at Forrester.</p><p>“The rise of privacy-oriented class action lawsuits and complaints shows consumers are increasingly privacy savvy and taking action,” Liu said. </p><p>“Transparency is critical — companies have to explain how data is shared and used,” she added. </p><p>Going forward, companies will need to ensure that they are open and honest about where and how they are tracking data, as violations such as these will leave enterprises vulnerable to accusations of data misuse, Liu noted.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ovMSxaaARrLd4LYsh7bM4m" name="The Business Value of Zscaler Data Protection_listing.jpg" caption="" alt="Whitepaper cover with male and female colleague looking at, and pointing to, a digital padlock" src="https://cdn.mos.cms.futurecdn.net/ovMSxaaARrLd4LYsh7bM4m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/the-business-value-of-zscaler-data-protection"><em>Minimize the risks related to data loss and other security events</em></a></p></div></div><p>“There has been a steady drumbeat of complaints, lawsuits, and regulatory action centered on companies collecting or sharing customer data in unexpected ways,” she said.</p><p>“The Google Chrome settlement is part of a broader trend of consumers filing complaints about their data being used in ways they don&apos;t expect."</p><p><a href="https://www.itpro.com/marketing-comms/social-media/369779/meta-to-pay-725-million-in-cambridge-analytica-lawsuit"><u>Meta, for example, found itself caught up in the growing trend of class action privacy cases when it was forced to pay $725 million in 2022</u></a> over its handling of personal user information with Cambridge Analytica. </p><p>Though Meta did not admit its guilt as part of the settlement, this was still the largest-ever monetary sum paid as part of a privacy lawsuit. </p><p><a href="https://www.itpro.com/software/video-conferencing/360443/zoom-settles-85-million-lawsuit-over-zoombombing"><u>Slightly further back, Zoom agreed to pay $85 million to settle privacy claims</u></a> against it relating to the sharing of personal user data with other firms such as Google, Facebook, and LinkedIn.   </p><p><a href="https://www.itpro.com/security/privacy/369517/google-agrees-record-3915m-settlement-in-us-digital-tracking-case"><u>This case isn’t Google’s only run-in with privacy regulation in recent memory</u></a>, as the firm forked out a $391.5 million settlement in 2022 following claims that it was tracking location data improperly.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Avast framed itself as a data privacy champion - it failed customers, and now it's paid the price ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/avast-framed-itself-as-a-data-privacy-champion-it-failed-and-now-its-paying-the-price</link>
                                                                            <description>
                            <![CDATA[ Avast offered users a host of tools to protect their privacy rights while selling data to more than 100 third-party clients ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZbuRGC4KJQbbiAzSUADj8E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pM2tanNJGoDPqgDV5XY4uX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Feb 2024 21:00:38 +0000</pubDate>                                                                                                                                <updated>Wed, 28 Feb 2024 15:02:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pM2tanNJGoDPqgDV5XY4uX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Avast Software logo seen displayed on a smartphone with an economic stock exchange index graph in the background]]></media:description>                                                            <media:text><![CDATA[Avast Software logo seen displayed on a smartphone with an economic stock exchange index graph in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Avast Software logo seen displayed on a smartphone with an economic stock exchange index graph in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pM2tanNJGoDPqgDV5XY4uX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Avast was a brand name that became synonymous with <a href="https://www.itpro.com/tag/data-privacy">data privacy</a> in recent years, but that’s all come crashing down in one fell swoop. </p><p>Billing itself as a champion for users, the company offered a range of products, from <a href="https://www.itpro.com/security/29665/does-antivirus-software-do-more-harm-than-good">antivirus software</a> to Chrome extensions and various other tools aimed at boosting privacy, keeping snooping brands at bay online, and protecting from a growing array of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> threats.</p><p>It was a position - and product portfolio - that naturally resonated with consumers and businesses alike amidst an increasingly privacy-conscious age. But beneath the seemingly impeccable veneer, the company was secretly selling off user data to the highest bidder.</p><p>Between 2014 to 2020, Avast was hoovering up user browser information and selling it to upwards of 100 companies through a subsidiary firm known as Jumpshot, which Avast acquired in 2014 and has since shuttered.</p><p>Details on the relationship between Avast and Jumpshot appear to have been relatively unknown to customers throughout this period. It wasn’t until 2020 that reports from <a href="https://www.vice.com/en/article/qjdkq7/avast-antivirus-sells-user-browsing-data-investigation"><em>Motherboard</em> </a>found clients had been purchasing data from the firm.</p><p>These included major household brands including <a href="https://www.itpro.com/software/google">Google</a>, <a href="https://www.itpro.com/software/microsoft">Microsoft</a>, Pepsi, McKinsey, and US retail giant Home Depot.</p><p>Documents obtained by Motherboard, for example, found that third parties could buy data pertaining to Google Maps queries and social media page searches on LinkedIn. Sources told the publication that the information sold to these parties was “very granular” and represented a treasure trove of data.</p><p>This campaign of selling user data has since landed Avast in hot water with US regulators. An investigation by the <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">Federal Trade Commission</a> (FTC) recently ordered the firm to pay $16.5 million to redress consumers impacted by the data sharing practices.</p><p>The FTC also ruled that Avast will be prohibited from selling future browsing data, and from here onward will be required to obtain express consent on data gathering.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KYv46an8MeP685DXEY8o24" name="AI code, security, and trust_ Organizations must change their approach_listing.jpg" caption="" alt="Dark whitepaper cover with image of a dog looking at text" src="https://cdn.mos.cms.futurecdn.net/KYv46an8MeP685DXEY8o24.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ai-code-security-and-trust"><em>Discover why development teams need to adopt a responsible approach to AI</em></a></p></div></div><p>A key talking point in this investigation, and one that alarmed regulators, is that both Avast and the now-shuttered Jumpshot claimed all data had identifying information removed. The regulator ruled this was “not sufficient”.</p><p>Jumpshot framed its products as being able to offer “unique insights” into user browsing behaviors, providing clients with device identifiers for specific <a href="https://www.itpro.com/network-internet/web-browser/357253/8-most-secure-web-browsers">browsers</a> based on ‘feeds’.</p><p>This included an ‘<em>All Clicks Feed</em>’, &apos;<em>Search Plus Click Feed</em>’, and a ‘<em>Transaction Feed</em>’.</p><p>Clients, the FTC found, flocked to these, purchasing specific feeds and using this to collate with their own internal datasets to gain a detailed understanding of customer purchasing behavior and preferences.</p><h2 id="avast-tried-to-quell-jumpshot-data-selling-fears">Avast tried to quell Jumpshot data selling fears</h2><p>The FTC’s investigation into the matter uncovered a concerning lack of transparency on the extent of the relationship between Avast and Jumpshot. Investigators found that Avast actively downplayed its involvement with Jumpshot through its own official web forums, for example.</p><p>The firm repeatedly insisted that Jumpshot only used non-aggregated data and that it told users during the installation of products and purchase of services that it conducted <a href="https://www.itpro.com/network-internet/32363/what-web-30-means-for-data-collection-and-security">data collection</a> to “better understand new and interesting trends”.</p><p>Lesley Fair, senior attorney for the FTC, described Avast’s practices as “alarming”, noting that the company’s claims for its <a href="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions">software</a> and browser extensions essentially amounted to nothing more than “attention-getters”.</p><p>“All companies must honor their privacy promises, but that holds especially true for businesses that pitch their products as a way for consumers to protect their privacy,” Fair wrote in a <a href="https://www.ftc.gov/business-guidance/blog/2024/02/ftc-says-avast-promised-privacy-pirated-consumers-data-treasure" target="_blank">blog post</a>.</p><p>“There aren’t enough r’s in “<em>Arrrrrrrgghh</em>” to convey the FTC’s concern about a company that advertises its products as a means for people to maintain their privacy online, and then double-crosses them by selling their highly personal browsing information.</p><p>“The irony – and injury – in this case is alarming and the FTC will give no quarter when businesses lie to consumers about how their personal information will be protected.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ICO threatens to name and shame cookie consent rogues ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/ico-threatens-to-name-and-shame-cookie-consent-rogues</link>
                                                                            <description>
                            <![CDATA[ Websites failing on cookie consent have until January before the ICO takes action ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bX8f8TAFak6EFXmjSc5QJk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LJKsE3hDnDuuSnPSAEWNvi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Nov 2023 12:54:27 +0000</pubDate>                                                                                                                                <updated>Wed, 22 Nov 2023 14:50:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LJKsE3hDnDuuSnPSAEWNvi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cookie banner displayed on a website]]></media:description>                                                            <media:text><![CDATA[Cookie banner displayed on a website]]></media:text>
                                <media:title type="plain"><![CDATA[Cookie banner displayed on a website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LJKsE3hDnDuuSnPSAEWNvi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office</a> (ICO) has warned it may impose harsh penalties and publicly name websites that fail to make changes to their cookie consent policies. </p><p>The ICO said that some are failing to give users a clear choice about whether they want to opt-in to personalized advertising, and make it just as easy to &apos;reject all&apos; as to &apos;accept all&apos;.</p><p>While websites can still display adverts when users reject all tracking, they must not tailor these ads to the person browsing.</p><p>Stephen Almond, ICO executive director for regulatory risk issued a warning to websites that consistently fail on <a href="https://www.itpro.com/network-internet/web-browser/369894/the-cookie-law-is-finally-crumbling-good-riddance">cookie consent</a>, adding that the regulator will clamp down on those who don’t comply.</p><p>"We’ve all been surprised to see adverts online that seem designed specifically for us – an ad for a hotel when you’ve just booked a flight abroad, for instance. Our research shows that many people are concerned about companies using their personal information to target them with ads without their consent,” he said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Q78FXEQYdWxt9sQ9poVpxb" name="Security_Padlock_GettyImages-1279251103.jpg" caption="" alt="Binary digital security padlock and network data on a huge cyberspace" src="https://cdn.mos.cms.futurecdn.net/Q78FXEQYdWxt9sQ9poVpxb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/surge-in-workplace-monitoring-prompts-new-ico-guidelines-on-employee-privacy">Surge in workplace monitoring prompts new ICO guidelines on employee privacy</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/almost-one-third-of-data-breaches-reported-to-ico-came-from-outsiders">Almost one-third of data breaches reported to ICO came from outsiders</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/incorrectly-copying-people-into-emails-could-get-you-fined-under-new-ico-guidelines">Incorrectly copying people into emails could get you fined under new ICO guidelines</a></p></div></div><p>"Gambling addicts may be targeted with betting offers based on their browsing record, women may be targeted with distressing baby adverts shortly after miscarriage and someone exploring their sexuality may be presented with ads that disclose their sexual orientation."</p><p>Without naming names, the ICO said it has written to companies running some of the UK’s most-visited websites to voice concerns about their cookie consent policies.</p><p>The regulator has given them 30 days to ensure their websites comply with current legislation on the matter.</p><p>"Many of the biggest websites have got this right," said Almond. "We’re giving companies who haven’t managed that yet a clear choice: make the changes now, or face the consequences."</p><p>The ICO said it will provide an update on progress in January. For organizations that are still to comply, it will provide the public with details.  </p><h2 id="cookie-consent-crackdown">Cookie consent crackdown</h2><p>The move follows a warning earlier this summer in which the ICO began assessing cookie consent banners. The regulator said at the time it would take action against those who don’t comply.</p><p>While the legal requirement for cookie banners derives from the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, the UK&apos;s departure from the EU hasn&apos;t yet led to any change in the rules.</p><p>Companies are required to gain explicit consent from users before using <a href="https://www.itpro.com/marketing-comms/digital-marketing/367745/third-party-cookie-phase-out-adtech-apocalypse">marketing cookies</a> or trackers, and the buttons used for this must make it at least as easy to deny as to consent.</p><p>In the EU, rules are similar, although there&apos;s no clear rule that &apos;reject all&apos; must appear at the same time, and be as easy to choose as &apos;accept all&apos;.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZwJYgYeWHbjAH7vhgezPkD" name="Healthcares next chapter revolutionizing how you care with EPR experts you can trust_listing.jpg" caption="" alt="A whitepaper from Telefonica Tech on how to revolutionize care with their EPR experts" src="https://cdn.mos.cms.futurecdn.net/ZwJYgYeWHbjAH7vhgezPkD.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Telefonica Tech)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how Telefónica Tech helps NHS Trusts meet the mandate for operational EPR systems <br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/business/digital-transformation/healthcares-next-chapter-revolutionizing-how-you-care-with-epr-experts-you-can-trust">DOWNLOAD NOW</a></p></div></div><p>Different countries within the union have slightly different policies. Austria and Spain, for example, require a &apos;reject all&apos; button in the first layer of the consent process while Germany does not.</p><p>Earlier this month, the European Data Protection Board (EDPB) published new guidelines on the use of cookies, clarifying which tracking techniques are covered.</p><p>"These guidelines discuss solutions, such as tracking links and pixels, local processing, and unique identifiers, to ensure that the consent obligations set out by the article are not circumvented," said EDPB chair Anu Talus.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Surge in workplace monitoring prompts new ICO guidelines on employee privacy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/surge-in-workplace-monitoring-prompts-new-ico-guidelines-on-employee-privacy</link>
                                                                            <description>
                            <![CDATA[ Detailed guidance on how to implement workplace monitoring could prevent data protection blunders ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5Kb3rDhmEbGcVFX3MAeu9Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MzC9cx83DFE6FrwkLYmxZX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Oct 2023 08:30:33 +0000</pubDate>                                                                                                                                <updated>Wed, 04 Oct 2023 10:38:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MzC9cx83DFE6FrwkLYmxZX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[High angle view of male and female programmers working on computers at desk in office.]]></media:description>                                                            <media:text><![CDATA[High angle view of male and female programmers working on computers at desk in office.]]></media:text>
                                <media:title type="plain"><![CDATA[High angle view of male and female programmers working on computers at desk in office.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MzC9cx83DFE6FrwkLYmxZX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Information Commissioner&apos;s Office (ICO) has issued fresh guidance urging organizations to “consider workers’ rights” when introducing workplace monitoring tools. </p><p>The advisory follows a report that found 70% of the public would find workplace monitoring practices “intrusive”. Almost one-in-five (19%) of respondents told the ICO they believe they have been monitored by an employer at some stage. </p><p>The watchdog warned that excessive monitoring can “easily intrude into people’s private lives” and undermine privacy. </p><p>“With the rise of <a href="https://www.itpro.com/business/careers-and-training/strategies-for-effective-upward-management-while-working-remotely"><u>remote working</u></a> and developments in the technology available, many employers are looking to carry out checks on workers,” the ICO said in a statement.  </p><p>“The ICO has today published guidance to help employers fully comply with <a href="https://www.itpro.com/uk/security/data-protection"><u>data protection</u></a> law if they wish to monitor their workers.” </p><p>The guidance is aimed at employers spanning both the public and private sector, and provides a “clear direction” on how organizations can implement monitoring techniques in a fair and lawful manner. </p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MeaYrVLJwwckrchsLimEcT" name="MeaYrVLJwwckrchsLimEcT.jpg" caption="" alt="Office workers in a workspace with monitors on desks" src="https://cdn.mos.cms.futurecdn.net/MeaYrVLJwwckrchsLimEcT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/363929/majority-of-workers-experienced-surveillance-in-the-past-year">Employee surveillance tech risks “spiraling out of control”, TUC warns</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/flexible-working/361937/how-to-avoid-corrupting-your-hybrid-work-strategy">How to avoid corrupting your hybrid work strategy</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361472/one-in-three-uk-workers-now-surveilled-by-employers-at-home">A third of UK workers are surveilled by employers</a></p></div></div><p>Monitoring can include tracking calls, messages and keystrokes, webcam footage or audio recordings, or using “specialist monitoring software” to track worker activity, the ICO said. </p><p>In addition, the advisory outlines best practice techniques for employers to help “build trust with their workers and respect their rights to privacy”. </p><p>This includes informing staff about monitoring practices in a “way that is easy to understand” and ensuring workers are made fully aware of the “nature, extent, and reasons for monitoring”. </p><p>The guidance also warns that organizations must have a “lawful basis” for processing workers data - such as consent or legal obligation. </p><p>This includes the need for <a href="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr">data protection impact assessments</a>, which must be conducted for any monitoring practices that are “likely to result in a high risk” to workers’ rights.</p><h2 id="transparency-in-workplace-monitoring">Transparency in workplace monitoring</h2><p>Emily Keaney, deputy commissioner for regulator policy at the ICO said that while data protection laws permit monitoring, organizations must prioritize <a href="https://www.itpro.com/uk/security/privacy"><u>privacy</u></a> and the potential impact on workers.  </p><p>“As the data protection regulator, we want to remind organizations that business interests must never be prioritized over the privacy of their workers,” she said. </p><p>“Transparency and fairness are key to building trust and it is crucial that organizations get this right from the start to create a positive environment where workers feel comfortable and respected."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LbVXVECgLJ3Ripr3r6rYVA" name="How the way we work will change the Office of the Future.jpg" caption="" alt="How the way we work will change the Office of the Future" src="https://cdn.mos.cms.futurecdn.net/LbVXVECgLJ3Ripr3r6rYVA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><em>Hybrid work continues to be a prevalent approach. Download this eBook now to learn more about designing workspaces for meaningful work experiences</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/how-the-way-we-work-will-change-the-office-of-the-future"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Ella Bond, senior employment solicitor at Harper James, commended the publication of the guidance, and echoed Keaney’s comments on transparency.  </p><p>Organizations that fail to communicate with staff could risk harming relationships with their workforce and impact performance and morale.  </p><p>“It is crucial for employers to strike a balance between managing productivity and performance whilst respecting workers&apos; privacy,” said Bond. “Workers have a legitimate expectation of privacy, even in the course of carrying out their duties.” </p><p>“Monitoring should only be undertaken when it is necessary and proportionate, and it should be conducted in a way that respects workers&apos; rights and freedoms. It is essential that employers communicate clearly with their staff about the nature, extent, and reasons for any monitoring activities. </p><p>“Employers should have clear signage, procedures and policy documentation in place in order to help them to achieve this.”</p><p>Workplace monitoring practices <a href="https://www.itpro.com/business/business-strategy/359712/what-has-the-move-to-remote-working-meant-for-employee-monitoring"><u>have increased significantly</u></a> since the onset of the COVID pandemic in 2020 and the subsequent shift to remote and hybrid working practices as employers sought to keep tabs on employee activities.  </p><p>A 2021 survey conducted by Prospect recorded a <a href="https://www.itpro.com/security/privacy/361472/one-in-three-uk-workers-now-surveilled-by-employers-at-home"><u>sharp rise in cases of webcam and video-based monitoring</u></a> practices among employers.  </p><p>At the time, a majority (52%) of employees polled by the firm said they believe monitoring practices should be banned outright, while 28% said more robust regulation of the trend was required.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Explained: The state of end-to-end encryption in the UK now the Online Safety Bill saga is over ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/explained-the-state-of-end-to-end-encryption-in-the-uk-now-the-online-safety-bill-saga-is-over</link>
                                                                            <description>
                            <![CDATA[ Industry stakeholders have previously criticized the Online Safety Bill over its heavy-handed approach to encryption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iaQT4VRRFQrgMEz8Ar7rjP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VMijHAaX6UXm6jUbbFnym8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Sep 2023 15:26:52 +0000</pubDate>                                                                                                                                <updated>Fri, 22 Sep 2023 15:13:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VMijHAaX6UXm6jUbbFnym8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Online Safety Bill&#039;s encryption policies denoted by a series of gold padlocks lined up side-by-side, with the center padlock cracked down the middle, showing a break]]></media:description>                                                            <media:text><![CDATA[Online Safety Bill&#039;s encryption policies denoted by a series of gold padlocks lined up side-by-side, with the center padlock cracked down the middle, showing a break]]></media:text>
                                <media:title type="plain"><![CDATA[Online Safety Bill&#039;s encryption policies denoted by a series of gold padlocks lined up side-by-side, with the center padlock cracked down the middle, showing a break]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VMijHAaX6UXm6jUbbFnym8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s Online Safety Bill is set to become law after officially passing through parliament on Tuesday. </p><p>Framed by the government as a push to make Britain the “safest place in the world to be online”, the bill will impose requirements on tech firms and social media platforms to moderate and remove illegal content, and will be enforced by Ofcom. </p><p>One of the most prominent debates around the Online Safety Bill so far has been in regard to its so-called ‘spy clause’ allowing the UK government to read messages and files sent over end-to-end encrypted messaging platforms.</p><p>The government’s stance on the matter has been firm, despite heavy pushback from the technology and privacy sectors.</p><p>Some of the most popular encrypted messaging platforms have suggested they would leave the UK if they were compelled to remove <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it"><u>end-to-end encryption</u></a> (E2EE) technology from their products. </p><p>With the bill passing and set to become law imminently, questions still remain over the future of E2EE in the UK. But is it as bad as first thought? </p><p>Here’s what you need to know. </p><h2 id="will-e2ee-still-exist-in-the-uk">Will E2EE still exist in the UK?</h2><p>Simply put, yes. The <a href="https://www.itpro.com/business/policy-legislation/368807/how-will-the-online-safety-bill-change-the-tech-industry"><u>Online Safety Bill</u></a> doesn’t equate to an outright ban of end-to-end encryption. However, there are certain clauses within the bill that will see changes introduced. </p><p>Chief among these is a requirement that encrypted messaging apps, such as WhatsApp or Signal, will be legally obliged to examine user messages for illegal or harmful material, such as terrorism or child abuse-related content. </p><p>Ofcom, the regulator in charge of overseeing the implementation of the bill, can request that providers conduct such activities, on the suspicion of materials being distributed via any given platform. </p><p>This aspect of the bill is a serious point of contention, especially with regard to the feasibility of the practice. </p><h2 id="why-does-the-uk-think-it-can-break-e2ee">Why does the UK think it can break E2EE?</h2><p>The Online Safety Bill specifically mentions the use of “accredited technology” to conduct such assessments, but some industry stakeholders have noted that the wording remains highly ambiguous. </p><p>Earlier this month, techUK deputy CEO Antony Walker questioned the feasibility of this move and raised serious concerns about user <a href="https://www.itpro.com/security/privacy">privacy</a>. </p><p>"One of our biggest concerns centers on Ofcom’s ability to remotely view tests which use live user data, a move that not only poses a security threat but also jeopardizes user privacy,” he said. </p><p>“We urge the government to restrict Ofcom’s ability to view live user data and to ensure these powers are only applied to viewing information in a test environment.”</p><p>"We support the objectives of the Online Safety Bill. Our emphasis lies in the practical implementation of these objectives.”</p><p>The government has repeatedly touted ‘client-side scanning’ as a solution to identifying extreme content distributed via encrypted messaging apps. However, given the nature of encrypted messaging, only the sender and recipient of messages can view the content. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UAy7JoLiKzKxkmEMaJny9e" name="LevelUpYourLogManagement.jpg" caption="" alt="Level up your log management: Six-phase strategy for achieving continuous improvement" src="https://cdn.mos.cms.futurecdn.net/UAy7JoLiKzKxkmEMaJny9e.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Graylog)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about a six-phase strategy that will improve your log management</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/level-up-your-log-management-six-phase-strategy-for-achieving-continuous-improvement">DOWNLOAD FOR FREE</a></p></div></div><p>Providers are unable to access said content. In this context, CSS would require the examination of content before it was even sent. </p><p>Opponents have argued that this is simply unfeasible. Apple famously introduced client-side scanning technology for <a href="https://www.itpro.com/network-internet/email-providers/367882/icloud-mail-review"><u>iCloud</u></a> content, but later rolled back the move after it was found to have serious discrepancies. </p><p>However, research into the use of CSS techniques has been conducted by leading cryptographers in the UK in recent years. </p><p>A 2022 <a href="https://arxiv.org/pdf/2207.09506.pdf" target="_blank">research paper</a> authored by experts at the UK’s NCSC and GCHQ lent credence to the idea that CSS-style content moderation could be achieved without compromising user privacy or security. </p><p>“Researchers rightly point out that poor designs for safety systems could have catastrophic effects on users safety and <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>security</u></a>,” the paper reads. </p><p>“However, we do not believe that the techniques necessary to provide user safety will inevitably lead to these outcomes.”</p><p>This, the paper argued, could include the use of language models “running entirely locally on the client” to detect language related to grooming, for example. </p><p>The paper noted that this would require human moderation in certain circumstances, however. </p><p>“If the model suggests that a conversation is heading towards a risky outcome, the potential victim is warned and nudged to report the conversation for human moderation. </p><p>“Since the models can be tested and the user is involved in the provider’s access to content, we do not believe this sort of approach attracts the same vulnerabilities as others.”</p><h2 id="is-e2ee-weaker-now">Is E2EE weaker now?</h2><p>End-to-end encryption is still very much available to users of apps such as WhatsApp or Signal at present. The government has been keen to emphasize that this doesn’t equate to a ban. </p><p>However, the requirements of the bill do raise questions over the potential long-term implications of encryption for users of such platforms. </p><p>Privacy campaigners have argued that the bill, if passed, will weaken encryption and as a result, wider digital privacy across the country. </p><h2 id="does-the-uk-still-want-to-break-e2ee">Does the UK still want to break E2EE?</h2><p>The government’s stance on end-to-end encryption has been steadfast for several years now. Fundamentally, lawmakers view this as a serious inhibitor for law enforcement in tackling extreme materials online. </p><p>This isn’t the first attempt by the government to tackle the technology, either. </p><p>Former prime minister Theresa May called for new legislation to tackle encryption in the wake of a 2018 terrorist attack in London. In the year prior, she banged the drum for a charge against <a href="https://www.itpro.com/security/encryption">encryption</a> also. </p><p>Two former home secretaries, Amber Rudd and Priti Patel, were both vocal on the matter, calling for stronger legislative powers to tackle the issue. </p><p>The government’s crusade against end-to-end encryption may have temporarily calmed in the wake of the bill’s passing. However, long term, there could be a renewed charge against the technology, providing the feasibility of techniques such as CSS or alternatives are realized</p><h2 id="will-tech-firms-have-to-make-any-changes-to-e2ee">Will tech firms have to make any changes to E2EE?</h2><p>Since there is no actual ban to E2EE, tech firms won’t have to make any changes to the technology itself, but may be responsible for developing, or helping to co-develop, a bespoke tool that can scan encrypted messages “as a last resort”.</p><p>That’s according to technology secretary Michelle Donelan speaking to <a href="https://www.reuters.com/technology/uk-minister-says-position-encryption-not-changed-2023-09-07/" target="_blank"><u><em>Reuters</em></u></a> earlier this month. She also told <em>Times Radio </em>that if tech companies were not implementing adequate mitigations, or showing they can abide by the Online Safety Bill’s requirements, then there would be a conversation about the long-term survival of E2EE.</p><p>She also admitted that the tools don’t currently exist, but pointed to the possible implementations outlined in the paper written by leading cryptographers Dr Ian Levy of the UK’s NCSC and Crispin Robinson of GCHQ.</p><p>Junior minister Stephen Parkinson, addressing the House of Lords, also said that Ofcom’s ability to request for content scanning would be limited to cases only where it was “technically feasible”.</p><p>The statements of the two ministers appear to contradict one another with one saying that tech firms must demonstrate they’re taking steps to adhere to the Online Safety Bill’s requirements, or risk the survival of E2EE altogether, and another saying they won’t have to comply unless it’s technically feasible.</p><h2 id="how-could-the-government-achieve-its-goals-while-maintaining-e2ee">How could the government achieve its goals while maintaining E2EE?</h2><p>According to the paper from Levy and Robinson, due to messages being encrypted and not seen by servers, there must be some activity on the client’s (user’s) side to adequately identify harmful or criminal content.</p><p>The research paper outlined a selection of different methods that could be employed in this scenario, but insisted they don’t endorse any of the methods specifically and understood a range of approaches would likely be necessary to achieve results.</p><p>Included are ‘matching techniques’, whereby media of known abuse images or content would be compared with media being distributed via a service. </p><p>Matching techniques in themselves can be approached from a variety of ways, the paper notes, such as ‘client-side hashing with client-side matching’. </p><p>In this instance, the hashing process and the hashed database of abuse material would be stored on the user’s device. </p><p>While researchers said this approach would afford “maximum privacy” to users as both images and the hash would “never leave the device unless a match occurs”, having the <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm"><u>algorithm</u></a> and database stored on the user’s device could open both up to compromise It’s possible that criminals could reverse-engineer the algorithm or manipulate the database in a way that allows them to evade detection.</p><p>Other techniques, such as ‘client-side hashing with server-side matching’ and ‘hashing with client-server multi-party computation’ were also touted as impactful and E2EE-preserving techniques. </p><p>This would see the hashed material stored on the user’s device and sent to a third-party server that held the database of criminal material. It would lessen the risk of compromising the database itself but not eliminate it entirely. </p><p>“It would be possible, at least in theory, for a malicious server to build a database of all known images, and thereby to gain the capability to discover which images are being shared in the majority of communications,” the paper reads.</p><p>This would be an incredibly expensive way to undermine E2EE, but the cryptographers noted that even the possibility of such a scenario could risk confidence in the model.</p><p>Using a multi-party model, whereby multiple servers communicate with a device to compute the hash would mean less of the algorithm required for the process would be stored on the user&apos;s device, lessening the chance of it being reverse-engineered. It would also mean the server sees less of the material, or in some cases none of it, preserving user privacy.</p><p>There are drawbacks to these approaches that involve a degree of on-device processing, however.</p><p>The possibility of compromising servers, databases, and algorithms have already been acknowledged but what hasn’t been said is the potential for these types of hashing, that connect to a third-party, potentially government-controlled database, to be used for other types of surveillance without the user’s knowledge.</p><p>The Internet Society <a href="https://www.internetsociety.org/resources/doc/2020/fact-sheet-client-side-scanning/" target="_blank"><u>cited</u></a> a 2021 Columbia University <a href="https://www.internetsociety.org/resources/doc/2020/fact-sheet-client-side-scanning/" target="_blank"><u>study</u></a>, saying: “System[s] could be built in a way that gives an agency the ability to preemptively scan for any type of content on any device, for any purpose, without a warrant or suspicion. </p><p>“Likewise, the same techniques to prevent the distribution of child sexual abuse material (CSAM) can be used to enforce policies such as censorship and suppression of political dissent by preventing legitimate content from being shared or blocking communications between users, such as political opponents.”</p><h2 id="why-does-the-uk-want-to-ban-e2ee">Why does the UK want to ban E2EE?</h2><p>The two main arguments for breaking E2EE are to scout out and prevent crimes related to child abuse and terrorism. </p><p>It’s seen as a major inhibitor for law enforcement who cannot monitor content sent over the secure communication protocol like they can with SMS messages or telephone calls, for example.</p><p>The Online Safety Bill is not the first time the UK has tried to break E2EE with legislation. The <a href="https://www.itpro.com/policy-legislation/33407/what-is-the-investigatory-powers-act-2016"><u>Investigatory Powers Act 2016</u></a> also has provisions for encrypted messaging platforms to be “active participants” in data interception efforts - a legal gray area that has not led to any major cases of compromising E2EE for the benefit of law enforcement.</p><p>It’s thought that the UK government has so far resisted enacting its power to ban E2EE outright through fear of losing major tech companies from operating in the UK. </p><h2 id="what-are-the-arguments-against-banning-e2ee">What are the arguments against banning E2EE?</h2><p>Digital privacy campaigners have long fought for E2EE to remain. Encrypted messaging channels are seen as crucial tools in democratic societies to preserve personal privacy from unauthorized actors looking to monitor individuals. These could be the platforms themselves, national governments, or cyber criminals of all flavors (including hackers and stalkers).</p><p>Proponents of E2EE also argue that the crimes that the technology is said to facilitate are not an issue that will be entirely solved, or are caused by, E2EE itself. </p><p>Both crimes against children and terror offenses existed before widespread access to E2EE messaging platforms, and so campaigners argue that efforts should be focused on combating the source of the crime rather than a privacy-preserving technology that, regardless of its merits, undoubtedly helps to protect the worst kind of criminals in the UK.</p><p>If E2EE were banned, criminals would likely seek out alternative forms of anonymity such as a greater reliance on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> to mask their communications. </p><p>While the dark web doesn’t offer the strength of protection for communications as does E2EE, it would still make the work of law enforcement agencies significantly difficult, all while the public is left without a means to communicate privately.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Putting privacy-enhancing technologies to use ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/putting-privacy-enhancing-technologies-to-use</link>
                                                                            <description>
                            <![CDATA[ Data can be protected in use without breaking privacy boundaries ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w5s7QKzvtVWNXAQrQareHU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HfeJbAgkrfB5CesnyHEJUP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Aug 2023 11:49:08 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Aug 2023 16:09:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HfeJbAgkrfB5CesnyHEJUP-1280-80.jpg">
                                                            <media:credit><![CDATA[Future / Unsplash - H Heyerlein]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The words ‘Putting privacy-enhancing technologies to use’ with ‘privacy-enhancing technologies’ highlighted in yellow and the other words in white, against a blurred photo of a person with UV paint spattered on their face, which is glowing in a range of colors. In the bottom right corner, the words ‘ITPro Podcast’ are written.]]></media:description>                                                            <media:text><![CDATA[The words ‘Putting privacy-enhancing technologies to use’ with ‘privacy-enhancing technologies’ highlighted in yellow and the other words in white, against a blurred photo of a person with UV paint spattered on their face, which is glowing in a range of colors. In the bottom right corner, the words ‘ITPro Podcast’ are written.]]></media:text>
                                <media:title type="plain"><![CDATA[The words ‘Putting privacy-enhancing technologies to use’ with ‘privacy-enhancing technologies’ highlighted in yellow and the other words in white, against a blurred photo of a person with UV paint spattered on their face, which is glowing in a range of colors. In the bottom right corner, the words ‘ITPro Podcast’ are written.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HfeJbAgkrfB5CesnyHEJUP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=56365576&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>As the economy has become increasingly dependent on data, companies have sought to make more profit from mining user actions such as through loyalty schemes or social media interactions. </p><p>But individual rights also have to be respected, and businesses have to follow strict data protection procedures.</p><p>Privacy-enhancing technologies (PETs) are one method for companies to securely search through data to derive value – for example, a bank could search through customer data to expose fraudulent activity without putting the personal information of all the customers involved at risk.</p><p>This episode, Rory and Jane are joined by Ellison Anne Williams, CEO and founder of privacy-enhancing technology company Enveil, to discuss the dos and don’ts of data use, and how organizations can make use of PETs for enhanced data mining.</p><h2 id="highlights">Highlights</h2><p>“Gartner predicts that by 2025, you&apos;re going to see about 60% of all large organizations globally, leveraging some form of privacy-enhancing technologies for secure data sharing collaboration, monetization etcetera.”</p><p>“Now, privacy enhancing technologies uniquely protect data in use, when it&apos;s being used or processed, not when the data is sitting at rest in the file system or moving around the network in transit.”</p><p>“So when you talk about allowing any type of organization to be able to securely and privately use data across those boundaries or silos, one form of kind of boundary or silo that you can cross for secure and private data sharing and collaboration is that of organization. So for example, bank to bank, or maybe a healthcare entity to another healthcare entity.”</p><p>“It&apos;s equally applicable even down to the consumer level. However, I don&apos;t believe that&apos;s the way we&apos;re going to see adoption actually occur. I think at first it&apos;s going to follow a natural kind of innovation technology adoption curve, I believe, which is it will start with very large organizations.”</p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/privacy/369840/what-are-privacy-enhancing-technologies-pets"><u>What are privacy-enhancing technologies (PETs)?</u></a></li><li><a href="https://www.itpro.com/security/29671/what-is-aes-encryption"><u>What is AES encryption?</u></a></li><li><a href="https://www.itpro.com/security/encryption/358818/intel-joins-forces-with-darpa-to-help-build-encryption-holy-grail"><u>Intel joins forces with DARPA to help build encryption ‘holy grail’</u></a></li><li><a href="https://www.itpro.com/strategy/28071/what-is-machine-learning"><u>What is machine learning and why is it important?</u></a></li><li><a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai"><u>What are the pros and cons of AI?</u></a></li></ul><h2 id="subscribe">Subscribe</h2><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154" target="_blank"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M" target="_blank"><u>Subscribe to The IT Pro Podcast on Google Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ" target="_blank"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup" target="_blank"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://www.itpro.co.uk/magazine-signup" target="_blank"><u>Subscribe to IT Pro 20/20</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon's Ring agrees to $5.8m settlement over alleged use of its cameras to spy on female customers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/amazons-ring-agrees-to-dollar58m-settlement-over-alleged-use-of-its-cameras-to-spy-on-female-customers</link>
                                                                            <description>
                            <![CDATA[ The firm will also pay $25m for allegations Alexa stored child voice recordings indefinitely ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2TUX5pmVorsx9LnvYHyp5P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZHxyN3Axi5CJxLUoBRP4G8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Jun 2023 11:36:35 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 07:38:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZHxyN3Axi5CJxLUoBRP4G8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ring doorbell camera mounted on a door frame]]></media:description>                                                            <media:text><![CDATA[Ring doorbell camera mounted on a door frame]]></media:text>
                                <media:title type="plain"><![CDATA[Ring doorbell camera mounted on a door frame]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZHxyN3Axi5CJxLUoBRP4G8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon subsidiary Ring has agreed to a $5.8 million settlement over allegations it failed to prevent employees from violating customer privacy.</p><p>The Federal Trade Commission (FTC) laid out the claims in a complaint, which stated that every Ring employee and hundreds of third-party contractors had full access to customer videos prior to February 2018.</p><p>One employee was found to have viewed “thousands of video recordings belonging to at least 81 unique female users” including video feeds from bathrooms and bedrooms. </p><p>A co-worker of the employee is said to have discovered the activity by chance and reported it to a supervisor. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dtpH7ABWWxgvQp4kuATPb9" name="Protect and Preserve Your Data from Endpoint to Infrastructure_listing.jpg" caption="" alt="Whitepaper cover with title and background circuit board image" src="https://cdn.mos.cms.futurecdn.net/dtpH7ABWWxgvQp4kuATPb9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell Technologies)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Protect and preserve your data from endpoint to infrastructure</strong></p><p class="fancy-box__body-text"><em>Achieve cyber resilience with help from a powerhouse partnership</em></p><p class="fancy-box__body-text"><strong>DOWNLOAD FOR FREE</strong></p></div></div><p>Details of the misconduct were laid out in the FTC’s <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/complaint_ring.pdf"><u>complaint</u></a> [PDF], which alleged that no action was initially taken against the perpetrator and it was only after all the victims were proven to have been women that they were terminated.</p><p>“We want our customers to know that the FTC complaint draws on matters that Ring promptly addressed on its own, well before the FTC began its inquiry; mischaracterizes our security practices; and ignores the many protections we have in place for our customers,” Ring <a href="https://blog.ring.com/about-ring/rings-response-to-our-recent-settlement-with-the-ftc/" target="_blank"><u>wrote</u></a>.</p><p>“While we disagree with the FTC’s allegations and deny violating the law, this settlement resolves this matter so we can focus on innovating on behalf of our customers.”</p><p>Although employees used this access for legitimate purposes such as for training Amazon <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm"><u>algorithms</u></a>, the FTC found that adequate notice or consent of this practice was not given to customers.</p><p>Policies that required Ring employees or contractors to receive customer consent to access their videos were not put in place until February 2019.</p><p>The FTC stated that Ring has been unable to identify the number of employees that accessed videos prior to this date.</p><p>Although employees were required to sign an agreement prohibiting misuse of data, the complaint alleged, they were not provided with training on <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures"><u>data privacy or data security</u></a> prior to May 2018.</p><p>The complaint also alleged that Ring did not secure its devices against <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>hacking techniques like brute force attacks</u></a> and <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks"><u>credential stuffing</u></a>, which led to the compromise of 55,000 customers’ accounts.</p><p>Hackers gained access to video feeds from around 1,250 devices, with 40% of these being internal cameras. In some cases, threat actors used the intercom functions of the devices to verbally harass victims inside their homes.</p><p>This is not the first time that Ring has been put in the spotlight over privacy concerns.</p><p>In 2022, the firm admitted it had <a href="https://www.itpro.com/security/privacy/368542/amazon-gave-police-ring-footage-without-permission"><u>given police departments device footage without user consent</u></a> on 11 occasions that calendar year.</p><p>At the time, the firm stated that it had determined the disclosure of videos “without delay” had helped to prevent the danger of serious injury or death.</p><p>In 2019, a Ring vulnerability let <a href="https://www.itpro.com/internet-of-things-iot/34786/ring-doorbells-leak-users-wi-fi-passwords-in-clear-text"><u>hackers intercept Wi-Fi passwords in clear text</u></a> which exposed victims to follow-up attacks.</p><h2 id="further-fines-for-alexa-child-privacy-allegations">Further fines for Alexa child privacy allegations</h2><p>Amazon has also agreed to a $25 million settlement over allegations it violated privacy laws pertaining to children and misled parents over its data practices.</p><p>The firm was accused of retaining voice recordings of children indefinitely, and in violation of a children’s privacy law that allows parents to request deletion.</p><p>An official FTC <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/Amazon-Complaint-%28Dkt.1%29.pdf" target="_blank"><u>complaint</u></a> [PDF], filed by the Department of Justice, stated that Amazon acted in violation of the Children’s Online Privacy Protection Act (COPPA) by retaining voice recordings and transcripts of children for “longer than is reasonably necessary”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ovMSxaaARrLd4LYsh7bM4m" name="The Business Value of Zscaler Data Protection_listing.jpg" caption="" alt="Whitepaper cover with male and female colleague looking at, and pointing to, a digital padlock" src="https://cdn.mos.cms.futurecdn.net/ovMSxaaARrLd4LYsh7bM4m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The business value of Zscaler Data Protection</strong></p><p class="fancy-box__body-text"><em>Understand how this tool minimizes the risks related to data loss and other security events</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/the-business-value-of-zscaler-data-protection"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Amazon policy states that Alexa data will be deleted upon request and that parents can choose whether it is retained, but the FTC found that until September 2019 parents were required to delete data themselves.</p><p>It also alleged that Amazon failed to honor deletion requests in violation of COPPA. The FTC noted that child voice recordings are valuable to Amazon as training data for its algorithms.</p><p>The firm denied the allegations, and in a <a href="https://www.aboutamazon.com/news/policy-news-views/amazon-response-to-ftc-settlement-regarding-alexa?tag=cnet-buy-button-20&ascsubtag=06c6440b4da642dba7ea45aef6eaccfe%7C9afbea0b-e7fd-42d6-9bb5-0f1baee416f8%7Cdtp%7Ccn" target="_blank"><u>blog post</u></a> drew attention to the privacy measures already in place to protect Alexa data.</p><p>“We take our responsibilities to our customers and their families very seriously,” Amazon stated.</p><p>“We have consistently taken steps to protect customer privacy by providing clear privacy disclosures and customer controls, conducting ongoing audits and process improvements, and maintaining strict internal controls to protect customer data. While we disagree with the FTC’s claims and deny violating the law, this settlement puts the matter behind us, and we believe it’s important to put the settlement in the right context.”</p><p>Alvaro M Bedoya, the commissioner of the FTC, noted that Amazon’s justification for retaining data was inadequate.</p><p>“Today’s settlement sends a message to all those companies: Machine learning is no excuse to break the law,” he stated. </p><p>“Claims from businesses that data must be indefinitely retained to improve algorithms do not override legal bans on indefinite retention of data. The data you use to improve your algorithms must be lawfully collected and lawfully retained. Companies would do well to heed this lesson.”</p><p>In addition to the settlement, Amazon will be required to delete child data including geolocation, and will be barred from using said data to train algorithms.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shopify bets on 'Audiences' tool to combat Apple's tracking restrictions for retailers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/e-commerce/369787/shopify-bets-on-audiences-tool-to-combat-apples-tracking-restrictions</link>
                                                                            <description>
                            <![CDATA[ The ecommerce giant hopes its millions of customers will benefit from the Apple-compliant customer-targeting capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u9uwaP4PSgKnaJyF1epZSu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JeaGxaSeEoMA4qiBvFrzSk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jan 2023 13:16:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JeaGxaSeEoMA4qiBvFrzSk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Illustration of a Shopify logo displayed on a smartphone]]></media:description>                                                            <media:text><![CDATA[Illustration of a Shopify logo displayed on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Illustration of a Shopify logo displayed on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JeaGxaSeEoMA4qiBvFrzSk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Shopify has committed to providing its retail customers with new avenues to target prospective customers in the wake of Apple's ongoing privacy crackdown.</p><p>According to CEO Harley Finkelstein, Shopify aims to invest heavily into its 'Audiences' marketing tool which launched last year. Further development of Audiences aims to enable retailers housed on the platform to boost engagement with customers now it's more difficult to track iPhone users' shopping habits.</p><p>Finkelstein told the <a href="https://www.ft.com/content/84ea2a9c-c28d-42a6-b3a9-0d6cc0fb37bb"><em>Financial Times</em></a> that the rollout of Audiences with be a “key area of focus” moving forward. The tool allows retailers on the platform to consolidate customer data, improve outreach and ad targeting, and is integrated with Meta and Google’s advertising platforms. </p><p>Through this, the company said that <a href="https://www.itpro.com/strategy/28225/cmo-job-description-what-does-a-cmo-do" data-original-url="https://www.itpro.com/strategy/28225/cmo-job-description-what-does-a-cmo-do">marketers</a> will be able to better target ads at “lookalike” customers based on purchases from other retailers. Shopify told the <em>FT</em> that the system is designed specifically to compensate for Apple’s current rules on tracking iPhone users.</p><p>Similarly, Finkelstein said the new tool will enable <a href="https://www.itpro.com/development/web-development/368256/shopify-website-builder-review" data-original-url="https://www.itpro.com/development/web-development/368256/shopify-website-builder-review">Shopify</a> to compete with Amazon’s rapidly-expanding advertising business. </p><h2 id="competitive-landscape">Competitive landscape </h2><p>The expansion of Amazon’s <a href="https://www.itpro.com/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media">advertising</a> division poses a significant challenge for Shopify, which is used by more than 1.7 million retailers globally. Advertising revenue at Amazon increased rapidly across the second and third quarters of 2022, surging by around 30% in Q3 and surpassing $9.5 billion. </p><p>While this poses a lingering threat to Shopify, ongoing changes to how Apple processes and shares user data are also prompting concerns amidst a significant slowdown in the global ecommerce industry. </p><p>New requirements on data processing for iPhone users mean that users can now choose to opt out of tracking between apps and websites. The decision sparked major upheaval across the advertising industry, with businesses raising concerns that they will be effectively blocked from targeting users. </p><p>Meta was a <a href="https://www.itpro.com/security/privacy/361406/facebook-youtube-snap-lose-10bn-apple-app-tracking-user-consent" data-original-url="https://www.itpro.com/security/privacy/361406/facebook-youtube-snap-lose-10bn-apple-app-tracking-user-consent">vocal critic</a> of the move, with the social media giant claiming that advertising on its family of platforms will become less effective without the ability to target users. </p><p>However, while the move by Apple raised concerns across the industry, Amazon is among a number of firms set to benefit from the decision due to its policy of targeting ads based on first-party data. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/web-development/368201/how-to-build-a-website-with-shopify" data-original-url="/development/web-development/368201/how-to-build-a-website-with-shopify">How to build a website with Shopify</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/development/web-development/368211/squarespace-vs-shopify" data-original-url="/development/web-development/368211/squarespace-vs-shopify">Squarespace vs Shopify</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/business-apps/355470/new-shopify-app-helps-people-shop-local-from-the-safety-of-home" data-original-url="/software/business-apps/355470/new-shopify-app-helps-people-shop-local-from-the-safety-of-home">Shopify's new app helps people shop local from the safety of home</a></p></div></div><p>Shopify believes that the expansion of its Audiences tool will allow retailers to continue targeting customers in a similar fashion to pre-Apple changes and engage with customers via Instagram, Google’s search engine, and YouTube platform. </p><p>A key factor in this move is that retailers will be able to opt in to adding customer data to a broader pool, which it claims will constitute “first-party” data. </p><p>But although Finkelstein insisted there will be long-term benefits for merchants leveraging the platform, some have raised minor concerns about sharing data within a larger pool that might include rival businesses’ data sets. </p><p>There’s always going to be some apprehension about sharing data,” Finkelstein said. “But that’s often offset by, net net, am I making more money, am I selling more?” </p><h2 id="industry-disruption">Industry disruption </h2><p>Shopify announced last year that it planned to implement more than $46 billion in cutbacks across the business while company share values dropped by nearly 75% compared to a 2021 peak. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xGGDnAjNSsM78xP8HcDtUB" name="xGGDnAjNSsM78xP8HcDtUB.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/xGGDnAjNSsM78xP8HcDtUB.jpg" mos="https://cdn.mos.cms.futurecdn.net/xGGDnAjNSsM78xP8HcDtUB.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Technology Ecosystem benchmark report</strong></p><p class="fancy-box__body-text">The evolution of the IT industry</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/369703/technology-ecosystem-benchmark-report" data-original-url="/technology/369703/technology-ecosystem-benchmark-report">FREE DOWNLOAD</a></p></div></div><p>In July, the firm also announced more than 1,000 redundancies after encountering an unexpected slowdown in ecommerce sales in the wake of a pandemic-induced boom. </p><p>The <a href="https://www.itpro.com/network-internet/web-hosting/368197/best-ecommerce-website-builders-in-2022" data-original-url="https://www.itpro.com/network-internet/web-hosting/368197/best-ecommerce-website-builders-in-2022">ecommerce</a> giant appears concerned over the prospect of heightened industry competition ahead of a <a href="https://www.itpro.com/business/business-strategy/369075/as-the-global-economic-downturn-hits-big-tech-small-businesses" data-original-url="https://www.itpro.com/business/business-strategy/369075/as-the-global-economic-downturn-hits-big-tech-small-businesses">looming recession</a>. As such, enabling retailers to bolster engagement and outreach could be crucial as the company weathers difficult market conditions. </p><p>“Especially right now, merchants want to be able to find more customers,” Finkelstein told the <em>FT</em>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World Cup security expert says devices have "a huge potential to be abused” ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369734/world-cup-security-expert-says-devices-have-a-huge-potential-to-be-abused</link>
                                                                            <description>
                            <![CDATA[ As audiences prepare for the World Cup final, fans have been urged to remain vigilant for cyber threats and potential disruption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s1o9bCXC7g8C3TdBKWh24A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cfHvauSS6pAct3EWuXoKy7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Dec 2022 12:37:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cfHvauSS6pAct3EWuXoKy7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World Cup trophy against a city skyline backdrop]]></media:description>                                                            <media:text><![CDATA[World Cup trophy against a city skyline backdrop]]></media:text>
                                <media:title type="plain"><![CDATA[World Cup trophy against a city skyline backdrop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cfHvauSS6pAct3EWuXoKy7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A World Cup security expert has warned that personal devices are among the most serious cyber security considerations tournament organisers face amid concerns over attacks targeting the event.</p><p>Michael Smith, field CTO at Neustar Security Services, who led the cyber security strategy for the 2014 World Cup and Winter Olympics, said threat actors could target devices and applications to launch damaging cyber attacks.</p><p>“This is a fascinating topic,” he told <em>IT Pro</em>. “It’s been commonplace for a long time to use mobile applications for events. They hold our stadium tickets and our schedule. People at the event use social media applications to share events and interact with the event, its sponsors, and other attendees.”</p><p>While event apps provide attendees with vital information and complement the visitor experience, there is a risk attached as user data can be harvested and used for nefarious reasons, Smith warned.</p><p>“It has a huge potential to be abused. If you build the application to export the data without any other kind of logic, the user really doesn’t know how or what you are using.”</p><p>In November, European privacy regulators warned that two official <a href="https://www.itpro.com/security/369537/qatar-world-cup-apps-prompt-digital-privacy-warnings" data-original-url="https://www.itpro.com/security/369537/qatar-world-cup-apps-prompt-digital-privacy-warnings">World Cup apps</a> posed serious privacy and security risks.</p><p>Germany’s data protection commissioner said that data collected by the two apps “goes much further” than what the respective privacy notices claim. These concerns reached such a point that security experts advised visitors to use blank phones if they were absolutely required to download them.</p><p>This isn’t the first occasion that a global sporting event has triggered security concerns either. Earlier this year, Chinese authorities were accused of using <a href="https://www.itpro.com/security/362110/fbi-urges-olympic-athletes-to-leave-personal-devices-at-home" data-original-url="https://www.itpro.com/security/362110/fbi-urges-olympic-athletes-to-leave-personal-devices-at-home">official event apps</a> to harvest user data and monitor athlete communications during the Beijing Winter Olympics. </p><h2 id="hacktivism-and-disruption">Hacktivism and disruption</h2><p>While data privacy risks for users were a key recurring topic throughout the build-up to the Qatar World Cup, Smith said that broader external threats are also a serious cause for concern.</p><p>Large sporting events are “very interesting” from the perspective of attackers and offer a prime opportunity to cause serious disruption to the event, target a huge pool of potential victims, and capitalise on the inevitable strain placed on infrastructure by the influx of visitors.</p><p>“An event like the World Cup is more like an ecosystem than it is a single unified event,” he says. “As a security expert, this means that you have a wide variety of attackers with different abilities and goals which leads to having multiple targets that need protecting.”</p><p>The two key targets include online resources such as websites and local digital infrastructure, and end-users at the event itself.</p><p>“Online targets such as the official event website where the schedule, results, and news are posted is like a 24/7 news site, and a common attacker objective is to cause a website outage or a defacement to get publicity about their issue.”</p><p>During the preparation for the 2014 World Cup in Brazil, hacktivists caused serious disruption amidst concerns that vital funds were being allocated to build stadiums rather than improve housing and address long-running social issues.</p><p>Smith watched this process unfold in real-time in 2014 and said that cyber threats rapidly escalated as hacktivists sought to raise wider awareness of their respective causes.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect" data-original-url="/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect">Stifling Russian disinformation through hacktivism 'having the opposite effect'</a></p></div></div><p>“The protest shifted into the online sphere, and at first focused on the state and local government,” he explained. “The hacktivists were wildly successful as far as their technical and tactical goals: gaining system access, stealing data, posting sensitive information in public, and causing website outages.”</p><p>Before long, <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivists</a> shifted their attention to a broader pool of critical targets. Attacks were launched against the Brazilian central government, critical infrastructure, and well-known Brazilian brands.</p><p>Similarly, organisations outside of Brazil were targeted, including <a href="https://www.itpro.com/security/32275/fifa-discloses-massive-hack-as-internal-documents-are-leaked-to-press" data-original-url="https://www.itpro.com/security/32275/fifa-discloses-massive-hack-as-internal-documents-are-leaked-to-press">FIFA</a> and official World Cup sponsors.</p><h2 id="final-security-concerns">Final security concerns</h2><p>With previous instances of hacktivist-led disruption at sporting occasions, it comes as no surprise that security experts have been watching events closely in Qatar.</p><p>The competition has been fraught with long-running claims of corruption and criticism of domestic social policies, making the final an opportune moment for hacktivists to make a statement on the global stage.</p><p>In late November, the warning signs were already there. Hacktivists waged a successful attack on the Qatari Ministry of Justice which saw a large volume of data stolen from a web application <a href="https://www.itpro.com/cloud/367937/best-cloud-databases-in-2022" data-original-url="https://www.itpro.com/cloud/367937/best-cloud-databases-in-2022">database</a> and disruption to the website.</p><p>Ahead of the final, Smith said there is a serious risk that threat actors will attempt to disrupt the occasion by targeting official websites and broadcasting.</p><p>“Live video streaming from the stadium is usually licensed to a series of broadcasters and can be disrupted by a <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS) attack</a> against the entry point where the distribution network gets the video feed,” he said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369537/qatar-world-cup-apps-prompt-digital-privacy-warnings" data-original-url="/security/369537/qatar-world-cup-apps-prompt-digital-privacy-warnings">Qatar World Cup apps prompt digital privacy warnings from regulators</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32037/summer-dip-in-malware-attacks-credited-to-world-cup-drama" data-original-url="/security/32037/summer-dip-in-malware-attacks-credited-to-world-cup-drama">Summer dip in malware attacks credited to World Cup drama</a></p></div></div><p>“Or, in a worst-case, admittedly movie-plot scenario, the attackers [could] change the video feed to show their own content.”</p><p>The prospect of a movie-plot-type scenario isn’t as far-fetched as it seems. Earlier this week, US-based sports broadcaster FuboTV was the target of a sophisticated cyber attack which knocked services offline during the semi-final between France and Morocco.</p><p>The outage sparked a wave of complaints from frustrated viewers who were unable to watch France battle for a hard-earned victory.</p><p>In a statement, the broadcaster confirmed that the outage was due to a “criminal cyber attack” and revealed it was working with <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> firm Mandiant to investigate the incident.</p><h2 id="ticketing-risk">Ticketing risk</h2><p>Visitors attending the final in person on Sunday are also at risk of the disruption posed by cyber attacks, Smith said. </p><p>In 2014, Smith's teams were forced to contend with a piece of bot <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> known as ‘Scorpyn Scanner’ which affected ticket sales infrastructure. With match tickets being released on a timed basis, this <a href="https://www.itpro.com/network-internet/bots/360765/bad-bots-make-up-huge-slice-of-internet-traffic-and-target-e-commerce" data-original-url="https://www.itpro.com/network-internet/bots/360765/bad-bots-make-up-huge-slice-of-internet-traffic-and-target-e-commerce">malicious bot</a> would reserve tickets and cause serious disruption to customers. </p><p>“When it detected that tickets were released, it would reserve them and pop up a dialogue in the users’ browser so that they could click through and fulfil the order. However, people were running this bot and doing the online equivalent of queue-cutting, resulting in people not getting their tickets,” he said. </p><p>“Bots like this are still being used and are easy to find through simple Google searches.” </p><h2 id="don-t-take-risks-with-personal-devices">Don’t take risks with personal devices </h2><p>For fans on the ground in Qatar this weekend, Smith issued a final warning over the prospect of using personal mobile devices at the event.</p><p>Similar to calls made by European privacy regulators, Smith says that using mobile devices places fans at great risk and advised them to take steps to mitigate potential threats.</p><p>“For the Sochi and Beijing Olympics, there were a lot of warnings about not taking electronic devices into those countries because they have a higher risk of your device getting attacked,” he said.</p><p>“These hacked devices are then taken home or to work where they are then connected to a different network, enabling attackers to use that malware to pivot into that network. Those attackers are criminal gangs or <a href="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses" data-original-url="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses">nation-state actors</a> who want to hack devices in order to get access to other systems.</p><p>“One thing I would take under serious consideration is taking a device to a sporting event. If you need to take it, the best practice would be enabling airplane mode, so it doesn’t connect to a network.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data governance and privacy for data leaders ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/data-insights/369356/data-governance-and-privacy-for-data-leaders</link>
                                                                            <description>
                            <![CDATA[ Create your ideal governance and privacy solution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gBVipNJyLkSDUNP8VZ4NBC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Oct 2022 12:26:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper library with title and logo and man cycling over a bridge]]></media:description>                                                            <media:text><![CDATA[Whitepaper library with title and logo and man cycling over a bridge]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper library with title and logo and man cycling over a bridge]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Few things are more important than having quality data that is easy to use, but simultaneously secure and compliant. Being unable to fulfil this need can result in erroneous insights and reduced customer trust. </p><p>This whitepaper analyses several topics related to data governance and privacy such as scalability, establishing and implementing organisation-wide standards, and data lineage and traceability. Building blocks like data cataloguing, automated metadata generation, and reporting are also covered alongside a discussion of how governance and privacy are related to a data fabric.</p><p>Download now to learn more from real-world examples featuring ING.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49813/ibm-q4-2022-en?locale=1&p=false&wp=10353"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Identity theft: What to do if the worst happens ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368587/identity-theft-what-to-do-if-the-worst-happens</link>
                                                                            <description>
                            <![CDATA[ Act quickly to minimize damage as a result of identity theft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aXpEreBrSkiAXZm6BACPtT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AEaJn4dBVm2zS6KPMMVaVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Oct 2022 01:20:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Katy Ward ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/mK5dqajh2RY5ELrk7JW2CZ.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AEaJn4dBVm2zS6KPMMVaVW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A graphic presenting two people emerging from laptops with one person being a criminal posing as a customer]]></media:description>                                                            <media:text><![CDATA[A graphic presenting two people emerging from laptops with one person being a criminal posing as a customer]]></media:text>
                                <media:title type="plain"><![CDATA[A graphic presenting two people emerging from laptops with one person being a criminal posing as a customer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AEaJn4dBVm2zS6KPMMVaVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Business owners are constantly hearing about the threat of identity theft, but would you know what to do if you were a victim? Would you feel confident you could act swiftly to minimize any damage? For many entrepreneurs, the answer is no.</p><p>According to Javelin’s <a href="https://www.javelinstrategy.com/coverage-area/2020-identity-fraud-study-genesis-identity-fraud-crisis">2020 Identity Fraud Survey</a>, this type of crime affected 13 million American consumers during 2019, and the total losses stood at almost $17 billion. Once a hacker has access to your business’s information or the personally identifiable data (PID) of your clients, they can buy goods illegally, take out a new line of credit, or even claim a fraudulent tax refund. </p><p>Even if you have one of the support packages discussed in our guide to the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection</a>, there are further steps you can take if your business’s data has been compromised.</p><p>It took the average victim of a data breach 280 days to detect the crime, according to data from IBM. More than any other, this statistic highlights the importance of acting quickly if you are a victim of this type of crime. However, the most effective actions you can take when it comes to identity theft and what to do about it are, in fact, preventative. </p><p>As you probably know, identity thieves often gain access to their victims’ data by rifling through their garbage or stealing their mail. It’s therefore essential you carefully dispose of any correspondence containing your personal details.</p><p>With many cases of identity theft taking place in cyberspace, it’s also crucial to take all the precautions you can to secure devices in your home and work networks against data breaches. It perhaps goes without saying that the principal step you should take is to routinely change the passwords on all your online accounts, ensuring you use random strings of numbers and letters.</p><p>As well as installing robust antivirus software, you might want to select a package that offers a VPN: a virtual private network, which will keep your details anonymous when browsing the internet.</p><h2 id="step-1-contact-the-relevant-fraud-departments">Step 1: Contact the relevant fraud departments </h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qKxoxbyQZKxzzWvaKgTb8S" name="" alt=""Fraud Alert" on a computer screen" src="https://cdn.mos.cms.futurecdn.net/qKxoxbyQZKxzzWvaKgTb8S.jpg" mos="https://cdn.mos.cms.futurecdn.net/qKxoxbyQZKxzzWvaKgTb8S.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>If you suspect you’ve been a victim of identity theft, the feelings of stress and anxiety can be overwhelming. Luckily, most banks and credit card companies offer dedicated fraud departments, with specially trained advisors who can help you deal with these matters.</p><p>Contacting these departments should be your first port of call if you suspect you have been a victim. The first step the bank or credit card company is likely to take is to freeze your account, cancel your cards, and work with you to change your security details.</p><p>Even if you don’t have access to any paper statements about your account, you should be able to find the relevant phone numbers online. If information such as your Social Security number has also been used in the fraud, you may also want to notify the Internal Revenue Service.</p><h2 id="step-2-notify-your-threat-protection-company">Step 2: Notify your threat protection company</h2><p>If you have <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">identity theft protection</a>, the next step you need to take is to report the matter to the company that provides your policy. As a part of their services, these providers will work to restore the affected accounts, which should dramatically reduce the amount of stress you experience. </p><p>These services often involve freezing your credit, cancelling any cards that have been issued, and arranging replacements. Depending on the policy you choose, the company may also cover any legal costs associated with the crime.</p><h2 id="step-3-report-the-crime-to-the-police-ftc">Step 3: Report the crime to the police/FTC</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mSUZh7mjxZb3ikPEyeV6mb" name="" alt="The FTC crest on a building" src="https://cdn.mos.cms.futurecdn.net/mSUZh7mjxZb3ikPEyeV6mb.jpg" mos="https://cdn.mos.cms.futurecdn.net/mSUZh7mjxZb3ikPEyeV6mb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>As a victim of identity theft, your first priority may be to limit the damage to your finances and future credit. However, you shouldn’t forget that identity theft is also a serious crime, and you should file a report with your local police department. As well as alerting the authorities to the crime, doing so can create a paper trail in the event of further investigation into the fraud. </p><p>You should also report the matter to the Federal Trade Commission (FTC), which monitors data on identity theft. As well as working with government agencies such as the FBI, the FTC can work with you to create a personalized recovery plan.</p><h2 id="step-4-run-a-credit-check">Step 4: Run a credit check</h2><p>If you discover your PID has been stolen, there is a strong chance that more than one account will have been affected. The most effective method of checking for anomalies with your data is to run business credit checks with Equifax, Experian, and Dun & Bradstreet, which are the three major credit reporting bureaus. </p><p>You should also consider running a check on your personal finances. In order to do so, you should consult Experian and Equifax, as well as TransUnion. As a part of this process, you can ask for a fraud notification to be added to your file, which will notify potential borrowers checking your credit that your identity has been stolen in the past.</p><h2 id="step-5-gather-evidence">Step 5: Gather evidence</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aTx4FwTRwcMbgz9CFCWWhn" name="" alt="business finance" src="https://cdn.mos.cms.futurecdn.net/aTx4FwTRwcMbgz9CFCWWhn.jpg" mos="https://cdn.mos.cms.futurecdn.net/aTx4FwTRwcMbgz9CFCWWhn.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>While you’ll no doubt be feeling overwhelmed as a result of the crime, it’s a good idea to provide as many details as possible about your business’s account when contacting the relevant fraud departments. It also helps if you can thoroughly explain the reasons you believe you have been the victim of fraud. </p><p>You’ll also be in a stronger position if you can provide a record of your activities during the period in which the fraud occurred, in order to demonstrate you could not have committed the theft.</p><h2 id="step-6-get-everything-in-writing">Step 6: Get everything in writing</h2><p>If your suspicions prove correct and you have indeed been the victim of identity theft, you may - in a worst-case scenario - struggle to prove you haven’t taken out certain loans, and find yourself pursued for debts you don’t owe.</p><p>Whenever you speak to a company representative over the phone, you should keep a note of the employee’s name and the time of the call. It’s also worth sending a follow-up email to confirm the details of your conversation, and request a confirmation of receipt from the company.</p><h2 id="step-7-seek-specialized-legal-advice">Step 7: Seek specialized legal advice</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fhduH3aUV9J3X5bAYS7m4k" name="" alt="Statue of a woman holding scales of justice" src="https://cdn.mos.cms.futurecdn.net/fhduH3aUV9J3X5bAYS7m4k.jpg" mos="https://cdn.mos.cms.futurecdn.net/fhduH3aUV9J3X5bAYS7m4k.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Bigstock)</span></figcaption></figure><p>If you can afford to do so, it’s essential you contact a lawyer who has specialized experience in dealing with this type of crime. However difficult it may be for you to accept, the companies involved in the fraud may not automatically believe your version of events, and you may find yourself a suspect. In another major plus point, your lawyer may be able to deal with your alleged creditors on your behalf regarding the identity theft and what to do about it.</p><h2 id="step-8-notify-affected-clients">Step 8: Notify affected clients</h2><p>As a business owner, you’re likely to be in a position of trust in which your clients enter some of their PID into your systems. Should you fall victim to a data breach, this means it isn’t only your data that could be at risk.</p><p>If your clients’ information has been compromised, you should let the affected individuals know as soon as possible, so they can take appropriate steps in order to minimize damage to their own identities. As such an incident has significant potential for reputational damage and also potential legal implications, it’s wise to take legal advice if your clients’ data has been stolen, as well as consulting your own PR department, if you have one. </p><h2 id="summary">Summary</h2><p>When it comes to identity theft and what to do about it, your first instinct may be to panic as you struggle to determine what to do next. Fortunately, there are numerous steps you can take to minimize damage, and get your company’s finances in order.</p><p>One point to bear in mind is that you needn’t wait until your business’s data has been compromised to follow certain good hygiene practices in cyberspace, such as regularly changing your passwords and purchasing <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">identity theft protection software</a>. However much of a cliché it may sound, the best offense against identity theft could be a good defense.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Identity theft: How to check if your ID has been stolen ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368585/identity-theft-how-to-check-if-your-id-has-been-stolen</link>
                                                                            <description>
                            <![CDATA[ A step-by-step guide to keeping your identity safe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8zMmAdDTVTDGFh3j1MViU6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xa8grchEzV9sYX23atEPEW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Oct 2022 00:11:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Liam Barker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/NnKnoi2YbR2Hsv2WZsHKmi.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xa8grchEzV9sYX23atEPEW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man entering fake ID information onto a computer]]></media:description>                                                            <media:text><![CDATA[Man entering fake ID information onto a computer]]></media:text>
                                <media:title type="plain"><![CDATA[Man entering fake ID information onto a computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xa8grchEzV9sYX23atEPEW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity theft is a serious and unnerving crime. You could be a victim of it for some time without realizing, after which you might be left with troubling financial, or even legal, repercussions.</p><p>What’s more, identity theft can take several forms—from credit card cloning to online account hacking. Therefore, exploring the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection</a> is a wise move.</p><p>If you’re worried that you might be vulnerable to ID theft, there are some tell-tale signs to look out for, as well as proactive steps you can take to stay safe—all of which we’ll discuss in this article. Here’s everything you need to know about identity theft and how to check if you've been a victim of this crime. </p><h2 id="step-1-check-your-bank-account-for-unusual-transactions">Step 1: Check your bank account for unusual transactions</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QZz6UPiXADLxn3EBZwjus3" name="" alt="Woman's hand on a smartphone showing a mobile banking app" src="https://cdn.mos.cms.futurecdn.net/QZz6UPiXADLxn3EBZwjus3.jpg" mos="https://cdn.mos.cms.futurecdn.net/QZz6UPiXADLxn3EBZwjus3.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It’s important to carefully and regularly check your bank account and credit card statements—ideally every week—so you can quickly spot unfamiliar transactions. If you know the normal patterns of your expenditure, you can easily identify unusual activity.</p><p>Check for outgoing payments to vendors/services you don’t recognize, as well as any other spending or cash withdrawals that don’t seem right—however small. These could be signs that a criminal has stolen your banking or credit card details, perhaps by hacking into one of your online accounts or by cloning your card at an ATM.</p><p>If you’re sure that a transaction wasn’t made by you, you should immediately report it to your bank/credit card company. The faster you raise the red flag, the less damage a criminal can do.</p><h2 id="step-2-check-for-suspicious-activity-on-your-online-accounts">Step 2: Check for suspicious activity on your online accounts</h2><p>These days, most people have multiple online accounts containing sensitive data, including your home address, date of birth, and banking details. Therefore, these accounts are natural targets for identity thieves.</p><p>It’s important to look out for any activity that you can’t explain, including login attempts from unknown devices or locations, unauthorized password changes, and unfamiliar times and dates relating to last access. These could be indications that a cybercriminal has hacked into your account and should be investigated.</p><p>If you’re confronted with suspicious activity, re-secure your account by changing your password, remotely logging out on all devices, and enabling two-factor authentication (which means a second piece of verifying information, like a passcode or PIN, must be provided to log in). You’ll also want to check your bank account to see if any unrecognized purchases have been made.</p><h2 id="step-3-look-out-for-unusual-emails-texts-and-letters">Step 3: Look out for unusual emails, texts, and letters</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Jz34rF8RYaQCCP96PiRyCV" name="" alt="Somebody checking their phone next to a burger" src="https://cdn.mos.cms.futurecdn.net/Jz34rF8RYaQCCP96PiRyCV.jpg" mos="https://cdn.mos.cms.futurecdn.net/Jz34rF8RYaQCCP96PiRyCV.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Mail from an unfamiliar, official source could be an indicator of identity theft. This might be something like a letter from a bailiff demanding payment for debts you don’t owe, or a registration email or text message from a paid service you didn’t sign up for.</p><p>Unsolicited mail may not seem like a big issue, but if it doesn’t feel right, don’t be tempted to pass it off as misdirected junk. Instead, contact the helpline of the relevant service provider, company, or bank and ask them to investigate any irregularities.</p><h2 id="step-4-take-note-of-how-much-mail-you-re-receiving">Step 4: Take note of how much mail you’re receiving</h2><p>One tell-tale sign of identity theft is if the amount of mail you’ve received over a four or five-month period has noticeably decreased. This is particularly true for postal bank or credit card statements but it can also apply to emails—especially if you’ve opted to go paperless.</p><p>If you haven’t received your usual statements or other regular mail for a while, and your bank or provider can’t account for the delay, it’s worth alerting your postal service to the possibility of fraudulent mail redirection.</p><p>Additionally, if you’re waiting for a new credit card that should have arrived weeks ago, contact your credit card provider and query the delay. There might be a harmless explanation, but it’s also possible that an opportunist may have intercepted it.</p><h2 id="step-5-check-your-credit-report">Step 5: Check your credit report</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QpiPQPZEVXTUM7FzEFjz87" name="" alt="A padlock clipped on a yellow credit card perched on a keyboard" src="https://cdn.mos.cms.futurecdn.net/QpiPQPZEVXTUM7FzEFjz87.jpg" mos="https://cdn.mos.cms.futurecdn.net/QpiPQPZEVXTUM7FzEFjz87.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Checking your credit report is an effective way to see if any large loans have been applied for in your name, and several companies can provide this service for free. It’s advisable to check your credit score at least once a year—if not quarterly or every month—to make sure you have an accurate record of your financial activities.</p><p>If your credit score is inexplicably low, it might be a sign of fraudulent activity. Check the contents of the report carefully to see if you can spot anything untoward.</p><p>If something is obviously amiss that you can’t find an explanation for, you should contact a consumer credit bureau such as Equifax, Experian, or TransUnion, and outline the problem.</p><h2 id="step-6-check-for-data-breaches">Step 6: Check for data breaches</h2><p>Data breaches are unfortunate and, sadly, largely beyond most people’s control. Thankfully, it’s possible to check if your personal information has been involved in a data leak.</p><p>Firstly, if you become aware that a company holding your personal details has fallen victim to a breach, you can contact them to see whether your data was leaked. Secondly, you can use a free online service like Firefox Monitor or Have I Been Pwned, to check if your email address has been linked with any known data breaches.</p><p>Having your personal details leaked doesn’t automatically mean that you will have had your identity stolen. That said, it does increase the likelihood, as your details may have featured on dark web marketplaces. So, it’s wise to invest in an advanced antivirus suite that includes continual dark web monitoring, such as Norton 360 with LifeLock.</p><h2 id="step-7-check-your-tax-return-status">Step 7: Check your tax return status</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DjQ5tYvxKveXzkGuqYTG2N" name="" alt="tax return form and calculator" src="https://cdn.mos.cms.futurecdn.net/DjQ5tYvxKveXzkGuqYTG2N.jpg" mos="https://cdn.mos.cms.futurecdn.net/DjQ5tYvxKveXzkGuqYTG2N.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Individuals may become aware of identity theft when they go to submit an electronic tax return and find it’s automatically rejected. In these cases, it could be that a criminal has already submitted one in the victim’s name, to gain access to their tax refund.</p><p>If you’re concerned that this might have happened to you, you can log in to your online tax account to check if any unfamiliar tax returns have been submitted. Should you find you’ve become a victim of tax-refund identity theft, contact the revenue service’s fraud department without delay.</p><h2 id="step-8-check-that-your-id-documents-aren-t-missing">Step 8: Check that your ID documents aren’t missing</h2><p>This might seem a little obvious, but keeping a watchful eye over your ID is important, especially when you’re out in public spaces.</p><p>If you lose your passport or driver’s license, for example, there’s a chance it could be picked up by a criminal who can then use it to steal your identity. Similarly, a mislaid credit card could be used to make dubious financial transactions if it’s not swiftly reported to your credit lender and cancelled.</p><h2 id="summary-2">Summary</h2><p>Although identity theft can be difficult to detect, these tell-tale signs and their subsequent actions can help you protect yourself from ID fraud.</p><p>It’s important to keep a close eye on your bank account and credit card statements, as well as on any emails, letters, and texts you receive. It’s also worthwhile checking to see if your personal details have been involved in any online data breaches, while exploring different identity theft protection providers can give you the upper hand over fraudsters.</p><p>In all cases, proactivity is the key to keeping your data safe. By keeping tabs on your regular spending activities and any correspondence you receive, you should be able to spot any irregularities before they become a bigger problem.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Best identity theft companies  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367833/best-identity-theft-companies</link>
                                                                            <description>
                            <![CDATA[ With data breaches happening daily, it’s time to check out the best identity theft companies to safeguard your information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">86oJYgNWWPmxaY58QxKYNW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rRtDLPPnZoJHu3KCebfkDo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 20:55:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ritoban Mukherjee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YyxtgeDS3pnqqJBiJU3DFH.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rRtDLPPnZoJHu3KCebfkDo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[woman unlocking smartphone in front of laptop]]></media:description>                                                            <media:text><![CDATA[woman unlocking smartphone in front of laptop]]></media:text>
                                <media:title type="plain"><![CDATA[woman unlocking smartphone in front of laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rRtDLPPnZoJHu3KCebfkDo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>According to a <a href="https://www.statista.com/statistics/273550/data-breaches-recorded-in-the-united-states-by-number-of-breaches-and-records-exposed">recent study</a>, there were over 12,000 data breaches in the US between 2008 and 2020. That’s millions of people who have had their sensitive personal data exposed online. Even today, you will be surprised at how easy it is to find leaked credit card details online if you know where to look. </p><p>Whether you are an individual or run or own a business, it has become more important than ever to secure your identity from potential fraud, be it online or offline. A good identity theft protection service can help you do just that.</p><p>The best identity theft companies use a variety of techniques to keep your personal data safe from online abuse. In exchange for a fee, they will carefully monitor any data breaches to make sure that your information hasn’t been exposed anywhere. And if there’s a breach that concerns you, knowing that your information has been compromised at the right time can make all the difference.</p><h2 id="the-best-identitity-theft-companies-for-protecting-your-identity">The best identitity theft companies for protecting your identity</h2><h3 class="article-body__section" id="section-1-norton-lifelock"><span>1. Norton LifeLock</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QAEM8YdzJXFfvksZDKZKmj" name="" alt="Norton LifeLock's homepage" src="https://cdn.mos.cms.futurecdn.net/QAEM8YdzJXFfvksZDKZKmj.jpg" mos="https://cdn.mos.cms.futurecdn.net/QAEM8YdzJXFfvksZDKZKmj.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  >Pros</th><th  >Cons</th></tr></thead><tbody><tr><td  >Proactive support</td><td  >Expensive</td></tr><tr><td  >Theft insurance</td><td  ></td></tr><tr><td  >Dark web monitoring</td><td  ></td></tr><tr><td  >VPN service</td><td  ></td></tr></tbody></table></div><p><a href="https://www.jdoqocy.com/click-8900245-14433466?sid=hawk-custom-tracking">LifeLock</a> was acquired by <a href="https://securitycloud.symantec.com">Symantec</a>, the company behind <a href="http://www.norton.com">Norton Antivirus</a>, in 2017. Since then, it has made great strides establishing trust as an identity protection service. Its yellow interface denotes a feeling of trust, marked by a clean dashboard that gives you all the necessary tools right at your fingertips. Just by looking at the UI, you can tell that this is a company that cares about customer experience.</p><p>Right now, LifeLock offers comprehensive packages that monitor online traffic, dark web activity, finance applications, court records, and much more to issue real-time alerts whenever someone attempts to do anything criminal under your name. In the event that your identity does get stolen, LifeLock will take care of all the legal heavy lifting so that you can continue to live your life. Its team will make the necessary calls, inform all concerned authorities, and fill official forms to ensure that everything gets back to normal as soon as possible. </p><p>There are <a href="https://www.jdoqocy.com/click-8900245-14433466?sid=hawk-custom-tracking">several plans</a> to choose from. LifeLock Standard, which costs $8.99 a month, offers credit monitoring and social security number protection. It also comes with $25,000 in theft protection insurance. LifeLock Select, which also costs $8.99, offers all of this on top of a virtual private network (VPN). The pricing is only for the first year, however, after which Standard costs $12 and Select costs $15 a month. Then there’s LifeLock Advantage, which costs $20 a month. Finally, LifeLock Ultimate Plus sets you back $34.99 and offers $100,000 in insurance.</p><p>Read our full <a href="https://www.itpro.com/security/cyber-security/367985/norton-lifelock-review" data-original-url="https://www.itpro.com/security/cyber-security/367985/norton-lifelock-review">Norton LifeLock review</a>.</p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$8.99 a month+</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$25,000+</td></tr><tr><td  ><strong>Features</strong></td><td  >Credit monitoring, social security number protection, dark web activity</td></tr></tbody></table></div><h3 class="article-body__section" id="section-2-identityforce"><span>2. IdentityForce</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GVMmVk7Uch5JAshTob2PVk" name="" alt="IdentityForce's pricing plans" src="https://cdn.mos.cms.futurecdn.net/GVMmVk7Uch5JAshTob2PVk.jpg" mos="https://cdn.mos.cms.futurecdn.net/GVMmVk7Uch5JAshTob2PVk.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  >Pros</th><th  >Cons</th></tr></thead><tbody><tr><td  >Reasonably priced</td><td  >None, really</td></tr><tr><td  >Anti-phishing and keylogger protection</td><td  ></td></tr><tr><td  >Real-time alerts</td><td  ></td></tr><tr><td  >Intuitive dashboard</td><td  ></td></tr></tbody></table></div><p>Based in Massachusetts, <a href="https://secure.identityforce.com/sales_landing">IdentityForce</a> has versatile protection plans for individuals, businesses, and government agencies alike. Its most basic plan offers access to credit reports from providers like <a href="http://www.equifax.com">Equifax</a> and <a href="http://www.experian.com">Experian</a>, whereas higher-tier subscriptions offer monitoring services for social security numbers, bank accounts, mailing addresses, and even the sex offender registry. With that, IdentityForce keeps track of any potential abuse of your identity and takes necessary steps to secure you against fallout.</p><p>Software-wise, IdentityForce is available as a web-based client as well as a smartphone app. It even throws in additional security services like keylogger protection and anti-phishing software to stop your data from being stolen in the first place. </p><p>There’s also a social media monitoring network that scans for fake accounts under your name on Facebook, Instagram, YouTube, and Twitter. All of this, combined with regular alerts via email and messaging, provide for complete peace of mind as you go about your daily business.</p><p>IdentityForce is <a href="https://www.identityforce.com/products-and-pricing/products-and-pricing">priced reasonably</a>, starting at just $8.99 a month, and it comes with an insurance cover of up to $1 million. If you require additional features, you can also upgrade to a plan that adds credit monitoring for a total of $19.99 a month. </p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$8.99 a month+</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$1 million</td></tr><tr><td  ><strong>Features</strong></td><td  >Credit report monitoring, social security protection, social media lookups</td></tr></tbody></table></div><h3 class="article-body__section" id="section-3-experian-identityworks"><span>3. Experian IdentityWorks</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VvuG92yoYBnvi9WwM9jCCK" name="" alt="Experian IdentityWorks' website" src="https://cdn.mos.cms.futurecdn.net/VvuG92yoYBnvi9WwM9jCCK.jpg" mos="https://cdn.mos.cms.futurecdn.net/VvuG92yoYBnvi9WwM9jCCK.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  >Pros</th><th  >Cons</th></tr></thead><tbody><tr><td  >Affordably priced</td><td  >Focuses mainly on credit</td></tr><tr><td  >Clean interface</td><td  >Past breaches may reduce trust</td></tr><tr><td  >Social media and dark web scanning</td><td  ></td></tr><tr><td  >Court record monitoring</td><td  ></td></tr></tbody></table></div><p>Experian is the same credit reporting agency that’s infamous for a 2015 data breach that exposed the email accounts of 15 million customers. While that doesn’t necessarily exude confidence, its identity protection service may still be worth considering in 2021. <a href="https://www.experian.com/consumer-products/compare-identity-theft-products.html">IdentityWorks</a> specializes in credit report monitoring, but it also keeps track of other activity, like dark web activity, social media accounts, court records, and bank transactions, to give you a comprehensive protection plan against identity theft. </p><p>Once you’re logged in to the interface, IdentityWorks presents you with a professionally-designed dashboard that goes to great lengths to ensure that you understand what you’re looking at. Everything is very clearly explained, with an onboarding wizard that takes you through the steps for getting set up. There is no jargon anywhere, and the console is very easy to familiarize yourself with. </p><p>In terms of <a href="https://www.experian.com/consumer-products/compare-identity-theft-products.html">payment plans</a>, the IdentityWorks Plus plan consists of credit report monitoring and dark web scanning. It comes with $500,000 in identity theft insurance, and costs $8.33 a month for one adult and up to 10 children. It’s easy to add another adult to the plan for another $8.33. </p><p>IdentityWorks Premium offers more well-rounded protection, monitoring court records and social networks, among other things. The insurance amount also goes up to $1 million, and the plan costs $19.99 a month. </p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$8.33 a month+</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$500,000</td></tr><tr><td  ><strong>Features</strong></td><td  >Credit report monitoring, dark web scanning, court record monitoring</td></tr></tbody></table></div><h3 class="article-body__section" id="section-4-privacyguard"><span>4. PrivacyGuard</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="imw6DRfJu7AKWRYqrNcY7C" name="" alt="PrivacyGuard's homepage" src="https://cdn.mos.cms.futurecdn.net/imw6DRfJu7AKWRYqrNcY7C.jpg" mos="https://cdn.mos.cms.futurecdn.net/imw6DRfJu7AKWRYqrNcY7C.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  >Pros</th><th  >Cons</th></tr></thead><tbody><tr><td  >Pick only what you need</td><td  >No family plan</td></tr><tr><td  >Trial plan available</td><td  >No social media monitoring</td></tr><tr><td  >Anti-keylogger and secure browser</td><td  ></td></tr></tbody></table></div><p>Owned and operated by the Trilegiant Corporation, <a href="https://www.privacyguard.com">PrivacyGuard</a> offers credit reporting and identity protection services in exchange for a fee. At the base level, the credit monitoring plan is actually offered separately from identity protection, which means that if you want both, you’ll need to subscribe to the costliest plan. </p><p>Services include everything from social security monitoring to credit fraud protection, depending on the <a href="https://www.privacyguard.com/plans-pricing.html">plan you choose</a>. While this means you can pick and choose what you need, it also stands to reason that you’ll end up paying more if you need both services. </p><p>The identity theft protection service comes with dark web surveillance, social security event monitoring, annual public records reports, online fraud assistance, stolen credit card protection, anti-keylogging software, and secure web browsing. The credit report monitoring solution actually costs more, offering three-bureau credit reports, credit record monitoring, and online fraud assistance. It also comes with an anti-keylogger and a secure browser. </p><p>PrivacyGuard ID Protection costs $9.99 a month and offers $1 million in insurance. PrivacyGuard Credit Protection sets you back $19.99 a month and offers 24/7 credit monitoring. PrivacyGuard Total Protection offers the benefits of both plans for $24.99. If you’d like to try out the service before you commit, you can go for the trial plan, which costs $1 per day for the first 14 days of your subscription. </p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$9.99 a month+</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$1 million</td></tr><tr><td  ><strong>Features </strong></td><td  >24/7 credit monitoring, identity theft insurance, dark web surveillance</td></tr></tbody></table></div><h3 class="article-body__section" id="section-5-identity-guard"><span>5. Identity Guard</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jjUvwBogJEjvXXJLMenyKQ" name="" alt="Identity Guard's homepage" src="https://cdn.mos.cms.futurecdn.net/jjUvwBogJEjvXXJLMenyKQ.jpg" mos="https://cdn.mos.cms.futurecdn.net/jjUvwBogJEjvXXJLMenyKQ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  >Pros</th><th  >Cons</th></tr></thead><tbody><tr><td  >AI-powered enhanced protection</td><td  >Annual credit reports only</td></tr><tr><td  >Detailed scans and real-time alerts</td><td  >No credit monitoring in base plan</td></tr><tr><td  >Credit monitoring features</td><td  ></td></tr></tbody></table></div><p>Founded in 1996, <a href="https://www.identityguard.com">Identity Guard</a> uses proprietary machine learning algorithms developed by IBM Watson to constantly scan the internet for potential threats of identity theft. It issues real-time alerts to protect users against data leaks through websites, public records, and social media activity. For example, it scans the dark web for any potential mentions of your social security number to ascertain whether you might be exposed. It also provides annual credit reports to its users through Equifax, Experian, and <a href="http://www.transunion.com">TransUnion</a>.</p><p>In a market saturated with competition, Identity Guard adds extra edge to its offering by using IBM Watson’s artificial intelligence technology. This strategic partnership helps the identity protection service identify possible data leaks faster than any other service provider on this list. It also comes with secure browsing and payment protection tools as an added bonus to subscribers. The highest-tier plan also includes a monthly credit score from TransUnion.</p><p>Identity Guard offers <a href="https://www.identityguard.com/plans">three different subscription plans.</a> Value provides the most basic protection, with dark web scanning, safe browsing, and anti-phishing tools. You also gain access to a caseworker who will assist you with reclaiming your identity should the worst-case scenario ever happen. It costs $7.50 a month for individuals and $12.50 a month for families. </p><p>The Total plan offers all of this along with credit monitoring for $16.67 a month for individuals and $25 a month for families. Finally, the Identity Guard Ultra plan provides the most benefits, with three-bureau credit reports, card monitoring, criminal records scans, and sex offender registry monitoring. It costs $25 a month for individuals and $33.33 a month for families. </p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$7.50 a month+</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$1 million</td></tr><tr><td  ><strong>Features </strong></td><td  >IBM Watson, secure browsing, credit score monitoring</td></tr></tbody></table></div><h3 class="article-body__section" id="section-6-complete-id"><span>6. Complete ID</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wGxjmV5HDPEntptadELCXm" name="" alt="Complete ID's homepage" src="https://cdn.mos.cms.futurecdn.net/wGxjmV5HDPEntptadELCXm.jpg" mos="https://cdn.mos.cms.futurecdn.net/wGxjmV5HDPEntptadELCXm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  ><strong>Pros</strong></th><th  >Cons</th></tr></thead><tbody><tr><td  >Reliable provider</td><td  >Lacks distinguishing features</td></tr><tr><td  >Comprehensive credit monitoring services</td><td  >Interface could use a rework</td></tr><tr><td  >$1 million insurance with zero deductibles</td><td  ></td></tr></tbody></table></div><p><a href="https://www.completeid.com/pricing">Complete ID</a> is the product of a partnership between Experian and <a href="https://www.costco.com">Costco</a>. It offers wholesome identity protection services at attractive price rates. It’s packed with features like dark web scanning and social security monitoring. Apart from identity protection, Complete ID also offers credit monitoring and identity restoration services. While the user interface is a bit clunkier than the other providers on this list, the <a href="https://www.completeid.com/pricing">highly affordable packages</a> make it well worth the compromise.</p><p>Complete ID scans court records, criminal databases, financial accounts, and change of address requests to locate and flag potential cases of identity theft. It also scans the dark web for your social security number (SSN). As it is owned by Experian, you can expect an in-depth credit monitoring service to go along with your plan. Detailed credit reports are obtained from all three credit bureaus and alerts are issued whenever someone opens an account with your information. </p><p>In case your identity gets stolen, Complete ID offers theft coverage of up to $1 million with no deductibles. This should be enough to cover things like legal fees, lost income, and emotional duress. The interface is clean and easy to use, even if slightly outdated.</p><p>Complete ID requires you to have a Costco membership in order to sign up. It usually costs $13.99 per user per month, but Costco Executive members get a discounted rate of $8.99. You can extend your coverage to include up to five children for another $3.99 a month ($2.99 if you have a Costco Executive membership).</p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$13.99 a month+</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$1 million</td></tr><tr><td  ><strong>Features </strong></td><td  >Three-bureau credit reports, dark web scanning, court records checking</td></tr></tbody></table></div><h3 class="article-body__section" id="section-7-adt-identity-theft-protection"><span>7. ADT Identity Theft Protection</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UWGFYg62fznewsQSVeCiT4" name="" alt="ADT Identity Theft Protection's homepage" src="https://cdn.mos.cms.futurecdn.net/UWGFYg62fznewsQSVeCiT4.jpg" mos="https://cdn.mos.cms.futurecdn.net/UWGFYg62fznewsQSVeCiT4.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div ><table><thead><tr><th  >Pros</th><th  >Cons</th></tr></thead><tbody><tr><td  >Trusted brand</td><td  >Annual credit report only</td></tr><tr><td  >Highly affordable</td><td  >Lacks distinguishing features</td></tr><tr><td  >$1 million in theft protection</td><td  ></td></tr></tbody></table></div><p>ADT is a company best known for its smart alarms and motion detectors. <a href="https://www.adt.com/identity-theft-protection">ADT Identity Theft Protection</a>, however, is a new service that expands its offerings to security in the digital space. For a surprisingly affordable price, the company gives you access to features like theft insurance, credit monitoring, dark web scanning, financial account security, passport monitoring, and more. While these are run-of-the-mill features that you can get from any service provider, the brand reputation and price affordability alone make this deal worth considering.</p><p>Most services at this price point offer $100,000 to $500,000 in insurance. But not ADT. With no-strings-attached coverage up to $1 million, ADT Identity Theft Protection makes for a solid offering indeed. You are limited to only one credit report per year, but you can always obtain unlimited free credit reports from a website like <a href="https://www.annualcreditreport.com">Annual Credit Report</a>.</p><p>There aren’t any major extras to speak of, but the package covers your most essential identity protection needs. Experian and Equifax offer limited plans at a similar price range, but they have both experienced data breaches that have been on the news for quite some time.</p><p>ADT Identity Theft Protection costs $9.99 a month. You can’t just sign up online, though; you have to call a dedicated hotline. You can also chat with the sales team online if you have questions. </p><div ><table><tbody><tr><td  ><strong>Price</strong></td><td  >$9.99 a month</td></tr><tr><td  ><strong>Insurance coverage</strong></td><td  >$1 million</td></tr><tr><td  ><strong>Features</strong></td><td  >Dark web scanning, annual credit report, passport monitoring</td></tr></tbody></table></div><ul><li>Read our guide to <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">the best online security suite</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Identity theft: What it is, and how it can affect your business ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367885/identity-theft-what-it-is-and-how-it-can-affect-your-business</link>
                                                                            <description>
                            <![CDATA[ Discover clear identity theft definitions, and the various forms this crime can take ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2RBpvoYUjzSBefh9PrY77f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9bRcgDy4shEwju6sTm7nY4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 20:54:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Katy Ward ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/mK5dqajh2RY5ELrk7JW2CZ.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9bRcgDy4shEwju6sTm7nY4-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[person holding glasses up to focus on MacBook on desk]]></media:description>                                                            <media:text><![CDATA[person holding glasses up to focus on MacBook on desk]]></media:text>
                                <media:title type="plain"><![CDATA[person holding glasses up to focus on MacBook on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9bRcgDy4shEwju6sTm7nY4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you're a business owner, you're no doubt concerned about any threat to your data and that of your customers, with identity theft being one of the most dangerous forms of cybercrime. </p><p>In fact, identity theft has become so prevalent that it now affects approximately one in 20 Americans every year, according to Javelin’s 2020 Identity Fraud Survey.</p><p>But even if you’re already using one of the packages discussed in our guide to the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection</a>, do you really know what identity theft is? And are you aware of the impact it could have on your business? </p><p>We’ll provide identity theft definitions, and walk you through some of the key points every business owner needs to know in order to safeguard themselves against this increasingly common form of cybercrime.</p><h2 id="identity-theft-definition">Identity theft - definition</h2><p>As the name suggests, identity theft is the act of stealing another individual’s personal details, often with the intention of applying for credit or buying goods illegally in that person's name. Tax fraud is a common form of identity theft, in which a criminal uses a victim’s data to file a tax return and illegally claim a refund.</p><p>The consequences of identity crime can be devastating. Should credit be taken out in your name or that of your company, you could face significant difficulties in proving that you did not indeed take out the credit or purchase the item yourself. In a worst-case scenario, you could find yourself pursued for a debt you don’t owe.</p><p>Even if you’re able to demonstrate your identity has been stolen, you could discover your credit has been destroyed by the incident, leaving you and your business unable to borrow money in the future through legitimate means.</p><p>As a business owner, it’s also important to be aware of employment identity theft, in which a perpetrator uses another person’s details to falsely apply for employment.</p><h2 id="how-does-identity-theft-happen">How does identity theft happen?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZhCZqVKFo3W9gQebcFVZzc" name="" alt="stack of Social Security cards" src="https://cdn.mos.cms.futurecdn.net/ZhCZqVKFo3W9gQebcFVZzc.jpg" mos="https://cdn.mos.cms.futurecdn.net/ZhCZqVKFo3W9gQebcFVZzc.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>For many identity thieves in the USA, gaining access to their victims’ Social Security number is key to the crime. Once a criminal is in possession of this information, he or she can easily represent themselves as the intended victim when dealing with financial institutions.</p><p>Non-digitally, identity theft has historically occurred when a perpetrator went through another’s post or rubbish in order to uncover correspondence, such as bank statements or tax details. In the case of businesses, criminals could obtain your details by entering your premises or stealing your business’s files, which can expose both your own information and that of your clients.</p><p>Other identity thieves may use similar low-tech methods of gaining access to your company’s details. They may, for example, call or email your business to ask for details about the organisation, perhaps masquerading as a potential customer, claiming to sell services, or claiming to represent a market research agency. </p><p>Account takeover is another common form of identity theft in which perpetrators, especially hackers, illegally gain access to another person's accounts in order to change passwords or transfer funds.</p><h3 class="article-body__section" id="section-the-dangers-of-cyberspace"><span>The dangers of cyberspace</span></h3><p>In an increasingly digital landscape, it’s no surprise that old-school methods of identity theft are becoming less widespread, with many cases of identity theft against businesses occurring in cyberspace. </p><p>One of the most common forms of attack is through the use of spyware, in which a piece of malicious software covertly monitors a company’s online activity by gaining access to a hard drive within the company’s network, and then sharing this information with third parties. </p><p>Man-in-the-middle attacks are another common method of identity theft. Using this tactic, a hacker will monitor any business activity conducted over unsecured networks, and then steal information such as login details. Once inside your organisation's network, the criminal can easily access your most sensitive information.</p><p>Yet not all attacks in cyberspace need to be so high-tech. Hackers can frequently gain access to personal information the victim has (over) shared on social media. This can leave sole proprietors especially vulnerable, as these individuals often reveal a great deal of information about themselves online in order to promote their brands. </p><p>One point to bear in mind, given the rise of remote working, is the potential risk employees pose when logging into your network from home via their own devices and home Wi-Fi. In many cases, personal devices and networks lack adequate threat protection software, which could leave your entire business network vulnerable to attack.</p><h3 class="article-body__section" id="section-learn-from-big-name-casualties"><span>Learn from big-name casualties</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XmkGwKGGhpozA7xCjEccsF" name="" alt="Zoom displayed on a laptop and smartphone" src="https://cdn.mos.cms.futurecdn.net/XmkGwKGGhpozA7xCjEccsF.jpg" mos="https://cdn.mos.cms.futurecdn.net/XmkGwKGGhpozA7xCjEccsF.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Zoom)</span></figcaption></figure><p>As we all know, stories of large-scale data breaches are constantly hitting the headlines. Some of the more high-profile examples include an attack against video conferencing giant Zoom. In April 2020, it was widely reported that the personal details of more than 500,000 users, including email addresses and passwords, had been found for sale on the dark web.</p><p>Although you probably don't class your business in the same league as Zoom, it's nevertheless essential to recognize the potential devastation a breach could cause. Should you fall victim to an attack, the reputation damage to your business could be devastating, and you may never recover your customers’ trust. </p><p>In more extreme cases, falling victim to a beach could potentially destroy your business. If, in the event of a data breach, your customers determine you have been negligent with your cybersecurity measures, they may decide to take legal action, leaving you with catastrophic legal bills.</p><p>As proof of this, aviation giant British Airways is currently facing an estimated $3.3 billion bill following a data breach that took place in 2018 in which the personal details of more than 43,000 passengers were exposed.</p><h3 class="article-body__section" id="section-get-the-right-tech-in-place"><span>Get the right tech in place</span></h3><p>With threats such as spyware and man-in-the middle attacks posing a risk to your data, it’s essential you have a comprehensive antivirus software in place. When you’re choosing threat protection software, it’s wise to look for a plan that provides a VPN: a virtual private network that will keep you anonymous when browsing the internet.</p><p>If you’re particularly concerned about the threat of identity theft across your business, however, you may want to take additional precautions. A number of companies offer specialized <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">identity theft services</a> to offer additional support. <a href="https://www.identityforce.com">IdentityForce</a>, for example, provides fraud monitoring services to alert you if your data is used illegally, as well as offering 24/7 support services and $1 million of identity theft cover.</p><h3 class="article-body__section" id="section-not-all-threats-are-external"><span>Not all threats are external</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p9ksmdAtBg3SYAUNk5hawK" name="" alt="office workers" src="https://cdn.mos.cms.futurecdn.net/p9ksmdAtBg3SYAUNk5hawK.jpg" mos="https://cdn.mos.cms.futurecdn.net/p9ksmdAtBg3SYAUNk5hawK.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It’s tempting to imagine that all data breaches originate from organized gangs of cybercriminals, or teenage hackers locked away in their bedrooms. It may therefore be a surprise to learn that most data breaches are caused by human error, according to research from CybSafe.</p><p>As a business owner, it’s therefore vital you provide your employees with adequate training on the potential dangers of identity theft, and ensure they understand the rules surrounding confidentiality within your organization.</p><h3 class="article-body__section" id="section-conclusion"><span>Conclusion</span></h3><p>Although we constantly hear about the importance of being on our guard in many aspects of our lives, vigilance really is the key to protecting your business against the threat of identity theft. Being familiar with identity theft definitions and the various guises the crime can take is the first step toward taking effective precautions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 14 identity theft statistics that'll make you want ID protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367947/14-identity-theft-statistics-thatll-make-you-want-id-protection</link>
                                                                            <description>
                            <![CDATA[ Check out these 14 identity theft statistics to see if you need identity theft protection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">484Swg6YTXbUuMhGSmn4bZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eRtHvms9qKRSgcWXaFnR5o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 20:54:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nikshep Myle ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8xJpkPnHQV9hRzzUHoTYyb.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eRtHvms9qKRSgcWXaFnR5o-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[person searching for someone on Facebook on Mac and iPhone]]></media:description>                                                            <media:text><![CDATA[person searching for someone on Facebook on Mac and iPhone]]></media:text>
                                <media:title type="plain"><![CDATA[person searching for someone on Facebook on Mac and iPhone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eRtHvms9qKRSgcWXaFnR5o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>We’ve witnessed tremendous advancements in the digital world. But as our digital tools grow powerful, so does the threat from cybercriminals. Identity theft, especially, has grown rampant over the years. It’s risen steadily across the globe, and many identity theft protection applications have been launched to curb this trend. </p><p>In this article, we’ll go over 14 identity theft statistics that may help you determine whether you need protection. If you choose to opt for it, you can read our guide to the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection</a> to find the right software for yourself. </p><ul><li><a href="https://www.itpro.com/security/privacy/367885/identity-theft-what-it-is-and-how-it-can-affect-your-business" data-original-url="https://www.itpro.com/security/privacy/367885/identity-theft-what-it-is-and-how-it-can-affect-your-business">Identity theft: What it is, and how it can affect your business</a></li></ul><h2 id="1-there-s-a-new-identity-theft-victim-every-two-seconds">1. There’s a new identity theft victim every two seconds</h2><p>It’s an understatement to say that cybercrime is increasing rapidly. The fact that every two seconds there’s a new victim of identity fraud is testimony to this. In the US alone, <a href="https://www.iii.org/fact-statistic/facts-statistics-identity-theft-and-cybercrime#:~:text=In%202020%2C%201.4%20million%20complaints,from%2020%20percent%20in%202019.">there were close to 1.4 million reports of identity theft in 2020</a>. What’s more shocking is that it’s more than twice the number of reports from 2019. </p><ul><li><a href="https://www.itpro.com/security/privacy/368587/identity-theft-what-to-do-if-the-worst-happens" data-original-url="https://www.itpro.com/security/privacy/368587/identity-theft-what-to-do-if-the-worst-happens">Identity theft: What to do if the worst happens</a></li></ul><h2 id="2-social-media-users-are-at-a-46-higher-risk">2. Social media users are at a 46% higher risk</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="o4rUCDcyB8eo4h2sm7nfuh" name="" alt="Social media icons on phone screen" src="https://cdn.mos.cms.futurecdn.net/o4rUCDcyB8eo4h2sm7nfuh.png" mos="https://cdn.mos.cms.futurecdn.net/o4rUCDcyB8eo4h2sm7nfuh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Social media users are more likely to experience fraud compared to those who aren’t active on these platforms. As exciting as it may feel to be active on social media, cybercriminals too are actively seeking targets through these platforms. </p><p>This particularly applies to users active on Instagram, Facebook, and Snapchat, who are at a <a href="https://www.javelinstrategy.com/press-release/identity-fraud-hits-record-high-154-million-us-victims-2016-16-percent-according-new">46% higher risk of identity theft</a>. The popularity of a platform doesn’t guarantee foolproof safety. For example, during the Cambridge Analytica scandal of 2018, around 50 million accounts on Facebook had their data compromised. </p><h2 id="3-40-of-fraud-happens-within-24-hours-of-account-takeover">3. 40% of fraud happens within 24 hours of account takeover</h2><p>Improvements in technology are making it easier for cybercriminals to gain unauthorized access to people’s online accounts. Without a powerful security application, users may not even realize that their data has been compromised. This is dangerous, seeing how <a href="https://www.javelinstrategy.com/press-release/identity-fraud-losses-increase-15-percent-consumer-out-pocket-costs-more-double">40% of fraud happens within 24 hours of account takeover</a>. </p><h2 id="4-kids-are-more-likely-to-be-identity-theft-victims-than-adults">4. Kids are more likely to be identity theft victims than adults</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QtfUohEjr8JETVzZ9iyvJK" name="" alt="child using tablet" src="https://cdn.mos.cms.futurecdn.net/QtfUohEjr8JETVzZ9iyvJK.jpg" mos="https://cdn.mos.cms.futurecdn.net/QtfUohEjr8JETVzZ9iyvJK.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Children and teenagers often lack financial experience and are not cautious about the websites they visit and the data they share online. This makes them <a href="https://tylerpaper.com/news/business/protect-your-child-from-identity-theft/article_f7373b1e-b942-11e8-9b63-db622f5cf8c6.html">51 times more likely to face identity theft</a> compared to an adult.</p><h2 id="5-more-than-1-million-children-in-the-us-experienced-identity-theft-in-2017">5. More than 1 million children in the US experienced identity theft in 2017</h2><p>Cybercriminals value a child’s data over an adult’s because there’s no existing record and it’s easy to create a new identity and open a line of credit. Since children now leave digital footprints earlier than they used to, they’re also more susceptible to identity theft. <a href="https://www.businessinsider.com/over-1-million-children-were-victims-of-identity-theft-in-2017-2018-4">2017 saw over 1 million children in the US facing identity theft</a>, resulting in a loss of $2.6 billion. </p><h2 id="6-consumers-lost-more-than-1-9-billion-to-identity-theft-in-2019">6. Consumers lost more than $1.9 billion to identity theft in 2019</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cTtvKDWLopcxZ6gCMj5dV5" name="" alt="A photo of a person holding a bank card in one hand and their phone in the other, sitting at a laptop and making a purchase online" src="https://cdn.mos.cms.futurecdn.net/cTtvKDWLopcxZ6gCMj5dV5.jpg" mos="https://cdn.mos.cms.futurecdn.net/cTtvKDWLopcxZ6gCMj5dV5.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p><a href="https://www.ftc.gov/news-events/press-releases/2020/01/new-ftc-data-shows-ftc-received-nearly-17-million-fraud-reports">Consumers reportedly lost over $1.9 billion due to identity theft and fraud in 2019</a>. Compared to 2018, this was a 28% increase in losses. The median amount the victims lost in these cases was $320.</p><h2 id="7-more-than-one-in-four-older-adults-are-victims-of-identity-theft">7. More than one in four older adults are victims of identity theft</h2><p>An older adult refers to individuals aged 55 and above, and <a href="https://www.aarp.org/money/scams-fraud/info-2020/identity-fraud-survey.html">more than one in four</a> in this category have been a victim of identity theft. One reason for this could be that older adults are often not tech-savvy, and are unable to distinguish an authentic website from a fraudulent one. Another reason could be difficulty in remembering passwords and using the same password across all websites, which makes it easier for cybercriminals to acquire access. </p><h2 id="8-33-of-us-respondents-have-been-victims-of-identity-theft">8. 33% of US respondents have been victims of identity theft</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JMVVe4RaNt3B5oxceHA7F6" name="" alt="person typing on laptop at desk" src="https://cdn.mos.cms.futurecdn.net/JMVVe4RaNt3B5oxceHA7F6.jpg" mos="https://cdn.mos.cms.futurecdn.net/JMVVe4RaNt3B5oxceHA7F6.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A <a href="https://www.proofpoint.com/us/newsroom/press-releases/global-cybersecurity-awareness-survey-reveals-33-percent-us-respondents-have">2018 report from Proofpoint</a> found that 33% of US respondents had experienced identity theft. This was more than three times that of German and French respondents, and more than twice the global average. Turns out, US respondents also shared their social check-ins more than other global users, and this meant they were exposing more of their information to cybercriminals.</p><h2 id="9-stolen-credit-card-data-could-be-sold-for-50-cents-per-card">9. Stolen credit card data could be sold for 50 cents per card</h2><p>Cybercriminals sell credit card data <a href="https://theweek.com/articles/535818/stolen-credit-card-data-probably-worth-only-50-cents-black-market">for as low as $0.50 per card</a> on the dark web. Considering how much financial damage this can do, it’s astonishing to see the price at which such sensitive information is available. Cards that had more details, like the CVV number, were more expensive, sometimes going up to $0.45 per card. </p><h2 id="10-credit-card-fraud-tops-identity-theft">10. Credit card fraud tops identity theft</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QpiPQPZEVXTUM7FzEFjz87" name="" alt="A padlock clipped on a yellow credit card perched on a keyboard" src="https://cdn.mos.cms.futurecdn.net/QpiPQPZEVXTUM7FzEFjz87.jpg" mos="https://cdn.mos.cms.futurecdn.net/QpiPQPZEVXTUM7FzEFjz87.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>2019 saw credit card fraud topping the list of identity theft reports. <a href="https://www.ftc.gov/system/files/documents/reports/consumer-sentinel-network-data-book-2019/consumer_sentinel_network_data_book_2019.pdf">The Federal Trade Commission received</a> over 271,000 reports from individuals who stated that their information was illegally used to open new credit card accounts, or that their existing account was misused.</p><h2 id="11-50-of-us-adults-think-cybercriminals-won-t-target-individuals-with-poor-credit">11. 50% of US adults think cybercriminals won’t target individuals with poor credit </h2><p><a href="https://www.experian.com/blogs/ask-experian/survey-findings-are-consumers-making-it-easier-for-identity-thieves">An online Experian survey in 2017</a> found that 50% of US adults believed that identity thieves wouldn’t target individuals with poor credit records. This, however, is far from the truth. The number of identity theft cases has been rising steadily, and this means even people with poor credit can be at risk.</p><h2 id="12-87-of-consumers-haven-t-secured-private-information-online">12. 87% of consumers haven’t secured private information online</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tv6NVWKWVoCrpeCDfQtSkA" name="" alt="An abstract concept of someone making online purchases on a smartphone" src="https://cdn.mos.cms.futurecdn.net/tv6NVWKWVoCrpeCDfQtSkA.jpg" mos="https://cdn.mos.cms.futurecdn.net/tv6NVWKWVoCrpeCDfQtSkA.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>A report from Symantec saw that <a href="https://www.ftc.gov/system/files/documents/reports/consumer-sentinel-network-data-book-2019/consumer_sentinel_network_data_book_2019.pdf">87% of consumers had left their private information exposed online</a> while accessing their email or important financial information. </p><p>Furthermore, <a href="https://us.norton.com/internetsecurity-wifi-why-hackers-love-public-wifi.html">60% of consumers felt safe using public Wi-Fi</a>, which means that these consumers don’t realize the dangers of accessing personal information on public channels. Not surprisingly, most users weren’t using a virtual private network (VPN) to secure their online information.</p><h2 id="13-the-global-average-cost-of-a-data-breach-is-3-86-million">13. The global average cost of a data breach is $3.86 million</h2><p>A 2020 report from IBM Security showed that around the world, <a href="https://www.ibm.com/security/digital-assets/cost-data-breach-report">the average data breach costs $3.86 million</a>. Additionally, having a remote workforce increased the average cost of a data breach by $137,000. </p><h2 id="14-45-of-victims-feel-a-lack-of-trust-in-family-members">14. 45% of victims feel a lack of trust in family members</h2><p>Handling identity theft swiftly is crucial, but it’s also essential to handle the emotional turmoil this event can cause. The <a href="https://www.idtheftcenter.org/aftermath2018">Identity Theft Resource Center published a study in 2018</a> that suggested that over 45% of identity theft victims felt a lack of trust in their family members after experiencing identity theft.</p><h2 id="summary-3">Summary </h2><p>All these statistics about identity theft might feel overwhelming, but unfortunately, the threat is real. These cases of cybercrime are likely to increase as more of our transactions move online, and we can’t simply expect it to not happen to us. </p><p>By taking the right precautions, we can ensure security for our private data and information. Cybercrime is expensive, and general alertness while operating in the digital space is essential. To seriously bolster your security against identity theft, you must use <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">identity theft protection</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Complete ID review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367855/complete-id-review</link>
                                                                            <description>
                            <![CDATA[ Our Complete ID review will take a closer look at this identity monitoring service to help you decide whether it’s worth the money. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9QJ9gun68iqw3T6gqs3MEg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wXat8TBmMpY5YwHU3s9jRC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 20:53:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Graw ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ADXsvngupQQBbEPYbpX8D5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wXat8TBmMpY5YwHU3s9jRC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Complete ID&amp;#039;s homepage]]></media:description>                                                            <media:text><![CDATA[Complete ID&amp;#039;s homepage]]></media:text>
                                <media:title type="plain"><![CDATA[Complete ID&amp;#039;s homepage]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wXat8TBmMpY5YwHU3s9jRC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.completeid.com">Complete ID</a> is an identity theft and credit monitoring service from Experian, one of the three major credit agencies. The service is only available to Costco members, but the price represents the kind of incredible deal for which Costco is known. Complete ID isn’t the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection</a> option on the market, but it’s a great option if you’re already a Costco member.</p><h2 id="complete-id-plans-and-pricing">Complete ID: Plans and pricing</h2><p>Complete ID requires a Costco membership (which starts at $60 per year) in order to sign up. The service costs $13.99 per person a month, but Costco Executive members get discounted pricing of $8.99 per person per month. You can also add identity monitoring for up to five children for $3.99 a month ($2.99 a month for Executive members).</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5Cv2WtJiA3yZkTkvz2Dd4Y" name="" alt="Complete ID's pricing options" src="https://cdn.mos.cms.futurecdn.net/5Cv2WtJiA3yZkTkvz2Dd4Y.jpg" mos="https://cdn.mos.cms.futurecdn.net/5Cv2WtJiA3yZkTkvz2Dd4Y.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h2 id="complete-id-features">Complete ID: Features</h2><p>Complete ID offers a limited set of features compared to other identity monitoring services. That said, it covers all the basics well at a fraction of the cost of competing services.</p><p>To start, Complete ID monitors for any unauthorized use of your identity. The service automatically scans criminal databases, court records, change of address records, and financial accounts for your name. It also scans the dark web for your personal information, including your social security number. If Complete ID finds a match in any of its scans, you’ll receive a notification.</p><p>The service also offers in-depth credit monitoring, which makes sense given that Complete ID is owned by Experian. You get full credit reports from Experian, Transunion, and Equifax, along with alerts anytime a new account is opened using your information.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="72WnFmeKJ5SMHZvUavNnZG" name="" alt="Complete ID's user interface" src="https://cdn.mos.cms.futurecdn.net/72WnFmeKJ5SMHZvUavNnZG.jpg" mos="https://cdn.mos.cms.futurecdn.net/72WnFmeKJ5SMHZvUavNnZG.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Perhaps the best part of Complete ID is that if your identity is stolen, you’re covered by up to $1 million in insurance to cover lost income, legal fees, and other damages. There’s no deductible to access this money, which makes the low monthly subscription fee an even sweeter deal.</p><p>In addition, Complete ID provides you with a dedicated identity restoration specialist. They can help you get new identification documents, work with credit agencies to restore your financial history, and wipe away any records forged under your name. You get direct contact information for your dedicated specialist, which can make the months-long process of restoring your identity feel a bit more smooth.</p><h2 id="complete-id-interface-and-in-use">Complete ID: Interface and in use</h2><p>Complete ID’s online interface is relatively easy to use, although sorting through alerts and other information isn’t as simple as it could be. To start, you can add personal details like your social security, passport, and driver’s license numbers to your account to enable comprehensive monitoring.</p><p>Once that’s set up, Complete ID will automatically collect information and add it to your online dashboard. Much of the dashboard is dedicated to credit monitoring, and the interface looks a lot like the credit reporting you might already receive from your bank or credit card provider. It’s not overly informative, although your credit score is graphed over time so that it’s easy to see if there’s a sudden change.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xMCVJLyWNmnLDWwwJ7ceEF" name="" alt="Complete ID's credit score update tab" src="https://cdn.mos.cms.futurecdn.net/xMCVJLyWNmnLDWwwJ7ceEF.jpg" mos="https://cdn.mos.cms.futurecdn.net/xMCVJLyWNmnLDWwwJ7ceEF.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The alert system in Complete ID was also a little disappointing. You can opt to receive notifications about suspicious activities by email or push notification through the mobile app, but you cannot get alerts by text message. Alerts were also relatively few and far between. While no one wants to be bombarded with identity theft warnings, it would be nice to feel as if the service was picking up a bit more information in its scans.</p><h2 id="complete-id-support">Complete ID: Support</h2><p>Complete ID’s support team is available by phone 24/7 every day of the year to answer questions and respond to identity theft incidents. One of the best things about this service is that you are assigned a dedicated identity restoration specialist when you report an incident, and that same agent remains your point of contact until your case is resolved.</p><h2 id="the-competition">The competition</h2><p>Complete ID doesn’t have many of the bells and whistles of competing services. Norton LifeLock, for example, offers a suite of security tools that includes a VPN, cloud backup, webcam blocking, and a password manager. The online interface is also easier to use, and you have more control over how you receive alerts about suspicious activity. IdentityForce offers many of the same features, and it’s similarly easier to use than Complete ID.</p><p>That said, LifeLock costs $12.49 a month and IdentityForce costs $23.95 a month with credit monitoring. If you already have a Costco membership, and especially an Executive membership, Complete ID covers the essentials at a significantly cheaper price.</p><h2 id="final-verdict">Final verdict</h2><p>Complete ID doesn’t go above and beyond when it comes to features, but it’s still a fairly reliable identity theft monitoring service. You get credit monitoring and dark web monitoring among other essentials, plus up to $1 million in insurance coverage and dedicated support in the event of identity theft. We’d like to see a more robust user interface and more customizable alerts, but this isn’t a deal-breaker.</p><p>Overall, Complete ID is worthwhile if you already have a Costco membership. If you don’t, we recommend an alternative like Norton LifeLock or IdentityForce.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LifeLock vs Identity Guard ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367957/lifelock-vs-identity-guard</link>
                                                                            <description>
                            <![CDATA[ We compare LifeLock vs Identity Guard to find the best identity theft protection service ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">46Z3vbLYzYemFzaQeWCMwD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3KmKJ7aK7XwqKHcoUoAUZB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 20:52:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah James ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/j6cwthzSgjGeyuZgkqDdN.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3KmKJ7aK7XwqKHcoUoAUZB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LifeLock vs Identity Guard]]></media:description>                                                            <media:text><![CDATA[LifeLock vs Identity Guard]]></media:text>
                                <media:title type="plain"><![CDATA[LifeLock vs Identity Guard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3KmKJ7aK7XwqKHcoUoAUZB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anytime you share your credit card number, address, or even your name online, you become vulnerable to identity theft. Cybercriminals are always on the lookout for new ways to steal your personal information, in order to engage in fraudulent activities like maxing out your credit cards or stealing your tax refunds. </p><p>Even the most careful online users are vulnerable to data breaches, making identity theft protection essential.</p><p>In this article, we’ll compare two of the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection services</a> available, pitting <a href="https://www.lifelock.com">LifeLock</a> vs <a href="https://www.identityguard.com">Identity Guard</a>. We’ll take a look at the features, performance, support, and price of each, so you can find the best product for your identity theft protection needs. </p><h2 id="features">Features</h2><p>LifeLock is part of Norton AntiVirus, a well-known name in antivirus protection. That means that with most levels of LifeLock, you also get the anti-malware services of Norton 360 - a crucial component of identity theft protection, since cybercriminals can obtain your information through malware attacks.</p><p>Identity Guard also offers a virus scanning component with some of its services, but unfortunately, it is only for PCs, whereas Norton 360 is also compatible with Macs and mobile devices. </p><p>Both LifeLock and Identity Guard offer the standard identity theft protection services: monitoring databases, the web, and the dark web for your social security number and other private information. They both provide ID verification, alerting you of potentially malicious activities such as applications for a new credit card in your name. </p><p>Both will monitor your credit reports to alert you of any changes. Both will even help you replace or cancel credit cards if your wallet is stolen. </p><p>The main difference between the features of LifeLock and Identity Guard lie in the services they provide if you do become a victim of identity theft. If identity theft is detected, Identity Guard will appoint you a personal case manager so you won’t be stuck dealing with the problem on your own. They also offer up to $1 million of identity theft insurance, including stolen fund reimbursement, for all customers.</p><p>LifeLock also offers reimbursement for funds stolen due to identity theft, but the level of reimbursement varies depending on your membership level. Standard LifeLock customers only have access to $25,000 of stolen funds reimbursement. Only with the most expensive membership - LifeLock Ultimate Plus - does LifeLock match Identity Guard’s stolen fund reimbursement amount. </p><p>But this doesn’t necessarily make Identity Guard the clear winner. LifeLock offers other reimbursement features, such as personal expense compensation and coverage for lawyers, that could make up for the lower stolen funds reimbursement figure. Plus, with the benefit of Norton 360’s trusted antiviral scanning, we think LifeLock just beats Identity Guard when it comes to features. </p><h2 id="performance">Performance</h2><p>LifeLock is extremely easy to set up, requiring just a few minutes and a valid ID and credit card. If you have been a Norton customer in the past, you will find the interface familiar and easy to navigate, although it is intuitive even for new users. </p><p>LifeLock customers can either log in to their account on the LifeLock website, or download the mobile app, available on both iOS and Android. The mobile app enables LifeLock users to receive fraud alerts on the go, so you don’t have to waste any time before taking action to protect your accounts. </p><p>One important time-saving feature of the app is the ability to contact LifeLock Member Services with an in-app calling service, meaning if there is an issue, you won’t be fumbling around trying to figure out who to call.</p><p>Like LifeLock, Identity Guard is very simple to set up and start using. Identity Guard also offers users the option to log in to the website or download a mobile app for iOS and Android. While Identity Guard and LifeLock offer comparable features on their browser login pages, we found that the LifeLock mobile app was better designed and more intuitive to use. </p><h2 id="support">Support</h2><p>As mentioned above, Identity Guard assigns users a personal case manager to work with them if they experience any identity theft issues. While this can be a nice benefit - saving users the time of having to explain their problem over and over again to a new customer service rep - it doesn’t make up for the one glaring problem with Identity Guard’s user support: it’s not available 24/7.</p><p>While Identity Guard’s monitoring services work around-the-clock, its customer services team is only available from certain hours Monday through Saturday, and not at all on Sundays.</p><p>Unfortunately, this means that if you experience an issue late at night or early in the morning, you’ll have to wait for Identity Guard’s business hours to deal with it—potentially costing you crucial hours.</p><p>LifeLock, however, offers 24/7 customer support. Cybercriminals don’t operate on normal business hours, and you never know when a security breach will happen. For the added peace of mind of knowing you won’t have to wait for help if you need it, we think LifeLock offers greater user support.</p><h2 id="pricing-and-plans">Pricing and plans</h2><p>Identity Guard offers <a href="https://www.identityguard.com/plans">three levels of plans</a>: Value, Total, and Ultra. The Value plan offers standard monitoring and data breach notifications at either $8.99 a month, or $7.50 a month billed annually. The Total plan adds credit monitoring and costs $19.99 a month, or $16.67 a month billed annually. </p><p>The Ultra plan adds monitoring of your bank accounts and credit cards, and for criminal activity associated with your name. The Ultra plan costs $29.99 a month, or $25 a month when billed annually. All of Identity Guard’s plans, even the Value plan, offer $1 million of identity theft insurance—a bargain if lost fund reimbursement is most important to you.</p><p>LifeLock offers <a href="https://www.lifelock.com/products">four levels of plans</a>. The Standard plan includes only LifeLock’s monitoring services without Norton 360, and costs $9.99 a month for your first year (or $8.29 a month annually.) LifeLock Select adds Norton 360 for up to five devices at the same price as the Standard plan for the first year. Both plans offer $25,000 of stolen fund reimbursement. </p><p>LifeLock Advantage ups that to $100,000 and enables you to secure up to 10 devices with Norton 360 for $17.99 a month for your first year (or $14.99 a month annually). LifeLock Ultimate Plus adds three-bureau credit monitoring, Norton 360 on unlimited devices, and $1 million in stolen fund reimbursement for $25.99 a month for the first year, or $20.99 a month annually. </p><p>It’s important to note that all of LifeLock’s plans renew at a higher price after the first year, so if you’re looking for long-term coverage, make sure the second-year price is within your budget. </p><h2 id="verdict">Verdict</h2><p>If you’re only looking for basic identity theft monitoring and reimbursement insurance, Identity Guard’s Value Plan is a great option, providing far more in stolen fund reimbursement than the equivalent LifeLock plan. </p><p>However, we believe the extra security of Norton 360, plus the access to 24/7 customer support, makes LifeLock the superior choice for greater peace of mind when it comes to securing your identity online. If you want more details on either service, please read our <a href="https://www.itpro.com/security/cyber-security/367985/norton-lifelock-review" data-original-url="https://www.itpro.com/security/cyber-security/367985/norton-lifelock-review">LifeLock review</a> and our Identity Guard review.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IDShield vs LifeLock ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367956/idshield-vs-lifelock</link>
                                                                            <description>
                            <![CDATA[ We compare IDShield vs LifeLock to see which identity theft protection service is best for keeping you safe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pzgGjzumAZhXNKtmdT2RfW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/c5KPrMFuyda6VALfQtJ6aJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 20:51:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah James ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/j6cwthzSgjGeyuZgkqDdN.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/c5KPrMFuyda6VALfQtJ6aJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IDShield vs LifeLock]]></media:description>                                                            <media:text><![CDATA[IDShield vs LifeLock]]></media:text>
                                <media:title type="plain"><![CDATA[IDShield vs LifeLock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/c5KPrMFuyda6VALfQtJ6aJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you buy things online, post to social media, or even file your taxes over the internet, you could be vulnerable to identity theft. Even users who are careful to only share their data on secure, trusted websites could be victims of data breaches undertaken by cybercriminals eager to max out your credit cards, or make fraudulent purchases in your name.</p><p>That’s why having the best identity theft protection service is essential for anyone who shares information online. In this article, we’ll compare two options for identity theft protection: <a href="https://www.idshield.com">IDShield</a> vs <a href="https://www.lifelock.com">LifeLock</a>. We’ll look at their features, performance, support, and cost to help you find the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection</a>. </p><h2 id="features-2">Features</h2><p>Both IDShield and LifeLock come with the basic features you will need to monitor your information online: social security number monitoring, dark web monitoring, and alerts if there are unusual changes to your credit reports or bank accounts. Both even offer lost wallet assistance, helping you change or cancel your credit cards in case of a stolen or misplaced wallet. </p><p>IDShield users can choose between one-bureau credit monitoring or the more comprehensive three-bureau credit monitoring, whereas most LifeLock plans only offer one-bureau monitoring. IDShield comes with a few bonus features that LifeLock is missing, like social media scanning and reputation management. If you’re job hunting and want to ensure you’re making the best digital first impression possible, this is a useful tool.</p><p>LifeLock is part of Norton AntiVirus, a familiar and trusted name in antivirus protection. That means that with most levels of LifeLock, you’ll also have access to the scanning, privacy, and anti-malware services of Norton 360. Since one way cybercriminals can access your private information is through malware attacks, the added protection of Norton 360 is a huge benefit of LifeLock.</p><p>Another crucial benefit of the <a href="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies" data-original-url="https://www.itpro.com/security/privacy/367833/best-identity-theft-companies">best identity theft protection services</a> are the features and assistance they provide if you are the victim of identity theft. One unique feature offered by IDShield is access to in-house licensed private investigators to assist you in restoring your identity. </p><p>IDShield also offers unlimited consultations with identity theft specialists who can answer all your questions. Plus, every IDShield plan comes with $1 million in protection to cover stolen funds, legal fees, and other expenses. Only the most expensive level of LifeLock, LifeLock Ultimate Plus, matches IDShield’s stolen fund reimbursement. </p><p>The lower levels of LifeLock only offer between $25,000 and $100,000 of stolen fund reimbursement—but LifeLock also offers up to $1 million of coverage for lawyers and experts at all levels. </p><p>Overall, the core components of IDShield and LifeLock are pretty comparable, with IDShield offering a few more extras that may or may not be relevant to you. To us, however, IDShield’s handful of extras don’t compare to the security advantages of bundling LifeLock with Norton 360.</p><h2 id="performance-2">Performance</h2><p>LifeLock is easy to set up, requiring answers to a few simple questions, a valid ID, and a credit card. </p><p>Once purchased, LifeLock users can either log on to their account via LifeLock’s website, or download the LifeLock mobile app for iOS or Android. With the LifeLock mobile app, you’ll receive alerts of fraudulent activity on your mobile device, enabling you to take action right away to protect your accounts. </p><p>Like LifeLock, IDShield also offers users the ability to log in to their account either from the web or on the go with an iOS or Android app. When you log in, your most recent credit score is front and center, as well as any new alerts that you may need to review. </p><p>If space on your phone is at a premium, you might want to go with IDShield, as the app takes up on only 29MB of space on an iPhone versus LifeLock’s 82MB. However, both apps and web interfaces are intuitive and easy-to-use. When it comes to performance, both LifeLock and IDShield offer comparable experiences. </p><h2 id="support-2">Support</h2><p>You never know when an attack on your identity may occur, and a key component of identity theft protection is knowing someone will be available to assist you, day or night.</p><p>LifeLock offers 24/7 support to its members, with priority support offered to Ultimate Plus members. In the event of identity theft, LifeLock also offers its members access to identity restoration specialists. Additionally, the LifeLock app features an in-app calling service connecting you to LifeLock Member Services, meaning if you do encounter an issue, help is right at your fingertips.</p><p>IDShield also offers 24/7 access to customer service. Like LifeLock, IDShield has identity restoration services for its members. IDShield offers a few extras when it comes to support, like the in-house private investigators and unlimited consulting mentioned above. </p><p>IDShield also makes it easy to contact their user support directly through their app, with a prominently-placed, hard-to-miss green button. Overall, IDShield and LifeLock both offer comprehensive, easy-to-access support for their members. </p><h2 id="pricing-and-plans-2">Pricing and plans</h2><p>IDShield <a href="https://www.idshield.com/plans-and-pricing">offers</a> an Individual plan and a Family plan. With both options, users have the ability to select either one-bureau or three-bureau credit monitoring—meaning there are four total levels of plans.</p><p>IDShield’s Individual plan will cost you $13.95 a month for one-bureau credit monitoring, or $17.95 a month for three-bureau. The Individual plan only covers one person. The Family plan, however, covers one individual, a spouse or domestic partner, and up to 10 dependent children. </p><p>The Family plan is $26.95 monthly for one-bureau credit monitoring, or $32.95 a month for three-bureau credit monitoring. IDShield also offers users a free 30-day trial, so you can see if you like the service before committing.</p><p>LifeLock’s <a href="https://www.lifelock.com/products">plans and pricing</a> are a bit more confusing, offering four levels of support depending on your needs. The most basic, the Standard plan, includes just LifeLock’s monitoring services without Norton 360. The Standard plan costs $9.99 a month for your first year, or $8.29 a month if you choose to bill annually. </p><p>LifeLock Select includes Norton 360 for up to five devices at the same price as the Standard plan (all of LifeLock’s prices increase after the first year.) Both of these plans offer up to $25,000 of stolen fund reimbursement.</p><p>LifeLock customers looking for more stolen fund reimbursement might also want to opt for the LifeLock Advantage Plan, which offers up to $100,000 and Norton 360 protection for up to 10 devices. The Advantage Plan is $17.99 a month for your first year, or $14.99 a month billed annually.</p><p>The most comprehensive LifeLock plan is LifeLock Ultimate Plus, offering three-bureau credit monitoring, up to $1 million in stolen fund reimbursement, and Norton 360 protection for unlimited devices. LifeLock Ultimate Plus is $25.99 a month for the first year, or $20.99 a month if billed annually.</p><p>When it comes to pricing and plans, it’s nice that LifeLock offers a discount to users who pay annually, and a discount for your first year. But the 30-day free trial of IDShield is hard to beat.</p><h2 id="verdict-2">Verdict</h2><p>Ultimately, we think the extras IDShield provides - like social media monitoring - simply don’t stack up to the added benefits of bundling LifeLock with Norton 360. The most basic LifeLock with Norton 360 package, LifeLock Select, is cheaper for an individual than IDShield for the first year, and not significantly more expensive after. </p><p>For us, LifeLock is the superior choice for greater peace of mind when protecting your identity online. If you want more details, please read our <a href="https://www.itpro.com/security/cyber-security/367985/norton-lifelock-review" data-original-url="https://www.itpro.com/security/cyber-security/367985/norton-lifelock-review">LifeLock review</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TikTok considers changes to data policies amid rising security concerns  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/369182/tiktok-considers-changes-to-data-policies-amid-rising-security-concerns</link>
                                                                            <description>
                            <![CDATA[ The ByteDance-owned app also faces a potential £27m fine over privacy violations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xAgzPoXP1ib5uGZjLkzntN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Sep 2022 12:54:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:description>                                                            <media:text><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US lawmakers and TikTok are negotiating changes to the short-form video app's data security and governance strategies, the New York Times reported on Monday.</p><p>The changes could prove instrumental in deflecting a plausible sale among rising security concerns. A potential agreement between the ByteDance-owned app and the Biden administration is in the works, as matters stand.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FaB2FMpWMfQo5Z9ruoKGdb" name="FaB2FMpWMfQo5Z9ruoKGdb.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" mos="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Just enough data governance</strong></p><p class="fancy-box__body-text">Building program momentum and scale with agility</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-governance/369172/just-enough-data-governance" data-original-url="/policy-legislation/data-governance/369172/just-enough-data-governance">FREE DOWNLOAD</a></p></div></div><p>The company can "fully satisfy all reasonable US national security concerns" a TikTok spokesperson revealed.</p><p>Over two years have passed since a US national security panel ordered ByteDance to divest TikTok for concerns over data abuse by China's communist government.</p><p>As of September 2022, TikTok could face a £27 million fine under UK data protection laws for failing to safeguard children's privacy on its platform.</p><p>The app also suffered a data breach earlier this month, which included 790GB of user information. The firm, however, refuted the allegations of a massive security breach.</p><p>TikTok’s security incident follows the discovery of a “high-severity vulnerability” in its Android app by Microsoft researchers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Oracle's massive advertising database operates without user consent, lawsuit claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368883/oracles-massive-advertising-database-lacks-user-consent-lawsuit-claims</link>
                                                                            <description>
                            <![CDATA[ Rights organisers have accused Oracle of collecting an undue level of sensitive data to identify consumers online ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cdWzLhcX4pwLdvXpWbSXQB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/J6QTBpeTyjN8SZ7qtQQdRT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Aug 2022 14:00:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/J6QTBpeTyjN8SZ7qtQQdRT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A side on photo of an Oracle sign on a lawn in front of a large blue-glass building]]></media:description>                                                            <media:text><![CDATA[A side on photo of an Oracle sign on a lawn in front of a large blue-glass building]]></media:text>
                                <media:title type="plain"><![CDATA[A side on photo of an Oracle sign on a lawn in front of a large blue-glass building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/J6QTBpeTyjN8SZ7qtQQdRT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Oracle is facing a class-action lawsuit over its alleged use of extensive data aggregation to match the sensitive information of hundreds of millions of customers without informed consent.</p><p>In addition to its role as a <a href="https://www.itpro.com/data-insights/data-management/366305/the-role-of-data-management-platforms-in-building-a-robust" data-original-url="https://www.itpro.com/data-insights/data-management/366305/the-role-of-data-management-platforms-in-building-a-robust">data management</a>, cloud, and enterprise solutions firm, Oracle also acts as a data broker, and runs Oracle Data Marketplace - the largest third-party data marketplace in the world.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fJdhYc6ZH7tbvEagDKoFBA" name="fJdhYc6ZH7tbvEagDKoFBA.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/fJdhYc6ZH7tbvEagDKoFBA.png" mos="https://cdn.mos.cms.futurecdn.net/fJdhYc6ZH7tbvEagDKoFBA.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The trusted data centre and storage infrastructure</strong></p><p class="fancy-box__body-text">Invest in infrastructure modernisation to drive improved outcomes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/368836/the-trusted-data-centre-and-storage-infrastructure" data-original-url="/infrastructure/server-storage/368836/the-trusted-data-centre-and-storage-infrastructure">FREE DOWNLOAD</a></p></div></div><p>The <a href="https://www.iccl.ie/wp-content/uploads/2022/08/File-Stamped-2022-08-19-Oracle-Complaint.pdf">complaint</a> alleges that Oracle’s current notice of <a href="https://www.itpro.com/data-insights/data-management/358099/the-rise-of-consent-and-preference-management" data-original-url="https://www.itpro.com/data-insights/data-management/358099/the-rise-of-consent-and-preference-management">consent</a> for data collection does not justify the use of the Oracle’s BlueKai Data Management Platform <a href="https://www.itpro.com/security/361576/what-are-cookies" data-original-url="https://www.itpro.com/security/361576/what-are-cookies">cookies</a> and <a href="https://www.itpro.com/security/privacy/368588/meta-begins-encrypting-facebook-urls-nullifying-tracking-countermeasures" data-original-url="https://www.itpro.com/security/privacy/368588/meta-begins-encrypting-facebook-urls-nullifying-tracking-countermeasures">tracking pixels</a> to collect and store sensitive data of individuals including address, life events such as marriage or childbirth, education, and purchase history.</p><p>This, it states, builds up an excessively-detailed picture of each of the many millions of customers within its database. The major grievance outlined in the complaint is with the aggregation of this data within Oracle’s 'ID graphing', which matches sensitive data drawn from disaggregated sources to existing data profiles on US citizens and individuals around the world, in order to inform targeted advertising.</p><p>Oracle chairman Larry Ellison is credited as having claimed that there were five billion people in Oracle’s ID graph by 2016.</p><p>Internal documentation published by Oracle credits its BlueKai cookies and ID graphing with the successful collection of data of more than 155 million US households. Other tools such as AddThis, a widget service that Oracle acquired in 2016, tracks user activity on over 15 million websites, enabling the identification of 1.9 billion unique users.</p><p>The complaint notes that the cookies and pixels bundled with AddThis are utilised without prior notice or user consent.</p><p>Much of the complaint focuses on this issue of consent. The plaintiffs allege that Oracle is guilty of an <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">invasion of privacy under the California constitution</a>, which lists “privacy” as an inalienable right of the citizens of California, and of violating the California Invasion of Privacy Act.</p><p>“Oracle knows, or reasonably should know, that Internet users such as Plaintiffs and Class members have insufficient knowledge or basis to reasonably comprehend the extent to which Oracle is obtaining their data, tracking their activity, and compiling it into digital dossiers, nor the deeply invasive and detailed nature of those dossiers,” the complaint reads.</p><p>Unlike the UK and EU GDPR, the US has no federal digital privacy legislation, so state privacy laws are one of the few avenues by which individuals can assert rights to privacy in court.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/368588/meta-begins-encrypting-facebook-urls-nullifying-tracking-countermeasures" data-original-url="/security/privacy/368588/meta-begins-encrypting-facebook-urls-nullifying-tracking-countermeasures">Meta begins encrypting Facebook URLs, nullifying tracking countermeasures</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/368880/snapchat-settles-for-35-million-in-illinois-biometrics-lawsuit" data-original-url="/security/privacy/368880/snapchat-settles-for-35-million-in-illinois-biometrics-lawsuit">Snapchat settles for $35 million in Illinois biometrics lawsuit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-governance/368517/oracle-to-build-sovereign-cloud-regions-in-the-eu-for-2023" data-original-url="/policy-legislation/data-governance/368517/oracle-to-build-sovereign-cloud-regions-in-the-eu-for-2023">Oracle to build sovereign cloud regions in the EU for 2023</a></p></div></div><p>In 2020, a lawsuit filed in the the Netherlands <a href="https://www.itpro.com/data-insights/big-data/356775/oracle-hits-back-at-meritless-gdpr-lawsuit" data-original-url="https://www.itpro.com/data-insights/big-data/356775/oracle-hits-back-at-meritless-gdpr-lawsuit">accused Oracle of GDPR violations</a> in its handling of personal data through third-party cookies. BlueKai was specifically named in this lawsuit, with one expert noting that "Everyone who has ever used the internet is at risk from this technology".</p><p>“It may be largely hidden but it is far from harmless," said Dr Rebecca Rumbul, class representative and a claimant on the suit in England.</p><p>At the time, Oracle dubbed the lawsuit a "meritless action based on deliberate misrepresentations of the facts". Earlier in 2022, the suit was dismissed, although the new complaint claims that in response to the UK/NL suit, Oracle did “cease certain of the practices complained of in that lawsuit only weeks after it was filed”.</p><p>Oracle declined to provide comment to <em>IT Pro</em>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ India forced Twitter to hire a government agent, whistleblower claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368874/india-forced-twitter-to-hire-a-government-agent-whistleblower-claims</link>
                                                                            <description>
                            <![CDATA[ Former employee Peiter Zatko says the social media platform gave the agent direct unsupervised access to the company’s systems and user data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tSv157BEXCBnjbnHS7E7Jx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6KsFcmhPHT4XkPerGwkTES-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Aug 2022 11:24:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6KsFcmhPHT4XkPerGwkTES-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Twitter logo as seen hidden among several other images including fingerprints ]]></media:description>                                                            <media:text><![CDATA[The Twitter logo as seen hidden among several other images including fingerprints ]]></media:text>
                                <media:title type="plain"><![CDATA[The Twitter logo as seen hidden among several other images including fingerprints ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6KsFcmhPHT4XkPerGwkTES-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Indian government forced Twitter to hire a government agent and grant them unsupervised access to data, according to a former employee of the social media platform.</p><p>Former senior Twitter executive Peiter “Mudge” Zatko alleged that the government forced the social media company to hire one or more individuals who were government agents and who then had access to huge amounts of Twitter’s user data, as reported by <a href="https://indianexpress.com/article/technology/tech-news-technology/india-forced-twitter-agent-payroll-whistleblower-8107758" target="_blank"><em>The</em> <em>Indian Express</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359656/indian-police-visit-twitter-to-serve-notice-on-investigation" data-original-url="/business/policy-legislation/359656/indian-police-visit-twitter-to-serve-notice-on-investigation">Indian police visit Twitter over "manipulated" tweet</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/368696/twitter-reports-largest-ever-data-requests-new-transparency-report" data-original-url="/marketing-comms/social-media/368696/twitter-reports-largest-ever-data-requests-new-transparency-report">Twitter reports largest ever period for data requests in new transparency report</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359670/whatsapp-sues-indian-government-over-new-privacy-laws" data-original-url="/policy-legislation/data-protection/359670/whatsapp-sues-indian-government-over-new-privacy-laws">WhatsApp sues Indian government over new privacy laws</a></p></div></div><p>Zatko, who made the comments during a whistleblower disclosure with US regulators, alleged that Twitter knowingly permitted an <a href="https://www.itpro.com/hardware/components/368368/why-india-wants-to-become-a-chipmaking-powerhouse" target="_blank" data-original-url="https://www.itpro.com/hardware/components/368368/why-india-wants-to-become-a-chipmaking-powerhouse">Indian government</a> agent direct unsupervised access to the company’s systems and user data.</p><p>“The company did not in fact disclose to users that it was believed by the executive team that the Indian government had succeeded in placing agents on the company payroll,” Zatko, former head of safety at Twitter, said in his complaint filed with the US Securities and Exchange Commission (SEC).</p><p>This comes as Twitter is currently engaged in a legal challenge with India's Ministry of Electronics and IT (MeitY) after it asked a court in July to overturn some government orders to remove content from the platform, alleging abuse of power by officials.</p><p>MeitY introduced Information Technology Rules in February 2021 which forced <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">social media</a> companies to hire employees who would liaison with law enforcement agencies to help them in investigations. The platforms also had to hire a compliance officer who would ensure the companies were following the rules, as well as a grievance officer to respond to any complaints.</p><p>It isn’t clear whether there’s a link between the whistleblower’s allegations of the government agent being hired and the new rules requiring the platforms to hire <a href="https://www.itpro.com/business/business-strategy/356408/why-you-should-prioritise-employee-experience" target="_blank" data-original-url="https://www.itpro.com/business/business-strategy/356408/why-you-should-prioritise-employee-experience">employees</a> for the new roles. However, Zatko told <em>The Washington Post</em> that the evidence to support his allegations has been shared with US intelligence agencies.</p><p>Zatko added that in countries where Twitter had to have a physical presence and employees, the threat of harm to Twitter employees was enough to cause it to seriously consider complying with foreign government requests it would otherwise fundamentally oppose. He said that the government of India, along with <a href="https://www.itpro.com/security/cyber-warfare/367342/russian-cyber-attacks-should-your-business-worry" target="_blank" data-original-url="https://www.itpro.com/security/cyber-warfare/367342/russian-cyber-attacks-should-your-business-worry">Russia</a> and Nigeria, aimed to force Twitter to hire local employees that could be used as leverage.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="X45j9iJmNPhLBRNurdifFT" name="X45j9iJmNPhLBRNurdifFT.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" mos="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cyber resiliency and end-user performance</strong></p><p class="fancy-box__body-text">Reduce risk and deliver greater business success with cyber-resilience capabilities</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368832/cyber-resiliency-and-end-user-performance" data-original-url="/security/368832/cyber-resiliency-and-end-user-performance">FREE DOWNLOAD</a></p></div></div><p><em>IT Pro</em> has contacted Twitter for comment.</p><p>Zatko was fired from his role for ineffective leadership and poor performance, a Twitter spokesperson told <em>The Indian Express</em>.</p><p>“What we’ve seen so far is a false narrative about Twitter and our <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">privacy</a> and <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">data security</a> practices that is riddled with inconsistencies and inaccuracies and lacks important context,” said the spokesperson. “Mr. Zatko’s allegations and opportunistic timing appear designed to capture attention and inflict harm on Twitter, its customers and its shareholders. Security and privacy have long been company-wide priorities at Twitter and will continue to be.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[  Microsoft blocking Tutanota users from Teams registration, claims fix unfeasible ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-operations/368753/microsoft-blocking-tutanota-users-from-teams-registration</link>
                                                                            <description>
                            <![CDATA[ Tutanota claim this is an antitrust issue, as the company shares the problem with the public ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8SMRYXBaPdifgHu9PxpA2E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/33Q8TY8cQJq2PoPetof4Z5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Aug 2022 10:49:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/33Q8TY8cQJq2PoPetof4Z5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Microsoft Teams logo is shown on a smartphone, with the Microsoft logo displayed in the background on a wall]]></media:description>                                                            <media:text><![CDATA[The Microsoft Teams logo is shown on a smartphone, with the Microsoft logo displayed in the background on a wall]]></media:text>
                                <media:title type="plain"><![CDATA[The Microsoft Teams logo is shown on a smartphone, with the Microsoft logo displayed in the background on a wall]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/33Q8TY8cQJq2PoPetof4Z5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>German email provider Tutanota has publicly called out Microsoft for allegedly blocking users using Tutanota email addresses from registering a Teams account.</p><p>The company had discovered that anyone who attempts to sign up for <a href="https://www.itpro.com/business-strategy/collaboration/362211/microsoft-teams-uses-50-less-power-than-first-launch" data-original-url="https://www.itpro.com/business-strategy/collaboration/362211/microsoft-teams-uses-50-less-power-than-first-launch">Microsoft Teams</a> with a Tutanota email address is shown an error message reading “[email address] hasn’t been added to your organization’s directory. Contact your admin or try a different email.”</p><p>Tutanota has been in a back-and-forth with Microsoft for weeks over the issue, but was repeatedly told by Microsoft that it is “currently not feasible for the domain to become a public domain”.</p><p>Disputing this claim, Tutanota has taken the issue to the public and accused Microsoft of engaging in an anti-competitive practice.</p><p>With millions of users worldwide, the company maintains that its customers have a right to privacy that should not be compromised through a requirement to use a secondary email provider.</p><p>The problem, according to <em>TechCrunch,</em> appears to be linked to the fact that Teams recognises Tutanota addresses as corporate emails, hence the request for denied users to contact their administrator.</p><p>At the time of writing, <em>IT Pro </em>has been informed, that emails using the Tutanota domains tutanota.com and tutanota.de now work with Teams registration. This follows a <a href="https://twitter.com/NathanMcNulty/status/1556555271962406912">Twitter exchange</a> that the company believes improved the situation behind the scenes.</p><p>Three other domains, tuta.io, keemail.me and tutamail.com, remain blocked.</p><p>"To us it is very frustrating that such a step is needed to get an issue resolved by Microsoft. In our view it is negligence on Microsoft's part that does result in antitrust issues,” said a Tutanota spokesperson.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" data-original-url="/network-internet/email-providers/358887/the-most-secure-email-services">The most secure email services of 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/368733/north-korean-sharpext-spyware-harvesting-gmail" data-original-url="/security/368733/north-korean-sharpext-spyware-harvesting-gmail">North Korean-linked Gmail spyware 'SHARPEXT' harvesting sensitive email content</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/368705/every-leading-uk-university-is-compromising-on-email-security" data-original-url="/security/phishing/368705/every-leading-uk-university-is-compromising-on-email-security">Every leading UK university is compromising on email security, researchers say</a></p></div></div><p>Unlike many email providers, Tutanota encrypts its entire mailbox and address book and allows users to send end-to-end encrypted emails to any email address via the use of a password. For these reasons along with a whole host of other privacy features, it is considered one of <a href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" data-original-url="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services">the most secure email services available</a>.</p><p>“This severe anti-competitive practice forces our customers to register a second email address – possibly one from Microsoft themselves – to create a Teams account,” said Tutanota co-founder Matthias Pfau, in a <a href="https://tutanota.com/blog/posts/microsoft-blocks-tutanota-users-from-own-service">blog post</a>.</p><p>“When asked to change the current situation, a spokesperson for Microsoft simply said it would not be possible for them to allow people to register a Teams account with a Tutanota email address. Period. We repeatedly tried to solve the issue with Microsoft, but unfortunately our request was ignored.”</p><p><em>IT Pro</em> has approached Microsoft for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TikTok to give researchers new API for insight, greater transparency ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-operations/368667/tiktok-to-give-researchers-new-api-for-insight-greater-transparency</link>
                                                                            <description>
                            <![CDATA[ Trends identified by independent analysts could inform business decisions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWdaf7g8eGi2nKVRgCKurF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Jul 2022 11:12:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:description>                                                            <media:text><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[The TikTok logo on an application store accessed from a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SWZGB5pCATEVXed2beupWg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>TikTok has announced new initiatives aimed at improving transparency around the company’s data use, measurement of trends and moderation systems. </p><p>In a <a href="https://newsroom.tiktok.com/en-us/strengthening-our-commitment-to-transparency">blog post</a>, chief operating officer Vanessa Pappas laid out a series of plans in detail to involve researchers, industry experts and academics to test and advise on TikTok’s platform.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WvTN5p4tPpqD7o7rbLAShY" name="WvTN5p4tPpqD7o7rbLAShY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/WvTN5p4tPpqD7o7rbLAShY.jpg" mos="https://cdn.mos.cms.futurecdn.net/WvTN5p4tPpqD7o7rbLAShY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 Gartner critical capabilities for data integration tools</strong></p><p class="fancy-box__body-text">How to identify the right tool in support of your data management solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/368471/2021-gartner-critical-capabilities-for-data-integration-tools" data-original-url="/technology/machine-learning/368471/2021-gartner-critical-capabilities-for-data-integration-tools">FREE DOWNLOAD</a></p></div></div><p>Researchers will be given access to an application programming interface (API) through which they will be able to study public and anonymised data about content on the platform. This will be made available later this year. </p><p>The short-form video hosting service and editing app is extremely popular, with an active base of over one billion users. If research led by the data is made publicly available, insight into the trends and data analysis of TikTok’s vast dataset could prove highly valuable to the tech sector.</p><p>Businesses could benefit from knowledge of the factors that drive content to do well on the platform, as well as an understanding of how trends grow in popularity to release videos before or during them. Often, by the time businesses engage with a viral trend, much of the user interest in it has waned.</p><p>This month, Ofcom <a href="https://www.ofcom.org.uk/news-centre/2022/instagram,-tiktok-and-youtube-teenagers-top-three-news-sources#:~:text=TikTok%20clocks%20up%20millions%20more,adults%20in%202022%20(7%25).">published a report</a> stating that TikTok is the second most popular news source for teenagers with 28% using it to inform themselves, just one percent behind Instagram’s 29% of teens. </p><p>This marks it as a vital frontier in the battle against <a href="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation" data-original-url="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation">disinformation</a>, and the moves announced today will allow greater oversight into this ongoing issue. In the same announcement, the company pledged to publish information on covert influence operations in all further quarterly Community Guidelines Enforcement Reports.</p><p>Select researchers will be given a similar API focused on TikTok's moderation system, to probe existing content moderation systems and the current state of content on the platform. The API will also have the functionality to let researchers upload their own content, to see what is permitted, rejected, or passed on to moderators.</p><p>In addition, select independent experts will be given access to TikTok’s list of filter keywords, which it uses to identify content as harmful and asked to offer advice based on this.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media-marketing/368526/tiktok-launches-programme-to-help-smbs-with-social" data-original-url="/marketing-comms/social-media-marketing/368526/tiktok-launches-programme-to-help-smbs-with-social">TikTok launches programme to help SMBs with social media marketing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" data-original-url="/data-protection/34415/how-to-maintain-your-privacy-on-social-media">How to maintain your privacy on social media</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics" data-original-url="/business-strategy/28163/what-is-big-data-analytics">What is big data analytics?</a></p></div></div><p>Those chosen will include members of TikTok’s US Content Advisory Council, which was set up in 2020 to give industry experts a say in the company’s safety strategies and content policies. The expert members of TikTok’s regional Safety Advisory Councils, namely Europe, the Middle East and North Africa, Asia Pacific, Brazil and Latin America will also be included.</p><p>“We've been listening to feedback from different communities of researchers, academics, and experts, and are today sharing new initiatives to strengthen transparency and accountability of our platform,” wrote Pappas in the post.</p><p>TikTok and its parent company ByteDance have faced harsh criticism in recent months, with FCC commissioner Brendan Carr last month <a href="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok">urging Apple and Google to remove TikTok from their respective app stores</a>. This was prompted by growing concerns over the security risk posed by the app's data harvesting.</p><p><em>IT Pro</em> has approached TikTok for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google fined $971k for litigation misconduct in privacy suit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368577/google-fined-971k-for-litigation-misconduct-in-privacy-suit</link>
                                                                            <description>
                            <![CDATA[ The sanction was imposed after the tech giant failed to disclose key pieces of evidence pertinent to the case ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ju1Z2tU28yTxksGbEWqPuz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sxj2GjQycVRNxaqCB5N2cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Jul 2022 16:08:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sxj2GjQycVRNxaqCB5N2cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Privacy]]></media:description>                                                            <media:text><![CDATA[Google Privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Google Privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sxj2GjQycVRNxaqCB5N2cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An order issued by a US judge on Friday mandates Google to pay over $971,000 in legal fees and costs as part of litigation misconduct in a lawsuit filed in the Northern District of California.</p><p>“The plaintiffs' lawyers at Boies Schiller Flexner and other firms had sought more than $1 million in fees and costs, after US Magistrate Judge Susan van Keulen in San Jose, California, a federal court in May found Google had failed to timely disclose some pieces of evidence,” reported <em>Reuters</em>. </p><p>Back in 2020, Google was hit with a $5 billion privacy <a href="https://www.reuters.com/article/us-alphabet-google-privacy-lawsuit/google-faces-5-billion-lawsuit-in-u-s-for-tracking-private-internet-use-idUSKBN23933H">lawsuit</a> over allegations of tracking users' data while in private or incognito mode. The penalty resulted from Google's "failure to timely identify witnesses, additional documents and data sources relevant to this litigation," Judge Keulen stated in a previous order. Nevertheless, Google has denied the allegation. </p><p>Per billing reports submitted in the case, Boies Schiller Flexner founder David Boies’ hourly rate accounts for $1,950. Altogether, he sought compensation for 49 hours, or about $96,000.</p><p>Google's lawyers at Quinn Emanuel argued the plaintiffs had not offered a "justification for their decision to have David Boies get up to speed to argue the complex issues in the sanctions motion."</p><p>Andrew Schapiro, one of Google’s lawyers, said in a statement that the plaintiffs "were seeking extreme sanctions and, at the end of the day, they are getting a partial payment of their inflated bill for the time they devoted to bringing the motion."</p><p>As matters stand, a hearing is set for September for the Brown v Google case.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon gave police departments Ring footage without permission ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368542/amazon-gave-police-ring-footage-without-permission</link>
                                                                            <description>
                            <![CDATA[ The tech giant has done this 11 times this year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qrfY2HFipPez5Qe9rrSLiP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sHvxeX58Pn2GfcabxjYb2K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jul 2022 10:20:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sHvxeX58Pn2GfcabxjYb2K-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A ring doorbell fixed next to a door on the wall]]></media:description>                                                            <media:text><![CDATA[A ring doorbell fixed next to a door on the wall]]></media:text>
                                <media:title type="plain"><![CDATA[A ring doorbell fixed next to a door on the wall]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sHvxeX58Pn2GfcabxjYb2K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon’s Ring doorbell unit has admitted to providing police forces with data without users' consent 11 times so far this year, according to a prominent US politician.</p><p>Democratic senator Edward Markey released the findings from his probe into Ring, which highlighted the close relationship between the company and law enforcement, according to a <a href="https://www.markey.senate.gov/imo/media/doc/amazon_response_to_senator_markey-july_13_2022.pdf" target="_blank">letter</a> the senator received from the company. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/359763/amazons-ring-now-requires-police-to-request-doorbell-videos-publicly" data-original-url="/security/privacy/359763/amazons-ring-now-requires-police-to-request-doorbell-videos-publicly">Amazon’s Ring now requires police to request doorbell videos publicly</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/360441/civil-rights-groups-ask-the-ftc-to-stop-amazon-surveillance" data-original-url="/business/policy-legislation/360441/civil-rights-groups-ask-the-ftc-to-stop-amazon-surveillance">Civil rights groups ask the FTC to stop Amazon surveillance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/357251/amazons-flying-security-drone-is-a-security-risk-warns-kaspersky" data-original-url="/security/hacking/357251/amazons-flying-security-drone-is-a-security-risk-warns-kaspersky">Kaspersky blasts Amazon's indoor drone as a 'major security risk'</a></p></div></div><p>The company said it <a href="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security">provided the videos</a> to law enforcement in response to emergency requests. It said that in each instance, Ring made a good-faith determination that there was an imminent danger of death or serious physical injury to a person requiring disclosure of information without delay.</p><p>"It’s simply untrue that Ring gives anyone unfettered access to customer data or video, as we have repeatedly made clear to our customers and others," a spokesperson for Amazon's Ring said in a statement. "The law authorises companies like Ring to provide information to government entities if the company believes that an emergency involving danger of death or serious physical injury to any person, such as a kidnapping or an attempted murder, requires disclosure without delay. Ring faithfully applies that legal standard."</p><p>The doorbell unit also revealed that its Neighbors Public Safety Service (NPSS), a platform that allows police and others to ask Ring owners for footage, currently has 2,161 law enforcement agencies and 455 fire departments enrolled. This represents a more than five-fold increase in law enforcement partnerships on the platform since November 2019.</p><p>“As my ongoing investigation into Amazon illustrates, it has become increasingly difficult for the public to move, assemble, and converse in public without being tracked and recorded,” said Markey. “We cannot accept this as inevitable in our country. Increasing law enforcement reliance on private surveillance creates a crisis of accountability, and I am particularly concerned that <a href="https://www.itpro.com/security/29705/what-are-biometrics" target="_blank" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">biometric</a> surveillance could become central to the growing web of surveillance systems that Amazon and other powerful tech companies are responsible for.”</p><p>The senator has called on Congress to pass the <a href="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology" target="_blank" data-original-url="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology">Facial Recognition</a> and Biometric Technology Moratorium Act to stop law enforcement from accessing sensitive information about citizens’ faces, voices, and bodies.</p><p>Ring also refused to commit to not incorporating voice recognition technology in its products. It stated that only police and fire departments are on NPSS, despite the company’s commitment to actively recruit public health departments, animal services, and agencies that primarily address homelessness, drug addiction, and mental health onto Ring’s platform.</p><p>The doorbell unit failed to clarify the distance from which Ring products can capture audio recordings and refused to commit to eliminate Ring doorbells’ default setting of automatically recording audio, stated the senator. The company also refused to commit to make <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption</a> the default storage option for consumers.</p><p>"It takes a lot of nerve for Amazon's Ring to promise a sense of safety to the face of its customers only to go around their backs giving away their private footage to the police without consent," said Nuno Guerreiro de Sousa, a technologist from Privacy International. "Allowing police to skip due processes such as warrants is not making anyone safer, one the very contrary, it opens extremely dangerous precedents."</p><p>In 2019, over 30 civil rights organisations wrote <a href="https://www.fightforthefuture.org/news/2019-10-07-open-letter-calling-on-elected-officials-to-stop" target="_blank">an open letter</a> that called on government officials to investigate Amazon Ring’s business practices and end its numerous police partnerships. The letter added that Amazon is able to vacuum up <a href="https://www.itpro.com/business-intelligence/28173/what-is-big-data" target="_blank" data-original-url="https://www.itpro.com/business-intelligence/28173/what-is-big-data">enormous amounts of data</a> which is then used to bolster Amazon’s corporate interests, often at the expense of local businesses and smaller competitors. </p><p>“Amazon’s latest encroachment with the Ring-police partnerships exemplify the company’s willingness to do what it takes to expand their data empire,” the organisations said. “Once they have this data, there is nothing stopping them from using it for their own profit-driven purposes.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google merges Chrome and Android password managers after community feedback ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368410/google-merges-chrome-and-android-password-managers-after-community-feedback</link>
                                                                            <description>
                            <![CDATA[ The tech giant is also giving users the ability to generate passwords for iOS apps when Chrome is set as the autofill provider ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">di5L2qGQd6JGmFuYuxjLk1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2avCogaCVrzjp8oj7rnZRR-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Jul 2022 11:27:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/2avCogaCVrzjp8oj7rnZRR-1280-80.png">
                                                            <media:credit><![CDATA[Google]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image of three devices with open padlocks on their screens connected to a series of asterisks representing a password]]></media:description>                                                            <media:text><![CDATA[An abstract image of three devices with open padlocks on their screens connected to a series of asterisks representing a password]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image of three devices with open padlocks on their screens connected to a series of asterisks representing a password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2avCogaCVrzjp8oj7rnZRR-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google is merging its Chrome and Android password manager to make it more consistent, as part of a number of new updates that aim to make the feature generally easier to use and more secure.</p><p>The tech giant is rolling out a simplified and unified management experience that’s the same in Chrome and Android settings, after receiving feedback that managing passwords between the two has been confusing at times. </p><p>“We're always grateful for feedback, and many of you have shared that managing passwords between Chrome and Android has been confusing at times: "It's the same info in both places, so why does it look so different?” wrote Ali Sarraf, product manager in Chrome.</p><p>Google will also automatically group passwords if a user <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">has multiple ones for the same sites</a> or apps. They will also be able to create a shortcut on their Android home screen to make it easier to access their passwords.</p><p>The company is also giving users the ability to generate passwords for iOS apps when they set Chrome as their autofill provider.</p><p>Chrome can automatically check passwords when users enter them into a site, but now it’s hoping to provide them with extra confidence by checking them in bulk with Password Checkup.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/web-browser/358385/google-chrome-makes-it-easier-to-fix-weak-passwords" data-original-url="/network-internet/web-browser/358385/google-chrome-makes-it-easier-to-fix-weak-passwords">Google Chrome makes it easier to fix weak passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32928/google-launches-password-checkup-and-cross-account-protection" data-original-url="/security/32928/google-launches-password-checkup-and-cross-account-protection">Google launches Password Checkup and Cross Account Protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359666/google-now-allows-you-to-password-protect-your-activity" data-original-url="/policy-legislation/data-protection/359666/google-now-allows-you-to-password-protect-your-activity">Google now allows you to password-protect your activity page</a></p></div></div><p>It will now be able to flag not only <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">compromised passwords</a>, but also weak and re-used passwords on Android. Users will be able to use the automated password change feature on Android to fix any passwords that Google warns them about. Additionally, the company is expanding its compromised password warning to all Chrome users on Android, Chrome OS, iOS, Windows, MacOS and Linux.</p><p>Lastly, Google is also allowing users to add their passwords directly to its app, and is bringing this functionality to Google Password Manager on all platforms. The tech giant will also bring Touch-to-Login to Chrome on Android to speed up logging in by allowing users to securely log into sites directly from the overlay at the bottom of the screen.</p><p>Google hasn’t explicitly said when the updates will be rolled out, but said they will be introduced over the next few months.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blockchain-based Gmail plugin lets users keep control over email attachments after they're sent ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/network-internet/email-delivery/367523/blockchain-gmail-tool-attachments</link>
                                                                            <description>
                            <![CDATA[ Document GPS email extension for Google Workspace considered world's first Gmail tokenization tool ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tnpVsBvzXBHqKw1aroSjbV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wQas8urwXei8qAppmSYK85-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Apr 2022 12:13:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wQas8urwXei8qAppmSYK85-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gmail application icon on a smartphone screen]]></media:description>                                                            <media:text><![CDATA[Gmail application icon on a smartphone screen]]></media:text>
                                <media:title type="plain"><![CDATA[Gmail application icon on a smartphone screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wQas8urwXei8qAppmSYK85-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Blockchain smart document specialist ShelterZoom has announced the launch of its new Document GPS solution in the Google Chrome Store. </p><p>The first Gmail document tokenization tool on the market, the offering has been designed to monitor and control email attachments so users can manage their entire journey – gaining visibility over who downloaded the file, who opened it, and who forwarded it.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" data-original-url="/network-internet/email-providers/358887/the-most-secure-email-services">The most secure email services of 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/34659/the-best-email-sign-off-and-14-to-avoid" data-original-url="/business-strategy/careers-training/34659/the-best-email-sign-off-and-14-to-avoid">10 best ways to sign off an email and 10 sign-offs to avoid - and why</a></p></div></div><p>Document GPS also allows senders to revoke a recipient’s ability to download or share the attachments at any time – even after the email has been sent.</p><p>“ShelterZoom was built on the premise of upgrading the safety and security of how people exchange information online by making it easy and effortless to integrate with blockchain,” explained ShelterZoom CEO and Co-Founder Chao Cheng-Shorland.</p><p>“What we have already created for documents and contracts we have now brought to email attachments so the full lifecycle of a document’s journey is secure. Document GPS also complements our virtual negotiating platform so users can carry out a complete workflow in the same secure ecosystem.”</p><p>With the <a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3" data-original-url="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3">growth of Web3</a>, ShelterZoom says that digital security will take on an even more crucial role than it already does. To help tackle this, Document GPS provides email senders with a timestamped log in their interactive Attachment Library built into their email interface – allowing complete visibility into how each recipient has interacted with the file.</p><p>The company has built the solution on the same <a href="https://www.itpro.com/security/28031/what-is-blockchain" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain technology</a> that powers their entire platform to give Gmail and Google Workspace users an extra layer of security integrated into the system.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7aXsyZevCE4BJaQcNzp4zm" name="7aXsyZevCE4BJaQcNzp4zm.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" mos="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of email security 2022</strong></p><p class="fancy-box__body-text">Confronting the new wave of cyber attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/367501/the-state-of-email-security-2022" data-original-url="/security/cyber-security/367501/the-state-of-email-security-2022">FREE DOWNLOAD</a></p></div></div><p>ShelterZoom says it plans to release a similar tool for Microsoft Outlook users later this year. For now, current use cases include crypto banking professionals, <a href="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security" data-original-url="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security">small business owners</a>, as well as personal Google users.</p><p>“With the click of a button, our clients and collaborators are now empowered with total control over important documents, giving us peace of mind of their origin, authenticity and access, greatly reducing risk of fraud, document loss or mishandling,” commented Michel Garibaldi of Arab Bank. “For the finance industry, this is a game-changer.”</p><p>Gregg Farrauto, Founder and CEO of US-based Farrauto Wealth Management said: “By using Document GPS for high-stakes attachments, I can rest easier knowing I can track the documents I send and my clients' private information is protected even if their email system gets hacked."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IRS lets taxpayers bypass facial recognition with virtual interviews ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/362810/irs-lets-taxpayers-bypass-facial-recognition-with-virtual-interviews</link>
                                                                            <description>
                            <![CDATA[ The temporary solution will be in effect through the 2022 tax filing season ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fFzU7aosimcU3dwA7a2NqN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WSmWpBxgfURPinZwXYRAvi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Feb 2022 14:09:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WSmWpBxgfURPinZwXYRAvi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Internal Revenue Service (IRS) building in Washington, D.C]]></media:description>                                                            <media:text><![CDATA[The Internal Revenue Service (IRS) building in Washington, D.C]]></media:text>
                                <media:title type="plain"><![CDATA[The Internal Revenue Service (IRS) building in Washington, D.C]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WSmWpBxgfURPinZwXYRAvi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US taxpayers will no longer need to use facial recognition or any other form of biometric authenticationjavascript:void(0) to access their online Internal Revenue Service (IRS) accounts, the agency <a href="https://www.irs.gov/newsroom/irs-statement-new-features-put-in-place-for-irs-online-account-registration-process-strengthened-to-ensure-privacy-and-security">announced</a> on Monday.</p><p>Instead, taxpayers will have the option of verifying their identity through a live, virtual interview conducted by a tax agent. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/362260/us-senators-urge-labour-department-to-drop-facial-recognition" data-original-url="/security/privacy/362260/us-senators-urge-labour-department-to-drop-facial-recognition">US senators urge Labor Department to drop facial recognition</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash" data-original-url="/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash">IRS backtracks on facial recognition plans following backlash</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/biometrics/361430/facebook-shutdown-facial-recognition-system" data-original-url="/security/biometrics/361430/facebook-shutdown-facial-recognition-system">Facebook is shutting down its controversial facial recognition system</a></p></div></div><p>The new option comes on the heels of <a href="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash" data-original-url="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash">IRS backtracking on its decision to mandate facial recognition</a> through external identity verification firm ID.me, which raised privacy concerns among taxpayers, lawmakers, and advocacy groups.</p><p>"The IRS takes taxpayer privacy and security seriously, and we understand the concerns that have been raised," said Chuck Rettig, IRS commissioner. </p><p>"Everyone should feel comfortable with how their personal information is secured, and we are quickly pursuing short-term options that do not involve facial recognition."</p><p>However, the IRS noted that taxpayers will still be able to verify their identity using the self-assistance tool provided by ID.me, if desired.</p><p>For security reasons, all images provided during biometric verification will be deleted following account creation. The IRS will also permanently delete any biometric data gathered from taxpayers with existing accounts in the next few weeks.</p><p>Furthermore, the IRS announced that while it plans to use the short-term virtual interview solution for the current filing season, it intends to implement Login.Gov as an authentication tool in the future</p><p>A partnership between General Services Administration (GSA) and the IRS is underway to meet the standards and scale required of Login.Gov, which is slated to launch after the 2022 filing deadline.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US senators urge Labor Department to drop facial recognition  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/362260/us-senators-urge-labour-department-to-drop-facial-recognition</link>
                                                                            <description>
                            <![CDATA[ In half of US states, workers filing for unemployed insurance must create an account with ID.me ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fVUbRBUxJKydHNTvt711Km</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Le7DUjBRxSN8tEzX75rrRf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Feb 2022 12:05:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Le7DUjBRxSN8tEzX75rrRf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman looks at her phone to scan her face using facial recognition technology]]></media:description>                                                            <media:text><![CDATA[A woman looks at her phone to scan her face using facial recognition technology]]></media:text>
                                <media:title type="plain"><![CDATA[A woman looks at her phone to scan her face using facial recognition technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Le7DUjBRxSN8tEzX75rrRf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three US senators have urged the Department of Labor to ditch facial recognition technology for unemployment benefits, raising concerns around privacy and bias in the technology. </p><p>Senate Finance Committee members Ron Wyden, Sherrod Brown, and Elizabeth Warren urged the department to ensure state unemployment insurance (UI) programmes are able to securely verify their applicants’ identities without sacrificing claimant privacy.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash" data-original-url="/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash">IRS backtracks on facial recognition plans following backlash</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/362254/texas-sues-facebook-for-misusing-facial-recognition-data" data-original-url="/security/privacy/362254/texas-sues-facebook-for-misusing-facial-recognition-data">Texas sues Facebook for misusing facial recognition data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/biometrics/359928/information-commissioner-deeply-concerned-about-use-of-facial" data-original-url="/security/biometrics/359928/information-commissioner-deeply-concerned-about-use-of-facial">ICO: Use of facial recognition tech in public spaces deeply concerning</a></p></div></div><p>In a letter sent to Labor secretary Marty Walsh, the senators highlighted that in over half of US states, workers filing for UI must sign up for an account with ID.me. Most users have to submit facial recognition to verify their identity and access benefits. They explained that many states started using the service during the pandemic to combat fraud and identity theft, but said that this shouldn’t mean claimant privacy is compromised in the process.</p><p>The three senators underlined that facial recognition should not be a prerequisite for accessing UI or any other essential government services. They added that facial recognition technologies don’t only raise privacy and civil liberty concerns, but also are biased in ways that negatively impact vulnerable groups, including people of colour, women, and seniors. They also said that it was concerning that so many state and federal government agencies have outsourced their core technology <a href="https://www.itpro.com/infrastructure" target="_blank" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> to the private sector.</p><p>“It is particularly concerning that one of the most prominent vendors in the space, ID.me, not only uses facial recognition and lacks transparency about its processes and results, but frequently has unacceptably long wait times for users to be screened by humans after being rejected by the company’s automated scanning system,” stated the senators.</p><p>Instead, the senators advised that the department should assist state unemployment insurance programmes gain access to federal alternatives like login.gov, run by the General Services Administration, which offers a federal identity verification option.</p><p>Login.gov is currently used by 200 websites run by 28 Federal agencies, with over 40 million US citizens having accounts on the service.</p><p>“This call to transition away from private facial recognition contractors will only add further fuel to the debate around the practices of ethical data collection and analysis," said Camilla Winlo, head of Data Privacy at Gemserv. "This shows that organisations that want to harness the possibilities of AI and data-driven innovation must do so in a way that protects individuals. Organisations should be entitled to trust that providers are engaging in ethical practices and that their services can be used lawfully. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nrLP4J9zrGeXVej3Fjg2DP" name="nrLP4J9zrGeXVej3Fjg2DP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" mos="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Secure hybrid cloud for dummies</strong></p><p class="fancy-box__body-text">Accelerate transformation with hybrid cloud</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies" data-original-url="/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies">FREE DOWNLOAD</a></p></div></div><p>“Whether it’s fighting crime, preventing fraud or other forms of safeguarding through data, when the public and private sector combine, they must ensure the right processes are put in place in order to comply with data protection regulation.”</p><p>A spokesperson from ID.me told <em>IT Pro</em>: "ID.me isn’t commenting outside of publicly available statements.”</p><p>This comes after the <a href="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash" target="_blank" data-original-url="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash">IRS announced earlier in February it would no longer employ ID.me</a>, following concerns over user privacy. It had announced that from the summer of 2022, taxpayers would have to validate their accounts by providing a government-issued photo document as well as taking a video selfie.</p><p>However, it reversed the decision, with the IRS commissioner stating that it takes taxpayer privacy and security seriously, and it understood the concerns that had been raised.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Texas sues Facebook for misusing facial recognition data  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/362254/texas-sues-facebook-for-misusing-facial-recognition-data</link>
                                                                            <description>
                            <![CDATA[ State wants up to $25,000 per alleged violation for discontinued program ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">huLgStHNqKqTGMDv7ZucZz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WGCsRefGv8J2gf78DhKqj8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Feb 2022 09:23:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WGCsRefGv8J2gf78DhKqj8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook sign at entrance of its campus]]></media:description>                                                            <media:text><![CDATA[Facebook sign at entrance of its campus]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook sign at entrance of its campus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WGCsRefGv8J2gf78DhKqj8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The state of Texas has sued Facebook parent company Meta over its <a href="https://www.itpro.com/security/biometrics/361430/facebook-shutdown-facial-recognition-system" target="_blank" data-original-url="https://www.itpro.com/security/biometrics/361430/facebook-shutdown-facial-recognition-system">discontinued facial recognition system</a>, claiming that it captured citizens' facial data without their informed consent.</p><p>In a <a href="https://texasattorneygeneral.gov/sites/default/files/images/child-support/State%2520of%2520Texas%2520v.%2520Meta%2520Platforms%2520Inc..pdf">suit</a> filed Tuesday, state Attorney General Ken Paxton accused the company of "illegal and deceptive conduct" that it repeated billions of times by running recognition algorithms on pictures of them, their friends and family.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash" data-original-url="/security/privacy/362186/irs-backtracks-on-facial-recognition-plans-following-backlash">IRS backtracks on facial recognition plans following backlash</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/362195/facebook-protect-users-doxxing-oversight-board-says" data-original-url="/policy-legislation/data-protection/362195/facebook-protect-users-doxxing-oversight-board-says">Meta Oversight Board urges Facebook to protect users from doxing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/biometrics/361430/facebook-shutdown-facial-recognition-system" data-original-url="/security/biometrics/361430/facebook-shutdown-facial-recognition-system">Facebook is shutting down its controversial facial recognition system</a></p></div></div><p>The lawsuit says that the practices violated a 2009 state law known as CUBI that required informed consent for the capture of biometric identifiers. It also requires anyone holding biometric data to destroy it in a reasonable time period.</p><p>It accuses Meta of collecting biometric data from unwitting users and failing to delete it in line with CUBI's requirements. It also criticizes the company for running facial recognition on other pictures that users uploaded.</p><p>"Texas who used Facebook's social media services were oblivious to the fact that Facebook - without their permission - was capturing biometric information from photos and videos that users had uploaded for the sole purpose of sharing with family and friends," the suit said.</p><p>The company also failed to notify users of its Instagram service that it was using their data, it adds.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2X7xMX26emeazWsKDvsRED" name="2X7xMX26emeazWsKDvsRED.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/2X7xMX26emeazWsKDvsRED.png" mos="https://cdn.mos.cms.futurecdn.net/2X7xMX26emeazWsKDvsRED.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Smarter AIOps</strong></p><p class="fancy-box__body-text">AI powered automation helping your business assure app performance</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/application-programming-interface-api/362133/smarter-aiops" data-original-url="/development/application-programming-interface-api/362133/smarter-aiops">FREE DOWNLOAD</a></p></div></div><p>The suit requests payments of up to $25,000 per infraction, and says that Meta broke the law "not hundreds, or thousands, or millions of times - but billions of times".</p><p>Facebook <a href="https://about.fb.com/news/2021/11/update-on-use-of-face-recognition">shut down</a> its facial recognition system in November 2021, vowing to delete more than a billion individual facial recognition templates.</p><p>Paxton is no stranger to big tech investigations. He launched an investigation into Twitter's content moderation practices last year, which <a href="https://www.itpro.com/marketing-comms/social-media/358851/twitter-sues-texas-ag-for-violating-its-free-speech" data-original-url="https://www.itpro.com/marketing-comms/social-media/358851/twitter-sues-texas-ag-for-violating-its-free-speech">prompted a retaliatory suit</a> from Twitter. He filed an amicus brief last September with nine other AGs in support of <a href="https://www.itpro.com/marketing-comms/social-media/359667/florida-passes-new-anti-censorship-law-targeting-social-media" data-original-url="https://www.itpro.com/marketing-comms/social-media/359667/florida-passes-new-anti-censorship-law-targeting-social-media">Florida's social media censorship law</a>, after Texas passed a similar bill, and also filed an amicus brief supporting Epic Games in its <a href="https://www.itpro.com/hardware/mobile/356781/fortnite-maker-sues-google-and-apple-over-app-store-cut" data-original-url="https://www.itpro.com/hardware/mobile/356781/fortnite-maker-sues-google-and-apple-over-app-store-cut">lawsuit</a> against Apple earlier this month.</p><p>"This is yet another example of big tech’s deceitful business practices and it must stop. I will continue to fight for Texans’ privacy and security," Paxton said, describing the Meta lawsuit this week.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom users claim macOS app keeps 'listening' after meetings end ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/362236/zoom-bug-microphone-active-macos</link>
                                                                            <description>
                            <![CDATA[ Numerous users report 'privacy breaches' as macOS indicators revealed the device's microphone remained enabled long after meetings had ended ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hoTkTqDXveM1oLtVB5S4vU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H2heBA8LLKeWu4Tq9zzFHj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Feb 2022 10:51:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H2heBA8LLKeWu4Tq9zzFHj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand in shadow holding a phone with the Zoom app]]></media:description>                                                            <media:text><![CDATA[A hand in shadow holding a phone with the Zoom app]]></media:text>
                                <media:title type="plain"><![CDATA[A hand in shadow holding a phone with the Zoom app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H2heBA8LLKeWu4Tq9zzFHj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Video conferencing and collaboration platform Zoom has released an update to its macOS client addressing a security issue whereby a Mac's microphone remained enabled even after a meeting had ended.</p><p>Zoom users running the latest version of <a href="https://www.itpro.com/operating-systems/ios/359804/apple-wwdc-2021-the-biggest-announcements" data-original-url="https://www.itpro.com/operating-systems/ios/359804/apple-wwdc-2021-the-biggest-announcements">macOS Monterey</a> had been concerned about the apparent privacy issues since December 2021, according to <a href="https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/m-p/41449#M20549">posts</a> made on the official Zoom community support forums, first reported by <em><a href="https://www.theregister.com/2022/02/10/zoom_mac_microphone">The Register</a>.</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357710/zoom-shares-tumble-after-ftc-settlement" data-original-url="/security/357710/zoom-shares-tumble-after-ftc-settlement">Zoom settles with the FTC over 'deceptive' encryption claims</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/zero-day-exploit/33976/apple-rolls-out-its-own-fix-for-zoom-zero-day" data-original-url="/zero-day-exploit/33976/apple-rolls-out-its-own-fix-for-zoom-zero-day">Apple rolls out its own fix for Zoom zero-day</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360625/zoom-incompatible-with-gdpr" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360625/zoom-incompatible-with-gdpr">Zoom is no longer compatible with GDPR, Hamburg data watchdog claims</a></p></div></div><p>The issue in question involved the orange dot in the Mac's Control Centre appearing, indicating that the device's microphone was being used in an application. That app was revealed to be Zoom, which was open in the taskbar but not actively in a meeting.</p><p>Numerous replies to the original post echoed concerns regarding where the audio data was being sent, and that it wasn't a single use case. </p><p>"The Zoom client for macOS 5.9.3, released on January 25, 2022, fixed a bug involving the failure to properly terminate the microphone use post-meeting," a Zoo spokesperson told <em>IT Pro</em>.</p><p>"Zoom has determined that this bug did not result in audio data being transmitted back to Zoom's platform," they added. "As always, we recommend users make sure their Zoom client is updated to the latest version."</p><p>The <a href="https://support.zoom.us/hc/en-us/articles/201361963-New-Updates-for-Mac-OS">release notes</a> accompanying version 5.9.3 made no explicit mention of the macOS bug, but earlier release notes for version 5.9.1 issued on 20 December 2021 indicated the big had been fixed, though no explanation was provided as to why the bug presented itself, or what was done with recordings.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDWPShop8idtg5y5PK4Eu4" name="TDWPShop8idtg5y5PK4Eu4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TDWPShop8idtg5y5PK4Eu4.png" mos="https://cdn.mos.cms.futurecdn.net/TDWPShop8idtg5y5PK4Eu4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Hybrid cloud for video surveillance</strong></p><p class="fancy-box__body-text">What it is and why you'll want one</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/360218/hybrid-cloud-for-video-surveillance" data-original-url="/cloud/360218/hybrid-cloud-for-video-surveillance">FREE DOWNLOAD</a></p></div></div><p>Numerous users also reported the bug persisting even after updating to version 5.9.1 and complaints persisted well into January 2022, long after even the 5.9.3 patch was released.</p><p>At the time, users commenting on the community support thread voiced their concerns around privacy, re-iterating their experience with Zoom's privacy issues in years gone by. One user said: "This is [a] major privacy breach and I am considering dropping Zoom and asking my IT department to replace Zoom with a more secure option".</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/EmlLQse9r6g" allowfullscreen></iframe></div></div><p>In 2019, Zoom was <a href="https://www.itpro.com/zero-day-exploit/33976/apple-rolls-out-its-own-fix-for-zoom-zero-day" data-original-url="https://www.itpro.com/zero-day-exploit/33976/apple-rolls-out-its-own-fix-for-zoom-zero-day">criticised for installing a local web server on Mac users' machines</a> that allowed websites to automatically launch users into meetings and enable their webcams.</p><p>The incident prompted Apple to roll out a silent update removing the web server from all Mac machines which followed Zoom's own update achieving the same purpose. Apple said at the time that no user intervention was required to enable the update but <em>IT Pro's </em>testing, at the time, showed the issue persisted until the user rebooted their machine.</p><p>The company also <a href="https://www.itpro.com/security/357710/zoom-shares-tumble-after-ftc-settlement" data-original-url="https://www.itpro.com/security/357710/zoom-shares-tumble-after-ftc-settlement">settled a case with the Federal Trade Commission</a> (FTC) in 2020 after the claims it made about the use of <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption</a> (E2EE) on its platform, which was used by <a href="https://www.itpro.com/software/video-conferencing/355180/zoom-does-not-use-end-to-end-encrypted" data-original-url="https://www.itpro.com/software/video-conferencing/355180/zoom-does-not-use-end-to-end-encrypted">governments</a> and <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360625/zoom-incompatible-with-gdpr" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360625/zoom-incompatible-with-gdpr">local authorities</a> during the pandemic, turned out to be false.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass announces integration with Google Workspace ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/integration/361812/lastpass-announces-integration-with-google-workspace</link>
                                                                            <description>
                            <![CDATA[ Employers can now automatically provide employees with a LastPass account through Google’s directory integration ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NzZJMDuNY2PECFkDKpRJy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vqZP2Th57ieFuSE5BPrEBf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Dec 2021 11:00:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vqZP2Th57ieFuSE5BPrEBf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Workspace login for LogMeIn]]></media:description>                                                            <media:text><![CDATA[Google Workspace login for LogMeIn]]></media:text>
                                <media:title type="plain"><![CDATA[Google Workspace login for LogMeIn]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vqZP2Th57ieFuSE5BPrEBf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use" data-original-url="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use">LastPass</a> has announced a new integration with <a href="https://www.itpro.com/business-strategy/collaboration/361222/google-workspace-adds-jira-and-appsheet-integrations" data-original-url="https://www.itpro.com/business-strategy/collaboration/361222/google-workspace-adds-jira-and-appsheet-integrations">Google Workspace</a> in a bid to provide a seamless login process for <a href="https://www.itpro.com/business" data-original-url="https://www.itpro.com/business">business</a> users.</p><p>Employers can now automatically provide employees with a LastPass account through Google’s directory integration, allowing them to store all their passwords for seamless logins without compromising on <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a>.</p><p>The integration allows users to access LastPass using their corporate Google Workspace credentials without any additional passwords, minimising <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password</a> reset frustrations and time spent on logging into accounts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers" data-original-url="/security/information-security-infosec/361806/skip-three-words-use-password-managers">Skip the three words thing, go straight for the ‘use a password manager, dammit’ jugular</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords" data-original-url="/security/361695/over-90-of-it-decision-makers-reuse-passwords">More than 90% of IT decision makers reuse passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure" data-original-url="/security/cyber-security/361037/what-makes-a-password-secure">What makes a password secure?</a></p></div></div><p>The Google active directory also allows for employers to easily add and remove users, simplifying management and ensuring the security of the organisation.</p><p>Dan DeMichele, VP of Product Management at LogMeIn, said: “Between this new integration with Google Workspace, and the combination of zero-knowledge infrastructure and multi-key approach, this security model that is unique to LastPass offers a level of security uncommon with such a simple login experience.” </p><p>According to DeMichele, “this ensures the keys used to unlock a user’s vault only reunite locally on the end-user’s device”.</p><p>“LastPass is the leading password manager on the market, providing this level of security authentication for federated login integrations with identity providers,” he added.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BvaxdVesrBPpDZeCYx49S" name="BvaxdVesrBPpDZeCYx49S.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S.jpg" mos="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Multi-factor authentication deployment guide</strong></p><p class="fancy-box__body-text">A complete guide to selecting and deploying your MFA authentication guide</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide" data-original-url="/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide">FREE DOWNLOAD</a></p></div></div><p>The integration with Google Workspace comes months after LogMeIn, LastPass’ parent company, announced that users on the service’s free tier would <a href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" data-original-url="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">no longer have unlimited access to their stored passwords</a> on both desktop and mobile devices. Since 16 March 2021, users are only able to view and manage passwords on either desktop or mobile, being forced to choose which platform they want to use to access their password vaults and being locked out of the other. </p><p>LastPass’s Premium and Family subscriptions start at £2.60 and £3.40 per month, respectively, and include additional features such as expanded multifactor authentication support, dark web monitoring and improved password sharing. </p><p>LastPass’s business offerings start with Teams, priced at £40.80 per user, per year, and intended for SMEs or workgroups with up to 50 users, although this is a recommendation rather than a hard limit. This provides each user with an industry-standard password storage vault with optional <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a>, shared folders for your team, and a dashboard to administrate everything.</p><p>The next tier up, Enterprise, has no recommended ceiling on user numbers and adds Single Sign-On support, personal customer support, API and app integrations and customisable security policies. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>