From the Desk
Compliance & GRC
Regulatory updates, compliance frameworks, governance, risk management.
20
Stories filed
3
Desks covered
≥ 6/10
Editorial floor
Coverage:RegulatoryComplianceSecurity
§
On the Compliance & GRC Desk
The latest stories filtered for your beat, organised by sub-section.
Security11 stories
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was DeletedData that should have been deleted under contractual terms was retained and then breached — a clear failure in data-lifecycle governance with GDPR and contractual implications.2d
- IDScan sued over alleged data breach affecting 153 million driversLawsuits following the breach underscore the litigation exposure when a processor fails to safeguard personal data at scale—directly relevant to GDPR Article 28 obligations.3d
- Your Employee’s Password Appeared in an Infostealer Log. Now What?4d
- US and Canadian court data exposed in Thomson Reuters breachExposure of sealed judicial records and personal data across multiple jurisdictions raises cross-border data protection questions relevant to GDPR-aligned risk assessments of US-based service providers.4d
- Health data of more than 9.5 million people leaked from Aesto record systemA breach of this scale at a health data processor raises questions about vendor due diligence, data-processing agreements, and breach notification timelines — directly relevant to GDPR Article 28 obligations.5d
- The Agentic SOC – From AI Theater to Real Defense1 Sept
- Toy-making giant Hasbro disclose data breach affecting employeesEmployee data breaches trigger notification obligations under GDPR and equivalent frameworks; this case illustrates reputational and regulatory exposure for large employers.28 Aug
- Manchester Airports Group says hackers stole travelers' dataAirport Wi-Fi sign-up data falls under GDPR; the breach may trigger UK/EU DPA investigations and demonstrates ongoing public-infrastructure data-protection gaps.27 Aug
- Carhartt data breach exposes information of 12.9 million accounts27 Aug
- Boston Scientific says cyberattack disrupted operations globallyNIS2 essential-entity obligations require healthcare supply-chain risk management — this incident illustrates the kind of third-party disruption regulators expect organisations to plan for.26 Aug
- Is Cyber Facing an Affordability Crisis?Under NIS2's supply-chain provisions, enterprises must ensure that smaller suppliers meet baseline security standards—an affordability gap upstream becomes a compliance risk downstream.25 Aug
Regulatory3 stories
- G7 urges organizations to prepare for quantum cyber threatsThe G7 advisory creates a soft regulatory expectation that will likely harden into NIS2 and DORA technical standards — early movers reduce future compliance friction.3d
- Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warnsFSB's warning directly informs DORA operational resilience requirements and may trigger new supervisory expectations around AI-related third-party risk management for EU financial entities.6d
- Defining an AI Kill Switch Is Hard, but NecessaryLegislative proposals to mandate AI shutdown capabilities directly intersect with EU AI Act obligations around high-risk AI system oversight and human control requirements.28 Aug
Compliance6 stories
- Compliance teams have gone continuous, but their evidence-gathering hasn’t caught upA survey of 201 practitioners confirms that most organisations already operate continuous compliance but still rely on manual evidence collection — a gap that directly affects audit readiness under NIS2 and DORA.3d
- Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New ChainsA deployed system scoring 835 million blockchain addresses with label-free cross-chain transfer could reshape sanctions-screening obligations, especially as EU AML frameworks expand to crypto assets.4d
- French hospital fined €500,000 after breach exposes data of 727,000CNIL's fine directly penalises failures in technical and organisational measures under GDPR—a precedent for healthcare and any sector processing sensitive personal data at scale.4d
- Identification of Compositional Risks in Data Protection Impact Assessments and BeyondWhen multiple processors handle personal data in a service composition, hidden compositional privacy risks can emerge that single-provider DPIAs miss—directly relevant to GDPR and NIS2 supply-chain obligations.6d
- You Know GDPR Is Good Based on Who Hates It29 Aug
- Why Provision 29 is raising the bar for board accountability26 Aug