From the Desk
Compliance & GRC
Regulatory updates, compliance frameworks, governance, risk management.
20
Stories filed
3
Desks covered
≥ 6/10
Editorial floor
Coverage:RegulatoryComplianceSecurity
§
On the Compliance & GRC Desk
The latest stories filtered for your beat, organised by sub-section.
Security11 stories
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was DeletedData that should have been deleted under contractual terms was retained and then breached — a clear failure in data-lifecycle governance with GDPR and contractual implications.5d
- IDScan sued over alleged data breach affecting 153 million driversLawsuits following the breach underscore the litigation exposure when a processor fails to safeguard personal data at scale—directly relevant to GDPR Article 28 obligations.6d
- Your Employee’s Password Appeared in an Infostealer Log. Now What?3 Sept
- US and Canadian court data exposed in Thomson Reuters breachExposure of sealed judicial records and personal data across multiple jurisdictions raises cross-border data protection questions relevant to GDPR-aligned risk assessments of US-based service providers.3 Sept
- Health data of more than 9.5 million people leaked from Aesto record systemA breach of this scale at a health data processor raises questions about vendor due diligence, data-processing agreements, and breach notification timelines — directly relevant to GDPR Article 28 obligations.2 Sept
- The Agentic SOC – From AI Theater to Real Defense1 Sept
- Toy-making giant Hasbro disclose data breach affecting employeesEmployee data breaches trigger notification obligations under GDPR and equivalent frameworks; this case illustrates reputational and regulatory exposure for large employers.28 Aug
- Manchester Airports Group says hackers stole travelers' dataAirport Wi-Fi sign-up data falls under GDPR; the breach may trigger UK/EU DPA investigations and demonstrates ongoing public-infrastructure data-protection gaps.27 Aug
- Carhartt data breach exposes information of 12.9 million accounts27 Aug
- Boston Scientific says cyberattack disrupted operations globallyNIS2 essential-entity obligations require healthcare supply-chain risk management — this incident illustrates the kind of third-party disruption regulators expect organisations to plan for.26 Aug
- Is Cyber Facing an Affordability Crisis?Under NIS2's supply-chain provisions, enterprises must ensure that smaller suppliers meet baseline security standards—an affordability gap upstream becomes a compliance risk downstream.25 Aug
Regulatory3 stories
- G7 urges organizations to prepare for quantum cyber threatsThe G7 advisory creates a soft regulatory expectation that will likely harden into NIS2 and DORA technical standards — early movers reduce future compliance friction.6d
- Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warnsFSB's warning directly informs DORA operational resilience requirements and may trigger new supervisory expectations around AI-related third-party risk management for EU financial entities.1 Sept
- Defining an AI Kill Switch Is Hard, but NecessaryLegislative proposals to mandate AI shutdown capabilities directly intersect with EU AI Act obligations around high-risk AI system oversight and human control requirements.28 Aug
Compliance6 stories
- Compliance teams have gone continuous, but their evidence-gathering hasn’t caught upA survey of 201 practitioners confirms that most organisations already operate continuous compliance but still rely on manual evidence collection — a gap that directly affects audit readiness under NIS2 and DORA.6d
- Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New ChainsA deployed system scoring 835 million blockchain addresses with label-free cross-chain transfer could reshape sanctions-screening obligations, especially as EU AML frameworks expand to crypto assets.4 Sept
- French hospital fined €500,000 after breach exposes data of 727,000CNIL's fine directly penalises failures in technical and organisational measures under GDPR—a precedent for healthcare and any sector processing sensitive personal data at scale.3 Sept
- Identification of Compositional Risks in Data Protection Impact Assessments and BeyondWhen multiple processors handle personal data in a service composition, hidden compositional privacy risks can emerge that single-provider DPIAs miss—directly relevant to GDPR and NIS2 supply-chain obligations.2 Sept
- You Know GDPR Is Good Based on Who Hates It29 Aug
- Why Provision 29 is raising the bar for board accountability26 Aug