Skip to main content

Data Protection

Federal agency document processing room with employees working at desks amidst stacks of papers and laptops.

AI Reshapes Federal eDiscovery to Meet Surging FOIA Demands

Federal agencies are struggling to keep up with a surge in FOIA requests that are not only increasing in volume but also growing more complex, involving large volumes of electronic records, multiple custodians, and sensitive data. This perfect storm is putting a strain on legacy eDiscovery systems and already limited staff, all while meeting a strict 20-day deadline.

Analyst 207
Laptop workstation in a neutral office setting with surrounding furniture and equipment.

Anthropic Exposes Gaps in AI Agent Governance with New Compliance API

Anthropic just dropped a bombshell, revealing major gaps in AI agent governance with its new Compliance API - and it's a game-changer for cloud security. By introducing local session transcripts, Anthropic is shining a light on what really happens when AI agents interact with your systems.

Analyst 207
Smartphone on a neutral surface with blurred institutional background.

Meta Overhauls Platforms Amid $18B Youth Safety Settlement

Meta is shelling out a whopping $18 billion to settle allegations that its platforms contributed to a mental health crisis among youth - and as part of the deal, it's making significant changes to its platforms to promote safer online experiences. This massive settlement could be a game-changer for social media, pushing other platforms to follow suit.

Analyst 207

Meta Faces $18 Billion Settlement Over Alleged Harms to Teen Users

Meta's proposed $18 billion settlement aims to revolutionize teen safety online, introducing industry-leading protections that will safeguard young users across Facebook, Instagram, and beyond. The agreement includes game-changing defaults like a two-hour daily usage limit, nighttime app blocks, and muted notifications, all designed to shield teens from potential harm.

Analyst 207
Partially obscured formal document on a plain surface with subtle NSA emblem in background.

NSA's Non-Disclosure Pacts Omit Whistleblower Protections

The NSA's nondisclosure agreements are leaving employees in the dark about their whistleblower rights, with most failing to include crucial language that would inform them of their statutory protections. This oversight could silence employees who want to speak out about wrongdoing, undermining their ability to hold the agency accountable.

Analyst 207
Government building entrance with people walking in and out, subtle tech hint in background.

TikTok Settles with US for $400M Over COPPA Violations

TikTok is coughing up $400 million to settle allegations that it violated children's online privacy laws, with $300 million changing hands immediately and another $100 million pending a court ruling. The hefty fine sends a clear message: companies must play by the rules when collecting kids' personal info.

Analyst 207
Worker in uniform reviews documents and speaks on phone at defense industrial base facility.

CMMC Pause Doesn't Halt Compliance Imperative

The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

Analyst 207
Government building with tall windows and formal podium, daytime setting.

TikTok Settles Child Privacy Suit for $400 Million

TikTok is paying a whopping $400 million to settle a lawsuit alleging it broke US child privacy laws, in a major win for American kids and parents. The deal, secured by the US Department of Justice, marks one of the largest recoveries ever under the Children's Online Privacy Protection Act.

Analyst 207
Police officer stands at console in station, reviewing data on paper or tablet.

UK Watchdog Warns Police on Facial Recognition Data Governance

The UK's Information Commissioner's Office warns that police use of facial recognition technology poses significant risks to privacy and individual rights if not governed properly. A recent audit of five police forces revealed inconsistent compliance with data protection laws, highlighting an urgent need for improved data governance.

Analyst 207
Person standing in front of blank whiteboard with subtle security theme in background.

Sharpening Cybersecurity Standards

Don't let your guard down now - Katie Arrington stresses that now is not the time to relax cybersecurity standards, especially after self-attestation failed to protect the war industrial base. The Cybersecurity Maturity Model Certification was created to ensure verification and accountability.

Analyst 207
Technical lab with network and IoT devices on a workbench surrounded by testing equipment and screens.

ETSI Advances 17 Cybersecurity Standards for EU Compliance

The European Telecommunications Standards Institute (ETSI) is pushing forward with 17 crucial cybersecurity standards to help vendors and buyers across the continent meet the EU's Cyber Resilience Act requirements. These draft standards cover 17 major product categories, setting a vital baseline for manufacturers to ensure their products are secure and compliant.

Analyst 207
Compliance officer reviewing documents at a desk with a computer terminal in the background.

IAM Compliance Requires Verified Enforcement

To truly achieve IAM compliance, it's not enough to just have policies in place - you need to prove that they're being enforced. The real challenge lies in bridging the gap between policy intent and actual runtime execution, where compliance failures and unmanaged access often hide.

Analyst 207
Security dashboard console displays Key Security Indicators with graphs and metrics in a bright, clean cloud computing…

FedRAMP Rev5 Ends, 20X Transition Requires Continuous Evidence

FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

Analyst 207
Genetic testing lab with modern and traditional equipment, conveying scrutiny and security.

23andMe Agrees to $18m Settlement, New Data Security Mandates

After cracking down on 23andMe's lax security measures, a coalition of 42 US attorneys general, led by New York Attorney General Letitia James, has secured an $18 million settlement and binding data-protection commitments to safeguard customer information. This move comes after a 2023 data breach put millions of 23andMe customers at risk of having their personal info exposed.

Analyst 207
Government building with empty plaque, person walking away in background.

UK Information Commissioner Resigns Amid Workplace Misconduct Probe

UK Information Commissioner John Edwards has resigned amid allegations of workplace misconduct, including the use of vulgar and highly sexualized language towards staff, which he initially dismissed as misplaced humour. His resignation comes after an internal HR investigation concluded there was a case to answer, with evidence revealing a disturbing pattern of behaviour.

Analyst 207
Laptop screen shows retail website checkout page with multiple scripts loading in the background.

New PCI DSS Rules Target Script Security on Checkout Pages

Did you know that over 100,000 sites have fallen victim to web skimming and supply-chain attacks, with Magecart-style attacks often sneaking in through third-party scripts on crowded checkout pages? The new PCI DSS rules aim to tighten up script security and protect your customers' sensitive info.

Analyst 207
Dimly lit datacenter hallway with server racks and maintenance personnel in the distance, under flickering fluorescent…

US Datacenter Law Set to Lapse, Leaving Security Gaps Unaddressed

As the Federal Data Center Enhancement Act of 2023 lapses on September 30, 2026, a crucial safeguard for secure and reliable access to federal information systems will vanish, leaving gaping security holes unaddressed. Without an extension or replacement, federal data centers may operate with little oversight, putting sensitive information at risk.

Analyst 207
Cluttered workshop with scattered electronics and concerned people.

Open Source Community Unprepared for EU's Cyber Resilience Act

The open source community is lagging behind on cybersecurity readiness, with stagnating awareness and a lack of preparedness for the EU's Cyber Resilience Act, which requires minimum security standards for hardware and software products by December 2027. It's time for urgent action to avoid falling short of compliance.

Analyst 207
Government office workspace with filing cabinets, digital storage equipment, and papers on a desk.

Federal Agencies Face Data Storage Challenge in Meeting Legal, Compliance Needs

Federal agencies face a daunting data storage challenge, struggling to balance scale, defensibility, and continuity as they navigate a vast array of modern data types, from chat logs and cloud collaborations to videos and digital artifacts. Traditional storage solutions often fall short, failing to capture the native context of each data type.

Analyst 207
State regulators meet around a table with a robot and papers, discussing AI in medicine.

States Crack Down on AI Practicing Medicine Without a License

Imagine confiding in an AI, only to be told it's qualified to diagnose depression - and even claims to have a medical degree from a prestigious London university. Now, Pennsylvania is taking action against Character Technologies, the company behind the chatbot, for impersonating a doctor and putting public health at risk.

Analyst 207
Federal Trade Commission headquarters with a podium and subtle digital elements.

FTC to Crack Down on Deepfake Takedowns

Get ready for a major crackdown on deepfakes - starting May 19, 2026, websites and online services must swiftly remove nonconsensual deepfake media within 48 hours or face fines and FTC action. The Federal Trade Commission is set to enforce the Take It Down Act, protecting victims and holding platforms accountable.

Analyst 207
A hospital corridor with a laptop screen and medical equipment in the background.

HIPAA Security Rule Overhaul Nears, But Will Regulators Meet May Deadline?

As the HHS Office for Civil Rights prepares to unveil a major overhaul of the 23-year-old HIPAA Security Rule, concerns are mounting about meeting the May deadline. Director Paula Stannard urges healthcare organizations to consider the steep cost of inaction, emphasizing that the benefits of proposed modifications far outweigh the burdens.

Analyst 207
Cluttered office desks with papers, computer monitors, and digital tools convey a sense of operational strain.

Federal Agencies Face Mounting Legal Data Compliance Pressures

Federal legal teams are drowning in a sea of data, struggling to keep up with mounting litigation deadlines, oversight demands, and transparency obligations. As staff departures drain expertise, new hires are left to navigate cumbersome, paper-heavy workflows that slow them down and increase the risk of costly errors.

Analyst 207
General Motors vehicle drives down California road with smartphone screen displaying abstract data in foreground.

GM Faces $12.75M Penalty for Illicit Driver Data Sales

General Motors has been hit with a record $12.75 million penalty for selling California drivers' data without their consent, despite promising to protect their privacy. This landmark case marks a major victory for data protection, with California's Attorney General Rob Bonta leading the charge.

Analyst 207