• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Hanna Hewitt

Avatar photo

About Hanna Hewitt

Hanna helps clients navigate cybersecurity and data protection matters in the U.K., European Union, and beyond. She assists clients throughout the lifecycle of a cyber incident: helping with immediate response, working with forensic providers to eradicate and contain cyber threats, and advising clients on their regulatory and contractual obligations. At only two years qualified, she has managed over 20 large international incidents, often acting as the main point of contact for clients.

[Read Bio]

The EU Data Act Comes Into Force

September 18, 2025 By Hanna Hewitt and Kelly Hagedorn

The EU officially adopted the Data Act in January 2024, and it came into force on September 12, 2025. The Data Act builds on existing laws like the General Data Protection Regulation and the Data Governance Act. Now that the legislation is active, companies that fall under its scope must proactively review its provisions and […]

Filed Under: Data Act, EU, Legislation Tagged With: Cloud Services, Connected Products, Data Act, EU, EU Regulation, Europe, Regulation

EU-wide Breach Notification Template On The Horizon

July 24, 2025 By Hanna Hewitt, Wim Nauwelaerts and Alice Portnoy

                  Following their recent meeting in Finland, the EU Data Protection Authorities acting through the European Data Protection Board (EDPB) announced their intention to release new tools and an EU-wide data breach notification template to help companies comply with the requirements of the EU General Data Protection […]

Filed Under: Data Breach, EDPB, EU, GDPR Tagged With: Cyber, Data breach, Data Breach Notifi, EDPB, European Union (EU), GDPR

Inside the SK Telecom Data Breach: What Happened and What Companies Can Learn

July 15, 2025 By Hanna Hewitt and Kim Peretti

In April 2025, SK Telecom—South Korea’s largest mobile carrier—formally notified regulators of a significant data breach that compromised sensitive SIM card data belonging to nearly 27 million users. Following an investigation, the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) concluded in July 2025 that SK Telecom was negligent in […]

Filed Under: Cybersecurity, Data Breach, Enforcement, South Korea Tagged With: Breach reporting, Cybersecurity, Enforcement, Enforcement Action, International, South Korea

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

July 2, 2025 By Hanna Hewitt and Kelly Hagedorn

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK users. The penalty followed a joint investigation with the Office of the Privacy Commissioner of Canada, highlighting  how regulators are […]

Filed Under: Cybersecurity, Data Breach, Security Breach, UK Tagged With: Data breach, ICO, security, UK, UK Cybersecurity

European Vulnerability Database Published by the European Union Agency for Cybersecurity

June 2, 2025 By Hanna Hewitt and Kelly Hagedorn

The European Union Agency for Cybersecurity (ENISA) has launched the European Vulnerability Database (EUVD), a tool designed to enhance digital security across the EU. The EUVD is available here. ENISA created the EUVD under the Network and Information Securities 2 Directive (NIS2). It is a centralised database containing information on cybersecurity vulnerabilities affecting information technology […]

Filed Under: Data Security, EU, NIS 2, Uncategorized Tagged With: Cybersecurity, European Union (EU), Vulnerability

  • Page 1
  • Page 2
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • FTC Cracks Down on Messaging App Operator on Child Data Exploitation
  • Unlocking the MIND Act: The Senate To Take on the Challenge of Neurotechnology
  • California Finalizes New and Amended CCPA Regulations
  • The EU Data Act Comes Into Force
  • Chilean Regulator Launches Public Consultation on New Cybersecurity Law
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.