• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Hanna Hewitt

UK Data Protection Regulator Fines Capita ~$18.8 Million Following a Ransomware Attack

October 20, 2025 By Hanna Hewitt and Kelly Hagedorn

On October 15, 2025, the UK’s Information Commissioner’s Office (ICO) fined Capita plc and Capita Pension Solutions Limited (collectively “Capita”) £14 million (~$18.8 million) for failing to implement adequate security measures to protect the personal data of over ~6.6 million individuals following a ransomware attack by Black Basta. The ICO’s penalty notice is available here. […]

Filed Under: Crisis & Data Breach Response, European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Cybersecurity Incidents, Enforcement Action, ICO, UK, UK Cybersecurity, UK GDPR

The EU Data Act Comes Into Force

September 18, 2025 By Hanna Hewitt and Kelly Hagedorn

The EU officially adopted the Data Act in January 2024, and it came into force on September 12, 2025. The Data Act builds on existing laws like the General Data Protection Regulation and the Data Governance Act. Now that the legislation is active, companies that fall under its scope must proactively review its provisions and […]

Filed Under: European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement Tagged With: Cloud Services, Connected Products, Data Act, EU, EU Regulation, Europe, Regulation

EU-wide Breach Notification Template On The Horizon

July 24, 2025 By Hanna Hewitt, Wim Nauwelaerts and Alice Portnoy

                  Following their recent meeting in Finland, the EU Data Protection Authorities acting through the European Data Protection Board (EDPB) announced their intention to release new tools and an EU-wide data breach notification template to help companies comply with the requirements of the EU General Data Protection […]

Filed Under: Crisis & Data Breach Response, European Privacy & Cybersecurity Tagged With: Cyber, Data breach, Data Breach Notifi, EDPB, European Union (EU), GDPR

Inside the SK Telecom Data Breach: What Happened and What Companies Can Learn

July 15, 2025 By Hanna Hewitt and Kim Peretti

In April 2025, SK Telecom—South Korea’s largest mobile carrier—formally notified regulators of a significant data breach that compromised sensitive SIM card data belonging to nearly 27 million users. Following an investigation, the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) concluded in July 2025 that SK Telecom was negligent in […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: Breach reporting, Cybersecurity, Enforcement, Enforcement Action, International, South Korea

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

July 2, 2025 By Hanna Hewitt and Kelly Hagedorn

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK users. The penalty followed a joint investigation with the Office of the Privacy Commissioner of Canada, highlighting  how regulators are […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, European Privacy & Cybersecurity Tagged With: Data breach, ICO, security, UK, UK Cybersecurity

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • Colorado Replaces Landmark AI Act—Creating New Trails for AI Rules and Private AI Litigation
  • Your AI Therapist May Need a Lawyer: Pennsylvania Brings Suit Against Chatbot Developer
  • UK Cyber Security Breaches Survey 2025/2026: Key Takeaways
  • The Era of AI-Driven Data Breaches Has Arrived
  • Dutch DPA Fines Taxi App €100M Over Unlawful Transfers of Personal Data to Russia, Despite Use of EU Standard Contractual Clauses
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.