• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Data Breach

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

July 2, 2025 By Hanna Hewitt and Kelly Hagedorn

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK users. The penalty followed a joint investigation with the Office of the Privacy Commissioner of Canada, highlighting  how regulators are […]

Filed Under: Cybersecurity, Data Breach, Security Breach, UK Tagged With: Data breach, ICO, security, UK, UK Cybersecurity

Suite Victory: Marriott Finally Checks Out of Court

June 9, 2025 By Donald Houser, Gavin Reinke and Nicole Weeks

On June 3, 2025, the U.S. Court of Appeals for the Fourth Circuit issued a pivotal ruling in longstanding litigation against Marriott International, Inc., arising out of a 2018 data breach involving its Starwood Preferred Guest Program.  In reversing the lower court’s grant of class certification, the Fourth Circuit determined that the customers’ contractual agreements […]

Filed Under: Data Breach, Privacy Litigation Tagged With: Class Action, Cybersecurity, Litigation

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

May 6, 2025 By Hanna Hewitt and Kelly Hagedorn

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found that DPP failed to implement appropriate technical and organisational measures, as required by Article 5(1)(f) and Article 32 UK GDPR. This is the […]

Filed Under: Cybersecurity, Data Breach, GDPR, UK Tagged With: Cybersecurity, Data breach, Regulatory Enforcement, UK GDPR

UK’s Data Protection Regulator fines a UK SaaS provider ~$4 million following a ransomware incident

April 4, 2025 By Hanna Hewitt and Kelly Hagedorn

On March 26, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined Advanced Computer Software Group Ltd (“Advanced”) £3.07 million (approximately $4 million). In 2022, Advanced suffered a ransomware incident that put the personal data of 79,404 people at risk. In its penalty notice, the ICO found that Advanced failed to implement […]

Filed Under: Cybersecurity, Data Breach, International, Ransomware Tagged With: Data breach, ICO, UK Cybersecurity, UK data protection, UK GDPR

New York Amends Data Breach Notification Law with Immediate Implications

January 6, 2025 By Kim Peretti and Alysa Austin

In late December 2024, the New York Governor signed two bills (S2659B and S2376B) amending the state’s data breach notification law (N.Y. Gen. Bus. Law § 899-aa), to expand the definition of reportable personal information and impose new covered entity reporting obligations in the event of a data breach. Effective immediately, companies will have 30 […]

Filed Under: Data Breach, Data Security, New York, New York, NYDFS, Privacy

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 34
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up

@ALSTONPRIVACY
Click here to follow us on Twitter

Secondary Sidebar

Categories

Recent Posts

  • UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack
  • NYDFS Issues Guidance on Heightened Cybersecurity and Sanctions Risk from Global Conflict
  • Are You Ready For The Department Of Justice’s Bulk Data Transfer Rule?
  • Trump Administration Releases Cyber Executive Order Revealing Renewed Strategy for U.S. Cybersecurity
  • New Artificial Intelligence Laws in Effect in Utah
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website. OkCookie policy