All CosmicBytez Labs articles tagged #GDPR, across news, security advisories, how-to guides, and projects.
Grindr will pay £26M to settle a UK High Court claim by 12,000 users alleging HIV status and PrEP data was shared with advertisers pre-2020.
CNIL fined Hôpital privé de la Loire €500K for GDPR failures — no MFA for external doctors and no real-time monitoring — after a teen attacker's breach.
A critical flaw in the WPLP Cookie Consent WordPress plugin lets unauthenticated attackers upload arbitrary files, opening a path to remote code execution.
The Dutch DPA fined Uber €825M for GDPR violations after its algorithm suspended driver accounts without meaningful human review or transparent explanation.
ZeroBytes hacker breached France's DGFiP via stolen credentials, exfiltrating tax data on 678,000 individuals including income and withholding tax rates.
Pokemon Center is notifying UK and Germany customers of a third-party breach at logistics provider CEVA Logistics that exposed personal and order data.
Polish authorities are investigating a breach at healthcare software firm MyDr that may have exposed personal data of up to 19 million patients.
Valve is notifying Steam hardware customers in Europe that hackers stole shipping and personal data after compromising its logistics partner CEVA Logistics between July 29 and August 1, 2026. No Steam account credentials or payment data were exposed, but the stolen PII creates a high-quality phishing dataset.
Spain's data protection agency AEPD has fined 23andMe approximately $3 million for cybersecurity failures that enabled the 2023 credential-stuffing breach...
German supermarket giant Lidl has notified customers in Germany, Belgium, and the Netherlands that personal data was stolen following a breach at one of...
Starting August 3, 2026, Google will use IP addresses from UK, EEA, and Switzerland users for ad measurement and personalization — a reversal of its...
This week's security roundup covers Google's controversial security team layoffs, Europol's dismantling of the AudiA6 ransomware crypto laundering...
The UK's Information Commissioner's Office has fined South Staffordshire Water Plc and its parent company £963,900 ($1.3 million) after a cyberattack...
Italy's data protection authority fined Poste Italiane €6.6 million and Postepay €5.9 million for illegally processing millions of users' personal data,...
Italy's data protection authority, the Garante, has fined Intesa Sanpaolo €36 million for serious shortcomings in personal data security, citing...
A Dutch court has ordered Elon Musk's xAI to stop generating nonconsensual nude images via Grok or face fines of €100,000 ($115,000) per day for...