PrivacySignal
Breach

Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs

EDPB · · EU · Data Breaches

Greece's data protection authority ruled against the Ministry of Social Cohesion and Family Affairs following a large-scale personal data breach, finding violations across multiple GDPR articles including security, breach notification, and data protection by design. The ministry's processor, E.E.T.A.A. S.A., was also implicated in the decision, which resulted in fines and a compliance order.

Why this matters: When a government ministry responsible for family and social welfare suffers a data breach, the people exposed are often those least equipped to deal with the fallout. These are not just names and emails. They are likely benefit recipients, vulnerable families, and people who had no choice but to share personal details with the state. The Greek DPA found failures at multiple levels, from security practices to breach notification. That means people may not have been told their data was exposed. Governments owe citizens more than a fine after the fact.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Breach
CyberScoop · · US Federal

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Zohar Pinhasi allegedly deceived ransomware recovery clients into a payment scheme disguised as a specialized service that helped victims avoid paying cybercriminals. The post Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

Laboratory Services Cooperative Agrees to Pay $6.1 Million to Settle Data Breach Litigation

Laboratory Services Cooperative, a Seattle-based nonprofit lab serving Planned Parenthood affiliates, has agreed to pay $6.1 million to settle litigation stemming from a data breach. The organization provides clinical diagnostic and testing services, meaning the exposed data likely included sensitive health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

OAuth grants pile up faster than you can review them. Here's how to keep up.

OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →