California Consumer Privacy Act vs. GDPR: What Your Business Needs to Know

by Sarah Harvey / December 22, 2022

Data Privacy and Security in the US According to Pew Research Center, 64% of American adults have experienced data theft. Yahoo, eBay, Equifax, Target, Anthem, Home Depot – it has become habitual to worry about data breaches, identity theft, and other privacy concerns. With every new headline of a data breach, it seems like consumers are losing more control over what personal information is publicly available. At the same time,…

Horror Stories – Magecart’s Malicious Skimming Campaign

by Sarah Harvey / June 14, 2023

In September, British Airways announced that 380,000 transactions were compromised during a breach that took place between August 21 and September 5. Fortunately, no travel or passport details were compromised, but payment information was obtained through digital skimming of the airline’s website and app. The UK’s National Crime Agency, National Cybersecurity Centre, and Information Commissioner’s Office are investigating this incident. This breach is being linked to Magecart, a threat group that…

Horror Stories: Facebook Fallout

by Sarah Harvey / June 14, 2023

In late September, Facebook gave a new security update, outlining a breach that has impacted 50 million users – Facebook’s largest breach ever. The social network has been under intense scrutiny this year after the Cambridge Analytica scandal and has been redirecting their security team since the departure of their chief security officer, Alex Stamos. With the midterm elections coming up, this massive breach couldn’t have come at a worse…

What to Ask Your Vendors About GDPR Compliance

by Sarah Harvey / December 16, 2022

Are Your Vendors Data Processors? Vendor compliance management is a key starting point towards GDPR compliance. When your organization is deciding whether to use a vendor as part of your GDPR compliance efforts, you must follow GDPR vendor (processor) compliance management best practices. As a controller, you determine the purpose and means for processing personal data. You have authority and decision-making over personal data and take on the responsibilities of…

Who’s Enforcing GDPR?

by Sarah Harvey / December 16, 2022

The Information Commissioner's Office (ICO) enforces the GDPR as of May 25, 2018. There’s no doubt that GDPR has brought its fair share of challenges into the world of data privacy. GDPR was specifically designed to impact businesses across the globe, not just European Union Member States. Its ultimate goal, though, is to reduce regulatory differences in order to make data protection laws more consistent and make businesses more transparent.…