The Gibraltar GDPR takes effect
Following the end of the Brexit transition period, Gibraltar’s own GDPR-equivalent regime takes effect.
Insights for the EU, the EEA, and the rest of Europe.
Following the end of the Brexit transition period, Gibraltar’s own GDPR-equivalent regime takes effect.
Vastaamo, a Finnish psychotherapy provider, reveals a breach of patient records, and tens of thousands of patients are targeted with extortion.
A ransomware attack forces Düsseldorf University Hospital to turn away emergency patients, prompting a police investigation.
The CJEU has invalidated the EU–US Privacy Shield and set new expectations for Standard Contractual Clauses.
Reports reveal the CIA and West German intelligence secretly owned Swiss firm Crypto AG and rigged its encryption devices for decades.
Germany’s BSI publishes C5:2020, updating its Cloud Computing Compliance Criteria Catalogue for cloud security attestations.
Fraudsters reportedly used AI to mimic a chief executive’s voice and persuade a UK energy firm to wire €220,000 to a Hungarian account.
The EU Cybersecurity Act gives ENISA a permanent mandate and creates an EU-wide cybersecurity certification framework.
Norwegian aluminium producer Norsk Hydro is hit by LockerGoga ransomware, switching plants to manual operation and refusing to pay.
France’s CNIL fines Google €50 million, then the largest GDPR penalty, for unclear information and invalid consent for ad personalisation.
Spain’s Organic Law 3/2018 takes effect, supplementing the GDPR and introducing new digital rights.
The Council of Europe opens the protocol modernising Convention 108 for signature, with the UK among the first signatories.