Data Protection News Update 17 August 2026

Cyber security image

United Kingdom

ICO reprimands ACRO after cyber security failings put sensitive data at risk

  • The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office after cyber security failings potentially exposed the personal information of up to 10,920 people.
  • The information potentially affected included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence and special category information.
  • The ICO found that a hacker gained unauthorised access to ACRO’s website and content management system between August 2022 and March 2023, allowing personal information to be staged for potential theft.
  • The investigation identified weaknesses in ACRO’s patch management and security monitoring, including unclear responsibility for critical security updates and failures to adequately investigate security alerts.

Live facial recognition expands to London Underground station

  • British Transport Police (BTP) has expanded its trial of Live Facial Recognition technology to London Underground stations, beginning at Victoria station.
  • The technology scans faces and compares them against a police watchlist, with any potential match reviewed by an officer before further action is taken.
  • The cameras will rotate between Underground and Network Rail stations until the trial ends in November, with BTP stating that images of people who do not match the authorised watchlist are deleted immediately and permanently.
  • Privacy campaigners have criticised the expansion over concerns about routine public surveillance and the risk of people being incorrectly identified by facial recognition systems.

United States

New Jersey court clarifies liability under law protecting officials’ personal data

  • New Jersey’s Supreme Court has ruled that individuals seeking damages under Daniel’s Law do not need to prove that an organisation intended to breach the law when failing to remove protected personal information.
  • The law allows judges, police officers and prosecutors to seek at least US$1,000 in statutory damages per violation where their personal information remains online more than 10 days after a valid removal request.
  • Billions of dollars in potential claims are at stake in litigation over compliance with the law, with one lead plaintiff having been assigned claims from more than 19,000 people.
  • The case will now return to the US Court of Appeals for the Third Circuit, where defendants are challenging aspects of the legislation on First Amendment grounds.

Uber Freight investigates alleged data theft by Helix hacking group

  • Uber Freight is investigating a data security incident after the Helix extortion group claimed to have gained access to the company’s systems and stolen nearly one million files.
  • Uber Freight confirmed that unauthorised access affected a portion of its systems and repositories, but said the incident had been contained and had not disrupted its business operations.
  • Helix claims to have stolen files from mailboxes, OneDrive accounts, the accounts receivable department and other repositories, although Uber Freight has not confirmed whether the leaked material is authentic.
  • Google Threat Intelligence Group has linked Helix to a wider cluster of cybercriminal activity known as UNC6671, whose operators commonly use voice phishing and other social engineering techniques to obtain access to organisations’ systems.

Europe

France confirms taxpayer information stolen in cyberattack

  • France’s Finance Ministry has confirmed that personal data relating to individual and professional taxpayers was stolen during a cyberattack on the country’s tax authority.
  • Investigations found that an attacker gained access to the General Directorate of Public Finances and was able to consult and extract taxpayer information.
  • The French Finance Ministry later confirmed that data relating to 678,000 users had been stolen, while investigations continued into the specific information affected.
  • Affected individuals will be contacted directly and informed of the data that may have been accessed or extracted, together with any precautionary measures they should take.

German privacy watchdog calls for EU-wide alternative to cookie banners

  • Germany’s federal data protection watchdog has called for cookie banners to be replaced with a new centralised solution across the EU.
  • One approach under consideration would allow users to set their cookie preferences once through their browser rather than responding to consent banners on individual websites.
  • The proposal forms part of discussions around the EU’s Digital Omnibus reforms and efforts to reduce repeated cookie consent requests.

International

Brazilian regulator orders Discord to suspend livestreaming over safeguards for young users

  • Brazil’s data protection authority, ANPD, has ordered Discord to suspend its “Go Live” livestreaming feature over concerns about inadequate protections for children and teenagers.
  • The regulator said Discord lacked real-time access to livestream content
  • for automated detection and relied on other systems and user reports that it considered inadequate.
  • Discord has been given three business days to demonstrate compliance and could face fines of up to 50 million reais per violation.
  • The platform can appeal the decision within 10 business days, with a further appeal to ANPD’s board also possible.

Cl0p claims data theft from nearly 50 companies worldwide

  • Cybercrime group Cl0p has claimed that it stole large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE.
  • Philips confirmed that it had contained an attempted compromise involving an internal enterprise server, while Shell and GE said they were investigating potential incidents.
  • Fiserv said its investigation had found no evidence that customer, banking, transaction or personal data had been compromised or that its operating environment had been affected.
  • Security researchers have linked the campaign to the exploitation of vulnerabilities in widely used enterprise software, although the scale and nature of the data claimed to have been stolen has not been independently verified.


For the latest updates on live facial recognition on the London Underground, the ICO’s ACRO reprimand and wider data protection developments, out Data Protection News Hub.

Share:

More Posts

Send Us A Message