home.social

#gdprcompliance — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #gdprcompliance, aggregated by home.social.

fetched live
  1. BVDW's email marketing guide tackles AI agents and a 376-billion daily inbox: Germany's digital economy association BVDW published a 24-page email marketing guide on March 18, 2026, covering AI agents, KPIs, accessibility, and GDPR compliance. ppc.land/bvdws-email-marketing #EmailMarketing #AIAgents #DigitalEconomy #GDPRCompliance #KPI

  2. BVDW's email marketing guide tackles AI agents and a 376-billion daily inbox: Germany's digital economy association BVDW published a 24-page email marketing guide on March 18, 2026, covering AI agents, KPIs, accessibility, and GDPR compliance. ppc.land/bvdws-email-marketing #EmailMarketing #AIAgents #DigitalEconomy #GDPRCompliance #KPI

  3. ISO 27701 Certification for Data Privacy & Protection

    globalisocertificates.com/iso-

    Strengthen your data privacy framework with ISO 27701 certification. Build trust, ensure compliance, and protect sensitive information effectively.

  4. Third-party breach, 38M impacted, European e-commerce sector.
    ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
    Authorities notified: CNIL, ANSSI.
    Passwords not reportedly accessed.
    Subcontractor access revoked.

    Key risk vectors:
    – SaaS support platforms
    – Vendor access governance
    – Over-retention of ticketing data
    – Centralized customer communication logs
    – Supply chain attack surface expansion

    This case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.

    How mature is your third-party risk telemetry?
    Engage below.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for high-signal infosec reporting.

    Repost to amplify awareness across the security community.

    #Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC

  5. Third-party breach, 38M impacted, European e-commerce sector.
    ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
    Authorities notified: CNIL, ANSSI.
    Passwords not reportedly accessed.
    Subcontractor access revoked.

    Key risk vectors:
    – SaaS support platforms
    – Vendor access governance
    – Over-retention of ticketing data
    – Centralized customer communication logs
    – Supply chain attack surface expansion

    This case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.

    How mature is your third-party risk telemetry?
    Engage below.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for high-signal infosec reporting.

    Repost to amplify awareness across the security community.

    #Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC

  6. Third-party breach, 38M impacted, European e-commerce sector.
    ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
    Authorities notified: CNIL, ANSSI.
    Passwords not reportedly accessed.
    Subcontractor access revoked.

    Key risk vectors:
    – SaaS support platforms
    – Vendor access governance
    – Over-retention of ticketing data
    – Centralized customer communication logs
    – Supply chain attack surface expansion

    This case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.

    How mature is your third-party risk telemetry?
    Engage below.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for high-signal infosec reporting.

    Repost to amplify awareness across the security community.

    #Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC

  7. Sector alert: European football club targeted.

    Olympique de Marseille confirmed an attempted cyberattack following alleged data leak claims involving:
    • ~400,000 supporter records
    • 2,050+ Drupal CMS accounts
    • E-commerce and membership-related data
    No confirmed compromise of banking credentials, investigation ongoing, incident reported to CNIL.
    Attack surface observations:
    – CMS exposure risk
    – High-value fan PII aggregation
    – Merchandising platforms as entry vectors
    – Sector-wide vulnerability patterns (preceded by FFF breach)
    Sports organizations increasingly mirror enterprise-scale digital infrastructures - yet often lack comparable security maturity.

    What baseline controls should leagues enforce - MFA mandates, zero trust architecture, CMS hardening standards?

    Source: bleepingcomputer.com/news/secu

    Engage in the comments.
    Follow TechNadu for high-signal infosec coverage.

    Repost to amplify sector awareness.

    #Infosec #DrupalSecurity #DataBreach #SportsSecurity #ThreatIntelligence #CyberRisk #GDPRCompliance #SecurityOperations #DigitalForensics #CyberDefense

  8. Sector alert: European football club targeted.

    Olympique de Marseille confirmed an attempted cyberattack following alleged data leak claims involving:
    • ~400,000 supporter records
    • 2,050+ Drupal CMS accounts
    • E-commerce and membership-related data
    No confirmed compromise of banking credentials, investigation ongoing, incident reported to CNIL.
    Attack surface observations:
    – CMS exposure risk
    – High-value fan PII aggregation
    – Merchandising platforms as entry vectors
    – Sector-wide vulnerability patterns (preceded by FFF breach)
    Sports organizations increasingly mirror enterprise-scale digital infrastructures - yet often lack comparable security maturity.

    What baseline controls should leagues enforce - MFA mandates, zero trust architecture, CMS hardening standards?

    Source: bleepingcomputer.com/news/secu

    Engage in the comments.
    Follow TechNadu for high-signal infosec coverage.

    Repost to amplify sector awareness.

    #Infosec #DrupalSecurity #DataBreach #SportsSecurity #ThreatIntelligence #CyberRisk #GDPRCompliance #SecurityOperations #DigitalForensics #CyberDefense

  9. Sector alert: European football club targeted.

    Olympique de Marseille confirmed an attempted cyberattack following alleged data leak claims involving:
    • ~400,000 supporter records
    • 2,050+ Drupal CMS accounts
    • E-commerce and membership-related data
    No confirmed compromise of banking credentials, investigation ongoing, incident reported to CNIL.
    Attack surface observations:
    – CMS exposure risk
    – High-value fan PII aggregation
    – Merchandising platforms as entry vectors
    – Sector-wide vulnerability patterns (preceded by FFF breach)
    Sports organizations increasingly mirror enterprise-scale digital infrastructures - yet often lack comparable security maturity.

    What baseline controls should leagues enforce - MFA mandates, zero trust architecture, CMS hardening standards?

    Source: bleepingcomputer.com/news/secu

    Engage in the comments.
    Follow TechNadu for high-signal infosec coverage.

    Repost to amplify sector awareness.

    #Infosec #DrupalSecurity #DataBreach #SportsSecurity #ThreatIntelligence #CyberRisk #GDPRCompliance #SecurityOperations #DigitalForensics #CyberDefense

  10. Complaints filed in Europe allege cross-app data tracking involving sensitive personal data categories protected under GDPR, raising questions about consent, transparency, and third-party data brokers.

    While no regulatory findings have been issued yet, the case highlights ongoing challenges in enforcing privacy-by-design principles across complex app ecosystems.

    How should organizations better operationalize GDPR transparency and data access rights?

    Share your insights and follow TechNadu for responsible InfoSec and privacy reporting.

    #InfoSec #PrivacyEngineering #GDPRCompliance #DataGovernance #AdTech #UserConsent #TechNadu

  11. Complaints filed in Europe allege cross-app data tracking involving sensitive personal data categories protected under GDPR, raising questions about consent, transparency, and third-party data brokers.

    While no regulatory findings have been issued yet, the case highlights ongoing challenges in enforcing privacy-by-design principles across complex app ecosystems.

    How should organizations better operationalize GDPR transparency and data access rights?

    Share your insights and follow TechNadu for responsible InfoSec and privacy reporting.

    #InfoSec #PrivacyEngineering #GDPRCompliance #DataGovernance #AdTech #UserConsent #TechNadu

  12. Complaints filed in Europe allege cross-app data tracking involving sensitive personal data categories protected under GDPR, raising questions about consent, transparency, and third-party data brokers.

    While no regulatory findings have been issued yet, the case highlights ongoing challenges in enforcing privacy-by-design principles across complex app ecosystems.

    How should organizations better operationalize GDPR transparency and data access rights?

    Share your insights and follow TechNadu for responsible InfoSec and privacy reporting.

    #InfoSec #PrivacyEngineering #GDPRCompliance #DataGovernance #AdTech #UserConsent #TechNadu

  13. youtu.be/As4z5i1YwdM

    🎙️ SOMETHING LEGENDARY IS COMING 🎙️

    I'm absolutely BUZZING to announce a new hashtag#podcast that I believe is not just needed—it's going to be very special.

    Yes, we may look a bit vintage (just like good radio should), but I promise you the topics will be very present, modern, and futuristic. You can bet on this.

    📡 ITSPmagazine Europe: The Transatlantic Broadcast 📡
    Where #cybersecurity #technology, and #society meet — across borders and perspectives.

    Your Hosts:
    🎙️ Marco Ciappelli (Florence/Los Angeles) - Political Science, Sociology of Communication
    🎙️ Sean Martin, CISSP (New York City) - Cybersecurity Analysis & Editorial Leadership
    🎙️ Rob Black (London) - UK Cyber Citizen 2024, International Relations

    Our Pilot Episode:
    Broadcasting from Los Angeles and UK, Rob and I get the waves up in the air!

    The Transatlantic Broadcast is the flagship podcast of ITSPmagazine Europe — a new editorial initiative dedicated to cybersecurity, technology, and society through a distinctly European lens.

    Recorded between Florence, London, Los Angeles, NYC and beyond — the show explores the stories, policies, and people shaping digital life across Europe. With our rotating host format and guests from academia, public policy, private sector, and civil society, we highlight European perspectives while drawing occasional comparisons to developments in the U.S. and beyond.

    What we're exploring in this pilot:
    The Birth of a Transatlantic Conversation
    European Approaches to Digital Transformation
    The Sociological Lens We're Missing
    Building Bridges, Not Walls
    Cross-Border Collaboration for a Global Digital Future

    This isn't just another hashtag#tech podcast. We're creating space for European voices to explain their approaches in their own terms—not as responses to American innovation, but as distinct philosophical and practical approaches to technology's role in democratic society.

    Enjoy the teaser below and watch the full pilot episode

    Here youtu.be/As4z5i1YwdM

    Who's ready to join this transatlantic conversation?

    #EuropeanCybersecurity #TransatlanticTechnology #DigitalSovereignty #EUTechPolicy #EuropeanDigitalRights #GDPRCompliance #EuropeanInnovation #CybersecurityWorkforce #TechRegulation #DigitalTransformation #EuropeanVsAmericanCybersecurity #TransatlanticTechCooperation #UKCyberCitizen2024 #EuropeanAIRegulation #CybersecurityLeadership #infosec #infosecurity

  14. youtu.be/As4z5i1YwdM

    🎙️ SOMETHING LEGENDARY IS COMING 🎙️

    I'm absolutely BUZZING to announce a new hashtag#podcast that I believe is not just needed—it's going to be very special.

    Yes, we may look a bit vintage (just like good radio should), but I promise you the topics will be very present, modern, and futuristic. You can bet on this.

    📡 ITSPmagazine Europe: The Transatlantic Broadcast 📡
    Where #cybersecurity #technology, and #society meet — across borders and perspectives.

    Your Hosts:
    🎙️ Marco Ciappelli (Florence/Los Angeles) - Political Science, Sociology of Communication
    🎙️ Sean Martin, CISSP (New York City) - Cybersecurity Analysis & Editorial Leadership
    🎙️ Rob Black (London) - UK Cyber Citizen 2024, International Relations

    Our Pilot Episode:
    Broadcasting from Los Angeles and UK, Rob and I get the waves up in the air!

    The Transatlantic Broadcast is the flagship podcast of ITSPmagazine Europe — a new editorial initiative dedicated to cybersecurity, technology, and society through a distinctly European lens.

    Recorded between Florence, London, Los Angeles, NYC and beyond — the show explores the stories, policies, and people shaping digital life across Europe. With our rotating host format and guests from academia, public policy, private sector, and civil society, we highlight European perspectives while drawing occasional comparisons to developments in the U.S. and beyond.

    What we're exploring in this pilot:
    The Birth of a Transatlantic Conversation
    European Approaches to Digital Transformation
    The Sociological Lens We're Missing
    Building Bridges, Not Walls
    Cross-Border Collaboration for a Global Digital Future

    This isn't just another hashtag#tech podcast. We're creating space for European voices to explain their approaches in their own terms—not as responses to American innovation, but as distinct philosophical and practical approaches to technology's role in democratic society.

    Enjoy the teaser below and watch the full pilot episode

    Here youtu.be/As4z5i1YwdM

    Who's ready to join this transatlantic conversation?

    #EuropeanCybersecurity #TransatlanticTechnology #DigitalSovereignty #EUTechPolicy #EuropeanDigitalRights #GDPRCompliance #EuropeanInnovation #CybersecurityWorkforce #TechRegulation #DigitalTransformation #EuropeanVsAmericanCybersecurity #TransatlanticTechCooperation #UKCyberCitizen2024 #EuropeanAIRegulation #CybersecurityLeadership #infosec #infosecurity

  15. youtu.be/As4z5i1YwdM

    🎙️ SOMETHING LEGENDARY IS COMING 🎙️

    I'm absolutely BUZZING to announce a new hashtag#podcast that I believe is not just needed—it's going to be very special.

    Yes, we may look a bit vintage (just like good radio should), but I promise you the topics will be very present, modern, and futuristic. You can bet on this.

    📡 ITSPmagazine Europe: The Transatlantic Broadcast 📡
    Where #cybersecurity #technology, and #society meet — across borders and perspectives.

    Your Hosts:
    🎙️ Marco Ciappelli (Florence/Los Angeles) - Political Science, Sociology of Communication
    🎙️ Sean Martin, CISSP (New York City) - Cybersecurity Analysis & Editorial Leadership
    🎙️ Rob Black (London) - UK Cyber Citizen 2024, International Relations

    Our Pilot Episode:
    Broadcasting from Los Angeles and UK, Rob and I get the waves up in the air!

    The Transatlantic Broadcast is the flagship podcast of ITSPmagazine Europe — a new editorial initiative dedicated to cybersecurity, technology, and society through a distinctly European lens.

    Recorded between Florence, London, Los Angeles, NYC and beyond — the show explores the stories, policies, and people shaping digital life across Europe. With our rotating host format and guests from academia, public policy, private sector, and civil society, we highlight European perspectives while drawing occasional comparisons to developments in the U.S. and beyond.

    What we're exploring in this pilot:
    The Birth of a Transatlantic Conversation
    European Approaches to Digital Transformation
    The Sociological Lens We're Missing
    Building Bridges, Not Walls
    Cross-Border Collaboration for a Global Digital Future

    This isn't just another hashtag#tech podcast. We're creating space for European voices to explain their approaches in their own terms—not as responses to American innovation, but as distinct philosophical and practical approaches to technology's role in democratic society.

    Enjoy the teaser below and watch the full pilot episode

    Here youtu.be/As4z5i1YwdM

    Who's ready to join this transatlantic conversation?

    #EuropeanCybersecurity #TransatlanticTechnology #DigitalSovereignty #EUTechPolicy #EuropeanDigitalRights #GDPRCompliance #EuropeanInnovation #CybersecurityWorkforce #TechRegulation #DigitalTransformation #EuropeanVsAmericanCybersecurity #TransatlanticTechCooperation #UKCyberCitizen2024 #EuropeanAIRegulation #CybersecurityLeadership #infosec #infosecurity

  16. 🚨 GDPR Reminder: A DPO must be independent—not the CEO, not the legal rep, not anyone making decisions on data.

    🇮🇹 Italy’s Garante voided a company’s DPO appointment for this exact mistake.
    💸 €70K fine.
    📜 Article 38(3) is crystal clear.

    Don’t just tick a box—get a truly independent DPO.
    External DPOs = objectivity + compliance + trust.

    Read @Tsaaro’s full breakdown:
    🔗 tsaaro.com/newsletter/why-dpo-
    #DPO #GDPRCompliance #PrivacyMatters #DataGovernance #DigitalRights

  17. Password protection is Meta-critical: €91M fine underscores that plain storage of passwords is a plain mistake, even when errors remain internal. #DataPrivacy #GDPRCompliance
    reuters.com/technology/eu-priv

  18. Is there research, whether placing an "accept all" button left or right of "reject all" button in a cookie consent dialogue, leads to fewer or more clicks on "accept all"?

    How about buttons on top of each other?

    Is tab index relevant? Is this an #accessibility topic at all?

    //cc @MoritzGiessmann

    #webdev #gdpr #gdprcompliance #cookiebanner

  19. Is there research, whether placing an "accept all" button left or right of "reject all" button in a cookie consent dialogue, leads to fewer or more clicks on "accept all"?

    How about buttons on top of each other?

    Is tab index relevant? Is this an #accessibility topic at all?

    //cc @MoritzGiessmann

    #webdev #gdpr #gdprcompliance #cookiebanner

  20. Is there research, whether placing an "accept all" button left or right of "reject all" button in a cookie consent dialogue, leads to fewer or more clicks on "accept all"?

    How about buttons on top of each other?

    Is tab index relevant? Is this an #accessibility topic at all?

    //cc @MoritzGiessmann

    #webdev #gdpr #gdprcompliance #cookiebanner

  21. @tdp_org Why are third-party analytics cookies considered "strictly necessary" on the BBC website?

    bbc.com/usingthebbc/cookies/st

    Strict necessity is defined as those required for the site's basic functionality to work, such as remembering which shopping cart is yours, or saving your cookie preferences so you are not asked on every page (which could be seen as coercing the user to accept more cookies).

    @noybeu, what do you think?

    #gdpr #gdprcompliance #UKGDPR #cookies

  22. @tdp_org Why are third-party analytics cookies considered "strictly necessary" on the BBC website?

    bbc.com/usingthebbc/cookies/st

    Strict necessity is defined as those required for the site's basic functionality to work, such as remembering which shopping cart is yours, or saving your cookie preferences so you are not asked on every page (which could be seen as coercing the user to accept more cookies).

    @noybeu, what do you think?

    #gdpr #gdprcompliance #UKGDPR #cookies

  23. @tdp_org Why are third-party analytics cookies considered "strictly necessary" on the BBC website?

    bbc.com/usingthebbc/cookies/st

    Strict necessity is defined as those required for the site's basic functionality to work, such as remembering which shopping cart is yours, or saving your cookie preferences so you are not asked on every page (which could be seen as coercing the user to accept more cookies).

    @noybeu, what do you think?

    #gdpr #gdprcompliance #UKGDPR #cookies

  24. @noybeu This is a very broken national law that has not kept up with time. This isn't used just by journalists, it's also used to publish all sorts of private information about individuals by "information broker sites"; things like income, possible crime information, property ownership, etc.

    Some (if not most) of these brokers keep their data on US cloud services like Amazon, Microsoft, etc.

    This is being debated in Sweden, but, well, you know ... 😑

    #gdpr #gdprcompliance #dataprotection

  25. @noybeu This is a very broken national law that has not kept up with time. This isn't used just by journalists, it's also used to publish all sorts of private information about individuals by "information broker sites"; things like income, possible crime information, property ownership, etc.

    Some (if not most) of these brokers keep their data on US cloud services like Amazon, Microsoft, etc.

    This is being debated in Sweden, but, well, you know ... 😑

    #gdpr #gdprcompliance #dataprotection

  26. @noybeu This is a very broken national law that has not kept up with time. This isn't used just by journalists, it's also used to publish all sorts of private information about individuals by "information broker sites"; things like income, possible crime information, property ownership, etc.

    Some (if not most) of these brokers keep their data on US cloud services like Amazon, Microsoft, etc.

    This is being debated in Sweden, but, well, you know ... 😑

    #gdpr #gdprcompliance #dataprotection