home.social

#gdprcompliance — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #gdprcompliance, aggregated by home.social.

fetched live
  1. BVDW's email marketing guide tackles AI agents and a 376-billion daily inbox: Germany's digital economy association BVDW published a 24-page email marketing guide on March 18, 2026, covering AI agents, KPIs, accessibility, and GDPR compliance. ppc.land/bvdws-email-marketing #EmailMarketing #AIAgents #DigitalEconomy #GDPRCompliance #KPI

  2. Third-party breach, 38M impacted, European e-commerce sector.
    ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
    Authorities notified: CNIL, ANSSI.
    Passwords not reportedly accessed.
    Subcontractor access revoked.

    Key risk vectors:
    – SaaS support platforms
    – Vendor access governance
    – Over-retention of ticketing data
    – Centralized customer communication logs
    – Supply chain attack surface expansion

    This case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.

    How mature is your third-party risk telemetry?
    Engage below.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for high-signal infosec reporting.

    Repost to amplify awareness across the security community.

    #Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC

  3. Third-party breach, 38M impacted, European e-commerce sector.
    ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
    Authorities notified: CNIL, ANSSI.
    Passwords not reportedly accessed.
    Subcontractor access revoked.

    Key risk vectors:
    – SaaS support platforms
    – Vendor access governance
    – Over-retention of ticketing data
    – Centralized customer communication logs
    – Supply chain attack surface expansion

    This case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.

    How mature is your third-party risk telemetry?
    Engage below.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for high-signal infosec reporting.

    Repost to amplify awareness across the security community.

    #Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC

  4. Sector alert: European football club targeted.

    Olympique de Marseille confirmed an attempted cyberattack following alleged data leak claims involving:
    • ~400,000 supporter records
    • 2,050+ Drupal CMS accounts
    • E-commerce and membership-related data
    No confirmed compromise of banking credentials, investigation ongoing, incident reported to CNIL.
    Attack surface observations:
    – CMS exposure risk
    – High-value fan PII aggregation
    – Merchandising platforms as entry vectors
    – Sector-wide vulnerability patterns (preceded by FFF breach)
    Sports organizations increasingly mirror enterprise-scale digital infrastructures - yet often lack comparable security maturity.

    What baseline controls should leagues enforce - MFA mandates, zero trust architecture, CMS hardening standards?

    Source: bleepingcomputer.com/news/secu

    Engage in the comments.
    Follow TechNadu for high-signal infosec coverage.

    Repost to amplify sector awareness.

    #Infosec #DrupalSecurity #DataBreach #SportsSecurity #ThreatIntelligence #CyberRisk #GDPRCompliance #SecurityOperations #DigitalForensics #CyberDefense

  5. Sector alert: European football club targeted.

    Olympique de Marseille confirmed an attempted cyberattack following alleged data leak claims involving:
    • ~400,000 supporter records
    • 2,050+ Drupal CMS accounts
    • E-commerce and membership-related data
    No confirmed compromise of banking credentials, investigation ongoing, incident reported to CNIL.
    Attack surface observations:
    – CMS exposure risk
    – High-value fan PII aggregation
    – Merchandising platforms as entry vectors
    – Sector-wide vulnerability patterns (preceded by FFF breach)
    Sports organizations increasingly mirror enterprise-scale digital infrastructures - yet often lack comparable security maturity.

    What baseline controls should leagues enforce - MFA mandates, zero trust architecture, CMS hardening standards?

    Source: bleepingcomputer.com/news/secu

    Engage in the comments.
    Follow TechNadu for high-signal infosec coverage.

    Repost to amplify sector awareness.

    #Infosec #DrupalSecurity #DataBreach #SportsSecurity #ThreatIntelligence #CyberRisk #GDPRCompliance #SecurityOperations #DigitalForensics #CyberDefense

  6. Complaints filed in Europe allege cross-app data tracking involving sensitive personal data categories protected under GDPR, raising questions about consent, transparency, and third-party data brokers.

    While no regulatory findings have been issued yet, the case highlights ongoing challenges in enforcing privacy-by-design principles across complex app ecosystems.

    How should organizations better operationalize GDPR transparency and data access rights?

    Share your insights and follow TechNadu for responsible InfoSec and privacy reporting.

    #InfoSec #PrivacyEngineering #GDPRCompliance #DataGovernance #AdTech #UserConsent #TechNadu

  7. Complaints filed in Europe allege cross-app data tracking involving sensitive personal data categories protected under GDPR, raising questions about consent, transparency, and third-party data brokers.

    While no regulatory findings have been issued yet, the case highlights ongoing challenges in enforcing privacy-by-design principles across complex app ecosystems.

    How should organizations better operationalize GDPR transparency and data access rights?

    Share your insights and follow TechNadu for responsible InfoSec and privacy reporting.

    #InfoSec #PrivacyEngineering #GDPRCompliance #DataGovernance #AdTech #UserConsent #TechNadu

  8. youtu.be/As4z5i1YwdM

    🎙️ SOMETHING LEGENDARY IS COMING 🎙️

    I'm absolutely BUZZING to announce a new hashtag#podcast that I believe is not just needed—it's going to be very special.

    Yes, we may look a bit vintage (just like good radio should), but I promise you the topics will be very present, modern, and futuristic. You can bet on this.

    📡 ITSPmagazine Europe: The Transatlantic Broadcast 📡
    Where #cybersecurity #technology, and #society meet — across borders and perspectives.

    Your Hosts:
    🎙️ Marco Ciappelli (Florence/Los Angeles) - Political Science, Sociology of Communication
    🎙️ Sean Martin, CISSP (New York City) - Cybersecurity Analysis & Editorial Leadership
    🎙️ Rob Black (London) - UK Cyber Citizen 2024, International Relations

    Our Pilot Episode:
    Broadcasting from Los Angeles and UK, Rob and I get the waves up in the air!

    The Transatlantic Broadcast is the flagship podcast of ITSPmagazine Europe — a new editorial initiative dedicated to cybersecurity, technology, and society through a distinctly European lens.

    Recorded between Florence, London, Los Angeles, NYC and beyond — the show explores the stories, policies, and people shaping digital life across Europe. With our rotating host format and guests from academia, public policy, private sector, and civil society, we highlight European perspectives while drawing occasional comparisons to developments in the U.S. and beyond.

    What we're exploring in this pilot:
    The Birth of a Transatlantic Conversation
    European Approaches to Digital Transformation
    The Sociological Lens We're Missing
    Building Bridges, Not Walls
    Cross-Border Collaboration for a Global Digital Future

    This isn't just another hashtag#tech podcast. We're creating space for European voices to explain their approaches in their own terms—not as responses to American innovation, but as distinct philosophical and practical approaches to technology's role in democratic society.

    Enjoy the teaser below and watch the full pilot episode

    Here youtu.be/As4z5i1YwdM

    Who's ready to join this transatlantic conversation?

    #EuropeanCybersecurity #TransatlanticTechnology #DigitalSovereignty #EUTechPolicy #EuropeanDigitalRights #GDPRCompliance #EuropeanInnovation #CybersecurityWorkforce #TechRegulation #DigitalTransformation #EuropeanVsAmericanCybersecurity #TransatlanticTechCooperation #UKCyberCitizen2024 #EuropeanAIRegulation #CybersecurityLeadership #infosec #infosecurity

  9. youtu.be/As4z5i1YwdM

    🎙️ SOMETHING LEGENDARY IS COMING 🎙️

    I'm absolutely BUZZING to announce a new hashtag#podcast that I believe is not just needed—it's going to be very special.

    Yes, we may look a bit vintage (just like good radio should), but I promise you the topics will be very present, modern, and futuristic. You can bet on this.

    📡 ITSPmagazine Europe: The Transatlantic Broadcast 📡
    Where #cybersecurity #technology, and #society meet — across borders and perspectives.

    Your Hosts:
    🎙️ Marco Ciappelli (Florence/Los Angeles) - Political Science, Sociology of Communication
    🎙️ Sean Martin, CISSP (New York City) - Cybersecurity Analysis & Editorial Leadership
    🎙️ Rob Black (London) - UK Cyber Citizen 2024, International Relations

    Our Pilot Episode:
    Broadcasting from Los Angeles and UK, Rob and I get the waves up in the air!

    The Transatlantic Broadcast is the flagship podcast of ITSPmagazine Europe — a new editorial initiative dedicated to cybersecurity, technology, and society through a distinctly European lens.

    Recorded between Florence, London, Los Angeles, NYC and beyond — the show explores the stories, policies, and people shaping digital life across Europe. With our rotating host format and guests from academia, public policy, private sector, and civil society, we highlight European perspectives while drawing occasional comparisons to developments in the U.S. and beyond.

    What we're exploring in this pilot:
    The Birth of a Transatlantic Conversation
    European Approaches to Digital Transformation
    The Sociological Lens We're Missing
    Building Bridges, Not Walls
    Cross-Border Collaboration for a Global Digital Future

    This isn't just another hashtag#tech podcast. We're creating space for European voices to explain their approaches in their own terms—not as responses to American innovation, but as distinct philosophical and practical approaches to technology's role in democratic society.

    Enjoy the teaser below and watch the full pilot episode

    Here youtu.be/As4z5i1YwdM

    Who's ready to join this transatlantic conversation?

    #EuropeanCybersecurity #TransatlanticTechnology #DigitalSovereignty #EUTechPolicy #EuropeanDigitalRights #GDPRCompliance #EuropeanInnovation #CybersecurityWorkforce #TechRegulation #DigitalTransformation #EuropeanVsAmericanCybersecurity #TransatlanticTechCooperation #UKCyberCitizen2024 #EuropeanAIRegulation #CybersecurityLeadership #infosec #infosecurity

  10. Is there research, whether placing an "accept all" button left or right of "reject all" button in a cookie consent dialogue, leads to fewer or more clicks on "accept all"?

    How about buttons on top of each other?

    Is tab index relevant? Is this an #accessibility topic at all?

    //cc @MoritzGiessmann

    #webdev #gdpr #gdprcompliance #cookiebanner

  11. Is there research, whether placing an "accept all" button left or right of "reject all" button in a cookie consent dialogue, leads to fewer or more clicks on "accept all"?

    How about buttons on top of each other?

    Is tab index relevant? Is this an #accessibility topic at all?

    //cc @MoritzGiessmann

    #webdev #gdpr #gdprcompliance #cookiebanner

  12. @tdp_org Why are third-party analytics cookies considered "strictly necessary" on the BBC website?

    bbc.com/usingthebbc/cookies/st

    Strict necessity is defined as those required for the site's basic functionality to work, such as remembering which shopping cart is yours, or saving your cookie preferences so you are not asked on every page (which could be seen as coercing the user to accept more cookies).

    @noybeu, what do you think?

    #gdpr #gdprcompliance #UKGDPR #cookies

  13. @tdp_org Why are third-party analytics cookies considered "strictly necessary" on the BBC website?

    bbc.com/usingthebbc/cookies/st

    Strict necessity is defined as those required for the site's basic functionality to work, such as remembering which shopping cart is yours, or saving your cookie preferences so you are not asked on every page (which could be seen as coercing the user to accept more cookies).

    @noybeu, what do you think?

    #gdpr #gdprcompliance #UKGDPR #cookies

  14. @noybeu This is a very broken national law that has not kept up with time. This isn't used just by journalists, it's also used to publish all sorts of private information about individuals by "information broker sites"; things like income, possible crime information, property ownership, etc.

    Some (if not most) of these brokers keep their data on US cloud services like Amazon, Microsoft, etc.

    This is being debated in Sweden, but, well, you know ... 😑

    #gdpr #gdprcompliance #dataprotection

  15. @noybeu This is a very broken national law that has not kept up with time. This isn't used just by journalists, it's also used to publish all sorts of private information about individuals by "information broker sites"; things like income, possible crime information, property ownership, etc.

    Some (if not most) of these brokers keep their data on US cloud services like Amazon, Microsoft, etc.

    This is being debated in Sweden, but, well, you know ... 😑

    #gdpr #gdprcompliance #dataprotection

  16. I notice that EU-based clients' vendor agreements increasingly include a clause granting the client the right to "inspect" and "audit" the place where I do my work, in order to ensure compliance. Do any other home-based workers think the prospect of letting strangers "inspect" and "audit" your home is incredibly creepy?

    #GDPR #GDPRCompliance #RemoteWork #privacy

  17. "GDPRhub is a wiki with GDPR-related decisions and knowledge, enabling anyone to find and share GDPR insights across Europe!" 🇪🇺🧐

    gdprhub.eu

    #gdpr #gdprcompliance #dataskydd #dataprotection #eu #gdprhub

  18. "GDPRhub is a wiki with GDPR-related decisions and knowledge, enabling anyone to find and share GDPR insights across Europe!" 🇪🇺🧐

    gdprhub.eu

    #gdpr #gdprcompliance #dataskydd #dataprotection #eu #gdprhub

  19. Tankesmedjan Timbro har lite otur med sina webbutvecklare då sajten timbro.se dryper av problem med läckage av personuppgifter 🤔 🇪🇺

    xray.joho.se/2023/09/01/timbro

    #gdpr #gdprcompliance #eprivacy #dataskydd #dataprotection #timbro @SmedjanTimbro

  20. Visma pratar gärna och ofta om hur de hjälper företagare med olika tjänster. Deras webbplats, visma.se, lämnar mycket att önska vad gäller hantering av personuppgifter 😑 🇪🇺

    xray.joho.se/2023/08/29/visma-

    #gdpr #gdprcompliance #eprivacy #dataskydd #dataprotection #visma

  21. J-vligt roligt att få vara med om och se till att det gick bra, med allt vad det innebär 😊

    "WebbPlatsen levererar Nextcloud och Collabora till EU-projekt 😊 🇪🇺 🇸🇪"

    webbplatsen.se/nyheter/blogg/w

    #nextcloud #collabora #collaboraonline #saas #gdpr #gdprcompliance #dataskydd

  22. J-vligt roligt att få vara med om och se till att det gick bra, med allt vad det innebär 😊

    "WebbPlatsen levererar Nextcloud och Collabora till EU-projekt 😊 🇪🇺 🇸🇪"

    webbplatsen.se/nyheter/blogg/w

    #nextcloud #collabora #collaboraonline #saas #gdpr #gdprcompliance #dataskydd

  23. Mobiloperatören Hallon visar med all tydlighet att det går att genomföra markanta förbättringar på en webbplats när det kommer till att efterleva ePrivacy och GDPR! 🇪🇺🧐👍

    xray.joho.se/2023/08/11/hallon

    #gdpr #gdprcompliance #eprivacy #privacy #privacymatters #dataskydd #dataprotection #xray

  24. If you're within the EU, you may want to consider an open communications platform, instead of putting more data in the hands of US corporations 😑🤔🕵️🇪🇺

    "Zoom's Updated Terms of Service Permit Training AI on User Content Without Opt-Out"

    stackdiary.com/zoom-terms-now-

    #privacy #gdpr #privacymatters #gdprcompliance #dataskydd #dataprotection #jitsi #zoom #ai

  25. If you're within the EU, you may want to consider an open communications platform, instead of putting more data in the hands of US corporations 😑🤔🕵️🇪🇺

    "Zoom's Updated Terms of Service Permit Training AI on User Content Without Opt-Out"

    stackdiary.com/zoom-terms-now-

    #privacy #gdpr #privacymatters #gdprcompliance #dataskydd #dataprotection #jitsi #zoom #ai

  26. So now, there's (finally) talk about Google Analytics and GDPR from more data protection agencies, and how that will not work out. It'd be nice if these agencies had a hard look at reCaptcha too... 🇪🇺🧐

    #gdpr #recaptcha #dataprotection #gdprcompliance #dataskydd #privacy

  27. I really hope the #eu will be looking into this clear violation of #gdprcompliance. I’m gonna request a #gdpr-deletion from #reddit myself.

    From: @MattHodges
    mastodon.social/@MattHodges/11