home.social

#privacycommissioner — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #privacycommissioner, aggregated by home.social.

fetched live
  1. Senate orders Privacy Commissioner to release report on American Express security failures

    The Privacy Commissioner has been ordered by parliament to hand over a secret report detailing its investigation into…
    #Australia #abcinvestigations #alastairmacgibbon #americanexpress #AU #australianinformationcommissioner #Austrlia #davidshoebridge #privacycommissioner
    europesays.com/australia/42923/

  2. Privacy Commissioner Investigating Centurion Project. Strongly Worded Letter Could Follow

    The lack of any real privacy laws could play a role in the Centurion Project scandal that exposed millions of Alberta voters.

    freezenet.ca/privacy-commissio

    #News #Privacy #Security #Alberta #Canada #CanPol #CenturionProject #DataLeak #JasonKenney #politics #PrivacyCommissioner #PrivacyReform

  3. So of course the NZ Privacy Commissioner will be pushing for third-party service providers to be subject to the OIA for every aspect of public service work they handle, just like the agencies commissioning them, right? Riiiight?

    (2/2)

    #PolicyNZ #PrivacyCommissioner #OIA #PublicService

  4. So of course the NZ Privacy Commissioner will be pushing for third-party service providers to be subject to the OIA for every aspect of public service work they handle, just like the agencies commissioning them, right? Riiiight?

    (2/2)

    #PolicyNZ #PrivacyCommissioner #OIA #PublicService

  5. So of course the NZ Privacy Commissioner will be pushing for third-party service providers to be subject to the OIA for every aspect of public service work they handle, just like the agencies commissioning them, right? Riiiight?

    (2/2)

    #PolicyNZ #PrivacyCommissioner #OIA #PublicService

  6. So of course the NZ Privacy Commissioner will be pushing for third-party service providers to be subject to the OIA for every aspect of public service work they handle, just like the agencies commissioning them, right? Riiiight?

    (2/2)

    #PolicyNZ #PrivacyCommissioner #OIA #PublicService

  7. @biddy_sue @felix @kyhwana @ThisCJ @oseiler

    Privacy Commissioner's response to ManageMyHealth breach: A masterclass in looking busy while doing nothing
    Timeline:

    29 Dec 2025: ManageMyHealth breach detected (108K-126K users affected)
    21 Jan 2026: Privacy Commissioner announces inquiry
    31 Mar 2026, 16:30: Privacy Commissioner sends email (effective 1 Apr - <24hrs notice)

    What the email says:

    Enquiries email address closing 1 April
    All complaint actions PAUSED until inquiry completes (no timeline given)
    To complain, you must FIRST:
    • Contact ManageMyHealth (who didn't respond to my 3 emails)
    • Contact Te Whatu Ora
    • Contact your GP
    • Provide documentary evidence of all attempts
    • Prove you gave them "reasonable chance to respond"
    Must demonstrate individual harm (not "general concerns about the breach")

    The Catch-22:

    Data not breached? = No individual harm = "general concerns" = not actionable
    Data was breached? = Must exhaust remedies with organisations that failed to protect you first
    Either way? = Complaint action paused indefinitely anyway

    What this reveals:
    The Privacy Commissioner is conducting an inquiry (looks like action) while making individual complaints nearly impossible (avoids making findings against government agencies/contractors).
    Independent security analysis showed ManageMyHealth had:

    DMARC set to monitoring only (anyone could spoof their domain)
    Weak 1024-bit DKIM keys (not industry standard 2048-bit)
    Zero DNSSEC protection across 19 subdomains
    Misconfigured email transport security

    These are basic infrastructure failures, known best practices for over a decade.
    But apparently that's a "general concern" not worth the Privacy Commissioner's time.
    Sent at 16:30 on 31 March, effective 1 April. You were meant to miss it.

    #NZPol #Privacy #DataBreach #ManageMyHealth #PrivacyCommissioner #Accountability

  8. @biddy_sue @felix @kyhwana @ThisCJ @oseiler

    Privacy Commissioner's response to ManageMyHealth breach: A masterclass in looking busy while doing nothing
    Timeline:

    29 Dec 2025: ManageMyHealth breach detected (108K-126K users affected)
    21 Jan 2026: Privacy Commissioner announces inquiry
    31 Mar 2026, 16:30: Privacy Commissioner sends email (effective 1 Apr - <24hrs notice)

    What the email says:

    Enquiries email address closing 1 April
    All complaint actions PAUSED until inquiry completes (no timeline given)
    To complain, you must FIRST:
    • Contact ManageMyHealth (who didn't respond to my 3 emails)
    • Contact Te Whatu Ora
    • Contact your GP
    • Provide documentary evidence of all attempts
    • Prove you gave them "reasonable chance to respond"
    Must demonstrate individual harm (not "general concerns about the breach")

    The Catch-22:

    Data not breached? = No individual harm = "general concerns" = not actionable
    Data was breached? = Must exhaust remedies with organisations that failed to protect you first
    Either way? = Complaint action paused indefinitely anyway

    What this reveals:
    The Privacy Commissioner is conducting an inquiry (looks like action) while making individual complaints nearly impossible (avoids making findings against government agencies/contractors).
    Independent security analysis showed ManageMyHealth had:

    DMARC set to monitoring only (anyone could spoof their domain)
    Weak 1024-bit DKIM keys (not industry standard 2048-bit)
    Zero DNSSEC protection across 19 subdomains
    Misconfigured email transport security

    These are basic infrastructure failures, known best practices for over a decade.
    But apparently that's a "general concern" not worth the Privacy Commissioner's time.
    Sent at 16:30 on 31 March, effective 1 April. You were meant to miss it.

    #NZPol #Privacy #DataBreach #ManageMyHealth #PrivacyCommissioner #Accountability

  9. @biddy_sue @felix @kyhwana @ThisCJ @oseiler

    Privacy Commissioner's response to ManageMyHealth breach: A masterclass in looking busy while doing nothing
    Timeline:

    29 Dec 2025: ManageMyHealth breach detected (108K-126K users affected)
    21 Jan 2026: Privacy Commissioner announces inquiry
    31 Mar 2026, 16:30: Privacy Commissioner sends email (effective 1 Apr - <24hrs notice)

    What the email says:

    Enquiries email address closing 1 April
    All complaint actions PAUSED until inquiry completes (no timeline given)
    To complain, you must FIRST:
    • Contact ManageMyHealth (who didn't respond to my 3 emails)
    • Contact Te Whatu Ora
    • Contact your GP
    • Provide documentary evidence of all attempts
    • Prove you gave them "reasonable chance to respond"
    Must demonstrate individual harm (not "general concerns about the breach")

    The Catch-22:

    Data not breached? = No individual harm = "general concerns" = not actionable
    Data was breached? = Must exhaust remedies with organisations that failed to protect you first
    Either way? = Complaint action paused indefinitely anyway

    What this reveals:
    The Privacy Commissioner is conducting an inquiry (looks like action) while making individual complaints nearly impossible (avoids making findings against government agencies/contractors).
    Independent security analysis showed ManageMyHealth had:

    DMARC set to monitoring only (anyone could spoof their domain)
    Weak 1024-bit DKIM keys (not industry standard 2048-bit)
    Zero DNSSEC protection across 19 subdomains
    Misconfigured email transport security

    These are basic infrastructure failures, known best practices for over a decade.
    But apparently that's a "general concern" not worth the Privacy Commissioner's time.
    Sent at 16:30 on 31 March, effective 1 April. You were meant to miss it.

    #NZPol #Privacy #DataBreach #ManageMyHealth #PrivacyCommissioner #Accountability

  10. @biddy_sue @felix @kyhwana @ThisCJ @oseiler

    Privacy Commissioner's response to ManageMyHealth breach: A masterclass in looking busy while doing nothing
    Timeline:

    29 Dec 2025: ManageMyHealth breach detected (108K-126K users affected)
    21 Jan 2026: Privacy Commissioner announces inquiry
    31 Mar 2026, 16:30: Privacy Commissioner sends email (effective 1 Apr - <24hrs notice)

    What the email says:

    Enquiries email address closing 1 April
    All complaint actions PAUSED until inquiry completes (no timeline given)
    To complain, you must FIRST:
    • Contact ManageMyHealth (who didn't respond to my 3 emails)
    • Contact Te Whatu Ora
    • Contact your GP
    • Provide documentary evidence of all attempts
    • Prove you gave them "reasonable chance to respond"
    Must demonstrate individual harm (not "general concerns about the breach")

    The Catch-22:

    Data not breached? = No individual harm = "general concerns" = not actionable
    Data was breached? = Must exhaust remedies with organisations that failed to protect you first
    Either way? = Complaint action paused indefinitely anyway

    What this reveals:
    The Privacy Commissioner is conducting an inquiry (looks like action) while making individual complaints nearly impossible (avoids making findings against government agencies/contractors).
    Independent security analysis showed ManageMyHealth had:

    DMARC set to monitoring only (anyone could spoof their domain)
    Weak 1024-bit DKIM keys (not industry standard 2048-bit)
    Zero DNSSEC protection across 19 subdomains
    Misconfigured email transport security

    These are basic infrastructure failures, known best practices for over a decade.
    But apparently that's a "general concern" not worth the Privacy Commissioner's time.
    Sent at 16:30 on 31 March, effective 1 April. You were meant to miss it.

    #NZPol #Privacy #DataBreach #ManageMyHealth #PrivacyCommissioner #Accountability

  11. @biddy_sue @felix @kyhwana @ThisCJ @oseiler

    Privacy Commissioner's response to ManageMyHealth breach: A masterclass in looking busy while doing nothing
    Timeline:

    29 Dec 2025: ManageMyHealth breach detected (108K-126K users affected)
    21 Jan 2026: Privacy Commissioner announces inquiry
    31 Mar 2026, 16:30: Privacy Commissioner sends email (effective 1 Apr - <24hrs notice)

    What the email says:

    Enquiries email address closing 1 April
    All complaint actions PAUSED until inquiry completes (no timeline given)
    To complain, you must FIRST:
    • Contact ManageMyHealth (who didn't respond to my 3 emails)
    • Contact Te Whatu Ora
    • Contact your GP
    • Provide documentary evidence of all attempts
    • Prove you gave them "reasonable chance to respond"
    Must demonstrate individual harm (not "general concerns about the breach")

    The Catch-22:

    Data not breached? = No individual harm = "general concerns" = not actionable
    Data was breached? = Must exhaust remedies with organisations that failed to protect you first
    Either way? = Complaint action paused indefinitely anyway

    What this reveals:
    The Privacy Commissioner is conducting an inquiry (looks like action) while making individual complaints nearly impossible (avoids making findings against government agencies/contractors).
    Independent security analysis showed ManageMyHealth had:

    DMARC set to monitoring only (anyone could spoof their domain)
    Weak 1024-bit DKIM keys (not industry standard 2048-bit)
    Zero DNSSEC protection across 19 subdomains
    Misconfigured email transport security

    These are basic infrastructure failures, known best practices for over a decade.
    But apparently that's a "general concern" not worth the Privacy Commissioner's time.
    Sent at 16:30 on 31 March, effective 1 April. You were meant to miss it.

    #NZPol #Privacy #DataBreach #ManageMyHealth #PrivacyCommissioner #Accountability

  12. OTTAWA - The Privacy Commissioner of Canada today held a press conference regarding the digital attack on Telus Canada's networks and information systems. Telus recently announced that attackers had claimed to have exfiltrated nearly 1 petabyte of company data, including customer data, equivalent to approximately 250,000 DVD movies.

    The Commissioner announced a full investigation will take place. He also indicated that Canadian consumers should not be excessively worried about the breach of their personally identifiable information (PII), as the attackers will still be obligated to follow the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's data privacy law since passage in 2000.

    #Canada #privacy #Telus #hack #hackers #intrusion #exfiltration #PIPEDA #PrivacyCommissioner #security #PII

  13. OTTAWA - The Privacy Commissioner of Canada today held a press conference regarding the digital attack on Telus Canada's networks and information systems. Telus recently announced that attackers had claimed to have exfiltrated nearly 1 petabyte of company data, including customer data, equivalent to approximately 250,000 DVD movies.

    The Commissioner announced a full investigation will take place. He also indicated that Canadian consumers should not be excessively worried about the breach of their personally identifiable information (PII), as the attackers will still be obligated to follow the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's data privacy law since passage in 2000.

    #Canada #privacy #Telus #hack #hackers #intrusion #exfiltration #PIPEDA #PrivacyCommissioner #security #PII

  14. OTTAWA - The Privacy Commissioner of Canada today held a press conference regarding the digital attack on Telus Canada's networks and information systems. Telus recently announced that attackers had claimed to have exfiltrated nearly 1 petabyte of company data, including customer data, equivalent to approximately 250,000 DVD movies.

    The Commissioner announced a full investigation will take place. He also indicated that Canadian consumers should not be excessively worried about the breach of their personally identifiable information (PII), as the attackers will still be obligated to follow the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's data privacy law since passage in 2000.

    #Canada #privacy #Telus #hack #hackers #intrusion #exfiltration #PIPEDA #PrivacyCommissioner #security #PII

  15. OTTAWA - The Privacy Commissioner of Canada today held a press conference regarding the digital attack on Telus Canada's networks and information systems. Telus recently announced that attackers had claimed to have exfiltrated nearly 1 petabyte of company data, including customer data, equivalent to approximately 250,000 DVD movies.

    The Commissioner announced a full investigation will take place. He also indicated that Canadian consumers should not be excessively worried about the breach of their personally identifiable information (PII), as the attackers will still be obligated to follow the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's data privacy law since passage in 2000.

    #Canada #privacy #Telus #hack #hackers #intrusion #exfiltration #PIPEDA #PrivacyCommissioner #security #PII

  16. OTTAWA - The Privacy Commissioner of Canada today held a press conference regarding the digital attack on Telus Canada's networks and information systems. Telus recently announced that attackers had claimed to have exfiltrated nearly 1 petabyte of company data, including customer data, equivalent to approximately 250,000 DVD movies.

    The Commissioner announced a full investigation will take place. He also indicated that Canadian consumers should not be excessively worried about the breach of their personally identifiable information (PII), as the attackers will still be obligated to follow the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's data privacy law since passage in 2000.

    #Canada #privacy #Telus #hack #hackers #intrusion #exfiltration #PIPEDA #PrivacyCommissioner #security #PII

  17. 🚨 Ah, #Kmart, the retail tech pioneer, bravely tackling refund fraud by trying to turn into a discount version of Minority Report—until the Privacy Commissioner crashed the sale. 📸💰 Who knew that trading your face for a 5% discount could be considered "unlawful"? 🙄
    oaic.gov.au/news/media-centre/ #RefundFraud #RetailTech #PrivacyCommissioner #Discounts #MinorityReport #HackerNews #ngated

  18. 🚨 Ah, #Kmart, the retail tech pioneer, bravely tackling refund fraud by trying to turn into a discount version of Minority Report—until the Privacy Commissioner crashed the sale. 📸💰 Who knew that trading your face for a 5% discount could be considered "unlawful"? 🙄
    oaic.gov.au/news/media-centre/ #RefundFraud #RetailTech #PrivacyCommissioner #Discounts #MinorityReport #HackerNews #ngated

  19. 🚨 Ah, #Kmart, the retail tech pioneer, bravely tackling refund fraud by trying to turn into a discount version of Minority Report—until the Privacy Commissioner crashed the sale. 📸💰 Who knew that trading your face for a 5% discount could be considered "unlawful"? 🙄
    oaic.gov.au/news/media-centre/ #RefundFraud #RetailTech #PrivacyCommissioner #Discounts #MinorityReport #HackerNews #ngated

  20. 🚨 Ah, #Kmart, the retail tech pioneer, bravely tackling refund fraud by trying to turn into a discount version of Minority Report—until the Privacy Commissioner crashed the sale. 📸💰 Who knew that trading your face for a 5% discount could be considered "unlawful"? 🙄
    oaic.gov.au/news/media-centre/ #RefundFraud #RetailTech #PrivacyCommissioner #Discounts #MinorityReport #HackerNews #ngated

  21. Google Laughs Off Strongly Worded Letter From Privacy Commissioner

    Canada's privacy laws continue to be a long running joke after Google laughs of the strongly worded letter from the privacy commissioner.

    freezenet.ca/google-laughs-off

    #Business #News #Privacy #Security #Canada #Google #PersonalInformation #PrivacyCommissioner #RightToBeForgotten

  22. Google Laughs Off Strongly Worded Letter From Privacy Commissioner

    Canada's privacy laws continue to be a long running joke after Google laughs of the strongly worded letter from the privacy commissioner.

    freezenet.ca/google-laughs-off

    #Business #News #Privacy #Security #Canada #Google #PersonalInformation #PrivacyCommissioner #RightToBeForgotten

  23. Google Laughs Off Strongly Worded Letter From Privacy Commissioner

    Canada's privacy laws continue to be a long running joke after Google laughs of the strongly worded letter from the privacy commissioner.

    freezenet.ca/google-laughs-off

    #Business #News #Privacy #Security #Canada #Google #PersonalInformation #PrivacyCommissioner #RightToBeForgotten

  24. Google Laughs Off Strongly Worded Letter From Privacy Commissioner

    Canada's privacy laws continue to be a long running joke after Google laughs of the strongly worded letter from the privacy commissioner.

    freezenet.ca/google-laughs-off

    #Business #News #Privacy #Security #Canada #Google #PersonalInformation #PrivacyCommissioner #RightToBeForgotten

  25. Google Laughs Off Strongly Worded Letter From Privacy Commissioner

    Canada's privacy laws continue to be a long running joke after Google laughs of the strongly worded letter from the privacy commissioner.

    freezenet.ca/google-laughs-off

    #Business #News #Privacy #Security #Canada #Google #PersonalInformation #PrivacyCommissioner #RightToBeForgotten

  26. This is what a privatised health system looks like folks.

    The same people who can buy a McDonalds can buy a franchise to host your most personal data. Under terms that are legal only because the NZ Privacy Act is a leaky sieve, protecting only the most cut'n'dried lowest common denominator of privacy rights. Overseen by a toothless #PrivacyCommissioner, hamstrung by underfunding.

    rnz.co.nz/news/national/513289

    I won't be using Manage My Health. I suggest you think twice before you do.

    (14/14)

  27. This is what a privatised health system looks like folks.

    The same people who can buy a McDonalds can buy a franchise to host your most personal data. Under terms that are legal only because the NZ Privacy Act is a leaky sieve, protecting only the most cut'n'dried lowest common denominator of privacy rights. Overseen by a toothless #PrivacyCommissioner, hamstrung by underfunding.

    rnz.co.nz/news/national/513289

    I won't be using Manage My Health. I suggest you think twice before you do.

    (14/14)

  28. This is what a privatised health system looks like folks.

    The same people who can buy a McDonalds can buy a franchise to host your most personal data. Under terms that are legal only because the NZ Privacy Act is a leaky sieve, protecting only the most cut'n'dried lowest common denominator of privacy rights. Overseen by a toothless #PrivacyCommissioner, hamstrung by underfunding.

    rnz.co.nz/news/national/513289

    I won't be using Manage My Health. I suggest you think twice before you do.

    (14/14)

  29. This is what a privatised health system looks like folks.

    The same people who can buy a McDonalds can buy a franchise to host your most personal data. Under terms that are legal only because the NZ Privacy Act is a leaky sieve, protecting only the most cut'n'dried lowest common denominator of privacy rights. Overseen by a toothless #PrivacyCommissioner, hamstrung by underfunding.

    rnz.co.nz/news/national/513289

    I won't be using Manage My Health. I suggest you think twice before you do.

    (14/14)

  30. @batichi

    Canada's Privacy Commissioner reported to parliament that it was, in fact, illegal.

    Canada Post doesn't want to hear it.

    Contact your MP to complain about that part!

    #privacy #PrivacyCommissioner #illegal #law #Canada

  31. @batichi

    Canada's Privacy Commissioner reported to parliament that it was, in fact, illegal.

    Canada Post doesn't want to hear it.

    Contact your MP to complain about that part!

    #privacy #PrivacyCommissioner #illegal #law #Canada

  32. @batichi

    Canada's Privacy Commissioner reported to parliament that it was, in fact, illegal.

    Canada Post doesn't want to hear it.

    Contact your MP to complain about that part!

    #privacy #PrivacyCommissioner #illegal #law #Canada

  33. @batichi

    Canada's Privacy Commissioner reported to parliament that it was, in fact, illegal.

    Canada Post doesn't want to hear it.

    Contact your MP to complain about that part!

    #privacy #PrivacyCommissioner #illegal #law #Canada

  34. @batichi

    Canada's Privacy Commissioner reported to parliament that it was, in fact, illegal.

    Canada Post doesn't want to hear it.

    Contact your MP to complain about that part!

    #privacy #PrivacyCommissioner #illegal #law #Canada

  35. The TikTok Privacy “Investigation” Faces a Very Uphill Battle in Canada

    Headlines have said that TikTok is facing a privacy "investigation" in Canada. It faces an enormous uphill battle.

    If you live in the US or a number of other countries, the headlines will sound very familiar to you

    freezenet.ca/the-tiktok-privac

    #Privacy #Security #app #BillC-27 #Canada #personalinformation #PrivacyCommissioner #TikTok

  36. The TikTok Privacy “Investigation” Faces a Very Uphill Battle in Canada

    Headlines have said that TikTok is facing a privacy "investigation" in Canada. It faces an enormous uphill battle.

    If you live in the US or a number of other countries, the headlines will sound very familiar to you

    freezenet.ca/the-tiktok-privac

    #Privacy #Security #app #BillC-27 #Canada #personalinformation #PrivacyCommissioner #TikTok

  37. Making people host their own #LiveStreams, by leasing server resources and setting up #FreeCode streaming software, just shifts the problem sideways. Then instead of FB, the #PrivacyCommissioner and the #ChiefCensor would be blaming whichever ISP leased use of their server to people who used it for objectionable streams.