Hello all, and happy Thursday!
When communicating with non-privacy professionals about what Osano does, I often have to clarify the distinction between data privacy and data security. (Iām sure plenty of privacy pros can empathize.) In fact, this happens so often that I sometimes forget the opposite problem exists: Plenty of people underemphasize the relationship between data security and privacy.
The UKās Information Commissionerās Officeās (ICOās) recent fine against Capita, an outsourcing firm, brought this fact to mind. In 2023, Capita suffered a breach in which 6.6 million peopleās data was stolen, and they subsequently received a Ā£14m fine.
In some respects, financial penalties levied against the victims of a cyberattack can be seen as rubbing salt in the woundāafter all, a cyberattack already costs a great deal of money in cleanup and reputational costs. You have to wonder: Do regulators almost automatically apply non-compliance fines against companies that suffer a breach regardless of their security measuresā quality? Or do regulators carefully assess whether lackluster security played a significant role in the cyberattack?
In this case, the UK ICO did a good job of explaining what specific security failures enabled the attack to take place. Itās a good reminder that robust organizational and technical security measures are part of protecting peopleās privacy too.
Best,
Arlo
Highlights From Osano
Events
Event: P.S.R.
Come by booth 400 at this yearās Privacy. Security. Risk (P.S.R.) conference! Not only will your favorite privacy vendor be in attendance, but youāll also have the opportunity to schedule a one-on-one strategy chat with our privacy experts, enjoy a(n awkward family) photo-worthy Osanoverse experience, and more.
Schedule time at the booth | October 28-31 | San Diego, CA
Meetup: AI, IRL: Hexes and Hallucinations
Itās already in your stack, your prompts, your daily lifeā¦and sometimes it can haunt instead of help. Join us this spooky season as we yap AI terror tales! Seats are limited for this meetup, so grab yours today!
Register today | October 22nd | 1-3 PM EST
Top Privacy Stories of the Week
UK Fines Outsourcing Firm Capita £14 Million for Data Breach Affecting Over 6 Million People
The UKās Information Commissionerās Office (ICO) has issued a fine of Ā£14 million to Capita for failing to ensure the security of personal data related to a breach in 2023 that saw hackers steal millions of peopleās information. The personal information of 6.6 million people was stolen, from pension records and staff records to the details of the customers of Capitaās clients. For some people, this included sensitive information such as details of criminal records, financial data, or special category data.
EU Delays 'Chat Control' Law Over Privacy Concerns
Last week, Germany said it would vote against Chat Control, a contentious EU measure designed to protect children online. The countryās leaders argued that it could be abused to monitor all citizensā private chats. Since Berlin has the swing vote, the move to postpone the vote and remove it from this weekās agenda, which was scheduled October 14th, isnāt exactly surprising. This won't be the first time that the Chat Control bill has been shot down, and it likely wonāt be the last.
Britain Issues First Online Safety Act Fine to US Website 4chan
Ofcom, the British communications regulator, announced recently that it had issued imageboard 4chan a £20,000 ($26,000) fine for noncompliance with the Online Safety Act. The fine was issued after 4chan failed to respond to Ofcom's request for a copy of its illegal harms risk assessment and a second request relating to its qualifying worldwide. The fine amount will increase by £100 ($133) per day from Tuesday, and if ignored, could see British ISPs block the site.
California Expands Privacy Protections as Democratic-Led States Resist Trumpās Immigration Agenda
Immigrants comprise a significant portion of Californiaās urban sidewalk vendors. Some have been swept up in immigration enforcement actions, in part, because their outdoor work in public places makes them easier targets than people behind closed doors. A new law signed by Governor Gavin Newsom prohibits local governments from inquiring about vendorsā immigration status, requiring fingerprinting or disclosing personal informationāname, address, birth date, social media identifiers and telephone, driverās license and Social Security numbers, among other thingsāwithout a judicial subpoena.
EU Biometric Border Checks Begin for Non-EU Travelers
Europeās long-delayed Entry/Exit System (EES) officially starts rolling out October 12, marking a major change in how non-EU travelers enter and leave the Schengen Area. The system now requires all non-EU visitors to register their fingerprints and facial images when crossing into Europeās passport-free zone. While privacy groups have voiced concerns about biometric surveillance, the EU maintained that the system fully follows data protection laws.
Like what you hear from the Privacy Insider newsletter?
There's more to explore:
šļøThe Privacy Insider Podcast
We go deeper into additional privacy topics with incredible guests monthly. Available on Spotify or Apple.
š The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If youāre interested in working at Osano, check out our Careers page!
Arlo Gilbert
Arlo Gilbert
Arlo Gilbert is the CIO & co-founder of Osano. A native of Austin, Texas, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
