PrivaScan Weekly Privacy Roundup: Multi-Million Dollar Settlements, SDK Tracking Risks, and European Enforcement
This week's privacy news highlights 23andMe's $18M settlement, Italy's €1.7M telecom fine, Stardust tracker leaks, and evolving UK compliance rules.
Welcome to the weekly PrivaScan data privacy roundup. This week, we analyze major financial penalties for data breaches, regulatory investigations into age verification, and the compliance risks of third-party tracking scripts.
High-Profile Breaches & Multi-Million Dollar Settlements
The legal and financial fallout from the 23andMe genetic data breach continues to expand. The New York Attorney General secured an $18 million settlement from the company for failing to protect customer data. Additionally, both Alabama and Michigan have settled bankruptcy claims against the firm stemming from the same incident.
In other security news, medical giant Abbott is currently investigating two separate cyber incidents claimed by the threat groups ShinyHunters and ShadowByt3$. In the US, dairy producer Fairlife temporarily suspended production following a cyber incident, while All About Women's Care reported a breach affecting up to 12,000 patients. Morris Communications Company is also facing potential legal action following a reported data breach.
Why it matters: These incidents demonstrate that data security failures carry massive, multi-jurisdictional financial penalties and operational disruptions. For business owners, safeguarding customer data is a critical operational requirement.
Regulatory Enforcement: Italy Fines WINDTRE €1.7 Million
European regulators continue their strict enforcement of data protection standards. Italy's data protection authority has fined telecommunications company WINDTRE €1.7 million over data breaches.
Meanwhile, in the UK, regulators are investigating TikTok over alleged lapses in its age-verification processes, which potentially exposed children to online harms. In contrast, Australia's privacy regulator released preliminary findings indicating that airline Qantas did not breach its privacy obligations in a recent review.
Why it matters: Regulators are actively issuing seven-figure fines for security lapses. Ensuring your platform's user verification and data security measures are robust is essential to avoiding regulatory scrutiny.
Third-Party Trackers and the Privacy Trap
A recent investigation by Mozilla revealed that the period tracking app Stardust has been sharing users' sensitive health data with an external analytics firm. This highlights a common compliance pitfall: third-party software development kits (SDKs) and analytics trackers often transmit user data behind the scenes without clear user consent.
Why it matters: Web agencies and developers must have full visibility into what external scripts are doing on their platforms. Utilizing tools like PrivaScan's pre-consent tracker scanning helps identify unauthorized data transmissions before they trigger regulatory complaints or public backlash.
Shifting Compliance & Cross-Border Landscapes
The legal landscape for employers and international businesses is evolving. The UK has introduced new data protection complaint requirements that employers must navigate. On the international front, legal experts point out that robust GDPR readiness is increasingly linked to successful cross-border business expansion. Meanwhile, US lawmakers and Attorneys General are pushing to rehear an FCC data breach case, and US senators are urging pushback against proposed Canadian surveillance legislation.
Why it matters: Navigating international data transfers requires precise mapping. Utilizing a GDPR Article 30 data inventory and cross-border detection tools allows organizations to maintain clear records of where data is stored and processed.
What This Means for You
This week's news underscores that data privacy is not a set-it-and-forget-it task. Whether it is managing third-party analytics trackers, preparing for cross-border data transfers, or securing employee data under new UK guidelines, compliance requires proactive monitoring. Regularly auditing your website's trackers and maintaining an up-to-date data inventory are critical steps to mitigating risk and building trust with your users.
Sources
- Medical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breaches — DataBreaches.net
- GDPR READINESS: PROPELLING CROSS-BORDER SUCCESS - McDermott Will & Schulte — McDermott Will & Schulte
- NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data — DataBreaches.net
- UK Introduces New Data Protection Complaint Requirements for Employers - JD Supra — JD Supra
- GOP Lawmakers, AGs Want FCC Data Breach Case Reheard - Broadband Breakfast — Broadband Breakfast
- Morris Communications Company Data Breach Reported, Lawsuit Possible - ClassAction.org — ClassAction.org
- FBI arrests man accused of using Steam games to drain victims’ crypto wallets — DataBreaches.net
- Dairy company Fairlife suspends production in US after cyber incident — The Record
- Zelensky appoints Ukraine's acting security service chief as acting defense minister — The Record
- All About Women’s Care Data Breach Affects Up to 12,000 Patients - The HIPAA Journal — The HIPAA Journal
More articles
- Turning a Privacy Scan Into GDPR Art. 30 Evidence 16 Jul 2026
- Weekly Privacy Roundup: Major Telecom Breaches, Multi-Million Dollar Settlements, and Evolving EU Reporting Standards 13 Jul 2026
- Weekly Privacy Roundup: Cross-Border Transfer Risks, AI-Driven Attacks, and Major Corporate Breaches 06 Jul 2026