Weekly Privacy Roundup: Cookie Banner Debates, Regulatory Updates, and Key Breach Lessons
A summary of this week's top privacy news, covering US state law updates, EU cookie banner debates, and critical security breaches.
Welcome to this week's roundup of data privacy and cybersecurity news. As regulatory landscapes shift and security threats evolve, keeping your business compliant and secure remains a top priority. This week, we look at significant updates in state-level privacy laws, major data breaches stemming from social engineering and compromised credentials, and emerging debates over cookie consent banners in the EU.
Regulatory Updates & Compliance Tools
Several updates this week highlight the changing regulatory environment in the United States:
- Delaware Privacy Updates: Delaware has updated its Consumer Privacy and Data-Breach laws, signaling a continued push toward stronger state-level protections.
- New Security Tools & Guidance: The Department of Health and Human Services (HHS) released an updated Security Risk Assessment Tool to help organizations evaluate their security postures. Similarly, the New York State Department of Financial Services (NYS DFS) issued new cybersecurity guidance focusing on risk assessments for financial services entities.
- FTC Policy Shift: The Federal Trade Commission (FTC) has withdrawn its health app data breach notification policy, indicating shifting priorities in how digital health data is monitored.
For businesses operating across multiple jurisdictions, keeping track of where and how user data is processed is critical. Implementing a robust data mapping process, such as a GDPR Article 30 data inventory, can help you maintain a clear picture of your compliance posture across different state and international laws.
Cookie Banners & Consent Under Scrutiny
In Europe, the debate over online tracking consent continues to heat up. A civil society coalition has published an open letter urging the European Union to "kill the cookie banner." The coalition argues that current banner implementations fail to protect user privacy effectively and lead to consent fatigue.
While the future of consent mechanisms remains a topic of debate among policymakers, businesses must comply with current ePrivacy and GDPR requirements. To ensure compliance without disrupting user experience, utilizing tools like PrivaScan's pre-consent tracker scanning can help you verify that no unauthorized trackers or cookies are deployed before a user provides explicit consent.
Notable Data Breaches & Social Engineering
This week's headlines highlight how social engineering and compromised credentials remain primary entry points for attackers:
- Revolut: The financial technology company confirmed a sensitive customer data breach resulting from unauthorized access gained via fake government requests.
- Florida Motor Vehicle Data: A breach involving Florida motor vehicle data was traced back to credentials stolen from an officer's personal device, emphasizing the risks associated with securing remote work and personal endpoints.
- Roanoke City: A phishing email was identified as the root cause of a data breach affecting Roanoke City, demonstrating the persistent threat of email-based attacks.
- Google: Reports emerged indicating that Google leaked identifying information for victims of sex crimes globally, underscoring the high stakes of managing highly sensitive personal data.
Privacy Disputes & Litigation
Legal actions and disputes highlight the consequences of non-compliance and disputed data practices:
- SCHUFA & noyb: The privacy advocacy group noyb announced that a lawsuit is now certain against German credit bureau SCHUFA over its insistence on maintaining a "shadow database."
- Facebook Trial: In New Mexico, the trial against Facebook has commenced regarding its alleged role in the historic Cambridge Analytica data breach.
- Settlements: Managed Care of North America has reached a class-action settlement following a major data breach, illustrating the financial liabilities associated with security failures.
Cyber Threats & Enforcement Actions
Regulators and law enforcement continue to crack down on both internal and external threats:
- Insider Threats: An AT&T store worker was sentenced to 16 months in prison for participating in a SIM-swapping scheme.
- Ransomware Sentencing: A Ukrainian hacker received a four-year prison sentence in the US for involvement in Conti ransomware attacks.
- AI Exploitation: Anthropic reported detecting Russia-linked spies utilizing its Claude AI assistant in hacking operations, highlighting how threat actors are adapting to new technologies.
- Targeted Attacks: Reports indicate that six out of ten cyberattacks in Colombia currently target hospitals, highlighting the vulnerability of critical healthcare infrastructure. In response to evolving threats, the NSA announced a reorganization that will establish five new "mission centers," including dedicated units for cyber and AI.
What This Means for You
This week's developments show that data protection is as much about managing human risk and third-party integrations as it is about securing servers. Breaches frequently stem from compromised personal devices, phishing, or sophisticated social engineering. For web agencies, developers, and business owners, securing your digital footprint requires continuous vigilance. Ensure your team is trained against phishing, restrict access from unsecured personal devices, and routinely audit your website's external scripts and data flows to prevent unauthorized data leaks.
Disclaimer: This roundup is for informational purposes only and does not constitute legal advice. Consult a qualified professional for specific compliance guidance.
Sources
- Six in 10 Cyberattacks in Colombia Target Hospitals — DataBreaches.net
- Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI — The Record
- Delaware Consumer Privacy and Data-Breach Law Updates — DataBreaches.net
- AT&T store worker gets 16 months inside for SIM-swap side hustle — DataBreaches.net
- HHS Releases Updated Security Risk Assessment Tool — DataBreaches.net
- Not just Korea: Google leaked identifying info for sex crime victims across the world — DataBreaches.net
- NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities — DataBreaches.net
- Florida investigates data breach tied to cybercriminal organization - WPBF — WPBF
- Revolut confirms sensitive customer data breach after fake government requests - Reuters — Reuters
- Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device — The Record
More articles
- Weekly Privacy & Security Roundup: Multi-Million Dollar Settlements, Vendor Vulnerabilities, and Evolving Smart-Tech Policies 07 Sep 2026
- PrivaScan Weekly Privacy Roundup: Massive Retail Breaches, Public Sector Ransomware, and Evolving Cyber Threats 31 Aug 2026
- Weekly Privacy Roundup: Historic $966M Uber Fine & The Growing Threat of Fourth-Party Breaches 24 Aug 2026