Weekly Privacy Roundup: EDPB Fine Guidelines, €7M IQVIA Penalty, and the Risks of Misaligned Cookie Consent
Keep your website compliant with our weekly roundup of global privacy updates, DPA enforcement actions, and emerging data security trends.
Welcome to this week's privacy roundup from the PrivaScan team. As web developers, agencies, and business owners, keeping pace with global privacy regulations is a constant challenge. From evolving regulatory guidelines in Europe to unexpected legal risks associated with cookie compliance in the US, staying informed is your first line of defense. This week, we examine major regulatory movements, significant healthcare breaches, and the shifting landscape of consent.
Regulatory Updates & Enforcement
- EDPB Launches Consultation on GDPR Fines: The European Data Protection Board (EDPB) has published new guidelines on GDPR fines and other corrective powers for public consultation. This initiative aims to harmonize how supervisory authorities calculate penalties and enforce compliance across the EU.
- Italy's Garante Fines IQVIA €7 Million: Italy's Data Protection Authority has issued a €7 million fine against healthcare data firm IQVIA over a data protection breach, highlighting the high stakes of processing sensitive data without flawless compliance frameworks.
- OpenAI Subpoenaed by California DOJ: OpenAI is facing a subpoena from the California Department of Justice amid a growing wave of cybersecurity incident notices, signaling increased domestic scrutiny on AI developers and their data handling practices.
Cookie Consent & Compliance Risks
- The Risk of 'Translating' Cookie Consent: A recent analysis by Dentons highlights how European-style cookie consent mechanisms can actually create unexpected legal risks when applied directly to websites operating in the United States. This "lost in translation" effect underscores the danger of using generic, one-size-fits-all compliance templates.
- Why it matters: Web agencies must implement localized consent strategies. Utilizing tools like PrivaScan's pre-consent tracker scanning ensures that trackers and scripts only execute in accordance with the specific legal requirements of the user's jurisdiction, protecting businesses from accidental non-compliance.
Healthcare and Public Sector Breaches
- Texas Hospice Breach Affects 35,000: A data breach at a Texas Hospice Management Company has compromised the personal information of approximately 35,000 Texas residents, highlighting the vulnerability of healthcare providers.
- School District Rejects Ransom Demand: The Slate Valley Unified School District voted not to pay a ransom demand following a cyberattack, with reports indicating that the Kairos threat group is likely to leak the stolen data.
- Additional Healthcare Incidents: Both Family Physicians in Jackson Township and Gibson Area Hospital & Health Services have reported or are investigating data breaches, with the latter already facing potential class-action scrutiny.
- Why it matters: For organizations handling sensitive user data, maintaining an accurate GDPR Article 30 data inventory is essential. Knowing exactly where personal data is stored, processed, and shared makes containment and regulatory reporting much faster if a breach occurs.
Infrastructure & Global Cyber Threats
- Ransomware Shuts Down Mississippi City: A ransomware incident forced a Mississippi mayor to shut down municipal systems to contain the threat, demonstrating the persistent danger cyberattacks pose to public administration.
- South Korea Orders Bank Probe: Following data breaches at local banks, South Korea's President Lee Jae Myung has ordered a thorough investigation into financial sector cybersecurity.
- 'Warlock' Ransomware Targets Critical Infrastructure: A new ransomware strain named "Warlock" has been active, specifically targeting critical infrastructure in Portuguese- and Spanish-speaking countries.
- International Arrests and Extraditions: Law enforcement continues to push back, with Jordan detaining a ShinyHunters hacker known as "Rey" (allegedly involved in FBI data theft) and Montenegro extraditing an Iranian national accused of hacking American universities.
Surveillance & Device Privacy
- Backlash Against License Plate Readers: Bipartisan concern is growing in the US over Automated License Plate Readers (ALPRs), with two high-profile bills introduced to regulate their use. This comes alongside resident concerns in Marin County following a data breach involving Flock safety cameras.
- California Smart Glasses Bill Vetoed: California's governor vetoed a bill that aimed to ban the use of wearable devices (referred to as 'pervert glasses') to secretly record individuals in public.
- Pegasus Spyware Case Dismissed: A US judge has dismissed a lawsuit brought by Salvadoran journalists who were targeted with the Pegasus spyware, marking a setback for civil society challenges against commercial spyware manufacturers.
What this means for you
This week’s developments emphasize that data privacy is not a static checkbox. Whether you are managing consent across different international legal frameworks or securing sensitive databases, compliance requires continuous monitoring. For developers and agencies, relying on manual audits is no longer viable. Implementing automated solutions—such as pre-consent tracker scanning and cross-border data transfer detection—helps ensure your web properties respect user choices and comply with local laws. Note: This roundup is for informational purposes only and does not constitute legal advice.
Sources
- Healthcare Privacy Leaders Look to AI to Improve Monitoring and Data Breach Investigations - MedCity News — MedCity News
- South Korea’s President Lee Jae Myung orders thorough probe into data breaches at local banks — DataBreaches.net
- Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data — DataBreaches.net
- Italy’s Data Protection Authority fines IQVIA €7 million over data protection breach — DataBreaches.net
- ShinyHunters hacker “Rey,” allegedly involved in FBI data theft, detained in Jordan — DataBreaches.net
- DHS readies major cyber contract — DataBreaches.net
- OpenAI faces California DOJ subpoena amid growing cybersecurity incident notices — DataBreaches.net
- Marin County residents concerned after report reveals Flock cameras data breach - NBC Bay Area — NBC Bay Area
- Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus — The Record
- Bipartisan backlash to ALPRs grows as two high-profile bills are introduced — The Record
More articles
- PrivaScan Weekly Privacy Roundup: Healthcare Fines, Cloud Misconfigurations, and EU AI Recruitment Rules 28 Sep 2026
- Weekly Privacy Roundup: AI Agent Breaches, ePrivacy in Email Tracking, and Shifting Notification Laws 21 Sep 2026
- Weekly Privacy Roundup: Cookie Banner Debates, Regulatory Updates, and Key Breach Lessons 14 Sep 2026