California regulators have announced a major privacy settlement with General Motors (GM) over allegations that the company unlawfully sold the location and driving data of hundreds of thousands of Californians to two data brokers: Verisk Analytics and LexisNexis Risk Solutions.
Data Privacy + Cybersecurity Insider
Leveraging Knowledge to Manage Your Data Risks
Data Privacy + Cybersecurity Insider, published by Robinson & Cole LLP, focuses on legal developments and issues related to data privacy, cybersecurity, and information security. The blog covers topics such as data breaches, regulatory enforcement actions, privacy litigation, law enforcement access to digital data, AI governance and risks, and the implications of forum selection clauses in privacy class actions. It also addresses emerging challenges in technology law including blockchain security vulnerabilities, cross-chain bridge incidents, and the evolving standards for protecting personal and sensitive information in various contexts.
Latest from Data Privacy + Cybersecurity Insider - Page 10
When an AI Chatbot Calls Itself a Doctor
Pennsylvania’s lawsuit against Character Technologies, Inc., is a notable early test of how professional licensing laws may apply to consumer-facing AI chatbots. The Commonwealth, acting through the Department of State and State Board of Medicine, filed a Petition for Review…
Privacy Tip #491 – ShinyHunters Hit Zara
According to HaveIBeenPwned, ShinyHunters targeted fashion brand Zara in a cyber-attack and claimed that it had stolen 197,000 unique email addresses, product SKUs, order IDs, and the originating market. The incident involved a former technology provider (AI analytics platform…
ShinyHunters Target Medical Device Company Medtronic
Global medical device company Medtronic recently confirmed that it had been attacked by the threat actor group, ShinyHunters. According to Bleeping Computer, Medtronic is “the largest medical device maker in the world by revenue ($33.5 billion) and also develops…
CISA Warning: Firestarter Malware Persists in Cisco Devices
The Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) have confirmed that threat actors are using FIRESTARTER malware to maintain persistence on Cisco network devices, allowing the threat actors to maintain access even after…
No Standing in the Parking Lot: Court Dismisses DPPA Suit
The Driver’s Privacy Protection Act (DPPA) may not draw as much regular attention as statutes like the VPPA, CCPA, or TCPA, but it remains a source of privacy litigation risk where motor vehicle record information is involved. The DPPA is…
From Future Requirement to Present Risk: California Privacy Audit Readiness
California companies may have less time than they think to prepare for privacy audits. The California Privacy Protection Agency’s (CPPA) new Audits Division, created in February 2026, is expected to begin assessing companies’ compliance with the California Consumer Privacy Act…
Privacy Trends Fashion, Beauty, and Wearable Tech Brands Need to Watch
Fashion, beauty, and wearable technology brands are heading into 2026 with a lot more to think about concerning data privacy. What used to feel like a back-end legal issue is now shaping how companies design products, personalize experiences, and build…
Privacy Tip #490 – Dating App Hijacks + Repurposes College Student’s TikTok Video
In the category of how technology can be fun, yet dangerous, a 19 year old college student alleges that the dating app Meete took a video she innocently posted on TikTok of her high school graduation, then “overlayed it with…
Phishing Now Top Method for Initial Unauthorized Network Access
According to Cisco Talus researchers, phishing is the primary method threat actors use to gain unauthorized access to networks, accounting for more than one-third of all incidents in the first quarter of 2026. This increase is attributed to threat actors…