Latest report from international data protection and privacy authorities has identified credential stuffing as a significant and growing cyber threat to personal information. Credential stuffing is a cyber-attack method that exploits people’s tendency to use the same username and password combination across multiple online accounts. These attacks are automated and often in large scale, using stolen and legitimate credentials obtained from unrelated data breaches to access people’s accounts across websites. The report, published by a sub-working group of the Global Privacy Assembly’s International Enforcement Working Group (IEWG), including the ICO…
Read MoreTag: ICO
ICO fines facial recognition database company Clearview AI Inc more than £7.5m and orders UK data to be deleted
The Information Commissioner’s Office (ICO) has fined Clearview AI Inc £7,552,800 for using images of people in the UK, and elsewhere, that were collected from the web and social media to create a global online database that could be used for facial recognition. The ICO has also issued an enforcement notice, ordering the company to stop obtaining and using the personal data of UK residents that is publicly available on the internet, and to delete the data of UK residents from its systems. The ICO enforcement action comes after a…
Read MoreICO takes action against companies over predatory marketing calls targeting elderly, vulnerable people
The Information Commissioner’s Office (ICO) has announced fines totalling £405,000 to five companies responsible for over 750,000 unwanted marketing calls targeted at older, vulnerable people. The ICO also issued these companies with enforcement notices that require them to immediately stop making these predatory calls. After receiving complaints from the public and information from partner organisations, including Action Fraud, Trading Standards, the consumer group Which? and the call blocker provider trueCall, the ICO began investigating a number of companies that were calling people to sell insurance products or services for white…
Read MoreNew UK Information Commissioner begins term
John Edwards began his new role as UK Information Commissioner on Tuesday 4 January. Mr Edwards, who joins on a five year term, spent the past eight years as New Zealand Privacy Commissioner, and before that worked as a barrister. He succeeds Elizabeth Denham CBE, whose term as UK Information Commissioner ended last year. Mr Edwards said: “Privacy is a right not a privilege. In a world where our personal data can drive everything from the healthcare we receive to the job opportunities we see, we all deserve to have…
Read MoreICO invites comments on how it uses its powers to investigate, regulate and enforce
The Information Commissioner’s Office (ICO) has launched a consultation to gather the views of stakeholders and the public on how it regulates the laws it monitors and enforces. People will have 14 weeks to comment on three documents, which are all designed to give direction and focus to the organisations it regulates. The Regulatory Action Policy (RAP) updates the ICO’s 2018 policy and sets out the regulator’s general approach. It reinforces the ICO’s commitment to a proportionate and risk-based approach to enforcement, and it explains the factors taken into consideration…
Read More