Site icon Privacy Desk

Issue 97

Enforcement updates

SEC issues fine for USD 10 Million for misrepresenting alternate data

The Securities and Exchange Commission (SEC) has fined USD 10 million on the app Annie Inc., as securities fraud charges for making material misrepresentations about how the alternative data was derived. Annie is a leading alternative data provider for the mobile app industry. Alternate data, such as estimates on the number of times an app is downloaded and how often it’s used, was agreed not to be disclosed to third parties. Contrary to these undertaking, the app used non-aggregated and non-anonymized data to alter its model-generated estimates for making them more valuable to sell to trading firms and thus have been held in violation.

T-Mobile faces privacy investigation in Massachusetts

T-Mobile, an international wireless carrier is facing an investigation by the office of Attorney General Maura Healey. In July 2021, the company faced a massive breach of their computer network which resulted in data compromised of over 13.1 million current customers and 40 million former and prospective customers. The information breached included names, drivers license information, government identification numbers, social security numbers, addresses, and date of birth. The investigation has been launched to determine the steps taken to address the breach and notify the consumers, and to determine whether the company had proper safeguards in place to protect consumer information.

University fined for using non-compliant proctoring software

It is reported that the Italian Data Protection Authority, Garante has issued a fine of EUR 200 thousand on a University in Milan for using proctoring tools from the company ‘Respondus Inc’. The Luigi Bocconi University used proctoring tools to supervise written tests during the pandemic. It was reported that these systems are invasive and involve unnecessary monitoring of students. It was also held that the use of such technology for processing the biometric data of students for exams cannot be considered as a legal basis for processing under GDPR.

Reserve Bank of New Zealand served privacy compliance notice

The Reserve Bank of New Zealand faced a cyber-attack in December 2020. Upon the introduction of the Privacy Act 2020 and the powers bestowed on the Office of the Privacy Commissioner, a compliance notice has been issued on the Reserve Bank. The Privacy Act allows for the publication of compliance notices on a case-by-case basis if the Commissioner believes it is desirable to do so in the public interest. The compliance notice issued provides a template for the Bank to report, confirming the improvements made to policies and procedures to make the systems more secure and less prone to cyber-attacks.

Guidance updates

Regulatory updates

News around the globe

 Singapore updates

  International updates

 US updates

 India updates

Recent developments

Read our digital newsletter here.


© 2019 Reina Consulting LLP – All rights reserved

Exit mobile version