Privacy
French Hospital Fined €500,000 Over Breach of 727,000 Records
CNIL fines Hôpital privé de la Loire for security lapses after a hacker stole data on over 727,000 patients and relatives.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
French Hospital Fined €500,000 Over Breach of 727,000 Records
France’s data protection authority, CNIL, has fined Hôpital privé de la Loire (HPL) €500,000 for failing to adequately protect patient data, leading to a summer 2025 breach that exposed sensitive information belonging to 524,867 patients and 202,246 trusted third parties. The Saint-Étienne hospital, part of the Ramsay Santé group, was found to have violated GDPR Articles 32 and 34 after an attacker accessed its electronic patient record system and extracted data over several days without detection.
French hospital fined €500,000 after breach exposes data of 727,000 →
CNIL Details Security Failures Behind Hospital Data Theft
The CNIL investigation found that external users, including private-practice physicians, could access the system without a VPN or multi-factor authentication, and inadequate access controls allowed a compromised account to view records for all hospital patients. The hospital also lacked real-time monitoring and alerting, enabling the attacker to explore the system undetected. A teen hacker using the alias Marak claimed responsibility, saying the attack began with a breach of a single doctor’s account, and attempted to sell the data for between €2,000 and €5,000, though it was reportedly neither sold nor published.
French hospital fined €500,000 after breach exposes data of 727,000 →
Hospital Penalized for Failing to Notify All Breach Victims
Beyond the security failures, CNIL noted that HPL informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen. The hospital took several security strengthening measures during the proceedings, which the committee acknowledged. The fine, equivalent to $580,000, underscores the GDPR’s requirements for robust access controls, monitoring, and breach notification, and serves as a warning to healthcare providers handling sensitive data.
French hospital fined €500,000 after breach exposes data of 727,000 →
ICE Gave New Hires Access to Palantir App Before Background Checks
The ELITE app, created by Palantir, was introduced on ICE deportation officers’ phones during a winter immigration enforcement surge in Minneapolis, and thousands of new hires were able to work without cleared background checks, according to whistleblowers and former DHS officials. ELITE, which stands for Enhanced Lead Identification and Targeting, helps ICE target immigrants, produces dossiers, and maps locations, and is standard on every deportation officer’s phone. The expedited hiring surge added over 12,000 employees with cuts to training, and new officers receive ELITE as one of their first applications, even without full background clearance.
ICE Gave New Hires Access to Restricted Info on Palantir App Before They Passed Background Checks →
Privacy Experts Warn ICE’s ELITE App Lacks Required Oversight
Mary Ellen Callahan, former DHS chief privacy officer, said no one should have been hired before background reviews were completed, and that ELITE did not go through the usual process government tools undergo to prevent abuses. The DHS privacy office has not published a privacy impact assessment (PIA) for ELITE, despite a 2002 law requiring one for new technology that collects personally identifiable information. The linked assessment on DHS’s site is a 2019 PIA for a different database, and privacy lawyer Clare Garvie said the failure to conduct a proper PIA is not a technicality, undermining confidence in the tool’s lawful use.
ICE Gave New Hires Access to Restricted Info on Palantir App Before They Passed Background Checks →
ICE Officers Without Clearance Still Using ELITE Nearly a Year Later
Five ICE officials working in different regions told The Intercept that deportation officers without completed background checks continue to work in all their jurisdictions, some hired nearly a year ago. One officer expressed concern that ELITE is used on illegal immigrants now but could easily be used on Americans. The app’s user guide identifies a dozen data sources, including addresses, criminal histories, and immigration records, much of which constitutes PII. Neither DHS nor Palantir responded to requests for comment, and the lack of a PIA raises national security and civil liberties concerns.
ICE Gave New Hires Access to Restricted Info on Palantir App Before They Passed Background Checks →
Federal Judges’ Home Addresses Still Exposed Despite Privacy Law
A report dated Sept. 1 found that home addresses for all 100 federal judges examined remain widely available online, despite the Daniel Anderl Judicial Security and Privacy Act designed to protect them. Researchers located addresses even for judges enrolled in the judiciary’s vulnerability management program, and found them on data broker websites listed as audited by DeleteMe, the federal vendor for removal. The report, led by Matthew Adkisson of Atlas Data Privacy Corp. and co-authored by former US Marshals chief inspector John Muffler, concluded the federal law is falling short compared to New Jersey’s Daniel’s Law, which allows private lawsuits to force data brokers to remove information.
US Judges’ Addresses Exposed Despite Privacy Law, Report Says →
Report: Federal Judicial Privacy Law Lacks Enforcement Teeth
The federal law, passed nearly four years ago, prohibits data brokers from knowingly selling certain personal information about federal judges and their families, but enforcement is left to designated officials, and no federal enforcement litigation has been filed. In contrast, the New Jersey law has generated 184 lawsuits. The report found that on websites audited by DeleteMe, nearly a third disclose the average judge’s address, and on non-audited sites, the average judge appears on more than half. The Marshals Service tracked 564 threats against federal judges last fiscal year, up from 403 three years prior, and Judge Esther Salas, whose son’s death inspired the laws, called the report alarming but not surprising.
US Judges’ Addresses Exposed Despite Privacy Law, Report Says →
Judges’ Address Exposure Rate Higher Than State Officers’
The exposure rate for federal judges on audited websites was higher than for state officers who have worked with Atlas to have their information removed: 10.5% of audited websites and 19.7% of non-audited websites contained the average state officer home address, compared to higher rates for federal judges. The report said silence is not compliance, and the federal Act’s silent public enforcement record is not a sign of a job done but of a right no one visibly enforces. Adkisson hopes the report drives conversation and builds consensus on shoring up security protections for judges, while the Administrative Office of the US Courts declined to comment.
US Judges’ Addresses Exposed Despite Privacy Law, Report Says →
Australia Proposes Consent Requirement for Ad Tech Pixel Sharing
Australia’s Attorney-General’s Department opened consultation on an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, which would make consent a precondition for disclosing personal information for direct marketing, including cookies or pixels in programmatic advertising. The bill, running to six schedules and 54 pages, contains roughly 40 proposals from the Privacy Act Review, and consultation closes on 18 September 2026. A new Australian Privacy Principle 4.2 would prohibit trading personal information without consent unless an exception applies, with four carve-outs including disclosures necessary for providing a requested service and controller-to-processor transfers.
Australia would force ad tech to get consent before sharing pixels →
Australia’s Draft Privacy Bill Defines Trade in Personal Data
The bill would define trade in personal information as disclosure for money or other consideration or for direct marketing purposes, capturing disclosures that support or inform marketing even where not the sole purpose. Direct marketing would cover emails, text messages, telemarketing calls, targeted social media advertising, and online behavioural advertising, including cohort-level targeting built from personal information. Where multiple entities are involved, the platform will generally carry the opt-out requirement unless it acts solely as a processor, and each communication must carry opt-out information in clear and plain language.
Australia would force ad tech to get consent before sharing pixels →
Australia’s Privacy Overhaul Targets Dark Patterns and AI Inferences
The draft bill would require consent to be voluntary, informed, current, specific and unambiguous, with bundled consent and pre-ticked boxes likely not meeting the standard. A new APP 3 would prohibit collection, use, or disclosure of personal information unless fair and reasonable, considering factors like genuine choice and privacy impact, with dark patterns influencing choice as a negative factor. The definition of personal information would expand to include information that allows a person to be recognised or singled out, and AI-generated inferences would count as collection, with derived sensitive information triggering collection at the moment of derivation.
Australia would force ad tech to get consent before sharing pixels →
Australia’s Privacy Bill Adds Geolocation and Biometric Protections
The draft bill would add precise geolocation tracking data, genomic information, and biometric templates to the definition of sensitive information, with geolocation defined as identifying a location within a radius of 500 meters. Disclosure would receive a statutory definition for the first time, excluding mere transmission or storage unless information is made accessible. The bill also addresses ad-supported services, allowing organisations to offer different terms when an individual opts out of direct marketing, provided there is a genuine choice, drawing on UK and EU consent or pay guidance, but setting no price ceiling or equivalence test.
Australia would force ad tech to get consent before sharing pixels →