Privacy
Google fined $462M in Ireland as BYD scrubs China from privacy policy
Google owes Ireland $462M over location tracking, BYD quietly rewrites its Australian privacy policy, and cheap smart glasses leak user data.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Ireland fines Google $462M over location data tracking
Ireland’s Data Protection Commission fined Google €403 million, about $462 million, for collecting users’ location data in breach of GDPR. The probe, opened in 2020, covered three features: Web & App Activity, Timeline and Google Location Accuracy, and examined data collected between May 25, 2018, when GDPR took effect, and Feb. 4, 2020. Regulators found Google breached GDPR’s lawfulness, fairness and transparency principle, which requires firms to detail what personal data they collect and how long they keep it. Alongside the fine, the DPC ordered Google to bring its data collection practices into compliance within six months. Google said the case concerns historical policies it has since updated, citing changes made from 2019 onward.
Google fined $462M in Ireland over location data collection practices - SiliconANGLE →
BYD removes China and surveillance references from Australian privacy policy
BYD deleted references to China and surveillance from its Australian privacy policy days after questions from Four Corners. The original text let the company collect data on Australian vehicle owners and disclose it in connection with suspected illegal or improper activities through surveillance activities, and named China among 16 countries receiving Australians’ data. UNSW privacy law expert Katharine Kemp called the wording highly concerning. BYD said the policy had undergone a review and been updated; the new version was uploaded to its Australian website about an hour before the company sent it to Four Corners. BYD, which has sold cars in Australia since 2022 and is on track to sell roughly 100,000 this year, said it has not and would not transfer Australians’ data to Chinese authorities.
Cheap AI smart glasses found leaking user data to China
Independent testing for ABC News found more than a dozen serious vulnerabilities in ultra-cheap AI smart glasses sold in Australia, letting an attacker take control of the glasses and stored images using only Bluetooth. Researcher David Crees of NSB Cyber and Abstract Shield said the glasses have no password, so anyone with the same app can log in. The two pairs tested cost $60 from Temu and $110 from importer BDI Technology via Big W Marketplace, and similar models rely on the same HeyCyan app. Testing also found Australian user data sent to a server in Shenzhen, then possibly onward, with the policy naming only Singapore. University of Sydney specialist Kimberlee Weatherall said the flaws likely breach the Privacy Act, consumer law and the Cyber Security Act. Some flaws were patched after the ABC shared findings, but most remained.
Ultra-cheap smart glasses leaving Australians’ personal data exposed to hackers →
OECD study: US employers punish workers with software 16 times more than Europe
New OECD research covering more than 6,000 firms across six countries found U.S. employers are far more likely than European counterparts to use workplace software that punishes poor performance, a gap researchers attribute to law rather than technology. Sanctioning software is used by 67% of U.S. firms versus 4% in France, Germany, Italy and Spain combined, and 1% in Japan. U.S. firms typically run ten or more tracking and evaluation functions, while European firms average three to five. U.S. employers track work speed at 72% versus 15% in Europe, and monitor call, email and message content at 55% versus 6%. EU rules require informing and consulting worker representatives before rollout; U.S. labor law requires bargaining only in narrower circumstances.
U.S. Employers Use Software To Punish Workers At 16 Times More Than Europe Does →
WebRTC browser flaw can expose real IP addresses even through a VPN
WebRTC, built into most modern browsers and enabled by default, lets browsers establish direct peer-to-peer connections using a user’s public IP address for video calls, voice calls, live streaming and screen sharing. To do so it bypasses a VPN’s encrypted Transmission Control Protocol tunnel using User Datagram Protocol, which forgoes safety for speed, leaving the real IP address exposed for the duration of the transmission and giving attackers time to capture identifying information. WebRTC stays enabled even in Incognito Mode and while a VPN runs. VPN providers are adding leak prevention through firewalls and kill switches, but it often requires manual configuration. Firefox is the only major browser that disables WebRTC outright without extensions, by setting media.peerconnection.enabled to false via about:config, which breaks sites including Google Meet and Discord.
Even a VPN Can’t Protect You From This Browser Security Flaw →