HeadFlash

Privacy

TikTok Pays £12.7m UK Child Privacy Fine as EU Warns on Quantum Threat

TikTok drops its appeal and pays a £12.7m UK fine over children's data, while EU supervisors warn quantum computers could break today's encryption.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

TikTok Pays £12.7m UK Fine Over Children’s Data After Dropping Appeal

TikTok will pay a £12.7m fine from the UK Information Commissioner’s Office over its handling of children’s data, after withdrawing its appeal and making the 2023 penalty final. The ICO estimated up to 1.75 million British children under 13 used TikTok in 2020, despite rules barring their accounts, and found the platform failed to run adequate checks to identify and remove underage users or obtain parental consent. TikTok says it disagrees with the decision but notes the findings cover May 2018 to July 2020. The withdrawal also clears the way for the ICO to resume a separate investigation into how TikTok’s recommender systems use teenagers’ data.

Tiktok to pay £12.7m UK child privacy fine despite disputing watchdog findings →

Florida Rep. Steube Introduces FLAFO Act to Require Warrants for License Plate Surveillance

U.S. Representative Greg Steube, a Florida Republican, introduced the FLAFO Act to block federal agencies from using networked license plate readers without a court warrant. The bill targets automated license plate reader systems that log plates, vehicle models, colors and travel locations into searchable databases. Federal agencies could not buy, lease, run or access covered ALPR data without judicial approval, and Department of Justice grants to state, local and tribal police would depend on similar privacy rules. Narrow exceptions cover missing persons, imminent threats, terrorism and foreign espionage, plus specific Secret Service, Customs and Border Protection, and national security operations. Penalties include up to five years in prison and $100,000 civil fines.

No Warrant, No Tracking: Florida Rep. Steube’s New Bill Takes Aim At Flock Safety Surveillance Networks →

InterSecLab Finds Russia’s Max Messenger Can Vary Surveillance Per Account

Researchers at digital security lab InterSecLab found that Russia’s state-backed Max messenger has broad tracking capabilities whose configuration can vary per account and is controlled by developer VK. Over nine weeks, researchers observed real accounts, intercepted network traffic before encryption and checked the app’s code. Max has no end-to-end encryption, and VK can read correspondence; so-called secret chats are simply deleted on a timer. Max can decrypt voice messages on VK servers, block sending when a VPN is detected, collect in-app activity data and share identity information with third parties. It uploads entire address books unencrypted, and each launch reports IP address, carrier, VPN activity and service availability to VK.

Russia’s state-backed messaging app Max can secretly change how it surveils individual users, researchers at InterSecLab find — Meduza →

EU Data Chief Warns Digital Omnibus Could Weaken Worker Data Safeguards for AI

European Data Protection Supervisor Wojciech Wiewiórowski has joined trade unions and privacy activists in warning that the EU’s Digital Omnibus could allow data harvesting from workers without permission to feed AI models. He told EUobserver he is very concerned the text would remove all references to additional safeguards, including the unconditional right to object. A leaked proposal, set for technical discussion on 25 September in the EU Council, would amend Article 88 of the GDPR, now renamed 88bis, to state that processing personal data in developing and operating an AI system or model may be carried out for a legitimate interest of the controller.

EU data chief adds voice to unions’ fears of ‘carte blanche’ use of workers’ data for AI →

EU Financial Supervisors Warn Q-Day Could Arrive Before Quantum Computing Is Commercially Useful

The EU’s three financial supervisors warned in their autumn risk assessment that an advanced quantum computer could undermine cryptography securing communications, transactions, databases and blockchains, possibly earlier than any viable commercial application. The joint committee of the EBA, EIOPA and ESMA highlighted the harvest-now-decrypt-later risk, meaning data intercepted today could be decrypted later. The Digital Operational Resilience Act requires state-of-the-art cryptography, and the NIS Cooperation Group recommends member states adopt a post-quantum migration strategy by end-2026. Glassnode found in May that 6.04 million BTC, 30.2% of issued supply worth over $469 billion at the time, had public keys visible on-chain. Q-Day estimates run from 2030 to 2032 and later.

Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Warns →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches