Privacy
Denmark CPR Breach Exposes 8.8 Million Records
Denmark calls the population register breach extremely serious, Seattle bans data-driven grocery pricing, and Raleigh weighs driverless patrol cars.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Denmark’s Central Population Register breached, 8.8 million affected
Danish authorities are responding to what the Ministry of Science, Higher Education, Research and Digital Affairs calls an extremely serious incident after unknown perpetrators accessed the Central Population Register, known as CPR. The data included names, addresses, CPR numbers and other information belonging to around 8.8 million registered individuals. Minister Christina Egelund said authorities are working to establish the full extent of the breach, which remains unclear. Initial findings suggest the system was accessed through the legitimate login credentials of a Danish company. The register holds data on roughly 11 million people, including current residents, deceased individuals and people who have moved abroad, and also stores Church of Denmark membership and details of legal incapacitation.
Data breach hits Denmark’s population register, affecting 8.8 million →
Seattle bans personalized grocery pricing based on personal data
Seattle Mayor Katie Wilson signed the Fair and Transparent Pricing ordinance on Monday, barring large grocery chains and delivery services from using personal data to set individual grocery prices. The ban covers browsing history, location, employment status, race, gender, social media activity and chatbot conversations. The City Council passed the measure last month and it takes effect Sept. 1, 2027. It applies to retailers with at least 20 locations worldwide, including online delivery, while smaller chains, convenience stores and farmers markets are exempt. Traditional coupons and transparent discounts remain allowed. Industry groups warn the line between prohibited data-based pricing and voluntary loyalty programs is unclear, and say discounts could be at risk. A 2025 Consumer Reports investigation found algorithmic pricing could produce differences of as much as 23% for the same groceries.
Seattle mayor signs grocery law banning pricing differences based on personal data →
Raleigh police weigh autonomous patrol cars with cameras and drones
Raleigh police are exploring autonomous patrol vehicles that could monitor city streets, raising questions about surveillance, data collection and oversight. The department confirmed that Policing Lab, the nonprofit developing the technology, presented its concept to command staff in February. The vehicle follows predetermined routes and carries 360-degree cameras, license plate readers and facial-recognition-capable technology; the version tested in Miami-Dade County can also launch a drone and has thermal imaging. Raleigh police say they are still gathering information and have announced no pilot, purchase or deployment. Criminology professor Angelo Brown said safeguards should be set before rollout, including limits on footage retention and access, and warned more routine patrols do not necessarily reduce crime. The department did not answer questions on data collection, storage or privacy protections.
Texas suburb quotes $2.3M for records on Flock camera use
North Richland Hills, a Fort Worth suburb, told a privacy group it would cost $2.3 million to release records on how its police use Flock license plate cameras, estimating 14 years of labour at $15 an hour to search about a terabyte of communications. Other Texas agencies responded differently: Sealy charged nothing, Irving asked $70,000 for records Carrollton released free, and Houston station KPRC was quoted $121,000. Texas has about 13,000 Flock cameras. An audit prompted by a USA Today request found a Lufkin officer searching databases about his former girlfriend and her family; Zachary Anthony Klein pleaded guilty on 30 September to 100 felony counts and drew five years. A federal judge in Oklahoma ruled last week that a warrantless Flock search was unconstitutional mass surveillance.
Texas city wants $2.3M for public records on police Flock use →
Why AI redaction still exposes the sensitive data it removes
A redaction model must read sensitive data before it can remove it, so routing text through an AI redactor still exposes the original values to another system, argues a HackerNoon piece. Several major providers offer terms under which customer inputs are not used for training by default, but training is only one question; the relevant test is whether the system needs the original sensitive value at all. Much sensitive data is structured and can be detected deterministically: credit card numbers have Luhn checksums, Indian Aadhaar numbers use Verhoeff logic, and IBANs have MOD-97 validation. The preferred pipeline is candidate detection, structural validation, checksum validation, context checks, then redaction. For private keys, credentials or financial identifiers, blocking the request may be preferable to redacting it. The approach was packaged as PII Firewall Edge, covering 152 categories of sensitive information.
Why I Don’t Use AI to Remove PII Before Sending Data to AI | HackerNoon →