#Privacy Violation

Every story tagged Privacy Violation, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

15 stories · open in the command center

  • Security & PrivacyHacker News3m

    Footage Shows Cop Stalking Woman After Surveilling Her with a LPR

    A Florida police officer abused law enforcement access to license plate reader databases and vehicle registration systems to stalk a woman he met on a TV set, demonstrating a critical vulnerability in how police surveillance tools are governed and monitored. This incident exposes significant risks to organizational data governance, insider threat management, and the potential liability IT organizations face when access controls and audit trails for sensitive law enforcement databases are inadequate. IT leaders must urgently reassess access controls, logging mechanisms, and monitoring systems for sensitive databases to prevent misuse and ensure compliance with data protection regulations.

  • Security & PrivacyHacker News3m

    Dutch suicide prevention website shares data with tech companies without consent

    A Dutch suicide prevention hotline inadvertently violated GDPR by sharing sensitive visitor metadata (location, device, browsing history, and screen recordings) with Google and Microsoft without explicit user consent, exposing vulnerable individuals' digital footprints to third-party profiling. This incident highlights critical compliance risks for organizations handling health-related data and demonstrates how default tracking implementations can create significant privacy and regulatory violations, even when substantive conversation data remains protected. IT leaders must urgently audit their analytics and measurement tools to ensure proper consent mechanisms, data minimization practices, and vendor compliance, particularly for sensitive use cases.

  • Security & PrivacyTechMemeDavid Shepardson2m

    GM agrees to pay $12.75M to resolve a California investigation into claims that it illegally sold the location and driving data of OnStar subscribers to brokers (David Shepardson/Reuters)

    General Motors agreed to pay $12.75 million to California regulators after allegedly selling OnStar subscriber location and driving data to third-party brokers without proper authorization, highlighting critical data governance and privacy compliance risks for connected device manufacturers. This settlement underscores the growing regulatory scrutiny and financial exposure IT organizations face when managing customer data, particularly regarding unauthorized data monetization and inadequate consent mechanisms. Technology leaders must reassess data handling policies and third-party data sharing agreements to avoid similar regulatory penalties and reputational damage.

  • Security & PrivacyAndroid PoliceAndy Boxall2m

    The smartglasses privacy situation just keeps getting worse

    Smartglasses equipped with cameras are enabling non-consensual recording and covert surveillance, exemplified by incidents where users record and monetize videos of unsuspecting women—creating serious legal, reputational, and regulatory risks for organizations. The ease of circumventing recording indicators and inconsistent platform moderation creates liability exposure and threatens enterprise adoption of wearable technology. IT leaders must urgently address policy frameworks, security controls, and employee guidelines around smartglasses to mitigate legal risks and protect organizational reputation.

  • Security & PrivacyHacker News3m

    US healthcare marketplaces shared citizenship and race data with ad tech giants

    Nearly all U.S. state health insurance marketplaces inadvertently shared sensitive personal data—including citizenship status, race, and family incarceration details—with major ad tech companies through misconfigured tracking pixels, affecting over seven million Americans and exposing critical gaps in data governance practices. This breach highlights systemic risks in how government and healthcare organizations manage third-party integrations and underscores the urgent need for IT leaders to audit tracking technologies, enforce strict data handling policies, and implement technical controls to prevent sensitive information leakage to external vendors. The incident carries significant regulatory, reputational, and compliance risks, particularly as healthcare privacy regulations tighten and government agencies face increased scrutiny over citizen data protection.

  • Security & PrivacyTechCrunchZack Whittaker2m

    US healthcare marketplaces shared citizenship and race data with ad tech giants

    Nearly all 20 U.S. state healthcare marketplaces inadvertently shared sensitive personal data—including citizenship status, race, and incarceration information—with major ad tech companies through misconfigured pixel trackers, affecting over 7 million Americans and creating significant compliance and reputational risks. This incident exposes critical gaps in data governance and third-party vendor management within government IT systems, requiring urgent audits of tracking tools deployed across sensitive platforms. IT leaders must immediately assess their own healthcare and government-facing applications for similar vulnerabilities, as regulatory scrutiny and potential litigation exposure will intensify.

  • Security & PrivacyHacker News3m

    City Learns Flock Accessed Cameras in Children's Gymnastics Room as a Sales Demo

    A surveillance camera vendor (Flock Safety) accessed sensitive locations including children's facilities in a municipal contract without explicit notification, raising critical governance and privacy concerns despite claiming proper authorization. This incident exposes significant risks in vendor access management, data governance frameworks, and the need for transparent oversight of surveillance technology deployments—even when technically authorized. IT leaders must reassess vendor access controls, audit trails, and establish stricter policies around sensitive location monitoring to protect organizational reputation and stakeholder trust.

  • Security & PrivacyHacker News3m

    Police Have Used License Plate Readers at Least 14x to Stalk Romantic Interests

    Law enforcement has misused automated license plate reader (ALPR) technology at least 14 times to track romantic interests, revealing critical governance gaps in surveillance systems and raising urgent questions about access controls and audit mechanisms for sensitive technologies. This incident underscores the necessity for IT organizations to implement robust role-based access controls, comprehensive audit logging, and behavioral analytics on high-risk systems—particularly those handling personally identifiable information or capable of mass surveillance. For CIOs, this represents both a compliance risk and a reputational threat, demanding immediate review of data governance policies and implementation of multi-factor authentication and segregation of duties for sensitive law enforcement databases.

  • Security & PrivacyArs TechnicaScharon Harding2m

    Meta cuts contractors who reported seeing Ray-Ban Meta users have sex

    Meta terminated its contract with data annotation contractor Sama after workers reported viewing explicit and private footage recorded by Ray-Ban Meta smart glasses, raising critical data privacy and consent concerns that have triggered regulatory investigations and a class-action lawsuit. This incident exposes significant risks in AI training data collection practices and the inadequacy of current privacy safeguards in consumer devices, particularly when third-party contractors handle sensitive user-generated content. For IT organizations, this underscores the urgent need to strengthen vendor management protocols, implement robust data handling controls, and ensure transparent user consent mechanisms—or face regulatory penalties, reputational damage, and litigation.

  • Security & PrivacyHacker News3m

    LinkedIn scans for 6,278 extensions and encrypts the results into every request

    LinkedIn is actively scanning users' browsers for 6,278+ extensions and linking this detailed software inventory to verified professional identities without disclosure or consent, enabling inferences about job searching, personal beliefs, and organizational security posture. This practice represents a significant privacy and security risk that extends beyond LinkedIn through data-sharing ecosystems, potentially exposing employees' digital footprints to reveal competitive intelligence about their employers. Technology leaders should recognize this as a systemic fingerprinting problem that affects organizational security, employee privacy, and compliance obligations, while setting precedent for how platforms monetize behavioral data at scale.

  • Security & PrivacyHacker News3m

    Meta in row after workers who saw smart glasses users having sex lose jobs

    Meta terminated a major AI training contract with outsourcing firm Sama affecting 1,108 Kenyan workers shortly after they publicly disclosed viewing intimate content captured by Meta smart glasses users, raising serious concerns about data privacy, worker safety, and regulatory compliance. The incident has triggered investigations by UK and Kenyan data protection authorities and highlights critical risks around AI training workflows, vendor management, and the handling of sensitive personal data—issues that demand immediate attention from IT leadership responsible for third-party AI infrastructure. CIOs must urgently reassess vendor contracts involving sensitive content review, implement robust privacy-by-design frameworks, and establish clear governance policies for human-in-the-loop AI systems to avoid similar regulatory, reputational, and legal exposure.

  • Security & PrivacyThe VergeGaby Del Valle2m

    You can get dragged into a police investigation by proximity alone — for now

    The Supreme Court is deciding whether police can use 'geofence warrants' to access location data from tech companies without identifying a specific suspect, potentially allowing mass surveillance based on proximity alone. A ruling against warrant protections could expose all employees and customers to involuntary inclusion in criminal investigations through data held by third parties like Google, Uber, and Snap, fundamentally altering privacy expectations for location-aware services. IT organizations must prepare for either scenario: stricter data retention and access controls if warrants are required, or expanded law enforcement requests if geofence searches are deemed constitutional.

  • Security & PrivacyTechCrunchZack Whittaker2m

    US Supreme Court appears split over controversial use of ‘geofence’ search warrants

    The Supreme Court is reviewing the constitutionality of geofence search warrants in Chatrie v. United States, which could reshape law enforcement's access to location data from tech companies and redefine digital privacy standards. This landmark Fourth Amendment case addresses whether law enforcement can compel companies like Google to disclose location information for broad geographic areas without establishing probable cause for specific individuals, a practice that has surged thousands of times annually since 2016. CIOs and technology leaders face potential operational, compliance, and reputational impacts depending on the Court's ruling, which could either validate current law enforcement data-sharing practices or require significant changes to how companies handle location data requests.

  • Security & PrivacyHacker News3m

    Period tracking app has been yapping about your flow to Meta

    A period tracking application has been discovered sharing sensitive health data with Meta, exposing significant privacy and compliance risks for users and raising critical questions about third-party data handling practices. This incident underscores the urgent need for IT organizations to implement robust data governance frameworks, vendor security assessments, and privacy-by-design principles across all applications—particularly those handling sensitive personal health information that may trigger HIPAA, GDPR, or state privacy law violations.

  • Security & PrivacyHacker News3m

    Surveillance vendors caught abusing access to telcos to track people's locations

    Security researchers have exposed widespread abuse of telecom infrastructure vulnerabilities by surveillance vendors who exploit outdated protocols (SS7 and Diameter) to track individuals' locations globally, with evidence pointing to coordinated campaigns involving compromised cellular providers as entry points. This represents a critical infrastructure security gap that extends beyond traditional IT boundaries, requiring CIOs to reassess their organization's exposure to telecom-dependent services and potential location data vulnerabilities. The findings highlight that enterprises relying on cellular networks for operations or employee tracking face significant risks from both nation-state actors and commercial surveillance vendors abusing legitimate telecom access.

Browse all tags