France’s data protection authority, the Commission nationale de l’informatique et des libertés, published a fictitious case highlighting the risks of unsecured access to data held by subcontractors. The CNIL outlined a data breach in which a hacker pretended to be a known customer of a company and was able to access data through an employee’s stolen account. The CNIL outlined how to react, proper notification to the authority and affected individuals, and how to limit risks.Â
Full story