Implications of data breach at Uber

Yet another important data breach: this time revealed late. Uber has amitted that in 2016, information about 57 million users and drivers was stolen. Instead of disclosing the incident when it was discovered, senior executives decided to pay a ransom of $100 000 to delete the stolen data. Data privacy regulators in the US, UK, and Italy have decided to investigate and a class-action law suit has been filed in California against the company. Uber's action is likely to have an effect on other digital service providers. Sensitivity to the issues is increasing both among customers and among regulators wo are likely to favour robust measures. The implementation of GDPR in Europe next May will have a substantial impact on business. The International Association of Privacy Professionals and EY estimate than members of the Fortune 500 will spend a combined $7.8 billion on compliance measures. And there is more to come: an expanded Regulation on Privacy and Electronic Communication (ePrivacy Regulation), which will replace the 2002 ePrivacy Directive, will supplement GDPR withadditional reules targeted at electronic communication services, the use of cookies, online behhavioural advertising, direct marketing, and machine-to-machine communication (the "internet of things").
IADS is launching an Innovation Lab on Cybersecurity and Risk Management next March
innovation lab on cybersecurity
