Visualização de leitura

OnePlus 10T Is Out of Security Support: Should You Keep Using Yours?

OnePlus 10T security support has ended. Here’s how owners can check their patch level, understand the risks, and decide when to replace the phone.

The post OnePlus 10T Is Out of Security Support: Should You Keep Using Yours? appeared first on TechRepublic.

OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades

The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions.

The post OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades appeared first on TechRepublic.

Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices

Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data.

The post Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices appeared first on TechRepublic.

Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

Australia-India PACTS

Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.

The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.

The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.

Australia-India PACTS Built on Five Pillars

The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.

The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.

Australia-India PACTS Expands Critical Technology Collaboration

The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.

The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.

Australia-India Prioritises Cybersecurity

A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.

The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.

The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.

Australia-India PACTS Advances Digital Resilience

The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.

The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.

Defence Research and Governance Framework

The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.

Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.

The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.

With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.

Nearly 15,000 infected websites cleaned in SocGholish crackdown

We’re always happy to end the week with some positive news. A law enforcement action called Operation Endgame just delivered a major win against the long‑running SocGholish (aka FakeUpdates) operation.

SocGholish is a malware framework that has been active since at least 2017 and is best known for abusing hacked, legitimate WordPress sites to push fake browser and software updates to visitors. When a user clicks one of these convincing “update now” prompts, the malware opens a backdoor on the system, giving attackers initial access that is often used to deploy ransomware and other malicious software. The operation has been linked to the Russian cybercriminal group Evil Corp, previously associated with Zeus and Dridex malware, as well as major ransomware and money‑laundering schemes.

This week, Dutch police and the Public Prosecution Service, working with the Royal Canadian Mounted Police, FBI, German Federal Criminal Police Office, Europol, and Eurojust, struck directly at SocGholish’s infrastructure. As part of Operation Endgame, they took down 106 servers and domains and cleaned 14,971 infected WordPress sites that had been silently redirecting visitors into the FakeUpdates trap.

Investigators say they found exposed login credentials for around 1.4 million WordPress sites. To check whether any passwords associated with your email address have been exposed in a breach, use Malwarebytes Digital Footprint Scanner.

Dutch authorities also used their hacking powers to remove backdoors and malware from compromised sites and notified affected site owners, urging them to update WordPress, enable multi-factor authentication (MFA), and change passwords.

Authorities say the infected sites included everyday businesses such as restaurants and car garages, meaning visitors could have been exposed to malware simply by browsing trusted local websites.

The scale and intent matter here. Endgame is billed as the largest international operation against ransomware and cybercrime to date, and this SocGholish takedown specifically disrupts a key infection chain used by multiple ransomware groups. By breaking the link between thousands of everyday websites and a sophisticated malware‑as‑a‑service ecosystem, law enforcement has reduced the pool of future victims and increased the cost of operating for Evil Corp and its partners.

So, as you head into the weekend, here’s a malware story where the good guys actually pushed back and made it hurt.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

Ukraine Joins EU Cybersecurity Reserve

Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity providers. The move reflects ongoing EU-Ukraine cooperation on digital security and resilience amid evolving cyber threats.

Ukraine Joins EU Cybersecurity Reserve Under EU Cyber Solidarity Framework

The EU Cybersecurity Reserve was established under the Cyber Solidarity Act to help participating countries respond to significant cybersecurity incidents. Through the reserve, nations can request specialized assistance when their own incident response resources are overwhelmed. According to the European Commission, Ukraine will now be able to officially seek emergency European support if a cyberattack surpasses the capacity of its domestic response teams. This would allow cybersecurity experts from across the European Union to assist in incident containment and recovery efforts. The Commission described the decision as part of broader efforts to strengthen preparedness, improve rapid response capabilities, and encourage cooperation against growing cyber threats.

EU Highlights Digital Security Cooperation

Commenting on the development, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said Ukraine's inclusion strengthens collective cyber defenses and reflects the principle of solidarity at the core of Europe's digital future. The Commission noted that cyberattacks continue to present a persistent challenge and emphasized the importance of coordinated responses and shared expertise among partner nations. Ukraine's inclusion also aligns with the EU's strategic digital partnership agenda, which focuses on strengthening cybersecurity cooperation with neighboring countries.

Moldova Previously Granted Access

Ukraine becomes the second non-EU country to gain access to the reserve. Moldova was granted access in 2024 following an increase in Moscow-linked Cyber Threats and influence operations targeting the country. The Council's authorization for Moldova to use the reserve was described as a major step forward in regional cybersecurity cooperation. The arrangement was implemented under the Cyber Solidarity Act and formed part of broader EU-Moldova efforts to improve digital resilience. The European Commission stated that enhancing cybersecurity cooperation remains a key component of its partnership with Moldova.

Broader EU-Moldova Digital Cooperation Expands

Alongside cybersecurity initiatives, the European Union has expanded digital cooperation with Moldova in several strategic areas. The Commission welcomed a political agreement that will allow Moldova to join the EU Roaming Area under the "Roam Like at Home" framework following formal adoption. Once implemented, Moldovan citizens and EU travelers will be able to call, text, and use mobile data without additional roaming charges. Moldova has also joined the EU Third Countries' Trusted List, enabling easier validation of electronic signatures and seals between EU and Moldovan organizations, businesses, and citizens. To strengthen resilience against Disinformation and foreign interference, a new hub of the European Digital Media Observatory (EDMO) known as FACT has also been established with support from the European Commission.

Cyber Cooperation Advances as EU Membership Talks Progress

The cybersecurity announcement comes shortly after EU member states agreed to launch formal accession negotiations with both Ukraine and Moldova. European Commission President Ursula von der Leyen described the decision as a major milestone, stating that all member states had agreed to open the first accession negotiations cluster with the two countries. She said the move recognizes the reforms undertaken by Ukraine and Moldova despite significant challenges and reinforces the EU's commitment to peace, security, and stability across the region. With access to the EU Cybersecurity Reserve, Ukraine now gains an additional layer of support to strengthen its cyber resilience and coordinate responses to major cybersecurity incidents alongside European partners.

UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

UK social media ban

The UK government has announced plans to introduce a UK social media ban for under-16s, preventing children from accessing major platforms such as TikTok, Instagram, Snapchat, Facebook, YouTube and X under a sweeping package of online safety reforms. The measures, expected to be brought before Parliament later this year and enforced from Spring 2027, would make Britain one of the toughest countries in the world when it comes to regulating children's access to social media. The proposal is part of a wider government effort to strengthen online child safety and address growing concerns about the impact of social media algorithms, harmful content and excessive screen time on young users. Prime Minister Keir Starmer described the move as a "line in the sand," arguing that technology companies have failed to do enough to protect children online. "Parents want to keep their kids safe and happy, but the online world has made that harder than ever," Starmer said. "That's why we're going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back." UK Social Media Ban for Under-16s

UK Social Media Ban for Under-16s to Cover Major Platforms

The proposed UK social media ban for under-16s will apply to user-to-user platforms that allow users to interact and share content through algorithm-driven feeds. Platforms expected to fall under the restrictions include TikTok, Instagram, Snapchat, Facebook, YouTube and X. Messaging services such as WhatsApp and Signal are not expected to be included. Alongside the ban, the government plans to introduce new restrictions on features considered particularly risky for young users. These include livestreaming functions and communication between children and strangers across a wider range of digital services, including some gaming platforms. The government is also considering additional safeguards, including overnight access limits and measures designed to interrupt infinite scrolling for users under 18.

AI Chatbots Also Under Scrutiny

The reforms extend beyond social media platforms. Under the proposed rules, AI-powered "romantic companion" chatbots that simulate intimate or sexual relationships will be required to enforce a minimum age of 18. Similar intimate AI functions will also face restrictions for users under the age of 18. Officials say the broader approach reflects how children increasingly encounter online risks across multiple digital services rather than solely through social media platforms.

Global Momentum Builds Behind Social Media Age Restrictions

Britain's announcement comes amid growing international support for tighter social media age restrictions. Earlier this year, Spain announced plans to prohibit social media access for children under 16. Prime Minister Pedro Sanchez described the internet as a "digital Wild West" and said stronger protections were needed to shield young people from online harm. France has also moved in a similar direction. In February, French lawmakers approved legislation banning children under 15 from accessing social media platforms. The measure is expected to take effect at the start of the next school year. French President Emmanuel Macron strongly backed the proposal, stating that children's development should not be dictated by algorithms designed to maximize engagement. The developments have fueled debate over whether age-based restrictions could become a standard approach to child online protection across Europe and beyond.

Australia's Experience Highlights Enforcement Challenges

While support for restrictions is growing, Australia's experience shows that enforcement remains a major challenge. The Australia social media ban, introduced under Prime Minister Anthony Albanese, requires platforms to block users under 16 or face fines of up to AU$32 million. However, recent research suggests many children continue to access restricted platforms despite the rules. A study conducted by the Molly Rose Foundation and YouthInsight found that more than 60% of children aged 12 to 15 who previously used social media still had access to at least one account. The survey of 1,050 young people showed that 53% of former TikTok users, 53% of YouTube users and 52% of Instagram users remained active after the restrictions were introduced. Researchers also found evidence that some children created new accounts after the ban came into effect, raising questions about the effectiveness of current age verification systems.

Age Assurance Measures Key to Enforcement

To improve compliance, the UK government plans to introduce stronger age assurance measures and has tasked Ofcom with conducting a rapid review of age-verification technologies. The regulator will also review its enforcement capabilities, while ministers have pledged additional funding to support implementation of both the proposed regulations and existing provisions under the Online Safety Act. The announcement follows a national consultation that attracted more than 116,000 responses from parents, children and experts. According to government figures, nine in ten parents support a ban on social media access for children under 16. If approved, the reforms will mark one of the most significant changes to Britain's digital safety framework and could further accelerate a global shift toward stricter regulation of children's online experiences.

NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

Agentic AI Deployment

The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases, limiting system privileges, and maintaining strong human oversight throughout deployment. The advisory comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools, and carrying out actions with limited human involvement.

What Is Agentic AI?

Unlike traditional generative AI systems that primarily create text, images, or predictions, agentic AI systems are designed to independently pursue goals. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks. According to the NCSC, this added autonomy is what makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a wider attack surface and increases the difficulty of monitoring system behavior. The agency noted that many security risks linked to AI are not entirely new. Concerns around access control, supply chain security, monitoring, and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing large language model risks, including prompt injection and jailbreaking attacks. However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without proper safeguards.

Why Agentic AI Raises Security Risks

The guidance outlines several risks tied to agentic AI deployments. One of the main concerns is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not. The NCSC also highlighted the possibility of unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope. Another challenge involves visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in enterprise environments where multiple systems and workflows are interconnected. The guidance further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool usage, and autonomous actions creates additional complexity during incident investigations or compliance reviews.

NCSC Calls for Incremental Agentic AI Deployment

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually instead of deploying it across critical systems from the outset. The guidance recommends tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is genuinely necessary before integrating autonomous agents into existing workflows. “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance stated. The agency stressed that organizations should never grant unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and preserving meaningful human control were identified as key requirements for safe deployment.

Human Accountability Remains Essential

Despite the growing capabilities of autonomous AI systems, the NCSC emphasized that humans remain fully accountable for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents, and shutting systems down when necessary. Security teams were also advised to integrate agentic AI risk management into existing cybersecurity and governance frameworks instead of treating AI security as a separate process. Recommended practices include applying least-privilege access controls, limiting system scope, avoiding long-lived credentials, monitoring unusual behavior, and planning for incidents involving AI misuse or loss of control.

Path Forward

While warning about the risks, the NCSC acknowledged that agentic AI could deliver significant operational benefits, particularly for repetitive and low-risk tasks. The agency said organizations should focus on responsible and scalable adoption strategies built around existing cybersecurity practices and strong governance controls. The guidance ultimately encourages businesses to move carefully, test systems incrementally, and prepare for potential failures before expanding the role of autonomous AI systems across enterprise environments.

EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

EU Surveillance Technology

The European Union is facing renewed criticism over its failure to stop the export of surveillance technology to governments accused of human rights violations, according to a new report released by Human Rights Watch. The report claims that despite the EU’s landmark Dual-Use Regulation introduced in 2021, EU surveillance technology tool are still reaching countries where they are allegedly used to target journalists, activists, academics, and other critical voices. The 54-page report, titled “Looking the Other Way: EU Failure to Prevent Surveillance Exports to Rights Violators,” raises concerns about weak oversight, limited transparency, and gaps in enforcement within the EU’s surveillance technology export framework.

EU Surveillance Technology Exports Continue Despite Safeguards

The report highlights that the majority of EU member states host companies involved in the development and export of surveillance technology. These tools include intrusion software and telecommunication interception systems capable of monitoring private communications and tracking individuals. According to Human Rights Watch, the growing global use of commercial spyware and related surveillance technology has become a major human rights concern. Governments in several countries have allegedly used such technologies to suppress dissent, monitor opposition voices, and restrict civic freedoms. The EU’s Dual-Use Regulation was introduced to regulate exports of technologies that could serve both civilian and military purposes. The regulation aimed to strengthen oversight of surveillance technology exports by requiring member states to assess the human rights records of destination countries before approving sales. The law also introduced transparency and reporting obligations requiring EU member states to share export licensing data with the European Commission for inclusion in annual public reports. However, Human Rights Watch argues that the implementation of these measures has fallen short of their intended purpose.

Human Rights Watch Flags Weak Oversight and Transparency

A major focus of the report is the EU’s 2024 implementation guidelines for the Dual-Use Regulation. Human Rights Watch claims the guidelines weakened transparency requirements and limited public access to meaningful information about surveillance technology exports. The organization said the reporting system currently does not provide enough detail to determine whether exports are contributing to human rights abuses. To investigate further, Human Rights Watch submitted freedom of information requests to all 27 EU member states seeking data on surveillance technology licensing and exports. The findings revealed several examples of exports to countries with documented records of surveillance-related rights violations. Among the cases highlighted were exports of surveillance tools from Bulgaria to Azerbaijan in 2022 and telecommunication interception systems exported from Poland to Rwanda in 2023. The report states that these exports included technologies capable of intercepting communications and conducting intrusive digital surveillance. Human Rights Watch also criticized both EU institutions and member states for frequently citing trade secrets, national security, and international relations as reasons for withholding export information from public scrutiny.

Concerns Over Surveillance Technology and Human Rights

The report argues that surveillance technology can directly threaten several fundamental rights, including privacy, freedom of expression, freedom of assembly, and in some cases even the right to life and protection from torture. Human Rights Watch said journalists, activists, humanitarian workers, and anti-corruption investigators are among those most vulnerable to misuse of surveillance tools. The organization warned that digital surveillance can expose confidential sources, restrict independent reporting, and create risks to personal safety. According to the report, the EU remains one of the largest hubs for commercial surveillance technology companies globally. A 2024 report by Google’s Threat Analysis Group reportedly found that nearly all major commercial surveillance companies mentioned in its research were based in the EU.

European Commission Faces Pressure Ahead of 2026 Review

The European Commission is expected to begin a formal evaluation of the Dual-Use Regulation in September 2026. Human Rights Watch is urging the commission, the European Parliament, and EU member states to strengthen the rules governing surveillance technology exports during the review process. The organization is calling for stricter human rights due diligence requirements, stronger export controls, and greater transparency in reporting. It also wants surveillance companies to conduct more detailed assessments of whether their products could be used to facilitate rights abuses. In response to questions raised in the report, the European Commission stated that licensing decisions for dual-use exports are handled by individual EU member states. The commission also defended certain reporting limitations, saying that detailed disclosures could reveal commercially sensitive information or identify companies involved in exports. Still, Human Rights Watch argues that the current framework is failing to provide effective oversight. Zach Campbell, senior surveillance researcher at Human Rights Watch, said the EU needs “real transparency” to ensure that the regulation works as intended and prevents European surveillance technology from enabling abuse worldwide.

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

California Privacy Settlement

California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law. The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.

California Privacy Settlement Targets Driver Data Sales

According to the complaint, GM collected data through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers. Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums. The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties. Attorney General Rob Bonta said the settlement sends a clear message about consumer control over personal data. “General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the announcement, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

CCPA Violations and Data Minimization Concerns

A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023. Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties. Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information. Investigators said the company’s practices contradicted those statements. San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared. Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.

Connected Vehicle Privacy Under Scrutiny

The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices. In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices. California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums. However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.

Settlement Terms for General Motors

Under the proposed California privacy settlement, General Motors must implement several privacy-related measures over the coming years. The company will be required to:
  • Pay $12.75 million in civil penalties.
  • Stop selling driving data to consumer reporting agencies for five years.
  • Delete retained driving data within 180 days unless consumers provide express consent for limited uses.
  • Request the deletion of driver data already shared with LexisNexis and Verisk.
  • Establish and maintain a comprehensive privacy compliance program.
  • Submit privacy assessments and compliance reports to California regulators and prosecutors.
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA. CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled. Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.
❌