Experian gets €2.7M GDPR fine. Qantas breach exposes data of 5M customers.

by Sypher | Published in News - October 27, 2025


Welcome to #SypherPrivacyTalks — Your news and article roundup. Bringing you the top privacy & compliance stories of the week.

Experian closes down Dutch operation after €2.7m fine

decisionmarketing.co.uk • 3 min read

💶 The Dutch Data Protection Authority has fined Experian Netherlands €2.7 million for unlawfully collecting and using personal data to generate credit scores without the knowledge or consent of the individuals concerned… read more


Australia’s Qantas data breach exposes personal information of over 5 Million customers

travelnoire.com • 3 min read

💥 Qantas Airways has confirmed a major data breach affecting over five million customers. Hackers leaked stolen personal information on the dark web after a ransom deadline was missed… read more

💡 Related: The same notorious hacker group has reportedly exposed the customer data of over 40 companies worldwide, including Qantas, McDonald’s, Disney, IKEA, Adidas, Gap, Vietnam Airlines and Toyota, among others…. read more


Streamlined rules for cross-border privacy enforcement advance in EU

vitallaw.com • 3 min read

🏛️ The European Parliament has approved the GDPR Cross-Border Enforcement Regulation to speed up and clarify cross-border privacy cases. The new rules set strict deadlines for investigations, encourage early cooperation between national authorities and strengthen individuals’ rights to information and participation. The new rules will take effect 15 months after the EU Council's final approval… read more


Major Romanian electricity supplier fined €5,000 after sending another person's bill to a customer

startupcafe.ro • 2 min read

💶 This incident occurred as a result of a technical error in Hidroelectrica's computer system, which was used to send invoices to customers. This error led to a loss of control over the personal data of the data subject… read more (article in Romanian).

💡Related: E.ON Energie Romania has challenged its GDPR fine: The authority's report is "unfounded and unlawful." … read more


Who's liable? Legal accountability in the age of AI: Part 1

eversheds-sutherland.com • 7 min read

🤖 This article examines how existing legal frameworks address accountability when AI systems cause harm. Using a real-world recruitment example, it considers the emerging 'AI liability gap', where adaptive and autonomous technologies challenge traditional concepts of blame, contractual obligations, and foreseeability. It also explores what this means for organisations seeking to manage risk, compliance, and trust in their AI deployments… read more
 

--

Get connected with us on LinkedIn or by subscribing to our weekly newsletter. We do our best to select the most interesting and relevant content in our field and deliver it to you in a bite-sized format, so you can stay up to date on topics such as Privacy Management & Compliance.

Photo by rupixen on Unsplash