Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 15, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 15, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 15, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 15, 2025

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025

      NVIDIA’s drivers are causing big problems for DOOM: The Dark Ages, but some fixes are available

      May 15, 2025

      Capcom breaks all-time profit records with 10% income growth after Monster Hunter Wilds sold over 10 million copies in a month

      May 15, 2025

      Microsoft plans to lay off 3% of its workforce, reportedly targeting management cuts as it changes to fit a “dynamic marketplace”

      May 15, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      A cross-platform Markdown note-taking application

      May 15, 2025
      Recent

      A cross-platform Markdown note-taking application

      May 15, 2025

      AI Assistant Demo & Tips for Enterprise Projects

      May 15, 2025

      Celebrating Global Accessibility Awareness Day (GAAD)

      May 15, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025
      Recent

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025

      NVIDIA’s drivers are causing big problems for DOOM: The Dark Ages, but some fixes are available

      May 15, 2025

      Capcom breaks all-time profit records with 10% income growth after Monster Hunter Wilds sold over 10 million copies in a month

      May 15, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»European Parliament Faces Data Breach: Noyb Files Complaints with EDPS Over GDPR Violations

    European Parliament Faces Data Breach: Noyb Files Complaints with EDPS Over GDPR Violations

    August 22, 2024

    The European Parliament is under fire following a massive data breach affecting over 8,000 current and former employees. The European Parliament data breach, which occurred in the Parliament’s recruitment platform, “PEOPLE,” has prompted noyb, a privacy advocacy organization, to file two complaints with the European Data Protection Supervisor (EDPS).

    The complaints highlight violations of the EU General Data Protection Regulation (GDPR) and call for corrective action and potential fines to prevent future infractions.

    The European Parliament Data Breach and Its Implications

    In early May 2024, the European Parliament notified its staff of a significant data breach in its PEOPLE platform, which is used for recruitment purposes. The European Parliament data breach compromised sensitive personal data, including ID cards, passports, criminal record extracts, and residence documents.

    The breach also exposed highly sensitive information such as marriage certificates, which could reveal the sexual orientation of applicants. This incident has raised serious concerns about the Parliament’s ability to safeguard the personal data of its employees and applicants.

    The Parliament only became aware of the European Parliament data breach months after it occurred, and the exact cause remains unknown. This delay in detection has exacerbated concerns, especially given that the Parliament had been warned about vulnerabilities in its cybersecurity systems.

    According to noyb, the Parliament’s failure to secure such critical data is a gross violation of the GDPR, particularly Articles 4(1)(c) and (f), which pertain to data minimization and the lawful processing of personal data, as well as Article 33(1), which mandates the timely notification of data breaches.

    Noyb’s Response and Legal Action

    Noyb has taken action in response to the European Parliament data breach, filing complaints with the EDPS on behalf of four Parliament employees. The organization argues that the Parliament’s actions—or lack thereof—constitute clear violations of the GDPR. In particular, noyb has criticized the Parliament for retaining personal data far beyond what is necessary, a practice that contravenes the principle of data minimization outlined in Article 4(1)(c) of the GDPR.

    One of the complaints also highlights the Parliament’s refusal to honor an erasure request made by an individual who had not worked for the institution for several years. Despite the individual’s concerns following the breach, the Parliament cited a 10-year retention period as the reason for denying the request.

    Noyb has urged the EDPS to use its corrective powers to compel the Parliament to comply with GDPR regulations and has suggested the imposition of an administrative fine to deter future violations.

    Known Vulnerabilities and Repeated Cybersecurity Failures

    The European Parliament data breach is particularly concerning given the Parliament’s prior knowledge of its cybersecurity vulnerabilities. In November 2023, the Parliament’s IT department conducted a cybersecurity review that revealed the institution’s defenses were inadequate and did not meet industry standards. The review warned that existing measures were not fully aligned with the threat level posed by state-sponsored hackers.

    This data breach is just one in a series of cybersecurity incidents that have plagued EU institutions in recent years. In November 2022, Russian hacking groups targeted the Parliament’s website, and in autumn 2023, multiple European governments were similarly attacked. In February 2024, a separate breach occurred in the Parliament’s security and defense subcommittee, where Israeli spyware was found on the devices of two Members of the European Parliament (MEPs) and a staff member.

    Lorea Mendiguren, a Data Protection Lawyer at noyb, emphasized the gravity of the situation: “This breach comes after repeated cybersecurity incidents in EU institutions over the past year. The Parliament has an obligation to ensure proper security measures, given that its employees are likely targets for bad actors.”

    The Broader Implications of the European Parliament Data Breach

    The data breach not only exposes the Parliament’s failure to protect personal data but also raises broader concerns about the vulnerability of EU institutions to cyberattacks. Max Schrems, Chairman of noyb, expressed his concern at the ongoing cybersecurity issues within EU bodies: “As an EU citizen, it is worrying that EU institutions are still so vulnerable to attacks. Having such information floating around is not only frightening for the individuals affected, but it can also be used to influence democratic decisions.”

    The breach has also shed light on the Parliament’s data retention practices, which appear to be excessive. The GDPR mandates that personal data should only be retained for as long as necessary for the purposes for which it was collected. However, the Parliament’s 10-year retention period for recruitment files, which contain highly sensitive information, seems to violate this principle. Schrems noted, “The breach also shows that just getting rid of personal data in time could likely have limited the impact of the breach.”

    Moving Forward: The Role of the EDPS

    As the complaints move forward, all eyes are on the EDPS to see how it will respond to this significant data protection failure. Noyb has called on the EDPS to enforce compliance with the GDPR and to impose fines that reflect the seriousness of the violations. The outcome of this case could have far-reaching implications for how EU institutions handle personal data and address cybersecurity risks.

    For now, the European Parliament faces the challenge of rebuilding trust and implementing stronger security measures to prevent future breaches.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleWorld’s largest Oilfield Services Firm Halliburton Allegedly Hit by Cyberattack
    Next Article Warren Sponholtz, Veteran IT Leader, Becomes Florida’s State CIO Focusing

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 16, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4743 – Code-projects Employee Record System SQL Injection Vulnerability

    May 16, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    CVE-2025-3577 – Zyxel AMG1302-T10B Path Traversal Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Synnovis Confirms Data Published by Qilin Ransomware Gang as Legitimate

    Development

    Monster Hunter Wilds is the best-selling game of February in the US, and it’s already crossed another huge milestone

    News & Updates

    4-Step Approach to Mapping and Securing Your Organization’s Most Critical Assets

    Development

    Highlights

    Soft Skills: The true driver of success in tech

    January 16, 2025

    Post Content Source: Read More 

    OneDrive bug affects shared folders on Windows 11; no official workaround yet

    June 17, 2024

    CVE-2025-31232 – Apple macOS Sensitive Data Access Vulnerability

    May 12, 2025

    The Ongoing Challenges of Understanding Long COVID and Exploring Innovative Solutions

    April 15, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.