• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Miasma

    Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

    CVE-2026-41089

    Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

    ChatGPhish

    New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses

    OSM vulnerability

    CBSE Engages IIT Experts After Admitting OSM Security Vulnerabilities

    The Cyber Express weekly roundup TCE

    The Cyber Express Weekly Roundup: Supply Chain Attacks, Mobile Banking Malware, and Expanding Cloud Phishing Campaigns

    LA public transport cyberattack

    Iranian Hackers Linked to Cyberattack on Los Angeles Transit Network

    WP Maps Pro

    WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover

    CVE-2026-48770

    Notepad++ Patches High-Severity RCE Flaws in Version 8.9.6.1

    CERT-In

    CERT-In Urges Firms to Patch Critical Vulnerabilities Within 12 Hours Amid AI Threat Surge

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI-Native Cybersecurity

    Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

    First VPN, First VPN seized, VPN Seized, FBI, France, Dutch, Law Enforcement,

    European Agencies Shutter VPN Service Used for Ransomware Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    Shadow AI Is Growing in Silence

    Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

    EU Surveillance Technology

    EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Miasma

    Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

    CVE-2026-41089

    Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

    ChatGPhish

    New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses

    OSM vulnerability

    CBSE Engages IIT Experts After Admitting OSM Security Vulnerabilities

    The Cyber Express weekly roundup TCE

    The Cyber Express Weekly Roundup: Supply Chain Attacks, Mobile Banking Malware, and Expanding Cloud Phishing Campaigns

    LA public transport cyberattack

    Iranian Hackers Linked to Cyberattack on Los Angeles Transit Network

    WP Maps Pro

    WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover

    CVE-2026-48770

    Notepad++ Patches High-Severity RCE Flaws in Version 8.9.6.1

    CERT-In

    CERT-In Urges Firms to Patch Critical Vulnerabilities Within 12 Hours Amid AI Threat Surge

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI-Native Cybersecurity

    Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

    First VPN, First VPN seized, VPN Seized, FBI, France, Dutch, Law Enforcement,

    European Agencies Shutter VPN Service Used for Ransomware Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    Shadow AI Is Growing in Silence

    Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

    EU Surveillance Technology

    EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cyber News

European Parliament Faces Data Breach: Noyb Files Complaints with EDPS Over GDPR Violations

Noyb has called on the EDPS to enforce compliance with the GDPR and to impose fines that reflect the seriousness of the violations.

Samiksha Jain by Samiksha Jain
August 22, 2024
in Cyber News, Data Breach News, Firewall Daily
0
European Parliament Data Breach

Source: Freepik

674
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

The European Parliament is under fire following a massive data breach affecting over 8,000 current and former employees. The European Parliament data breach, which occurred in the Parliament’s recruitment platform, “PEOPLE,” has prompted noyb, a privacy advocacy organization, to file two complaints with the European Data Protection Supervisor (EDPS).

The complaints highlight violations of the EU General Data Protection Regulation (GDPR) and call for corrective action and potential fines to prevent future infractions.

The European Parliament Data Breach and Its Implications

In early May 2024, the European Parliament notified its staff of a significant data breach in its PEOPLE platform, which is used for recruitment purposes. The European Parliament data breach compromised sensitive personal data, including ID cards, passports, criminal record extracts, and residence documents.

The breach also exposed highly sensitive information such as marriage certificates, which could reveal the sexual orientation of applicants. This incident has raised serious concerns about the Parliament’s ability to safeguard the personal data of its employees and applicants.

The Parliament only became aware of the European Parliament data breach months after it occurred, and the exact cause remains unknown. This delay in detection has exacerbated concerns, especially given that the Parliament had been warned about vulnerabilities in its cybersecurity systems.

According to noyb, the Parliament’s failure to secure such critical data is a gross violation of the GDPR, particularly Articles 4(1)(c) and (f), which pertain to data minimization and the lawful processing of personal data, as well as Article 33(1), which mandates the timely notification of data breaches.

report-ad-banner

Noyb’s Response and Legal Action

Noyb has taken action in response to the European Parliament data breach, filing complaints with the EDPS on behalf of four Parliament employees. The organization argues that the Parliament’s actions—or lack thereof—constitute clear violations of the GDPR. In particular, noyb has criticized the Parliament for retaining personal data far beyond what is necessary, a practice that contravenes the principle of data minimization outlined in Article 4(1)(c) of the GDPR.

One of the complaints also highlights the Parliament’s refusal to honor an erasure request made by an individual who had not worked for the institution for several years. Despite the individual’s concerns following the breach, the Parliament cited a 10-year retention period as the reason for denying the request.

Noyb has urged the EDPS to use its corrective powers to compel the Parliament to comply with GDPR regulations and has suggested the imposition of an administrative fine to deter future violations.

Known Vulnerabilities and Repeated Cybersecurity Failures

The European Parliament data breach is particularly concerning given the Parliament’s prior knowledge of its cybersecurity vulnerabilities. In November 2023, the Parliament’s IT department conducted a cybersecurity review that revealed the institution’s defenses were inadequate and did not meet industry standards. The review warned that existing measures were not fully aligned with the threat level posed by state-sponsored hackers.

This data breach is just one in a series of cybersecurity incidents that have plagued EU institutions in recent years. In November 2022, Russian hacking groups targeted the Parliament’s website, and in autumn 2023, multiple European governments were similarly attacked. In February 2024, a separate breach occurred in the Parliament’s security and defense subcommittee, where Israeli spyware was found on the devices of two Members of the European Parliament (MEPs) and a staff member.

Lorea Mendiguren, a Data Protection Lawyer at noyb, emphasized the gravity of the situation: “This breach comes after repeated cybersecurity incidents in EU institutions over the past year. The Parliament has an obligation to ensure proper security measures, given that its employees are likely targets for bad actors.”

The Broader Implications of the European Parliament Data Breach

The data breach not only exposes the Parliament’s failure to protect personal data but also raises broader concerns about the vulnerability of EU institutions to cyberattacks. Max Schrems, Chairman of noyb, expressed his concern at the ongoing cybersecurity issues within EU bodies: “As an EU citizen, it is worrying that EU institutions are still so vulnerable to attacks. Having such information floating around is not only frightening for the individuals affected, but it can also be used to influence democratic decisions.”

The breach has also shed light on the Parliament’s data retention practices, which appear to be excessive. The GDPR mandates that personal data should only be retained for as long as necessary for the purposes for which it was collected. However, the Parliament’s 10-year retention period for recruitment files, which contain highly sensitive information, seems to violate this principle. Schrems noted, “The breach also shows that just getting rid of personal data in time could likely have limited the impact of the breach.”

Moving Forward: The Role of the EDPS

As the complaints move forward, all eyes are on the EDPS to see how it will respond to this significant data protection failure. Noyb has called on the EDPS to enforce compliance with the GDPR and to impose fines that reflect the seriousness of the violations. The outcome of this case could have far-reaching implications for how EU institutions handle personal data and address cybersecurity risks.

For now, the European Parliament faces the challenge of rebuilding trust and implementing stronger security measures to prevent future breaches.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: data breach newsEU Parliament Data BreachEuropean Parliament Data BreachThe Cyber ExpressThe Cyber Express NewsVulnerabilities
Previous Post

Warren Sponholtz, Veteran IT Leader, Becomes Florida’s State CIO Focusing

Next Post

World’s largest Oilfield Services Firm Halliburton Confirms Cyberattack

Next Post
Halliburton Cyberattack

World’s largest Oilfield Services Firm Halliburton Confirms Cyberattack

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

Miasma
Firewall Daily

Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

June 2, 2026
CVE-2026-41089
Firewall Daily

Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

June 2, 2026
ChatGPhish
Firewall Daily

New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses

June 1, 2026
OSM vulnerability
Firewall Daily

CBSE Engages IIT Experts After Admitting OSM Security Vulnerabilities

June 1, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information