Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Back To Home

Research Team (Tsaaro)

Amazon’s $2.25 Million Identity-Theft Records Settlement

On 14 August 2026, the U.S. Department of Justice confirmed that a federal court had entered a stipulated order against Amazon.com, resolving allegations brought following an investigation and referral by the Federal Trade Commission (FTC). Amazon must pay a $2.25 million civil penalty and comply with an injunction governing how it responds to identity-theft victims seeking transaction records. 

The case concerns Section 609(e) of the Fair Credit Reporting Act (FCRA). The provision gives identity-theft victims a right to obtain application and business transaction records relating to fraudulent transactions made using their identity. Businesses receiving a qualifying request must generally provide the relevant records within 30 days. 

The Core Failure 

The government alleged that Amazon repeatedly failed to provide these records or provided them after the statutory deadline. According to the FTC's complaint, some consumers were told that the information could not be disclosed for privacy or security reasons, even though those grounds did not justify refusing a valid section 609(e) request. 

In one particularly striking example, an identity-theft victim was told that Amazon could not release information about the fraudulent account unless the victim could identify the name used on it. The consumer reportedly tried to guess the name 30 times without success. The FTC also alleged that Amazon sometimes refused requests submitted by law-enforcement agencies acting on behalf of victims. 

The complaint further alleged that Amazon did not maintain a written section 609(e) response policy until early 2025, after learning that the FTC was investigating its compliance. 

What Changes Now? 

Under the court order, Amazon must provide qualifying identity-theft records free of charge and within 30 days, subject to verification requirements. It must also publish information explaining how victims can request these records. 

The practical lesson goes beyond the FCRA. Organisations increasingly build stro controls ng around who can access customer information, but those controls need exceptions for legally recognised access and disclosure rights. A frontline employee treating every request for another account's information as a security risk may appear cautious, but that approach can itself create a compliance failure where the law requires disclosure. 

Businesses handling sensitive customer records should therefore ensure that data-access requests can move quickly from customer support to the appropriate legal or compliance team, that statutory deadlines are built into the process, and that employees know the difference between an unauthorised disclosure and a legally required one. 

Source: https://www.justice.gov/opa/pr/amazon-agrees-225-million-settlement-and-injunction-resolve-alleged-violations-fair-credit 

News of the Week 

  1. EU E-Evidence Regulation Starts Applying Across the Bloc 
European judicial cooperation & transfer of criminal proceedings between  Member States - Navacelle

 Image Credits 

The EU's new e-Evidence Regulation became applicable on 18 August 2026, creating a common system for law-enforcement authorities to obtain electronic evidence across member state borders. 

The framework introduces European production orders and European preservation orders. A judicial authority in one member state can use a production order to obtain electronic evidence directly from a service provider or its legal representative in another participating member state. This can include information such as emails, app messages and data used to identify a person. A preservation order can require specified data to be retained while a subsequent production request is prepared. 

The timelines are significant. The commission states that providers will generally have 10 days to respond to a production order and eight hours in emergency cases. The regulation also contains safeguards relating to personal data, proportionality, information rights and effective remedies for affected individuals. 

For cloud, communications, hosting and other covered digital-service providers, this is not simply a law-enforcement development. Internal privacy and legal teams now need reliable processes for recognising cross-border orders, preserving the requested information, checking their validity and responding within much shorter timelines. 

Source: https://dig.watch/updates/eu-e-evidence-regulation-becomes-applicable 

https://home-affairs.ec.europa.eu/policies/internal-security/cybercrime/e-evidence_en 

2. CareCloud Breach Expands to More Than 3.75 Million People 

 Image Credits 

A healthcare breach that initially appeared to affect hundreds of thousands of people has become significantly larger. On 19 August 2026, CareCloud confirmed to federal regulators that hackers had stolen the personal and medical information of more than 3.75 million people. 

CareCloud had first disclosed the cybersecurity incident in March. Its SEC filing stated that a network disruption affected one of its six electronic-health-record environments and that the company considered the incident material because of the sensitivity of potentially affected information and the possible consequences for patients, customers and regulatory obligations. 

Subsequent notifications indicate that the compromised data included names, addresses, Social Security numbers, medical and health information, government identification numbers and financial information. The compromised information had been stored within an Amazon Web Services environment. 

The sharp increase in the reported number of affected people shows why breach impact assessments cannot end with the initial incident response. Where a healthcare technology provider holds information for multiple organisations, one compromised environment can create exposure across a much wider patient population than first understood. 

For businesses using processors that centralise sensitive information, the takeaway is clear: vendor risk assessments should consider not only whether a provider has security controls, but also how much data is concentrated with that provider and how quickly the scope of a breach can be established. 

Source: https://nationalcioreview.com/articles-insights/extra-bytes/carecloud-breach-expands-from-eight-hour-incident-to-3-7-million-patients/ 

  1. NSW Fast-Tracks Data Centres Under New Sustainability Guidelines 
Data Center Energy Efficiency: Hanwha's Top 11 Tips for 2025

Image Credits 

New South Wales has introduced a new framework aimed at speeding up data centre development while placing stronger conditions on energy, water and environmental performance. Under the guidelines, projects that align with the government's requirements can benefit from a faster planning process, with the state committing to keep the development application assessment period to no more than 75 days while the application is in government hands. 

The Guidelines are built around six principles. Data centres are expected to meet high environmental and efficiency standards, impose no net cost on consumers and communities, contribute to additional energy and water supply, improve local infrastructure, support future industries and invest in skills and employment.

The scheme effectively links faster approvals with stronger sustainability commitments. As Developers that comply with the new standards may receive accelerated assessments, while projects that do not meet the expectations still face the possibility of refusal. 

For data centre and AI infrastructure developers, the takeaway is clear: speed to market in NSW will increasingly depend on demonstrating, at the planning stage, how projects will manage their energy demand, water consumption, environmental impact and contribution to local infrastructure. 

Source: https://www.abc.net.au/news/2026-08-17/data-centres-fast-tracked-under-new-nsw-scheme/107043984 

https://www.infrastructure.nsw.gov.au/media/4jlictae/id0073_nsw-data-centre_guidelines.pdf 

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.