U.S. DOJ: Disney Agrees to $10M Civil Penalty and Injunction for Alleged Violations of Children’s Privacy Laws


The Justice Department announced today that a federal court has entered a stipulated order resolving a case against Disney Worldwide Services Inc. and Disney Entertainment Operations LLC, (collectively, Disney). The Federal Trade Commission (FTC) investigated this matter, negotiated a resolution with Disney, and referred the case to the Department.

Under the order, Disney will pay $10 million in civil penalties as part of a settlement to resolve Federal Trade Commission allegations that Disney violated the Children’s Online Privacy Protection Act and its implementing regulations (COPPA) in connection with Disney’s popular YouTube video content. COPPA prohibits website operators from knowingly collecting, using, or disclosing personal information from children under the age of 13 (hereinafter, children), unless they provide notice to and obtain consent from those children’s parents.

Read more…
Source: U.S. Department of Justice


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables

    January 31, 2022

    MuddyWater has conducted various campaigns against entities spread throughout the U.S.A, Europe, Middle East and South Asia. A typical TTP employed by the group is the heavy use of scripting in their infection chains using languages like PowerShell and Visual Basic coupled with the frequent use of living-off-the-land binaries (LoLBins). Cisco Talos recently observed a campaign operated ...

  • Potential for Malicious Cyber Activities to Disrupt the 2022 Beijing Winter Olympics and Paralympics

    January 31, 2022

    The FBI is warning entities associated with the February 2022 Beijing Winter Olympics and March 2022 Paralympics that cyber actors could use a broad range of cyber activities to disrupt these events. These activities include distributed denial of service (DDoS) attacks, ransomware, malware, social engineering, data theft or leaks, phishing campaigns, disinformation campaigns, or insider ...

  • U.S. unveils plan to improve cyber defenses for water utilities

    January 27, 2022

    The White House on Thursday unveiled a plan to beef up cybersecurity in the nation’s water sector, an extension of its efforts to thwart attacks against critical infrastructure including electricity and natural gas pipeline operators. Senior administration officials said water facilities use automation and electronic networks that are vulnerable to cyber attacks, which could include producing ...

  • Context and Recommendations to Protect Against Malicious Activity by Iranian Cyber Group Emennet Pasargad

    January 26, 2022

    This Private Industry Notice provides a historical overview of Iran-based cyber company Emennet Pasargad’s tactics, techniques, and procedures (TTPs) to enable recipients to identify and defend against the group’s malicious cyber activities. On 20 October 2021, a grand jury in the US District Court for the Southern District of New York indicted two Iranian nationals ...

  • Biden warns of US ‘cyber’ response after Ukraine says computers wiped during attack

    January 20, 2022

    US President Joe Biden responded forcefully to reports of a wide-ranging cyberattack on Ukrainian government systems Wednesday afternoon, telling reporters that the US would respond with its own cyberattacks if Russia continues to target Ukraine’s digital infrastructure. “The question is if it’s something significantly short of an…invasion or major military forces coming across,” Biden said in ...

  • Biden signs cybersecurity memorandum for Defense Department, intelligence agencies

    January 19, 2022

    US President Joe Biden signed a memorandum on Tuesday concerning the cybersecurity of the Defense Department and the country’s intelligence agencies, sketching out exactly how an executive order he signed in May 2021 will be implemented. “This NSM requires that, at minimum, National Security Systems employ the same network cybersecurity measures as those required of federal ...