data-breach

Cognizant Notifies Individuals of Data Breach, Offers Identity Theft Protection

Cognizant has notified individuals of a data breach and is offering identity theft protection to affected individuals. Learn what happened, what data may have been exposed, and the steps impacted individuals should take.

Cognizant has notified affected individuals of a data security breach that occurred around 21 April 2026, after determining that their personal information may have been exposed. While the company stated that it currently has no reason to believe the information has been misused, it has initiated notifications as a precautionary measure. Cognizant has not publicly disclosed the number of individuals affected, the precise categories of personal information involved, or the nature of the incident that led to the exposure.  

As part of its response, Cognizant is offering affected individuals 24 months of identity theft protection services through IDX. The package includes credit and CyberScan monitoring, managed identity-theft recovery services, and insurance reimbursement of up to US$1 million for eligible identity-theft-related losses. Individuals have also been advised to monitor their account activity and credit reports and consider additional safeguards, including fraud alerts and security freezes.   

The incident underscores the importance of a comprehensive response framework following a potential personal data breach. For organisations preparing for India's evolving data protection regime, the development is a timely reminder that breach preparedness must extend beyond technical containment.  

Effective incident response requires clear notification procedures, risk assessment mechanisms, remediation measures and support for affected individuals, particularly where compromised personal information may create continuing risks of identity misuse. 

Read More: Cognizant Notifies Individuals of Data Breach, Offers Identity Theft Protection 

📰 MINI HEADLINES 

  • TikTok Agrees to $400 Million Settlement Over Children’s Privacy 

TikTok and its parent company, ByteDance, have agreed to pay $400 million to resolve a U.S. Department of Justice lawsuit alleging violations of the Children’s Online Privacy Protection Act (COPPA). The lawsuit, filed in 2024, alleged that TikTok collected and retained personal information from users under the age of 13 without obtaining the legally required parental consent. The settlement represents one of the largest enforcement outcomes under the U.S. children’s privacy framework.  

Under the agreement, TikTok will pay $300 million immediately, while the remaining $100 million will become payable after a prior 2019 consent decree involving its predecessor, Musical.ly, is vacated. The 2024 lawsuit followed allegations that TikTok had continued to collect and retain children’s personal information despite earlier regulatory action concerning similar privacy concerns.  

The settlement underscores the growing regulatory focus on protecting children’s personal data and the heightened obligations imposed on digital platforms serving younger users. It reinforces the importance of effective age-assurance mechanisms, verifiable parental consent, and robust processes for limiting the collection and retention of children’s information. For organisations operating digital platforms, the case demonstrates the significant financial and regulatory consequences that can arise where privacy safeguards for minors are found to be inadequate. 

READ MORE - TikTok Agrees to $400 Million Settlement Over Children’s Privacy 

  • Supreme Court Flags Privacy Risks in Private Access to EPFO and ITR Data 

The Supreme Court has expressed concern over the alleged access, retrieval and verification of sensitive Employees Provident Fund Organisation (EPFO) and income-tax records by private entities, describing such access as “worrisome”. The issue arose from a PIL alleging the emergence of a commercial technology ecosystem that could access or commercially exploit personal information submitted by individuals to government authorities under statutory requirements.  

While declining to entertain the PIL, a Bench comprising Chief Justice Surya Kant and Justices Joymalya Bagchi and V. Mohana asked the Centre to consider devising appropriate safeguards to prevent the misuse of such information, with the assistance of domain experts. The petitioner had raised concerns regarding private verification systems allegedly retrieving information linked to identifiers such as PAN and UAN, including employment-related records.  

Importantly, the Supreme Court did not find that a data breach had occurred, nor did it conclude that private entities have unrestricted access to citizens EPFO or income-tax records. Instead, the Court flagged the allegations as requiring closer policy attention and called upon the government to consider an effective mechanism to prevent potential misuse and commercial exploitation of sensitive personal data.  

The development brings renewed focus to the protection of government-held financial and employment data, particularly where such information may intersect with private-sector verification ecosystems. It also raises broader questions around consent, access controls, purpose limitation and accountability in the sharing and verification of sensitive personal information. 

READ MORE - Supreme Court Flags Privacy Risks in Private Access to EPFO and ITR Data 

  • Dutch Regulator Fines Uber €825 Million Over Automated Driver Suspensions 

The Dutch Data Protection Authority has imposed a €825 million fine on Uber for allegedly using automated systems to suspend or deactivate driver accounts without adequately informing affected drivers or ensuring meaningful human oversight. The regulator found that Uber’s practices, which were examined in relation to incidents between 2018 and 2022, could have significant consequences for drivers by affecting their ability to earn a livelihood.  

The case centres on the safeguards required under the EU General Data Protection Regulation (GDPR) for automated decision-making that significantly affects individuals. According to the Dutch regulator, some driver accounts were restricted or deactivated based on algorithmic assessments, including suspected fraudulent activity and customer ratings, without sufficient warning or meaningful human involvement. The authority emphasised that decisions with such substantial consequences should not be made solely by automated systems.  

Uber has disputed the findings and announced that it will appeal the decision, maintaining that its policies include human reviews and mechanisms through which drivers can challenge suspensions. The company has also argued that the regulator examined historic practices that have since been discontinued. The penalty, reported as the second-largest fine issued under the GDPR, highlights the increasing regulatory scrutiny of algorithmic decision-making. As automated and AI-driven systems are increasingly used to make decisions affecting employment and livelihoods, the case reinforces the importance of transparency, meaningful human oversight and mechanisms for individuals to challenge consequential automated decisions 

READ MORE - Dutch Regulator Fines Uber €825 Million Over Automated Driver Suspensions. 

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands