Cybersecurity, Privacy, & AI

Trending Now
CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information • 10 Questions Every Organization Should Ask a Potential AI Vendor • VA Software Management Woes Linked in Part to CIO Vacancy, Watchdog Says • FedRAMP and Identity Security: Why Federal Organizations Are Consolidating Identity Security Platforms • NIST Announces Funding Opportunity for 14 MEP Centers to Advance Small and Medium-Sized U.S. Manufacturers

White House Pushing for Research Carve-Out in GDPR

The White House is asking through the State Department for European regulators to create an exception in their impending General Data Protection Regulation, one that would allow security researchers to easily look up data related to data breach and botnet investigations.

The GDPR applies to any company handling data about EU residents, and will have a significant impact on the billion dollar cybersecurity industry, but some of its privacy provisions could have a negative effect on security researchers’ work.

For example, the Internet Corporation for Assigned Names and Numbers (ICANN) collects basic information including name and physical address for every domain name that is registered, which is stored in its publicly searchable WHOIS database. These details are easily forged or obfuscated, but the information can provide clues about a cyberattack.

With the way GDPR is currently written, ICANN may withhold some of this information from public searches, thereby making it less useful to security researchers. The organization plans a system of “accreditation” which will allow journalists, law enforcement, and security researchers access to the full set of data, but that won’t be ready until December at the earliest.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.