Credit: Marco Piunti / Getty Images A class action lawsuit filed last week in the Northern District of California accused Oracle of running a “worldwide surveillance machine” and violating the fundamental privacy rights of hundreds of millions of people. The suit alleges that Oracle has violated California’s state constitution by compiling and selling off personal data and makes a common law tort claim for intrusion upon seclusion, along with five further causes of action ranging from state data protection laws to the federal wiretap act.Lawsuit claims Oracle created profiles without consentThe plaintiffs in the suit are two privacy rights activists in the U.S. and one in Ireland, all of whom assert that they have data to show that Oracle has created profiles of them without their consent. The amount of relief sought isn’t specified, but the suit – in addition to asking for certification as a class action – demands a halt to Oracle’s data collection activities, as well as restitution of profits made from data collected without consent.“As a data broker, Oracle effectuates ongoing, comprehensive surveillance of the Plaintiffs and Class members which grievously intrudes upon their privacy,” the complaint states. “Ordinary people, such as the Class members, do not and cannot possess an appropriate level of knowledge about the substantial threats that Oracle’s surveillance poses to their own autonomy.” Latest in a series of actions against Oracle’s data collection practicesIt’s not the first time that Oracle has dealt with legal trouble over its data collection practices, having faced a GDPR-based class action in Holland in 2020. (That case was dismissed earlier this year for a lack of standing, although the plaintiff, an activist group called The Privacy Collective, has said it plans to appeal.) UK courts also shot down a similar lawsuit against Google last year, saying that plaintiffs alleging that Google partially overrode iPhone privacy settings in the Safari browser couldn’t demonstrate that they’d suffered damage or a loss as a result. Whether the results will be different in U.S. federal court remains to be seen, but privacy experts will doubtless be watching the case closely. EU countries like Holland are subject to the wide-ranging GDPR, while the UK also has the Data Protection Act. By contrast, the U.S. is still without a national-level data protection rule, so legal action in this area has to take place in different contexts. Related content feature Looking outside: How to protect against non-Windows network vulnerabilities Security administrators who work in Windows-based environments should heed the lessons inherent in recent vulnerability reports. By Susan Bradley Apr 25, 2024 7 mins Windows Security Network Security Security Practices brandpost Sponsored by Palo Alto Networks Cloud security teams: What to know as M&A activity rebounds in 2024 Direct visibility is critical in M&A, and cloud-native application protection platforms (CNAPP) are ideal to provide this capability. By Amol Mathur, SVP & GM of Prisma Cloud, Palo Alto Networks Apr 25, 2024 4 mins Cloud Security news Salt Security adds defense against OAuth attacks The new offering is designed to mitigate vulnerabilities and misconfigurations associated with the open authentication (OAuth) authorization framework. By Shweta Sharma Apr 25, 2024 3 mins Authentication Security Software news Cisco urges immediate software upgrade after state-sponsored attack Hackers exploited previously undetected vulnerabilities in Cisco’s Adaptive Security Appliances — a product that combines multiple cybersecurity functions. By Prasanth Aby Thomas Apr 25, 2024 3 mins Vulnerabilities PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe