Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No. Unless they didn't report it to the regulators.


Article 34 clearly states that the breached organization must inform the data subject "without undue delay". Given that the event occurred in September, and it is now December, I would characterize that as an undue delay.

There should be GDPR consequences of this - it's time that law got properly put to the test.


I'd imagine what matters is the delay from when you learn about the issue, not the delay from when it happened. This blog post looks a lot more like something they discovered now than something they discovered in September. (E.g. the way they'll have "tools for figuring out who was affected next week").


What? You get fined under GDPR for a breach. If you don’t report it, the fine will be a lot higher if they find out.

We will see how this plays out, but there should be a fine nevertheless (because others have been fined and they reported it).


Based on what article?


If you process personal data, you must make sure to protect the data. If you fail to protect the data, you can get a fine. How high it is depends on various factors. Reporting the breach timely to the authorities can help to have a lower fine.

But reporting it doesn’t make the fine go away. After all, you started to process personal data and are responsible for it. Alternatively, you could’ve opted for not processing personal data if you think you can’t protect the data adequately.

You can read all this here: https://gdpr-info.eu/issues/fines-penalties/




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: