3 ms·
I think it’s unfair to say that just because there haven’t been legal action, there has been no action. I live in Denmark, our data-protection agency has only
by jaabe 7y ago
I think it’s unfair to say that just because there haven’t been legal action, there has been no action.
I live in Denmark, our data-protection agency has only recently gotten cases to a point where they could roll out fines. And that’s just for the small-scale offences that were legally easy to handle.
Some of the larger breaches will take many years to handle before a case is strong enough to be brought to the police. It’s also worth noting, that breaches of the GDPR don’t automatically lead to legal action. It’s only if organisations systematically abuse data or if they fail to fix whatever problems a GDPR audit points out to them, that legal action is the end result.
If you have a breach, like if a supplier forget to exclude an API key from their GitHub repository and I it leaves your employee names vulnerable to the entire world. But you find it, report it, fix it and tell the affected parties ie comply with the GDPR procedures. Then you’ll have breached the GDPR, but won’t have broken the law.