3 ms·
Full credit card details were leaked; The 72 hour window is reasonable. I’d go as far as forcing them to contact the banks of those cards as well.
by thitcanh 6y ago
Full credit card details were leaked; The 72 hour window is reasonable. I’d go as far as forcing them to contact the banks of those cards as well.
- tijmendj 6y agoAs far as I know there is no legal basis for them to contact the banks, at least under GDPR. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is there to enforce GDPR and will not add additional requirements.
- thitcanh 6y agoRight, my suggestion is that it should. Yahoo’s settlement included identity protection or something along those lines. Disclosure to the customer might not always be enough.
- zaarn 6y agoNotifying banks will likely be required by their payment processor, not by the GDPR, those are two separate processes.