4 ms·
> In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not sa
by buzzert 5y ago
> In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server!
Does anybody know if this threat is at all credible?
- DharmaPolice 5y agoThe way it's phrased doesn't make much sense but they could contact whoever is responsible for GDPR enforcement in a particular country (if in the EU) and make a complaint against you. But it's unlikely to come to anything (especially if all the data was deleted) and you won't be arrested.
- rndgermandude 5y agoYou could end up paying a fine if the regulatory authority investigates and finds that personal data was exposed (or deleted) due to lack of "appropriate technical and organisational measures to ensure a level of security appropriate to the risk"[1]. Relatedly, you can be fined for not telling the regulatory authority about breaches yourself: "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons."[2] British Airways[3] for example was fined for inadequate security measures. I also remember a case where some company (cannot quite remember which) itself told the regulator about some security snafu as they should, a snafu that most likely was not exploited. They were still issued a fine but a reduced one because they were very cooperative and most likely no actual damage happened. There is an enforcement tracker website[4] where you can filter for e.g. "security" in the type column. But nobody will go to prison for being the victim of a hack, that's just fearmongering by that attacker. [1] https://gdpr-info.eu/art-32-gdpr/ https://gdpr-info.eu/art-32-gdpr/ [2] https://gdpr-info.eu/art-33-gdpr/ https://gdpr-info.eu/art-33-gdpr/ [3] https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2020/10/ico-fines-british-airways-20m-for-data-breach-affecting-more-than-400-000-customers/ https://ico.org.uk/about-the-ico/news-and-events/news-and-bl... [4] https://www.enforcementtracker.com/ https://www.enforcementtracker.com/