4 ms·
You do know this means they have broken GDPR, by not reporting a noticed breach.
by failattu 5y ago
You do know this means they have broken GDPR, by not reporting a noticed breach.
- raffraffraff 5y agoDoesn't that depends on how well they separate access within the company? If they know that one of their support reps in Costa Rica was "turned", they might not have to declare anything in the EU if they can prove that the rep has zero access to EU customers. Edit: to be clear, I don't know, it's a genuine question. Does "any breach" count?
- sofixa 5y agoIt has to be a breach where EU citizens' PII was potentially accessed.
- ealexhudson 5y agoThey only have to report if there is significant risk to the individuals involved. If there are few individuals and the event was indeed contained, they have no reporting requirement.
- nokya 5y agoNotification is required only if their impact assessment concludes on a significant risk to users (which they must be able to produce to the data protection authority at any time). Otherwise, business as usual.
- hakre 5y agoOkta is a company in the United States of America, by law companies under GDPR are already in violation when transferring data to Okta and would have needed to report themselves long before the breach.