Data Breach Disclosure Lags Persist Despite Privacy Regulations (troyhunt.com)
0xBASE INTEL BRIEF
- Carnival notified victims 43 days after learning of ShinyHunters breach affecting 8.7M records.
- Zara delayed disclosure by 45 days; data included customer support records and order IDs.
- GDPR and CCPA loopholes allow organizations to avoid notification if no 'high risk' or 'sensitive data' involved.
- Class-action lawsuits immediately following breaches incentivize legal posturing over customer notification.
"Troy Hunt loaded the 1,000th breach into Have I Been Pwned. He notes that disclosure delays are worsening despite GDPR and CCPA. Examples: Carnival waited 43 days, Zara 45 days. He attributes delays to organizations prioritizing litigation protection over customer notification, and regulatory loopholes that allow non-disclosure if no 'high risk' or 'sensitive data' is involved."
#data breach disclosure delay
#privacy regulation loopholes
#class action impact on disclosure
no comments yet.