PPRuNe Forums - View Single Post - Here We Go Again
View Single Post
Old 22nd Nov 2018, 00:17
  #19 (permalink)  
YeahNahYeah
 
Join Date: Mar 2017
Location: Australia
Posts: 54
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by Hong Kong Dave
Surprising anyone would say this because it's not a judgement call at all. I can only assume this was the script from a Public Relations idiot, with zero knowledge of the law.
Under GDPR, if you have personal data on any EU residents, you have a duty to disclose a breach to the authorities within 72 hours, and to the affected persons "without undue delay".
While they did eventually notify the Hong Kong police cyber crime team, it was months after the event.
Even if the attack took place before the GDPR watershed on the 25th of May, the failure to notify within 72 hours was ongoing while the regulations were in force.
These are the facts.

It's now up to the EU whether they want to make an example of Cathay or not.
My unsubstantiated gut feel is that while it isn't the vampire squid involved, it is something close to it in terms of scale and rudely inserted tendrils, so it'll be a bit quietly sorted...
YeahNahYeah is offline