Earlier quoted context omitted.
They are absolutely required to report this to the data protection agencies in all European countries. As the other comment mentioned, missing the 72 hour deadline on this is enough to get a fine as Booking.com did. I'm curious to see the total in GDPR fines from this for Facebook. Will probably take a year or two before we know.
At this point they must be like a deer in front of the flashlights, hoping the car will dodge them.
Facebook does not plan to notify half-billion users affected by data leak
51–60 of 101 posts
Re: Facebook does not plan to notify half-billion users affected by data leak
#52Aren't they required to disclose this, at least to California residents, under California's data breach disclosure laws? Or was it not the type of PII covered under the law?
The July 2019 FTC settlement requires Facebook to report details about unauthorized access to data on 500 or more users within 30 days of confirming an incident."
Seems like it.
Re: Facebook does not plan to notify half-billion users affected by data leak
#53So after longing it out, today I had a look on haveibeenpwned, and it seems I am one of those whose data has leaked. After re-reading all of the events of this breach, it seems that the exploit was fixed in Aug 2019 (as claimed by Facebook). I had deleted my account some 2 years prior to that. Either these attackers have had access for over 2 years, or Facebook has not deleted my data, and likely everyone else's data…
Re: Facebook does not plan to notify half-billion users affected by data leak
#54Sometimes I wonder if the data from the cameras on my Oculus Quest 2 is being sent to FB's servers and kept. I guess I'll never know.
Re: Facebook does not plan to notify half-billion users affected by data leak
#55So after longing it out, today I had a look on haveibeenpwned, and it seems I am one of those whose data has leaked. After re-reading all of the events of this breach, it seems that the exploit was fixed in Aug 2019 (as claimed by Facebook). I had deleted my account some 2 years prior to that. Either these attackers have had access for over 2 years, or Facebook has not deleted my data, and likely everyone else's data…
Renowned hacker Inti De Ceukelaire informed facebook of this breach in 2017, but FB just sat on it for a year and did nothing, ultimately claiming it was scraped from publicly available data at the time.
So while we do not know and can only assume deleted data is merely indicated by a flag and not really deleted, this exploit does not include data from closed/deleted accounts.
FB doesn't allow user access to/control of/deletion of shadow account data, which is in violation of the GDPR.
Re: Facebook does not plan to notify half-billion users affected by data leak
#56And they apparently also didn't plan on deleting my PII (phone number was in the leak), even after I permanently deleted my account at FB over 3 years ago. I thought I had the 'right to be forgotten' because of the GDPR, as I'm a European citizen. Has there been any real enforcement of these laws aside from the relatively small fine here and there? I've been blocking FB actively for the last few years, I can't even v…
If you're in Europe you can file a complaint with your local data protection agency. They will definitely already have some investigation on Facebook so this just adds more to it.
Re: Facebook does not plan to notify half-billion users affected by data leak
#57Earlier quoted context omitted.
They are absolutely required to report this to the data protection agencies in all European countries. As the other comment mentioned, missing the 72 hour deadline on this is enough to get a fine as Booking.com did. I'm curious to see the total in GDPR fines from this for Facebook. Will probably take a year or two before we know.
GDPR is a gift to large corporations. Regulatory capture in return for a slap on the wrist. It also burdens startup competition and trains people to click "Allow Cookies" and "Accept the Terms of Service" as fast as possible.
The "Allow Cookies" and "Accept Terms of Service" click-throughs also barely meet any of the GDPR requirements and in the case of the latter don't necessarily constitute informed consent: EU courts have repeatedly ruled that a wall of text can not be used in software to hide "surprising" rules (e.g. that your WhatsApp account will be banned if you use a third-party client).
Re: Facebook does not plan to notify half-billion users affected by data leak
#58Yeah, can you imagine them having to tell Zuck his number got leaked. He's gonna be furious! Source: https://www.androidauthority.com/mark-zuckerberg-signal-1215...