Editorially speaking I'm glad to see this emerge even though it means more work for me personally. If anything some of the fines seem too low. (I'm looking at you, Equifax.)
Editorially speaking I'm glad to see this emerge even though it means more work for me personally. If anything some of the fines seem too low. (I'm looking at you, Equifax.)
A business that accepts credit cards can easily end up storing credit card numbers in places they do not intend to. That can happen even if they do all their intentional credit card handling through an outside service that their check out pages post to or AJAX to so in theory no credit card number ever even reaches the business' servers.
For example, customers will email you to tell them that the credit card they pay their subscription with is about to expire, and give their new credit card number and security code in the email (and for good measure often give the old credit card number and security code).
Same for your help desk system, regardless of whether it is based on email or web forms. Customers are going to stick credit card numbers in tickets.
I don't think I've personally seen a customer stick a credit card number in a forum post or in a blog comment, but I wouldn't it past them.
Basically, if customers can put text in it [1], you really have to assume some customer is going to put a credit card into it. I'm not kidding. I've seen credit card numbers show up in name and address fields.
Oh, and when they stick unrequested credit card numbers in emails, support chats, etc., they will often format them in weird ways. If you want to find these you have to make your scripts that search for them quiet lenient in what they accept, but then you get a lot of false positives.
[1] ...or speak into it.
Then the question is did they have the appropriate safe-guards in place, w.r.t. the importance of the data. I don't think we quite know what their systems look like. But the answer is probably not, given the scope, amount of very personal data, and the fact data from US, Canadian, and UK individuals was leaked, and the time it took to notice the breach.
Factoring both these things in and maybe the fact that an executive was charged with insider trading, they could be fined accordingly.
One of the major problems with the breach is that, if you are worried about Equifax's security, you can't just choose to not let them store your data: they will store it, and provide it to third parties, regardless of your consent.
Depending on cause, potentially also not having sufficient security procedures in place to avoid such a leak of PII occurring.
1.) Protect the data with methods corresponding the risk level (Articles 32 and 35)
2.) Enable users to erase, correct, or transfer data at will (Article 15)
3.) Enable users to consent to use of their data in the first place (Article 15)
So yes, it seems it would have been quite applicable.
4.) Notify the supervisory authority of any data breach within 72 hours (Article 33)
5.) Notify the subject of any data breach without undue delay (Article 34)
And the broader issue of remedies and penalties in Chapter 8.
They will however copy the GDPR as an excuse to create tools to prevent disruption, manipulate markets, and to expand their organizational reach.