Ask HN: Does GDPR force companies to disclosure security vulnerabilities?
If security researchers find a vulnerability involving direct access to PII and report it to the company affected, is the company required to disclose it to their customers?
Article 34[1] says it is required to so in case of a data breach.
Can an incident like this be seen as a data breach?
[1] https://gdpr-info.eu/art-34-gdpr/