Sales engagement startup Apollo says its massive contacts database was stolen
techcrunch.com
techcrunch.com
One wonders how much the dataset would go for in the black market.
I don't know how the "compliance world" treats, that but I bet it's a loophole many many people are trying to squeeze through.
(I do actually consider it personal to you. And I am a fan of what GDPR is trying to accomplish, in principle, but it's clear the law doesn't really work yet).
My read is that the text of the law doesn't apply to people acting on behalf of a corporation, in their corporate persona (but this is why I linked to the text itself and not someone else's interpretation. It's not that long).
The law talks about identifying a person in their personal sphere (doesn't apply to being in your home; talks about ties to fundamental human rights, genetic and health info, etc) or things like credit approval, and many many many exceptions for "national security" an "legal" uses. It clearly does apply to what your employer knows about you!
Normally I hate these kind of hair-splitting "gotcha" cases I write up below, so I feel weird typing them. But the economic value is so high and frankly some of the the use, and abuse, cases so clear, I wonder. It's still early days for GDPR so these questions are, at the moment, rhetorical.
Here's an example: part (26) says, "The principles of data protection should apply to any information concerning an identified or identifiable natural person." But if I call a company the telephone receptionist will answer and I will know I can reach them by calling that number. If they have three I know I can reach the one I want to by calling repeatedly. Yet you don't want to prevent publication of company phone numbers (and what about suppressing them until the receptionist leaves -- that leaks personal info too). (the section is actually about pseudonymisation BTW).
Likewise per your example of IP addresses (in 30) If a company uses NAT then the company's IP address does not identify any single person, though it could be presumed to identify a particular subset. (adding IP address to other info could ID one person, and that is covered in 30)
I think stealing a whole database raises very serious questions as to how technically this was done and how would you prevent this at your company.
Unfortunately "transparency first" aside, companies don't usually release this information which leaves us all wondering how we can better protect our users (outside of having sane defaults, closed by default, no ssh, private networks etc...).
I understand why those details don't make it into the media, but it's hard not to be curious about it.
Eh? So are email addresses included or not? They’re listed in both categories.
Wow. They emailed customers but made no public announcement that people's email addresses and personal info had been stolen and now available on the black market.
This is absolutely atrocious incident management and disclosure. I smell a lawsuit, possibly from the state or federal government.
So I guess email addresses are a nullable field?
Basically it's about the emails that they were scraping / guessing, not their users' emails.