Yes, but now you are a "known risk". IN theory, if a company does not have a policy for a "known risk", they could be liable if a data breach occurred, whereas an "unknown risk" there is nothing they could have done, and therefore less penalty under the law.