Granted this was years ago - I don't know what people do these days if all backend servers are unavailable.
I guess the alternative to "planned maintenance" is the more-accurate message of "OMG - shit's on fire dude!" but that is not appropriate for corporate PR speak ;-)
Sounds to me like someone probably got a "turn everything off while the police investigate - do not touch anything or we'll chop your fingers off/fire you" edict from management, so they wont even put up an unplanned-emergency message for fear of crossing-management/damaging evidence/screwing up while putting up a rushed message/letting hackers back in/etc
They should put up a responsible message and pro-actively notify customers too. I hope they will get the highest possible fine for GDPR violations. This is an appalling response and treatment of customer data.
* https://twitter.com/joetidy/status/1214599174664138757
edit: also they gave a different (spreading virus v. third party issue) statement here earlier: https://eandt.theiet.org/content/articles/2020/01/travelex-t...
Travelex should have notified their supervisory authority within 72 hours of the breach, and are also required to notify end users in a timely manner.
https://gdpr-info.eu/art-34-gdpr/
According to the article, end users still have not been notified.
The lack of timely and proper notification as well as the misleading website information can be taken into account by the data protection authority in determining if the company should be fined, and the fines in question can be quite substantial.
To clarify, it's not that Travelex is located in or operates in Europe, it's that they hold data of EU residents. If they operated in Zimbabwe yet held data on EU residents, they would still be bound by GDPR.
But your question is interesting. Imagine an onion service, theoretically perfectly shielded, that took Personal Data from it users and then sold it. Or even a normal Internet service, based in North Korea. GDPR would be unenforceable.
Ultimately we depend on the norms of international agreements, the desire and need to interoperate with global banking systems, etc.
The GDPR text basically says "we'll ask other countries nicely and negotiate with them".
I'll be interested to see how the first real case goes against even a US-based entity that doesn't operate in the EU, much less one based in a country like North Korea.
..they'll ask all the EU ISPs in each of 28 member states to block company X - nicely.
() "EU citizens" meaning potential customers of company X - the "enticement" for company X to pay the EU the fine.
All kinds of companies, from all over the world (eu or not) flooding the GDPR headquarters in Brussels with "pre-emptory warnings". The purpose of course being to let them know how ridiculous (and possibly/probably arbitrary) their regulatory framework
And is anyone else annoyed that since GDPR started, every single website that even so much as stores your username now has a "this website uses cookies" thing you have to click on to get rid of it? And if you turn off cookies, you see this damn intrusive thing every single time. How is this making the web "safer"?! Can "we" (whatever that means) petition them to enact a standard where people can set a preference in their web browsers that says "I don't care unless it's financial/medical/physical-address data" It's a $#%$5# pain in the collective derriere.
I wouldn't be surprised if some websites are doing it as a matter of course, "just in case" - like the "this product contains things that are known to cause cancer cause cancer to the state of California" - applied to everything - in a catalog that sells drill bits (okay, I suppose the couple of nano-grams of drill-bit-dust coming off it). Just to be safe (pun unintended).
I am indeed very annoyed that so many companies are throwing an online tantrum over the very reasonable requirements of GDPR. Most of those cookie banners aren't even GDPR-compliant because they don't let you opt-out of tracking and don't actually tell you what data they are tracking or who they are giving it to.
Just tell people what you are actually fucking doing with their data and let them opt-out of having their data collected. It's not that fucking hard.
In a hypothetical situation of a non EU company significantly breaching GDPR this could be resolved by e.g. seizing all funds belonging to the company in EU banks or in extremes by finding the company's board in contempt of court and then arresting and imprisoning them if they ever travel to a country with a extradition agreement.
I'm puzzled by this:
> "Stealing data essentially gives threat actors additional bargaining chips when it comes to dealing with companies unwilling to pay the ransom. The idea is to weaponise the hefty fines associated with GDPR violations to pressure the company into paying."
I can't imagine that promises from REvil/Sodinokibi that stolen data had been deleted would reduce fines over GDPR violations.
Website's "fine" - it's just waiting to be plugged into something that works.