> I wouldn't be surprised if this was never acknowledged by Meta.
It will, at least, have to be acknowledged by making GDPR Art. 33 notifications.
It will, at least, have to be acknowledged by making GDPR Art. 33 notifications.
They have yet to acknowledge the recovery method disclosure vulnerability which was exploited on a massive scale in February. The last time I checked, email addresses and phone numbers were PII. I don't live in the EU, but someone who does should complain to the relevant authorities about that.