Remix.run Logo
peri-cl 2 hours ago

> "The attack is not recent, however. It dates back to late June - the 26th, to be precise, according to the hacker - and the administration had detected and stopped it at the time, without ever saying a word publicly."

I thought GDPR mandated disclosure of data breaches involving PII. Is France's tax authority somehow exempt?

edit to add: Article 33 particularly,

https://gdpr.eu/article-33-notification-of-a-personal-data-b...

sam_lowry_ 2 hours ago | parent | next [-]

Rules for thee not for me.

hvb2 an hour ago | parent [-]

In the article I read about this it appears that they only found out now. They apparently launched an investigation and discovered the breach after being contacted by the hacker

rvz 2 hours ago | parent | prev | next [-]

Now you are realizing that some "rules" don't apply to others.

petcat 2 hours ago | parent | prev [-]

Well it certainly lends credence to the opinion that GDPR and similar regulations are mostly designed for EU revenue generation by extracting fines from American tech companies. The actual privacy protections are secondary.

Ylpertnodi an hour ago | parent | next [-]

That'll be the GDPR that protects my privacy and fines people that fuck about with it?

Yokolos an hour ago | parent | prev [-]

Having worked in multiple EU companies that went to great effort to comply with GDPR and also had legitimate issues that needed to be resolved under threat of real fines, this is just an incorrect take.