| ▲ | ratg13 10 hours ago | |
This is just a general American complaint that has merit on its own, but has nothing to do with the article and is just derailing any discussion about the article itself and driving the conversation to your own personal concerns about something completely separate. In this case, the EU does have consequences for data breaches where proper protocols are not followed. Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you. In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information. In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries. In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal. | ||