Skip to content

Comment on Universities Targeted by NetWalker Ransomwareparent

Comments

The GDPR has been here for two years already; the hypothetical scenario you describe has discussed but has not shown itself in practice.

Would we actually know if it had happened though? Or are you assuming that it would simply be infeasible to keep under wraps?

The hypothetical scenario of "if they don't pay the ransom, the data is leaked, and they are now liable under GDPR and will likely have to pay a (very large) fine to the regulator for the data leak." has not materialized. The grandparent post is based on the thieves making an empty threat.

If criminals compromise your systems and steal data that you are legitimately storing in a reasonable manner, then the breach by itself is not a justification for any major fines under GDPR - but not reporting a data breach definitely is punishable.

Here's a recent example of a data breach in a telecom company- https://www.timelex.eu/en/blog/belgian-data-protection-autho... - "the data breach was correctly reported and that the company had taken appropriate organisational and technical measures. A data breach therefore does not necessarily give rise to a fine."

The only scenario where this threat might be real is if the breach would expose some previous wrongdoings, e.g. if the company was collecting the data in an illegal manner and had kept that fact hidden until the breach, if then, sure, that could be a valid basis for blackmail because the breach would suddenly expose the fact that you deserved some regulatory action long ago. Of course, any disgruntled employee also could try the same blackmail. However, if you're a legitimate company doing everything as required per law (including proper notification of data breaches), then the consequences of publishing that data would involve reputation costs and perhaps some civil claims for damages, but not any GDPR fines.

There's a potential for fines if breach happened because of your gross negligence, there's some precedent for that - for example, the Mariott data breach case. But again, the fines and their amount aren't automatic (the law just sets a ceiling), administrative proceedings take into account the circumstances and intent, all the largest fines assigned so far are significantly below the maximum. However, we should expect that the scenario of intentionally paying a ransom to hide the breach and "avoid the fines" would actually result in more severe penalties (because it checks pretty much all the boxes for aggravating circumstances) while properly handling a breach would result in reduced fines even if serious negligence was involved.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.