Skip to content

Comment on Booking.com ignores twofactor, lets everyone email-login without a passwordparent

Comments

Send an email with a request to remove/delete your account. They are a Dutch registered company and therefore have to comply AFAIK. Otherwise, informing the Dutch consumer watchdog might be an alternative.

Note: IANAL

I also think they have to comply because of this: https://gdpr-info.eu/art-17-gdpr/

I mean, GDPR also requires them to disclose the data breach publicly within 72h of detection, but it seems like they're not even remotely interested in that.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.