Hasty Briefsbeta

Bilingual

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

a day ago
  • The 1,000th data breach was loaded into Have I Been Pwned, raising questions about why the service is still needed despite privacy regulations like GDPR and CCPA.
  • Increasingly long lag times for breach disclosure worsen the situation, with Carnival waiting 43 days and Zara 45 days before notifying victims.
  • Organizations often delay disclosure citing the need for thorough analysis, but early notification of email addresses is straightforward and feasible.
  • The rise of class-action lawsuits may contribute to longer disclosure lags as companies prioritize litigation posture over customer protection.
  • Privacy regulations contain loopholes allowing organizations to avoid notifying individuals if the breach is not deemed to pose a high risk or serious harm, leading to potentially infinite delays.
  • Despite legal obligations being absent in many cases, there is a social expectation for breach disclosure, which remains unfulfilled, justifying HIBP's continued existence.