- The 1,000th data breach was loaded into Have I Been Pwned, raising questions about why the service is still needed despite privacy regulations like GDPR and CCPA.
- Increasingly long lag times for breach disclosure worsen the situation, with Carnival waiting 43 days and Zara 45 days before notifying victims.
- Organizations often delay disclosure citing the need for thorough analysis, but early notification of email addresses is straightforward and feasible.
- The rise of class-action lawsuits may contribute to longer disclosure lags as companies prioritize litigation posture over customer protection.
- Privacy regulations contain loopholes allowing organizations to avoid notifying individuals if the breach is not deemed to pose a high risk or serious harm, leading to potentially infinite delays.
- Despite legal obligations being absent in many cases, there is a social expectation for breach disclosure, which remains unfulfilled, justifying HIBP's continued existence.