36
How much should an organisation reveal about a data breach?
(www.arrl.org)
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
Every little detail. Including access to the raw data that was leaked (that pertains to the individual). The steps taken to correct the action if possible. The source of the attack, including raw access logs if possible.
Basically, let me decide how fucked I am, how it happened, and who now has my data.
Please no. I don't want a copy my passport image included in the announcement about the data leak. Its extremely hard to change my passport, and its better if its not on the official announcement, even if it is being traded on the darknet.
They should say what data fields were leaked, but not re-leak the actual raw data to the world on the clearnet.
I didn’t mean they would publish the information to the internet in an insecure way. But I should, if i CHOOSE, get a copy of the leaked data. You don’t have to ask for it.
So you get kyc data on all their other customers? That's literally a criminal offence in some countries.
Nha they publish metadata describing the leaked data. If you’re a data subject concerned by the incident you then request a copy of yr information which requires proper identification.
Why would they share the data itself….
Why does wikileaks share the data itself? People do these things..
They are active in whistleblowing, not privacy leak management…