Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The French CNIL just fined an association for 75,000 € for a leak in their data.

It was a 2017 case, but I guess it will reflect what can happen ?



Can you link to this? Searching for "CNIL", "75,000" and "2017" doesn't turn up anything useful.


https://www.lexpress.fr/actualites/1/styles/protection-des-d...

tl;dr: a non-profit got fined 75K€ because their website leaked 42,562 private documents from their users. Anyone could modify numbers in the URL and read other users' documents. The documents included passports, tax information, identity documents, and more.

EDIT: better source: https://www.cnil.fr/fr/sanction-de-75-000-euros-pour-une-att...


Oof, I can see why then. On the other hand, if you're not storing people's passports... is this really something you should be worried about? And shouldn't somebody who's intentionally storing thousands of passports be required to implement basic security practices?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: