Hacker News new | ask | show | jobs
by reaperducer 2725 days ago
I read that there was some kind of grace period involving GDPR penalties. Has the EU handed out any fines yet, or is it still letting companies adjust?
2 comments

Yes, the first case is done: https://www.welivesecurity.com/2018/11/27/german-chat-site-f...

The question is probably if it is state of the art to encrypt passport numbers. If yes, then Marriot could be fine with a similiar argument of "the company knowingly violated its duty to ensure data security".

> I read that there was some kind of grace period involving GDPR penalties.

the grace period started two years ago until may 2018...

people seem to forget that the GDPR was technically already a law in 2016, it was just not enforced.