Hacker News new | ask | show | jobs
by WhoBeI 2502 days ago
Right, so slap the largest fine on each one. They had 2 years to prepare and obviously didn't.

Before the GDPR this would have been stamped "identity theft" putting the company in the clear. As if you were somehow responsible for the company not verifying the identity of their customers.

[Edit]

I should mention that around here there is an established 2FA solution used by banks and the government so verification has been de facto standardized.