Hacker News new | ask | show | jobs
by bastawhiz 1866 days ago
It sounds like the data leaked was not PII, which is outside the scope of GDPR personal data breach guidelines.
2 comments

Filenames were leaked, which could very well contain PII.
Something as simple as an IP address (which you're implicitly leaking by just loading any resource from the third-party domain) is considered PII under the GDPR.