| One important thing to note is that the DPC (Irish DPA) did not want to fine WhatsApp and only did so after being forced by other DPAs through the arbitration process. You can consult the EDPB decision on that matter here: https://edpb.europa.eu/our-work-tools/our-documents/binding-... EDIT: Max Schrems' reaction (NOYB): >"We welcome the first decision by the Irish regulator. However, the DPC gets about ten thousand complaints per year since 2018 and this is the first major fine. The DPC also proposed an initial € 50 million fine and was forced by the other European data protection authorities to move towards € 225 million, which is still only 0.08% of the turnover of the Facebook Group. The GDPR foresees fines of up to 4% of the turnover. This shows how the DPC is still extremely dysfunctional." source: https://noyb.eu/en/statement-dpc-issues-eu-225-million-fine-... |
> The objection raises that not all computationally possible numbers are indeed assigned. Therefore, the lossy hash refers not to at least 16 numbers but to a maximum of 16 numbers. Furthermore, if additional data is stored along with the lossy hash, the number of individuals represented by the associated phone numbers can be reduced as data subjects not matching this additional data can be excluded. If e.g., so the DE SA, the gender is also stored, it is possible to at least divide these 16 in half.
So their hashcodes can be mapped to 16 different users, which can be trivially reduced to a single person if you have any additional information about them.