Hacker News new | ask | show | jobs
by chippiewill 1548 days ago
The compromised tenant looks like it was specifically _not_ one of the EMEA ones so GDPR wouldn't be relevant here.
2 comments

I think the issue is that they just wouldn’t know. They didn’t know which customers were impacted. They didn’t know which users personal data might have been compromised. They most likely don’t have the ability to determine whether a user is a EU resident or not as this information would reside with their customers HR systems which all points to having to notify to avoid the legal complications.
If the tenant had 1 or more European employees in their system, then yes GDPR is likely relevant.