EasyJet took four months to warn customers that hackers had their personal information
Under the General Data Protection Regulation (GDPR), organisations must tell the ICO – the UK’s data protection regulator – about a personal data breach within 72 hours. And, if the breach is likely to result in a “high risk of adversely affecting individuals’ rights and freedoms”, organisations must also inform those individuals without undue delay. So why did EasyJet take four months to warn customers that hackers had their personal information?