Elektrine lite

← Feed

@Trikkitt@mastodon.social

Post #4322531

2026-08-02 06:40 UTC

@flyingpenguin@infosec.exchange @briankrebs@infosec.exchange you're making a lot of assumptions without knowledge of what has actually happened. OpenAI confirmed the data has been deleted, we have no way to know if it was deleted only after they were notified or if they automatically deleted it when their crawler processed it. To use the term attacker implies that malicious actions were taken in order to obtain the data. That doesn't appear to be the case here.

Replies (1)

  • @Trikkitt@mastodon.social @briankrebs@infosec.exchange Shame on you. Malice is your weird criterion made up by you, not the law. GDPR liability is whether processing had a lawful basis. Anyone talking about intent is drunk on power. It is the weakest form of regulation because it is the most likely to be corrupted. Those who say intent matters come from a position of privilege to abuse it. Behavior is the law. A crawler that ingests names, IBANs, and policy numbers with no basis is an unlawful processor. Period. End of story. Whether or not anyone meant harm is a power game only the elites like to play (because they can wield it unfairly). The attack is the behavior. If OpenAI deletes personal data on ingest automatically, it holds no lawful basis for the collection in the first place, and the deletion is remediation applied after the fact, which presupposes the violation it cleans up. If it deleted only after Universa's notice, it retained protected data until caught. Both ways, unlawful processing under GDPR. You've named the only two options; neither is exculpatory.

    Open ##4322530