I have reviewed the recording again. The sales engineer said "one of our largest European customers" while showing the graph. That is not anonymized. That is directional. My counsel appointment is Thursday. I will report back on what language they suggest for amendment.
DDoS mitigation vendor leaked my attack data in a sales deck
In France the CNIL can fine for this even with contract. GDPR article 32, security of processing. Attack metadata is operational data, can identify infrastructure. You have 72 hours to notify if you consider it breach. I do not know if you want this way, but is option.
GDPR! YES! FINALLY SOMEONE WITH TEETH! MARCUS HOP ON THIS! THE FINES ARE 4% GLOBAL TURNOVER! THEY WILL SETTLE BEFORE LUNCH!
Calm down. GDPR fines for this are rare and take years. Contract breach is faster. I had a vendor leak my latency benchmarks once, took 14 months to resolve. NDA with liquidated damages clause got me 6 months service credit. Not great but done.
In UAE we see this with cloud providers showing "regional case studies." They think removing company name is enough. I now require explicit appendix listing what data categories are excluded from any marketing use. Takes longer to negotiate but worth.
Following this thread closely. We are evaluating DDoS vendors now and I will add this to our RFP questions.
Same approach here. I also add "including derived metrics, visualizations, and any data that could identify customer infrastructure topology." They hate it. Good.
Which vendor? DM if you prefer. I maintain a private list of provider deck fingerprints. Not for public but I share with affected parties.
I will DM. Not naming publicly, same reason marchhopper is careful. But it is not a small provider. That is what makes it worse.
My Madrid colo neighbor had similar with CDN provider. They showed heat map of his traffic during Black Friday. He had not even told them it was Black Friday, they inferred from traffic pattern. That is not anonymized, that is competitive intelligence.