← Back to context

Comment by Volundr

6 days ago

Maybe it includes applications outside the US?

They use this site for hiring globally. The number of privacy regulators they will have to notify and deal with is going to make this messy.

  • If this was disclosed via a vulnerability disclosure or bug bounty program and there are no indicators of a data breach then it's effectively like the findings from a pen-test so very likely no regulatory reporting requirements.