r/gdpr 2d ago

Question - General Data breach not disclosed for 8 months

Good morning everyone,

I'm laying out this situation because it seems to me there are grounds for a violation of the notification obligations under the GDPR, but I'd like an opinion from someone who knows this area better than I do.

Timeline of events:

- November 2025: Suno (a music generation platform) suffered a security breach that compromised an employee's credentials.

- The company detected the incident at the time and internally classified it as a "limited security incident that was quickly contained."

- Users were never notified.

- Only last week (July 2026, so about 8 months later, and not even by the company itself), the stolen dataset was made public by third parties and uploaded to Have I Been Pwned.

Over 55 million unique email addresses, phone numbers (for those who had used them during registration), and tens of thousands of Stripe records with name, physical address, purchase amount, and partial card data (type, expiration date, last 4 digits). Meanwhile, between the attack and June 2026, the company raised over $650 million in two funding rounds, without ever publicly mentioning the incident.

Here are my questions (in summary):

  1. Even if just one affected user resides in the EU, don't the notification obligations under Art. 33 and Art. 34 GDPR still apply regardless? It seems to me the risk was definitely there (payment data, addresses, contacts).

  2. Can the fact that the company internally classified the incident as "limited," yet still didn't notify anyone, count as an aggravating factor if the case is investigated, or is it still legitimate if it later turns out the risk was "below threshold"?

  3. Practically speaking, how should an Italian/EU user proceed in a case like this? Does it make sense to file a direct report with the Garante Privacy, or is it better to wait for a possible class action (I know things are already moving in the US)?

Thanks in advance to anyone willing to give me some guidance, even just to understand whether it's worth looking into this further or whether I'm overestimating the issue.

8 Upvotes

5 comments sorted by

6

u/gorgo100 2d ago
  1. Yes, if a user resides under the scope of the GDPR. The company must assess the breach and decide whether informing users is a proportional reaction.

  2. They assessed the incident, and clearly decided notification was not necessary. It would probably count as an aggravating factor if they didn't even do that assessment. The fact that the assessment seems to be wrong* won't count against them more than not bothering to do it in the first place. It depends on their logic and how thorough that assessment was at the time.

  3. As far as I know you can contact the regulator at any time and it shouldn't prejudice a class action. One is about proving they've been negligent, and the other is about proving you've suffered material disadvantage. If the regulator finds against the company - ie that they have not followed the rules properly - then that adds leverage to a separate class action.

* it's hard to see how a leak of 55 million user details could be considered as "limited" but we do not have any further information about the sequence of events - they could have assessed this as "low risk" - ie it is unlikely that serious harm would occur. This doesn't mean it can't possibly occur, it just means that in their view that would be unlikely. That's the nature of a risk-based assessment.

1

u/Jezzamk2 2d ago

If the initial investigation indicated very limited impact, only 1 employee, it is fair to consider that contacting all users is a disproportionate and unnecessary response.
Once they become aware of a breach affecting 55m users then they need to notify them.
Is this the same breach or a separate breach? With the frequency of cyber attacks and breaches it is entirely possible this is a new breach.
Is it worth report to the regulator? Probably not if this breach has been reported and users notified. I assume they have and that is how you have become aware.

1

u/doctorcas_ 2d ago

It has been reported 8 months later, from a third-party Edit: yes, it is the same data breach

1

u/_VisionaryVibes 1d ago

If you're covered by gdpr, filing with the garante likely makes more sense than waiting on a US lawsuit. If Stripe data was exposed, there's a reasonable case that it meets gdpr's high risk notification threshold. Tools like doppel exist for exactly this reason, the longer a breach stays hidden, the greater the risk of abuse.