Some questions on the recent data breach

I’m about to crash out! Framework is losing me at this point for sure, I was about to order the newest Gen when the breach happened and now they show me why I should never buy again!

Am I alone or do others share this and do not get the answers they need? (No, i can’t use general, since read only! Not the way!)

They can’t answer basic request for it:

  1. Data Sharing Timeline: On what exact date(s) was my personal data transferred to or shared with Metabase?

  2. Purpose and Legal Basis: What was the specific business purpose for sharing my billing, shipping, and technical data with Metabase? Please specify the legal basis (e.g., Article 6(1) GDPR) relied upon for this transfer.

  3. Proof of Consent / Legal Ground: If this processing and third-party sharing was based on my consent, please provide definitive proof of when and how I explicitly agreed to it. If it was based on another legal ground (such as legitimate interest), please provide the details of your assessment.

  4. Mitigation Plan: What specific, immediate steps are you taking to mitigate the potential harm, risks, and negative consequences resulting from this breach for me?

  5. Future Prevention Measures: What technical and organizational measures have been or will be implemented to prevent such data breaches in the future?
    Automated Decision-Making, Profiling, and AI Usage:
    Furthermore, pursuant to Article 15(1)(h) of the GDPR, I hereby request that you clarify whether my personal data—either by your company or through the Metabase instance—has been subject to automated decision-making, including profiling.If profiling or automated evaluation took place, please provide meaningful information about the logic involved, as well as the significance and the envisioned consequences of such processing for me. In this context, I also request that you transparently inform me if any Artificial Intelligence (AI) systems or algorithms were involved in processing, analyzing, or profiling my data, and what safeguards were applied.

1 Like

FYI, there is a dedicated thread for this:

(Using my minor established-user powers, I have renamed your title, so that it matches the content of your message. I’ve also moved it to General, where I think you originally wanted it to go).

Incidentally, if you wish to assert your legal rights e.g. the basis for processing under GDPR then I suspect you should ask Support for a legal contact to message. Some companies operate a legal@ email alias, for example.

If it helps any, I was also hit in the third-party data leak, and while the event is unfortunate, I don’t think any claim that Framework were cavalier or acting with malice is going to succeed. There is a broad use category in GDPR called “legitimate interest” and I should think that will be the shield the legal-eagles will go for.

I would also like to see a substantive additional statement from FW, but it is not impossible that the lawyers are telling them not to do that. So, {shrug}, I guess. I still think they are a better company than Dell.

2 Likes