I think Sulake are playing with fire here. I was affected by the leak with personal info stolen. I had preliminary discussions about opening a legal case against Sulake which I won't discuss in detail. The information stolen here led to me being harassed at work, at home and over social media. I almost lost my job as a consequence of what people were able to do with my personal data. If I had lost my job, I would have undoubtedly taken decisive action.
Anyway, under the Data Protection Act Sulake are expected to do the following:
- Encrypt any personal information held electronically that would cause damage or distress if it were lost or stolen - they didn't.
Therefore, the rights of the individual in the same act states that:
- A right to claim compensation for damages caused by a breach of the Act.
Essentially, Sulake are expected to take measures to keep their systems secure. Okay, so the obvious argument is that it is Zendesk and not Sulake. However, Sulake are still legally responsible. They chose to remove their internal system and out source it to Zendesk. This decision ensured that a 15 year old boy could access thousands upon thousands of emails, phone numbers and credit card information.
They can sue people but they should have taken a lot more responsibility than they did. They never told me my information was stolen which also breaks the law. I had contact with Sulake staff in Finland who made it pretty clear they knew parts were stolen but did not know what, when or how. All of which I have email proof of.
If this game wasn't played mostly by teenagers who don't understand how dangerous this loss of information could be then they would have been sued and fined as and when it happened.