DataBait supports your GDPR compliance: the alert, sealed by a qualified eIDAS timestamp, proves your date of awareness, the certain starting point of your notification to the CNIL.
The GDPR requires you to notify a breach to the CNIL within 72 hours (article 33) and, where the risk to your customers is high, to communicate it to them (article 34): a critical deadline in e-commerce, where a leak triggers mass notification and exposure to collective redress (class action). Beyond the deadline, the leak itself is documented: in an inspection or in litigation, you demonstrate what you knew, when, and what you did about it. And when a third party uses your database for unsolicited marketing, the report establishes the breach under the electronic marketing rules (article L.34-5 of the French Postal and Electronic Communications Code).
If you run an online marketplace, Directive (EU) 2022/2555 (NIS2) classifies you among the important entities (annex II, digital providers); its transposition into French law (the Résilience bill) will require a documented ICT risk management framework, a notification timeline to ANSSI (early warning within 24 hours, notification within 72 hours, final report within 1 month), and monitoring of your providers. DataBait tools these pillars: a documented detection capability, an incident dossier timestamped within 72 hours, and continuous monitoring of your providers, with no additional audit.