Cbridge_Chief<p>Some thoughts on this <a href="https://mastodon.ie/tags/ArtsCouncil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ArtsCouncil</span></a> story in the Indo today <a href="https://m.independent.ie/irish-news/arts-council-asked-for-sexual-identity-and-religion-of-those-seeking-grants/a909106926.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">m.independent.ie/irish-news/ar</span><span class="invisible">ts-council-asked-for-sexual-identity-and-religion-of-those-seeking-grants/a909106926.html</span></a>. First off: DPC can’t “grant an extension” on data breach notifications under Article 33. 72 hours is a hard deadline. After that data controllers (like the Arts Council) got some ‘splainin’ to do. I suspect this is what has happened. Also: highly likely this breach only on DPC radar because of (waves hands) all the other things.</p>