Menu
Home
Forums
New posts
Search forums
What's new
Featured content
New posts
New media
New media comments
New resources
Latest activity
Media
New media
New comments
Search media
Resources
Latest reviews
Search resources
Nyuuz
Jinaral kantent
Log in
Register
What's new
Search
Search
Search titles only
By:
New posts
Search forums
Menu
Log in
Register
Install the app
Install
Home
Forums
Labrish
Nalij
Jinaral kantent
Why Suno's breach-notification decision matters
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Reply to thread
Message
[QUOTE="Bombastus, post: 92247, member: 2178"] Suno said it decided in November 2025 that individual breach notifications were not warranted under applicable privacy laws. The company also said its investigation found a limited incident involving mainly outdated source code and no sensitive personal information. Public reporting changed the picture months later. In July 2026, a verified breach dataset was described as containing more than 55 million unique email addresses, phone numbers for some users, and tens of thousands of Stripe purchase records with names, physical addresses, purchase amounts, and partial card details. Those two descriptions are uncomfortable beside each other, but they do not automatically prove a notification-law violation. The harder issue behind [B][URL='https://goldmidi.com/community/threads/suno-faced-a-proposed-class-action-over-a-55-3m-user-breach.77640/']Suno's decision not to notify affected users[/URL][/B] is whether the specific information taken from particular residents crossed the legal notification threshold in the states whose laws applied. [HEADING=2]Breach-notification law uses narrower definitions[/HEADING] Everyday language makes this sound simple. An email address, home address, phone number, and purchase history are plainly personal information in the ordinary sense, yet breach statutes often use narrower technical definitions that determine when mandatory notice begins. Massachusetts is a useful example because Suno is based there. Its breach law defines protected personal information around a resident's name combined with specified identifiers such as a Social Security number, driver's license number, or financial account or payment-card information capable of permitting access to a financial account. An email address by itself does not satisfy that statutory definition. The distinction matters for Suno because the publicly described dataset is uneven. More than 55 million email addresses form the broadest layer, while richer Stripe records make up a much smaller portion, and the public descriptions identify partial card details rather than complete card numbers. Knowing a breach contains names, addresses, and the last four digits of some cards does not tell you whether every affected Massachusetts record met the state's statutory trigger. [HEADING=2]A nationwide breach creates several legal tests[/HEADING] Suno had users across the United States, so Massachusetts law is not the only relevant rule. State breach statutes differ over the information they protect, the level of likely harm needed to trigger notice, deadlines, regulator reporting, and circumstances that permit delayed or substitute notice. The [B][URL='https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4164674']patchwork of breach-notification triggers and enforcement rules[/URL][/B] is especially important when a dataset mixes basic contact records with smaller pockets of richer information. A company's conclusion can therefore depend on which resident is being assessed and which fields were attached to that person's record, rather than on the headline size of the breach alone. South Dakota shows the difference clearly because Michael Beckham, the plaintiff in the newest proposed class action, is domiciled there. State law requires notice when covered personal or protected information was acquired, or is reasonably believed to have been acquired, by an unauthorized person. It generally sets a 60-day window after discovery or notification of the breach. South Dakota also allows an information holder to avoid individual disclosure after an appropriate investigation if it reasonably determines the breach is unlikely to result in harm, with notice to the attorney general and written documentation retained for at least three years. Its protected-information definition includes an email address paired with a password, security-answer information, or something else that permits access to an online account. An exposed email address standing alone is a different case. [HEADING=2]The missing facts decide more than the headline[/HEADING] The public record still lacks several facts needed to judge Suno's notification decision cleanly. We do not have a complete resident-by-resident breakdown of the stolen fields, Suno's internal legal analysis, its forensic findings at the time, or a full public record of any regulator communications made under individual state laws. Timing is another separate issue. Massachusetts requires covered notices as soon as practicable and without unreasonable delay, while South Dakota generally specifies 60 days unless an exception applies. Suno knew of the security incident in November 2025, but the breach became public roughly eight months later after outside reporting and the dataset's appearance in breach-notification services. A long gap can look damning without answering the legal trigger first. If a state's covered information was not compromised, its consumer-notice deadline may never have started under that statute. If covered information was compromised and no exception applied, the timing rules become much harder to ignore. The strongest unresolved point is therefore not simply that Suno stayed quiet for months. It is whether Suno's November assessment matched the information later shown to exist in the stolen corpus, including the smaller set of records containing physical addresses, purchase histories and partial payment-card details. Publicly available descriptions establish the tension, but the missing per-user data and internal investigation records are what would determine where a notification duty actually attached. [/QUOTE]
Insert quotes…
Name
Post reply
Home
Forums
Labrish
Nalij
Jinaral kantent
Why Suno's breach-notification decision matters
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.
Accept
Learn more…
Top