His first newsletter seemingly goes pretty well.
He writes it from his own email address, pasting everyone who signed up in the “to” field.
The problem is, each of these customers can now see each others’ email addresses by looking at who the message was sent to.
This is considered a GDPR data breach. It might not be as serious as having his account hacked, but it’s a breach nonetheless.
