{"id":2140198,"date":"2026-10-06T15:45:11","date_gmt":"2026-10-06T13:45:11","guid":{"rendered":"https:\/\/kohenavocats.fr\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/"},"modified":"2026-10-06T15:45:11","modified_gmt":"2026-10-06T13:45:11","slug":"has-asos-been-hacked-snowflake-notification-france-rights-gdpr","status":"publish","type":"post","link":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/","title":{"rendered":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France"},"content":{"rendered":"<p>On 6 October 2026, users of the ASOS mobile app received a push notification titled \u201cAsos hacked\u201d which claimed that the online fashion retailer&#8217;s data had been \u201cfully compromised\u201d through its Snowflake instance and directed readers to a Telegram channel, according to reports published the same day by the BBC, The Guardian and The Times. The retailer&#8217;s share price fell by more than 14 percent on the London Stock Exchange, while its website and app continued to operate. The company stated that it was aware of the reports and was still investigating whether any intrusion had actually taken place. No official source had, at the time of writing, confirmed an intrusion, a leak of customer data or any harm to account holders, and no liability has been established; only a court can decide such questions, and the contracts signed between the retailer and its customers prevail over any general analysis. The developments below are general in scope: they describe the practical and legal checks that are useful for any customer in France who receives such a notification, and they do not describe the situation of any particular company.<\/p>\n<p>French customers are directly concerned because the retailer sells and delivers in France through its French-language storefront, so the personal data of customers residing in France is processed under Regulation (EU) 2016\/679, the General Data Protection Regulation, alongside French criminal law. This article therefore answers two questions in order: what is known about the notification of 6 October 2026 and what to do immediately, then which remedies exist in France, from the complaint before the CNIL to compensation and the criminal complaint (plainte).<\/p>\n<h2>I. Has ASOS been hacked? What the notification of 6 October 2026 shows<\/h2>\n<h3>A. What is the \u201cASOS hacked\u201d Snowflake notification reported by the press?<\/h3>\n<p>According to The Guardian, thousands of customers received a notification titled \u201cAsos hacked\u201d with a link sending them to the Telegram messaging service, and the message read: \u201cDear Asos DPO (data protection officer) and IT, we have fully compromised the Snowflake instance.\u201d The acronym DPO designates the d\u00e9l\u00e9gu\u00e9 \u00e0 la protection des donn\u00e9es (data protection officer), the person whom the regulation requires large controllers to appoint as a contact point for data protection matters. The BBC reported app users describing a \u201cconcerning\u201d pop-up message apparently coming from hackers, and The Times described app customers receiving an alert suggesting a data breach. These three national outlets agree on the core facts: a message was genuinely pushed through the retailer&#8217;s own app notification channel, it asserted a total compromise of a Snowflake environment, and it invited the company&#8217;s data protection and IT teams to negotiate failing which data would be leaked.<\/p>\n<p>Snowflake, as described in the same press reports, is a cloud platform used to store, process and analyse data, including transactions and demographic information such as clothing sizes and body measurements, and it also enables push notifications to customers&#8217; phones. The fact that the message travelled through the app&#8217;s own notification system is what makes the episode worrying from a technical point of view: Dray Agha, senior manager of security operations at Huntress, an online security firm, is quoted as saying that Snowflake is a large cloud database where retailers typically store sensitive customer information and that the push notification suggests the attackers may also have reached the systems controlling the mobile app. That assessment remains an assessment, not a finding: at the time of writing, it is not established by any official source that customer data was accessed, copied or published, and the retailer itself has not confirmed any of the claims.<\/p>\n<p>The link in the message reportedly directed customers to a Telegram channel operated by an apparent group calling itself Xuanye. According to the press reports, threat researchers stated that they had never heard of that group on hacker forums or other Telegram channels, and one researcher quoted observed that new groups often wait for what they regard as a significant opportunity before announcing themselves so as to enter the ecosystem with credibility. In other words, the name behind the claim is unknown to the threat researchers who track extortion groups, which calls for caution in two directions: the claim may understate a real intrusion, or it may overstate access that the authors do not actually have. Customers should therefore treat the notification as a serious warning signal without treating the alleged compromise as a proven fact.<\/p>\n<p>The episode follows a series of cyber incidents affecting British retailers in 2025, recalled by The Guardian: Marks and Spencer, which had to close its website for several weeks, the Co-op, and Harrods. That context explains the market reaction, with the retailer&#8217;s shares diving more than 14 percent during the day, but a share price movement proves nothing about the underlying facts. For a customer residing in France, the useful conclusion at this stage is narrow: a message asserting a compromise was pushed through the retailer&#8217;s app on 6 October 2026, the national press reported it with the company&#8217;s acknowledgment that it was investigating, and everything beyond that, including whether French customers&#8217; data is affected, remains conditional.<\/p>\n<h3>B. Has the retailer confirmed a data breach, and what should customers in France do right now?<\/h3>\n<p>The short answer is no. According to The Guardian, the retailer said it was aware of the reports of a hack but did not confirm or comment further, and it is understood that it was still investigating whether any hack had taken place while the website and app appeared to continue operating normally on the morning of 6 October 2026. Several elements weigh in the company&#8217;s favour and must be stated plainly: the online store and the app stayed online, no category of allegedly affected data has been confirmed by any official source, no sample of customer data has been authenticated in the reports available at the time of writing, and the authors of the message remain unidentified. None of this rules out a real incident, since investigations of this kind take time, but none of it establishes one either.<\/p>\n<p>The most immediate danger for customers, including those in France, does not come from the alleged intrusion itself but from what follows such publicity. Marijus Briedis, chief technology officer at the online service provider NordVPN, is quoted in the press warning customers to watch what happens next, because high-profile cyber incidents create ideal conditions for phishing attacks in which criminals send emails and text messages claiming to be from the retailer, asking the recipient to reset a password, confirm payment details, check an order or claim a refund. That warning applies with full force to French customers: any message received in the coming days that invokes the incident to request credentials, bank details or a payment should be regarded as suspect by default, even when it displays the retailer&#8217;s logo and correct order references.<\/p>\n<p>Five practical steps are advisable without delay. First, do not click the link in the suspicious notification and do not join the Telegram channel it promotes; opening such channels exposes the visitor to further malicious content and weakens any later evidential record. Second, change the password of the retailer&#8217;s account, choosing a password used nowhere else, and activate multi-factor authentication if the account offers it, since credential reuse is the main way in which one incident becomes several. Third, keep dated evidence: screenshots of the notification as received on the phone, the time of receipt, the state of the account, and any subsequent suspicious message, because French courts and the CNIL both require proof of concrete facts rather than general assertions. Fourth, monitor bank statements and payment instruments linked to online purchases over the coming weeks, and use the opposition procedures of the card issuer at the first unexplained debit. Fifth, check the account&#8217;s order history and personal details for any modification the holder did not make, and report any anomaly to the retailer in writing so that a dated record exists. These steps cost nothing, preserve rights, and remain useful whatever the investigation eventually concludes.<\/p>\n<h2>II. What rights do customers in France have after a breach notification?<\/h2>\n<h3>A. Must the company notify the CNIL within 72 hours, and how does a customer complain in France?<\/h3>\n<p>European law places the first obligation on the controller, not on the customer. Article 33, paragraph 1, of Regulation (EU) 2016\/679 provides that \u201cEn cas de violation de donn\u00e9es \u00e0 caract\u00e8re personnel, le responsable du traitement en notifie la violation en question \u00e0 l&#8217;autorit\u00e9 de contr\u00f4le comp\u00e9tente conform\u00e9ment \u00e0 l&#8217;article 55, dans les meilleurs d\u00e9lais et, si possible, 72 heures au plus tard apr\u00e8s en avoir pris connaissance, \u00e0 moins que la violation en question ne soit pas susceptible d&#8217;engendrer un risque pour les droits et libert\u00e9s des personnes physiques. Lorsque la notification \u00e0 l&#8217;autorit\u00e9 de contr\u00f4le n&#8217;a pas lieu dans les 72 heures, elle est accompagn\u00e9e des motifs du retard.\u201d (\u201cIn the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.\u201d) (<a href=\"https:\/\/www.cnil.fr\/fr\/cybersecurite\/les-violations-de-donnees-personnelles\">CNIL guide on personal data breaches: notification within 72 hours<\/a>). The 72-hour period therefore runs from the moment the controller becomes aware of the breach, and any late notification must explain the delay. The controller must also document the breach, its effects and the remedial measures so that the supervisory authority can verify compliance.<\/p>\n<p>Where the breach is likely to create a high risk for individuals, the controller must also warn the customers themselves. Article 34, paragraph 1, of the same regulation states that \u201cLorsqu&#8217;une violation de donn\u00e9es \u00e0 caract\u00e8re personnel est susceptible d&#8217;engendrer un risque \u00e9lev\u00e9 pour les droits et libert\u00e9s d&#8217;une personne physique, le responsable du traitement communique la violation de donn\u00e9es \u00e0 caract\u00e8re personnel \u00e0 la personne concern\u00e9e dans les meilleurs d\u00e9lais.\u201d (\u201cWhen the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.\u201d) (<a href=\"https:\/\/www.cnil.fr\/fr\/cybersecurite\/les-violations-de-donnees-personnelles\">CNIL guide: informing the individuals concerned<\/a>). Paragraph 2 adds that \u201cLa communication \u00e0 la personne concern\u00e9e vis\u00e9e au paragraphe 1 du pr\u00e9sent article d\u00e9crit, en des termes clairs et simples, la nature de la violation de donn\u00e9es \u00e0 caract\u00e8re personnel et contient au moins les informations et mesures vis\u00e9es \u00e0 l&#8217;article 33, paragraphe 3, points b), c) et d).\u201d (\u201cThe communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in Article 33(3), points (b), (c) and (d).\u201d) In practice, a customer in France who received the push notification but no individual breach notice should not conclude that nothing happened: the duty to inform each person arises only above the high-risk threshold, and the assessment belongs first to the controller under the control of the supervisory authority, which may order the controller to notify the individuals concerned.<\/p>\n<p>That supervisory authority, for a customer residing in France, is the CNIL, the Commission nationale de l&#8217;informatique et des libert\u00e9s. The regulation gives each authority broad powers: Article 58 provides that \u201cChaque autorit\u00e9 de contr\u00f4le dispose de tous les pouvoirs d&#8217;enqu\u00eate suivants\u201d (\u201cEach supervisory authority shall have all of the following investigative powers\u201d), including the power to put the controller on notice of an alleged violation of the regulation (<a href=\"https:\/\/www.cnil.fr\/fr\/cybersecurite\/les-violations-de-donnees-personnelles\">CNIL guide on personal data breaches<\/a>). The CNIL publishes a guide on personal data breaches and operates an online breach-notification service for controllers (<a href=\"https:\/\/www.cnil.fr\/fr\/cybersecurite\/les-violations-de-donnees-personnelles\">CNIL guide on personal data breaches<\/a>; <a href=\"https:\/\/www.cnil.fr\/fr\/services-en-ligne\/notifier-une-violation-de-donnees-personnelles\">CNIL online service for notifying a personal data breach<\/a>). Customers cannot use that service themselves, since it is reserved for controllers and processors, but its existence shows where the retailer&#8217;s notification, if any, will be examined.<\/p>\n<p>The customer&#8217;s own procedural path is the individual complaint, the r\u00e9clamation. Article 77, paragraph 1, of the regulation provides that \u201cSans pr\u00e9judice de tout autre recours administratif ou juridictionnel, toute personne concern\u00e9e a le droit d&#8217;introduire une r\u00e9clamation aupr\u00e8s d&#8217;une autorit\u00e9 de contr\u00f4le, en particulier dans l&#8217;\u00c9tat membre dans lequel se trouve sa r\u00e9sidence habituelle, son lieu de travail ou le lieu o\u00f9 la violation aurait \u00e9t\u00e9 commise, si elle consid\u00e8re que le traitement de donn\u00e9es \u00e0 caract\u00e8re personnel la concernant constitue une violation du pr\u00e9sent r\u00e8glement.\u201d (\u201cWithout prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.\u201d) (Article 77 of Regulation (EU) 2016\/679). A customer residing in France may therefore complain to the CNIL, which must keep the complainant informed of the progress and outcome of the complaint, and the complaint can be filed through the CNIL&#8217;s online complaints service (<a href=\"https:\/\/www.cnil.fr\/fr\/plaintes\">CNIL online complaints service<\/a>).<\/p>\n<p>A well-built complaint file contains the account identifier, the dates and screenshots of the notification, any individual notice received from the controller, the written report sent to the retailer, and a precise description of any concrete consequence already observed, such as phishing messages, account modifications or unexplained debits. This discipline matters because the CNIL examines thousands of complaints and prioritises files that demonstrate a verifiable fact pattern. A similar method was described for French customers affected by an earlier breach of a national training body, where complaint, evidence preservation and compensation paths were presented together (<a href=\"https:\/\/kohenavocats.fr\/2026\/09\/22\/afpa-donnees-personnelles-piratees-que-faire-plainte-indemnisation\/\">what to do after personal data theft affecting a French organisation: complaint, evidence and compensation<\/a>). The complaint before the CNIL does not require the customer to prove the full technical chain of the intrusion; it requires the customer to show, documents in hand, why the processing of data relating to him or her appears to infringe the regulation.<\/p>\n<h3>B. Can a customer in France obtain compensation and file a criminal complaint?<\/h3>\n<p>Compensation is possible but never automatic, and French courts apply this rule strictly. Article 82, paragraph 1, of the regulation provides, in the words recalled by the Cour de cassation, &#8220;Aux termes de ce texte, toute personne ayant subi un dommage mat\u00e9riel ou moral du fait d&#8217;une violation du pr\u00e9sent r\u00e8glement a le droit d&#8217;obtenir du responsable du traitement ou du sous-traitant r\u00e9paration du pr\u00e9judice subi.&#8221; (\u201cAny person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.\u201d) (<a href=\"https:\/\/www.courdecassation.fr\/decision\/6a3cc051cdc6046d479d8eb0\">Cour de cassation, chambre sociale, 24 June 2026, no. 24-22.792, recalling Article 82 of Regulation (EU) 2016\/679<\/a>). The key words are damage suffered: the infringement alone is not enough, and the victim must establish a concrete material or moral prejudice (pr\u00e9judice mat\u00e9riel ou moral), such as financial loss, loss of time and steps taken, anxiety linked to the exposure of sensitive data, or misuse of the data.<\/p>\n<p>The Cour de cassation confirmed this reading in a published judgment of 24 June 2026. Its headnote states that \u201cLa violation du r\u00e8glement (UE) 2016\/679 du Parlement europ\u00e9en et du Conseil du 27 avril 2016, relatif \u00e0 la protection des personnes physiques \u00e0 l&#8217;\u00e9gard du traitement des donn\u00e9es \u00e0 caract\u00e8re personnel et \u00e0 la libre circulation de ces donn\u00e9es (RGPD) n&#8217;ouvre pas, \u00e0 elle seule, droit \u00e0 r\u00e9paration\u201d (\u201cInfringement of Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) does not, on its own, give rise to a right to compensation\u201d) (<a href=\"https:\/\/www.courdecassation.fr\/decision\/6a3cc051cdc6046d479d8eb0\">Cour de cassation, chambre sociale, 24 June 2026, no. 24-22.792, published in the Bulletin<\/a>). Quashing a Paris appeal ruling that had treated non-compliance as necessarily causing harm, the Court held: &#8220;En statuant ainsi, alors que la simple violation du r\u00e8glement g\u00e9n\u00e9ral sur la protection des donn\u00e9es n&#8217;ouvre pas, \u00e0 elle seule, droit \u00e0 r\u00e9paration et qu&#8217;il lui appartenait d&#8217;appr\u00e9cier si le salari\u00e9 \u00e9tablissait que la violation de ce r\u00e8glement qu&#8217;elle avait constat\u00e9e avait caus\u00e9 au salari\u00e9 un dommage mat\u00e9riel ou moral, la cour d&#8217;appel a viol\u00e9 le texte susvis\u00e9.&#8221; (\u201cIn ruling as it did, whereas the mere infringement of the General Data Protection Regulation does not, on its own, give rise to a right to compensation, and whereas it was for the court to assess whether the employee established that the infringement of that regulation which it had found had caused the employee material or non-material damage, the court of appeal infringed the above provision.\u201d)<\/p>\n<p>The same judgment recalls the two reference rulings of the Court of Justice of the European Union. In its judgment of 4 May 2023, \u00d6sterreichische Post, case C-300\/21, the Court of Justice held that &#8220;la simple violation des dispositions de ce r\u00e8glement ne suffit pas pour conf\u00e9rer un droit \u00e0 r\u00e9paration&#8221; (\u201cthe mere infringement of the provisions of that regulation is not sufficient to confer a right to compensation\u201d), while opposing &#8220;une r\u00e8gle ou une pratique nationale subordonnant la r\u00e9paration d&#8217;un dommage moral, au sens de cette disposition, \u00e0 la condition que le pr\u00e9judice subi par la personne concern\u00e9e ait atteint un certain degr\u00e9 de gravit\u00e9&#8221; (\u201ca national rule or practice making compensation for non-material damage, within the meaning of that provision, subject to the condition that the damage suffered by the data subject has reached a certain degree of seriousness\u201d) (<a href=\"https:\/\/curia.europa.eu\/juris\/liste.jsf?num=C-300\/21\">CJEU, 4 May 2023, \u00d6sterreichische Post, C-300\/21<\/a>; holdings recalled in <a href=\"https:\/\/www.courdecassation.fr\/decision\/6a3cc051cdc6046d479d8eb0\">Cour de cassation, chambre sociale, 24 June 2026, no. 24-22.792<\/a>). In its judgment of 25 January 2024, MediaMarktSaturn, case C-687\/21, the Court added that financial redress under Article 82 &#8220;doit permettre de compenser int\u00e9gralement le pr\u00e9judice concr\u00e8tement subi du fait de la violation de ce r\u00e8glement, et non une fonction punitive&#8221; (\u201cmust make it possible to compensate in full the damage actually suffered as a result of the infringement of that regulation, and does not have a punitive function\u201d), and that &#8220;la personne demandant r\u00e9paration au titre de cette disposition est tenue d&#8217;\u00e9tablir non seulement la violation de dispositions de ce r\u00e8glement, mais \u00e9galement que cette violation lui a caus\u00e9 un dommage mat\u00e9riel ou moral&#8221; (\u201ca person seeking compensation under that provision is required to establish not only the infringement of provisions of that regulation, but also that that infringement caused him or her material or non-material damage\u201d) (<a href=\"https:\/\/curia.europa.eu\/juris\/liste.jsf?num=C-687\/21\">CJEU, 25 January 2024, MediaMarktSaturn, C-687\/21<\/a>). For a customer in France, the practical consequence is direct: keep every piece of evidence of real harm, because a court will award nothing on the sole ground that a breach may have occurred.<\/p>\n<p>French domestic law provides the general fault-based complement to the European compensation right. Article 1240 of the Civil Code states that &#8220;Tout fait quelconque de l&#8217;homme, qui cause \u00e0 autrui un dommage, oblige celui par la faute duquel il est arriv\u00e9 \u00e0 le r\u00e9parer.&#8221; (\u201cAny act whatever of man which causes damage to another obliges the person by whose fault it occurred to repair it.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000032041571\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000032041571\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 1240 of the French Civil Code, in force on 6 October 2026<\/a>). A customer who proves a fault in the handling of personal data, a concrete damage and a causal link may therefore also rely on this general provision before the French courts, in addition to Article 82 of the regulation.<\/p>\n<p>Where to sue is settled in the customer&#8217;s favour. Article 79 of the regulation provides that \u201cSans pr\u00e9judice de tout recours administratif ou extrajudiciaire qui lui est ouvert, y compris le droit d&#8217;introduire une r\u00e9clamation aupr\u00e8s d&#8217;une autorit\u00e9 de contr\u00f4le au titre de l&#8217;article 77, chaque personne concern\u00e9e a droit \u00e0 un recours juridictionnel effectif si elle consid\u00e8re que les droits que lui conf\u00e8re le pr\u00e9sent r\u00e8glement ont \u00e9t\u00e9 viol\u00e9s du fait d&#8217;un traitement de ses donn\u00e9es \u00e0 caract\u00e8re personnel effectu\u00e9 en violation du pr\u00e9sent r\u00e8glement.\u201d (\u201cWithout prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.\u201d), and that \u201cToute action contre un responsable du traitement ou un sous-traitant est intent\u00e9e devant les juridictions de l&#8217;\u00c9tat membre dans lequel le responsable du traitement ou le sous-traitant dispose d&#8217;un \u00e9tablissement. Une telle action peut aussi \u00eatre intent\u00e9e devant les juridictions de l&#8217;\u00c9tat membre dans lequel la personne concern\u00e9e a sa r\u00e9sidence habituelle, sauf si le responsable du traitement ou le sous-traitant est une autorit\u00e9 publique d&#8217;un \u00c9tat membre agissant dans l&#8217;exercice de ses pr\u00e9rogatives de puissance publique.\u201d (\u201cProceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, except where the controller or processor is a public authority of a Member State acting in the exercise of its public powers.\u201d) (Article 79 of Regulation (EU) 2016\/679). A customer habitually resident in France, including in Paris and the \u00cele-de-France region, may therefore bring the compensation claim before the French courts of the domicile, without having to sue abroad.<\/p>\n<p>The criminal path runs in parallel and belongs to the public prosecutor, but it starts with the victim&#8217;s complaint, the plainte. French criminal law punishes the intrusion itself: Article 323-1 of the Criminal Code provides that &#8220;Le fait d&#8217;acc\u00e9der ou de se maintenir, frauduleusement, dans tout ou partie d&#8217;un syst\u00e8me de traitement automatis\u00e9 de donn\u00e9es est puni de trois ans d&#8217;emprisonnement et de 100 000 \u20ac d&#8217;amende. Lorsqu&#8217;il en est r\u00e9sult\u00e9 soit la suppression ou la modification de donn\u00e9es contenues dans le syst\u00e8me, soit une alt\u00e9ration du fonctionnement de ce syst\u00e8me, la peine est de cinq ans d&#8217;emprisonnement et de 150 000 \u20ac d&#8217;amende.&#8221; (\u201cFraudulently accessing or remaining in all or part of an automated data processing system is punished by three years&#8217; imprisonment and a fine of 100,000 euros. Where this has resulted in either the deletion or modification of data contained in the system, or an alteration of the functioning of that system, the penalty is five years&#8217; imprisonment and a fine of 150,000 euros.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000047052655\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000047052655\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 323-1 of the French Criminal Code, in force on 6 October 2026<\/a>). The subsequent handling of the data is also punishable: Article 323-3 punishes &#8220;Le fait d&#8217;introduire frauduleusement des donn\u00e9es dans un syst\u00e8me de traitement automatis\u00e9, d&#8217;extraire, de d\u00e9tenir, de reproduire, de transmettre, de supprimer ou de modifier frauduleusement les donn\u00e9es qu&#8217;il contient est puni de cinq ans d&#8217;emprisonnement et de 150 000 \u20ac d&#8217;amende.&#8221; (\u201cFraudulently introducing data into an automated processing system, or fraudulently extracting, holding, reproducing, transmitting, deleting or modifying the data it contains, is punished by five years&#8217; imprisonment and a fine of 150,000 euros.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000030939448\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000030939448\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 323-3 of the French Criminal Code, in force on 6 October 2026<\/a>).<\/p>\n<p>Two further provisions commonly apply to the aftermath of a breach affecting customers. Article 226-18 of the Criminal Code states that &#8220;Le fait de collecter des donn\u00e9es \u00e0 caract\u00e8re personnel par un moyen frauduleux, d\u00e9loyal ou illicite est puni de cinq ans d&#8217;emprisonnement et de 300 000 euros d&#8217;amende.&#8221; (\u201cCollecting personal data by fraudulent, unfair or unlawful means is punished by five years&#8217; imprisonment and a fine of 300,000 euros.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000006417968\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000006417968\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 226-18 of the French Criminal Code, in force on 6 October 2026<\/a>). And where the stolen data is used to deceive customers, Article 313-1 punishes fraud, defined as &#8220;le fait, soit par l&#8217;usage d&#8217;un faux nom ou d&#8217;une fausse qualit\u00e9, soit par l&#8217;abus d&#8217;une qualit\u00e9 vraie, soit par l&#8217;emploi de manoeuvres frauduleuses, de tromper une personne physique ou morale et de la d\u00e9terminer ainsi, \u00e0 son pr\u00e9judice ou au pr\u00e9judice d&#8217;un tiers, \u00e0 remettre des fonds, des valeurs ou un bien quelconque, \u00e0 fournir un service ou \u00e0 consentir un acte op\u00e9rant obligation ou d\u00e9charge. L&#8217;escroquerie est punie de cinq ans d&#8217;emprisonnement et de 375 000 euros d&#8217;amende.&#8221; (\u201cthe act, whether by the use of a false name or a false capacity, or by the abuse of a genuine capacity, or by the use of fraudulent manoeuvres, of deceiving a natural or legal person and thereby inducing that person, to his or her prejudice or to the prejudice of a third party, to hand over funds, valuables or any property, to provide a service or to consent to an act creating an obligation or a discharge. Fraud is punished by five years&#8217; imprisonment and a fine of 375,000 euros.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000006418192\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000006418192\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 313-1 of the French Criminal Code, in force on 6 October 2026<\/a>). A victim residing in Paris may file the plainte at the local commissariat, before the gendarmerie, or by letter to the public prosecutor (procureur de la R\u00e9publique), attaching the screenshots, the account records and any phishing message received afterwards. No office may turn the victim away: Article 15-3 of the Code of Criminal Procedure states that &#8220;Les officiers et agents de police judiciaire sont tenus de recevoir les plaintes d\u00e9pos\u00e9es par les victimes d&#8217;infractions \u00e0 la loi p\u00e9nale, y compris lorsque ces plaintes sont d\u00e9pos\u00e9es dans un service ou une unit\u00e9 de police judiciaire territorialement incomp\u00e9tents.&#8221; (\u201cOfficers and agents of the judicial police are required to receive complaints filed by victims of criminal offences, including where those complaints are filed with a judicial police service or unit that lacks territorial jurisdiction.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000054725475\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000054725475\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 15-3 of the French Code of Criminal Procedure, in force on 6 October 2026<\/a>). If the prosecutor decides not to prosecute, or if three months pass without a response, the victim may escalate: Article 85 of the same code provides that &#8220;Toute personne qui se pr\u00e9tend l\u00e9s\u00e9e par un crime ou un d\u00e9lit peut en portant plainte se constituer partie civile devant le juge d&#8217;instruction comp\u00e9tent en application des dispositions des articles 52, 52-1 et 706-42 .&#8221; (\u201cAny person claiming to have suffered harm as a result of a felony or misdemeanour may, by filing a complaint, become a civil party before the competent investigating judge pursuant to Articles 52, 52-1 and 706-42.\u201d) (<a href=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000038312069\" class=\"kohen-legifrance-popup-link\" data-kohen-legifrance-url=\"https:\/\/www.legifrance.gouv.fr\/codes\/article_lc\/LEGIARTI000038312069\" data-kohen-legifrance-title=\"Texte officiel Legifrance\" target=\"_blank\" rel=\"noopener\">Article 85 of the French Code of Criminal Procedure, in force on 6 October 2026<\/a>).<\/p>\n<h2>Conclusion<\/h2>\n<p>On the facts available on 6 October 2026, a threatening notification was pushed through the retailer&#8217;s own app, the national press reported it, the company stated that it was aware of the reports and was investigating, and the store and app remained online. At the time of writing, no intrusion, no data leak and no damage have been established by any official source, and no liability has been established against anyone; the general terms and privacy documents accepted by each customer prevail over any general analysis, and only a court, criminal or civil, can characterise the facts and allocate responsibility. Within those limits, customers in France hold three levers: immediate self-protection against phishing and credential reuse, the complaint before the CNIL in the State of residence with a documented file, and, where concrete harm is proven, the compensation claim before the French courts with a criminal complaint in support. The Cour de cassation&#8217;s message of June 2026 governs the last of these levers: an infringement alone compensates nothing, while proven harm, even moral harm without a threshold of seriousness, is compensated in full. Evidence gathered from the first day therefore decides everything that follows.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After the &#8216;ASOS hacked&#8217; notification sent to app users on 6 October 2026, this guide explains the Snowflake claim reported by the press and the French and European remedies for customers in France: CNIL complaint, compensation and criminal complaint.<\/p>\n","protected":false},"author":251031309,"featured_media":16464,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kj_source_type":"","_kj_official_id":"","_kj_official_url":"","_kj_judilibre_id":"","_kj_jur":"","_kj_lieu":"","_kj_chambre":"","_kj_rg":"","_kj_date":"","activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":4,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"federated","footnotes":""},"categories":[80314,80316],"tags":[],"class_list":["post-2140198","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-decryptage","category-numerique-donnees-personnelles"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.2 (Yoast SEO v28.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France - Ma\u00eetre Reda Kohen, Real Estate and Business Law Attorney in Paris<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France\" \/>\n<meta property=\"og:description\" content=\"After the &#039;ASOS hacked&#039; notification sent to app users on 6 October 2026, this guide explains the Snowflake claim reported by the press and the French and European remedies for customers in France: CNIL complaint, compensation and criminal complaint.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/\" \/>\n<meta property=\"og:site_name\" content=\"Ma\u00eetre Reda Kohen, Real Estate and Business Law Attorney in Paris\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-06T13:45:11+00:00\" \/>\n<meta name=\"author\" content=\"Kohen\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kohen\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"23 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/\"},\"author\":{\"name\":\"Kohen\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#\\\/schema\\\/person\\\/6254a643e6239d803134a01c800381bd\"},\"headline\":\"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France\",\"datePublished\":\"2026-10-06T13:45:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/\"},\"wordCount\":4722,\"publisher\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kohenavocats.fr\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp\",\"articleSection\":[\"D\u00e9cryptage\",\"Num\u00e9rique et donn\u00e9es personnelles\"],\"inLanguage\":\"en-US\",\"citation\":\"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France\",\"about\":[{\"@type\":\"Thing\",\"name\":\"D\u00e9cryptage\"},{\"@type\":\"Thing\",\"name\":\"Num\u00e9rique et donn\u00e9es personnelles\"}],\"dateModified\":\"2026-10-06T13:45:11+00:00\",\"speakable\":{\"@type\":\"SpeakableSpecification\",\"cssSelector\":[\".article-content > p:first-of-type\"]}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/\",\"url\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/\",\"name\":\"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France - Ma\u00eetre Reda Kohen, Real Estate and Business Law Attorney in Paris\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kohenavocats.fr\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp\",\"datePublished\":\"2026-10-06T13:45:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kohenavocats.fr\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp\",\"contentUrl\":\"https:\\\/\\\/kohenavocats.fr\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp\",\"width\":4586,\"height\":6878},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/2026\\\/10\\\/06\\\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/\",\"name\":\"Kohen Avocats\",\"description\":\"Ma\u00eetre Reda Kohen, attorney specialized in real estate and business law in Paris, advises and assists companies and individuals in their real estate, commercial and contractual transactions. He also handles real estate litigation and the resolution of complex commercial disputes.\",\"publisher\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#organization\",\"name\":\"Kohen Avocats\",\"url\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/kohenavocats.fr\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Logo-2-1.webp\",\"contentUrl\":\"https:\\\/\\\/kohenavocats.fr\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Logo-2-1.webp\",\"width\":2114,\"height\":1253,\"caption\":\"Kohen Avocats\"},\"image\":{\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/#\\\/schema\\\/person\\\/6254a643e6239d803134a01c800381bd\",\"name\":\"Kohen\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1c5e76ef76bbbfdd2b4da984e2bf2fa4056fd51a27d25ce2c332047f1dfd6e00?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1c5e76ef76bbbfdd2b4da984e2bf2fa4056fd51a27d25ce2c332047f1dfd6e00?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1c5e76ef76bbbfdd2b4da984e2bf2fa4056fd51a27d25ce2c332047f1dfd6e00?s=96&d=identicon&r=g\",\"caption\":\"Kohen\"},\"url\":\"https:\\\/\\\/kohenavocats.fr\\\/en\\\/author\\\/kohenmlk\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France - Ma\u00eetre Reda Kohen, Real Estate and Business Law Attorney in Paris","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/","og_locale":"en_US","og_type":"article","og_title":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France","og_description":"After the 'ASOS hacked' notification sent to app users on 6 October 2026, this guide explains the Snowflake claim reported by the press and the French and European remedies for customers in France: CNIL complaint, compensation and criminal complaint.","og_url":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/","og_site_name":"Ma\u00eetre Reda Kohen, Real Estate and Business Law Attorney in Paris","article_published_time":"2026-10-06T13:45:11+00:00","author":"Kohen","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kohen","Est. reading time":"23 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#article","isPartOf":{"@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/"},"author":{"name":"Kohen","@id":"https:\/\/kohenavocats.fr\/en\/#\/schema\/person\/6254a643e6239d803134a01c800381bd"},"headline":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France","datePublished":"2026-10-06T13:45:11+00:00","mainEntityOfPage":{"@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/"},"wordCount":4722,"publisher":{"@id":"https:\/\/kohenavocats.fr\/en\/#organization"},"image":{"@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/kohenavocats.fr\/wp-content\/uploads\/2024\/11\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp","articleSection":["D\u00e9cryptage","Num\u00e9rique et donn\u00e9es personnelles"],"inLanguage":"en-US","citation":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France","about":[{"@type":"Thing","name":"D\u00e9cryptage"},{"@type":"Thing","name":"Num\u00e9rique et donn\u00e9es personnelles"}],"dateModified":"2026-10-06T13:45:11+00:00","speakable":{"@type":"SpeakableSpecification","cssSelector":[".article-content > p:first-of-type"]}},{"@type":"WebPage","@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/","url":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/","name":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France - Ma\u00eetre Reda Kohen, Real Estate and Business Law Attorney in Paris","isPartOf":{"@id":"https:\/\/kohenavocats.fr\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#primaryimage"},"image":{"@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/kohenavocats.fr\/wp-content\/uploads\/2024\/11\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp","datePublished":"2026-10-06T13:45:11+00:00","breadcrumb":{"@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#primaryimage","url":"https:\/\/kohenavocats.fr\/wp-content\/uploads\/2024\/11\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp","contentUrl":"https:\/\/kohenavocats.fr\/wp-content\/uploads\/2024\/11\/anastassia-anufrieva-Lm7c-0yemo8-unsplash.webp","width":4586,"height":6878},{"@type":"BreadcrumbList","@id":"https:\/\/kohenavocats.fr\/en\/2026\/10\/06\/has-asos-been-hacked-snowflake-notification-france-rights-gdpr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kohenavocats.fr\/en\/"},{"@type":"ListItem","position":2,"name":"Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France"}]},{"@type":"WebSite","@id":"https:\/\/kohenavocats.fr\/en\/#website","url":"https:\/\/kohenavocats.fr\/en\/","name":"Kohen Avocats","description":"Ma\u00eetre Reda Kohen, attorney specialized in real estate and business law in Paris, advises and assists companies and individuals in their real estate, commercial and contractual transactions. He also handles real estate litigation and the resolution of complex commercial disputes.","publisher":{"@id":"https:\/\/kohenavocats.fr\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kohenavocats.fr\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/kohenavocats.fr\/en\/#organization","name":"Kohen Avocats","url":"https:\/\/kohenavocats.fr\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kohenavocats.fr\/en\/#\/schema\/logo\/image\/","url":"https:\/\/kohenavocats.fr\/wp-content\/uploads\/2024\/05\/Logo-2-1.webp","contentUrl":"https:\/\/kohenavocats.fr\/wp-content\/uploads\/2024\/05\/Logo-2-1.webp","width":2114,"height":1253,"caption":"Kohen Avocats"},"image":{"@id":"https:\/\/kohenavocats.fr\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/kohenavocats.fr\/en\/#\/schema\/person\/6254a643e6239d803134a01c800381bd","name":"Kohen","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1c5e76ef76bbbfdd2b4da984e2bf2fa4056fd51a27d25ce2c332047f1dfd6e00?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1c5e76ef76bbbfdd2b4da984e2bf2fa4056fd51a27d25ce2c332047f1dfd6e00?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1c5e76ef76bbbfdd2b4da984e2bf2fa4056fd51a27d25ce2c332047f1dfd6e00?s=96&d=identicon&r=g","caption":"Kohen"},"url":"https:\/\/kohenavocats.fr\/en\/author\/kohenmlk\/"}]}},"_links":{"self":[{"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/posts\/2140198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/users\/251031309"}],"replies":[{"embeddable":true,"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/comments?post=2140198"}],"version-history":[{"count":0,"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/posts\/2140198\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/media\/16464"}],"wp:attachment":[{"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/media?parent=2140198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/categories?post=2140198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kohenavocats.fr\/en\/wp-json\/wp\/v2\/tags?post=2140198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}