The General Data Protection Regulation became applicable on 25 May 2018, two years after it entered into force, and its arrival was announced to most of the world by email. For a fortnight beforehand, inboxes filled with subject lines of mounting desperation — we have updated our privacy policy, we would hate to lose you, please confirm you still wish to hear from us — from mailing lists nobody remembered joining. The substance was less funny than the delivery: a right to erasure and to data portability, a duty to notify a regulator of a personal data breach within 72 hours of becoming aware of it, and, for the gravest infringements, fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
The regulation was minutes old when it was tested. At midnight on 25 May, noyb — None Of Your Business, the non-profit founded by the Austrian lawyer Max Schrems — filed four complaints alleging what it called forced consent: that Google, Facebook, Instagram and WhatsApp had offered users a choice between accepting a new privacy policy in full and losing the account, which noyb argued Article 7(4) does not permit. Both companies rejected the characterisation: Facebook's chief privacy officer Erin Egan said the company had spent the previous eighteen months preparing to meet the regulation's requirements, and Google said it built privacy and security into its products from the earliest stages and was committed to complying. The filings were deliberately scattered across four regulators — Google's Android consent flow with France's CNIL, Facebook with the Austrian authority, Instagram with Belgium, WhatsApp with Hamburg. La Quadrature du Net lodged a parallel complaint against Google on 28 May. Nobody expected an answer quickly, and nobody received one.
The other visible response was retreat. On the morning of 25 May, European readers who went to the Los Angeles Times or the Chicago Tribune found a notice instead: the site, it read, was unavailable in most European countries. The same message appeared across the tronc group and the New York Daily News. It was cheaper to stop serving a continent than to rebuild an advertising stack, and two months later Nieman Lab counted more than a thousand US news sites still unreachable from Europe. Security paid its own share. Public WHOIS — the record showing who had bought a phishing domain, and when — was personal data under the new definition, and on 17 May ICANN's board approved a Temporary Specification redacting most of it from the 25th, replacing open lookup with tiered access.
The penalties arrived slowly, and then enormously. France's CNIL fined Google €50 million on 21 January 2019 over transparency and the legal basis for personalised advertising — the first substantial sanction under the regulation, and a direct product of the midnight filing in Paris. The Irish Data Protection Commission answered the Facebook and Instagram complaints on 4 January 2023 — four and a half years on — with fines of €210 million and €180 million. On 22 May 2023, three days short of five years after the law took effect, the same regulator fined Meta €1.2 billion over transfers of European data to the United States, another case that had begun with a Schrems complaint. By January 2026, DLA Piper's annual survey put the cumulative total of GDPR fines at roughly €7.1 billion.
Everyone was asked to reboot
Cisco Talos published on 23 May 2018 that at least 500,000 networking devices in at least 54 countries were running a modular implant it called VPNFilter — home and small-office routers and storage boxes from Linksys, MikroTik, NETGEAR, TP-Link and QNAP. The architecture was the alarming part. A first stage survived reboot and did nothing but fetch a second, which could collect files, run commands, exfiltrate data and, on instruction, overwrite the device's firmware and brick it. Third-stage plugins added a packet sniffer and the ability to watch Modbus SCADA traffic. Talos said it was publishing before its investigation was complete because of a sharp spike in infections on 8 May, almost all the new victims in Ukraine, and because the code overlapped with BlackEnergy. The Justice Department had obtained a seizure warrant for toknowall.com, the domain used to locate later stages, on an affidavit sworn the day before and unsealed as Talos published; the FBI attributed the operation to the Russian group known as Fancy Bear — the Bureau's assessment, not Talos's — and on 25 May advised the public to reboot their routers, which cleared stages two and three and pushed what remained into a sinkhole.
Two logs nobody meant to keep
On 1 May, GitHub emailed a small number of users to say that a recently introduced bug in its password-reset flow had written their plaintext passwords into internal logs. The company said the logs had never been reachable by the public or by other users, that it had found the problem during routine auditing, and that its servers had not been broken into. Two days later, on World Password Day, Twitter's chief technology officer Parag Agrawal published a post with the same shape and a far larger audience. Due to a bug, it read, passwords were written to an internal log before completing the hashing process. Twitter recommended that all its users — a base then generally reported as 330 million — change their password, and any password reused elsewhere. The company said it had found the bug itself, that its investigation showed no indication of a breach or of misuse by anyone, and that it was very sorry. It never said how many passwords were involved, or for how long. Neither disclosure described an intrusion; both were confessions about plumbing.
Thirty-eight days, and then silence
On 10 May 2018 a five-judge constitution bench of the Supreme Court of India rose after thirty-eight days of argument in K.S. Puttaswamy v. Union of India, reserving judgment on whether Aadhaar — the biometric number then held by more than a billion people — was constitutional. The hearing had begun on 17 January and was the second longest in the court's history. The petitioners argued that it violated the right to privacy the same court had recognised in August 2017, that it excluded the poorest from the rations and pensions it existed to deliver, and that it had been passed as a money bill to sidestep the Rajya Sabha. Then the court went quiet for four and a half months.
Fifteen days later the GDPR arrived from the other direction, reaching anyone processing the data of people in the European Union wherever they sat — which described a great deal of India's IT and business-process industry, firms newly liable as processors for contract terms, breach reporting and sub-processing they had never documented. NASSCOM and the Data Security Council of India spent the spring publishing readiness guidance for members with no domestic law to practise on; the expert committee chaired by Justice B.N. Srikrishna was still drafting one, and delivered its report and draft bill on 27 July. The judgment came on 26 September: Aadhaar upheld four to one, Section 57 struck down so private companies could no longer demand it, with Justice D.Y. Chandrachud dissenting that the entire Act was unconstitutional. That draft became the Digital Personal Data Protection Act in 2023; its rules were notified in November 2025, its substantive obligations taking effect on 14 May 2027 — nine years after the hearing ended.
The assistant that said mm-hmm
Sundar Pichai opened Google I/O on 8 May 2018 by playing two recordings. In each, an experimental system called Duplex telephoned a business — a hair salon, then a restaurant — to make a booking, and the person answering gave no sign of knowing that the voice pausing and saying mm-hmm was synthetic. The room applauded; the reaction outside it was colder. The sociologist Zeynep Tufekci wrote that the tics had been added to deceive whoever answered, and within two days Google said it was designing the feature with disclosure built in and would make sure the system was appropriately identified. Later reporting questioned how heavily the recordings had been edited. The same keynote brought Smart Compose, which finished sentences in Gmail, and a third-generation tensor processing unit whose pods forced Google to add liquid cooling to its data centres; a day earlier Satya Nadella had committed $25 million over five years to Microsoft's AI for Accessibility programme. The disclosure question outlived the product: by 2026 the duty to say so is written into California and European law.
Symantec falls as Avast lists
Symantec reported fourth-quarter results on 10 May 2018 and disclosed alongside them that its board's audit committee had opened an internal investigation into concerns raised by a former employee. The company said the matter did not touch the security of its products, that it could predict neither duration nor outcome, and that its annual report would probably be late. The shares fell after the bell and lost roughly a third the next day, closing at $19.52 — the worst session in seventeen years, and more than $6 billion of market value gone. Five days later Avast was admitted to the London market's premium segment, conditional dealings having begun on the 10th. It priced at 250 pence, the bottom of an already-cut range, valuing the Czech company near £2.4 billion and ranking among the exchange's five largest technology listings; the shares fell on debut. Symantec had contacted the Securities and Exchange Commission voluntarily; the regulator's investigation closed without action in 2022, by which time Broadcom held the enterprise half and NortonLifeLock, the consumer remnant, had merged with Avast.
⏳ Time capsule — May 2018
- Kīlauea began erupting through fissures in Hawaii's lower East Rift Zone on 3 May, forcing evacuations from Leilani Estates.
- Malaysia's opposition coalition won the general election on 9 May, ending sixty-one years of unbroken rule by Barisan Nasional; Mahathir Mohamad, aged 92, was sworn in the next day.
- Prince Harry married Meghan Markle at St George's Chapel, Windsor, on 19 May.
- Ireland voted on 25 May — the same day the GDPR took effect — to repeal the Eighth Amendment, by roughly two to one.
The law that travelled
Eight years on, the GDPR's most durable export is not the fines but the template. Brazil passed its LGPD three months later, California's Consumer Privacy Act was signed the following month, and India's own statute, drafted that same summer, eventually followed; by 2026 most of the world's population lives under a law borrowing the same vocabulary of controllers, processors, lawful bases and mandatory notification. The 72-hour rule in particular changed what this archive can even be. Every edition after May 2018 can set a discovery date against a disclosure date against the date of the attack, because from that month onward organisations were obliged to write those dates down and hand them to a regulator.
The rest of the month aged less kindly. VPNFilter surfaced eleven days after the first anniversary of WannaCry, and established the household router as the least-defended computer in any building and among the most useful to own — a lesson relearned in these pages with every later edge-device campaign. The plaintext logs kept reappearing, too: in March 2019 Facebook disclosed that hundreds of millions of user passwords had sat unencrypted in internal logs, some of them for years, the same class of mistake as Twitter's at a scale that made Twitter's look tidy. The Vault continues backwards from here, and the further back it goes, the more first drafts it finds.