Made contact with a few furs in the know who are Very Not Happy. This con has some serious skeletons in the closet.
Confuzzled has had at least two serious data breaches this year. Heard between six and ten in its 12-year history.
Latest breach involves a charity T-shirt order form which was set to allow anyone filling it out to view all entries. Full names, emails, addresses, social media and payment details of all the furfags filling it out.
My source close to the staff says "probably hundreds" of peoples data has been leaked and is now circulating.
Order form leak deets:
https://twitter.com/Captain_Vulpine/status/1274364873191960576 / archive
https://archive.is/a16oh
The con took the form down completely not long after. It was down for several months, CFZ says "due to technical issues".
Staff are under orders not to discuss the breaches in any way, internal or external. CFZ has threatened to take legal action against at least one person for "intentional interference in contractual relations" (aka tortious interference) and dismiss others.
And down the rabbit hole we go...
The convention is not and has never been registered as holding personal data - this is a requirement under UK law and has been since 1997. Search
https://ico.org.uk/ESDWebPages/Search for "ConFuzzled" - no results.
Fines for this can be up to £4,350 as of 2018:
https://ico.org.uk/about-the-ico/ne...s-that-have-not-paid-the-data-protection-fee/
2000 attendees x £600 registration = £1.2m turnover. £60 fee, £600 fine...
My source put me in contact with to two people who had contacted the con. Both have received bans for asking about the leaks. One two years "we reserve to extend", another permanent. Both bans use CFZ's "rule one" and "the final word" of its code of conduct as a justification: "we can ban you for any reason or no reason and there is no right of discussion or appeal".
No reason is given, and all the emails end thus:
> Our decision in this matter is final and we will not respond to emails requesting further explanation nor to any complaints on the decision. We reserve the right to extend this restriction of attendance permanently without notice to you. No reason or explanation will be given. Your details have been circulated to other events for protection of the fandom, the community and ConFuzzled.
The third sentence is a direct breach of GDPR.
Source informs me that "Crimson Nova" on the CFz Directors board has been approaching other events. Conversations have been along the lines of "ban this person or we will ban your staff from Confuzzled".
Funny they don't do this about the Nazifurs they've had on security for the last three years, or the animal rapists. My source said many senior staff are close to Elfasi and hiding him.
More incoming... this rabbithole keeps on giving...