LastPass suffered a serious two-stage breach in 2022: first, attackers stole source code in August; then in December, they accessed customer data including encrypted password vaults. Every LastPass customer's data was potentially exposed.
⚖️ Regulatory action: LastPass has not been publicly fined under GDPR as of 2025, but the breach is under regulatory review in multiple EU jurisdictions.
In a two-stage attack, hackers first stole source code and technical information, then used it to access a cloud backup containing encrypted customer password vaults along with unencrypted account metadata.
LastPass held some of the most sensitive data imaginable — encrypted vaults containing all your passwords. A GDPR access request reveals what account metadata they hold, how it was secured, and what third parties it was shared with. You may also have grounds for erasure.
You have two key rights under GDPR:
Fill in your details below. Address the completed letter to LastPass's Data Protection Officer — find the contact details via the link above.
Dear Data Protection Officer,
I am writing to exercise my rights under the General Data Protection Regulation (GDPR). As an individual whose personal data you process, I am requesting the following information:
Below is my information for your reference:
Name:
Email:
Address:
This request is of utmost importance to me and should not be ignored. The GDPR mandates that you respond within one month. Failure to comply may result in further action being taken.
Thank you for your prompt attention to this matter.
Sincerely,,
1. Copy and send this letter to the data controller of the organisation.
2. Follow up until you hear back. The GDPR requires a response within one month.
3. No response? Lodge a complaint with your local data protection authority.
Select your country to find your data protection authority: