Ghostery have exposed everyone’s email address in it’s GDPR email by not using BCC Got an email about 30 minutes ago from Ghostery about it's compliance with GDPR. Looks like everyone's email address has exposed in the To field instead of BCC being used to hide them… Here are some screenshots. I don't use Ghostery …