Does the GDPR, designed to protect customer data, unintentionally create opportunities for cybercriminals to exploit it?