Yes. Eurail has reported the incident to the relevant data protection authority, in line with GDPR requirements and we have notified other relevant data protection authorities outside of the EU (as required). We have also informed relevant partners who resell or distribute Eurail and Interrail passes to their own customers.