In the EU, who really pays for truck drivers’ infringements: the driver or the company?

I’ve travelled quite a lot with professional truck drivers in Europe, and one thing has always puzzled me.

From conversations with drivers, I often got the impression that when something goes wrong — especially fines related to driving, tachograph rules or other road infringements — the attitude is basically: “the fine is yours, you’re the driver.”

But I’ve recently been reading Regulation (EC) No 561/2006, and Article 10 seems more interesting than that.

It says that a transport undertaking can be liable for infringements committed by its drivers, even when the infringement takes place in another Member State or a third country.

It also requires transport companies to organise drivers’ work properly, give appropriate instructions and carry out regular checks.

That raises a question for people actually working in European road transport:

In practice, where is the line between the driver’s responsibility and the company’s responsibility?

For example, if a driver exceeds driving time, fails to take the required rest, or commits another tachograph-related infringement, who normally pays the fine in your country?

And does it matter whether the infringement resulted from the driver’s own decision or from schedules, dispatch instructions or pressure from the company?

I’m especially interested in real experiences from EU drivers, dispatchers and transport managers.

Regulation (EC) No 561/2006 — EUR-Lex:
https://eur-lex.europa.eu/eli/reg/2006/561/2024-05-22/eng

reddit.com
u/IceVeritas — 2 days ago
▲ 8 r/DINERO

Las fotos y los vídeos son solo una parte del producto

Veo con bastante frecuencia publicaciones de personas que quieren empezar a vender contenido para adultos y la primera pregunta suele ser la misma: ¿dónde puedo vender mis fotos o vídeos?
Creo que ahí hay un error de partida.
En internet existe una cantidad prácticamente ilimitada de contenido para adultos, y gran parte es gratuito. Por eso, una fotografía más o un vídeo más, por buenos que sean, difícilmente constituyen por sí solos una ventaja competitiva.
Las fotos y los vídeos forman parte del producto, pero no son todo el producto.
También se vende una identidad reconocible, una forma de comunicarse, un nicho, cierta sensación de cercanía, regularidad y una experiencia que haga que alguien quiera seguir precisamente a esa creadora y no a cualquiera de las miles de alternativas disponibles.
Por eso creo que, antes de obsesionarse con producir más material, tendría más sentido preguntarse:
¿Por qué alguien debería pagar por mi contenido cuando tiene una cantidad prácticamente infinita de contenido gratuito a un clic de distancia?
La respuesta a esa pregunta probablemente vale bastante más que una cámara mejor.

reddit.com
u/IceVeritas — 3 days ago

Spotted this Marilyn Monroe Iveco Stralis years ago. Definitely one of the most distinctive trucks I’ve come across.

u/IceVeritas — 3 days ago
▲ 20 r/aww

Burgas to Plovdiv. One passenger clearly got the best seat.

u/IceVeritas — 4 days ago
▲ 207 r/aww

Maya & Koni: when species don’t matter, only pure friendship. ❤️ 🐕🐈

u/IceVeritas — 4 days ago
▲ 0 r/gdpr

Could Facebook’s refusal to remove an inaccessible old phone number raise a GDPR security issue?

I have encountered an interesting situation with Facebook that, in my view, raises a broader GDPR question beyond ordinary account support.
I have full access to my Facebook account. I control my email address and I also have Google Authenticator enabled for 2FA.
However, an old Spanish phone number remains associated with the account. I have not controlled this number for more than a year, and it may eventually have been reassigned by the mobile operator to another person.
I therefore tried to remove it for security reasons.
The problem is the following:
If I try to remove the old number, Facebook requires a verification code sent by SMS/WhatsApp to that same old number.
If I try to add a new phone number, Facebook again requires verification through the old number.
I have access to my email and Google Authenticator, but Facebook does not offer either of them as an alternative for these particular changes.
Facebook actually sends security codes to the old number during these attempts.
I have reported the issue to Meta and explained explicitly that I no longer control the number.
I have also recorded the process continuously on video to document exactly how the account-security flow behaves.
This made me wonder whether the issue goes beyond poor account-recovery design.
In particular, I am interested in the interaction with Articles 5(1)(d), 5(1)(f), 16, 25 and 32 GDPR.
Once a controller has been explicitly informed that a telephone number used as a security/contact factor is no longer controlled by the data subject, is it appropriate to continue requiring exclusive access to that same number in order to remove or replace it?
There also seems to be an interesting security paradox here:
A security measure intended to prevent account takeover effectively prevents the legitimate account user from removing a factor that may itself have become a potential account-takeover vector.
I am not suggesting that possession of the recycled number would automatically allow another person to take over the Facebook account. I also understand that Meta may legitimately require enhanced verification before allowing changes to recovery methods.
My question is narrower:
Should a controller provide a secure alternative procedure when it knows that a particular authentication/contact factor is no longer under the data subject’s control, especially where other verified authentication factors remain available?
And, from a GDPR perspective:
Could this raise an issue under the accuracy principle if the number continues to be treated as a current contact/security identifier?
Could the inability to remove or replace it raise questions under data protection by design and security of processing (Articles 25 and 32)?
Is an actual unauthorised access or data breach necessary before an Article 32 issue can arise, or can the adequacy of the security design itself be challenged preventively?
Would Article 16 (rectification) potentially be more relevant here than Article 17 (erasure)?
If the same behaviour affects many Facebook accounts, could this potentially be considered a systemic GDPR issue rather than merely an individual account-support problem?
I would be particularly interested in views from DPOs, privacy lawyers and people familiar with EU supervisory-authority practice or relevant CJEU case law.

reddit.com
u/IceVeritas — 5 days ago
▲ 3 r/Objectivism+1 crossposts

Does lack of oversight change how people exercise authority?

I've been thinking about a fairly simple question from the perspective of social and organizational psychology.

It is not enough to ask what kind of person has been given authority. We should also look at the rules, supervision and consequences surrounding that authority.

What happens when someone has a certain amount of power, but their decisions are rarely reviewed? What happens when mistakes or inappropriate conduct have practically no consequences?

My view is that good systems should not depend solely on selecting “good people”. They should also provide clear limits, meaningful oversight, transparency and accountability.

This is not about assuming that everyone will abuse power. Quite the opposite: it is about designing institutions around the fact that human behaviour is influenced by roles, incentives and circumstances.

I'm curious how others see this: how important is institutional oversight compared with individual character in preventing abuses of authority?

reddit.com
u/IceVeritas — 6 days ago
▲ 0 r/gdpr

A lesson I’m learning from GDPR litigation: don’t become loyal to your strategy - stay loyal to your objective

I’ve been working through a fairly complex GDPR dispute, and one lesson has become increasingly clear: A legal strategy is a tool, not a commitment!!!

When new evidence, case law or procedural information appears, changing strategy is not inconsistency. Sometimes it is exactly what rational litigation requires.
In my case, I initially thought the strongest route was relatively straightforward:
maintain the complaint → cure the procedural deficiencies → obtain a formal decision → appeal if necessary.
So I started researching European decisions specifically to strengthen that route.
The interesting part is that the research began pointing in another direction.
The more I looked at the distinction between structural GDPR obligations and directly enforceable data-subject rights, the more I started questioning whether obtaining an early substantive ruling on the structurally complicated issue was actually desirable.

A different possibility emerged: preserve that issue for later and concentrate the next proceeding on the much more concrete rights involved, particularly Articles 12(5) and 15 GDPR, while treating the structural issue as potentially relevant context rather than necessarily making it the principal claim.
I still haven’t made the final procedural decision. And that is actually the point.
I think one of the easiest mistakes in legal disputes is becoming psychologically invested in a strategy because you have already spent time developing it. Then contrary evidence starts feeling like something that must be defeated rather than information that should change the plan.

I’m increasingly using a simpler test:
What does this procedural move preserve? What does it risk? What does it actually help me prove?

If tomorrow I find Austrian or EU case law showing that my original strategy is clearly superior, I’ll go back to it. If the evidence continues pointing toward the alternative, I’ll change course. And if a third option turns out to be better, both current strategies can go in the bin.
The objective stays the same. The route to it doesn’t have to.
Has anyone here had a case where researching how to strengthen Strategy A actually convinced you to abandon Strategy A?

reddit.com
u/IceVeritas — 11 days ago
▲ 3 r/gdpr

Can a potential DPO conflict of interest under Article 38 GDPR be challenged through an Article 77 complaint?

I recently received an interesting procedural response from an EU supervisory authority.

I had filed a complaint concerning a potential conflict of interest under Article 38(6) GDPR. The issue was not raised as an abstract concern about a company's organisational structure: I argued that the potential conflict arose in connection with the handling of my own Article 15 requests and the processing of my personal data.

The supervisory authority's preliminary position is that the appointment and organisational position of a DPO concern obligations of the controller under Chapter IV GDPR and do not constitute a subjective right that I can enforce through an individual complaint.

Interestingly, however, the authority expressly stated that the same facts can be investigated in an ex officio supervisory procedure, and suggested that I withdraw my complaint and instead request such an investigation.

This raises a question I find quite interesting in light of Article 77(1), which allows a data subject to lodge a complaint where they consider that the processing of personal data relating to them infringes the GDPR.

If an alleged Article 38(6) conflict is directly connected with the processing of the complainant's own personal data, should it really fall outside the scope of an Article 77 complaint simply because Article 38 is located in Chapter IV?

I'm particularly interested in case law or experiences from other EU supervisory authorities on this distinction between individual complaints and ex officio supervision.

reddit.com
u/IceVeritas — 12 days ago

Austrian criminal procedure: Is it common for a prosecutor to close a case only 3 working days after questioning the suspect?

This is a follow-up to my previous post:

Austria: Can you be prosecuted for false accusation if you only reported facts and asked the prosecutor to assess them? : r/LegaladviceAustria

(It contains the background of the case.)

I have another question about Austrian criminal procedure.

I was questioned as a suspect on 8 July 2026.

According to the official notification from the Public Prosecutor's Office, the investigation against me was discontinued on 13 July 2026.

Since 11 and 12 July were the weekend, this means the decision was taken after only three working days.

My questions are:

  • Is such a short period common in Austrian practice?
  • Does a very quick discontinuation sometimes indicate that the prosecutor considered the police file insufficient to justify continuing the investigation?
  • Or is the duration itself not meaningful at all?

I'm not asking for an assessment of my individual case, but rather about the general practice of Austrian prosecutors.

Thank you in advance.

u/IceVeritas — 21 days ago
▲ 5 r/gdpr

Beyond Privacy Policies and Cookie Banners: Is the Technical Side of GDPR Compliance Being Overlooked?

Many GDPR discussions seem to focus on privacy notices, cookie banners and legal documentation. These are obviously important, but isn't there a tendency to overlook the technical side of compliance?

Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In practice, this goes far beyond simply displaying a privacy policy or a cookie banner.

For example, depending on the website and the processing involved, developers should also consider:

  • HTTPS everywhere.
  • Secure, HttpOnly and SameSite cookie attributes where applicable.
  • Appropriate HTTP security headers, such as Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and clickjacking protection (X-Frame-Options or frame-ancestors in CSP).
  • Keeping software, dependencies and server configurations up to date.
  • Carefully reviewing third-party services such as embedded Google Maps, web fonts, analytics or other external resources.

Of course, not every website will require every one of these measures, and GDPR does not prescribe specific technologies. However, these are examples of technical safeguards that may help meet the Article 32 requirement to implement security measures appropriate to the risk.

In my opinion, GDPR compliance is not only about informing users; it's also about reducing unnecessary risks through secure technical implementation.

What technical measures do you think are most commonly overlooked by developers who are trying to build a GDPR-compliant website?

reddit.com
u/IceVeritas — 24 days ago
▲ 1 r/u_IceVeritas+1 crossposts

Lessons learned about structuring GDPR complaints

After several months of exercising my GDPR rights in relation to CCTV recordings, I’ve come to one conclusion that I wish I had understood from the beginning.
If I had to file my complaints again, I would do so in a different order.
Not because the substance of my case has changed, but because I now believe that some legal questions should be resolved before others.
This is the order I would follow:
1. Independence of the Data Protection Officer (DPO)
Before discussing access to personal data, I would first examine whether the DPO was able to act independently or whether there was a potential conflict between the DPO’s role and the organization’s legal interests.
2. The use of Article 12(5) GDPR
If access requests are rejected as “excessive” or “manifestly unfounded,” I believe this issue should be addressed before debating the merits of the access request itself.
In my case, each Article 15 request concerned a different incident, with a different date, time, location and factual background. The fact that they all related to CCTV did not automatically make them repetitive or excessive.
3. Effective exercise of the right of access under Article 15 GDPR
Only after resolving the previous issues would I focus on whether the controller effectively complied with Article 15 GDPR.
Looking back, I think this sequence provides a clearer legal framework. If the justification for refusing requests under Article 12(5) is found to be inadequate, the discussion about Article 15 becomes much more focused.
I’m sharing this simply as a lesson learned from my own experience. It may be useful to others dealing with repeated GDPR requests or CCTV access cases.
I’d be interested to hear whether others would structure their complaints differently.

reddit.com
u/IceVeritas — 1 month ago

Austria: Can you be prosecuted for false accusation if you only reported facts and asked the prosecutor to assess them?

I have a question about Austrian criminal law.

I submitted a criminal complaint under § 80 StPO regarding an incident at Vienna Airport. The facts described in my complaint are supported by audio and other evidence.

However, I did not state that a crime had definitely been committed. Instead, I asked the competent authorities to determine whether the reported facts could amount to criminal offences.

For example, the complaint contains wording such as:

>

("From my point of view, the described circumstances justify an examination of whether criminally relevant conduct may have occurred.")

It also refers to:

  • Mögliche Nötigung (§ 105 StGB)
  • Mögliche gefährliche Drohung (§ 107 StGB)

So I deliberately used expressions such as "aus meiner Sicht", "Anlass zur Prüfung", and "mögliche", rather than making categorical accusations.

Despite this, I later became the subject of a criminal investigation.

My question is:

Under Austrian law, is there a legal distinction between:

  1. reporting facts and asking the prosecutor to determine whether they constitute a criminal offence; and
  2. falsely asserting as a fact that someone committed a crime?

How do Austrian courts generally assess this distinction?

For context, I've attached a screenshot of the relevant section of my complaint (in German).

📷 Attached: excerpt from the original complaint.

u/IceVeritas — 1 month ago
▲ 3 r/u_IceVeritas+2 crossposts

Can a DPO remain independent if they are also involved in the controller’s legal defence?

I’m looking for views from privacy professionals and DPOs.
GDPR requires DPOs to perform their tasks independently (Article 38). At the same time, in practice, some organisations appear to have DPOs who are also closely involved in responding to complaints, defending the organisation’s legal position, or working within the legal department.
Where do you think the line should be drawn?
At what point does legitimate legal support become a conflict of interests affecting the DPO’s independence?
This question comes from a personal experience, but I’m deliberately asking about the broader legal principle rather than my specific case.
I’d also be interested if anyone is aware of EDPB guidance, CJEU case law, or decisions by supervisory authorities dealing with this issue.

reddit.com
u/IceVeritas — 1 month ago
▲ 9 r/europrivacy+1 crossposts

Is Article 15 GDPR effective when CCTV footage may reveal misconduct by the controller’s own employees?

One question has been on my mind recently.
Article 15 GDPR gives individuals the right to access their personal data, including CCTV footage where they can be identified. On paper, this is an important safeguard.
However, I wonder whether this right is always effective in practice.
Imagine a situation where CCTV footage is the only objective evidence of what happened during an interaction with employees of an organization. The recording could potentially confirm that procedures were followed correctly—or it could reveal inappropriate conduct or other irregularities.
In those circumstances, the controller is not only responsible for processing the data but may also have an institutional interest in the content of the recording.
If the footage is deleted under normal retention policies before access can realistically be exercised, or if preservation is not triggered early enough, does Article 15 still provide an effective remedy?
I’m not suggesting that controllers routinely act in bad faith, nor am I arguing that CCTV should be retained indefinitely.
I’m simply asking whether the current GDPR framework adequately protects data subjects in situations where the recording may also be relevant for accountability.
Do privacy professionals, lawyers or DPOs think the current system strikes the right balance, or is there room for legislative or procedural improvements?

reddit.com
u/IceVeritas — 1 month ago
▲ 0 r/gdpr

Is Article 15 GDPR really an effective right for accessing CCTV footage, or is it mostly theoretical?

The GDPR gives individuals the right to access their personal data under Article 15. In theory, this also includes CCTV footage where a person can be identified.
However, I’m wondering whether this right is genuinely effective in practice.
Many organisations retain CCTV recordings for only a few days. By the time an access request is received, identity is verified, and the request is processed, the footage may already have been automatically deleted. In some cases, controllers also argue that they cannot provide a copy because it contains images of third parties, offering only an on-site viewing or refusing disclosure altogether. In one response I received, it was also explained that footage would not necessarily be preserved merely because an Article 15 request had been submitted, unless it had first been established that the requester actually appeared in the recording.

This raises a broader question.
If CCTV is increasingly used in airports, railway stations, hospitals, shopping centres and other critical infrastructure, shouldn’t there also be an effective mechanism for individuals to verify how they were treated whenever their rights may have been affected?
Otherwise, the right of access risks becoming largely theoretical:
The organisation controls the cameras.
The organisation controls the retention period.
The organisation decides whether the footage is preserved.
By the time the legal process finishes, the footage may no longer exist.
I’m not arguing that every CCTV recording should be kept indefinitely or that privacy protections for third parties should be ignored. Blurring, redaction and supervised access already exist as possible solutions.
My question is more fundamental:

Does Article 15 GDPR currently provide an effective right of access to CCTV footage, or is it often only a right on paper?

I’d be especially interested in hearing from:
privacy lawyers,
Data Protection Officers,
supervisory authorities,
people who have actually submitted Article 15 requests for CCTV footage.
Do you think the current legal framework strikes the right balance, or should the GDPR provide stronger safeguards to ensure that this right can be exercised in practice?

reddit.com
u/IceVeritas — 1 month ago
▲ 1 r/LegaladviceAustria+1 crossposts

Opfervernehmung wegen Nötigung – Darf während der Vernehmung plötzlich eine Verwaltungsübertretung (Meldegesetz) eingeleitet werden?

Ich hätte eine Frage an Personen mit Kenntnissen des österreichischen Straf- und Verwaltungsrechts.
Ich wurde am 29.06.2026 als Opfer bzw. Zeuge in einem Strafverfahren wegen des Verdachts der Nötigung vernommen.

Während dieser Vernehmung stellte der vernehmende Beamte plötzlich Fragen zu meinem Aufenthalt in Österreich und teilte mir anschließend mit, dass ich wegen einer angeblichen Verwaltungsübertretung nach dem Meldegesetz angezeigt werde. Dies wurde auch im Protokoll festgehalten.

Wichtig ist dabei:

Ich hatte keine Wohnung oder Unterkunft in Österreich angemietet.
Ich befand mich während dieser Zeit überwiegend im Transitbereich bzw. am Flughafen Schwechat.
Gegenstand der Vernehmung war ursprünglich ausschließlich meine Anzeige wegen eines mutmaßlichen Straftatbestandes.

Daher stellen sich für mich folgende Fragen:
Ist es üblich oder rechtlich zulässig, dass während einer Opfervernehmung gleichzeitig eine mögliche Verwaltungsübertretung gegen das Opfer eingeleitet wird?
Könnte ein solches Vorgehen – je nach den Umständen – eine Form der Sekundärviktimisierung im Sinne der Richtlinie 2012/29/EU über die Rechte von Opfern darstellen?
Falls kein konkreter Anlass für diese Fragen bestand: Könnte darin ein möglicher Amtsmissbrauch oder zumindest eine unzulässige Vermischung zweier Verfahren gesehen werden?

Mich interessieren ausschließlich rechtliche Einschätzungen und Erfahrungen mit vergleichbaren Fällen.

reddit.com
u/IceVeritas — 1 month ago