r/gdpr

▲ 4 r/gdpr

If all your customers are in the US, do you actually need to care about GDPR?

Comes up constantly and the answers are all over the place, so curious how this sub reads it. If a business is US-based and its customers are all in the US, does GDPR actually apply?

The nuance I keep seeing missed: it's not about where your company is, it's about whose data you process. An EU visitor hitting your US site, an EU customer buying, EU traffic you're running analytics on – any of those can pull you in, even with no EU entity. But "we occasionally get EU visitors" isn't the same as "targeting the EU market" either.

(We work on the consent side, so we hit this question a lot. We're genuinely curious to know where people draw the line.)

Where do you all land: does incidental EU traffic trigger it, or only actually targeting the EU market?

reddit.com
u/iubenda_team — 22 hours ago
▲ 1 r/gdpr

Whose 'Purpose' is being pursued here?

Here's the situation:

We are Company A. We make investments into other companies. When we make an investment into a company, one of our senior employees takes a board member position within that company. Let's call them Company B.

Company B act independently of us (A) but we do have an interest in how our investment is doing, and by having an employee as a board member, we get regular updates through them.

Here's the interesting part- our employee retains and uses their Company A email account when performing their role as a board member of Company B. That means we have lots of data (and personal data) relating to Company B. This is where the question of purpose arises. It might be on our email system (and that's another debate entirely) but whose purpose is it for?

We've had a DSAR submitted to us from a former employee of Company B. I think it's fair to say that the former employee knows that we (A) hold their personal data because they are aware that one of the board members uses their Company A (our) email when performing their role as board member for B. They also likely know that we (A) therefore hold a lot of their personal data in our email system. The information requested relates to their time and role as an employee of Company B. I won't go into details, but the request is specific in nature (it's not a 'give me everything' DSAR).

Merely holding the data doesn't necessarily mean we are dictating the purpose as controller, and if that's the case, the data won't be in scope of the request. We do hold some personal data about the person where it is processed for our purpose (i.e. internal discussions about that person) but these are general discussions and don't meet the requirements of their request.

So the question is, whose purpose is being pursued? Are we in any way responsible for the data we hold in relation to our employee being a board member of B?

Thanks!

reddit.com
▲ 2 r/gdpr+1 crossposts

Are data relating to a sole proprietorship, rather than directly to the individual who owns it, considered personal data?

For example, the quantity and price of goods sold as shown on an invoice.

reddit.com
u/Difficult_Error_2712 — 21 hours ago
▲ 1 r/gdpr

DP control trainee interview

Hi everyone!

I’ll be interviewing for a trainee position in Data Protection Control in the banking sector. I’m a law graduate with some knowledge of GDPR. HR advised me to review the DORA regime, and the job description also mentions “knowledge in Risk, Cybersecurity and IT standards is a plus” - witch I don’t know anything.
Besides studying GDPR and DORA and others, what would you recommend I prepare that is essential for this type of role?

Any advice would be greatly appreciated!

reddit.com
u/Short-Hyena688 — 1 day ago
▲ 4 r/gdpr+2 crossposts

Iapp certified or Maastricht ECPC

Good day all,
I hope this is the right space where to ask for advice on which certification to get.

Context:

I currently work in AI governance for a fintech, with over 4 years of experience in guiding organisations in severely regulated spaces deal with digital regulation (GDPR, AI Act, mostly). I also have an LLM with a focus on privacy law.

Question:

My current employee is willing to pay for me to get certified, this year in privacy and next year in AI. For which option should I go? Cipp/e or Maastricht ecpc-b DPO?

reddit.com
u/sadbutnotsadidk — 2 days ago
▲ 0 r/gdpr

Gdpr Data breach 1 hour

Hello, What would you do if your colleague would give you a document that clearly contains data breach. What is your first hour plan?

reddit.com
u/AdventurousPop4459 — 2 days ago
▲ 20 r/gdpr+1 crossposts

Council officers added a neighbours number to my file.

England, Hampshire. I received an email from Environmental Health saying they had left a voicemail for me to arrange a meeting and discuss a complaint I had made. When I stated I received no message and queried what number they have on file, I was given a number I had not seen before. I looked up the number on WhatsApp and realised it belongs to a neighbour whom I complained about. This means every time I received updates from EH or they followed up on my complaints, my neighbour received it. I have had cases closed previously due to my "lack of engagement" and just convinced myself it's my phone not working properly and missing calls.

This neighbour has harassed me for years and I've had their family members threaten me with violence to the point they were arrested.

Aside from being a gdpr beach(?) I see it as a safety risk to myself and my child. As soon as I became aware, I submitted a SAR to try find the when of this mix up. I submitted this to the data protection officer at the council offices who employ the EH officer. I was told due to me being a post code out of the catchment, they cannot deal with my request.

What are my next steps? I'm unsure what to do but I do not want to let this go. I did not even receive an apology from the officer who caused this breach, I simply got an email saying "I've added my manager to this thread* and nothing else.

tldr; Council was accidentally giving my information and data to a hostile neighbour for a year.

reddit.com
u/National_Poetry8634 — 2 days ago
▲ 0 r/gdpr

How can a European business refund a North American in a GDPR-compliant manner?

A business in France wants to refund me for a botched aesthetic service (fortunately not permanent!) but I have since returned to Canada. I paid half online with my Canadian credit card through their website and half with the same card at the clinic. What would be the easiest way for them to issue a refund while protecting my credit card data? All I have are Canadian accounts (credit cards, banks, etc) or PayPal.

reddit.com
u/FearlessTravels — 3 days ago
▲ 2 r/gdpr

DSR related to how customer support case was handled

Hey folks! We have received a DSR asking copies of all data related to a customer support chat, including handling records and any info on decisions taken on the customer query.

Now I understand that as part of access, we need to provide them all copies. But do we also need to give an “explanation” of why their matter was not escalated? Also, honestly there are not really any handling records - a standard process was followed.

A follow up query - when you know that a matter might go to court or maybe is in court for such customer/consumer matter, do org. have any recourse to withhold any information on this ground?

reddit.com
u/Contract_Killer420 — 3 days ago
▲ 4 r/gdpr

What Are the Biggest Gaps in Data Broker Privacy Laws?

Privacy regulations have given consumers more tools to access, delete, and opt out of certain uses of their personal information.

But the practical reality seems more complicated.

Some of the biggest issues involve:

  • Exemptions for certain regulated data
  • Publicly available information
  • Data being transferred between multiple organizations
  • Opt-outs that don't necessarily prevent future collection
  • Information reappearing after removal

This raises an interesting question about how privacy services should actually work.

If a person's information is removed from one data broker but later appears again through another source, has the privacy problem really been solved?

It seems like effective privacy management may need to be an ongoing process involving discovery, removal, verification, and monitoring not simply a one-time opt-out.

For people working in privacy, compliance, security, or data operations, what do you think is the biggest gap in the current data broker ecosystem?

reddit.com
u/admin_PureWL — 3 days ago
▲ 0 r/gdpr

Looking for beta users.

I have built a browser extension that checks sites for compliance with real data protection laws. It also summarizes privacy policies and flags dark patterns.

Essentially I have built this database using statutes like the GDPR. The extension checks the data being collected by a site, any third parties used by the site, and what they declare in their terms. It then compares that information with the statutory requirements of the user's jurisdiction. And you can also download the report which is in pdf format.

The extension also summarizes terms into short, brief, and easy to read text.

I work in cybersecurity and originally built this for my own use. About two weeks ago, I realized it would serve no purpose sitting on my computer, so I remodelled it for other users and published it on the Chrome Store. Here is the URL https://chromewebstore.google.com/detail/consentinal/iolibolmcpilpdnplnjigfmlcalaheho .

I would like to hear what you might think of it, and any thoughts shared will be highly appreciated.

u/RegionPotential3134 — 4 days ago
▲ 6 r/gdpr

Privacy professionals, what is your daily workload?

I would appreciate any insights from peers on the type of tasks you are dealing with on a daily basis. I do almost everything in our organisation PIA and DPIA, LIA, TIA, ROPA, handling data subject rights (thankfully there are only several per month), handling incidents, reviewing Data Processing Agreements, reviewing supplier's due diligence questionnaires, drafting notices and policies and reviewing existing ones. While the workload itself is bottleneck but sill manageable, the constant context switching feels like it is taking a toll on my relationship with work and engagement. I am wondering if this is just how privacy work looks like for others, or whether you have a more defined scope of responsibilities and shared between your team members. How does your day to day work look like?

reddit.com
u/Head_Appeal2743 — 4 days ago
▲ 2 r/gdpr

What can I reasonably be told about how my data is kept safe?

I have sensitive data held by a UK company "A" who uses a database software that was recently hacked at another company "B" and has been a few times recently elsewhere. I am concerned that with the vulnerability of the database software, my data with A is vulnerable to a similar hack. I asked the DPO for some reassurance of how company A is protecting my (and other people's) data and they said they can't disclose that for security reasons but they're "doing all they can" and "following external advice".

I understand this reasoning to a point, but surely there is some degree of reassurance I can be given of the specifics of this beyond being fobbed off with platitudes? Is it reasonable to ask of a company that stores my data how it protects that? Or are they really okay to be completely vague and unreassuring like this?

reddit.com
u/Salty_Kaleidoscope85 — 4 days ago
▲ 7 r/gdpr

how to avoid GDPR fines related to cookie consent for a small online business

Help!

running a small online business and trying to make sure the cookie consent setup is actually GDPR compliant i know not to drop non essential cookies before consent to make rejecting cookies as easy as accepting them and keep a record of consent etc. but it seems like a lot to make sure of ive been looking at cookiebot to handle some of this rather than managing everything manually but im curious about what other small businesses are doing is a CMP generally the easiest approach for a small site or are you managing cookie consent yourself?

reddit.com
u/Appropriate_Topic749 — 4 days ago
▲ 0 r/gdpr

Could Facebook’s refusal to remove an inaccessible old phone number raise a GDPR security issue?

I have encountered an interesting situation with Facebook that, in my view, raises a broader GDPR question beyond ordinary account support.
I have full access to my Facebook account. I control my email address and I also have Google Authenticator enabled for 2FA.
However, an old Spanish phone number remains associated with the account. I have not controlled this number for more than a year, and it may eventually have been reassigned by the mobile operator to another person.
I therefore tried to remove it for security reasons.
The problem is the following:
If I try to remove the old number, Facebook requires a verification code sent by SMS/WhatsApp to that same old number.
If I try to add a new phone number, Facebook again requires verification through the old number.
I have access to my email and Google Authenticator, but Facebook does not offer either of them as an alternative for these particular changes.
Facebook actually sends security codes to the old number during these attempts.
I have reported the issue to Meta and explained explicitly that I no longer control the number.
I have also recorded the process continuously on video to document exactly how the account-security flow behaves.
This made me wonder whether the issue goes beyond poor account-recovery design.
In particular, I am interested in the interaction with Articles 5(1)(d), 5(1)(f), 16, 25 and 32 GDPR.
Once a controller has been explicitly informed that a telephone number used as a security/contact factor is no longer controlled by the data subject, is it appropriate to continue requiring exclusive access to that same number in order to remove or replace it?
There also seems to be an interesting security paradox here:
A security measure intended to prevent account takeover effectively prevents the legitimate account user from removing a factor that may itself have become a potential account-takeover vector.
I am not suggesting that possession of the recycled number would automatically allow another person to take over the Facebook account. I also understand that Meta may legitimately require enhanced verification before allowing changes to recovery methods.
My question is narrower:
Should a controller provide a secure alternative procedure when it knows that a particular authentication/contact factor is no longer under the data subject’s control, especially where other verified authentication factors remain available?
And, from a GDPR perspective:
Could this raise an issue under the accuracy principle if the number continues to be treated as a current contact/security identifier?
Could the inability to remove or replace it raise questions under data protection by design and security of processing (Articles 25 and 32)?
Is an actual unauthorised access or data breach necessary before an Article 32 issue can arise, or can the adequacy of the security design itself be challenged preventively?
Would Article 16 (rectification) potentially be more relevant here than Article 17 (erasure)?
If the same behaviour affects many Facebook accounts, could this potentially be considered a systemic GDPR issue rather than merely an individual account-support problem?
I would be particularly interested in views from DPOs, privacy lawyers and people familiar with EU supervisory-authority practice or relevant CJEU case law.

reddit.com
u/IceVeritas — 5 days ago
▲ 1 r/gdpr

No visibility into what our third party scripts are actually transmitting. How are you handling this for GDPR?

We load about 12 third party tools on our site, analytics, heatmaps, chat widget. Just realised we have no visibility into what data they're actually transmitting. How are people handling this for GDPR?

reddit.com
u/Dull_Appearance_1828 — 5 days ago
▲ 1 r/gdpr+3 crossposts

Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach? That's the title?

​

Home delivery operations for one of the major UK supermarkets, and I’m deeply concerned about a widespread, unmonitored practice happening at store level that I believe is a major data protection nightmare.

Managers and colleagues have established informal, personal WhatsApp groups on their personal mobile devices to manage daily operational issues and driver updates.

Because these groups are run on personal, unmanaged phones rather than secured corporate systems, the following data is routinely broadcast, downloaded, and stored across dozens of private handsets:

Full Customer PII: First and last names, direct personal telephone numbers, and full home addresses.

Property Access Data: Private gate codes, keylock numbers, door entry passcodes, and safe-place instructions.

Residential Property Photos: High-resolution photos of customers' front doors, driveways, and private building entryways taken on personal cameras.

Why this feels extremely dangerous:

Zero Data Lifecycle Control: When colleagues or managers leave the business, there is no corporate IT oversight to remote-wipe their personal devices. Ex-employees leave with complete camera-roll archives containing customer addresses, phone numbers, door codes, and photos of private properties.

Physical Security Risk: Pairing exact residential addresses and phone numbers with door access codes and visual photos of entryways creates a tangible physical security and burglary risk for homeowners.

UK GDPR & Data Protection Act Breaches:

This completely bypasses corporate security controls (Article 5(1)(f) Integrity and Confidentiality) and processes customer data outside its intended delivery purpose (Article 5(1)(b) Purpose Limitation).

My Questions:

From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?

If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?

What is the most effective route to force accountabilityreporting directly to the ICO, consumer privacy watchdogs (like Which?), or news media?

reddit.com
u/SnowImpossible5699 — 5 days ago
▲ 7 r/gdpr

Another Met Police data breach, when does further action need to be taken?

DISCLAIMER: I’m aware that the data processing and breaches described in this post are subject to the provisions of part 3 of the DPA 2018 rather than the UK GDPR, however this seems the most appropriate subreddit for my question/rant/discussion owing to this thing happening all too often in the UK, and the ICO not pulling their fingers out. Please humour me.

The Metropolitan Police has today apologised for inadvertently disclosing email addresses for alleged victims of sexual harassment from Mohamed Al Fayed - https://www.bbc.co.uk/news/articles/c1w1yv987jqo

This comes a couple of weeks after the Met received an ICO reprimand for inadvertently disclosing email addresses of alleged victims of the Westminster honeytrap scandal, presumably through the same methods - https://ico.org.uk/media2/nuxdnt0c/metropolitan-police-service-reprimand-and-enforcement-notice.pdf

As listless and leaderless as the ICO are at the minute with John Edwards’ resignation and in the midst of their transition to the Information Commission, how often does something like this need to happen before real action is taken?

I understand the enforcement directive is very much not to deprive public authorities of funds that could very much help victims, however a slap on the wrist is becoming less and less appropriate.

u/_Spoggie — 6 days ago
▲ 0 r/gdpr

Reasons ICO Closed Complaints

Given how many complaints are not investigated by the ICO, I anticipated my complaint to be closed. However, does my experience reflect how the ICO achieves their high non-investigation statistics? What closure reasons have people had in their ICO complaints, and has anyone used the local MP approach or alternatives?


I complained to the ICO about a private UK sports/healthcare organisation who among several actions and findings:

  • Without my consent, accessed health records about external treatment I was receiving to change my treatment with them to this since 'we are better'. I learned about their actions from SARs since they refused to tell me why my treatment suddenly changed and why my care was also terminated.
  • Ignored my rectification request and data protection complaint.
  • The DPO (who is the Founder, CEO and much more, which I raised a conflict of interest on, and changed/terminated my care) threatened legal action when I contacted to exercise my rights of deletion.

The ICO closed my complaint using a brief remark I had in my complaint...

ICO (after months of waiting since I submitted): An organisation can respond to a SAR on the final day of the deadline.

Me (appeal): Sure, but what about my whole complaint? I had detailed the harm (MRI scans, referrals, diagnoses etc) I attribute to the situation.

ICO: Section 165 of DPA 2018 informs the ICO does not determine the outcome of every concern within a complaint received. The ICO will not respond any further, but you can appeal our decision using your local MP.

reddit.com
u/MissionForce20 — 7 days ago
▲ 10 r/gdpr

Two DPO email addresses listed on the UK ICO register for WhatsApp/Meta reject my emails — is this compliant with UK GDPR?

I'm in the UK and I'm trying to exercise my data-protection rights in relation to an enforcement decision affecting my long-standing personal WhatsApp account.

My WhatsApp account was unexpectedly disabled on 12 August 2026. I immediately used the in-app review option, but shortly afterwards that route disappeared and WhatsApp now displays:

> "Requesting a review is not available."

I'm not posting here primarily for advice about the account ban itself. What I'm interested in is what happened when I subsequently tried to exercise my data-protection rights.

I pursued the matter through both ordinary WhatsApp Messenger Support and the separate WhatsApp Privacy Operations channel.

I made a formal UK data-protection request asking, amongst other things:

* What categories of my personal data were processed in connection with the enforcement decision.
* Whether another user's report was processed in connection with the restriction, to the extent this can lawfully be disclosed.
* Whether automated processing was used to make or materially influence the decision.
* For meaningful information about the factors involved in that decision, where applicable.
* Whether the decision received meaningful human review.
* Where applicable, for human intervention, an opportunity to make representations, and reconsideration of the decision.

I received several responses that did not substantively address those questions.

WhatsApp Privacy Operations eventually closed the matter, saying:

> "Based on the information provided, we are unable to support your request further."

They also stated:

> "We won't be able to take any further action on this report"

and specifically informed me that I had the right to contact the Information Commissioner's Office (ICO).

**This is where things became particularly strange.**

I looked up WhatsApp LLC on the ICO's public Data Protection Register.

Its current registration is **ZB540984**. The registration identifies the Data Protection Officer contact email as:

`dpowallc@meta.com`

I sent my data-protection correspondence to that address.

**Meta's mail infrastructure rejected it.**

The delivery failure stated that the `dpowallc` group:

> "may not exist, or you may not have permission to post messages to the group."

I therefore telephoned the ICO on 14 August and explained what had happened.

The ICO adviser suggested that I also look at the separate registration for Meta Platforms Ireland Limited, registration **ZB660539**.

That registration identifies a DPO and provides:

`dpo@fb.com`

I therefore sent my request to that address as well.

A short time later, **that email was also rejected by Meta's mail infrastructure.**

The error is essentially the same: the `dpo` group may not exist or I may not have permission to post messages to it.

So I now have the following situation:

  1. WhatsApp Privacy Operations has closed my data-protection case and directed me to the ICO.

  2. The DPO email currently appearing on the ICO registration for WhatsApp LLC (**ZB540984**) rejects my correspondence.

  3. After speaking to the ICO, I tried the DPO contact appearing under Meta Platforms Ireland Limited (**ZB660539**).

  4. That DPO email also rejects my correspondence.

  5. Both rejection messages originate from Meta's mail infrastructure and say either that the respective group may not exist or that I don't have permission to send messages to it.

**To be clear, I'm not claiming that this automatically establishes a UK GDPR infringement. That's ultimately something for the ICO/regulators to determine.**

However, my understanding is that the GDPR requires organisations that have appointed a DPO to publish the DPO's contact details so that data subjects can contact them regarding the processing of their personal data and the exercise of their rights.

That's why I'm struggling to understand how an email address can fulfil that function if correspondence from a data subject is rejected by the organisation's own mail system.

I'm now preparing an ICO complaint and intend to include both delivery failures as evidence.

**I'd be particularly interested in views from people familiar with UK GDPR/DPO requirements:**

**1. Does UK GDPR require a DPO contact method published/provided to the regulator to actually be capable of receiving communications from data subjects?**

**2. Could two registered DPO email addresses rejecting external correspondence potentially amount to a compliance issue in its own right, irrespective of the underlying WhatsApp dispute?**

**3. Is there anything specific I should ask the ICO to investigate regarding the accessibility of the DPO function/contact details?**

**4. Has anyone here previously tried to contact either WhatsApp LLC or Meta Platforms Ireland's DPO using the details appearing on the ICO register? If so, was your correspondence accepted?**

I'm particularly interested in whether the email rejection is reproducible for other people who have had a legitimate reason to contact the DPO, rather than being something specific to my email address.

I have retained the original correspondence, both delivery-failure notices, the WhatsApp Privacy Operations responses and the relevant ICO registration details for my complaint.

reddit.com
u/Balsingh84 — 7 days ago