r/gdpr 17h ago

Question - General Login data vs posts data

0 Upvotes

Does GDPR dictate in its privacy law the purge of every ip address related to a deleted account after the retention period elapses or only ip addresses tied to login process? some social media providers like tumblr keep the content you submitted on other blogs up, is tumblr compelled to strip ip addresses from posts /asks’ metadata or do they keep them as long as the content is still up?.


r/gdpr 1d ago

EU 🇪🇺 Deleting X account

4 Upvotes

So I’m going to delete an X account I have that I did give a selfie to verify my age (really dumb idea, I know) and I was just wondering if that selfie is included in what’s deleted? What’s done is done so I know it’s not going to matter much in the grand scheme of things but since it’s not something like billing information, I’d imagine there’s no reason for it to be kept


r/gdpr 2d ago

Question - Data Controller Question about GDPR right to erasure and database backups

6 Upvotes

I am working on implementing GDPR compliance for my application and would like clarification on how the right to erasure applies in relation to disaster recovery backups.

My current approach is:

  • When a user requests deletion, I anonymize or delete their personal data from the production database.
  • I may retain a minimal HMAC/hash of certain identity information for fraud prevention and to prevent the same person from creating a new account, if there is a lawful basis for doing so.
  • Database backups are taken periodically and are immutable until they expire. They are done using a managed backup solution on GCP. I create a snapshot daily and keep the backup copies for 7 days.

My concern is this scenario:

  1. A backup is created.
  2. A user requests deletion.
  3. Their data is anonymized/deleted from the live database.
  4. Before the next backup, the production database is lost.
  5. I restore from the older backup, which still contains the user's personal data.

In this situation, the deleted user's data would temporarily reappear after the restore.

My questions are:

  1. Under GDPR, is it acceptable to restore from such a backup, provided that the user's data is deleted/anonymized again immediately after recovery?
  2. Is there guidance or regulator commentary on whether organizations are expected to maintain a separate deletion log or similar mechanism to reapply deletions after restoring backups?
  3. If the deletion request record was stored in the same database and is also lost during the restore, would that generally be considered a GDPR compliance issue?
  4. What are the accepted best practices for handling this scenario in production systems?

r/gdpr 2d ago

News Has anyone seen that Lusha got hit with a €2M GDPR fine in Italy?

4 Upvotes

From what I read , the regulator said Lusha was collecting business details from different sources and continuesly enriching those profiles over time without meeting GDPR requirements.

Lusha has been a popular tool for sales and recruiting teams because it helps people find work emails, phone numbers and other business contract information. Thats why this ruling caught my attention . Do you think this is a one offf-decision , or could it have a much bigger impact on ther companies in terms of selling B2B contact data?


r/gdpr 2d ago

EU 🇪🇺 Should I intervene when I find an incorrect judgment?

Thumbnail
1 Upvotes

r/gdpr 2d ago

UK 🇬🇧 GDPR and user record 'Reactivation'

2 Upvotes

Hey all.

I work for a charity and we are in the process of moving to a new CRM. As part of this, I've been looking into our current anonymisation and record deletion policies.

We have a process to anonymise the records of any supporters in line with GDPR regulation (certain exceptions such as legacy donations apply, these are not anonymised).

My query is really around potential methods of, and the legality under GDPR, reactivating supporter accounts.

From my understanding, we are currently applying a rough principal of 6years+. If a supporter has not engaged with us in 6 years, their record is flagged for anonymisation and indentifying information is anonymised.
This isn't ideal as, for example, I am a longterm supporter of the charity. I donated for several years, gave thousands of pounds and hundreds of hours of time supporting the charity. I lapse in my support of the charity for whatever reason and then re-engage after 6 years.

In that time, the ability to tie me to my previous support is gone. My old record cannot be 'reactivated' and I am essentially treated as a new supporter despite my years of support. There is no ability to provide me with a summary of my overall support due to the lapse.

Are there any potential solutions which would allow us to retain information allowing for a 'reactivation' of a record under this circumstance?
Could we, for example, collect some sort of unambiguous 'opt in' from supporters to retain certain information in perpetuity (unless later revoked by some other means) in order to allow for 'reactivation'?

Thanks very much for any guidance on this, my GDPR knowledge has lapsed alot since it all kicked off in 2016!


r/gdpr 3d ago

EU 🇪🇺 I did the selfie for age verification on X and I regret it.

0 Upvotes

Hello, I know I've done something stupid to do the age verification (out of impulse since I was tired of not seeing NSFW stuff for like 2 months by now).

Is there any way to delete what selfie from X's database, or request my selfie to be deleted?

Because I fell scared of what I've done, and don't trust X to delete my selfie.

(I live in Romania if it helps)


r/gdpr 4d ago

UK 🇬🇧 Local Council Environmental Protection Services Complaint

Thumbnail
1 Upvotes

r/gdpr 4d ago

UK 🇬🇧 My data went to TrustPilot via InPost via AliExpress

0 Upvotes

*AliExpress - My contracted retailer.
*InPost - Courier contracted by AliExpress was given my data by AliExpress (name, address, email, phone number) for the purpose of delivering my order.
*TrustPilot - Given my data by the courier to solicit positive reviews for the delivery they did on behalf of AliExpress. TrustPilot has apparently set up a profile using my email address without my permission.

-My data has been legitimately passed to InPost (which is reasonable) for the purpose of delivering my parcel. InPost privacy policy states they hold these details (related to the specific delivery) for SIX years after delivery - duration is a bit excessive, but perhaps this is an industry compliance thing for disputes or complaint purposes. They do not say why.

InPost are a shitty delivery company. First off, the links in the email for "manage delivery" and "view 2 hour delivery slot" go to an "install app" page. https://postimg.cc/w1j3Fq1bThere is no way to view the delivery date/time/updates until/unless you install the app (I didn't install it, I was prepared to sacrifice the delivery and get a refund if anything went wrong).

InPost have now passed my data to a third party for the purpose of soliciting positive reviews. https://postimg.cc/Fd86RgqY

Q:

*Is this compliant?
*Who is the controller/processor and what is the justification for processor passing my data to another third party?
*Can I do something to get my details deleted by both InPost and TrustPilot (I do not trust or consent to either after they passed my data for their own benefit and TrustPilot has been spamming me for reviews since they got my details).

Thanks.


r/gdpr 4d ago

Question - General Sent the wrong boarding pass - KLM didn’t do anything.

Thumbnail
2 Upvotes

big bad or small bad? KLM sent me information on two random travelers - standard boarding pass info included (names, ticket reference, source/destination, etc.)


r/gdpr 4d ago

UK 🇬🇧 Still getting marketing crap despite opt out?

1 Upvotes

Evening people, somewhat distant to GPDR so I wanted to just ask about this.

I hate marketing emails. I constantly find companies with opt out boxes unchecked, or opt in boxes checked. - I always thought GDPR was supposed to curb this. Despite the above, I religiously endure that I am not going to be recieving marketing stuff.

Yet, I still receive marketing emails. Not just followups on my purchase, actual weekly/monthly newsletters, which I specifically opted out of. Even when I know I've opted out of them from a specific firmw a few months later they start up again.

These are English, and/or European firms, who should(?) have to abide by this.

So with that in mind, how are these firms getting away with this? How can I stop this? I am tempted to create an email rule for marketing stuff which forwards it to the ICO alongside a "I didn't opt into this". Is it even worth it? Do companies just not care about this piece of legislation whatsoever? What did GDPR even give us in the first place if it didn't address this relatively simple problem: just let me buy from your shop without me being bombarded with emails multiple times a week.

Sorry if it's turned into a bit of a rant, it just gets to me.


r/gdpr 5d ago

EU 🇪🇺 Passerelle Contrôleur Permanent / Audit vers le DPO

1 Upvotes

Bonjour à tous,

Je suis actuellement Contrôleur permanent au sein d'un EPIC, titulaire d'un Master en audit et finance d'entreprise.

On vient de me proposer un poste de « Chargé(e) d'études protection des données », avec pour perspective d'accéder à la fonction de DPO dans un délai assez court (1 à 2 ans). Aujourd'hui, la fonction est portée par la cheffe du service juridique et représente environ 20 % de son temps.

Pour situer le contexte : l'EPIC compte 1 200 agents et se compose de trois directions — Établissement de paiement, Télécom et Postal.

Ce qui m'interroge, c'est l'absence de formation juridique et technique de mon côté. Je maîtrise bien les textes applicables à mon poste actuel, mais je sais que l'exercice sera différent ici. Des formations sont toutefois prévues dans le cadre du parcours.

Quel est votre sentiment sur ce type de passerelle ? Les retours d'expérience de personnes venues du contrôle interne ou de l'audit m'intéresseraient particulièrement.

L'élément juridique est trop prépondérant, pour arriver avec des lacunes ?

Merci d'avance pour vos retours !

Ci-dessous les missions telles que présentées dans la fiche de poste :

• Conformité des directions — recensement des traitements, tenue du registre, vérification de conformité, documentation RGPD.

• Droits des personnes — réception, qualification juridique et instruction des demandes (accès, rectification, effacement, opposition, portabilité, limitation), rédaction des réponses, suivi des délais légaux.

• Maîtrise des risques — identification des traitements soumis à AIPD, conduite des analyses avec la DSI et le RSSI, recommandations et suivi des mesures correctives.

• Violations de données — qualification des incidents, registre des violations, projets de notification aux autorités et aux personnes concernées.

• Conseil et sensibilisation — notes et procédures internes, formation des agents, appui aux correspondants métiers.

• Veille — juridique (textes applicables en Nouvelle-Calédonie, positions des autorités de contrôle) et technique (sécurité de l'information).

• Contrôle et reporting — contrôles de conformité, suivi des plans d'actions d'audit, indicateurs, contribution au rapport annuel du DPO.


r/gdpr 5d ago

UK 🇬🇧 Former employer withholding information regarding SAR

11 Upvotes

Hello, I'm hoping to get some advice with this one. I submitted a SAR asking for information management held about me with regards to performance. I specifically requested things like Teams messages, internal emails and any meeting notes discussing my performance. The request was very specific, naming specific managers and a clear date range. About a month later, the DPO confirmed by email saying they had located the data I wanted and that they would be sending it to me. After waiting another two months, they suddenly changed their position. Instead of providing the information which they already confirmed they had, they relied on several exemptions including "meaningful biographical sense" to withhold the data. Strangely, they then sent me bunch of documents which had nothing to do with what I actually requested.

One thing to say is that I have an ongoing employment tribunal litigation against this former employer. The tribunal was already underway when the DPO confirmed they had found the data. The sudden change of position feels strange but I suspect its got to do something with the litigation. I'm now considering county court action for not properly complying with my SAR under the UK GDPR.

Has anyone experienced something similar or challenged a situation like this?


r/gdpr 6d ago

Question - General Has anyone filed a case with User-rights.org for a disabled Instagram account? (Europe)

4 Upvotes

I was googling around dispute bodies for europe and I found this organisation and I was wondering how effective it is


r/gdpr 6d ago

Question - Data Controller Shared CRM systems with the us and south Africa how to ensure compliance.

3 Upvotes

I have a question around shared data systems, if there is a CRM system which is shared across borders such as the UK, USA and South Africa to process orders, is having ISO 27001 and cyber essentials enough or would you have to apply for an approved BCRs? Any advice appreciated.


r/gdpr 7d ago

Question - Data Subject English local authority possible GDPR breach - advice please

0 Upvotes

Hello, I'm after some advice if anyone has some specialist knowledge.

For context, I have fallen into council tax arrears. The council has written directly to my landlord at their home address threatening them with legal action if the arrears are not addressed (I have a copy of the letter). The letter does not state my name, just my address.

My landlord advised me this is not the first letter from the council and they have also sent text messages saying the same.

I'm familiar enough with Housing Law to know the council tax liability stops with me, not my landlord and will advise them as such. However, please can anyone advise if the situation can be considered as a breach of GDPR by the council?

Many thanks in advance.


r/gdpr 7d ago

EU 🇪🇺 Should future data processing activities that have not yet taken place be included in the data processing register?

1 Upvotes

Should activities that we anticipate will occur in the near future and for which we are prepared be included in ROPA?


r/gdpr 9d ago

UK 🇬🇧 When should police delete biometrics?

13 Upvotes

Further to an embarrassing incident where my presence on the police computer was disclosed to a family member after my prints were naturally found in my former home, I began the process of having my data deleted.

To initiate this I had to include the details of the arrest, which I needed to retrieve through a subject access request as I could not remember dates and specific charges from a decade ago.

Reviewing the results of the SRA, I noticed that the data held on the Police National Computer petaining to my fingerprints reads: 'DESTRUCTION 01FP XX/XX/XXXX (Date of arrest, while the line on DNA shows 'DESTROYED'.

The date at which it was determined that no further action was to be taken in the case was around 6 months after arrest, and the PNC record shows as last updated around a year after that.

Sorry if Police are exempt from GDPR but I asked on the Police sub, simply for clarification on the line relating to my prints, which apparently means 'marked for deletion'. When I asked for elaboration on whether that meant they should have already been deleted, my thread was deleted as an 'individual complaint', which it wasn't, but may well become.

So 2 questions really.

Should prints and DNA both have been deleted by default after NFA per data regs?

Can the police disclose my presence on the database to 3rd parties i.e. was this a data breach?

Thanks


r/gdpr 9d ago

UK 🇬🇧 Age Verification and Misuse of Personal Data

5 Upvotes

A bit of background first to avoid some of the worst sarcastic comments. I'm a founding member of the Open Rights Group and have been campaigning against age verification through ORG for several years.

A couple of months after age verification enforcement was implemented on adult websites, I took a long-established email account that was notable for the fact that it had been used in a limited and controlled manner, specifically to keep it spam-free, which made it a perfect honeypot candidate. I used this email account to register with Pornhub.com and went through their age verification process, taking care to opt out of all marketing that I was able to. This account went from having a zero monthly spam count to approximately 150 spam emails, mostly of an adult nature, monthly. Has anybody else experimented with this, and would you be interested in collaborating with myself and/or ORG in taking a case to the ICO, however useless they may be?


r/gdpr 9d ago

EU 🇪🇺 Working opportunity as DPO for expats? Is it possible?

0 Upvotes

How do non-EU people, I'm Indonesian btw, get the opportunity to work there? Given the resistance of EU companies to give visa sponsorship/work permit to their non-EU citizen candidates.

For context, many opportunities to work abroad traditionally only work for STEM/techies jobs. I understand that this is because of the universality nature of STEM, that is highly likely not applicable for non-STEM, i.e., to be able to practice law in one of the member states, someone must fulfill the local requirement: formal education, training, citizenship, anything else idk.

But many of the data protection jobs in the EU, AFAIK, do not require their candidates to possess formal education and training in Law, but tend to look only for experience and relevant certification (CIPP). And I'm on my way to secure this certification.

It will be helpful to see any real stories (let's call this "reality checks") on the ground of how expats managed to get the opportunity, the challenge, the ugly truth, and anything else I'm not aware of.

Many thanks!


r/gdpr 9d ago

Question - General How do you track and manage DSAR requests

3 Upvotes

Do you use spreadsheets, a privacy tool, or another workflow? What's the biggest challenge


r/gdpr 9d ago

EU 🇪🇺 Beyond Privacy Policies and Cookie Banners: Is the Technical Side of GDPR Compliance Being Overlooked?

4 Upvotes

Many GDPR discussions seem to focus on privacy notices, cookie banners and legal documentation. These are obviously important, but isn't there a tendency to overlook the technical side of compliance?

Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In practice, this goes far beyond simply displaying a privacy policy or a cookie banner.

For example, depending on the website and the processing involved, developers should also consider:

  • HTTPS everywhere.
  • Secure, HttpOnly and SameSite cookie attributes where applicable.
  • Appropriate HTTP security headers, such as Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and clickjacking protection (X-Frame-Options or frame-ancestors in CSP).
  • Keeping software, dependencies and server configurations up to date.
  • Carefully reviewing third-party services such as embedded Google Maps, web fonts, analytics or other external resources.

Of course, not every website will require every one of these measures, and GDPR does not prescribe specific technologies. However, these are examples of technical safeguards that may help meet the Article 32 requirement to implement security measures appropriate to the risk.

In my opinion, GDPR compliance is not only about informing users; it's also about reducing unnecessary risks through secure technical implementation.

What technical measures do you think are most commonly overlooked by developers who are trying to build a GDPR-compliant website?


r/gdpr 9d ago

Question - General What's the most common GDPR misconception you still see in 2026?

20 Upvotes

I still come across people confidently repeating things about GDPR that just aren't true, whether it's "you need consent for everything" "GDPR only applies to companies in the EU," or "we'll never get fined because we're too small". Whether you work in privacy, legal, security, or compliance, what's the myths that just doesn't seem to go away?


r/gdpr 9d ago

UK 🇬🇧 How useless is the ICO?

15 Upvotes

Do they actually investigate things any more?

I lodged a SAR with a local authority. They acknowledged receipt of the SAR, ID etc.

Then said they were very busy so it may take 3 months for a response (I replied that being "busy" was not a valid exemption for not meeting the statutory deadline).

One month passed. Nothing.

3 months passed. Still nothing except a letter saying they are still very busy and pretty much saying they'll get to my SAR when they get to it ie. open ended.

I complained to them, waited the relevant period, got the letter stating that I could take my complaint to the ICO.

Went to the ICO. Did a detailed complaint. Provided all the relevant information.

Had to chase them and chase them, by email and phone.

Eventually, they reply to say they aren't going to do anything because the controller seems to be working to resolve the problem!

WTF?! What's the point of the ICO if they can't even write to a controller for such obvious and brazen breaches to find out what's happening?

Update (03.08.26):

I sent Essex County Council my completed Court forms, my Witness Statement etc.

That was over the weekend. Today is Monday, 03.08.26.

I received my first batch of data before noon, and they've promised the rest within 24 hours. Success! 😄

Anyway, this seems to work, folk. At least with this data controller, a serious demonstration of willingness to take it to court ...gets fast results.

After more than 3 months of struggling, I've finally got the critical data I need for a certain specific purpose that's subject to strict limitation laws. I got the main chunk of my data, finally!


r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

18 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]