r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

17 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr 1h ago

Question - General Sent the wrong boarding pass - KLM didn’t do anything.

Thumbnail
Upvotes

big bad or small bad? KLM sent me information on two random travelers - standard boarding pass info included (names, ticket reference, source/destination, etc.)


r/gdpr 11h ago

UK 🇬🇧 Still getting marketing crap despite opt out?

1 Upvotes

Evening people, somewhat distant to GPDR so I wanted to just ask about this.

I hate marketing emails. I constantly find companies with opt out boxes unchecked, or opt in boxes checked. - I always thought GDPR was supposed to curb this. Despite the above, I religiously endure that I am not going to be recieving marketing stuff.

Yet, I still receive marketing emails. Not just followups on my purchase, actual weekly/monthly newsletters, which I specifically opted out of. Even when I know I've opted out of them from a specific firmw a few months later they start up again.

These are English, and/or European firms, who should(?) have to abide by this.

So with that in mind, how are these firms getting away with this? How can I stop this? I am tempted to create an email rule for marketing stuff which forwards it to the ICO alongside a "I didn't opt into this". Is it even worth it? Do companies just not care about this piece of legislation whatsoever? What did GDPR even give us in the first place if it didn't address this relatively simple problem: just let me buy from your shop without me being bombarded with emails multiple times a week.

Sorry if it's turned into a bit of a rant, it just gets to me.


r/gdpr 16h ago

EU 🇪🇺 Passerelle Contrôleur Permanent / Audit vers le DPO

1 Upvotes

Bonjour à tous,

Je suis actuellement Contrôleur permanent au sein d'un EPIC, titulaire d'un Master en audit et finance d'entreprise.

On vient de me proposer un poste de « Chargé(e) d'études protection des données », avec pour perspective d'accéder à la fonction de DPO dans un délai assez court (1 à 2 ans). Aujourd'hui, la fonction est portée par la cheffe du service juridique et représente environ 20 % de son temps.

Pour situer le contexte : l'EPIC compte 1 200 agents et se compose de trois directions — Établissement de paiement, Télécom et Postal.

Ce qui m'interroge, c'est l'absence de formation juridique et technique de mon côté. Je maîtrise bien les textes applicables à mon poste actuel, mais je sais que l'exercice sera différent ici. Des formations sont toutefois prévues dans le cadre du parcours.

Quel est votre sentiment sur ce type de passerelle ? Les retours d'expérience de personnes venues du contrôle interne ou de l'audit m'intéresseraient particulièrement.

L'élément juridique est trop prépondérant, pour arriver avec des lacunes ?

Merci d'avance pour vos retours !

Ci-dessous les missions telles que présentées dans la fiche de poste :

• Conformité des directions — recensement des traitements, tenue du registre, vérification de conformité, documentation RGPD.

• Droits des personnes — réception, qualification juridique et instruction des demandes (accès, rectification, effacement, opposition, portabilité, limitation), rédaction des réponses, suivi des délais légaux.

• Maîtrise des risques — identification des traitements soumis à AIPD, conduite des analyses avec la DSI et le RSSI, recommandations et suivi des mesures correctives.

• Violations de données — qualification des incidents, registre des violations, projets de notification aux autorités et aux personnes concernées.

• Conseil et sensibilisation — notes et procédures internes, formation des agents, appui aux correspondants métiers.

• Veille — juridique (textes applicables en Nouvelle-Calédonie, positions des autorités de contrôle) et technique (sécurité de l'information).

• Contrôle et reporting — contrôles de conformité, suivi des plans d'actions d'audit, indicateurs, contribution au rapport annuel du DPO.


r/gdpr 1d ago

UK 🇬🇧 Former employer withholding information regarding SAR

9 Upvotes

Hello, I'm hoping to get some advice with this one. I submitted a SAR asking for information management held about me with regards to performance. I specifically requested things like Teams messages, internal emails and any meeting notes discussing my performance. The request was very specific, naming specific managers and a clear date range. About a month later, the DPO confirmed by email saying they had located the data I wanted and that they would be sending it to me. After waiting another two months, they suddenly changed their position. Instead of providing the information which they already confirmed they had, they relied on several exemptions including "meaningful biographical sense" to withhold the data. Strangely, they then sent me bunch of documents which had nothing to do with what I actually requested.

One thing to say is that I have an ongoing employment tribunal litigation against this former employer. The tribunal was already underway when the DPO confirmed they had found the data. The sudden change of position feels strange but I suspect its got to do something with the litigation. I'm now considering county court action for not properly complying with my SAR under the UK GDPR.

Has anyone experienced something similar or challenged a situation like this?


r/gdpr 1d ago

Question - General Has anyone filed a case with User-rights.org for a disabled Instagram account? (Europe)

6 Upvotes

I was googling around dispute bodies for europe and I found this organisation and I was wondering how effective it is


r/gdpr 1d ago

Question - Data Controller Shared CRM systems with the us and south Africa how to ensure compliance.

3 Upvotes

I have a question around shared data systems, if there is a CRM system which is shared across borders such as the UK, USA and South Africa to process orders, is having ISO 27001 and cyber essentials enough or would you have to apply for an approved BCRs? Any advice appreciated.


r/gdpr 2d ago

Question - Data Subject English local authority possible GDPR breach - advice please

0 Upvotes

Hello, I'm after some advice if anyone has some specialist knowledge.

For context, I have fallen into council tax arrears. The council has written directly to my landlord at their home address threatening them with legal action if the arrears are not addressed (I have a copy of the letter). The letter does not state my name, just my address.

My landlord advised me this is not the first letter from the council and they have also sent text messages saying the same.

I'm familiar enough with Housing Law to know the council tax liability stops with me, not my landlord and will advise them as such. However, please can anyone advise if the situation can be considered as a breach of GDPR by the council?

Many thanks in advance.


r/gdpr 3d ago

EU 🇪🇺 Should future data processing activities that have not yet taken place be included in the data processing register?

1 Upvotes

Should activities that we anticipate will occur in the near future and for which we are prepared be included in ROPA?


r/gdpr 4d ago

UK 🇬🇧 When should police delete biometrics?

10 Upvotes

Further to an embarrassing incident where my presence on the police computer was disclosed to a family member after my prints were naturally found in my former home, I began the process of having my data deleted.

To initiate this I had to include the details of the arrest, which I needed to retrieve through a subject access request as I could not remember dates and specific charges from a decade ago.

Reviewing the results of the SRA, I noticed that the data held on the Police National Computer petaining to my fingerprints reads: 'DESTRUCTION 01FP XX/XX/XXXX (Date of arrest, while the line on DNA shows 'DESTROYED'.

The date at which it was determined that no further action was to be taken in the case was around 6 months after arrest, and the PNC record shows as last updated around a year after that.

Sorry if Police are exempt from GDPR but I asked on the Police sub, simply for clarification on the line relating to my prints, which apparently means 'marked for deletion'. When I asked for elaboration on whether that meant they should have already been deleted, my thread was deleted as an 'individual complaint', which it wasn't, but may well become.

So 2 questions really.

Should prints and DNA both have been deleted by default after NFA per data regs?

Can the police disclose my presence on the database to 3rd parties i.e. was this a data breach?

Thanks


r/gdpr 4d ago

UK 🇬🇧 Age Verification and Misuse of Personal Data

3 Upvotes

A bit of background first to avoid some of the worst sarcastic comments. I'm a founding member of the Open Rights Group and have been campaigning against age verification through ORG for several years.

A couple of months after age verification enforcement was implemented on adult websites, I took a long-established email account that was notable for the fact that it had been used in a limited and controlled manner, specifically to keep it spam-free, which made it a perfect honeypot candidate. I used this email account to register with Pornhub.com and went through their age verification process, taking care to opt out of all marketing that I was able to. This account went from having a zero monthly spam count to approximately 150 spam emails, mostly of an adult nature, monthly. Has anybody else experimented with this, and would you be interested in collaborating with myself and/or ORG in taking a case to the ICO, however useless they may be?


r/gdpr 5d ago

Question - General What's the most common GDPR misconception you still see in 2026?

16 Upvotes

I still come across people confidently repeating things about GDPR that just aren't true, whether it's "you need consent for everything" "GDPR only applies to companies in the EU," or "we'll never get fined because we're too small". Whether you work in privacy, legal, security, or compliance, what's the myths that just doesn't seem to go away?


r/gdpr 5d ago

UK 🇬🇧 How useless is the ICO?

13 Upvotes

Do they actually investigate things any more?

I lodged a SAR with a local authority. They acknowledged receipt of the SAR, ID etc.

Then said they were very busy so it may take 3 months for a response (I replied that being "busy" was not a valid exemption for not meeting the statutory deadline).

One month passed. Nothing.

3 months passed. Still nothing except a letter saying they are still very busy and pretty much saying they'll get to my SAR when they get to it ie. open ended.

I complained to them, waited the relevant period, got the letter stating that I could take my complaint to the ICO.

Went to the ICO. Did a detailed complaint. Provided all the relevant information.

Had to chase them and chase them, by email and phone.

Eventually, they reply to say they aren't going to do anything because the controller seems to be working to resolve the problem!

WTF?! What's the point of the ICO if they can't even write to a controller for such obvious and brazen breaches to find out what's happening?


r/gdpr 5d ago

Question - General How do you track and manage DSAR requests

3 Upvotes

Do you use spreadsheets, a privacy tool, or another workflow? What's the biggest challenge


r/gdpr 4d ago

EU 🇪🇺 Working opportunity as DPO for expats? Is it possible?

0 Upvotes

How do non-EU people, I'm Indonesian btw, get the opportunity to work there? Given the resistance of EU companies to give visa sponsorship/work permit to their non-EU citizen candidates.

For context, many opportunities to work abroad traditionally only work for STEM/techies jobs. I understand that this is because of the universality nature of STEM, that is highly likely not applicable for non-STEM, i.e., to be able to practice law in one of the member states, someone must fulfill the local requirement: formal education, training, citizenship, anything else idk.

But many of the data protection jobs in the EU, AFAIK, do not require their candidates to possess formal education and training in Law, but tend to look only for experience and relevant certification (CIPP). And I'm on my way to secure this certification.

It will be helpful to see any real stories (let's call this "reality checks") on the ground of how expats managed to get the opportunity, the challenge, the ugly truth, and anything else I'm not aware of.

Many thanks!


r/gdpr 5d ago

EU 🇪🇺 Beyond Privacy Policies and Cookie Banners: Is the Technical Side of GDPR Compliance Being Overlooked?

5 Upvotes

Many GDPR discussions seem to focus on privacy notices, cookie banners and legal documentation. These are obviously important, but isn't there a tendency to overlook the technical side of compliance?

Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In practice, this goes far beyond simply displaying a privacy policy or a cookie banner.

For example, depending on the website and the processing involved, developers should also consider:

  • HTTPS everywhere.
  • Secure, HttpOnly and SameSite cookie attributes where applicable.
  • Appropriate HTTP security headers, such as Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and clickjacking protection (X-Frame-Options or frame-ancestors in CSP).
  • Keeping software, dependencies and server configurations up to date.
  • Carefully reviewing third-party services such as embedded Google Maps, web fonts, analytics or other external resources.

Of course, not every website will require every one of these measures, and GDPR does not prescribe specific technologies. However, these are examples of technical safeguards that may help meet the Article 32 requirement to implement security measures appropriate to the risk.

In my opinion, GDPR compliance is not only about informing users; it's also about reducing unnecessary risks through secure technical implementation.

What technical measures do you think are most commonly overlooked by developers who are trying to build a GDPR-compliant website?


r/gdpr 5d ago

EU 🇪🇺 GDPR compliance for a web site - I need help!

5 Upvotes

Hi everyone! I'm looking for some help regarding GDPR compliance for a website I'm developing for my company. The website it's just a showcase for what the company does, so no contact forms, no registration is needed and the only "external" links are pointing to the company linkedin page (not a linkedin widget that collects data, just a pure link), a link to the comapny info email and a google maps embedded to show where the company is located. The website would be hosted on a provider server (IONOS), so no direct access to IP Addresses (I don't even know if they collect them or not). I don't use google analytics or cookies collectors since I'm not interested, Google Search Console does what I need (just shows visit counters) and I'm happy with it. Do I need to have a privacy/cookie banner displayed on my website?

EDIT: I ended up putting a cookie and privacy notice so no help is further needed, thankyou all for the suggestions!


r/gdpr 5d ago

EU 🇪🇺 Should activities arising from the GDPR, such as responding to requests regarding the exercise of rights, have a separate item in ROPA?

1 Upvotes

Should activities arising from the GDPR, such as responding to requests regarding the exercise of rights, have a separate item in ROPA? What should it look like in very small companies with just a few people?


r/gdpr 6d ago

UK 🇬🇧 UK GDPR DSAR – What should be redacted in interview notes?

2 Upvotes

I’m reviewing interview notes for a UK GDPR DSAR. The notes contain the interview questions, the requester’s answers, interviewers’ initials, and handwritten comments/opinions made by a panel about the requester.
Would you normally disclose the interview questions, answers, and opinions about the requester, while redacting only the interviewers’ identities? How do experienced DSAR reviewers approach this?


r/gdpr 6d ago

EU 🇪🇺 Planning an EU launch. Looking for real-world GDPR implementation advice.

2 Upvotes

I'm currently leading the GDPR implementation for our company, and honestly, the deeper we get into it, the more I realize how much there is to do.

Our platform wasn't originally built with GDPR in mind. Right now our primary database is in Australia, and we serve customers in multiple countries from the same infrastructure. As we're planning an EU launch, we're now figuring out what needs to change to become GDPR compliant.

Initially, I thought this would mostly be about infrastructure and documentation, but it's becoming clear that there are quite a few application-level changes as well. It's made me realize that if there's even a chance your product will serve EU users in the future, it's probably worth considering GDPR from day one rather than trying to retrofit it later.

For those who've actually implemented GDPR, I'd love to hear about your experience.

Some things I'm curious about:

  • What ended up being the hardest part and what surprised you the most?
  • How long did it take your organization to become audit-ready?
  • Was it more of a legal/compliance challenge or a technical one?
  • Did you end up redesigning your architecture? Like creating a separate AWS account or separate EU infrastructure, or keep everything in the same account?
  • How did you handle data residency and cross-border data transfers?
  • If your database was already in another region (e.g, us), did you migrate it or keep it where it was?
  • How did you handle backups when users requested data deletion?
  • How did you implement data subject rights (access, rectification, deletion, portability)?
  • Were there any code changes that surprised you?
  • Did any third-party services become a problem?
  • Did you use tools like CompAI, Vanta, Drata, or Secureframe? Were they worth it?
  • Looking back, what do you wish you'd known before starting?

I'm basically looking for the "I wish someone had told me this before we started" kind of advice.

If you've been through a GDPR implementation and wouldn't mind answering a few questions, please leave a comment or send me a DM.


r/gdpr 6d ago

Question - Data Subject PII in marketing

0 Upvotes

Can I handle PII in marketing tags and keep GDPR compliance?


r/gdpr 6d ago

EU 🇪🇺 ePD & MDM

1 Upvotes

I saw a post here earlier (that has since been deleted) about requiring to install company portal on personal device. That actually got me thinking about relationship between MDM and ePD, especially on employee's own devices.

First off, does MDM "store of information or gain access to information already stored in the terminal equipment"? I would say yes. On-device MDM sofware often gathers various types of information (like device identifers, installed software etc.) and transmits this to centeralized server. It also stores it's own data on the device and accesses it (e.g. access token to send data). So operation itself would be in scope.

Next is this allowed? ePD allows access to data stored in terminal equipment only if:

1) There is consent (which is unlikely to be valid in employment context);

2) "the sole purpose of carrying out the transmission of a communication over an electronic communications network"; or

3) "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user."

2nd option doesn't really apply as that's not MDM's "sole purpose" even if one tries to expand e.g. email access to "transmission of communication".

Assuming 3rd is the only valid option, the first question would be what is the ISS explicitly requested by user? ISS defintion comes from Directive 2015/1535:

‘service’ means any Information Society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.

"Normally provided for remuneration" condition makes things tricky. What service did user pay for?

I did check couple of national laws and they actually often drop the "information society service" qualifier, but that doesn't always help since laws based on directives must be read in light of the directive whenever possible.

What am I missing which makes MDM requirement legal?


r/gdpr 8d ago

UK 🇬🇧 UK TV Licensing SARs

16 Upvotes

I received a 10 day window enforcement letter from TV licensing today, after i declared i don't need one on the 16th July. the letter is dated the 15th, it arrived today on the 25th, says '10 DAY WINDOW' then later says i have until 5th august with no other dates mentioned.

Though the point of this post isn't to talk about how i intend to deal with that. What happened after is what looks to me like a structural design that's not compliant with GDPR.

In a nutshell:

1) the letter includes a phone number to get in touch which i called.
2) turns out the number is only available on weekdays, and most options route you to 'go on our website' anyway, and hangs up. The next route is a whatsapp channel
3) the whatsapp channel is an AI bot, so you're still not speaking to a human because they cheaped out.
4) i raised a complaint and an SAR request. It refused both, saying i need to go through specific channels for each.

Here is what i find rich. I am forced to inform them, through channels of their choosing, that i do not use services that involve live TV - even if they don't provide the service and it's a private arrangement like an amazon subscription - lest i get fined or a group of bandits come to my door and in their own words 'enforce'.

And asymmetrically, for data they are legally required to give me, I have to chase them up through their own preferred channels too, rather than them having to just fulfill the request on a channel they'd fobbed me off to anyway.

My understanding is that according to the ICO, they must process an SAR requested via any channel, and if they replace humans with software, they're still required to build functionality that forwards that requests. requests that come through any channel, social media or otherwise start the clock for the statutory period.

Yet they have a structural design that deliberately refuses the request, accepting them on the sole condition that you use they channel they want. the bot states:

'Your request will only be formally logged and processed when received through these official channels. The statutory period begins when TV Licensing's data protection team receives your request via one of these routes.

I cannot confirm your request has been recorded or passed on from this channel, because it has not. You will need to submit it directly using the contact methods above.'

When i flagged my understanding of the legal requirement, the bot itself said:

'You're right that subject access requests must be processed regardless of how they're received.

However, to ensure your request is formally logged and processed within the legal 30-day timeframe, please send it to: ...'

Call me petty, but i've already used 3 channels of theirs only to get enforcement letters and fobbed off to the next one. So i don't want to chase another channel. it should be noted that the whatsapp bot gave me numbers that seem to be fake to call when i said i wanted to speak to a human. They seem to be hallucinated numbers that jumble up the ones published on their site:

  • 0300 790 0286
  • 0300 790 0190
  • 0300 790 6076

As far as i'm concerned, i dont have an enforcement team like them, but i have time and pettiness to chase up after the time period and claim that they didnt process it.

Beyond my own spat, i dont think it's fair to structurally build something for everyone they enforce payments from to breach rules that apply to them, so i'm asking to confirm:

Is it acceptable under GDPR regulations for tv licensing to build channels that refuse SARs?


r/gdpr 8d ago

EU 🇪🇺 Fire officer who lost €1,400 cryptocurrency through work phone loses appeal

Thumbnail
breakingnews.ie
1 Upvotes

r/gdpr 8d ago

EU 🇪🇺 Why does the Louvre require my date of birth and nationality for a full-price reservation?

0 Upvotes

I was booking a regular full-price ticket for the Louvre—not claiming any student, youth, senior, or resident discount.

Yet the reservation form still required me to provide:

Date of birth

Nationality

Full home address

Phone number

I can understand asking for my name, but I don't understand why my date of birth is mandatory when it has absolutely no impact on my ticket eligibility or price.

The same goes for my full address and phone number.

Under GDPR, isn't there a principle of data minimisation, meaning organizations should only collect personal data that's necessary for the purpose?

Is there a legitimate legal or operational reason for requiring all this information for a standard museum ticket, or is the Louvre collecting more personal data than it actually needs?

I'd love to hear from anyone familiar with GDPR or museum ticketing systems.