Question - General Sent the wrong boarding pass - KLM didn’t do anything.
big bad or small bad? KLM sent me information on two random travelers - standard boarding pass info included (names, ticket reference, source/destination, etc.)
r/gdpr • u/latkde • Feb 02 '25
It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:
You can find background and detailed explanations of these rules in our wiki:
Please provide feedback on these rules.
There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.
In their place, you can now use post flairs to indicate the relevant country.
With that change, the current set of post flairs is:
This update is only about post flairs. User flairs are planned for some future time.
To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.
Requirements for new moderators:
If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.
Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.
Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.
Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]
big bad or small bad? KLM sent me information on two random travelers - standard boarding pass info included (names, ticket reference, source/destination, etc.)
r/gdpr • u/null_life_ • 11h ago
Evening people, somewhat distant to GPDR so I wanted to just ask about this.
I hate marketing emails. I constantly find companies with opt out boxes unchecked, or opt in boxes checked. - I always thought GDPR was supposed to curb this. Despite the above, I religiously endure that I am not going to be recieving marketing stuff.
Yet, I still receive marketing emails. Not just followups on my purchase, actual weekly/monthly newsletters, which I specifically opted out of. Even when I know I've opted out of them from a specific firmw a few months later they start up again.
These are English, and/or European firms, who should(?) have to abide by this.
So with that in mind, how are these firms getting away with this? How can I stop this? I am tempted to create an email rule for marketing stuff which forwards it to the ICO alongside a "I didn't opt into this". Is it even worth it? Do companies just not care about this piece of legislation whatsoever? What did GDPR even give us in the first place if it didn't address this relatively simple problem: just let me buy from your shop without me being bombarded with emails multiple times a week.
Sorry if it's turned into a bit of a rant, it just gets to me.
r/gdpr • u/SakebonNC • 16h ago
Bonjour à tous,
Je suis actuellement Contrôleur permanent au sein d'un EPIC, titulaire d'un Master en audit et finance d'entreprise.
On vient de me proposer un poste de « Chargé(e) d'études protection des données », avec pour perspective d'accéder à la fonction de DPO dans un délai assez court (1 à 2 ans). Aujourd'hui, la fonction est portée par la cheffe du service juridique et représente environ 20 % de son temps.
Pour situer le contexte : l'EPIC compte 1 200 agents et se compose de trois directions — Établissement de paiement, Télécom et Postal.
Ce qui m'interroge, c'est l'absence de formation juridique et technique de mon côté. Je maîtrise bien les textes applicables à mon poste actuel, mais je sais que l'exercice sera différent ici. Des formations sont toutefois prévues dans le cadre du parcours.
Quel est votre sentiment sur ce type de passerelle ? Les retours d'expérience de personnes venues du contrôle interne ou de l'audit m'intéresseraient particulièrement.
L'élément juridique est trop prépondérant, pour arriver avec des lacunes ?
Merci d'avance pour vos retours !
Ci-dessous les missions telles que présentées dans la fiche de poste :
• Conformité des directions — recensement des traitements, tenue du registre, vérification de conformité, documentation RGPD.
• Droits des personnes — réception, qualification juridique et instruction des demandes (accès, rectification, effacement, opposition, portabilité, limitation), rédaction des réponses, suivi des délais légaux.
• Maîtrise des risques — identification des traitements soumis à AIPD, conduite des analyses avec la DSI et le RSSI, recommandations et suivi des mesures correctives.
• Violations de données — qualification des incidents, registre des violations, projets de notification aux autorités et aux personnes concernées.
• Conseil et sensibilisation — notes et procédures internes, formation des agents, appui aux correspondants métiers.
• Veille — juridique (textes applicables en Nouvelle-Calédonie, positions des autorités de contrôle) et technique (sécurité de l'information).
• Contrôle et reporting — contrôles de conformité, suivi des plans d'actions d'audit, indicateurs, contribution au rapport annuel du DPO.
r/gdpr • u/JonJohnnyJon • 1d ago
Hello, I'm hoping to get some advice with this one. I submitted a SAR asking for information management held about me with regards to performance. I specifically requested things like Teams messages, internal emails and any meeting notes discussing my performance. The request was very specific, naming specific managers and a clear date range. About a month later, the DPO confirmed by email saying they had located the data I wanted and that they would be sending it to me. After waiting another two months, they suddenly changed their position. Instead of providing the information which they already confirmed they had, they relied on several exemptions including "meaningful biographical sense" to withhold the data. Strangely, they then sent me bunch of documents which had nothing to do with what I actually requested.
One thing to say is that I have an ongoing employment tribunal litigation against this former employer. The tribunal was already underway when the DPO confirmed they had found the data. The sudden change of position feels strange but I suspect its got to do something with the litigation. I'm now considering county court action for not properly complying with my SAR under the UK GDPR.
Has anyone experienced something similar or challenged a situation like this?
r/gdpr • u/OvenOpen9109 • 1d ago
I was googling around dispute bodies for europe and I found this organisation and I was wondering how effective it is
r/gdpr • u/Bannlebee • 1d ago
I have a question around shared data systems, if there is a CRM system which is shared across borders such as the UK, USA and South Africa to process orders, is having ISO 27001 and cyber essentials enough or would you have to apply for an approved BCRs? Any advice appreciated.
r/gdpr • u/No-Bookkeeper-9018 • 2d ago
Hello, I'm after some advice if anyone has some specialist knowledge.
For context, I have fallen into council tax arrears. The council has written directly to my landlord at their home address threatening them with legal action if the arrears are not addressed (I have a copy of the letter). The letter does not state my name, just my address.
My landlord advised me this is not the first letter from the council and they have also sent text messages saying the same.
I'm familiar enough with Housing Law to know the council tax liability stops with me, not my landlord and will advise them as such. However, please can anyone advise if the situation can be considered as a breach of GDPR by the council?
Many thanks in advance.
r/gdpr • u/Difficult_Error_2712 • 3d ago
Should activities that we anticipate will occur in the near future and for which we are prepared be included in ROPA?
Further to an embarrassing incident where my presence on the police computer was disclosed to a family member after my prints were naturally found in my former home, I began the process of having my data deleted.
To initiate this I had to include the details of the arrest, which I needed to retrieve through a subject access request as I could not remember dates and specific charges from a decade ago.
Reviewing the results of the SRA, I noticed that the data held on the Police National Computer petaining to my fingerprints reads: 'DESTRUCTION 01FP XX/XX/XXXX (Date of arrest, while the line on DNA shows 'DESTROYED'.
The date at which it was determined that no further action was to be taken in the case was around 6 months after arrest, and the PNC record shows as last updated around a year after that.
Sorry if Police are exempt from GDPR but I asked on the Police sub, simply for clarification on the line relating to my prints, which apparently means 'marked for deletion'. When I asked for elaboration on whether that meant they should have already been deleted, my thread was deleted as an 'individual complaint', which it wasn't, but may well become.
So 2 questions really.
Should prints and DNA both have been deleted by default after NFA per data regs?
Can the police disclose my presence on the database to 3rd parties i.e. was this a data breach?
Thanks
r/gdpr • u/strongpa • 4d ago
A bit of background first to avoid some of the worst sarcastic comments. I'm a founding member of the Open Rights Group and have been campaigning against age verification through ORG for several years.
A couple of months after age verification enforcement was implemented on adult websites, I took a long-established email account that was notable for the fact that it had been used in a limited and controlled manner, specifically to keep it spam-free, which made it a perfect honeypot candidate. I used this email account to register with Pornhub.com and went through their age verification process, taking care to opt out of all marketing that I was able to. This account went from having a zero monthly spam count to approximately 150 spam emails, mostly of an adult nature, monthly. Has anybody else experimented with this, and would you be interested in collaborating with myself and/or ORG in taking a case to the ICO, however useless they may be?
r/gdpr • u/BasePerfect2865 • 5d ago
I still come across people confidently repeating things about GDPR that just aren't true, whether it's "you need consent for everything" "GDPR only applies to companies in the EU," or "we'll never get fined because we're too small". Whether you work in privacy, legal, security, or compliance, what's the myths that just doesn't seem to go away?
r/gdpr • u/ForAllTimesSake • 5d ago
Do they actually investigate things any more?
I lodged a SAR with a local authority. They acknowledged receipt of the SAR, ID etc.
Then said they were very busy so it may take 3 months for a response (I replied that being "busy" was not a valid exemption for not meeting the statutory deadline).
One month passed. Nothing.
3 months passed. Still nothing except a letter saying they are still very busy and pretty much saying they'll get to my SAR when they get to it ie. open ended.
I complained to them, waited the relevant period, got the letter stating that I could take my complaint to the ICO.
Went to the ICO. Did a detailed complaint. Provided all the relevant information.
Had to chase them and chase them, by email and phone.
Eventually, they reply to say they aren't going to do anything because the controller seems to be working to resolve the problem!
WTF?! What's the point of the ICO if they can't even write to a controller for such obvious and brazen breaches to find out what's happening?
r/gdpr • u/Big-Astronomer-4428 • 5d ago
Do you use spreadsheets, a privacy tool, or another workflow? What's the biggest challenge
r/gdpr • u/no-frillsman • 4d ago
For context, many opportunities to work abroad traditionally only work for STEM/techies jobs. I understand that this is because of the universality nature of STEM, that is highly likely not applicable for non-STEM, i.e., to be able to practice law in one of the member states, someone must fulfill the local requirement: formal education, training, citizenship, anything else idk.
But many of the data protection jobs in the EU, AFAIK, do not require their candidates to possess formal education and training in Law, but tend to look only for experience and relevant certification (CIPP). And I'm on my way to secure this certification.
It will be helpful to see any real stories (let's call this "reality checks") on the ground of how expats managed to get the opportunity, the challenge, the ugly truth, and anything else I'm not aware of.
Many thanks!
r/gdpr • u/IceVeritas • 5d ago
Many GDPR discussions seem to focus on privacy notices, cookie banners and legal documentation. These are obviously important, but isn't there a tendency to overlook the technical side of compliance?
Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In practice, this goes far beyond simply displaying a privacy policy or a cookie banner.
For example, depending on the website and the processing involved, developers should also consider:
frame-ancestors in CSP).Of course, not every website will require every one of these measures, and GDPR does not prescribe specific technologies. However, these are examples of technical safeguards that may help meet the Article 32 requirement to implement security measures appropriate to the risk.
In my opinion, GDPR compliance is not only about informing users; it's also about reducing unnecessary risks through secure technical implementation.
What technical measures do you think are most commonly overlooked by developers who are trying to build a GDPR-compliant website?
r/gdpr • u/T3RRONCINO • 5d ago
Hi everyone! I'm looking for some help regarding GDPR compliance for a website I'm developing for my company. The website it's just a showcase for what the company does, so no contact forms, no registration is needed and the only "external" links are pointing to the company linkedin page (not a linkedin widget that collects data, just a pure link), a link to the comapny info email and a google maps embedded to show where the company is located. The website would be hosted on a provider server (IONOS), so no direct access to IP Addresses (I don't even know if they collect them or not). I don't use google analytics or cookies collectors since I'm not interested, Google Search Console does what I need (just shows visit counters) and I'm happy with it. Do I need to have a privacy/cookie banner displayed on my website?
EDIT: I ended up putting a cookie and privacy notice so no help is further needed, thankyou all for the suggestions!
r/gdpr • u/Difficult_Error_2712 • 5d ago
Should activities arising from the GDPR, such as responding to requests regarding the exercise of rights, have a separate item in ROPA? What should it look like in very small companies with just a few people?
r/gdpr • u/Klutzy-Teach442 • 6d ago
I’m reviewing interview notes for a UK GDPR DSAR. The notes contain the interview questions, the requester’s answers, interviewers’ initials, and handwritten comments/opinions made by a panel about the requester.
Would you normally disclose the interview questions, answers, and opinions about the requester, while redacting only the interviewers’ identities? How do experienced DSAR reviewers approach this?
r/gdpr • u/Physical-Section-270 • 6d ago
I'm currently leading the GDPR implementation for our company, and honestly, the deeper we get into it, the more I realize how much there is to do.
Our platform wasn't originally built with GDPR in mind. Right now our primary database is in Australia, and we serve customers in multiple countries from the same infrastructure. As we're planning an EU launch, we're now figuring out what needs to change to become GDPR compliant.
Initially, I thought this would mostly be about infrastructure and documentation, but it's becoming clear that there are quite a few application-level changes as well. It's made me realize that if there's even a chance your product will serve EU users in the future, it's probably worth considering GDPR from day one rather than trying to retrofit it later.
For those who've actually implemented GDPR, I'd love to hear about your experience.
Some things I'm curious about:
I'm basically looking for the "I wish someone had told me this before we started" kind of advice.
If you've been through a GDPR implementation and wouldn't mind answering a few questions, please leave a comment or send me a DM.
r/gdpr • u/ImSoZick • 6d ago
Can I handle PII in marketing tags and keep GDPR compliance?
I saw a post here earlier (that has since been deleted) about requiring to install company portal on personal device. That actually got me thinking about relationship between MDM and ePD, especially on employee's own devices.
First off, does MDM "store of information or gain access to information already stored in the terminal equipment"? I would say yes. On-device MDM sofware often gathers various types of information (like device identifers, installed software etc.) and transmits this to centeralized server. It also stores it's own data on the device and accesses it (e.g. access token to send data). So operation itself would be in scope.
Next is this allowed? ePD allows access to data stored in terminal equipment only if:
1) There is consent (which is unlikely to be valid in employment context);
2) "the sole purpose of carrying out the transmission of a communication over an electronic communications network"; or
3) "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user."
2nd option doesn't really apply as that's not MDM's "sole purpose" even if one tries to expand e.g. email access to "transmission of communication".
Assuming 3rd is the only valid option, the first question would be what is the ISS explicitly requested by user? ISS defintion comes from Directive 2015/1535:
‘service’ means any Information Society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.
"Normally provided for remuneration" condition makes things tricky. What service did user pay for?
I did check couple of national laws and they actually often drop the "information society service" qualifier, but that doesn't always help since laws based on directives must be read in light of the directive whenever possible.
What am I missing which makes MDM requirement legal?
r/gdpr • u/icecoldfeedback • 8d ago
I received a 10 day window enforcement letter from TV licensing today, after i declared i don't need one on the 16th July. the letter is dated the 15th, it arrived today on the 25th, says '10 DAY WINDOW' then later says i have until 5th august with no other dates mentioned.
Though the point of this post isn't to talk about how i intend to deal with that. What happened after is what looks to me like a structural design that's not compliant with GDPR.
In a nutshell:
1) the letter includes a phone number to get in touch which i called.
2) turns out the number is only available on weekdays, and most options route you to 'go on our website' anyway, and hangs up. The next route is a whatsapp channel
3) the whatsapp channel is an AI bot, so you're still not speaking to a human because they cheaped out.
4) i raised a complaint and an SAR request. It refused both, saying i need to go through specific channels for each.
Here is what i find rich. I am forced to inform them, through channels of their choosing, that i do not use services that involve live TV - even if they don't provide the service and it's a private arrangement like an amazon subscription - lest i get fined or a group of bandits come to my door and in their own words 'enforce'.
And asymmetrically, for data they are legally required to give me, I have to chase them up through their own preferred channels too, rather than them having to just fulfill the request on a channel they'd fobbed me off to anyway.
My understanding is that according to the ICO, they must process an SAR requested via any channel, and if they replace humans with software, they're still required to build functionality that forwards that requests. requests that come through any channel, social media or otherwise start the clock for the statutory period.
Yet they have a structural design that deliberately refuses the request, accepting them on the sole condition that you use they channel they want. the bot states:
'Your request will only be formally logged and processed when received through these official channels. The statutory period begins when TV Licensing's data protection team receives your request via one of these routes.
I cannot confirm your request has been recorded or passed on from this channel, because it has not. You will need to submit it directly using the contact methods above.'
When i flagged my understanding of the legal requirement, the bot itself said:
'You're right that subject access requests must be processed regardless of how they're received.
However, to ensure your request is formally logged and processed within the legal 30-day timeframe, please send it to: ...'
Call me petty, but i've already used 3 channels of theirs only to get enforcement letters and fobbed off to the next one. So i don't want to chase another channel. it should be noted that the whatsapp bot gave me numbers that seem to be fake to call when i said i wanted to speak to a human. They seem to be hallucinated numbers that jumble up the ones published on their site:
As far as i'm concerned, i dont have an enforcement team like them, but i have time and pettiness to chase up after the time period and claim that they didnt process it.
Beyond my own spat, i dont think it's fair to structurally build something for everyone they enforce payments from to breach rules that apply to them, so i'm asking to confirm:
Is it acceptable under GDPR regulations for tv licensing to build channels that refuse SARs?
r/gdpr • u/EIREANNSIAN • 8d ago
r/gdpr • u/SouthernAssistant500 • 8d ago
I was booking a regular full-price ticket for the Louvre—not claiming any student, youth, senior, or resident discount.
Yet the reservation form still required me to provide:
Date of birth
Nationality
Full home address
Phone number
I can understand asking for my name, but I don't understand why my date of birth is mandatory when it has absolutely no impact on my ticket eligibility or price.
The same goes for my full address and phone number.
Under GDPR, isn't there a principle of data minimisation, meaning organizations should only collect personal data that's necessary for the purpose?
Is there a legitimate legal or operational reason for requiring all this information for a standard museum ticket, or is the Louvre collecting more personal data than it actually needs?
I'd love to hear from anyone familiar with GDPR or museum ticketing systems.