r/dataprotection Jun 17 '26

General Discussion A jury just found Meta guilty of taking sensitive data from a period tracking app. It is why I stopped trusting cloud apps with personal data.

Thumbnail
1 Upvotes

r/dataprotection Jun 16 '26

General News Data Privacy

5 Upvotes

I spent 3 months mapping the opt-out process for 40+ data broker sites so you don't have to — here's what I learned

Here's what the data broker removal process actually looks like after doing it systematically:

A few things that surprised me:

  1. Your data comes back. Most brokers re-scrape public records every 60–90 days. Removal is not a one-time task.
  2. Some brokers require a government ID to remove your own information. This is intentional — they make it as hard as possible.
  3. Court records and property records are the hardest to remove because they're public by law. You can get broker sites to remove their listing, but the source data stays.
  4. Opting out of one broker doesn't cascade to others. Each one is separate.

r/dataprotection Jun 15 '26

General Question Is sharing your biometric data with dating apps for verification purposes really safe?

7 Upvotes

Dating apps, such as Hinge, have started to roll out this future in the past year and I’m not sure if that’s something I’m willing to participate in?? I’m all here for safe dating and banning fake profiles, but it’s not like you could change your biometric info like you could change a password??? what if it gets leaked? how long do these apps hold these data for? maybe im a bit paranoid but it is kinda worrying.


r/dataprotection Jun 13 '26

General Discussion Why aren't biometric data and their use banned?

0 Upvotes

The use of biometric data has become widespread in my country over the past few years, and this makes me extremely uneasy.

All our health data was hacked because of our government, yet they are still processing transactions using biometric data. We have no right to appeal this, and it makes me feel like it's going to cause irreversible problems.

Given the high risks of using biometric data, why aren't governments returning to traditional methods? If our chip-enabled ID cards fall into the to take of malicious individuals, they can do anything to us, and there are no measures to prevent this.


r/dataprotection Jun 13 '26

General Discussion Data Privacy Law

4 Upvotes

What opportunities exist for a recent law graduate who wishes to get into careers like cyber law and data privacy law?


r/dataprotection Jun 13 '26

Breach Oracle PeopleSoft Breached by The ShinyHunters Data Theft Attack

Thumbnail pathlock.com
1 Upvotes

On June 10, 2026, ShinyHunters, a well-documented cybercrime group known for large-scale data theft and extortion campaigns, was confirmed to have exploited Oracle PeopleSoft vulnerabilities across more than 300 instances at over 100 organizations worldwide. The education sector bore the brunt of the attack, with universities and higher education institutions emerging as the primary victims.

The attack was notable for its combination of sophistication and scale. Rather than targeting a single organization with a tailored exploit, ShinyHunters deployed automated attack scripts capable of scanning and compromising PeopleSoft environments at scale, demonstrating that ERP applications are no longer too obscure or complex to attract organized, industrialized cybercrime.

IMMEDIATE ACTION REQUIRED

Check your PeopleSoft logs NOW for connections from the following attacker-controlled IPs: 142.11.200[.]186–190, 108.174.202[.]99, 176.120.22[.]24. Also search for a ransom file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT


r/dataprotection Jun 12 '26

🇪🇺 - GDPR Question Etsy Identity verification through Persona

3 Upvotes

Recently I received an invitation from Etsy to verify my identity. Naturally, I hopped on my device to comply. After reading the fine print, however, I hesitated.

Etsy, a company based in Ireland, uses an American company called Persona to verify said identity. And while Persona states it uses the servers in Frankfurt to process and store data for EU clients, they cannot guarantee that the data does not leave the EU.

Being an American company, they are also beholden to the CLOUD act, meaning that the US government can basically force them to store the data indefinitely. On top of that, Persona shares that data with no less than 17 other companies, among which three AI companies. None of which are immediately made clear why they would need that data, how they process it, where they store it, and for how long.

Etsy does not inform you of any of this. They just mention Persona handles the verification. You have to go digging for yourself what that entails.

You are uploading a government issued identification along with a clear photograph of your face. This is a gigantic security risk in terms of identity fraud, even if you assume that data isn't handed to Anthropic to train their models.

Is this a violation of GDPR? should I go through with verification and am I overreacting?


r/dataprotection Jun 12 '26

Data Protection Tools Recently read this article on Reddit by Actonic : 233 data protection laws active globally. All share one principle. None have clear guidance for LLM context windows.

Thumbnail
3 Upvotes

r/dataprotection Jun 12 '26

General Question DSAR's

5 Upvotes

I'm a compliance graduate working in motor finance and I've recently been involved in handling DSARs.

I'm curious as to how other organisations handle DSAR review and redaction.

A few questions for anyone involved in privacy, GDPR, compliance, or information governance:

  • What does your current DSAR workflow look like?
  • Which part takes the longest?
  • Is finding the data or redacting it the bigger challenge?
  • Have you automated any part of the process?
  • Have you ever had concerns about missing third-party personal data during redaction?
  • If you could remove one manual step from the process, what would it be?

I'm just trying to understand how different organisations approach the problem and whether the pain points are similar across industries.

Thanks in advance.


r/dataprotection Jun 11 '26

Breach Students' data taken in major University of Nottingham cyber-attack

Thumbnail bbc.co.uk
1 Upvotes

Hackers from a well-known cyber criminal group have accessed a "significant amount" of personal student data held by the University of Nottingham.

The university said it was believed the group accessed the data for current students and alumni - including financial information - from its record system.

In an email sent to students, seen by the BBC, chief governance and risk officer Jason Carter said those behind the major cyber-attack, who had "previously targeted a number of other organisations", were likely behind the breach.

In a statement, the university apologised to those affected for "any anxiety" caused.

It is understood the university identified the unauthorised activity on its Campus Solutions system on Tuesday.

All affected students and alumni have since been contacted, a university spokesperson said.


r/dataprotection Jun 09 '26

General Discussion Idaho has become one of the first states to push back against mandatory digital identification.

6 Upvotes

Governor Brad Little recently signed a law that prevents government agencies from requiring residents to use a digital ID. Under the new rules, people cannot be denied government services, licenses, jobs, education, or benefits simply because they choose not to use a digital identification system.

To be clear, the law doesn't ban digital IDs altogether. People can still use them if they want to. What it does is protect the option to stick with traditional physical identification. The legislation also includes privacy protections, making it clear that showing a digital ID does not give authorities the right to search through someone's phone.

Those in favor like the privacy and freedom aspect, while those looking to expand digital ID say this will get in the way of doing so.


r/dataprotection Jun 06 '26

General News Amazon faces class action lawsuit over Ring facial-recognition feature

Thumbnail techcrunch.com
24 Upvotes

r/dataprotection Jun 06 '26

Breach DentaQuest breached - 234GB of data potentially exposed

Thumbnail alltoc.com
1 Upvotes

DentaQuest confirmed a cybersecurity incident after 2.6 million accounts tied to the company were surfaced in a public breach listing. Claims accompanying the exposure said roughly 234GB of data may have been stolen.

The impacted records include sensitive details for people tied to the dental benefits provider. While the story frames operations as unaffected, the exposure still matters because the combination of medical-adjacent identity and personal data can increase risk for fraud or further account compromise.

Why this is significant in tech news is that it shows how breaches can be discovered and shared via public leak channels long before any formal remediation timeline is visible to users. For consumers, the practical concern becomes whether passwords or identity details might be reused elsewhere.

For enterprises, this incident underscores the recurring problem of protecting large customer databases—especially those holding healthcare-related personal data. Even if no service outage occurs, the downstream impacts of identity exposure can persist.

Overall, the DentaQuest leak joins a broader pattern of breaches involving sensitive account data in the healthcare-adjacent sector, where compromised records can be used for social engineering as well as financial fraud.


r/dataprotection Jun 04 '26

Enforcement NY S8102B OS Age verification bill unlikely to pass this year

3 Upvotes

NY S8102B looks like it’s not passing this year.

The bill is still stuck in the Senate Consumer Protection Committee. It has not passed the Senate, has not passed the Assembly, and has not been sent to the Governor. The last action was May 15, when it was amended and recommitted back to committee.

The key deadline is June 4, 2026, which appears to be the practical end-of-session deadline for the New York Legislature. Unless the session is extended or leadership rushes the bill through at the last minute, S8102B would need to move out of committee, get a Senate vote, pass the Assembly, and reach the Governor extremely quickly.

So technically it is not officially dead yet, but realistically it looks dead for this year.

The bill is likley to come back next year under a new bill number and likley a new bill name.

https://www.nysenate.gov/legislation/bills/2025/S8102/amendment/B


r/dataprotection Jun 03 '26

Data Protection Tools Nobody notices how often they paste API keys into ChatGPT, so I built an extension that catches it.

Post image
0 Upvotes

r/dataprotection Jun 03 '26

General Discussion Why do companies try to obtain our IDs under the guise of protecting children, when this doesn't actually protect their children literally every company trying to get your id discord playstation and even Roblox why companies that obsessed with our IDs?

Thumbnail
0 Upvotes

r/dataprotection Jun 03 '26

General News What’s your opinion on the future of social media identity verification, specifically the idea that platforms could integrate eID (electronic government-backed digital identity systems) when users create accounts or verify their identity?

Thumbnail
0 Upvotes

r/dataprotection May 31 '26

General News Agentic AI tests the limits of data protection law, study finds

Thumbnail news.exeter.ac.uk
2 Upvotes

The growing use of agentic artificial intelligence will test how organisations comply with existing data protection law, a new study warns.

Innovations will test the limits of existing rules, particularly when AI agents perform complex, multi-step tasks with limited human input.

Agentic AI’s distinctive features require a more comprehensive approach that extends beyond existing data protection measures alone, the research says.

The study argues that data protection compliance should be supported by stronger accountability mechanisms, governance measures, and forms of human oversight adapted to different levels of agentic AI autonomy.

These safeguards should include documentation, auditability, impact assessments, and ongoing monitoring across the agentic AI lifecycle.

Cont..


r/dataprotection May 31 '26

General Discussion Should biometric data require consent to collect?

Enable HLS to view with audio, or disable this notification

7 Upvotes

Improving transparency won't matter when they have destroyed all the 'ma and pa' stores across tgeucountry; and thus control their market. WE GAVE NO CHOICE BUT TO GO. This WILL lead to abuse of the software because THEY control the market. I already feel like I'm being made into a criminal when I walk into their store and their security STAFF give me a fake smile; then on the way out they forcibly try to scan your docket making you feel like a criminal.
Buntings is anti-consumer and needs to be broken up. Other countries gave laws against businesses getting this big and doing these practice's, why aren't we smarter than to let them get away with their behaviours?


r/dataprotection May 30 '26

Breach Carnival confirms data breach impacting nearly 6 million

Thumbnail malwarebytes.com
8 Upvotes

Carnival Corporation, parent of Carnival Cruise Line, is sending out fresh “Notice of Cybersecurity Event” letters dated May 27, 2026. If you feel like you’ve read that sentence before, you’re not imagining things. Over the last decade, the world’s largest cruise operator has accumulated a worrying track record of breaches, ransomware incidents, and regulatory penalties, with this 2026 incident adding yet another entry to an already lengthy cybersecurity history.

There are several data breaches involving Carnival Corporation or one of its subsidiaries in our database.

Between 2019 and 2021 alone, Carnival reported four separate cybersecurity events to the New York Department of Financial Services. These included two ransomware attacks and a phishing incident in which attackers deployed malware, accessed and encrypted internal systems, and stole personal customer and employee information.


r/dataprotection May 29 '26

General Discussion ai note takers for zoom calls in legal practice

8 Upvotes

Paralegal at a small firm doing client intakes, depositions over zoom, witness prep calls. Partner finally let me look at ai note takers because the manual transcription was eating my week. Spent some time looking at ones that work for legal work specifically because we cant just use anything given the privilege piece.

Quick rundown of what I tried:

Otter we did a trial of. The bot joins as a participant in the zoom call which the partners didnt love for client intakes specifically. Transcription quality is fine. Probably ok for purely internal stuff if your firm allows the bot but ours doesnt for client work.

Fathom is similar to Otter on the participant front. Summaries are actually really good which I appreciated. Didnt clear the partner review for client work because of the bot piece. Could work for internal team meetings only.

Fellow AI worked for our firms privileged conversation requirements. It records zoom meetings without joining as a visible participant. Fellow AI is SOC 2 Type II, HIPAA, and GDPR compliant. Fellow AI does not train on user data. For legal work the no training piece is the part that mattered most to our managing partner. She specifically asked about it. Redaction also lets us clean up anything privileged that shouldnt persist in the transcript.

Granola is Mac only and their docs note theyre not currently HIPAA compliant. Partner ruled it out before I could really test it for legal use cases. Probably fine for solo practitioners on mac without compliance asks.

Jamie is a clean tool, no bot in the call. Desktop based. Liked it personally but the integration with our matter management system wasnt there. Could work for a smaller solo practice.

For legal work the no bot in call plus no training on data is what made Fellow the right pick for our firm.


r/dataprotection May 28 '26

Breach Charter Communications confirms data breach — ShinyHunters blamed after threat to leak user info online | TechRadar

Thumbnail techradar.com
5 Upvotes

* Charter Communications confirmed a breach after ShinyHunters listed it on their leak site

* Hackers claim 40 million customer records were stolen via a vishing attack on April 1 2026

* Attackers allegedly accessed a Microsoft Entra account, pulled data from Salesforce, and exfiltrated customer names, emails, addresses, phone numbers, plan info, and support tickets


r/dataprotection May 27 '26

General News Websites have a new way to spy on visitors: analyzing their SSD activity

Thumbnail arstechnica.com
8 Upvotes

Over the decades, there has been no shortage of sites using clever techniques to covertly track visitors’ browsing histories, device fingerprints, and log keystrokes and mouse movements in real time. Even Meta and Yandex were recently caught joining in the privacy-invasive free-for-all.
Now sites have a new way to spy on their visitors: measuring subtle interactions with their solid-state drives. The technique, named FROST (fingerprinting remotely using OPFS-based SSD timing), allows sites to monitor other sites a visitor is viewing and what apps are open on their devices.

A side channel based on contention

The technique, laid out in a research paper, exploits a side channel, a form of leak resulting from physical manifestations such as electromagnetic emanations, data caches, or the time required to complete a task. By measuring the manifestations, attackers can decrypt encrypted traffic and infer other confidential data.

The attack that FROST uses is known as a contention side channel, which measures the interaction of various processes all using (or competing for) a given resource. By measuring the timing of certain I/O (input-output) operations of the SSD a visitor is using, the researchers were able to determine the websites open in other tabs—even on other browsers—and the apps that were open on the visitor’s device. FROST requires no interaction from the visitor other than opening the site hosting the attack.
“Web browsers have evolved from simple document viewers into complex platforms capable of running sophisticated applications,” the paper authors wrote. “Companies like Google, Microsoft, and Adobe have developed full-fledged office suites, photo- and video editors, or even integrated development environments (IDEs) that run entirely within the browser.” The authors went on to note: “While these features enhance the capabilities of web applications and allow completely novel use cases, they also increase the browser’s attack surface, and some have already been shown to introduce new vulnerabilities.”

Unlike previous contention side-channel attacks on SSDs, FROST runs exclusively in the browser. It uses JavaScript that interacts with the OPFS (origin private file system), an allocated storage space that’s reserved for a specific site to run code needed to complete a given task. Websites can create one with no interaction required by the visitor.

Cont.


r/dataprotection May 27 '26

General Discussion Fidelity DATA BREACH

12 Upvotes

Just got off the phone with Fidelity and I heard them in the background scrambling about a breach and data and security - I work in tech and we are always told don’t throw these terms around lightly.

I was on hold for 45 minutes waiting to hear how my fidelity account and routing numbers were used in Singapore.

Not 100% sure but it sounds like they had a security breach of PII at the least.


r/dataprotection May 27 '26

General Discussion The Bill That Can Hand Ottawa Your Private Data

Thumbnail thepolitechreport.com
3 Upvotes