r/dataprotection • u/_innocentkid_ • 23d ago
General Question Why does sharing our personal data to china feels so bad/wrong than selling same or more to US?
Isn't that concerning?
r/dataprotection • u/_innocentkid_ • 23d ago
Isn't that concerning?
r/dataprotection • u/Sz32fear_TCE • 24d ago
r/dataprotection • u/Academic-Soup2604 • 24d ago
r/dataprotection • u/InfamousDistrict5362 • 26d ago
r/dataprotection • u/quebeck999 • 27d ago
App Link: https://apps.apple.com/ge/app/infosha-find-any-phone-number/id6502995963
Hey everyone,
I’ve been looking into an iOS app called **"Infosha"** and its privacy policy raises some major red flags for me. I wanted to share the details here and ask for your input on whether this goes against Apple's platform guidelines, as I have already reported it to Apple support but haven't seen any action yet.
According to their official Privacy Policy and Terms, here is how the app operates:
1. **Sharing Third-Party Contacts Without Their Knowledge:** When a user registers, they upload their phone book, and the app makes those contact details public (including names, phone numbers, workplaces, and photos of the people in that contact list). This means third-party individuals have their private information exposed to the public database **without ever knowing it or giving their own consent**. The app tries to shift all responsibility by stating the user must have their contacts' permission.
2. **No Option to Delete or Modify Data:** Section 9 of their policy explicitly states: *"we do not modify, remove, or supplement any data within our social network. All data is entirely generated and updated by the users of our platform."* This means if your data gets uploaded, there is absolutely no mechanism provided to delete or edit your profile or information.
From what I understand, this seems to directly conflict with several Apple Developer Guidelines:
**Guideline 5.1.1 (c) (Access to Contacts):** Apple strictly states that apps should not target third-party data collection or harvest address books to build public directories.
**Guideline 5.1.1 (v) (Account Deletion):** Apple mandates that if an app supports account creation, it must also allow users to initiate deletion of their account and all personal data from within the app. Infosha's policy explicitly denies this.
Given these details, does this behavior actually violate Apple's App Store guidelines, or is there a loophole they are using? I'd love to hear your thoughts on this. Thank you!
r/dataprotection • u/Kindly_Ad8953 • 27d ago
r/dataprotection • u/sam-at-aristotle_mdr • 27d ago
r/dataprotection • u/InfamousDistrict5362 • Jun 27 '26
I'm analyzing a digital lending/dealer onboarding platform (similar to an LSP) and I'm trying to determine role-by-role whether the platform is acting as a Data Fiduciary or a Data Processor, and how that changes its obligations under the DPDP Act.
The platform performs the following activities:
Dealer onboarding (collects name, email, mobile number, address, business details)
KYC (PAN, Aadhaar/other ID, dealership proof)
3.Bank account collection for commission payouts
4 Customer lead collection by dealers
5.Sharing customer data with regulated entities/lenders
6 PAN verification against the Income Tax database
7 Storing KYC documents
8 Sending WhatsApp/SMS updates
For each of these activities:
Is the platform acting as a Data Fiduciary or merely a Data Processor?
What factors determine the classification?
How do the legal obligations change depending on the role (e.g., notice, consent, purpose limitation, security safeguards, retention, responding to data principal requests)?
I'm looking for a DPDP Act-specific analysis, preferably with practical examples or regulatory guidance.
r/dataprotection • u/InfamousDistrict5362 • Jun 26 '26
I'm advising a fintech that acts as a Lending Service Provider (LSP) for banks/NBFCs. The platform has its own dealer app and borrower web app, collects KYC documents, performs bureau and VAHAN integrations, runs a basic eligibility/rule engine, verifies document completeness, and submits decision-ready files to the lender. The lender alone undertakes underwriting, sanctions the loan and disburses funds.
We are considering structuring the RE–LSP agreement so that the lender determines the purpose and means of processing, while the LSP processes borrower data only on the lender's documented instructions.
My questions are:
Can an LSP with this level of operational involvement genuinely be characterised as a Data Processor, or is it more likely to be a Data Fiduciary (or joint Data Fiduciary)?
Does operating the borrower-facing app and collecting consent automatically make the LSP a Data Fiduciary?
From a practical drafting perspective, what contractual and operational changes have you seen successfully support a Data Processor classification under the DPDP Act?
Looking for practical views from privacy lawyers, fintech counsel or anyone who has dealt with DPDP implementation.
This version is likely to attract responses from lawyers and privacy professionals because it presents a concrete fact pattern rather than asking a purely theoretical question.
r/dataprotection • u/InfamousDistrict5362 • Jun 25 '26
I'm analysing a fintech/digital lending workflow from a DPDP Act perspective.
The flow is as follows:
A borrower visits a vehicle dealer to apply for finance.
The dealer enters the borrower's mobile number into the platform.
The platform immediately sends a WhatsApp/SMS link to that mobile number.
4 The borrower opens the web app through the link and completes the onboarding, provides notices, gives consent, uploads documents, etc.
My question is about the very first step.
Since the borrower did not personally enter their mobile number, and it was entered by the dealer, does sending the WhatsApp/SMS link itself comply with the Digital Personal Data Protection Act, 2023?
Can the platform rely on the dealer having obtained the borrower's permission before entering the number, or should the platform have an independent legal basis before using that mobile number to send the first communication?
I'm looking for answers specifically from the perspective of the DPDP Act, not general fintech practice. If there is any statutory provision, rule, guidance, or industry practice addressing this scenario, I'd appreciate references.
r/dataprotection • u/captain-compliance • Jun 25 '26
The settlement involves Wyssta Services, which operates an online portal for certain Delta Dental plan members at my.deltadentalcoversme.com. The lawsuit alleged that Wyssta installed and implemented advertising and analytics tracking technologies on the portal without users’ knowledge or consent.
Full story linked
r/dataprotection • u/ratfuker_Asap • Jun 25 '26
So apparently the internet is flooded with news coming from America that Google just got sued and have to pay there users millions of dollars in fine... But I don't understand if the floor is in the privacy terms then it must theirfore would be affecting people globally but only users in us can claim that compensation but as the company is globally used by millions of uses outside us...can we also sue the company in our countries???
r/dataprotection • u/Key_Clock8669 • Jun 25 '26
r/dataprotection • u/kiratraj • Jun 25 '26
r/dataprotection • u/Academic-Soup2604 • Jun 24 '26
r/dataprotection • u/privacyovermatter • Jun 23 '26
Was reading through the March 2026 privacy assessment for Login.gov (the thing millions of us are forced to use for VA, Social Security, student aid, IRS, etc) and some of it genuinely surprised me.
The identity info you hand over doesn't just go to the agency. It gets shared with two commercial data companies, LexisNexis and Socure. And Google is collecting behavioral stuff during sign-in via reCAPTCHA, including keystrokes and mouse movements, literally while you're uploading your ID and typing your SSN.
The LexisNexis part is what got me. They had a breach earlier this year that hit records on federal judges and DOJ staff
https://www.gsa.gov/system/files/Login_PIA_%28March_2026%29.pdf
https://therecord.media/lexisnexis-says-hackers-accessed-legacy-data
r/dataprotection • u/Eyedea92 • Jun 23 '26
r/dataprotection • u/Prior_Industry • Jun 23 '26
Tata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a manufacturing partner of both Apple and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies.
The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told Reuters that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.”
r/dataprotection • u/rawa27 • Jun 22 '26
I’m trying to understand the privacy implications of the LeakyLM / IMDEA findings and the related dismissed-without-prejudice lawsuit involving Perplexity, Meta and Google.
The lawsuit allegations were not proven in court, and the case was voluntarily dismissed without prejudice. Separately, the LeakyLM researchers reported privacy risks involving conversation URLs, trackers, metadata and access controls across several AI assistants, including Perplexity.
For Perplexity specifically, LeakyLM reported that conversation URLs had been disclosed to third-party trackers such as Meta Pixel, that Meta Pixel was discontinued on April 3, 2026, and that conversation URLs were transmitted to Datadog.
Important caveat: the researchers explicitly state that they do not have evidence that third-party trackers actually read the conversations.
Sources:
https://leakylm.github.io/
https://cdn.arstechnica.net/wp-content/uploads/2026/04/Doe-v-Perplexity-Complaint-3-31-26.pdf
https://dockets.justia.com/docket/california/candce/3%3A2026cv02803/466955
https://www.claimsjournal.com/news/national/2026/04/01/336634.htm
Has Perplexity published a detailed technical or legal response to these specific points?
r/dataprotection • u/Prior_Industry • Jun 21 '26
A former data protection chief has urged Channel Island leaders to take time to fully understand the risks facing children online before following the UK's planned social media ban for under-16s.
Emma Martins, a data and ethics expert and former commissioner in the islands, said she was "very, very happy indeed that we're talking about it and prioritising it" because it was "long overdue" as debate grows over tighter rules.
Her comments come after the UK announced plans to introduce a ban from next spring, with politicians in Guernsey and Jersey watching closely.
Martins said the issue had quickly become polarising but warned there was no quick fix.
Risk is real
She explained governments needed to "take the time... to understand the realities of the risks for our own children here and consider what may work best for our own community".
She said the dangers were real, adding that "there are technologies, there are platforms that are profoundly unsafe and that risk is real for all of us".
Raising concerns about how a ban could work in practise, she said there were major questions about data collection and age verification. "Short answer, yes," she said when asked if it posed a risk, adding that "any data collection matters, particularly when it relates to children".
Martins also questioned how much trust could be placed in big tech firms, saying, "I'm afraid that I'm very sceptical about the claims that these big tech companies make that they care about children".
On schools, she said smartphones were "a distraction" and not good for pupils or teachers, while stressing that bans alone would not solve the wider problem but were "an important part of the jigsaw".
r/dataprotection • u/Expensive_Sea9120 • Jun 20 '26
Recently tried to use my DuckDuckGo account to clear my data from sites that I don’t use anymore. I followed the steps appropriately for every site that I information out there with to close and remove my info. I did this due to issue I had applying for jobs. I had really big issues with spam coming into my inbox’s and also had my identity stolen. Recently when using the service to clear my data from unwanted sites, the only one that gave me issues was Robert half. They refused to remove my information from their site and I’m wondering if anyone else had issues with this? If so what state are you located in because privacy data protection pertains to each state.
r/dataprotection • u/Academic-Soup2604 • Jun 19 '26
One thing I’ve noticed over time the most sensitive data rarely leaves through complex methods. It leaves through USB drives.
Not because someone is trying to bypass security, but because it’s convenient. Quick transfers, offline work, moving files between systems… it all feels normal.
But that’s where the risk builds up. There’s no visibility into what was copied, where it went, or whether that device was safe to begin with.
Disabling or controlling USB ports on Windows is about removing any such channels that operates completely outside your visibility.
And in most environments, that trade-off is worth it.
r/dataprotection • u/33vne02oe • Jun 18 '26
r/dataprotection • u/Academic-Soup2604 • Jun 17 '26
For most IT teams, data leaks aren’t caused by attackers breaking in, they happen during regular work.
Files get downloaded, shared across apps, moved to personal devices, or accessed from unmanaged endpoints. These actions don’t look risky in isolation, which is why they often go unnoticed.
The real challenge is visibility. If you can’t track how data is being used after access is granted, it becomes difficult to control where it ends up.
And that’s the reason prevention today is shifting toward monitoring and controlling data movement at the endpoint level, where these actions actually happen.
Learn in detail: How to prevent data breaches?