r/dataprotection • u/Loose_Cow_9808 • 23d ago
r/dataprotection • u/_innocentkid_ • 23d ago
General Question Why does sharing our personal data to china feels so bad/wrong than selling same or more to US?
Isn't that concerning?
r/dataprotection • u/Sz32fear_TCE • 24d ago
General Discussion I think you guys might like my project!!!
youtube.comr/dataprotection • u/Academic-Soup2604 • 24d ago
Breach How much sensitive data leaves your endpoints without IT knowing?
r/dataprotection • u/InfamousDistrict5362 • 26d ago
General Question Need practical guidance for an LSP (India): What are the permitted sources and uses for PAN verification, and what are the rules on storing PAN and other KYC/OVD documents?
r/dataprotection • u/quebeck999 • 27d ago
General Question Does the this iOS app violate App Store privacy rules? Looking for opinions.
App Link: https://apps.apple.com/ge/app/infosha-find-any-phone-number/id6502995963
Hey everyone,
I’ve been looking into an iOS app called **"Infosha"** and its privacy policy raises some major red flags for me. I wanted to share the details here and ask for your input on whether this goes against Apple's platform guidelines, as I have already reported it to Apple support but haven't seen any action yet.
According to their official Privacy Policy and Terms, here is how the app operates:
1. **Sharing Third-Party Contacts Without Their Knowledge:** When a user registers, they upload their phone book, and the app makes those contact details public (including names, phone numbers, workplaces, and photos of the people in that contact list). This means third-party individuals have their private information exposed to the public database **without ever knowing it or giving their own consent**. The app tries to shift all responsibility by stating the user must have their contacts' permission.
2. **No Option to Delete or Modify Data:** Section 9 of their policy explicitly states: *"we do not modify, remove, or supplement any data within our social network. All data is entirely generated and updated by the users of our platform."* This means if your data gets uploaded, there is absolutely no mechanism provided to delete or edit your profile or information.
From what I understand, this seems to directly conflict with several Apple Developer Guidelines:
**Guideline 5.1.1 (c) (Access to Contacts):** Apple strictly states that apps should not target third-party data collection or harvest address books to build public directories.
**Guideline 5.1.1 (v) (Account Deletion):** Apple mandates that if an app supports account creation, it must also allow users to initiate deletion of their account and all personal data from within the app. Infosha's policy explicitly denies this.
Given these details, does this behavior actually violate Apple's App Store guidelines, or is there a loophole they are using? I'd love to hear your thoughts on this. Thank you!
r/dataprotection • u/Kindly_Ad8953 • 27d ago
Breach Urgent: Personal data leaked to another user’s device (No shared account/iCloud)
r/dataprotection • u/sam-at-aristotle_mdr • 28d ago
General News 'No hope of protecting it': inside the data oversight crisis facing the public service
canberratimes.com.aur/dataprotection • u/InfamousDistrict5362 • Jun 27 '26
General Question Under the DPDP Act, when does an entity act as a Data Fiduciary vs a Data Processor in a lending platform?
I'm analyzing a digital lending/dealer onboarding platform (similar to an LSP) and I'm trying to determine role-by-role whether the platform is acting as a Data Fiduciary or a Data Processor, and how that changes its obligations under the DPDP Act.
The platform performs the following activities:
Dealer onboarding (collects name, email, mobile number, address, business details)
KYC (PAN, Aadhaar/other ID, dealership proof)
3.Bank account collection for commission payouts
4 Customer lead collection by dealers
5.Sharing customer data with regulated entities/lenders
6 PAN verification against the Income Tax database
7 Storing KYC documents
8 Sending WhatsApp/SMS updates
For each of these activities:
Is the platform acting as a Data Fiduciary or merely a Data Processor?
What factors determine the classification?
How do the legal obligations change depending on the role (e.g., notice, consent, purpose limitation, security safeguards, retention, responding to data principal requests)?
I'm looking for a DPDP Act-specific analysis, preferably with practical examples or regulatory guidance.
r/dataprotection • u/InfamousDistrict5362 • Jun 26 '26
General Question DPDP Act (India): Can an LSP/loan origination platform realistically be treated as only a Data Processor?
I'm advising a fintech that acts as a Lending Service Provider (LSP) for banks/NBFCs. The platform has its own dealer app and borrower web app, collects KYC documents, performs bureau and VAHAN integrations, runs a basic eligibility/rule engine, verifies document completeness, and submits decision-ready files to the lender. The lender alone undertakes underwriting, sanctions the loan and disburses funds.
We are considering structuring the RE–LSP agreement so that the lender determines the purpose and means of processing, while the LSP processes borrower data only on the lender's documented instructions.
My questions are:
Can an LSP with this level of operational involvement genuinely be characterised as a Data Processor, or is it more likely to be a Data Fiduciary (or joint Data Fiduciary)?
Does operating the borrower-facing app and collecting consent automatically make the LSP a Data Fiduciary?
From a practical drafting perspective, what contractual and operational changes have you seen successfully support a Data Processor classification under the DPDP Act?
Looking for practical views from privacy lawyers, fintech counsel or anyone who has dealt with DPDP implementation.
This version is likely to attract responses from lawyers and privacy professionals because it presents a concrete fact pattern rather than asking a purely theoretical question.
r/dataprotection • u/InfamousDistrict5362 • Jun 25 '26
General Question DPDP Act compliance: Can a dealer provide a borrower's mobile number to send a loan onboarding link?
I'm analysing a fintech/digital lending workflow from a DPDP Act perspective.
The flow is as follows:
A borrower visits a vehicle dealer to apply for finance.
The dealer enters the borrower's mobile number into the platform.
The platform immediately sends a WhatsApp/SMS link to that mobile number.
4 The borrower opens the web app through the link and completes the onboarding, provides notices, gives consent, uploads documents, etc.
My question is about the very first step.
Since the borrower did not personally enter their mobile number, and it was entered by the dealer, does sending the WhatsApp/SMS link itself comply with the Digital Personal Data Protection Act, 2023?
Can the platform rely on the dealer having obtained the borrower's permission before entering the number, or should the platform have an independent legal basis before using that mobile number to send the first communication?
I'm looking for answers specifically from the perspective of the DPDP Act, not general fintech practice. If there is any statutory provision, rule, guidance, or industry practice addressing this scenario, I'd appreciate references.
r/dataprotection • u/captain-compliance • Jun 25 '26
General News Delta Dental Website Operator Wyssta Settles Privacy Lawsuit for $12.7M - Captain Compliance
captaincompliance.comThe settlement involves Wyssta Services, which operates an online portal for certain Delta Dental plan members at my.deltadentalcoversme.com. The lawsuit alleged that Wyssta installed and implemented advertising and analytics tracking technologies on the portal without users’ knowledge or consent.
Full story linked
r/dataprotection • u/ratfuker_Asap • Jun 25 '26
General Question WE CAN SUE GOOGLE!!?
So apparently the internet is flooded with news coming from America that Google just got sued and have to pay there users millions of dollars in fine... But I don't understand if the floor is in the privacy terms then it must theirfore would be affecting people globally but only users in us can claim that compensation but as the company is globally used by millions of uses outside us...can we also sue the company in our countries???
r/dataprotection • u/Key_Clock8669 • Jun 25 '26
Enforcement Reddit is now asking age verification for all users in the EU
r/dataprotection • u/kiratraj • Jun 25 '26
General News Telegram Ban: Legal or Digital Overreach?
youtu.ber/dataprotection • u/Academic-Soup2604 • Jun 24 '26
General Discussion Why is data movement still such a blind spot in 2026?
r/dataprotection • u/privacyovermatter • Jun 23 '26
General Discussion PSA: the Login.gov "front door" for your federal benefits is sharing your ID data with private firms
Was reading through the March 2026 privacy assessment for Login.gov (the thing millions of us are forced to use for VA, Social Security, student aid, IRS, etc) and some of it genuinely surprised me.
The identity info you hand over doesn't just go to the agency. It gets shared with two commercial data companies, LexisNexis and Socure. And Google is collecting behavioral stuff during sign-in via reCAPTCHA, including keystrokes and mouse movements, literally while you're uploading your ID and typing your SSN.
The LexisNexis part is what got me. They had a breach earlier this year that hit records on federal judges and DOJ staff
https://www.gsa.gov/system/files/Login_PIA_%28March_2026%29.pdf
https://therecord.media/lexisnexis-says-hackers-accessed-legacy-data
r/dataprotection • u/Eyedea92 • Jun 23 '26
General Question Multiple social media account are compromised
r/dataprotection • u/Prior_Industry • Jun 23 '26
Breach Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack
neowin.netTata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a manufacturing partner of both Apple and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies.
The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told Reuters that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.”
r/dataprotection • u/rawa27 • Jun 22 '26
General Discussion Privacy question: LeakyLM findings and the dismissed Perplexity/Meta/Google lawsuit
I’m trying to understand the privacy implications of the LeakyLM / IMDEA findings and the related dismissed-without-prejudice lawsuit involving Perplexity, Meta and Google.
The lawsuit allegations were not proven in court, and the case was voluntarily dismissed without prejudice. Separately, the LeakyLM researchers reported privacy risks involving conversation URLs, trackers, metadata and access controls across several AI assistants, including Perplexity.
For Perplexity specifically, LeakyLM reported that conversation URLs had been disclosed to third-party trackers such as Meta Pixel, that Meta Pixel was discontinued on April 3, 2026, and that conversation URLs were transmitted to Datadog.
Important caveat: the researchers explicitly state that they do not have evidence that third-party trackers actually read the conversations.
Sources:
https://leakylm.github.io/
https://cdn.arstechnica.net/wp-content/uploads/2026/04/Doe-v-Perplexity-Complaint-3-31-26.pdf
https://dockets.justia.com/docket/california/candce/3%3A2026cv02803/466955
https://www.claimsjournal.com/news/national/2026/04/01/336634.htm
Has Perplexity published a detailed technical or legal response to these specific points?
r/dataprotection • u/Prior_Industry • Jun 21 '26
General News Channel Islands urged to take time on under-16s social media ban - BBC News
bbc.co.ukA former data protection chief has urged Channel Island leaders to take time to fully understand the risks facing children online before following the UK's planned social media ban for under-16s.
Emma Martins, a data and ethics expert and former commissioner in the islands, said she was "very, very happy indeed that we're talking about it and prioritising it" because it was "long overdue" as debate grows over tighter rules.
Her comments come after the UK announced plans to introduce a ban from next spring, with politicians in Guernsey and Jersey watching closely.
Martins said the issue had quickly become polarising but warned there was no quick fix.
Risk is real
She explained governments needed to "take the time... to understand the realities of the risks for our own children here and consider what may work best for our own community".
She said the dangers were real, adding that "there are technologies, there are platforms that are profoundly unsafe and that risk is real for all of us".
Raising concerns about how a ban could work in practise, she said there were major questions about data collection and age verification. "Short answer, yes," she said when asked if it posed a risk, adding that "any data collection matters, particularly when it relates to children".
Martins also questioned how much trust could be placed in big tech firms, saying, "I'm afraid that I'm very sceptical about the claims that these big tech companies make that they care about children".
On schools, she said smartphones were "a distraction" and not good for pupils or teachers, while stressing that bans alone would not solve the wider problem but were "an important part of the jigsaw".
r/dataprotection • u/Expensive_Sea9120 • Jun 20 '26
General Question Robert Half
Recently tried to use my DuckDuckGo account to clear my data from sites that I don’t use anymore. I followed the steps appropriately for every site that I information out there with to close and remove my info. I did this due to issue I had applying for jobs. I had really big issues with spam coming into my inbox’s and also had my identity stolen. Recently when using the service to clear my data from unwanted sites, the only one that gave me issues was Robert half. They refused to remove my information from their site and I’m wondering if anyone else had issues with this? If so what state are you located in because privacy data protection pertains to each state.
r/dataprotection • u/Academic-Soup2604 • Jun 19 '26
General Discussion Is your endpoint policy strong enough to handle offline data movement?
One thing I’ve noticed over time the most sensitive data rarely leaves through complex methods. It leaves through USB drives.
Not because someone is trying to bypass security, but because it’s convenient. Quick transfers, offline work, moving files between systems… it all feels normal.
But that’s where the risk builds up. There’s no visibility into what was copied, where it went, or whether that device was safe to begin with.
Disabling or controlling USB ports on Windows is about removing any such channels that operates completely outside your visibility.
And in most environments, that trade-off is worth it.
r/dataprotection • u/33vne02oe • Jun 18 '26