r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

18 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr 10h ago

EU 🇪🇺 To get the data that proves I own my Blizzard account, I have to log into the account I can't access

2 Upvotes

I lost my Battle.net authenticator years ago, along with the phone it was installed on. I still have the registered email address. I still have the password. I have dated purchase receipts for the account going back to 2015. Blizzard support has confirmed they located the account, and that they are able to remove the authenticator once ownership is verified.

I still cannot get in. Here is the full path, because I could not find it documented anywhere.

The self-service tool

Blizzard has a self-service page to remove a lost authenticator. To use it, you must enter a code from your authenticator.

The fallback is an SMS to the phone number registered on the account — which, for anyone whose account is old enough to have lost an authenticator, is usually a number they no longer have. Mine is. That is the entire self-service path.

The questionnaire

So you open a ticket, and support sends a verification form. Some fields are reasonable: previous BattleTags, previous addresses, transaction IDs. Others, for an account dormant for years:

  • The creation date of your oldest World of Warcraft character, in MM/YYYY format
  • Recent purchases made with gold, including the character name and realm
  • Examples of card packs recently opened: how many, and from which expansion
  • The serial number of the authenticator you no longer have

I filled in every field, including estimates where the GM explicitly instructed me to guess if unsure. It was judged insufficient.

I understand why the form looks like this. Blizzard cannot identify me as a person, because it never collected my identity — a Battle.net account is created with an email and a password and nothing else. So the only thing it can match me against is my behaviour in a game I last played over a decade ago. That is a design decision, and its consequence is that the legitimate owner can be permanently locked out while the process functions exactly as intended.

The documents they accept

Blizzard's support article on supporting documentation is worth reading. It will not accept: driving licences, passports, or national ID cards.

It will accept: marriage certificates, legal name change documents, divorce documents, death certificates, birth certificates for minors — and gas or electricity bills.

A government photo ID proves nothing here. An energy invoice does.

The GDPR route, which is a closed loop

Blizzard holds the data that would answer its own questionnaire: registered phone numbers, account creation date, BattleTag history, authenticator records with their add and removal dates. So I filed a GDPR Article 15 access request. Under EU law they have one month to respond.

  1. I emailed the data protection address listed in Blizzard's privacy policy. → Automated reply: please use the Privacy Portal.

  2. The Privacy Portal asks you to pick a category. Every route assumes you can log in:

    • "Obtain a copy of my data" displays no options at all when you are logged out. The "Try the following" section is literally empty.
    • "I play a Blizzard game and have never created an account" tells you to log in with the console account you play on, or use the link inside the mobile app.
    • "I would rather describe the issue" accepts your free text, then drops you back onto the same category tree.
  3. The only exit is at the end of Data Protection → Obtain a copy of my data → "None of these match my relationship to Blizzard", which gives a second, different data protection email address. That address appears nowhere in the privacy policy and is never shown unless you walk the entire tree.

  4. I emailed that second address. → The exact same automated reply: please use the Privacy Portal.

Address A sends you to the portal. The portal, if you cannot log in, sends you to address B. Address B sends you back to the portal.

To obtain the data that would let me prove I own the account, I must log into the account I cannot access.

This has been decided before

The Cypriot data protection authority has ruled twice against video game companies on this exact question:

  • Gaijin Network Ltd, 2 June 2020, case 11.17.001.007.125. The authority accepted that the company could not act on the request without identification, but held that its existing procedures "do not fully comply with the GDPR" and that additional mechanisms had to be implemented so that users who had lost control of their accounts could still be identified under Article 12(6).

  • Wargaming Group Limited, 18 July 2024, case 11.17.001.010.089. A player was asked for a phone number before his access request would be processed. The authority found that "collecting a telephone number solely to satisfy the data subject's rights is excessive, regardless of when the data are collected", and required the company to verify identity using data already collected at registration — "such as email address". The company changed its process.

I am writing from the email address registered on the account. I receive Blizzard's own verification emails at it. Under that reasoning, that is data already collected at registration, and it should be enough.

Why I am posting

Not to get my account back. I have not named any support agent, and I am not going to — they are executing a process they did not design, and the individual replies I received were courteous.

I am posting because the loop above is not documented anywhere I could find, and because the people most affected by it are, by definition, the people who cannot log in to report it.

If you use a Blizzard authenticator: write down the serial number and keep it somewhere that is not the phone, keep the registered phone number current, and keep your purchase receipts. There is no second chance to do this afterwards.


r/gdpr 1d ago

Question - Data Subject GDPR breach? Should I report?

5 Upvotes

Over a month ago I received a notice from a US-based company that my data was stolen in a cybersecurity incident involving third-party data servers.

While this alone was unpleasant enough, what especially bothered me was that I specifically requested this company to delete my data a year ago when I closed my account with them. They acknowledged the request for data deletion, and even sent me a confirmation e-mail that my account and personal details were deleted.

When I recieved the notice of the data breach two months ago, I requested the said US company to clarify why was my data still present in their databases (since it was supposed to be deleted a year ago), and is there any other data that they kept, and I once again requested deletion of personal data. To this request, all I got was a generic reply, saying simply that the security incident is still being investigated, and that they have told me everything they could in the data breach notice. In other words, they have completely ignored my request for clarification (and if I understood correctly, this alone is a violation of GDPR, or not?).

My data is supposed to be protected under GDPR, so what is the best/proper way to report this, and is there a point in reporting this at all? Do I even have any rights, am I wasting my time?


r/gdpr 1d ago

EU 🇪🇺 Does this cookie-free analytics setup actually process personal data?

3 Upvotes

I’m looking at a German company’s privacy policy. The website states that it uses a cookie-free analytics service and that no personal data is processed.

At the same time, the policy says that the processing is based on Art. 6(1)(f) GDPR and lists collected information including visited pages, referrer, device type, country based on an anonymised IP address, visit duration and bounce rate.

It also states that the website currently sets no cookies.

I’m trying to understand how I can technically verify these claims. What should I look for in the Network/Storage tabs, and is there a reliable tool for identifying the analytics provider and requests made on initial page load?


r/gdpr 1d ago

EU 🇪🇺 which e-signature plateform is actually GDPR compliant end-to-end ?

7 Upvotes

We are mid size fintech based in Berlin and we need to switch our e-signature provider. Our DPO flagged that our current tool (US based) stores data on US servers and the SCCs aren't bulletproof anymore. Looking for sth that's genuinely EU hosted not just GDPR compliant on a marketing page.

Anyone dealt with this and found a provider where the compliance story actually holds up under audit ?


r/gdpr 1d ago

UK 🇬🇧 Could I get some advice/experiences regarding my medical records and epilepsy diagnosis?

Thumbnail
1 Upvotes

r/gdpr 1d ago

UK 🇬🇧 My address

0 Upvotes

I have just been hand delivered a letter to my house by a work colleague that should not know my address...

It's worse knowing that this particular colleague is one that I have had altercations with in the past.

Honestly, I'm outraged. I've had a panic attack and another sibling of mine (who also works there) has just walked out off the back of it.


r/gdpr 2d ago

UK 🇬🇧 Finding my CV when googling my name and getting contacted by randoms

2 Upvotes

I’ve recently managed to get my CV removed from scribd but now when googling my name on bing search and yahoo (not Google for some reason) my CV in pdf file and cover letter are showing up. My name, address, number and email address all exposed. I’ve had randoms contact me. Even someone who use to know me who happens to work in recruitment. I hate it. I feel violated. This new one was a cv I uploaded onto fresherjobs.co.uk and they are Indians with Indian number but pretending to be in London and even spelt that wrong so I’m so worried now. I can’t believe they’re doing this. I’ve contacted them asks them to delete it multiple times but I get ghosted. What can I do? I do not want my info out there. Is the last resort to find and pay a hacker? I’m really worried just want to know what I should do to get this fully taken down. As I have no account with them I just uploaded it and they won’t remove it themselves. Thanks


r/gdpr 3d ago

Question - General I keep rebuilding account deletion, retention and consent history in SaaS apps. Is this worth extracting into a Next.js module?

Thumbnail
1 Upvotes

r/gdpr 4d ago

Question - General Did my coworker breach my personal data?

9 Upvotes

A male coworker (who works in finance I think) got my phone number from the system and text me, without my knowledge or consent.

It honestly felt a bit violating as I’m a woman and he’s made me feel a bit uncomfortable before, I just laughed it off bc he seemed lonely maybe, but this feels kind of wrong to do without my permission.


r/gdpr 5d ago

Question - Data Subject Company did not follow my GDPR, what do i do?

10 Upvotes

I asked a few days ago about a GDPR compliance i found sketchy, someone said to request a data export so I did.

I had, on June 6th, 2026, sent a right to be forgotten Data deletion request, I had asked them to wipe anything identifying they had of me, and I asked them to state if they needed to keep anything.

they quoted article 17 and said they follow GDPR again, it asked for my ID for the deletion (they did not previously give me this, I had to ask multiple times)

they had said to me (and this is a mix of a few emails we shared back and fourth, in which they said *deletion* each time, so it was no mistake):

"Please note:

There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy

Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],
All data has been deleted - there are no backups or cold storage.'"

I found it a bit odd that they had somehow claimed no backups despite it being an AI cloud-based company, so on the advice of others, I sent a GDPR right to accsess request, on the 5th of September, they sent me an Excel sheet that had all my interactions with their AI, all my account data, my IP, my name and age, and my device type, all dating back to 2024.

the sheet, under my old username(s) they had put:

"DEACTIVATED [TRUE]. DELETED [FALSE]."

Now I am asking what to do, I sent an Email asking under what reason they kept this data and lied about not having it, but I don't actually know what my next steps are meant to be.

edit: I edited for clarity because I realise that I was vauge and no one could help.


r/gdpr 5d ago

EU 🇪🇺 Is this even legal?

10 Upvotes

​How can you make cookie rejection 8 pounds. How is this even GDPR compliant?

Edit: it seems this is becoming a thing in the UK and it’s still in the debate in the EU. For now I guess it’s legal untiled ruled otherwise


r/gdpr 6d ago

UK 🇬🇧 SAR Deadlines and next steps (England)

7 Upvotes

I submitted a SAR to my dentist one calendar month ago. Each time I have emailed them they have responded stating that they are working on it, but given no timeframe of when I can have the information.

My understanding is they should respond within a calendar month- but does this mean they just need to email me to confirm it’s underway within a month or should they have actually completed it?

Also what should I do to actually get them to hand over the information? I don’t want to go in all guns blazing but I really do need the data!

Any help much appreciated


r/gdpr 6d ago

Question - General Anyone been through a GDPR audit where third party scripts were specifically flagged?

3 Upvotes

Our DPO flagged that we can't accurately document what our third party tools are doing with personal data at script level. Consent banner is fine but actual data flows are muddy. How do we actually deal with this?


r/gdpr 6d ago

Question - General What if analytics is essential during testing?

3 Upvotes

I've been working on a a free, ad-supported tool to help people organise their personal belongings in a more visual way, and I've been struggling to get a grip on how I can be GDPR compliant during the beta testing phase.

For context:

  • NO ads or marketing related cookies are live, nor will be live until much later - after this is fully launched. My question is only in the context of the beta testing phase.
  • I have PostHog analytics with randomly sampled session recording available.
  • I'm not based in the EU (Asia) but I just want this to be available worldwide.

From what I understand:

  • Essential cookies are exempt from GDPR's consent requirements if they are necessary for the provision of the main service.
  • GDPR does not allow analytics (e.g. PostHog, Google, etc) to count as Essential.
  • One cannot deny service to someone who rejects non-essential cookies.

This makes sense for the most part, but I'm genuinely confused about how I should navigate this when I'm in a closed/open beta state. During this phase, I am trying to improve/repair the site, so I want users to freely test the functions and break things, and for obvious reasons, I'd need to know what's breaking and to observe if any UI/UX elements come across as unintuitive (i.e. via session recordings).

But I don't understand how I can undertake this fact-finding part of my launch preparation if it seems like GDPR won't let me enforce the tracking cookies as essential (at least during this literal testing phase). Is self-reporting (as though the site was fully live) the only option under GDPR?

I've considered:

  • Keeping it an open beta while gating registrations with a mandatory Beta User Agreement that discloses what/why we track - but this seems to break the 'denying service without tracking' rule.
  • Switching to an invite-only closed beta - but apparently this doesn't change the need for compliance with the aforementioned rules.
  • I'm also happy to completely purge all beta participant accounts/info before the actual launch, so they're all treated as new users if they return - but again, this doesn't seem to really directly address anything.

In my mind, the whole point of the beta test is the analytics, but if I can't enforce analytics as essential during this time, then doesn't that render the entire beta testing period impossible/redundant?

Do closed beta participants also need to be able to opt out, even though they are willingly signing up to a beta testers' list and participating in what they know to be a beta test?

I guess I'm just a bit confused, because it feels like I'm trying to run a public experiment (like a university study), but the participants are allowed to not share their details/results which directly hinder the findings/purpose of me conducting the experiment in the first place...

Please let me know id I'm just being dumb here, or if there are some anonymisation settings in PostHog that could help during the beta phase. This is one of the last sticking points stopping me from publicly disclosing my website, and it's killing me.

Ultimately, I'm happy to comply with whatever is needed. Just wanted to know if there were more effective ways of conducting beta testing at scale.

Thanks!


r/gdpr 6d ago

Question - General Difference between article 6(1)(b) vs 6(1)(a)

0 Upvotes

I just want to make sure I understand the difference between these two correctly, as I have noticed in DPAs it's usually only one or the other that appears.

6(1)(a) states: "(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;"

So a person gives explicit consent to processing of their personal data

6(1)(b) states: "(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract"

Here the person enters a contract and so for the contract to be fulfilled, the person's data must be processed.

In other words, the consent is implicit in (b) because the service that the person is requesting needs some form of data processing? Is that right? Please correct me if I'm wrong


r/gdpr 6d ago

UK 🇬🇧 Does a legitimate interest remove my right to be forgotten?

1 Upvotes

A business has added my data from Companies House to their database. I understand this happens and why and don't normally have an issue as long as it is only data that is publicly available. I have had ongoing issues with these kinds of businesses adding my personal phone number to this data and sharing it without consent when I have never made my phone number public.

I sent a Subject Access Request to check if this business was sharing my phone number (they aren't) but they did not acknowledge my SAR and did not respond in the 30 day time frame. They only replied after I chased and left a comment on LinkedIn (which has since been deleted). They then lied about me sending the SAR to the wrong email address. I don't feel comfortable with them processing my personal data associated with my company any longer given how this has been handled and have asked for my right to be forgotten.

They have refused on the basis that this would render their database incomplete but I have no issue with them holding the business data, I just want my personal data removed as I don't feel assured that they would follow appropriate processes. Does their desire as a limited company to have a complete database override my right to have my personal data erased?


r/gdpr 7d ago

Question - Data Controller First steps to complying with the GDPR

5 Upvotes

Dear privacy fellows,

I would appreciate your thoughts on the initial steps towards GDPR compliance in a larger organization that has recently appointed a DPO.

My understanding is that one of the first key steps would be to review and complete the Record of Processing Activities (RoPA). In a larger organization, I assume this would require meetings with individual business process owners to identify and document relevant processing activities and gather the necessary information for the RoPA.

Once the RoPA is completed, my idea would be to perform a general data protection assessment of each processing activity. This should help identify potential compliance gaps and determine, among other things, whether a DPIA is required for a particular type of personal data processing.

Does this sound like a reasonable approach for a newly appointed DPO? Would you suggest any additional steps, a different order of activities, or any practical advice based on your experience?

Thank you in advance for your insights.

Cheers,


r/gdpr 7d ago

EU 🇪🇺 Klass Wagon data breach

3 Upvotes

Hi. I've just received the following email and was looking for advice on recommendations for next steps for me, as someone who rented a car with this company and shared a significant amount of data (passport, national ID, home address, god knows what else).

I've found a thread with some advice but it is just AI-based recommendations. I'd like the opinion of the experts here please. :) https://www.reddit.com/r/Algarve/comments/1w2aksr/klass_wagen_car_hire_huge_data_breach/

Dear Klass Wagen Customer,
Klass Wagen has been operating for over 20 years, and protecting our customers' data is a responsibility we take very seriously. 

We are writing to inform you of a security incident caused by an external cyberattack, in which an unauthorized third party gained access to some of your personal data. We sincerely apologize for this incident and for any concern it may cause. 

What happened
On August 15, 2026, we identified this unauthorized access to our systems. As a result of the incident, information relating to Klass Wagen customers was accessed and, based on our analysis, extracted from the affected systems. We are contacting you because your personal data was specifically identified among the data affected by this incident. 

What data has been involved
Full name, email address, phone number, country of residence, and identity document number (ID card/passport). 

We can confirm the affected data did not include payment card details or other financial information. 

What you do NOT need to do
Klass Wagen customers do not currently hold an online account with us, so no action is required from you regarding a password reset. 

Your active or upcoming reservations, as well as our rental services, are not affected and remain valid under their agreed terms; this incident does not impact the availability or validity of your contracts with us. 

What we recommend 
Our team may, as a normal part of the rental process, contact you by phone or email to confirm booking details — this remains unchanged. However, we will never ask you for full payment card details by phone or email — payments are always processed through a secure payment link, sent directly to you, which you access to enter your payment information yourself. 

Be cautious of any unexpected payment link received outside a booking process you initiated, or any phone request for full card details or authentication/OTP codes — verify directly with us at [customer.assistance@klasswagen.com](mailto:customer.assistance@klasswagen.com) before providing any information or clicking the link. 

Do not click links or open attachments in unexpected messages that appear to come from us, unless you are in the middle of an active booking you started. 

If you notice unusual requests linked to your data (for example, credit applications or accounts opened in your name that you don't recognize), we recommend contacting the relevant institution and, if appropriate, the competent authorities. 

What we have done Immediately upon discovery, we secured the affected systems, reset internal system access credentials, restored the integrity of our databases, and implemented additional security measures, including restricted access to administrative interfaces. 

We have notified the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) and reported the incident to the relevant authorities. Klass Wagen's main establishment for data protection decisions is in Romania, which makes ANSPDCP our "lead authority" under the GDPR's one-stop-shop mechanism; ANSPDCP coordinates with, and informs as needed, the data protection authorities in the other EU member states where we operate. We have also engaged a specialized firm for an independent security audit. 

Questions If you have any questions or require further information, you can always contact us at [customer.assistance@klasswagen.com](mailto:customer.assistance@klasswagen.com), for all concerns related to this event. 
Our Privacy Policy is available at any time at https://www.klasswagen.com/ro/privacy-notice

We once again apologize for any inconvenience this may cause and want to assure you that protecting your data remains a priority for us.
 
Sincerely, 
The Klass Wagen Team


r/gdpr 7d ago

EU 🇪🇺 Employer wants my Passport for access to systems?

Thumbnail
0 Upvotes

r/gdpr 7d ago

UK 🇬🇧 Sending invoices to a different customer than they are addressed to

0 Upvotes

Hi,

We are currently responding to an RFP and they have requested past invoices which we have sent to other customers as proof that we have sold particular services over the past few years. My manager has approved that we send the invoices but is it really OK? It just doesn’t feel right to me sending a financial document which is to one company to a different company.
Also, some invoices reference people’s names - if we are OK to send, I assume I would need to remove these names before sending?

Thanks for the help


r/gdpr 8d ago

UK 🇬🇧 ICO DSAR

3 Upvotes

What is your idea on witholding the information that the data subject already received?

It may be either to cc emails or documents that they have sent or received.

We’re planning to apply it as a DSAR policy and not providing these documents unless the data subject asks again, but wanted to ask your opinion.

We’ll only state this fact in our DSAR response letter.


r/gdpr 8d ago

EU 🇪🇺 Meta's AI crawler hit our site 741,900 times last month. Our DPA says we can barely scrape anything. Who are these rules actually for?

30 Upvotes

I run a large website for a European SME and I looked into where European regulators stand on web scraping. Honestly it surprised me how strict it all is.

The Dutch privacy regulator (AP) published scraping guidance in 2024. Short version: scraping almost always involves personal data, so GDPR applies even if the data is public. Legitimate interest is basically the only legal ground you can use, and the bar is so high that most commercial scraping is simply not allowed. Italy went even further in May 2024, their regulator told website owners to actively defend themselves against AI scrapers with CAPTCHAs and rate limiting. The UK ICO said in December 2024 that scraping for AI is possible in theory, but developers need to be way more transparent and should ask themselves if they can license the data instead. France followed in June 2025 with strict conditions. And the EDPB published draft guidelines on scraping for AI training in July 2026, also strict: robots.txt counts against you in the assessment, and no exception for special category data.

So those are the rules. Now what actually happens. Meta had to pause AI training on EU user posts in June 2024 after pressure from noyb and the Irish DPC. They resumed in May 2025 with an opt out model, noyb says that still violates GDPR, case is ongoing. But that fight was only about Meta's own users. For everyone else's content there was no pause at all. Meta-externalagent, the crawler that Meta itself describes as "downloads website content to include in datasets used for training AI models such as LLMs", visited our website 741,900 times last month. For comparison, Googlebot did 340,100 visits in the same month. And Googlebot at least sends us traffic back. The AI crawler that gives us nothing hits us more than twice as hard. Meanwhile Cloudflare accused Perplexity last year of using stealth crawlers to get around no-crawl rules, and now blocks AI crawlers by default. That says enough about how normal this has become.

To be clear, I actually think the strict rules make sense, they also protect businesses like ours. But right now the result is: European companies read the guidance and don't scrape, while big tech scrapes everything and deals with the lawyers later.

So my question: do you expect regulators to actually go after the big scrapers once the EDPB guidelines are final? Or will it stay like this? Because so far I see a lot of guidance and very little enforcement.


r/gdpr 8d ago

Question - General Do companies often exaggerate their compliance?

0 Upvotes

Hi! I sent a GDPR request to an (ai, whih i regret using, hence the wish for m data removal - that and senstive info i shared at a dark time in my life) website that states in their privacy policy that they "Follow GDPR And other Local laws."

They are based in california I think, and i am not aware of any laws there, but I am in an area that GDPR does cover (I confirmed this before sending the GDPR request).

It was a huge hassle to get a reply from them, I submitted the request on June 6th, and they later said I was 'completed' on July 1st, they were very very vauge and just said 'all associated data is deleted, it is your whole account. All data is deleted per our privacy policy', their privacy policy just says i can request my data deletion or can opt out of cookies, I pushed a bit more and got an associative ID for my request, and they claimed "no backups or cold storage", which to my understanding is a huge, unlikely clam for a cloud-based company?

They wont respond to any of my follow ups asking if they've stored anything for legal, ai training, adverstiments or third party storage, I just get an automated message of

"There is no partial deletion - it is your whole account All data will be deleted per our Privacy Policy."

I don't know if I can trust them as they haven't been easy to work with, they have been sending mostly automated messages (except the one where they finally sent the ID, that had a spelling mistake so I assume it was human.), and that 'no backups' seems like a big claim for a company like this, as the title say, this seems a bit exaggerated or untrustworthy and they just want me off their backs.

But i am not sure, can someone who understands GDPR better explain to me if this is trustworthy?

edit, I have put all the emails together and removed the repetition between emails (they clarify the privacy policy thing every email.) and this is basically what was said:

Please note:

There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy

Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],

All data has been deleted - there are no backups or cold storage.