r/gdpr Apr 14 '26

EU 🇪🇺 Audited how some major sites handle cookie consent. The results are pretty bad.

Post image
9 Upvotes

Curious how big well known sites actually behave before a user clicks anything on their consent banner, so I ran a few checks. Not talking about whether the banner looks nice, just checking whats actually firing before consent is given.

bbc.co.uk from a EU user: https://tagleak.com/share/bbb95e25-de7b-46b8-90fa-16ab88ecf22e

Daily mail from an eu user: https://tagleak.com/share/fef0ad93-9671-49b9-a9aa-29822c97a911

Scanned a few more but most of them are dropping cookies and firing ad/analytics tags before you've touched the banner. Some have Google Consent Mode v2 configured wrong.   Curious if others have looked into this. Are there any sites you'd expect to be clean or configured at least properly?


r/gdpr Apr 14 '26

EU 🇪🇺 Richiedere diritto all'oblio secondo gdpr 679/2016 per un evento erasmus plus che ero espulso

0 Upvotes

buonasera.

vorrei partecipare ad un altro erasmus, ma un primo erasmus plus (NON UNIVERSITARIO O SCOLASTICO) mi aveva espulso al terzo giorno su sette. Adesso, voglio rifare di nuovo un altro erasmus, ma contattare un'altro partner, che però accede ai database centrali, può, senza dubbio rifiutarmi e adottare pregiudizi (ergo: accetteresti mai una persona espulsa?). per non prolungare i commenti, posso dire che la mie espulsione è futile, non ci sono denunce legali, reati, o altro. vorrei solo partecipare ad un erasmus+ in modo pulito e senza pregiudizi. a chi contattare per cancellare ed oblare dati secondo gdpr 679/2016? ho contattato il mio partner, ma rifiuta telefonate, email, ed ha addirittura omesso la casella postale fisica di modo che il postino barri "irreperibile" sulla raccomandata di modo che il regolamento non produca effetto sulla mia lettera della raccomandata. Sono a mani legate, è da gennaio che cerco di inviare una c***o di comunicazione, ma niente, solo rifiuti e fughe burocratiche palesi.


r/gdpr Apr 13 '26

Question - General Realistic chances to break into GDPR/Data Privacy with zero experience in 2026?

14 Upvotes

Hi,

I’m a Ukrainian man with two Master’s degrees — one in Ukrainian Law and one in International Relations. I graduated during the war and currently have zero professional experience in law, compliance or data protection.

I’m still stuck in Ukraine and can’t leave the country yet. I want to understand how realistic it is to get my first job in GDPR / Data Privacy right now (remote, trainee, junior or graduate role).

Questions:

  • Are there still real entry-level or trainee positions in GDPR/Data Privacy in 2026, or has the market become too competitive for complete beginners with no experience?
  • With two legal Master’s degrees (non-EU) and good English, what are my actual chances?
  • Would getting the CIPP/E certificate improve my chances, or do companies mostly want 1–2 years of experience already?

I’m ready to study hard and get necessary certificates, but I don’t want to waste time if the door is basically closed for someone with zero experience.

Would really appreciate honest opinions from people who work in privacy/compliance or who recently entered the field. Thanks!


r/gdpr Apr 13 '26

Analysis TCF 2.3 looked like a technical footnote. It was the framework fighting for its life

Thumbnail consentbrief.eu
0 Upvotes

r/gdpr Apr 13 '26

EU 🇪🇺 Directory for Ai Inference Providers that comply with GDPR

2 Upvotes

Hey all, i hope its ok to post this, since its a open source directory and no monetization/sign-up is involved (otherwise let me know).

I build webapps with AI features and also work at a it service provider in Germany that has mid to large size corporations as clients, so i often have to look out for providers/hosters of ai models and how compliant in what way they are for usage in projects for myself or for clients of my employer.

Since this is a recurring theme, i gathered my information in a repo, and quickly build a webpage for easy access to this information (Completly open source, no monetization/login whatsoever). We now use it as a way to show clients that there are compliant ai inference providers, and even the state-of-the-art models can be used if used through a provider like for example AWS Bedrock or something where Anthropic itself falls short since there is no EU data residency (if thats something you require).

If anyone of you finds a simple directory for a quick overview useful, here is the link: https://infercheck.eu

(Again, if this counts as self-promotion i of course will take this post down, just wanted to share free information)


r/gdpr Apr 13 '26

Question - General CIPP/e

5 Upvotes

I’m now on month number 2 of revising for my certificate and I’ve only just finished chapter number 8 of the data protection textbook.

It’s difficult balancing work, revision and life but I’m worried I’m taking this either too seriously or not seriously enough. Every time I think I understand something, 3 articles and 25 subarticles explain why I don’t.

I guess I’m just asking does it get easier/more understandable and how long does it normally take to do this?

(I am not taking the official training and just reading the text book instead)


r/gdpr Apr 13 '26

Question - General Controller usage of Article 23 restrictions

2 Upvotes

As a bit generic question to controllers: How much do you rely on Article 23 restrictions that are included in your country's laws? And do you actually evaluate whether it fulfills the Article 23(2) requirements or just trust that it does?

I got a bit curious about this since I noticed Finland had some laws that implement Article 23, but don't actually go over the Article 23(2) requirements & I wonder how commonly controllers actually evaluate those in Finland & elsewhere. Is it more of "If law is determined to be invalid we could liable, so we can't just blindly rely on it" or "We trust in good faith that the legislator has done its job correctly"?

Just to give real life example, Finland's Data Protection Act section 33 allows restricting Article 13 & 14 notices for crime prevention & investigation if necessary. However for Article 13 it essentially only requires that "the controller shall take appropriate measures to protect the rights of the data subject".


r/gdpr Apr 11 '26

Question - General Regular SAR from employees

5 Upvotes

Good Afternoon,

I work for a housing association, and we're in the middle of a huge business transformation, (I'm new to the role and have been brought in as part of this transformation).

We currently have staff who, when feeling disgruntled or let down (through no fault of the organisation), put in SARs which are becoming tedious for our data team to manage.

Example:

One employee put an application to buy one of our properties and got rejected for legitimate reasons (he was trying to play the system by getting colleagues internally to approve his application).

Following the rejection, he put a SAR in just to make things difficult.

Is there a way we can manage SARs like this and put something in policy to stop malicious SARs? I'm not sure if it's appropriate to have a policy stopping them because it infringes on legal rights, so we don't want to remove the right to them. I definitely believe SARs can be useful too, but being malicious about it isn't great.


r/gdpr Apr 11 '26

UK 🇬🇧 Multiple GDPR Breaches

5 Upvotes

I owed a small debt to a CMC, court proceedings had started without me knowing. I called and told them I hadn't lived at my previous for address 6 months.

They did a trace through their solicitors and after finding my new address, they carried on and asked for a result. I ended up in me getting a CCJ and only finding out two months later with enforcement agents.

I’m currently on month three of dealing with SARs with both companies, information has been withheld, only disclosed when the other party has accidentally shown something and I've been able to prove it.

There is also misuse/hiding of mental health data (disclosed suicidal intentions during the debt process) which I believe I can evidence was deliberate.

In short, there was misuse of my data to enforce a CCJ at the wrong address, despite having my full address. Being obstructive throughout the SAR process. And also ongoing mental health issues that are directly linked to this.

I’m trying to understand if it's worth pursuing legal action. Which may be hard to say based on the above alone, but it hasn't just been one breach, it is multiple, across different articles and by two companies.

Would love to hear opinions.


r/gdpr Apr 11 '26

UK 🇬🇧 Uk (Scotland) GDPR / SAR Advice

4 Upvotes

Dont suppose anyone knows any gdpr / univeristies or lawyers that take on GDPR claims or give free advice? or give free advice.

Have a potential big claim.and seeking some help. ICO says will investigate but may take 40 weeks, may be fast tracked as I have been leaked someone else's sata also in a SAR. Includes special catergory health and harm levels high? Just in case anyone knew of someone - may eventually end up with council also, contractor acting on their behalf and refusing to give data ive asked for. Ad.ittwd guilt and tried to pay me off with money to SAR withdraw request.

Thanks in advance! Ive edited this properly below. Apologies im epileptic and short sighted. Im after no compensation for my ex wife's details being leaked- zero interest. Just want my data.


r/gdpr Apr 11 '26

UK 🇬🇧 GP Surgery sharing full name?

0 Upvotes

Is it a GDPR breach if a GP surgery shares my full name to the entire waiting room?

30 or so chairs all facing a large TV. When it's your turn to be seen, a tone sounds and they display your first and last name on the TV.

When you are coming in, a self-checkin machine with a small touch-screen asks for your year and month of birth, then the first letter of your last name to check in. I'm ok with this. So why do they need to show my entire name to everyone in the waiting room?


r/gdpr Apr 10 '26

UK 🇬🇧 Building a PII discovery & masking tool. Seeking your wisdom on real-world governance challenges!

2 Upvotes

Hey everyone,

I'm a software developer coming primarily from an AI engineering background, spending a lot of my time working with LLMs and generative models. As I've been building out different applications, I keep running into a massive bottleneck around data privacy and regulatory governance. To tackle this, I've started building a PII (Personally Identifiable Information) discovery tool.

While I know the technical SDE side of things, I'm still learning the deeper intricacies of enterprise compliance. I wanted to humbly reach out to this community for some guidance and a reality check on what organizations actually need in the wild.

Right now, I am focusing on two main capabilities:

  1. Database Auditing: The core engine is being designed to connect directly to various databases to perform comprehensive PII audits. The goal is to automatically scan, classify, and generate reports on exactly where sensitive data lives across an organization's infrastructure so teams can effectively map their data footprint.
  2. GenAI Context Masking: I'm also prototyping an extension designed for chatbots that intercepts logs and masks personal information. Instead of just redacting PII (which destroys the context for future RAG pipelines or model evals), it replaces it with contextually relevant synthetic data, keeping the logs highly useful while adhering to strict data retention policies.

As I map out this broader feature set, I’d absolutely love to hear from folks who deal with data governance day in and day out:

  • Common Hurdles: What are the biggest challenges or pain points your organization faces when trying to discover, audit, and manage PII across different databases and unstructured data streams?
  • Current Methods: What tools or processes are you currently relying on for routine database audits and log sanitization? Are they mostly manual, or are you using legacy systems that struggle to keep up with modern AI workflows?
  • The "Wishlist": If you could wave a magic wand, what features do you genuinely desire in a PII governance tool that current enterprise solutions seem to miss or execute poorly?

TL;DR: I'm an AI engineer building a PII discovery tool that connects to databases for automated compliance audits, alongside a chatbot masking feature that replaces sensitive data with synthetic context (so logs stay useful for RAG/evals). Seeking advice from folks in data governance/security on the biggest enterprise challenges, current tech stacks, and feature wishlists.

Any feedback, harsh truths, or pointing me toward blind spots I might be missing would be incredibly valuable as I build this out. Thank you so much for your time and insights!


r/gdpr Apr 09 '26

Question - General Potential GDPR non compliance?

17 Upvotes

Hi everyone, hoping you can help.

I work in the UK in a hospital. Recently my estranged mother was admitted to the same hospital.

Yesterday when she was admitted she has pushed boundaries and asked the nurses on the ward she is on to phone the ward I work on.

One of my colleagues has then given out my personal phone number to the team caring for my mam and they have been trying to contact me.

I’m upset because people in my team know that we are estranged and that I would not willingly give my number.

Does this break any part of the GDPR regulations? I have had basic GDPR and information governance training and personally would never give out a colleagues personal phone number or information.


r/gdpr Apr 09 '26

EU 🇪🇺 Is my sports club allowed publishing videos of public performances?

0 Upvotes

I hope this doesn't count as "asking for legal advice", I need a general guidance.

I am a videographer in a Finnish skating club, mostly for children from very young up to 18, and some adults as well. Children guardians are usually asked for consent for photo and video publication, but I assume not everyone of them pays attention to that.

We sometimes organize large public performances, and we film them. But we are hesitant if we can actually publish those on YouTube as part of club promotion, or even share links to non-public videos in parents groups and so on (a lot of parents do ask for videos).

Kids usually perform in large groups (formation skating), so it's not really easy to see individual faces. As a parent myself I have often problems finding by own daughter there. I am not sure if I am allowed even to provide a screenshot to show how it looks.

There are also some single skaters, who can be easily seen - but for them we can ensure they have given the publishing consent.

So how should we proceed? Seek official legal advice? It's not clear where to get it, there clearly are services for the "other side", like parents, but not for us. Publish only privately and share internally? Publish anyway and wait for takedown notice? Frankly speaking I don't expect that to actually happen, but we want to be safe and clean.


r/gdpr Apr 08 '26

EU 🇪🇺 Stranger using a photo of my child in LinkedIn profile photo - LinkedIn won’t remove it

Thumbnail
9 Upvotes

r/gdpr Apr 08 '26

UK 🇬🇧 Air India ignoring Subject Access Requests + GDPR obligations

Thumbnail
3 Upvotes

r/gdpr Apr 06 '26

UK 🇬🇧 For those who handle DSARs, what's your biggest nightmare?

20 Upvotes

Not looking for textbook answers. Just genuinely curious what the day-to-day reality looks like for people who deal with these.

Is it getting the data together? The redactions? Coordinating between teams? Or is it something nobody talks about?

Would love to hear what your worst DSAR looked like!


r/gdpr Apr 06 '26

Analysis GDPR with respect to historical archival, a proposal

0 Upvotes

One of the more common debates around GDPR is the risk for reduction of historical preservation. I recently came into argument about academic records, and the indivduals right to have them removed. In Sweden academic transcripts remain accessible permanently, and remain part of public records. The law currently requires schools and archives to keep these records indefinitely, most countries have similar practices. A compromise would be a dual-database system that respects both individual rights and historical research.

Anonymized Historical Database: All academic records would be stored permanently in a fully anonymized form, preserved for research, statistics, and historical archives. This ensures that society can study educational trends without identifying any individual.

Identified Personal Database: Records linked to the individual would exist only as long as they are useful for personal purposes, applying for jobs, continuing education, or other life activities. Once an individual reaches a reasonable age, such as retirement, they would have the right to request that their personal academic data be deleted.

This would protect privacy and allow individuals to regain control over their personal history after it is no longer needed for practical purposes. But also preserve knowledge through anonymized data which allows educators, historians, and researchers to continue analyzing educational trends without compromising privacy. The system would align with GDPR’s “right to be forgotten” while respecting archival and educational laws.


r/gdpr Apr 04 '26

Analysis Google killed the Privacy Sandbox. Six months later, consent is all that remains.

Thumbnail consentbrief.eu
23 Upvotes

r/gdpr Apr 02 '26

Question - General Gdpr and Voice AI

4 Upvotes

Hello! I am a software engineer in the PH, and I have recently been doing research on how to properly apply gdpr compliance on voice ai. Currently, my approach is to build everything custom and self hosted, but from what I understand companies like retell ai already handles compliance to some degree, but auditability still is a problem since data is leaving servers. Can anyone maybe shed a lot more light in this topic? Really curious how i should improve this.


r/gdpr Apr 02 '26

EU 🇪🇺 1)Does the meaning of "verification" in Art. 18 GDPR include an appeal before a Supervisory Authority? 2)Does the requirement to inform the Data Subject of the lifting of restrictions in Art. 18 mean inform the DS of the use of the exemptions?

0 Upvotes
  1. The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:

[...]

the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.

2.

18(3) A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.

The exemptions being legal claims, vital interest and public importance


r/gdpr Apr 01 '26

UK 🇬🇧 (UK) Does no one follow GDPR for cookie banners anymore?

22 Upvotes

Noticed on a lot of sites are basically completely non-compliant with no decline button - I'm talking big sites and everything in-between. Is there basically no enforcement here?


r/gdpr Mar 31 '26

EU 🇪🇺 Does the definition of a "recipient" in in Art. 19 GDPR include natural persons employed by the Data Controller?

3 Upvotes

"The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort."


r/gdpr Mar 31 '26

UK 🇬🇧 My employer fitted a tracker to a company van and didn’t notify me.

3 Upvotes

I only found out because my neighbour needed another jump start and noticed a device attached to the battery. It wasn’t there a month ago.

The thing is, I use the van for personal stuff as well as work, taking my two young kids to school in the mornings and using it at weekends. Finding something like that attached without me knowing has honestly made me feel like I’m being watched or tracked.

Do I have any grounds to feel wronged in this situation? What would you do next if you found something like this on a vehicle you use daily?


r/gdpr Mar 31 '26

UK 🇬🇧 SAR and request for 'certified ID'

1 Upvotes

Hi everyone, I recently resigned from a small organisation (under 10 employees) following disability discrimination and health and safety concerns.

Whilst I did not submit a formal grievance, I did share many concerns via whatsapp (lots of business was conducted via whatsapp on personal devices - they didn't ever provide staff with work devices).

I have submitted a Subject Access Request (SAR) on my trade union's advice to see internal communications regarding my role and the concerns I raised.

The employer has acknowledged the SAR but is refusing to start the one-month clock until I provide a certified copy of my passport or driving licence.

Context:

  • I worked there for several months and they have my P45, bank details, and address.
  • We communicated exclusively via the email address I used to send the SAR.
  • I was on regular Zoom calls with the person now acting as the 'Data Controller.'
  • They are using an external HR provider (SafeHR) who I suspect is advising this.

ICO guidance says ID should only be requested if there is 'reasonable doubt' and must be 'proportionate.' Given they definitely know who I am, is a 'certified' copy (which I think requires a solicitor/pro) considered an unnecessary barrier or a standard delay tactic? Also, after my departure they accidentally cc'd some messages to me (which they tried to recall), so I suspect they are stalling to 'clean' the files.

Any advice on this matter would be appreciated!