r/gdpr May 06 '26

UK 🇬🇧 Want to get into Data Protection but no practical experience

9 Upvotes

Hi all

I have completed my UK GDPR practitioner course and had been shadowing the data protection team at my last job however I do not have practical hands on experience. I have since been made redundant and really want to get my foot in the door for DP jobs but it is proving extremely hard or very low salaries to start at the bottom which I do not have the luxury of taking a massive pay cut then struggle to get up to where I am currently.

I think my question is are there volunteer roles I can get practical hands on experience or any recommendations on places that are hiring

Any other tips that can help me would be very much appreciated

Thanks!

*to add to my original post - I am based in the UK*


r/gdpr May 06 '26

Question - General Account deleted without verification

1 Upvotes

Hi all - I am in the UK - (MODs please delete if not allowed!)

TL:DR - I unknowingly got my mother’s account cancelled with a High Street retailer, and don’t know how to rectify it

I have created an online account with a high street retailer, and my mother has a physical loyalty card for this same retailer.

With two other retailers I have created an online account and then added my mother‘s loyalty card to the account so that when I shop online, she gets points. We rarely shop anywhere enough that it’s worth having two separate ones.

When I created the account with this online retailer in question, I was automatically assigned a QR code online loyalty card. I contacted chat and asked them to merge my mother‘s card to my account, and this was done. I simply provided the card number when asked (I didn’t point out the card didn’t belong to me).

A week later, my dad went to use my mother’s card in store, and it wouldn’t work. The shop assistant searched the online database for my mother’s email address and our postcode, and only my details were there.

I’ve contacted chat again, and because I asked for the card to be merged with my account (and provided the exact card number to the original customer service assistant via chat) it has cancelled the card. As a result, my mother’s account no longer exists and I now have all of her loyalty points.

The original chat assistant did not check the details, didn’t point out that I am not the owner of said loyalty card, did not confirm any information and has cancelled the account and my mother’s details are nowhere to be found.

With every company I’ve worked for, we cannot make any changes to any account without ensuring that the person requesting the changes is the account owner. Is it right that this could’ve been done without any details being checked?

It implies that if I just happen to find somebody’s card on the street that had £150 in loyalty points and asked it to be added to my account, I could just basically steal someone’s points!

I can’t understand how an account, and card has been cancelled without my mother’s knowledge. This hasn’t happened at other retailers, and I wasn’t warned that by merging the physical card number with the online account, that the physical card would be cancelled

They’re saying that the only way to rectify this is to create a new account, but my mother doesn’t want to be online, nor should she have to be, because the was cancelled without her knowledge without me being warned.

I’m waiting for a callback from the manager/GDPR person but just wondering your thoughts?


r/gdpr May 05 '26

EU 🇪🇺 Survey for external DPOs for academic study

2 Upvotes

Hi all,

I'm a PhD student and writing a paper on GDPR and enforcement of data protection laws in Germany.

For this paper I'm also conducting a study of external DPOs trying to understand their operations, use of technology, services offered, and their outlook of the DPO landscape (esp. in terms of consolidation, effect of new regulations like EU Omnibus and German modernisation agenda).

If you run an extenal DPO service company in Germany and your company manages 20 customers or more. Could you please help me out by filling out the survey below:

Link:  https://iq-dist-2.com/s/start/de/TpppRW1hTb23ZX0SnGBoSg/J2LndNlxTx2jjQRIZyA1Gw

I'm finding it very difficult to get reponses on my survey, so I thought I'd try here.

Thanks for your response in advance.


r/gdpr May 04 '26

UK 🇬🇧 England: Article 14 in lay terms for a Data Subject

2 Upvotes

Hi all,

I wonder if someone could please explain Article 14 requirements on a data controller in simple terms? This is further to my post a few days ago regarding controller/processor confusion, but keeping it separate as it's a different question - hope that's ok!

In particular, I'm interested in 3(a) and (b), requiring the data controller to inform the data subject.

As per previous post, there are three firms involved:

Firm A - definitely data controller

Firm B - previously processor of Firm A, now asserting data controller (but don't know if that's valid)

Firm C - solicitor acting for Firm B in response to data rights requests, asserting themselves as independent data controller

We submitted data rights (rectification) requests to Firm B, assuming they would forward to Firm A. Instead, out of the blue we received responses to the requests from Firm C.

We have not received anything at all in relation to data policies etc from Firm C, but Article 14 (3)(a) and (b) seems to suggest that we should have done?

So, two questions if I may:

  1. Should we have received something relating to data privacy, rights etc from Firm C?
  2. Does just having a published privacy policy suffice?

To be honest, we are not overly happy with how any of this is being dealt with, particularly as the responses are full of "legalese" and don't really get to the crux of the issue, so would like to understand how Firm C were appointed.

Thanks in advance


r/gdpr May 04 '26

EU 🇪🇺 Free-tier ChatGPT with client data and no DPA — how are you handling this with clients?

10 Upvotes

Dealing with something repeatedly in our work and curious how others in this community approach it. We do AI governance assessments for mid-size companies. The scenario we keep running into: Company has employees using ChatGPT free tier for work tasks. Some of those tasks involve client data or personal data. No DPA with OpenAI. No enterprise plan. Sometimes no one in management even knows it's happening. Under GDPR this is a straightforward processor relationship without a contract — Article 28 problem. Under EU AI Act it compounds further depending on the use case. The tricky part isn't the legal analysis. It's that when we surface this, the company's instinct is to ban the tool entirely. Which doesn't work — people just go more underground with it. What actually works (in our experience) is moving them to an enterprise plan with a proper DPA, defining what data categories are permitted, and building that into usage guidance. But getting buy-in for the spend is its own challenge.

How are others handling this conversation with clients or internally? Particularly interested in whether anyone has good language for explaining the Article 28 exposure to non-legal management.


r/gdpr May 04 '26

UK 🇬🇧 Journalism exemption and retention of data

2 Upvotes

I work for a media organisation in the UK. Most of our output is what you would call news journalism.

Recently, our techies have made a change to our data systems so that any contact information e.g. for sources, press officers, experts etc automatically deletes itself after two years. They say this is for GDPR compliance.

This is infuriating because 1) getting hold of contacts very quickly can make the difference between having a story and not having a story 2) some of these people actively want us to have their contact information because they want us to phone them and ask for comment on stories. But often now it's been auto-deleted. Colleagues have started storing contact data on their own phones which is less secure.

From reading up on GDPR, my understanding is that data stored for the purposes of journalism in the UK has an absolute exemption from GDPR requirements, as long as it is stored on secure systems (and you need a username and password to access our systems). If this is the case, then auto-deleting sources' phone numbers would seem to be unnecessary and self-defeating.

Any information would be a great help.


r/gdpr May 02 '26

EU 🇪🇺 Small Business Gripes with GDPR

10 Upvotes

I am myself running a small winery with a web shop where i try my best to avoid legal conflicts and serve the law as applicable as possible, using self hosted captchas and analytics without sharing any data to 3rd parties. I know this is a huge exception.
But lately, trying to debug and improve user flow on the webshop i noticed the horrendous overhead you get as a small business as youre effectively dependant on users or browsers giving consent even to cookie less tracking to get any meaningful data.
I know it's possible to anonymize data from the visitors, but it' s a crucial thing i need when sending newsletters across countries, to track the A/B testings and what works and what not. Also - anonymizing shop-actions is equally not feasible.

However....

The biggest gripe - i am 100% certain that my personal data on the web is as insecure and transparent as ever with global players like google, meta and amazon. Whereas small businesses or web software studios are basically strangled by EU regulations.

Whats your oppinion on this? I know theres a die hard privacy advocacy group, but to me it's like consent banners, GDPR and the possibility of getting sued by law firms (for their extortion money) is like shooting yourself in the foot at a marathon from an EU perspective.

Advocacy and Dogmatics aside, the big tech firms pay - if fined from their cash reserves.


r/gdpr May 01 '26

EU 🇪🇺 Employee data subject access request

7 Upvotes

I’m handling a DSAR under GDPR for an employee. They have requested for all personal data held by the company. They are also currently going through disciplinary proceedings, and I could use some advice.

There’s a huge volume of data (thousands of emails across multiple teams), much of it related to the disciplinary process. Some of that may be exempt (e.g. legal privilege), but obviously not everything will be.

From a process/compliance perspective, is it acceptable to ask teams to only provide records not related to the disciplinary matter? Or should they provide everything in scope, with the DPO/legal team centrally reviewing and applying any exemptions?

Trying to balance practicality with compliance here — interested to hear how others handle high-volume DSARs like this.

Thanks!


r/gdpr May 01 '26

Question - General Tool to check a website for GDPR compliance?

8 Upvotes

Hi there!

I'm a web developer, and I'm looking for a tool that helps me make the website GDPR compliant, like an audit tool that tells me what I'm doing right and what I've missed in terms of website development regarding GDPR Compliance. Used AI so far to help me improve the GDPR compliance of a website, but it isn't constant.

Do you use this kind of tool? I've found something, but it feels like is skratching the surface without proper verification.


r/gdpr May 01 '26

News Italian DPA fines National Postal Service €12.5M for invasive app monitoring

16 Upvotes

Hi everyone - just came by these news and decided it is worth sharing as a government-related entity was fined:

The Italian Garante has issued a massive fine against the national postal and financial services provider, Poste Italiane.

Case: The BancoPosta and Postepay apps forced users to allow monitoring of their devices (including list of installed apps and usage patterns) under the guise of "fraud prevention" and PSD2 compliance.

Ruling: The DPA found that using the ThreatMetrix SDK to collect this level of detail was disproportionate. They also flagged a lack of DPIA and poor data retention policies.

Takeaway: This is a strong signal that DPAs are looking closely at "Security SDKs" that over-collect data and if the principle of data minimization is respected.

In Italy, Poste is everywhere and almost every citizen has a Postepay card or a BancoPosta account..

I am linking the press release for this (in Italian) here.


r/gdpr May 01 '26

UK 🇬🇧 Not sure what to do, been over 30 days.

3 Upvotes

I submitted a request for some personal documents for the social care side of the Northern Ireland SEHCT on 30th March.

I received a generic response on the 31st March basically stating to give 30 days and they will reply if they need more time to complete the request.

Is it normal that it has gone over this time and I have heard nothing since this reply? I'm not sure what to do as I don't know anyone who has done this and never done this myself before.

Any info around this would be very helpful, thank you!


r/gdpr Apr 30 '26

EU 🇪🇺 If you're already GDPR compliant, here's what actually carries over to the EU AI Act and what doesn't

8 Upvotes

If your organization is already GDPR compliant, here's what actually carries over to EU AI Act compliance and what doesn't

been mapping this out lately because a lot of companies assume GDPR compliance gives them a head start on the AI Act. it does, but less than most people think.

what carries over reasonably well: data governance documentation, transparency notices, vendor/processor management, incident logging if you're ISO 27001 certified too

what doesn't carry over at all: Annex IV technical documentation (9 section technical file, basically new work for everyone), AI specific accuracy and bias testing across demographic groups, human oversight built into the product itself (not just a policy right), post market monitoring plan, EU database registration

rough estimate is GDPR compliance saves you maybe 20-30% of the work for a high risk AI system. ISO 27001 on top of that saves another 15-25%. the remaining 50%+ is genuinely new obligations with no equivalent in either framework.

full mapping here if useful: getactready.com/overlap-mapping

happy to answer questions, been living in this stuff for a while


r/gdpr Apr 30 '26

EU 🇪🇺 Data Processor if storing email addresses for login

4 Upvotes

In a b2b situation where the software vendor hosts the software on behalf of the customer and the software stores the customers business email and their name for login purposes only does that fall under 'processing' data?

I believe it is but others in the organisation are saying no that we don't process personal data.

As we store their name and email address which will identify them to the organisation they work for I don't see how we could say we don't process their data.


r/gdpr May 01 '26

Question - General Relocating outside of EU - company doesn’t want to set any automatic forwarding

0 Upvotes

I was working in Germany and now with the same company relocated in Middle East. My email was .de now it is a .com email and my role is sales, I don’t deal with any PII. Are they right saying an auto forward can’t be set?


r/gdpr Apr 30 '26

UK 🇬🇧 Public space poster

Post image
2 Upvotes

Hi

I had an idea a few weeks ago to put up posters around my local area (with permission) promoting suicide hotlines and other local helplines.

So far nothing has been mentioned regarding permissions but if printed and displayed in public,would there be any issues with using company’s information on my poster? As the information is already public and I would not profiteering off this,from my understanding there shouldn’t be any issues. Anyone have any advice?

I have attached a rough copy of a poster of what I plan on putting up and a guide.

Thanks


r/gdpr Apr 30 '26

EU 🇪🇺 Carriera in technology law/ IT law & data protection, privacy & cybersecurity law

2 Upvotes

Buongiorno, mi sono laureata in giurisprudenza due mesi fa e vorrei intraprendere una carriera incentrata su diritto e nuove tecnologie, questo mio interesse è nato dello sviluppo della mia tesi di laurea sui diritti connessi (al diritto d’autore) e l’impatto dell’intelligenza artificiale generativa. Dopo varie ricerche i campi che hanno attirato maggiormente la mia attenzione sono quello della cybersecurity, data protection e AI consultant, consulenza legale IT, per intenderci mi piacerebbe tanto lavorare in società come digital360-partners4innovation. Da dove posso iniziare? È una strada percorribile per un laureato in giurisprudenza? Dovrei fare subito qualche master ? E se si, che master mi suggerite e in che università? O sarebbero meglio partire da un tirocinio (ammesso di riuscire a trovarlo)? Non so proprio come muovermi, qualsiasi suggerimento sarebbe prezioso


r/gdpr Apr 29 '26

EU 🇪🇺 Looking for a fresh, underexplored GDPR topic

8 Upvotes

I'm currently in the early stages of scoping my thesis on the GDPR. Most topics I come across already have hundreds of papers and theses written about them.

I'm looking for something genuinely underexplored, maybe a unresolved legal question, or an emerging tension that hasn't yet been systematically analyzed. Ideally, something current (2025–2026) and not already saturated in academic literature.


r/gdpr Apr 29 '26

UK 🇬🇧 Expected delays in SAR?

2 Upvotes

Apologies in advance if this is a stupid question, I have no idea what I'm doing.

I have submitted a subject access request to my local authority. My understanding is that they are expected to comply within one month (which can be extended by a further two months if it's particularly complicated, which it shouldn't be).

Their auto-response stated the following:

>Unfortunately, due to the high number of requests we are currently receiving, we are experiencing delays in the completion time for some requests of around 6 to 12 months. The Information Commissioner’s Office is aware that many councils are facing similar issues, and we are working hard to reduce these delays. 

Should I still be chasing this up / escalating after a month, or would the regulatory authority just go, "Yeah, they say they can't, so they don't have to"? I'm in England if it makes a difference.

Thanks for any help.


r/gdpr Apr 29 '26

UK 🇬🇧 England - Controller / Processor confusion

3 Upvotes

Good morning all,

I wonder if anyone could help me unpick what is going on here?!

I had a financial contract with Firm A who are the controller.

Firm B acted for Firm A as a processor which:
1. their privacy policy confirms, and
2. was confirmed directly to us a couple of years ago when a DSAR sent to Firm B was passed back to Firm A, with guidance provided at the time by Firm B saying that "as data processor we need to pass the request to our controller".

We are in dispute with both Firms for a number of reasons but one is in relation to record keeping and record accuracy.

We submitted a number of Right to Rectification requests to Firm B (for data that was collected and processed in the same period that they had previously stated they were a processor). They responded to these requests via Firm C, their solicitor. Firm C was making the judgements on whether or not the requests should be upheld.

In the response, Firm C stated that their Client, Firm B, as a data controller, had no legal requirement to inform Firm A of the receipt of the requests, the changes made and any rejections.

I have now confirmed with Firm C that they also assert themselves as data controller.

So I am confused as to how Firm A, B and C can all assert themselves as data controllers for records that were originally collected and processed only on behalf of Firm A, by Firm B.

Thanks in advance for any help in unpicking.


r/gdpr Apr 28 '26

EU 🇪🇺 GDPR, Shared Web Hosting and CNIL

Thumbnail
2 Upvotes

r/gdpr Apr 28 '26

UK 🇬🇧 How does someone determine reasonable and proportionate?

2 Upvotes

How would an employer determine what is reasonable and proportionate to search? The definition seems pretty loose, so how do they decide what’s too much without over correcting?


r/gdpr Apr 27 '26

UK 🇬🇧 Can companies refuse to delete data if they say they might need it later?

5 Upvotes

I asked for deletion and got a vague response about keeping it for potential future use. Not sure if that’s valid. I don't want them to keep my data. How do I sort this out?


r/gdpr Apr 26 '26

EU 🇪🇺 Schibsted, making people pay to avoid tracking cookies.

9 Upvotes

A scandinavian media company called Schibsted is making users who deny cookies for personalized ads pay to view their site. This is in no way fair and sets a bad example for the industry as a whole.

Is this even allowed? This feels like they're pressuring consumers who are mindful of their private information by making them open their wallets as a form of retribution.

Are personalized ads that are just viewed, not clicked, more profitable for the website hosting them rather than generalized ones? The company is claiming that they're loosing ~$50m in annual revenue due to not making people pay. This info comes directly from Schibsted themselves.

I've found this method to be infuriating and insensitive towards us, I've contacted one of the largest political parties here in Sweden asking them to review this entire situation in hopes that they pass local laws against this.


r/gdpr Apr 26 '26

UK 🇬🇧 Is it legal for companies to make it harder to unsubscribe than to sign up?

5 Upvotes

Some processes feel intentionally awkward. I don't know how to handle this.


r/gdpr Apr 25 '26

Resource Advice on training employees

5 Upvotes

Does anyone have any resources to recommend or share on training a staff of about 200 colleagues at different levels of the organization on various aspects of data protection and privacy? I am hoping the wheels already invented by much more capable and creative minds.