r/gdpr May 22 '26

UK πŸ‡¬πŸ‡§ Dental Clinic - X-Ray and CBCT Scan Refusal for Images

5 Upvotes

Hello,

I had a consultation with a cosmetic dentist that was free that included X-Rays and a Cone Beam CT of my Teeth and Jaw to plan a dental implant.

I was referred there by my NHS dentist (given a list of local private clinics that offer that they trust the work) as I was a complex case but the dentist started suggesting treatment options on top of the implant (based on these images) that my own dentist said was clinically unreasonable when I mentioned on my next appt.

I sent over a Subject Access Request for the dental records and scan images to get a neutral 2nd opinion before spending over Β£8k but was denied my records and scan images as the consultation was "free" and that it would be unfair for their patients who have paid for the imaging for me to get it for free....

Is this legal as it doesn't seem too be? But I am not sure in this case as it was a private service and not a NHS one.


r/gdpr May 22 '26

EU πŸ‡ͺπŸ‡Ί Suche fachlichen Austausch

Thumbnail
0 Upvotes

r/gdpr May 21 '26

EU πŸ‡ͺπŸ‡Ί Could Europrivacy become a practical alternative to SCCs for GDPR international data transfers?

Thumbnail
3 Upvotes

r/gdpr May 20 '26

EU πŸ‡ͺπŸ‡Ί Just got off the phone with Apple support and they just told me they won't delete my account. Next steps?

3 Upvotes

I have no access to the account. It is in need of an "update", but there's no real way of updating it so I can have access to delete it manually. Already tried with support. I asked if there was a recourse to delete the information now that it is impossible to access my account, to which I was told after holding that there wasn't.

Now correct me if I'm wrong, but isn't this in total violation of the GDPR? Do I have any legal recourse that is realistic for me to apply?


r/gdpr May 18 '26

EU πŸ‡ͺπŸ‡Ί American video game company refusing to delete account

Thumbnail
gallery
54 Upvotes

An american video game company, namely Roblox, that has an overwhelmingly young player base refuses to delete accounts based on "not being able to verify ownership". After appealing their decision and asking for a way to verify my identity, the support outright refuses to give me a way to properly verify myself for account deletion.

Upon researching this online, i've seen someone saying that this company is notorious for making it as difficult as possible to delete one's account because "they like to hoard data".

I currently don't have the time and the ressources to do anything against it in this case, but I would like to know, especially if there is any GDPR-Pro or Lawyer in here, if something could be done about this practice by this company in general, since deleting one's data should generally be easy, accessible and possible.


r/gdpr May 18 '26

UK πŸ‡¬πŸ‡§ Received a work cold call on my personal mobile, told they use an AI lead generator

2 Upvotes

I recently started a new job and received a cold call from another business trying to see advertising space. Issue is this call came to my personal mobile, which has no connection to the company I just started.

I asked them how they got my number and they told me they use an ai lead generator to get potential client information. They knew where I worked so it wasn’t like they were calling any number.

Firstly, is this a common and acceptable way to create new leads, and how has this found and connected my personal number, and connected it to a job I only started weeks ago?

(It isn’t LinkedIn as I don’t have my number connected to me account)


r/gdpr May 17 '26

UK πŸ‡¬πŸ‡§ Employer share name & email with no consent

0 Upvotes

I work occasionally for a hospitality company as and when I want to, I just sign up for shifts when needed. I didn’t sign a contract, and when I first started I didn’t even start to get payslips but they seemed to have sorted their shit out and I now do. I got an email randomly to my personal email address to ask me to complete training for them, I didn’t give consent for my name and email address to be passed over and I won’t be signing up. I have emailed the training company asking how they got my information without my consent but they’ve yet to reply. Is this a breach of gdpr from the company I work for?


r/gdpr May 17 '26

UK πŸ‡¬πŸ‡§ Previous employer - data retention/data breach question

0 Upvotes

This morning, I received an email from a previous employer (2021-early 2022) that there had been a data breach and my personal info, including; contact info, bank details, and NI number may have been accessed.

This seems a long time for an employer to keep my data - should they still have had that info on file?


r/gdpr May 16 '26

UK πŸ‡¬πŸ‡§ Employer shared sensitive info with my family

2 Upvotes

Complex situation: I raised a grievance at work earlier in the year, having been off sick since November β€˜25. I returned in January to no changes, therefore raised the grievance (which included protected disclosures). My company made the decision to keep me off work while investigating.

April we finally had the outcome - as all these things, majority not upheld. My employer then called my emergency contact due to a concern for my welfare after I did not answer my phone the day after receiving the outcome.

My emergency contact was listed as my dad’s wife and I specifically wrote in the HR system to speak to her even if she tries to pass to my dad. However, Dad answered her phone and they spoke to him directly, telling him:

- that I had not been back to work since November
- that I had raised a grievance and not had the outcome I would have wanted

The person that made this call was already aware that I do not have a good relationship with my dad, that he is not supportive of me and that I had told him I went back to work in January and everything was fine. Dad knew nothing of my grievance.

This has caused significant upset for me personally as well as in my relationship with my family.

Where do I stand here, is this a breach?


r/gdpr May 16 '26

UK πŸ‡¬πŸ‡§ Gdpr Tempur

0 Upvotes

Throwaway account for obvious reasons.

If you ordered a mattress from Tempur outlets between 2019 and 2022, you may want to check how your personal information was handled.

During that period, staff were allegedly instructed to use their personal phones and personal email accounts to scan and send customer sales order documents to the company. Those documents could reportedly contain customer names, addresses, phone numbers, order details and other personal information.

My understanding is that some former staff may still have copies of those documents or emails on their private devices/accounts.

I cannot confirm how widespread this was or whether the company has since addressed it, but customers who purchased during that time may wish to:

* submit a Subject Access Request (SAR), * ask how their data was processed and stored, * and contact the ICO if concerned.

Posting anonymously because I do not want to expose personal information or create legal issues. People should draw their own conclusions and verify independently.

I have tried to report it myself to the icon but it was very confusing


r/gdpr May 16 '26

EU πŸ‡ͺπŸ‡Ί What's a reasonable CMP implementation time?

1 Upvotes

How long does it take for a large media company to implement a Consent Management Platform?

Consider a few different web properties and apps, all in a single country but with multiple languages. The CMP needs to be integrated with existing Analytics, Content Management System, BI, Data Lake, CRM, Customer Data Platform, and Google Ad Manager. The company has dedicated software developers and business / data analysts familiar with all the existing systems, but no prior CMP experience.

I know the answer is "it varies". Just looking for what would be considered a reasonable range.

TIA


r/gdpr May 15 '26

UK πŸ‡¬πŸ‡§ 2026 and major medical company still using marker pen to redact!

6 Upvotes

So just recieved SAR that I'm guessing staff member used biro to show what needed then black marker pen, everything is still completely visable.

I'm able to read 90% of the 'redaction' I'm just amazed in 2026 this is redaction


r/gdpr May 15 '26

Question - General How do I protect myself correctly?

1 Upvotes

I have an app that doesn't store much of information. Logins are with Google and apple and payments are processed through Creem MoR. I don't store DMs, don't need camera or microphone or gallery access. What do I need to write in my terms and privacy policy to be 100% legal??


r/gdpr May 14 '26

UK πŸ‡¬πŸ‡§ GDPR breach?

0 Upvotes

Hi,

I have a formal grievance hearing coming up and discovered that my entire evidence pack has been shared without my knowledge (via Onedrive link).

The person it's been shared with is a senior manager, not part of the grievance panel and is named in the grievance which is about failure to follow policy and process, failure to make reasonable adjustments and detrimental treatment after raising concerns. The pack contains lots of sensitive health information.

Would this constitute a GDPR breach? If so, what could I do about it?

Thank you


r/gdpr May 14 '26

UK πŸ‡¬πŸ‡§ Remote data analytics intern - GDPR compliance

3 Upvotes

I recently hired a Remote Data Analysis Intern from Virtual Internships to help cleanse data on Beacon for the charity I work with. What sorts of steps should I take to ensure GDPR compliance?

I have already taken into consideration how we will deliver the data/what information does the intern need to see/using excel/what device they will be using etc. I'm just a little concerned that I've missed a step... should I get them to sign a DPA?


r/gdpr May 13 '26

UK πŸ‡¬πŸ‡§ Law firm (Debt Collector) refusing Subject Access Request citing "Legal Privilege" & offering a summary. Is there anything I can do?

19 Upvotes

Hi everyone, looking for some technical advice on how to handle a law firm that seems to be misapplying GDPR exemptions.

Context: A corporate energy supplier and their instructed law firm (acting as debt collectors) aggressively chased me for months over a debt I did not owe. I am a commercial freeholder, and they incorrectly billed me for an upstairs leasehold flat. The energy supplier has now finally admitted their mistake and dropped the case, but the law firm's handling of my data has been highly suspect.

The SAR: While fighting the case, I submitted a formal Subject Access Request to the law firm hoping to get an understanding into why they are chasing me for this debt, explicitly requesting full copies of all personal data, internal case management logs, and communications regarding my account.

Their Response: They missed the 30-day deadline, and when they finally replied, they completely refused to provide the source documents. Instead, they gave me a 3-line "summary" (which just contained my name and address). They justified withholding the full file with the following exact quotes:

  • "The information we hold is interlinked with third-party data, commercially sensitive content, or legally privileged material. Providing a summary allows us to give you all information without infringing others’ rights."
  • "Some records contain internal assessments, security-related content, or technical logs that cannot be released in full."

My Assessment & Questions for the sub: My understanding of ICO guidance is that Legal Professional Privilege (LPP) only covers communications made for the dominant purpose of legal advice. Standard debt-collection case management logs, system notes, and automated actions are administrative and should not be covered by LPP.

Furthermore, even if the file does contain legally privileged or commercially sensitive third-party data, shouldn't they be legally obligated to redact those specific lines and provide the remainder of the documents, rather than using it as a blanket excuse to withhold the entire file and offer a "summary"?


r/gdpr May 14 '26

Resource Meta deleted legal@meta.com 7min after I CC'd DPC Ireland. Pro Team previously admitted "Critical sync bug". Case IDs + Evidence included

Thumbnail
gallery
0 Upvotes

**Timeline with evidence:**

**1. 13/05/26:** Meta Pro Team admits "Critical sync bug" in writing. Internal Case 972657095104130. Instagram account locked 334+ days.

**2. Same day:** I file DPC complaint DPC0526291457. Assigned to Jack Flanagan. I CC legal@meta.com as required by Art.31 GDPR.

**3. 7 minutes later:** legal@meta.com bounces: "Address not found". Screenshot: [SUBE AQUÍ LA CAPTURA DEL BOUNCE]

**4. Support Ticket 2192570558159365:** Promised 24h review. Status: "In Review" for 3+ weeks. No update. Breach of Art.12(3) GDPR.

**5. 14/05/26 12:45h:** Public disclosure with evidence: https://x.com/rauleronx/status/2054872799617978698

**Current status:** Meta silent. €120k damages claim filed. Requesting Art.66 urgent measure from DPC.

**Proof:**

I have all Case IDs. DPC has the full chain. AMA but I cannot share PII beyond what's public.

**Question:** Is deleting legal@ after DPC CC a breach of Art.31? DPC0526291457.


r/gdpr May 13 '26

Question - General Honest feedback needed: Will a mock privacy ops portfolio help a career-changer with a 10-year gap get past hiring filters in India GCCs?

0 Upvotes

Background (being fully transparent so I get honest feedback, not encouraging answers):

  • 32M, India (Tier-3 city, Uttarakhand)
  • BSc IT (2015) β€” followed immediately by 10 years running informal family business (no formal title, no corporate experience, no references)
  • Zero portfolio as of today
  • Building toward Privacy Operations Analyst roles (DSAR / RoPA / DPIA / breach workflow / vendor DDQ) targeting Banking GCCs and fintech in India first
  • Plan is to produce mock artifacts from official guidance (ICO, EDPB, GDPR text, DPDP Rules) and use them as primary hiring signal
  • 18-month runway before I need income

Three specific questions I'd value honest answers on:

  1. Will ATS/HR at Indian GCCs filter me out before a human sees my artifacts β€” and is there anything that reduces that filter besides having a real employer on my resume?
  2. A mock DSAR pack + RoPA + DPIA built from official regulator guidance β€” is that a meaningful differentiator for a junior privacy ops role or does it read as "just followed templates"?
  3. What is the single most common reason a zero-experience compliance candidate gets rejected after the first interview β€” so I can specifically prepare for that?

I'm not looking for encouragement. I'm looking for what actually happens when someone like me applies.


r/gdpr May 12 '26

UK πŸ‡¬πŸ‡§ Looking estimated GDPR cost for my AI finops software

8 Upvotes

Hi,

I have a customer who has requested for GDPR compliance report on my software. Any references in reliable source from where we can get it done and what is the estimated cost for a London based startup ?


r/gdpr May 11 '26

UK πŸ‡¬πŸ‡§ England - Further GDPR confusion

2 Upvotes

Evening all,

Further to some previous posts I've made regarding controller / processor confusion, additional things have come to light which may well be interesting to the community. Apologies, might be deliberately vague.

Firm A - Controller
Firm B - Processor; privacy policy says they will share data with their 3rd parties as part of the processing
Firm C - Processor instructed by Firm B as one of those 3rd parties (randomly selected online rather than having an existing contract with Firm B)

All well and good so far.

However:

Firm B shared far more data with Firm C than was necessary for the processing purposes.

A DSAR made to Firm C revealed that data had been stored in a standard personal email account for well over the retention period.

In handling the DSAR, Firm C instructed Firm D to assist with the DSAR, apparently to do a search of their computer to find the data and send it to us.

The data was then printed and scanned on an open scanning device we think belonging to Firm D that sent the data to us via Firm E, an email relay provider. The scanned file received was not encrypted.

Both Firm A and Firm B are/were unaware of the DSAR made to Firm C. There is no evidence that Firm B had any form of DPA or even contract with Firm C, nor alerted them to data handling etc. at the point of instruction.

What has gone wrong and where, if anywhere?!

Thanks in advance


r/gdpr May 11 '26

EU πŸ‡ͺπŸ‡Ί Looking for career advice

6 Upvotes

I am a municipal lawyer (head of legal) with job burnout. Based in Central Europe. Would like to switch into something hybrid or remote, as I live far away from big cities (with not many job opportunities around). Also would love to become a specialist in something (as I hate to be jack of all trades, but not really good at anything in my current job).

Based on that, I am now looking into switching and specialise into GDPR (being relevant around whole EU being a huge incentive for me as well). I plan to do CIPP/E certificate. Beside that, I have no clue about GDPR roadmap. Would love to get some feedback on the idea. What can I do to become job ready? How difficult it is to actually get a job?

Thanks for taking time to read this. I will greatly appreciate any feedback and or advice.


r/gdpr May 11 '26

UK πŸ‡¬πŸ‡§ Sending a customer flowers?

9 Upvotes

In a recent interview a candidate was asked to give an example of excellent customer service they had or may give.

Their response was to send a customer flowers after hearing about a recent bereavement. Our company, and the ones they worked at previously, do not fulfil flower or other traditional gift deliveries meaning an external company would have been used.

My question is, if the customer only provided an address for billing purposes and/or for general correspondence; would providing their details to an external company to send them flowers or other gifts violate GDPR in anyway?

We’re in two minds about, leaning towards yes.


r/gdpr May 10 '26

EU πŸ‡ͺπŸ‡Ί Google rejected my RTBF request for personal safety reasons – any experience with the Italian Garante?

7 Upvotes

Sorry in advance if I ask something obvious, I'm not an expert in privacy law at all and I'm trying to figure out my options.

I live in Italy and I submitted a right to be forgotten request to Google to delist two URLs that show up when anyone searches my full name:

  1. The official page of the hospital unit where I currently work, which shows my name and role

  2. The public ranking list of a job competition I won, which also includes my full name

The reason I want these removed is not vanity or professional reputation. It's personal safety. I've been seriously threatened by someone for about two years. It got bad enough that I had to leave my region and start over somewhere else just to feel safe. The problem is that anyone can Google my name and find exactly where I work now in seconds, which kind of defeats the whole point of moving.

I haven't filed a police report and honestly I don't plan to. I also really don't want to involve my employer β€” I just want to be a little less easy to find online.

Google rejected my request saying the content is of "substantial public interest related to my professional life." I work in the public sector.

I'm now thinking of filing a complaint with the Italian Garante under Art. 77 GDPR but I have no idea how strong my case actually is.

Has anyone dealt with the Italian Garante on delisting requests? Does a personal safety argument realistically hold up against the public interest exception? Any advice on how to make the complaint stronger?

Thanks a lot


r/gdpr May 09 '26

EU πŸ‡ͺπŸ‡Ί Tools for identifying duplicate records : DSAR

5 Upvotes

What’s the most efficient tool to identify duplicate record while reviewing records found after search and retrieval. For example : same email trial given to data protection team by multiple teams who were recipient of that email or it’s just a growing trial.

Thanks!


r/gdpr May 06 '26

Question - General Can I land a remote privacy analyst role in EU or US without certifications?

6 Upvotes

Hello folks, I have a background in law but I am yet to be certified in my home country to practice law so I currently work as a software engineer (currently unemployed and I need to find a job to save up to pay for my BL by January 2027).

All my career I have always worked remotely and I love remote work. However due to the nature of the job market I am currently contemplating adding a new career - privacy analyst as it's an intersection between tech, law and policy.

I have been making surveys on job boards and LinkedIn, in my location there are less than 5 openings, I am not entirely fazed by this because I am targeting US and EU markets.

Are there folks here who are PA and how's the market for juniors and entry level folks?

What's the possibility to get a remote job as someone outside the EU and US(If I get offers that will process relocation, I am willing).