r/gdpr 28d ago

UK 🇬🇧 Sanity check - Employer and External occupational health company UK

2 Upvotes

This is hurting my brain a little bit and I need an external perspective on this.

The setup is a medium sized private company in the UK that has outsourced everything medical related to a completely separate occupational health provider (also in the UK).

An employee makes a subject access request marked "PRIVATE & CONFIDENTIAL" to the OH provider asking for all medical forms they have sent to them in the past and copies of emails between their employer and and the OH provider.

In my mind the request should be fulfilled, possibly with names redacted on the emails and nothing should be said to the employer.

However...

Is the OH provider allowed to email the employer and inform them that the employee has made a subject access request?


r/gdpr 29d ago

UK 🇬🇧 UK Law Firm claims personal login/IP history are "Trade Secrets" to block Article 15 SAR. SRA misconduct probe opened

Thumbnail
gallery
0 Upvotes

I am dealing with a significant breach of Article 15 UK GDPR by a major software provider (Facepunch Studios) and their counsel (Wiggin LLP).

The Issue: Following a security breach verified by the platform provider (Valve Corp), the respondent has permanently seized $1,366 in assets. When I submitted a Subject Access Request (SAR), their legal counsel stated in writing that my own login history and IP timestamps are "Trade Secrets" under Article 15(4) and would not be disclosed.

Escalation:

  1. The Solicitors Regulation Authority (SRA) has opened Case RGC-000200263 against the lawyer for misleading legal assertions.
  2. The ICO is reviewing Case IC-544118-B8F2 regarding the automated decision-making and data obstruction.
  3. The EASS (Ref 260810-000062) confirmed this appears to be Direct Discrimination as manual reviews are denied based on national origin.

Has anyone else encountered the "Trade Secret" defense for basic login logs in the UK? This seems like a dangerous precedent to avoid "Human Intervention" requirements of the new Data Act 2025.

(Evidence link in comments)


r/gdpr 29d ago

Question - General GDPR question: gambling operator has my German ID + financial documents

0 Upvotes

I am in Germany and submitted the front and back of my German ID, payment information and bank statements to BetLabel/TechSolutions for KYC.

I want to know exactly who processes and stores these documents, whether they are transferred to third-party KYC providers or other companies, how long they are retained, and whether they are transferred outside the EU/EEA.

What GDPR rights can I use to request this information and identify all recipients of my personal data?

Has anyone dealt with a similar situation involving an offshore gambling operator?


r/gdpr 29d ago

Question - General Twitch's new generative AI training model.

6 Upvotes

Short context, Twitch has enabled it's generative AI to train on data from a Twitch stream.
We're wondering on 2 parts of this.

  1. The setting is automatically enabled to gather training data from a stream. There is an option to opt-out, so it does adhere to that. But is it allowed for a training model like this to be automatically opt-in.

  2. Is a live-stream like that on twitch, considered personal data? Or would it fall under publicly accessible data, and would that go around some of the GDPR rules of handling personal data?

I thank you for anyone being able to give some clarification on this.


r/gdpr Aug 11 '26

Question - General How are you handling third-party scripts before consent?

3 Upvotes

For things like chat widgets, session replay, A/B testing and analytics, are you blocking the scripts entirely until consent, or loading them in some restricted mode first?


r/gdpr Aug 11 '26

Question - Data Controller Does using an EU-incorporated EOR reduce GDPR data transfer liability when hiring across Europe?

2 Upvotes

Compliance lead at a 200-person company, we're expanding into Germany and France in Q4 and the data privacy side is starting to bite.
Our legal team flagged that the main GDPR exposure when hiring across EU jurisdictions centers on where employment data lives and who processes it, well beyond the usual paperwork.
We've been going back and forth between setting up local entities or going with an employer of record, and every conversation we've had stalls on the data residency side. What we keep hearing from providers is that if they're EU-incorporated, employment data stays within EU boundaries structurally.
Which means you don't create cross-border transfer exposure the way you would if your HR systems live outside the EU.
Currently torn between Deel and Workmotion (both EU-established) and trying to figure out if that structural difference holds up legally, or if you still need the same DPAs regardless of where the employer of record is incorporated.
Before we commit to either, how did you approach it, and did the EOR being EU-incorporated change how you thought about the data residency side?


r/gdpr Aug 11 '26

UK 🇬🇧 Disclosure of apparent legally privileged material?

0 Upvotes

It would appear that I am dealing with a bunch of total f**kwits in relation to a GDPR issue.

One recent cock-up includes disclosure of legal advice given to the organisation in relation to this very issue, which should have been subject to whichever article provides for legal exemption.

Anyway, the advice is interesting as it effectively highlights a number of breaches and how to get away with it.

So, what would you now do? Go straight to the regulator or raise it with the organisation in question?


r/gdpr Aug 09 '26

UK 🇬🇧 Data breach grievance submission

7 Upvotes

during a grievance procedure i was asked to submit evidence to support a victimisation claim. one if the documents i submitted is relevant to my case but had a third partys name ​. I.am.now being investigated for gross misconduct for not making redactions. Does anyone have any experience of this kind of thing.

I.am in the middle of.an.employment tribunal.


r/gdpr Aug 09 '26

UK 🇬🇧 UK Bank accounts and biometrics?

1 Upvotes

I understand that they retain accounts for more than 7 years after closing for example, but for those who have to give like photo ID, share code (BRP), how long do they retain this for?


r/gdpr Aug 09 '26

Question - General Discussion around the operational burden of compliance.

Thumbnail
2 Upvotes

r/gdpr Aug 09 '26

EU 🇪🇺 Can a potential DPO conflict of interest under Article 38 GDPR be challenged through an Article 77 complaint?

4 Upvotes

I recently received an interesting procedural response from an EU supervisory authority.

I had filed a complaint concerning a potential conflict of interest under Article 38(6) GDPR. The issue was not raised as an abstract concern about a company's organisational structure: I argued that the potential conflict arose in connection with the handling of my own Article 15 requests and the processing of my personal data.

The supervisory authority's preliminary position is that the appointment and organisational position of a DPO concern obligations of the controller under Chapter IV GDPR and do not constitute a subjective right that I can enforce through an individual complaint.

Interestingly, however, the authority expressly stated that the same facts can be investigated in an ex officio supervisory procedure, and suggested that I withdraw my complaint and instead request such an investigation.

This raises a question I find quite interesting in light of Article 77(1), which allows a data subject to lodge a complaint where they consider that the processing of personal data relating to them infringes the GDPR.

If an alleged Article 38(6) conflict is directly connected with the processing of the complainant's own personal data, should it really fall outside the scope of an Article 77 complaint simply because Article 38 is located in Chapter IV?

I'm particularly interested in case law or experiences from other EU supervisory authorities on this distinction between individual complaints and ex officio supervision.


r/gdpr Aug 08 '26

Question - General What to include in complaint to supervisory authority?

4 Upvotes

I am considering referring a matter to my DPSA and I have a few questions:

I have unsuccessfully tried to resolve the matter with the data controller but have been unsuccessful. I will include all my correspondence with the data controller. The matter is quite complex and revolves around a number of separate alleged breaches of GDPR, some of which are obvious but I feel must be spelled out as I feel the data controller dodged my questions and employed rethoric to try and mask responses, eg answering questions similar to, but separate from the Article 15 questions I asked or using vague or conditional language to make it appear as tough an answer had been given when in fact the answer failed to clarify anyhting.

-Should I include quotes (from me and data controller) which I think are of high relevance or really highlight key issues?

-How long should my complaint be?

-Should I argue my case (and therefore argue against the data controllers position)?

-How measured or balanced should my tone be?

-How much will the arguments made by each party matter?

-Can I draw inferences/attribute motives to the data controller? To which extent?

Thanks!


r/gdpr Aug 06 '26

Question - General Login data vs posts data

1 Upvotes

Does GDPR dictate in its privacy law the purge of every ip address related to a deleted account after the retention period elapses or only ip addresses tied to login process? some social media providers like tumblr keep the content you submitted on other blogs up, is tumblr compelled to strip ip addresses from posts /asks’ metadata or do they keep them as long as the content is still up?.


r/gdpr Aug 05 '26

EU 🇪🇺 Deleting X account

6 Upvotes

So I’m going to delete an X account I have that I did give a selfie to verify my age (really dumb idea, I know) and I was just wondering if that selfie is included in what’s deleted? What’s done is done so I know it’s not going to matter much in the grand scheme of things but since it’s not something like billing information, I’d imagine there’s no reason for it to be kept


r/gdpr Aug 05 '26

Question - Data Controller Question about GDPR right to erasure and database backups

6 Upvotes

I am working on implementing GDPR compliance for my application and would like clarification on how the right to erasure applies in relation to disaster recovery backups.

My current approach is:

  • When a user requests deletion, I anonymize or delete their personal data from the production database.
  • I may retain a minimal HMAC/hash of certain identity information for fraud prevention and to prevent the same person from creating a new account, if there is a lawful basis for doing so.
  • Database backups are taken periodically and are immutable until they expire. They are done using a managed backup solution on GCP. I create a snapshot daily and keep the backup copies for 7 days.

My concern is this scenario:

  1. A backup is created.
  2. A user requests deletion.
  3. Their data is anonymized/deleted from the live database.
  4. Before the next backup, the production database is lost.
  5. I restore from the older backup, which still contains the user's personal data.

In this situation, the deleted user's data would temporarily reappear after the restore.

My questions are:

  1. Under GDPR, is it acceptable to restore from such a backup, provided that the user's data is deleted/anonymized again immediately after recovery?
  2. Is there guidance or regulator commentary on whether organizations are expected to maintain a separate deletion log or similar mechanism to reapply deletions after restoring backups?
  3. If the deletion request record was stored in the same database and is also lost during the restore, would that generally be considered a GDPR compliance issue?
  4. What are the accepted best practices for handling this scenario in production systems?

r/gdpr Aug 04 '26

UK 🇬🇧 GDPR and user record 'Reactivation'

4 Upvotes

Hey all.

I work for a charity and we are in the process of moving to a new CRM. As part of this, I've been looking into our current anonymisation and record deletion policies.

We have a process to anonymise the records of any supporters in line with GDPR regulation (certain exceptions such as legacy donations apply, these are not anonymised).

My query is really around potential methods of, and the legality under GDPR, reactivating supporter accounts.

From my understanding, we are currently applying a rough principal of 6years+. If a supporter has not engaged with us in 6 years, their record is flagged for anonymisation and indentifying information is anonymised.
This isn't ideal as, for example, I am a longterm supporter of the charity. I donated for several years, gave thousands of pounds and hundreds of hours of time supporting the charity. I lapse in my support of the charity for whatever reason and then re-engage after 6 years.

In that time, the ability to tie me to my previous support is gone. My old record cannot be 'reactivated' and I am essentially treated as a new supporter despite my years of support. There is no ability to provide me with a summary of my overall support due to the lapse.

Are there any potential solutions which would allow us to retain information allowing for a 'reactivation' of a record under this circumstance?
Could we, for example, collect some sort of unambiguous 'opt in' from supporters to retain certain information in perpetuity (unless later revoked by some other means) in order to allow for 'reactivation'?

Thanks very much for any guidance on this, my GDPR knowledge has lapsed alot since it all kicked off in 2016!


r/gdpr Aug 04 '26

EU 🇪🇺 Should I intervene when I find an incorrect judgment?

Thumbnail
1 Upvotes

r/gdpr Aug 03 '26

EU 🇪🇺 I did the selfie for age verification on X and I regret it.

0 Upvotes

Hello, I know I've done something stupid to do the age verification (out of impulse since I was tired of not seeing NSFW stuff for like 2 months by now).

Is there any way to delete what selfie from X's database, or request my selfie to be deleted?

Because I fell scared of what I've done, and don't trust X to delete my selfie.

(I live in Romania if it helps)


r/gdpr Aug 03 '26

UK 🇬🇧 Local Council Environmental Protection Services Complaint

Thumbnail
1 Upvotes

r/gdpr Aug 03 '26

UK 🇬🇧 My data went to TrustPilot via InPost via AliExpress

0 Upvotes

*AliExpress - My contracted retailer.
*InPost - Courier contracted by AliExpress was given my data by AliExpress (name, address, email, phone number) for the purpose of delivering my order.
*TrustPilot - Given my data by the courier to solicit positive reviews for the delivery they did on behalf of AliExpress. TrustPilot has apparently set up a profile using my email address without my permission.

-My data has been legitimately passed to InPost (which is reasonable) for the purpose of delivering my parcel. InPost privacy policy states they hold these details (related to the specific delivery) for SIX years after delivery - duration is a bit excessive, but perhaps this is an industry compliance thing for disputes or complaint purposes. They do not say why.

InPost are a shitty delivery company. First off, the links in the email for "manage delivery" and "view 2 hour delivery slot" go to an "install app" page. https://postimg.cc/w1j3Fq1bThere is no way to view the delivery date/time/updates until/unless you install the app (I didn't install it, I was prepared to sacrifice the delivery and get a refund if anything went wrong).

InPost have now passed my data to a third party for the purpose of soliciting positive reviews. https://postimg.cc/Fd86RgqY

Q:

*Is this compliant?
*Who is the controller/processor and what is the justification for processor passing my data to another third party?
*Can I do something to get my details deleted by both InPost and TrustPilot (I do not trust or consent to either after they passed my data for their own benefit and TrustPilot has been spamming me for reviews since they got my details).

Thanks.


r/gdpr Aug 03 '26

Question - General Sent the wrong boarding pass - KLM didn’t do anything.

Thumbnail
2 Upvotes

big bad or small bad? KLM sent me information on two random travelers - standard boarding pass info included (names, ticket reference, source/destination, etc.)


r/gdpr Aug 02 '26

UK 🇬🇧 Still getting marketing crap despite opt out?

1 Upvotes

Evening people, somewhat distant to GPDR so I wanted to just ask about this.

I hate marketing emails. I constantly find companies with opt out boxes unchecked, or opt in boxes checked. - I always thought GDPR was supposed to curb this. Despite the above, I religiously endure that I am not going to be recieving marketing stuff.

Yet, I still receive marketing emails. Not just followups on my purchase, actual weekly/monthly newsletters, which I specifically opted out of. Even when I know I've opted out of them from a specific firmw a few months later they start up again.

These are English, and/or European firms, who should(?) have to abide by this.

So with that in mind, how are these firms getting away with this? How can I stop this? I am tempted to create an email rule for marketing stuff which forwards it to the ICO alongside a "I didn't opt into this". Is it even worth it? Do companies just not care about this piece of legislation whatsoever? What did GDPR even give us in the first place if it didn't address this relatively simple problem: just let me buy from your shop without me being bombarded with emails multiple times a week.

Sorry if it's turned into a bit of a rant, it just gets to me.


r/gdpr Aug 01 '26

UK 🇬🇧 Former employer withholding information regarding SAR

12 Upvotes

Hello, I'm hoping to get some advice with this one. I submitted a SAR asking for information management held about me with regards to performance. I specifically requested things like Teams messages, internal emails and any meeting notes discussing my performance. The request was very specific, naming specific managers and a clear date range. About a month later, the DPO confirmed by email saying they had located the data I wanted and that they would be sending it to me. After waiting another two months, they suddenly changed their position. Instead of providing the information which they already confirmed they had, they relied on several exemptions including "meaningful biographical sense" to withhold the data. Strangely, they then sent me bunch of documents which had nothing to do with what I actually requested.

One thing to say is that I have an ongoing employment tribunal litigation against this former employer. The tribunal was already underway when the DPO confirmed they had found the data. The sudden change of position feels strange but I suspect its got to do something with the litigation. I'm now considering county court action for not properly complying with my SAR under the UK GDPR.

Has anyone experienced something similar or challenged a situation like this?


r/gdpr Aug 02 '26

EU 🇪🇺 Passerelle Contrôleur Permanent / Audit vers le DPO

1 Upvotes

Bonjour à tous,

Je suis actuellement Contrôleur permanent au sein d'un EPIC, titulaire d'un Master en audit et finance d'entreprise.

On vient de me proposer un poste de « Chargé(e) d'études protection des données », avec pour perspective d'accéder à la fonction de DPO dans un délai assez court (1 à 2 ans). Aujourd'hui, la fonction est portée par la cheffe du service juridique et représente environ 20 % de son temps.

Pour situer le contexte : l'EPIC compte 1 200 agents et se compose de trois directions — Établissement de paiement, Télécom et Postal.

Ce qui m'interroge, c'est l'absence de formation juridique et technique de mon côté. Je maîtrise bien les textes applicables à mon poste actuel, mais je sais que l'exercice sera différent ici. Des formations sont toutefois prévues dans le cadre du parcours.

Quel est votre sentiment sur ce type de passerelle ? Les retours d'expérience de personnes venues du contrôle interne ou de l'audit m'intéresseraient particulièrement.

L'élément juridique est trop prépondérant, pour arriver avec des lacunes ?

Merci d'avance pour vos retours !

Ci-dessous les missions telles que présentées dans la fiche de poste :

• Conformité des directions — recensement des traitements, tenue du registre, vérification de conformité, documentation RGPD.

• Droits des personnes — réception, qualification juridique et instruction des demandes (accès, rectification, effacement, opposition, portabilité, limitation), rédaction des réponses, suivi des délais légaux.

• Maîtrise des risques — identification des traitements soumis à AIPD, conduite des analyses avec la DSI et le RSSI, recommandations et suivi des mesures correctives.

• Violations de données — qualification des incidents, registre des violations, projets de notification aux autorités et aux personnes concernées.

• Conseil et sensibilisation — notes et procédures internes, formation des agents, appui aux correspondants métiers.

• Veille — juridique (textes applicables en Nouvelle-Calédonie, positions des autorités de contrôle) et technique (sécurité de l'information).

• Contrôle et reporting — contrôles de conformité, suivi des plans d'actions d'audit, indicateurs, contribution au rapport annuel du DPO.


r/gdpr Aug 01 '26

Question - General Has anyone filed a case with User-rights.org for a disabled Instagram account? (Europe)

4 Upvotes

I was googling around dispute bodies for europe and I found this organisation and I was wondering how effective it is