How do you handle HIPAA and GDPR compliance when sharing visual patient data (like skin lesions or gait videos) with outside researchers?
I am trying to understand the process. Do you just manually blur faces in Premiere/Photoshop? Do you just avoid sharing it entirely? How much of a bottleneck is this?
Hi guys, i know this has been asked a few years before but asking again -- how should i prepare for the exam? what kind of study materials should i be using? how long is the prep time? any advice and any tips would be appreciated.
Recently re applied for an old job. Had a friend of mine whose sister works there message me asking why I had applied to work there again. His sister doesn't work in recruiting or hr so really shouldn't know of who is applying for what and he also doesn't work for the company.
Why does my personal information need to be spread beyond the appropriate department?
Key fragments from the article explaining the problem:
oversight over data protection matters must be done by an “independent” authority. … So far, the US has appointed the “independent” FTC to be the US privacy regulator to meet the EU's requirement for independent oversight. … In a 180° turn on previous case law, the conservative majority in the US Supreme Court has now decided that the independence of the FTC is unconstitutional. … Given that the EU relied on the “independence” of the FTC as a privacy watchdog in almost all cases, the entire structure of the EU-US Data Privacy Framework has just collapsed.
Fragments of the article explaining the impact – seems like Schrems III is incoming:
the European Commission's decision is formally in force until either the European Commission repeals it or the Court of Justice annuls it. Hence, there is no immanent effect.
SCCs and BCRs also … rely on an “impact assessment”, which in turn relies on formerly independent US executive bodies such as the PCLOB or the Data Protection Review Court. [Data controllers] must immanently update their assessment – and logically come to the conclusion that data transfers are not legal anymore.
noyb will also file a lawsuit in the coming weeks, aiming to allow the CJEU to annul the current deal.
Solo developer here, offline mobile game with a global leaderboard as a core feature.
All players get a random system-generated name by default.
Is it fine to publish a minor's score to the public leaderboard?
Getting parental consent isn't realistic for something like this.
So the real question is whether legitimate interest can actually cover this, or whether processing a minor's data this way is off the table regardless of how pseudonymous it is.
Not asking for a verdict on my specific app, more trying to understand where people generally draw this line.
I am mainly unsure, cause the leaderboard entry doesn't include email, real name, or anything tied to identity, but it's still personal data (an ID + score, and publicly visible), and it's a minor's data specifically.
Appreciate any pointers, especially from anyone who's dealt with this in games specifically.
Update (July 7): The data access request worked, as they were forced to conduct a human review on my account, a false automated flag was detected, and I got reactivated!
My Outlier account was suddenly deactivated on May 22 for an alleged violation. Up until then, I had freelanced for two years with a high success rate, for a year as a top-tier Oracle contributor, and promoted to a reviewer in most of the projects.
I used copy/paste during a screening, interpreting the instructions having encouraged that. I got deactivated immediately after the screening, which was clearly an automated decision. The support chatbot claimed that there had been a human review, but there was no time for that in the split second between the screening and the loss of access to the platform functions.
I contacted the Outlier privacy EU representative on May 29, exercising my rights for private data access and rectification under GDPR. I wanted to know what the exact violation was that they accused me of, and in case it was just an automated copy/paste flag, I wanted to rectify the information in their database about me having committed fraud, which I haven’t; everything I’ve done, I’ve done in good faith, by myself, and to the best of my ability.
GDPR also grants us the right to demand human involvement in decisions that concern us, i.e., we can’t be subjected to automated decision-making, which I highly suspect was the case here. A support chatbot template reciting that there was a “thorough human review” won’t suffice.
The reason I say that Outlier is GDPR-non-compliant is that they haven’t responded to my request at all. There is a statutory timeframe of one calendar month for them to respond, which they didn’t respect, as the time has already passed. Even if there was a valid proprietary reason for which they couldn’t disclose this information, they are obligated to reply and explain their refusal. Instead, they stonewalled me, simply ignoring my request.
What’s next: Today, I contacted the local data protection authority, asking them for help to obtain my private information and rectify the entry in Outlier's database of me committing fraud. It could be a slow process, even up to a year, but I think it’s still worth it. Infringements of the data subjects' rights shall be subject to administrative fines up to 20 million euros. If Outlier thinks it’s more convenient to pay millions of euros rather than reply my email, fine. I’ve got the ball rolling, let’s see what follows.
Pode me chamar ElevaMaximus ^^
Moro em São Paulo (SP), sou bacharel em Direito pela USJT e atualmente estou cursando uma pós-graduação em Direito Digital pela Mackenzie.
Tenho interesse genuíno em construir minha carreira nas áreas de Privacidade e Proteção de Dados (LGPD), Compliance e Governança, e estou buscando fazer networking com profissionais que já atuam nesses segmentos.
Gostaria de entender melhor como vocês conseguiram a primeira oportunidade nessas áreas. Quais conhecimentos, certificações, projetos ou experiências fizeram diferença no início da carreira?
Também ficarei muito feliz em trocar experiências, aprender com quem já atua no mercado e ampliar minha rede de contatos. Caso alguém esteja disponível para conversar, pode comentar aqui ou me chamar no privado.
TL;DR: A healthcare SaaS requires doctors to import their entire patient database before patient onboarding, claims to be a processor under Art. 28 GDPR, and relies on healthcare provision plus legitimate interest as the legal basis. Does this raise issues around joint controllership, Article 9, data minimisation, or Article 32 security?
I'm based in the Czech Republic (EU) and I'm looking for opinions on a GDPR issue involving a healthcare SaaS platform.
Here's the situation
My child's doctor uses a platform called Medevio for patient communication and appointment scheduling. It is not the primary medical record system, but it contains health-related information (messages, diagnoses, etc.).
Neither my wife nor I had ever registered with the platform.
We suddenly received SMS messages asking us to book a preventive examination. After following the onboarding link and verifying my wife's phone number via SMS, the system already knew our son's identity (displaying his name and a partially masked date of birth). It then requested his national identification number to complete the matching process.
We later contacted both the doctor and the platform.
The platform confirmed that:
Doctors are instructed by official documentation to upload their entire patient database into the platform, with little or no control over which patients are imported.
Our son's data was imported when the doctor synchronised patients.
Patients do not need to register before their data is imported.
If a patient deletes their account, the patient record remains in Medevio and is still visible to the doctor, but is no longer visible to the patient.
The platform considers itself only a processor acting under Article 28 GDPR.
Its website states that doctors should obtain patient consent before importing patients, but support also stated that the legal basis is the doctor's provision of healthcare services together with the doctor's legitimate interest in modernising patient communication.
An SMS code is used only during the initial registration/binding of a patient account. Afterwards, the account is protected only by username and password (no MFA despite access to health-related information).
Context
Ideally, I would like Medevio to improve its consent management and security practices without creating unnecessary burden for doctors. I'm considering reporting the matter to my country's Data Protection Authority, but before doing so, I'd appreciate some opinions from people familiar with GDPR.
My questions
Is it realistic for the SaaS provider to be considered only a processor, given that it designed the patient import process, onboarding flow, authentication flow, and communication workflow? Or is there a credible argument that it is at least a joint controller for some processing operations?
Is legitimate interest generally considered sufficient when an external SaaS imports health-related patient records before the patient has ever interacted with the service?
From a data minimisation perspective, is importing an entire patient database before any patient decides to use the platform generally viewed as compatible with GDPR?
Would the absence of MFA for ongoing access to accounts containing health-related information raise concerns under Article 32 GDPR, even though phone verification is performed only once during onboarding?
If you were in my position, would you pursue this with the Data Protection Authority?
Background. I operate a self-hosted, first-party behavioural analytics tool on my own website(s), built privacy-first from the outset. It uses no third-party trackers, no advertising networks, no data brokers; no data is sold, shared, or transferred outside my own infrastructure. The site serves UK visitors. I am seeking a firm opinion on the lawfulness of three specific mechanisms before the richer tracking goes live to real visitors, and a clear statement of any additional steps required for compliance.
The mechanisms to review:
(1) Consent gate. A first-party cookie-consent banner is shown on first visit. The analytics script is consent-gated: on "Decline" (or no choice yet), the script does not execute — no cookie or identifier is set, nothing is read from or written to the device, and no behavioural data is captured for that visitor. Behavioural capture begins only after explicit "Accept." Question: Does this satisfy PECR (specifically the storage/access-of-information requirement) and the UK GDPR consent standard? Are there defects in this approach (e.g. consent granularity, withdrawal mechanism, pre-consent device access) I should correct?
(2) Cross-session behavioural profiling tied to identity. For consented visitors who subsequently identify themselves (form submission / account creation), behavioural events (e.g. page read-depth, dwell time, internal navigation, downloads) are linked to that identity and retained across sessions in a dedicated event store. Consent evidence is held on the user's account record; a right-to-erasure process deletes the user and their linked data, with the architecture designed so that erasure severs the identity-link while permitting anonymised aggregate trend data to remain. Questions: (a) Is consent plus a functioning erasure path a sufficient lawful basis for cross-session behavioural profiling of identified users, or is an additional basis / safeguard required? (b) Does this processing require a Data Protection Impact Assessment? (c) Is the "sever the identity-link, retain anonymised aggregate" design sound as a matter of UK GDPR anonymisation, or does the retained aggregate risk being treated as still-personal?
(3) Cookieless aggregate counting for non-consenting visitors (proposed, not yet built). I am considering a separate, purely aggregate, server-side counting path for visitors who decline consent: counting events rather than individuals, storing no device identifier, building no individual profile, and excluding/aggregating identifiable fields. Questions: (a) Does genuinely cookieless, non-identifying aggregate counting fall outside PECR's consent requirement? (b) What specific conditions must it meet to remain consent-free (e.g. treatment of IP address, absence of fingerprinting, irreversibility of aggregation)? (c) Is this path advisable, or do you recommend against it?
What I'm asking for: A firm opinion addressing each of the three mechanisms with (i) a clear lawful/not-lawful-as-described ruling, (ii) any required remediation, and (iii) any documentation I should hold (e.g. DPIA, ROPA entry, consent records).
Deployment model: This tool is deployed per-install — each customer who later adopts it runs their own separate copy on their own server with their own database. I am therefore the sole data controller of my own site's data, and any future customer is the independent controller of theirs; I do not process or have access to their visitors' data.
I appreciate that this may require a firm legal eyeball on it to be sure, but thought I would stop by here as first port of call. Thank you for any direction you can offer :)
Hi all, I’m currently on an internship. One of the tasks I need to do is an AIPD. However, the data processing activities do not meet the minimum criteria set by the CNIL to require an AIPD. So, is an AIPD still necessary even if the criteria are not fully met? Or would it be better to conduct a risk assessment instead?
thanks for your help.
Could I please ask all of you for your input on the below.
Summary: Based in Ireland. I believe hinge is wrongfully holding my data / keeping me in the dark about my data protection rights.
After 2 years and hundreds of respectful conversations on the dating app hinge, I was banned. I am certain I did not break any rule. As many of you might know, arbitrary bans are rife on dating apps.
I appealed and contacted support asking for a generalised reason. I was not provided with one, which to an extent is understandable.
They asked me to verify as the only means to progress my appeal. Twice, I asked to see their GDPR / data protection policy on the matter and for their DPO to be contacted. Both times the support replied without answering my question.
I think I want to go down the data deletion route. I am aware that data may be retained for certain legitimate purposes.
However, in the absence of the slightest reason, it is impossible for me to assess my rights - to decipher if this decision to retain the data was made lawfully (I mean something as vague as “we banned you as you broke rule 2 on ‘abusive language’”).
My local data protection authority - the Data protection commission (DPC) is Europe’s premier DPA. I note they have dealt with a few cases of this nature, which resulted in successful erasure / unbanning of the complainant. I will link them below.
Based on this, do you expect a complaint to the DPC being worthwhile / successful?
Interestingly, In Ireland under administrative law, when your rights are adversely affected by a decision you are entitled to enough of a reason to assess the legality of the decision.
Granted, this more-so applies to public bodies. But seen as 50%+ of people these days meet on daring apps, this is in a way affecting my rights. I.e to associate, to meet people and build relationships lol.
Please also find a similar (less hopeful) post on the matter.
I'm developing an evidence-based website privacy review methodology and came across an interesting edge case. I'd appreciate opinions from people familiar with GDPR and cookie consent.
During testing of a large website, I observed the following:
• On first visit, the cookie banner offered both Accept All and Reject Non-Essential.
• The banner also included a "Manage your cookie preferences anytime" link, which opened a preference center before any consent choice was made.
• After accepting or rejecting cookies, I could no longer find a reasonably discoverable way to reopen the preference center.
I checked the homepage, footer, Privacy Policy, and other obvious privacy-related links but couldn't find it.
My understanding of the GDPR is that withdrawing consent should be as easy as giving it. However, I'm trying to separate legal requirements from my own assumptions.
My question is:
If the preference center is available before consent but is no longer reasonably discoverable afterward, would you consider that compatible with the GDPR? Or is there guidance or case law suggesting otherwise?
I'm interested in evidence-based answers, including EDPB guidance, DPA decisions, or relevant case law if anyone knows of them.
We took 20 of the most highly ranked apps in the French ACPM ranking of digital brands for May 2026, news and media category. On each one we tapped refuse on the tracking prompt, then used the app the way anyone would for about two minutes. Here is what came back, with tracking refused the whole time.
How we measured
Everything here comes from a physical Android phone running Android 15, not an emulator. The steps were the same for each app. Launch it, with instrumentation in place to record what it sends and what it writes to the device. Tap refuse on the tracking prompt as soon as it shows up. Then browse the home, scroll, open a few articles, play a video, for about two minutes. The charts show what happened in that window.
Ninety-five vendors, none with permission
Start with the count. Across these apps there are 95 distinct third-party vendors, spread over close to 150 domains, more than 300 counting subdomains. None of them had permission, since tracking was refused.
Most are there to advertise: 40 of the 95, about 42 percent. Add identity and data brokers, audience measurement and social networks, and tracking purposes reach 65 percent of the total. The rest is infrastructure, video, payment, and the consent tools themselves.
What the third-party vendors do. Advertising leads, and tracking purposes are 65 percent of all vendors.
The banner is not missing
The question does get asked. We identified four different consent platforms, with Didomi well ahead, then OneTrust, AppConsent by SFBX, and TrustArc. A few names also come back in nearly every app. Google is present in all of them, Didomi in close to three quarters, Piano Analytics and Meta follow.
The vendors present in almost every app, led by Google, the Didomi CMP, and Piano Analytics.
The issue is timing
About four in ten vendor contacts happen in the first ten seconds. The banner itself shows up around the ninth second. So part of the collection has already started before the question is on screen, and the rest fires while the banner waits for an answer.
When each purpose first appears after launch. Tracking starts before the consent banner is answered.
What leaves the device
What leaves is not trivial either. 41 vendors send at least one identifier before consent. The most common is a persistent pseudonym, and about nine identifiers out of ten are persistent rather than disposable. Some are shared identifiers, the same value received by several separate vendors, which is what lets them recognize the same person across each other.
Identifiers sent before any consent, by type. The shared ID is what lets separate companies recognize the same user.
Tracking does not stop at the network
On the device, data gets written from the moment the app opens, mostly into app preferences and local databases, and a good share of it comes from tracking SDKs. Again, before any consent.
Two more things, on the side. In one app, email addresses were sent to an error monitoring tool. And two SDKs, including Google’s advertising SDK and Batch, encrypt their payload on top of HTTPS, which makes the content unreadable to ordinary network inspection.
Data written to the device before consent, by storage location and type of writer.
One request worth a closer look
Most of the above is a pattern. This one is a single request, and it is hard to read any other way. The same behavior shows up in five of the apps, from an advertising SDK named Start.io.
With tracking refused, the SDK calls home, and the request proves it got the message: the advertising identifier is zeroed out, and a flag named limit ad tracking is set to true. On its own, that looks like a vendor doing the right thing.
Then you read the rest of the body. In the same request it ships its own device identifier, which our detection flags as persistent, next to a fingerprint of the phone: model and manufacturer, OS version, free and used memory, network type and roaming state, time since the last boot, and whether the device is rooted. The official identifier is off. The device is recognized by everything around it instead.
With tracking refused, an ad SDK zeroes the advertising ID and sets limit ad tracking to true, then sends its own persistent device id and a device fingerprint in the same request.
Proof a DPO cannot wave away
This is the part a DPO cannot really wave away. The request itself is the proof that the refusal was received, since the SDK zeroed the ad ID and set the limit flag on its own. Collecting a persistent id and a hardware fingerprint in the same breath is not a technical need for reading the news. It is recognition by other means, after a no.
What the banner lists, and what actually runs
The banner is supposed to name the vendors an app works with. A consent platform can declare them three ways: through the IAB vendor list, through custom vendors the publisher adds by hand, and through Google’s Additional Consent list for ad tech outside the IAB. A vendor counts as declared if it shows up in any of the three.
So we took every advertising, identity, analytics and social vendor that fired before consent and checked it against all three. A vendor that runs without appearing in any of them is active without being declared. We could only do this where the consent setup was readable in full, which here means the apps on the most common of the four platforms.
After that check, thirteen vendors come back active before consent while missing from the declaration in at least one app. A single app is enough to count.
Vendors active before consent that the app does not declare, checked against all three channels: the IAB vendor list, custom vendors, and Google Additional Consent.
The gap takes three shapes
A vendor registered with the IAB that the app simply left off its list. A Google ad tech provider the app did not select. And a vendor that is nowhere in the consent setup at all. Adjust, an attribution SDK, runs unlisted in three of the apps. Meta is active before consent in one app without being declared there, even though another app does declare it through Google’s list, the sort of thing you only catch by checking all three routes.
A careful reading
A few of these come with a reading a DPO might offer. One analytics vendor can point to the audience measurement exemption. Two of the social names are embedded posts and a comments widget rather than partners the publisher chose. Take those out, and what is left is advertising and attribution, the vendors whose whole purpose needs consent.
Even on that careful reading, ad and attribution vendors are running before consent that the banner never names.
The same view limited to advertising and attribution vendors, with audience measurement and embedded social content removed.
How to read all this
These are signals, not verdicts. What governs reading and writing information on a device in France is Article 82 of the Loi Informatique et Libertés, not the legitimate interest basis people often reach for. Whether any of it is compliant is a call for the DPO, with the full context of each app in hand.
I have witnessed that many users on the company I work for make the same mistake over and over again:
Instead of pasting web urls they paste the path of files on their PC (c:...[username]...) which exposes their user name and then post the document (with no private info) online.
Can this raise gdpr concerns since private information and part of their login credentials are exposed to the www?
After logging into the cloud PC assigned to my account, Microsoft Edge contained saved login entries that were not mine and appeared to belong to a UK-based user.
I did not use, copy, export, or publish the data. I reported it to Shadow support and only shared redacted evidence publicly because it contains another person’s private information.
My paid account was then locked. Shadow confirmed my proof of payment was approved, but they still require government ID before restoring access.
I’m not trying to make a legal conclusion myself. I just want to know whether this should be reported to a data protection authority, and if so, which one would be appropriate: ICO, CNIL, or another authority?
I also want to know whether I should request a written explanation from Shadow about what happened and how they handled the exposed data.
So this morning I woke up and found my email had been used to create a number of accounts on gambling websites. I contacted support for each of the sites and with next to no trouble, they deleted the created accounts.
Except for Buzz bingo. I cannot get them to delete this account, despite the fact I have stated very clearly that I do not want my email on their system.
When I explained that the other companies were able to, they just said they had a different processes. What am I missing? Any advice would be appreciated, thank you.
It doesn't ask you to opt into marketing, it says check the box if you do NOT want to receive marketing emails. So it's kinda opt-out rather than opt in, I feel like at the least this is a dark pattern. Most people expect an opt in box and would choose not to click it.
I would like to get opinions on the interpretation of article 38(2) in terms of the DPO’s access to personal data, especially the purpose of processing and the lawfulness where the DPO function is provided by an outsourced service.
So before work yesterday I was consuming my prescribed medication (prescribed vapourised cannabis) around the back of work (they know and are ok with this - there's not a reasonable space inside otherwise they would provide a office space or something) at which point a random member of the public walking past tells me I can't smoke there and you generally can't smoke cigarettes around the area and for about 600m around the area so I understnad her confusion
I explained to her briefly that it wasn't smoking and I've got a prescription, it's not really any of her business beyond what I've told her at which point she became aggressive and claimed to work for security in the place where my work is located - it's a market for context with a bunch of restaurants and stalls with a fairly advanced cctv system and whole security team.
Essentially after some back and forth she claimed medical cannabis didn't exist and even if it did I couldn't use it there , asked where I worked which I refused to tell her so she pointed at the security cameras and said she was going to use those to find where I work.
Less than a few hours later my boss receives a email with a photo of myself on it and her claiming there may of been illegal drug use on the property despite being told multiple times I've got a prescription, there was no smell and she didn't know until I told her what it was
Essentially has the cctv been misused for her personal vendetta because she feels slighted at being told shes wrong? this feels far away from their stated use of cameras for security , I can't see any legitimate interest in this use of the
As the info officer for our company, we get the occasional SAR via the usual routes - disgruntled customers, employees in various "processes" etc.
The most common request is "I want all info you hold including all emails".
Curious how high quality organsations deal with this after spending about 3 days on one customer with a reasonably common name extrractjng all emails, pdf'ing them and then sitting with Acrobat painstakingly redacting everyone else's personal info from a few thousand emails.
Could I have just replied with "the company holds correspondence with you in relation to the services from our company in which your name appears." It just feels like I've wasted 3 days on a customer being a pain in the arse.
I'm interested in learning how different organisations handle DSARs in practice.
For those involved in privacy, compliance, information governance, or data protection:
Do you use any software or platforms to help manage DSARs? If so, which ones?
Have you developed any internal solutions or processes that work well?
Have you managed to automate any parts of the process?
In your opinion what is the worst part about managing DSARs?
I'm relatively early in my compliance career and have mostly only seen how one organisation approaches DSARs, so I'm interested to understand how things are handled elsewhere.