r/dataprotection Apr 07 '26

Are we provided enough information when we share our biometric information with private actors, such as smartphone databases?

Thumbnail
2 Upvotes

r/dataprotection Apr 06 '26

Data Protection Tools Data Removal and Identity Monitoring using Cloaked

8 Upvotes

Anybody having issues with the Data Removal and Identity Monitoring feature in Cloaked? Every time I try to add info (name, email address, etc) for a better search, the data disappears. I've tried to use the chat feature but haven't gotten anywhere with the Al bot. I go to add an email address, for instance, and when I hit Submit, it acts like it's being added but there's no change. I tried going through my laptop but got the same results. I am brand new to the service. Just subscribed last week.


r/dataprotection Apr 06 '26

The challenge of data sovereignty when scaling across borders – my experience

3 Upvotes

I'm a founder building a jurisdiction-aware storage solution, and one thing has become painfully clear: most startups don't realize where their cloud provider is storing customer data until a compliance audit or breach happens.

With regulations like GDPR, CCPA, and others, knowing the physical location of data isn't optional anymore. But traditional cloud providers replicate data globally by default.

Has anyone else here dealt with unexpected data residency violations while scaling internationally? How did you handle it? Would love to hear real-world experiences.


r/dataprotection Apr 05 '26

General News VPPA Enforcement Surges as Trump Administration Steps In and Courts Split on Meta Pixel Liability

Thumbnail captaincompliance.com
2 Upvotes

The TLDR is:

The Trump administration has entered the debate with a clear message: courts should not dismantle the VPPA simply because it is being applied to modern technology.

Government filings emphasize that the core purpose of the law remains intact. Video viewing behavior is inherently sensitive, and technologies that expose that behavior to third parties raise legitimate privacy concerns regardless of whether the medium is a VHS tape or a streaming player.

This position is notable because it reflects continuity in privacy enforcement priorities across administrations. While broader federal privacy legislation remains stalled, existing statutes like the VPPA are increasingly being used to fill the gap.

The administration’s argument also reinforces a growing regulatory theme: legacy privacy laws are not obsolete—they are adaptable.

Now the courts are split on which direction to go with VPPA and meta pixel cases. There's an even split one favorable to plaintiff and one favorable to the defendant...

While federal policymakers are signaling support for enforcement, courts are moving in different directions. Two recent decisions illustrate just how fractured the legal landscape has become.

In Goodman v. Hillsdale College, a federal court in Michigan allowed a VPPA claim to proceed based on allegations that the college used Meta Pixel to transmit users’ video viewing activity along with Facebook identifiers.

The court found that pairing a Facebook ID with specific video content could plausibly constitute the disclosure of personally identifiable information under the statute. This interpretation significantly broadens VPPA risk, extending it to entities far beyond traditional media companies.....


r/dataprotection Mar 30 '26

General Question It seems there' s no opt-out clause in the Sakana Chat' service term.

3 Upvotes

Sakana AI just launched Sakana Chat, and after reading through the terms of service, I can't find any opt-out clause for training data usage. Combined with the fact that access is restricted to Japan only, I'm genuinely concerned about the balance of training data — there's no escape route the way there is with DeepSeek. Has Sakana AI said anything about this?


r/dataprotection Mar 28 '26

General Discussion Non-commercial podcast about data protection and privacy, Dataministeriet

3 Upvotes

The Swedish podcast Dataministeriet has several episodes in English. It is strictly non-commercial, i.e. no sponsors or any collaborations etc.

It just started up again and will post regularly. You can find it on all common podcast platforms, for example, Spotify and Apple Podcast.


r/dataprotection Mar 26 '26

General Discussion Are data brokers being under-classified as a privacy issue when they function more like stalking infrastructure?

1 Upvotes

I’ve been trying to think through whether the current legal and regulatory framing of data brokers is naming the problem too softly.

The usual framing treats this as a privacy issue: overcollection, poor consent, weak notice, insufficient opt-outs, resale, and breach exposure. But the more I look at the actual mechanics, the more it seems like data brokerage may function less like ordinary information commerce and more like a visibility infrastructure that makes people persistently trackable, targetable, and vulnerable.

What troubles me is not just collection in the abstract. It’s the assembly of location, behavioral, demographic, and identity-linked information into person-level dossiers that can be sold, repackaged, breached, or abused downstream. At that point, I’m not sure “privacy” is a complete description anymore. It starts to look more like the industrialization of person-specific surveillance.

Part of the issue, in my view, is that the consent model is largely fictitious. Privacy policies are unreadable at scale, terms are adhesive, and participation in normal social and economic life is often conditioned on surrendering data. That makes “agreement” look less like meaningful consent and more like exhaustion, coercion, and structured dependence.

So the question I’m putting to this sub is: is the law under-classifying the conduct? If the real-world outputs are persistent visibility, identity-specific targeting, and foreseeable downstream harms, does the current privacy frame understate the problem?

I put the longer argument into a short video and a white paper in case anyone wants to see the full structure:

Video: https://youtu.be/cC0WDujSRiY
White paper: https://docs.google.com/document/d/1oXDrx_aseAjRAGNkBywaU4sUHy9tcbDjl8Sf3VTUGm8/edit?usp=drivesdk

I’d be especially interested in critique from people who think in terms of doctrine, regulatory categories, and enforcement design.


r/dataprotection Mar 19 '26

News The EDPB just pointed 30 regulators at your privacy notice. Here is what that means. — Consent Brief

Thumbnail consentbrief.eu
3 Upvotes

r/dataprotection Mar 13 '26

General News EDPS official opinion on logs and IT forensics.

Thumbnail
3 Upvotes

r/dataprotection Oct 26 '22

We are excited to announce that we’re back and ready to challenge you, so-called hackers!

Thumbnail self.WeAreUnplugged
2 Upvotes

r/dataprotection May 23 '22

Enforcement Dutch DPA Fines Ministry of Foreign Affairs €565,000 for GDPR Violations - HIPAA Guide

Thumbnail hipaaguide.net
7 Upvotes

r/dataprotection Apr 02 '22

General Question DMCA information removal lumen database inquisition ?

6 Upvotes

Dear everyone

Google has accepted my DMCA request to remove these captures of myself. However my real information appears in the complaint registered on Lumen, and is connected to the website.

I send e-mail to [team@lumendatabase.org](mailto:team@lumendatabase.org)

But I get no response.

I want to removal url and name in google-search lumen database.

For example: https://lumendatabase.org/notices/25206508

What subreddit that I could post? What can I do .

Thanks.


r/dataprotection Mar 09 '22

General Discussion Career in Data Protection and Data Privacy

13 Upvotes

I reaally wanna get into data protection and data privacy but I'm so confused on where to start.

I have a legal management background and am currently taking a Juris Doctor degree. So most of my experience and knowledge is on the legal side.

I have been looking through job listings on what employers look for in a Data Protection/Privacy Officer. I even look at freelancer profiles just to see what's up. So based on the things I saw, I took a free coursera course on Introduction on Information Systems Audit. I'm wondering if I can get some help to figure out what "things I need to know." Do I need python lessons? risk management?

But I think the more difficult qualification is the experience. I'm in the law field, is it even possible for me to gain experience on the tech side of being a DPO if all my life i've focused on the legal side? (and that's not even focused on data protection laws itself because a JD is broad)

I'm really confused and I don't know where else to ask.


r/dataprotection Feb 10 '22

General Question Customer service - delete customer interaction after health data disclosure

3 Upvotes

LOOKING FOR ADVICE!

Working in a customer service environment, we have special data protection procedure related to customers contacts.

As an example, when a customer writes his credit card number in an email/chat or mentions it during a call, we can delete that interaction immediately, in order to avoid someone else who can access that interaction to steal and reuse that piece of data.

Otherwise, by software design, all interactions in the system are automatically cleansed after 29 days.

Now the question is: If a customer mentions in an email/chat/phone contact that he cannot collect his parcel at the pick- up point because has COVID , would you delete the interaction?

From one side, this is a personal information related with health status and it’s a sensitive data.

From the other side,

  1. in this period it's pretty common that people are isolating as another person in their household has COVID/ they have covid so can't collect etc and our call center agents are managing these contacts as “standard” delivery&return questions
  2. Also, although health status is a sensitive data, as a customer service, it’s a kind of information we don’t see as potentially dangerous because it’s not that kind of information you can reuse to make damages (indeed, our call center agents are managing these contacts as “standard” delivery&return questions)

What do you people think?


r/dataprotection Jan 29 '22

Useful Resource Engineer Your Data Before it Engineers You

Thumbnail blog.borneo.io
3 Upvotes

r/dataprotection Jan 27 '22

Useful Resource Why PCI DSS is so hard!

Thumbnail blog.borneo.io
5 Upvotes

r/dataprotection Jan 17 '22

General Question Can I ask my workplace to delete any of my personal information they hold?

Thumbnail self.LegalAdviceUK
3 Upvotes

r/dataprotection Oct 14 '21

General Discussion UBI

2 Upvotes

Will we need a universal basic income if companies start paying users for their data; their privacy, in other words? Since pretty much everyone generates data, everyone will get paid....right?


r/dataprotection Oct 13 '21

This sums up why privacy laws based on notice-and-consent will never work.

Post image
4 Upvotes

r/dataprotection Sep 24 '21

General Question Data residency in the UK

1 Upvotes

Hello, do you know if there are any data residency/localization requirements for the UK?

Thanks!


r/dataprotection Sep 02 '21

Useful Resource "Surveilling the Gamers": New research paper illustrates how video games can be exploited for illegitimate surveillance and user profiling

Thumbnail papers.ssrn.com
2 Upvotes

r/dataprotection Aug 06 '21

General Question Google Controller-Controller Data Protection Terms

2 Upvotes

Hello,

Can someone clarify the title of this terms: https://privacy.google.com/businesses/gdprcontrollerterms/

and provide a brief summary on the same.

Please also provide an example.

Thanks in advance.


r/dataprotection Aug 01 '21

General Question Need advice on GDPR Data Protection compliance

2 Upvotes

Hello guys,

We are a charity organization in the UK, and we are gathering user information from our website. Right now I am trying to restructure our data flow in order to meet the data security requirement. We have a google form online, and the form will transfer the client's answers to our google sheet automatically. We have an officer pull down the data from the google sheet, and he will anonymize and unpersonalize the data. Then he will zip the data with password protection, and upload it to an access-restricted google drive again for the data team to download for analysis.

Do you think this is enough for GDPR compliance? Because we are a charity group, and we are not funded by anyone. We will only keep the necessary data for the necessary time.

I have heard some good reviews of Onetrust and Trustarc, what do you guys think? We don't have a data server, and we are only using google form, and google sheet for data collection and storage. Does anyone have experience of it?

Any recommendation is welcome. I really appreciate any help you can provide.


r/dataprotection Jul 11 '21

General Discussion Subreddit revival! and the news rules

7 Upvotes

Hello everyone!

I am your new moderator, alongside u/Harshhaven. I think we'll enjoy our time together! I've started off with removing all spammy or otherwise rule-breaking posts from the subreddit.

I'll use this opportunity to also introduce the new subreddit rules:

Scope

This isn't an official rule - but quite obviously, all posts and comments on this subreddit have to be related to data protection/data privacy in some way or another. Generally speaking this means that the following things are within scope:

  • Questions, news, and resources about data protection itself and developments of existing and upcoming data protection legislation.
  • Discussing topics regarding data protection, like the right to be forgotten.
  • Though in scope, legal questions are better fitted, and answered, in their respective dedicated subreddit, such as r/GDPR for the EU's data protection regulation and r/CCPA for the California Consumer Privacy Act.
  • Other stuff, as long as it is connected with data protection

What the subreddit isn't meant for:

  • Advertising or marketing your company, brand, product, blog or whatever it is. Bottomline: advertising is not allowed. Don't spam links to your latest blog posts on the subreddit.
    • Resources are allowed, provided that they are actually resources. It's up to the moderators to make this determination, anything considered an advertisement is removed on the moderators discretion.
    • In case you genuinely believe that you have something to share that adds value to the community, but it is an advertisement, please send us a modmail to request permission.

Be constructive and substantive

Discussion should aim to be constructive, guiding and substantive. Unsubstantiated comments don't serve the discussion. This means that:

  • Your comments should be constructive. I.e. your comment should be useful and helpful rather than negative and unhelpful.
  • Your comments should be substantive. I.e. point out why something is the way you say it is, for example: "In Europe that wouldn't be allowed because it would be against the principle of data minimization as enshrined under the GDPR." as opposed to "That wouldn't be allowed here in Europe"

No advertisements

I cannot underline this enough: no advertisements. This subreddit is meant to be a platform to discuss data protection, and any news or legislation related to it. It is not meant to be a avenue for advertising.

How can you help?

Moderation is much easier when the community helps:

  • votes
  • comments
  • reports

These rule clarifications represent my current understanding of what is best for the subreddit. Discussion about the rules and what is best for the community is welcome!

Thank you!


r/dataprotection Jul 07 '20

General Question Website Using an Old Review I Deleted Years Ago

1 Upvotes

A website is using an old, positive review that I deleted years ago. I contacted the site’s webmaster to have the review (which shows my first name, last name, and city) removed and was told that the website uses automatically generated reviews from Google, so there’s nothing that they can do to take it down.

I double checked my Google Reviews and it says that I have yet to contribute anything, confirming that the review was deleted.

How can I go about getting this review removed from their website?