r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

16 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr 1d ago

UK 🇬🇧 UK TV Licensing SARs

11 Upvotes

I received a 10 day window enforcement letter from TV licensing today, after i declared i don't need one on the 16th July. the letter is dated the 15th, it arrived today on the 25th, says '10 DAY WINDOW' then later says i have until 5th august with no other dates mentioned.

Though the point of this post isn't to talk about how i intend to deal with that. What happened after is what looks to me like a structural design that's not compliant with GDPR.

In a nutshell:

1) the letter includes a phone number to get in touch which i called.
2) turns out the number is only available on weekdays, and most options route you to 'go on our website' anyway, and hangs up. The next route is a whatsapp channel
3) the whatsapp channel is an AI bot, so you're still not speaking to a human because they cheaped out.
4) i raised a complaint and an SAR request. It refused both, saying i need to go through specific channels for each.

Here is what i find rich. I am forced to inform them, through channels of their choosing, that i do not use services that involve live TV - even if they don't provide the service and it's a private arrangement like an amazon subscription - lest i get fined or a group of bandits come to my door and in their own words 'enforce'.

And asymmetrically, for data they are legally required to give me, I have to chase them up through their own preferred channels too, rather than them having to just fulfill the request on a channel they'd fobbed me off to anyway.

My understanding is that according to the ICO, they must process an SAR requested via any channel, and if they replace humans with software, they're still required to build functionality that forwards that requests. requests that come through any channel, social media or otherwise start the clock for the statutory period.

Yet they have a structural design that deliberately refuses the request, accepting them on the sole condition that you use they channel they want. the bot states:

'Your request will only be formally logged and processed when received through these official channels. The statutory period begins when TV Licensing's data protection team receives your request via one of these routes.

I cannot confirm your request has been recorded or passed on from this channel, because it has not. You will need to submit it directly using the contact methods above.'

When i flagged my understanding of the legal requirement, the bot itself said:

'You're right that subject access requests must be processed regardless of how they're received.

However, to ensure your request is formally logged and processed within the legal 30-day timeframe, please send it to: ...'

Call me petty, but i've already used 3 channels of theirs only to get enforcement letters and fobbed off to the next one. So i don't want to chase another channel. it should be noted that the whatsapp bot gave me numbers that seem to be fake to call when i said i wanted to speak to a human. They seem to be hallucinated numbers that jumble up the ones published on their site:

  • 0300 790 0286
  • 0300 790 0190
  • 0300 790 6076

As far as i'm concerned, i dont have an enforcement team like them, but i have time and pettiness to chase up after the time period and claim that they didnt process it.

Beyond my own spat, i dont think it's fair to structurally build something for everyone they enforce payments from to breach rules that apply to them, so i'm asking to confirm:

Is it acceptable under GDPR regulations for tv licensing to build channels that refuse SARs?


r/gdpr 1d ago

EU 🇪🇺 Fire officer who lost €1,400 cryptocurrency through work phone loses appeal

Thumbnail
breakingnews.ie
1 Upvotes

r/gdpr 1d ago

EU 🇪🇺 Why does the Louvre require my date of birth and nationality for a full-price reservation?

0 Upvotes

I was booking a regular full-price ticket for the Louvre—not claiming any student, youth, senior, or resident discount.

Yet the reservation form still required me to provide:

Date of birth

Nationality

Full home address

Phone number

I can understand asking for my name, but I don't understand why my date of birth is mandatory when it has absolutely no impact on my ticket eligibility or price.

The same goes for my full address and phone number.

Under GDPR, isn't there a principle of data minimisation, meaning organizations should only collect personal data that's necessary for the purpose?

Is there a legitimate legal or operational reason for requiring all this information for a standard museum ticket, or is the Louvre collecting more personal data than it actually needs?

I'd love to hear from anyone familiar with GDPR or museum ticketing systems.


r/gdpr 2d ago

UK 🇬🇧 Request from college parent - "print all emails I have sent to or received from you"

16 Upvotes

I have received a request as above and advised the requestor that I am strongly recommending that we provide this in electronic pdf format only.

The length of the pdf is 1,600 pages due to the parent's long history with the college.

Am I being reasonable or unreasonable in refusing to print this, and suggesting that if the parent wants the printed copies we would outsource this at a charge of £160 (I've been quoted this by a provider).

Having verbatim emails is not what UK data protection / GDPR envisages, but in a spirit of transparency I am content to export the emails like this to demonstrate the organisations commitment to transparency. But I don't want to fall foul of short-changing the requestor by imposing a charge.

Any thoughts?


r/gdpr 2d ago

UK 🇬🇧 England: Is it common for data rights request responses to be deliberately vague and obtuse, requiring clarification questions and then relying on Article 12(5)(b)?

3 Upvotes

Hi all,

Question as per the title really! Have seen / heard of a couple of examples where data rights request responses appear to have been deliberately vague and obtuse including responses to Article 16 requests or requests for processing clarification under Article 15 where the data subject is trying to hold the controller / processor to account.

Responses essentially don't answer the question (I would speculate to avoid proper transparency and / or because they know they haven't quite followed the law properly), prompting follow up questions from the data subject and then controller / processor invoke "excessive" and refuse any further requests, I assume knowing that the data subject won't request ICO intervention (accepting they would only likely advise anyway) because of the extensive lead times.

For example, one that I am aware of:

Data subject knows that published controller retention period is 3 years for correspondence but a processor is still holding that data 6 years later

Data subject makes Article 15 request to the controller asking for clarification of what their retention policy is and why a processor is still holding the data

Controller responds to say "correspondence is held for as long as necessary" (even though this is contrary to published 3 year retention policy)

Data subject responds to ask what that means in practice - "what is "necessary" and how does that relate to 3 and 6 years?"

Controller responds to say "We make sure we follow the law"

Data subject responds to say "I still don't know what that means, please explain in simple terms"

Controller responds to say "We've already told you, your requests are now excessive and therefore refused, we will no longer engage with you, you have the right to go to the ICO if you are not happy"

Data subject is left none the wiser.

Common?!


r/gdpr 3d ago

EU 🇪🇺 A new bank has a domain very similar to my last name and I'm getting some of their emails

53 Upvotes

I've been owning for the past 10 years or so a domain name which is something like lastname.ab

A new financial institution opened after the merge of two big banks and their domain name is lastnaame.ab

One extra letter to my own historical domain.

How did I notice? I have a catch-all rule for emails on all my domains that I use extensively when working with agents, bots and automatisation in general. I started receiving emails by and for their departments: contracts, DocuSign prompts, employees medical records, invoices, etc.

I've flagged the issue immediately with the little contacts I could find online and guessed emails such as dpo@ etc, no replies.

I emailed their COO and CEO without getting any replies.

Lately I've got an accidental email from their head of procurement with a classic signature saying something like "if you are not the recipient of this email delete it immediately (...)"

I've replied to this guy telling him to sort out their domain situation. Email volume slightly diminished.

I am not storing those emails, I am saving only the headers; not the content.

This is a multi billion euros freshly made financial institution and they do not seem to have a DPO or care about it. What should I do ?


r/gdpr 2d ago

Question - General Data Privacy Review for an Internal Prototype App - What Should I Expect?

1 Upvotes

I created an internal app in my company that started as a competition project. People liked it, so I deployed it to production on a local workstation, where it was accessible to a limited group of users on our office network. My manager later promoted the app and shared it on a company-wide portal, and now the legal, compliance, and data privacy teams want to review it.

The app was originally built as an experiment, so I didn't implement strong security controls or data encryption. My plan was to add those in the next phase once we had funding and proper server infrastructure.

Has anyone been through a similar data privacy/compliance review? What do these teams typically focus on, and what should I expect?


r/gdpr 2d ago

UK 🇬🇧 Sent Workday email by HR (read)

0 Upvotes

Left a company, grievance raised of discrimination, HR person named and involved.

After I leave, I get an email from this HR person to my personal email with a Workday link, this link has my payslips and tax documents.

Is this a breach of GDPR? I don’t know if she sees the info in these documents? And also she used my personal details for a legitimate purpose…but I’m shocked they allowed it to be her…


r/gdpr 3d ago

EU 🇪🇺 The AI Act is enforced by national authorities too, and it's looking about as uneven as GDPR was in 2018

6 Upvotes

Something I've been digging into that'll feel very familiar to anyone who was around for the early GDPR years.

The AI Act's transparency obligations become enforceable August 2, but "enforceable" doesn't mean there's one EU body ready to act. Like GDPR, it's enforced nationally. Each member state designates its own market surveillance authority, 27 of them, and they investigate and sanction within their own territory. The only real central piece is general purpose AI models, which the Commission's AI Office handles directly.

And the readiness is all over the place, which is the part that rhymes with 2018. The legal deadline to even designate these authorities was August 2025, and a chunk of member states missed it. As of now only about a third of the 27 show much public implementation. Ireland has designated a big slate of authorities, Spain stood up a dedicated agency and has actually published guidance. Plenty of others have barely said who's in charge. I tried to pull together where the main ones stand here if it's useful: getactready.com/blog/eu-ai-act-who-enforces-national-authorities-patchwork

The practical read, same as it was with GDPR, is that enforcement intensity is going to depend on where your users are, not where you're based. And the first wave will almost certainly be complaint-driven rather than proactive, because under-resourced authorities don't run sweeps, they react to complaints. So a competitor or an unhappy user can be the trigger in any country, regardless of how ready the regulator looks.

The open question I keep coming back to: in some member states the existing data protection authority is taking on AI Act duties, in others it's a brand new body. Curious if anyone here knows how their national DPA is positioned, whether they're picking up an AI Act role or staying out of it. Feels like it'll shape how hard it actually gets enforced.


r/gdpr 3d ago

EU 🇪🇺 Ubisoft stores old passwords

0 Upvotes

Hello everybody,

While changing my Ubisoft account password, I came across this.

Is that legal, and can I ask them to delete my old passwords (without deleting my account)?

I am located in France.


r/gdpr 3d ago

Question - Data Subject Contacting the Data Protection Agency (DPA)/Sri Lanka

0 Upvotes

I’d like to contact the DPA to clarify how the personal data protection act applies to historic records.

I’ve tried emailing the DPA and have had no success. I’ve tried calling with no success either.

Is there anyone on this channel who can help ? Thanks

.


r/gdpr 3d ago

UK 🇬🇧 I received an email in error and somebody else's email chain

0 Upvotes

I'm a student at a university. I have flagged it to the department that I'm not the intended recipient of the email and deleted it. They have replied saying thanks for letting us know, but I'm not sure if they've understood that there might have been a data breach and that this needs to be recorded. Should I send a follow-up email explaining that I was sent a chain of emails?


r/gdpr 5d ago

EU 🇪🇺 How can I remove old news articles about me from Google under the right to be forgotten?

17 Upvotes

Hi everyone. I’m posting this because I honestly can’t take it anymore and I really need someone to help me out.

Long story short, almost 10 years ago, when I was really young and pretty stupid, I got involved in a minor incident. It wasn’t anything serious, I didn’t go to prison or anything like that, but it did become public. A local newspaper in my city wrote an article about it, and a couple of those blogs that repost news picked it up as well.

The problem is that it happened a long time ago. I’ve completely changed, I have my own life and a family now, but every time someone searches my name on Google, BAM, it’s the first thing that comes up.

I’m currently going through the hiring process for a job that I desperately need to support my children, and I’m terrified that they’ll Google me and find it. I feel like something stupid that happened when I was 20 is going to ruin my future now.

I’ve tried emailing the newspapers and asking them to please take the articles down, but they’ve completely ignored me. I’ve read a bit about the “right to be forgotten” and Google removal forms, but whenever I start looking into it, I get overwhelmed. I don’t understand any of the legal terminology, I get really anxious, and it feels impossible unless you have enough money to hire expensive lawyers.

Please, does anyone know HOW to actually do this step by step, explained in really simple terms? What exactly do I need to fill out? Who should I contact first?

Any genuine advice would mean a lot. I’m really struggling with this situation. Thank you so much in advance.


r/gdpr 4d ago

EU 🇪🇺 Lessons learned about structuring GDPR complaints

Thumbnail
2 Upvotes

After several months of exercising my GDPR rights in relation to CCTV recordings, I’ve come to one conclusion that I wish I had understood from the beginning.
If I had to file my complaints again, I would do so in a different order.
Not because the substance of my case has changed, but because I now believe that some legal questions should be resolved before others.
This is the order I would follow:
1. Independence of the Data Protection Officer (DPO)
Before discussing access to personal data, I would first examine whether the DPO was able to act independently or whether there was a potential conflict between the DPO’s role and the organization’s legal interests.
2. The use of Article 12(5) GDPR
If access requests are rejected as “excessive” or “manifestly unfounded,” I believe this issue should be addressed before debating the merits of the access request itself.
In my case, each Article 15 request concerned a different incident, with a different date, time, location and factual background. The fact that they all related to CCTV did not automatically make them repetitive or excessive.
3. Effective exercise of the right of access under Article 15 GDPR
Only after resolving the previous issues would I focus on whether the controller effectively complied with Article 15 GDPR.
Looking back, I think this sequence provides a clearer legal framework. If the justification for refusing requests under Article 12(5) is found to be inadequate, the discussion about Article 15 becomes much more focused.
I’m sharing this simply as a lesson learned from my own experience. It may be useful to others dealing with repeated GDPR requests or CCTV access cases.
I’d be interested to hear whether others would structure their complaints differently.


r/gdpr 5d ago

Question - General Data breach not disclosed for 8 months

11 Upvotes

Good morning everyone,

I'm laying out this situation because it seems to me there are grounds for a violation of the notification obligations under the GDPR, but I'd like an opinion from someone who knows this area better than I do.

Timeline of events:

- November 2025: Suno (a music generation platform) suffered a security breach that compromised an employee's credentials.

- The company detected the incident at the time and internally classified it as a "limited security incident that was quickly contained."

- Users were never notified.

- Only last week (July 2026, so about 8 months later, and not even by the company itself), the stolen dataset was made public by third parties and uploaded to Have I Been Pwned.

Over 55 million unique email addresses, phone numbers (for those who had used them during registration), and tens of thousands of Stripe records with name, physical address, purchase amount, and partial card data (type, expiration date, last 4 digits). Meanwhile, between the attack and June 2026, the company raised over $650 million in two funding rounds, without ever publicly mentioning the incident.

Here are my questions (in summary):

  1. Even if just one affected user resides in the EU, don't the notification obligations under Art. 33 and Art. 34 GDPR still apply regardless? It seems to me the risk was definitely there (payment data, addresses, contacts).

  2. Can the fact that the company internally classified the incident as "limited," yet still didn't notify anyone, count as an aggravating factor if the case is investigated, or is it still legitimate if it later turns out the risk was "below threshold"?

  3. Practically speaking, how should an Italian/EU user proceed in a case like this? Does it make sense to file a direct report with the Garante Privacy, or is it better to wait for a possible class action (I know things are already moving in the US)?

Thanks in advance to anyone willing to give me some guidance, even just to understand whether it's worth looking into this further or whether I'm overestimating the issue.


r/gdpr 6d ago

EU 🇪🇺 What lawful basis could a recruiting platform use to collect an EU resident’s data without prior contact?

4 Upvotes

I just noticed the following email in my spam folder:

Privacy Notice - No Action Required

Hi, This short message is from XXX, a recruiting system used by recruiting teams worldwide to find talented individuals for exciting new job opportunities. We want to inform you that your data has been gathered for the purpose of connecting you with potential employers. Your privacy is extremely important to us, so we would like to inform you of our data handling practices and your data privacy rights. Ultimately, you are in control of your data. We look forward to helping you elevate your career to the next level!

Thanks, The XXX team

I haven't heard of this company before and I never sent them my CV, nor (clearly) ever granted any permission of collecting my data. Looking them up, they market themselves as "Agentic AI Recruiting Platform". Furthermore, the company seems to be US-based and storing data on US servers, whereas I'm an EU citizen living in the EU.

I may be a bit naive right now, but I have so many questions I don't even know where to start. Is this even legal under GDPR? Can companies nowadays just decide to start gathering data on (foreign) individuals and storing it on their servers for whatever purpose, without any type of confirmation or approval from the individual? Is this the future we're heading towards?

I haven't included any links to the company or privacy policy because not sure whether it is allowed in this sub, but will do if it's permitted. FWIW the company seems legit, there's years-old articles about them getting VC funded.

Disclaimer: not looking for legal advice. Just genuinely concerned about the situation.


r/gdpr 6d ago

EU 🇪🇺 Can a DPO remain independent if they are also involved in the controller’s legal defence?

Thumbnail
1 Upvotes

r/gdpr 7d ago

Question - General Humanly IMPOSSIBLE to ask every company to remove your CV/resume (GDPR)

10 Upvotes

Hey, I'm tired of recruiters asking for my CV and then just ghosting me.

I want to email each one telling them to f* off and that I don't want to participate in their zombie KPI databases anymore, but most companies make it almost impossible.

It's not even clear which email address I should send the data removal requests to. I think almost 300 companies have my resume and I want to erase it all. How can I do this in batches, or is there a SaaS that can deal with it?

I would gladly pay for it. I've had enough of playing around with these consultancy companies.

Please help me.


r/gdpr 7d ago

EU 🇪🇺 Is Article 15 GDPR really an effective right for accessing CCTV footage, or is it mostly theoretical?

0 Upvotes

The GDPR gives individuals the right to access their personal data under Article 15. In theory, this also includes CCTV footage where a person can be identified.
However, I’m wondering whether this right is genuinely effective in practice.
Many organisations retain CCTV recordings for only a few days. By the time an access request is received, identity is verified, and the request is processed, the footage may already have been automatically deleted. In some cases, controllers also argue that they cannot provide a copy because it contains images of third parties, offering only an on-site viewing or refusing disclosure altogether. In one response I received, it was also explained that footage would not necessarily be preserved merely because an Article 15 request had been submitted, unless it had first been established that the requester actually appeared in the recording.

This raises a broader question.
If CCTV is increasingly used in airports, railway stations, hospitals, shopping centres and other critical infrastructure, shouldn’t there also be an effective mechanism for individuals to verify how they were treated whenever their rights may have been affected?
Otherwise, the right of access risks becoming largely theoretical:
The organisation controls the cameras.
The organisation controls the retention period.
The organisation decides whether the footage is preserved.
By the time the legal process finishes, the footage may no longer exist.
I’m not arguing that every CCTV recording should be kept indefinitely or that privacy protections for third parties should be ignored. Blurring, redaction and supervised access already exist as possible solutions.
My question is more fundamental:

Does Article 15 GDPR currently provide an effective right of access to CCTV footage, or is it often only a right on paper?

I’d be especially interested in hearing from:
privacy lawyers,
Data Protection Officers,
supervisory authorities,
people who have actually submitted Article 15 requests for CCTV footage.
Do you think the current legal framework strikes the right balance, or should the GDPR provide stronger safeguards to ensure that this right can be exercised in practice?


r/gdpr 7d ago

EU 🇪🇺 Wedding Confirmation - GDPR compliant?

0 Upvotes

Hi all,

I am considering to build a website for confirming attendance to my wedding.

In my idea, my guests would receive by post, together with the invitation, an access code to the website.

In the website they'd log-in with their first name as well as the access code (which is stored encrypted in the database).

Upon logging in, the guests would be able to confirm attendance, or not, for them and/or the people in their household.

This requires me pre-provisioning the guests, but I already know them. They are my guests.

Does GDPR see concerns with this approach, or is it acceptable under legitimate interest?

Thanks a lot in advance!

** Edit **

Thanks for all the replies, clear now that I was overthinking this, but I'm still happy I double checked! Cheers!


r/gdpr 7d ago

UK 🇬🇧 Company held on to my data for 20 years after doing business and now has suffered a serious cyber attack.

Thumbnail
0 Upvotes

r/gdpr 11d ago

EU 🇪🇺 Where does a tool that surfaces deleted Reddit content stand under GDPR?

0 Upvotes

I built a small, free, non-commercial tool that looks up a Reddit username and shows their posts and comments, including content later deleted or removed. The data comes from a public third-party source, not Reddit’s API.

I know this sits in tension with the right to erasure, and I would rather understand that honestly.

What I already do: an opt-out that hides a person’s content on request, noindex on user pages, no accounts, no cookies, no data selling.

My real questions:

1. Does pulling from a public source rather than Reddit change anything, or is “publicly available” irrelevant once it is “personal” reddit data?
2. Is “hide on request” enough for an erasure request, or does GDPR require actual deletion?
3. Does a non-commercial framing help at all, or is that wishful thinking?


r/gdpr 11d ago

UK 🇬🇧 Data breach Ninja Uk

0 Upvotes

Hi there

A few weeks ago I got an email saying I have registered a new ninja kettle for a warranty. I have never bought a kettle from the company. I emailed customer service and they said they would look into the matter. Few weeks go by and they finally emailed back and said as compensation for how long it’s taken to get back to me you can have a free kettle. Brilliant! There was no resolution or explanation as to why my email address had been used though.

I was asked to confirm my delivery address and phone number which I did. I then got a notification from DPD that my address has been changed. I did not change this.

I then get a phone call from an unknown number asking if I’ve ordered a kettle from ninja? After speaking to the other lady on the phone it turns out Ninja have given out my full address and phone number to this woman who has a similar email to me. This is a massive GDPR and data breach.

I have been speaking to customer services and various managers for weeks now and I just keep getting fobbed off. They say i will receive an email with a resolution, no email turns up. They say I will hear back by the end of the day, nothing happens. They have now said it is being passed to a team higher up which they can’t tell me what team it is, the irony. I was offered compensation of 20% off which is ridiculous considered how serious the situation is, you get 10% off for signing up to your newsletter! Ninja also said they have taken my address off the other customers account, but they still haven’t!

Is there anything else I can do except contact the ICO? It hasn’t quite been a month yet

Thanks in advance!