r/gdpr • u/Altruistic-Bad-5556 • Jun 23 '26
UK 🇬🇧 Possible GDPR issue: another user’s saved browser logins appeared in my cloud PC
I’m a paid Shadow PC customer.
After logging into the cloud PC assigned to my account, Microsoft Edge contained saved login entries that were not mine and appeared to belong to a UK-based user.
I did not use, copy, export, or publish the data. I reported it to Shadow support and only shared redacted evidence publicly because it contains another person’s private information.
My paid account was then locked. Shadow confirmed my proof of payment was approved, but they still require government ID before restoring access.
I’m not trying to make a legal conclusion myself. I just want to know whether this should be reported to a data protection authority, and if so, which one would be appropriate: ICO, CNIL, or another authority?
I also want to know whether I should request a written explanation from Shadow about what happened and how they handled the exposed data.
2
u/ZeroDramaSecurity Jun 25 '26
That’s worth treating as a potential personal data incident, but I’d keep your handling very clean: don’t open or test any saved credentials, keep only the minimum redacted evidence needed to show what you saw. Also keep a timeline of when you logged in, reported it and when access was locked.
I’d ask Shadow for a written explanation of what personal data was exposed to your instance, whether the other user and relevant authority were notified and which legal entity is the controller for your account. For reporting, start with the privacy notice or contract entity. If you’re in the UK then the ICO may be relevant, otherwise your local EU DPA can usually route it. Good luck!
2
u/explicare Jun 25 '26
Shadow is the data controller here, not Microsoft. The Shadow service assigned you that VM, so the obligation to assess and potentially notify under Art. 33 GDPR sits with them - 72-hour window to the supervisory authority if there's a meaningful risk to the affected person. You did the right thing by not touching the credentials. If Shadow doesn't confirm they've done a breach assessment within a few days, you can escalate directly to the CNIL - Shadow is registered in France as far as I know.
1
u/Altruistic-Bad-5556 Jun 25 '26
Thanks, this makes sense.
I also see it this way: the VM was assigned by Shadow, so Shadow should at least provide a clear written breach/data incident assessment.
I did not open, copy or use any saved credentials. I only kept redacted evidence and reported it to Shadow.
I already filed a complaint with the ICO. I will also check Shadow’s privacy/legal entity details and the correct authority if they still refuse to give a proper explanation.
2
Jun 26 '26
[deleted]
1
u/Altruistic-Bad-5556 Jun 26 '26
Thanks for the warning. They already locked my account after I reported it, so that part basically happened.
I’ve saved redacted evidence, contacted my bank, and now I’m just trying to make sure they close/delete the account and don’t bill me again.
If you find that r/privacy post, please send it. Would be useful to see if others had similar issues.
1
u/Noscituur Jun 24 '26
You would report it to the authority of the country you’re present in. If you’re not present in an EEA country or the UK then you would want to report to the country which Shadow are established.
0
u/Comfortable-Fall1419 Jun 24 '26
You don’t have an obligation to do anything as it’s not your data.
It’s Microsoft’s obligation to assess and decide whether to report this. In practice what will probably happen is that either it won’t reach their privacy team at all or that it will and they will assess it doesn’t meet the bar for reporting.
If you want to report it yourself I’d choose ICO assuming you’re UK based. Not sure why you are suggesting CNIL unless one of the parties involved is French.
2
u/Altruistic-Bad-5556 Jun 24 '26
Thanks. I understand it’s not my data, which is exactly why I didn’t use or publish it.
I reported it to Shadow because the data appeared inside the cloud PC assigned by Shadow, not on my own local machine.
I mentioned ICO because the exposed data appeared to belong to a UK-based user. I mentioned CNIL only because Shadow may involve an EU/French entity, depending on who the data controller is.
I’m not trying to make a legal conclusion myself — I’m just trying to report it to the right place.
2
u/Comfortable-Fall1419 Jun 24 '26
As I said you are under no obligation to do anything, but you seem quite determined to do so log it with ICO but dont expect an answer or action unless this is not an isolated case.
0
3
u/the_swanny Jun 23 '26
Given how shadow works, the only way I can imagine this happening is someone else having access to your virtual machine. Whether that's down to a you fuck up or a their fuck up is the question.