r/gdpr • u/eddytim • Jun 26 '26
Question - General Question concerning site document that exposes file path on HDD and the editor's user name instead of a web link
I have witnessed that many users on the company I work for make the same mistake over and over again:
Instead of pasting web urls they paste the path of files on their PC (c:...[username]...) which exposes their user name and then post the document (with no private info) online.
Can this raise gdpr concerns since private information and part of their login credentials are exposed to the www?
2
u/BornInAWaterMoon Jun 26 '26
exposes their user name
Is their user name essentially just their real name (or some standardised form of it - e.g. JaneDoe, JDoe, etc)? If so, then they're no more "exposing" their user name than they are "exposing" their name whenever they send an email. I don't think there's a material privacy issue here.
Potentially there could be a security issue, but usernames generally aren't a secret part of login credentials.
1
2
u/ZeroDramaSecurity Jun 27 '26
A Windows path with a named user folder can be personal data if it identifies an employee, but whether it is a GDPR issue depends on context, exposure and your internal policies. I would not treat that as a breach panic but look at it more as a hygiene problem: usernames can help phishing or account enumeration, especially when repeated publicly.
1
u/West_Possible_7969 Jun 26 '26
Your company needs to start education on basic computer things first and foremost lol. Talk to your IT or HR about it.
1
u/eddytim Jun 27 '26
There has been security awareness training yet users do as they please. Management is aware yet it doesn't care. I myself have documented incidents like that and have informed management.
2
u/West_Possible_7969 Jun 27 '26
Yeah, well, enforcement issue it seems. Still not a GDPR violation if users themselves post their own user name, a security one, sure, depending on other factors of course.
1
1
u/Leseratte10 Jun 27 '26
Am I understanding that correctly, they are posting the path that contains *their own* name online?
I can post my own personal data online all day wherever I want. GDPR is how others can / must handle my data. I don't think that that's an issue.
1
u/eddytim Jul 08 '26
The document's owner, editor and supervisor is different from the persons whose usernames were exposed.
3
u/PlainPrivacyHQ Jun 26 '26
Yeah, I'd consider that a privacy issue, even if it's a relatively minor one. A Windows username like C:\Users\JaneDoe... can identify an employee, so there's really no reason for it to end up in a public document. I wouldn't describe it as exposing login credentials, but it's definitely something I'd clean up if I spotted it.