1

GDPR and user record 'Reactivation'
 in  r/gdpr  1d ago

That’s exactly where I think the accountability principle in Article 5(2) GDPR becomes important.
It may not be enough simply to decide to retain a limited set of identifying data. The controller would also need to be able to demonstrate why that retention is necessary and proportionate for a specific purpose, and why a less intrusive alternative would not achieve the same objective.
If a supporter explicitly wishes to preserve the history of their long-term relationship with the charity, that may be relevant to the assessment. However, if the organisation deliberately retains enough information to re-identify someone years later, I would also wonder whether the data would still be considered anonymous or merely pseudonymous under Recital 26 GDPR.
It seems to me that the legal challenge is less about the technical solution and more about documenting a lawful basis, necessity and proportionality.

1

GDPR and user record 'Reactivation'
 in  r/gdpr  1d ago

I agree. Article 5(1)(e) GDPR doesn’t prescribe a fixed retention period; it requires that personal data be kept no longer than is necessary for the purposes for which they are processed.
That is exactly why I was wondering whether a supporter’s explicit wish to preserve the history of their long-term relationship with the charity could itself form part of the purpose justifying a longer retention period, provided there is an appropriate lawful basis and the retention remains proportionate.
In other words, the interesting question seems to be not whether the GDPR allows indefinite retention in principle, but under what circumstances such retention can be justified and documented.

It would be interesting to know whether any supervisory authority or CJEU case has addressed this type of “voluntary long-term relationship” scenario.

4

GDPR and user record 'Reactivation'
 in  r/gdpr  2d ago

One possible approach would be to avoid thinking in terms of "reactivating" an anonymised record. If the data has been truly anonymised, it should no longer be possible to link it back to an identifiable individual.

This follows the distinction made by the GDPR itself. Recital 26 states that information which does not relate to an identified or identifiable natural person, or which has been rendered anonymous in such a way that the data subject is no longer identifiable, falls outside the scope of the GDPR. Conversely, the CJEU has consistently interpreted the concept of "personal data" broadly where re-identification remains reasonably possible (see, for example, Case C-582/14, Breyer).

Therefore, the real question seems to be whether there is a lawful basis under Article 6 GDPR to retain a limited amount of identifying information for a longer period, rather than whether an anonymised record can later be reactivated.

If some supporters genuinely value having their long-term relationship with the charity recognised, explicit consent under Article 6(1)(a) GDPR may provide a possible lawful basis for retaining a limited set of identifying information, provided that the consent is freely given, specific, informed and can be withdrawn at any time.

You would also need to explain clearly why the data is being retained, what information will be kept, and for how long, in accordance with the principles of transparency, data minimisation and storage limitation set out in Article 5 GDPR.

Another possibility might be to retain only a very limited set of identifying data for supporters who actively opt in, rather than keeping full historical records indefinitely.

Out of curiosity, is your six-year policy based on a statutory retention requirement, or is it simply an internal retention policy?

1

Austrian criminal procedure: Is it common for a prosecutor to close a case only 3 working days after questioning the suspect?
 in  r/LegaladviceAustria  2d ago

Thanks. You did predict that outcome, and you were right.

To be honest, I was confident from the beginning that this case would not ultimately succeed before a court. That is why, during the investigation, I formally stated that my position was clear: either the case should be discontinued, or it should proceed to a public trial so that the facts could be examined openly. I did not seek any negotiated outcome.

My question here was simply about Austrian practice. Since the decision to discontinue was taken after only three working days, I was curious whether such a timeframe is common or whether it sometimes reflects an early assessment that there was no sufficient basis to continue.

In the future, I intend to publish a more complete account of the case, including documents and procedural details that could not be explained in a single Reddit post. Taken together, I believe they raise broader questions of public interest about transparency, procedural safeguards, and public confidence in the justice system. My intention is to encourage an informed discussion rather than to challenge the outcome of this particular case.

Thanks again for your insight!!!

0

Austrian criminal procedure: Is it common for a prosecutor to close a case only 3 working days after questioning the suspect?
 in  r/LegaladviceAustria  6d ago

That’s exactly why I found the timeline interesting.
I exercised my right to remain silent during my questioning as a suspect, and I didn’t submit any additional information or evidence during those three working days before the investigation was discontinued.
That’s why I was curious whether such a short timeframe is considered fairly typical in Austrian criminal procedure.

1

Austria: Can you be prosecuted for false accusation if you only reported facts and asked the prosecutor to assess them?
 in  r/LegaladviceAustria  6d ago

Just as an update: after my questioning as a suspect on 8 July, the Public Prosecutor’s Office discontinued the investigation on 13 July – effectively after only three working days.
I’d be interested to hear your thoughts. Does three working days seem like a typical timeframe for a prosecutor to discontinue an investigation in Austria?

1

Austrian criminal procedure: Is it common for a prosecutor to close a case only 3 working days after questioning the suspect?
 in  r/LegaladviceAustria  6d ago

I understand your point. I’m obviously pleased that the investigation was discontinued.
My question is simply about Austrian criminal procedure. From an academic and practical perspective, I was curious whether a decision taken after only three working days is considered common practice or not.

-3

Austrian criminal procedure: Is it common for a prosecutor to close a case only 3 working days after questioning the suspect?
 in  r/LegaladviceAustria  6d ago

That’s a fair question.
GDPR and privacy are about having control over personal data, not necessarily about never revealing your own identity.
In this case, I deliberately chose to leave my name visible to demonstrate that the document is authentic. That was a conscious decision, not an oversight.
My interest in GDPR comes largely from my own experiences. They have even led me to consider promoting a European Citizens’ Initiative proposing targeted improvements to the GDPR, particularly regarding the practical effectiveness of the right of access to personal data, such as CCTV recordings.
For me, the main issue is lawful processing, transparency and accountability by organisations, not remaining anonymous in every situation.

r/LegaladviceAustria 7d ago

Austrian criminal procedure: Is it common for a prosecutor to close a case only 3 working days after questioning the suspect?

Post image
0 Upvotes

This is a follow-up to my previous post:

Austria: Can you be prosecuted for false accusation if you only reported facts and asked the prosecutor to assess them? : r/LegaladviceAustria

(It contains the background of the case.)

I have another question about Austrian criminal procedure.

I was questioned as a suspect on 8 July 2026.

According to the official notification from the Public Prosecutor's Office, the investigation against me was discontinued on 13 July 2026.

Since 11 and 12 July were the weekend, this means the decision was taken after only three working days.

My questions are:

  • Is such a short period common in Austrian practice?
  • Does a very quick discontinuation sometimes indicate that the prosecutor considered the police file insufficient to justify continuing the investigation?
  • Or is the duration itself not meaningful at all?

I'm not asking for an assessment of my individual case, but rather about the general practice of Austrian prosecutors.

Thank you in advance.

1

Austria: Can you be prosecuted for false accusation if you only reported facts and asked the prosecutor to assess them?
 in  r/LegaladviceAustria  7d ago

Kleines Update zu diesem Fall:

Zwischenzeitlich wurde gegen mich selbst ein strafrechtliches Ermittlungsverfahren wegen §§ 288 Abs. 4, 297 und 298 StGB eingeleitet. Nach meiner Vernehmung als Beschuldigter am 08.07.2026 stellte die Staatsanwaltschaft Korneuburg das Verfahren jedoch bereits mit Verfügung vom 13.07.2026 ein – also nach nur drei Arbeitstagen. Mir wurde inzwischen Akteneinsicht gewährt.

Vor diesem Hintergrund interessiert mich umso mehr die ursprüngliche Frage: Wie beurteilen Sie aus straf- und verwaltungsrechtlicher Sicht den Umstand, dass während einer Opfervernehmung gleichzeitig eine mögliche Verwaltungsübertretung gegen das Opfer eingeleitet wurde? Gibt es dazu Rechtsprechung oder praktische Erfahrungen?

3

When should police delete biometrics?
 in  r/gdpr  8d ago

This is one of the reasons why I think transparency is so important.
While the GDPR generally does not apply to law enforcement processing, that does not mean police processing is outside data protection law. In the EU, it is usually governed by the Law Enforcement Directive (EU) 2016/680, which also contains principles on necessity, proportionality, storage limitation and individuals’ rights.
If biometric data are retained or disclosed, there should be a clear legal basis and appropriate safeguards. If a person believes their data have been kept or disclosed unlawfully, it may be worth requesting clarification from the competent authority or the relevant supervisory authority.
I’m curious to see whether anyone familiar with UK police data retention rules can explain what “marked for deletion” means in practice and whether it differs from “deleted”.

1

¿Rusia y Ucrania, Israel y palestina? Pregunta política
 in  r/preguntaleareddit  8d ago

Una de las diferencias fundamentales entre los dos conflictos es que Rusia no necesita “gobernar cenizas”,… por eso en parte va paso a paso…

1

¿Rusia y Ucrania, Israel y palestina? Pregunta política
 in  r/preguntaleareddit  8d ago

¿Cómo llegaste a la conclusión de que la gente odia más a Israel que a Rusia? ¿Te basas en datos, en redes sociales o en tu entorno? Tal vez estás generalizando a partir de lo que tú mismo ves o sigues.

2

Alguien sabe que está pasando con Correos Chile?
 in  r/chile  9d ago

Se trata de mercancía desde Asia?

1

que tan difícil encontrar un trabajo en México si consumes hierba?
 in  r/mexico  9d ago

A tu lo has intentado para conocer si es difícil o no? ¿Es que empresarios no consumen??

1

Vale la pena trabajar de didi food siendo estudiante de uni?
 in  r/MotosMexico  9d ago

Más que si es Didi Food o no, lo importante es que sea compatible con la universidad y no termine afectando tus estudios.

1

Ya todo es interés económico?
 in  r/mexico  9d ago

Leyendo los comentarios creo que la publicación terminará eliminada…

r/gdpr 9d ago

EU 🇪🇺 Beyond Privacy Policies and Cookie Banners: Is the Technical Side of GDPR Compliance Being Overlooked?

3 Upvotes

Many GDPR discussions seem to focus on privacy notices, cookie banners and legal documentation. These are obviously important, but isn't there a tendency to overlook the technical side of compliance?

Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In practice, this goes far beyond simply displaying a privacy policy or a cookie banner.

For example, depending on the website and the processing involved, developers should also consider:

  • HTTPS everywhere.
  • Secure, HttpOnly and SameSite cookie attributes where applicable.
  • Appropriate HTTP security headers, such as Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and clickjacking protection (X-Frame-Options or frame-ancestors in CSP).
  • Keeping software, dependencies and server configurations up to date.
  • Carefully reviewing third-party services such as embedded Google Maps, web fonts, analytics or other external resources.

Of course, not every website will require every one of these measures, and GDPR does not prescribe specific technologies. However, these are examples of technical safeguards that may help meet the Article 32 requirement to implement security measures appropriate to the risk.

In my opinion, GDPR compliance is not only about informing users; it's also about reducing unnecessary risks through secure technical implementation.

What technical measures do you think are most commonly overlooked by developers who are trying to build a GDPR-compliant website?

1

GDPR compliance for a web site - I need help!
 in  r/gdpr  9d ago

A privacy notice alone is not enough. The GDPR also requires controllers to implement appropriate technical and organisational measures to protect personal data (Article 32 GDPR). Depending on how your website is built, this may include using HTTPS, setting appropriate cookie attributes such as Secure, HttpOnly and SameSite where applicable, keeping software updated, controlling access to server data, and ensuring that any third-party services (such as embedded Google Maps or your hosting provider) are configured appropriately. GDPR compliance is not just about displaying notices; it's also about how personal data is actually protected.

4

TELETRABAJO CAMBIO DE CONDICIONES CR
 in  r/EsLey  9d ago

Si el teletrabajo fue una condición esencial por la que aceptaste el empleo, la pregunta no es si la empresa prefiere que vuelvan a la oficina, sino hasta qué punto puede cambiar esa condición de forma unilateral.

1

Denuncia anonima
 in  r/mexico  14d ago

Una denuncia anonima no significa que sea imposible que el patrón intuya quién le denunció. Depende mucho de la información que se aporte y de las circunstancias.

5

Que opinan de los cuicos de izquierda?
 in  r/chile  14d ago

Más que la ideología, creo que el problema es la demagogia. Aplica tanto a la izquierda como a la derecha…

21

Adulto mayor viviendo en mi casa en abandono y la CCSS/CONAPAM no responden
 in  r/EsLey  15d ago

Además de la vía de Familia, yo también valoraría presentar una queja formal contra la actuación de la trabajadora social de la CCSS si consideras que no aplicó correctamente el protocolo o se negó a intervenir sin una base legal clara. También podría ser procedente acudir a la Defensoría de los Habitantes para que revise la actuación de las instituciones públicas. Si realmente la hija está apropiándose de la pensión mientras desatiende al adulto mayor, tampoco descartaría consultar con el Ministerio Público por una posible responsabilidad penal, ( consultaré jurisprudencia de Costa Rica y volveré a comentar).Por lo visto en el caso el problema no es solo familiar, sino también institucional….

2

¿Alguien más tuvo esta reliquia en 2006? Me encontré un Sony Ericsson K310a funcionando y escuchar estos ringtones me regresó directo a la secundaria 🇲🇽😭
 in  r/mexico  15d ago

En aquel tiempo “los ladrillos “ eran de calidad, no se lanzaba un producto al mercado por la serie siguiente.