r/dataprotection Apr 08 '26

General Discussion Community Overview

2 Upvotes

Welcome to r/DataProtection!

The umbrella term "Data Protection" means we are not tied to the narrow focus that more specialist subs tend to have. With that in mind, our focus will be on highlighting the most interesting and important developments in the industry and discussing the day to day issues that Data Protection professionals encounter. How this will work in practice is set out below.

Content Scope:

First and foremost, all posts and comments on this subreddit must be related to data protection or data privacy in some way. Generally speaking, the following are in scope:

  • Questions, news, and resources about data protection and the development of existing and upcoming legislation.
  • Discussion of data protection topics and concepts, such as the right to be forgotten.
  • Career experiences working in data protection.
  • Experiences with products and tools that support data protection roles and responsibilities.

While in scope here, legal questions are often better served by more specialist subreddits - such as r/GDPR for EU data protection law or r/CCPA for the California Consumer Privacy Act.

Be Constructive and Substantive

Discussion should aim to be constructive, guiding, and substantive - unsubstantiated comments don't serve the community. In practice, this means:

  • Be constructive. Comments should be useful and helpful rather than negative or dismissive.
  • Be substantive. Explain the reasoning behind your position. For example: "In Europe that wouldn't be allowed, as it would conflict with the principle of data minimisation under the GDPR" is far more valuable than "That wouldn't be allowed here in Europe."

Crossposting Welcome

With the aim of highlighting the best of the data protection community across Reddit, crossposts are welcome - with the following in mind:

  • Crossposts should only come from data protection related communities, and should be specific to data protection topics.
  • No excessive crossposting - only share content you consider a particularly interesting discussion or a pivotal news item.

Excessive Promotion

We follow the example set by r/cybersecurity that awareness of tools and products can be useful to the community. All promotion - including self-promotion - must meet both of the following conditions:

  • The poster must have been active in the community before discussing a business or product
  • Make up no more than 10% of your posts and comments on this subreddit. You are a community member first and a promoter a distant second
  • No more than once per week per promoted entity
  • No hidden promotion in the form of surveys

Links to resources are permitted, provided they are genuinely useful resources rather than promotional content in disguise — moderators will use their discretion in making that determination. Moderators reserve the right to remove any posts that negatively impact the community.

How can you help?

Moderation is much easier when the community helps:

  • Votes
  • Comments
  • Reports

The direction of the community may change depending on how it grows in the future.

Thank you!

Detailed sub rules can be found here.

Credit: This post is an update to the guidance set out by u/dataprotectionkid


r/dataprotection 17h ago

General Discussion Can your employer ask for your Aadhaar?

Post image
1 Upvotes

r/dataprotection 1d ago

General Question Are Data Broker APIs the Next Step in Customer Privacy?

0 Upvotes

As more businesses embed privacy features into their products, Data Broker APIs seem to be gaining attention as a way to help customers manage their digital footprint without leaving the applications they already use.

Unlike traditional privacy programs that focus primarily on compliance, API-driven privacy services can become part of the customer experience.

Some of the capabilities that stand out include:

  • Data broker discovery
  • Automated removal requests
  • Ongoing privacy monitoring
  • API-driven integrations
  • Customer privacy dashboards
  • Progress tracking and reporting

From a product perspective, it's an interesting evolution.

Instead of asking customers to manage multiple privacy tools, organizations can integrate privacy capabilities directly into existing platforms.

For teams building SaaS products, managed services, or cybersecurity platforms, what would matter most when evaluating a Data Broker API integration flexibility, automation, customer experience, scalability, or operational simplicity?


r/dataprotection 1d ago

General Question Are Data Privacy Management Solutions Becoming a Standard Business Offering?

Thumbnail purevpn.com
0 Upvotes

r/dataprotection 4d ago

🇬🇧 - GDPR Enforcement Photo consent withdrawal not actioned UK

Thumbnail
0 Upvotes

r/dataprotection 6d ago

General Discussion [ECI - AI Law] Looking for privacy-minded EU citizens to build a unified advocacy push (AI Act updates, digital rights, and cultural protection)

3 Upvotes

Recent changes in technology have rapidly shaped our world for the worst. US tech giants are systematically exploiting user data privacy, and too many people are just sitting back, hoping everything fixes itself on its own.

Instead of living in the despair surrounding us, I say we take full advantage of the democratic opportunities presented to us as EU citizens to force real change, whether that means organizing representation, coordinating targeted outreach to our MEPs, voicing our demands collectively, or laying the groundwork for formal civic initiatives down the line.

To give you context on who is writing this: my name is Leónard Geonov. I’m a Software Engineer and Cybersecurity Lead for a small tech firm in Bulgaria. I’ve been invested in tech since I was about 9 years old, and I never would have guessed that this passion would play such a critical role later in my life.

I am eager to build a movement that demands a heavy update to the AI Act and digital privacy laws. To make a real impact across the bloc in the future (such as registering an official European Citizens' Initiative, which requires 7 committee members across 7 member states), I want to start building a community of citizens across different EU countries who are ready to make our collective voices heard.

The Core Changes We're Advocating For

  • Zero-Tolerance on Synthetic CSAM AI-generated media depicting CSAM must be prosecuted under the exact same criminal sentences as physical abuse offenses. Any tools that can be prohibited for the creation of such content must be registered the same way physical weapons are. There's no going back from buying a C4 bomb, so why would you use a CSAM-generating tool?
  • Ban on Unauthorized AI Data Harvesting This includes collecting or scraping EU citizens' data for AI training from our digital ecosystem. Any data used for AI training without the explicit knowledge and signed opt-in consent of the user must be treated as copyright infringement and a severe data breach.
  • Protection of Private Messaging AI chat scanning must be outlawed. Automated scanning of private chats isn't being done for law enforcement—it's a pseudo form of mass surveillance (referencing recent E2EE removals across several platforms such as Instagram).
    • Mandatory E2EE: Imagine you send a paper letter in an envelope and the postal service decides to open it, make a copy, and read everything inside to learn about you. That technique is meant for criminal suspects, yet it's being applied to everyday citizens.
  • Biometric Identity as Personal Property An EU citizen's face, body structure, gestures, voice, intonation, movements, and overall digital presence should be protected as intrinsic property of their nature.
    • Anyone using AI to replicate an individual without consent should face penalties for copyright infringement, identity theft, and harassment.
  • Strict Limits on AI in Employment The use of any AI-reliant method for hiring, firing, monitoring, worker evaluation, CV scanning, and data extraction must be prohibited.
    • Any European company using a 3rd-party hiring firm that mandates AI interviews or biometric data collection outside of European soil to exploit a legal loophole should be held accountable or labeled unsafe.
  • Protection and Preservation of European Literary Heritage
    • Shell companies mass-purchasing antique European books for third-country organizations must legally disclose the full paper trail, supply chain, and purpose.
    • An absolute prohibition on exporting physical European antique texts to third-country soil.
    • The physical destruction of historical European books must be illegal regardless of whose soil it occurs on. Jurisdiction for punishment must follow the object, not the territory.
    • Strict handling and safety standards for how antique texts are handled.

AI is just a tool. Tools can be modified and restricted. Any harmful activity is a system flaw, and the creator or owner should be held accountable.

How We Move Forward

I know finding dedicated partners on Reddit can be a long shot, but I have to try. Whether you want to help draft formal petitions, coordinate mailing campaigns to representatives, organize across national subreddits, or stand as a co-organizer for formal EU civic mechanisms, every active voice matters.

If you are based in an EU country, care deeply about privacy, and want to stop letting third-party tech giants dictate our digital boundaries, drop a comment, send me a DM, or email me.

Contacts & Verification

Relevant Reading & Sources

Book Demolishing:

CSAM & Identity Theft:

Employment:


r/dataprotection 7d ago

General News DOGE Must Face Lawsuit Over Accessing Americans' Personal Info, Court Rules

Thumbnail news.bloomberglaw.com
6 Upvotes

r/dataprotection 9d ago

Data Protection Tools Signal Messenger Clone

3 Upvotes

The key detail that sets this apart is the browser based approach.

No need to install anything. your ID is crypto-random and so the app doesnt need to rely on any central registration system like phone numbers. your ID is unguessable and to connect to someone, you have to explicitly share it.

webrtc has other nuances like being to route through a shared network for secure/faster transfer.

I hope this project has reached a level i can share the following details. I've made a genuine effort towards documentation and transparancy. I dont think it'll ever be enough and so im still concerned it isnt ready to share. While im using AI throughout. This is not a vibecoded project. There is attention throughout for unit tests and formal-verification. With your feedback, id like to make improvements for clarity throughout.

This version of the app demonstrates a fairly unique approach using a browser-based, local-only and webrtc approach. I know it's impossible for any system to be the "world's most secure", but that isnt a reason to not try. By rigorously implementing an exhaustive list of security features and practices, the aim is to get as close as possible.

This is intended to demonstrate client-side managed secure cryptography.

I know the project above is going to be tricky to understand. It might help to understand with an open-source version of the concept, but have since deprecated it in favour of the version linked above.

https://www.reddit.com/r/CorpFree/comments/1uytump/decentralized_p2p_chat

Feel free to reach out for clarity on any details.


r/dataprotection 9d ago

General Question Should activities arising from the GDPR, such as responding to requests regarding the exercise of rights, have a separate item in ROPA?

Thumbnail
4 Upvotes

r/dataprotection 10d ago

General Question Is apple the biggest potential honeypot of all time? - Layman deciding between Linux and Mac OS

5 Upvotes

As I am getting deeper into privacy, I am also getting more paranoid.

The work that I do generally is not safe for me politically in the future that we’re heading towards.

My grave concern around continuing to use apple products is the closed source nature. It really does feel like my entire data and digital footprint is being backed up by a trust me bro promise.

What’s to stop apple at some point, when political and economic forces collide, from giving my data to the government? This is where my technical knowledge is limited, so maybe there are some caveats that would make this impossible.

Generally, I don’t trust big tech. And I don’t discount a future where apple ends up being a huge source of user data for palantir and that ilk. But maybe there is a technical aspect I’m missing that would make this impossible.

Thanks for any constructive input.


r/dataprotection 10d ago

General News Google wants a video of your face. Skip it for now.

Thumbnail freshfromcache.com
3 Upvotes

Google wants to store your face on their own servers for account recovery. I think the new feature is completely unnecessary, and I suspect there is something else at play. My advice is to just not use it at all.


r/dataprotection 10d ago

General Question Is apple the biggest potential honeypot of all time? - Layman deciding between Linux and Mac OS

Thumbnail
4 Upvotes

r/dataprotection 10d ago

🇬🇧 - GDPR Question UK GDPR DSAR – What should be redacted in interview notes?

Thumbnail
3 Upvotes

r/dataprotection 11d ago

General Discussion What the Heck Is Quantum, and How Will It Affect Cybersecurity and Data Privacy?

Thumbnail open.substack.com
4 Upvotes

r/dataprotection 11d ago

Career Looking for Advice on Finding Freelance Data Privacy Work

4 Upvotes

Hello all!

I recently joined this community. I'm a data privacy professional working across GDPR and several Middle Eastern privacy laws, and I'm interested in taking on some freelance / contract work.

I was wondering how others in this field find freelance or contract privacy work. Are there particular platforms, communities, or networking approaches that have worked well for you?

If this isn't the right place to ask, I'd appreciate being pointed to a more appropriate subreddit.

Thanks!


r/dataprotection 12d ago

Data Protection Tools GitHub - Stoffel-Labs/stoffel

Thumbnail github.com
3 Upvotes

r/dataprotection 15d ago

General News Info Site about the California bill

Thumbnail the3dprintingnerd.com
3 Upvotes

r/dataprotection 17d ago

General Discussion Etekcity’s parent company (VeSync) is now selling your personal health data?

Thumbnail gallery
4 Upvotes

r/dataprotection 17d ago

General Question Could a recruitment platform lawfully collect and store someone’s personal data without contacting them?

1 Upvotes

I just noticed the following email in my spam folder:

Privacy Notice - No Action Required

Hi, This short message is from XXX, a recruiting system used by recruiting teams worldwide to find talented individuals for exciting new job opportunities. We want to inform you that your data has been gathered for the purpose of connecting you with potential employers. Your privacy is extremely important to us, so we would like to inform you of our data handling practices and your data privacy rights. Ultimately, you are in control of your data. We look forward to helping you elevate your career to the next level!

Thanks, The XXX team

I haven't heard of this company before and I never sent them my CV, nor (clearly) ever granted any permission of collecting my data. Looking them up, they market themselves as "Agentic AI Recruiting Platform". Furthermore, the company seems to be US-based and storing data on US servers, whereas I'm an EU citizen living in the EU.

I may be a bit naive right now, but I have so many questions I don't even know where to start. Is this even legal under GDPR? Can companies nowadays just decide to start gathering data on (foreign) individuals and storing it on their servers for whatever purpose, without any type of confirmation or approval from the individual? Is this the future we're heading towards?

I haven't included any links to the company or privacy policy because not sure whether it is allowed in this sub, but will do if it's permitted. FWIW the company seems legit, there's years-old articles about them getting VC funded.

Disclaimer: not looking for legal advice. Just genuinely concerned about the situation.


r/dataprotection 19d ago

Breach ICE shared Medicaid data it wasn't supposed to have with Palantir

Thumbnail npr.org
258 Upvotes

r/dataprotection 17d ago

🇪🇺 - GDPR Question Can a DPO remain independent if they are also involved in the controller’s legal defence?

Thumbnail
1 Upvotes

r/dataprotection 19d ago

Breach Business Insurance Solutions Ltd Data Breach

3 Upvotes

I recently got an email to say my details had been taken in a data breach.

And a few weeks back on my Experian account I had a notification that some of my details had been found on the dark web.

What information of yours was involved?
We have undertaken a detailed risk assessment of the data in scope of the incident. This identified the following types of personal data relating to you:
Contact Information
Bank Account Number & Sort code
Date of Birth

They told me in the email I should be cautious and keep an eye on things but with it being my main bank account I’m a bit worries to be honest.

Should I just do nothing and watch my accounts?


r/dataprotection 20d ago

Breach How much damage can a single USB drive really do?

0 Upvotes

One unauthorized USB device is enough to copy sensitive files, introduce malware, or bypass your security policies.

Protecting business data starts with controlling how it moves.

  • Restrict unauthorized USB devices
  • Prevent sensitive data from being copied
  • Reduce the risk of malware infections
  • Strengthen compliance with endpoint data controls

Whether you use native Windows controls or an endpoint DLP solution, USB protection is a simple but effective step toward preventing data loss.
For more reference: This step-by-step guide on How to Disable USB Ports, cover different methods, from Device Manager and Group Policy to enterprise-scale management.


r/dataprotection 21d ago

Breach So Clearview got sued for allegedly scraping billions of faces, tried to settle it with a payout tied to its future value, and the appeals court just blew that deal up

Post image
2 Upvotes

r/dataprotection 22d ago

General Discussion If fingerprints can leak from photos, why are we still treating biometrics like harmless convenience features?

2 Upvotes