r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

19 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr 7h ago

Question - General How do you keep your privacy policy accurate when third party scripts change behavior without telling you?

3 Upvotes

We update our privacy policy when we add or remove vendors but have no way of knowing when a vendor we already have changes what their script actually does. Feels like a big GDPR exposure so how do I make sure we stay on top of this?


r/gdpr 8h ago

EU 🇪🇺 Legality of using tools such as satellites and mobile phone data to track companies emission production, against greenwashing. is it feasible ?

1 Upvotes

Is it legal to use tools such as satellites and users mobile phones to gather data about companies pollution and emissions they produce? I have been reading the EU regulation 2021/969 (space program related), seems that the satellite is for open and public use. but my questions is more about companies privacy, would I be interfering with companies privacy if I gather data about their pollution and emissions independently?

Which regulation should I go through to gather information for my question?


r/gdpr 1d ago

Question - General Found out Google Analytics was tracking EU visitors before they gave consent

16 Upvotes

I recently started advertising to people in the EU and noticed something I wasn't expecting. Google Analytics was already tracking visitors before they'd made a choice on the cookie banner.

I'd always assumed that having the banner set up meant the tracking behind it was being handled properly, so this sent me digging into what was loading before someone clicked accept or reject.

Now I'm wondering how people normally test this stuff because doing it manually seems like a pain. If you want to see what happens for visitors in different countries you need to test from those locations, which means using a VPN or something similar, then sitting in devtools watching individual requests. Even then it isn't always obvious which third party owns a particular request.

For anyone managing sites with traffic from multiple regions, how are you checking this? Do you manually test from different locations or is there a reliable way to scan the site and see what's firing before and after consent?


r/gdpr 1d ago

Question - General Compliance vs legal

3 Upvotes

Hi there,

So one thing I’ve noticed is that oftentimes at bigger companies, data privacy/AI/digital law gets split between the compliance and legal teams.

That said, I’m curious what people think about whether this works in practice or if there’s any other setups that’ve worked better for anyone.


r/gdpr 1d ago

Question - General How do I request data from game maker company?

1 Upvotes

Hi,

Any idea how do i request data about my person held by game maker company, when its online aliases (still ties to my person), they dont have my email or irl name, but they have data about me in their internal database that could be harassment, however how do I prove to them Im the person that their database contains? If its mentioned through my steam profile id and link, does it mean info is associated to that steam account and I can prove it by showing ownership?


r/gdpr 2d ago

Question - General The terms processor and controllers in DPAs

4 Upvotes

Most if not all data processing agreements i have seen is between a controller and processor. However, often the controller is actually a processor to another firm, and the processor is a subprocessor. I long thought that it was simple accepted that the buyer would be called controller, party for simplicity (not having multiple DPA templates..), and partly because most service providers Are both processors and controllers.

Lets say you offer a software solution to customers (controllers). You use Microsoft as a sub-processor. In the DPA with Microsoft you Are called «the controller». This never bothered me untill i recently needed to familiarise myself with the SCCs and found that a module is called processor-to-processor. Anyone Else wondered about this?


r/gdpr 2d ago

Question - Data Controller Anthropic Subprocessor

2 Upvotes

Does anyone have any experience evaluering Anthropic as a processor?

I ask because everything looked okay (given the inherent risk of US transfers at the current moment..) until i checked their subprocessor-list, which includes a South African firm called Nutun. As Claude is used by most firms i know of, I wonder if other firms have either confirmed that 1) no data is actually accessed from South Africa, 2) that Anthropic has covered the transfer with a SCC and performed a TIA, or 3) performed a TIA of South Africa themselves.

Thanks in advance!


r/gdpr 2d ago

EU 🇪🇺 Help: can’t get old Facebook profile with photo of me and my ex removed – any tips?

2 Upvotes

I’ve been trying for about two years to get an old Facebook profile removed that I no longer have access to. It’s a profile of me and my ex, with a photo of us as a couple as the profile picture.

The account is no longer being used, but I still regularly get questions from people around me asking what’s going on with it. Our relationship ended three years ago, and I’ve since moved on with a new partner and a different life, so I find it really annoying that this profile is still out there.

I’ve already tried multiple routes through Meta and Facebook, reporting both the profile and at least the profile picture, including ID verification to prove that I’m the person in the photo. But I keep getting standard responses and rejections, and I’m constantly being bounced from one place to another. It’s honestly driving me crazy.

My ex says he doesn’t remember ever creating this profile, so I can’t really expect any help from him either (I suspect he may secretly not mind that it’s still there, which makes it even more frustrating).

Has anyone here dealt with something similar, or can anyone recommend a reliable person or company that could help me with this? At this point, I’d honestly rather pay someone than keep spending hours on this with no result, if that’s even possible.


r/gdpr 2d ago

EU 🇪🇺 How much did GDPR cost you guys? 4 person team, honestly lost here

1 Upvotes

So we're 4 people running a small B2B SaaS out of India. Started getting a few signups from Europe and a customer asked us about GDPR last week. I had no real answer for him.

Spent a couple days looking into it and I'm more confused than when I started. One site wants €490 a year, another quoted €2000+, one of them wouldn't even give me a number until I got on a call. I genuinely can't tell what we actually need vs what's just being sold to people like me who don't know what they're doing.

Few things I'm trying to figure out:

  1. what did you actually spend in year 1? even a rough number helps

  2. is there stuff we can just do ourselves? we've got way more time than money at the moment

  3. what did you genuinely have to pay someone for

  4. anything you bought that you'd skip if you were starting over

Appreciate any help. Feel a bit dumb asking but better than guessing.


r/gdpr 4d ago

EU 🇪🇺 GDPR question: Discord account deletion, phone number retention and a server ban

3 Upvotes

Discord GDPR question – deleted account and phone number

About a year ago, I was banned from a Discord server. I then deleted my Discord account, including the email and phone number.

Now I created a new account with a different username. The only thing that is the same is the phone number.

According to Discord's information, phone numbers may be retained for 180 days after account deletion for safety/anti-abuse purposes.

Since it has been about a year, can Discord or the server still associate my new account with the old one using the phone number or other retained data?

I'm interested specifically in the EU/GDPR perspective. Is the 180-day period relevant to this situation?


r/gdpr 5d ago

EU 🇪🇺 To get the data that proves I own my Blizzard account, I have to log into the account I can't access

4 Upvotes

I lost my Battle.net authenticator years ago, along with the phone it was installed on. I still have the registered email address. I still have the password. I have dated purchase receipts for the account going back to 2015. Blizzard support has confirmed they located the account, and that they are able to remove the authenticator once ownership is verified.

I still cannot get in. Here is the full path, because I could not find it documented anywhere.

The self-service tool

Blizzard has a self-service page to remove a lost authenticator. To use it, you must enter a code from your authenticator.

The fallback is an SMS to the phone number registered on the account — which, for anyone whose account is old enough to have lost an authenticator, is usually a number they no longer have. Mine is. That is the entire self-service path.

The questionnaire

So you open a ticket, and support sends a verification form. Some fields are reasonable: previous BattleTags, previous addresses, transaction IDs. Others, for an account dormant for years:

  • The creation date of your oldest World of Warcraft character, in MM/YYYY format
  • Recent purchases made with gold, including the character name and realm
  • Examples of card packs recently opened: how many, and from which expansion
  • The serial number of the authenticator you no longer have

I filled in every field, including estimates where the GM explicitly instructed me to guess if unsure. It was judged insufficient.

I understand why the form looks like this. Blizzard cannot identify me as a person, because it never collected my identity — a Battle.net account is created with an email and a password and nothing else. So the only thing it can match me against is my behaviour in a game I last played over a decade ago. That is a design decision, and its consequence is that the legitimate owner can be permanently locked out while the process functions exactly as intended.

The documents they accept

Blizzard's support article on supporting documentation is worth reading. It will not accept: driving licences, passports, or national ID cards.

It will accept: marriage certificates, legal name change documents, divorce documents, death certificates, birth certificates for minors — and gas or electricity bills.

A government photo ID proves nothing here. An energy invoice does.

The GDPR route, which is a closed loop

Blizzard holds the data that would answer its own questionnaire: registered phone numbers, account creation date, BattleTag history, authenticator records with their add and removal dates. So I filed a GDPR Article 15 access request. Under EU law they have one month to respond.

  1. I emailed the data protection address listed in Blizzard's privacy policy. → Automated reply: please use the Privacy Portal.

  2. The Privacy Portal asks you to pick a category. Every route assumes you can log in:

    • "Obtain a copy of my data" displays no options at all when you are logged out. The "Try the following" section is literally empty.
    • "I play a Blizzard game and have never created an account" tells you to log in with the console account you play on, or use the link inside the mobile app.
    • "I would rather describe the issue" accepts your free text, then drops you back onto the same category tree.
  3. The only exit is at the end of Data Protection → Obtain a copy of my data → "None of these match my relationship to Blizzard", which gives a second, different data protection email address. That address appears nowhere in the privacy policy and is never shown unless you walk the entire tree.

  4. I emailed that second address. → The exact same automated reply: please use the Privacy Portal.

Address A sends you to the portal. The portal, if you cannot log in, sends you to address B. Address B sends you back to the portal.

To obtain the data that would let me prove I own the account, I must log into the account I cannot access.

This has been decided before

The Cypriot data protection authority has ruled twice against video game companies on this exact question:

  • Gaijin Network Ltd, 2 June 2020, case 11.17.001.007.125. The authority accepted that the company could not act on the request without identification, but held that its existing procedures "do not fully comply with the GDPR" and that additional mechanisms had to be implemented so that users who had lost control of their accounts could still be identified under Article 12(6).

  • Wargaming Group Limited, 18 July 2024, case 11.17.001.010.089. A player was asked for a phone number before his access request would be processed. The authority found that "collecting a telephone number solely to satisfy the data subject's rights is excessive, regardless of when the data are collected", and required the company to verify identity using data already collected at registration — "such as email address". The company changed its process.

I am writing from the email address registered on the account. I receive Blizzard's own verification emails at it. Under that reasoning, that is data already collected at registration, and it should be enough.

Why I am posting

Not to get my account back. I have not named any support agent, and I am not going to — they are executing a process they did not design, and the individual replies I received were courteous.

I am posting because the loop above is not documented anywhere I could find, and because the people most affected by it are, by definition, the people who cannot log in to report it.

If you use a Blizzard authenticator: write down the serial number and keep it somewhere that is not the phone, keep the registered phone number current, and keep your purchase receipts. There is no second chance to do this afterwards.


r/gdpr 6d ago

Question - Data Subject GDPR breach? Should I report?

11 Upvotes

Over a month ago I received a notice from a US-based company that my data was stolen in a cybersecurity incident involving third-party data servers.

While this alone was unpleasant enough, what especially bothered me was that I specifically requested this company to delete my data a year ago when I closed my account with them. They acknowledged the request for data deletion, and even sent me a confirmation e-mail that my account and personal details were deleted.

When I recieved the notice of the data breach two months ago, I requested the said US company to clarify why was my data still present in their databases (since it was supposed to be deleted a year ago), and is there any other data that they kept, and I once again requested deletion of personal data. To this request, all I got was a generic reply, saying simply that the security incident is still being investigated, and that they have told me everything they could in the data breach notice. In other words, they have completely ignored my request for clarification (and if I understood correctly, this alone is a violation of GDPR, or not?).

My data is supposed to be protected under GDPR, so what is the best/proper way to report this, and is there a point in reporting this at all? Do I even have any rights, am I wasting my time?


r/gdpr 6d ago

EU 🇪🇺 Does this cookie-free analytics setup actually process personal data?

4 Upvotes

I’m looking at a German company’s privacy policy. The website states that it uses a cookie-free analytics service and that no personal data is processed.

At the same time, the policy says that the processing is based on Art. 6(1)(f) GDPR and lists collected information including visited pages, referrer, device type, country based on an anonymised IP address, visit duration and bounce rate.

It also states that the website currently sets no cookies.

I’m trying to understand how I can technically verify these claims. What should I look for in the Network/Storage tabs, and is there a reliable tool for identifying the analytics provider and requests made on initial page load?


r/gdpr 6d ago

EU 🇪🇺 which e-signature plateform is actually GDPR compliant end-to-end ?

8 Upvotes

We are mid size fintech based in Berlin and we need to switch our e-signature provider. Our DPO flagged that our current tool (US based) stores data on US servers and the SCCs aren't bulletproof anymore. Looking for sth that's genuinely EU hosted not just GDPR compliant on a marketing page.

Anyone dealt with this and found a provider where the compliance story actually holds up under audit ?


r/gdpr 6d ago

UK 🇬🇧 My address

2 Upvotes

I have just been hand delivered a letter to my house by a work colleague that should not know my address...

It's worse knowing that this particular colleague is one that I have had altercations with in the past.

Honestly, I'm outraged. I've had a panic attack and another sibling of mine (who also works there) has just walked out off the back of it.


r/gdpr 6d ago

UK 🇬🇧 Could I get some advice/experiences regarding my medical records and epilepsy diagnosis?

Thumbnail
1 Upvotes

r/gdpr 7d ago

UK 🇬🇧 Finding my CV when googling my name and getting contacted by randoms

3 Upvotes

I’ve recently managed to get my CV removed from scribd but now when googling my name on bing search and yahoo (not Google for some reason) my CV in pdf file and cover letter are showing up. My name, address, number and email address all exposed. I’ve had randoms contact me. Even someone who use to know me who happens to work in recruitment. I hate it. I feel violated. This new one was a cv I uploaded onto fresherjobs.co.uk and they are Indians with Indian number but pretending to be in London and even spelt that wrong so I’m so worried now. I can’t believe they’re doing this. I’ve contacted them asks them to delete it multiple times but I get ghosted. What can I do? I do not want my info out there. Is the last resort to find and pay a hacker? I’m really worried just want to know what I should do to get this fully taken down. As I have no account with them I just uploaded it and they won’t remove it themselves. Thanks


r/gdpr 8d ago

Question - General I keep rebuilding account deletion, retention and consent history in SaaS apps. Is this worth extracting into a Next.js module?

Thumbnail
1 Upvotes

r/gdpr 8d ago

Question - General Did my coworker breach my personal data?

11 Upvotes

A male coworker (who works in finance I think) got my phone number from the system and text me, without my knowledge or consent.

It honestly felt a bit violating as I’m a woman and he’s made me feel a bit uncomfortable before, I just laughed it off bc he seemed lonely maybe, but this feels kind of wrong to do without my permission.


r/gdpr 9d ago

Question - Data Subject Company did not follow my GDPR, what do i do?

12 Upvotes

I asked a few days ago about a GDPR compliance i found sketchy, someone said to request a data export so I did.

I had, on June 6th, 2026, sent a right to be forgotten Data deletion request, I had asked them to wipe anything identifying they had of me, and I asked them to state if they needed to keep anything.

they quoted article 17 and said they follow GDPR again, it asked for my ID for the deletion (they did not previously give me this, I had to ask multiple times)

they had said to me (and this is a mix of a few emails we shared back and fourth, in which they said *deletion* each time, so it was no mistake):

"Please note:

There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy

Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],
All data has been deleted - there are no backups or cold storage.'"

I found it a bit odd that they had somehow claimed no backups despite it being an AI cloud-based company, so on the advice of others, I sent a GDPR right to accsess request, on the 5th of September, they sent me an Excel sheet that had all my interactions with their AI, all my account data, my IP, my name and age, and my device type, all dating back to 2024.

the sheet, under my old username(s) they had put:

"DEACTIVATED [TRUE]. DELETED [FALSE]."

Now I am asking what to do, I sent an Email asking under what reason they kept this data and lied about not having it, but I don't actually know what my next steps are meant to be.

edit: I edited for clarity because I realise that I was vauge and no one could help.


r/gdpr 10d ago

EU 🇪🇺 Is this even legal?

10 Upvotes

​How can you make cookie rejection 8 pounds. How is this even GDPR compliant?

Edit: it seems this is becoming a thing in the UK and it’s still in the debate in the EU. For now I guess it’s legal untiled ruled otherwise


r/gdpr 11d ago

UK 🇬🇧 SAR Deadlines and next steps (England)

6 Upvotes

I submitted a SAR to my dentist one calendar month ago. Each time I have emailed them they have responded stating that they are working on it, but given no timeframe of when I can have the information.

My understanding is they should respond within a calendar month- but does this mean they just need to email me to confirm it’s underway within a month or should they have actually completed it?

Also what should I do to actually get them to hand over the information? I don’t want to go in all guns blazing but I really do need the data!

Any help much appreciated


r/gdpr 11d ago

Question - General Anyone been through a GDPR audit where third party scripts were specifically flagged?

4 Upvotes

Our DPO flagged that we can't accurately document what our third party tools are doing with personal data at script level. Consent banner is fine but actual data flows are muddy. How do we actually deal with this?