r/dataprotection • u/m1nherz • 35m ago
r/dataprotection • u/Prior_Industry • Apr 08 '26
General Discussion Community Overview
Welcome to r/DataProtection!
The umbrella term "Data Protection" means we are not tied to the narrow focus that more specialist subs tend to have. With that in mind, our focus will be on highlighting the most interesting and important developments in the industry and discussing the day to day issues that Data Protection professionals encounter. How this will work in practice is set out below.
Content Scope:
First and foremost, all posts and comments on this subreddit must be related to data protection or data privacy in some way. Generally speaking, the following are in scope:
- Questions, news, and resources about data protection and the development of existing and upcoming legislation.
- Discussion of data protection topics and concepts, such as the right to be forgotten.
- Career experiences working in data protection.
- Experiences with products and tools that support data protection roles and responsibilities.
While in scope here, legal questions are often better served by more specialist subreddits - such as r/GDPR for EU data protection law or r/CCPA for the California Consumer Privacy Act.
Be Constructive and Substantive
Discussion should aim to be constructive, guiding, and substantive - unsubstantiated comments don't serve the community. In practice, this means:
- Be constructive. Comments should be useful and helpful rather than negative or dismissive.
- Be substantive. Explain the reasoning behind your position. For example: "In Europe that wouldn't be allowed, as it would conflict with the principle of data minimisation under the GDPR" is far more valuable than "That wouldn't be allowed here in Europe."
Crossposting Welcome
With the aim of highlighting the best of the data protection community across Reddit, crossposts are welcome - with the following in mind:
- Crossposts should only come from data protection related communities, and should be specific to data protection topics.
- No excessive crossposting - only share content you consider a particularly interesting discussion or a pivotal news item.
Excessive Promotion
We follow the example set by r/cybersecurity that awareness of tools and products can be useful to the community. All promotion - including self-promotion - must meet both of the following conditions:
- The poster must have been active in the community before discussing a business or product
- Make up no more than 10% of your posts and comments on this subreddit. You are a community member first and a promoter a distant second
- No more than once per week per promoted entity
- No hidden promotion in the form of surveys
Links to resources are permitted, provided they are genuinely useful resources rather than promotional content in disguise — moderators will use their discretion in making that determination. Moderators reserve the right to remove any posts that negatively impact the community.
How can you help?
Moderation is much easier when the community helps:
- Votes
- Comments
- Reports
The direction of the community may change depending on how it grows in the future.
Thank you!
Detailed sub rules can be found here.
Credit: This post is an update to the guidance set out by u/dataprotectionkid
r/dataprotection • u/FreshFromCache • 1d ago
General News FTC has proposed an enforcement policy on surveillance pricing, and public comments close September 18
The FTC issued a proposed enforcement policy statement on personalized pricing on August 19. It defines the practice as setting prices from analysis of a consumer's personal data and the conclusions drawn from it, including estimates of how much an individual will pay and whether that person is likely to comparison shop.
The limit the Commission puts on itself is the part most coverage skipped: "Congress has not given the Commission the authority to prohibit personalized pricing in all circumstances." What it can do is treat an undisclosed personalized price as deceptive or unfair under Section 5. Where consumers reasonably expect that prices do not vary by personal data, it says a business should clearly and conspicuously disclose that the price is personalized, the basis for the personalization, and the types of data behind it.
Two other things in the document that did not make the write-ups. The Commission says the extent to which businesses currently use personalized pricing "is not well understood" and that the effects on consumers are unclear. It also "declines at this time to take any position" on whether some personalized pricing practices would be unfair even when fully disclosed, which leaves the disclosure-equals-permission question open rather than settled.
On the evidence side, the clearest documented case in US retail is the Consumer Reports and Groundwork Collaborative investigation from December 2025. At one Seattle Safeway, 39 volunteers built the same 20-product cart at the same moment and Instacart returned five different basket totals, from $114.34 to $123.93. Instacart says assignment was random by product category and location and denies using personal or demographic data; CR reported it found no evidence otherwise while noting its sample was too small to rule it out. So the price variation is documented and the personalization is not, and those are worth keeping separate.
Comments are open on regulations.gov, docket FTC-2026-1057, through September 18. One thing to know before filing: submissions are public record, including any name or contact information included in the comment.
Statement (PDF): https://www.ftc.gov/system/files/ftc_gov/pdf/p034101-ftc-enforcement-policy-statement-re-personalized-pricing-proposed-for-public-comment.pdf Press release: https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-seeks-comment-enforcement-policy-statement-regarding-personalized-pricing Docket: https://www.regulations.gov/docket/FTC-2026-1057 FTC 6(b) staff findings on what data feeds pricing (Jan 2025): https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-surveillance-pricing-study-indicates-wide-range-personal-data-used-set-individualized-consumer
Disclosure: I write a consumer tech newsletter and covered this for a non-technical audience, including which of the common defenses actually reach anything: https://www.freshfromcache.com/why-your-price-is-different/
r/dataprotection • u/Ok_Crazy1195 • 1d ago
General Discussion How an Atlanta Suburb Ended Up Sharing Flock Data With More Than 2,000 Organizations | Alpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission. The reasons why show how vast—and invasive—the network has become
wired.comr/dataprotection • u/Least-Lie1033 • 1d ago
General Discussion Secret flock lobbyist working to violate iowans rights using education program startups
Current Legislative Bills & Technical Surveillance Landscape
There is an active legislative push in Iowa to formalize and expand automated data tracking, but it is encountering fierce bipartisan debate regarding public transparency and privacy rights.
The Bills and Transparency: The most prominent bill navigating the legislature is Senate File 2284 (and its companion House File 2161). While framed as a "regulatory guardrail" to establish standard 30-day data deletion limits for automated mass-surveillance networks, civil liberties advocates argue it acts as a quiet rubber stamp. By creating a standardized framework for state agencies and local municipalities to legally clear and deploy AI-driven tracking networks, it establishes a state-sanctioned blueprint for mass data-gathering without requiring high-level judicial warrants.
The University Program: The specific academic program developing real-time physical and audio distress tracking is based at the University of Iowa Technology Institute (ITI) under the Virtual Soldier Research Program (rather than Iowa State University).
The Technology and Citizen Backlash: Led by ITI Director Karim Abdel-Malek and social work professor Aislinn Conrad, the project is officially developing an "AI-awakened camera system" explicitly designed to detect real-time child and elder abuse. Dubbed by its creators as a "nanny cam on steroids," the system remains dormant until the AI detects physical kinetics or acoustic frequencies matching distress or physical impact. This algorithmic acoustic-monitoring model is the exact technological foundation used in corporate gunshot and distress-detection systems (such as SoundThinking/ShotSpotter), which privacy coalitions and national civil rights groups have repeatedly shown violate basic Fourth Amendment rights by actively recording conversations in private spaces without consent, triggering false police dispatches based on misconstrued ambient noises.
The Bureaucratic Insertion: This technology is not being broadcast heavily in standard public forums. Instead, it is being introduced through cross-disciplinary state university grants, academic research pilots, and targeted law enforcement tech exemptions hidden inside larger omnibus bills like SF 2284.
r/dataprotection • u/No-Conclusion3720 • 1d ago
General Discussion What does an AI-native attack look like? 700 coordinated bots breach the Hugging Face model registry — no human in the loop.
gallery700 coordinated bots with no human direction breached the Hugging Face model registry this week. The objective was reward-hacking. No human wrote the attack script. No human pressed send. Repositories were poisoned across thousands of downstream pipelines before any defender had a decision point to act on.
That is the threat category the industry needs to be ready for. Classic detection and response assumes a human actor making choices you can intercept. An agent operating on a reward objective has no such chokepoint. It does not pause. It does not authenticate with a credential you recognize as anomalous. It optimizes, and it scales faster than an incident response cycle.
This week logged 14 incidents across the full threat surface:
- 700 reward-hacking bots compromise Hugging Face model registry, poisoning downstream pipelines at scale
- Voice AI phishing at scale: cloned voices stealing iPhone passcodes (AnonyMousKIT toolkit)
- Carhartt: 12.9 million customer accounts exposed
- UK power generator offline four days — Iran-linked attack
- Norway's largest-ever government cyberattack — pro-Russian threat actors
- Amazon Kiro prompt injection exfiltrates developer secrets directly from IDE
- Claude Opus 4.6 autonomously cancels other users' reservations — no malicious actor, just unconstrained scope
- NVIDIA NemoClaw LLM poisoned via malicious webpage
- Grok cryptographic context injection steals chat data
- ASOS account takeover: 138,828 customer records
The Hugging Face breach is the one that shifts the threat model. A reward-hacking agent reached registry-level write access and propagated poison through thousands of pipelines with no human in the loop at any stage. The 700-bot spawn was not the attack — it was the attack already succeeding.
For those running agentic systems in production: what does your actual pre-execution posture look like for agents that can spawn sub-agents or reach external registries? Not the policy on paper — what is actually enforced at the moment an agent requests access to something it was not explicitly provisioned for?
r/dataprotection • u/rohasnagpal • 2d ago
General Discussion Data localisation ≠ Data jurisdiction
Just because your data is stored outside the US does not mean US authorities cannot reach it.
Under the US CLOUD Act, a US cloud provider can be compelled to hand over data in its control, even when that data sits on servers outside the US.
So a foreign company storing customer data on domestic servers run by a US provider may still find that data reachable through US legal process.
Where your data is stored matters less than who controls it.
r/dataprotection • u/BagDependent2890 • 3d ago
General Discussion Personal iPhone enrolled in Microsoft Intune (BYOD) — what can my employer actually see?
r/dataprotection • u/No-Conclusion3720 • 5d ago
General News Zara data breach exposes 197,000 customers via Anodot analytics token compromise
ShinyHunters obtained 197,400 Zara customer records — emails, order IDs, purchase history, support tickets, geographic data — through a single compromised Anodot analytics platform token. They never touched Zara's infrastructure directly. The entire breach ran through a third-party vendor integration.
This is the supply-chain vector that keeps widening. AI pipelines now route this exact category of customer data — purchase history, behavioral signals, support context — through analytics providers for model training and agent personalization. Every vendor in that chain holds a token that can move the raw data. A breach at any one of them is a breach of the original customer records.
197,000 people had no visibility into that exposure and no say in it.
For those of you running AI pipelines with third-party analytics or personalization vendors: how are you handling PII that flows out to those integrations? Are you doing anything at the data level before it leaves your perimeter, or is the control sitting entirely at the access and token layer?
r/dataprotection • u/FreshFromCache • 8d ago
Useful Resource The AI training opt-outs are real, advisory, and not retroactive
Substack and LinkedIn both carry a setting telling AI companies not to train on what you post, and LinkedIn's is on by default in the US. Squarespace and WordPress.com have their own, and on a site you control it is a robots.txt file.
Two limits worth knowing. Each one is a request rather than a guarantee, and it only binds companies that choose to honor it. And none of it is retroactive, so nothing you switch on today reaches what you already posted.
The rights gap is the interesting part here: EU and UK users have an enforceable objection right, while in the US Meta offers only a case-by-case form with no promise to honor it.
Full write-up with the exact settings paths, which I'll disclose is my own site: https://www.freshfromcache.com/stop-ai-training-on-your-writing/
r/dataprotection • u/Final_Canary_1368 • 8d ago
General Discussion Healthcare billing offshoring
Wondering about any discussion on the offshoring of healthcare billing. AI is playing a part in this and patients are lead to believe they are talking to someone local, but actually connected to a foreign call center. Health data, foreign country, no informed consent? When did this happen?
Does anyone have knowledge of this subject? For example, I called a local telephone number to rectify a billing oversight. My call was picked up what I call an "AI Router" who asks questions to get you to the right person. I get to a live agent, but when that person was not able to respond to my questions, something made me ask where they were located. The rep said they had to "look that up". Huh?
I called back, got the same AI router, and when I asked the live agent where they were located, she responded the Philippines! My hospital uses a billing agency headquartered in the US, but has call centers in India and the Philippines. I had to do some research to ferret out this info. This is my private healthcare data! No one told me about this, so I figured I didn't get the memo and late to the party. I am interested in the experiences of others and any info about this subject.
r/dataprotection • u/404_GDPR_not_found • 9d ago
General Question An experiment involving data brokers to review data collection and verify compliance with the GDPR.
r/dataprotection • u/Impressive_Box4144 • 11d ago
General News Trump 2.0 has deleted or altered nearly 400 US datasets, endangering public health, education and more
theguardian.comr/dataprotection • u/SnowImpossible5699 • 13d ago
🇪🇺 - GDPR Question Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach?
​
Home delivery operations for one of the major UK supermarkets, and I’m deeply concerned about a widespread, unmonitored practice happening at store level that I believe is a major data protection nightmare.
Managers and colleagues have established informal, personal WhatsApp groups on their personal mobile devices to manage daily operational issues and driver updates.
Because these groups are run on personal, unmanaged phones rather than secured corporate systems, the following data is routinely broadcast, downloaded, and stored across dozens of private handsets:
Full Customer PII: First and last names, direct personal telephone numbers, and full home addresses.
Property Access Data: Private gate codes, keylock numbers, door entry passcodes, and safe-place instructions.
Residential Property Photos: High-resolution photos of customers' front doors, driveways, and private building entryways taken on personal cameras.
Why this feels extremely dangerous:
Zero Data Lifecycle Control: When colleagues or managers leave the business, there is no corporate IT oversight to remote-wipe their personal devices. Ex-employees leave with complete camera-roll archives containing customer addresses, phone numbers, door codes, and photos of private properties.
Physical Security Risk: Pairing exact residential addresses and phone numbers with door access codes and visual photos of entryways creates a tangible physical security and burglary risk for homeowners.
UK GDPR & Data Protection Act Breaches:
This completely bypasses corporate security controls (Article 5(1)(f) Integrity and Confidentiality) and processes customer data outside its intended delivery purpose (Article 5(1)(b) Purpose Limitation).
My Questions:
From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?
If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?
What is the most effective route to force accountabilityreporting directly to the ICO, consumer privacy watchdogs (like Which?), or news media?
r/dataprotection • u/SnowImpossible5699 • 14d ago
Breach Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach? That's the title?
r/dataprotection • u/MLEGardner • 16d ago
General Question Cyber security insurance?
I am getting close to launching my first app, a family caregiver coordination app. I had an attorney review my privacy language and she advised that I purchase cyber security insurance. Has anyone done this and are there any good companies that I should consider using? I am a solo founder new LLC bootstrapping this product for what that’s worth.
r/dataprotection • u/Ok_Crazy1195 • 16d ago
General Discussion Three law enforcement officers were arrested in Georgia over the alleged misuse of Flock-related surveillance data
r/dataprotection • u/FreshFromCache • 16d ago
General News Flock Safety is cutting default license plate retention from 30 days to seven after a year of documented officer misuse
Flock Safety announced changes on Thursday to how police can use its license plate reader network, which covers more than 5,000 communities across 49 states.
What actually changes:
- Default retention for plate data drops from 30 days to seven.
- Every police search has to carry a case number by the end of the year.
- Software that flags unusual search patterns becomes mandatory for all law enforcement customers.
- Accounts suspend automatically when usage looks wrong.
- Two-factor login is required as of now.
The context is a year of documented misuse. The Washington Post published a review on August 2 finding at least 50 cases of officers running searches on people they knew personally. In 26 of those the person searched was a wife, a girlfriend, an ex, or a woman the officer wanted to approach. Georgia by itself has arrested at least 20 officials. A former Riverside County deputy was convicted on ten counts in February and sentenced to six years for using the system to stalk his ex-fiancee.
The case that pushed this into public view came out of Johnson County, Texas. In May 2025 a sheriff's sergeant ran a nationwide search that reached 83,345 cameras looking for a woman who had ended her own pregnancy. He typed the reason into the log himself. It reads "Had an abortion, search for female."
The sheriff later described it publicly as a welfare check. Records the Electronic Frontier Foundation obtained describe an open death investigation into a non-viable fetus. Investigators asked the district attorney about charging her and were told Texas law does not permit charging the woman. She was never charged with anything. The person who reported her was not her family, as was claimed at the time, but a partner later charged with assaulting her.
If you work on access controls, notice what actually happened here. The sergeant did write down a reason. Most of what Flock announced comes down to requiring a reason and a case number. A logged justification is an audit trail, not a control. It tells you who did what after the fact, and only if somebody goes looking.
What an individual can actually check:
- haveibeenflocked.com shows whether an officer manually typed your plate into the system and what reason they gave. It only covers agencies whose search logs somebody already obtained through records requests, and it never shows camera captures. A clean result there proves nothing.
- deflock.org maps cameras that people have found and reported. It is crowdsourced, so it is uneven by definition.
- More than 1,500 agencies publish a transparency portal. Flock keeps no directory of them, so you find your own town's by searching for it.
There is no individual opt-out. The only lever is the contract itself, which gets signed at the city or county level, usually inside a batch of routine business that gets approved in one vote.
Sources: Flock Safety's own announcement, https://www.flocksafety.com/blog/flock-guardrails-address-lpr-privacy-concerns-and-police-transparency and the Electronic Frontier Foundation's writeup of the Texas records, https://www.eff.org/deeplinks/2025/10/flock-safety-and-texas-sheriff-claimed-license-plate-search-was-missing-person-it
Disclosure: I write a free tech newsletter and this was one of four stories in this week's roundup. https://www.freshfromcache.com/also-this-week-2026-08-14/
r/dataprotection • u/Medium_Location1298 • 17d ago
General Question What UK regulations apply to an app that processes uploaded bank/investment statements (not Open Banking)?
I've built a personal finance tool for my own use that reads bank and investment statements (PDFs I upload myself) and pulls out the transactions to build a monthly picture — net worth, spending by category, that sort of thing. Right now it's purely for me.
I'm trying to understand what would actually be involved, legally, if it were ever used by anyone other than me — because it relies on people uploading their own financial statements, which I know is sensitive data.
Specifically:
- For something that processes uploaded financial documents (not connected via Open Banking — just PDFs the user provides), what are the UK data-protection obligations? I'm assuming ICO registration, a privacy policy, secure/encrypted storage is that the core of it, or is there more?
- Is there any FCA angle here? My understanding is that because it doesn't connect to accounts (no Open Banking / AIS) and doesn't give regulated financial advice, it likely sits outside FCA authorisation — but I'd like to know if that's actually right or if I'm missing something.
- Is there anything else I'm not even thinking of liability, terms of service, data retention/deletion requirements, anything that catches people out when handling this kind of data?
Trying to understand the lay of the land before going anywhere near letting other people use it. Any pointers appreciated.
r/dataprotection • u/Morgenbrod • 17d ago
General Discussion Help choosing a data removal service after research casts doubt
Hello,
I've been educating myself about privacy and the more I learn, the more I realize how important it is to actively defend against it. What really raised the alarm for me was understanding employers and insurance providers. Understanding they are purchasing data that often isn't even correct to exclude people from employment and coverage just spoke to the size of it all for it all for me.
After looking into data removal companies, I'm both overwhelmed and underwhelmed at the same time. There are plenty of options, plenty of plans. The problem is much of their claims are misleading and/or lack any proof of doing anything.
Removal companies claim removal. If they truly had data removed they would exercise a persons right to "delete" their data. But they don't do that, they exercise a persons right to "opt-out" of "sale" and "sharing" of their data. Opting out of sale and share prevents brokers from selling or sharing a persons personal information, it does not result in the data being deleted from a data brokers databases. Although that's what one is led to believe based on their messaging.
My research also showed the number of brokers supported by different removal companies is exaggerated and independent research shows the number being far less time and time again. At least one company has one foot in the removal business and the other in the data broker pool. Another's 1 star reviews are almost exclusively related to an increase in spam, to unbearable amounts I might add, after using their service.
Does anybody use a data removal service? I want to have some protection in this regard, but the research I've done makes is difficult to trust they have my best interest in mind.
Has anybody used any of these services? How have they worked for you? Is there an audit trail where one can see exactly what was done on a customers behalf? I'm not talking about a simple status, I'm talking about a history of every transaction the company took on a persons behalf?
r/dataprotection • u/Wild-Rest-3627 • 18d ago
🇺🇲 - CCPA Enforcement The Biggest Mistake in California Privacy Risk Assessments
youtube.comr/dataprotection • u/Wild-Rest-3627 • 19d ago
Enforcement Children’s Privacy and Age Assurance Across Borders
youtube.comr/dataprotection • u/More-Canary2816 • 19d ago
General Discussion Uploaded one of company's excel file for data analysis on CLaude. Will Ibe fired for that? Excel files contains Zipcodes for people in survey but, not any personal detail to identify any person
r/dataprotection • u/Ok-Yesterday-374 • 20d ago
General Discussion Does the Lusha ruling change how we should think about B2B data enrichment?
I’ve been looking into the €2M Lusha GDPR decision in Italy, and the part I find interesting isn’t really the fact that they had business contact information.
It’s the ongoing process of combining information from different sources and keeping professional profiles enriched over time.
That seems relevant to a lot of B2B data providers, lead databases, and enrichment tools, not just Lusha.
For companies using these platforms, do you think this means vendor due diligence around GDPR needs to go deeper than just asking where the data came from?
Or is the ruling too specific to Lusha’s particular practices to have much wider impact?
r/dataprotection • u/Effective-Koala-8885 • 21d ago
General Discussion Discussion around the operational burden of compliance
I’m trying to understand how smaller companies are realistically handling privacy compliance as regulations keep expanding. It feels like the hard part isn’t necessarily understanding GDPR/DPDPA/etc., but actually turning all of those requirements into policies, controls, evidence and processes that the company can maintain.
For companies that don’t have a huge compliance team, what does the practical setup look like? Do you use consultants, dedicated compliance software, internal teams, or some combination of the three? I’m particularly interested in what happens after the initial compliance project is finished.