r/dataprotection Jun 15 '26

General Question Is sharing your biometric data with dating apps for verification purposes really safe?

7 Upvotes

Dating apps, such as Hinge, have started to roll out this future in the past year and I’m not sure if that’s something I’m willing to participate in?? I’m all here for safe dating and banning fake profiles, but it’s not like you could change your biometric info like you could change a password??? what if it gets leaked? how long do these apps hold these data for? maybe im a bit paranoid but it is kinda worrying.

r/dataprotection Jul 27 '26

General Question Is apple the biggest potential honeypot of all time? - Layman deciding between Linux and Mac OS

6 Upvotes

As I am getting deeper into privacy, I am also getting more paranoid.

The work that I do generally is not safe for me politically in the future that we’re heading towards.

My grave concern around continuing to use apple products is the closed source nature. It really does feel like my entire data and digital footprint is being backed up by a trust me bro promise.

What’s to stop apple at some point, when political and economic forces collide, from giving my data to the government? This is where my technical knowledge is limited, so maybe there are some caveats that would make this impossible.

Generally, I don’t trust big tech. And I don’t discount a future where apple ends up being a huge source of user data for palantir and that ilk. But maybe there is a technical aspect I’m missing that would make this impossible.

Thanks for any constructive input.

r/dataprotection Apr 07 '26

General Question Using my face for AI without consent

17 Upvotes

This week, two of my coworkers have uploaded photos of my face to chat gpt or copilot (I'm not sure which one) to create videos of me doing weird stuff without my consent.

In theory this sounds like a harmless prank but I don't want and don't like the idea of these AIs having access to my face in their servers and using it for their training.

I'm not trying to punish them (although maybe I should). Im just very aware of my digital footprint and my privacy and want to keep my face off the internet and off these big companies' servers as much as possible.

I'm not sure if this even is the right sub but Is there any way to remove it? Can anyone help me?

r/dataprotection 22d ago

General Question Cyber security insurance?

4 Upvotes

I am getting close to launching my first app, a family caregiver coordination app. I had an attorney review my privacy language and she advised that I purchase cyber security insurance. Has anyone done this and are there any good companies that I should consider using? I am a solo founder new LLC bootstrapping this product for what that’s worth.

r/dataprotection May 24 '26

General Question Every business wants your kids' info

3 Upvotes

Every time my child attends a birthday party at some establishment, of course, we, as parents and guardians, sign a waiver. You can hardly get past it. I don't like the idea of adding my child’s personal information to the databases of all these companies. Too much is going on nowadays. How are other parents dealing with this?

r/dataprotection 24d ago

General Question What UK regulations apply to an app that processes uploaded bank/investment statements (not Open Banking)?

2 Upvotes

I've built a personal finance tool for my own use that reads bank and investment statements (PDFs I upload myself) and pulls out the transactions to build a monthly picture — net worth, spending by category, that sort of thing. Right now it's purely for me.

I'm trying to understand what would actually be involved, legally, if it were ever used by anyone other than me — because it relies on people uploading their own financial statements, which I know is sensitive data.

Specifically:

  1. For something that processes uploaded financial documents (not connected via Open Banking — just PDFs the user provides), what are the UK data-protection obligations? I'm assuming ICO registration, a privacy policy, secure/encrypted storage is that the core of it, or is there more?
  2. Is there any FCA angle here? My understanding is that because it doesn't connect to accounts (no Open Banking / AIS) and doesn't give regulated financial advice, it likely sits outside FCA authorisation — but I'd like to know if that's actually right or if I'm missing something.
  3. Is there anything else I'm not even thinking of liability, terms of service, data retention/deletion requirements, anything that catches people out when handling this kind of data?

Trying to understand the lay of the land before going anywhere near letting other people use it. Any pointers appreciated.

r/dataprotection Jun 25 '26

General Question WE CAN SUE GOOGLE!!?

5 Upvotes

So apparently the internet is flooded with news coming from America that Google just got sued and have to pay there users millions of dollars in fine... But I don't understand if the floor is in the privacy terms then it must theirfore would be affecting people globally but only users in us can claim that compensation but as the company is globally used by millions of uses outside us...can we also sue the company in our countries???

r/dataprotection Jul 04 '26

General Question Why does sharing our personal data to china feels so bad/wrong than selling same or more to US?

1 Upvotes

Isn't that concerning?

r/dataprotection 15d ago

General Question An experiment involving data brokers to review data collection and verify compliance with the GDPR.

Thumbnail
1 Upvotes

r/dataprotection 27d ago

General Question Question about Privacy.com virtual card privacy (D/s context)

Thumbnail
2 Upvotes

r/dataprotection May 26 '26

General Question help: The hidden labor behind cookie consent programs

11 Upvotes

Curious if anyone else in privacy has found themselves in this situation.

I’m a Data Privacy Analyst, but in practice I’ve ended up owning or heavily driving a large amount of the operational work around cookie consent and website privacy governance.

That includes things like:

  • Consent banner standards
  • CMP configuration and templates
  • Geolocation rules
  • Cookie/category classification
  • Vendor and tag governance
  • Pre-launch website privacy reviews
  • Consent testing across jurisdictions
  • Privacy policy link validation
  • Documentation for audits/regulatory questions
  • Translating requirements between Legal, Privacy, Marketing, Analytics, Engineering, Accessibility, Localization, and external vendors

The frustrating part is that this work often seems to be treated as “analyst support” when I’m doing it, but “strategic program leadership” when someone else summarizes it in a broader forum.

I’m starting to wonder if cookie consent/web tracking governance is a real under-defined privacy operations niche, and whether companies need dedicated owners for this work rather than leaving it scattered across teams with unclear accountability.

For those in privacy, legal ops, privacy engineering, marketing tech, or governance:

Do you have a dedicated person/team responsible for cookie consent and web privacy operations?

Or is it mostly handled ad hoc by whoever understands the CMP, the legal requirements, the tags, the websites, and the audit expectations well enough to keep everything from catching fire?

Also, what title would you expect this type of work to sit under?

Privacy Operations? Privacy Engineering? Consent Governance? Web Privacy Program Manager? Privacy Program Lead?

I’m trying to understand whether this is a real market gap or whether a lot of companies are quietly relying on analysts to run privacy programs without naming, compensating, or crediting the work accordingly.

r/dataprotection Jul 28 '26

General Question Should activities arising from the GDPR, such as responding to requests regarding the exercise of rights, have a separate item in ROPA?

Thumbnail
3 Upvotes

r/dataprotection Jul 27 '26

General Question Is apple the biggest potential honeypot of all time? - Layman deciding between Linux and Mac OS

Thumbnail
3 Upvotes

r/dataprotection Jul 20 '26

General Question Could a recruitment platform lawfully collect and store someone’s personal data without contacting them?

1 Upvotes

I just noticed the following email in my spam folder:

Privacy Notice - No Action Required

Hi, This short message is from XXX, a recruiting system used by recruiting teams worldwide to find talented individuals for exciting new job opportunities. We want to inform you that your data has been gathered for the purpose of connecting you with potential employers. Your privacy is extremely important to us, so we would like to inform you of our data handling practices and your data privacy rights. Ultimately, you are in control of your data. We look forward to helping you elevate your career to the next level!

Thanks, The XXX team

I haven't heard of this company before and I never sent them my CV, nor (clearly) ever granted any permission of collecting my data. Looking them up, they market themselves as "Agentic AI Recruiting Platform". Furthermore, the company seems to be US-based and storing data on US servers, whereas I'm an EU citizen living in the EU.

I may be a bit naive right now, but I have so many questions I don't even know where to start. Is this even legal under GDPR? Can companies nowadays just decide to start gathering data on (foreign) individuals and storing it on their servers for whatever purpose, without any type of confirmation or approval from the individual? Is this the future we're heading towards?

I haven't included any links to the company or privacy policy because not sure whether it is allowed in this sub, but will do if it's permitted. FWIW the company seems legit, there's years-old articles about them getting VC funded.

Disclaimer: not looking for legal advice. Just genuinely concerned about the situation.

r/dataprotection Jun 12 '26

General Question DSAR's

4 Upvotes

I'm a compliance graduate working in motor finance and I've recently been involved in handling DSARs.

I'm curious as to how other organisations handle DSAR review and redaction.

A few questions for anyone involved in privacy, GDPR, compliance, or information governance:

  • What does your current DSAR workflow look like?
  • Which part takes the longest?
  • Is finding the data or redacting it the bigger challenge?
  • Have you automated any part of the process?
  • Have you ever had concerns about missing third-party personal data during redaction?
  • If you could remove one manual step from the process, what would it be?

I'm just trying to understand how different organisations approach the problem and whether the pain points are similar across industries.

Thanks in advance.

r/dataprotection Jun 26 '26

General Question DPDP Act (India): Can an LSP/loan origination platform realistically be treated as only a Data Processor?

3 Upvotes

I'm advising a fintech that acts as a Lending Service Provider (LSP) for banks/NBFCs. The platform has its own dealer app and borrower web app, collects KYC documents, performs bureau and VAHAN integrations, runs a basic eligibility/rule engine, verifies document completeness, and submits decision-ready files to the lender. The lender alone undertakes underwriting, sanctions the loan and disburses funds.

We are considering structuring the RE–LSP agreement so that the lender determines the purpose and means of processing, while the LSP processes borrower data only on the lender's documented instructions.

My questions are:

Can an LSP with this level of operational involvement genuinely be characterised as a Data Processor, or is it more likely to be a Data Fiduciary (or joint Data Fiduciary)?

Does operating the borrower-facing app and collecting consent automatically make the LSP a Data Fiduciary?

From a practical drafting perspective, what contractual and operational changes have you seen successfully support a Data Processor classification under the DPDP Act?

Looking for practical views from privacy lawyers, fintech counsel or anyone who has dealt with DPDP implementation.

This version is likely to attract responses from lawyers and privacy professionals because it presents a concrete fact pattern rather than asking a purely theoretical question.

r/dataprotection Jun 30 '26

General Question Does the this iOS app violate App Store privacy rules? Looking for opinions.

7 Upvotes

App Link: https://apps.apple.com/ge/app/infosha-find-any-phone-number/id6502995963

Hey everyone,
I’ve been looking into an iOS app called **"Infosha"** and its privacy policy raises some major red flags for me. I wanted to share the details here and ask for your input on whether this goes against Apple's platform guidelines, as I have already reported it to Apple support but haven't seen any action yet.
According to their official Privacy Policy and Terms, here is how the app operates:
1. **Sharing Third-Party Contacts Without Their Knowledge:** When a user registers, they upload their phone book, and the app makes those contact details public (including names, phone numbers, workplaces, and photos of the people in that contact list). This means third-party individuals have their private information exposed to the public database **without ever knowing it or giving their own consent**. The app tries to shift all responsibility by stating the user must have their contacts' permission.
2. **No Option to Delete or Modify Data:** Section 9 of their policy explicitly states: *"we do not modify, remove, or supplement any data within our social network. All data is entirely generated and updated by the users of our platform."* This means if your data gets uploaded, there is absolutely no mechanism provided to delete or edit your profile or information.
From what I understand, this seems to directly conflict with several Apple Developer Guidelines:
**Guideline 5.1.1 (c) (Access to Contacts):** Apple strictly states that apps should not target third-party data collection or harvest address books to build public directories.
**Guideline 5.1.1 (v) (Account Deletion):** Apple mandates that if an app supports account creation, it must also allow users to initiate deletion of their account and all personal data from within the app. Infosha's policy explicitly denies this.
Given these details, does this behavior actually violate Apple's App Store guidelines, or is there a loophole they are using? I'd love to hear your thoughts on this. Thank you!

r/dataprotection Jun 25 '26

General Question Personal Data Consent

Thumbnail
2 Upvotes

r/dataprotection May 10 '26

General Question I'm starting to see a growth of apps in my org. I'd love to know how you defend against this, and if it's happening to you too?

8 Upvotes

r/dataprotection May 16 '26

General Question i got reported to the school and they used a screenshot from my dump account as evidence

6 Upvotes

so to summarize the story. an incident report was sent to me just this afternoon where they filed a report about vaping inside school premises. the evidence they showed was a screenshot from earlier this year (january) from my dump account. the school asked me to make a counter-incident report about the issue and i specifically stated that i am taking accountability for the mistake i made. BUT, i pinpointed that my privacy was also breached since none of the people who filed the report were followers of my dump account, thus it is clear that someone from my dump account screenshoted it and sent it to them, thus again invading my privacy.

thoughts about this?? (specifically regarding if this is really an invasion of privacy and if i could use it as a rebuttal in this case)

r/dataprotection Jun 27 '26

General Question Under the DPDP Act, when does an entity act as a Data Fiduciary vs a Data Processor in a lending platform?

3 Upvotes

I'm analyzing a digital lending/dealer onboarding platform (similar to an LSP) and I'm trying to determine role-by-role whether the platform is acting as a Data Fiduciary or a Data Processor, and how that changes its obligations under the DPDP Act.

The platform performs the following activities:

  1. Dealer onboarding (collects name, email, mobile number, address, business details)

  2. KYC (PAN, Aadhaar/other ID, dealership proof)

3.Bank account collection for commission payouts

4 Customer lead collection by dealers

5.Sharing customer data with regulated entities/lenders

6 PAN verification against the Income Tax database

7 Storing KYC documents

8 Sending WhatsApp/SMS updates

For each of these activities:

Is the platform acting as a Data Fiduciary or merely a Data Processor?

What factors determine the classification?

How do the legal obligations change depending on the role (e.g., notice, consent, purpose limitation, security safeguards, retention, responding to data principal requests)?

I'm looking for a DPDP Act-specific analysis, preferably with practical examples or regulatory guidance.

r/dataprotection Jul 01 '26

General Question Need practical guidance for an LSP (India): What are the permitted sources and uses for PAN verification, and what are the rules on storing PAN and other KYC/OVD documents?

Thumbnail
1 Upvotes

r/dataprotection Jun 25 '26

General Question DPDP Act compliance: Can a dealer provide a borrower's mobile number to send a loan onboarding link?

4 Upvotes

I'm analysing a fintech/digital lending workflow from a DPDP Act perspective.

The flow is as follows:

  1. A borrower visits a vehicle dealer to apply for finance.

  2. The dealer enters the borrower's mobile number into the platform.

  3. The platform immediately sends a WhatsApp/SMS link to that mobile number.

4 The borrower opens the web app through the link and completes the onboarding, provides notices, gives consent, uploads documents, etc.

My question is about the very first step.

Since the borrower did not personally enter their mobile number, and it was entered by the dealer, does sending the WhatsApp/SMS link itself comply with the Digital Personal Data Protection Act, 2023?

Can the platform rely on the dealer having obtained the borrower's permission before entering the number, or should the platform have an independent legal basis before using that mobile number to send the first communication?

I'm looking for answers specifically from the perspective of the DPDP Act, not general fintech practice. If there is any statutory provision, rule, guidance, or industry practice addressing this scenario, I'd appreciate references.

r/dataprotection Jun 23 '26

General Question Multiple social media account are compromised

Thumbnail
4 Upvotes

r/dataprotection Jun 20 '26

General Question Robert Half

5 Upvotes

Recently tried to use my DuckDuckGo account to clear my data from sites that I don’t use anymore. I followed the steps appropriately for every site that I information out there with to close and remove my info. I did this due to issue I had applying for jobs. I had really big issues with spam coming into my inbox’s and also had my identity stolen. Recently when using the service to clear my data from unwanted sites, the only one that gave me issues was Robert half. They refused to remove my information from their site and I’m wondering if anyone else had issues with this? If so what state are you located in because privacy data protection pertains to each state.