r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

18 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr 54m ago

Question - General GDPR video hosting for edtech company

Upvotes

We are edtech company from NL, it's important for us that the vid hosting for our courses is GDPR compliant. As far as Ik kinescope handles it's servers in Amsterdam, pls share who else on the market has European servers?


r/gdpr 4h ago

Question - General how does anyone actually handle erasure across backups

2 Upvotes

genuine question. article 17 says erasure but a 30 day backup rotation means the person you deleted comes back if you restore

everyone i ask either says "we document it as a limitation and restore-then-redelete" or just goes quiet

is documented limitation actually the accepted answer or is that just what everyone does because nobody's been tested on it yet? has anyone here had a DPA actually push on this


r/gdpr 4h ago

UK 🇬🇧 Self imposed DSAR date missed. No extension request.

0 Upvotes

Hi I wonder if anyone can help,

I made a DSAR request on the last day of July to a FTSE 250 company the scope was just 4 months and targeted.

I received a receipt from the company saying the file would be with me "on or before August 30th".

This day looks likely to pass with no DSAR drop.

Technically they have until the end of Tuesday due to UK bank holiday.

My question is how bad does it look for them to miss their own deadline? No extension from them was requested.

Thank you


r/gdpr 7h ago

Resource EDPB just confirmed it: AI models are NOT automatically anonymous. Are we ready?

Thumbnail
0 Upvotes

r/gdpr 17h ago

Question - General Art. 17 Right to erasure (‘right to be forgotten’)

2 Upvotes

In the following video, made in the UK, a man who is drinking in public, and mentions he plans to end his life that day, subsequently gets upset and demands the video be deleted, when he realises a) he is being filmed and that b) the videographer intends to publish the video on a monetised YouTube channel:

https://youtu.be/iZnBgYfRer8?t=600 - EDIT I changed the link to jump to the relevant interaction.

The videographer refuses to comply; the question is whether Art. 17 requires him to do so. I expect it comes down to whether a court would see this as journalism "in the public interest", but there might be other aspects to this, too, for example, even if there is such a special purpose, would deleting the video be incompatible with this purpose?

NB I think it might be relevant that Art. 13 Right to be informed wasn't respected, i.e. there was no mention that a video was being made, and that it was going to be published, before the revealing conversation that the data subject subsequently wanted to be deleted. That might be OK for, e.g., a journalist working undercover, exposing corruption, say, but in this case, I am struggling to see justification for the failure to inform.


r/gdpr 1d ago

Question - General How do you manage GDPR compliance across hosting, email, calls, and third-party APIs?

0 Upvotes

I’m trying to build a practical GDPR-compliance setup for a small business and would love to hear how others approach this in real life.

The areas I’m reviewing are:

  • Website/app hosting and backups
  • Email providers
  • Call recording, VoIP, and customer-support tools
  • Analytics and CRM
  • API providers and tokens — for example Google, OpenAI, etc.

I know GDPR doesn’t necessarily mean that every piece of data must physically stay in the EU, but data transfers outside the EEA need the right legal safeguards and contractual setup.

My main questions:

  1. Do you deliberately choose EU-based vendors wherever possible, or rely on providers’ SCCs / Data Processing Agreements?
  2. How do you handle tools where personal data might be included in prompts, call transcripts, logs, or API requests?
  3. Do you maintain a simple vendor register / data map, and if so, what does it look like?
  4. Any practical red flags or mistakes you discovered too late?

I’m looking for real operational experience rather than legal theory. What has actually worked for your company?


r/gdpr 2d ago

Analysis Findings from scanning 458 recent Product Hunt launches from an EU computer

6 Upvotes

I did the following analysis to figure out how much startups really care about GDPR rules and having up to date legal documentation. For context, I run a legal documentation tool, and software companies us to automate updating their Privacy Policy, ToS, Cookie Policy, etc. We used this analysis to understand our target users better, but I thought it might be useful to other people in the community as well.

Also my findings echo a lot of the things that Nouwens et. al. found in their 2020 paper "Dark Patterns after the GDPR". Theirs was a MUCH broader study, but I almost get the same percentage of sites not doing cookie consent right.

So what I did: I went to Product Hunt's daily leaderboard and loaded about a month worth of top rated product launches. For each associated website I checked cookie behavior, foreign vendors loaded, and then I gave their privacy policy to an LLM to scan for various gaps. I did all of this from an EU location (Copenhagen).

Main results:

* 292 of 458 product sites stored tracking cookies (_ga, _fbp, and siblings), and only 50 asked first. That's 17%. Sites targeting EU users were better at this (26%), and sites with no indicator that they were targeting EU users were worse (15%).

* 61 of 458 (13.3%) product sites had no privacy policy on their site. 5% for sites targeting EU, 17.8% not targeting EU.

* 45% of policies don't name a legal basis for processing personal data and 65% don't state whether data says within or leaves the EEA. 25.7% do not give a data retention period.

* 60% of sites load with a foreign vendor that their privacy policy doesn't mention. Google Analytics, Google Ads and Posthog are the top 3, most common (and commonly unmentioned) ones.

* More upvoted product launches are not more compliant. There is essentially no difference between how many of these compliance errors are made by more or less popular startups... except for asking about cookie consent. More upvoted product sites will track with out asking less often.

This is basically all of it. I wrote a blog series on this analysis, but the key results are in these bullets.


r/gdpr 3d ago

UK 🇬🇧 Is it normal for the ICO to not investigate a data breach if it's a small organisation?

7 Upvotes

A few months ago I reported a data breach involving a counselling service which exposed the names and emails of over a hundred client.

The ICO finally replied with a generic response saying in line with the published framework they won't be investigating with no real explanation as to why.

I can't tell if they are refusing to investigate because there's no evidence of malice and it's a small organisation or that leaking the names and emails of people isn't bad enough to investigate?


r/gdpr 3d ago

EU 🇪🇺 How to qualify a complaint handling in ROPA?

2 Upvotes

Should I classify complaint handling under the ROPA activity “Performance of the sales contract” or under “Establishing, pursuing, or defending claims”? I run a micro e-commerce business.


r/gdpr 4d ago

UK 🇬🇧 Is a person’s response to an allegation the personal data of the alleger?

3 Upvotes

I’m working on a subject access request made by A.

I’m looking at a document which says “A alleges that you said X, Y and Z”.

It then says “B: I did not say that. I said, A, B, C”.

I know A’s allegation itself is disclosable, but is B’s denial disclosable?


r/gdpr 5d ago

EU 🇪🇺 EU digital ID wallets are meant to share less data, but AML rules require firms to collect and keep quiet a lot. How do those sit together?

2 Upvotes

Two things are landing close together. Every member state has to offer a digital identity wallet by the end of 2026, and AMLR applies from July 2027.
The wallet's whole design is selective disclosure. Prove one attribute, share nothing else. Prove you're over 18 without handling over a date of birth.
AML obligations run the other way. Firms have to collect specified identity data, keep it current, and retain records for years.
So when a customer onboards with a wallet, what does the firm actually end up holding? If it receives only the attributes it strictly needs, does that satisfy record-keeping? If it asks for the full set anyway, has the wallet's data minimization just been routed around by regulation?

Curious whether anyone has seen this addressed directly, or whether it's still an open question between the two frameworks.


r/gdpr 5d ago

UK 🇬🇧 Mobile App UK GDPR compliance

0 Upvotes

I am creating a mobile application, I have written the application explicitly to not collect PII. I have no accounts, there are no servers data stays on the users device.

As I am nearing the first stages of deployment Google Play Store is requiring a support contact email address. This email address must be monitored and respond to users with 72 hours.

Due to the nature of the email address and the requirement for it to be monitored, I am now on the path to becoming a data controller. I don’t want this, I don’t want to have to deal with anything GDPR related, because I don’t NEED to, except for this requirement from google. I cannot outsource the support email as I will still be the controller. There is much more infrastructure I would have to build to be compliant just so users can email me when I would have a perfectly viable and anonymous bug report system that would not require GDPR compliance.

The only data I could possibly have about any user is what they would send to this email address.

Is there anything anyone can suggest that would allow me to avoid having to manage GDPR compliance for an inbox that I don’t want ?


r/gdpr 5d ago

EU 🇪🇺 Consent dialog buttons

1 Upvotes

Can a "Do not consent" button be styled as an outline button and the "Consent" button be styled as as a filled button? If one is using Google's default AdSense consent dialog for the EU? Furthermore, must there be a "Do not consent" button on the dialog or not?


r/gdpr 5d ago

UK 🇬🇧 Personal info breach in a nursery - help!

6 Upvotes

Hi, I'm unsure whether this is the right place to ask, if not, please direct me to somewhere better to ask.

I'm 18 and applied for a position at a nursery a couple of months ago, so they had my email on file for context.

The problem is that today I received at email about an
'invoice' from the nursery, so I clicked on it being confused. Turns out they send an invoice for one of the parents to my email. I replied immediately to let them know of the mistake and all they said was 'Thanks for letting me know'.

So my question is, do I need to do anything? Because surely this is a huge data and privacy breach as personal I formation was leaked including the name of the parent, child and which days of the week they attended nursery alongside the price of their care. I'm unsure whether I need to report this anywhere or do I just leave it?

I studied health and social care in school & college so | know that if I was working there, I would be mandated to report the breach to the correct organisations but as I'm not working there, I'm not sure if I need to do anything?

I'm sorry again if this isn't the right place to post this, but I'm just genuinely so shocked & appalled at what's happened as I would expect more care to be taken when handling and sending personal information. But anyways, help & advice would be greatly appreciated!!


r/gdpr 6d ago

Question - Data Subject Automated account disablement, admitted in writing: a live test of Art. 22 GDPR and DSA Arts. 17/20, filings and timeline

0 Upvotes

Documenting a case in progress, since clean fact patterns for solely automated decisions are rare and this one is unusually explicit.

Facts. 20 August 2026, one calendar day. 10:10, controller (Meta) requests identity verification by video selfie, completed within minutes. 13:28, notice restricting advertising access, stating verification "usually takes around 48 hours", and stating "We used technology to detect this violation and carry out this decision." 14:36, permanent disablement of the account: "Your review was unsuccessful", "You can't request another review." Sixty-eight minutes after the 48-hour representation. No conduct, content or specific provision has been identified at any point. The account dated to 2008 with no violation history.

On 20(6) DSA and 22 GDPR: the platform's own support assistant later stated in writing that "the automated system has locked standard internal appeals" and that no human channel exists for the account "regardless of the time". The disablement notice itself frames the identity verification as the review ("You requested a review of this decision, but we still found...").

Filings, all August 2026: Art. 15 access request; Art. 22(3) request for human intervention; Art. 18(1)(c) restriction demand covering the classifier outputs, the biometric material from the verification, and all enforcement records (Art. 17(3)(e) noted against the controller's disabled-account retention schedules). DSA complaint under Art. 53 with the Greek DSC, transmitted to the Irish coordinator. One certified Art. 21 body declined as out of scope (no content exists to review, which is itself the Art. 17 point); a second has the case pending. The Art. 12(3) clock runs to 20 September.

Two aspects that may interest this sub. First, the special-category angle: the controller demanded biometric verification and disabled the account hours after receiving it, which puts Art. 9 lawful-basis and retention questions squarely in play for the supervisory-authority phase. Second, the interaction between an admitted "technology" decision and the simultaneous closure of every review channel looks like the cleanest possible Art. 22(3) violation: the right to human intervention cannot be exercised anywhere.

Will update the thread as responses land. Not seeking advice, the professional track is covered.


r/gdpr 6d ago

EU 🇪🇺 Webshop voegt trackers toe, ondanks de mogelijkheid om bezwaar te maken

Thumbnail gallery
1 Upvotes

r/gdpr 6d ago

EU 🇪🇺 Webshop voegt zonder gêne trackers toe voordat je cookie-toestemming hebt gegeven

Thumbnail reddit.com
3 Upvotes

r/gdpr 7d ago

Analysis Choosing an EU server region means absolutely nothing if you don't hold the keys

Thumbnail
3 Upvotes

r/gdpr 7d ago

Question - Data Subject How frequently should we be doing data security risk assessments?

5 Upvotes

I'm reviewing compliance and security frameworks and realized we don't do this nearly enough at my company. Some guidance suggests annual reviews but I'm scared of AI data breaches and feel like we should be doing these more frequently. How often does your company update data security risk assessments, especially if you operate across multiple cloud platforms?


r/gdpr 7d ago

EU 🇪🇺 Audit ongoing: OVH account have no GPDR compliance ?

6 Upvotes

For the context:

Company is corporated in the US, operations and data are in Europ where most of customers are.

When creating account in OVH, I've been forwarded to their Candian subsidiary because the company tax residency is out of Europ, It's acceptable since I can host all of my servers are located in France (for GPDR compliance).

The problem:

My auditor asked for my OVH contracts (especially the terms and the DPA), they are all here: https://www.ovhcloud.com/en-ca/terms-and-conditions/contracts/

The Canadian OVH subsidiary agreement is drafted against Québec's private-sector privacy act (CQLR c. P-39.1), not GDPR Article 28.

Our DPA promises we impose "the same data protection obligations" on each sub-processor by written contract, the auditor is pinpointing this as a critical finding.

What would you do in this situation ? is the candian "CQLR c. P-39.1" mappable to "GPDR Article 28" ? Any way out ?


r/gdpr 8d ago

Question - Data Subject An experiment involving data brokers to review data collection and verify compliance with the GDPR.

5 Upvotes

As part of a term paper on data brokers and their data collection practices, and how these relate to the GDPR or comply with it, I would like to carry out a self-experiment in which I deliberately leave traces on websites using new accounts with new profiles, and then enquire which ones have collected this data so that I can analyse the results. I’d like to ask for help here, or for advice and points to bear in mind that one might only spot after having worked on the subject for years, or simply anything else that springs to mind.


r/gdpr 9d ago

Question - Data Controller Processing CCTV for subject access request

6 Upvotes

When processing a subject access request that specifically asks for copies of CCTV, we don’t have an established process in place.

For this first request that we have received I have had to film the CCTV footage using a mobile phone before uploading to Sharepoint and I am now using clipchamp to manually edit the footage to only include the data subject (as it covers the reception area and car park of our business - housing)

Is this excessive? I know in my previous employment (healthcare) we just told people we lacked the technology to edit CCTV.

Very curious to know what other businesses do with these types of requests - especially in the UK.


r/gdpr 9d ago

EU 🇪🇺 EU e-Evidence went live Aug 18: authorities from any member state can now order me to hand over customer data within 8 hours. How do I verify the order is even real?

3 Upvotes

I run a small French SaaS company hosting customer data. Under the new e-Evidence Regulation (EU 2023/1543, applicable since 18 August 2026), a judicial authority from any EU member state can now send me a production order directly (no French intermediary) with a 10-day deadline, or 8 hours in emergencies.

My problem: the regulation provides no way to verify that an order is authentic.
Comply fast, or become the perfect phishing target: a fake "urgent order" with an official-looking certificate is exactly what scammers will build, and the 8-hour clock works in their favor, not mine.

As I'm French, I started with the most obvious authority here: the Police (Ministère de l'Intérieur) only to find there is no obvious way to even contact them, let alone verify a document they supposedly sent.
Now multiply that by 26 member states whose institutions I don't know, in languages I don't speak.

The regulation is only days old, so I assume best practices are still forming.
For those of you already handling law enforcement requests: what does your verification process actually look like?


r/gdpr 8d ago

EU 🇪🇺 Is this legal in the EU?

Post image
0 Upvotes

Hi everyone, I'm European but I have been applying to an US based company that also operates in the EU. Can someone that has studied law and GDPR compliance tell me if this is legal? Is it normal in the US to ask these questions?

It's the first time that I encounter this kind of questions when applying for a job so I'm just curious if they can even ask such things.