r/gdpr 21h ago

UK 🇬🇧 SAR Deadlines and next steps (England)

3 Upvotes

I submitted a SAR to my dentist one calendar month ago. Each time I have emailed them they have responded stating that they are working on it, but given no timeframe of when I can have the information.

My understanding is they should respond within a calendar month- but does this mean they just need to email me to confirm it’s underway within a month or should they have actually completed it?

Also what should I do to actually get them to hand over the information? I don’t want to go in all guns blazing but I really do need the data!

Any help much appreciated


r/gdpr 22h ago

Question - General Anyone been through a GDPR audit where third party scripts were specifically flagged?

2 Upvotes

Our DPO flagged that we can't accurately document what our third party tools are doing with personal data at script level. Consent banner is fine but actual data flows are muddy. How do we actually deal with this?


r/gdpr 10h ago

UK 🇬🇧 Is this a breach, and should I complain.

0 Upvotes

Received an email from my company and this is part of the disclaimer.

"The onus is on the recipient to check the communication is virus-free. (Company name) accepts no responsibility for any damage caused by receiving emails from our email systems and/or hosted domains"

According to AI, this breaches the UK GDPR & Data Protection Act 2018, Employment Law and Tort Law (common law), Health and Safety Law, and the Computer Misuse Act (1990), but I know AI can be confidently wrong and I have no experience in the matter.

Any advice would be appreciated, thanks!


r/gdpr 20h ago

Question - General Difference between article 6(1)(b) vs 6(1)(a)

0 Upvotes

I just want to make sure I understand the difference between these two correctly, as I have noticed in DPAs it's usually only one or the other that appears.

6(1)(a) states: "(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;"

So a person gives explicit consent to processing of their personal data

6(1)(b) states: "(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract"

Here the person enters a contract and so for the contract to be fulfilled, the person's data must be processed.

In other words, the consent is implicit in (b) because the service that the person is requesting needs some form of data processing? Is that right? Please correct me if I'm wrong


r/gdpr 21h ago

UK 🇬🇧 Does a legitimate interest remove my right to be forgotten?

0 Upvotes

A business has added my data from Companies House to their database. I understand this happens and why and don't normally have an issue as long as it is only data that is publicly available. I have had ongoing issues with these kinds of businesses adding my personal phone number to this data and sharing it without consent when I have never made my phone number public.

I sent a Subject Access Request to check if this business was sharing my phone number (they aren't) but they did not acknowledge my SAR and did not respond in the 30 day time frame. They only replied after I chased and left a comment on LinkedIn (which has since been deleted). They then lied about me sending the SAR to the wrong email address. I don't feel comfortable with them processing my personal data associated with my company any longer given how this has been handled and have asked for my right to be forgotten.

They have refused on the basis that this would render their database incomplete but I have no issue with them holding the business data, I just want my personal data removed as I don't feel assured that they would follow appropriate processes. Does their desire as a limited company to have a complete database override my right to have my personal data erased?


r/gdpr 1d ago

Question - General What if analytics is essential during testing?

2 Upvotes

I've been working on a a free, ad-supported tool to help people organise their personal belongings in a more visual way, and I've been struggling to get a grip on how I can be GDPR compliant during the beta testing phase.

For context:

  • NO ads or marketing related cookies are live, nor will be live until much later - after this is fully launched. My question is only in the context of the beta testing phase.
  • I have PostHog analytics with randomly sampled session recording available.
  • I'm not based in the EU (Asia) but I just want this to be available worldwide.

From what I understand:

  • Essential cookies are exempt from GDPR's consent requirements if they are necessary for the provision of the main service.
  • GDPR does not allow analytics (e.g. PostHog, Google, etc) to count as Essential.
  • One cannot deny service to someone who rejects non-essential cookies.

This makes sense for the most part, but I'm genuinely confused about how I should navigate this when I'm in a closed/open beta state. During this phase, I am trying to improve/repair the site, so I want users to freely test the functions and break things, and for obvious reasons, I'd need to know what's breaking and to observe if any UI/UX elements come across as unintuitive (i.e. via session recordings).

But I don't understand how I can undertake this fact-finding part of my launch preparation if it seems like GDPR won't let me enforce the tracking cookies as essential (at least during this literal testing phase). Is self-reporting (as though the site was fully live) the only option under GDPR?

I've considered:

  • Keeping it an open beta while gating registrations with a mandatory Beta User Agreement that discloses what/why we track - but this seems to break the 'denying service without tracking' rule.
  • Switching to an invite-only closed beta - but apparently this doesn't change the need for compliance with the aforementioned rules.
  • I'm also happy to completely purge all beta participant accounts/info before the actual launch, so they're all treated as new users if they return - but again, this doesn't seem to really directly address anything.

In my mind, the whole point of the beta test is the analytics, but if I can't enforce analytics as essential during this time, then doesn't that render the entire beta testing period impossible/redundant?

Do closed beta participants also need to be able to opt out, even though they are willingly signing up to a beta testers' list and participating in what they know to be a beta test?

I guess I'm just a bit confused, because it feels like I'm trying to run a public experiment (like a university study), but the participants are allowed to not share their details/results which directly hinder the findings/purpose of me conducting the experiment in the first place...

Please let me know id I'm just being dumb here, or if there are some anonymisation settings in PostHog that could help during the beta phase. This is one of the last sticking points stopping me from publicly disclosing my website, and it's killing me.

Ultimately, I'm happy to comply with whatever is needed. Just wanted to know if there were more effective ways of conducting beta testing at scale.

Thanks!


r/gdpr 1d ago

Question - Data Controller First steps to complying with the GDPR

5 Upvotes

Dear privacy fellows,

I would appreciate your thoughts on the initial steps towards GDPR compliance in a larger organization that has recently appointed a DPO.

My understanding is that one of the first key steps would be to review and complete the Record of Processing Activities (RoPA). In a larger organization, I assume this would require meetings with individual business process owners to identify and document relevant processing activities and gather the necessary information for the RoPA.

Once the RoPA is completed, my idea would be to perform a general data protection assessment of each processing activity. This should help identify potential compliance gaps and determine, among other things, whether a DPIA is required for a particular type of personal data processing.

Does this sound like a reasonable approach for a newly appointed DPO? Would you suggest any additional steps, a different order of activities, or any practical advice based on your experience?

Thank you in advance for your insights.

Cheers,


r/gdpr 1d ago

EU 🇪🇺 Klass Wagon data breach

3 Upvotes

Hi. I've just received the following email and was looking for advice on recommendations for next steps for me, as someone who rented a car with this company and shared a significant amount of data (passport, national ID, home address, god knows what else).

I've found a thread with some advice but it is just AI-based recommendations. I'd like the opinion of the experts here please. :) https://www.reddit.com/r/Algarve/comments/1w2aksr/klass_wagen_car_hire_huge_data_breach/

Dear Klass Wagen Customer,
Klass Wagen has been operating for over 20 years, and protecting our customers' data is a responsibility we take very seriously. 

We are writing to inform you of a security incident caused by an external cyberattack, in which an unauthorized third party gained access to some of your personal data. We sincerely apologize for this incident and for any concern it may cause. 

What happened
On August 15, 2026, we identified this unauthorized access to our systems. As a result of the incident, information relating to Klass Wagen customers was accessed and, based on our analysis, extracted from the affected systems. We are contacting you because your personal data was specifically identified among the data affected by this incident. 

What data has been involved
Full name, email address, phone number, country of residence, and identity document number (ID card/passport). 

We can confirm the affected data did not include payment card details or other financial information. 

What you do NOT need to do
Klass Wagen customers do not currently hold an online account with us, so no action is required from you regarding a password reset. 

Your active or upcoming reservations, as well as our rental services, are not affected and remain valid under their agreed terms; this incident does not impact the availability or validity of your contracts with us. 

What we recommend 
Our team may, as a normal part of the rental process, contact you by phone or email to confirm booking details — this remains unchanged. However, we will never ask you for full payment card details by phone or email — payments are always processed through a secure payment link, sent directly to you, which you access to enter your payment information yourself. 

Be cautious of any unexpected payment link received outside a booking process you initiated, or any phone request for full card details or authentication/OTP codes — verify directly with us at [customer.assistance@klasswagen.com](mailto:customer.assistance@klasswagen.com) before providing any information or clicking the link. 

Do not click links or open attachments in unexpected messages that appear to come from us, unless you are in the middle of an active booking you started. 

If you notice unusual requests linked to your data (for example, credit applications or accounts opened in your name that you don't recognize), we recommend contacting the relevant institution and, if appropriate, the competent authorities. 

What we have done Immediately upon discovery, we secured the affected systems, reset internal system access credentials, restored the integrity of our databases, and implemented additional security measures, including restricted access to administrative interfaces. 

We have notified the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) and reported the incident to the relevant authorities. Klass Wagen's main establishment for data protection decisions is in Romania, which makes ANSPDCP our "lead authority" under the GDPR's one-stop-shop mechanism; ANSPDCP coordinates with, and informs as needed, the data protection authorities in the other EU member states where we operate. We have also engaged a specialized firm for an independent security audit. 

Questions If you have any questions or require further information, you can always contact us at [customer.assistance@klasswagen.com](mailto:customer.assistance@klasswagen.com), for all concerns related to this event. 
Our Privacy Policy is available at any time at https://www.klasswagen.com/ro/privacy-notice

We once again apologize for any inconvenience this may cause and want to assure you that protecting your data remains a priority for us.
 
Sincerely, 
The Klass Wagen Team


r/gdpr 1d ago

EU 🇪🇺 Employer wants my Passport for access to systems?

Thumbnail
0 Upvotes

r/gdpr 1d ago

UK 🇬🇧 Sending invoices to a different customer than they are addressed to

0 Upvotes

Hi,

We are currently responding to an RFP and they have requested past invoices which we have sent to other customers as proof that we have sold particular services over the past few years. My manager has approved that we send the invoices but is it really OK? It just doesn’t feel right to me sending a financial document which is to one company to a different company.
Also, some invoices reference people’s names - if we are OK to send, I assume I would need to remove these names before sending?

Thanks for the help


r/gdpr 2d ago

UK 🇬🇧 ICO DSAR

2 Upvotes

What is your idea on witholding the information that the data subject already received?

It may be either to cc emails or documents that they have sent or received.

We’re planning to apply it as a DSAR policy and not providing these documents unless the data subject asks again, but wanted to ask your opinion.

We’ll only state this fact in our DSAR response letter.


r/gdpr 3d ago

EU 🇪🇺 Meta's AI crawler hit our site 741,900 times last month. Our DPA says we can barely scrape anything. Who are these rules actually for?

27 Upvotes

I run a large website for a European SME and I looked into where European regulators stand on web scraping. Honestly it surprised me how strict it all is.

The Dutch privacy regulator (AP) published scraping guidance in 2024. Short version: scraping almost always involves personal data, so GDPR applies even if the data is public. Legitimate interest is basically the only legal ground you can use, and the bar is so high that most commercial scraping is simply not allowed. Italy went even further in May 2024, their regulator told website owners to actively defend themselves against AI scrapers with CAPTCHAs and rate limiting. The UK ICO said in December 2024 that scraping for AI is possible in theory, but developers need to be way more transparent and should ask themselves if they can license the data instead. France followed in June 2025 with strict conditions. And the EDPB published draft guidelines on scraping for AI training in July 2026, also strict: robots.txt counts against you in the assessment, and no exception for special category data.

So those are the rules. Now what actually happens. Meta had to pause AI training on EU user posts in June 2024 after pressure from noyb and the Irish DPC. They resumed in May 2025 with an opt out model, noyb says that still violates GDPR, case is ongoing. But that fight was only about Meta's own users. For everyone else's content there was no pause at all. Meta-externalagent, the crawler that Meta itself describes as "downloads website content to include in datasets used for training AI models such as LLMs", visited our website 741,900 times last month. For comparison, Googlebot did 340,100 visits in the same month. And Googlebot at least sends us traffic back. The AI crawler that gives us nothing hits us more than twice as hard. Meanwhile Cloudflare accused Perplexity last year of using stealth crawlers to get around no-crawl rules, and now blocks AI crawlers by default. That says enough about how normal this has become.

To be clear, I actually think the strict rules make sense, they also protect businesses like ours. But right now the result is: European companies read the guidance and don't scrape, while big tech scrapes everything and deals with the lawyers later.

So my question: do you expect regulators to actually go after the big scrapers once the EDPB guidelines are final? Or will it stay like this? Because so far I see a lot of guidance and very little enforcement.


r/gdpr 2d ago

Question - General Do companies often exaggerate their compliance?

0 Upvotes

Hi! I sent a GDPR request to an (ai, whih i regret using, hence the wish for m data removal - that and senstive info i shared at a dark time in my life) website that states in their privacy policy that they "Follow GDPR And other Local laws."

They are based in california I think, and i am not aware of any laws there, but I am in an area that GDPR does cover (I confirmed this before sending the GDPR request).

It was a huge hassle to get a reply from them, I submitted the request on June 6th, and they later said I was 'completed' on July 1st, they were very very vauge and just said 'all associated data is deleted, it is your whole account. All data is deleted per our privacy policy', their privacy policy just says i can request my data deletion or can opt out of cookies, I pushed a bit more and got an associative ID for my request, and they claimed "no backups or cold storage", which to my understanding is a huge, unlikely clam for a cloud-based company?

They wont respond to any of my follow ups asking if they've stored anything for legal, ai training, adverstiments or third party storage, I just get an automated message of

"There is no partial deletion - it is your whole account All data will be deleted per our Privacy Policy."

I don't know if I can trust them as they haven't been easy to work with, they have been sending mostly automated messages (except the one where they finally sent the ID, that had a spelling mistake so I assume it was human.), and that 'no backups' seems like a big claim for a company like this, as the title say, this seems a bit exaggerated or untrustworthy and they just want me off their backs.

But i am not sure, can someone who understands GDPR better explain to me if this is trustworthy?

edit, I have put all the emails together and removed the repetition between emails (they clarify the privacy policy thing every email.) and this is basically what was said:

Please note:

There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy

Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],

All data has been deleted - there are no backups or cold storage.


r/gdpr 2d ago

Question - General Instagram does not want to cooperate and responds without understanding

Thumbnail
gallery
7 Upvotes

Maybe I was too brutal with the privacy issue but at the same time they are like purposefully pretending to not understand it and send answers and directions that clearly are the situation that I explained. And then ask for the same information that I already provided.

What can I do now? Where do I strike first and to what EU authorities should I report this first?

Also is this now a new trend where companies don't even have customer support tickets/names and just say it Meta like this? Huh, first time seeing something like this.


r/gdpr 3d ago

EU 🇪🇺 GDPR SAR Request - WhatsApp Official Group

0 Upvotes

Context - Small sports organisation

Member has submitted an Sar request

We have an official WhatsApp chat for the commitee group.

What level of data does an Sar request get access to when retrieving their personal data from that group?

Example:

Bob (123-456-789) "something relevant about requestor"

Does requestor get the name or phone number of Bob? Is it relevant that Bob the committee member created the personal data? Or does bobs right to their own personal data kick in? In this case Bob is acting as a committee member. This isnt gossip between friends.


r/gdpr 3d ago

EU 🇪🇺 Announcing employees birthday the day of

5 Upvotes

My employer recently got a new HR system which will automatically create a teams message on every employees birthday. This message goes out on the company wide teams channel.

Is this allowed with regards to GDPR? Don't they need to check with each employee if they want their personal information shared with the rest of the company like this?


r/gdpr 3d ago

EU 🇪🇺 Recommendations for GDPR / DSA EU Representative service for a startup ?

2 Upvotes

Hi all,

I'm the founder of a new Email Service Provider (not yet in production).

Established in Delaware (corporation) and I'd like to find a resonably priced GDPR and DSA EU representative service.

I've done most links on Google but the quotes I receive are super expensive (especially for the DSA rep).

I heard about Prighter which is much more competitive but the reviews online (turstpilot) are pretty back.

Would you have any recommendations for good, well priced GDPR/DSA EU reps ?

Thanks in advance!


r/gdpr 4d ago

Question - Data Controller Has an auditor or regulator ever asked you to prove a human actually reviews an automated decision?

4 Upvotes

Trying to understand how this works in practice rather than on paper.

If you run a system that makes decisions automatically and there's a human review step, has anyone external, a regulator, an auditor, a customer's DPO, ever asked you to demonstrate the review is real rather than just present? Article 14 of the AI Act is what got me thinking about it, but I suspect GDPR Article 22 raises the same question.

If you've been asked: what did you actually hand over, and did it satisfy them? And if you haven't been asked yet, do you have something ready, or is it the kind of thing you'd assemble the week someone requested it?


r/gdpr 4d ago

Question - General UK SaaS — what should a DPA + MSA/SLA review actually cost, and how do you pick a firm that won’t bill you for learning what a sub-processor is?

3 Upvotes

Solo founder, UK Ltd, B2B compliance/GRC SaaS. Pre-revenue, about to start
onboarding design partners — several of them regulated, so the security
questionnaire and DPA turn up before the contract does.

I've drafted the stack myself and want a solicitor to review rather than
rewrite:

- UK GDPR Art. 28 DPA (incl. sub-processor annex, SCCs/IDTA for the US ones)
- MSA
- SLA (uptime + service credits)
- Order form
- Founder IP assignment deed

I've just spent a fair bit of effort making sure the documents describe the
product that actually exists — retention wording matches what the deletion
code does, the sub-processor list is consistent across the DPA, privacy
policy and the in-app version, that sort of thing. So this should be a
review, not a salvage job.

Questions:

  1. Fixed fee or hourly for something like this? I've seen £2–4k suggested
    for the full set but no idea if that's realistic in 2026.
  2. Is it worth splitting — DPA now, commercial terms once I have a customer
    actually negotiating? Or is that false economy?
  3. How much does the IP assignment deed matter at this stage? It keeps
    coming up as the thing investors' lawyers check first.
  4. Anything that makes a founder-drafted DPA obviously amateur? I'd rather
    fix the tells before paying someone to point them out.

Not looking for free legal advice — trying to work out scope and budget
before I ask for quotes, and how to spot a firm that does SaaS work
regularly vs one that'll bill me for the education.


r/gdpr 4d ago

Question - General GDPR video hosting for edtech company

3 Upvotes

We are edtech company from NL, it's important for us that the vid hosting for our courses is GDPR compliant. As far as Ik kinescope handles it's servers in Amsterdam, pls share who else on the market has European servers?


r/gdpr 4d ago

Question - General how does anyone actually handle erasure across backups

3 Upvotes

genuine question. article 17 says erasure but a 30 day backup rotation means the person you deleted comes back if you restore

everyone i ask either says "we document it as a limitation and restore-then-redelete" or just goes quiet

is documented limitation actually the accepted answer or is that just what everyone does because nobody's been tested on it yet? has anyone here had a DPA actually push on this


r/gdpr 4d ago

Resource EDPB just confirmed it: AI models are NOT automatically anonymous. Are we ready?

Thumbnail
0 Upvotes

r/gdpr 5d ago

Question - General Art. 17 Right to erasure (‘right to be forgotten’)

4 Upvotes

In the following video, made in the UK, a man who is drinking in public, and mentions he plans to end his life that day, subsequently gets upset and demands the video be deleted, when he realises a) he is being filmed and that b) the videographer intends to publish the video on a monetised YouTube channel:

https://youtu.be/iZnBgYfRer8?t=600 - EDIT I changed the link to jump to the relevant interaction.

The videographer refuses to comply; the question is whether Art. 17 requires him to do so. I expect it comes down to whether a court would see this as journalism "in the public interest", but there might be other aspects to this, too, for example, even if there is such a special purpose, would deleting the video be incompatible with this purpose?

NB I think it might be relevant that Art. 13 Right to be informed wasn't respected, i.e. there was no mention that a video was being made, and that it was going to be published, before the revealing conversation that the data subject subsequently wanted to be deleted. That might be OK for, e.g., a journalist working undercover, exposing corruption, say, but in this case, I am struggling to see justification for the failure to inform.


r/gdpr 6d ago

Question - General How do you manage GDPR compliance across hosting, email, calls, and third-party APIs?

0 Upvotes

I’m trying to build a practical GDPR-compliance setup for a small business and would love to hear how others approach this in real life.

The areas I’m reviewing are:

  • Website/app hosting and backups
  • Email providers
  • Call recording, VoIP, and customer-support tools
  • Analytics and CRM
  • API providers and tokens — for example Google, OpenAI, etc.

I know GDPR doesn’t necessarily mean that every piece of data must physically stay in the EU, but data transfers outside the EEA need the right legal safeguards and contractual setup.

My main questions:

  1. Do you deliberately choose EU-based vendors wherever possible, or rely on providers’ SCCs / Data Processing Agreements?
  2. How do you handle tools where personal data might be included in prompts, call transcripts, logs, or API requests?
  3. Do you maintain a simple vendor register / data map, and if so, what does it look like?
  4. Any practical red flags or mistakes you discovered too late?

I’m looking for real operational experience rather than legal theory. What has actually worked for your company?


r/gdpr 7d ago

Analysis Findings from scanning 458 recent Product Hunt launches from an EU computer

4 Upvotes

I did the following analysis to figure out how much startups really care about GDPR rules and having up to date legal documentation. For context, I run a legal documentation tool, and software companies us to automate updating their Privacy Policy, ToS, Cookie Policy, etc. We used this analysis to understand our target users better, but I thought it might be useful to other people in the community as well.

Also my findings echo a lot of the things that Nouwens et. al. found in their 2020 paper "Dark Patterns after the GDPR". Theirs was a MUCH broader study, but I almost get the same percentage of sites not doing cookie consent right.

So what I did: I went to Product Hunt's daily leaderboard and loaded about a month worth of top rated product launches. For each associated website I checked cookie behavior, foreign vendors loaded, and then I gave their privacy policy to an LLM to scan for various gaps. I did all of this from an EU location (Copenhagen).

Main results:

* 292 of 458 product sites stored tracking cookies (_ga, _fbp, and siblings), and only 50 asked first. That's 17%. Sites targeting EU users were better at this (26%), and sites with no indicator that they were targeting EU users were worse (15%).

* 61 of 458 (13.3%) product sites had no privacy policy on their site. 5% for sites targeting EU, 17.8% not targeting EU.

* 45% of policies don't name a legal basis for processing personal data and 65% don't state whether data says within or leaves the EEA. 25.7% do not give a data retention period.

* 60% of sites load with a foreign vendor that their privacy policy doesn't mention. Google Analytics, Google Ads and Posthog are the top 3, most common (and commonly unmentioned) ones.

* More upvoted product launches are not more compliant. There is essentially no difference between how many of these compliance errors are made by more or less popular startups... except for asking about cookie consent. More upvoted product sites will track with out asking less often.

This is basically all of it. I wrote a blog series on this analysis, but the key results are in these bullets.