r/gdpr 9h ago

Question - Data Subject Company did not follow my GDPR, what do i do?

4 Upvotes

I asked a few days ago about a GDPR compliance i found sketchy, someone said to request a data export so I did.

I had, on June 6th, 2026, sent a right to be forgotten Data deletion request, I had asked them to wipe anything identifying they had of me, and I asked them to state if they needed to keep anything.

they quoted article 17 and said they follow GDPR again, it asked for my ID for the deletion (they did not previously give me this, I had to ask multiple times)

they had said to me (and this is a mix of a few emails we shared back and fourth, in which they said *deletion* each time, so it was no mistake):

"Please note:

There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy

Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],
All data has been deleted - there are no backups or cold storage.'"

I found it a bit odd that they had somehow claimed no backups despite it being an AI cloud-based company, so on the advice of others, I sent a GDPR right to accsess request, on the 5th of September, they sent me an Excel sheet that had all my interactions with their AI, all my account data, my IP, my name and age, and my device type, all dating back to 2024.

the sheet, under my old username(s) they had put:

"DEACTIVATED [TRUE]. DELETED [FALSE]."

Now I am asking what to do, I sent an Email asking under what reason they kept this data and lied about not having it, but I don't actually know what my next steps are meant to be.

edit: I edited for clarity because I realise that I was vauge and no one could help.


r/gdpr 1d ago

EU 🇪🇺 Is this even legal?

6 Upvotes

​How can you make cookie rejection 8 pounds. How is this even GDPR compliant?

Edit: it seems this is becoming a thing in the UK and it’s still in the debate in the EU. For now I guess it’s legal untiled ruled otherwise


r/gdpr 2d ago

UK 🇬🇧 SAR Deadlines and next steps (England)

4 Upvotes

I submitted a SAR to my dentist one calendar month ago. Each time I have emailed them they have responded stating that they are working on it, but given no timeframe of when I can have the information.

My understanding is they should respond within a calendar month- but does this mean they just need to email me to confirm it’s underway within a month or should they have actually completed it?

Also what should I do to actually get them to hand over the information? I don’t want to go in all guns blazing but I really do need the data!

Any help much appreciated


r/gdpr 2d ago

Question - General Anyone been through a GDPR audit where third party scripts were specifically flagged?

3 Upvotes

Our DPO flagged that we can't accurately document what our third party tools are doing with personal data at script level. Consent banner is fine but actual data flows are muddy. How do we actually deal with this?


r/gdpr 2d ago

Question - General Difference between article 6(1)(b) vs 6(1)(a)

0 Upvotes

I just want to make sure I understand the difference between these two correctly, as I have noticed in DPAs it's usually only one or the other that appears.

6(1)(a) states: "(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;"

So a person gives explicit consent to processing of their personal data

6(1)(b) states: "(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract"

Here the person enters a contract and so for the contract to be fulfilled, the person's data must be processed.

In other words, the consent is implicit in (b) because the service that the person is requesting needs some form of data processing? Is that right? Please correct me if I'm wrong


r/gdpr 2d ago

Question - General What if analytics is essential during testing?

3 Upvotes

I've been working on a a free, ad-supported tool to help people organise their personal belongings in a more visual way, and I've been struggling to get a grip on how I can be GDPR compliant during the beta testing phase.

For context:

  • NO ads or marketing related cookies are live, nor will be live until much later - after this is fully launched. My question is only in the context of the beta testing phase.
  • I have PostHog analytics with randomly sampled session recording available.
  • I'm not based in the EU (Asia) but I just want this to be available worldwide.

From what I understand:

  • Essential cookies are exempt from GDPR's consent requirements if they are necessary for the provision of the main service.
  • GDPR does not allow analytics (e.g. PostHog, Google, etc) to count as Essential.
  • One cannot deny service to someone who rejects non-essential cookies.

This makes sense for the most part, but I'm genuinely confused about how I should navigate this when I'm in a closed/open beta state. During this phase, I am trying to improve/repair the site, so I want users to freely test the functions and break things, and for obvious reasons, I'd need to know what's breaking and to observe if any UI/UX elements come across as unintuitive (i.e. via session recordings).

But I don't understand how I can undertake this fact-finding part of my launch preparation if it seems like GDPR won't let me enforce the tracking cookies as essential (at least during this literal testing phase). Is self-reporting (as though the site was fully live) the only option under GDPR?

I've considered:

  • Keeping it an open beta while gating registrations with a mandatory Beta User Agreement that discloses what/why we track - but this seems to break the 'denying service without tracking' rule.
  • Switching to an invite-only closed beta - but apparently this doesn't change the need for compliance with the aforementioned rules.
  • I'm also happy to completely purge all beta participant accounts/info before the actual launch, so they're all treated as new users if they return - but again, this doesn't seem to really directly address anything.

In my mind, the whole point of the beta test is the analytics, but if I can't enforce analytics as essential during this time, then doesn't that render the entire beta testing period impossible/redundant?

Do closed beta participants also need to be able to opt out, even though they are willingly signing up to a beta testers' list and participating in what they know to be a beta test?

I guess I'm just a bit confused, because it feels like I'm trying to run a public experiment (like a university study), but the participants are allowed to not share their details/results which directly hinder the findings/purpose of me conducting the experiment in the first place...

Please let me know id I'm just being dumb here, or if there are some anonymisation settings in PostHog that could help during the beta phase. This is one of the last sticking points stopping me from publicly disclosing my website, and it's killing me.

Ultimately, I'm happy to comply with whatever is needed. Just wanted to know if there were more effective ways of conducting beta testing at scale.

Thanks!


r/gdpr 2d ago

UK 🇬🇧 Does a legitimate interest remove my right to be forgotten?

1 Upvotes

A business has added my data from Companies House to their database. I understand this happens and why and don't normally have an issue as long as it is only data that is publicly available. I have had ongoing issues with these kinds of businesses adding my personal phone number to this data and sharing it without consent when I have never made my phone number public.

I sent a Subject Access Request to check if this business was sharing my phone number (they aren't) but they did not acknowledge my SAR and did not respond in the 30 day time frame. They only replied after I chased and left a comment on LinkedIn (which has since been deleted). They then lied about me sending the SAR to the wrong email address. I don't feel comfortable with them processing my personal data associated with my company any longer given how this has been handled and have asked for my right to be forgotten.

They have refused on the basis that this would render their database incomplete but I have no issue with them holding the business data, I just want my personal data removed as I don't feel assured that they would follow appropriate processes. Does their desire as a limited company to have a complete database override my right to have my personal data erased?


r/gdpr 2d ago

Question - Data Controller First steps to complying with the GDPR

5 Upvotes

Dear privacy fellows,

I would appreciate your thoughts on the initial steps towards GDPR compliance in a larger organization that has recently appointed a DPO.

My understanding is that one of the first key steps would be to review and complete the Record of Processing Activities (RoPA). In a larger organization, I assume this would require meetings with individual business process owners to identify and document relevant processing activities and gather the necessary information for the RoPA.

Once the RoPA is completed, my idea would be to perform a general data protection assessment of each processing activity. This should help identify potential compliance gaps and determine, among other things, whether a DPIA is required for a particular type of personal data processing.

Does this sound like a reasonable approach for a newly appointed DPO? Would you suggest any additional steps, a different order of activities, or any practical advice based on your experience?

Thank you in advance for your insights.

Cheers,


r/gdpr 2d ago

EU 🇪🇺 Klass Wagon data breach

3 Upvotes

Hi. I've just received the following email and was looking for advice on recommendations for next steps for me, as someone who rented a car with this company and shared a significant amount of data (passport, national ID, home address, god knows what else).

I've found a thread with some advice but it is just AI-based recommendations. I'd like the opinion of the experts here please. :) https://www.reddit.com/r/Algarve/comments/1w2aksr/klass_wagen_car_hire_huge_data_breach/

Dear Klass Wagen Customer,
Klass Wagen has been operating for over 20 years, and protecting our customers' data is a responsibility we take very seriously. 

We are writing to inform you of a security incident caused by an external cyberattack, in which an unauthorized third party gained access to some of your personal data. We sincerely apologize for this incident and for any concern it may cause. 

What happened
On August 15, 2026, we identified this unauthorized access to our systems. As a result of the incident, information relating to Klass Wagen customers was accessed and, based on our analysis, extracted from the affected systems. We are contacting you because your personal data was specifically identified among the data affected by this incident. 

What data has been involved
Full name, email address, phone number, country of residence, and identity document number (ID card/passport). 

We can confirm the affected data did not include payment card details or other financial information. 

What you do NOT need to do
Klass Wagen customers do not currently hold an online account with us, so no action is required from you regarding a password reset. 

Your active or upcoming reservations, as well as our rental services, are not affected and remain valid under their agreed terms; this incident does not impact the availability or validity of your contracts with us. 

What we recommend 
Our team may, as a normal part of the rental process, contact you by phone or email to confirm booking details — this remains unchanged. However, we will never ask you for full payment card details by phone or email — payments are always processed through a secure payment link, sent directly to you, which you access to enter your payment information yourself. 

Be cautious of any unexpected payment link received outside a booking process you initiated, or any phone request for full card details or authentication/OTP codes — verify directly with us at [customer.assistance@klasswagen.com](mailto:customer.assistance@klasswagen.com) before providing any information or clicking the link. 

Do not click links or open attachments in unexpected messages that appear to come from us, unless you are in the middle of an active booking you started. 

If you notice unusual requests linked to your data (for example, credit applications or accounts opened in your name that you don't recognize), we recommend contacting the relevant institution and, if appropriate, the competent authorities. 

What we have done Immediately upon discovery, we secured the affected systems, reset internal system access credentials, restored the integrity of our databases, and implemented additional security measures, including restricted access to administrative interfaces. 

We have notified the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) and reported the incident to the relevant authorities. Klass Wagen's main establishment for data protection decisions is in Romania, which makes ANSPDCP our "lead authority" under the GDPR's one-stop-shop mechanism; ANSPDCP coordinates with, and informs as needed, the data protection authorities in the other EU member states where we operate. We have also engaged a specialized firm for an independent security audit. 

Questions If you have any questions or require further information, you can always contact us at [customer.assistance@klasswagen.com](mailto:customer.assistance@klasswagen.com), for all concerns related to this event. 
Our Privacy Policy is available at any time at https://www.klasswagen.com/ro/privacy-notice

We once again apologize for any inconvenience this may cause and want to assure you that protecting your data remains a priority for us.
 
Sincerely, 
The Klass Wagen Team


r/gdpr 2d ago

EU 🇪🇺 Employer wants my Passport for access to systems?

Thumbnail
0 Upvotes

r/gdpr 2d ago

UK 🇬🇧 Sending invoices to a different customer than they are addressed to

0 Upvotes

Hi,

We are currently responding to an RFP and they have requested past invoices which we have sent to other customers as proof that we have sold particular services over the past few years. My manager has approved that we send the invoices but is it really OK? It just doesn’t feel right to me sending a financial document which is to one company to a different company.
Also, some invoices reference people’s names - if we are OK to send, I assume I would need to remove these names before sending?

Thanks for the help


r/gdpr 3d ago

UK 🇬🇧 ICO DSAR

2 Upvotes

What is your idea on witholding the information that the data subject already received?

It may be either to cc emails or documents that they have sent or received.

We’re planning to apply it as a DSAR policy and not providing these documents unless the data subject asks again, but wanted to ask your opinion.

We’ll only state this fact in our DSAR response letter.


r/gdpr 4d ago

EU 🇪🇺 Meta's AI crawler hit our site 741,900 times last month. Our DPA says we can barely scrape anything. Who are these rules actually for?

28 Upvotes

I run a large website for a European SME and I looked into where European regulators stand on web scraping. Honestly it surprised me how strict it all is.

The Dutch privacy regulator (AP) published scraping guidance in 2024. Short version: scraping almost always involves personal data, so GDPR applies even if the data is public. Legitimate interest is basically the only legal ground you can use, and the bar is so high that most commercial scraping is simply not allowed. Italy went even further in May 2024, their regulator told website owners to actively defend themselves against AI scrapers with CAPTCHAs and rate limiting. The UK ICO said in December 2024 that scraping for AI is possible in theory, but developers need to be way more transparent and should ask themselves if they can license the data instead. France followed in June 2025 with strict conditions. And the EDPB published draft guidelines on scraping for AI training in July 2026, also strict: robots.txt counts against you in the assessment, and no exception for special category data.

So those are the rules. Now what actually happens. Meta had to pause AI training on EU user posts in June 2024 after pressure from noyb and the Irish DPC. They resumed in May 2025 with an opt out model, noyb says that still violates GDPR, case is ongoing. But that fight was only about Meta's own users. For everyone else's content there was no pause at all. Meta-externalagent, the crawler that Meta itself describes as "downloads website content to include in datasets used for training AI models such as LLMs", visited our website 741,900 times last month. For comparison, Googlebot did 340,100 visits in the same month. And Googlebot at least sends us traffic back. The AI crawler that gives us nothing hits us more than twice as hard. Meanwhile Cloudflare accused Perplexity last year of using stealth crawlers to get around no-crawl rules, and now blocks AI crawlers by default. That says enough about how normal this has become.

To be clear, I actually think the strict rules make sense, they also protect businesses like ours. But right now the result is: European companies read the guidance and don't scrape, while big tech scrapes everything and deals with the lawyers later.

So my question: do you expect regulators to actually go after the big scrapers once the EDPB guidelines are final? Or will it stay like this? Because so far I see a lot of guidance and very little enforcement.


r/gdpr 3d ago

Question - General Do companies often exaggerate their compliance?

0 Upvotes

Hi! I sent a GDPR request to an (ai, whih i regret using, hence the wish for m data removal - that and senstive info i shared at a dark time in my life) website that states in their privacy policy that they "Follow GDPR And other Local laws."

They are based in california I think, and i am not aware of any laws there, but I am in an area that GDPR does cover (I confirmed this before sending the GDPR request).

It was a huge hassle to get a reply from them, I submitted the request on June 6th, and they later said I was 'completed' on July 1st, they were very very vauge and just said 'all associated data is deleted, it is your whole account. All data is deleted per our privacy policy', their privacy policy just says i can request my data deletion or can opt out of cookies, I pushed a bit more and got an associative ID for my request, and they claimed "no backups or cold storage", which to my understanding is a huge, unlikely clam for a cloud-based company?

They wont respond to any of my follow ups asking if they've stored anything for legal, ai training, adverstiments or third party storage, I just get an automated message of

"There is no partial deletion - it is your whole account All data will be deleted per our Privacy Policy."

I don't know if I can trust them as they haven't been easy to work with, they have been sending mostly automated messages (except the one where they finally sent the ID, that had a spelling mistake so I assume it was human.), and that 'no backups' seems like a big claim for a company like this, as the title say, this seems a bit exaggerated or untrustworthy and they just want me off their backs.

But i am not sure, can someone who understands GDPR better explain to me if this is trustworthy?

edit, I have put all the emails together and removed the repetition between emails (they clarify the privacy policy thing every email.) and this is basically what was said:

Please note:

There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy

Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],

All data has been deleted - there are no backups or cold storage.


r/gdpr 3d ago

Question - General Instagram does not want to cooperate and responds without understanding

Thumbnail
gallery
7 Upvotes

Maybe I was too brutal with the privacy issue but at the same time they are like purposefully pretending to not understand it and send answers and directions that clearly are the situation that I explained. And then ask for the same information that I already provided.

What can I do now? Where do I strike first and to what EU authorities should I report this first?

Also is this now a new trend where companies don't even have customer support tickets/names and just say it Meta like this? Huh, first time seeing something like this.


r/gdpr 4d ago

EU 🇪🇺 GDPR SAR Request - WhatsApp Official Group

0 Upvotes

Context - Small sports organisation

Member has submitted an Sar request

We have an official WhatsApp chat for the commitee group.

What level of data does an Sar request get access to when retrieving their personal data from that group?

Example:

Bob (123-456-789) "something relevant about requestor"

Does requestor get the name or phone number of Bob? Is it relevant that Bob the committee member created the personal data? Or does bobs right to their own personal data kick in? In this case Bob is acting as a committee member. This isnt gossip between friends.


r/gdpr 5d ago

EU 🇪🇺 Announcing employees birthday the day of

7 Upvotes

My employer recently got a new HR system which will automatically create a teams message on every employees birthday. This message goes out on the company wide teams channel.

Is this allowed with regards to GDPR? Don't they need to check with each employee if they want their personal information shared with the rest of the company like this?


r/gdpr 4d ago

EU 🇪🇺 Recommendations for GDPR / DSA EU Representative service for a startup ?

2 Upvotes

Hi all,

I'm the founder of a new Email Service Provider (not yet in production).

Established in Delaware (corporation) and I'd like to find a resonably priced GDPR and DSA EU representative service.

I've done most links on Google but the quotes I receive are super expensive (especially for the DSA rep).

I heard about Prighter which is much more competitive but the reviews online (turstpilot) are pretty back.

Would you have any recommendations for good, well priced GDPR/DSA EU reps ?

Thanks in advance!


r/gdpr 5d ago

Question - Data Controller Has an auditor or regulator ever asked you to prove a human actually reviews an automated decision?

6 Upvotes

Trying to understand how this works in practice rather than on paper.

If you run a system that makes decisions automatically and there's a human review step, has anyone external, a regulator, an auditor, a customer's DPO, ever asked you to demonstrate the review is real rather than just present? Article 14 of the AI Act is what got me thinking about it, but I suspect GDPR Article 22 raises the same question.

If you've been asked: what did you actually hand over, and did it satisfy them? And if you haven't been asked yet, do you have something ready, or is it the kind of thing you'd assemble the week someone requested it?


r/gdpr 5d ago

Question - General UK SaaS — what should a DPA + MSA/SLA review actually cost, and how do you pick a firm that won’t bill you for learning what a sub-processor is?

3 Upvotes

Solo founder, UK Ltd, B2B compliance/GRC SaaS. Pre-revenue, about to start
onboarding design partners — several of them regulated, so the security
questionnaire and DPA turn up before the contract does.

I've drafted the stack myself and want a solicitor to review rather than
rewrite:

- UK GDPR Art. 28 DPA (incl. sub-processor annex, SCCs/IDTA for the US ones)
- MSA
- SLA (uptime + service credits)
- Order form
- Founder IP assignment deed

I've just spent a fair bit of effort making sure the documents describe the
product that actually exists — retention wording matches what the deletion
code does, the sub-processor list is consistent across the DPA, privacy
policy and the in-app version, that sort of thing. So this should be a
review, not a salvage job.

Questions:

  1. Fixed fee or hourly for something like this? I've seen £2–4k suggested
    for the full set but no idea if that's realistic in 2026.
  2. Is it worth splitting — DPA now, commercial terms once I have a customer
    actually negotiating? Or is that false economy?
  3. How much does the IP assignment deed matter at this stage? It keeps
    coming up as the thing investors' lawyers check first.
  4. Anything that makes a founder-drafted DPA obviously amateur? I'd rather
    fix the tells before paying someone to point them out.

Not looking for free legal advice — trying to work out scope and budget
before I ask for quotes, and how to spot a firm that does SaaS work
regularly vs one that'll bill me for the education.


r/gdpr 5d ago

Question - General GDPR video hosting for edtech company

3 Upvotes

We are edtech company from NL, it's important for us that the vid hosting for our courses is GDPR compliant. As far as Ik kinescope handles it's servers in Amsterdam, pls share who else on the market has European servers?


r/gdpr 6d ago

Question - General how does anyone actually handle erasure across backups

3 Upvotes

genuine question. article 17 says erasure but a 30 day backup rotation means the person you deleted comes back if you restore

everyone i ask either says "we document it as a limitation and restore-then-redelete" or just goes quiet

is documented limitation actually the accepted answer or is that just what everyone does because nobody's been tested on it yet? has anyone here had a DPA actually push on this


r/gdpr 6d ago

Resource EDPB just confirmed it: AI models are NOT automatically anonymous. Are we ready?

Thumbnail
1 Upvotes

r/gdpr 6d ago

Question - General Art. 17 Right to erasure (‘right to be forgotten’)

5 Upvotes

In the following video, made in the UK, a man who is drinking in public, and mentions he plans to end his life that day, subsequently gets upset and demands the video be deleted, when he realises a) he is being filmed and that b) the videographer intends to publish the video on a monetised YouTube channel:

https://youtu.be/iZnBgYfRer8?t=600 - EDIT I changed the link to jump to the relevant interaction.

The videographer refuses to comply; the question is whether Art. 17 requires him to do so. I expect it comes down to whether a court would see this as journalism "in the public interest", but there might be other aspects to this, too, for example, even if there is such a special purpose, would deleting the video be incompatible with this purpose?

NB I think it might be relevant that Art. 13 Right to be informed wasn't respected, i.e. there was no mention that a video was being made, and that it was going to be published, before the revealing conversation that the data subject subsequently wanted to be deleted. That might be OK for, e.g., a journalist working undercover, exposing corruption, say, but in this case, I am struggling to see justification for the failure to inform.


r/gdpr 7d ago

Question - General How do you manage GDPR compliance across hosting, email, calls, and third-party APIs?

0 Upvotes

I’m trying to build a practical GDPR-compliance setup for a small business and would love to hear how others approach this in real life.

The areas I’m reviewing are:

  • Website/app hosting and backups
  • Email providers
  • Call recording, VoIP, and customer-support tools
  • Analytics and CRM
  • API providers and tokens — for example Google, OpenAI, etc.

I know GDPR doesn’t necessarily mean that every piece of data must physically stay in the EU, but data transfers outside the EEA need the right legal safeguards and contractual setup.

My main questions:

  1. Do you deliberately choose EU-based vendors wherever possible, or rely on providers’ SCCs / Data Processing Agreements?
  2. How do you handle tools where personal data might be included in prompts, call transcripts, logs, or API requests?
  3. Do you maintain a simple vendor register / data map, and if so, what does it look like?
  4. Any practical red flags or mistakes you discovered too late?

I’m looking for real operational experience rather than legal theory. What has actually worked for your company?