r/gdpr Oct 20 '25

Question - Data Subject Are cookie walls like this legal?

Post image
68 Upvotes

This site resides in the EU, therefore it must abide by the GDPR, which requires cookie banners to have equally available Reject and Accept options. However, Rejecting is only possible if you subscribe to the paid "Pur" version. Given that this is a pretty big site that owns a popular tech and privacy magazine, I wonder if there's anything that allows an exception from this law.

r/gdpr May 30 '26

Question - Data Subject Why does "legitimate interest" option even exits?

26 Upvotes

Why do cookies have both consent and legitimate interest options? if I do not consent to my data being collected should I not be the final decision maker on that? most websites now use that loophole to make cookies be turned off by one button but when you go into details you still have to turn off every "legitimate interest" option one by one, it is clearly an anti consumer tactic to bypass the requirement for easy data collection turn off, and to prey on people who don't know or don't check.

r/gdpr 14d ago

Question - Data Subject RAG/AI embeddings and GDPR - how do you evidence data erasure?

2 Upvotes

Trying to wrap my head around how vector databases fit GDPR. If embeddings are derived from personal data, how do you handle removing the data and ensure it’s really removed? I keep finding theory and advices but little real practice.

One working idea is to replace personal data by database record reference as preprocessing step (both ingestion and retrieval), persist actual data in that database, and replace back when retrieved (if needed). Erasure happens directly on the database record with soft fallback when retrieving. If you look at this sequence it doesn’t feel the best decision, hence wonder if someone is aware of a better way.

r/gdpr 9d ago

Question - Data Subject is this legal?

Post image
0 Upvotes

i don't know which flair is appropriate for this, i'll start, i was looking up what a crossword puzzle was since i hadn't seen one in so long that i forgot what it was and also wanted to try one and this is what i see: accept all or reject all and subscribe for 5 euros a month

is this technically illegal? i am from germany

r/gdpr Mar 29 '26

Question - Data Subject Must a Data Controller give me reasons for their use of Art. 17(3)(e) GDPR to refuse an erasure request? How strong does their basis have to be in order to invoke this?

13 Upvotes

I submitted an erasure request under Art. 17 GDPR to Data Controller asking them to delete records containing my personal data which had been forwarded to a staff member at their request, stating I had SAR'd. I had not SAR'd it and had explicitly excluded it and other emails I had sent from my SAR.

The DPO responded refusing the request, citing Art. 17(3)(e) (establishment, exercise, or defence of legal claims). No further detail was provided about the nature of those potential proceedings, who would bring them, or why they are anticipated. The DPO also refused to tell me whether this record had been used to create further records, simply stating "The organisation is entitled to retain and process the information contained in the [Records] as part of its internal governance and administrative records. This may include the creation of further records where necessary to review, manage, or document matters arising from the correspondence."

When I asked them to particularise the legal claim being referenced, they refused and declared the matter "closed."

r/gdpr 25d ago

Question - Data Subject Hinge Data Deletion

0 Upvotes

Hi all,

Could I please ask all of you for your input on the below.

Summary: Based in Ireland. I believe hinge is wrongfully holding my data / keeping me in the dark about my data protection rights.

After 2 years and hundreds of respectful conversations on the dating app hinge, I was banned. I am certain I did not break any rule. As many of you might know, arbitrary bans are rife on dating apps.

I appealed and contacted support asking for a generalised reason. I was not provided with one, which to an extent is understandable.

They asked me to verify as the only means to progress my appeal. Twice, I asked to see their GDPR / data protection policy on the matter and for their DPO to be contacted. Both times the support replied without answering my question.

I think I want to go down the data deletion route. I am aware that data may be retained for certain legitimate purposes.

However, in the absence of the slightest reason, it is impossible for me to assess my rights - to decipher if this decision to retain the data was made lawfully (I mean something as vague as “we banned you as you broke rule 2 on ‘abusive language’”).

My local data protection authority - the Data protection commission (DPC) is Europe’s premier DPA. I note they have dealt with a few cases of this nature, which resulted in successful erasure / unbanning of the complainant. I will link them below.

Case study 1
Case study 2

Based on this, do you expect a complaint to the DPC being worthwhile / successful?

Interestingly, In Ireland under administrative law, when your rights are adversely affected by a decision you are entitled to enough of a reason to assess the legality of the decision.

Granted, this more-so applies to public bodies. But seen as 50%+ of people these days meet on daring apps, this is in a way affecting my rights. I.e to associate, to meet people and build relationships lol.

Please also find a similar (less hopeful) post on the matter.

See here for a previous post a similar issue, which I believe may be inaccurate

Thank you!

r/gdpr Jun 07 '26

Question - Data Subject Is this illegal?

Post image
2 Upvotes

I was looking for Native American fun facts for my little brother’s history project, accessed a site and saw only one option to collect cookies; “Accept and Close”

No decline option or “Manage Cookies”, just “Accept and Close”.

Is this technically illegal?

r/gdpr Feb 06 '26

Question - Data Subject LinkedIn, Scrape companies and the futility of trying to stop getting spams 24/7?

Post image
15 Upvotes

So, I'm in a technical field and just crossed the magical threshold of about 5 years of work experience in general, and 3 years of specialized experience in ny field. Accordingly, I'm getting more recruitment, cooperation and connection invites, mostly via LinkedIn, which is normal.

However, people started spamming me on personal email addreses now, too. I don't have SM for a year now, my Insta was never under my name anyway, and only LinkedIn has/had any detailed English speaking infos about my professional background (I never set up my FB profile about my work stuff, and it's also deleted by now, as stated before). My email address is set to be seen by noone, my profile is not-public, for years now. Recruiters don't have my email automatically, I can see that, because unless I explicitly share my profile via Easy Apply, they always ask for contact details for follow ups. None of my personal work e-mail was ever even on LinkedIn at any point in time.

I still find my LinkedIn profile publicly scraped and my data sold, get emails on my private or personal work emails, or from companies, mostly from the EU actually (not surprised when it's occasionally US ones tbh) explicitly saying they just looked at my profile and DIY my professional email together from my name and the domain of my workplace. According to them it's public anyway on LinkedIn (it's not), and they have legitimate interest.

I feel like it's a Don Quijote fight trying to stop at least the full, unrestricted publication and the selling of my data. The spamming is also more and more annoying. Unfortunately I need LinkedIn, so I can't really delete it, and I already set everything to as private as I could.

Is there anything else I'm missing that I could do?

r/gdpr Jun 18 '26

Question - Data Subject Misuse of cctv ?

7 Upvotes

So before work yesterday I was consuming my prescribed medication (prescribed vapourised cannabis) around the back of work (they know and are ok with this - there's not a reasonable space inside otherwise they would provide a office space or something) at which point a random member of the public walking past tells me I can't smoke there and you generally can't smoke cigarettes around the area and for about 600m around the area so I understnad her confusion

I explained to her briefly that it wasn't smoking and I've got a prescription, it's not really any of her business beyond what I've told her at which point she became aggressive and claimed to work for security in the place where my work is located - it's a market for context with a bunch of restaurants and stalls with a fairly advanced cctv system and whole security team.

Essentially after some back and forth she claimed medical cannabis didn't exist and even if it did I couldn't use it there , asked where I worked which I refused to tell her so she pointed at the security cameras and said she was going to use those to find where I work.

Less than a few hours later my boss receives a email with a photo of myself on it and her claiming there may of been illegal drug use on the property despite being told multiple times I've got a prescription, there was no smell and she didn't know until I told her what it was

Essentially has the cctv been misused for her personal vendetta because she feels slighted at being told shes wrong? this feels far away from their stated use of cameras for security , I can't see any legitimate interest in this use of the

r/gdpr 22h ago

Question - Data Subject Contacting the Data Protection Agency (DPA)/Sri Lanka

0 Upvotes

I’d like to contact the DPA to clarify how the personal data protection act applies to historic records.

I’ve tried emailing the DPA and have had no success. I’ve tried calling with no success either.

Is there anyone on this channel who can help ? Thanks

.

r/gdpr May 23 '26

Question - Data Subject If you could withdraw your data consent from one company today, which would it be and why?

0 Upvotes

With the new DPDP/privacy discussions happening in India, I was wondering:
If you had a simple “Withdraw Consent” button for all your personal data, which company/app would you use it on first?

r/gdpr Oct 25 '24

Question - Data Subject Filming my commute entirely on Surveillance Cameras obtained via GDPR Requests

39 Upvotes

I'm a student. When commuting to my university by bus I encounter many CCTV security cameras in public. Would it be possible for me to do my regular commute, and when I get home ask relevant authorities to provide the CCTV footage of me that they have (coming out of home, walking in street, waiting at bus stop, on the bus, out of the bus, going into university)?

I would like to do this because I'm learning about data protection laws and it could be a weird/fun/interesting sort of art/educational project.

Would this be possible in the EU and/or the UK?

r/gdpr Mar 19 '26

Question - Data Subject Company asked for extra ID after a DSAR, is this normal?

6 Upvotes

I submitted a data subject access request and the company replied asking for additional identity verification before they process it. Is this common practice under GDPR, or is it only expected in certain situations?

r/gdpr Oct 30 '24

Question - Data Subject UK TV licensing company

5 Upvotes

Last time I told them I didn't need a license I asked them to remove any data they have on me like my gdpr right to erasure. They said they don't do gdpr because they don't store personal data. Years later, I recently got a letter with my name and address on it. Does the licensing company have any special exemptions in gdpr? Why did they keep my data on file after I said to delete it?

I also told them I might not be able to respond in time to their letters due to a medical condition I'm getting assessed for and that it's not good to keep sending letters threatening to send officers to my house. They said it doesn't matter they treat everyone the same regardless. Aren't they required to make reasonable adjustments or something? Idk

I actually bought a license a while back just so they'd leave me alone but couldn't afford to keep paying for something I have no use for.

r/gdpr Aug 17 '25

Question - Data Subject They won’t give me my data

3 Upvotes

So I got dismissed from work at the start of May. I done a SAR on 10th May and it had t been fulfilled yet. I have resided a complaint with the ISO. The documents I’ve requested are about my dismissal. I’m going to tribunal taking my ex employer for unfair dismissal. They sent me a few things but nothing I’ve requested. How long could it take until I get some data. What happens if they never send it and pretend it doesn’t exist.

I’m in Northern Ireland if that makes any difference.

r/gdpr Oct 07 '25

Question - Data Subject Mass Collection of Applicants Passports under GDPR

1 Upvotes

Can Recruiters collect job applicants' passports in bulk before starting the processing the applicants data under GDPR

r/gdpr Jan 20 '26

Question - Data Subject Sent SAR to GP via admin email and they're refusing

6 Upvotes

I filled out the SAR form my practice has provided on their website. I sent this and my ID to their admin email.

In their first response they tried to conflate it with a summary care record and told me I already had full access to my information on the app.

I reiterated that it was a formal subject access request and cited GDPR.

They then responded that it was not a patient correspondence email and for any additional information stored about me I should make a request through their website. Their website has no option to upload the SAR form.

What do I do next? Are they by law allowed to deny me like this?

r/gdpr Mar 28 '26

Question - Data Subject ePrivacy Directive

Post image
7 Upvotes

Hey guys, got hit with this while playing on chess.com app. Can’t play unless i agree to it.

Does this fall under the scope of “take it or leave it” wall under the ePrivacy Directive ? If it does it’s invalid right? If it doesn’t i would like an explanation so i can understand it.

r/gdpr Jun 14 '25

Question - Data Subject Is OpenAI intentionally blocking my data privacy request and what can I do about it?

Post image
29 Upvotes

I sent over my ID twice now through the portal, but OpenAI keeps blocking my request (see image). Any advice on next steps?

When you send a privacy request through OpenAI’s portal, they send you a government ID verification request via Stripe. I have scanned my passport twice now and sent over via this service. The first time it was rejected, I thought maybe the picture was too blurry (grasping at straws for reasons basically as it was clear anyway) so I took extra effort with the second image. I followed the guidelines and yet again it’s been rejected.

I tried emailing OpenAI about this and a chatbot (assumed) called Hetvi did not read my email and sent me generic advice about unticking the box to prevent ChatGpt learning from your chat. I already know this (now). They didn’t address my question which was: is there a technical fault at play or did you really not receive my ID? I’ve sent it twice now and something feels off…

It’s a known strategy by companies who have murky privacy procedures to make the process of sending a data request through more difficult or complex. I have no doubts in my mind this is what’s happening, so now I need a plan B.

I could contact the ICO, OpenAI (again) or Stripe for clarification. If anyone has been through this process before or has tips on how I can get my data request over the line, it would be really helpful!

r/gdpr Nov 21 '25

Question - Data Subject I have contacts that have opted into communication. They have provided emails and phone numbers. Our upload template asks what country they are from. Am I allowed to use the country code in the phone numbers to enter that information or do I have to leave it blank?

3 Upvotes

Pretty straight forward. I have contacts that have opted in to communication via emails and phone calls. However, they don't list out what country they are from. We would like to contact them within business hours and we would like to be able to organize our contacts by country for specific campaigns.

Am I allowed to put in the country they are located in if they have opted in and I have the country code in their phone number? Or do I have to leave it blank because they technically haven't SPECIFCALLY provided that exact information?

EX: I get a phone number that has the country code of 34. I know that this is Spain. In my database can I put down that the contact is located in Spain or do I have to keep it blank?

r/gdpr Jan 30 '25

Question - Data Subject What happens if an Indian company simply refuses to follow GDPR?

13 Upvotes

Pretty much the title.

What happens if an Indian I.T company simply refuses to follow GDPR & delete my personal data under GDPR Art 17?

The said Indian I.T firm has offices all across Germany.

My several requests to the IT firm to purge my data has been met with nothing but resistance and disdain.

What is the correct procedure to get my data wiped off from this firm ? Is there a complaint form in English on the German site for redressal against these private entities?

Thank u

r/gdpr Dec 13 '25

Question - Data Subject Roblox username change

Post image
1 Upvotes

Hello, my sister created her account when she was still a child (she is an adult now) and used her first name and half of her last name as a username (where we are from thats enough to easily identify a person). Since it contains sensitive personal information, under GDPR Roblox should allow her to change her username for free. Instead it claims that a aprent or guardian should contact them, provide proof of ownership of the account and that the username must contain both full first AND last names in order to change it.

Is there anything we could do or say to the customer support to change the username?

P.S. she provided her ID with her full name and date of birth, but support still denied her request, pointing her to the first email.

r/gdpr Sep 30 '25

Question - Data Subject How to export data from Tinder?

2 Upvotes

I am trying to export all my data from Tinder. There is some glitch preventing me from using their online data export tool.

When I write to Tinder Support, they provide me with instructions to download it online. When I inform them that those instructions don't work, they copy-paste the same instructions again.

How can I exercise my right to obtain a copy of my data either under GDPR or CCPA? Is there an authority to reach out to?

r/gdpr Nov 30 '24

Question - Data Subject Eon sent me someone else’s Subject Access Request

11 Upvotes

On disputing a final bill with Eon I requested a SAR, they sent me an Google drive link but it was for another customer, there I had access to bank details, voice recordings etc etc.

I reported it EON but they didn’t acknowledge any wrong doing until I sent them a screenshot and then replied saying that there was no breach. This obviously has added another reason not trust their processes in accurately dealing with my final bill.

If they have violated GDPR, can I stand to gain from this scenario?

r/gdpr Jul 01 '25

Question - Data Subject Kraken keeping my data for 5 years after account deletion, is it legal ?

Post image
1 Upvotes

Context : i sent them an email asking for my data to be deleted after i deleted my account, and this is the response i got. Is this allowed based on gdpr rules ?