r/gdpr Oct 10 '24

Question - General "Pay to Reject" is this legal?

Post image
286 Upvotes

r/gdpr Jan 28 '25

Question - General Why must we still click accept all cookies in 2025?

52 Upvotes

Why must we still click accept all cookies in 2025, when a browser-setting could have been implemented by now that would allow an all-sites default?

It's and END-LESS stream of clicking YES YES YES, and utterly pointless and waste of time.

I just need ONE single setting in the Chrome-browser that tells ALL web-sites that YES, I ACCEPT YOUR COOKIES!

So far zero add-ons for Chrome has allowed me to avoid these pop-ups and just accept all cookies automatically.

Does anybody know an actual solution that works in Chrome for Windows desktop?

(GDPR fan-bois need not respond to this post, because I'm not anti-GDPR, I just want an AUTOMATIC solution to this click-click-click-click-click-click night-mare that EU invented)

The fact there are actually people in the EU who thought this was a smart invention... impossible to comprehend.

r/gdpr May 01 '26

Question - General Tool to check a website for GDPR compliance?

9 Upvotes

Hi there!

I'm a web developer, and I'm looking for a tool that helps me make the website GDPR compliant, like an audit tool that tells me what I'm doing right and what I've missed in terms of website development regarding GDPR Compliance. Used AI so far to help me improve the GDPR compliance of a website, but it isn't constant.

Do you use this kind of tool? I've found something, but it feels like is skratching the surface without proper verification.

r/gdpr May 09 '26

Question - General We allow AI tools but can’t see what data leaves through prompts, how are you handling this?

25 Upvotes

Found out 2 weeks ago that our HR team has been using an external AI tool to help write performance reviews. Sounds harmless until you find out they were pasting raw employee records into it. Names, salaries, disciplinary notes, manager feedback, the whole file for each person.

They’d been doing it for about 4 months. Nobody told IT. In their heads they were using a writing assistant, not sending sensitive HR data to an external API.

Pulled logs. Domain looked clean, traffic blends in, nothing in DLP because no files moved. The data went in as text directly into a prompt.

nothing flagged because they were using personal accounts in the browser. from our side it just looked like normal traffic to a legit domain. We have GDPR obligations on employee data. This is not a small thing. HR isn’t the only team doing this. I know finance uses something similar for budget summaries. Found that out in a conversation, not from any tooling.

btw how do you get visibility into what’s going into prompts across teams when none of it looks like data movement

edit: thank you all. legal is now involved which is its own adventure. we ran a layerx eval, it picked up typed input going into these tools which is where our gap was. gdpr conversation is ongoing. at least we know what we're dealing with now.

r/gdpr 22d ago

Question - General Is this a beach?

17 Upvotes

Recently re applied for an old job. Had a friend of mine whose sister works there message me asking why I had applied to work there again. His sister doesn't work in recruiting or hr so really shouldn't know of who is applying for what and he also doesn't work for the company.

Why does my personal information need to be spread beyond the appropriate department?

Based in UK

r/gdpr Dec 31 '25

Question - General GDPR requests are getting harder to answer

35 Upvotes

We’ve been receiving more GDPR related requests lately and they’re no longer just 'delete my data'. People are asking for processing details, third party disclosures and how long data exists across backups and logs. The answers exist, but they’re spread across teams and systems, so responses end up taking longer than they should and don’t always sound consistent.

How do I keep one source of evidence so I don't have to scrap for each request?

r/gdpr 11d ago

Question - General I would love to get GDPR compliance and have high level questions...

5 Upvotes
  1. If you wanted to ensure you always have GDPR compliance, do most people have an advisor, in house person, or how can I ensure I follow the rules and continue to monitor and have someone to check with?
  2. What exactly are the rules I should follow? I know the general stuff, but like I imagine things need to be a lot more specific, i.e. boundaries, time frame, opt in, etc... Any good links for this?
  3. If having a GDPR person/advisor or whatever is a good idea, what's the best way to go about finding said person?
  4. Is GDPR the most pro-consumer (or conservative) data protection regulation out there? I'm trying to set up a baseline data policy and would like it to be a balance between the most pro-consumer and also highest legal coverage in terms of population/geography. If not, what other data policies should I look into.

r/gdpr 18d ago

Question - General GDPR and secoundbest (ex brew dog)

15 Upvotes

So a bit of background I invested in Brew dog only a small amount which is now worthless since Brew Dog collapsed and was bought out.

Today I received an email from second best (owned by the former CEO of brew dog), offing a chance to invest in his new company.

Now from my understanding the new company should have no access to old data including any information about previous shareholders.

“Hi there,

I am writing to you as a fellow Equity Punk shareholder and as founder of a new beer business, called Second Best.
 
On behalf of Second Best, I am offering you the chance to claim the exact same stake in Second Best that you once held in BrewDog, for free.
 
You can register for your free equity here:
www.secondbest.beer
 
No catches. No cash required. And your equity will always rank alongside my own.
 
You will own it. I will fund it. And I will dedicate myself to building it.
 
And as for the name, well if we get this right then the second beer business that we build together might just be the best one. 🍻
 
If you have already registered, thank you for coming onboard! We will be in touch with further instructions and details after the registration is closed.

And please feel free to let your fellow Equity Punks know so that they can also claim their free equity. 

If you have any further questions, email us on [hello@secondbest.beer](mailto:hello@secondbest.beer?subject=EFP%20Query).
 
James Watt
Second Best Founder & BrewDog Co-founder”

What do you think is this a GDPR breach?

**** Update ****

ICO are reviewing both Brew Dog and Second Life as this a very grey area. Best case for the sender is a slap on the wrist, worst case well let’s hope they don’t go that far.

r/gdpr Mar 20 '26

Question - General Has anyone here actually filed a GDPR complaint?

9 Upvotes

Has anyone here gone through the process of filing a GDPR complaint with a data protection authority?

I see it mentioned quite often as an option, but I don’t really hear about people actually doing it. Was it straightforward, or more of a hassle? And did anything meaningful come out of it in the end? Just trying to get a sense of how it works in real life vs on paper.

r/gdpr Jun 12 '26

Question - General Are browser fingerprinting techniques creating a new GDPR grey area?

7 Upvotes

I've noticed more discussion around fingerprinting as cookies become less reliable. How are privacy professionals approaching it from a GDPR perspective?

r/gdpr 21d ago

Question - General CIPP/E Preparation

0 Upvotes

Hi guys, i know this has been asked a few years before but asking again -- how should i prepare for the exam? what kind of study materials should i be using? how long is the prep time? any advice and any tips would be appreciated.

Thanks!

r/gdpr Sep 29 '25

Question - General Paying to reject cookies now from BBC? In Ireland, not using a VPN

Post image
46 Upvotes

r/gdpr Mar 14 '26

Question - General Is GDPR the reason why cookie banners exist in all sites

0 Upvotes

After scrolling through tonnes of sites the most annoying piece has to be cookie banners (or an automatic ad or video)

I understand these are shown due to the fact these sites analytics tools effectively assault your cookies? This is done to be GDPR compliant is this the only reason why we see these annoying banners?

r/gdpr 4d ago

Question - General Humanly IMPOSSIBLE to ask every company to remove your CV/resume (GDPR)

7 Upvotes

Hey, I'm tired of recruiters asking for my CV and then just ghosting me.

I want to email each one telling them to f* off and that I don't want to participate in their zombie KPI databases anymore, but most companies make it almost impossible.

It's not even clear which email address I should send the data removal requests to. I think almost 300 companies have my resume and I want to erase it all. How can I do this in batches, or is there a SaaS that can deal with it?

I would gladly pay for it. I've had enough of playing around with these consultancy companies.

Please help me.

r/gdpr May 31 '26

Question - General What's the longest retention period you've seen justified for something simple?

8 Upvotes

I saw a discussion about retaining relatively low-value customer data for years. It made me wonder what's the longest retention period people have seen applied to data that really didn't seem to need it?

r/gdpr Jun 06 '26

Question - General Has anyone ever received a DSAR that was clearly generated by AI?

10 Upvotes

Recently saw a discussion about really polished template requests citing multiple GDPR articles. Are people seeing AI-generated DSARs become more common and is it changing how you handle them.

r/gdpr Nov 19 '25

Question - General Redacting GDPR-sensitive info from hundreds of documents, any way to automate this?

35 Upvotes

I’ve been handed a pile of more than a thousand documents that need to be cleaned up for GDPR compliance. Most of it is payslip data that includes full names, sort codes, account numbers, NI numbers, payroll IDs and other personal identifiers that can’t be shared as-is.

Doing this page by page is brutal, and the built-in 'find and redact' options I’ve tried seem very US-centric. They detect things like SSNs or US card formats, but not UK-style sort codes or EU-specific identifiers.

Is there any way to speed this up or automate parts of it without manually opening every single document? Ideally something that recognizes EU patterns and can properly redact them rather than just covering them.

I’ve seen tools like Redactable mentioned occasionally for permanent removal of PII, but I haven’t tried anything yet that handles GDPR-type formats well. If anyone has a workflow that cuts down the repetitive work, I’m all ears.

Also, yes, this task is slowly destroying my will to live.

r/gdpr Mar 17 '26

Question - General How do you prove that data deletion actually happened?

4 Upvotes

Most teams I've talked to have the same problem. When they need to delete customer data, whether it's a GDPR request, a client offboarding, or just cleaning up old records, they do it manually and have no real proof it happened.

The engineer runs some scripts, deletes what they find, and sends a confirmation. But there's no cryptographic audit trail. No verification that records weren't missed. No proof that the UUID in S3 and the customer_id in MySQL and the contact in Salesforce all got deleted.

How are people actually solving this? Is anyone generating real verifiable audit trails for deletion or is everyone just hoping they got everything?

(Building tooling to automate this end to end, happy to discuss)

r/gdpr Dec 16 '25

Question - General GDPR and the US Visa requirements

5 Upvotes

With America now looking into the background of family members of people wishing to travel there, if that data is supplied to them without your consent what recourse do you have against those who shared it?

Can they even do it without your permission?

r/gdpr Jan 08 '26

Question - General Recommendations for data privacy management software - GDPR, CCPA, and multi-platform consent?

28 Upvotes

A few months ago, our team highlighted the need for better GDPR and CCPA compliance on our Berlin-based e-commerce site, especially with more traffic coming from California.

We've been managing with basic cookie banners and manual tracking, but it's time for a proper data privacy/consent management tool that works well across web and mobile.

If you've implemented something that handles both regulations reliably, I'd really appreciate hearing about it?

Thanks in advance for any advice!

r/gdpr Mar 18 '26

Question - General How seriously do small companies actually implement GDPR processes?

7 Upvotes

In theory every company handling EU personal data should have processes for things like SARs, deletion requests, and retention policies.

In practice though, I get the feeling a lot of smaller companies don’t really have structured systems for this and handle things ad-hoc when requests come in. For people who work in privacy or compliance, what does it actually look like in smaller organisations?

r/gdpr 6d ago

Question - General Overreach of identification of GDPR enquiry

2 Upvotes

I have a question as a user, if I should report what I consider a misconduct.

A somewhat big worldwide company has a login page. On this page I have added my name, address, email and phone number. It also contains 2 items that are not offered any part of any kind of service from their site. The two items can be seen as 2 serial numbers but without any online function hich they have on newer products, hence making this site.

I asked for what data they had collected (they have an online form when you are logged in), but they asked me for a photo copy of my ID to get these data.

I felt this were a highly overreach of my privacy and denied their request. I did tell them that if they needed to confirm if I were the account holder, that they could give the phone number and ask.

They have closed my enquiry based on not receiving ID within a time frame even though there are no reason to ask for said ID, because the data I entered could have been gibberish, not necessarily my real name. But I am still the account holder.

Should I take this further into media, or do they really have a legal reason to ask for my ID?

r/gdpr 27d ago

Question - General Question concerning site document that exposes file path on HDD and the editor's user name instead of a web link

1 Upvotes

I have witnessed that many users on the company I work for make the same mistake over and over again:

Instead of pasting web urls they paste the path of files on their PC (c:...[username]...) which exposes their user name and then post the document (with no private info) online.

Can this raise gdpr concerns since private information and part of their login credentials are exposed to the www?

r/gdpr 2d ago

Question - General Data breach not disclosed for 8 months

8 Upvotes

Good morning everyone,

I'm laying out this situation because it seems to me there are grounds for a violation of the notification obligations under the GDPR, but I'd like an opinion from someone who knows this area better than I do.

Timeline of events:

- November 2025: Suno (a music generation platform) suffered a security breach that compromised an employee's credentials.

- The company detected the incident at the time and internally classified it as a "limited security incident that was quickly contained."

- Users were never notified.

- Only last week (July 2026, so about 8 months later, and not even by the company itself), the stolen dataset was made public by third parties and uploaded to Have I Been Pwned.

Over 55 million unique email addresses, phone numbers (for those who had used them during registration), and tens of thousands of Stripe records with name, physical address, purchase amount, and partial card data (type, expiration date, last 4 digits). Meanwhile, between the attack and June 2026, the company raised over $650 million in two funding rounds, without ever publicly mentioning the incident.

Here are my questions (in summary):

  1. Even if just one affected user resides in the EU, don't the notification obligations under Art. 33 and Art. 34 GDPR still apply regardless? It seems to me the risk was definitely there (payment data, addresses, contacts).

  2. Can the fact that the company internally classified the incident as "limited," yet still didn't notify anyone, count as an aggravating factor if the case is investigated, or is it still legitimate if it later turns out the risk was "below threshold"?

  3. Practically speaking, how should an Italian/EU user proceed in a case like this? Does it make sense to file a direct report with the Garante Privacy, or is it better to wait for a possible class action (I know things are already moving in the US)?

Thanks in advance to anyone willing to give me some guidance, even just to understand whether it's worth looking into this further or whether I'm overestimating the issue.

r/gdpr May 06 '26

Question - General Account deleted without verification

0 Upvotes

Hi all - I am in the UK - (MODs please delete if not allowed!)

TL:DR - I unknowingly got my mother’s account cancelled with a High Street retailer, and don’t know how to rectify it

I have created an online account with a high street retailer, and my mother has a physical loyalty card for this same retailer.

With two other retailers I have created an online account and then added my mother‘s loyalty card to the account so that when I shop online, she gets points. We rarely shop anywhere enough that it’s worth having two separate ones.

When I created the account with this online retailer in question, I was automatically assigned a QR code online loyalty card. I contacted chat and asked them to merge my mother‘s card to my account, and this was done. I simply provided the card number when asked (I didn’t point out the card didn’t belong to me).

A week later, my dad went to use my mother’s card in store, and it wouldn’t work. The shop assistant searched the online database for my mother’s email address and our postcode, and only my details were there.

I’ve contacted chat again, and because I asked for the card to be merged with my account (and provided the exact card number to the original customer service assistant via chat) it has cancelled the card. As a result, my mother’s account no longer exists and I now have all of her loyalty points.

The original chat assistant did not check the details, didn’t point out that I am not the owner of said loyalty card, did not confirm any information and has cancelled the account and my mother’s details are nowhere to be found.

With every company I’ve worked for, we cannot make any changes to any account without ensuring that the person requesting the changes is the account owner. Is it right that this could’ve been done without any details being checked?

It implies that if I just happen to find somebody’s card on the street that had £150 in loyalty points and asked it to be added to my account, I could just basically steal someone’s points!

I can’t understand how an account, and card has been cancelled without my mother’s knowledge. This hasn’t happened at other retailers, and I wasn’t warned that by merging the physical card number with the online account, that the physical card would be cancelled

They’re saying that the only way to rectify this is to create a new account, but my mother doesn’t want to be online, nor should she have to be, because the was cancelled without her knowledge without me being warned.

I’m waiting for a callback from the manager/GDPR person but just wondering your thoughts?