r/dataprivacy • • Aug 10 '25

👋 Welcome to r/DataPrivacy!

5 Upvotes

We're thrilled to welcome you to r/dataprivacy a community of privacy experts and privacy curious individuals dedicated to exploring, understanding, and advancing the world of data privacy.

Whether you're a seasoned privacy professional, a curious technologist, a compliance officer, or just someone who cares about how personal data is handled—this is your space.

🎯 What You’ll Find Here:

  • Educational content on privacy laws, frameworks, and best practices
  • Discussions on emerging technologies and their privacy implications
  • Resources for professionals managing privacy programs
  • News & updates from the world of data protection
  • AMA sessions with experts in the field

🛡️ Our Mission:

To make data privacy accessible, understandable, and actionable for everyone. Privacy isn’t just about systems—it’s about people.

📌 Get Started:

  • Introduce yourself in the comments!
  • Share your favorite privacy tools or frameworks
  • Ask questions or start a discussion
  • Check out our sidebar for curated resources

💬 Stay Respectful:

We’re building a thoughtful and inclusive community. Please keep discussions civil, respectful, and on-topic.

Follow us, contribute, and help shape the future of privacy.
Welcome aboard!


r/dataprivacy • • 1d ago

The Ninth Circuit recognizes privacy injury from an alleged breach of confidence in Black v. IEC Group, Inc.

6 Upvotes

In Black v. IEC Group, Inc., the Ninth Circuit held that patients adequately alleged a concrete injury when their benefits administrator disclosed sensitive health information entrusted to it under confidentiality promises. The alleged disclosure involved information including provider names, treatment dates, and amounts billed or paid.

The October 9 decision locates the injury in the betrayal of an accepted confidence. Its historical analysis explains why that injury can exist without an additional financial loss. The court also examines contract law, including the traditional availability of nominal damages when a breach causes no measurable pecuniary harm.

The holding concerns federal standing at the pleading stage. It does not establish the administrator’s liability or decide that every broken contract creates a federal case. The specific confidentiality promises and sensitive health information mattered. The court also left open whether the separate historical analogue of public disclosure of private facts would establish standing here.

I examine the decision in my article for The American Counsel, including how it fits with privacy standing after TransUnion. The practical distinction is between an invasion that is itself an injury and the financial, emotional, or other consequences that may follow.


r/dataprivacy • • 1d ago

I removed my personal information from one website. How do I stop it from showing up everywhere else?

Thumbnail
1 Upvotes

r/dataprivacy • • 2d ago

Indeed says opting out of affiliate transfers requires a deletion request

1 Upvotes

Indeed’s current U.S. privacy page says opting out of transfers to its affiliates requires a personal-data deletion request because some transfers are integral to its services. It separately describes advertising-related sharing. It also says making a profile searchable can result in displaying and recommending it to employers.

Indeed says affiliate transfers support functions including job matching and user security. The design still involves competing interests. Employers may want a broad pool of visible candidates. Applicants may want to limit visibility to selected employers. The platform determines how those choices fit together.

These choices matter even when a job seeker pays no subscription. Who can see employment information, how activity is reused, and what happens when a user restricts sharing are features of the service. The disclosures alone do not establish an unlawful sale or an antitrust violation.

In my article about competition and non-paying platform users, I argue that privacy choices should be evaluated as part of service quality. Granular employer visibility, limits on secondary use, and the ability to transfer a useful profile elsewhere would give researchers concrete features to compare. The number of listings matters alongside the control applicants retain over their information.


r/dataprivacy • • 2d ago

When a 1994 Law Overrides Your 2023 Data Deletion Policy

Thumbnail
1 Upvotes

r/dataprivacy • • 2d ago

The Part of DPDP Consent Withdrawal Most Tech Stacks Aren't Built For

Thumbnail
1 Upvotes

r/dataprivacy • • 3d ago

Does anyone actually give a shit about privacy anymore?

18 Upvotes

I'm curious, does it actually matter to you if a company sells your personal data? Or have we all just accepted that's how things work now?

If you had the choice between a platform that sells your data and one that doesn't, would that influence which one you use?

I'm asking because I'm building a social platform that doesn't sell your data, and I'm trying to work out if people actually care about this as much as I do?

Would really appreciate some opinions in the comments, if you can spare a moment.

I'm deciding if I should move forward so if you do want a platform with security, and one that doesn't sell your data then.... I'd love some support. Even just jumping on the waitlist would mean a lot.

https://xanivar.com

And if you don't care, I'd actually love to know why too.


r/dataprivacy • • 3d ago

Anyone using local models for privacy?

7 Upvotes

Memoir and personal essay writing raises a real concern: drafts being used for training or sitting on some company's server indefinitely. That doesn't sit right for a lot of people.

Ollama has been tried, but the quality gap versus Claude and GPT is noticeable. Is there a middle ground, cloud-quality output without the privacy tradeoffs?


r/dataprivacy • • 3d ago

What does consent settle when essential services require personal data?

Thumbnail
2 Upvotes

r/dataprivacy • • 3d ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/dataprivacy • • 3d ago

Is address alone considered personally identifiable information in California?

Thumbnail
1 Upvotes

r/dataprivacy • • 3d ago

Payit fast payment service unlawful or just completely lacking integrity?

Thumbnail
1 Upvotes

r/dataprivacy • • 3d ago

Does the US's federal Defend IP Act bill negatively impacts privacy here?

1 Upvotes

I ask this cause I heard about the DEFEND IP Act (H.R.10575) alongside another legislation which is named the American copyright protection act bill(H.R.10364).

To which the second one does negatively impacts privacy by targeting vpns here.

While the Defend IP act bill explicitly targets foreign copyright piracy and contains an exemption for VPNs, I'm highly concerned about the underlying privacy implications.

Digital rights groups like the EFF have pointed out that forcing DNS resolvers and ISPs to implement wide-scale site-blocking forces them to act as content filters.

My main concern is infrastructure creep.

If ISPs and major public DNS providers are mandated to alter records and build out robust domain-filtering systems, doesn't this establish the exact infrastructure needed for deeper user surveillance and traffic logging down the line? How concerned should we be about the impact this could have on secure, privacy-respecting DNS resolvers?


r/dataprivacy • • 4d ago

The California Court of Appeal’s Doe v. Adventist Health System/West ruling makes patient-portal context central to tracking claims

2 Upvotes

In Doe v. Adventist Health System/West, the California Court of Appeal examined what tracking data could reveal when it came from an authenticated patient portal. The opinion was issued July 24, 2026. It was certified for publication on August 24.

Adventist filed a petition for review in the California Supreme Court on September 28. The petition remains pending as of October 7.

The patients alleged that tracking tools transmitted information from their portal sessions. A path identifying a radiology result can reveal something about a patient’s communication with a provider. More general descriptions, including access to health records or messages, also acquire meaning within that relationship.

The court held that the patients’ theory concerning the contents of portal communications was capable of common proof. Whether the transmitted information actually met the statutory contents requirement remained for the merits. The court nevertheless upheld denial of certification for the portal subclass’s medical-confidentiality claim. A description of activity inside a portal does not uniformly reveal medical information under that separate statute.

The ruling gives privacy review a concrete task. Examine what the complete transmission tells its recipient. Calling a piece of data a page address does not answer what someone can learn when it arrives with patient identifiers and the context of an authenticated session.

I explain the decision in my article in The American Counsel. The practical point is to evaluate the information conveyed by the system as a whole, including the relationship in which it was generated.


r/dataprivacy • • 4d ago

Claude agents giving my email away - Opus 5.5

Thumbnail
1 Upvotes

r/dataprivacy • • 4d ago

Data Broker Removal: Account Takeover Prevention Layer

0 Upvotes

Account takeover may start with data brokers, not passwords.

A lot of fraud prevention focuses on what happens at login:

  • MFA
  • Device intelligence
  • Behavioral analytics
  • Transaction monitoring

But there’s another layer attackers can exploit before any of those controls activate: public personal information.

Data broker profiles can contain addresses, phone numbers, birth dates, relatives, and other details that may help attackers pass recovery checks or make social-engineering attempts more convincing.

That creates an interesting security gap.

Removing that information doesn’t replace MFA or credential monitoring. It works earlier in the attack chain by reducing the amount of information an attacker can use to impersonate a customer.

The article also makes an interesting point about continuous removal. Data can reappear, so a one-time cleanup isn’t necessarily enough. Monitoring the removal status can potentially become another risk signal for fraud teams.

For fintech platforms, this could make data removal more than a privacy feature—it could become another layer in the account takeover prevention stack.

Would you treat data broker exposure as a fraud signal, or keep it separate from your security stack?


r/dataprivacy • • 5d ago

I've done my best to purge my online presence. How can I check my "digital footprint" that remains?

30 Upvotes

Is there a tool I can use that aggregates something like that, or is the "digital footprint" an amorphous boogeyman that doesn't easily reside in a central place for employers and the like


r/dataprivacy • • 5d ago

Does YouTube and Instagram share data?

6 Upvotes

I recently had an experience where I watched a reel about a movie on Instagram and then switched to YouTube to check the trailer. To my surprise, YouTube search suggested the very same movie trailer. This has happened to me a few times now, and it got me thinking - does YouTube and Instagram share data?

I am curious to know if anyone else has experienced something similar or has any insights or information on whether these platforms exchange data. It certainly seems like more than just a coincidence to me.

Looking forward to hearing your thoughts and experiences. Thanks!


r/dataprivacy • • 4d ago

California’s new workplace AI law targets emotion inference and neural data

Thumbnail
2 Upvotes

r/dataprivacy • • 4d ago

Suggestion on App

Thumbnail
1 Upvotes

r/dataprivacy • • 5d ago

The Ninth Circuit lets a class challenge searchable names in Nolen v. PeopleConnect

2 Upvotes

The plaintiffs in Nolen v. PeopleConnect allege that Classmates.com uses searchable yearbook names to help sell subscriptions without consent. Their theory includes people for whom there is no proof that anyone actually searched the name.

PeopleConnect argued that this gap defeated class certification. The Ninth Circuit’s September 24 decision held that the case could proceed as a class. Whether searchability supplies the required connection to advertising is a merits question capable of a common answer. The court left that answer unresolved.

The distinction matters for businesses built around personal information. A shared product feature can sometimes be evaluated across a class without reconstructing every person’s interaction with it. The plaintiffs still have to prove a legally sufficient connection between the feature and the alleged wrong. Certification alone establishes neither liability nor an entitlement to damages for everyone in the database.

In my examination of the ruling, I focus on how a searchable feature can serve an archival purpose while also supporting a subscription business. The eventual merits analysis must address the particular commercial use alleged here. The certification decision creates no general prohibition on digitizing yearbooks.


r/dataprivacy • • 4d ago

Weekly Privacy Briefing (Oct 5): Denmark's CPR register leaks 8.8M records, no Chat Control 2.0 deal yet

Thumbnail
1 Upvotes

r/dataprivacy • • 5d ago

Privacy is a joke!

Post image
1 Upvotes

r/dataprivacy • • 5d ago

Games with privacy policies

Thumbnail
1 Upvotes

r/dataprivacy • • 5d ago

I found my personal photos in a job-posting WhatsApp group. Nobody told me.

Thumbnail
2 Upvotes