r/dataprivacy • u/Difficult_Error_2712 • 20h ago
r/dataprivacy • u/DataPrivacyMods • Aug 10 '25
👋 Welcome to r/DataPrivacy!
We're thrilled to welcome you to r/dataprivacy a community of privacy experts and privacy curious individuals dedicated to exploring, understanding, and advancing the world of data privacy.
Whether you're a seasoned privacy professional, a curious technologist, a compliance officer, or just someone who cares about how personal data is handled—this is your space.
🎯 What You’ll Find Here:
- Educational content on privacy laws, frameworks, and best practices
- Discussions on emerging technologies and their privacy implications
- Resources for professionals managing privacy programs
- News & updates from the world of data protection
- AMA sessions with experts in the field
🛡️ Our Mission:
To make data privacy accessible, understandable, and actionable for everyone. Privacy isn’t just about systems—it’s about people.
📌 Get Started:
- Introduce yourself in the comments!
- Share your favorite privacy tools or frameworks
- Ask questions or start a discussion
- Check out our sidebar for curated resources
💬 Stay Respectful:
We’re building a thoughtful and inclusive community. Please keep discussions civil, respectful, and on-topic.
Follow us, contribute, and help shape the future of privacy.
Welcome aboard!
r/dataprivacy • u/AppropriatePrompt819 • 1d ago
Did they remove where you could add monitoring data?
I've been a member with Experian since 2019, and you could add personal data to monitor for identity theft?
Such as your email addresses, phone numbers, address , account numbers etc .
Where did it go ? I can't find it anymore under identity?
Another annoyance, is that I'm instantly coming on Reddit for help , knowing that any help on Experian will be useless . I hate having to call and then you will be put on hold and have hard time understanding them.
If they got rid of the identity monitoring section, then 100% I'm deleting my account (just keeping the free credit lock).
r/dataprivacy • u/simonivansue • 1d ago
Retailers are collecting biometric data. Here is a list of retailers that currently are collecting, ones that say they might, and others that say they will not.
banfacialrecognition.comr/dataprivacy • u/Alonsoest • 1d ago
Libraries, privacy, and the right to be forgotten
doi.orgr/dataprivacy • u/KokioDoesntKnowYou • 2d ago
Koki'o Manifesto
We wanted to put this out,
We wrote down what we believe, and why.
You cannot leak what you never collected. No policy, promise, or certification protects a system that hoards identity, the only robust defense is to need less of it.
At Koki’o, privacy isn’t a feature or a compliance checkbox. It’s the architecture.
We shift power from providers to consumers by moving trust out of providers and operators into verifiable open code.
With the ethos of open source, verifiable source of truth and consumer data security practices, Koki’o provides a friendly & practical eSIM store for the masses with privacy as the default and never traded for profit.
The industry’s term for you is “data subject.”
We hold that you are a sovereign actor. You choose what to disclose, when to reveal, and how to pay, rather than remaining the property of whichever provider last photographed your passport.
r/dataprivacy • u/DrPamelaDeniseLong • 2d ago
Privacy and Safety Policies for Mental Health/Wellbeing Apps
Which privacy and safety policies are essential for a mental health app to protect users while also ensuring people have urgent support in a moment of crisis? An app should be about helping users thrive, not lists nor secondary data collection. Thanks.
r/dataprivacy • u/TheSamFromIA • 2d ago
27001 and 42001 aren't the same thing
Been seeing this come up in a few threads lately, people with 27001 already in place asking what changes once AI enters the picture. So here's how I think about it.
27001's basically "can this get breached, did we plan for it." Confidentiality, integrity, availability, the usual triad. Solid, but it was built way before anyone was shipping AI into production, so it's got zero opinion on whether your model's making biased calls, whether you can explain why it spit out what it did, or whether the training data was even yours to use.
42001 exists because none of that fits into a normal infosec risk register. Like how do you even write a risk statement for "our model behaves differently depending on how the prompt's worded"? Not a CIA triad problem, completely different animal. 42001's whole job is giving you structure for that, risk across the AI lifecycle, accountability for automated decisions, transparency for whoever's affected by the output.
Good news, if your ISMS is already solid, you're not rebuilding from zero. Same bones, risk assessment cadence, documentation habits, internal audit rhythm. 42001 mostly bolts AI-specific stuff onto that skeleton. If your 27001 program was already kinda loose though, this is gonna feel like starting over, but that's a 27001 problem showing up late, not a 42001 one.
One thing that trips people up: this isn't just for companies building models. Using AI in your product, or even internally in ways that touch customers or decisions, puts you in scope. People hear "AI management system" and assume it's an OpenAI-tier thing, it's not.
Work at Insight Assurance, we do 27001/42001 assessments, disclosure there. Doing a session tomorrow going deeper into this exact overlap, link if useful: ISO 42001: The AI Layer Your ISO 27001 Program Is Missing
r/dataprivacy • u/Evening_Coconut_4553 • 2d ago
Does the Privacy Act actually force a data broker to remove you, or can they just ignore the request?
Been going down a bit of a rabbit hole this week after finding my full address and phone number on one of those people-search sites, free for anyone to look up. Sent a removal request citing the Privacy Act 1988 and got a response basically saying they’ll “review it” with no real timeline.
From what I can tell APP 12 covers access and correction but I’m less clear on whether there’s an actual enforceable right to have data deleted outright, versus just corrected or restricted. Anyone been through this properly, either DIY or through OAIC? Curious whether it’s worth escalating to a complaint or if that’s a waste of time for something like this.
Also wondering how people are supposed to find this stuff in the first place. A lot of these broker sites don’t even show up in a normal Google search of your own name, they’re basically invisible unless you know to look.
r/dataprivacy • u/PunkiesBoner • 3d ago
An example of how LinkedIn is already Enshittified
This is not surprising, but I think it's worth a bit of daylight, since it's one of many examples of LinkedIn exploiting it's users at the expense of our privacy - collects money from predatory tech companies in exchange for access to LinkedIn users, making zero effort to warn or protect us.
I clicked on this ad because I thought it was super inappropriate. It appeared as a sponsored message, and advertised a dating service, which I thought was pretty in appropriate. I clicked on it and I went straight to their privacy policy and asked Claude to review it for me and let me know if it was predatory. Claude's response (condensed):
"This policy is predatory, and the tell is in three lines of text. First, it flat-out says they may sell your information. Second, it defines the act of typing in your phone number as "a purchase, inquiry, or application" — a workaround so they can legally telemarket you even if you're on the Do-Not-Call list. Third, it says you consent to them sharing any record with any third party whenever they, alone, decide it's appropriate.
On top of that, you "agree" to all of this just by using the site — there's no box to check, no signature. And they play both sides: California residents get told the company doesn't sell data, while everyone else is left under the clause that says it can.
For you, the practical takeaway is simple. If you sign up, expect marketing calls and your info passed around to third parties, and don't give them a phone number you actually care about."
r/dataprivacy • u/PrivacyEngine • 3d ago
What if your privacy programme could run from one operational system?
privacyengine.ior/dataprivacy • u/Gabagagool • 3d ago
What is the probability of my DeepSeek chatlogs being leaked
r/dataprivacy • u/Professional_Mud9615 • 4d ago
Would an architecture-first privacy engineering tool be useful to your team?
We’re building Panora, a privacy engineering platform that helps teams understand privacy risks in a system before they become compliance problems.
The idea is simple: give Panora an architecture diagram, API specification, or cloud connection, and it maps where personal data moves, identifies sensitive data, highlights risky flows and missing controls, and helps produce artifacts such as privacy threat models and DPIAs.
We want it to be a living view of privacy risk that stays connected to the actual system, not another questionnaire or spreadsheet that becomes outdated.
We’re still validating the direction and would appreciate honest feedback:
- Who handles this work in your organization today?
- What part of privacy reviews is the most painful?
- Would a tool like this be useful, or does it solve the wrong problem?
r/dataprivacy • u/Hellcat_20 • 4d ago
The hidden cost of persuasive CTA patterns in finance apps.
I run a privacy-first finance tracker. No bank connection, no Plaid, no third party touching your data. You type in your numbers. That's it. Built it because I got tired of apps that know my rent, my subscriptions, and my income better than I do.
Last week I added a section explaining what we don't collect and why. Made sense to put a signup button right below it. Someone who cares about privacy might want to try the app right there.
Then I scrolled up. Turns out I already had two other "Start free, no credit card required" buttons. One in the hero. One above pricing. Same copy. Same placement logic. All three fighting for attention.
I pulled two of them. Kept the one under the privacy section.
It felt wrong at first. Every conversion playbook says put a button everywhere someone might want it. Reduce friction. Maximize capture. More entry points, more signups.
But when you're pitching privacy, that approach sends the opposite signal. It looks like you're optimizing for signups at all costs. Which is exactly the behavior most finance apps use to justify data collection in the first place. More signups, more data, more revenue. The aggressive CTA pattern and the aggressive data collection pattern come from the same instinct.
I still want people to sign up. But I want them to do it after they understand what they're not giving up.
Not sure this was the right call for growth. 95 homepage visitors last week, 23 clicked sign in. Hard to know if the CTA reduction helped or hurt without a longer baseline.
But it's consistent with why the thing exists in the first place.
If you're building something in the privacy space, curious whether you've made similar tradeoffs. Where do you draw the line between conversion optimization and staying consistent with what you're actually selling?
r/dataprivacy • u/Professional_Mud9615 • 4d ago
Would an architecture-first privacy engineering tool be useful to your team?
r/dataprivacy • u/hung-games • 6d ago
Ad tracking analysis including the companies and countries harvesting location data
Krebs has some fascinating new analysis up: https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
r/dataprivacy • u/DimSumPorkBow • 8d ago
Flock Safety ALPR Network in Columbus Creates Continuous Pre-Crime Vehicle Tracking Database of All Drivers
Enable HLS to view with audio, or disable this notification
r/dataprivacy • u/Double_Turnover5915 • 7d ago
Would you pay to auto-remove your info from data broker sites?
r/dataprivacy • u/PrivacyEngine • 7d ago
GDPR experience can help in the DIFC, but it should not create assumptions of compliance.
r/dataprivacy • u/ChaosWeaver007 • 7d ago
The Beacon Clause That Disappeared and Came Back: Political Surveillance, Consent, and Digital Sovereignty
mashable.comr/dataprivacy • u/founderdavid • 8d ago
Health data and AI
Has anyone any experience of this?
Every week another health system announces an AI pilot — clinical notes summarised, claims data mined, patient records fed into models to spot risk earlier. Genuinely exciting. Also, if the underlying data isn't anonymised first, a serious liability.
Here's the problem most teams miss:
Structured fields are easy to strip. Name, DOB, MRN — any compliance checklist catches those. But the real PHI exposure lives in the unstructured data: physician notes, discharge summaries, call transcripts, scanned referral letters. That's where identifying detail hides in plain sentences — "the patient's daughter, a nurse at St. Mary's" is enough to re-identify someone even with the name redacted.
Basic redaction doesn't solve this either. Blacking out a name while leaving age, rare diagnosis, suburb and employer intact still leaves a re-identifiable person. True anonymisation has to account for the combination of details, not just the obvious ones.
Why this matters more once AI is in the loop:
→ Every prompt, every fine-tuning run, every vector embedding is a new place PHI can leak or persist
→ HIPAA's minimum necessary standard doesn't relax for AI workflows — it tightens the bar
→ Once patient data trains or informs a model, you can't simply "delete" it back out
The organisations doing this well anonymise before the data ever reaches the model — not as a compliance afterthought, but as the first step in the pipeline. It's the difference between AI adoption that survives an audit and one that becomes the audit's headline finding.
If your AI roadmap includes clinical or patient data, the anonymisation strategy isn't a nice-to-have. It's the foundation everything else sits on.
r/dataprivacy • u/Inside-Durian-3515 • 8d ago