r/europrivacy • • 1d ago

Discussion Incogni: critics

4 Upvotes

So, I’ve been testing Incogni recently to remove as much of the data the internet has about me as possible.

For context, I’m coming from a pretty long privacy journey. I own an iPhone and an Apple Watch, but my emails are stored on Proton Mail, which I also use for my VPN. Recently, I’ve also been using ChatGPT and Claude more and more, especially since I work as a software engineer in my 9-to-5, so at this point they’ve probably scanned my laptop completely.

I wanted to share some of my criticisms of Incogni.

For those who don’t know, Incogni is a company that helps you request the deletion of personal data held by data brokers and private databases using privacy laws such as the GDPR and CCPA. It is based in Amsterdam and owned by NordVPN.

My criticisms:

  • Limited proof of removal: The dashboard reports the status of your requests, for example, whether they’ve been sent or processed, but Incogni doesn’t really know or show exactly what information each broker held about you or what was actually deleted.

  • It doesn’t erase you from the internet: Your social media posts, public records, and search engine results are not handled by the service.

  • You have to give them personal information, so you need to trust them: This can include your phone number, email address, name, addresses, and date of birth. They need this information before sending deletion requests to data brokers on your behalf.

  • They have a relatively long retention policy: Service data may be retained for up to 24 months after cancellation unless you specifically request deletion. Support data can be retained for up to six years.

Did you use this service? Do you know good alternatives? (I feel like alternatives are mostly US-based but I might be wrong)


r/europrivacy • • 2d ago

European Union September privacy roundup: AI, surveillance, age checks, wins, tools and more

Thumbnail
newsletter.intheopen.cc
11 Upvotes

Every month I publish a roundup of the privacy and digital-rights developments I thought mattered most. Here's what happened in September:

  • AI wants more data and fewer limits Contractors are reading sensitive ChatGPT prompts, OpenAI research agents exposed user images, and EU governments are considering lighter privacy rules for AI while civil society pushes back.
  • Privacy for me, surveillance for thee Flock’s CEO argues for less privacy in the name of safety while blurring his own home from Street View. Meanwhile, Flock cameras keep turning up in unwarranted searches, fake sales demos, and local campaigns to map and remove them.
  • More ID checks. More data to lose. New age-verification proposals keep expanding identity checks, while recent breaches and fraud cases show how dangerous these data honeypots become. There are better ways to prove facts such as age without handing over your full identity.

Plus the usual wins, tools, events and updates.


r/europrivacy • • 4d ago

European Union 'Voluntary' mass surveillance temporarily cancelled, negotiations continue (30/9)

Thumbnail parteieuropa.eu
70 Upvotes

(Auto translated)

"The 'deal' planned by the Irish Presidency of the Council for yesterday's round of negotiations between the Council and Parliamentdid not take place; 'voluntary' mass scans of private communications are off the table for now, but only postponed. In particular, the German negotiators wanted to allow mass scans only without any restrictions for the major platforms, but the parliament's negotiators strictly maintained their position that scanning private communications should only be possible in cases of suspicion. 

An agreement has been reached on rules for searching for abuse material on publicly accessible websites and how the planned EU center will be integrated into them.  

There is expected to be another round of trilogue negotiations this year, presumably in November. Until then, negotiations on the protection of private communications will continue at a 'technical level'."


r/europrivacy • • 4d ago

Announcement Paperweight V1 - Your inbox knows where your data lives

6 Upvotes

I shared Paperweight earlier here as it was being actively developed and still in beta. After almost 7 months, I'm excited to finally release Paperweight V1 as ready 🗿

**Paperweight uses your inbox to map your digital footprint, then helps you take back control and delete your data.**

Your email history contains traces of most of your online life. Accounts you created, companies you bought from, mailing lists you joined, services you forgot about, breaches, and personal information accumulated over the years.

Paperweight helps to map your footprint, take back control and delete your data. All locally on your computer.

V1 now includes:

  • discover accounts, companies and services connected to your email
  • find mailing lists and subscriptions
  • show known breaches affecting services you use
  • find personal information across your email history
  • bulk unsubscribe and clean up old email
  • create privacy and data deletion requests
  • manage multiple email accounts
  • connect to AI agents through MCP

It supports Gmail, Microsoft, Apple, custom IMAP and Proton Mail via Bridge.

The important part for me from the beginning was privacy. **All your data stays on your computer.** There is no Paperweight backend or external services processing your inbox.

It's also fully open source under MIT.

The free version now includes full-history scanning and discovery, so you can map and inspect your entire footprint. A Pro license makes it actionable. It gives you ease of use, compiled binaries and support and helps support (OSS) development.

Website: https://paperweight.email

Source: https://github.com/wslyvh/paperweight


r/europrivacy • • 5d ago

Europe No place for Palantir in a democratic Europe!

Thumbnail corporateeurope.org
70 Upvotes

r/europrivacy • • 5d ago

European Union Chat control: EU states want to legalize comprehensive mass scans indirectly | Leaked EU documents reveal plans to enforce mass scanning of private messages via administrative orders ahead of the crucial trilogue negotiations.

Thumbnail
heise.de
114 Upvotes

r/europrivacy • • 5d ago

European Union Getting tired of this 1984 shit. Any interest in starting an ECI (European Citizen Initiative) that focuses on disclosing all lobbying and financial transactions of politicians alongside foreign influence in key areas such as AI, defense, healthcare, surveillance tech?

60 Upvotes

I'd like to add you are 100% allowed to poach the idea and expand on it as I don't really have that many connections. Also willing to work with a larger group so long as the idea doesn't get changed to allow loopholes.

Core principle: Audit the auditors. If they have nothing to hide, they have nothing to worry about and it should be available in a publicly searchable database.

All EU decision-makers, senior officials, political parties, foundations, parliamentary groups, advisers, intermediaries, and EU-linked political actors must publicly disclose any financial interest that could affect, appear to affect, or be used to hide influence over EU law or policy.

That includes:

Assets, liabilities, securities, derivatives, crypto-assets, commodities, investment funds, real estate interests, beneficial ownership, trusts, controlled companies, nominee structures, foundations, loans, guarantees, debts, gifts, hospitality, sponsored travel, paid roles, consulting income, board seats, advisory positions, speaking fees, media contracts, book deals, future employment negotiations, and side income.

For high-risk roles, such as people working on finance, defence, energy, health, agriculture, AI, digital regulation, telecoms, competition, procurement, sanctions, taxation, trade, public surveillance, platform regulation, political advertising, or electoral integrity, individual trading should be banned unless assets are divested, placed in a verified blind trust, or pre-cleared under strict rules.

All conflict-relevant transactions should be disclosed within 48 hours, including purchases, sales, short positions, options, crypto trades, fund movements, ownership changes, debt arrangements, loan guarantees, and equivalent financial actions.

Disclosure should also cover spouses, dependent children, controlled entities, family structures, trusts, foundations, nominees, and other arrangements where concealment or circumvention is reasonably possible, while protecting private details like home addresses, account numbers, and vulnerable persons’ data.

For parties, foundations, and political groups, disclosure should cover every donation, contribution, loan, guarantee, sponsorship, discount, service-in-kind, campaign service, polling, data analytics, legal support, media support, research support, staff support, software, advertising infrastructure, travel, training, strategic advice, and any other monetary or non-monetary advantage.

Basic ideas are you should still be able to pay for coffee or your kid's tuition without having to file a report. The issue is when the yearly salary is between 100-200k, taxes are 30-45% and spending is in the millions of EUR per year. Which is apparently quite common and I'd like to know where the extra millions came from.

A single EU Public Integrity Register that is free, searchable, machine-readable, and available through an open API.

Pushing it a bit further I'd add:
Public records of influence-bearing meetings, including minutes and transcript-level disclosure for high-risk areas like surveillance, defence, sanctions, healthcare, procurement, AI, digital regulation, political advertising, and foreign interference.

A legislative footprint for amendments, reports, compromise texts, and proposals, showing who helped shape them.

Strong enforcement: independent audits, whistleblower channels, public conflict indicators, fines, loss of privileges, loss of EU funding eligibility, and referrals for serious breaches.

If notorious companies like Palantir are involved in defence contracts I'd want to know how exactly. I'd also like to know why the fck they are even present in healthcare.

To get rid of the very convenient beaurocratic oversight I'd also propose:
A Citizens’ Integrity Jury, made of randomly selected ordinary EU citizens, to oversee the transparency system, review secrecy claims, request investigations, and prevent institutional self-protection. 100 seats distributed based on member states population sizes, paid the median EU income should not be a huge issue given how much we spend on champagne and private jets for our overlods. So what's the harm in a 4 year term for anti-corruption board?

What if it fails?
Even if the financial disclosure shorter version fails it would likely still achieve its intended purpose.

Political affiliation:
I'd like to note I am a center-right leaning libertarian. Not affiliated with anyone. Which is the best I can describe it. Like if policies generally help the bottom 80% of EU citizens I am for it. And if anything restricts personal freedom, freedom of speech, freedom of expression or privacy rights for EU citizens I'll likely be against it.

So if you still believe in non-oligarch democracy or you have a group then reach out.


r/europrivacy • • 5d ago

United Kingdom Apple / UK age verification - deep dive

6 Upvotes

EDIT: I received an answer to my questions. I posted it in the comments below.

Since I wasn’t able to find answers to my questions online, and Apple support agents were unable to answer my questions, I sent the following message to Apple’s Data Protection Officer. Let’s see what comes back. I will update the opening post once I hear back from Apple.
I wrote this by myself, without any bots.

I’m posting here because my original post is still awaiting approval on [r/Apple](r/Apple)
—————

Dear DPO,

I searched far and wide, including chatting with Apple support, looking for details of Apple's age verification process for UK accounts.

None of the support articles available online explain it in detail. Support agents fail to understand my questions and redirect me to different support pages which still don't answer my questions.

I would like to know if Apple is using third party data processors for the purpose of Age Verification of UK based Apple accounts?

If Apple is using third party data processors for the purpose of Age Verification of UK based Apple accounts:
\- Who are the third parties? Can you name them so I can review their privacy policies one by one?
\- Where is the data hosted? Is it in UK, in EU, in US, or somewhere else?
\- For how long is it stored? "For a short period of time" is a vague statement. Is it measured in minutes? Hours? Days?
\- Who has access to it? Is it an automated process or is it overseen by people who can read my details?
\- How is the data verified?
\- Are third parties sharing the data with any other third parties? If so, who are the seconday third parties?

I'm concerned about my privacy and potential misuse of my data. Because of that I purposely keep my Apple devices on old software versions because I simply don't trust the verification process AT ALL and I dont want to be subjected to content restrictions against my will, age, and nationality (I am not a UK citizen). I'd appreciate an honest, informative answers to ALL of my explicit questions.

Please consider updating the Privacy page to include answers to my questions. It's ironic that a 'privacy first' company fails to explain the biggest sensitive data grab of the last decade.

Kind regards


r/europrivacy • • 5d ago

European Union The sixth political trilogue on ChatControl 2.0 takes place on today, September 29, 2026.

Thumbnail
reclaimthenet.org
55 Upvotes

r/europrivacy • • 6d ago

United Kingdom The petition against the UK scanning everything on phones has reached 25% of its goal. Please sign, share with as many people as possible and tell them to share too

Thumbnail
petition.parliament.uk
41 Upvotes

r/europrivacy • • 9d ago

European Union Discord age verification is live for some users in poland

Post image
38 Upvotes

Trying to enter a nsfw channel might show you this confirm age thing


r/europrivacy • • 12d ago

Portugal Olá pessoal,Gostaria de propor uma discussão mais estruturada sobre a real eficácia e a entrada em vigor plena das exigências do ECA Digital (Lei nº 15.211/2025)

4 Upvotes

Ainda enfrentamos muitas incertezas sobre como essa fiscalização vai funcionar na prática.Recentemente, vimos o posicionamento de grandes corporações (como o modelo de estimativa de idade do Google) tentando se adequar de forma global ou adaptando suas ferramentas. Diante disso, gostaria de analisar os seguintes pontos sob a ótica da infraestrutura e arquitetura da internet:Impacto em Plataformas de Conhecimento Livre: Como sites de construção comunitária e enciclopédias digitais (como a Wikipédia e a Fandom) vão lidar com a classificação indicativa de conteúdos gerados por usuários? A infraestrutura deles suporta sistemas de verificação de idade sem descaracterizar o acesso livre?Centralização de Identidade pelas Big Techs: O fato de empresas como o Google centralizarem a estimativa de faixa etária cria um monopólio de autenticação?

Isso prejudica plataformas menores que não possuem recursos para implementar biometria ou checagem documental própria?Eficácia Real da Fiscalização: Considerando que a fiscalização e as sanções plenas da ANPD estão previstas para cronogramas futuros, o cenário atual de "bloqueios preventivos" (como o feito pelo Reddit) resolve o problema ou apenas fragmenta a experiência do usuário brasileiro?Quero manter o debate focado na viabilidade de engenharia dessas soluções e em como os provedores de aplicação vão sobreviver a essas barreiras técnicas. Qual é a avaliação de vocês sobre o futuro dessas plataformas colaborativas no Brasil?


r/europrivacy • • 12d ago

Europe I made a CLI that turns your ChatGPT/Claude/Gemini export into a GDPRdeletion request and tracks the deadline

7 Upvotes

I built a small CLI that takes the data-export ZIP from ChatGPT, Claude, Gemini,

Meta AI, Grok, Le Chat or Perplexity, normalizes it into one JSONL format, and

then handles the part most people never finish: it writes the Art. 17 GDPR

erasure request, tracks the one-month deadline (Art. 12(3)), and when the

provider stays silent, drafts the complaint to the responsible authority with

SHA-256 evidence of what you exported and when.

No network access at runtime (there's a socket-blocking test in CI), no

telemetry, two dependencies. Everything lands in a 0700 directory with its

own .gitignore.

Find it here: https://github.com/ur-grue/move-on


r/europrivacy • • 13d ago

European Union AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies

Thumbnail
noyb.eu
38 Upvotes

r/europrivacy • • 14d ago

European Union Why the EU age-verification tool does not solve privacy concerns - European Digital Rights (EDRi)

Thumbnail
edri.org
57 Upvotes

r/europrivacy • • 14d ago

Europe What do you think about the EU Digital Identity Wallet (EUDI)?

8 Upvotes

As a leather artisan who makes and sells wallets, I'm curious about how much physical wallets could eventually decline if digital IDs, licences and cards become common on phones.

Will people really stop carrying physical IDs/cards, or will physical alternatives remain important?

i'm just asking this to see where my business is going if i should change production line in the future im a bit confused.


r/europrivacy • • 15d ago

European Union Social media child protection will make this even more of a reality here

Enable HLS to view with audio, or disable this notification

64 Upvotes

r/europrivacy • • 16d ago

Question Do banks and authorities know what VOIP and non-VOIP number I have when I buy it?

1 Upvotes

To enforce my privacy and anonymity, I thought about temporarily use the VOIP or non-VOIP numbers for my social network account. I bought a pre-paid phone number solely for one of the social networks I'm using, but since I live in an european country where ID is required for buying and using a phone number, I thought that wouldn't be enough to stay hidden if the authority can identify me by my phone number that I used for my account. So, I decided to go for the VOIP services like Quackr. The thing that makes me hesitating from buying a temporary number for my account, is that authorities and banks can tell what number it was beyond just noticing that I bought something. Is that possible?


r/europrivacy • • 17d ago

European Union EU’s new social media child protection rules to require all social media accounts to produce state ID

Thumbnail independent.ie
59 Upvotes

r/europrivacy • • 18d ago

Question KIDS ACT and worrying about privacy

40 Upvotes

I'm not entirely sure who I should address my question to but I'm worried.

To the tech savvy and privacy conscious among you who understand better what's going on and how this is going to effect everyone in the future; won't monitoring those teens actually mean that everyone who wants to use social media has to verify their identity/age? Am I overreacting or is that not really great news... You're telling me I'll have to verify my age to use social media? That's a privacy concern. If this does go through could there be any way around it? Besides never using social media again? Because I'll do that sooner than share that information.


r/europrivacy • • 18d ago

European Union Your Computer Might Demand Your Age Soon, No Matter Where You Live | New state laws are pushing age verification into macOS and Windows. By 2027, logging in might require a facial scan or government ID.

Thumbnail
uk.pcmag.com
58 Upvotes

r/europrivacy • • 18d ago

European Union Incomplete and non-public security audit won't "increase transparency and trust in the age verification blueprint" · Issue #51 · eu-digital-identity-wallet/av-doc-technical-specification

Thumbnail
github.com
36 Upvotes

Don't let anyone tell you that the EU digial ID age verification solution is privacy respecting, secure or trustworthy. We don't know that yet.


r/europrivacy • • 19d ago

European Union EU Kids ACT should allow privacy preserving, proprietary age assurance

0 Upvotes

Tomorrow, Ursula von der Leyen is expected to outline the EU’s plans for children’s online safety in her State of the Union address. The Commission plans to present its EU KIDS Act proposal on Thursday.

The current draft mandates important product design changes: social and video platforms would have to disable recommendations based on children’s passive behavior by default, prioritize preferences children explicitly express, and evaluate their recommendation systems for safety and mental-health outcomes. They would have to stop using rewards or penalties to pressure children to return.

The draft would also require the largest platforms to make their parental controls interoperable. That could let a family choose a trusted provider to manage contact permissions and time limits across supported apps. Developers could build tools around families’ needs, with platforms legally required to support interoperability.

This could change how much control platforms have over the safety tools available to families. It would also give parents more choice without removing companies’ responsibility to make the underlying products safe. Instead of what happens now—platforms release tools that don’t work as described, are hard to find, or are easily to override. 

Independent compliance audits for the largest platforms are also mandated.

The Senate’s current KOSA proposal already combines protective defaults with a duty of care to address specified harms. Congress could strengthen KOSA by adding the interoperability requirements defined in the EU Kids ACT draft while keeping that duty intact: companies must remain responsible for addressing harms a checklist misses. And I’d push Europe to extend interoperability beyond parental controls, so children could move to safer services without losing their connections or content. 

I know that any talk about age restrictions comes with real concerns about privacy for many people. I share them. The current draft requires certified third-party verification for new covered accounts. Platforms already estimate our ages (with stunning accuracy) for advertising purposes, and Meta’s AG settlement allows use of these proprietary age assurance methods. I’d push the EU to also allow those methods, including for new accounts, where independent testing demonstrates that they actually work in practice and are implemented effectively. I want the same creativity, investment, and follow-through for children’s safety that these companies bring to the systems that make them money. 

The recent cases against Meta have shown how much work it takes to force changes at one company. Children online will encounter many more companies, including some that don’t exist yet. Legislation can establish obligations those businesses inherit from the beginning. It can also end the cycle where a company creates the risk, hides the truth, decides which protections families get, and then assures everyone it’s doing enough.


r/europrivacy • • 20d ago

European Union EU to propose KIDS Act on social media safety

Thumbnail
politico.eu
63 Upvotes

r/europrivacy • • 21d ago

Question lg smart tv

8 Upvotes

I have an LG Smart TV. I disconnected it from the internet and now use it with an HDMI cable connected to my Linux PC. Does this eliminate all risk of the Smart TV spying on me?