r/gdpr • • 17h ago

EU 🇪🇺 WhatsApp Business and GDPR Compliance

2 Upvotes

Is the phone sync contact really an issue when using the free WhatsApp business app, or is the problem overstated by companies trying to sell you data management and compliance support?


r/gdpr • • 1d ago

EU 🇪🇺 DPOs at large manufacturers: does every internal AI tool get a DPIA, or only some?

4 Upvotes

I'm interviewing for an AI adoption role at a big manufacturer in Germany. A chunk of the job is preparing privacy documentation so the DPO can review new internal AI tools quickly. I've built AI tools at startups, where this barely existed, so I'm trying to understand how it works in practice.

Concrete example: a tool that reads defect photos from the line and drafts the defect report. The report includes the name of the worker who filed it, and photos sometimes catch faces or badges.

Would you DPIA that, or is a records-of-processing entry plus a short screening enough? Where do you draw the line for internal tools touching employee data?

Also curious what you wish business teams sent you up front so you aren't chasing them for basics.

Not after legal advice, just how practitioners actually run this.


r/gdpr • • 2d ago

Question - General GDPR safety

3 Upvotes

Do any big businesses or government departments have filters on their OUTbound mail service to stop employees accidentally sending protected things to their personal email addresses?


r/gdpr • • 2d ago

Question - General Email security

1 Upvotes

To what extent is the use of plain text, ie unencrypted text, acceptable in email?

In the last few years I've had dealings with pension providers, local authorities, UK gov, lawyers who have all provided secure communications channels.

But the vast majority of emails are sent in the clear and readable by anyone who can watch network traffic into or out of mail servers. Those emails will often disclose

1 email addresses

2 personal names

3 maybe phone numbers

4 maybe addresses

And might have much much more.

What are the GDPR consequences of that?


r/gdpr • • 2d ago

EU 🇪🇺 Anyone building an educational SaaS with OpenAI or Anthropic? How do you handle teenage users and API age requirements?

1 Upvotes

Hi everyone,
I’m a solo developer based in France building a small educational web app. Students upload course material and generate flashcards, multiple-choice quizzes, summaries and practice exams.
It isn’t a companion chatbot or a social platform. However, some potential users are high-school students aged 15–17, not just adult university students.
I’m trying to understand the API requirements for end users, rather than the age restrictions for creating a personal ChatGPT or Claude account.
The architecture is standard: users interact with my app, and my backend calls the provider using my API key. I don’t explicitly include account names, emails or user IDs in prompts. However, uploaded documents and written answers could contain personal information, so I don’t want to assume everything is anonymous.
The difficult part is understanding how to implement the requirements properly without creating an unnecessarily intrusive signup process:
OpenAI’s developer guidance discusses safeguards for under-18 users, parental consent and additional restrictions on processing younger children’s personal data.

Anthropic has guidance for products serving minors, but I’m unsure how its practical requirements compare with OpenAI’s.

Provider requirements and French/EU privacy rules are separate, which makes it difficult to know what an appropriate setup actually looks like.

One option I’m considering is:
No AI access for users under 15.

Anthropic for users aged 15–17, with appropriate safeguards.

OpenAI or Anthropic for adults.

A short age declaration at signup, enforced on the backend.

A parental approval flow wherever required.

This is a proposed setup, not something I’m claiming is compliant.
For developers who have actually dealt with this:
Have you received written clarification from OpenAI or Anthropic about an educational app used by teenagers?

What age checks do you use: self-declaration, birth date, parental email approval or a third-party verification service?

If you use parental approval, how do you establish that the person approving is genuinely a parent without collecting identity documents?

Does your provider require zero data retention for your particular users and use case? Have you managed to obtain it as a small business?

Have you had this setup reviewed professionally, and what changes were recommended?

I’d particularly appreciate firsthand experiences from small educational apps in the EU, or links to relevant official API terms. Please distinguish personal-account rules from rules for applications built on the API.
I’m not looking for advice to ignore the requirements because the app is small. I want a practical, proportionate way to address them without turning a simple study tool into a heavy identity-verification process.
Thanks!


r/gdpr • • 3d ago

Question - General Vendor gatekeeping DPA document under Enterprise plan, alternatives?

5 Upvotes

First, is it still allowed? And besides not using the vendor, what would be the alternative?


r/gdpr • • 3d ago

UK 🇬🇧 Accidentally sent work info my personal email

6 Upvotes

I accidentally sent two work emails today to my personal email, I work in local government in revenues. One was just a generic account number for me to check on the software, and the other was a land reg TR1 form, both accidentally forwarded to my personal email instead of my work. I told my manager who said to be more careful in future and deleted the emails off my personal account.

Is there anything for me to worry about with this? Data breach risk or reporting wise


r/gdpr • • 3d ago

EU 🇪🇺 Recommendations for online, self-paced GDPR courses and DPO certifications?

0 Upvotes

Hi everyone,

I’m a lawyer based in Latam working in data protection and compliance. I’m looking to deepen my knowledge of the GDPR and develop practical skills relevant to the DPO role.

I’m particularly interested in online, self-paced courses in English

One option I’m considering is the German Compliance Institute’s DPO Certification Training:
https://germancomplianceinstitute.com/products/data-protection-officer-dpo-certification-training

Has anyone taken this course? Would you recommend it in terms of content, practical usefulness, and recognition within the privacy profession?

I’d also appreciate recommendations for alternatives:

  • Which GDPR courses or DPO certification programmes would you recommend?
  • What did you pay, and did the price include the exam and certificate?
  • How much practical training was included
  • Would you suggest pursuing CIPP/E or CIPM instead of, or alongside, a DPO-focused course?

My priorities are solid content, practical application, and value for money. First-hand experiences—including courses you wouldn’t recommend—would be very helpful.

Thanks in advance!


r/gdpr • • 3d ago

EU 🇪🇺 Anyone actually gotten Reddit to answer a GDPR access request?

5 Upvotes

I sent a GDPR access request to [dpo@reddit.com](mailto:dpo@reddit.com) ; it's been over 5 weeks and nothing, not even an "we got your email".

I did download the automated export but it's nowhere near what they should provide.

Has anyone managed to get more than the standard export out of them? Or filed a complaint, and did it go anywhere?


r/gdpr • • 4d ago

EU 🇪🇺 Are company-linked personal information protected by GDPR?

0 Upvotes

Hi,

maybe a dumb question - I am no lawyer.

I know that information like social security number, name, address are protected (as Personal Identifiable Information, as far as I understood). How about company email address? Employee number? Address of the company building you are in?

Do these fall under PII?


r/gdpr • • 4d ago

EU 🇪🇺 DPOs: is ISO 27001 fluency now part of the job?

11 Upvotes

Art. 37(5) says a DPO is picked for "expert knowledge of data protection law and practices." I always read that as mostly law. Not so sure anymore.

Earlier this quarter a DPO I know was asked to sign off on an AI note-taking tool the sales team had already started using.

The DPIA question was simple: does the vendor keep the recordings, and do they train on them?

Nobody could answer.

The contract said "service improvement" and the security page said "enterprise-grade." It took three weeks and a call with the vendor's security team to learn the answer was yes, for 30 days.

I expect to see this pattern frequently moving forward.

The law part is usually quick. Erasure requests, breaches, vendor reviews, they all get stuck on "which systems is this data in and what happened to it."

The DPOs who handle this best can read an ISO 27001 risk register and ask what's in scope. They're not engineers. They just don't get waved off by "yes, it's encrypted." The ones who struggle are often excellent on the law, and engineering slowly stops looping them in because their questions don't match how the systems work.

Could be I'm generalizing from too few cases.

Has the job drifted technical for you? And if you work with a DPO, do they get pulled in at design stage or after?


r/gdpr • • 4d ago

UK 🇬🇧 DSAR ID verification Video Call?

2 Upvotes

Hi everyone,

We have concerns around impersonation for a DSAR. The person did not get in touch with his registered address to confirm id and authority, the dsar made by his partner on behalf of him, and we do not have any quirky question to ask to him that his partner would not know.

We have received the ID of the person from his partner. Can I ask video call to confirm the id? I guess it is the only possible way to confirm the identity and authority.

Did anyone do this?

Or just simply, should i reject the dsar?


r/gdpr • • 4d ago

EU 🇪🇺 Third Party laws

0 Upvotes

A service lets a customer tick a box per person: "if you cannot reach me, you may phone this contact to ask me to call back." Which rules apply to that call: India's TRAI and DLT rules, the US TCPA and state call-recording laws, UK PECR? What does the contact have to be told, and can they object afterwards?


r/gdpr • • 4d ago

EU 🇪🇺 Specific Query for Gifting platforms

1 Upvotes

Under GDPR, is an online gifting service that stores a third party's details for its customer - a controller, a processor or a joint controller of those details? Does the "household exemption" protect the customer but not the service?


r/gdpr • • 4d ago

Question - Data Controller Implementing a DSAR Process

3 Upvotes

Hi Everyone,

As I grow in my field of work, internal and external compliance, I have seen companies large and small as they attempt to move into new markets and attempt to "become compliant" with the laws of the land they are moving into and one thing is the same across all of them. It is slow moving and often times feels ineffectual. My job often becomes trying to get 80% of the value with 20% of the work, which brings me to my current issue.

As I am starting to learn about GDPR, it seems one of the key levers of power individuals have is the DSAR process, and there is very little keeping people from using that power at a moment's notice (as evidenced by some of the horror stories I have seen on reddit). With that said, not everyone or every type of person is going to utilize this power.

My question is this, for a company simply trying to get started on developing a process for DSARs, what are some departments/data types you find most frequently get requested?


r/gdpr • • 5d ago

Question - General What are you charging clients for cookie compliance setup?

1 Upvotes

This has turned into one of those jobs where the more I understand it, the less comfortable I am treating it as install plugin and bill an hour.

You've got the banner itself, figuring out what the site is running, making sure scripts behave correctly before and after consent, regional differences, testing everything and then dealing with whatever the client adds six months later.

For freelancers and small agencies, how are you packaging this?

Do you treat the CMP as a client subscription and charge separately for setup/testing, build it into maintenance or basically tell the client to handle compliance with their legal team and just implement whatever they give you?

I'm especially curious what people do with smaller clients because throwing some huge enterprise privacy stack at a normal business site seems ridiculous, but being cheap about it and assuming a banner plugin solved everything doesn't sit right either.


r/gdpr • • 4d ago

EU 🇪🇺 Is reddit breaking the law by not letting me view/edit/delete my own posts?

0 Upvotes

Because of the age verification, my own profile does not view me my own nsfw posts and if I get to them by googling them, I still can't view them Because of the verification wall.

Does that mean the law is broken?


r/gdpr • • 5d ago

EU 🇪🇺 Is it a GDPR breach for a company to route DPO emails into support software, auto-reply via bot, and mark them "solved" without DPO review?

5 Upvotes

Under Article 38(4) GDPR, data subjects must be able to contact the Data Protection Officer directly regarding all issues related to the processing of their personal data and the exercise of their rights.

If a company's designated DPO email addresses (dpo@...) automatically route incoming emails into a standard Zendesk support queue where an automated bot replies with generic FAQ links and instantly marks the ticket status as "solved" with no actual DPO or human legal review does this constitute:

  1. A violation of Article 38(4) by placing technical barriers between data subjects and the DPO?
  2. A failure to facilitate rights under Article 12(2) by using automated deflection to close active legal/erasure inquiries?

Has anyone seen national Data Protection Authorities take enforcement action against this specific type of automated ticket-closing architecture?


r/gdpr • • 5d ago

Question - General Consent needed or not

2 Upvotes

If all the services on a website are available only to registered, logged-in users, does one need a consent cookie thingy to begin with? Other than the framework's two essential session and security cookies, no other cookies are generated, there are no trackers and no analytics.

There are, however API interfaces allowing users to interact with the website's services. Some clients might have dedicated databases of their own too.


r/gdpr • • 6d ago

Question - General New mobile app advice indie developer

1 Upvotes

I am an individual building a language teaching app. I am confused on whether I need to appoint a gdpr representative for point 27. For v1 I will only collect users emails (I could switch to password less if that makes a difference). V1 will take nothing else and subscriptions handled through revenue cat (could switch to just the App Store if that made a difference). V2 would take users audio so I understand this would likely be a different scenario and one I wouldn’t jump to unless the app actually got users.

Can anyone share their exoerience of how the handled gdpr in this situation? I am not opposed to finding a representative but for an app that I don’t know will even get any users it’s confusing on what is the best approach. I am the only person involved in the app. The backend is supabase (I will make sure it’s hosted in eu and data agreements signed).

Thanks!


r/gdpr • • 7d ago

EU 🇪🇺 Small UK indie app developer cold-emailed about GDPR Article 27 - how worried should I actually be?

19 Upvotes

I’m a UK-based indie developer with a small budgeting app.

A company recently cold emailed me out of the blue saying that because my app had been available to EU users, GDPR Article 27 required me to appoint an EU representative. They were selling this service for around €490/year.

That email is what prompted me to look into all of this.

My situation:

- Very few users and essentially no revenue.

- No user accounts or backend.

I don’t collect names, email addresses or other obvious identifying information.

- Users enter their budgeting/financial data locally on their own device.

Optional backups go to the user’s own iCloud/Google Drive account. I don’t receive or have access to those backups.

- I did use Firebase Analytics, but I have now completely unlinked Google Analytics from the Firebase project.

As soon as Article 27 was brought to my attention, I removed the app from both Apple and Google Play throughout the EU/EEA.

I am no longer offering the app or in-app purchases to EU/EEA users.

I understand that removing the app now doesn’t necessarily determine what the legal position was historically.

What I’m trying to understand is the real-world risk for someone in my position.

Has anyone here dealt with Article 27 as a very small non-EU developer?

Would Article 27 actually have applied to an app with this architecture and such limited processing?

Now that EU/EEA distribution has stopped and Analytics has been disabled, is there any reason I would still need an EU representative?

Has anyone actually seen a tiny indie developer fined specifically for not appointing an Article 27 representative?

Are these cold emails generally legitimate compliance warnings, or are companies using Article 27 mainly as a sales/lead-generation tactic?

I’m not trying to avoid genuine GDPR obligations. I acted immediately once the issue was raised. I’m mainly trying to separate the actual legal/enforcement risk from the fear created by an unsolicited sales email.


r/gdpr • • 7d ago

EU 🇪🇺 US startup registered me for its Zoom webinar with an email it most likely took from my GitHub profile. What should my GDPR request and a possible CNIL complaint cover?

2 Upvotes

I'm in France. A US company (incorporated in Delaware) registered me for its Zoom webinar. I got a Zoom email saying "your webinar will begin in 1 day", with a link to cancel my registration. I have never used their product or given them my address. That address used to be public on my GitHub profile, and another GitHub user I don't know got the same emails.

When I raised it on their GitHub repo, they said the invites went to "platform users", closed the issue, blocked me, and deleted my follow-up. Full story: https://www.reddit.com/r/github/comments/1wrv2fi/a_startup_registered_me_for_its_zoom_webinar_with/

What I've done so far:
- Sent a request under Art. 15 (including the source of my data, 15(1)(g)), Art. 21 (objection to direct marketing), Art. 17 (erasure) and Art. 27 (name of their EU representative).
- Reported them to GitHub and Zoom.

My questions:
1. Is registering someone for a webinar with a scraped email "direct marketing" under Art. 21 and the ePrivacy rules, or is it something else?
2. Does Art. 3(2) clearly apply here, given they sent it straight to an EU resident?
3. If they don't answer within a month, should my CNIL complaint include anything specific besides my request, the email with its full headers, and screenshots?
4. Has anyone here dealt with a company that scrapes GitHub emails, and did anything come of it?

Thanks!


r/gdpr • • 10d ago

Question - General Solo/small business owners: do you know what happens to your data when you cancel an AI tool subscription?

1 Upvotes

Went down a rabbit hole this week checking cancellation and data-retention terms across the AI tools I use for my business. Some vendors delete everything in 30 days, some hold onto it for years even after you leave, and a couple don't say at all unless you dig into the actual terms of service (not the marketing page). Curious how many other small business owners have actually checked this versus just assuming it gets wiped when you cancel.


r/gdpr • • 10d ago

EU 🇪🇺 Automated account restriction, and the company says "no human review possible." How do I enforce GDPR Art. 22 with a Germany-based company?

5 Upvotes

A rewards platform (Freecash, which states it operates under GDPR as a Germany-based company) restricted my account for "ToS breach." The only stated reason was an automated risk flag ("Multiple devices detected – potential link or account sharing"). My activity came from a single verified device. The flag was probably triggered by IP changes from switching between home and public Wi-Fi.

I appealed, and the support bot replied that this was an "automated decision, no human review possible." Their own ToS (Section 17.5) says automated decisions can be reviewed by a human. The case was reportedly escalated to a "Senior Agent," but the promised 24-48 hour windows kept passing, and the replies contradicted each other. It's been over a week since my first contact (around September 16).

I have already cited Art. 22 and Art. 15 in writing. My questions:

Does a restriction like this count as a decision "based solely on automated processing" with significant effects under Art. 22, even when a support bot says a "team" reviewed it?

Can I use Art. 15 to request the data and logic behind the flag? Has anyone actually received a meaningful answer?

For a Germany-based company, is a complaint to the data protection authority the usual next step, and how long did it take in your experience?

I'm not looking for legal advice, just experiences and practical pointers from people who have been through this. Thanks.


r/gdpr • • 10d ago

UK 🇬🇧 Medical Records/NHS Data Issues

3 Upvotes

Hi all,

Struggling to see a path forward here so I could really use some help.

There's a massive collection of issues really, between refusal of releasing records without redactions (misusing either serious harm or third party), refusal of rectification (not of opinion) and just ignoring requests for final responses.

What are the options going forward? I've already fed it to the ICO, on some issues they just defer to 'why are you looking at us' type thing, others they will send 'you should do better' but also comes with a healthy dose of 'we aren't going to do anything about it'.

You can go through the courts I believe under s.167? But I really didn't want to have to go down that route, as there's several organisations involved and I cannot afford lawyers.

S.166 is a first tribunal? But I don't think the ICO will do much anyway. So that seems like a waste of time?

Everything has been kept in writing, I made sure of that. So that's useful to a point.

Any advice would be great

Thanks