r/dataprotection • u/gra8na8 • 10h ago
r/dataprotection • u/Prior_Industry • Apr 08 '26
General Discussion Community Overview
Welcome to r/DataProtection!
The umbrella term "Data Protection" means we are not tied to the narrow focus that more specialist subs tend to have. With that in mind, our focus will be on highlighting the most interesting and important developments in the industry and discussing the day to day issues that Data Protection professionals encounter. How this will work in practice is set out below.
Content Scope:
First and foremost, all posts and comments on this subreddit must be related to data protection or data privacy in some way. Generally speaking, the following are in scope:
- Questions, news, and resources about data protection and the development of existing and upcoming legislation.
- Discussion of data protection topics and concepts, such as the right to be forgotten.
- Career experiences working in data protection.
- Experiences with products and tools that support data protection roles and responsibilities.
While in scope here, legal questions are often better served by more specialist subreddits - such as r/GDPR for EU data protection law or r/CCPA for the California Consumer Privacy Act.
Be Constructive and Substantive
Discussion should aim to be constructive, guiding, and substantive - unsubstantiated comments don't serve the community. In practice, this means:
- Be constructive. Comments should be useful and helpful rather than negative or dismissive.
- Be substantive. Explain the reasoning behind your position. For example: "In Europe that wouldn't be allowed, as it would conflict with the principle of data minimisation under the GDPR" is far more valuable than "That wouldn't be allowed here in Europe."
Crossposting Welcome
With the aim of highlighting the best of the data protection community across Reddit, crossposts are welcome - with the following in mind:
- Crossposts should only come from data protection related communities, and should be specific to data protection topics.
- No excessive crossposting - only share content you consider a particularly interesting discussion or a pivotal news item.
Excessive Promotion
We follow the example set by r/cybersecurity that awareness of tools and products can be useful to the community. All promotion - including self-promotion - must meet both of the following conditions:
- The poster must have been active in the community before discussing a business or product
- Make up no more than 10% of your posts and comments on this subreddit. You are a community member first and a promoter a distant second
- No more than once per week per promoted entity
- No hidden promotion in the form of surveys
Links to resources are permitted, provided they are genuinely useful resources rather than promotional content in disguise — moderators will use their discretion in making that determination. Moderators reserve the right to remove any posts that negatively impact the community.
How can you help?
Moderation is much easier when the community helps:
- Votes
- Comments
- Reports
The direction of the community may change depending on how it grows in the future.
Thank you!
Detailed sub rules can be found here.
Credit: This post is an update to the guidance set out by u/dataprotectionkid
r/dataprotection • u/BitOfATinkerer • 2d ago
General Discussion Etekcity’s parent company (VeSync) is now selling your personal health data?
galleryr/dataprotection • u/Kydje • 2d ago
General Question Could a recruitment platform lawfully collect and store someone’s personal data without contacting them?
I just noticed the following email in my spam folder:
Privacy Notice - No Action Required
Hi, This short message is from XXX, a recruiting system used by recruiting teams worldwide to find talented individuals for exciting new job opportunities. We want to inform you that your data has been gathered for the purpose of connecting you with potential employers. Your privacy is extremely important to us, so we would like to inform you of our data handling practices and your data privacy rights. Ultimately, you are in control of your data. We look forward to helping you elevate your career to the next level!
Thanks, The XXX team
I haven't heard of this company before and I never sent them my CV, nor (clearly) ever granted any permission of collecting my data. Looking them up, they market themselves as "Agentic AI Recruiting Platform". Furthermore, the company seems to be US-based and storing data on US servers, whereas I'm an EU citizen living in the EU.
I may be a bit naive right now, but I have so many questions I don't even know where to start. Is this even legal under GDPR? Can companies nowadays just decide to start gathering data on (foreign) individuals and storing it on their servers for whatever purpose, without any type of confirmation or approval from the individual? Is this the future we're heading towards?
I haven't included any links to the company or privacy policy because not sure whether it is allowed in this sub, but will do if it's permitted. FWIW the company seems legit, there's years-old articles about them getting VC funded.
Disclaimer: not looking for legal advice. Just genuinely concerned about the situation.
r/dataprotection • u/IceVeritas • 2d ago
🇪🇺 - GDPR Question Can a DPO remain independent if they are also involved in the controller’s legal defence?
r/dataprotection • u/Alternative-Day-7414 • 3d ago
Breach ICE shared Medicaid data it wasn't supposed to have with Palantir
npr.orgr/dataprotection • u/sirjont • 4d ago
Breach Business Insurance Solutions Ltd Data Breach
I recently got an email to say my details had been taken in a data breach.
And a few weeks back on my Experian account I had a notification that some of my details had been found on the dark web.
What information of yours was involved?
We have undertaken a detailed risk assessment of the data in scope of the incident. This identified the following types of personal data relating to you:
Contact Information
Bank Account Number & Sort code
Date of Birth
They told me in the email I should be cautious and keep an eye on things but with it being my main bank account I’m a bit worries to be honest.
Should I just do nothing and watch my accounts?
r/dataprotection • u/Academic-Soup2604 • 5d ago
Breach How much damage can a single USB drive really do?
One unauthorized USB device is enough to copy sensitive files, introduce malware, or bypass your security policies.
Protecting business data starts with controlling how it moves.
- Restrict unauthorized USB devices
- Prevent sensitive data from being copied
- Reduce the risk of malware infections
- Strengthen compliance with endpoint data controls
Whether you use native Windows controls or an endpoint DLP solution, USB protection is a simple but effective step toward preventing data loss.
For more reference: This step-by-step guide on How to Disable USB Ports, cover different methods, from Device Manager and Group Policy to enterprise-scale management.
r/dataprotection • u/SockOk5701 • 6d ago
Breach So Clearview got sued for allegedly scraping billions of faces, tried to settle it with a payout tied to its future value, and the appeals court just blew that deal up
r/dataprotection • u/SockOk5701 • 7d ago
General Discussion If fingerprints can leak from photos, why are we still treating biometrics like harmless convenience features?
Enable HLS to view with audio, or disable this notification
r/dataprotection • u/FunnyMarch847 • 7d ago
General Discussion PSA: Anthropic and OAI may have switched your data sharing consents.
You all need to check your privacy settings. Anthropic had changed mine to enable model training on my data without my knowledge or consent. OpenAI did the same but worse (opting me in for ads and everything). Check your privacy settings. They are likely not what you consented to. Worse in the terms they give themselves permission to take **past** conversations and coding history while sharing is enabled. If you care about IP, check your settings haven't been switched underneath you. These companies' ethics are on the floor RN.
r/dataprotection • u/furself333 • 9d ago
General Discussion Flock ALPR Database Misuse by Georgia Officers Exposes Nationwide Surveillance Privacy and Accountability Failures
Enable HLS to view with audio, or disable this notification
r/dataprotection • u/furself333 • 10d ago
General Discussion Flock ALPR Database Misuse by Georgia Officers Exposes Nationwide Surveillance Privacy and Accountability Failures
Enable HLS to view with audio, or disable this notification
r/dataprotection • u/SockOk5701 • 9d ago
General News The EU says Meta’s Facebook and Instagram design may breach the DSA and wants autoplay and infinite scroll turned off by default.
Enable HLS to view with audio, or disable this notification
r/dataprotection • u/ChronicallyCasual4u • 11d ago
General Discussion How do you keep up with regulatory changes and privacy news without feeling overwhelmed ?
r/dataprotection • u/technadu • 11d ago
General Discussion UK's Ofcom proposes new rules that would make Big Tech more accountable for scam ads
Ofcom has published draft rules that would require major online platforms to take stronger action against fraudulent advertisements under the UK's Online Safety Act.
The proposed Fraudulent Advertising Code includes measures such as:
- Verifying advertisers claiming to represent legitimate businesses
- Checking that financial advertisers are authorized by the FCA
- Banning repeat scam advertisers
- Improving protections against account hijacking
- Testing AI-powered advertising tools to reduce scam risks
- Creating faster reporting channels for law enforcement and trusted organizations
According to Ofcom, more than half of UK adults have encountered suspected scam ads, with annual losses exceeding £200 million.
The proposals are currently open for consultation, and if they become law, companies that fail to comply could face significant financial penalties.
Do you think stronger platform accountability will meaningfully reduce online scams, or will fraudsters simply adapt to new enforcement measures?
r/dataprotection • u/EdikTheFurry • 12d ago
General Discussion Deleted from the database but alive in the backups.
r/dataprotection • u/SnooBunnies9221 • 12d ago
Career Advice on where to move after postgrad in UK
Hi everyone,
I'm an international student currently studying for an LLM in Bristol, and I'll be finishing my course this September.
I'll need to move out of my student accommodation, ano I'm trying to decide which city to move to while I job hunt.
I'm hoping to start a career in data protection/privacy, so I'm looking for a city with a good job market in that field, while also having more affordable rent than Bristol.
I'm finding it difficult to work out where would be the best place to move. Does anyone have any recommendations for cities with good opportunities in data protection or privacy roles and a relatively affordable cost of living?
I'd really appreciate any suggestions or advice, thank you!
r/dataprotection • u/Vox-Digital1989 • 16d ago
General News NUCLEAR DROP: PJ 2029 proposes to require Digital ID to use the Internet
Internal leaks confirm the plan to erase digital privacy, in order to 'protect children'.
Europe, wake up until it's too late.
A Mass Surveillance plan known as Project 2029 proposes to end digital privacy and arrest people for online comments.
This happened in the Five Eyes (UK, New Zealand, USA, Canada, Australia) and will happen to us if we don't take action.
What's this all about, the truth the elites are afraid to show:
- Ban for all Social Media. The definition is too ambiguous. Social Media means the combination between a forum, a video platform and a messenger app.
- The youth rights violation. Human Rights violation. Cause? The right to information for everyone will be violated.
- End of Privacy? Unfortunately yes. By mandatory ID scans, privacy will die. The state will know everything about you and what you're doing. "Big Brother is watching you", will become true.
Share this article fast and to as many people as possible. Everyone needs to see the truth. Don't let Big Brother control your life. We don't want to end up like Singapore or China.
Share massively the article
r/dataprotection • u/psyll_com • 16d ago
General News Why the right to be forgotten fails with AI
psyll.comWe're currently dealing with a massive mismatch between privacy law and AI tech. The Right to be Forgotten worked for Google because they just delisted links. LLMs are different; they 'digest' your data into weights.
To actually delete your info from a model like GPT-3, they'd have to retrain it, which costs millions and emits hundreds of tons of CO2. With 80% of us already suffering from digital exhaustion, we don't have the bandwidth to monitor how these models are reconstructing our identities. The system is fundamentally broken.
r/dataprotection • u/Greedy-chilli • 16d ago
General Discussion People often claim that Chinese AI poses a threat to personal data policies, but in reality, all major tech companies are constantly collecting our data.
r/dataprotection • u/Loose_Cow_9808 • 18d ago
General Discussion AI age verification with KYC data
r/dataprotection • u/_innocentkid_ • 18d ago
General Question Why does sharing our personal data to china feels so bad/wrong than selling same or more to US?
Isn't that concerning?
r/dataprotection • u/Sz32fear_TCE • 19d ago