r/gdpr 6h ago

UK 🇬🇧 Can I file a complaint to the ICO?

0 Upvotes

Hello, I used Workable to apply and do recorded video answers for a role for a UK company, which rejected me. I asked the team to please delete my data, to which they did not reply to, so I am unsure if they did or did not.

May I send the ICO a complaint and send evidences after a few weeks of request?

I read a lot of experiences that ICO is notorious for not doing anything. Thanks!


r/gdpr 1d ago

EU 🇪🇺 How can I remove old news articles about me from Google under the right to be forgotten?

18 Upvotes

Hi everyone. I’m posting this because I honestly can’t take it anymore and I really need someone to help me out.

Long story short, almost 10 years ago, when I was really young and pretty stupid, I got involved in a minor incident. It wasn’t anything serious, I didn’t go to prison or anything like that, but it did become public. A local newspaper in my city wrote an article about it, and a couple of those blogs that repost news picked it up as well.

The problem is that it happened a long time ago. I’ve completely changed, I have my own life and a family now, but every time someone searches my name on Google, BAM, it’s the first thing that comes up.

I’m currently going through the hiring process for a job that I desperately need to support my children, and I’m terrified that they’ll Google me and find it. I feel like something stupid that happened when I was 20 is going to ruin my future now.

I’ve tried emailing the newspapers and asking them to please take the articles down, but they’ve completely ignored me. I’ve read a bit about the “right to be forgotten” and Google removal forms, but whenever I start looking into it, I get overwhelmed. I don’t understand any of the legal terminology, I get really anxious, and it feels impossible unless you have enough money to hire expensive lawyers.

Please, does anyone know HOW to actually do this step by step, explained in really simple terms? What exactly do I need to fill out? Who should I contact first?

Any genuine advice would mean a lot. I’m really struggling with this situation. Thank you so much in advance.


r/gdpr 1d ago

EU 🇪🇺 Lessons learned about structuring GDPR complaints

Thumbnail
1 Upvotes

After several months of exercising my GDPR rights in relation to CCTV recordings, I’ve come to one conclusion that I wish I had understood from the beginning.
If I had to file my complaints again, I would do so in a different order.
Not because the substance of my case has changed, but because I now believe that some legal questions should be resolved before others.
This is the order I would follow:
1. Independence of the Data Protection Officer (DPO)
Before discussing access to personal data, I would first examine whether the DPO was able to act independently or whether there was a potential conflict between the DPO’s role and the organization’s legal interests.
2. The use of Article 12(5) GDPR
If access requests are rejected as “excessive” or “manifestly unfounded,” I believe this issue should be addressed before debating the merits of the access request itself.
In my case, each Article 15 request concerned a different incident, with a different date, time, location and factual background. The fact that they all related to CCTV did not automatically make them repetitive or excessive.
3. Effective exercise of the right of access under Article 15 GDPR
Only after resolving the previous issues would I focus on whether the controller effectively complied with Article 15 GDPR.
Looking back, I think this sequence provides a clearer legal framework. If the justification for refusing requests under Article 12(5) is found to be inadequate, the discussion about Article 15 becomes much more focused.
I’m sharing this simply as a lesson learned from my own experience. It may be useful to others dealing with repeated GDPR requests or CCTV access cases.
I’d be interested to hear whether others would structure their complaints differently.


r/gdpr 1d ago

Question - General Data breach not disclosed for 8 months

8 Upvotes

Good morning everyone,

I'm laying out this situation because it seems to me there are grounds for a violation of the notification obligations under the GDPR, but I'd like an opinion from someone who knows this area better than I do.

Timeline of events:

- November 2025: Suno (a music generation platform) suffered a security breach that compromised an employee's credentials.

- The company detected the incident at the time and internally classified it as a "limited security incident that was quickly contained."

- Users were never notified.

- Only last week (July 2026, so about 8 months later, and not even by the company itself), the stolen dataset was made public by third parties and uploaded to Have I Been Pwned.

Over 55 million unique email addresses, phone numbers (for those who had used them during registration), and tens of thousands of Stripe records with name, physical address, purchase amount, and partial card data (type, expiration date, last 4 digits). Meanwhile, between the attack and June 2026, the company raised over $650 million in two funding rounds, without ever publicly mentioning the incident.

Here are my questions (in summary):

  1. Even if just one affected user resides in the EU, don't the notification obligations under Art. 33 and Art. 34 GDPR still apply regardless? It seems to me the risk was definitely there (payment data, addresses, contacts).

  2. Can the fact that the company internally classified the incident as "limited," yet still didn't notify anyone, count as an aggravating factor if the case is investigated, or is it still legitimate if it later turns out the risk was "below threshold"?

  3. Practically speaking, how should an Italian/EU user proceed in a case like this? Does it make sense to file a direct report with the Garante Privacy, or is it better to wait for a possible class action (I know things are already moving in the US)?

Thanks in advance to anyone willing to give me some guidance, even just to understand whether it's worth looking into this further or whether I'm overestimating the issue.


r/gdpr 2d ago

EU 🇪🇺 What lawful basis could a recruiting platform use to collect an EU resident’s data without prior contact?

4 Upvotes

I just noticed the following email in my spam folder:

Privacy Notice - No Action Required

Hi, This short message is from XXX, a recruiting system used by recruiting teams worldwide to find talented individuals for exciting new job opportunities. We want to inform you that your data has been gathered for the purpose of connecting you with potential employers. Your privacy is extremely important to us, so we would like to inform you of our data handling practices and your data privacy rights. Ultimately, you are in control of your data. We look forward to helping you elevate your career to the next level!

Thanks, The XXX team

I haven't heard of this company before and I never sent them my CV, nor (clearly) ever granted any permission of collecting my data. Looking them up, they market themselves as "Agentic AI Recruiting Platform". Furthermore, the company seems to be US-based and storing data on US servers, whereas I'm an EU citizen living in the EU.

I may be a bit naive right now, but I have so many questions I don't even know where to start. Is this even legal under GDPR? Can companies nowadays just decide to start gathering data on (foreign) individuals and storing it on their servers for whatever purpose, without any type of confirmation or approval from the individual? Is this the future we're heading towards?

I haven't included any links to the company or privacy policy because not sure whether it is allowed in this sub, but will do if it's permitted. FWIW the company seems legit, there's years-old articles about them getting VC funded.

Disclaimer: not looking for legal advice. Just genuinely concerned about the situation.


r/gdpr 2d ago

EU 🇪🇺 Can a DPO remain independent if they are also involved in the controller’s legal defence?

Thumbnail
1 Upvotes

r/gdpr 3d ago

Question - General Humanly IMPOSSIBLE to ask every company to remove your CV/resume (GDPR)

7 Upvotes

Hey, I'm tired of recruiters asking for my CV and then just ghosting me.

I want to email each one telling them to f* off and that I don't want to participate in their zombie KPI databases anymore, but most companies make it almost impossible.

It's not even clear which email address I should send the data removal requests to. I think almost 300 companies have my resume and I want to erase it all. How can I do this in batches, or is there a SaaS that can deal with it?

I would gladly pay for it. I've had enough of playing around with these consultancy companies.

Please help me.


r/gdpr 3d ago

EU 🇪🇺 Is Article 15 GDPR really an effective right for accessing CCTV footage, or is it mostly theoretical?

0 Upvotes

The GDPR gives individuals the right to access their personal data under Article 15. In theory, this also includes CCTV footage where a person can be identified.
However, I’m wondering whether this right is genuinely effective in practice.
Many organisations retain CCTV recordings for only a few days. By the time an access request is received, identity is verified, and the request is processed, the footage may already have been automatically deleted. In some cases, controllers also argue that they cannot provide a copy because it contains images of third parties, offering only an on-site viewing or refusing disclosure altogether. In one response I received, it was also explained that footage would not necessarily be preserved merely because an Article 15 request had been submitted, unless it had first been established that the requester actually appeared in the recording.

This raises a broader question.
If CCTV is increasingly used in airports, railway stations, hospitals, shopping centres and other critical infrastructure, shouldn’t there also be an effective mechanism for individuals to verify how they were treated whenever their rights may have been affected?
Otherwise, the right of access risks becoming largely theoretical:
The organisation controls the cameras.
The organisation controls the retention period.
The organisation decides whether the footage is preserved.
By the time the legal process finishes, the footage may no longer exist.
I’m not arguing that every CCTV recording should be kept indefinitely or that privacy protections for third parties should be ignored. Blurring, redaction and supervised access already exist as possible solutions.
My question is more fundamental:

Does Article 15 GDPR currently provide an effective right of access to CCTV footage, or is it often only a right on paper?

I’d be especially interested in hearing from:
privacy lawyers,
Data Protection Officers,
supervisory authorities,
people who have actually submitted Article 15 requests for CCTV footage.
Do you think the current legal framework strikes the right balance, or should the GDPR provide stronger safeguards to ensure that this right can be exercised in practice?


r/gdpr 3d ago

EU 🇪🇺 Wedding Confirmation - GDPR compliant?

0 Upvotes

Hi all,

I am considering to build a website for confirming attendance to my wedding.

In my idea, my guests would receive by post, together with the invitation, an access code to the website.

In the website they'd log-in with their first name as well as the access code (which is stored encrypted in the database).

Upon logging in, the guests would be able to confirm attendance, or not, for them and/or the people in their household.

This requires me pre-provisioning the guests, but I already know them. They are my guests.

Does GDPR see concerns with this approach, or is it acceptable under legitimate interest?

Thanks a lot in advance!

** Edit **

Thanks for all the replies, clear now that I was overthinking this, but I'm still happy I double checked! Cheers!


r/gdpr 3d ago

UK 🇬🇧 Company held on to my data for 20 years after doing business and now has suffered a serious cyber attack.

Thumbnail
0 Upvotes

r/gdpr 5d ago

Question - General Overreach of identification of GDPR enquiry

1 Upvotes

I have a question as a user, if I should report what I consider a misconduct.

A somewhat big worldwide company has a login page. On this page I have added my name, address, email and phone number. It also contains 2 items that are not offered any part of any kind of service from their site. The two items can be seen as 2 serial numbers but without any online function hich they have on newer products, hence making this site.

I asked for what data they had collected (they have an online form when you are logged in), but they asked me for a photo copy of my ID to get these data.

I felt this were a highly overreach of my privacy and denied their request. I did tell them that if they needed to confirm if I were the account holder, that they could give the phone number and ask.

They have closed my enquiry based on not receiving ID within a time frame even though there are no reason to ask for said ID, because the data I entered could have been gibberish, not necessarily my real name. But I am still the account holder.

Should I take this further into media, or do they really have a legal reason to ask for my ID?


r/gdpr 7d ago

EU 🇪🇺 Where does a tool that surfaces deleted Reddit content stand under GDPR?

0 Upvotes

I built a small, free, non-commercial tool that looks up a Reddit username and shows their posts and comments, including content later deleted or removed. The data comes from a public third-party source, not Reddit’s API.

I know this sits in tension with the right to erasure, and I would rather understand that honestly.

What I already do: an opt-out that hides a person’s content on request, noindex on user pages, no accounts, no cookies, no data selling.

My real questions:

1. Does pulling from a public source rather than Reddit change anything, or is “publicly available” irrelevant once it is “personal” reddit data?
2. Is “hide on request” enough for an erasure request, or does GDPR require actual deletion?
3. Does a non-commercial framing help at all, or is that wishful thinking?


r/gdpr 7d ago

UK 🇬🇧 Data breach Ninja Uk

0 Upvotes

Hi there

A few weeks ago I got an email saying I have registered a new ninja kettle for a warranty. I have never bought a kettle from the company. I emailed customer service and they said they would look into the matter. Few weeks go by and they finally emailed back and said as compensation for how long it’s taken to get back to me you can have a free kettle. Brilliant! There was no resolution or explanation as to why my email address had been used though.

I was asked to confirm my delivery address and phone number which I did. I then got a notification from DPD that my address has been changed. I did not change this.

I then get a phone call from an unknown number asking if I’ve ordered a kettle from ninja? After speaking to the other lady on the phone it turns out Ninja have given out my full address and phone number to this woman who has a similar email to me. This is a massive GDPR and data breach.

I have been speaking to customer services and various managers for weeks now and I just keep getting fobbed off. They say i will receive an email with a resolution, no email turns up. They say I will hear back by the end of the day, nothing happens. They have now said it is being passed to a team higher up which they can’t tell me what team it is, the irony. I was offered compensation of 20% off which is ridiculous considered how serious the situation is, you get 10% off for signing up to your newsletter! Ninja also said they have taken my address off the other customers account, but they still haven’t!

Is there anything else I can do except contact the ICO? It hasn’t quite been a month yet

Thanks in advance!


r/gdpr 8d ago

UK 🇬🇧 Could my College/sixth form reject me/cancel my enrollment there for invoking GDPR rights?

Post image
6 Upvotes

I'm starting college in september, Ive already been accepted, passed interview, etc, but im yet to do my enrollment forum. Recently, they sent out consent forums, one section of which includes consent for marketing.

I would rather not have my photo nor my data used for marketing, so, I have decided to write a letter- If I send this to them, would they be allowed to refuse this? also, could they just say im not allowed to go to sixth form/cancel my position, enrollment point, etc preventing me from going there? I still want to go to this college... thanks.


r/gdpr 7d ago

UK 🇬🇧 Delayed DSAR request with no update

0 Upvotes

For context I worked there for 4 months so there probably isn't too much information on me, this was in england. I requested my DSAR on the 12th June and provided identification on the 14th June. My email was acknowledged on the 15th June stating "Following receipt of this, under UK GDPR, we are required to respond within one calendar month. This would place a response due by, 14th July 2026, if not before." from the director of compliance. It is now the 15th July 2026, I have not heard a response from them nor have they asked for an extension within the 30 days. As I am a previous employee (my last day was the 18th June) specifically asked for all communications to continue through my private email which they have been good at continuing through.

I am planning on sending a follow up email today but I am one day post surgery and I would like some clear opinions on what to do as I am very out of it from my medications.


r/gdpr 7d ago

EU 🇪🇺 I regret doing the age verification on X

0 Upvotes

Hi, i'm new to reddit but i really need help with this one thing. Apologies for my bad english, it's my third language :D.

I recently verified my age on twitter with a selfie, but now i regret it. I didn't reconsider my actions as I did it, which i realise now was really stupid.

I'm scared that the picture and my data will be saved, so I want to find a way to delete my verification data under GDPR (I live in Europe).

The only methods i found was to contact X, but i doubt they'll actually do anything. I also found a post here on here from one year ago, but that was about the ID verification method.

But I don't know if the deletion of verification data is different from the ID-method and the selfie-method. Afterall mine was "only" a selfie, but i'm still overthinking and concerned.

To sum it up, I wan't to know if there's a way to ask for my data to be deleted under gdpr, and I also hope one of you can assure me that my stupid choices aren't that bad :((.


r/gdpr 8d ago

Question - Data Subject is this legal?

Post image
0 Upvotes

i don't know which flair is appropriate for this, i'll start, i was looking up what a crossword puzzle was since i hadn't seen one in so long that i forgot what it was and also wanted to try one and this is what i see: accept all or reject all and subscribe for 5 euros a month

is this technically illegal? i am from germany


r/gdpr 10d ago

Analysis Master's Research on AI Governance & the EU AI Act

Thumbnail ai-act-simulation.web.app
2 Upvotes

r/gdpr 10d ago

Question - General I would love to get GDPR compliance and have high level questions...

5 Upvotes
  1. If you wanted to ensure you always have GDPR compliance, do most people have an advisor, in house person, or how can I ensure I follow the rules and continue to monitor and have someone to check with?
  2. What exactly are the rules I should follow? I know the general stuff, but like I imagine things need to be a lot more specific, i.e. boundaries, time frame, opt in, etc... Any good links for this?
  3. If having a GDPR person/advisor or whatever is a good idea, what's the best way to go about finding said person?
  4. Is GDPR the most pro-consumer (or conservative) data protection regulation out there? I'm trying to set up a baseline data policy and would like it to be a balance between the most pro-consumer and also highest legal coverage in terms of population/geography. If not, what other data policies should I look into.

r/gdpr 11d ago

UK 🇬🇧 DSAR: How should a Subject Access Request (SAR) be handled when there is a pending disciplinary investigation involving an employee or a student?

5 Upvotes

For instance, if a student or an employee submits a Data Subject Access Request (DSAR) during a pending disciplinary investigation, what is the best approach to handling it as a DPO?


r/gdpr 12d ago

UK 🇬🇧 SAR clarification

1 Upvotes

On DSAR, are reference letters totally exempted or once I request for my personal, everything would be released?


r/gdpr 12d ago

UK 🇬🇧 Advice on where to move after postgrad (UK)

1 Upvotes

Hi everyone,
I'm an international student currently studying for an LLM in Bristol, and I'll be finishing my course this September.
I'll need to move out of my student accommodation, ano I'm trying to decide which city to move to while I job hunt.
I'm hoping to start a career in data protection/privacy, so I'm looking for a city with a good job market in that field, while also having more affordable rent than Bristol.
I'm finding it difficult to work out where would be the best place to move. Does anyone have any recommendations for cities with good opportunities in data protection or privacy roles and a relatively affordable cost of living?
I'd really appreciate any suggestions or advice, thank you!


r/gdpr 13d ago

Question - Data Subject RAG/AI embeddings and GDPR - how do you evidence data erasure?

2 Upvotes

Trying to wrap my head around how vector databases fit GDPR. If embeddings are derived from personal data, how do you handle removing the data and ensure it’s really removed? I keep finding theory and advices but little real practice.

One working idea is to replace personal data by database record reference as preprocessing step (both ingestion and retrieval), persist actual data in that database, and replace back when retrieved (if needed). Erasure happens directly on the database record with soft fallback when retrieving. If you look at this sequence it doesn’t feel the best decision, hence wonder if someone is aware of a better way.


r/gdpr 13d ago

Analysis Tracking pixels: conflicting guidelines across countries (FR/IT)

4 Upvotes

CNIL (France) and Garante (Italy) both published guidelines on how to deal with tracking pixels. Both agree that explicit consent is required and without it tracking pixels can't be used.

The huge difference lies in what happens during the transition window (3 months for CNIL, 6 months for Garante):

- CNIL says that existing users (collected email addresses) have to be informed of the changes and must be provided with an easy-to-use opt-out link. Without action, controllers can keep using tracking pixels

- Garante says that existing users have to be informed of the changes and tracking pixels can't be used anymore unless the user explicitly opts in

Scenario: a citizen living in Italy has registered to a newsletter before april 16th (start of the transitioning window) and is sent, accordingly to CNIL's guidelines, an email notifying him/her that tracking pixels have been/are being/will be used unless he/she opts out. His/her local DPO's guidelines though state he/she must not receive tracking pixels if no action is taken. What happens if the citizen raise a complaint to the DPA (Garante)?