r/gdpr Feb 02 '25

Meta Rule Updates + Call for Moderators

17 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr 15h ago

EU 🇪🇺 Meta's AI crawler hit our site 741,900 times last month. Our DPA says we can barely scrape anything. Who are these rules actually for?

15 Upvotes

I run a large website for a European SME and I looked into where European regulators stand on web scraping. Honestly it surprised me how strict it all is.

The Dutch privacy regulator (AP) published scraping guidance in 2024. Short version: scraping almost always involves personal data, so GDPR applies even if the data is public. Legitimate interest is basically the only legal ground you can use, and the bar is so high that most commercial scraping is simply not allowed. Italy went even further in May 2024, their regulator told website owners to actively defend themselves against AI scrapers with CAPTCHAs and rate limiting. The UK ICO said in December 2024 that scraping for AI is possible in theory, but developers need to be way more transparent and should ask themselves if they can license the data instead. France followed in June 2025 with strict conditions. And the EDPB published draft guidelines on scraping for AI training in July 2026, also strict: robots.txt counts against you in the assessment, and no exception for special category data.

So those are the rules. Now what actually happens. Meta had to pause AI training on EU user posts in June 2024 after pressure from noyb and the Irish DPC. They resumed in May 2025 with an opt out model, noyb says that still violates GDPR, case is ongoing. But that fight was only about Meta's own users. For everyone else's content there was no pause at all. Meta-externalagent, the crawler that Meta itself describes as "downloads website content to include in datasets used for training AI models such as LLMs", visited our website 741,900 times last month. For comparison, Googlebot did 340,100 visits in the same month. And Googlebot at least sends us traffic back. The AI crawler that gives us nothing hits us more than twice as hard. Meanwhile Cloudflare accused Perplexity last year of using stealth crawlers to get around no-crawl rules, and now blocks AI crawlers by default. That says enough about how normal this has become.

To be clear, I actually think the strict rules make sense, they also protect businesses like ours. But right now the result is: European companies read the guidance and don't scrape, while big tech scrapes everything and deals with the lawyers later.

So my question: do you expect regulators to actually go after the big scrapers once the EDPB guidelines are final? Or will it stay like this? Because so far I see a lot of guidance and very little enforcement.


r/gdpr 9h ago

Question - General Instagram does not want to cooperate and responds without understanding

Thumbnail
gallery
3 Upvotes

Maybe I was too brutal with the privacy issue but at the same time they are like purposefully pretending to not understand it and send answers and directions that clearly are the situation that I explained. And then ask for the same information that I already provided.

What can I do now? Where do I strike first and to what EU authorities should I report this first?

Also is this now a new trend where companies don't even have customer support tickets/names and just say it Meta like this? Huh, first time seeing something like this.


r/gdpr 23h ago

EU 🇪🇺 GDPR SAR Request - WhatsApp Official Group

0 Upvotes

Context - Small sports organisation

Member has submitted an Sar request

We have an official WhatsApp chat for the commitee group.

What level of data does an Sar request get access to when retrieving their personal data from that group?

Example:

Bob (123-456-789) "something relevant about requestor"

Does requestor get the name or phone number of Bob? Is it relevant that Bob the committee member created the personal data? Or does bobs right to their own personal data kick in? In this case Bob is acting as a committee member. This isnt gossip between friends.


r/gdpr 1d ago

EU 🇪🇺 Announcing employees birthday the day of

5 Upvotes

My employer recently got a new HR system which will automatically create a teams message on every employees birthday. This message goes out on the company wide teams channel.

Is this allowed with regards to GDPR? Don't they need to check with each employee if they want their personal information shared with the rest of the company like this?


r/gdpr 1d ago

Question - Data Controller Has an auditor or regulator ever asked you to prove a human actually reviews an automated decision?

5 Upvotes

Trying to understand how this works in practice rather than on paper.

If you run a system that makes decisions automatically and there's a human review step, has anyone external, a regulator, an auditor, a customer's DPO, ever asked you to demonstrate the review is real rather than just present? Article 14 of the AI Act is what got me thinking about it, but I suspect GDPR Article 22 raises the same question.

If you've been asked: what did you actually hand over, and did it satisfy them? And if you haven't been asked yet, do you have something ready, or is it the kind of thing you'd assemble the week someone requested it?


r/gdpr 1d ago

EU 🇪🇺 Recommendations for GDPR / DSA EU Representative service for a startup ?

1 Upvotes

Hi all,

I'm the founder of a new Email Service Provider (not yet in production).

Established in Delaware (corporation) and I'd like to find a resonably priced GDPR and DSA EU representative service.

I've done most links on Google but the quotes I receive are super expensive (especially for the DSA rep).

I heard about Prighter which is much more competitive but the reviews online (turstpilot) are pretty back.

Would you have any recommendations for good, well priced GDPR/DSA EU reps ?

Thanks in advance!


r/gdpr 2d ago

Question - General UK SaaS — what should a DPA + MSA/SLA review actually cost, and how do you pick a firm that won’t bill you for learning what a sub-processor is?

4 Upvotes

Solo founder, UK Ltd, B2B compliance/GRC SaaS. Pre-revenue, about to start
onboarding design partners — several of them regulated, so the security
questionnaire and DPA turn up before the contract does.

I've drafted the stack myself and want a solicitor to review rather than
rewrite:

- UK GDPR Art. 28 DPA (incl. sub-processor annex, SCCs/IDTA for the US ones)
- MSA
- SLA (uptime + service credits)
- Order form
- Founder IP assignment deed

I've just spent a fair bit of effort making sure the documents describe the
product that actually exists — retention wording matches what the deletion
code does, the sub-processor list is consistent across the DPA, privacy
policy and the in-app version, that sort of thing. So this should be a
review, not a salvage job.

Questions:

  1. Fixed fee or hourly for something like this? I've seen £2–4k suggested
    for the full set but no idea if that's realistic in 2026.
  2. Is it worth splitting — DPA now, commercial terms once I have a customer
    actually negotiating? Or is that false economy?
  3. How much does the IP assignment deed matter at this stage? It keeps
    coming up as the thing investors' lawyers check first.
  4. Anything that makes a founder-drafted DPA obviously amateur? I'd rather
    fix the tells before paying someone to point them out.

Not looking for free legal advice — trying to work out scope and budget
before I ask for quotes, and how to spot a firm that does SaaS work
regularly vs one that'll bill me for the education.


r/gdpr 2d ago

Question - General GDPR video hosting for edtech company

3 Upvotes

We are edtech company from NL, it's important for us that the vid hosting for our courses is GDPR compliant. As far as Ik kinescope handles it's servers in Amsterdam, pls share who else on the market has European servers?


r/gdpr 2d ago

Question - General how does anyone actually handle erasure across backups

3 Upvotes

genuine question. article 17 says erasure but a 30 day backup rotation means the person you deleted comes back if you restore

everyone i ask either says "we document it as a limitation and restore-then-redelete" or just goes quiet

is documented limitation actually the accepted answer or is that just what everyone does because nobody's been tested on it yet? has anyone here had a DPA actually push on this


r/gdpr 2d ago

Resource EDPB just confirmed it: AI models are NOT automatically anonymous. Are we ready?

Thumbnail
1 Upvotes

r/gdpr 2d ago

Question - General Art. 17 Right to erasure (‘right to be forgotten’)

4 Upvotes

In the following video, made in the UK, a man who is drinking in public, and mentions he plans to end his life that day, subsequently gets upset and demands the video be deleted, when he realises a) he is being filmed and that b) the videographer intends to publish the video on a monetised YouTube channel:

https://youtu.be/iZnBgYfRer8?t=600 - EDIT I changed the link to jump to the relevant interaction.

The videographer refuses to comply; the question is whether Art. 17 requires him to do so. I expect it comes down to whether a court would see this as journalism "in the public interest", but there might be other aspects to this, too, for example, even if there is such a special purpose, would deleting the video be incompatible with this purpose?

NB I think it might be relevant that Art. 13 Right to be informed wasn't respected, i.e. there was no mention that a video was being made, and that it was going to be published, before the revealing conversation that the data subject subsequently wanted to be deleted. That might be OK for, e.g., a journalist working undercover, exposing corruption, say, but in this case, I am struggling to see justification for the failure to inform.


r/gdpr 4d ago

Question - General How do you manage GDPR compliance across hosting, email, calls, and third-party APIs?

0 Upvotes

I’m trying to build a practical GDPR-compliance setup for a small business and would love to hear how others approach this in real life.

The areas I’m reviewing are:

  • Website/app hosting and backups
  • Email providers
  • Call recording, VoIP, and customer-support tools
  • Analytics and CRM
  • API providers and tokens — for example Google, OpenAI, etc.

I know GDPR doesn’t necessarily mean that every piece of data must physically stay in the EU, but data transfers outside the EEA need the right legal safeguards and contractual setup.

My main questions:

  1. Do you deliberately choose EU-based vendors wherever possible, or rely on providers’ SCCs / Data Processing Agreements?
  2. How do you handle tools where personal data might be included in prompts, call transcripts, logs, or API requests?
  3. Do you maintain a simple vendor register / data map, and if so, what does it look like?
  4. Any practical red flags or mistakes you discovered too late?

I’m looking for real operational experience rather than legal theory. What has actually worked for your company?


r/gdpr 5d ago

Analysis Findings from scanning 458 recent Product Hunt launches from an EU computer

5 Upvotes

I did the following analysis to figure out how much startups really care about GDPR rules and having up to date legal documentation. For context, I run a legal documentation tool, and software companies us to automate updating their Privacy Policy, ToS, Cookie Policy, etc. We used this analysis to understand our target users better, but I thought it might be useful to other people in the community as well.

Also my findings echo a lot of the things that Nouwens et. al. found in their 2020 paper "Dark Patterns after the GDPR". Theirs was a MUCH broader study, but I almost get the same percentage of sites not doing cookie consent right.

So what I did: I went to Product Hunt's daily leaderboard and loaded about a month worth of top rated product launches. For each associated website I checked cookie behavior, foreign vendors loaded, and then I gave their privacy policy to an LLM to scan for various gaps. I did all of this from an EU location (Copenhagen).

Main results:

* 292 of 458 product sites stored tracking cookies (_ga, _fbp, and siblings), and only 50 asked first. That's 17%. Sites targeting EU users were better at this (26%), and sites with no indicator that they were targeting EU users were worse (15%).

* 61 of 458 (13.3%) product sites had no privacy policy on their site. 5% for sites targeting EU, 17.8% not targeting EU.

* 45% of policies don't name a legal basis for processing personal data and 65% don't state whether data says within or leaves the EEA. 25.7% do not give a data retention period.

* 60% of sites load with a foreign vendor that their privacy policy doesn't mention. Google Analytics, Google Ads and Posthog are the top 3, most common (and commonly unmentioned) ones.

* More upvoted product launches are not more compliant. There is essentially no difference between how many of these compliance errors are made by more or less popular startups... except for asking about cookie consent. More upvoted product sites will track with out asking less often.

This is basically all of it. I wrote a blog series on this analysis, but the key results are in these bullets.


r/gdpr 5d ago

UK 🇬🇧 Is it normal for the ICO to not investigate a data breach if it's a small organisation?

9 Upvotes

A few months ago I reported a data breach involving a counselling service which exposed the names and emails of over a hundred client.

The ICO finally replied with a generic response saying in line with the published framework they won't be investigating with no real explanation as to why.

I can't tell if they are refusing to investigate because there's no evidence of malice and it's a small organisation or that leaking the names and emails of people isn't bad enough to investigate?


r/gdpr 5d ago

EU 🇪🇺 How to qualify a complaint handling in ROPA?

2 Upvotes

Should I classify complaint handling under the ROPA activity “Performance of the sales contract” or under “Establishing, pursuing, or defending claims”? I run a micro e-commerce business.


r/gdpr 6d ago

UK 🇬🇧 Is a person’s response to an allegation the personal data of the alleger?

3 Upvotes

I’m working on a subject access request made by A.

I’m looking at a document which says “A alleges that you said X, Y and Z”.

It then says “B: I did not say that. I said, A, B, C”.

I know A’s allegation itself is disclosable, but is B’s denial disclosable?


r/gdpr 7d ago

EU 🇪🇺 EU digital ID wallets are meant to share less data, but AML rules require firms to collect and keep quiet a lot. How do those sit together?

2 Upvotes

Two things are landing close together. Every member state has to offer a digital identity wallet by the end of 2026, and AMLR applies from July 2027.
The wallet's whole design is selective disclosure. Prove one attribute, share nothing else. Prove you're over 18 without handling over a date of birth.
AML obligations run the other way. Firms have to collect specified identity data, keep it current, and retain records for years.
So when a customer onboards with a wallet, what does the firm actually end up holding? If it receives only the attributes it strictly needs, does that satisfy record-keeping? If it asks for the full set anyway, has the wallet's data minimization just been routed around by regulation?

Curious whether anyone has seen this addressed directly, or whether it's still an open question between the two frameworks.


r/gdpr 7d ago

UK 🇬🇧 Mobile App UK GDPR compliance

0 Upvotes

I am creating a mobile application, I have written the application explicitly to not collect PII. I have no accounts, there are no servers data stays on the users device.

As I am nearing the first stages of deployment Google Play Store is requiring a support contact email address. This email address must be monitored and respond to users with 72 hours.

Due to the nature of the email address and the requirement for it to be monitored, I am now on the path to becoming a data controller. I don’t want this, I don’t want to have to deal with anything GDPR related, because I don’t NEED to, except for this requirement from google. I cannot outsource the support email as I will still be the controller. There is much more infrastructure I would have to build to be compliant just so users can email me when I would have a perfectly viable and anonymous bug report system that would not require GDPR compliance.

The only data I could possibly have about any user is what they would send to this email address.

Is there anything anyone can suggest that would allow me to avoid having to manage GDPR compliance for an inbox that I don’t want ?


r/gdpr 7d ago

EU 🇪🇺 Consent dialog buttons

1 Upvotes

Can a "Do not consent" button be styled as an outline button and the "Consent" button be styled as as a filled button? If one is using Google's default AdSense consent dialog for the EU? Furthermore, must there be a "Do not consent" button on the dialog or not?


r/gdpr 8d ago

UK 🇬🇧 Personal info breach in a nursery - help!

7 Upvotes

Hi, I'm unsure whether this is the right place to ask, if not, please direct me to somewhere better to ask.

I'm 18 and applied for a position at a nursery a couple of months ago, so they had my email on file for context.

The problem is that today I received at email about an
'invoice' from the nursery, so I clicked on it being confused. Turns out they send an invoice for one of the parents to my email. I replied immediately to let them know of the mistake and all they said was 'Thanks for letting me know'.

So my question is, do I need to do anything? Because surely this is a huge data and privacy breach as personal I formation was leaked including the name of the parent, child and which days of the week they attended nursery alongside the price of their care. I'm unsure whether I need to report this anywhere or do I just leave it?

I studied health and social care in school & college so | know that if I was working there, I would be mandated to report the breach to the correct organisations but as I'm not working there, I'm not sure if I need to do anything?

I'm sorry again if this isn't the right place to post this, but I'm just genuinely so shocked & appalled at what's happened as I would expect more care to be taken when handling and sending personal information. But anyways, help & advice would be greatly appreciated!!


r/gdpr 8d ago

Question - Data Subject Automated account disablement, admitted in writing: a live test of Art. 22 GDPR and DSA Arts. 17/20, filings and timeline

0 Upvotes

Documenting a case in progress, since clean fact patterns for solely automated decisions are rare and this one is unusually explicit.

Facts. 20 August 2026, one calendar day. 10:10, controller (Meta) requests identity verification by video selfie, completed within minutes. 13:28, notice restricting advertising access, stating verification "usually takes around 48 hours", and stating "We used technology to detect this violation and carry out this decision." 14:36, permanent disablement of the account: "Your review was unsuccessful", "You can't request another review." Sixty-eight minutes after the 48-hour representation. No conduct, content or specific provision has been identified at any point. The account dated to 2008 with no violation history.

On 20(6) DSA and 22 GDPR: the platform's own support assistant later stated in writing that "the automated system has locked standard internal appeals" and that no human channel exists for the account "regardless of the time". The disablement notice itself frames the identity verification as the review ("You requested a review of this decision, but we still found...").

Filings, all August 2026: Art. 15 access request; Art. 22(3) request for human intervention; Art. 18(1)(c) restriction demand covering the classifier outputs, the biometric material from the verification, and all enforcement records (Art. 17(3)(e) noted against the controller's disabled-account retention schedules). DSA complaint under Art. 53 with the Greek DSC, transmitted to the Irish coordinator. One certified Art. 21 body declined as out of scope (no content exists to review, which is itself the Art. 17 point); a second has the case pending. The Art. 12(3) clock runs to 20 September.

Two aspects that may interest this sub. First, the special-category angle: the controller demanded biometric verification and disabled the account hours after receiving it, which puts Art. 9 lawful-basis and retention questions squarely in play for the supervisory-authority phase. Second, the interaction between an admitted "technology" decision and the simultaneous closure of every review channel looks like the cleanest possible Art. 22(3) violation: the right to human intervention cannot be exercised anywhere.

Will update the thread as responses land. Not seeking advice, the professional track is covered.


r/gdpr 8d ago

EU 🇪🇺 Webshop voegt trackers toe, ondanks de mogelijkheid om bezwaar te maken

Thumbnail gallery
1 Upvotes

r/gdpr 8d ago

EU 🇪🇺 Webshop voegt zonder gêne trackers toe voordat je cookie-toestemming hebt gegeven

Thumbnail reddit.com
3 Upvotes

r/gdpr 9d ago

Analysis Choosing an EU server region means absolutely nothing if you don't hold the keys

Thumbnail
4 Upvotes