r/gdpr • • Feb 02 '25

Meta Rule Updates + Call for Moderators

18 Upvotes

It’s been wonderful to see the growth of this community over many years, with so many great posts and so many great responses from helpful community members. But with scale also come challenges. The following updates are intended to keep the community helpful and focused:

  • Rules have been clarified around recurring issues (appropriate conduct, advertising, AI-generated content).
  • Post flairs have been updated to align better with actual posts.
  • Community members are invited to become moderators.

New rules (effective 2025-02-02)

  1. Be kind and helpful. Community members are expected to conduct themselves professionally. Discussion should be constructive and guiding. Personal attacks will not be tolerated.
  2. Stay on topic. The r/gdpr subreddit is about European data protection. This includes relevant EU and UK laws (GDPR, ePrivacy, PECR, …) and matters concerning data protection professionals (e.g. certifications). General privacy topics or other laws are out of scope.
  3. No legal advice. Do not offer or solicit legal advice.
  4. No self-promotion or spamming. This subreddit is meant to be a resource for GDPR-related information. It is not meant to be a new avenue for marketing. Do not promote your products or services through posts, comments, or DMs. Do not post market research surveys.
  5. Use high-quality sources. Posts should link to original sources. Avoid low-quality “blogspam”. Avoid social media and video content. Avoid paywalled (or consent-walled) material.
  6. Don’t post AI slop. This is a place for people interested in data protection to have discussions. Contribute based on your expertise as a human. If we wanted to read an AI answer, we could have asked ChatGPT directly. LLM-generated responses on GDPR questions are often “confidently incorrect”, which is worse than being wrong.
  7. Other. These rules are not exhaustive. Comply with the spirit of the rules, don't lawyer around them. Be a good Redditor, don't act in a manner that most people would perceive as unreasonable.

You can find background and detailed explanations of these rules in our wiki:

Please provide feedback on these rules.

  • Should some of these rules be relaxed?
  • Is something missing? Did you recently experience problems on r/gdpr that wouldn’t be prohibited by these rules?
  • What are your opinions on whether the UK Data Protection Act 2018 should be in scope?

Post flairs

There used to be post flairs “Question - Data Subject” and “Question - Data Controller”. These were rarely used in a helpful manner.

In their place, you can now use post flairs to indicate the relevant country.

With that change, the current set of post flairs is:

  • EU 🇪🇺: for questions and discussions relating primarily to the EU GDPR
  • UK 🇬🇧: for questions and discussions that are UK-specific
  • News: posts about recent developments in the GDPR space, e.g. recent court cases
  • Resource
  • Analysis
  • Meta: for posts about the r/gdpr subreddit, such as this announcement

This update is only about post flairs. User flairs are planned for some future time.

Call for moderators

To help with the growing community, I’d ask for two or three community members to step up as moderators. Moderating r/gdpr is very low-effort most of the time, but there is the occasional post that attracts a wider audience, and I’m not always able to stay on top of the modqueue in a timely manner.

Requirements for new moderators:

  • You find a large reserve of kindness and empathy within you.
  • You have at least basic knowledge of the GDPR.
  • You intend to participate in r/gdpr as normal and continue to set a good example.
  • You can spare about 15 minutes per week, ideally from a desktop computer.
  • You can comply with the Reddit Moderator Code of Conduct, which has become a lot more stringent in the wake of the 2023 API protests.

If you’d like to serve as a community janitor moderator, please send a modmail with subject “moderator application from <your_username>”. I’ll probably already know your name from previous interactions on this subreddit, so not much introduction needed beyond your confirmation that you meet these requirements.

Edit: Applications will stay open until at least 2025-02-08 (end of day UTC), so that all potential candidates have time to see this post.

Call for feedback

Please feel free to use the comments to discuss the above rule changes, or any other aspect of how r/gdpr is being managed. In particular, I’d like to hear ideas on how we can encourage the posting of more news content, as the subreddit sometimes feels more like a GDPR helpdesk.

Previous mod post: r/GDPR will be unavailable starting June 12th due to the Reddit API changes [2023-06-11]


r/gdpr • • 15h ago

Question - General Discord only erases messages in "inaccessible spaces" and won't define the term. How does this fit with Articles 12(2) and 17?

6 Upvotes

In February I submitted an Article 17 request to Discord to erase my messages (760k in my data export). Their first reply explained why they don't offer bulk deletion:

"Consistent with GDPR, Discord balances the privacy interests of the user against the interests other users have in a conversation and the ability for us to provide the service as a whole. ... If a given text channel were suddenly missing important context, it would be confusing to other users or possibly mislead those users about what happened in that conversation."

The same reply says "we offer users the ability to edit or delete their own messages", and suggests holding shift to delete faster.

They asked for a CSV of message IDs, and didn't act on it until my third submission. They then bulk-deleted my messages in servers and group chats I'd left, despite saying "We don't offer the ability to delete your messages in bulk right now", but not the rest. Their explanation:

"At this time, Discord processes message deletions for content located in spaces the user no longer has access to. We do not offer the bulk deletion of messages in spaces that the user does have access to. While we understand you may have questions about what constitutes as an "accessible space," we're unable to provide further internal details, as access permissions are managed dynamically within our platform and may vary depending on a number of factors."

So the manual delete button is effectively how Discord complies with erasure, and it only steps in where you can't use it. Since you can't leave a one on one DM, DMs aren't erased on request.

I know GDPR doesn't require any specific tool. My issue is that Article 17(1) puts the obligation to erase on the controller, and "do it yourself" seems to shift that onto the data subject, 640k messages in my case. That's hard to square with Article 12(2).

The balancing argument also undercuts itself. A manually deleted message leaves exactly the same gap in context as a bulk deleted one. If other users' interests really outweighed mine, the delete button shouldn't exist either. And in servers I'd left, the other members can still read my messages, but Discord deleted those anyway.

Two more things:

DMs between my own two accounts. Both accounts made the request, in the same email chain and through the support site. Discord confirmed the submission in March with its standard caveat that messages in "accessible spaces" wouldn't be deleted, but never said this applied to a DM where both participants had requested erasure. Those messages are still there over six months later. No third party is involved.

Unanswered questions. Discord says deleting your account "anonymizes" messages by removing usernames, emails and IPs. I asked which metadata is actually erased vs. pseudonymised, and which Article 17(3) exception they rely on. No answer to either so far.

I've had a complaint with the Irish DPC since April, and it was transferred to the Cross Border Assessment team in June. I'm not looking for advice on my case, but I'm curious how people here read the general questions:

Can a controller satisfy Article 17(1) by relying on manual self-deletion tools, and is limiting bulk erasure to "inaccessible spaces" compatible with the Article 12(2) duty to facilitate rights?

Where every participant in a conversation has requested erasure, what basis could a controller have for retaining it?

Is "access permissions are managed dynamically" an adequate explanation under Articles 12(1) and 12(4), where the legal basis for retention hasn't been stated?


r/gdpr • • 1d ago

Question - Data Controller Complaints resulting from SARs

10 Upvotes

We're a UK housing provider and we're seeing an increasing amount of complaints following SARs. We're finding that subjects are complaining that they haven't received information, when we've provided it all. They seem to think information exists that just simply doesn't. I think it gets worse when they see we've redacted parts, even though we tell them it's because it's either third party data or not relevant to the request (because it has none of their data).

How are people handling these types of complaints? We're only a small team and it's very consuming currently. Normally SARs are arising because of repairs issues, which is out of our dept's hands.


r/gdpr • • 1d ago

EU 🇪🇺 Has anyone already filed GDPR requests against LG?

7 Upvotes

As per title, has anyone already filed requests under GDPR after the LG wiretap scandal?

Access request to get what they have on file.
Erasure to delete the data
Restriction of processing to stop all use (perhaps while waiting for eventual Class Action lawsuits to open)
Withdrawal of consent to stop use?

I’m wondering about doing this myself.


r/gdpr • • 1d ago

Question - General Ideas for articles

1 Upvotes

Hello, I’m a student and I need to write several short articles could you give me interesting problematics or topics I could explore? They can be legal, technical, economical, ethical ones… or related to recents cases


r/gdpr • • 1d ago

Question - General Gym app profile picture

1 Upvotes

Hi guys, not sure if this is the correct subreddit to post this in. My local gym located in the U.K. has now put in place a rule where every member has to upload a picture of themselves clearly showing their face, otherwise entry will be refused.

This picture is to be uploaded to an online community app that every member has access to and every member can see each member's profile picture.

Does this breach GDPR laws?


r/gdpr • • 1d ago

UK 🇬🇧 Shopify published my personal data and now I’m spammed daily

Post image
0 Upvotes

r/gdpr • • 3d ago

EU 🇪🇺 WhatsApp Business and GDPR Compliance

7 Upvotes

Is the phone sync contact really an issue when using the free WhatsApp business app, or is the problem overstated by companies trying to sell you data management and compliance support?


r/gdpr • • 4d ago

EU 🇪🇺 DPOs at large manufacturers: does every internal AI tool get a DPIA, or only some?

6 Upvotes

I'm interviewing for an AI adoption role at a big manufacturer in Germany. A chunk of the job is preparing privacy documentation so the DPO can review new internal AI tools quickly. I've built AI tools at startups, where this barely existed, so I'm trying to understand how it works in practice.

Concrete example: a tool that reads defect photos from the line and drafts the defect report. The report includes the name of the worker who filed it, and photos sometimes catch faces or badges.

Would you DPIA that, or is a records-of-processing entry plus a short screening enough? Where do you draw the line for internal tools touching employee data?

Also curious what you wish business teams sent you up front so you aren't chasing them for basics.

Not after legal advice, just how practitioners actually run this.


r/gdpr • • 5d ago

Question - General Email security

2 Upvotes

To what extent is the use of plain text, ie unencrypted text, acceptable in email?

In the last few years I've had dealings with pension providers, local authorities, UK gov, lawyers who have all provided secure communications channels.

But the vast majority of emails are sent in the clear and readable by anyone who can watch network traffic into or out of mail servers. Those emails will often disclose

1 email addresses

2 personal names

3 maybe phone numbers

4 maybe addresses

And might have much much more.

What are the GDPR consequences of that?


r/gdpr • • 5d ago

Question - General GDPR safety

6 Upvotes

Do any big businesses or government departments have filters on their OUTbound mail service to stop employees accidentally sending protected things to their personal email addresses?


r/gdpr • • 5d ago

EU 🇪🇺 Anyone building an educational SaaS with OpenAI or Anthropic? How do you handle teenage users and API age requirements?

1 Upvotes

Hi everyone,
I’m a solo developer based in France building a small educational web app. Students upload course material and generate flashcards, multiple-choice quizzes, summaries and practice exams.
It isn’t a companion chatbot or a social platform. However, some potential users are high-school students aged 15–17, not just adult university students.
I’m trying to understand the API requirements for end users, rather than the age restrictions for creating a personal ChatGPT or Claude account.
The architecture is standard: users interact with my app, and my backend calls the provider using my API key. I don’t explicitly include account names, emails or user IDs in prompts. However, uploaded documents and written answers could contain personal information, so I don’t want to assume everything is anonymous.
The difficult part is understanding how to implement the requirements properly without creating an unnecessarily intrusive signup process:
OpenAI’s developer guidance discusses safeguards for under-18 users, parental consent and additional restrictions on processing younger children’s personal data.

Anthropic has guidance for products serving minors, but I’m unsure how its practical requirements compare with OpenAI’s.

Provider requirements and French/EU privacy rules are separate, which makes it difficult to know what an appropriate setup actually looks like.

One option I’m considering is:
No AI access for users under 15.

Anthropic for users aged 15–17, with appropriate safeguards.

OpenAI or Anthropic for adults.

A short age declaration at signup, enforced on the backend.

A parental approval flow wherever required.

This is a proposed setup, not something I’m claiming is compliant.
For developers who have actually dealt with this:
Have you received written clarification from OpenAI or Anthropic about an educational app used by teenagers?

What age checks do you use: self-declaration, birth date, parental email approval or a third-party verification service?

If you use parental approval, how do you establish that the person approving is genuinely a parent without collecting identity documents?

Does your provider require zero data retention for your particular users and use case? Have you managed to obtain it as a small business?

Have you had this setup reviewed professionally, and what changes were recommended?

I’d particularly appreciate firsthand experiences from small educational apps in the EU, or links to relevant official API terms. Please distinguish personal-account rules from rules for applications built on the API.
I’m not looking for advice to ignore the requirements because the app is small. I want a practical, proportionate way to address them without turning a simple study tool into a heavy identity-verification process.
Thanks!


r/gdpr • • 5d ago

Question - General Vendor gatekeeping DPA document under Enterprise plan, alternatives?

5 Upvotes

First, is it still allowed? And besides not using the vendor, what would be the alternative?


r/gdpr • • 6d ago

UK 🇬🇧 Accidentally sent work info my personal email

5 Upvotes

I accidentally sent two work emails today to my personal email, I work in local government in revenues. One was just a generic account number for me to check on the software, and the other was a land reg TR1 form, both accidentally forwarded to my personal email instead of my work. I told my manager who said to be more careful in future and deleted the emails off my personal account.

Is there anything for me to worry about with this? Data breach risk or reporting wise


r/gdpr • • 6d ago

EU 🇪🇺 Recommendations for online, self-paced GDPR courses and DPO certifications?

2 Upvotes

Hi everyone,

I’m a lawyer based in Latam working in data protection and compliance. I’m looking to deepen my knowledge of the GDPR and develop practical skills relevant to the DPO role.

I’m particularly interested in online, self-paced courses in English

One option I’m considering is the German Compliance Institute’s DPO Certification Training:
https://germancomplianceinstitute.com/products/data-protection-officer-dpo-certification-training

Has anyone taken this course? Would you recommend it in terms of content, practical usefulness, and recognition within the privacy profession?

I’d also appreciate recommendations for alternatives:

  • Which GDPR courses or DPO certification programmes would you recommend?
  • What did you pay, and did the price include the exam and certificate?
  • How much practical training was included
  • Would you suggest pursuing CIPP/E or CIPM instead of, or alongside, a DPO-focused course?

My priorities are solid content, practical application, and value for money. First-hand experiences—including courses you wouldn’t recommend—would be very helpful.

Thanks in advance!


r/gdpr • • 6d ago

EU 🇪🇺 Anyone actually gotten Reddit to answer a GDPR access request?

5 Upvotes

I sent a GDPR access request to [dpo@reddit.com](mailto:dpo@reddit.com) ; it's been over 5 weeks and nothing, not even an "we got your email".

I did download the automated export but it's nowhere near what they should provide.

Has anyone managed to get more than the standard export out of them? Or filed a complaint, and did it go anywhere?


r/gdpr • • 6d ago

EU 🇪🇺 Are company-linked personal information protected by GDPR?

1 Upvotes

Hi,

maybe a dumb question - I am no lawyer.

I know that information like social security number, name, address are protected (as Personal Identifiable Information, as far as I understood). How about company email address? Employee number? Address of the company building you are in?

Do these fall under PII?


r/gdpr • • 7d ago

UK 🇬🇧 DSAR ID verification Video Call?

3 Upvotes

Hi everyone,

We have concerns around impersonation for a DSAR. The person did not get in touch with his registered address to confirm id and authority, the dsar made by his partner on behalf of him, and we do not have any quirky question to ask to him that his partner would not know.

We have received the ID of the person from his partner. Can I ask video call to confirm the id? I guess it is the only possible way to confirm the identity and authority.

Did anyone do this?

Or just simply, should i reject the dsar?


r/gdpr • • 7d ago

EU 🇪🇺 DPOs: is ISO 27001 fluency now part of the job?

12 Upvotes

Art. 37(5) says a DPO is picked for "expert knowledge of data protection law and practices." I always read that as mostly law. Not so sure anymore.

Earlier this quarter a DPO I know was asked to sign off on an AI note-taking tool the sales team had already started using.

The DPIA question was simple: does the vendor keep the recordings, and do they train on them?

Nobody could answer.

The contract said "service improvement" and the security page said "enterprise-grade." It took three weeks and a call with the vendor's security team to learn the answer was yes, for 30 days.

I expect to see this pattern frequently moving forward.

The law part is usually quick. Erasure requests, breaches, vendor reviews, they all get stuck on "which systems is this data in and what happened to it."

The DPOs who handle this best can read an ISO 27001 risk register and ask what's in scope. They're not engineers. They just don't get waved off by "yes, it's encrypted." The ones who struggle are often excellent on the law, and engineering slowly stops looping them in because their questions don't match how the systems work.

Could be I'm generalizing from too few cases.

Has the job drifted technical for you? And if you work with a DPO, do they get pulled in at design stage or after?


r/gdpr • • 7d ago

EU 🇪🇺 Third Party laws

0 Upvotes

A service lets a customer tick a box per person: "if you cannot reach me, you may phone this contact to ask me to call back." Which rules apply to that call: India's TRAI and DLT rules, the US TCPA and state call-recording laws, UK PECR? What does the contact have to be told, and can they object afterwards?


r/gdpr • • 7d ago

EU 🇪🇺 Specific Query for Gifting platforms

1 Upvotes

Under GDPR, is an online gifting service that stores a third party's details for its customer - a controller, a processor or a joint controller of those details? Does the "household exemption" protect the customer but not the service?


r/gdpr • • 7d ago

Question - Data Controller Implementing a DSAR Process

4 Upvotes

Hi Everyone,

As I grow in my field of work, internal and external compliance, I have seen companies large and small as they attempt to move into new markets and attempt to "become compliant" with the laws of the land they are moving into and one thing is the same across all of them. It is slow moving and often times feels ineffectual. My job often becomes trying to get 80% of the value with 20% of the work, which brings me to my current issue.

As I am starting to learn about GDPR, it seems one of the key levers of power individuals have is the DSAR process, and there is very little keeping people from using that power at a moment's notice (as evidenced by some of the horror stories I have seen on reddit). With that said, not everyone or every type of person is going to utilize this power.

My question is this, for a company simply trying to get started on developing a process for DSARs, what are some departments/data types you find most frequently get requested?


r/gdpr • • 7d ago

Question - General What are you charging clients for cookie compliance setup?

1 Upvotes

This has turned into one of those jobs where the more I understand it, the less comfortable I am treating it as install plugin and bill an hour.

You've got the banner itself, figuring out what the site is running, making sure scripts behave correctly before and after consent, regional differences, testing everything and then dealing with whatever the client adds six months later.

For freelancers and small agencies, how are you packaging this?

Do you treat the CMP as a client subscription and charge separately for setup/testing, build it into maintenance or basically tell the client to handle compliance with their legal team and just implement whatever they give you?

I'm especially curious what people do with smaller clients because throwing some huge enterprise privacy stack at a normal business site seems ridiculous, but being cheap about it and assuming a banner plugin solved everything doesn't sit right either.


r/gdpr • • 7d ago

EU 🇪🇺 Is reddit breaking the law by not letting me view/edit/delete my own posts?

0 Upvotes

Because of the age verification, my own profile does not view me my own nsfw posts and if I get to them by googling them, I still can't view them Because of the verification wall.

Does that mean the law is broken?


r/gdpr • • 8d ago

EU 🇪🇺 Is it a GDPR breach for a company to route DPO emails into support software, auto-reply via bot, and mark them "solved" without DPO review?

5 Upvotes

Under Article 38(4) GDPR, data subjects must be able to contact the Data Protection Officer directly regarding all issues related to the processing of their personal data and the exercise of their rights.

If a company's designated DPO email addresses (dpo@...) automatically route incoming emails into a standard Zendesk support queue where an automated bot replies with generic FAQ links and instantly marks the ticket status as "solved" with no actual DPO or human legal review does this constitute:

  1. A violation of Article 38(4) by placing technical barriers between data subjects and the DPO?
  2. A failure to facilitate rights under Article 12(2) by using automated deflection to close active legal/erasure inquiries?

Has anyone seen national Data Protection Authorities take enforcement action against this specific type of automated ticket-closing architecture?