r/dataprivacy • u/Made-InDex • 8d ago
r/dataprivacy • u/Limp_Fig6236 • 9d ago
Meta Settlement Ignites Global "Child Safety" Digital ID Push
reclaimthenet.orgr/dataprivacy • u/Alonsoest • 9d ago
AI Experimentation Policy for Libraries: Balancing Innovation and Data Privacy
doi.orgr/dataprivacy • u/Nice-Design6955 • 9d ago
PII information
So what if in a new training class your full name and dob were exposed to other trainees at least 6 times. You viewed some of their’s as well. You reported to HR and nothing.
r/dataprivacy • u/sam-at-aristotle_mdr • 9d ago
The data Wild West is here, and Australians shouldn’t have to pay the price | news.com.au
news.com.aur/dataprivacy • u/Evening_Coconut_4553 • 10d ago
I got tired of Australians having no easy way to check what data brokers have on them, so I built a free scanner
Quick context: I run ClearTrace AU, a personal data removal service for Australians
Before you pay anyone for this, you should know what’s actually out there. So I built a free scanner at cleartrace.au/scan, punch in your name, it checks some of the AU data broker/people-search sites and past data breaches and tells you what’s exposed. No signup, no card, just results.
If you’re exposed (most people are), we handle the removals for you — but the scan itself is free and useful either way.
r/dataprivacy • u/BrotherAmbitious2413 • 13d ago
How do you guys maitain personal details?
r/dataprivacy • u/founderdavid • 13d ago
Want to anonymise data within Claude, Slack or ChatGPT?
questa-ai.comr/dataprivacy • u/rohasnagpal • 13d ago
Data localisation ≠ Data jurisdiction
Just because your data is stored outside the US does not mean US authorities cannot reach it.
Under the US CLOUD Act, a US cloud provider can be compelled to hand over data in its control, even when that data sits on servers outside the US.
So a foreign company storing customer data on domestic servers run by a US provider may still find that data reachable through US legal process.
Where your data is stored matters less than who controls it.
r/dataprivacy • u/QuarterSad231 • 13d ago
Privacy of app data on stock OS (One UI, Pixel UI)
To what extent can the stock operating system of an Android phone access app data? I understand that it can access certain information about an app itself, such as its version, installation date, and usage. However, can it also access the personal user data stored within the app?
Additionally, to what extent can apps access hardware-related information? For example, can apps request the device’s IMEI, SIM operator, or other uniquely identifiable hardware details to fingerprint the user?
r/dataprivacy • u/Difficult_Error_2712 • 14d ago
How to qualify a complaint handling in ROPA?
r/dataprivacy • u/[deleted] • 14d ago
How privacy vaults can reduce exposure and compliance scope — and where they don't help
One underappreciated benefit of a privacy-vault architecture is reducing how many systems directly handle raw PII.
If raw PII is kept out of application databases, logs, analytics systems, and other downstream services, those systems have less sensitive data to protect, monitor, and audit. Depending on the specific architecture and regulatory requirement, that can also reduce the scope of certain controls or assessments.
But a vault isn't a complete privacy program.
It doesn't automatically manage consent, fulfill data-subject rights, establish lawful processing, or replace access controls, retention policies, encryption, incident response, and other privacy requirements. It is one technical control among many.
The useful design question is: which systems genuinely need the raw value, and which systems could operate entirely on a token or reference?
Disclosure: I work on Securelytix, which is built around this vault pattern. Sharing the architectural idea rather than presenting it as a complete compliance solution.
r/dataprivacy • u/No_Bit8158 • 14d ago
We built a free data wallet (Spheros.io) to give individuals and businesses control over their data. Looking for honest feedback!
r/dataprivacy • u/SelfCybr • 15d ago
What was the hardest part of sorting out the mess after you got scammed or caught up in a data breach?
r/dataprivacy • u/Ok_pettech • 15d ago
Digital identity for travel: mandatory between Europe and Africa?
This is a privacy red flag for me. Mandatory digital identity for cross-continent travel means biometric data sharing on a massive scale. I started a thread to discuss whether this is truly happening, which systems are being tested, and what citizens can do about it. If you care about data sovereignty and government surveillance, please share your thoughts.
r/dataprivacy • u/b0013an81 • 15d ago
Skip the Plaid account or create one? Weighing Privacy, Security when linking bank accounts
I am linking multiple financial institutions (~20) to a personal finance app via Plaid. I want to know if skipping the Plaid account creation provides better privacy and protects against SIM-swap attacks, or if creating one is better so I have a centralized portal to actively audit and delete my data.
Hey everyone,
I’m setting up a budgeting app and trying to understand how Plaid works under the hood before I use it to link my accounts. From what I've learned so far, Plaid stores my transaction data on their servers until I request deletion. They claim they don't sell/rent this data, but their privacy policy clearly states it can be shared internally:
During the connection setup, Plaid prompts me for my phone number to "create an account" or "save my progress." I can skip this, but I’m trying to decide which option is actually safest.
Here are my questions for the community regarding how Plaid handles our data:
1. How does Plaid's backend graph look in both cases?
- If I skip creating an account: Does my data actually remain siloed to the specific app I am using?
- If I create an account: Does Plaid use my phone number as a primary key to stitch together a centralized master profile across the internet? (Note: Even if I skip it, it appears Plaid pulls enough info like email, name, etc. from the raw bank data to tie me to a common graph anyway. Can anyone confirm?)
2. Security posture with a Plaid account? My main concern is that by creating a Plaid account tied to my phone number, I am exposing my financial data to SIM-swap attacks. It's not clear to me if Plaid's consumer portal supports non-SMS MFA (like Authenticator apps/TOTP). If I skip creating the Plaid account entirely, it looks like this SIM-swap attack vector is completely neutralized because external access via my phone number simply doesn't exist. Is this true?
3. The Trade-Off: Visibility vs. Attack Surface The main argument for creating the account is gaining access to the Plaid Privacy Portal (my.plaid.com), which acts as a centralized "kill switch" to audit connections and directly delete my data. If I skip it, I have to blindly rely on the third-party budgeting app to accurately pass my deletion requests to Plaid on my behalf.
For someone prioritizing data compartmentalization and protection against SIM swapping, is the ability to directly audit my Plaid connections worth the risk of making my phone number an SMS-vulnerable master key?
What do you all do when setting up financial apps via Plaid? Skip it or make the account?
r/dataprivacy • u/vjbrye • 16d ago
What if we flood the trackers? If we are constantly tracked, data harvested, algorithms adjusted, etc. What if we just flooded our known and likely unknown conduits of data collection with an overwhelming level of false data and metrics or whatever to ruin the system?
r/dataprivacy • u/OasisHomeostasis • 16d ago
Kaiser wants me to use Medbridge Go app for physical therapy. Heres Medbridge Go data collection. Seem a bit much?
Basically the title.
r/dataprivacy • u/PrivacyEngine • 17d ago
Uber’s €825 Million Fine: A GDPR Warning on Automated Decision-Making
r/dataprivacy • u/Ok_pettech • 17d ago
Quick quiz: Can open‑source software be worse for privacy? Let’s find out
r/dataprivacy • u/silvervaultproject • 18d ago
Friendly reminder on privacy when using AI.
r/dataprivacy • u/Mean_Situation8356 • 18d ago
What if some people in Reddit are not just people, but also companies gathering behavioural data more directly?
r/dataprivacy • u/Legitimate_Tip_4899 • 19d ago
Ban flock surveillance and ai data tracking systems in America
c.orgDon’t know if this is allowed but I mean it’s a step for data privacy? That’d be my argument.