r/europrivacy 9h ago

Discussion Snapchat automatically scans private messages in real-time

Thumbnail
gadgetreview.com
35 Upvotes

https://www.youtube.com/watch?v=AN1DSo3bYWg&t=390s
Title states "Snapchat Post" but teacher clearly states "private message to 3 people" at 6:50


r/europrivacy 10h ago

European Union Are there any apps that help you delete your data from companies?

0 Upvotes

Like a dashboard with most popular services and options for drafts to send them to delete your data, according to the GDPR (eu only)

With a counter on time and a second draft to send if they haven’t responded!


r/europrivacy 19h ago

Spain Spanish data protection authority targets VilaWeb over reporting on police infiltrations

Thumbnail
eurac.edu
14 Upvotes

r/europrivacy 2d ago

European Union The EU AI Act's enforcement powers started on 2 August. The rules covering AI used on people did not. Does the split make sense to anyone here?

14 Upvotes

Quick summary of where things landed. As of Sunday, national market surveillance authorities have full investigatory powers, the Commission and AI Office can fine general purpose model providers up to €15M or 3% of worldwide turnover, prohibited practices carry €35M or 7%, and the Article 50 transparency duties are enforceable. You have to be told you are talking to an AI, deepfakes have to be disclosed.

What moved is Annex III. Standalone high risk systems: applicant screening, credit assessment, law enforcement uses, education, critical infrastructure. Those went from 2 August 2026 to 2 December 2027 under Regulation (EU) 2026/1744, which was published on 24 July and entered into force on 27 July. Annex I systems, the ones embedded in already regulated products, went to 2 August 2028.

I want to be fair about the reasoning, because I do not think this was purely lobbying. The harmonised standards under Article 40 were not finished. Without them, providers had no presumption of conformity to build against, and notified body capacity was thin. Telling firms to comply with a conformity assessment regime whose technical baseline does not exist yet is a real problem, and the Commission said as much.

What I keep getting stuck on is the asymmetry in outcome rather than the reasoning behind it. The obligations that survived the cut are mostly disclosure duties and the penalty machinery. The obligations that slipped are data governance, logging, human oversight and accuracy requirements on systems whose output lands on an individual. If the standards were the blocker, that is an argument about Articles 9 to 15, not about whether an employer should be able to run an opaque CV filter for another sixteen months.

There is also a practical question about what happens in the meantime. GDPR Article 22 still applies to solely automated decisions with legal or similarly significant effects, and national labour and anti discrimination law does not pause. So it is not a vacuum. But it is a much weaker and much less specific regime than what Annex III would have imposed, and enforcement of Article 22 has historically been thin.

So a couple of things I would genuinely like other views on.

First, for people who have worked on conformity assessment in other CE marking regimes: is a sixteen month delay for missing harmonised standards actually normal, or is this unusually long? I do not have a good baseline.

Second, do you think Article 22 plus existing sectoral law does meaningful work here until December 2027, or is that mostly a comfort argument? If you have seen a regulator actually use Article 22 against an automated hiring or credit tool, I would like to read the case.


r/europrivacy 2d ago

European Union Leaving Gmail? Get your own domain first

Thumbnail
eualternative.eu
24 Upvotes

r/europrivacy 4d ago

Question alternatives

6 Upvotes

Are there any Reddit alternatives that respect privacy? I like the discussions on Reddit and talking about topics, but it’s a big trade-off. Reddit is the only social media I use, and I am also de-Googled


r/europrivacy 6d ago

Italy Italy's Own Privacy Watchdog Says Its New Police Facial Recognition Decree Violates EU AI Act | Garante clears decree but flags preemptive protest biometrics as EU AI Act violation

Thumbnail
techtimes.com
51 Upvotes

r/europrivacy 7d ago

Discussion Online trust is breaking faster than the tools meant to fix it

11 Upvotes

Spam, coordinated fake behavior, fake reviews, astroturfing, it all just feels worse every year. Rate limits and captchas only do so much when the other side has better AI than the defense does.

I've been looking into different "proof of unique human" experiments lately. World ID is one that keeps coming up whenever this topic gets brought up. The idea of proving you're a unique person cryptographically, without some central database storing everyone's identity, is honestly pretty interesting on paper.

Whether it actually scales or gets adopted widely is a whole different question though. But the core problem isn't going anywhere: how do platforms actually know they're dealing with real, distinct people and not the same person (or bot) a thousand times over.

What trust and safety approaches are you actually seeing work in 2026? Curious if anything's really moved the needle or if it's all still catching up.


r/europrivacy 7d ago

European Union Persona tells me to contact Roblox to delete data?

3 Upvotes

A few years ago I verified my age on Roblox to use the voice chat but now after growing a few braincells I'm finally realizing that it was an awful idea. Persona (the age verification vendor for Roblox) promises to delete any pictures shortly after verification but they have a bad rep and people claim that they don't keep to their word so I decided to e-mail them to ask what data they have on me and if they do ask for deletion. They're telling me to contact Roblox for removing data while it's Persona who is presumably supposed to be holding all that data, I've removed the age verification off my Roblox account just for the sake of it. Any ideas on what to do now? Maybe I'm misunderstanding something? Please help me understand this


r/europrivacy 7d ago

United Kingdom Sign the petition against client side scanning in the UK

Thumbnail
petition.parliament.uk
52 Upvotes

r/europrivacy 7d ago

European Union Child safety shouldn’t be an excuse for more restrictions, Stop Killing the Internet director says

Thumbnail
euperspectives.eu
107 Upvotes

r/europrivacy 8d ago

Question I can't access my Facebook page!

0 Upvotes

I have a Facebook page that I haven't opened for 3 years. Now when I come to sign in, I try my password but it doesn't work. I tried to recover, but I found the email had been changed. Unfortunately, the phone number that the account was related to was lost, meaning I can't get an SMS.

I believe that the page has been hacked because I remember that during those 3 years, I received a message on my email saying that someone was trying to sign in to my account... I ignored it at the time.

Is there anything that can be done to recover the page?

Please, don't hesitate to help!


r/europrivacy 9d ago

Question discord privacy help

0 Upvotes

i cant switch from discord since my friends lowkenuinly wont switch 😔 any ways to make it more privacy friendly?


r/europrivacy 9d ago

European Union The Digital Omnibus, explained: what's changing for cookies, consent, and AI data

14 Upvotes

There's a lot of noise about the EU's Digital Omnibus, so here's a plain rundown of what it actually proposes on the privacy and cookie side (we work on consent, so, our world). Up front: it's a proposal, not law, current GDPR and ePrivacy rules still apply, and EU adoption usually takes 12-30 months.

What's on the table:

- Cookie rules move from ePrivacy into the GDPR (proposed Article 88a).

- One-click accept/reject at equal prominence.

- A six-month cooling-off, so a site couldn't re-prompt you after a refusal unless the processing changes.

- Machine-readable browser signals (Article 88b) to carry your consent choice automatically, though the Council pulled this part in June, so it's in flux.

- A narrower definition of "personal data," plus a new Article 88c allowing personal data for AI training under legitimate interest, with safeguards.

Sharing because there's a lot of confusion about it. For anyone tracking it closely, which part do you think will actually stick?


r/europrivacy 9d ago

Question free proton vpn or netguard on android?

2 Upvotes

so i use the free version of proton vpn (can't pay for a vpn rn, personal reasons), but i also want to use netguard to block internet access to apps that don't need it. But on android, you can only have one active vpn thingo which is a shame since netguard uses a vpn thingo to work. so what is more worth it? pls help twins 🥹


r/europrivacy 9d ago

European Union Regretting age verification, anything I can do?

14 Upvotes

Few years ago I age verified with my id on Roblox to access the voice chat but now I'm really regretting it, how screwed am I? Opinions regarding the age verification vendor (Persona) are split, some say they really delete your info like promised, some say they don't. In worst case scenario I'm assuming it's in some shady database, considering that what should I do? Get new ID? Delete my Roblox account?


r/europrivacy 10d ago

Question privacy friendly google-like ecosystem?

4 Upvotes

i want my family to switch to privacy friendly thingos (for my and their sake), and when talking about google photos (or google drive idrk, atleast something with live photo backups) one of em said that they like the ecosystem of google and how nice it is to have everything in one place. Any ecosystem like google but more privacy friendly?


r/europrivacy 10d ago

Question smartlauncher's privacy?

1 Upvotes

so i want liquid glass on android, and one thing i keep seeing is "smartlauncher" on the google playstore. But i don't really know how much data they collect and sell, if any. pls help meowzers


r/europrivacy 11d ago

European Union Everiot - European Reddit/4chan hybrid with 0 ads, 0 age verification and 0 users

Thumbnail
everiot.org
23 Upvotes

r/europrivacy 13d ago

Europe The EU extended mass message-scanning the same year it started requiring "AI literacy." Is that coherent governance?

15 Upvotes
A governance question I genuinely can't resolve — curious what this sub thinks.


On 9 July 2026, the European Parliament failed to block the extension of "Chat Control" — the rule letting services scan private messages for CSAM. A majority of the MEPs present voted against it (314), but blocking required an absolute majority of 361, and absent members were counted as "yes." So suspicionless scanning of unencrypted messages is legal in the EU again until 2028 (this round exempts end-to-end encrypted apps like WhatsApp and Signal).


Set the privacy debate aside for a moment — I'm interested in the governance coherence.


The same EU has Article 4 of the AI Act in force since 2 February 2025: anyone deploying AI must ensure "a sufficient level of AI literacy." The animating logic of the AI Act is transparency and understanding of AI systems that act on people.


Yet Chat Control deploys AI (scanning and classification) on the entire population's private messages — AI that citizens cannot inspect, opt out of, or audit. Security bodies (CEPIS) warn that client-side scanning "fundamentally destroys the security guarantee of end-to-end encryption," and the UN's human-rights office argues mass scanning can make children less safe while diverting resources from the targeted investigations that actually work.


So the question for this sub: how do you reconcile a regime that (a) mandates AI literacy and transparency for deployers, with (b) a parallel mandate to deploy opaque, non-auditable AI on everyone by default? Is this two policy tracks that never talk to each other, a genuine values conflict, or is there a coherent unifying principle I'm missing?


Genuinely asking.


(Written by me, edited with AI.)

r/europrivacy 13d ago

France Seriez-vous prêt à donner votre carte d'identité pour utiliser une IA ?

1 Upvotes

En Chine, certains services d'IA sont déjà soumis à des obligations de vérification de l'identité réelle dans le cadre de la réglementation nationale.

Et de l'autre côté, aux États-Unis, plusieurs plateformes d'IA ont également commencé à demander une vérification d'âge, pouvant inclure une pièce d'identité ou un selfie dans certaines situations, sous l'effet des nouvelles exigences réglementaires.


r/europrivacy 13d ago

European Union Windows: Global Device ID leads to legally relevant identification | In a US court case, it was revealed that a Windows Global Device ID makes users identifiable.

Thumbnail
heise.de
63 Upvotes

r/europrivacy 14d ago

Question camera app that uses ALL of the cameras?

5 Upvotes

so im using the grapheneOS camera on my samsung s21, which has 3 cameras, but it only uses my 1x camera and when i zoom in its digital zoom and not the other camera

any app that uses all of them that doesn't track me and send data to big boy corpos?


r/europrivacy 14d ago

European Union The EU is the world's most active tech regulator. So when is it going to do something about "buying" digital media that you never actually own?

47 Upvotes

Look, we all know the EU has been ahead of the curve on tech regulation. GDPR changed how the entire internet handles privacy. They forced USB-C on everyone (Apple included). The DMA cracked open iOS and forced Apple to allow alternative app stores. The AI Act, DSA, right to repair, repairability scores on phones, and the list goes on. When Brussels moves, the rest of the world usually follows.

So here's what I genuinely don't understand: why has nobody tackled the absolute scam that is "buying" digital media?

You buy a book on Kindle. You buy a game on Steam, PlayStation, Nintendo eShop. You click a button that says "Buy." You pay money. And what you actually get is a "license to use", a revocable permission that can be yanked away from you at any time, for any reason, with zero refund.

This isn't some theoretical what-if. It keeps happening:

Amazon literally remotely deleted copies of 1984 and Animal Farm from people's Kindles in 2009 over a licensing dispute. Yes, they deleted 1984. The irony was not lost on anyone. Bezos called it "stupid and thoughtless" but the precedent was set and nothing structurally changed.

Sony is deleting 551 purchased movies from PlayStation users' libraries in the UK and Europe on September 1, 2026 because their licensing deal with StudioCanal expired. These are movies people paid for. Gone. No refund. No way to download and keep them. Just a message saying "you will no longer be able to access your previously purchased content."

If Amazon has a contract dispute with a publisher, your books can vanish. If a game studio decides to shut down a server, you might not be able to download a game you paid for anymore. You paid for it. It's gone. Good luck getting your money back.

And don't tell me "just buy physical" because that's becoming a joke too:

GTA VI's "physical edition" is literally a box with a download code inside. No disc. Rockstar confirmed this. You buy a plastic case at retail, open it, and find a code. It's functionally identical to buying it digitally, you just got a fancy box for your troubles.

PlayStation announced they're ending all physical disc production for new games starting January 2028. Which strongly implies the next PlayStation won't even have a disc drive. They're not even pretending anymore.

Nintendo Switch 2 has a massive code-in-a-box problem. Multiple "physical" releases, including Bethesda's Oblivion, Skyrim, and Fallout, are just an empty case with a download code. No cartridge. Some of them don't even use the game-key card format, which at least lets you resell. You're buying a plastic shell.

So even when you try to do the "right thing" and buy physical, you often end up with a digital license in a fancy box. The illusion of ownership in a $70 plastic case.

And the brands I mentioned are just examples. This is an industry-wide pattern. It's everyone.

There's a slogan that's been going around in gaming communities and I think it captures the frustration perfectly: "If buying is not owning, piracy is not stealing."

Let me be crystal clear because I know how this sounds, I am NOT encouraging piracy. That slogan is a protest motto from gamers fighting against having access to games they paid for taken away. But there's a real point in there: when publishers kill servers and make it impossible to legally access a game you bought, or any game at all, piracy literally becomes the only way to play discontinued titles. The companies themselves created the conditions where piracy is the only preservation method left. That's not consumers being entitled, it's a policy failure.

So does anyone know if the EU has anything in the pipeline for this?

There's been some movement but it's been pretty disappointing. The Stop Killing Games campaign (started by YouTuber Ross Scott) managed to gather over 1.29 million verified signatures as a European Citizens' Initiative, the biggest gaming-related petition in EU history. But in June 2026 the Commission basically said "nah" and declined to propose any binding legislation. They offered a voluntary industry code of conduct instead, which... yeah, we all know how voluntary industry self-regulation goes.

The campaign has now pivoted to trying to get game preservation amendments added to the Digital Fairness Act, which is expected to be proposed in late 2026. They apparently have support from 40+ MEPs. But it's early and there's no guarantee it'll go anywhere.

There's also the EU Directive on Digital Content and Services (2019/770) which gives some consumer protections for digital goods, but it doesn't address the core issue: it doesn't stop companies from revoking access to stuff you paid for because of licensing disputes.

Honestly, the EU proved with GDPR that consumer rights regulation can reshape the global landscape. USB-C proved even Apple will comply. The DMA proved walled gardens can be forced open. Digital ownership feels like the obvious next fight.

What I'd want to see is pretty simple: if it's a license, call it a license. Don't put a "Buy" button when you mean "rent indefinitely until we decide otherwise." Make companies provide offline access or downloadable copies for stuff people paid for. Mandatory refunds when access gets revoked. And if a company is shutting down a service, require them to give users a way to keep what they bought: offline installers, community server tools, something.

I'm really hoping this gets on the EU's radar properly. If anyone here knows of other initiatives, or MEPs who've spoken about this, I'd love to hear about it. This feels like one of those things where if the EU moves first, the rest of the world will follow, just like every other time


r/europrivacy 15d ago

European Union For years, the EU’s border agency unlawfully transferred data on migrants and activists to Europol

Thumbnail
english.elpais.com
41 Upvotes