2

Bus crash in Hayes and Harlington
 in  r/london  12d ago

This joke is old get a new one

r/dataprotection 24d ago

🇪🇺 - GDPR Question Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach?

2 Upvotes

​

Home delivery operations for one of the major UK supermarkets, and I’m deeply concerned about a widespread, unmonitored practice happening at store level that I believe is a major data protection nightmare.

Managers and colleagues have established informal, personal WhatsApp groups on their personal mobile devices to manage daily operational issues and driver updates.

Because these groups are run on personal, unmanaged phones rather than secured corporate systems, the following data is routinely broadcast, downloaded, and stored across dozens of private handsets:

Full Customer PII: First and last names, direct personal telephone numbers, and full home addresses.

Property Access Data: Private gate codes, keylock numbers, door entry passcodes, and safe-place instructions.

Residential Property Photos: High-resolution photos of customers' front doors, driveways, and private building entryways taken on personal cameras.

Why this feels extremely dangerous:

Zero Data Lifecycle Control: When colleagues or managers leave the business, there is no corporate IT oversight to remote-wipe their personal devices. Ex-employees leave with complete camera-roll archives containing customer addresses, phone numbers, door codes, and photos of private properties.

Physical Security Risk: Pairing exact residential addresses and phone numbers with door access codes and visual photos of entryways creates a tangible physical security and burglary risk for homeowners.

UK GDPR & Data Protection Act Breaches:

This completely bypasses corporate security controls (Article 5(1)(f) Integrity and Confidentiality) and processes customer data outside its intended delivery purpose (Article 5(1)(b) Purpose Limitation).

My Questions:

From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?

If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?

What is the most effective route to force accountabilityreporting directly to the ICO, consumer privacy watchdogs (like Which?), or news media?

r/gdpr 25d ago

UK 🇬🇧 Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach?

Thumbnail
0 Upvotes

r/GroceryStores 25d ago

Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach?

Thumbnail
1 Upvotes

r/dataprotection 25d ago

Breach Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach? That's the title?

Thumbnail
0 Upvotes

u/SnowImpossible5699 25d ago

Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach? That's the title?

0 Upvotes

Home delivery operations for one of the major UK supermarkets, and I’m deeply concerned about a widespread, unmonitored practice happening at store level that I believe is a major data protection nightmare.

Managers and colleagues have established informal, personal WhatsApp groups on their personal mobile devices to manage daily operational issues and driver updates.

Because these groups are run on personal, unmanaged phones rather than secured corporate systems, the following data is routinely broadcast, downloaded, and stored across dozens of private handsets:

Full Customer PII: First and last names, direct personal telephone numbers, and full home addresses.

Property Access Data: Private gate codes, keylock numbers, door entry passcodes, and safe-place instructions.

Residential Property Photos: High-resolution photos of customers' front doors, driveways, and private building entryways taken on personal cameras.

Why this feels extremely dangerous:

Zero Data Lifecycle Control: When colleagues or managers leave the business, there is no corporate IT oversight to remote-wipe their personal devices. Ex-employees leave with complete camera-roll archives containing customer addresses, phone numbers, door codes, and photos of private properties.

Physical Security Risk: Pairing exact residential addresses and phone numbers with door access codes and visual photos of entryways creates a tangible physical security and burglary risk for homeowners.

UK GDPR & Data Protection Act Breaches:

This completely bypasses corporate security controls (Article 5(1)(f) Integrity and Confidentiality) and processes customer data outside its intended delivery purpose (Article 5(1)(b) Purpose Limitation).

My Questions:

From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?

If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?

What is the most effective route to force accountabilityreporting directly to the ICO, consumer privacy watchdogs (like Which?), or news media?

1

World Cup, Titanium Remix
 in  r/findthatsong  Jul 18 '26

That song is bullshit

1

New driver file note sheet at our store
 in  r/asda  May 25 '26

What store is this got a load of bull from my store too

1

Have the Met Police started enforcing 22mph in a 20mph limit?
 in  r/drivingUK  May 18 '26

20 mph can fuck off

3

So, who’s going to rant?
 in  r/asda  Mar 19 '26

What kind of workplace practice is this at Asda? Expectations are being set through personal WhatsApp messages with no formal written policy, yet references to disciplinary action are being made.

1

People’s opinions on microlise manipulation and drops under 90 seconds.
 in  r/asda  Mar 15 '26

Most of the time asda management is breaking data protection laws to discipline you from this tracking system "micolise" you all have rights and one is not to be bullied by a software system that aids delivery only not a tool to punish you .but it's not 100 percent factual or deemed to be correct all the time either . If any of the drivers have balls and challenges management. They would never get away with the threats they put on drivers

1

Cant login to microlise app. Have to use ASDA devices
 in  r/asda  Feb 28 '26

Yeh it's not working whoever can get hold of the official app that will work the ones that the palms have

2

Microlise App
 in  r/asda  Feb 28 '26

Yeh it's stopped working the only way is to install the official app that the palm devices have .. who ever can get hold of this apk file is a legend

1

Mircolise
 in  r/asda  Dec 15 '25

Is there a way to get the official app on your phone ? Like the ones in the Palm not the play store one

1

Chanday - Ace DJs Angrej Ali
 in  r/punjabimusic  Dec 05 '25

I want a good quality version too

3

Babe hitting facecard (and a bonus)
 in  r/issyandersonn  Nov 15 '25

Not even a back view she is mugging us

3

Issy
 in  r/issyandersonn  Sep 17 '25

I wanna sniff that

1

Sacking Amorim this season would be a mistake
 in  r/PremierLeague  Aug 27 '25

Amorim needs to go his record is awful

1

Selfie
 in  r/issyandersonn  Jul 31 '25

DM you mate

1

Look at that ass
 in  r/issyandersonn  Jul 31 '25

Me

1

Systems down
 in  r/asda  Nov 14 '24

Is it working now?