Privacy in practice
Stories, anecdotes, and asides – always with a lesson to learn
No posts with this tag yet.
The download form asks for an email for the guide. The app asks for location to function. Is that consent — or payment in another currency?
Read more →The boat wasn't just about bad security. It was about no one being responsible for the system.
Read more →Mailchimp shows you who opened your newsletter at 9:14 AM on an iPhone. Have you told your subscribers you can see that?
Read more →Send a request for access to your personal data to yourself – as if you were a customer. Can you respond within 30 days, with everything GDPR requires?
Read more →«Accept terms» is not valid consent — at least not when the alternative is losing access to the service.
Read more →The loyalty card collected points. Your email address was forwarded to a social network – without anyone telling you.
Read more →750,000 of those exposed were not even active members anymore. The association had never deleted them.
Read more →Schibsted wants 39 kroner. Facebook was fined two billion. The question isn't the size of the price – but whether privacy should have a price.
Read more →VG, Aftenposten, and BT are offering you a choice – share your data with advertisers, or pay an extra 39 kroner a month. The Norwegian Data Protection Authority is not impressed.
Read more →Da 2,1 millioner menneskers data ble publisert på Darknet etter SportAdmin-bruddet, var det ikke bare programvareselskapet som hadde et problem. Hvert idrettslag som brukte systemet…
Read more →The online store was hacked through a system no one used anymore. The fine was over ten million kroner.
Read more →The prospecting tool stored contact data for five years—and automatically reset the deadline each time the person changed jobs. In practice, the data was never deleted.
Read more →Your newsletter knows who opens it, when, and on what device. The CNIL says you need consent for that.
Read more →83.5 percent of the insight requests Noyb has sent to companies over the past eight years did not receive a response in line with the law.
Read more →Merely using the app revealed the user's sexual orientation. The Norwegian Data Protection Authority imposed a fine of 65 million. The Court of Appeal agreed.
Read more →The retail chain shared the customer list with a social network. 10.5 million people's emails and phone numbers were used to show them ads. No one was asked.
Read more →To maskerte menn banket på døren midt på natten. De visste navnet hans, adressen og at han hadde skydevåpen hjemme. Opplysningene kom fra et hack…
Read more →The bank app required access to the list of all installed apps on your phone. Garante said: that's too much.
Read more →The sports app was hacked. Data from 2.1 million children — personal identification numbers, health information, club affiliation — ended up on the Darknet.
Read more →160 million contact profiles. Harvested from LinkedIn without asking. Stored for five years. CNIL fined KASPR €240,000.
Read more →22. desember 2025 bøtela det franske datatilsynet CNIL programvareselskapet NEXPUBLICA FRANCE med €1,7 millioner. Selskapet utvikler PCRM — et forvaltningssystem brukt av franske sosialtjenester, blant…
Read more →14. april 2026 vedtok EDPB en felles mal for personvernkonsekvensvurdering — det GDPR kaller en DPIA. Malen er gratis, strukturert med forhåndsdefinerte felt, og følges…
Read more →Den 29. januar 2026 satte det danske Datatilsyn et foreløpig punktum i en sak som startet i 2022. 51 kommuner brukte Google Workspace og Chromebooks…
Read more →DLA Pipers årsundersøkelse, publisert 28. januar 2026, viser at europeiske virksomheter meldte om 443 databrudd per dag i 2025 — den første gangen snittet har…
Read more →De fleste norske virksomheter bruker minst én tjeneste som overfører persondata til USA — Microsoft 365, Google Workspace, Salesforce eller lignende. Den juridiske basisen for…
Read more →Les også: France Travail: 43 millioner rammet fordi ansatte hadde for mye tilgang Da CNIL etterforsket France Travail-bruddet, fant de noe mange virksomheter kjenner igjen…
Read more →I mars 2024 ble France Travail, den franske statlige arbeidsformidlingen, rammet. Angriperne brukte ikke avansert teknologi — de brukte sosial manipulering. De ga seg ut…
Read more →Most privacy policies are written for lawyers. GDPR says they should be written for people. What should actually be in them?
Read more →25 European supervisory authorities are now checking whether your privacy policy gives people what they are entitled to know.
Read more →Reddit hadn't done a single risk assessment before they let children in. It cost £14 million.
Read more →You deleted the customer from the CRM. But the backup system remembers everything. Are you actually in compliance—or just in the production environment?
Read more →32 supervisory authorities checked 764 businesses. Most do not know what they are storing, why, or when they should delete it.
Read more →Older than 90 days
NSM has said the same thing for ten years - weak login is the biggest risk.
Read more →You are switching HR systems. Employee data remains with the old provider. Who is responsible — and who has access?
Read more →The store went bankrupt. The employees wanted their payrolls. The supplier said no. It cost 250,000 kroner.
Read more →The company kept personal data of customers who had left long ago. When the data was stolen, the damage was much greater than it needed to be.
Read more →They didn't have MFA on the VPN. An attacker just logged in. 24 million subscribers had their IBAN data leaked.
Read more →Someone sent the wrong attachment Thursday after lunch. The deadline to report to the Norwegian Data Protection Authority? Sunday. Do you have a plan for the 72 hours?
Read more →Styringssystem for informasjonssikkerhet høres ut som noe bare store selskaper har. Men for en SMB handler det om fire konkrete ting.
Read more →The Norwegian Data Protection Authority is now checking all 357 Norwegian municipalities. What they are looking for, most businesses are also missing.
Read more →3,191 breach notifications to the Norwegian Data Protection Authority in 2024. The most common? Someone sent an email to the wrong person.
Read more →EDPB slår fast — du kan ikke tvinge kunder til å lage konto for å handle. Gjestekasse er ikke en nice-to-have — det er en…
Read more →€325 million. Not for hacking anyone. For showing ads without consent and making it harder to refuse than to accept.
Read more →SHEIN was fined €150 million. Not for collecting too much, but because the reject button didn't actually reject anything.
Read more →