Privacy in practice

From the GDPR world – with a sideways glance

Stories, anecdotes, and asides – always with a lesson to learn

No posts with this tag yet.

5 May 2026
Do you give your customers a real choice?

The download form asks for an email for the guide. The app asks for location to function. Is that consent — or payment in another currency?

Read more →
5 May 2026
Who owns the system no one is using?

The boat wasn't just about bad security. It was about no one being responsible for the system.

Read more →
4 May 2026
What does your newsletter tool know about your subscribers?

Mailchimp shows you who opened your newsletter at 9:14 AM on an iPhone. Have you told your subscribers you can see that?

Read more →
2 May 2026
What do you do when someone requests access?

Send a request for access to your personal data to yourself – as if you were a customer. Can you respond within 30 days, with everything GDPR requires?

Read more →
2 May 2026
«Accept terms» is not consent

«Accept terms» is not valid consent — at least not when the alternative is losing access to the service.

Read more →
2 May 2026
The loyalty card was used to track you on social media

The loyalty card collected points. Your email address was forwarded to a social network – without anyone telling you.

Read more →
2 May 2026
750,000 weren't even members anymore

750,000 of those exposed were not even active members anymore. The association had never deleted them.

Read more →
1 May 2026
When privacy becomes a subscription

Schibsted wants 39 kroner. Facebook was fined two billion. The question isn't the size of the price – but whether privacy should have a price.

Read more →
30 April 2026
Schibsted charges for privacy — The Data Protection Authority reacts

VG, Aftenposten, and BT are offering you a choice – share your data with advertisers, or pay an extra 39 kroner a month. The Norwegian Data Protection Authority is not impressed.

Read more →
29 April 2026
The sports team chose the system. The responsibility is theirs.

Da 2,1 millioner menneskers data ble publisert på Darknet etter SportAdmin-bruddet, var det ikke bare programvareselskapet som hadde et problem. Hvert idrettslag som brukte systemet…

Read more →
29 April 2026
Old system went online — no one noticed

The online store was hacked through a system no one used anymore. The fine was over ten million kroner.

Read more →
29 April 2026
How long does your prospecting tool retain contact data?

The prospecting tool stored contact data for five years—and automatically reset the deadline each time the person changed jobs. In practice, the data was never deleted.

Read more →
28 April 2026
Your newsletter tracks who opens it — now CNIL requires consent

Your newsletter knows who opens it, when, and on what device. The CNIL says you need consent for that.

Read more →
27 April 2026
83 percent do not answer correctly when asked for access

83.5 percent of the insight requests Noyb has sent to companies over the past eight years did not receive a response in line with the law.

Read more →
27 April 2026
The app shared that you were the user. That was enough.

Merely using the app revealed the user's sexual orientation. The Norwegian Data Protection Authority imposed a fine of 65 million. The Court of Appeal agreed.

Read more →
27 April 2026
10.5 million customers' data - used for ads no one asked for

The retail chain shared the customer list with a social network. 10.5 million people's emails and phone numbers were used to show them ads. No one was asked.

Read more →
27 April 2026
The hackers used the membership list as a shopping list

To maskerte menn banket på døren midt på natten. De visste navnet hans, adressen og at han hadde skydevåpen hjemme. Opplysningene kom fra et hack…

Read more →
24 April 2026
The bank app knew everything you had installed — €12.5M bot

The bank app required access to the list of all installed apps on your phone. Garante said: that's too much.

Read more →
23 April 2026
Sports app was hacked — children's data on the Darknet

The sports app was hacked. Data from 2.1 million children — personal identification numbers, health information, club affiliation — ended up on the Darknet.

Read more →
23 April 2026
Sales tool scraped contacts from LinkedIn without permission — €240,000

160 million contact profiles. Harvested from LinkedIn without asking. Stored for five years. CNIL fined KASPR €240,000.

Read more →
17 April 2026
The supplier knew about the security flaw — and did nothing

22. desember 2025 bøtela det franske datatilsynet CNIL programvareselskapet NEXPUBLICA FRANCE med €1,7 millioner. Selskapet utvikler PCRM — et forvaltningssystem brukt av franske sosialtjenester, blant…

Read more →
16 April 2026
The EDPB created a free DPIA template — do you know if you need one?

14. april 2026 vedtok EDPB en felles mal for personvernkonsekvensvurdering — det GDPR kaller en DPIA. Malen er gratis, strukturert med forhåndsdefinerte felt, og følges…

Read more →
16 April 2026
Chromebook case: you are responsible for what the vendor's vendor does

Den 29. januar 2026 satte det danske Datatilsyn et foreløpig punktum i en sak som startet i 2022. 51 kommuner brukte Google Workspace og Chromebooks…

Read more →
16 April 2026
443 fractures per day in Europe - do you have a plan for when it happens to you?

DLA Pipers årsundersøkelse, publisert 28. januar 2026, viser at europeiske virksomheter meldte om 443 databrudd per dag i 2025 — den første gangen snittet har…

Read more →
15 April 2026
The agreement that makes your cloud services legal — is under pressure again

De fleste norske virksomheter bruker minst én tjeneste som overfører persondata til USA — Microsoft 365, Google Workspace, Salesforce eller lignende. Den juridiske basisen for…

Read more →
14 April 2026
Who in your company is looking more than they should?

Les også: France Travail: 43 millioner rammet fordi ansatte hadde for mye tilgang Da CNIL etterforsket France Travail-bruddet, fant de noe mange virksomheter kjenner igjen…

Read more →
10 April 2026
France Travail: 43 million affected because employees had too much access

I mars 2024 ble France Travail, den franske statlige arbeidsformidlingen, rammet. Angriperne brukte ikke avansert teknologi — de brukte sosial manipulering. De ga seg ut…

Read more →
23 March 2026
What should actually be in a privacy policy?

Most privacy policies are written for lawyers. GDPR says they should be written for people. What should actually be in them?

Read more →
19 March 2026
25 supervisory authorities are checking your privacy policy

25 European supervisory authorities are now checking whether your privacy policy gives people what they are entitled to know.

Read more →
24 February 2026
Reddit — no DPIA, £14M bot

Reddit hadn't done a single risk assessment before they let children in. It cost £14 million.

Read more →
22 February 2026
What do you do with data in the backup system?

You deleted the customer from the CRM. But the backup system remembers everything. Are you actually in compliance—or just in the production environment?

Read more →
18 February 2026
Most people don't know what they have stored — or when to delete it

32 supervisory authorities checked 764 businesses. Most do not know what they are storing, why, or when they should delete it.

Read more →

Older than 90 days

6 February 2026
NSM Risk 2026 — Every Authentication Again and Again

NSM has said the same thing for ten years - weak login is the biggest risk.

Read more →
24 January 2026
What happens to the data when you switch systems?

You are switching HR systems. Employee data remains with the old provider. Who is responsible — and who has access?

Read more →
20 January 2026
The store went bankrupt — the supplier kept the data

The store went bankrupt. The employees wanted their payrolls. The supplier said no. It cost 250,000 kroner.

Read more →
17 January 2026
Are you storing data about past customers longer than necessary?

The company kept personal data of customers who had left long ago. When the data was stolen, the damage was much greater than it needed to be.

Read more →
13 January 2026
MFA missing - 24 million subscribers leaked, €42M fine

They didn't have MFA on the VPN. An attacker just logged in. 24 million subscribers had their IBAN data leaked.

Read more →
5 January 2026
72 hours - that's all you have

Someone sent the wrong attachment Thursday after lunch. The deadline to report to the Norwegian Data Protection Authority? Sunday. Do you have a plan for the 72 hours?

Read more →
5 January 2026
What exactly is an information security management system?

Styringssystem for informasjonssikkerhet høres ut som noe bare store selskaper har. Men for en SMB handler det om fire konkrete ting.

Read more →
1 January 2026
The Data Inspectorate is checking all 357 Norwegian municipalities

The Norwegian Data Protection Authority is now checking all 357 Norwegian municipalities. What they are looking for, most businesses are also missing.

Read more →
1 January 2026
3,191 unanswered messages—is that common? Email to the wrong person

3,191 breach notifications to the Norwegian Data Protection Authority in 2024. The most common? Someone sent an email to the wrong person.

Read more →
4 December 2025
You cannot force customers to create an account to shop.

EDPB slår fast — du kan ikke tvinge kunder til å lage konto for å handle. Gjestekasse er ikke en nice-to-have — det er en…

Read more →
1 September 2025
Google €325M — ads in Gmail without consent

€325 million. Not for hacking anyone. For showing ads without consent and making it harder to refuse than to accept.

Read more →
1 September 2025
SHEIN: The "no" button rejected nothing — €150M

SHEIN was fined €150 million. Not for collecting too much, but because the reject button didn't actually reject anything.

Read more →

Newsletter

Stay updated

Sign up and get the latest articles, GDPR insights, and useful privacy perspectives.