Privacy in practice

Privacy in practice

The question isn't whether the data exists. The question is whether you get it back.

Sorter Latest / Elder

No posts in this category yet.

5 May 2026
Article 6, 7
Do you give your customers a real choice?

The download form asks for an email for the guide. The app requests location to function. Is that consent — or payment in...

Read more →
5 May 2026
Article 5(1)(f), 5(2), 32
Who owns the system no one is using?

The boat wasn't just about bad security. It was about no one being responsible for the system.

Read more →
4 May 2026
ePrivacy, Articles 12-14
What does your newsletter tool know about your subscribers?

Mailchimp shows you who opened your newsletter at 9:14 AM on an iPhone. Have you told your subscribers that you see…

Read more →
2 May 2026
Article 15, paragraph 12
What do you do when someone requests access?

Send a request for insights to yourselves — as if you were a customer. Can you respond within 30 days, with…

Read more →
2 May 2026
Article 6, 7
«Accept terms» is not consent

«Accept terms» is not valid consent — at least not when the alternative is losing access to the service.

Read more →
2 May 2026
Article 6, 14
The loyalty card was used to track you on social media

The loyalty card collected points. Your email address was forwarded to a social network – without anyone telling you.

Read more →
2 May 2026
Paragraph 5, Article 17
750,000 weren't even members anymore

750,000 of those exposed were not even active members anymore. The association had never deleted them.

Read more →
1 May 2026
Article 6, 7
When privacy becomes a subscription

Schibsted wants 39 kroner. Facebook was fined two billion. The question is not the size of the price — but whether...

Read more →
30 April 2026
Article 6, 7
Schibsted charges for privacy — The Data Protection Authority reacts

VG, Aftenposten, and BT give you a choice—share your data with advertisers, or pay an extra 39 kroner per month…

Read more →
29 April 2026
Article 28, 32
The sports team chose the system. The responsibility is theirs.

When data from 2.1 million people was published on the Darknet following the SportAdmin breach, it wasn't just the software company that had a problem. Every sports team using the system was also affected.

Read more →
29 April 2026
Article 5(1)(f), 32, 33, 34
Old system went online — no one noticed

The online store was hacked through a system no one used anymore. The fine was over ten million kroner.

Read more →
29 April 2026
Paragraph 5, Article 17
How long does your prospecting tool retain contact data?

The prospecting tool stored contact data for five years—and automatically reset the deadline each time the person changed jobs. In practice, the data was never deleted.

Read more →
28 April 2026
ePrivacy, art. 5
Your newsletter tracks who opens it — now CNIL requires consent

Your newsletter knows who opens it, when, and on what device. The CNIL says you need consent for that.

Read more →
27 April 2026
Article 15, paragraph 12
83 percent do not answer correctly when asked for access

83.5 percent of the transparency requests that noyb has sent to companies over the last eight years did not receive a response in line with...

Read more →
27 April 2026
article 6, 9
The app shared that you were the user. That was enough.

Merely using the app revealed the user's sexual orientation. The Norwegian Data Protection Authority imposed a fine of 65 million. The Court of Appeal agreed.

Read more →
27 April 2026
Article 6, paragraph 13
10.5 million customers' data - used for ads no one asked for

The retail chain shared its customer list with a social network. 10.5 million people's emails and phone numbers—used to show them ads…

Read more →
27 April 2026
article 32, paragraph 5
The hackers used the membership list as a shopping list

Two masked men knocked on the door in the middle of the night. They knew his name, his address, and that he had firearms at home.

Read more →
24 April 2026
Article 5
The bank app knew everything you had installed — €12.5M bot

The bank app required access to the list of all installed apps on your phone. Garante said: that's too much.

Read more →
23 April 2026
Art. 32
Sports app was hacked — children's data on the Darknet

The sports app was hacked. Data from 2.1 million children — personal identification numbers, health information, club affiliation — ended up on the Darknet.

Read more →
23 April 2026
article 6, 14, 5
Sales tool scraped contacts from LinkedIn without permission — €240,000

160 million contact profiles. Harvested from LinkedIn without asking. Stored for five years. CNIL fined KASPR €240,000.

Read more →
17 April 2026
Article 32, paragraph 28
The supplier knew about the security flaw — and did nothing

The vendor had carried out a security audit. The errors were documented. None were fixed. When the breach occurred, data about disabled individuals was leaked. The fine was €1.7 million.

Read more →
16 April 2026
Article 35
The EDPB created a free DPIA template — do you know if you need one?

Most businesses know they should consider risks before adopting new systems. Few know what the assessment should entail. Now the EDPB has created the template – for free.

Read more →
16 April 2026
art. 28, 44
Chromebook case: you are responsible for what the vendor's vendor does

51 municipalities used Google in schools. The Danish Data Inspection Agency found that they didn't know who was actually processing the data — and stated that it was the municipalities' fault, not Google's.

Read more →
16 April 2026
art. 33
443 fractures per day in Europe - do you have a plan for when it happens to you?

In 2025, 443 data breaches were reported per day in Europe — up 22 percent from the previous year. Most of the businesses affected did not have a plan.

Read more →
15 April 2026
Article 44, 46
The agreement that makes your cloud services legal — is under pressure again

Almost all cloud usage in Norwegian businesses is based on one agreement between the EU and the US. That agreement is under pressure — again.

Read more →
14 April 2026
Article 5, Paragraph 32
Who in your company is looking more than they should?

When the CNIL investigated the France Travail breach, one of the findings was this: access rights were defined too broadly. It's not sabotage. That's how the system was set up.

Read more →
10 April 2026
article 32, paragraph 5
France Travail: 43 million affected because employees had too much access

France Travail was not hacked. The attacker only asked for help. When he was inside, he had access to data on 43 million people.

Read more →
23 March 2026
article 13, 14
What should actually be in a privacy policy?

Most privacy policies are written for lawyers. GDPR says they should be written for people. What should actually be in them?

Read more →
19 March 2026
art. 12-14
25 supervisory authorities are checking your privacy policy

25 European supervisory authorities are now checking whether your privacy policy gives people what they are entitled to know.

Read more →
24 February 2026
Article 35, paragraph 25
Reddit — no DPIA, £14M bot

Reddit hadn't done a single risk assessment before they let children in. It cost £14 million.

Read more →
22 February 2026
Article 17, paragraph 5
What do you do with data in the backup system?

You deleted the customer from the CRM. But the backup system remembers everything. Are you actually in compliance—or just in the production environment?

Read more →
18 February 2026
Article 17, paragraph 5, item 30.
Most people don't know what they have stored — or when to delete it

32 supervisory authorities checked 764 businesses. Most do not know what they are storing, why, or when they should delete it.

Read more →

Older than 90 days

6 February 2026
Art. 32
NSM Risk 2026 — Every Authentication Again and Again

NSM has said the same thing for ten years - weak login is the biggest risk.

Read more →
24 January 2026
Article 28, paragraph 15
What happens to the data when you switch systems?

You are switching HR systems. Employee data remains with the old provider. Who is responsible — and who has access?

Read more →
20 January 2026
Article 15
The store went bankrupt — the supplier kept the data

The store went bankrupt. The employees wanted their payrolls. The supplier said no. It cost 250,000 kroner.

Read more →
17 January 2026
Article 5, Paragraph 32
Are you storing data about past customers longer than necessary?

The company kept personal data of customers who had left long ago. When the data was stolen, the damage was much greater than it needed to be.

Read more →
13 January 2026
Articles 32-34
MFA missing - 24 million subscribers leaked, €42M fine

They didn't have MFA on the VPN. An attacker just logged in. 24 million subscribers had their IBAN data leaked.

Read more →
5 January 2026
art. 33
72 hours - that's all you have

Someone sent the wrong attachment Thursday after lunch. The deadline to report to the Norwegian Data Protection Authority? Sunday. Do you have a plan for the 72 hours?

Read more →
5 January 2026
Art. 32
What exactly is an information security management system?

«Information security management system» sounds like something only big companies have. But for an SMB, it's about four concrete things.

Read more →
1 January 2026
Art. 32
The Data Inspectorate is checking all 357 Norwegian municipalities

The Norwegian Data Protection Authority is now checking all 357 Norwegian municipalities. What they are looking for, most businesses are also missing.

Read more →
1 January 2026
Article 33, paragraph 5
3,191 unanswered messages—is that common? Email to the wrong person

3,191 breach notifications to the Norwegian Data Protection Authority in 2024. The most common? Someone sent an email to the wrong person.

Read more →
4 December 2025
Article 6, Paragraph 5
You cannot force customers to create an account to shop.

EDPB rules - you cannot force customers to create an account to shop. Guest checkout is not a nice-to-have - it's a right.

Read more →
1 September 2025
ePrivacy
Google €325M — ads in Gmail without consent

€325 million. Not for hacking anyone. For showing ads without consent and making it harder to refuse than to accept.

Read more →
1 September 2025
ePrivacy
SHEIN: The "no" button rejected nothing — €150M

SHEIN was fined €150 million. Not for collecting too much, but because the reject button didn't actually reject anything.

Read more →

Newsletter

Stay updated

Sign up and get the latest articles, GDPR insights, and useful privacy perspectives.