Tag
A travel agent's AI chatbot violated GDPR regulations without any user prompt, raising concerns about data protection compliance in AI applications.
Analysis of LLM usage in legal and compliance tasks reveals that models often produce confident but unverifiable citations, raising questions about reliable legal grounding for AI outputs.
A privacy advocate's complaint about Elkjop's forced consent for marketing led to a €1.8 million fine after five years, highlighting GDPR violations.
Google's AI strategy is criticized as a surveillance-based profiling engine that forces users into consent through mandatory login, circumventing GDPR. The article exposes Google's plan to replace traditional search with AI-generated answers and personalized tracking, calling it a legal loophole wrapped in AI hype.
The author built a Claude skill for automated PII detection during development, translating existing compliance knowledge into a tool that checks for regulations like CCPA and HIPAA. They plan to release more compliance-focused skills in the near future.
A Dutch suicide prevention hotline was found to share sensitive visitor metadata with Google and Microsoft without proper consent, leading to the suspension of tracking tools and potential GDPR violations.
The author details their personal migration of digital infrastructure to European and Swiss-based services like Proton and Matomo to enhance data sovereignty and privacy.
A researcher discovered that deleteduser.com was being used as a placeholder domain by multiple companies to overwrite user email addresses during data deletion compliance, and after acquiring the domain, received PII from 30+ organizations including gyms, hotels, energy companies, and cybersecurity firms.
OpenAI announces data residency capabilities in Europe for ChatGPT Enterprise, ChatGPT Edu, and API Platform, enabling organizations to store customer data at rest in-region and meet local data sovereignty and GDPR compliance requirements.