<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Journal on GDPR Audit — Technical Audit of Personal Data Processing</title><link>https://gdpru.eu/en/journal/</link><description>Recent content in Journal on GDPR Audit — Technical Audit of Personal Data Processing</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 20 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://gdpru.eu/en/journal/index.xml" rel="self" type="application/rss+xml"/><item><title>Eight Microseconds. How the Speed of Data Transmission Affects the Price You Pay for Everything</title><link>https://gdpru.eu/en/journal/eight-microseconds.-how-the-speed-of-data-transmission-affects-the-price-you-pay-for-everything/</link><pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/eight-microseconds.-how-the-speed-of-data-transmission-affects-the-price-you-pay-for-everything/</guid><description>&lt;h2 id="a-300-million-cable-for-eight-milliseconds"&gt;A $300 Million Cable. For Eight Milliseconds.&lt;/h2&gt;
&lt;ol start="2009"&gt;
&lt;li&gt;The company Spread Networks begins construction.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The task — lay a fiber-optic cable from Chicago to New Jersey. A distance of roughly 1,300 kilometers. The cable has to be as straight as physically possible, given the terrain, rivers, and private property. In some places, crews drill through mountains. In others, they buy right-of-way from landowners. Elsewhere, they negotiate with city governments.&lt;/p&gt;
&lt;p&gt;The project&amp;rsquo;s budget — $300 million.&lt;/p&gt;</description></item><item><title>Dating Apps. The Most Intimate Data in the Least Trustworthy Hands</title><link>https://gdpru.eu/en/journal/dating-apps.-the-most-intimate-data-in-the-least-trustworthy-hands/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/dating-apps.-the-most-intimate-data-in-the-least-trustworthy-hands/</guid><description>&lt;h2 id="what-you-hand-over-when-youre-looking-for-love"&gt;What you hand over when you&amp;rsquo;re looking for love&lt;/h2&gt;
&lt;p&gt;Journalist Judith Duportail decided to check what Tinder knew about her. She filed a data-access request under European law. A few weeks later, she got a response.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;800 pages.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Everything was in there. Every click. Every swipe left and right. Every message — including the ones she&amp;rsquo;d already deleted. Her exact location every time she opened the app. How many times she&amp;rsquo;d opened the chat with each person. How many seconds she&amp;rsquo;d looked at each profile. Information pulled from her Facebook — political views, likes, interests. Data about her phone.&lt;/p&gt;</description></item><item><title>The Machine That Records Everything</title><link>https://gdpru.eu/en/journal/the-machine-that-records-everything/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-machine-that-records-everything/</guid><description>&lt;p&gt;How the car became a round-the-clock source of data — and why it hits your wallet.&lt;/p&gt;
&lt;h2 id="a-bill-21-higher"&gt;A bill 21% higher&lt;/h2&gt;
&lt;p&gt;Kenn Dahl drives carefully. No accidents. No fines. Decades behind the wheel.
Two years ago the insurance on his Chevrolet Bolt rose by 21%. Without explanation. Without warning. Just a new bill.
Dahl began to look into it. He requested his data from the broker LexisNexis. He received a 130-page report.
One hundred and thirty pages. About his trips. Over six months.
Everything was there. Routes. Departure and return times. Speed on every segment. Moments of hard braking. Instances of hard acceleration. Seat-belt data.
He did not sign up for surveillance. He bought a car. He pressed the OnStar button on first start-up — and somewhere in a long user agreement that no one reads, he gave consent to the transfer of trip data to third parties.
General Motors sold this data to LexisNexis and Verisk. They sold it to insurance companies. The insurers raised the tariff.
Dahl told the New York Times: they take information he did not know he was transmitting and hit him with it in the wallet.
This is not an isolated case. It is a system.&lt;/p&gt;</description></item><item><title>Your Face. Forever</title><link>https://gdpru.eu/en/journal/your-face.-forever/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/your-face.-forever/</guid><description>&lt;h2 id="twelve-years-of-one-life"&gt;Twelve years of one life&lt;/h2&gt;
&lt;p&gt;Imagine a scenario.
&lt;strong&gt;2012.&lt;/strong&gt; A young woman creates an Instagram account. She posts her first photo — a smile, a summer day, a good mood. Geotag: Tallinn. Caption: first name, surname, a link to Facebook.
&lt;strong&gt;2015.&lt;/strong&gt; A corporate party. A photographer shoots everyone. The photos are posted to a shared group. She is in them. Where she works is visible.
&lt;strong&gt;2018.&lt;/strong&gt; A friend&amp;rsquo;s wedding. Photos from the celebration — in the friend&amp;rsquo;s profile, with a tag. The family circle is visible.
&lt;strong&gt;2021.&lt;/strong&gt; She tries a new app — a filter that «ages» your face. Funny. She shares it with friends.
&lt;strong&gt;2024.&lt;/strong&gt; A job-search app asks for a profile photo. She uploads it.
She did not think of it as a system. Each action was separate, innocent, personal.
But the system thought for her.
Over twelve years she built a biometric database about herself. More precise than any state surveillance system. Voluntarily. For free. With pleasure.
Her face is in dozens of databases. On servers in countries she has never visited. In algorithms she never authorised. In profiles that are sold to companies whose existence she does not know about.
And to delete it is impossible.&lt;/p&gt;</description></item><item><title>The Overton Window. How Surveillance Became the Norm</title><link>https://gdpru.eu/en/journal/the-overton-window.-how-surveillance-became-the-norm/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-overton-window.-how-surveillance-became-the-norm/</guid><description>&lt;p&gt;Six steps no one noticed. Because they were not meant to be noticed. There is a thought experiment.
Imagine it is 1993. There is almost no internet in homes. Mobile phones — with a handful of people. And onto television comes a serious man in a suit and says the following into the camera.
«In the future every inhabitant of the planet will carry in their pocket a device that records their location every second. Records all their conversations — not the content, but the metadata. Knows whom they call, for how long, when and from where. Records what they read. What they buy. Who they communicate with. What photographs they look at. How much time they spend on each page. And all of this — voluntarily. With their own money. People will buy these devices themselves, pay for access to the services themselves, and press the &amp;lsquo;Accept&amp;rsquo; button themselves to permit all of this.»
The audience&amp;rsquo;s reaction in 1993 would have been unambiguous.
The man would have been taken off the air. He would have been compared to a paranoiac or a provocateur. The editor would have apologised to the viewers. Because what he describes — is a totalitarian dystopia. It is Orwell. It is Big Brother. It is unthinkable in a free society.
Thirty years passed.
Everything he described — happened. Exactly. Literally. Down to the details.
And no one took to the streets. No one declared it totalitarianism. No one refused to buy the device. On the contrary — queues at Apple stores on the day a new model comes out. Billions of downloaded apps. Trillions of pressed «Accept» buttons.
How did this happen?
Not by force. Not by coercion. Not by deception in the crude sense of the word.
By means of a mechanism the American sociologist Joseph Overton described back in the nineties. A mechanism thanks to which any idea — even the most unthinkable — can become a political norm. If you move correctly. Consistently. Patiently. Imperceptibly.
Six steps. Thirty years. And now you hold in your hands a device that knows more about you than your closest friend — and you consider this perfectly normal.
Let us examine how this happened. Step by step.&lt;/p&gt;</description></item><item><title>The Gap Between the HAR File and the GDPR Article</title><link>https://gdpru.eu/en/journal/the-gap-between-the-har-file-and-the-gdpr-article/</link><pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-gap-between-the-har-file-and-the-gdpr-article/</guid><description>&lt;p&gt;The gap between the HAR file and the GDPR article. A systemic problem no one calls by its name.&lt;/p&gt;
&lt;p&gt;The violations are visible. They&amp;rsquo;re not hidden. They&amp;rsquo;re not encrypted. They don&amp;rsquo;t require secret access or insider information. They sit right there in the open network logs of any browser. Everything is written down. Who received the data. Exactly when — down to the millisecond. How many requests. Which identifiers flew off to someone else&amp;rsquo;s servers. Whether there was any consent at all — or whether the page was still loading when the data had already left.&lt;/p&gt;</description></item><item><title>Psychographics: How Advertising Learns Not What You Do, But Who You Are Inside</title><link>https://gdpru.eu/en/journal/psychographics-how-advertising-learns-not-what-you-do-but-who-you-are-inside/</link><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/psychographics-how-advertising-learns-not-what-you-do-but-who-you-are-inside/</guid><description>&lt;p&gt;We&amp;rsquo;ve been told the same safety rule our whole lives: don&amp;rsquo;t tell strangers about yourself. Don&amp;rsquo;t give out your address. Don&amp;rsquo;t say how much you earn. Don&amp;rsquo;t share personal things. Be careful.&lt;/p&gt;
&lt;p&gt;Good advice. Except it arrived about twenty years too late.&lt;/p&gt;
&lt;p&gt;While we were learning to keep quiet about ourselves, an entire industry grew up that doesn&amp;rsquo;t need to ask. It doesn&amp;rsquo;t wait for you to tell it anything. It just watches — what you open, what your eyes linger on, what you read to the end and what you scroll past. And from that, it assembles a portrait — one that&amp;rsquo;s sometimes more accurate than the one you could draw yourself.&lt;/p&gt;</description></item><item><title>The Art of War in the Digital Age</title><link>https://gdpru.eu/en/journal/the-art-of-war-in-the-digital-age/</link><pubDate>Sat, 30 May 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-art-of-war-in-the-digital-age/</guid><description>&lt;p&gt;There&amp;rsquo;s a book that&amp;rsquo;s two and a half thousand years old. It was written by a Chinese strategist named Sun Tzu, believed to date to the 5th century BC. It&amp;rsquo;s short — thirteen chapters, a few thousand characters. It&amp;rsquo;s studied at the military academies of West Point and Saint-Cyr. It&amp;rsquo;s read at the business schools of Harvard and London. Lawyers, negotiators, intelligence officers, and politicians cite it.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s called &amp;ldquo;The Art of War.&amp;rdquo;&lt;/p&gt;</description></item><item><title>The Five Virtues of a General</title><link>https://gdpru.eu/en/journal/the-five-virtues-of-a-general/</link><pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-five-virtues-of-a-general/</guid><description>&lt;h2 id="sun-tzu-fushan-and-the-person-who-defends-digital-rights"&gt;Sun Tzu, Fushan, and the Person Who Defends Digital Rights&lt;/h2&gt;
&lt;p&gt;We devoted the first article in this trilogy to strategy. &amp;ldquo;The Art of War&amp;rdquo; as a guide for the digital age. Victory through knowledge, not force. Acting from calm, not from anger.&lt;/p&gt;
&lt;p&gt;The second — to tools. The HAR file as an evidentiary base. GDPR articles as the legal language for technical facts. The gap between those who see a violation and those who know how to classify it.&lt;/p&gt;</description></item><item><title>The Cycle of Digital Surveillance — in Plain Words</title><link>https://gdpru.eu/en/journal/the-cycle-of-digital-surveillance--in-plain-words/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-cycle-of-digital-surveillance--in-plain-words/</guid><description>&lt;p&gt;The beginning — you just live.
You wake up. Check your phone. Read the news. Buy coffee with a card. Search for something online. Watch a video. Write a message to a friend. You just live your life.
But each of these actions leaves a trace. Not because you did something wrong. But because the system is built that way.&lt;/p&gt;
&lt;h2 id="step-1--collection"&gt;Step 1 — Collection&lt;/h2&gt;
&lt;p&gt;Your phone knows where you are. The browser knows what you search for. The store knows what you buy. The bank knows how much you spend and when. Apps know when you sleep and when you wake up. Each platform collects its piece of your life. Individually this seems harmless.&lt;/p&gt;</description></item><item><title>«Eagle Eye». What a 2008 Film Predicted More Precisely Than Forecasts</title><link>https://gdpru.eu/en/journal/eagle-eye.-what-a-2008-film-predicted-more-precisely-than-forecasts/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/eagle-eye.-what-a-2008-film-predicted-more-precisely-than-forecasts/</guid><description>&lt;p&gt;In reality this is not one system — it is an ecosystem of hundreds of companies: TTD, Oracle BlueKai, Meta, Criteo, Piano, Cxense. Each sees a piece. Together they see everything.&lt;/p&gt;
&lt;h3 id="layer-1--identity-resolution--who-you-are-as-a-person"&gt;Layer 1 — Identity Resolution — (who you are as a person)&lt;/h3&gt;
&lt;p&gt;These companies solve the main task: to link an anonymous digital trace with a real person.
LiveRamp — the world&amp;rsquo;s largest identity graph. Takes your online actions and links them with offline purchases, home address, phone. Works with thousands of brands around the world.
Tapad — specialises in cross-device matching. Determines that your phone, work laptop and home tablet belong to one person — even if you did not log in anywhere.
Acxiom — stores profiles on 2.5 billion people, that is about 68% of all internet users in the world. Demographics, incomes, lifestyle, purchasing habits. Clients — banks, insurance companies, retail chains, governments.
Experian, Equifax, TransUnion — the three largest credit agencies. They know your financial history and sell it not only to banks but also to advertisers.
Epsilon/Publicis — data from loyalty programmes. They know exactly what you bought in a store, how often and for what sum.
ID5, Neustar/TransUnion — identification without cookies, a new generation of surveillance technology that works even when you have cleared your browser history.&lt;/p&gt;</description></item><item><title>Digital Surveillance in Russia</title><link>https://gdpru.eu/en/journal/digital-surveillance-in-russia/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/digital-surveillance-in-russia/</guid><description>&lt;h2 id="open-sources"&gt;Open Sources&lt;/h2&gt;
&lt;p&gt;This system has three tiers. The first is state infrastructure for direct access. The second is ecosystem platforms that collect data commercially but are required to hand it over on request. The third is technical intermediaries that provide the infrastructure for the first two. Together, they form a closed loop from which data never leaves — it only accumulates.&lt;/p&gt;
&lt;h2 id="tier-one--state-infrastructure"&gt;Tier One — State Infrastructure&lt;/h2&gt;
&lt;p&gt;This is the foundation of the system. Not commercial players, not advertising brokers — but a legally established, direct state access to any and all data of any user within Russian territory. No court order presented to the operator. No notification to the data subject. No right to challenge it.&lt;/p&gt;</description></item><item><title>By the Time You Finished Reading This Headline — You'd Already Been Sold</title><link>https://gdpru.eu/en/journal/by-the-time-you-finished-reading-this-headline--youd-already-been-sold/</link><pubDate>Sat, 11 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/by-the-time-you-finished-reading-this-headline--youd-already-been-sold/</guid><description>&lt;p&gt;It&amp;rsquo;s called Real-Time Bidding — RTB. Bidding in real time. And it&amp;rsquo;s arguably the largest invisible market in human history.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Not metaphorically. Literally. Over the last few seconds, while you were scrolling your feed, several dozen auctions took place. In each one, companies bid for the right to show you an ad. They knew who you were. They knew where you were. They knew what you were watching last night. And the entire process took less time than the blink of an eye.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It&amp;rsquo;s called Real-Time Bidding — RTB. Bidding in real time. And it&amp;rsquo;s arguably the largest invisible market in human history.&lt;/p&gt;</description></item><item><title>Algorithmic Recommendations</title><link>https://gdpru.eu/en/journal/algorithmic-recommendations/</link><pubDate>Wed, 08 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/algorithmic-recommendations/</guid><description>&lt;p&gt;There is a question that seems simple.
Why does YouTube show you exactly this video. Why does TikTok show exactly this clip. Why does Spotify play exactly this song.
Most people answer — because they like it. Because the algorithm has studied their tastes. Because the platform wants to make their experience better.
That is not the answer. That is what the platforms want you to think.
The real answer is different. And it changes everything.&lt;/p&gt;</description></item><item><title>What Consent Means in the Digital World</title><link>https://gdpru.eu/en/journal/what-consent-means-in-the-digital-world/</link><pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/what-consent-means-in-the-digital-world/</guid><description>&lt;p&gt;Every day billions of people press a button.
«Accept all». «Agree». «I accept the terms». «Continue».
And every time they think they made a choice. That they consented consciously. That now everything is lawful — both for them and for the company.
It is not so.
Most of what is called consent in the digital world is not consent by law. Is not consent by meaning. And is not consent in fact.
Below we examine why. Not abstractly — concretely. What real consent is. What fake consent looks like. And why the difference between them is worth billions of euros in fines.&lt;/p&gt;</description></item><item><title>Your Digital Twin. It Already Exists. You Just Didn't Know</title><link>https://gdpru.eu/en/journal/your-digital-twin.-it-already-exists.-you-just-didnt-know/</link><pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/your-digital-twin.-it-already-exists.-you-just-didnt-know/</guid><description>&lt;p&gt;How many versions of you exist right now?
You think — one. Yourself. A living person with thoughts, habits, a history. One and unrepeatable.
In fact — dozens. Maybe hundreds. In databases all over the world, copies of you live right now. They do not know what you are thinking this morning. But they know something about you that you yourself may not realise. They predict your behaviour. They influence decisions that are made about you. They exist independently of you — and you cannot switch them off.
This is called a digital twin.
And before you say «this sounds like science fiction» — let me show you exactly how it was created. Step by step. Out of things you did every day without thinking.&lt;/p&gt;</description></item><item><title>Advertising Brokers. The Industry No One Sees</title><link>https://gdpru.eu/en/journal/advertising-brokers.-the-industry-no-one-sees/</link><pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/advertising-brokers.-the-industry-no-one-sees/</guid><description>&lt;h2 id="part-one--who-they-are"&gt;Part One — Who They Are&lt;/h2&gt;
&lt;p&gt;You never see them, but they know everything about you.&lt;/p&gt;
&lt;p&gt;Name. Address. Income. Health. Political views. Sexual orientation. Religion. Financial difficulties. Family problems. Fears. Desires. Weaknesses.&lt;/p&gt;
&lt;p&gt;They&amp;rsquo;ve never met you. You never gave them permission. But they have a profile on you — detailed, accurate, constantly updated. And it&amp;rsquo;s for sale. Right now. While you&amp;rsquo;re reading this.&lt;/p&gt;
&lt;p&gt;These are advertising data brokers. Data brokers. And this is one of the largest industries in the world that ordinary people know almost nothing about.&lt;/p&gt;</description></item><item><title>Your Phone as a Surveillance Tool</title><link>https://gdpru.eu/en/journal/-your-phone-as-a-surveillance-tool/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/-your-phone-as-a-surveillance-tool/</guid><description>&lt;p&gt;It knows where you&amp;rsquo;ve been every minute of the last several years. Who you&amp;rsquo;ve talked to. What you&amp;rsquo;ve searched for. What you&amp;rsquo;ve bought. How you&amp;rsquo;ve slept. How many steps you&amp;rsquo;ve taken. What your heart rate is. What makes you laugh and what makes you angry — because it sees how you react to content.&lt;/p&gt;
&lt;p&gt;This isn&amp;rsquo;t a bug someone planted on you. It&amp;rsquo;s the phone you bought yourself. Voluntarily. And that you never turn off.&lt;/p&gt;</description></item><item><title>Children in the Digital World</title><link>https://gdpru.eu/en/journal/children-in-the-digital-world/</link><pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/children-in-the-digital-world/</guid><description>&lt;h2 id="part-one--a-profile-that-begins-before-the-child-has-learned-to-speak"&gt;Part one — a profile that begins before the child has learned to speak&lt;/h2&gt;
&lt;p&gt;This is not a metaphor. It is literally what happens. And it is only the beginning of a process that will go on for the next eighteen years — until the child becomes an adult and discovers that everything about them is already known. Long before they themselves decided to tell anything.
Today — about how this works. From the very beginning. Step by step.&lt;/p&gt;</description></item><item><title>Where GDPR Came From. The Story Few Know in Full</title><link>https://gdpru.eu/en/journal/where-gdpr-came-from.-the-story-few-know-in-full/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/where-gdpr-came-from.-the-story-few-know-in-full/</guid><description>&lt;p&gt;&amp;ldquo;To understand why this law is needed — you have to understand what was happening before it. Because GDPR did not appear out of thin air. It was written by people who saw concrete things.&amp;rdquo;&lt;/p&gt;
&lt;h2 id="the-internet-in-the-nineties-was-different"&gt;The internet in the nineties was different&lt;/h2&gt;
&lt;p&gt;When the network first became widely available — no one thought of data as a value. People visited sites, read, left. No accounts, no personalisation, no tracking. The internet was like a library — you take a book, read it, put it back. The library does not know who you are or what you were looking for.
Then advertising appeared.
The first advertising banner on the internet appeared in 1994. The company AT&amp;amp;T bought space on the site HotWired. The banner was simple — just a picture. 44% of everyone who saw it clicked. Today the average figure is less than 0.1%. People stopped clicking because there became too much advertising and it stopped being interesting.
And this is where the story that led to GDPR begins.
The advertising market ran into a problem. Banners do not work if they are shown to everyone indiscriminately. You need to show the right advertising to the right person at the right moment. For this you need to know who this person is. What interests them. Where they live. How old they are. What they searched for yesterday. What they are thinking about today.
Thus the surveillance industry was born. Not all at once. Gradually. Step by step — each of which seemed harmless.&lt;/p&gt;</description></item><item><title>IoT — Why Smart Devices Are a Hole in Your Home</title><link>https://gdpru.eu/en/journal/iot--why-smart-devices-are-a-hole-in-your-home/</link><pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/iot--why-smart-devices-are-a-hole-in-your-home/</guid><description>&lt;p&gt;A smart bulb. A smart plug. A smart TV. A smart fridge. Each of them is a potential entry point into your home network.&lt;/p&gt;
&lt;h2 id="the-scale-of-the-problem--the-figures"&gt;The scale of the problem — the figures&lt;/h2&gt;
&lt;p&gt;By 2025 more than 15 billion IoT devices are connected worldwide. By 2030, 30 billion are forecast. Each of them is a computer. Small, cheap, with minimal protection. Connected to your home network. Working 24 hours a day. Often — forgotten and never updated. IoT stands for the Internet of Things. But it would be more accurate to call it the internet of vulnerabilities.&lt;/p&gt;</description></item><item><title>You Think You're Reading the News. In Fact — the News Is Reading You</title><link>https://gdpru.eu/en/journal/you-think-youre-reading-the-news.-in-fact--the-news-is-reading-you/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/you-think-youre-reading-the-news.-in-fact--the-news-is-reading-you/</guid><description>&lt;h2 id="morning-you-open-the-feed"&gt;Morning. You open the feed&lt;/h2&gt;
&lt;p&gt;Seven in the morning. You pick up your phone. You open a social network. You scroll.
You think you are seeing the news. What is happening in the world. What is important.
But what you see is not the news. It is a personal newspaper that the algorithm assembled specially for you. In the last few seconds. On the basis of everything it knows about you.
Your neighbour opens the same social network at the same minute. He sees something different. Completely different. Different topics, different emotions, a different reality.
You live in the same building. But in different information worlds.&lt;/p&gt;</description></item><item><title>How to Find the Identifiers Companies Leave on Your Device</title><link>https://gdpru.eu/en/journal/how-to-find-the-identifiers-companies-leave-on-your-device/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/how-to-find-the-identifiers-companies-leave-on-your-device/</guid><description>&lt;p&gt;Do not simply ask «what do you know about me». Show them their own ID, which they left without asking. This changes everything.&lt;/p&gt;
&lt;h2 id="why-this-matters"&gt;Why this matters&lt;/h2&gt;
&lt;p&gt;Most people, when they learn about GDPR, start with a general request — «provide my data». Companies respond with a template. They send the minimum.
There is another approach. More precise. More inconvenient for the company.
You open the browser. Press three buttons. And you see a concrete identifier — a unique code that the company assigned specifically to you and stores in your browser without your knowledge.
Now in the request you write not «provide the data» — but «provide all data associated with the identifier f7a3c291-4e8b-4d12-b063-9a2e17f83c44 that your company set in my browser».
This is specifics. This is proof. This is something companies find inconvenient to dodge.&lt;/p&gt;</description></item><item><title>Why Your Data Is Your Security</title><link>https://gdpru.eu/en/journal/why-your-data-is-your-security/</link><pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/why-your-data-is-your-security/</guid><description>&lt;p&gt;&amp;ldquo;I have nothing to hide.&amp;rdquo; That&amp;rsquo;s exactly what everyone in these stories thought — before everything changed.&lt;/p&gt;
&lt;h3 id="before-we-begin"&gt;Before we begin&lt;/h3&gt;
&lt;p&gt;Eric Schmidt — former CEO of Google — said it outright: &amp;ldquo;We know where you are. We know where you&amp;rsquo;ve been. We can more or less know what you&amp;rsquo;re thinking about.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s not a threat. It&amp;rsquo;s a description of what&amp;rsquo;s already working. Right now. In Tallinn, Riga, Warsaw, Berlin, Moscow.&lt;/p&gt;</description></item><item><title>How to Read a Privacy Policy. What to Look For and What They Hide</title><link>https://gdpru.eu/en/journal/how-to-read-a-privacy-policy.-what-to-look-for-and-what-they-hide/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/how-to-read-a-privacy-policy.-what-to-look-for-and-what-they-hide/</guid><description>&lt;p&gt;These documents are written so as not to be read. Let us examine how to read them correctly.&lt;/p&gt;
&lt;h2 id="why-a-privacy-policy-is-not-a-boring-formality"&gt;Why a privacy policy is not a boring formality&lt;/h2&gt;
&lt;p&gt;The average privacy policy is about 4,000 words. Reading it takes 18 minutes. Studies show that fewer than 10% of users read it, even partially.
Companies know this. And write it exactly so — long, legalistic, with references within the document to other documents that also no one reads.
But inside these documents is everything they do with your data. Openly. Officially. Written by their own hands.
You do not need to read everything. You need to know where to look.&lt;/p&gt;</description></item><item><title>Anonymity Doesn't Exist. How the System Recognises You Even Without a Name</title><link>https://gdpru.eu/en/journal/anonymity-doesnt-exist.-how-the-system-recognises-you-even-without-a-name/</link><pubDate>Thu, 05 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/anonymity-doesnt-exist.-how-the-system-recognises-you-even-without-a-name/</guid><description>&lt;p&gt;You open the browser in incognito mode. You think — now they don&amp;rsquo;t see me. I&amp;rsquo;m going in anonymously. No. Incognito mode hides your history from your browser. Not from the internet.&lt;/p&gt;
&lt;p&gt;Five ways the system recognises you without cookies and without a name:&lt;/p&gt;
&lt;h2 id="first--the-ip-address"&gt;First — the IP address&lt;/h2&gt;
&lt;p&gt;Every time you go online — your provider assigns you an IP address. It is like an apartment number on the internet. The site you open sees this number automatically.
From the IP address the country, city, provider are determined. If the IP is static — it is permanently tied to you. If dynamic — it changes but the behaviour pattern remains.&lt;/p&gt;</description></item><item><title>Mobile Apps. One App — Dozens of Invisible Guests</title><link>https://gdpru.eu/en/journal/mobile-apps.-one-app--dozens-of-invisible-guests/</link><pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/mobile-apps.-one-app--dozens-of-invisible-guests/</guid><description>&lt;p&gt;You download an app. One. Simple. Say a flashlight or weather. But inside this app live other programs you did not download and about which no one asked you.
This is called an SDK — Software Development Kit. A set of tools that the developer embeds in their app. Convenient for them. Invisible to you.&lt;/p&gt;
&lt;h2 id="how-it-works"&gt;How it works&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The developer creates an app. To add analytics — they embed an SDK from Google Firebase. To show advertising — an SDK from Meta Audience Network. To track installs — an SDK from AppsFlyer. To analyse behaviour — an SDK from Amplitude.&lt;/li&gt;
&lt;li&gt;One app. Four invisible guests inside. Each with its own servers, its own data policy, its own interests.
The average mobile app contains from 10 to 30 SDKs simultaneously. Popular apps — up to 50.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-these-sdks-collect"&gt;What these SDKs collect&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Each SDK has access to all the permissions you gave the main app.&lt;/li&gt;
&lt;li&gt;You gave the weather app access to geolocation — all 15 SDKs inside it also received your geolocation.&lt;/li&gt;
&lt;li&gt;You gave access to contacts — all the SDKs see your phone book.&lt;/li&gt;
&lt;li&gt;You gave access to the microphone — all the SDKs can potentially use it.&lt;/li&gt;
&lt;li&gt;You gave permission to one app. Dozens of companies received it.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-most-widespread-sdks-and-who-they-belong-to"&gt;The most widespread SDKs and who they belong to&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google Firebase — analytics, crash reports, push notifications. Installed in billions of apps. Everything that happens in the app goes to Google&amp;rsquo;s servers.&lt;/li&gt;
&lt;li&gt;Meta SDK — the Facebook and Instagram advertising network. Even if you do not use Facebook — Meta receives data about your behaviour through apps where their SDK is installed.&lt;/li&gt;
&lt;li&gt;AppsFlyer / Adjust — tracking of marketing campaigns. They know where you came from, what you installed, how much time you spent.&lt;/li&gt;
&lt;li&gt;Yandex AppMetrica — the Russian analogue of Firebase. Installed in most Russian apps. The data goes to Yandex&amp;rsquo;s servers.&lt;/li&gt;
&lt;li&gt;AppTracer — it is precisely this SDK that was recorded in the VKontakte app. Not mentioned in VK&amp;rsquo;s Privacy Policy. It collects data about the device and sessions and sends it to external servers without notifying the user. This is documented in the technical logs and attached to the official complaint to AKI.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="why-developers-do-this"&gt;Why developers do this&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Money. A simple answer.
Advertising SDKs pay the developer for each user. The more data the SDK collects — the more precise the targeting — the more expensive the advertising — the more money the developer receives.
A free app is never free. You pay with data.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-most-telling-example"&gt;The most telling example&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Popular phone keyboards — SwiftKey, Gboard, many others. The keyboard sees absolutely everything you type. Passwords, messages, card numbers, personal correspondence. Everything.
And most keyboards contain analytics SDKs that send input data to external servers. Think about this next time you enter a password.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-to-do"&gt;What to do&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;First — fewer apps.
Each app is potentially dozens of SDKs. Delete what you do not use. Each deleted app — minus ten invisible guests.&lt;/li&gt;
&lt;li&gt;Second — use the web version instead of the app.
A site in a browser contains trackers — but they are easier to block. An app on the phone — significantly harder. Bank, store, news — go in through the browser.&lt;/li&gt;
&lt;li&gt;Third — check permissions after installation.
You installed an app — immediately go into the settings and revoke everything unnecessary. Leave only what the app physically cannot work without.&lt;/li&gt;
&lt;li&gt;Fourth — read not only the reviews but also the privacy policy. Look for the «third parties» or «partners» section. If it says «we may transfer data to partners to improve the service» — this means SDKs inside the app.&lt;/li&gt;
&lt;li&gt;Fifth — for Android use NetGuard.
This is a firewall that shows which apps go online and blocks those you do not want to let through. You see in real time who sends data and where.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-main-thing-to-understand"&gt;The main thing to understand&lt;/h2&gt;
&lt;p&gt;When you download an app — you do not merely install a program. You open a door into your phone for dozens of companies you have never heard of.
They do not ask permission separately. They enter together with the app — quietly, imperceptibly, forever until you delete the app.&lt;/p&gt;</description></item><item><title>How the Browser Leaks Everything About You. A Full Breakdown</title><link>https://gdpru.eu/en/journal/how-the-browser-leaks-everything-about-you.-a-full-breakdown/</link><pubDate>Wed, 25 Feb 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/how-the-browser-leaks-everything-about-you.-a-full-breakdown/</guid><description>&lt;p&gt;You think the browser is just a window into the internet. In fact it is the most informative surveillance tool that exists.
Let us break it down by layers.&lt;/p&gt;
&lt;h3 id="what-the-browser-knows-about-you-without-cookies"&gt;What the browser knows about you without cookies&lt;/h3&gt;
&lt;p&gt;Even if you cleared all cookies, logged out of all accounts and turned on incognito mode — you can still be identified. This is called fingerprinting — a digital fingerprint.&lt;/p&gt;
&lt;h2 id="what-it-consists-of-i-will-show-it-on-my-own-example"&gt;What it consists of (I will show it on my own example)&lt;/h2&gt;
&lt;p&gt;User Agent — the exact version of the browser and operating system. «Chrome 122.0.6261.112 on Windows 11 64-bit» — this already narrows the circle to millions but not to anonymity.
Screen resolution and scaling — 1536x864, DPR 1.375, zoom 1.11. It is precisely these parameters that VK recorded in the remixscreen_* cookies on every visit.
Installed fonts — the browser can check which fonts are installed in the system. A combination of 50–100 fonts is unique for each device.
Canvas fingerprint — the browser draws an invisible graphic element. Each device renders it slightly differently because of the GPU, drivers, OS. The result is hashed — a unique ID is obtained.
WebGL fingerprint — similarly, through 3D graphics. Even more precise than Canvas.
AudioContext fingerprint — the browser processes an audio signal. The result depends on the audio chip and drivers — unique for the device.
Time zone and language — Europe/Tallinn + ru-RU already says a lot.
List of plugins — which extensions are installed in the browser.
Mouse and keyboard behaviour — typing speed, mouse-movement patterns. This is a behavioural biometric profile. Unique like a signature.
The totality of all these parameters creates a fingerprint that identifies me with an accuracy of 90–99% — without a single cookie, without an account, without a name.
Check your fingerprint right now: coveryourtracks.eff.org&lt;/p&gt;</description></item><item><title>Your Holiday Costs More Than You Think</title><link>https://gdpru.eu/en/journal/your-holiday-costs-more-than-you-think/</link><pubDate>Sun, 15 Feb 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/your-holiday-costs-more-than-you-think/</guid><description>&lt;p&gt;Let us go through it step by step.&lt;/p&gt;
&lt;h2 id="tickets"&gt;Tickets&lt;/h2&gt;
&lt;p&gt;When you book a plane ticket — the data enters the global booking system. Amadeus, Sabre, Travelport — three companies that process almost all plane tickets in the world. Your name, passport, route, seat on the plane, meal preferences, flight history — all of this is in their databases.
This data is transmitted to the airline, the airport, the border services of the countries you fly through, insurance companies, advertising networks.
The US requires the transmission of passenger data 72 hours before departure — including citizens of third countries who are simply flying through American airspace.
What to do: Book directly through the airline&amp;rsquo;s website — fewer intermediaries receive the data. Avoid intermediary sites like Skyscanner and Kayak for the final booking — use them only to search for the price.&lt;/p&gt;</description></item><item><title>Cookies. The Digital Traces You Leave Everywhere</title><link>https://gdpru.eu/en/journal/cookies.-the-digital-traces-you-leave-everywhere/</link><pubDate>Tue, 10 Feb 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/cookies.-the-digital-traces-you-leave-everywhere/</guid><description>&lt;p&gt;You visit a site. The site asks — «accept cookies?» Most people press «accept all» to close the annoying window faster.&lt;/p&gt;
&lt;h3 id="what-is-a-cookie"&gt;What is a cookie?&lt;/h3&gt;
&lt;p&gt;It is a small text file that a site saves in your browser. The size of a few lines of text. It contains a unique identifier — your personal number for this site. When you return to the site — it reads this file and recognises you, not by name — but by number, but that is enough.&lt;/p&gt;</description></item><item><title>The Cloud Service, Let Me Reveal the Details</title><link>https://gdpru.eu/en/journal/the-cloud-service-let-me-reveal-the-details/</link><pubDate>Sat, 07 Feb 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/the-cloud-service-let-me-reveal-the-details/</guid><description>&lt;p&gt;The cloud.
Every phone, every account, every app offers the same thing — upload to the cloud. Photos, documents, contacts, notes. Convenient, always at hand, you won&amp;rsquo;t lose it. But let us examine how this really works.
What is the cloud?
It is simply someone else&amp;rsquo;s computer. Not an abstract «cloud» — but a physical server in a data centre that belongs to a corporation. Google, Apple, Microsoft, Yandex, Mail.ru — each has its own servers, its own rules, its own access to your data.
When you upload a photo to iCloud or Google Photos — you hand it over for storage to a company. Not for storage in an abstract space — but to a specific corporation with specific interests.&lt;/p&gt;</description></item><item><title>What Your Profile Looks Like at a Data Broker</title><link>https://gdpru.eu/en/journal/what-your-profile-looks-like-at-a-data-broker/</link><pubDate>Thu, 05 Feb 2026 00:00:00 +0000</pubDate><guid>https://gdpru.eu/en/journal/what-your-profile-looks-like-at-a-data-broker/</guid><description>&lt;p&gt;How a profile with a permanent ID is assembled from scattered traces.
Let us start with a simple question. Why does advertising for trainers chase you across three different sites after you looked at them once in a store? You did not give these sites permission. You did not even register with them. But the advertising knows who you are. Here is how it works from the inside.&lt;/p&gt;
&lt;h2 id="the-architecture-of-the-system"&gt;The architecture of the system&lt;/h2&gt;
&lt;p&gt;There are three levels that most people do not see.&lt;/p&gt;</description></item></channel></rss>