{"id":11425,"date":"2025-12-22T10:26:19","date_gmt":"2025-12-22T09:26:19","guid":{"rendered":"https:\/\/techgdpr.com\/?p=11425"},"modified":"2025-12-22T14:05:05","modified_gmt":"2025-12-22T13:05:05","slug":"data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/","title":{"rendered":"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#8216;guest&#8217; mode, or voluntary account creation"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\"><strong>E-commerce user data<\/strong><\/h4>\n\n\n\n<p> As a general rule, users should have the option to engage with e-commerce websites, including the <a href=\"https:\/\/www.edpb.europa.eu\/news\/news\/2025\/edpb-gives-recommendations-make-online-shopping-more-respectful-users-privacy_en\">ability to make purchases, without creating an account<\/a>. In such cases, the EDPB recommends that e-commerce websites offer a choice: either a &#8216;guest&#8217; mode, allowing users make purchases without creating an account, or the option to voluntarily create an account. This approach minimises the collection and processing of personal data, and therefore aligns with the GDPR&#8217;s principle of data protection by design and by default. However, mandatory account creation can be justified in a limited number of cases, including for example, offering a subscription service or providing access to exclusive offers.&nbsp;<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><mark style=\"background-color:#fbdfcb;color:#bc7df7\" class=\"has-inline-color\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/mark><\/a><\/h6>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Google antitrust investigation<\/strong><\/h4>\n\n\n\n<p>The EU Commission has opened an investigation into possible <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_25_2964\">anticompetitive conduct by Google in the use of online content for AI purposes &#8211; using the content of web publishers, as well as content uploaded on the online video-sharing platform<\/a> YouTube. The investigation will notably examine whether Google is distorting competition by imposing unfair terms and conditions on publishers and content creators, or by granting itself privileged access to such content, thereby placing developers of rival AI models at a disadvantage. It should be noted that there is no legal deadline in the EU for bringing an antitrust investigation to an end.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<p><strong>US AI national policy: <\/strong>On 11 December, President Trump signed an Executive Order on&nbsp; establishing a <a href=\"https:\/\/digitalpolicyalert.org\/event\/36029-president-adopted-presidential-executive-order-on-a-national-artificial-intelligence-policy-framework\">national policy framework for AI<\/a> and lifting barriers to innovation. According to digitalpolicyalert.org, the US Administration will work with Congress to establish a single national AI standard that avoids <a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2025\/12\/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy\/\">conflicting state legislation<\/a>. This standard would override any state laws that contradict the policy and would include protections for children, respect for copyrights, prevention of censorship, and measures to keep communities safe.&nbsp;<\/p>\n\n\n\n<p><strong>US immigration data: <\/strong>According to Privacy International, the US Government also intends to force visitors who are not required to get visas, such as British and French citizens, to submit their <a href=\"https:\/\/privacyinternational.org\/news-analysis\/5713\/trump-administration-wants-your-dna-and-social-media\">digital history and even DNA as the price of entry<\/a>. With this much data AI tools will likely be deployed to unlock details of your life for border and immigration agencies. In particular, it wants to know all about:&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u2018telephone numbers used in the last five years\u2019<\/li>\n\n\n\n<li>\u2018email addresses used in the last ten years\u2019<\/li>\n\n\n\n<li>\u2018family number telephone numbers (sic) used in the last five years\u2019<\/li>\n\n\n\n<li>biometrics \u2013 face, fingerprint, DNA, and iris<\/li>\n\n\n\n<li>business telephone numbers used in the last five years<\/li>\n\n\n\n<li>business email addresses used in the last ten years.<\/li>\n<\/ol>\n\n\n\n<p>If the proposed changes, published on 10th of December, are adopted after the 60-day consultation, travellers will have to use <a href=\"https:\/\/www.govinfo.gov\/content\/pkg\/FR-2025-12-10\/pdf\/2025-22461.pdf\">dedicated apps for their ESTA application<\/a>, and to provide biometric proof of their departure. The latter <strong>will disclose the user\u2019s location once they have left the US and run live detection on the selfie photo<\/strong>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Password managers<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-4-1024x682.jpeg\" alt=\"e-commerce\" class=\"wp-image-11427 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-4-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-4-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-4-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-4.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong> <\/strong>The German Federal Office for Information Security (BSI) examined this product category and investigated the IT security features of ten selected password managers. <a href=\"https:\/\/www.bsi.bund.de\/DE\/Service-Navi\/Presse\/Pressemitteilungen\/Presse2025\/251209_Verbesserungsbedarf_Passwortmanager.html\">Three out of ten stored passwords in a way that theoretically allows manufacturers access<\/a>. This increases the attack surface on the manufacturer&#8217;s side, which must be mitigated by additional compensatory measures. Users must trust these additional measures. <\/p>\n<\/div><\/div>\n\n\n\n<p>If the password manager stores data in the cloud, consumers should be informed about the storage location and data protection measures. This information can be included, for example, on the manufacturer&#8217;s website, in the terms and conditions for using the product, or in the privacy policy.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>AI Training guidance<\/strong><\/h4>\n\n\n\n<p>The Swedish data protection authority IMY has investigated the possibility of <a href=\"https:\/\/www.imy.se\/nyheter\/imy-ger-vagledning-om-traning-av-ai\/\">using personal data to create synthetic data for AI training purposes<\/a>. Such data is created to resemble the original data without being able to be linked to individuals. It can be very positive from a privacy perspective, even though the synthesis itself means that personal data is processed, so it needs to comply with the GDPR. The particular project IMY investigated was about custody cases. It therefore involved a large amount of data of a very sensitive nature, which requires <a href=\"https:\/\/techgdpr.com\/blog\/reconciling-the-regulatory-clock\/\">special considerations and measure<\/a>s.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<p><strong>Medical research: <\/strong>The Hessian data protection commissioner has published a guide to data protection in medical research (in German). The guide presents four concrete use cases from the practice of medical research and classifies them from a data protection perspective. In particular, the cases describe the <a href=\"https:\/\/datenschutz.hessen.de\/sites\/datenschutz.hessen.de\/files\/2025-12\/20251028_dgim_hbdi_leifaden_datenschutz_1.01.pdf\">use of AI in cancer screening, pathology, intensive care, and the distinction between quality assurance and scientific research<\/a>. The guide pays particular attention to the question of under what circumstances data can be considered anonymous. The use of <a href=\"https:\/\/datenschutz.hessen.de\/presse\/hbdi-und-dgim-veroeffentlichen-leitfaden-fuer-datenschutz-in-der-medizinischen-forschung\">anonymised data is especially relevant for medical research and the training of AI models<\/a>. For research projects where anonymisation is not practical, the guide presents alternative legal bases under data protection law.<\/p>\n\n\n\n<p><strong>Consent forms: <\/strong>Consent is one of the lawful grounds for processing personal data. It means that a <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-ka-jaizskatas-datu-apstrades-piekrisanas-anketai\">person freely, specifically and unambiguously agrees to the processing of their data for one or more purposes<\/a>. Consent has to be verifiable so that the controller can demonstrate that it was received in accordance with the requirements. Therefore, in situations where consent is requested in person, a written form is useful, which provides clarity for both the organisation and the customer. It can include the minimum information that is most important at the time of consent, so as not to overload the information to be received, as well as not to delay the duration of the service or process itself. The consent form must state:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Who will process the data (company, individual entrepreneur), with their name<\/li>\n\n\n\n<li>Why is data needed<\/li>\n\n\n\n<li>What data is needed<\/li>\n\n\n\n<li>How to withdraw consent<\/li>\n\n\n\n<li>Customer ID (data subject&#8217;s first name, last name)<\/li>\n\n\n\n<li>Date, signature<\/li>\n\n\n\n<li>Information on where to find more information about data processing, including the duration of data storage and how to contact the controller<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Cambridge Analytica compensations<\/strong><\/h4>\n\n\n\n<p>Eligible Australian Facebook users impacted by the Cambridge Analytica affair have until 31 December to register under a payment program established in a landmark settlement. The 50 million dollars <a href=\"https:\/\/www.oaic.gov.au\/news\/media-centre\/australians-eligible-for-cambridge-analytica-payment-program-must-register-by-31-december\">payment program was established by Meta Platforms<\/a> as part of an <a href=\"https:\/\/www.oaic.gov.au\/news\/media-centre\/landmark-settlement-of-%2450m-from-meta-for-australian-users-impacted-by-cambridge-analytica-incident\">enforceable undertaking<\/a> the Australian Information Commissioner accepted from Meta in December 2024. This brings to an end 7 years of investigation and litigation related to the Cambridge Analytica matter in Australia.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Meta data access<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-5-1024x640.jpeg\" alt=\"\" class=\"wp-image-11430 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-5-1024x640.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-5-300x188.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-5-768x480.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-5.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Austrian Supreme Court ordered Meta must provide full access to all personal users data requests within 14 days, including the sources, recipients and purposes for which each information was used, Privacy advocacy group NOYB reports. <a href=\"https:\/\/noyb.eu\/en\/austrian-supreme-court-meta-must-give-users-full-access-their-data\">Meta&#8217;s claims of trade secrets or other limitations were rejected<\/a>. The company claimed it would lead to unprecedented access to the inner systems of the platform.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Meta must also ensure that sensitive information (political views, sexual orientation, or health) is not processed together with other data unless a valid legal basis according to Art. 9 GDPR applies, even if it was collected unintentionally or technically distinguishing it would be impossible. The case was brought by the NOYB activist Max Schrems in 2014 and laboured 11 years in Austrian courts and the CJEU. The plaintiff was awarded 500 euros in damages.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>American Express cookie fine<\/strong><\/h4>\n\n\n\n<p>The French privacy regulator CNIL fined American Express Carte France, the French subsidiary of the <a href=\"https:\/\/www.cnil.fr\/fr\/cookies-la-cnil-sanctionne-american-express-dune-amende-de-15-million-deuros\">American Express group, 1.5 million euros for non-compliance with the rules applicable to cookies<\/a>: a) by depositing trackers without having user consent, or b) despite their refusal to consent, or c) by continuing to read the trackers previously deposited despite subsequent consent withdrawal.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In other news<\/h4>\n\n\n\n<p><strong>Germany telecommunications fine:<\/strong> Due to massive violations of data protection rights, the North Rhine-Westphalia data protection commissioner has imposed a fine of 300,000 euros on a local telecommunications company. Since 2022, consumers have repeatedly contacted the regulator for the same reason: they received personalised ad letters promoting a contract for an internet and telephone connection. The recipients consistently stated that they had never had any prior contact with this company. However, the advertising letters were remarkably detailed. The recipients were only required to add their IBAN and sign the form.<\/p>\n\n\n\n<p>Due to the design of the letters and the <a href=\"https:\/\/www.ldi.nrw.de\/Telekommunikation\">similarity of the name to very well-known telecommunications provider, many consumers were unaware that it wasn&#8217;t an offer for a different tariff with their existing provider, but rather an offer to switch providers<\/a>. As a result, those affected often signed the contract documents. Only when they later realized they had switched providers did they cancel or revoke the contracts \u2013 and were then hit with a demand for a flat-rate compensation fee by the company.&nbsp;<\/p>\n\n\n\n<p><strong>Direct marketing fine: <\/strong>The Italian data protection authority has fined Verisure Italia for unlawful processing of personal data for marketing purposes. The measure stems from a complaint from a former customer who continued to receive <a href=\"https:\/\/www.garanteprivacy.it\/garante\/doc.jsp?ID=10201989\">unwanted promotional text messages even after objecting to the processing<\/a> of his data, and from a report from a potential customer who, after requesting a quote, began receiving promotional phone calls, emails, and text messages.&nbsp;The communications continued despite the exercise of the right to object provided for by the GDPR. Furthermore, the regulator deemed the retention period for potential customer data envisaged for telemarketing (12 months) to be excessive.&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_f3205f2814bfd498ffdac5645cfe230b\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement actions<\/h4>\n\n\n\n<p><strong>Data processor breach<\/strong>: The French CNIL imposed a fine on Mobius Solutions, the processor behind a data breach affecting users of Deezer. The company was fined 1 million euros for failing to comply with the applicable rules regarding subcontracting. In 2022, Deezer reported that its users&#8217; data had been posted on the dark web and that its former processor, Mobius Solutions, whose services it used to carry out personalised advertising campaigns for its customers, was involved.<\/p>\n\n\n\n<p>The processor <a href=\"https:\/\/www.cnil.fr\/en\/data-breach-mobius-solutions-ltd-fined-eu1-million\">retained a copy of the data of more than 46 million DEEZER users after the end of their contractual relationship, despite its obligation to delete<\/a> all such data at the end of the contract.<\/p>\n\n\n\n<p><strong>University data breach:<\/strong> The Dutch AP imposed a 175,000-euro fine on HAN University of Applied Sciences for breaching the GDPR data security rules.&nbsp; A <a href=\"https:\/\/autoriteitpersoonsgegevens.nl\/actueel\/han-krijgt-boete-van-175000-euro-voor-onvoldoende-beveiliging-van-persoonsgegevens\">hacker used SQL injection through a web form to access HAN&#8217;s database<\/a>. The individual threatened to make personal data, including addresses, names, passwords, and citizen service numbers, public and unsuccessfully demanded ransom from the university.<\/p>\n\n\n\n<p><strong>Password manager data breach: <\/strong>The UK Information Commissioner fined password manager provider LastPass 1.2 million pounds following a 2022 data breach that compromised the personal information of up to 1.6 million of its UK users. LastPass failed to implement sufficiently robust technical and security measures, which ultimately enabled a hacker to gain unauthorised access to its backup database. The incidents occurred when a <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2025\/12\/password-manager-provider-fined\/\">hacker gained access first to a corporate laptop of an employee<\/a> based in Europe and then to a US-based employee\u2019s personal laptop on which the hacker implanted malware and was then able to capture the employee\u2019s master password.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In case you missed it<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-1024x1024.png\" alt=\"e-commerce\" class=\"wp-image-11426 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-1024x1024.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-300x300.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-150x150.png 150w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-768x768.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-200x200.png 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Meta personalised ads: <\/strong>On 8 December, the European Commission acknowledged Meta&#8217;s undertaking to offer users in the EU an alternative choice of Facebook and Instagram services that would show them fewer personalised ads, to comply with the Digital Markets Act. This is the first time that such a choice is offered on Meta&#8217;s social networks. Meta will give users the effective choice between:&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li>consenting to share all their data and seeing fully personalised advertising, or&nbsp;<\/li>\n\n\n\n<li>opting to <a href=\"https:\/\/digital-markets-act.ec.europa.eu\/meta-commits-give-eu-users-choice-personalised-ads-under-dma-2025-12-08_en#:~:text=Meta%20will%20give%20users%20the,the%20EU%20in%20January%202026.\">share less personal data for an experience with more limited personalised advertising<\/a>.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Meta will present these new options to users in the EU in January 2026. This follows a close dialogue between the Commission and Meta after the Commission found Meta in breach of the Digital Markets Act and issued Meta a <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_25_1085\">non-compliance decision related to Meta&#8217;s \u201cconsent or pay\u201d model<\/a> in April 2025.<\/p>\n\n\n\n<p><strong>TikTok usage risks in the EU:<\/strong> The Dutch AP urges users and organisations to carefully consider whether they wish to continue using TikTok and other services that transfer personal data to countries outside the EU, including China. The Irish data protection authority DPC has previously ruled that this transfer is in breach of the GDPR. In addition, the Irish court <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/ap-waarschuwt-gebruikers-tiktok-blijft-persoonlijke-gegevens-naar-china-sturen\">required TikTok to better inform users on data processing activities<\/a>. Users can still decide whether they want to continue using TikTok under these circumstances. If not, they can (temporarily) delete the app or deactivate an account.<br><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>E-commerce user data As a general rule, users should have the option to engage with e-commerce websites, including the ability to make purchases, without creating an account. In such cases, the EDPB recommends that e-commerce websites offer a choice: either a &#8216;guest&#8217; mode, allowing users make purchases without creating an account, or the option to [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11392,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,129,100,122,58,79],"class_list":["post-11425","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-consumer-data-protection","tag-cookies","tag-data-subject-access-requests","tag-gdpr-compliance","tag-international-transfers"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-150x150.jpeg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-300x200.jpeg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-768x512.jpeg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1024x682.jpeg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-200x200.jpeg",200,200,true]},"post_excerpt_stackable":"<p>E-commerce user data As a general rule, users should have the option to engage with e-commerce websites, including the ability to make purchases, without creating an account. In such cases, the EDPB recommends that e-commerce websites offer a choice: either a &#8216;guest&#8217; mode, allowing users make purchases without creating an account, or the option to voluntarily create an account. This approach minimises the collection and processing of personal data, and therefore aligns with the GDPR&#8217;s principle of data protection by design and by default. However, mandatory account creation can be justified in a limited number of cases, including for example,&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-150x150.jpeg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-300x200.jpeg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-768x512.jpeg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1024x682.jpeg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-200x200.jpeg",200,200,true]},"post_excerpt_stackable_v2":"<p>E-commerce user data As a general rule, users should have the option to engage with e-commerce websites, including the ability to make purchases, without creating an account. In such cases, the EDPB recommends that e-commerce websites offer a choice: either a &#8216;guest&#8217; mode, allowing users make purchases without creating an account, or the option to voluntarily create an account. This approach minimises the collection and processing of personal data, and therefore aligns with the GDPR&#8217;s principle of data protection by design and by default. However, mandatory account creation can be justified in a limited number of cases, including for example,&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#039;guest&#039; mode, or voluntary account creation - TechGDPR<\/title>\n<meta name=\"description\" content=\"E-commerce websites should offer a choice: either a &#039;guest&#039; mode, or the voluntarily creation of an account - EDPB\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#039;guest&#039; mode, or voluntary account creation - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"E-commerce websites should offer a choice: either a &#039;guest&#039; mode, or the voluntarily creation of an account - EDPB\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-22T09:26:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-22T13:05:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#8216;guest&#8217; mode, or voluntary account creation\",\"datePublished\":\"2025-12-22T09:26:19+00:00\",\"dateModified\":\"2025-12-22T13:05:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/\"},\"wordCount\":2085,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/image.jpeg\",\"keywords\":[\"Artificial Intelligence\",\"consumer data protection\",\"cookies\",\"data subject access requests\",\"GDPR Compliance\",\"International transfers\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/\",\"name\":\"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between 'guest' mode, or voluntary account creation - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/image.jpeg\",\"datePublished\":\"2025-12-22T09:26:19+00:00\",\"dateModified\":\"2025-12-22T13:05:05+00:00\",\"description\":\"E-commerce websites should offer a choice: either a 'guest' mode, or the voluntarily creation of an account - EDPB\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/image.jpeg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/image.jpeg\",\"width\":1280,\"height\":853,\"caption\":\"e-commerce\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#8216;guest&#8217; mode, or voluntary account creation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between 'guest' mode, or voluntary account creation - TechGDPR","description":"E-commerce websites should offer a choice: either a 'guest' mode, or the voluntarily creation of an account - EDPB","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between 'guest' mode, or voluntary account creation - TechGDPR","og_description":"E-commerce websites should offer a choice: either a 'guest' mode, or the voluntarily creation of an account - EDPB","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/","og_site_name":"TechGDPR","article_published_time":"2025-12-22T09:26:19+00:00","article_modified_time":"2025-12-22T13:05:05+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#8216;guest&#8217; mode, or voluntary account creation","datePublished":"2025-12-22T09:26:19+00:00","dateModified":"2025-12-22T13:05:05+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/"},"wordCount":2085,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg","keywords":["Artificial Intelligence","consumer data protection","cookies","data subject access requests","GDPR Compliance","International transfers"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/","name":"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between 'guest' mode, or voluntary account creation - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg","datePublished":"2025-12-22T09:26:19+00:00","dateModified":"2025-12-22T13:05:05+00:00","description":"E-commerce websites should offer a choice: either a 'guest' mode, or the voluntarily creation of an account - EDPB","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.jpeg","width":1280,"height":853,"caption":"e-commerce"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22122025-e-commerce-websites-should-offer-a-choice-between-guest-mode-or-voluntary-account-creation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 3-18 Dec 2025: E-commerce websites should offer a choice between &#8216;guest&#8217; mode, or voluntary account creation"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11425"}],"version-history":[{"count":11,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11425\/revisions"}],"predecessor-version":[{"id":11443,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11425\/revisions\/11443"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11392"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}