Tech News : EU Renews UK Data Adequacy Decisions Until 2031

The European Commission has renewed its decisions allowing personal data to flow freely between the EU and the UK, confirming that the UK’s data protection framework continues to meet EU standards despite recent legal changes.

Applies To Two Frameworks

The decision, announced on 19 December 2025, extends the EU’s existing data adequacy arrangements with the UK for a further six years, until December 2031. It applies to two parallel frameworks, one under the General Data Protection Regulation and another covering law enforcement data under the Law Enforcement Directive. Together, these decisions determine whether personal data can be transferred from the European Economic Area to the UK without additional safeguards or legal mechanisms.

What Data Adequacy Means In Practice

Under EU law, personal data can only be transferred outside the EU and EEA if the receiving country provides an “adequate” level of protection. Adequacy decisions are adopted by the European Commission and confirm that a third country’s legal and regulatory framework offers protections that are essentially equivalent to those guaranteed under EU law.

For example, when an adequacy decision is in place, organisations can transfer personal data without needing to rely on alternative tools such as standard contractual clauses, binding corporate rules, or case by case risk assessments. For businesses, public bodies, and digital services, this significantly reduces legal complexity, compliance costs, and operational friction.

The UK first received adequacy decisions in 2021, following its departure from the EU. Those decisions were time limited and included a sunset clause, reflecting concerns about future regulatory divergence after Brexit.

Why The Renewal Was Not Automatic

The original UK adequacy decisions were due to expire on 27 December 2025 but, in June 2025, the Commission adopted a technical six month extension to avoid a legal cliff edge while it reassessed the UK’s legal framework. This review was triggered by the passage of the Data (Use and Access) Act, which amended aspects of UK data protection law.

The Act introduced targeted changes, including adjustments to how personal data can be used for research and charitable fundraising, alongside new requirements for organisations to operate clearer data protection complaints procedures. The UK government described the reforms as limited and pragmatic rather than a wholesale departure from GDPR, but they nonetheless required close scrutiny by EU regulators.

During the extension period, the Commission assessed whether the amended UK framework continued to meet the threshold of essential equivalence required under EU law. This assessment covered both general data protection under GDPR and the handling of personal data for policing and criminal justice purposes under the Law Enforcement Directive.

The Role Of EU Oversight Bodies

The renewal decision followed a formal process involving EU institutions and Member States. The European Data Protection Board, which brings together national data protection authorities across the EU, issued an opinion on the UK’s legal framework. Member States then gave their approval through the so-called comitology procedure, which allows national representatives to scrutinise and endorse Commission implementing decisions.

Sufficiently Aligned

The Commission concluded that the UK’s safeguards remain sufficiently aligned with EU standards, including in areas such as individual rights, oversight mechanisms, and restrictions on onward transfers of data to other third countries.

As with the original decisions, the renewed adequacy determinations include safeguards designed to monitor future developments. A review of how the arrangements are functioning is scheduled after four years, with the option to amend, suspend, or revoke adequacy if the UK diverges in ways that undermine data protection.

A Six Year Extension With Built In Limits

The renewed adequacy decisions will now run until 27 December 2031 and include a fresh sunset clause. This essentially means adequacy is not permanent and must be actively reassessed in light of legal, political, and technological changes.

From the Commission’s perspective, this structure balances continuity with control. It provides long-term legal certainty for organisations that depend on EU UK data transfers, while preserving the EU’s ability to intervene if standards fall.

For UK businesses, the extension avoids what many had warned would be a serious disruption. The UK is one of the EU’s largest data partners, with personal data flowing daily for purposes including trade, financial services, health research, cloud computing, advertising, and human resources management.

Economic And Operational Significance

Industry groups and legal experts have repeatedly warned that losing adequacy would impose substantial compliance burdens. Organisations would need to put alternative transfer mechanisms in place, reassess international data flows, and potentially redesign systems and contracts at short notice.

Previous estimates from UK industry bodies have suggested that the administrative cost of relying on standard contractual clauses and transfer risk assessments could run into billions of pounds across the economy. Also, smaller organisations, charities, and public sector bodies would likely be hit hardest.

The Commission explicitly highlighted these practical implications in its announcement. Henna Virkkunen, Executive Vice President for Tech Sovereignty, Security and Democracy, said the renewal “benefits businesses and citizens alike on both sides of the Channel”. She added that it “ensures the free flow of personal data between the EEA and the UK in full compliance with data protection rules while reducing costs and administrative burdens”.

Virkkunen also emphasised continuity for European organisations, stating that the decision allows companies to keep sharing data seamlessly with UK partners, supporting innovation, competitiveness, and trusted digital cooperation.

Law Enforcement And Justice Cooperation

The adequacy decision covering law enforcement data is particularly significant because it underpins data sharing between EU Member States and UK authorities for policing, criminal investigations, and judicial cooperation.

Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection, described the United Kingdom as “an important strategic partner for the European Union”. He said the adequacy decisions “form a central pillar of this partnership” by enabling both commercial exchanges and cooperation in the fields of justice and law enforcement.

McGrath added that the renewal reflects the Commission’s assessment that the UK’s legal framework continues to provide robust safeguards for personal data that remain closely aligned with EU standards, including in the context of recent legislative developments.

Ongoing Concerns And Future Scrutiny

It should be noted here, however, that while the renewal provides stability, it does not remove all uncertainty. Privacy advocates and some EU lawmakers have previously raised concerns about the UK’s approach to surveillance, data sharing with third countries, and the potential for future divergence from GDPR principles.

The four year review mechanism is intended to address these risks by allowing the Commission and the European Data Protection Board to reassess adequacy in light of concrete evidence rather than hypothetical concerns. Any significant weakening of protections could still result in suspension or revocation of the decisions.

For now though, it looks as though the Commission’s renewal signals confidence that the UK remains closely aligned with EU data protection standards, while retaining the ability to revisit that judgement if circumstances change.

What Does This Mean For Your Business?

The renewal confirms that the EU continues to see the UK as a trusted destination for personal data, despite political separation and limited legal divergence since Brexit. It removes the immediate risk of disruption to data flows that underpin everyday commercial activity, public services, and cross border cooperation. For now, the legal foundations that allow organisations to move personal data between the EU and UK without additional safeguards remain intact.

For UK businesses, this brings practical certainty. For example, companies operating across borders can continue to rely on existing systems, contracts, and data driven services without having to introduce costly transfer mechanisms or redesign operations at short notice. That stability is particularly important for sectors such as finance, technology, healthcare, research, and professional services, where routine access to EU personal data is fundamental rather than optional.

The decision also has wider implications beyond commerce. Continued adequacy supports cooperation between regulators, law enforcement agencies, and public authorities, ensuring that data sharing for policing, justice, and safeguarding purposes can continue without new legal barriers. At the same time, the inclusion of a sunset clause and a four year review reflects the EU’s ongoing caution, making clear that adequacy depends on sustained alignment rather than historical precedent.

Taken together, the renewal appears to strike a careful balance. In essence, it signals confidence in the UK’s current data protection framework while reinforcing that future reforms will be judged against EU standards. For businesses and other stakeholders, the takeaway message is that the current framework offers breathing space and legal certainty, but long-term stability will depend on how closely the UK continues to track core principles of EU data protection law.

Featured Article : How New Data Laws Will Affect You

Here, we look at how the Data Use and Access Bill is poised to reshape how our personal data is handled in the UK and we also review the significant changes it will bring, with implications for the NHS and beyond.

What Is the Data Use and Access Bill? 

Introduced as a cornerstone of the government’s plan to modernise data governance, the Data Use and Access Bill aims to overhaul existing data laws to improve economic growth, streamline public services, and enhance data security. Originating from a need to update the UK’s data legislation post-Brexit, the bill seeks to replace or amend elements of the EU’s General Data Protection Regulation (GDPR) to better suit national interests. The government claims that streamlining data usage and access could generate £10 billion of economic benefit. While the exact date of its enactment remains uncertain, the bill is expected to come into force within the coming year, subject to parliamentary approval.

How Will It Affect Our Data Handling? 

At the heart of the bill lies a fundamental shift in how personal data will be managed, accessed, and shared across both public and private sectors. For individuals, this means their data could be used more extensively to improve services, but it also raises concerns about privacy and consent.

In the context of the NHS, the bill mandates that all IT systems adopt common data formats, enabling real-time sharing of patient information such as pre-existing conditions, appointments, and test results between NHS trusts, GPs, and ambulance services. The Department for Science, Innovation and Technology (DSIT) estimates this could free up 140,000 hours of NHS staff time annually. The government envisions that by breaking down data silos, patient care will become more efficient, reducing medical errors and eliminating the need for repeat tests.

What About Patient Passports? 

Many people will have heard the term ‘patient passport’. As part of the UK’s NHS digital transformation strategy, this will be the centralised digital record that holds a patient’s comprehensive health information, including medical history, test results, and treatment notes. It’s hoped that this passport will allow healthcare providers to access a patient’s entire medical record seamlessly across different healthcare settings, whether at GP surgeries, hospitals, or through ambulance services. By consolidating data, the aim of patient passports is to reduce redundancies, prevent repeated tests, and improve continuity of care, ensuring clinicians can make quicker, well-informed decisions in critical moments.

Privacy Warnings 

However, privacy advocates have said that increased data sharing must be balanced with safeguards, including protecting patient passports from third-party access. For example, one key question they’re asking is who exactly will have access to this sensitive health data? The potential involvement of multinational tech firms (known for less-than-stellar transparency records) adds to this concern. For example, the Good Law Project (a key privacy advocate), has raised concerns about the NHS’s partnership with private data firms, especially Palantir, for managing the Federated Data Platform (FDP). They argue that without sufficient scrutiny, sensitive patient data could be open to misuse or could be shared without adequate patient control. The group has highlighted potential issues with the National Data Opt-Out (NDOO), which allows patients to restrict their data from being used outside of their direct care but doesn’t yet fully cover the FDP, sparking concerns that the NDOO’s limitations might not uphold patients’ data rights effectively.

Beyond Healthcare – The Police 

Beyond healthcare, the bill also proposes allowing police forces to automate certain manual data tasks. Currently, officers must log each instance they access personal information on the police database. Automating such steps could save an estimated 1.5 million hours per year, enabling officers to focus more on frontline duties. While increased efficiency is welcomed, civil liberties groups express concern over potential overreach and lack of oversight. Liberty, a UK human rights organisation, points out that “automation without accountability could lead to unchecked surveillance and data misuse.” 

Infrastructure Too 

The bill also introduces the creation of a digital “National Underground Asset Register,” requiring infrastructure firms to upload data on underground pipes and cables. This initiative aims to reduce the 600,000 accidental strikes on buried assets annually, minimising disruption from roadworks and construction projects.

A Digital Register of Births and Deaths 

Another aspect of the bill that’s drawn attention is a plan for the creation of a digital register for births and deaths. This register is proposed to simplify how vital records are accessed and managed, with the goal of moving away from paper-based systems. Creating a digital registry should, it’s argued, make it easier for individuals and relevant authorities to access official records, such as birth and death certificates. This digital transformation will also align with broader efforts to streamline public records, similar to electronic registration in other sectors.

Consumer Data 

The bill also discusses enhancing how consumer data (like energy usage or purchasing history) might be used to provide personalised services. For example, individuals could use data about their energy consumption to choose better tariffs, or purchasing data could inform tailored online shopping deals.

The Digital Revolution in the NHS 

The digital revolution within the NHS is a critical component of the broader objectives outlined in the Data Use and Access Bill. The government’s new 10-year strategy for the NHS in England aims to transform how patients interact with the health service, mirroring the convenience and accessibility offered by modern banking apps.

Currently, the NHS App’s functionality is limited due to the fragmented nature of patient records, which are held separately by GPs and hospitals. The government’s push for a single, unified patient record (the patient passport) is intended to bridge this gap. As Health Secretary Wes Streeting has stated, “Moving from analogue to digital is essential if we are to create a more efficient, patient-centred NHS” (BBC, 2023).

This shift is anticipated to speed up patient care, reduce redundant testing, and minimise medical errors. For example, immediate access to a patient’s full medical history could enable faster diagnosis and treatment decisions, potentially saving lives.

Open to Abuse? 

However, this digital transformation is not without controversy. Privacy campaigners, such as MedConfidential (a UK group advocating for privacy and transparency in health data usage), have expressed concerns that a single patient record / patient passport system could be “open to abuse” if not properly safeguarded. The involvement of private firms like Palantir, which has been awarded contracts to create databases joining up individual records, exacerbates these fears. As Sam Smith of MedConfidential says, “Handing over vast amounts of sensitive health data to companies with questionable track records poses significant risks to patient confidentiality”. 

Too Hasty? 

There has also been a public backlash against the perceived haste in implementing these changes without adequate consultation. A “national conversation” has been launched to gather public input, but critics argue that more needs to be done to ensure transparency and trust. As Rachel Power, Chief Executive of the Patients Association, said in a Patients Association Statement (2023): “For far too long, patients have felt their voices weren’t fully heard in shaping the health service. Any digital transformation must put patients at the heart of its evolution.” 

The Backlash and Privacy Concerns 

Despite assurances, scepticism remains. For example, the launch of the public engagement exercise was marred by inappropriate and irrelevant submissions, suggesting a disconnect between the government’s intentions and public perception. Also, reports about patient passports and usage of wearable technology (like Fitbits) to monitor health conditions remotely (to offer convenience and improved care) have also raised further privacy issues.

The British Medical Association (BMA) has expressed caution, stating that any move towards increased data sharing must be accompanied by “rigorous ethical standards and patient consent”. Critics fear that without proper oversight, personal health data could be exploited by private companies or misused by the state.

What About the Financial Aspects? 

Many have highlighted that the financial aspects can’t be ignored. For example, Prof Nicola Ranger, General Secretary of the Royal College of Nursing, has said (in an RCN Press Release, 2023) that any future plans will require “new investment” to be successful and that, “Digital transformation is not just about technology; it’s about investing in people and processes to make it work effectively.” 

Efficiency Gains 

With figures in mind, as highlighted earlier, key examples of the efficiency savings that the proposed Data Use and Access Bill could bring by streamlining data use across sectors (especially in healthcare and law enforcement) include:

– An estimated £10 billion boost to the economy (UK government), primarily through simplifying data access and by reducing administrative inefficiencies and fostering innovation across sectors.

– Saving NHS staff 140,000 hours by standardising data formats across NHS trusts, hospitals, and GPs. This saved time could then be redirected to patient care, improving treatment speed and accessibility for patients.

– Automation of routine data tasks, such as logging access to personal data in police databases, could free up 1.5 million hours annually for the police. This reduction in administrative tasks could allow more time for frontline work, which could strengthen law enforcement efficiency and public safety.

Balancing Efficiency and Privacy 

The implications of the Data Use and Access Bill extend beyond immediate efficiency gains. By fostering a more data-driven approach, the UK hopes to position itself as a leader in the global digital economy. The government asserts that modernising data laws will not only improve public services but also attract investment and innovation in sectors like artificial intelligence and biotechnology.

Public Trust Needed 

However, the success of this ambitious agenda hinges on public trust. Past experiences with data initiatives, such as the failed Care.data programme in 2016, have left a legacy of scepticism. That programme sought to share GP records for research and planning but was abandoned due to public outcry over privacy concerns.

As Prof Sir Nigel Shadbolt, co-founder of the Open Data Institute, has said: “Data can be a powerful tool for good, but only if handled responsibly. Building and maintaining public trust is essential for any data initiative to succeed.” 

Government Says Data Will Be Protected 

In response to these challenges, the government has pledged to implement strict data protection measures. The bill is expected to outline clear guidelines on consent, data minimisation, and purpose limitation. Additionally, there will be provisions for individuals to access, correct, or delete their data, aligning with principles established under GDPR.

However, critics argue that replacing or modifying GDPR protections could weaken individual rights. The Information Commissioner’s Office (ICO), the UK’s data protection authority, has urged caution. In a statement last year, the ICO said, “Any changes to data protection laws must not dilute the rights of individuals or reduce the accountability of organisations.” 

There is also the matter of international scrutiny to consider. As the UK diverges from EU data regulations, questions are being asked about the adequacy decisions that currently allow for the free flow of data between the UK and EU countries. Losing this status could have significant repercussions for businesses operating across borders.

Looking Ahead

The Data Use and Access Bill represents a significant step towards modernising the UK’s data infrastructure. While the potential benefits in terms of efficiency, economic growth, and improved public services are substantial, it seems clear that they must be carefully balanced against the imperative to protect individual privacy and maintain public trust. The coming months will be crucial as the bill progresses through Parliament and the national conversation unfolds.

What Does This Mean For Your Business? 

As the Data Use and Access Bill stands poised for implementation, it signals a transformation across public services, private enterprise, and individual rights. For the government, this legislation offers a pathway to harness data as a tool for national progress. The projected £10 billion economic boost, alongside potential time savings within the NHS and police forces, embodies the bill’s intent to streamline services, foster efficiency, and support sectors such as artificial intelligence and biotechnology. For the government, success means creating a framework where data is a secure, accessible resource that fuels growth, with implications not only domestically but also in terms of the UK’s reputation on the international stage.

For the public, the stakes are particularly high. On one hand, individuals stand to benefit from improved public services, from faster healthcare diagnoses and treatments to enhanced law enforcement capabilities. But this convenience comes with concerns around privacy, choice, and transparency. Past data initiatives like Care.data have shown that public trust can falter without robust consent frameworks and clear assurances on data security. Therefore, establishing transparency and giving individuals genuine control over their information are pivotal if the public is to feel safeguarded rather than surveilled.

In healthcare, the NHS’s anticipated transformation via digital records and patient passports could make a tangible difference in patient care given the estimation that it could free up over 140,000 hours in staff time to improve responsiveness and patient outcomes. However, this potential relies on more than just technical feasibility. For example, some would say that significant investment in staff training and infrastructure, as well as strict privacy protocols, are needed to prevent data misuse. Partnerships with private tech companies, which bring efficiency but sometimes questionable records on transparency, will need to be tightly regulated to ensure that patient data is handled responsibly and ethically.

The police, meanwhile, are expected to gain valuable hours through automation, potentially redirecting 1.5 million hours away from administrative duties to active police work, which many would welcome. However, without careful oversight, automated data access could risk privacy rights and lead to unintentional overreach, a concern for civil liberties advocates who call for accountability mechanisms to match this increased efficiency.

Third-party companies, particularly in tech, are also significant stakeholders in this bill. The opportunity to innovate and participate in data-driven public projects is substantial, yet comes with the responsibility to uphold rigorous privacy standards. For UK businesses, especially those relying on cross-border data flows, alignment with international data regulations will be critical. Divergence from GDPR raises questions about future adequacy agreements with the EU, impacting data-dependent enterprises if this alignment weakens.

As this ambitious bill moves forward, its success depends not only on the economic and operational benefits it promises but also its commitment to protecting individual rights and maintaining public trust. Establishing transparent, secure data frameworks that place privacy and consent at the forefront will be essential. With appropriate safeguards, the Data Use and Access Bill could indeed lead the UK into a new era of responsible data innovation. Without them, however, it risks compromising the very rights it aims to modernise.

Featured Article : Face-Recognition & Personal Data Concerns

Two Harvard students have developed a program which (when used with Meta’s smart glasses) can identify people without their knowledge, thereby highlighting a potentially serious privacy risk.

Why? 

In their report about their research, the two Harvard students, AnhPhu Nguyen and Caine Ardayfio, said their goal was “to demonstrate the current capabilities of smart glasses, face search engines, LLMs, and public databases, raising awareness that extracting someone’s home address and other personal details from just their face on the street is possible today”. 

Turning Glasses Into Facial Recognition Tools

As part of a project they called I-XRAY, the students developed a program that demonstrates the potential privacy risks of using AI with smart glasses like Meta’s Ray-Ban models.

Using their experimental system, the students have reported that they can stream live recordings from Meta’s Ray-Ban smart glasses (which are equipped with camera) to a computer, where AI is then used to spot when the glasses are looking at a face. Next, they are able to use AI and facial recognition tools, notably the PimEyes facial search engine while live streaming video from the glasses to Instagram, to positively identify strangers to whom the faces in the video belong.

Once the glasses detect a person’s face, the program can pull up images and publicly available personal information, including names, addresses, and more, within minutes.

The experiment shows how it’s possible to quickly access personal details of random individuals simply by walking past them and capturing their faces on camera, highlighting how invasive and dangerous this technology could become, if misused.

What Is PimEyes and How Can They Use It? 

PimEyes is a facial recognition search engine that allows users to upload an image of a face and find other images of that person across the web. It scans public databases, websites, and social media platforms to match facial features, making it possible to track someone’s online presence. In their experiment, the Harvard students used PimEyes to identify people in real-time by integrating it with Meta’s Ray-Ban smart glasses. As the glasses recorded video, PimEyes was used to find additional images and public information about individuals whose faces were captured.

Leveraged Today’s LLMs 

The students said that what makes their I-XRAY system so unique is that it operates entirely automatically, thanks to the recent progress in AI Large Language Models (LLMs). The system leverages the ability of LLMs to understand, process, and compile huge amounts of information from diverse sources, inferring relationships between online sources, such as linking a name from one article to another, and logically parsing a person’s identity and personal details through text. The students said that is this “synergy between LLMs and reverse face search” that “allows for fully automatic and comprehensive data extraction that was previously not possible with traditional methods alone”. 

Used ‘FastPeopleSearch’ To Get Other Personal Details From Names 

Worryingly, the students reported how their system (once they get an LLM-extracted name) can use a ‘FastPeopleSearch’ lookup to identify the person’s home address, phone number, plus their relatives. FastPeopleSearch is a free online tool that allows users to find personal information about individuals, such as addresses, phone numbers, and even family members or associates. It aggregates publicly available data from various sources to offer these details.

To use it, you go to the FastPeopleSearch.com website (if access is allowed – the website is using a security service – you may need a VPN), enter a person’s name, phone number, or address, and the tool will search its database to return matching results. It’s often used for background checks, though it raises privacy concerns due to the accessibility of personal information.

Doesn’t Have To Be Smart Glasses 

The students have highlighted that although Meta’s smart glasses have been used in their experiments, using their system, the same results could be achieved using just a simple phone camera. This means that anyone could use this technology to identify, track, or access personal information about strangers in real time, without their knowledge or consent. This raises serious privacy and security concerns, especially regarding stalking, harassment, or ‘doxxing’.

Are We Ready For This? 

As one of the student researchers in this experiment, AnhPhu Nguyen, said in an ‘X’ post about their findings, “Are we ready for a world where our data is exposed at a glance?”, with others commenting “Fascinating but Dystopian” and “looks like some govt entity will try and get hold of this”. 

How Can You Protect Yourself?

Despite demonstrating how easily facial recognition systems can be built using publicly available technologies and data, the Harvard researchers have also provided steps to help individuals protect their privacy – helpful links to do this can be found here. They explained how people can remove their data from major facial recognition and people search engines like PimEyes and FastPeopleSearch. Both PimEyes and Facecheck.id offer free services to opt-out, while major people search engines like FastPeopleSearch, CheckThem, and Instant Checkmate allow users to remove their information. Also, considering the potential financial havoc if a person’s US social security number (SSN) is leaked/part of a data dump, the researchers have recommended freezing credit and using two-factor authentication to prevent identity theft.

What Has Meta Said? 

Meta has reportedly said that the students’ experiment appears to involve them “simply using publicly-available facial recognition software on a computer that would work with photos taken on any camera, phone or recording device”, and has highlighted that its smart glasses are designed to comply with privacy laws, such as including a visible light to indicate when they are recording.

What Does This Mean For Your Business? 

This could be an important experiment in that it highlights just how vulnerable personal data can be in the age of advanced AI and facial recognition technology. While Nguyen and Ardayfio’s research shows the remarkable capabilities of current technologies, it also serves as a wake-up call to the broader public. The ease with which private details, such as names and addresses, can be extracted from something as simple as a passing glance on the street is a stark reminder of the privacy risks we face. The fact that these tools can be used not just with specialised smart glasses, but also with everyday devices like smartphones, makes the issue even more pressing.

For businesses, this raises important questions about the ethical and legal responsibilities of companies developing and deploying similar technologies. As facial recognition becomes more ubiquitous, organisations must navigate the fine line between innovation and privacy, ensuring that they not only comply with existing laws but also proactively address the potential misuse of their products. Meta’s response that their smart glasses are compliant with privacy regulations is likely to do very little to quell the growing concerns about how easily such technologies can be repurposed for invasive uses.

Looking ahead, as the use of AI and facial recognition continues to expand, so too will the need for stricter regulations and public awareness. Individuals, businesses, and governments alike must engage in a broader conversation about the balance between technological advancement and personal privacy to ensure that such powerful tools are not misused.

Tech News : Glassdoor Site Shows Real Users’ Names

It’s been reported that Glassdoor (the website that allows current employees to anonymously review their employer) posted users’ real names to their profiles without their consent.

What Is Glassdoor? 

By allowing users to register anonymously, Glassdoor is a website that allows current and former employees to anonymously review their companies and management. Founded in 2007 in Mill Valley, California, the platform is used for obtaining insights into company cultures, salaries, and interview processes. Its aim is to foster workplace transparency, enabling job seekers to make better-informed decisions about their careers by learning from the experiences of others.

Reported 

Unfortunately for Glassdoor, a user’s account (taken from her personal blog) of her recent negative experience with Glassdoor (following her contacting Glassdoor’s customer support ) has been widely reported in the press.

Added Name To Profile 

Following the lady (reportedly named Monica) sending an email to Glassdoor’s customer support that showed her full name in the ‘From’ line, Monica alleges that she then discovered that Glassdoor had updated her profile by adding her real name and location (the name pulled from the email), without her consent.

Users Leaving Glassdoor 

It’s been reported that the experience of Monica, identified as a Midwest-based software professional who joined Glassdoor 10 years ago, has now led to other members leaving the platform over fears they could also be ‘outed’. Not only could this be regarded as a breach of trust of the anonymity and privacy that users signed up with but could also have adverse employment consequences from employer retaliation.

Following reports of Monica’s experience in the media, it’s been reported that another user, identified as Josh Simmons, has also said Glassdoor added information about him to his personal profile, again without his consent.

Had To Delete Account 

It’s been reported that although Glassdoor’s privacy policy states “If we have collected and processed your personal information with your consent, then you can withdraw your consent at any time,”  Monica claims that she was not given this option, that Glassdoor stored her name, and that her only recommended option to remove her details was to delete her account altogether. Deleting also meant deleting her reviews.

Shared With Fishbowl

One of the complications of the case appears to be the fact that Glassdoor was integrated with Fishbowl (an app for work-related discussions), three years ago. This led to:

– Glassdoor now saying that it “may update your Profile with information we obtain from third parties. We may also use personal data you provide to us via your resume(s) or our other services.” 

– Glassdoor staff reportedly consult publicly-available sources of information to verify information that is then used to update users’ Glassdoor accounts, in order to improve the accuracy of information for Fishbowl users.

– Glassdoor updating users’ profiles without notifying the user, e.g. if inaccuracies are found, because of its commitment to keeping Fishbowl’s information accurate.

What Does Glassdoor Say? 

Glassdoor has issued a statement saying: “Glassdoor is committed to providing a platform for people to share their opinions and experiences about their jobs and companies, anonymously – without fear of intimidation or retaliation. User reviews on Glassdoor have always and will always be anonymous.” 

What Does This Mean For Your Business? 

A large part of the value of Glassdoor is the fact that users are willing to share their ‘honest’ views about their employers and managers. One of the key reasons they feel able to do so is the anonymity that they had during registration and the assumption that this would remain and that their privacy would be protected. However, if reports are to be believed, integration with and cross-pollination between Fishbowl and Glassdoor has led to policy changes and a new approach whereby a user’s details can be updated, allegedly without consent, and obtained from other sources thereby potentially meaning that users could be unmasked to employers.

The widely publicised stories of this allegedly happening appear likely to have damaged a key source of Glassdoor’s value – the trust that users have that their anonymity will be protected. This may explain why users are reportedly leaving the platform. This story illustrates how important matters of data protection are to businesses and individuals, particularly around privacy and consent, plus how risks can increase for users if aspects of data protection are damaged and changed.

The consequences of putting users in what could be described as a difficult and risky position could potentially be severe and/or long-lasting damage for Glassdoor’s business and reputation.

Tech Tip – Remove Hidden And Personal Data Before Sharing A Word Document

If you’ve got a desktop Word document that you need to share externally, and you want a fast way to check for (and remove) personal information, comments, or other hidden data that you might not want to distribute, Document Inspector can help. Here’s how to use it:

– Click on the ‘File’ tab.

– Click ‘Info,’ then click ‘Check for Issues,’ and select ‘Inspect Document.’

– In the Document Inspector dialog box, select the types of content you want to inspect.

– Click ‘Inspect.’ Review the results and click ‘Remove All’ for any types of hidden content you want to remove.