#LegitimateInterest

Ben Companjen 🟥bencomp@code4lib.social
2025-12-03

"We’re contacting you based on a legitimate interest in sharing solutions relevant to your role."

This was rightfully classified as spam, but it's the second email from someone pretending not to be spammers. It angers me.

#GDPR #spam #LegitimateInterest

Nicola Fabianonicfab@fosstodon.org
2025-11-20

📝 Digital Omnibus: Cookies, GDPR and AI Training - New European Privacy Rules

Analysis of GDPR and ePrivacy changes in the Digital Omnibus: new Art. 88a, automated consent signals, legitimate interest for AI training, and criticism from digital rights organizations.

🔗 nicfab.eu/en/posts/digital-omn

#EURegulation #AITraining #LegitimateInterest #FundamentalRights #DigitalOmnibus #AI #GDPR

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-20

@Em0nM4stodon +9001%

My website is #cookie- and #tracker-free and any potential #logging on the #hoster site is covered by "#LegitimateInterest" like fending off #DDoS attacks and tracing as well as twarting #hacking attempts.

PPC Landppcland
2025-11-08

Ecuador establishes framework for legitimate interest data processing: Ecuador's data protection superintendent issues comprehensive regulations on November 7 requiring documented balancing tests before companies can process personal data based on legitimate interest. ppc.land/ecuador-establishes-f

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-12

@purplepadma #KYC Is the #IllicitActivity!

  • Ask the people who got kidnapped for their #Bitcoin...

#Anonymity is a #HumanRight and #BlueSky has no #LegitimateInterest in demanding an #ID or any other proof of age!

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-25

@walkinglampshade @jrredho @fj It's basic #InfoSec, really:

Thus #Signal fails at protevting #Journalists and theor sources because they do have that data and can be #subopena'd for it if they don't already provide #BulkSurveillance & #LawfulInterception #API|s to comply with #CloudAct. (Or are you guys so naive and believe @Mer__edith will risk dying of old age in jail for non-paying users?)

  • This entire "thread vector" just doesn't exist with #XMPP+#OMEMO nor #PGP/MIME!

And if you believe "this won't ne used/abused me because I'm from 'Murica!" and point at #ANØM as an example, then you really ignored all tze #Cyberfacism since 9/11…

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-14

@Avitus @lispi314 @lauren

#TLDR: @signalapp HAS NO "#LegitimateInterest" TO DEMAND A #PhoneNumber (or any #PII for that matter) TO BEGIN WITH!

  • #BDSG literally bans such unnecessary data collection per law!
Kevin Karhan :verified:kkarhan@infosec.space
2025-02-14

@lispi314 @lauren Not.only.that, but with a #PhoneNumber it makes it trivial to get details from @signalapp targeting a known individual.

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-03

@tauon

1) #CloudAct is just #CyberFacism, look it up!
en.wikipedia.org/wiki/CLOUD_Act

-

2) @signalapp 's #Server code is proprietary and since it's centralized we can't trust that the code they release is what's running on their backend!

-

3) #Signal still demands #PhoneNumbers which are #PII either by association (#Number => #ICCID = #SIM = #IMSI => #IMEI => Location Data as I explained beforetwice) or mandatory #KYC / #ID requirements (even on prepaid cards), which an increasing amount of juristictions do...

-

But don't take my word for it.
youtube.com/watch?v=tJoO2uWrX1M

2024-12-27

First the #LegitimateInterest loophole around literally any #cookie consent and now more and more pages ask you to give up your privacy or pay a monthly fee to almost have no profiling and almost no adverts.

I really wonder why the @EUCommission is so chill with methods like this?

Maybe theyre too busy pushing out the next skewed legislation in their DMA wars?

The frontpage of spiegel.de - you either get the choice of allowing full tracking, personal nation and profiling for adverts or you become an "ad free" user that pays a monthly fee.
2024-12-24

“Legitimate interest” -

Die! x10k x10k x10k x…

I don’t boost posts promoting websites that lead me down a ‘Legitimate interest’ garden path

#LegitimateInterest

2024-12-16

📢 @EtienneDrouard: "Scraping of data and training AI should be compatible with the #GeneralDataProtectionRegulation and #LegitimateInterest. This means protecting people, not asking for their consent."

Session on #consent and #legitimateinterest at #dma conference. Speakers include @CR_UK. Audience was asked - who has read GDPR?

Kevin Karhan :verified:kkarhan@infosec.space
2024-10-15

@frodo @evacide @monocles

I don't compromise on #ITsec, #InfoSec, #OpSec and #ComSec.

If I were to use #Signal or #Threema or #Telegram or #SimpleX or whatever shit messenger is trendy, I'd indirectly vouch for it and endorse it.

Trust must be earned, and @signalapp didn't even bother to do basic design considerations:

  • All their "but #Metadata" #FUD is horseshite when they demand #PII like a #PhoneNumber and are openly able and willing to discriminate and/or restrict service solely based off said info they have NO "#legitimateInterest" in demanding at all!
Kevin Karhan :verified:kkarhan@infosec.space
2024-09-21

@privacyint Furthermore your website contains #Cloudflare #Cookies & [malicious per concept] #JavaScript, which has no "#LegitimateInterest" to be there.

Please reconsider your #TechStack AND the opening, cuz 40k p.a. won't get you a legal consultant except #remote or part-timer...

NoScript showing cloudflareinsights.com as blocked JS code on pricacyinternational.org
Kevin Karhan :verified:kkarhan@infosec.space
2024-09-10

@GrapheneOS @thomas @wonka Also I think the issues usually outweigh the benefits - at least when we look at individuals & devices owned by consumers vs. corporate #ITsec where locking down devices is seen as desireable!

  • It should be the sole discretion of the devices' owners whether or not such a feature should be used or accessible and it shpuld be disallowed to coerce people into "consenting" under threat of denied access.

Because for every "#LegitimateInterest" (i.e. #2FA #Authenticator) I can find a dozen reasons this "functionaloty" should be discontinued and considered malware.

Kevin Karhan :verified:kkarhan@infosec.space
2024-08-01

Whoever at @EUCouncil decided to install #ClownFlare-like, #ableist bs like this deserves to get fired!

Espechally since there is no "#LegitimateInterest" for blocking @torproject / #Tor users from accessing i.e. press releases anonymously!

FIX THAT SHIT - NOW!
consilium.europa.eu

#noJS

Checking your browser before accessing a GSC Managed Website

Please turn JavaScript on and reload the page.
Kevin Karhan :verified:kkarhan@infosec.space
2024-06-18

@dangillmor @eff Yes, but also acknowledge obvious misguidings.

2024-05-28

Dammit.

There is no "#LegitimateInterest" for spying on me while I read something, dear internet.

If in a library someone would try to go through my purse while I read a paper .. that would end very badly for that person.

Maby the anonymus ad-people of #Cookiedom should get their fair share of being beaten up too.

🤕

Kevin Karhan :verified:kkarhan@infosec.space
2024-05-26

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst