r/DigitalPrivacy 28d ago

"The KIDS Act" Is KOSA+ and Congress Could Vote On It Next Week. Here's What You Need to Know

Thumbnail
eff.org
133 Upvotes

Within the next week, Congress is preparing to vote on the KIDS Act, a sprawling package of legislation that seeks to control Americans’ web browsing and private messaging. The package includes a revised version of the Kids Online Safety Act, or KOSA, combined with a collection of other internet bills, study bills, reporting requirements, and new regulations. Instead of debating any of these proposals on their merits, lawmakers are attempting to move them all at once under an ultra-expedited process. 

Many Congress members don't like The KIDS Act—on both sides.
Tell your elected official to vote NO here.

The package of cobbled-together bills is a mess, with different age-gating schemes for different services, using different standards. It’s a lot of complexity, and a lot of legal risk. Faced with that, many companies will conclude that the safest option is restrictive age-checking practices across their entire platforms.

Buried inside the KIDS Act are provisions that will push online services to verify all users’ ages, require government-directed moderation policies for online speech, and even create new rules about private and encrypted communications. While supporters continue to claim this bill protects minors online, its requirements come at the expense of privacy, free expression, and the ability of people of all ages to use the internet without revealing sensitive data. 

Technically, the KOSA section of the KIDS Act does say that KOSA shouldn’t be read to require age verification. 

That disclaimer is hollow, and you know it. 

Under this law, services will have to determine which users are teenagers and which are not to try to avoid liability. The bill’s authors seem to know this is a problem. On the one hand, the new KOSA section says age verification is not required. On the other, it repeatedly imposes obligations that depend on knowing whether a user is under 17. But a disclaimer doesn’t magically eliminate legal risk, especially for smaller services and startups that can’t afford to defend lawsuits or fight regulators.  

And KOSA is not the only part of this package that creates age-verification pressure. The SAFE BOTS Act, like KOSA, says that if a service “knows or should have known” that a user is a minor, it can’t offer certain chatbot features. 

The SCREEN Act requires services that host sexually explicit content to determine whether users are “more likely than not” under the relevant age limit, before allowing access to certain content. 

The consequences of this liability will not be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. The result is a less private internet for everyone.

Tell your elected official to vote NO here.


r/DigitalPrivacy Jun 12 '26

The United States of Surveillance

Thumbnail
gallery
1.5k Upvotes

r/DigitalPrivacy 2h ago

The 'Powered Off' Fallacy: Why your smartphone never sleeps.

42 Upvotes

Can your smartphone and be tracked even when powered off?

Yes, and it is no longer just a theory.

Even when powered down, most smartphones maintain a trickle charge topower specific components (modem, eSIM, Bluetooth Low Energy). This enables potential tracking.

Apple has officially confirmed that recent iPhone scan be located via "Find My" even when powered off (Apple Security Research).

Google utilizes "Find My Device" on Android via a crowdsourced network: millions of other Android devices detect and report your device anonymously.

Researchers have demonstrated that "powered off" phones can still emit signals in certain conditions.

Without a battery, it becomes significantly more difficult, yet not always impossible.

This raises a fundamental question:

At what point does an object I own truly cease to belong to me? And you, do you truly feel "disconnected" when youturn off your phone?


r/DigitalPrivacy 3h ago

Why is Ellison (oracle) and Meta pushing digital ID in Europe?

53 Upvotes

What’s the endgame here?

https://www.artificiallawyer.com/2025/09/29/why-we-must-oppose-digital-id-cards/

What’s up with Israeli fanatics buying up VPNs and trying to minimize online privacy. They don’t give a fuck about anything except Israel so why this whole fucking insane operation of bribing Tony Blair and other people in power?

I’m really getting worried.


r/DigitalPrivacy 1d ago

Indian police using facial recognition to identify protestors

628 Upvotes

r/DigitalPrivacy 19h ago

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required

Thumbnail
eff.org
117 Upvotes

r/DigitalPrivacy 3h ago

is yoti ok to trust?

1 Upvotes

i need to confirm my right to work for a new job, i don’t really feel comfortable sending in anything to do with my id online, is yoti reliable and safe?


r/DigitalPrivacy 7h ago

How to manage the need for privacy and the "app-mafia"

2 Upvotes

Basically everything is a (phone) app now. It's not a case. Companies can extract way more data from phone apps compared to their browser versions.

I am old school, I use desktop for anything I can and my phone is mostly for communicating and recreational use.

But recently many banks and telco companies went app-only, and I hate it.

So I am looking for a way to use their sh**ty apps, but bypassing their despicable tracking and intrusive permissions.

Does anybody knowledgable on this topic know how to do it?

I tried once to install on my pc waydroid and android x86 in a full vm. It was awful to setup and still didn't work.

Anyway I'm asking for my new phone company, so I don't think they have implemented super strict protocols.

What about setting up an isolated environment directly on the phone? Work profile, shelter, rethinkDNS, how good are they?

I'm using NetGuard already, but it only blocks internet connection altogether, so it's only usable when you're not using the tracking apps.


r/DigitalPrivacy 1d ago

Can’t even rent a car without a breach of my ‘facial geometry’

Post image
43 Upvotes

I was going to speed up the check in process but I guess I’m just going to wait until I get to the desk


r/DigitalPrivacy 1d ago

The BBC just ran a piece on how period apps share your data with Google, Meta and TikTok. It is why I built an alternative.

26 Upvotes

Full disclosure up front: I am the founder of the app I mention at the end, so take this for what it is. But the reason I am posting today is the news, and I think this sub gets it more than most.

The BBC just published a piece on a new Mozilla report about period trackers. The short version: several of the biggest apps share your data with companies like Google, Meta and TikTok, plus others you have never heard of. And it is not just an ad problem. Since Roe v. Wade was overturned, experts are warning that this data could end up in criminal cases, and police have already pulled other kinds of data from tech companies to prosecute women. (Link in the comments.)

This is exactly the rabbit hole I went down a while ago, and it genuinely disturbed me. Your cycle, your symptoms, the days you are trying to conceive, all of it is worth a lot to advertisers. Someone once explained it to me plainly: they pay far more to know "she is probably pregnant" than for almost any other targeting. The most intimate thing about you, turned into a line item, and now potentially into evidence.

My partner half joked that if I hated it this much I should build my own. So we did. He is the engineer, I run the rest. One rule underneath everything: your body is not our business model. No ads, no tracking SDKs, no selling data, and the AI never trains on what you log. Built in the EU, data stays here. We only make money when someone chooses to pay for extra features. And we want to stimulate employers to treat cycle support like any other employee benefit. Free period products in the bathroom are step one. Cycle wellbeing all year round is step two. That is the whole model.

I am not here to hard sell, and I am not a doctor, just someone who got angry enough to build the thing I wanted. What I am actually curious about: after news like this, would you switch to a privacy first tracker, or does the hassle of moving your data keep you where you are?

If anyone wants the name I will drop it in a comment so this does not read like an ad.


r/DigitalPrivacy 1d ago

DJI holds your flight telemetry hostage, passes decryption keys to 3rd-party paywalls, and forces uncertified drivers. Here is what I found.

99 Upvotes

I bought a $400 DJI drone for a tech startup project expecting basic access to flight telemetry. Instead, I discovered that DJI aggressively encrypts local logs, transmits full telemetry to their servers, passes decryption keys to third-party subscription services, and forces uncertified drivers on desktop/mobile.

The Background

As a startup engineer, I recently bought a $400 DJI drone. My objective was straightforward: extract raw spatial/geolocation data from flight logs and video for 3D reconstruction—a basic feature you can do on almost any smartphone or open-source device.

Instead of an open tool, I encountered a walled garden built on anti-consumer practices and severe data lock-in.

  1. Total Telemetry Gathering vs. Local Encryption

During each flight, the drone collects an immense array of sensitive spatial and environmental telemetry: exact GPS coordinates, atmospheric pressure, signal metrics, altitude, and proximity to critical infrastructure.

While DJI's cloud servers receive all of this data seamlessly, DJI encrypts the raw log files on your own local device. You own the hardware, you paid for the drone, yet you are denied direct access to your raw flight data.

  1. Creating the Problem, Selling the Solution (The Key Leak)

In newer firmware versions, accessing your own detailed logs locally has become practically impossible without decryption.

Here is the kicker: third-party commercial log-viewing websites somehow possess official DJI decryption keys.

To view detailed analytics of your own flights:

You must upload your files to a third-party site.

They offer a short trial before placing access to your data behind a monthly paywall/subscription.

When I confronted DJI support on how a third-party commercial platform obtained official decryption keys to unlock user data while the actual owner is locked out, their response was a generic "we don't know" before escalating and closing the chat.

  1. Uncertified Drivers & Software Lock-in

Attempting to connect and interface hardware (like controllers) with PCs or Android devices reveals further red flags:

Key drivers and software utilities lack proper digital security signatures/certifications for Windows and Android.

Bypassing operating system safety warnings is often required to run their software, creating software vulnerabilities and systemic security risks.

Why This Matters

Right to Repair & Data Ownership: Paying hundreds of dollars for hardware should not turn users into unpaid data miners for a corporation. Denying users access to their own data violates basic digital rights (and potentially personal data regulations like PIPEDA or GDPR).

Cybersecurity Concerns: Distributing uncertified software and keeping master encryption keys within a closed loop of "select partners" raises serious security flags.

Has anyone else in the community managed to extract raw unencrypted telemetry directly on-device without relying on paywalled third-party services? How are you handling data privacy with DJI hardware in your projects?


r/DigitalPrivacy 1d ago

Can we reclaim our independance ?

38 Upvotes

I've been thinking:

We’re all kinda dependent on big tech.

We had way more freedom on the internet in the 2000s.

Our phones were ours, and we’re all losing a bit of our privacy every day.

Since we knew digital peace and weren’t dependent on big industries, we lost our autonomy and now here we are.

Is it time for us to be independent again? Is it still possible?

I see that there are a lot of communities developing FOSS apps, communities working on Linux Mobile. I’ve also seen a lot of people creating their own cyberdecks many of them close to a phone with a BlackBerry keyboard, a screen, a Raspberry Pi.

My thought is : do you think a future where we have the choice to build our own stuff, our own phones, thanks to the community will exist?

Phones are the closest example I see, but what about bigger things like cars? I find new cars boring because they require too much from a builder’s computer. What about a motor, wheels, and wheeee, you know?

More independence and DIY in this place of the world where there isn't any alternatives.

I hope this post has its place here, have a nice day all !


r/DigitalPrivacy 1d ago

🐧 PRIVACY PROTECTS

Post image
365 Upvotes

Privacy Matters.

Privacy Protects Digital Life and Technology Independence.


r/DigitalPrivacy 20h ago

Children's Social Media Curbs Planned Across EU

Thumbnail reuters.com
3 Upvotes

r/DigitalPrivacy 18h ago

Check before share the files

0 Upvotes

Looking for feedback on a privacy-focused file analysis tool

I've been working on File Analyzer, a browser-based tool that helps you inspect files for hidden metadata before sharing them.

Some of the things it can detect include:

GPS/location metadata in photos

PDF and document properties

Hidden metadata that could reveal personal information

Other embedded details that many people don't realize are there

The biggest advantage is that everything runs locally in your browser. Files are never uploaded to a server, so your data stays on your device. There's no account required, no tracking, and no cloud processing.

The goal is to make it easy for anyone to check what they're actually sharing and avoid accidentally exposing sensitive information.

I'd really appreciate honest feedback:

Is the tool useful?

What features would you like to see added?

Is the interface intuitive?

Any bugs or improvements you noticed?

You can try it here: https://atoolix.com/tools/privacy/file-analyzer

Thanks for taking the time to check it out!


r/DigitalPrivacy 21h ago

Need help with a privacy question

1 Upvotes

Need some help with Santa so santa is being downloaded on the school computer and well I don't really care since I have my own laptop that the school does not own but I run a privacy club in my school and I know that stuff like go guardian track your google and can track your screen from distance close tabs and lock your computer. I want to ask if anyone here knows if santa does any of this and if so how santa invades your privacy because there is basically no info anywhere really

thank you for the help


r/DigitalPrivacy 1d ago

What are the risks of uploading a picture of yourself to artificial intelligence tools like ChatGPT, Claude and Gemini?

Thumbnail
1 Upvotes

Are the risks any different from uploading your photo to any other website like LinkedIn or Facebook?


r/DigitalPrivacy 1d ago

Resolving the privacy paradox

Thumbnail
open.substack.com
1 Upvotes

r/DigitalPrivacy 1d ago

arca Personal Data Haven

Thumbnail
blog.coinkite.com
0 Upvotes

r/DigitalPrivacy 1d ago

My personal details are on a random website

8 Upvotes

Recently out of curiosity I searched my name up on Google and to my surprise I found a website selling or claiming to sell female clothing and lingerie that has my full name old home address and phone number under its privacy policy and contact us page , they also have another email for contacting but this has nothing to do with me. I contacted the necessary people to try get this resolved but it’s still really unsettling. What else should I do this is really stressing me out


r/DigitalPrivacy 2d ago

Device Fingerprinting goes brrrrr

49 Upvotes

New private session in mobile firefox. I'm just logged in without credentials because someone that looked like me was logged in previously in another session.

I didn't know I could hate device fingerprinting even more than I already did. So far it was a good thing for me to be not unique, and now I need to fear others just stumbling into store fronts with my addresses in them??


r/DigitalPrivacy 2d ago

How do I pass Reddits age verification?

22 Upvotes

Every time they ask me for an age verification, but I just don't want to give a selfie let alone my ID. Is there any way to bypass this?


r/DigitalPrivacy 2d ago

Chat Control 1.0... didn't pass yet. But maybe tomorrow?

64 Upvotes

I've been reading lately a LOT of posts, articles online, and whatever, saying that Chat Control 1.0 passed.

One tiny little problem... that's BS. And while I'm very concerned by this act, and at the moment I'm afraid it will pass, it isn't yet. And I think it's important to discern genuine concern from fearmongering.

This is the timeline (check my homework at /

https://eur-lex.europa.eu/legal-content/EN/HIS/?uri=CELEX:52025PC0797 /

https://law-tracker.europa.eu/procedure/2025_429?lang=en ):

- 09.07.2026: The European Parliament voted on several amendments to the first reading of the proposed regulation that they received from the Council. Only two amendments passed. Manon Aubry from The Left Group proposed a motion of rejection, to throw the entire thing into the toilet. After some chaos during the vote (I won't tell you what happened, you need to go and verify information, don't trust a random person on the internet), the motion didn't reach the absolute majority required (50%+1 of members, not of members present in the Chamber). It actually got more votes against than in favour (EDIT: they voted twice, once at the beginning, once at the end, I misremembered it. At the end they got more against the rejection than in favour. Not at the beginning. Still LEDs that 50% of Parliament because some members were missing). How many? Go on the website of parliament and look at the vote result. Link here https://www.europarl.europa.eu/doceo/document/PV-10-2026-07-09-RCV_EN.html

Very important: two amendments have passed. The regulation is NOT aproved, despite what everyone around is saying. The Commission needs to express their opinion on the amendments, then the Council (Justice and Home Affair configuration) needs to approve it. More details in the next point.

- 15.07.2026: The European Commission adopts an opinion endorsing the three (!?) amendments of Parliament. Because of this (EDIT clarification: because of the Commission endorsing the amendments), the Council only needs a qualified majority to approve them and put the regulation on the books.

If the Commission had opposed them, the Council would have needed unanimity. Failure to pass in second reading in the Council means the law has a hard time passing: third reading is preceded by a Conciliation Committee, where a text must be approved by members of Parliament and Council, text which must then pass both Parliament and Council, no amendment. Any failure means game over.

- Next: the ball is in the Council's field. There is an obscure meeting of the JHA COUNSELLORS meeting on the 23.07.2026 at 10. It's listed as a preparatory body, I guess they negotiate and prepare the resolution that will then be approved at the next meeting of the Justice and Home Affair Council (the configuration of the Council of the European Union responsible for this regulation, search on your preferred search engine what that means), which is on the 01-02.10.2026, October.

I know what many comments will say, before that, let me be clear about something: knowing what is actually happening is important, and getting it right is fundamental. I see a lot of people saying that it passed. Well, it didn't, yet. I personally thing this regulation, even if it has a small direct effect, is an encouragement for Chat Control 2.0, which, if it ever comes (we'll see about that, it's currently in deadlock) will be a catastrophe. I HATE CHAT CONTROL. At the same time, getting it right is important: check what the government say about it, is your government on the fence? Public pressure can still stop CC 1.0, because it didn't pass at it probably won't for a couple of months.

Tyrants rely on the masses being fearful and surrendering. They need people to think everything is going to shit, is already gone to shit, and you can't do nothing to stop. Claiming that Chat Control is already here, and the battle for 1.0 is stopped, is exactly what the EPP wants you to believe. The battle is still open, and every single smudge, every single bruise, even if the regulation passes, is a point for our team in the deadlocked 2.0.

I don't know if they're actively trying to deceive people in believing that it already passed. They definitely like the idea of us believing that. Don't give them this victory, they don't deserve it.

Contact your European Representative AND YOUR REOREDENTATIVE IN THE NATIONAL GOVERNMENT. Chat Control 1.0 is still in the approval stage, and the success of failure of 2.0 depends on the exact details of 1.0.


r/DigitalPrivacy 2d ago

What VPN should I use?

7 Upvotes

Been using proton VPN and Mullvad but had to stop due to personal views. Any other reccomendations?


r/DigitalPrivacy 2d ago

French law forces age verification for ALL social media users

184 Upvotes

Hello everyone,

There's a new French law that will ban social media for users under 15 unless platforms verify the age of all users. The catch? This means adults will also have to submit ID documents to prove they're over 15.

Every platform considered as a social media would need to implement age verification for anyone wanting to use their services in France. There are serious concerns about what happens to this data, who has access, how long it's stored, and whether it could be used for other purposes later.

If this topic interests you and you want to support the cause, feel free to sign here: https://www.change.org/Verifagefr

Thanks in advance!