I informed a country's DPA that a company was leaking millions of user IDs within DSA transparency reports. EU developer documentation + DSA text states PII must not be within this data multiple times, proving severe incompetency.
On the day of their final update, the company suddenly banned my account, losing access to a significant chunk of my online life as well as nearly a decade of daily conversations with friends and family.
From that day onward, daily DSA transparency reports were empty for weeks (down from thousands daily).
Eventually they resumed, and past files containing PII were replaced with user IDs removed.
Tried contacting NGOs like EFF and the DPA again, they won't help either due to my non-EU status or because of their own caseload.
The company's DPO & legal teams have been locking and ignoring all communication attempts for months, they don't have any contact point outside of zendesk.
I can't afford lawyers either.
What should my next steps be?
almosthere•1h ago
hn773746483•43m ago