I found Deliveroo sending highly detailed location information to a marketing company(Braze) yesterday[0]. I can't remember every giving explicit consent for this and AFAIK under GDPR just covering this in a Privacy Policy is not enough. On the topic of this story it seems like a case of credential stuffing so it's not a breach in Deliveroo's systems. Do the requirements as a "Data Controller" still apply in such as…
> I can't remember every giving explicit consent for this and AFAIK under GDPR just covering this in a Privacy Policy is not enough. I don't believe Deliveroo is obligated to tell you who they send such information to. They are however obligated to tell you that they gather such information and, should they share it with a third party, ensure that said third party is GDPR compliant and sign a data processing agreemen…
Sounds like an issue to me.