Good Faith and Respect for the GDPR are not a Lawful Basis
This blog explores why and how mission-driven platforms built on sensitive data mistake their good intentions for "good enough" data protection compliance. Inspired by a true story.
@giancarlor_photo on Unsplash
Recently I found myself asking a technology company some hard questions:
How it processed personal and special category data, and
What the lawful basis was for a new AI feature built on top of it.
This blog post isn’t about them. The pattern is bigger than any one company, and if you work in privacy, I am sure you will seen it too.
Long story short, they maintained that:
They were compliant with the GDPR.
They worked closely with and had great respect for the ICO.
They also had deep appreciation and respect for the people using the app.
The work they did mattered greatly to them, and I may have misunderstood the AI feature.
I have a lot to say about each, but I will limit myself to the below:
Their privacy policy, including updates following my communication, didn’t address the lawful basis question and neither did their response.
Respect for the ICO is neither here nor there – what you think about a regulator makes no difference to compliance.
Being the “good guys and gals” doesn’t mean you’re excused from the hard data protection questions.
In fact, the more sensitive data you process (here, it was health and sometimes information about sexual orientation), the more important it is you ask the hard questions and have a compliant answer for them.
Belief in compliance isn’t the same as actual compliance. Doing good is not the same as doing it lawfully either.
Vulnerable People Raise the Compliance Bar
It’s very easy for any one of us to suddenly become a “vulnerable” person for GDPR purposes.
I define a vulnerable person as someone who has been through something emotional or deeply personal, making them more volatile in their decisions. This person is likely to make these decisions based on the emotion at the moment rather than a logical decision-making process. For example:
A tired parent who hasn’t had more than 2 hours of consecutive sleep in days and is looking for baby sleep solutions.
A woman who has miscarried and is being sent marketing material by a baby loss charity asking her to make a donation.
A person who has a gambling addiction and sees ads that encourage them to gamble.
A well-off person whose investments suddenly take a nose dive and the person loses money.
Any company developing apps for users like these must be aware of data protection laws and follow them; not just “respect” them in principle.
The mission itself, as noble as it can be, does not earn anyone goodwill on compliance. Imagine a surgeon who's brilliant in theatre but never bothers with consent forms. Saving lives doesn't make the paperwork optional.
I am not saying it’s fair. The law can be an ass,* but it’s the law until someone changes it.
As my questions pertained mainly to my personal data, the discussion quickly ended because the rest was, or would have been, a freedom of information request which a private company does not need to answer.
But why wouldn’t you answer if you could, for the sake of your mission, hard work and transparency, if you did have the answers and compliance evidence? All it would have taken is: “the lawful basis is X; we did / did not do a data protection impact assessment (DPIA); that’s all from us.”
Consent is not Stretchable
The lack of confirmation of the lawful basis for the AI feature was where I really struggled to let go. You can’t safeguard what you don’t lawfully process. Health information in the AI machine is just that.
Users who sign up for one purpose (peer support, community, connection) cannot give explicit Article 9 consent for their special category data to be repurposed, especially when AI features get bolted onto platforms whose original terms never contemplated them.
"You used the app" is not a lawful basis for everything that follows.
The worst I saw was their privacy policy which said, paraphrasing: “We don’t collect special category or criminal offence data, but you can give it; if you do, you agree it’s visible and useable.”
This is the organisation passing the compliance burden onto people themselves, which is neither what the law expects, nor what companies should do. Not least of all because nobody reads privacy policies and because it would be much harder on the team to show compliance by:
Having a dedicated explicit consent mechanism and records.
Completing what could be a long and tough DPIA, which might transpire risks they don’t want to see.
Signing off these risks, knowing someone somewhere might complain or be unhappy.
If you leave this to the Product team, you’re asking them to mark their homework. It’s expected that they will say of course that the mission justifies the risks.
But if you ask an independent DPO, you may actually get an objective view and some recommendations how to make this compliant.
The GDPR as a Communication Problem
My query was first handled by the customer service team, then passed to Product (I can't confirm this, but I'm confident) once the questions got more technical. And that, in a sentence, is the problem: data protection was treated as something to be communicated rather than something to be governed.
"You don’t understand the feature" is not an answer to a question about lawful basis. I'm perfectly willing to accept that I misunderstood something — but if I did, why could nobody explain it?
A team confident in its compliance can point to the legal basis, the assessment, the records. A team that mistakes confidence for compliance can only reassure you that intentions are good.
This is the same problem I raised earlier, wearing different clothes.
Ask a Product team whether its own feature is compliant and you're asking them to mark their own homework. Of course the mission justifies the risk — they built the thing for the mission.
When the people who designed the processing are also the people certifying it’s lawful, subjective opinions stand in for analysis. The answers come back well-meaning but untested.
An independent DPO exists precisely to break that loop. Not to be the department of "no," but to ask the questions the mission makes it uncomfortable to ask, and to insist on an answer that survives contact with the law rather than with the team's self-image.
None of this means the company was acting in bad faith. I don't think it was; I am not saying it’s non-compliant. That's rather the point. Good faith was never the thing in question — a lawful basis was. And believing you're compliant, however sincerely, is not the same as having checked.
* Charles Dickens, Oliver Twist.