Last week I received an email from Meta Plattforms Inc about their new ToS and Privacy Policy addressed to my first Name.
But I don’t have any accounts on any services from Meta Platforms (I deleted them a few years ago). Therefore I contacted the DPO and requested a copy of my personal data and asked them to delete it according to GDPR.
They told me that there is no account associated to my email, I should provide my account details to the account in question, which I don’t have. They are unable to help me with the data I provided and I should contact the irish or my local data protection authority and bring my claims before court.
So they obviously have at least my first name and my email address and refuse to comply with GDPR.
Has anyone had any simmilar experiences or any recommendations on my further actions?
I don’t have the time and money to sue Meta, but I will contact my local data protection authority.
Are you sure it wasn’t a phishing email? With stolen creds?
This was the sender email: notification@email.meta.com
And all links point to meta.com, so no phishing
Check the email headers. You can spoof a sender address
I know, already done. Looks fine
All good, just wanted to make sure since it wasn’t clear
Thank you anyways for the hint
Spoofing a sender while falsifying compliance with SP
DIF and DKIM are another matter entirely.OP, do you know if your email host performs these checks? (The popular webmail services do)
S/PDIF (Sony/Philips Digital InterFace) is an audio interface, perhaps you meant to refer to SPF (the Sender Policy Framework)?
Ahh yes, you are correct, I got mixed up!
:)
It is a gmail address
Then you are probably fine unless you’re a high value target. Gmail checks these, and any such bypass would not be burned on a common target.