+### For individuals and organizations
-๐ฌ **Messaging communication:** Move your text message communication, audio calls, and video calls to [Signal](../../real-time-communication.md/#signal). Enable Signal's username and disappearing message features.
+
-๐ง
**Sensitive messaging communication:** If your threat model requires a peer-to-peer solution that doesn't need a phone number and transits over the [Tor network](https://www.privacyguides.org/articles/2025/04/30/in-praise-of-tor/), you might want to use an application such as [Cwtch](https://docs.cwtch.im/) or [Briar](../../real-time-communication.md/#briar).
+
-๐ง **Email communication:** Migrate to a privacy-respectful email service that offers end-to-end encryption, such as [Proton Mail](../../email.md/#proton-mail) or [Tuta Mail](../../email.md/#tuta). Make sure to inform yourself about the limitations of email privacy when using email for sensitive communication.
+- **[Messaging communication](../../real-time-communication.md):** Move your text message communication, audio calls, and video calls to a secure messenger like Signal. Enable features like Signal's username option and disappearing messages.
-
-
Service providers disclosure and compatibility
+- **Sensitive messaging communication:** If your threat model requires a peer-to-peer solution that doesn't need a phone number and transits over the [Tor network](https://www.privacyguides.org/articles/2025/04/30/in-praise-of-tor/), you might want to use an application such as [Cwtch](https://docs.cwtch.im/) or [Briar](../../real-time-communication.md/#briar).
-If you use your own custom domain name for email addresses, let the people you communicate with know what your service provider is.
+- **[Email communication](../../email.md):** Migrate to a privacy-respectful email service that offers end-to-end encryption, such as Proton Mail or Tuta. Make sure to inform yourself about the limitations of email privacy when using email for sensitive communication.
-That way, they will know that if they use a compatible service provider, they might benefit from end-to-end encryption protections for the content of their communications with you without requiring any additional steps. For example, this is the case when emailing from a Proton Mail account to another Proton Mail account, or from a Tuta Mail account to another Tuta Mail account.
+
+ Service providers disclosure and compatibility
-
+ If you use your own custom domain name for email addresses, let the people you communicate with know what your service provider is.
-๐ **Document storing and sharing:** Move away from privacy-invasive Google products to store and share documents. Instead, use an end-to-end encrypted solution such as [CryptPad](https://www.privacyguides.org/articles/2025/02/07/cryptpad-review/) for your collaborative documents and forms. Proton Drive also now offers collaborative documents with [Docs](https://proton.me/support/drive-create-edit-docs) and [Sheets](https://proton.me/support/sheets-getting-started).
+ That way, they will know that if they use a compatible service provider, they might benefit from end-to-end encryption protections for the content of their communications with you without requiring any additional steps. For example, this is the case when emailing from a Proton Mail account to another Proton Mail account, or from a Tuta Mail account to another Tuta Mail account.
-โ๏ธ **Storing files:** Choose an [end-to-end encrypted cloud](../../cloud.md) solution to store and share files. Always keep in mind that if a cloud service provider doesn't offer solid end-to-end encryption, then it can potentially access any of your stored files.
+
-โ **Surveys:** Stop using products such as Google Forms to poll your community. Instead, choose a privacy-focused alternative such as [CryptPad Form](https://www.privacyguides.org/articles/2025/02/07/cryptpad-review/#form) or [Framaforms](https://framaforms.org/abc/en/).
+- **[Document storing and sharing](../../document-collaboration.md):** Move away from privacy-invasive Google products to store and share documents. Instead, use an end-to-end encrypted solution such as [CryptPad](https://www.privacyguides.org/articles/2025/02/07/cryptpad-review/) for your collaborative documents and forms. Proton Drive also offers collaborative documents with *Proton Docs* and *Sheets*.
-๐ **Online calendar:** Your online calendar can be an important source of sensitive data. Moreover, you might store other's people data in it, or use it to share event links with collaborators. It's essential to make sure to use a privacy-protective solution for online and collaborative [calendars](../../calendar.md).
+- **[Storing files](../../cloud.md):** Choose an end-to-end encrypted cloud solution to store and share files. Always keep in mind that if a cloud service provider doesn't offer solid end-to-end encryption, then it can potentially access any of your stored files.
-๐ฃ๏ธ **Groups and events:** When organizing groups or events, be careful to choose platforms that are privacy-respectful and don't require participants to register personal information. Keep in mind that if you only use Facebook groups, you are contributing to people staying on a privacy-invasive platform. If you only use a closed Meetup group, you are demanding people create an account and share their sensitive data in order to join. Instead, use privacy-respectful platforms such as [Mobilizon](https://mobilizon.org/) or [LAUTI](https://lauti.org/) for groups and events, [Discourse](https://www.discourse.org/) for forums, or simply use your own website to advertise in-person events.
+- **Surveys:** Stop using products such as Google Forms to poll your community. Instead, choose a privacy-focused alternative such as [CryptPad Form](https://www.privacyguides.org/articles/2025/02/07/cryptpad-review/#form) or [Framaforms](https://framaforms.org/abc/en/).
-๐ช **Website analytics and cookies:** If you own a website for your organization or for your individual advocacy, make sure to remove from it any [tracking technologies](https://blog.mozilla.org/en/firefox/cross-site-tracking-lets-unpack-that/) that could be sending your visitors' data to Google, Facebook, or other advertising corporations. You shouldn't need a cookie banner for your website, because *your website shouldn't use any non-essential cookies*. If you really need website analytics, try using a privacy-respectful alternative such as [Umami](https://umami.is/) or [Plausible Analytics](https://plausible.io/).
+- **[Online calendar](../../calendar.md):** Your online calendar can be an important source of sensitive data. Moreover, you might store other's people data in it, or use it to share event links with collaborators. It's essential to make sure to use a privacy-protective solution for online and collaborative calendars.
-๐ **Smart devices:** Whether you are meeting with other advocates at home or organizing an event, make sure the location is free from Big Tech [surveillance devices](https://www.privacyguides.org/articles/2025/03/10/the-privacy-of-others/#notify-guests-if-you-are-using-a-smart-speaker) that might get easily forgotten. This may include a doorbell equipped with a camera, a smart speaker such as Amazon Echo, Google Home or Google Nest, or any other audio or video recording devices that is on. Physically unplug any such devices in the location *before* guests arrive. If you cannot unplug them, at least provide a proper warning to any guests before they enter the location and the device collects their audio or video data.
+- **Groups and events:** When organizing groups or events, be careful to choose platforms that are privacy-respectful and don't require participants to register personal information. Keep in mind that if you only use Facebook groups, you are contributing to people staying on a privacy-invasive platform. If you only use a closed Meetup group, you are demanding people create an account and share their sensitive data in order to join. Instead, use privacy-respectful platforms such as [Mobilizon](https://mobilizon.org/) or [LAUTI](https://lauti.org/) for groups and events, [Discourse](https://www.discourse.org/) for forums, or simply use your own website to advertise in-person events.
-๐ค **Usage of AI:** Be extremely careful if you are using AI platforms. Most current mainstream AI products will send at least some data or metadata to the company's remote server. This can create many privacy issues, ranging from mild to severe. Never use these products to upload data about another person without their *prior explicit consent*. Ideally, refrain from using any AI tools in your advocacy work entirely.
+- **Website analytics and cookies:** If you own a website for your organization or for your individual advocacy, make sure to remove from it any [tracking technologies](https://blog.mozilla.org/en/firefox/cross-site-tracking-lets-unpack-that/) that could be sending your visitors' data to Google, Facebook, or other advertising corporations. You shouldn't need a cookie banner for your website, because *your website shouldn't use any non-essential cookies*. If you really need website analytics, try using a privacy-respectful alternative such as [Umami](https://umami.is/) or [Plausible Analytics](https://plausible.io/).
-๐ผ **Candidates data:** If your organization hires people, be mindful of how you handle candidates' data. Try to select privacy-respectful solutions such as email communication instead of using commercial platforms that might share candidates' data with third-parties. Only request the minimum information required from applicants, and always delete all data you are no longer required to keep, as soon as you don't need it anymore.
+- **Smart devices:** Whether you are meeting with other advocates at home or organizing an event, make sure the location is free from Big Tech [surveillance devices](https://www.privacyguides.org/articles/2025/03/10/the-privacy-of-others/#notify-guests-if-you-are-using-a-smart-speaker) that might get easily forgotten. This may include a doorbell equipped with a camera, a smart speaker such as Amazon Echo, Google Home or Google Nest, or any other audio or video recording devices that is on. Physically unplug any such devices in the location *before* guests arrive. If you cannot unplug them, at least provide a proper warning to any guests before they enter the location and the device collects their audio or video data.
-๐ **Availability:** Make sure you or your organization is reachable outside the Big Tech ecosystem. If your organization only has a Facebook page, then people without a Facebook account cannot reach out to you. The same is true for other commercial social media. Instead, try to rely on a website you control yourself, or a social network page you can host yourself.
+- **Usage of AI:** Be extremely careful if you are using AI platforms. Most current mainstream AI products will send at least some data or metadata to the company's remote server. This can create many privacy issues, ranging from mild to severe. Never use these products to upload data about another person without their *prior explicit consent*. Ideally, refrain from using any AI tools in your advocacy work entirely.
-๐ **Social media:** Move away from commercial social media platforms. Mainstream platforms are almost all abusing their users' data. By keeping an account there, you are indirectly encouraging your followers to stay there as well, perpetuating the platform's abuse.
+- **Candidates data:** If your organization hires people, be mindful of how you handle candidates' data. Try to select privacy-respectful solutions such as email communication instead of using commercial platforms that might share candidates' data with third-parties. Only request the minimum information required from applicants, and always delete all data you are no longer required to keep, as soon as you don't need it anymore.
-While you may want to keep a minimal presence to advertise that you have now moved your activity to a more privacy-respectful platform, you should keep your engagement there to a minimum.
+- **Availability:** Make sure you or your organization is reachable outside the Big Tech ecosystem. If your organization only has a Facebook page, then people without a Facebook account cannot reach out to you. The same is true for other commercial social media. Instead, try to rely on a website you control yourself, or a social network page you can host yourself.
-Instead, migrate your advocacy work to better social networks that aren't abusing users' data, and encourage your followers to migrate with you. Choose and support a platform that is more aligned with your privacy values, such as [Mastodon](https://www.privacyguides.org/articles/2025/07/15/mastodon-privacy-and-security/) or any other open-source non-commercial applications connected to the [Fediverse](https://blog.elenarossini.com/fediverse-video/).
+- **[Social media](../../social-networks.md):** Move away from commercial social media platforms. Mainstream platforms are almost all abusing their users' data. By keeping an account there, you are indirectly encouraging your followers to stay there as well, perpetuating the platform's abuse.
+
+ While you may want to keep a minimal presence to advertise that you have now moved your activity to a more privacy-respectful platform, you should keep your engagement there to a minimum.
+
+ Instead, migrate your advocacy work to better social networks that aren't abusing users' data, and encourage your followers to migrate with you. Choose and support a platform that is more aligned with your privacy values, such as [Mastodon](https://www.privacyguides.org/articles/2025/07/15/mastodon-privacy-and-security/) or any other open-source non-commercial applications connected to the [Fediverse](https://blog.elenarossini.com/fediverse-video/).
diff --git a/docs/activism/toolbox/tip-protect-your-allies.md b/docs/activism/toolbox/tip-protect-your-allies.md
index 851efdc2..aabe2d97 100644
--- a/docs/activism/toolbox/tip-protect-your-allies.md
+++ b/docs/activism/toolbox/tip-protect-your-allies.md
@@ -16,6 +16,10 @@ It's important to develop an awareness of the data we collect and share ourselve
Here are a some examples of other people's data we might collect or share in the context of our privacy advocacy work, whether intentionally or inadvertently:
+
+
+
+
- [ ] Contact information (personal advocacy or professional work)
- [ ] Donation information (including legal names, emails, and phone numbers)
- [ ] Purchase information (including legal names and shipping addresses)
@@ -30,6 +34,11 @@ Here are a some examples of other people's data we might collect or share in the
- [ ] Chatbot logs
- [ ] Survey answers
- [ ] Shared documents
+
+
+
+
+
- [ ] Shared photos and images
- [ ] Legal names of people on work contracts or partnership agreements
- [ ] Home addresses of people on work contracts or partnership agreements
@@ -44,6 +53,10 @@ Here are a some examples of other people's data we might collect or share in the
- [ ] Screenshots of people's social media posts
- [ ] And so much more
+
+
+
+
## How to protect the data of others
Each time we collect data from others, we become its guardian. This isn't a small responsibility, and we should always treat the data of others as [toxic asset](https://www.schneier.com/blog/archives/2016/03/data_is_a_toxic.html).
diff --git a/docs/activism/toolbox/tip-refuse-to-participate.md b/docs/activism/toolbox/tip-refuse-to-participate.md
index 4a5fd850..94481456 100644
--- a/docs/activism/toolbox/tip-refuse-to-participate.md
+++ b/docs/activism/toolbox/tip-refuse-to-participate.md
@@ -28,33 +28,43 @@ When we use products that do not reflect the values we are asking people to adop
There are many ways to refuse to participate in privacy-invasive practices and platforms. Here are a few things you can try to do in your daily life, and in your privacy advocacy work:
-
+
-โ๏ธ Use an [ad blocker](https://www.privacyguides.org/en/browser-extensions/) everywhere you can.
+
-๐ช Categorically and obstinately reject all cookies, every single time.
+- Use an [ad blocker](https://www.privacyguides.org/en/browser-extensions/) everywhere you can.
-๐ท๏ธ Read apps' privacy-labels, and always favor applications that are the least intrusive.
+- Categorically and obstinately reject all cookies, every single time.
-๐ฆ Migrate [away from abusive Big Tech](tip-migrate-outside-the-surveillance-ecosystem.md) products and platforms.
+- Read apps' privacy-labels, and always favor applications that are the least intrusive.
-๐ฑ Try to move out or reduce your usage of [privacy-exploiting social media](tip-improve-your-social-media-and-build-resilient-communities.md).
+- Migrate [away from abusive Big Tech](tip-migrate-outside-the-surveillance-ecosystem.md) products and platforms.
-โ๏ธ Each time you install a new application or create a new account, go through the settings to disable all the privacy-invasive features you can disable. Make sure to disable any AI features as well.
+- Try to move out or reduce your usage of [privacy-exploiting social media](tip-improve-your-social-media-and-build-resilient-communities.md).
-๐
When requested to provide unnecessary personal information by a cashier or an online form, firmly refuse to provide anything that isn't legally necessary.
+- Each time you install a new application or create a new account, go through the settings to disable all the privacy-invasive features you can disable. Make sure to disable any AI features as well.
-โน๏ธ Inform yourself in advance about potential legal options to opt out of privacy-invasive technologies such as airport facial scanner.
+- When requested to provide unnecessary personal information by a cashier or an online form, firmly refuse to provide anything that isn't legally necessary.
-๐ชช Refuse to provide an official piece of ID online for purposes that aren't strictly necessary, such as government requests. Do not comply with intrusive [age-verification](https://www.privacyguides.org/articles/2025/05/06/age-verification-wants-your-face/) processes. Leave your account abandoned instead, or [delete it](../../basics/account-deletion.md) if you still can. Additionally, consider contacting your government representatives and the platform's complaint email to voice your privacy concerns about such practice.
+- Inform yourself in advance about potential legal options to opt out of privacy-invasive technologies such as airport facial scanner.
-๐จ [Report privacy violations](tip-report-privacy-violations.md) of your local privacy laws whenever you can.
+- Refuse to provide an official piece of ID online for purposes that aren't strictly necessary, such as government requests. Do not comply with intrusive [age-verification](https://www.privacyguides.org/articles/2025/05/06/age-verification-wants-your-face/) processes. Leave your account abandoned instead, or [delete it](../../basics/account-deletion.md) if you still can. Additionally, consider contacting your government representatives and the platform's complaint email to voice your privacy concerns about such practice.
-๐ Depending on your position, refuse to collect or share personal information on others without their prior, explicit, and informed consent (unless you are *legally* required). Be mindful of the software or third-party partners you use that could inadvertently share more information about others than you intended, such as [website telemetry](https://sebastiangreger.net/2014/02/privacy-aware-design-replacing-google-analytics/) or [social media buttons](https://www.tunnelbear.com/blog/why-we-created-our-own-social-media-buttons-on-our-website/).
+- [Report privacy violations](tip-report-privacy-violations.md) of your local privacy laws whenever you can.
-๐ค Never share the personal information of others with an AI chatbot or platform. Decline to do this in your work, whenever possible.
+- Depending on your position, refuse to collect or share personal information on others without their prior, explicit, and informed consent (unless you are *legally* required). Be mindful of the software or third-party partners you use that could inadvertently share more information about others than you intended, such as [website telemetry](https://sebastiangreger.net/2014/02/privacy-aware-design-replacing-google-analytics/) or [social media buttons](https://www.tunnelbear.com/blog/why-we-created-our-own-social-media-buttons-on-our-website/).
-๐ข Promote refusal around you. Inform others of their rights and responsibilities to opt out. Create accessible guides to educate the public on how they can also refuse to participate.
+- Never share the personal information of others with an AI chatbot or platform. Decline to do this in your work, whenever possible.
+
+- Promote refusal around you. Inform others of their rights and responsibilities to opt out. Create accessible guides to educate the public on how they can also refuse to participate.
diff --git a/docs/activism/toolbox/tip-report-privacy-violations.md b/docs/activism/toolbox/tip-report-privacy-violations.md
index 6b8b7d19..4f96c582 100644
--- a/docs/activism/toolbox/tip-report-privacy-violations.md
+++ b/docs/activism/toolbox/tip-report-privacy-violations.md
@@ -4,7 +4,7 @@ description: Submitting an official complaint for violation of your privacy righ
icon: fontawesome/solid/gavel
cover: activism/banner-toolbox-tip-report.webp
---
-Once you are [informed on your local privacy laws](tip-know-your-privacy-laws.md), it's important to get familiar with the process to report violations of the law. Submitting an official complaint is often simple, and can have a significant impact both for yourself and for your community.
+Once you are [informed on your local privacy laws](tip-know-your-privacy-laws.md), it's important to get familiar with the process to **report violations of the law**. Submitting an official complaint is often simple, and can have a significant impact both for yourself and for your community.
Here's why and how you should report violations of your local privacy laws:
@@ -21,18 +21,11 @@ This tip cannot cover each regulation individually. There will be variations for
For many if not most privacy regulations, there isn't a mechanism to systematically audit every single organization collecting data from people located in its jurisdiction.
-Unless the enforcing authority decides to investigate an especially important abuse, the process often relies on individual complaints reporting violations of **data subject** rights in order to trigger an investigation.
-
-
-
What is a data subject?
-
-Different laws might use different terms for this. Sometimes, a regulation might simply refer to a *person*, an *individual*, a *consumer*, a *patient*, or a *customer*. Other times, the equivalent expression used will be a *data subject*. A data subject is simply anyone from whom personal information is collected by an organization. Data subject will be used as an umbrella term on this page.
-
-
+Unless the enforcing authority decides to investigate an especially important abuse, the process often relies on individual complaints reporting violations of [**data subject**](tip-know-your-privacy-laws.md#where-is-the-data-subject) rights in order to trigger an investigation.
If you believe that your privacy rights have been violated by an organization, infringing your local privacy regulations, you can likely report this violation to the entity responsible for enforcing the law, the **Data Protection Authority** (DPA).
-
+
What is a Data Protection Authority?
Again, different laws might use different terms for this, depending on the region. For example, in Canada the enforcing authority for a privacy law is often called a *Privacy Commissioner*. In Europe, the term used is a *Data Protection Authority*. In the state of California in the United States, the entity responsible for enforcing the California Consumer Privacy Act (CCPA) is the *California Privacy Protection Agency*.
@@ -45,27 +38,37 @@ Reporting even small violations can help improve privacy rights not only for you
Once an organization is ordered to bring corrective changes or is sanctioned for malpractice by a DPA, this can have many beneficial effects at the individual and collective level:
-
+
-๐งโโ๏ธ A delinquent organization might be mandated by law to correct the problem. For example, a company without a clear privacy policy might get ordered to publish one.
+
-๐ฎ You might be able to get personal data that you were unable to delete before finally deleted with the help of your DPA (and similarly for access requests).
+- A delinquent organization might be mandated by law to correct the problem. For example, a company without a clear privacy policy might get ordered to publish one.
-๐ซ An abusive organization might get banned from operating in your country entirely.
+- You might be able to get personal data that you were unable to delete before finally deleted with the help of your DPA (and similarly for access requests).
-โญ๏ธ Individual complaints can create a legal precedent that could speed up enforcement for similar violations in the future.
+- An abusive organization might get banned from operating in your country entirely.
-๐จ Strong sanctions that are made public can send a powerful warning to other organizations to avoid making the same mistakes, and adopt corrective measures preventively.
+- Individual complaints can create a legal precedent that could speed up enforcement for similar violations in the future.
-โน๏ธ Cases and sanctions that are publicized can inform the public about potential problems, and potential solutions.
+- Strong sanctions that are made public can send a powerful warning to other organizations to avoid making the same mistakes, and adopt corrective measures preventively.
-๐ If a DPA receives multiple complaints targeting a single organization, they might decide to launch a larger investigation and order the organization to improve its privacy practices more broadly.
+- Cases and sanctions that are publicized can inform the public about potential problems, and potential solutions.
+
+- If a DPA receives multiple complaints targeting a single organization, they might decide to launch a larger investigation and order the organization to improve its privacy practices more broadly.
## When you can report a violation
-You can submit a complaint anytime your local privacy rights have been violated by an organization required to comply with the law, and that you weren't able to resolve the issue on your own.
+You can **submit a complaint** anytime your local privacy rights have been violated by an organization required to comply with the law, and that you weren't able to resolve the issue on your own.
To report a privacy law violation, first ask yourself these questions:
@@ -75,7 +78,7 @@ To report a privacy law violation, first ask yourself these questions:
- [x] Which article(s) of the law has been breached by the organization?
-**In case of doubt, never hesitate to ask questions to your local DPA.**
+In case of doubt, never hesitate to send any questions you have to your local DPA.
People working at your local DPA are the best specialists to contact to get the correct information specific to your local privacy protections.
@@ -101,47 +104,80 @@ This is applicable for any other data subject rights.
On the website of your local privacy law's DPA, you should be able to find either a form to submit a complaint or an email address you can contact with the details.
-**When sending an official complaint, make sure to:**
+When sending an official complaint, make sure to:
-