← Retour au blog
tech 13 May 2026

Sensitive Data Sharing: When Privacy is Compromised

The Dutch suicide prevention foundation 113 shared visitor data with tech companies without consent. What is the extent of the issue and what are the implications for personal data protection?

Article inspired by the original source
Dutch suicide prevention website shares data with tech companies without consent ↗ nltimes.nl

Introduction

The 113 Zelfmoordpreventie foundation, the suicide prevention service in the Netherlands, recently found itself embroiled in a media storm following revelations of controversial data-sharing practices with tech companies like Google and Microsoft. This sharing occurred without the explicit consent of visitors, potentially violating the General Data Protection Regulation (GDPR). This incident raises crucial questions about data privacy, especially concerning sensitive medical data.

The Shocking Revelation

The case came to light thanks to the work of ethical hacker Mick Beer, associated with Hackedemia.nl. He discovered that the 113 foundation was sharing visitors' web browsing data, including information about location, browser used, device type, and even previously visited sites. These data, although technical, are particularly sensitive in the context of a suicide prevention service.

GDPR Implications

The GDPR imposes strict restrictions on the processing of personal data, particularly those considered sensitive, such as medical data. Sharing metadata with third parties, even if it does not directly include conversation content, can nonetheless constitute a serious breach of confidentiality. Users must be able to navigate sites like 113 with the assurance that their privacy is respected.

113 Foundation's Response

In response to the controversy, 113 temporarily suspended all measurement and analysis tools on its site to prevent any further data sharing. According to a spokesperson, the foundation is investigating the incident to understand how it could have happened and what its consequences were. Although they assured that conversations and chats were not shared, concern remains palpable among users.

Consequences and Lessons Learned

This case highlights the crucial importance of transparency and informed consent in data processing. Organizations, especially those operating in the medical or social domain, must double their efforts to ensure that their data management practices comply with regulations and respect individuals' privacy.

Conclusion

The 113 foundation must now rebuild user trust and ensure such incidents do not occur again. For tech decision-makers and entrepreneurs, this event serves as a powerful reminder of the importance of GDPR compliance and ethical responsibility in handling personal data.

Let's discuss your project in 15 minutes.

data privacy GDPR suicide prevention tech ethics data sharing
Deepthix newsletter · 100% AI · every Monday 8am

An AI agent reads tech for you.

Our AI agent scans ~200 sources per week and ships the best articles to your inbox Monday 8am. Free. One click to unsubscribe.

Visit the newsletter page →

Want to automate your operations?

Let's talk about your project in 15 minutes.

Book a call