Register and share your invite link to earn from video plays and referrals.

Cheeses Of Nazareth
@OhCheesesChrist
Views my own, don't work for MUFC. MUFC ticket information, away games/ballots. Been told I'm a busy bastard, and I have to agree I don't RT ticket requests
295 Following    9.3K Followers
An update on the ongoing #MUFC# ticketing restrictions and the data behind them. I've reviewed a formal response to a Subject Access Request (SAR) submitted to Manchester United regarding the tracking data used to flag accounts. For those interested in how the club and its third-party providers are handling data protection, compliance, and transparency, the response exposes serious contradictions. Here is an analysis of what the club disclosed, what they withheld, and why their position under UK GDPR is deeply flawed. 1. The Investigation Thresholds and Device Totals The Data Protection Team confirmed the underlying mechanics behind the "trawling": "Our review identified where one device had been used to access multiple accounts. In order to do this, we used tooling to allocate unique identifiers to devices... we applied a lower threshold at which we would contact account holders for more information, which is why you received our email." In the disclosure, they provided aggregate figures across linked accounts: One device accessed 16 accounts in total between 1 March and 12 July 2026. Another linked device accessed 40 accounts across the same period. 4 different devices accessed each individual account. 4 distinct IP addresses were recorded against login details on one account, and 5 distinct IP addresses against the other. While this confirms that device fingerprinting was the primary mechanism used to flag accounts, providing summary numbers is not the same as providing the actual personal data. A SAR is meant to provide the data subject with copies of their raw data, including the actual device fingerprint hashes, unique identifiers, and timestamped access logs generated against the account, not merely an executive summary written by an administrator. 2. The IP Address Contradiction: Using Data as Evidence While Denying Access The most glaring contradiction in the club’s response comes down to how they treat IP addresses: "4 different IP addresses are recorded against the log in details for [Account A], and 5 different IP addresses are recorded against the log in details for [Account B]. We are unable to provide you with those specific IP addresses, as this is personal data which we cannot verify as being about you." Let that sink in. The club used these exact IP addresses and login events to monitor, flag, and restrict supporter accounts. Yet, when a supporter asks to see the specific IP logs associated with their own login history under Article 15 of the UK GDPR, the club refuses on the grounds that they "cannot verify" whether the IP belongs to them. You cannot have it both ways. If an IP address is considered reliable enough evidence to restrict a supporter's account and restrict their match tickets, it cannot suddenly become too detached to disclose when that same supporter exercises their statutory legal rights. Under ICO guidelines and established data protection law, network logs linked directly to an identified user account form part of that individual's processing history. 3. Conflating Statutory Legal Rights with Internal Appeals A Subject Access Request is a legal process governed by the Data Protection Act 2018 and UK GDPR. It is entirely separate from club ticketing operations. Yet, the Data Protection Team used a statutory legal response to lobby on behalf of the ticketing appeals department: "If you have not already, we encourage you to reply to the email you received from the Club. The best way to resolve any of these issues is to share the information we need to understand the account activity in question. Every response is reviewed individually by a member of the ticketing team." A Data Protection Officer's role is to ensure legal compliance and provide unredacted personal data held on file, not to act as an administrative chaser nudging supporters into complying with an internal ticketing interrogation. 4. General Disclaimers Instead of Specific Compliance When requested to provide the exact purposes of processing and third-party disclosures under Article 15, the club simply pointed to a generic webpage: "In addition to the data we have provided, you are entitled to understand why we hold your data, in accordance with Article 15 of the UK GDPR. To this end, we direct you to the Club's Privacy Policy which contains all the relevant details." Directing individuals to a broad, off-the-shelf privacy policy does not meet the requirement to explain which specific third-party data processors (the external analytics firm) processed the data, how long those unique device identifiers are retained, or how the profiling was executed in this specific investigation. Where This Leaves Us The club has declared the SAR "completed in full," but this response raises more questions than it answers: Why are supporters denied access to the specific IP and timestamp logs used to place restrictions on their accounts? What specific third-party data processor was engaged to harvest and generate these unique device identifiers? Why is the club relying on high-level summaries rather than providing the underlying audit data as required by law? If the club is genuinely committed to the transparency promised in its public statements, that transparency must extend to supporters exercising their statutory rights under data protection law. Refusing to hand over the underlying technical data while using that very same data to justify account restrictions falls well short of that standard.
Show more