My Dog vs. Elite GDPR Lawyers: The Valve Data Breach Nobody is Talking About
How a routine GDPR request handled by an international law firm led to a catastrophic data breach of Steam users and minors.
My Dog: 0 hours billed. 0 data leaks. 100% better at handling PDFs than elite corporate lawyers.
Let’s explore an absurd but highly practical question in the realm of corporate data privacy: Should a global tech giant like Valve Corporation hire elite attack-dog lawyers — like the ones at the international law firm Taylor Wessing — to handle standard GDPR data requests?
The answer depends entirely on your situation:
- If your company is completely innocent and compliant: Absolutely not.
- If your company has a massive internal data trove to hide: Oh, yes. Hire them immediately.
Why? Because these elite corporate lawyers act as unwitting double agents. They will gladly help your opponent discover every single thing you are desperately trying to hide from regulators. The only technical requirement is that your opponent knows how to open a poorly redacted PDF.
This is exactly why, in the battle for the ultimate Data Protection Officer (DPO), my dog beats a high-priced corporate lawyer hands down. A dog might chew through an ethernet cable, but it will never serve up your most sensitive corporate secrets and cause a GDPR data breach on a silver platter.
The Weaponization of Bureaucracy
The core strategy of these top-tier legal firms is to project an aura of secret knowledge, threaten the opponent straight out of the gate, and artificially stall the legal process. Does EU law require a GDPR response within 30 days? They will deliver it on day 35, ask a meaningless clarifying question, and restart the clock. The goal isn’t compliance; the goal is to exhaust the person challenging the corporation.
We have the exact timeline of this bureaucratic ping-pong. On August 15, one Taylor Wessing lawyer (Dr. Tobias Schelinski) sent a formal letter doing everything possible to stall the GDPR request. He demanded additional proof of identity, arguing that the user’s burner email address (an alias that literally translates to “NotImportant”) didn’t explicitly contain their real name. He then used this manufactured delay to immediately and permanently ban the Steam account in question.
They dragged this simple data request out for months. Finally, on October 1, a different lawyer (Dr. Patrick Zurheide) took over and delivered the requested data.
(And yes, Taylor Wessing, we know how absolutely thrilled you must be about this article. We are so sorry for revealing your elite corporate strategy to your competitors. Wait, do you even have competitors at this level of digital incompetence? Actually, never mind, don’t answer that. We don’t have 30 days to wait for a reply from a party we couldn’t care less about.)
But while weaponizing delays is a standard legal tactic, what happened next was a catastrophic operational failure. While these guard dogs were busy barking at the fence, they left the back door wide open.
A Brief IT Crash Course for IT Lawyers (Module 101)
Before we look at the leaked data, we need to talk about how this happened.
If you look at the syllabus for any respectable Master of Laws (LL.M.) program in IT Law, you will find extensive modules on International Data Protection, Cybersecurity Frameworks, and the legal interpretation of GDPR Article 32 (“Security of processing”). Professors spend months drilling students on the theoretical necessity of securing personal data.
However, universities assume that a graduate student already knows how a computer works. They don’t teach “How to save a file” or “How to use Adobe Acrobat.” And this is where the elite corporate legal system collapsed.
Here is the technical reality that escaped the experts:
A Portable Document Format (PDF) is not a flat photograph. It is a layered digital container. When you use a basic PDF editor to draw a black vector rectangle over a line of text, you are not erasing the text. You are simply placing a digital post-it note over it.
Anyone who opens that document in a program like LibreOffice Draw, Adobe Illustrator, or even a basic text-scraping script can simply select the text layer underneath the black box, copy it, and paste it into Notepad.
Proper redaction requires “sanitization” — a process that permanently strips the text objects and metadata from the document code. Drawing a black shape is not cybersecurity; it is digital arts and crafts.
The Leaked Data: When Incompetence Becomes Dangerous
In response to a standard GDPR Article 15 request, Valve’s legal representation delivered a massive 830-page document filled with these digital “arts and crafts.” They carefully placed black vector shapes over thousands of rows of data — leaving visible only the information convenient to their narrative (specifically, user reports filed against the requester).
At first glance, the sheer dedication to drawing black boxes on 830 pages is almost impressive. But when you simply bypass the vectors and look at the actual data that was leaked, the humor instantly vanishes.
Through our analysis of how major corporations handle GDPR Article 15 requests, we’ve identified a systemic issue. Corporate law firms acting on behalf of tech giants often function more like aggressive PR departments or insurance adjusters. Their primary tactic is to intimidate, stall, and pressure the applicant to prevent data disclosure.
However, when they finally are forced to hand over the data, their technical incompetence is exposed. In an attempt to hide the personal data of third parties or internal corporate secrets, these lawyers routinely use fundamentally flawed PDF redaction methods.
Our urgent recommendation to all users, legal opponents, and privacy advocates:
If you, your colleagues, or anyone you know has ever requested data and received a PDF from these corporate lawyers with text covered by black boxes — check those files immediately.
Open the PDF in a basic editor (like LibreOffice Draw, Adobe Illustrator) or simply try to highlight the text under the black rectangle with your cursor and paste it into Notepad. If the text copies over, a massive Data Breach has occurred. Pass this information on to anyone fighting similar legal battles. Check every single document. Their intimidation tactics are a bluff, and their technical incompetence works against them — but it also compromises the privacy of countless individuals.
What the Elite Lawyers Actually Leaked:
- De-anonymized User Logins: Because a Steam login is often deeply personal and linked to other online identities, over 60% of the users in that document were instantly and fully identified.
- Unencrypted, Raw Chat Logs & Absurd Reports: These weren’t just standard server logs. The document exposed a trove of absolutely unhinged, absurd user reports. We are talking about raw, unredacted messages heavily laced with extreme profanity, pure envy, and unchecked hate. It included literal death wishes, nationalistic slurs, and severe geopolitical vitriol from Russian users directed at a Ukrainian user. Instead of properly securing this highly sensitive and toxic data, the elite lawyers essentially packaged a raw database of hate speech and handed it over, completely exposed.
- Putting Minors at Risk: The Ukrainian user whose privacy rights Valve was trying to suppress was not a random teenager. He is an individual with serious technical capabilities. By failing to execute a basic PDF redaction, the lawyers handed him a fully de-anonymized database of the people who reported him. This placed those Steam users — many of whom are minors — in direct physical and digital danger.
My dog would never do this. My dog would just eat the paperwork. Zero data breach.
The Masterpiece of Hypocrisy: Page 8
If you think the technical failure is funny, the official cover letter accompanying this leak elevates the situation to absolute high comedy.
On page 8 of the official legal response, Dr. Zurheide formally denies the user access to certain account details. His legal justification for withholding the information? We quote directly from the German document:
“Eine genauere Auskunft ist aufgrund des Schutzes der personenbezogenen Daten anderer Nutzer der Steam-Plattform… nicht möglich.”
(English translation: “A more detailed response is not possible due to the protection of personal data of other Steam users…”)
Let that sink in for a moment. The highly paid Salary Partner at Taylor Wessing explicitly refused to provide certain details in order to protect the privacy of other Steam users… in the exact same email package where he attached an 830-page PDF that completely leaked the de-anonymized identities, chat logs, and raw hate speech of those exact same users.
He proudly declared in writing that he was protecting the very data he was actively hemorrhaging.
The letter then concludes with a classic corporate intimidation tactic: threatening the user with criminal prosecution under the German Criminal Code (StGB), while simultaneously holding the rest of the user’s legally guaranteed GDPR data hostage until the user “explains” certain account behaviors to the lawyers. It is a masterclass in weaponized, yet utterly incompetent, bureaucracy.
A 5-Star Review for “Elite” IT Law Expertise
To understand the gravity of this failure, you have to look at who is handling this data. We are not talking about an intern.
According to public professional profiles, the individual responsible for this response is a recently promoted Salary Partner at Taylor Wessing. This is a professional who boasts a Master of Laws in International Commercial Law from the University of Aberdeen and — irony of ironies — literally completed PhD studies in IT Law.
When you hire a specialist with a PhD in Information Technology Law from a top-tier international firm, you expect them to know how to properly sanitize a digital document before transmitting sensitive user data across borders.
Instead, this catastrophic failure in basic digital literacy inadvertently verified technical realities that Valve has aggressively denied for years. Thanks to this spectacular legal blunder, we now have officially documented proof that:
- Massive Account Linking: Valve possesses the capability to link Steam accounts dating back to 2019.
- Deep Telemetry: Valve maintains an internal telemetry and logging system on its users that rivals state intelligence agencies in its depth.
- Official Confirmation: The elite legal team conveniently confirmed all of this in official, verifiable legal correspondence.
A Humble Plea to IT Law Professors (And a Reality Check)
To the esteemed professors at the University of Aberdeen and other prestigious institutions offering degrees in IT Law: we have a humble request. Please, we beg you, push your students harder on the actual “IT” part of their degrees.
Teach them how vector graphics work. Teach them that drawing a box in Adobe Acrobat doesn’t magically erase the underlying text code. These are absolute digital basics that should be mastered before anyone is handed a PhD or allowed anywhere near sensitive GDPR user data.
But let’s be entirely fair to the academic institutions. Universities are highly authoritative and respectable entities. We know for a fact that no reputable professor teaches a student how to artificially delay a legally mandated GDPR response to exhaust a victim.
That specific skill — the weaponization of bureaucracy and the deliberate dragging out of legal timelines — is not part of any university curriculum. That is strictly an in-house corporate initiative. It’s the kind of dark art you only learn when you join a firm like Taylor Wessing.
It actually highlights a brutal, unspoken reality about the modern legal career pipeline. It seems that the graduates who truly understand technology go on to find normal, respectable jobs building, protecting, and innovating in the real world.
And the others? The ones who just want to wear the expensive suits and play with buzzwords? They go to firms like Taylor Wessing to act as high-priced corporate fixers, tasked with burying the dirty secrets of tech giants behind poorly drawn digital black boxes.
A Formal Petition to EU Data Protection Regulators
To the GDPR regulators and data protection authorities currently tasked with overseeing this mess: assuming your offices aren’t staffed by the exact same type of “experts,” we respectfully ask you to investigate the circus operating under the name Taylor Wessing.
Is there a legal mechanism to mandate digital re-certification for these professionals? Or perhaps someone should just check their temperatures? It genuinely seems that the moment these lawyers receive their prestigious “Dr.” prefix, they catch a severe corporate fever that permanently wipes basic computer literacy from their brains.
Do you realize the sheer volume of GDPR violations contained in this single interaction? They artificially delayed a legally mandated response, withheld data under the false guise of “protecting” others, weaponized the bureaucracy, and then accidentally leaked the raw, de-anonymized data of those exact same people.
Meanwhile, let’s look at the scoreboard. My dog still has exactly zero data breaches. Sure, she didn’t successfully process the GDPR request. But she also didn’t commit a massive, cross-border data leak while billing the client hundreds of euros an hour. In the modern corporate ecosystem, doing absolutely nothing and simply not screwing up makes my dog the undisputed Employee of the Month.
Time to Change the Game on Steam
This isn’t just about a lawyer making a mistake with a PDF. It is about a multi-billion dollar platform’s systemic disregard for user safety.
Our project, PhishDestroy, was born because Valve simply did not care about the unchecked spam, phishing, and hijacked accounts devouring its ecosystem. We grew in that vacuum of corporate responsibility.
Now, thanks directly to Valve’s choice of legal representation and this subsequent data leak, the curtain has been pulled back. It is time to dismantle their policy of looking the other way while children are robbed, ignoring unregulated skin gambling, and permanently freezing user inventories to pad their own bottom line.
We have compiled the evidence, the timeline of corporate absurdity, and the full technical breakdown of their failures. It is a dense, serious read, because the truth of how global corporations handle your data usually is.
Read the full, extensive investigation into Valve’s practices here:
PhishDestroy: How Valve Profits From Stolen Accounts
A Special Disclaimer for Taylor Wessing & Dr. Zurheide
We know exactly what happens next. We know you are probably drafting a ToS complaint or a cease-and-desist letter right now to get this article taken down.
Before you do, let’s get a few things straight on the public record.
First, PhishDestroy is a 100% non-profit initiative. We make exactly $0 from this. This is not a hit piece ordered by your competitors (assuming you have any at this specific level of digital arts and crafts). We are publishing this because your catastrophic leak forms the foundational evidence for our massive investigation into Valve.
Second, we want to genuinely compliment your artwork. Those 830 pages of manually placed black rectangles are truly exquisite. The squares are deep, rich, and remarkably consistent. It is a beautiful testament to the fact that corporate money means absolutely nothing to the corporations spending it. Given your hourly billing rate at Taylor Wessing, this might be the most expensive modern art project in gaming history.
(Pro tip for your next GDPR response: Since you are already billing Valve for hundreds of hours to draw black squares on 800+ pages, maybe try drawing some nice little circles underneath them? Just to mix it up. It won’t secure the data any better, but it will be fun for the person extracting the text).
Finally, consider this a polite warning:
Any attempt to report, strike, or legally threaten this publication will be treated as a direct attack on legitimate, non-profit security research. We operate by a very simple rule of the internet. You are welcome to try and take this link down. But if you do, we will do what we always do: for every one link you destroy, five new ones will appear.
Welcome to the internet.
A Legal Reminder for Taylor Wessing: The 72-Hour Rule
We wouldn’t normally offer you business advice other than “close your doors,” but as cybersecurity experts, we feel obligated to point out the legal reality of your technical failure.
Your practice of using graphic vector overlays instead of proper structural document sanitization is a direct violation of GDPR Article 32 (Security of processing).
We strongly advise you to audit every single PDF you have ever sent to any opponent, applicant, or client. If you haven’t been checking these documents on a foundational IT level (stripping metadata and hidden layers), there is an extremely high probability that you are actively responsible for multiple, ongoing data leaks.
Furthermore, let us remind your esteemed IT Law PhDs of GDPR Article 33: Once a data controller becomes aware of a personal data breach, they are legally mandated to notify the competent supervisory authority within 72 hours.
Considering the cross-border nature of these leaks and the sheer volume of highly sensitive, de-anonymized data you are mishandling, attempting to sweep this under the rug will only trigger maximum regulatory penalties. You have now been made aware of the breach. The clock is ticking.
Once again, read the full investigation here:
PhishDestroy: How Valve Profits From Stolen Accounts
