Not a vulnerabilityNothing is broken from the builder's point of view. The absence of an off switch is a product decision, and there is no security register that records product decisions.
What it is
A device or application collects data with no control to prevent it, or with a control that resets on update, on reboot or after a period, so the collection resumes without the owner doing anything.
Why it is a separate entry
Consent that cannot be withdrawn is not consent. On a device this bites harder than on a website, because the owner cannot walk away from something they paid for and installed in their home or their car.
How it arises
setting absent from the interface entirely
preference stored in volatile configuration and lost on firmware update
regional default reapplied after an update
Not to be confused with
If a control exists and holds, this entry does not apply, however buried the control is. The distinguishing feature is that it is missing or does not survive.
How to establish it
Collection continues after the control is set to off, or the control returns to on after a reboot or update, established by capturing before and after.
method differentialQoD 97
Requirements on the measurement
capture with the control on, then off, then again after a reboot and after an update
record the firmware version at each step; a reset on update is a different finding from a reset on reboot
What would refute it
by handThe control exists elsewhere, for instance in a companion app or a web interface.finding falls
by handThe remaining traffic is strictly necessary to operate the device.reclassify
by handThe reset was caused by a factory reset performed during testing.finding falls
Where this plugs into existing processes
The one question that surfaces itTurn it off, restart it, update it, and show me it is still off.
In a DPIA, verify this
Verify that the control that stops collection exists and survives a reboot and an update.
As a procurement clause
Any collection beyond what is strictly necessary can be switched off, and the setting survives updates.
With a complaint, hand over
Captures with the control on, off, and again after a reboot and an update.
Reproduction
repro/deadend/MANUAL.md · by hand · identical outbound traffic with the control on and off, or the control reverting after a reboot
Legal framing
eu-gdpr-6-1-a
Objections, and the answer
“The device cannot function without it.”
Then say so, and establish it. Necessity is a claim that can be tested by disabling the traffic and seeing what stops working.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0014: No working off switch. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0014
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0014, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.