DPE-2026-0023

Presence revealed by an automatic reply

A system answers an unsolicited signal by itself, and the answer discloses whether someone is there.

In het NederlandsAanwezigheid via een automatisch antwoordWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data appAPIdesktopIoT status active
Not a vulnerabilityNothing is exploited and no control is circumvented. The automatic answer is a feature, sent over the intended channel and within the intended protocol; that it also reports presence is a property of the design.

What it is

Someone sends an ordinary, unrequested signal to an address belonging to a person: a message, a call setup, a lookup, a notification. The receiving system answers on its own, below the level at which the person is involved, and the answer or its absence is observable to the sender. Repeating it produces a timeline of when the device was on, awake, connected or nearby.

Why it is a separate entry

The person is not told, sees nothing and has no record. Encryption of the content does not help, because the fact and the timing of the answer are the signal. A pattern of such answers describes sleep, work, travel and who is in the same place at the same time, and the exposure survives every setting the person can reach.

How it arises

Not to be confused with

A status a person deliberately publishes is not this entry. Nor is the content of the message, which may be perfectly protected. The distinguishing feature is that the answer is automatic, unrequested, and invisible on the receiving side.

How to establish it

A stimulus sent to your own second account or device produces an observable response, with no notification on the receiving side, whose presence or timing changes with the state of that device. Establishing it requires repeating the stimulus while varying only the device state.

method differentialQoD 85

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itWhat does this system answer all by itself, to someone the user never agreed to hear from?
In a DPIA, verify this

Verify which signals the system answers without user action and what those answers disclose about the state of the device.

As a procurement clause

No unrequested signal from an arbitrary party produces a response that discloses device or user state, demonstrated on delivery.

With a complaint, hand over

A log of stimuli and responses with the device state per run, the setting state per run, and evidence that nothing was shown on the receiving side.

Reproduction

Legal framing

Objections, and the answer

“No content is exposed, the encryption holds.”

The finding is not about content. Whether someone is awake, at home or beside a particular person is personal data, and it travels outside the encrypted payload.

“The user can switch off confirmations.”

Test it. Where the setting suppresses the visible indicator but the underlying answer still leaves the device, the setting addresses the interface and not the disclosure.

“This is theoretical.”

It is measurable on your own devices, repeatedly, with a stated state per run. That is the opposite of theoretical, and the measurement needs nobody else's account.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0023 (Presence revealed by an automatic reply)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0023
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0023/index.json
Full
DPE Catalogue. DPE-2026-0023: Presence revealed by an automatic reply. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0023
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0023, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.