Not a vulnerabilityNothing is exploited and no control is circumvented. The automatic answer is a feature, sent over the intended channel and within the intended protocol; that it also reports presence is a property of the design.
What it is
Someone sends an ordinary, unrequested signal to an address belonging to a person: a message, a call setup, a lookup, a notification. The receiving system answers on its own, below the level at which the person is involved, and the answer or its absence is observable to the sender. Repeating it produces a timeline of when the device was on, awake, connected or nearby.
Why it is a separate entry
The person is not told, sees nothing and has no record. Encryption of the content does not help, because the fact and the timing of the answer are the signal. A pattern of such answers describes sleep, work, travel and who is in the same place at the same time, and the exposure survives every setting the person can reach.
How it arises
a delivery or read confirmation generated by the client before any human sees the message
a fetch of a link preview triggered by receipt rather than by opening
a status or availability field that any party may query
a silent notification that reaches the device and produces an observable acknowledgement
Not to be confused with
A status a person deliberately publishes is not this entry. Nor is the content of the message, which may be perfectly protected. The distinguishing feature is that the answer is automatic, unrequested, and invisible on the receiving side.
How to establish it
A stimulus sent to your own second account or device produces an observable response, with no notification on the receiving side, whose presence or timing changes with the state of that device. Establishing it requires repeating the stimulus while varying only the device state.
method differentialQoD 85
Requirements on the measurement
only your own accounts and your own devices, on both ends; probing someone else's device is outside the method
vary one state at a time: powered off, screen off, application in the background, application open
record the receiving side too, to establish that nothing was shown there
run the same stimulus with the relevant privacy settings on and off, since the finding is often that they change nothing
What would refute it
by handThe response is also produced when the device is off, meaning it comes from a server rather than from the device.Then it says something about the account, not about presence, which is a different and weaker finding.reclassify
by handThe receiving side is notified of the stimulus.The person can then see it happening, which removes the invisibility that defines this entry.weakens
by handA setting reachable by the person suppresses the response, and it holds.finding falls
by handThe response requires a prior relationship, such as an accepted contact, which the sender cannot obtain unilaterally.weakens
Where this plugs into existing processes
The one question that surfaces itWhat does this system answer all by itself, to someone the user never agreed to hear from?
In a DPIA, verify this
Verify which signals the system answers without user action and what those answers disclose about the state of the device.
As a procurement clause
No unrequested signal from an arbitrary party produces a response that discloses device or user state, demonstrated on delivery.
With a complaint, hand over
A log of stimuli and responses with the device state per run, the setting state per run, and evidence that nothing was shown on the receiving side.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
eu-gdpr-5-1-c
eu-gdpr-13
eu-gdpr-6-1-a
Objections, and the answer
“No content is exposed, the encryption holds.”
The finding is not about content. Whether someone is awake, at home or beside a particular person is personal data, and it travels outside the encrypted payload.
“The user can switch off confirmations.”
Test it. Where the setting suppresses the visible indicator but the underlying answer still leaves the device, the setting addresses the interface and not the disclosure.
“This is theoretical.”
It is measurable on your own devices, repeatedly, with a stated state per run. That is the opposite of theoretical, and the measurement needs nobody else's account.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0023: Presence revealed by an automatic reply. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0023
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0023, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.