All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Google has been found forwarding personal takedown requests from victims of image-based sexual abuse to a research institute known as Project L, including sensitive details such as names, workplaces, schools, phone numbers, and deeply personal messages.[1]
Project L then published these requests verbatim on its website, exposing the very people who were trying to have harmful content removed from the internet.
Researchers have also raised concerns that Project L may have been considering monetizing access to this data after it asked corporate users how much they would be willing to pay for “full URL access.”
This exposure could leave victims vulnerable to further harassment, doxxing, phishing attempts, and even identity theft.
Here’s what went down with the Google-Project L relationship and what you could do if you’ve been a victim of digital sexual abuse.
Project L’s survey raises concerns about selling access to the data
Korean authorities take action against Google
Google blames human error for the exposure
How leaked takedown data could put victims at risk
What can victims do to protect themselves
Bottom line
What data did Google share with Project L
Google has a system for removing search results relating to illegal filming and image-based sexual abuse. However, South Korean newspaper The Hankyoreh found that Google had been forwarding victims’ takedown requests, along with sensitive information such as their names, ages, workplaces, phone numbers, schools, and even their desperate personal messages, to Project L, which Google has described as a research institute affiliated with Harvard Law School.
Project L then published these requests verbatim on its website, exposing victims’ names, ages, workplaces, schools, mobile phone numbers, and messages pleading for help.
Along with individuals, removal requests submitted by the Ministry of Gender Equality and Family (MGEF) and the Korea Communications Standards Commission (KCSC) also ended up on Project L’s website. These agencies submit official takedown requests to Google on victims’ behalf.
The leak isn’t just limited to Korean citizens. The Hankyoreh also found takedown requests in Chinese, Japanese, and other languages, displaying the same pattern, along with real names and personal pleas.
Project L’s survey raises concerns about selling access to the data
Project L may also have been considering monetizing access to this data. The website recently conducted a survey of corporate clients, asking whether they were interested in “full URL access” and what they would consider a fair price to pay for it.
When The Hankyoreh confronted Project L about the survey, the institute initially dismissed the possibility of selling the data as a misunderstanding. However, it stopped responding when the newspaper pressed it about the survey.
The Hankyoreh alerted the relevant Korean ministries on August 25. Within 13 days, the personal information was deleted from Project L’s website.
Korean authorities take action against Google
Both the MGEF and KCSC demanded that Google and Project L delete the exposed material and launched a formal protest.
KCSC identified at least 47 individual victim requests that had been exposed on Project L’s website without consent, along with more than 100 cases where the names of organizations that help victims get their content removed were being used as searchable terms on the website. The requested material was subsequently deleted.
“We have filed a complaint with Google requesting to first delete posts containing the victims’ personal information and demanding detailed explanations and measures to prevent a recurrence,” a Korean ministry official said.
Gender Equality Minister Won Min-kyong also summoned Google officials to demand an explanation. Along with this, the Korea Media and Communications Commission questioned Google about why it had removed the consent step for information sharing.
Earlier, Google had a policy that required it to seek user permission before sharing information. However, it had eliminated this consent procedure as of August 12.
Many groups that help victims file takedowns, such as Korea’s National Center for Digital Sexual Crime Response, have since suspended such requests to Google because of the risk that sensitive information could be leaked.
Google blames human error for the exposure
Google said in its response that it doesn’t collect personal information when processing takedown requests. However, the data published on Project L’s website directly contradicts this claim.
Google reportedly told the ministry that a person checks the removal information for verification before it’s provided to Project L and blamed the exposed cases on human error.
The Google-Project L relationship dates all the way back to 2002. It was originally set up as a transparency and archive mechanism amid concerns that authorities could use indiscriminate removal requests to censor legitimate content such as political parodies. Google said it would preserve copies of these requests separately so they could be reviewed.
However, 24 years later, the system faces a very different privacy risk as more removal requests involve victims of sexual crimes and contain highly sensitive personal information. The system hasn’t been adapted to account for this.
How leaked takedown data could put victims at risk
Victims dealing with digital sexual crimes are already under massive distress, as seen in their messages, where they describe severe emotional distress and sexual humiliation.
On top of that, exposing their personal information, including names, phone numbers, schools, and workplace details, could lead to direct revictimization. Bad actors could monitor such takedown databases to identify victims and target them with harassment calls and doxxing campaigns, leading to further distress and trauma.
It also erodes trust in official help channels, and victims may eventually stop reporting such incidents to Google if doing so could lead to even more exposure. This risk is already becoming apparent, with organizations that help victims remove such content suspending their requests to Google.
Additionally, Project L’s “full URL access” survey raises concerns about possible commercial exploitation of the data. If sensitive information were to fall into the hands of bad actors, victims could potentially face targeted scams, phishing, blackmail, threats, and even identity theft.
What can victims do to protect themselves
Project L has already deleted the reported and flagged victim details from its website, so there’s no live page for you to check directly. If you believe you’ve been a victim of digital sexual crime in the past, here’s what you could do now.
- Search your name or image on the internet: There are various tools such as Google Lens, TinEye, PimEyes, and Yandex Image Search that let you reverse-search your images to find any existing copies of them on the internet. Run a periodic search to find any secondary copies that might have been cached, scraped, or mirrored onto other websites.
- Contact Korean officials: If you believe that your data was exposed, contact the Ministry of Gender Equality and Family or the KCSC and file a formal complaint. The agencies are working toward building a case against Google, and they’re the ones that conducted the audit. You could also reach out to victim support organizations for guidance on how to deal with the situation.
- For future exposure risks: Treat any online complaint or removal request as potentially public, regardless of what confidentiality they promise. Also, it’s a good idea to use a dedicated email ID or phone number for such sensitive complaints instead of your everyday contact details.
- Use an identity theft protection service: These tools regularly scan leaked databases and the dark web for your personally identifiable information, such as your name, phone number, and email address. They can alert you if they find your information and may also help you restore your identity through professional identity restoration specialists.
- Consider data broker removal services: Data broker removal services can help find your personal information on data broker websites and submit removal requests on your behalf.
Bottom line
Google’s alleged human error exposed sensitive information belonging to victims of digital sexual abuse, which was then published publicly by Project L. The information has since been removed following government intervention, but that doesn’t mean it has completely disappeared from the internet.
Scraped copies, cached pages, or other websites could still contain victims’ personal information, while the original sexually explicit content they reported may also remain online.
If you believe you may have been affected, search for your personal information and images online, report anything you find, and consider using identity theft protection and data removal services to limit further exposure.
[1] Google exposed personal data of victims seeking removal of image-based sex abuse material