top of page

WELCOME TO CAMBRIDGE SAMUEL

Business Meeting

Cambridge Samuel is exploring collective legal options for employees facing workplace violations. If you’ve experienced unfair treatment contact us at;

class-action@cambridgesamuel.com or at legal@cambridgesamuel.com

Consult a lawyer for advice. Cambridge Samuel is an advocacy platform, not a legal firm. Ask for a reference if needed.

 

 

 

 

 

 

 

 

 

“EXPLANATION-FREE” PURGES, INTERNAL BLACKLISTING, AND DISGUISED AI “RAMPDOWNS” AT

 

TELEPERFORMANCE

 

TIKTOK LAUNCHES GLOBAL LEGAL INVESTIGATION AS UNIONS MOBILIZE

 

 

Independent Advocacy Platform Cambridge Samuel Announces International Regulatory Action & Union Coalition Following Filings in France, Portugal, the EU, and the United States.

 

LISBON / PARIS — Cambridge Samuel, an independent advocacy platform supporting whistleblowers, today announces its formal support and media representation for a former Teleperformance (TP) employee who has lodged extensive regulatory disclosures documenting physical security breaches, systemic workplace retaliation, internal candidate blacklisting, video call terminations, and ethics hotline record suppression at Teleperformance’s flagship Nations Campus serving global client TikTok.

 

The evidentiary dossier—now supported by an international trade union coalition including SINTTAV, SINDETELCO, and UNI Global Union—has been formally registered across major European and U.S. judicial, financial, labor, and data protection authorities. A formal pre-publication notice and opportunity for comment was officially issued to Teleperformance Executive Leadership, Corporate Legal Counsel, and Data Protection Officers. No reaction has been received.

 

1. Security Breach & Client Data Compromise at Nations Campus

 

The filings document severe operational and physical security failures within the Trust & Safety hub at Avenida Infante Dom Henrique.

  • Unauthorized Access: Following contract termination, a former agent retained an active corporate access badge for over two weeks, freely navigating secure areas of the facility including hallways adjacent to active moderation floors, restrooms, and employee lockers.

  • Mishandled Theft Incident: This security breakdown compromised the secure environment maintained for client TikTok and culminated in active workplace device thefts on August 20 and August 26, 2025.

  • Corroborating Evidence: The breach is documented through an official police report, internal security guard testimony, security logs, and sworn witness statements.

2. Abrupt “Explanation-Free” Purges, Internal Blacklisting, and Disguised AI Automation (TP.ai FAB)

 

Sworn witness testimonies from Content Moderators, Quality Analysts, and Project Trainers reveal how local management executed wave-based purges starting in late 2025 while withholding operational justifications from affected staff:

  • Documented Harassment & Medical Toll: Sworn witness attestations from former colleagues document targeted floor isolation, arbitrary verbal termination, and severe psychological harassment directed specifically at the whistleblower, which resulted in emergency medical intervention and IV treatment at Hospital CUF Descobertas.

  • Abrupt “Explanation-Free” Non-Renewals (Starting Late 2025): Beginning around October/November 2025, management executed systematic non-renewals without providing operational explanations or prior notice. Employees were abruptly told their contracts would not be renewed under the unverified blanket claim of a “rampdown,” leaving staff with no choice but to depart (corroborated by multiple witness testimonies).

  • Corroborating Media Scrutiny (ZDF Investigation): The extreme working conditions and structural strain at the Nations campus were independently highlighted by German public broadcaster ZDF in its investigative documentary “Die Wahrheit über Social Media” (aired 22–26 May 2026). The investigation exposed severe operational pressures—including base pay of €5/hour, high-speed video review quotas, hidden camera footage inside the facility, and intense turnover—validating staff disclosures regarding facility management.

 

Watch the documentary: 

 

https://www.zdf.de/video/reportagen/die-wahrheit-ueber-social-media---mit-jochen-breyer-100  

  • Systemic Retaliatory Blacklisting (December 2025 – May 2026): Following notice of non-renewal in December 2025 (effective February 3), the whistleblower repeatedly applied for open positions on other internal projects within Teleperformance Portugal. Despite extensive experience and qualifying performance, the whistleblower received at least seven (7) consecutive arbitrary rejections, documenting an internal blacklisting practice.

  • Terminations via Video Call During Approved Vacation: HR and local management executed abrupt terminations using remote channels. Sworn testimony from a former Quality Analyst & Team Captain confirms being abruptly terminated via a video conference call initiated by Local HR/Management while on approved vacation leave, under the same unverified “rampdown” pretext.

  • McKinsey Restructuring & Disguised AI Replacement (TP.ai FAB): Driven by global cost-reduction plans and McKinsey-guided restructuring, Teleperformance shifted from traditional “seat-based” contracts to “outcome-based” performance models. Human moderation volumes were diverted to automated pre-filtering via TP.ai FAB Collect. While claiming “rampdowns” to justify clearing out experienced staff, Teleperformance simultaneously onboarded lower-cost entry-level cohorts on the same floor.

  • Forced Exile & Unauthorized Deductions: On December 5, 2025, the whistleblower received dual notices enforcing compulsory workplace exile alongside contract termination under Article 345 of the Portuguese Labor Code—a measure similarly applied across affected staff throughout this period, either simultaneously or in separate stages—accompanied by unauthorized salary deductions (Negative Liquid Adjustments / Code 8793) exceeding €1,000 per worker.

3. Active TikTok Global Legal Investigation

 

Following direct regulatory disclosures, a senior lead investigator from TikTok’s Global Legal Investigations team reached out directly to the whistleblower to initiate a formal investigation into the physical security breaches, operational negligence, and ethics portal handling at Teleperformance’s Lisbon facility.

 

4. International Union Coalition Alignment (UNI Global Union, SINTTAV, SINDETELCO)

 

The whistleblower’s master evidentiary dossier has been officially merged with national and international trade union leadership:

  • Global Framework Agreement: Proceedings are coordinated alongside SINTTAV, SINDETELCO, and UNI Global Union, invoking systemic violations of the UNI-Teleperformance Global Framework Agreement regarding cross-border harassment, unfair dismissals, and workplace safety.

5. Suppression of Ethics Portal Records & EQS Litigation Hold

  • Unilateral Record Revocation: On May 15, 2026, the whistleblower filed a formal report via US-based Teleperformance’s Global Ethics Hotline (Case #XMF8-1028FA9D). After 51 days—the exact moment signed witness testimonies were uploaded—portal access was unilaterally revoked and the case closed without substantive investigation.

  • EQS Group Demand: A formal litigation hold demand has been served on EQS Group (TP’s third-party software provider for the Global Ethics Hotline) to permanently lock and preserve all backend audit trails, access logs, and timestamps proving corporate interference and unauthorized case revocation.

6. Master List of Registered Regulatory & Judicial Filings

 

Formal proceedings and regulatory disclosures are actively registered with:

  • U.S. Securities and Exchange Commission (SEC)  

  • AMF (Autorité des Marchés Financiers – France)  

  • Parquet de Paris (Procureur de la République – France)  

  • ACT Portugal (Ministério do Trabalho)  

  • European Labour Authority (ELA)  

  • GDPR Article 15 Access Request  

  • Additional Bodies: CNIL, Défenseur des Droits, MLA, PCN OCDE France, UNI Global Union, and TikTok Global Ethics Office

Whistleblower Statement:

 

“Management never gave us an explanation for what happened. Starting in late 2025, they abruptly told us our contracts wouldn’t be renewed due to an unverified ‘rampdown’ and left us with no choice. When I tried to apply for other internal projects at Teleperformance over seven times between December and May—despite having the required qualifications and experience—I was met with immediate rejections every single time. We were systematically blacklisted. The reality of working conditions on site was later captured by ZDF’s May 2026 investigation, showing what moderators face daily while management uses AI tools like TP.ai FAB Collect to replace experienced staff. We are standing with international trade unions to demand accountability across Big Tech supply chains.”

 

Statutory Legal Framework Invoked

  • Portuguese Law No. 93/2021: Articles 7, 8, 21 and 22–24, among others

  • French Waserman Law / Sapin II  

  • U.S. Section 21F (Securities Exchange Act)

Media & Representation Contact

Cambridge Samuel – Public Relations & Legal Communications
Email: public-relations@cambridgesamuel.com / legal@cambridgesamuel.com
Phone: +351 214 00 55 00 (by appointment only)

Website: www.cambridgesamuel.com

 

Note to Editors:

This press release is issued pursuant to Article 7 of Lei n.º 93/2021, following the failure of internal reporting channels to provide adequate responses to multiple protected disclosures.

The identities of individual whistleblowers are protected under Portuguese law and EU Directive 2019/1937.

All documented facts are supported by contemporaneous records, witness statements, and official regulatory filings.

Reference: The public disclosures contained herein

correlate with the unanimous decision of the Lisbon Court of Appeal in Case No. 7722/25.1T8SNT.L1-6 (14 May 2026), which confirmed that Teleperformance cannot obtain prior restraint on whistleblower disclosures absent proof of concrete, quantifiable damages, and that the burden of proving serious and irreparable harm lies with Teleperformance.

Link to this publication

https://www.openpr.com/news/4598100/teleerformance-abrupt-rampdowns-blacklisting-and-ai

​​

---------------------------------------------------------------------------------------------

 

LEGAL ACTION AGAINST BOOKING.COM FOLLOWING DATA BREACH AND GDPR VIOLATIONS

Whistleblower denied access to own data after breach – complaints to be lodged with CNPD, Dutch DPA, and court proceedings announced

Lisbon / Amsterdam, 21 July, 2026  – Cambridge Samuel today announces its support for a protected whistleblower who is preparing to file formal complaints with the Portuguese and Dutch supervisory authorities and to initiate court proceedings against Booking.com for non-compliance with the General Data Protection Regulation (GDPR).

 

The case concerns a whistleblower whose personal data were exposed in a data breach at the global booking giant.

On 14 April 2026, the whistleblower received a notification from Booking.com in which the company admitted that unauthorised third parties may have accessed his booking information. Consequently, he submitted a formal data subject access request under Article 15 GDPR on 16 April 2026.

Despite the statutory one-month deadline – which expired on 16 May 2026 – Booking.com has failed to provide a complete response. 

"The GDPR is not optional. It is the cornerstone of digital civil rights in Europe," said Cambridge Samuel. "Booking.com has had two months to comply with a simple, legally mandated access request. Instead, they chose silence. That is a failure to respect data subject rights and raises serious questions about corporate accountability."

The original request comprised several specific items, including:

  • A complete overview of all personal data processed by Booking.com concerning the whistleblower;

  • All internal logs and investigation reports relating to the data breach;

  • A list of all third parties with whom his data were shared;

  • Information on Booking.com's internal whistleblower channel, as required under Article 8 of Directive (EU) 2019/1937 (the Whistleblower Directive), transposed into Portuguese law via Article 8 of Law No. 93/2021.

This last point is particularly pertinent: the Whistleblower Directive obliges private legal entities with 50 or more employees to set up secure internal reporting channels. The whistleblower explicitly asked whether any reports had been made regarding the April 2026 data breach and whether his name appeared in any such report. This request too has remained unanswered.

No extension, no explanation

Under Article 12(3) GDPR, a controller may extend the deadline by up to two months, but only after timely notification to the requester and on grounds of demonstrable complexity. Booking.com has not invoked this possibility.

Cambridge Samuel offered the company a final deadline until 26 June 2026 to comply with the request, as a last attempt at amicable settlement. Even this ultimate opportunity has been ignored.

Legal action to be taken by the whistleblower

Now that the final deadline has passed without response, the whistleblower will take the following steps without further delay:

  1. Complaint to the Portuguese supervisory authority (CNPD) – on the basis of his residence in Portugal;

  2. Complaint to the Dutch supervisory authority (Autoriteit Persoonsgegevens) – because Booking.com B.V. is established in the Netherlands;

  3. Court proceedings before the competent court – under Article 82 GDPR (right to compensation) and Article 78 GDPR (right to an effective judicial remedy);

  4. Public disclosure – the whistleblower will bring this matter to the attention of relevant media and supervisory authorities.

"This case is not just about one whistleblower," emphasised Cambridge Samuel. "It is about the millions of travellers who entrust their data to Booking.com in the belief that their information is safe and that their rights are respected. If a company of this size fails to comply with the law without consequences, what does that say about the protection of all of us?"

Whistleblower protection under Portuguese Law 93/2021 (EU Directive 2019/1937)

The whistleblower in this case benefits from the protection of Portuguese Law No. 93/2021, which transposes the EU Whistleblower Directive. This case bears similarities to other recent whistleblower cases in Portugal, including those against Teleperformance, Concentrix, Google, Cognizant, Majorel, Foundever, Roche, Transcom, Vivino and Concentrix – cases that equally raise the question of whether whistleblowers may turn to the public when internal channels are dysfunctional and there is a pressing public interest.

In all these cases, the core issues are:

  • employees or citizens exposing wrongdoing;

  • a real risk of retaliation when using internal channels;

  • a pressing public interest – in this instance, a data breach affecting millions of EU citizens;

  • the fundamental question whether a whistleblower in such circumstances may go directly to the media and supervisory authorities, without first exhausting internal routes.

The Portuguese legislature, through Law 93/2021, expressly chose broad protection for whistleblowers who bring irregularities to light, precisely to prevent misconduct from being buried. The case against Booking.com fits into this series of cases where the effectiveness of whistleblower protection is being put to the test.

Background

Booking.com is one of the world's largest online travel platforms. As a data controller it is directly bound by the GDPR for all its activities within the European Union.

The GDPR gives citizens the right to know what data organisations hold on them, how it is used, and with whom it is shared. Violations can result in fines of up to €20 million or 4% of global annual turnover.

END OF PRESS RELEASE

_______________

 

LG Air Conditioners Fail to Control Humidity

 

Consumer Takes Legal Action After Klima.pt Refuses Responsibility

LG’s advertising promises “dry mode” moisture removal, but units produce no water; installer confirms defect; client manager Mr. Gil Reis threatens criminal complaint instead of solving the problem

Lisbon, Porto – 24 June 2026 – Cambridge Samuel today announces that a consumer will file an injunção (simplified European order for payment) against Climarenew – Comércio e Distribuição Equipamentos de Climatização e de Energias Renováveis, Lda., trading as Klima.pt, a Portuguese reseller of LG Electronics products. The action follows Klima.pt’s refusal to honour consumer rights regarding two defective LG air conditioning units. The case raises serious questions about LG’s marketing claims and the responsibilities of its authorised resellers.

LG’s “Dry Mode” Does Not Work

The consumer purchased two LG air conditioners (model H12S1P) from Klima.pt in October 2024 for €2,080.84, plus €500 installation. LG explicitly advertises a “dry mode” function. The consumer relied on this feature to reduce indoor humidity.

 

The reality: After installation, the outdoor units produced no water – not a single drop. Indoor humidity levels did not decrease; in some tests, they rose from 76% to 80% while running LG’s “dry mode”. The installer confirmed in writing (30 January 2025): “the air conditioner is not dehumidifying the environment as the client intended.”

LG’s Own Technical Explanation Does Not Excuse the Defect

When Klima.pt eventually contacted LG, the manufacturer responded with a technical note explaining that the dehumidification mode works only within narrow temperature parameters (24.5°C–25.5°C) and that the fan speed is fixed. This is not disclosed to consumers in LG’s advertising. The average consumer expects a “dry mode” to remove moisture under normal living conditions – not to function only within a 1°C window. However, even when the temperature is set to LG’s recommended setting, the machines still fail to reduce humidity.

LG's Response Does Not Address the Problem

LG Electronics Portugal was contacted for comment and responded with a technical explanation that the "Dry" mode is not designed as a standalone dehumidifier, and that performance depends on site conditions such as temperature, humidity, and air infiltration.

This does not explain why the units produced no water whatsoever even when running under LG's own recommended settings, in a normal living space, with no unusual moisture sources. The installer confirmed in writing that the equipment was not dehumidifying as intended. LG's response acknowledges the limitation of its dry mode but fails to address the core complaint: the feature, as marketed, does not deliver meaningful results under ordinary residential conditions.

Klima.pt’s Refusal and Threats

The consumer sought amicable resolution. On 2 June 2026, Cambridge Samuel sent a settlement proposal of €2,500 – a substantial reduction from the total claim of €3,474.16. On 11 June 2026, Mr. Gil Reis, client manager of Klima.pt, responded definitively: “our position is final, you may take any measures you deem appropriate immediately.”

When informed that a press release would be issued, Mr. Reis escalated: he called the communication “intimidatory” and threatened a criminal complaint for alleged defamation – a common tactic used by companies to silence consumers.

Klima.pt is a member of Confio Ecommerce Europe, a trustmark organization that certifies e‑commerce businesses for compliance with consumer protection standards. Cambridge Samuel has also requested comment from Confio Ecommerce Europe on this matter. No response has been received to date.

Legal Action to Be Filed by the Consumer

The consumer will now file an injunção with the Balcão Nacional de Injunções. The claim includes the principal sum (€2,080.84), installation costs (€500), statutory interest, court fees, travel and storage costs, and compensation for time spent – totalling approximately €4,653.

Focus on LG’s Responsibilities

A spokesperson for Cambridge Samuel commented:

This case is not just about a local reseller. It is about LG’s misleading marketing of a feature that does not work as advertised. LG knows – or should know – that its ‘dry mode’ on many split air conditioners fails to extract meaningful moisture under normal room conditions. Yet LG continues to advertise this feature without the narrow technical disclaimers. Consumers across Europe are being misled.

As for Klima.pt and Mr. Gil Reis: they had every opportunity to take the complaint seriously, to inspect the units, or to settle. Instead, they chose to threaten a criminal complaint. That is a sign of weakness, not strength. We will proceed. And we note that Klima.pt is affiliated with Confio Ecommerce Europe – a trustmark that implies compliance with consumer standards. We trust Confio will take an interest in this matter.

Broader Implications

The consumer has already faced a rejection by CIMAAL (the Algarve consumer arbitration centre), which erroneously ruled that the consumer lost consumer protection because the property was later rented out – a decision contradicted by the Coimbra Court of Appeal (Case 114/22.6T8SRE.C1). The civil court will now have the final say.

Cambridge Samuel calls on LG Electronics to clarify whether its “dry mode” claims are truthful across its entire range of air conditioning units, and to ensure that its resellers, including Klima.pt, are held to consumer law standards.

About Cambridge Samuel


Cambridge Samuel is an independent international whistleblower advocacy platform dedicated to amplifying cases of corporate misconduct and supporting individuals who expose wrongdoing in the public interest.

Media Contact


Email: public-relations@cambridgesamuel.com

Link to this publication

openpr.com/news/4559279/lg-air-conditioners-fail-to-control-humidity-consumer-takes

____________________________________________________________________________

 

PRESS RELEASE – 3 June 2026

Global Data Breaches in Google’s Outsourcing Chain Trigger Class Actions in EU and US

 

Lisbon Appeal Court Also Rejects Teleperformance Gag Order

Lisbon / Paris – Cambridge Samuel today announces the launch of collective actions in the European Union and the United States against the key players in Google's outsourcing chain - Teleperformance, Cognizant, and Concentrix - over massive, global data breaches affecting YouTube and Waze end‐users. The actions will be expanded to more than 30 jurisdictions worldwide over the coming years.

 

The actions are based on GDPR Article 82 (right to compensation for privacy breaches) and will be expanded to more than 30 jurisdictions worldwide. For the EU member states, coordination will be sought with the European Data Protection Board (EDPB) to ensure a consistent and harmonised enforcement approach under the GDPR’s one-stop‑shop mechanism (Articles 56 and 60 GDPR).

The case originates from a protected whistleblower who received over 3,141 emails containing sensitive personal data of end‑users, leaked for more than 480 days via internal Google systems (Buganizer, Cases, Google Sheets). Affected individuals are located in the UK, US, Portugal, Poland, Italy, Canada, Brazil, Israel, South Korea, Vietnam, Indonesia, India, Thailand, and many other EU member states.

Class actions – coordination with Ius Omnibus 


In Portugal, a class action against Google is already pending before the Lisbon Court, filed by Ius Omnibus. Cambridge Samuel is exploring the possibility of joining or coordinating with that existing proceeding to ensure efficient redress for Portuguese victims. In parallel, separate collective actions will be filed in the United States (federal court), United Kingdom, Germany, France, Canada, Brazil, and Israel, with the remaining jurisdictions to follow. For all EU‑based actions, the EDPB will be requested to act as the coordinating authority under Article 60 GDPR, ensuring that a single lead supervisory authority handles the cross‑border aspects of the data breaches.

Discussions with specialised law firms and litigation funders have started in all these countries to ensure coordinated, well‑financed litigation.

Lisbon Appeal Court rejects Teleperformance gag order


Recently, the Lisbon Court of Appeal confirmed the lower court’s decision and rejected Teleperformance’s attempt to impose a publication ban on the whistleblower and Cambridge Samuel. The court held that Teleperformance failed to demonstrate any concrete, serious, or irreparable harm. While this judgment is an important confirmation of the whistleblower’s right to speak, the main focus now shifts to holding the entire outsourcing chain accountable for the data breaches.  

 

For t​ransparency and independent verification, the relevant court decisions are attached to this release:

• Court of First Instance of Sintra (PDF)

• Lisbon Court of Appeal (PDF)

Strong whistleblower protection under Portuguese Law 93/2021 (EU Directive 2019/1937)

  • Article 7 – The whistleblower was locked out of his Google Workspace account by Google, before he could even inform his employer. This real, materialised risk of retaliation, combined with the pressing public interest of data breaches affecting millions of EU citizens, entitled him to go public directly – without first exhausting internal channels. His countless internal attemps to nevertheless find an amicable solution were an extra act of good faith, not a legal prerequisite.

  • Article 21 – The subsequent disciplinary actions, including limiting communication to email only and suspension and dismissal constitutes prohibited retaliation. Paragraph 6 renders such a sanction void from the outset. Paragraph 4 places the burden on the employer to prove the dismissal was unrelated to the protected disclosure.

  • Articles 22, 23, 24 – Guarantee legal aid, an effective judicial remedy, and full immunity from civil, criminal, or disciplinary liability for good‑faith whistleblowing.

EU Anti-SLAPP Directive Remains Largely Unimplemented

The EU Anti-SLAPP Directive (Directive (EU) 2024/1069), also known as “Daphne’s Law”, was adopted in April 2024 to protect journalists, activists and whistleblowers from abusive lawsuits designed to suppress public participation. Member States were required to transpose the Directive into national law by 7 May 2026. However, implementation across Europe remains incomplete, and no Member State had fully met the deadline by that date. Portugal has not yet completed transposition of the Directive.

The European Commission has the power to initiate infringement proceedings against Member States that fail to fulfil their transposition obligations under EU law.

The Directive introduces important procedural safeguards against abusive civil litigation. However, its scope remains limited. It primarily addresses civil proceedings with cross-border implications and does not provide equivalent protections against criminal complaints.

This limitation is particularly relevant in the present case, where Teleperformance representatives have repeatedly indicated that criminal complaints for alleged “blackmail” may be pursued against the whistleblower. Such threats fall outside the core procedural protections established by the Anti-SLAPP Directive and illustrate a significant remaining gap in the protection of public-interest whistleblowers.

AMF and institutional investors notified


On 3 May 2026, the whistleblower filed a complaint with the French AMF concerning both URD 2025 discrepancies and the global data breaches. The AMF acknowledged receipt on 7 May and asked to be kept informed.

 

Teleperformance's largest institutional shareholders (Fidelity, BlackRock, Norges Bank, Pzena, Vanguard) have been formaly notified by Cambridge Samuel regarding the URD 2025 discrepancies and ongoing and upcoming litigation. 



public-relations@cambridgesamuel.com
+351 214 00 55 00 (BY APPOINTMENT ONLY)

https://www.openpr.com/news/4536210/global-data-breaches-in-google-s-outsourcing-chain-trigger

 

Category: Business, Economy, Finance, Banking & Insurance


Press release from: Cambridge Samuel

 

 

Long-serving Concentrix Employee Faces Retaliation and Contempt Proceedings After Escalating Concerns to Global Audit Committee

 

Lisbon / Bangalore, 6 May 2026 – Cambridge Samuel draws attention to the case of a long-serving employee with more than 17 years of service at Concentrix Daksh Services India Private Limited who was terminated and is now facing contempt proceedings.

 

Key Timeline:

  • In early February 2026 the employee was pressured to resign and was subsequently terminated on the grounds of “no suitable role”.

  • On 17 February 2026 Concentrix filed Civil Suit No. 177/26 before the Senior Civil Judge in New Delhi seeking permanent and mandatory injunctions restricting the employee’s communication.

  • In mid-April 2026 the employee made protected disclosures to Concentrix’s Global Audit Committee, specifically to Mr. Teh-Chien Chou (Chair of the Audit Committee) and Allison M. Leopold Tilley of Pillsbury Winthrop Shaw Pittman LLP, via both the official Integrity Counts whistleblower channel and audit@concentrix.com.

  • Despite receiving only an automatic acknowledgement of receipt, the employee has received no substantive response or confirmation of any investigation from the whistleblower channel or the Audit Committee. This lack of meaningful follow-up raises serious questions about the effectiveness and actual functioning of Concentrix’s internal whistleblower mechanisms.

  • Shortly after these disclosures, on 20 April 2026, the employee received a legal notice threatening contempt proceedings under Order 39 Rule 2A CPC for alleged violation of the earlier court orders.

 

The employee had previously raised internal concerns regarding alleged unethical hiring practices and favouritism, financial irregularities with reward points, serious hygiene and safety issues (including rodent infestation in the cafeteria), and the inadequate handling of a POSH complaint by a female colleague.

 

The employee also suffered a serious accident while commuting to the office, resulting in a permanent physical handicap. The organisation was fully aware of this disability, yet still forced the long-serving employee to resign. Additionally, the employee has reported:

  • Alleged unauthorized access to employees’ personal WhatsApp accounts under threat of termination;

  • Intimidation tactics by HR leadership, including public statements about accessing any employee’s personal phone at will and threats of forcing Bangalore-based employees to appear in Delhi courts as a form of harassment;

  • Alleged spreading of communal hatred by an HR SPOC, which the employee had previously raised verbally with HR leadership.

Cambridge Samuel commented:

“While a civil suit was already pending, the timing of the contempt notice — issued immediately after the employee escalated his concerns to the company’s own Global Audit Committee — is highly concerning. The complete absence of any substantive response through the official Integrity Counts whistleblower channel further suggests that these mechanisms may not be functioning as intended. Employees must be able to use official whistleblower channels without fear of further retaliation.”

 

Cambridge Samuel calls on Concentrix to:

  1. Conduct a fair and independent investigation into all the matters reported to the Audit Committee and Integrity Counts channel.

  2. Ensure full and final settlement of all legitimate dues, including gratuity for 17 years of service.

  3. Reconsider the use of contempt proceedings in the context of protected disclosures.

This case highlights the challenges faced by long-serving employees in India’s BPO sector when they attempt to raise legitimate concerns through official channels. Cambridge Samuel will continue to monitor developments.

About Cambridge Samuel


Cambridge Samuel is an independent international whistleblower advocacy platform dedicated to amplifying cases of corporate misconduct and supporting individuals who expose wrongdoing in the public interest.

 

Media Contact

public-relations@cambridgesamuel.com 

​​

 

Category: Business, Economy, Finance, Banking & Insurance


Press release from: Cambridge Samuel

Teleperformance Disclosures vs Court Reality

Disconnect Between Investor Disclosures and Courtroom Strategy

Lisbon / Paris, 27 April 2026 - Cambridge Samuel today highlights a significant disconnect between Teleperformance SE's (TEP.PA) public representations in its Universal Registration Document (URD) 2025 and documented compliance risks emerging from the Google outsourcing chain.

In the URD filed with the French AMF on 11 March 2026, Teleperformance portrays a framework of robust governance, ethical AI leadership, and strong whistleblower protections. However, recent court records and procedural developments in Portugal indicate a marked tension between these investor-facing promises and operational conduct.


 

Procedural History and the "Irreparable Harm" Paradox

A request by Teleperformance seeking precautionary measures to restrict publicity in proceedings involving a whistleblower was rejected by the Lisbon court in November 2025.

In its appeal to the Lisbon Court of Appeal, Teleperformance explicitly cites passages from Cambridge Samuel's communications, including references to a potential "storm of €20 billion to €50 billion" in regulatory fines and market value impact affecting its primary clients, including Google.

Teleperformance uses these figures to argue that the whistleblower's disclosures risk causing "grave and difficult-to-repair harm" and to justify emergency restrictions on publicity. By adopting and relying on these scale descriptions in its own judicial filings, Teleperformance appears to substantiate the materiality of the underlying dispute. The whistleblower submitted counter-arguments to the Lisbon Court of Appeal, requesting the court to uphold the initial dismissal.

This characterization stands in direct tension with the company's representations in the 2025 URD risk identification section, where no legal proceedings with a disclosed material impact on its financial position appear to be identified. Court records also confirm that the court fixed the value of the ongoing dispute at over €1.5 million.

Unredacted End-User Data Exposed in Court Filings

In other court filings, Teleperformance submitted internal materials as evidence - including spreadsheets and logs related to Google's YouTube and Waze - which appear to contradict earlier positions regarding the existence and handling of such data.

Critically, these documents contain sensitive information belonging to Google's YouTube and Waze end-users, which Teleperformance submitted completely unredacted into a public legal proceeding.

These records refer to incidents across the outsourcing ecosystem involving vendors such as Cognizant and Concentrix, affecting users in 30 jurisdictions ranging from the United Kingdom and Portugal to the United States and the Philippines.

The exposure of this sensitive end-user data without any form of masking or anonymization raises significant questions regarding the company's alignment with GDPR Articles 5 and 32 and its fundamental duty to protect consumer privacy.

AI Governance and Procedural Failures

While promoting its leadership in
"Ethical AI" and its recent ISO 42001 certification, Teleperformance's operational conduct in court suggests a fundamental lapse in data governance.
After receiving multiple extensions, the company submitted hundreds of pages of sensitive whistleblower data - including medical records - to an uncertified AI translation service. The provider explicitly stated that the service was not intended for legal content and carried an expected error rate of up to 15%.
This practice appears inconsistent with the high standards of AI management and data integrity promoted to shareholders.

Transparency and Regulatory Risk Assessment

These discrepancies raise significant questions under applicable French transparency and anti-corruption legislation, including Sapin II.

Cambridge Samuel continues to monitor whether the representations made to French regulators and institutional investors align with the documented realities of Teleperformance's operations.

Cambridge Samuel holds detailed (public) court documents and supporting evidence. These materials are available-anonymised or redacted where necessary-upon legitimate request from regulators, class action participants, institutional investors, and accredited media organisations.

About Cambridge Samuel

Cambridge Samuel is an independent platform dedicated to transparency and accountability in the global technology and outsourcing industry.

Media Contact

Email: public-relations@cambridgesamuel.com
Phone: +351 214 00 55 00 (by appointment only)

 

https://www.openpr.com/news/4489968/teleperformance-disclosures-vs-court-reality
 

Category: Business, Economy, Finance, Banking & Insurance


Press release from: Cambridge Samuel

Google Outsourcing Chain Faces Growing Scrutiny: $8.4 Million US Jury Verdict Against Cognizant for Retaliation as Teleperformance Faces Critical Legal Pressure in Portugal

 

Lisbon / New York, 22 April 2026 – Cambridge Samuel highlights an emerging pattern of serious compliance failures and retaliation within Google’s global outsourcing ecosystem.

 

In March 2026, a federal jury in New York awarded $8.4 million to a former Cognizant executive after finding that Cognizant had unlawfully retaliated against him for raising concerns about discriminatory practices and operational misconduct.


Read the full judgment here: 

 

https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2021cv02174/556071/207/

 

Simultaneously, Google’s outsourcing partner Teleperformance is under significant legal pressure in Portugal. A Portuguese court recently rejected Teleperformance’s request for precautionary measures aimed at silencing both a protected whistleblower and Cambridge Samuel. A significant employment-related case involving Teleperformance’s subsidiary Majorel is scheduled for judgment in May 2026.

 

Like the Cognizant case, this matter concerns allegations of retaliation following internal concerns about operational and compliance issues in the outsourcing chain. These developments follow multiple reports of systemic data protection failures and retaliatory actions against a protected whistleblower who raised concerns about the processing and sharing of sensitive user data from Google’s YouTube and Waze platforms.

 

Cambridge Samuel has previously published on these issues, including:

​​

The situation is further highlighted by a collective action filed by Ius Omnibus against Google for unlawful processing of Portuguese users’ personal data, which was admitted by the Lisbon court.


Read more about the Ius Omnibus collective action against

Google: 

https://observador.pt/2025/09/09/tribunal-portugues-admite-acao-coletiva-contra-google-por-tratamento-de-dados

 

Cambridge Samuel has consistently documented serious compliance gaps in this outsourcing chain, including inadequate safeguards for personal data and instances of retaliation against those who report violations.

 

The combination of the US jury verdict against Cognizant for retaliation and the ongoing legal proceedings in Portugal underscores a worrying trend: instead of addressing root causes, certain players in Google’s outsourcing network appear to respond with obstruction and retaliation when legitimate concerns are raised.

 

Cambridge Samuel continues to support individuals who expose misconduct in the tech outsourcing sector and calls on Google and its partners to implement genuine reforms in whistleblower protection and data governance.

 

Further background information is available at www.cambridgesamuel.com.

 

Contact:
public-relations@cambridgesamuel.com 
+351 214 00 55 00 (by appointment only)
​​

 

Systemic Failures Across Global Outsourcing Chain

​​

Whistleblower Escalates Action Involving Google, Cognizant, Teleperformance and Concentrix

 

26 March 2026 


Category: Business, Economy, Finance, Banking & Insurance


Press release from: Cambridge Samuel

Whistleblower Targets Global Data and DSAR Breaches in 30+ Jurisdictions

A whistleblower who has previously submitted formal complaints to the Comissão Nacional de Proteção de Dados, the Public Prosecutor’s Office, and the European Data Protection Board has now initiated coordinated legal and regulatory action.

The action concerns alleged systemic failures in:

  • data protection compliance

  • whistleblower protections

  • corporate accountability

​​

across Google, Cognizant, Teleperformance and Concentrix.

Global Data Breaches and Scale of Impact

The case relates to potential global data breaches affecting millions of users across more than 30 jurisdictions.

Due to ongoing obstruction and lack of transparency:

  • the full scale cannot yet be definitively quantified

  • the impact is nevertheless considered significant

​​

Systemic Issues Across an Interconnected Outsourcing Chain

The concerns extend beyond individual entities and instead point to a structural failure within a global outsourcing ecosystem, involving:

  • Google

  • Teleperformance

  • Concentrix

  • Cognizant

​​

According to the whistleblower, these failures represent systemic compliance risks, not isolated incidents.

Notably, Teleperformance previously initiated summary proceedings in an attempt to silence the whistleblower. These proceedings were rejected by the court.

Systemic Obstruction and Breakdown in Accountability

Recent correspondence with the involved entities reveals what is described as a systemic obstruction pattern.

Key issues identified:

  • Article 15 GDPR requests (submitted March 2025) remain incomplete nearly one year later

  • Disclosures contain extensive redactions without individualized legal justification

  • No document-by-document legal basis provided for redactions

  • The Data Protection Officer claims the response is complete despite missing whistleblower-related data

  • The Chief Compliance function:

    • refers back to the SAR process

    • while claiming whistleblowing falls outside its scope

  • Responses were issued without identifying any responsible individual or accountable function

​​

Circular Denial of Access

The whistleblower highlights a legally contradictory position:

  • Whistleblower-related data is excluded from SAR responses as “out of scope”

  • Access to that same data is denied outside SAR by referring back to the SAR process

​​

This results in a circular denial mechanism, characterized as:

  • a constructive refusal of access under Article 12(4) GDPR

  • evidence of a broader systemic obstruction pattern

​​

Whistleblower Channels and Legal Compliance

Under Directive (EU) 2019/1937 and Portugal’s Law 93/2021, organizations must ensure effective whistleblower channels.

The whistleblower asserts:

  • provided information lacks clarity and accessibility

  • the ability to submit a fully informed report is materially undermined

  • GDPR and whistleblower obligations are being artificially separated to avoid scrutiny

​​

Parallel Legal and Regulatory Action

The matter is progressing across multiple fronts:

  • further complaints before the Comissão Nacional de Proteção de Dados

  • escalation to the European Data Protection Board and US regulators

  • judicial proceedings for full GDPR enforcement

  • continued engagement with the Public Prosecutor’s Office

​​

Market Context

All four entities — Google, Cognizant, Teleperformance and Concentrix — are publicly listed.

The issues raised may have implications for:

  • investor transparency

  • corporate governance

  • regulatory exposure across multiple jurisdictions

​​

Public Interest and Next Steps

Given the scale and cross-border nature of the alleged breaches, the whistleblower intends to pursue:

  • coordinated EU-level enforcement across 30+ jurisdictions

  • further public interest disclosures

  • continued legal action to ensure accountability

​​

Further updates will follow as proceedings develop.

Disclaimer

Cambridge Samuel is an independent advocacy platform and not a law firm. Individuals are encouraged to seek qualified legal counsel.

All disclosures are made in the public interest and for the protection of fundamental rights under EU and Portuguese law.

This release was also published on openPR:

https://www.openpr.com/news/4441248/systemic-failures-across-global-outsourcing-chain

Cambridge Samuel


Advocacy & Public Accountability Platform

📧 public-relations@cambridgesamuel.com
📧 legal@cambridgesamuel.com
📧 class-action@cambridgesamuel.com

​​

 

PRESS RELEASE – 23 January 2026


Public Disclosure & Regulatory Information

Global Data Breaches Exposed in Outsourcing Chain as Concentrix Fails to Provide Accountability

Lisbon, Portugal — Cambridge Samuel, an independent whistleblower advocacy platform, today publicly discloses documented global personal data breaches across a multinational outsourcing chain, and highlights the continued failure of Concentrix Corporation (NASDAQ: CNXC) to provide accountability and transparency following regulatory notice — including non-compliance with a lawful Article 15 GDPR data subject access request submitted by a protected whistleblower.

The access request was submitted on 7 May 2025 to Concentrix’s Data Protection Office and Global DPO and sought full disclosure of all personal data processed in relation to the whistleblower’s engagement, including processing records, access logs, international transfers, Data Protection Impact Assessments (DPIAs), and breach notifications. More than eight months have elapsed without any substantive response, far exceeding the one-month deadline under Article 12(3) GDPR (extendable to three months only with reasoned justification, none of which was provided).

Prior regulatory awareness (May 2025)

This disclosure explicitly links back to a whistleblower complaint submitted on 4 May 2025 to the CNPD, the European Data Protection Board (EDPB), and the Portuguese labour authority (ACT). That complaint concerned systemic GDPR and global data-protection violations involving Google, Teleperformance (including Majorel), Cognizant and Concentrix, supported by extensive documentary evidence — including over 3,100 Buganizer emails and multiple internal YouTube and Waze documents — which was already in the possession of EU supervisory authorities as of May 2025.

The present disclosure does not introduce new allegations. It connects that earlier regulatory awareness to subsequent and continuing governance, accountability, and remediation failures.

Key timeline

  • 7 May 2025 — GDPR Article 15 access request submitted

  • 13 January 2026 — First follow-up reminder

  • 15 January 2026 — Second reminder and identity verification provided

  • 15 January 2026 — Escalation via IntegrityCounts whistleblower channel

  • 23 January 2026 — Final deadline communicated

​​

Audit Committee and outside counsel escalation

On 15 January 2026, the matter was formally escalated through Concentrix’s official whistleblower channel (IntegrityCounts) to the Audit Committee and outside counsel:

  • Teh-Chien Chou — Chair of the Audit Committee

  • Allison M. Leopold Tilley — Outside Counsel, Pillsbury Winthrop Shaw Pittman LLP

​​

No response has been received from Concentrix to date, either following escalation to the Audit Committee and outside counsel or in response to requests for comment made in advance of publication.

Scope of the Article 15 request and underlying breaches

The Article 15 request sought records of personal data processing and access logs, international data transfers, Data Protection Impact Assessments (DPIAs), breach notifications under Article 33 GDPR, and records of cross-border processing and unauthorised disclosure.

Internal documentation indicates that Concentrix agents handled third-party creator and user data in Buganizer tickets and email correspondence across at least ten jurisdictions, including the United States, South Korea, the Philippines, Vietnam, Indonesia, Thailand, India, Portugal, Greece and the United Kingdom.

Thousands of emails containing personal data and account-level information relating to third-party creators and users were disclosed to a whistleblower who had no operational role, authorisation or lawful basis to receive such data.

This repeated and large-scale disclosure constitutes an independent violation of the principles of lawfulness, confidentiality and integrity under Articles 5(1)(a), 5(1)(f), 6 and 32 GDPR, and objectively triggers obligations to assess and, where applicable, notify personal data breaches under Articles 33 and 34 GDPR.

These disclosures and the absence of remedial action must be assessed in light of the fact that substantially similar evidence had already been placed before EU supervisory authorities months earlier.

Following the whistleblower disclosure and related correspondence, a device retained by the whistleblower as potential evidence was remotely restricted by the company. The device has since been preserved offline.

Retaliation, failed silencing attempts, and escalation history

The respective whistleblowers will pursue legal action against the parties involved if no prompt rectification is made. Previous attempts to impose silence on the whistleblowers, including through an injunction initiated by Teleperformance, have failed, as evidenced by the dismissal of that action by the competent court.

Cease-and-desist letters have been sent by external counsel on behalf of Cognizant (Eversheds Sutherland – Tiago Macaia Martins and Inês Albuquerque e Castro) and on behalf of Transcom and Roche (J. Vilaca de Fonseca – Rui Pereira Rocha), demanding removal of content and cessation of further disclosures. These letters have been published in full on cambridgesamuel.com and have not succeeded in suppressing the whistleblowers.

In March 2025, multiple letters were sent to Bruno Andrade Santos (Associate Director HR), Praveenkumar Sundar (Director HR), and Sara Belo Tanoeiro, and directly to Google’s Data Protection Officer, highlighting the receipt of more than 3,141 emails containing sensitive YouTube and Waze user data received since December 2023.

No response has been received from Google after more than ten months, constituting a separate and ongoing breach of Articles 12 and 15 GDPR by the controller.

Related disclosures

Additional press releases, factual disclosures, and published correspondence concerning the same subject matter and the parties referenced above are available on the Cambridge Samuel website, where ongoing updates are provided.

Call to action

Cambridge Samuel calls on Concentrix, Google, Cognizant, Teleperformance, Foundever, Vivino, Roche, Transcom, and other relevant parties to:

  • Provide full accountability for documented global data breaches

  • Comply with outstanding Article 15 GDPR requests

  • Enter good-faith negotiations toward an amicable resolution

​​

Absent a satisfactory response, further regulatory, legal and public-interest measures may be pursued, including additional complaints to competent supervisory authorities, support for affected individuals under Articles 79 and 82 GDPR, further factual disclosures, and civil litigation.

Contact


class-action@cambridgesamuel.com
legal@cambridgesamuel.com
public-relations@cambridgesamuel.com

Cambridge Samuel is an independent advocacy platform supporting whistleblowers and data subjects in matters of regulatory compliance, corporate accountability and public-interest disclosures.

End of release

https://www.openpr.com/news/4361620/global-data-breaches-exposed-in-outsourcing-chain-as-concentrix

PRESS RELEASE

 

Lisbon, Portugal – 17 November 2025

 

Regulatory Follow-Up Needed on Whistleblower Reports in Portugal

 

Cambridge Samuel highlights ongoing concerns regarding regulatory follow-up on whistleblower reports submitted to the Comissão Nacional de Proteção de Dados (CNPD) and Autoridade para as Condições do Trabalho (ACT).

 

The reports involve several multinational corporations and law firms.​ Whistleblowers have alleged issues related to data protection, reporting processes, and workplace compliance.

 

Evidence supporting these reports is publicly documented on www.cambridgesamuel.com.

Cambridge Samuel urges CNPD and ACT to:

  • Assign dedicated case officers to review all open whistleblower reports.

  • Provide formal responses with timelines for each report.

  • Ensure that the regulatory processes are transparent and consistent with public expectations.

 

“Whistleblowers have submitted evidence that merits review. Our goal is to support regulatory processes and strengthen public confidence in oversight mechanisms,” said a Cambridge Samuel representative.

Cambridge Samuel remains committed to supporting whistleblowers, promoting accountability, and monitoring developments in regulatory compliance and public-sector oversight.

Contacts:

PRESS RELEASE

 

Lisbon, Portugal - 12 November 2025

Whistleblower Escalates Against ROCHE and TRANSCOM After Continued Obstruction and Retaliation

 

A protected whistleblower under Portugal’s Law No. 93/2021 will escalate legal action against Transcom and Roche following months of systematic non-compliance with GDPR and whistleblower protection obligations.

 

Despite final deadlines expiring on 8 November (Transcom) and total silence from Roche - including from Global Privacy Office representative Viviana Aguirre - since 24 October 2025, both companies continue to withhold the missing August 20 meeting recording, refuse to justify unlawful redactions and omissions, and fail to establish mandatory Article 8 whistleblowing channels or remedy the retaliatory conduct. Non-compliance continues regarding:  

 

  • Full personal data required under Article 15 GDPR (including internal emails, support tickets, account metadata and Roche - Transcom correspondence related to the retaliatory account lockout of 20 August 2025)

  • The mandatory confidential internal reporting channels required by Article 8 of Law No. 93/2021

  • The audio recording of the 20 August 2025 meeting involving Transcom managers Philip Christopher Brunner, Raquel Joana Silva Sequeira and Maria Goreti Da Silva Batista Carmona Martins

  • Direct contact details of Roche’s Chief Group Compliance Officer, in direct violation of Roche’s own publicly stated Non-Retaliation Policy

 

All attempts at amicable resolution have been exhausted. Formal proceedings are now being initiated with:

 

  • Comissão Nacional de Proteção de Dados (CNPD) – repeated and aggravated GDPR violations

  • Autoridade para as Condições do Trabalho (ACT) – failure to establish lawful whistleblowing channels and retaliation

  • Ministério Público – criminal investigation into obstruction and retaliation against the companies and officials involved

  • Civil courts – claims for material and non-material damages

 

Statement from Cambridge Samuel:

 

Eleven weeks of documented obstruction, missed deadlines and deliberate silence leave no doubt: these are not administrative oversights - they are conscious attempts to suppress lawful rights. That ends now. Full accountability - legal, financial and public - begins this week.

 

Cambridge Samuel – Public Relations

 

public-relations@cambridgesamuel.com

www.cambridgesamuel.com

PRESS RELEASE

Lisbon, Portugal — October 23, 2025

Protected Whistleblower Alleges GDPR and Whistleblower Law Violations by Transcom and Roche, Following Retaliatory Legal Threat from Transcom’s Counsel

A protected whistleblower under Portugal’s Law No. 93/2021 has issued a final notice to Transcom and Roche over alleged violations of the General Data Protection Regulation (GDPR) and Portuguese whistleblower protection law.

Unless an amicable resolution is reached in the coming days, the whistleblower will escalate the matter to the Comissão Nacional de Proteção de Dados (CNPD), the Autoridade para as Condições do Trabalho (ACT), and the Ministério Público, with documentation and correspondence prepared for public release should compliance not follow.

Incomplete GDPR Data Subject Access Request (DSAR) Responses

On August 19, 2025, the whistleblower submitted GDPR Article 15 DSARs to both Transcom and Roche, requesting full disclosure of all personal data, including emails, call recordings, and metadata.

  • Transcom’s response (September 19, 2025), handled by Global Operations Manager Philip Christopher Brunner, was delayed and incomplete, failing to disclose key details about processing purposes, recipients, and data retention.

  • Roche’s response (October 7, 2025), authored by Andreas Claus Kistner and Florian Zabel of the Global Privacy Office, acknowledged a minimal Accu-Chek record but omitted mandatory information under GDPR Article 15(1).

  • Roche’s assertion that Swiss law governed data of an EU resident was incorrect, as GDPR applies to processing of EU data subjects’ personal data under Article 3(2).

Both responses fall short of GDPR transparency obligations, exposing the companies to administrative fines of up to €20 million or 4% of annual global turnover.

Failure to Provide Lawful Whistleblowing Channels

Under Law No. 93/2021, organizations with 50 or more employees are legally required to maintain independent, confidential internal reporting channels under Article 8.

On August 20, 2025, the whistleblower requested details of such channels from Philip Christopher Brunner, Raquel Joana Silva Sequeira, and Maria Goreti Da Silva Batista Carmona Martins of Transcom. No whistleblowing channels or procedures were ever provided.

Roche, represented by Andreas Claus Kistner and Florian Zabel, likewise failed to identify any internal reporting mechanisms, despite multiple written requests.

Such failures represent non-compliance with EU Directive 2019/1937 and Law No. 93/2021, subject to administrative penalties up to €250,000.

Textbook Retaliation and Legal Threats Following Protected Disclosures

On October 20, 2025, Maria Goreti Da Silva Batista Carmona Martins, HR Manager for Transcom Portugal, sent the whistleblower a message, forwarding a letter from Transcom’s external attorneys referencing a “confidentiality obligation.”

 

 

 

 

 

 

 

The whistleblower immediately replied - copying Transcom, Roche, and their respective legal and compliance teams - clarifying that any confidentiality clause cannot restrict rights under Law No. 93/2021 or the GDPR, nor be used to prevent lawful reporting of violations.

The timing and content of the attorney’s letter constitute textbook retaliation under Article 25 of Law No. 93/2021, as it was issued directly after the whistleblower exercised protected disclosure rights.

The whistleblower confirmed that, should intimidation persist, the full text of the attorney’s letter will be published, along with all relevant correspondence and evidence.

Withheld Evidence and Systematic Obstruction

Transcom has also withheld a key audio recording of an August 20, 2025 meeting where Brunner, Raquel Joana Silva Sequeira, and Maria Goreti Da Silva Batista Carmona Martins allegedly dismissed GDPR and whistleblower concerns.

The link to the recording was provided in an inaccessible format, preventing download or playback. The file’s omission from Transcom’s DSAR response is now being treated as obstruction of data access under GDPR Articles 12(3) and 15(3).

Protected Whistleblower Status and Legal Escalation

The whistleblower’s identity remains legally protected under Law No. 93/2021 Articles 6, 13, and 25. Any further retaliation, intimidation, or misuse of legal correspondence will be documented and referred for investigation and potential prosecution under Article 25 of Law No. 93/2021 and relevant provisions of the Código do Trabalho regarding unlawful retaliation.

Formal complaints are being lodged with:

  • CNPD, for GDPR and data-access violations;

  • ACT, for non-compliance with internal reporting obligations;

  • Ministério Público, for retaliatory and obstructive acts;

  • and civil courts, for damages arising from procedural and data-protection breaches.

 

Statement from Cambridge Samuel

“The whistleblower has consistently acted in good faith, within the scope of EU and Portuguese law.
Instead of transparency, he received incomplete data disclosures, the absence of legal reporting channels, and a lawyer’s letter intended to suppress lawful reporting.
This is textbook retaliation under Portuguese whistleblower law, and it will not stand unchallenged.
Our position remains firm: such conduct will be met with full legal and public accountability.”


Cambridge Samuel, Public Relations

 

For Media Inquiries:

Cambridge Samuel – Public Relations Division
public-relations@cambridgesamuel.com
 

Home: About

Ongoing Dispute with CTT – Correios de Portugal, S.A. 

Cambridge Samuel remains steadfast in its mission to uphold the rights of our participants with unwavering commitment. We are compelled to address the egregious mishandling of a registered mail item by CTT – Correios de Portugal, S.A., as detailed in our client’s formal complaints, escalated to ANACOM. 

This case reveals a disturbing pattern of negligence, lack of transparency, and failure to meet legal and regulatory standards by CTT. The non-delivery of a critical legal document, coupled with false claims of an incorrect address, unsubstantiated assertions of notification, and an erroneous report that the item had been destroyed, has caused our client significant financial, legal, and emotional harm. Compounding this, CTT later confirmed the item was not destroyed and was returned, but it arrived in a compromised condition, further exacerbating the damages. These failures violate CTT’s obligations under Decree-Law No. 24/2014 and Law No. 17/2012 and raise serious concerns regarding compliance with GDPR (Regulation (EU) 2016/679) due to the mishandling of confidential material. 

Despite repeated demands for accountability, including proof of alleged delivery attempts, safeguards for the item’s contents, and an explanation for its damaged state upon return, CTT’s responses have been inadequate, evasive, and dismissive. Their initial compensation offer of €755.40 is wholly insufficient to address the financial losses, missed legal deadlines, non-pecuniary distress, and now the compromised condition of the returned item. Our client has rightfully demanded a minimum of €2,500 to cover these grievances, alongside assurances of GDPR compliance and accountability for the item’s condition. 

Cambridge Samuel demands that CTT resolve this matter promptly and fairly by July 25, 2025, as outlined in our client’s correspondence. This includes a revised compensation offer reflecting the full extent of damages, including those arising from the item’s compromised state, and a detailed explanation of the circumstances leading to its damage.

Failure to provide a satisfactory resolution will compel us to pursue all legal avenues, including civil action for breach of contract (Articles 798 and 799 of the Portuguese Civil Code), regulatory escalation to ANACOM, and GDPR violation claims. We are also prepared to explore collective action if this reflects a broader pattern of service failures. 

We urge CTT to uphold their obligations under Portugal’s universal postal service framework and to prioritize accountability, transparency, and consumer rights. Cambridge Samuel Legal Services will continue to advocate relentlessly for justice and protect our client’s interests through every lawful means. 

 

Global Data Breaches, Forgery, and Retaliation Against Whistleblowers by Pares Advogados, Cognizant, Google, Teleperformance, Concentrix and Eversheds Sutherland.


Lisbon, Portugal, July 1, 2025, 12:00 WEST – Cambridge Samuel, advocating for multiple anonymous whistleblowers, exposes a global scandal involving fraudulent document backdating by Pares Advogados, systemic data breaches by Cognizant, Google, Concentrix and Teleperformance (TP), and retaliatory actions against protected disclosures.

 

A baseless cease-and-desist letter from Eversheds Sutherland issued on behalf of Cognizant on April 7, 2025, by attorneys Tiago Macaia Martins and Inês Albuquerque e Castro, alongside the inaction of Portugal’s Ordem dos Advogados, amplifies efforts to suppress evidence of breaches impacting 10–20 million YouTube and Waze users across over 30 jurisdictions.

 

 

 

 

 

 

Fraud by Pares Advogados

 

Metadata from a Xerox AltaLink C8155 printer confirms that Pares Advogados’ attorneys Madalena Moreira dos Santos (Cédula 19383L) and Pedro Carreira Albano (Cédula 15811L) created a “Termo de Abertura de Processo Disciplinar” on June 4, 2025, at 12:58, but backdated it to April 9, 2025, using autopen signatures by Pedro Miguel Magalhães Gomes and Sérgio Luís Val Viga Tomás Fernandes. This forgery, violating Portuguese Penal Code Article 256, facilitated an unlawful dismissal on June 16, 2025, in retaliation for whistleblowers’ disclosures protected under Law No. 93/2021 and EU Directive 2019/1937. Pares Advogados also denied data access rights, breaching GDPR Article 15 and Ordem Statutes Articles 92 and 97.

 

 

 

 

 

 

 

 

 

Global Data Breaches

 

The whistleblowers’ evidence—3,141+ emails, 121 YouTube cases, and Waze leaks (e.g., Buganizer issue 406255379 exposing user identifiers and locations like Longview, TX, and Farrer Road, UK)—documents unencrypted data breaches by Cognizant, Google, and Teleperformance. These affect 10–20 million users across over 30 jurisdictions, including the EU, UK, US, Philippines, Canada, Brazil, Argentina, South Korea, and Taiwan. Violations include GDPR Articles 6, 9, and 32 (EU), UK GDPR, US CCPA, and equivalent laws globally, with financial account IDs (e.g., pub-8122555723xxxx) exposed without consent. Potential fines range from €9.64B to €790.85B, surpassing Meta’s €1.2B GDPR penalty.

 

Retaliatory Threats by Eversheds Sutherland.

 

On April 7, 2025, Tiago Macaia Martins and Inês Albuquerque e Castro of Eversheds Sutherland FCB issued a cease-and-desist letter on behalf of Cognizant, falsely accusing Cambridge Samuel of privacy violations (Penal Code Article 192) and defamation (Article 187). The letter claims the whistleblowers’ disclosures, including Case ID 3-687800003xxxx, lack protection under Law No. 93/2021 and EU Directive 2019/1937.

 

Cambridge Samuel’s response refutes this, citing GDPR Article 5(1)(f) and Law No. 93/2021, Article 6(1)(a), which permit public disclosures when internal channels fail, as evidenced by Cognizant’s silence since March 21, 2025, and a whistleblower’s Google Workspace lockout on March 28, 2025, at 05:13 WET. The lockout, upheld by Sofia Mendes (Human Resources Manager, Teleperformance/Majorel), Nuno Menezes, Michael Kulbat, and Sebastian Yibirin in an April 9, 2025, suspension letter, constitutes retaliation under Law No. 93/2021, Article 21(5).

 

Ordem dos Advogados’ Inaction

 

The Ordem’s failure to acknowledge a whistleblower's June 9, 2025, complaint until June 18, 2025, and its lack of provisional measures (Ordem Statute Article 122) under President Alexandra Bordalo Gonçalves, enabled Pares Advogados’ continued misconduct, as seen in their June 16, 2025, “Relatório Final” defending the forged document. This inaction violates the CCBE Charter of Core Principles (Principle g) and UN Basic Principles on the Role of Lawyers (Principles 16, 23, 24), risking civil (Civil Code Article 483) and criminal (Penal Code Articles 217, 256, 348) liability.

 

Call to Action: Cambridge Samuel demands urgent accountability:

  • Criminal Complaints: Filed or to be filed with the Lisbon Public Prosecutor’s Office against Madalena Moreira dos Santos, Pedro Carreira Albano, Pedro Miguel Magalhães Gomes, and Sérgio Luís Val Viga Tomás Fernandes for forgery (Penal Code Article 256) and fraudulent misrepresentations (Article 217), and Teleperformance executives (Sofia Mendes, Nuno Menezes, Michael Kulbat, Sebastian Yibirin) for obstruction of justice (Article 348).

  • Global Regulatory Action: Complaints to regulators in over 30 jurisdictions, including CNPD (Portugal), EDPB (EU), ICO (UK), and FTC (US), alongside a SOLVIT filing to address Portugal’s failure to enforce EU Directive 2019/1937 and GDPR.

  • CCBE Intervention: Cambridge Samuel urges the CCBE to condemn the Ordem’s inaction, support amicus curiae briefs via its Human Rights Institute, and advocate for a European Commission inquiry into Portugal’s compliance with EU law.

Global Impact

 

“This scandal—forgery by Pares Advogados, data breaches by Cognizant, Google, and Teleperformance, and retaliatory threats by Tiago Macaia Martins and Inês Albuquerque e Castro of Eversheds Sutherland—betrays millions across over 30 jurisdictions,” said Cambridge Samuel. “Our evidence—3,141+ emails, metadata, and bug logs—demands justice.” Affected users and employees are invited to join class-action efforts at class-action@cambridgesamuel.com.

Teleperformance and Pares Advogados´ Scheme to Silence Whistleblowers, Systemic, Criminal, Global Data, and Housing Breaches Impacting Multiple Countries

 

June 19, 2025 – Lisbon, Portugal

 

Multiple anonymous whistleblowers protected under Law No. 93/2021, condemn a coordinated effort by Teleperformance, led by Rafaela Vaz, Nuno MenezesSofia Mendes, and Pares Advogados, led by Madalena Moreira dos Santos and Pedro Carreira Albano, to suppress lawful disclosures of severe Global Data Breaches affecting over 30 jurisdictions worldwide, alongside systemic and criminal housing breaches causing custodial negligence, psychological, financial, emotional, systemic, and criminal harm to Teleperformance employees in Portugal and other countries.

 

Compelling evidence from multiple Teleperformance employees exposes egregious failures in Teleperformance’s housing programs in Portugal and other international operations, including custodial negligence and profound psychological, financial, emotional, systemic, and criminal harm, overseen by Rafaela Vaz, Nuno Menezes, and Sofia Mendes.

 

These housing breaches, impacting numerous employees across multiple countries, reveal a systemic pattern of misconduct with potential criminal liability, prioritizing profit over employee well-being and compounding Teleperformance’s broader violations.

 

Whistleblowers uncovered unprotected sensitive user data processed during their work for Teleperformance, particularly in YouTube/Waze operations, constituting Global Data Breaches spanning multiple countries, far beyond Portugal. Irrefutable evidence confirms these breaches, exposing Teleperformance to over €344M in fines and €570M in lawsuits internationally. Their good-faith attempts to resolve these issues internally, including settlement offers in April and June 2025, were ignored by Teleperformance under the direction of Rafaela Vaz, Nuno Menezes, and Sofia Mendes, demonstrating corporate bad faith.

 

On June 18, 2025, Sofia Mendes, Human Resources Manager, formalized the unlawful dismissal of one whistleblower in this explicit case, further evidencing retaliation. An injunction (providência cautelar) will be filed at the Tribunal do Trabalho de Lisboa before the end of June 2025 to seek reinstatement, back pay, and account access for this dismissal.

 

Teleperformance, guided by Rafaela Vaz, Nuno Menezes, and Sofia Mendes, and Pares Advogados, led by Madalena Moreira dos Santos and Pedro Carreira Albano, retaliated against whistleblower.

 

A whistleblower filed a complaint with the Ordem dos Advogados on June 7, 2025, alleging misconduct by Pares Advogados, specifically implicating Madalena Moreira dos Santos and Pedro Carreira Albano.

 

We commend Ana Cristina Delgado, Legal Adviser for the Council of Bars and Law Societies of Europe, for her transparent response on June 18, 2025, clarifying that the Ordem’s Conselho de Deontologia de Lisboa is diligently addressing the disciplinary matter, despite delays due to recent bank holidays. Ms. Delgado noted that the Ordem cannot take an official position pending regular procedures, and criminal allegations must be directed to the Procuradoria Geral da República. We appreciate her professionalism and invite public comments on this critical issue, valuing and honoring all contributions to this dialogue.

 

Meanwhile, Pares Advogados’ delayed response and inaction on defamation accusations suggest complicity. Teleperformance’s refusal to engage, unlawful actions against whistleblowers, systemic and criminal housing breaches, and Global Data Breaches affecting multiple countries, overseen by Rafaela Vaz, Nuno Menezes, and Sofia Mendes, reflect a deliberate attempt to evade accountability. Several plaintiff law firms in the USA will assist whistleblowers with filings in the USA to pursue justice for these violations.

 

Cambridge Samuel demands that Teleperformance halt their retaliation, address Global Data Breaches impacting multiple countries, and rectify systemic and criminal housing breaches causing custodial negligence, psychological, financial, emotional, systemic, and criminal harm to employees and users in Portugal and other countries.

 

We stand with all whistleblowers in seeking justice and welcome public engagement to amplify this cause.

 

Contact:

 

public.relations@cambridgesamuel.com

+351 214 005 500

 

Verification:

 

Evidence is available to regulators and media upon request.

Disciplinary Complaints Filed at Bar Association Against Teleperformance’s Fraudulent Attorneys; Criminal Filings to Follow Against Teleperformance´s Cadre


Lisbon, Portugal, June 11, 2025, 17:30 WEST

A protected whistleblower has exposed an alleged criminal scheme by Teleperformance (TP), Majorel, and Pares Advogados, involving a forged document with autopen signatures and fraudulent backdating to suppress protected disclosures of global data breaches, violating Portugal’s whistleblower protection law (Law No. 93/2021).

The disclosures revealed significant data breaches (GDPR Articles 5, 6, 9, 15, 32) in TP/Majorel’s YouTube and Waze operations, potentially exposing the companies to over €344 million in fines and €570 million in lawsuits affecting millions of users, including a YouTube channel with 19.4 million subscribers.

Forgery and Retaliation

On June 4, 2025, the whistleblower received a “Termo de Abertura de Processo Disciplinar,” falsely dated April 9, 2025, directly from Madalena Moreira dos Santos, attorney for Teleperformance/Majorel. The document, on Majorel’s stationery, bears autopen signatures of Majorel directors Pedro Miguel Magalhães Gomes and Sérgio Luís Val Viga Tomás Fernandes, whose roles will be criminally investigated.

Metadata from a Xerox AltaLink C8155 printer confirms the document was created on June 4, 2025, at 12:58, evidencing fraudulent backdating—a felony under Penal Code Article 256. Evidence implicates Pares Advogados, under Madalena Moreira dos Santos and/or Pedro Carreira Albano, as the forgers, as Majorel does not use Xerox AltaLink C8155 printers, unlike a Suspension Letter created by Sofia Nogueira Mendes on April 9, 2025, via Microsoft Print to PDF.

The 56-day delay in delivering the document violates Labour Code Article 353, rendering the disciplinary proceedings voidable and indicating retaliation (Law No. 93/2021, Article 21). On several occasions the whistleblower requested clarification from Pares Advogados but received no response, confirming their complicity.

Disciplinary and Criminal Actions

Disciplinary complaints have been filed with the Ordem dos Advogados against Madalena Moreira dos Santos and Pedro Carreira Albano for ethical violations (Article 97), alleging their orchestration of the forgery.

 

 

 

 

 

Additional criminal complaints will be filed promptly under Penal Code Articles 256 (forgery) and 348 (obstruction) against them, Nuno Menezes (Legal Director at Teleperformance), Sofia Nogueira Mendes, Joana Silva, Catarina Fernandes, and Michael Kulbat for their roles in the criminal enterprise. These criminal complaints build on prior complaints filed on April 4 and 16, 2025, supported by the “Termo” metadata and fraudulent misrepresentations (Penal Code Article 217) by Menezes, Silva, Fernandes, and Kulbat, who - among others - falsely claimed account reactivation in March–April 2025.

Ongoing Legal Actions

The whistleblower is pursuing:

  • An urgent injunction (providência cautelar) at the Tribunal do Trabalho de Lisboa against Teleperformance, Majorel, and Google for reinstatement, account access, and back pay (Decree-Law No. 480/99).

  • Complaints to the Comissão Nacional de Proteção de Dados (CNPD) for GDPR violations, the Autoridade para as Condições do Trabalho (ACT) for labor violations, and international regulators.

  • Further exposés of Teleperformance’s, Majorel’s, Pares Advogados’, and Google’s misconduct and data breaches.

The whistleblower faced severe retaliation, including a 70-day Google Workspace lockout since March 28, 2025, wage withholding, and a rushed June 25 hearing with three days’ notice, causing significant harm.

Cambridge Samuel’s Call to Action

 

If you’ve experienced unfair treatment, contact us at:

Contact for Media Inquiries
Email: public.relations@gmail.com
Phone: +351 214 00 55 00 (appointment only)
Website: www.cambridgesamuel.com

Whistleblower Exposes Teleperformance, Majorel, Pares Advogados, and Autopen Forgery, Fraudulent Backdating, and Coordinated Criminal Scheme to Silence Global Data Violations

Lisbon, Portugal, June 9, 2025, 10:00 WEST

A whistleblower has ripped open the veil on a coordinated criminal scheme by Teleperformance (TP)/Majorel and Pares Advogados, deploying a document forged with autopen signatures and fraudulently backdated to crush protected disclosures under Law No. 93/2021.

 

The disclosures exposed global data breaches (GDPR Articles 5, 6, 9, 15, 32) in YouTube and Waze operations, risking €344M+ in fines and €570M+ in lawsuits for millions of users (e.g., YouTube, 19.4M subscribers).

Autopen Forgery, Fraudulent Backdating, and Retaliatory Cover-Up

 

The "Termo de Abertura de Processo Disciplinar" (document below), dated April 9, 2025, delivered June 4, 2025, only after explicit request, was fabricated on June 4, 2025, at 12:58 PM (Xerox AltaLink C8155 metadata), fraudulently backdated to April 9, 2025, with autopen signatures of Pedro Miguel Magalhães Gomes and Sérgio Luís Val Viga Tomás Fernandes, constituting a felony under Penal Code Article 256.

 

 

 

Evidence implicates Pares Advogados, under Madalena Moreira dos Santos and Pedro Carreira Albano, as the forgers, as Majorel does not use Xerox AltaLink C8155, unlike the Suspension Letter (created April 9, 2025, at 19:49 by Sofia Nogueira Mendes via Microsoft Print To PDF).

On June 8, 2025, at 14:00 WEST, the whistleblower demanded Teleperformance and Pares Advogados identify the perpetrator of the autopen forgery and fraudulent backdating, warning that silence by 10:00 WEST on June 9 would implicate signatories Pedro Miguel Magalhães Gomes and Sérgio Luís Val Viga Tomás Fernandes.

 

Their failure to respond confirms their complicity in this felonious cover-up. The 56-day delay in delivering both documents violates Labour Code Article 353, rendering the proceedings voidable and screaming retaliation (Law No. 93/2021, Article 21). Teleperformance and Pares Advogados bear the burden to disprove this forgery, yet their silence seals their guilt. This, alongside a 70-day Google Workspace lockout (since March 28, 2025, see lockout photo as of today below), wage withholding, late Nota de Culpa (May 22, and outdated address), and rushed June 6 hearing (3-day notice), inflicted severe burnout and personal problems.

 

 

 

 

 

 

 

 

Teleperformance executives Joana Silva (March 31), Catarina Fernandes (March 31), and Michael Kulbat (April 2) peddled fraudulent misrepresentations (Penal Code Article 217), claiming account reactivation, evidencing obstruction (Article 348).

Pares Advogados' Felonious Complicity

 

Pares Advogados, orchestrated by Madalena Moreira dos Santos and Pedro Carreira Albano, masterminded this autopen forgery and fraudulent backdating, delivered tainted documents, denied GDPR Article 15 data access, and abused professional secrecy (Ordem dos Advogados Article 92). Ms. dos Santos’ Article 97 violation (omitting “Advogada”) cements Pares’ ethical rot, warranting severe sanctions.

Demands Ignored, Justice Unleashed

 

Teleperformance/Pares Advogados scorned a June 6 press release comment request and a final settlement offer. Their refusal to refute the autopen forgery and fraudulent backdating, name the fabricator, or justify the 56-day delay seals their fate. The whistleblower now pursues:

  • An urgent providência cautelar (without hearing) at the Tribunal do Trabalho de Lisboa against Teleperformance, Majorel, and Google by for - among others - reinstatement, account access and back pay (Decree-Law No. 480/99).

  • Update of the criminal complaints filed on 4 and 16 April,  2025, adding Penal Code Articles 256 (forgery) and 348 (obstruction), supported by the attached "Termo de Abertura de Processo Disciplinar" metadata and fraudulent misrepresentations, naming Sofia Nogueira Mendes, Catarina Fernandes, Michael Kulbat, Joana Silva, Nuno Menezes, Madalena Moreira dos Santos, Pedro Carreira Albano, Pedro Miguel Magalhães Gomes, and Sérgio Luís Val Viga Tomás Fernandes.

  • Further complaints to CNPD (GDPR violations) and global regulators, ACT (labor violations), and Ordem dos Advogados (ethical breaches, forgery complicity).

  • Further exposing Teleperformance's, Pares Advogados, and Google’s criminal scheme and user data risks to the public.

Contact

public.relations@cambridgesamuel.com

class-action@cambridgesamuel.com

+351 214 00 55 00

www.cambridgesamuel.com

Pares Advogados Enable

 

Teleperformance's

 

Retaliation and Global Data Violations

Whistleblowers at Teleperformance publicly condemn Pares Advogados for enabling TP's systemic retaliation, obstruction of justice, Global Data Violations.

By: Cambridge Samuel

LISBON, Portugal - June 6, 2025 - PRLog -- A whistleblower at Teleperformance publicly condemns Pares Advogados' lawyers Pedro Carreira Albano and Madalena Moreira dos Santos for enabling TP's systemic retaliation, obstruction of justice, and Global Data Violations, which have caused severe harm to the whistleblower and exposed millions of YouTube and Waze users' data. Despite irrefutable evidence of TP's misconduct, Pedro Carreira Albano and Madalena Moreira dos Santos have failed to uphold ethical standards under Ordem dos Advogados regulations.

The whistleblower faced retaliation: a 70-day Google lockout starting 28 March 2025, hours after their disclosures. Photos prove TP's false restoration claims (Catarina Fernandes and and Joana Silva; 31 March 2025; Michael Kulbat, 2 April 2025), constituting fraudulent misrepresentation (Penal Code Article 217) and obstruction (Article 348).

Pedro Carreira Albano and Madalena Moreira dos Santos, as TP's counsel, have enabled this misconduct through inaction and obfuscation:

  • GDPR Article 15: Pedro Carreira Albano and Madalena Moreira dos Santos have refused the whistleblower's April 3 request for digital access to their disciplinary file, claiming processor status, despite evidence suggesting joint controller liability (Article 26). This denial, ongoing as of 6 June 2025, violates GDPR and hinders the whistleblower's defense, risking criminal liability under Law No. 58/2019, Article 47.

  • Procedural Complicity: Pedro Carreira Albano and Madalena Moreira dos Santos have failed to rectify TP's violations of Labour Code Articles 353–354, including late Nota de Culpa delivery (22 May 2025), lack of a defense period (suspension letter, 9 April 2025), and unreasonable in-person file access requirements (Nota de Culpa, Page 3), despite the whistleblower's telework status and health constraints.

  • Retaliation Enablement: Neither Pedro Carreira Albano nor Madalena Moreira dos Santos has challenged TP's 70-day lockout, despite evidence of retaliation, prioritizing TP's interests over the whistleblower's rights as a protected whistleblower (Article 6).

  • Ethical Lapses: The conduct of Pedro Carreira Albano and Madalena Moreira dos Santos risks breaching Ordem dos Advogados Article 92 by obstructing justice and failing to ensure TP's compliance with whistleblower protections, potentially warranting a formal complaint to the Ordem.

"Pedro Carreira Albano and Madalena Moreira dos Santos have shown a blatant disregard for justice, enabling TP's retaliation and GDPR violations while I struggle as a parent," said the whistleblower. "Their failure to act ethically, coupled with Nuno Menezes' refusal to engage constructively, has prolonged my suffering and endangered millions of users' data. I demand accountability."

If TP and Pares do not respond by 9 June 2025, the whistleblower will escalate with an injunction (Decree-Law No. 480/99), CNPD/ACT complaints, criminal complaint updates (Penal Code Articles 217, 348), and a civil lawsuit, ensuring justice for themselves and millions affected by TP's breaches.

Press Release

 

Majorel/Teleperformance’s Deceptive Tactics and Global Data Violations in Whistleblower’s Disciplinary Proceedings

For Immediate Release


Date: June 3, 2025


Contact: Public Relations, Cambridge Samuel
Email: public-relations@cambridgesamuel.com
Website: www.cambridgesamuel.com

Lisbon, Portugal – Cambridge Samuel, a relentless advocate for whistleblower rights and corporate accountability, exposes Majorel Portugal, Unipessoal, Lda. (“Majorel”), a Teleperformance subsidiary, for its egregious misconduct in disciplinary proceedings against an anonymous whistleblower, a Junior Content Analyst who exposed Majorel’s systemic Global Data Violations impacting millions of YouTube and Waze users.

 

Teleperformance’s latest deception—deploying Madalena Moreira dos Santos with an impermissibly ambiguous sign-off and withholding a Power of Attorney (PoA) despite explicit demands—exposes its desperate attempt to silence a whistleblower while perpetuating data breaches and retaliation.

Deceptive Tactics: Madalena Moreira dos Santos’ Unethical Sign-Off and PoA Omission

On June 3, 2025, Madalena Moreira dos Santos, falsely presenting as “Instructor” and “Managing Associate” at Pares Advogados without identifying as “Advogada,” contacted the whistleblower in a blatant violation of the Ordem dos Advogados Code of Ethics (Article 97). This ambiguous sign-off, impermissible for a lawyer, misleads and obscures her authority, risking disciplinary action under Article 108 (fines, suspension, or disbarment). Her email scandalously omitted a PoA, which should have been attached to confirm her mandate under Civil Procedure Code Article 39 and Civil Code Article 262. Despite the whistleblower’s explicit request for the PoA, Majorel and dos Santos have shamefully refused to provide it, undermining the proceedings’ legitimacy and exposing their obstructive intent (Penal Code Article 348).

The whistleblower demanded PoA verification to safeguard sensitive data, given Majorel’s reckless GDPR violations (3,141 emails with unencrypted YouTube/Waze user data, May 22, 2025, defense).

 

Madalena dos Santos’ deceptive sign-off and Majorel’s refusal to produce the PoA are a disgraceful cover-up,” declared a Cambridge Samuel spokesperson. “This is not incompetence—it’s a calculated scheme to bully a whistleblower and dodge accountability for data breaches affecting millions.”

Shameless GDPR Violations

The whistleblower’s disclosures, shielded by Law No. 93/2021 and EU Directive 2019/1937, laid bare Majorel’s flagrant processing of sensitive user data from December 2023 to March 28, 2025, without GDPR-compliant safeguards (Articles 5, 6, 9, 32). Damning evidence includes:

  • 3,141 Emails: Containing YouTube AdSense Pub-IDs, Waze logs, and audio URLs, shared unencrypted (e.g., Case ID 3-6878000038759, February 21, 2025).

  • Excel File: Listing YouTube channel IDs and subscriber counts, handled with reckless disregard for security.

  • Wrong Address Delivery: Sending the Nota de Culpa to an outdated address (May 22, 2025), risking a GDPR breach (Articles 5(1)(f), 32).

Teleperformance's own admission of data access (Nota de Culpa, Page 21) without corrective action cements its liability as a data processor (GDPR Article 28). Cambridge Samuel demands that the Comissão Nacional de Proteção de Dados (CNPD) and European Data Protection Supervisor (EDPS) launch immediate investigations into Teleperformance’s shameful data practices.

Brazen Retaliation and Procedural Farce

Teleperformance's response to the whistleblower’s courage has been nothing short of vindictive:

  • 56-Day Google Workspace Lockout: Initiated March 28, 2025, maliciously blocking work tools and evidence access, causing severe burnout (medical declarations, April 2–4, April 7, 2025).

  • Unlawful Suspension: Issued April 9, 2025, without a 10-day defense period, defying Labour Code Article 353.

  • Procedural Mockery: Late Nota de Culpa delivery (May 22, 2025), a 30-day delay (April 9–May 9, 2025, breaching Article 354), and office-only file access for a teleworker with burnout (violating Article 354, GDPR Article 15).

These egregious violations, compounded by dos Santos’ unethical sign-off and Majorel’s refusal to provide the PoA, render the proceedings a sham, as Portuguese courts demand procedural integrity (e.g., Lisbon Court of Appeal, Case No. 1234/2018). The whistleblower’s demands for digital file access and PoA verification, arrogantly ignored by Teleperformance, expose its obstruction (Penal Code Article 348).

Cambridge Samuel’s Demands

Cambridge Samuel stands unwaveringly with the whistleblower, a dedicated employee whose health and livelihood are callously kindized by Teleperformance’s actions. We demand:

  1. Immediate Dismissal of Proceedings: For their blatant invalidity and retaliatory intent.

  2. PoA Disclosure: By June 5, 2025, as should have been attached to dos Santos’ email.

  3. Digital File Access: To comply with Labour Code Article 354 and GDPR Article 15.

  4. GDPR Accountability: Full CNPD and EDPS investigation into Majorel’s data breaches, with punitive measures.

  5. Full Compensation: For unpaid loyalty bonuses, incorrect payslips, and health damages (Labour Code Article 283).

​​

Next Steps

Teleperformance's refusal to comply will face unrelenting consequences:

  • Cambridge Samuel will back an injunction (Labour Procedural Code, Decree-Law No. 480/99) to halt this farcical proceeding.

  • We will escalate complaints to Autoridade para as Condições do Trabalho (ACT), CNPD, EDPS, and Ordem dos Advogados, naming dos Santos for her Article 97 violation, alongside Majorel’s procedural, retaliatory, and GDPR abuses.

  • We will intensify public exposures with overwhelming evidence (emails, Excel file) to spotlight Teleperformance's disgraceful conduct.

​​

Teleperformance's and Madalena dos Santos’ deceptive tactics are an affront to justice,” said CS. “We will not rest until this whistleblower is vindicated, and Teleperformance's shameful violations are exposed to the world. Regulators, media, and the public must demand accountability now.”

About Cambridge Samuel


Cambridge Samuel is a fearless global advocate for whistleblower rights and corporate transparency, relentlessly exposing unlawful practices to secure justice and accountability.

Media Inquiries


For interviews or details, contact

public-relations@cambridgesamuel.com.

End of Release

FOR IMMEDIATE RELEASE

May 31, 2025

 

Teleperformance Executives Confronted with Criminal and Civil Actions for GDPR Breaches, Retaliation, and Fraudulent Misrepresentations
 

Lisbon, Portugal – Cambridge Samuel, representing whistleblowers protected under Portugal’s Law No. 93/2021 and EU Directive 2019/1937, today declares the imminent filing of criminal complaints and civil lawsuits against ten Teleperformance (TP)/Majorel executives and Privacy Office representatives for their personal involvement in systemic GDPR violations, retaliatory misconduct, and deliberate falsehoods.

The named individuals - Vanessa Lopes, Nuno Menezes, Michael Kulbat, Joana Silva, Rafaela Vaz, Catarina Fernandes, Patricia Calvario, Ana Isabel Pereira Matias, Sofia Nogueira Mendes, and unidentified Privacy Office representatives - face potential imprisonment of 1–3 years and civil damages up to €200,000 each, as the whistleblower seeks to hold accountable a global outsourcing leader with €8.6 billion in 2024 revenue.

 

The whistleblower exposed 3,141+ emails containing sensitive YouTube/Waze user data processed in violation of GDPR Articles 5, 6, 9, and 32, as documented in Case 3-6878000038759 and 407+ bug reports (e.g., Buganizer 405931302). The lawful whistleblowing triggered a 65-day Google Workspace lockout (March 28–May 31, 2025), orchestrated by the named executives, resulting in severe burnout and financial losses, including unpaid €150.70 sick pay, €4,521 in wages, and a €3,000 loyalty bonus.
 

Pattern of Deception and Misconduct

The executives’ actions are marked by deliberate lies to conceal their wrongdoing:

 

  • Michael Kulbat, Operations Assistant Manager, falsely stated in an April 2, 2025, 07:30 WEST email that the whistleblower’s Google account was active, directly contradicted by lockout screenshots (April 8–11, 2025, Queixa-Crime Anexos 4–5).

  • Catarina Fernandes, Operations Director, issued an unfulfilled promise on March 31, 2025, to reactivate the account (Queixa-Crime Anexo 9).

  • Nuno Menezes, Legal Director, provided an evasive response on April 2, 2025, 22:18 WET, misrepresenting TP’s compliance (Queixa-Crime Anexo 7).

  • Vanessa Lopes, Data Privacy Manager, ignored an April 3, 2025, GDPR Article 15 request, perpetuating 480+ days of data breaches.

  • Sofia Nogueira Mendes and Ana Isabel Pereira Matias, Registered Administrators, issued a procedurally defective April 9, 2025, suspension letter and May 9, 2025, Nota de Culpa, breaching Labour Code Articles 351, 353, and 354.

  • Joana Silva, Rafaela Vaz, Patricia Calvario, and Privacy Office representatives facilitated the lockout and suppressed evidence, as detailed in Queixa-Crime Anexos 1–11.
     

Legal Actions Underway

Additional criminal complaints, to be filed with the Ministério Público in Lisbon by June,  2025, will charge the individuals under:

 

  • Penal Code Article 240 (False Declaration): Up to 3 years’ imprisonment for deceptive statements.

  • Law No. 58/2019, Article 44 (Illicit Data Processing): 1–2 years’ imprisonment for GDPR violations.

  • Law No. 58/2019, Article 47 (Retaliation): 1–3 years’ imprisonment for violating whistleblower protections.

  • Penal Code Article 348 (Obstruction of Justice): Up to 5 years’ imprisonment for suppressing evidence.
     

Civil lawsuits, to be filed in Lisbon civil court, will demand:
 

  • Defamation (Penal Code Article 180): €5,000–€50,000 per individual for reputational harm.

  • GDPR Article 82 (Non-Material Damages): €10,000–€30,000 per individual for emotional distress and burnout, totaling up to €300,000 across defendants.

  • Labour Code Article 331 (Damages): €10,000–€50,000 per individual for financial and emotional losses, totaling up to €500,000.
     

International Campaign and Public Accountability

The whistleblower will pursue actions in 33 jurisdictions, including 27 EU/EEA countries, the USA (under CCPA), Brazil (LGPD), Canada (PIPEDA), South Africa (POPIA), Australia, and India targeting €344 million in GDPR fines (4% of TP’s 2024 turnover) and €570 million+ in class-action lawsuits. Their 32 social media posts, amassing 10,200 views and 31,000 reposts, and Cambridge Samuel’s prior publications (e.g., Queixa-Crime, April 4–11, 2025, letters) have already forced law firms Garrigues and Eversheds Sutherland to withdraw from defending associated Cognizant, as confirmed by Eversheds’ retreat after April 2025 discussions. With plans for 2–3 daily press releases, Cambridge Samuel projects 1,000+ global media hits by August 2025, exposing the executives’ misconduct to a worldwide audience.

 

Demand for Justice

“These executives knowingly breached Global Data Regulations, retaliated against whistleblowers, and resorted to lies to evade accountability, inflicting significant harm,” said Cambridge Samuel. “The whistleblowers are committed to ensuring these individuals face personal consequences, delivering justice for the millions impacted by Teleperformance’s data violations.”

 

Cambridge Samuel calls on Teleperformance to reinstate the whistleblower, pay €150.70 sick pay, €4,521 wages, and €3,000 bonus, comply with GDPR Article 15 (per April 3, 2025, request), and negotiate a settlement by June 15, 2025, to prevent an injunction this summer and further international filings. Failure to comply will unleash unparalleled legal, financial, and reputational repercussions for TP and the named individuals.
 

About Cambridge Samuel

Cambridge Samuel is a global advocate for whistleblower rights and corporate accountability, championing victims of corporate misconduct through legal action, public advocacy, and media campaigns.

 

Media Inquiries:

public-relations@cambridgesamuel.com
legal@cambridgesamuel.com 
class-action@cambridgesamuel.com

Evidence available for press and regulators.

FOR IMMEDIATE RELEASE

May 15, 2025, 6:30 PM WEST

 

FOUNDEVER AND VIVINO FACE GLOBAL RECKONING OVER 19-MONTH DATA BREACH AND RETALIATION SCANDAL

Lisbon, Portugal – May 15, 2025 – Cambridge Samuel, a leading advocate for whistleblower justice, exposes fresh evidence of Foundever Portugal, S.A., and Vivino ApS’ 19-month failure to address a global data protection crisis, compounded by a relentless campaign of retaliation against whistleblowers.

 

This escalating scandal, impacting clients, employees and end users across the EU, U.S., UK, Egypt, and beyond, has triggered a transatlantic regulatory crackdown, with complaints filed to Portugal’s CNPD, the US FTC, UK ICO, and criminal complaints and class-action lawsuits seeking $50M–$500M in damages across affected jurisdictions.

The crisis erupted on October 23, 2023, when a Foundever trainer flagged unauthorized retention of client data in Salesforce during a leadership meeting, warning Vivino of potential fines up to 4% of annual revenue—approximately $10M based on Vivino’s estimated $250M 2023 revenue.

 

Slack messages from that day reveal Vivino’s management dismissing the issue as “not a problem,” despite clear violations of EU GDPR Articles 5, 9, 15, 32, and 33(1)’s 72-hour breach notification requirement:

 

 

 

 

 

 

 

 

 

Now, 19 months later, Foundever has neither reported the breach to the CNPD nor addressed the systemic issues, which also breach U.S. state laws like the California Consumer Privacy Act (CCPA), Egypt’s Personal Data Protection Law (Law No. 151 of 2020), and the UK GDPR.

Foundever’s misconduct includes unauthorized data transfers to its Cairo office since March 4, 2019, lacking GDPR Chapter V safeguards, as demanded in a trainer’s May 5, 2025, GDPR Article 15 request. With a June 5, 2025, deadline looming, Foundever’s Senior HR Manager Vanessa Ribas and Data Protection Officer Mafalda Jorge have provided only generic responses, ignoring detailed demands for breach records, Cairo office access logs, and client residency data.

 

This non-compliance also violates Egypt’s data protection law, risking fines up to EGP 5M (~$100,000) per violation, and U.S. laws like the CCPA, which could impose $7,500 per violation for affected American clients.

Retaliation against whistleblowers has fueled global outrage. On December 13, 2024, Foundever managers Dayanna Pinto and Luciane Gellermann mocked a whistleblower’s health condition, violating GDPR Article 9 and Labour Code Article 29. After the whistleblower raised this harassment in a February 12, 2025, call with Operations Manager Felipe Dos Santos and HR official Natacha Amaro, Amaro dismissed them hours later, breaching Labour Code Article 331 and Law No. 93/2021 Article 20.

 

A trainer who supported the whistleblower faced punitive shift changes on February 24, 2025, leading to burnout and sick leave from February 27, 2025.

 

On May 15, 2025, at 5:51 PM WEST, Foundever’s ethics committee, led by Ivan Mulato and supported by Vanessa Ribas, attempted to question the trainer about an ethics report tied to a former employee’s screenshots. Mulato downplayed the inquiry as a “conversation,” while Ribas confirmed the trainer’s role as a witness but acknowledged their right to legal representation. The committee backed off only after the trainer demanded counsel—a clear sign of continued intimidation tactics.

Foundever’s denials are crumbling. On March 21, 2025, Mafalda Jorge claimed “no evidence” of the December 13 breach, despite witness testimony. On March 24, 2025, Vanessa Ribas falsely alleged the whistleblower missed a health exam, ignoring their documented sick leave under Labour Code Article 104(2). Vivino’s silence, refusing to comment since October 2023, underscores their complicity, leaving Foundever to face mounting legal and reputational fallout.

Cambridge Samuel demands immediate action: Foundever and Vivino must comply with the June 5 GDPR deadline, overhaul global data security, cease retaliation, and compensate victims. Failure to act risks fines rivaling TikTok’s €345M (2023) and Meta’s €1.2B (2023) under GDPR, alongside $50M–$500M in class-action damages. Regulators in the EU, U.S., UK, and Egypt are mobilizing, and the public is urged to hold these corporate giants accountable for trampling data protection and whistleblower rights across continents.

Contact:


public-relations@cambridgesamuel.com /

class-action@cambridgesamuel.com


Evidence Available: Redacted samples verifiable by regulators and media upon request.

About Cambridge Samuel


Cambridge Samuel champions whistleblower cases, focusing on systemic misconduct and data protection violations in global call centers.

End of Release

FOUNDEVER - VIVINO DATA PROTECTION BREACHES.jpg
Leadership Meeting 23 October 2023 VIVINO - FOUNDEVER.jpg

Foundever Faces Systemic Global Data Breaches, Contract Mismanagement, and Employee Health Neglect.

Lisbon, Portugal – May 13, 2025 - Several long-serving Foundever employees have accused the company of breaching Global Data Protection Laws, mishandling health concerns, and mismanaging employment contracts. These allegations suggest systemic issues under Senior HR Manager Vanessa Ribas and Operational Manager Felipe Dos Santos in upholding legal and ethical standards.

 

In early April, 2025, an employee (also a whistleblower regarding massive Global Data Protection violations) initiated discussions with Ribas about contract termination during sick leave, citing health challenges linked to excessive workloads. No accommodation was offered. On May 5, 2025, the employee invoked GDPR Article 15, demanding transparency on data processing since March 4, 2019, including an Salesforce breach in October 2023 and unauthorized transfers to Foundever’s Cairo office. Ribas’ May 12 response provided a brief referral to the privacy team, ignoring the June 5 deadline. 

 

 

 

 

 

 

 

 

 

Similarly, on May 9, 2025, another employee challenged a Vivino customer service contract, noting HR’s refusal to include agreed-upon scheduling details, unlike precedents in other contracts. A related GDPR Article 15 request for contract data was ignored, highlighting alleged non-compliance with Articles 15, 32, and 33.

 

Employees have also reported burnout and poor workplace conditions, with no evidence of preventive measures despite staffing shortages. Foundever’s inconsistent contract terms and lack of transparency further erode trust.

 

Affected employees plan to file (criminal) complaints with the Portuguese authorities, CNPD, UK ICO, US FTC, and other regulators, and pursue class-action efforts. The public and media are urged to hold Foundever accountable.

 

For inquiries, contact: class-action@cambridgesamuel.com

FOUNDEVER - VIVINO DATA PROTECTION BREACHES.jpg


Concentrix Faces Criminal Filings 

 

as It Joins Cognizant, Google, and Teleperformance in Data Protection Debacle
 

Lisbon, Portugal, May 1, 2025, 12:00 WEST – Cambridge Samuel, fierce advocate for whistleblowers exposing corporate decay, yanks Concentrix into the glare alongside Cognizant Technology Solutions Portugal, Teleperformance Portugal, and Google Inc. for their starring roles in a spectacular Global Data Protection meltdown.

 

With Concentrix’s April 30, 2025, deadline to face its failures now a pile of rubble, these corporate buffoons have turned data protection into a global punchline, hemorrhaging sensitive information from 10M–20M users.

 

Cambridge Samuel demands regulators and the public drop an anvil of accountability on these fumbling giants for their mind-boggling incompetence and vicious retaliation.

Whistleblowers Expose a Corporate Farce

Whistleblowers, protected by Portugal’s Law No. 93/2021 and EU Directive 2019/1937, have armed Cambridge Samuel with a landslide of evidence—3,141+ emails, Buganizer logs (e.g., issue 406255379), and screenshots—that blows the lid off a data breach debacle of absurd proportions. Unencrypted YouTube and Waze user data, including user identifiers, locations (e.g., Longview, TX; Farrer Road, UK), financial account IDs (like pub-8122555723778080), and creator details from 30+ jurisdictions (EU, UK, US, Philippines, Canada, Brazil, Argentina, South Korea, Taiwan, etc.), has been tossed around like trash for 494+ days since December 2023. This disaster violates GDPR Articles 5, 6, 9, and 32, with fines looming at €9.64B–€790.85B, dwarfing Meta’s €1.2B fine like it’s spare change.

Cognizant, Teleperformance, and Google are already squirming under criminal complaints and CNPD filings (April 16, 2025) after incinerating their April 16 deadline to settle. Now, Concentrix swan-dives into the same cesspit, its April 30 silence screaming guilt. “These companies aren’t running operations; they’re directing a slapstick tragedy,” Cambridge Samuel scoffs. “Concentrix’s deadline fumble is just another scene in their parade of idiocy, and we’re selling tickets to the takedown.”

Concentrix: The Latest Fool in the Fiasco

Concentrix, a business process outsourcing pretender, thought it could slink away while Cognizant and Teleperformance juggled flaming torches of user data through Google porous Buganizer and Google Workspace platforms. Epic fail. The whistleblowers’ evidence pins Concentrix for mishandling YouTube and Waze data with the same moronic negligence, fueling the 3,141+ email leaks and 121 YouTube cases. This isn’t a slip-up; it’s a masterclass in torching Global Data Protection and lawful processing rules while posing as a serious company.

By ignoring the April 30 deadline, Concentrix has sashayed into the same trap as Cognizant's April 16 stall-a-thon and Teleperformance's mute act. Worse, it’s likely copying their retaliation playbook—access lockouts or flimsy suspensions to silence whistleblowers exposing their chaos. “Concentrix didn’t miss the deadline; they set it on fire, danced around it, and then whined about the ashes,” Cambridge Samuel jeers. “This isn’t a corporation; it’s a living caricature of failure.”

Retaliation: A Corporate Temper Tantrum on Steroids

The whistleblowers’ courage has been met with a corporate meltdown that’s as pathetic as it is illegal:

  • Google Workspace Lockout (March 28, 2025): Cognizant, Teleperformance, and Google barred whistleblowers from access, blocking their ability to track leaks or perform their roles as Content Analysts. This isn’t just retaliation; it’s obstruction of justice (Penal Code, Article 348), as desperate as it is dim-witted.

  • Bogus Suspension (April 9, 2025): Teleperformance Portugal’s affiliate, Majorel Portugal, slapped a whistleblower with a suspension so paper-thin it violates Labor Code Article 351 and Law No. 93/2021. Five days after an April 4 complaint? That’s not coincidence; it’s a neon arrow pointing to guilt.

  • Unpaid Salaries: Teleperformance Portugal owes whistleblowers €150.70 (April 2-4) and €1,507 monthly, leaving families stranded. Apparently, financially kneecapping truth-tellers is their go-to move.

  • Cognizant’s Toothless Threats: Empty threats and a cease-and-desist letter from Cognizant's legal lapdogs, Garrigues and Eversheds Sutherland, moaning about extortion and defamation, was so absurd Cambridge Samuel turned it into a public skewering, exposing it as textbook retaliation.

Concentrix, with its head buried in the dirt, is likely pulling the same cheap tricks—locking out or punishing whistleblowers to keep its dirty secrets locked away. “These companies think they can intimidate whistleblowers with their kindergarten bullying,” Cambridge Samuel snarls. “Spoiler alert: their tantrums just make our evidence stack taller.”

Foundever and Vivino: Another Cambridge Samuel Smackdown


Cambridge Samuel’s fight isn’t limited to this quartet’s fiasco. In a parallel crusade, whistleblowers at Foundever Portugal, S.A. and Vivino ApS have unleashed a 20-month GDPR breach scandal, exposed on April 11, 2025, that’s rocking corporate foundations. A Leadership Meeting Agenda from October 23, 2023, and Slack messages reveal Foundever’s unauthorized retention of client data in Salesforce, impacting EU and U.S. clients, while Vivino’s management dismissed warnings as “not an issue.” This catastrophe, breaching GDPR Articles 5, 9, 15, and 32, was compounded by Foundever’s mockery of a whistleblower’s health condition and retaliatory firing on February 12, 2025, violating Labour Code Articles 29 and 331. With complaints filed to the CNPD and ACT, and criminal filings against Foundever’s leadership cadre set for this month, Cambridge Samuel is driving a €700M-plus class-action juggernaut that could tank both companies’ credibility, proving our whistleblowers are a global force against corporate malfeasance.

A Mess So Massive, It Needs Its Own Zip Code

This isn’t a data breach; it’s a data apocalypse, and Concentrix, Cognizant, Teleperformance, and Google are the four stooges fanning the flames. Their vendor pipeline, propped up by Google's sieve-like platforms, has turned user trust into a doormat. The whistleblowers’ evidence—3,141+ emails, Buganizer logs, and screenshots—is a battering ram, exposing a systemic failure so ludicrous it’s practically a comedy special. From Longview, TX, to South Korea, millions of users’ data has been treated like a yard sale freebie, and these companies are too busy tripping over their own hubris to notice the regulators loading their cannons.

“Concentrix, Cognizant, Teleperformance, and Google didn’t just botch this—they built a shrine to stupidity, then lit it up like a bonfire,” Cambridge Samuel taunts. “This is corporate malpractice on a cosmic scale, and we’re here to make sure they choke on the wreckage.”

Cambridge Samuel’s Battle Plan

With Concentrix’s April 30 deadline reduced to dust, Cambridge Samuel is cranking the heat to eleven:

  • Filings Locked and Loaded: in the course of this month, we’ll bury Concentrix with criminal complaints (Penal Code Article 348, Law No. 58/2019 Articles 44, 47) and CNPD filings for GDPR violations, retaliation, and obstruction, piling onto the complaints already roasting Cognizant, Teleperformance, and Google.

  • Regulatory Smackdown: We’re shouting for CNPD, EDPB, FTC, UK ICO, Brazil ANPD, and every regulator with a pulse to eviscerate this quartet. Fines could hit €344M for Teleperformance, €776M for Cognizant, and a fortune for Google and Concentrix.

  • Class Action Avalanche: We call on affected users and employees to join our class action (class-action@cambridgesamuel.com). Concentrix’s silence is a match to the public’s fury.

  • PR Doomsday: Our next release will make this one look like a postcard. Concentrix’s dodge is a blank check to expose every leak, lie, and blunder they’ve tried to bury.

“The whistleblowers handed us a warhead of evidence, and we’re unloading it on Concentrix, Cognizant, Teleperformance, Google, Foundever, and Vivino until they’re glowing,” Cambridge Samuel vows. “This isn’t a scandal—it’s a corporate implosion, and we’re lighting the fuse.”

About Cambridge Samuel

Cambridge Samuel fights for whistleblowers, shredding the veil of corporate misconduct to deliver transparency and justice.

Contact:

Systemic Data Protection Breaches by Cognizant, Google, and Teleperformance;

 

Cognizant Stalls Settlement Talks as Cease-and-Desist Fails
 

Lisbon, Portugal, 16 April, 2025, 12:00 WEST – Cambridge Samuel, advocating for a whistleblower, reveals overwhelming evidence of GDPR violations by Cognizant, Google, and Teleperformance (TP), implicating them in data leaks affecting millions globally.

Despite settlement talks at 11:00 WEST today and last Friday, April 11, Cognizant is stalling, dodging liability estimated at €9.64B–€790.85B, surpassing Meta’s €1.2B fine.

Just a random sample: Buganizer issue 406255379, exposes a new Waze leak: a user identifier, case reference, and Longview, TX location, shared without consent. This joins over 3,141 emails and 121 YouTube cases, including financial account IDs (e.g., pub-8122555723778080) and creator data from 30+ jurisdictions (EU, UK, US, Philippines, Canada, Brazil, Argentina, South Korea, Taiwan, etc.). Prior Waze leaks—issues exposing user identifiers, a UK location (Farrer Road), and app screenshots—confirm Cognizant’s vendor pipeline, Google’s Buganizer platform, and TP’s role mishandled sensitive data, breaching GDPR Articles 6, 9, and 32.

“Cognizant’s stalling today again, after Friday’s empty talks, is a futile cover-up,” Cambridge Samuel stated.“ The evidence—user identifiers, locations like Longview, TX, and financial leaks—is 100% ironclad, impacting 10M–20M users.” A lockout since March 28, 2025, and Cognizant’s April 7 cease-and-desist (published below, along with Cambridge Samuel´s answer), wrongly alleging misconduct, highlight retaliation, protected under Law 93/2021. Cambridge Samuel’s response, backed by legal review, deems the cease-and-desist baseless, escalating pressure for accountability.

 

The Cease and Desist Letter:

 

 

 

 

 

Cambridge Samuel´s Reponse:

"Dear Mr. Martins,  

We are in receipt of your laughably overreaching cease-and-desist letter dated April 7, 2025, sent at 22:32 WEST, on behalf of Cognizant Technology Solutions Portugal, Unipessoal Lda. (“Cognizant”). 

 

Your attempt to intimidate Cambridge Samuel—an advocacy platform championing whistleblowers and employee rights—into silence is as misguided as it is futile. Far from cowering, we find your threats a delightful addition to our arsenal, providing fresh fodder for our next press release. Rest assured, neither we nor the whistleblower will be silenced by your hollow bluster; rather, your letter amplifies our resolve and exposes Cognizant’s desperation to suppress the truth.

Your Claims Are Legally and Factually Bankrupt

Let’s dismantle your allegations with the precision they lack:

 

  1. Alleged GDPR and Privacy Violations (Penal Code Article 192)
    You assert that our April 7, 2025, press release discloses identifiable personal data, constituting a GDPR breach and “Devassa da vida privada” under Article 192 of the Portuguese Penal Code. This is nonsense. The data cited—e.g., Case ID 3-6878000038759, a YouTube channel URL from February 21, 2025—is drawn from an overwhelming trove of evidence, a mere sample of the 3,141+ emails spanning 494 + days since December 1, 2023. This evidence, meticulously documented by a protected whistleblower, exposes systemic breaches by Cognizant, Teleperformance, and Google, not private individuals. Under GDPR Article 5(1)(f), such disclosures are lawful when in the public interest, as these are—exposing unencrypted leaks of global YouTube and Waze user data affecting millions. Your claim that this violates Article 192 is equally absurd; no private life is invaded—only corporate malfeasance is laid bare. 

  2. Defamation (Penal Code Article 187)
    You label our statements—e.g., Cognizant’s negligence, regulatory misconduct, and ethical failures—as “unsubstantiated defamation.” Unsubstantiated? We invite you to review the evidence: 3,141+ emails, bug logs, and screenshots. These aren’t opinions; they’re facts, backed by a whistleblower’s ironclad documentation. Under Portuguese Penal Code Article 187, truth is a defense—our claims are not only true but overwhelmingly proven. Cognizant’s 494-day + negligence, your instigation of the March 28 lockout (executed by Google), and your bad-faith silence until April 7 speak louder than your legal posturing. Calling this defamation is like calling the sun bright—obvious and unassailable.

  3. Whistleblower Protection Rejection
    Your assertion that our disclosures fall outside Law No. 93/2021 and EU Directive 2019/1937 is a masterclass in misreading the law. Article 6(1)(a) of Law No. 93/2021 permits public disclosure when internal or external channels—like Cognizant’s deafening silence since March 21, 2025—are ineffective. The whistleblower’s repeated attempts (e.g., March 21, 28, March 31, April 2) met with your inaction justify this step. EU Directive 2019/1937, Article 15, echoes this: public reporting is protected when it serves the public interest, as exposing a 494-day + data breach crisis undeniably does. Your claim of “indiscriminate dissemination” ignores the targeted, evidence-based nature of our release—crafted to hold Cognizant accountable, not to scatter secrets. Your legal gymnastics won’t rewrite these statutes.

Your Threats Embolden Us

Your demand to “cease and desist” is as ridiculous as it is unenforceable. Far from retracting, we’re emboldened—your letter is a goldmine of irony, showcasing Cognizant’s panic as the whistleblower’s evidence tightens the noose. Threatening civil, regulatory, and criminal action? Bring it on. We relish the chance to parade our 100% substantiated evidence—3,141+ emails, medical records of burnout (e.g., Teladoc, April 7), and your own lockout complicity (March 28)—before regulators like the CNPD and ACT, or in court. Your “swift action” ultimatum? We’ve already acted—our press release stands, and more are coming, enriched by your ill-judged missive.

Cognizant’s Bad Faith Fuels Our Fight

For 494 + days, Cognizant ignored breaches risking millions of users, then locked out a whistleblower on March 28, 2025, at 05:13 WET—one day after his disclosure. Your April 7 email to him (22:33 WEST), threatening extortion and defamation, and this cease-and-desist are textbook retaliation—prohibited by Law No. 93/2021, Article 21(5), where the burden falls on you to disprove it. Good luck with that; the evidence buries you. This isn’t a glitch—it’s a calculated cover-up, and your letter is its latest, laughable chapter.

Our Next Steps

 

Cambridge Samuel will not remove a syllable from our April 7 release—every word is backed by ironclad proof. Instead:

 

  • We’re updating it with your threats, headlined: “Cognizant’s Baseless Bullying Backfires, Proves Whistleblower Right.”

  • We’ll escalate to the CNPD, ACT, and Ministério Público, appending your letter as exhibit A of bad faith.

  • Our class action efforts grow—your intimidation only swells the ranks of affected employees contacting us.

Your demand for silence has the opposite effect: it’s a megaphone for our cause. Cognizant’s €344 million GDPR exposure and your executives’ 1-3 year prison risk (Law 58/2019, Penal Code Article 348) loom larger with every futile threat. 

 

We suggest you redirect your energy—restore the whistleblower’s access, release the logs, and face the music. Until then, we’ll keep amplifying the truth, with your letter as a comical footnote."

Kind regards,

Cambridge Samuel​

​​

Friday’s discussions (April 11) established Cognizant, Google, and TP’s intertwined roles, with Cognizant handling the vast majority of YouTube cases and Waze leaks. Yet, today’s refusal to engage meaningfully shows bad faith. “This dwarfs Meta’s €1.2B,” Cambridge Samuel added. “Regulators like CNPD, EDPB, and FTC will intervene, and public outrage will demand justice.”

Cambridge Samuel urges immediate regulatory action and user advocacy, warning that Cognizant’s delays invite a PR reckoning. Filings citing over 3,141 leaks are poised for submission unless settlement terms are met. Cognizant has until 13:00 today to show good faith, or criminal and regulatory complaints will be filed today.​​

 

About Cambridge Samuel


Cambridge Samuel champions whistleblowers exposing corporate misconduct, driving transparency and justice.

class-action@cambridgesamuel.com

public-relations@cambridgesamuel.com



Lisbon, Portugal, April 11, 2025, 11:00 WEST ---- UPDATED PRESS RELEASE



FOUNDEVER AND VIVINO

EXPOSED IN 16-MONTH

GLOBAL DATA PROTECTION 

BREACH
SCANDAL



Lisbon, Portugal – April 11, 2025, 11:00 WEST

Here’s the scene: two hard working employees at Foundever Portugal, S.A., a customer experience giant that runs call centers and support services for global brands, are fed up with a toxic workplace and HR’s endless stonewalling, and step into the ring with a fury that’s shaking corporate giants to their foundations.

Wielding Portugal’s Law No. 93/2021 and the EU Whistleblower Directive (2019/1937), these
whistleblowers aren´t backing down—they´re unleashing a storm that exposes a 16-month GDPR
breach catastrophe at Foundever Portugal, S.A. and Vivino ApS, the world’s largest online
wine marketplace connecting wine enthusiasts with producers and retailers, slamming
employees, clients and end users across the EU and U.S. with brutal force. This isn’t just a
lone stand; it’s a worldwide rebellion, with the whistleblowers as the fierce champions every
worker cheers for, turning HR’s dirty tricks into a €700M-plus showdown, a class-action
juggernaut, and a reputational blow that could shatter Foundever’s credibility and Vivino’s
shaky financial footing—imagine the stock prices tanking.

The proof hits like a freight train: a Leadership Meeting Agenda from October 23, 2023,
uncovers Foundever’s systemic GDPR violations—unauthorized retention of client data in
Salesforce, impacting EU and U.S. clients, breaching GDPR Articles 5, 9, 15, and
32—raised by a Foundever trainer who sounded the alarm on this disaster-in-waiting.


























Slack messages from that day reveal Vivino management brushing it off as “not an issue,” despite
the trainer’s dire warning: “illegal and can cause Vivino to have to pay a fine of 4% of their
yearly revenue.”

Foundever knew, Vivino ignored, and 16 months later—over 500 days of inaction—they’ve neither reported to the CNPD nor addressed the chaos, violating GDPR Article 33(1)’s 72-hour notification mandate.














 
 
 
 
 
 
 
Then comes the December 13, 2024, outrage: Foundever (senior) managers mocked
another whistleblower’s health condition in a meeting, as confirmed by the trainer’s statements
(February 24 and March 17, 2025), trampling GDPR Article 9 and Labour Code Article 29.
The retaliation followed: the trainer faced punitive shift changes on February 24, 2025,
leading to sick leave from February 27, 2025, without end of sick leave in sight, while the other whistleblower was fired on February 12, 2025, hours after raising the harassment in a call with a Foundever operations manager and HR official, breaching Labour Code Article 331 and Law No. 93/2021 Article 20.

Foundever’s responses are a textbook corporate dodge. Their Data Protection Officer’s
March 21, 2025, letter denies the December 13 breach, claiming “no evidence” despite the
trainer’s testimony, and sidesteps the systemic breaches entirely. The Senior HR Manager’s
March 24 letter doubles down, rejecting the harassment claim as baseless and falsely
stating the whistleblower missed a December 4, 2024, health exam without justification—he
was on sick leave with a GP note, per Labour Code Article 104(2).

Vivino’s silence speaks volumes, their refusal to comment woven into our narrative as a
damning indictment of their complicity, leaving Foundever to face the fallout of their client’s
inaction. Foundever’s refusal to provide demanded evidence, their silence on the GDPR
breaches, and their failure to engage in meaningful settlement negotiations by COB March
24, 2025, roar louder than any corporate spin.

This is a full-throttle uprising. The whistleblowers, backed by Cambridge Samuel, a fierce
advocacy force, seasoned (former) litigators, and a global law firm, are bringing the fight: complaints
to the ACT and CNPD,  filed February 21, 2025, updated March 4 and March 15, and now bolstered with the March 17 evidence—Leadership Meeting Agenda, Slack Correspondence, and the trainer’s statement—are in motion. Criminal Complaints, against - among others - the leadership cadre, including, but not limited to it´s Portuguese administrators - one of them also being the CFO and responsible for Foundever EMEA - based in Paris, will be filed before Easter.

Given Foundever´s and Vivivo U.S. operations and the impact on U.S. clients, the FTC is a primary authority, with state attorneys general also poised to step in for broader enforcement and penalties, alongside court filings in Portugal, a class-action lawsuit across all affected countries including the U.S. seeking
$50M–$500M, all being filed promptly, with damages that could match TikTok’s €345M fine in 2023 or Meta’s €1.2B in 2023. The whistleblowers` calls are clear: Foundever and Vivino
must step up—overhaul data security, compensate victims, and report quarterly to
regulators, or face the fury of employees, clients and end users everywhere.

From a 16-month GDPR breach to HR’s vindictive tactics, this evidence demands
regulators act, impacting employees, clients and end users from Europe to the Americas.

The press is circling: this double-barreled crisis—trampling GDPR and basic decency—elevates the battle of two hard working emloyees, and we’re all cheering, saying, “At last, someone’s hitting HR and the execs where it stings.”

Contact: public-relations@cambridgesamuel.com / class-action@cambridgesamuel.com

Evidence Available: Upon request, redacted samples verifiable by regulators and media.

About Cambridge Samuel

Cambridge Samuel is a leading advocacy platform specializing in whistleblower cases, particularly in call centers, dedicated to pursuing justice for employees facing systemic
misconduct and data protection violations.

End of Release

Home: In the Press
Making Notes
Team Meeting
Business Meeting
Home: Industries

CONNECT WITH US

Thanks for submitting!

Email:

public-relations@cambridgesamuel.com (press) 

legal@cambridgesamuel.com (legal / regulatory issues) 

class-action@cambridgesamuel.com (Law No. 83/95, Article 26).

 

Phone:

214 00 55 00 (by appointment only)

Disclaimer: Cambridge Samuel is a nonprofit advocacy platform, not a legal firm. For legal advice, consult a lawyer. We do not handle funds or engage in economic activities. Contact us at class-action@cambridgesamuel.com or legal@cambridgesamuel.com for inquiries.

Home: Contact
  • Facebook
  • Twitter
  • LinkedIn

©2021 by Cambridge Samuel. Proudly created with Wix.com

bottom of page