Thank you for raising this.
Yes, I have experienced similar issues as an EU consumer, although my situation involves three separate GDPR-related matters.
The first matter concerned the original GDPR complaint, which resulted in a settlement. A key condition for me accepting that settlement was written confirmation that the supplied products would have warranty and support, except for the agreed limitation regarding return/refund rights.
The second matter concerned stored personal data. I submitted a GDPR access request, and the response was provided two days after the statutory deadline. The data supplied was, in my view, incomplete, inconsistent and not possible to verify in any meaningful way. That matter concerns, among other things, GDPR Article 12 regarding clear communication and response obligations, Article 15 regarding access to personal data, Article 5 regarding accuracy, transparency and accountability, and Article 16 to the extent inaccurate data requires rectification.
The third and current matter concerns the support restriction itself. After Bambu Lab later treated the settlement items as if they were merely a gift, and after I was restricted from normal support handling, I submitted a new GDPR access request asking for all personal data and internal records behind that restriction and differential treatment. This includes account flags, support-system notes, moderation records, routing rules, ticket-handling records, internal decision logs, timestamps, and any manual or automated basis for restricting my support access.
The GDPR provisions I have relied on across these matters include, in particular:
- Article 5(1)(a), 5(1)(d) and 5(2): lawfulness, fairness, transparency, accuracy and accountability.
- Article 6(1): the legal basis for processing and using account, support and restriction data.
- Article 12(1)–(4): clear communication and the obligation to respond within the statutory time limit.
- Article 15(1) and 15(3): right of access and right to receive a copy of the personal data being processed.
- Article 16: right to rectification where stored data is inaccurate.
- Article 22, to the extent automated decision-making or profiling has been used for support restriction, prioritisation, moderation or ticket handling.
- Article 77: right to lodge a complaint with a supervisory authority.
- Article 79: right to an effective judicial remedy against a controller or processor.
- Article 82: right to compensation where damage results from unlawful processing.
After I reminded them that silence, internal clarification, or delay does not reset the GDPR response deadline, their ticket communication shifted into language suggesting that I should not reply further, otherwise I could supposedly violate their support policy.
These are not one single complaint from my side. They are three separate GDPR-related matters, and I am treating them as separate cases:
- The original GDPR complaint, which resulted in the settlement.
- The later GDPR access request concerning stored personal data, where the response was late and, in my view, incomplete and not meaningfully verifiable.
- The current GDPR access request concerning the support restriction, differential treatment, internal account flags, ticket handling, moderation/support notes, routing rules, and any manual or automated basis for restricting my access to support.
My position is that each of these matters must stand or fall on its own facts and evidence. It is therefore not necessary for every issue to be upheld for the matter to become serious. If only one of the three cases is found by a competent supervisory authority or court to be well-founded, that may still expose Bambu Lab to regulatory and/or judicial consequences.
The original GDPR matter has also been reactivated from my side because my position is that their later handling of the settlement items and support access contradicts the basis on which the original settlement was accepted.
I also want to be clear that this should not be directed at ordinary support staff. In most companies, support agents operate within policies, scripts and escalation rules set by management. My criticism is therefore aimed at the company’s handling, governance, support-policy enforcement and data-processing practices, not at individual frontline employees simply doing their job.
The only exception I previously considered was a separate matter involving a forum moderator, but I withdrew that complaint at the time. That situation arose after I was accused of having “done bad things” during a period when my account was already suspended and I could not even access it. The account was then removed entirely from the system, and I was prevented from registering a new account. The remaining anonymised account record was tagged as anon7206378@anonymized.invalid, which appears to be the address generated when an account is deleted or anonymised.
Because the first GDPR matter is now active again, I am also reviewing whether that moderator-related matter should be pursued further. My concern is not personal dislike. It is the principle that moderation must be rule-based, consistent and evidence-driven. A moderator should enforce forum rules neutrally, not make unsupported accusations or take account-level actions in an arbitrary manner.
As far as I know, Bambu Lab was not previously informed of that separate individual-related complaint, because it concerned the conduct of an individual moderator rather than the company as such. However, given how the broader GDPR and support-access issues have now developed, that matter may also become relevant again.
There are now publicly visible examples of users and creators coming into conflict with Bambu Lab over support, consumer rights and legal pressure. What I find notable is the asymmetry: Bambu Lab appears very comfortable relying on policy language, ticket rules and legal positioning when dealing with users, but when an EU consumer uses the same formal tools available under GDPR and consumer law, the response seems to shift toward restricting communication rather than giving a clear, documented answer.
For that reason, I am not treating this as a normal support disagreement. I am treating it as a documented pattern involving settlement compliance, access to personal data, transparency, accountability, forum/account handling, moderation records, and the restriction of support channels after GDPR rights were exercised.
So yes, I recognise the same pattern: conflicting support positions, lack of clear official clarification, restricted communication channels, delayed or inadequate GDPR responses, unclear account/moderation handling, and no transparent explanation for how support restrictions are decided or applied.