3 ms·
Which things that are mentioned do you believe are not covered?
by molf 9y ago
Which things that are mentioned do you believe are not covered?
- kasey_junk 9y agoI’m not a GDPR lawyer or auditer, do nothing in this reply should be seen as advice. My general feel is that if he didn’t cite a specific article it was on purpose. He took implications or broad interpretations for anything not explicitly cited. A couple that jump out immediately are the requests for server locality information, retention periods & specifics about security policies are the ones that are likely to get a very polite “we conform to industry best practices piss off” replies.
- molf 9y agoThat's all neatly laid out in article 13. [1] I'm not a lawyer but having extensively studied all of GDPR recently I'm afraid the letter seems legit. If there's any error it will be a minor one. [1] https://gdpr-info.eu/art-13-gdpr/ https://gdpr-info.eu/art-13-gdpr/
- kasey_junk 9y agoArticle 13, to my reading, provides no basis for requiring locality information or security policies. The retention declarations I’ve seen have been legal niceties that don’t answer the question in a way that makes it clear what the retention policy is. I’m not suggesting that the letter won’t get a response. I’m suggesting there isn’t anything in it that would cause a large organization to send any different a response than if they got a letter written in crayon that said “gives us the GDPR data”. In that way it’s not a “nightmare” letter. It’s the default thing you pay lawyers for.