5 ms·
That seems like a weak argument though. Two humans can also have same name and zipcode. They can also have same personal number and bank account number if they
by evfanknitram 8y ago
That seems like a weak argument though. Two humans can also have same name and zipcode. They can also have same personal number and bank account number if they are in different countries. Without tracking and correlation, most information on its own is useless.
- geocar 8y agoYes. That's The ICO's position: https://ico.org.uk/media/for-organisations/documents/1591/personal_information_online_cop.pdf https://ico.org.uk/media/for-organisations/documents/1591/pe...
- bostik 8y agoThis reads like you are intentionally trying to misunderstand. GDPR has two categories of user information: direct identifiers and indirect identifiers. Direct identifiers are pieces of data that allow to target a person, or a very small group of persons from a single data point. Indirect identifiers are anything that you could use to build a marketing cohort. Combining a few indirect identifiers allows to target very specific groups of people. Or, using the very examples you quoted: - The tuple (bank account number, country) is enough to target an individual. - The tuple (full name, zip code) is enough to target a very small group of individuals. By adding just one more element you can identify individuals.[ß] Each one of the four data points counts as user information under GDPR. Doesn't matter whether they are direct or indirect. Disclosure: I wear the DPO hat at Smarkets. As a gambling company we are legally required to know quite a lot about our customers. ß: For the nitpicking armchair lawyers: unless you happen to have a gated community for John Smiths.
- evfanknitram 8y agoI have no idea what you mean. I was not talking about GDPR.