3 ms·
Regardless of the size of organization, GDPR applies. In particular, note the section "Right of Access": * https://en.wikipedia.org/wiki/General_Data_Protectio
by coreyoconnor 8y ago
Regardless of the size of organization, GDPR applies. In particular, note the section "Right of Access":
* https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Right_of_access https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Which requires the organization to supply information about use of personal information. This will have an operational overhead regardless of scope of Personal Information used.
For a worse-case (hopefully impossible) variant of what this request looks like: https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/ https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
Oh please somebody correct me if I'm wrong. Otherwise that's a silly amount of operational overhead for bootstrapping. Even for systems designed from the start to not use personal data: The org would still need to handle a rather detailed and costly administrative request.
- jv22222 8y agoWow that article is scary. Even worse would be "remove all my data from all your backups".