3 ms·
I would say that you could provide a notice specifying that signing the guestbook also constitutes consent to the public display of the person's name. If you w
by donogh 8y ago
I would say that you could provide a notice specifying that signing the guestbook also constitutes consent to the public display of the person's name.
If you want to take it further, you could ask them to submit a small form confirming their consent.
Worst case, you redact their name -- use a marker! -- and document that process as part of your data review.
Either way, it's complete overkill. It's not about following the letter of the law; it's about the spirit of the law. No one is going to get sued or fined for providing a public guest book.
- existencebox 8y agoTwo notes here: First, pedantically, (But in the interest of maintaining my "trying to reiterate the letter of the law as I understand it") I'm pretty sure interactive/implied consent isn't considered sufficient; (Interactive consent being what was allowed for EU cookie compliance) and that one cannot "Sign away" GDPR protection. Second, while I agree that it's overkill, I'm operating from the "This is the rigorous interpretation that people far more legally versed than myself have established". This may not be the right decision for a smaller corp or business entity, as it is in my case for a notable multinational. While I might agree that I'd have an absolute spit-take if such a small entity were made an example of, I can also understand the paranoia on the other side, especially given the context of US jurisprudence and how it differs from the "tone" of EU-style enforcement.
- donogh 8y agoNo argument on either point. We have to be practical, though, and the law is usually forgiving of such practicalities. You're right, though: strictly speaking, it's not compliant.