3 ms·
I don’t see a lot of comments looking at the practical side of things. I am implementing GDPR and here are some suggestions: 1. Collect only what is necessary
by smooc 8y ago
I don’t see a lot of comments looking at the practical side of things. I am implementing GDPR and here are some suggestions:
1. Collect only what is necessary for providing your service
2. Make clear what you store and for what reason
3. Ask consent and give the opportunity to retract this consent as easily
Deletion:
1. PII means information that makes a person identifiable. This is the type of information that you need to remove
2. So if you are storing PII information for the use of profiling you will need to disconnect the profile from the PII information. E.g. you could use user table where you would overwrite the PII information with generic information. You can still use the now stale profile withou PII information (for example in statistics, aggregations etc), but you cannot tie it to a single person anymore. Ie. You should not be able to reconnect the person to profile you have stored.
3. As technical possibilities evolve you need to improve the disconnection over time.
There are legitimate business reasons to store some PII information. E.g. for security reasons, other laws etc. So IP addresses don’t need to be deleted from your web logs, but if not given consent you cannot use them for ads, sell them etc.
The required clarity that GDPR will bring to your data is actually going to benefit you. Your data scientists will love it, because the tooling that helps with Gdpr also helps with discoverability, data quality etc.
Enjoy GdPR, there is a lot of business opportunity in it.