2 ms·
"It is difficult to get a man to understand something, when his salary depends upon his not understanding it!" The law is pretty clear (not 100% clear, obvious
by Fradow 8y ago
"It is difficult to get a man to understand something, when his salary depends upon his not understanding it!"
The law is pretty clear (not 100% clear, obviously, there is going to be loophole and unclear things), and it's easy to decide about unclear spots by following the spirit of the law, and by understanding that any unclear technical requirements really means "what a sane engineer would do, that you could defend against a jury of your peer".
To answer a few of your questions (obvisouly IANAL):
- are IPs PII? Yes, there are legal case about that, your lawyer should have a more detailed answer.
- what exceptions can be allowed? When you have a case you could defend that doesn't go against the spirit of the law
- what falls under "security requirements"? You should be able to defend your choices securiy-wise against a jury of your peer, using your internal documentation. If you have unsalted passwords hashs for example, you are in trouble
- what sort of deanonymization is sufficient? Best practices at the current date.
Technical details aren't going to be in the law, because the goal of a law is to not be outdated every year.
Laws are enforced by humans, not by computers. Your company should be prepared to defend its interpretation of the law (that's your lawyer job) and your technical choices (that's your job).
Edit: obviously, that's a simplified vision, and you should always consult your lawyer. The biggest your company is, the more important it is to try your best to be compliant.