3 ms·
>What it means is that they are probably selling user data and cannot keep doing it without informing users of it. It seems like you'd have to willfully misund
by Permit 8y ago
>What it means is that they are probably selling user data and cannot keep doing it without informing users of it.
It seems like you'd have to willfully misunderstand the requirements of GDPR to argue that the only reason for non-compliance is that 'they are probably selling user data'.
However, if you can instead imagine that two employees might not want to manually manage GDPR requests for a userbase of two million users (in their free time, no less!) then you might come up with other likely reasons for non-compliance. For example, I wouldn't want to architect a backup system that deletes user info from my backups whenever I receive a GDPR request.
- bad_user 8y agoIf the service can’t delete a couple hundred links, representing private interests I might want to erase, then it’s not a service I’d like to use. Deleting my data is an ability that I want in all the services that I use. Also I do know what the GDPR requirements are, as I’ve been in charge of GDPR compliance. While we may disagree on how easy or hard it is to implement it, there’s nothing in it that’s not common sense, which shouldn’t need a law for companies to implement. Tip: if you’re doing backups, encrypt them with the user’s key and on deletion just throw away the key. Not rocket science.
- bcoates 8y agoI don't think that helps unless I don't back up the user's key too.