31 ms·
I don't believe that is true. Credit Bureau's and Insurance companies have information about every place you have lived and worked, what school you attended. T
by fromMars 7y ago
I don't believe that is true. Credit Bureau's and Insurance companies have information about every place you have lived and worked, what school you attended.
The actual ratings may be waited on information in the last X years.
Also, it is much easier to implement a policy where no data can be retained after X years than on-demand wipeout.
- NeedMoreTea 7y agoNeither has which school I attended, or has ever asked. An insurer has employers, but only those whilst insuring with that company. I suppose my bank could have told the credit rating agency, but they'd have to infer it from the monthly wages deposit. Is that required in the US? If they are only weighting on the last 5 years they no longer have a business case under GDPR to retain it[1]. Essentially it crystalises in law what should already have been the case. > it is much easier to implement a policy where no data can be retained after X years than on-demand wipeout Not sure how when all that changes is the clock. [1] If my account was fraudulent in some way, or there's a law requiring some retention, there is a business case for retaining longer, and it is permitted.
- fromMars 7y ago> Not sure how when all that changes is the clock. This is most surely not the case. Many data stores are simply dated collection of files. With fixed expiration for all data you can simply implement GDPR with things like TTLs and making sure that any downstream systems do not consume data older than a certain date. With individual wipeouts that can happen at any time this becomes much more challenging. Now all data, in all systems that use that data have to the ability to wipe data at the individual record level on demand. This broad implications especially depending on how interpret whether things like derived models, aggregate stats, etc. need to be recalculated in light of GDPR requests.