5 ms·
https://eur-lex.europa.eu/eli/reg/2016/679/oj https://eur-lex.europa.eu/eli/reg/2016/679/oj, the 26th section. I think that covers what we’re talking about her
by adav 7y ago
https://eur-lex.europa.eu/eli/reg/2016/679/oj https://eur-lex.europa.eu/eli/reg/2016/679/oj, the 26th section.
I think that covers what we’re talking about here. As in, it is ok to just delete the link between a real person to an anonymous key and not all their anonymised data. That allows one to avoid having to delete all the data itself (imagine how hard that would be from historical backups etc).
- icebraining 7y agoLike that text says, as long as a single person can be - even indirectly - identified from the data, it's only pseudonymized, and the GDPR protections apply. Even an IP address can be personal data.
- mgkimsal 7y agowouldn't you have to know about the person in question first before you can 'indirectly' make the connection?
- icebraining 7y agoYes, the point is also to limit "merges" of databases, which build extremely detailed profiles from seemingly inconsequential records. As the US Privacy Protection Study Commission wrote way back in 1977, “The real danger is the gradual erosion of individual liberties through automation, integration, and interconnection of many small, separate record-keeping systems, each of which alone may seem innocuous, even benevolent, and wholly justifiable.”