3 ms·
And yet other laws require the collection and retention of sensitive user data, in particular any service that allows for transmission of large amounts of money
by testvox 7y ago
And yet other laws require the collection and retention of sensitive user data, in particular any service that allows for transmission of large amounts of money (crypto exchanges were a good example).
- aforwardslash 7y agoThat is well covered within GDPR scope. Retaining data to fulfill legal obligations is allowed. One common related example is invoice data.
- AnthonyMouse 7y agoBut then "just don't keep the data" is not an effective response to these attacks of requesting someone else's data.
- rusk 7y agoYes, it requires people to be trained in this area to make these judgements ... imagine that!
- nameismypw 7y agoHow well is that turning out? You can't rely on people to get it right 100% of the time. I definitely wouldn't.
- johnisgood 7y agoI signed up to a crypto exchange, then I requested removal of my account and data and they said they cannot delete my data. Guess what? I had zero transactions, the account was new, etc. They are legally obliged to keep almost nothing for 7 years. How lovely. At least they were open about it, right? Some will just tell you they deleted your account when in fact it was just a soft delete. Screw these places. I, for one, hope that Bisq will become popular.
- rusk 7y agoYou don’t have to get it right 100% of the time, you just have to look like you’re trying.
- btown 7y agoNot to mention anything that requires the provision of real-world goods and/or services. If a data protection law ever had sufficient teeth and regulation to cause Uber or Seamless to force a user to type their credit card information and home address every time they wish to make a transaction, it would be wildly decried as paternalistic by the public. And those companies are equally vulnerable to this type of social engineering. GDPR identity verification as a service would be an amazing thing to have. Articles like [0] bring up a sad irony: in order to verify someone's request to delete their information, you need to obtain information from them in an unusual way that you may not have built infrastructure to easily or automatically delete. [0] https://www.braze.com/perspectives/article/gdpr-compliance-data-subject-identity-verificationgdpr-compliance-data-subject-identity-verification https://www.braze.com/perspectives/article/gdpr-compliance-d...