3 ms·
You are right. The rights of the user depend on the legal basis you choose. This is covered here[1] Basically: * The right to object is not applicable if you
by BeniBoy 6y ago
You are right. The rights of the user depend on the legal basis you choose.
This is covered here[1]
Basically:
* The right to object is not applicable if your processing is based on contract, legal obligation or protection of vital interest
* The right to erasure is not applicable in case of a legal obligation or public interest
[1]https://github.com/LINCnil/GDPR-Developer-Guide/blob/master/15-Take%20into%20account%20the%20legal%20basis%20in%20the%20technical%20implementation.md#rights-exercises-and-modalities-of-information-to-be-provided-according-to-legal-basis https://github.com/LINCnil/GDPR-Developer-Guide/blob/master/...
- ArnoVW 6y ago.. and since one is obliged to keep 10 years of history for tax auditing reaons, the whole point becomes moot. Yes, you can ask that your avatar image be removed. But they can easily claim that your name, address, bank account number are needed for tax auditing and Know Your Customer purposes. https://en.wikipedia.org/wiki/Know_your_customer https://en.wikipedia.org/wiki/Know_your_customer
- vertex-four 6y agoSure, but only if you you then never process that data for reasons not covered by your legal basis and privacy policy. It's not only the collection of data that is covered by the GDPR - it's any processing as well. Easiest way to do this is probably to duplicate data into another table for tax audit purposes, that your "normal" applications have no permission to read. Then you can delete everything your application can access and still keep legal records.
- njb311 6y agoI wouldn’t say the _whole point_ becomes moot. As you have to have a legal basis for each type of data that you are storing or processing, relying on different legal bases can add complexity to the problem of a deletion request. Just because you have to retain some information does not give a free pass to retain everything. Also, remember that data subjects have a right to limit the purposes for which their data is used – systems need to be able to cope with that. This is where a well thought-out and documented approach to personal information makes everything easier, for internal users of that data too. For legacy systems it can be a nightmare because nobody seemed to care, but with a clean sheet, _why wouldn’t you_ address data protection and privacy from the outset?