3 ms·
If you mean complying with requests for deletion, exports of personal data or name updates I suppose that can be handled via email as well. Since it's all manua
by t0astbread 5y ago
If you mean complying with requests for deletion, exports of personal data or name updates I suppose that can be handled via email as well. Since it's all manual I would assume you can just update the files and re-generate the site.
The only real problem is verifying the legitimacy of requests. How do you know for sure that an email containing a GDPR request came from the same person that also sent the comments? I guess you could come up with some rules. For example, if the request was signed with the same GPG key as the original comments or if a request passes DMARC...
I'm curious to hear what the author thinks of that!
Addendum: If you track your website's sources in a public VCS and include comments in there you probably have to run a "filter-branch" (or whatever your VCS has for that) over it to purge PII from the version history.