3 ms·
That is too simplified. At least the part about the right to delete the data. In my understanding it is not legal to keep all data because a user paid for a ser
by funcDropShadow 4y ago
That is too simplified. At least the part about the right to delete the data. In my understanding it is not legal to keep all data because a user paid for a service. In German law you are required to keep the data for the invoice. But I am not a lawyer.
- that_guy_iain 4y agoGerman lawyers told me that we were to keep all data. There is also an exception in the law for the need to provide abiltiy to provide legal defence. Which is mentioned in the blog but not in the examples. I'll an add an example so it clearer about that.
- funcDropShadow 4y agoThat may have been true in your specific case, but that does not generalize.
- beidnnwuudu 4y agoFrom someone who is not a lawyer, but was responsible for GDPR compliance at a major hospital in Germany: You may want to switch your lawyers.
- moooo99 4y agoSomeone who is not a lawyer but had to deal with our legal department more frequently than I wish: it absolutely depends. In German law you are to keep any information regarding invoices for at least 10 years in their original format. This legal necessity usually overrides the right to delete. However, what this archiving of payment data entails differs based on how the payments are received/processed and how invoices are issued. The implications are different depending on when you pay cash, via a SEPA transfer or via a third party processor like Stripe/PayPal/Paddle. But this whole debate is a perfectly adequate demonstration what the biggest issue with the GDRP/DSGVO is: it is extremely complex and intransparent. EU lawmakers successfully implemented a law that makes it rather difficult for newcomers to enter a market with a (digital) product without putting themselves at risk or spending tons of consulting with a specialized lawyer. Despite repeated claims of officials that they intend to make the EU a more attractive location for digital businesses, their actions often speak different words.
- markus92 4y agoYou need financial data of course, but you don't need a record stating I logged in 2 years and 5 months ago at 09:15 in the morning from an iPhone 8 from IP xxx.xxx.xxx.xxx and used your app for 12 minutes, I have every right to request you to delete that information as it is not necessary for legal defense (chargebacks) or lawful. You might be non-compliant by keeping that information actually.