4 ms·
If you’re in Europe (or a citizen living outside) you can make a GDPR subject access request to get a copy of your data. Try to specifically ask for a record of
by gingerlime 4y ago
If you’re in Europe (or a citizen living outside) you can make a GDPR subject access request to get a copy of your data. Try to specifically ask for a record of how your data was obtained. And you can also ask to be deleted permanently. It might or might not work but it’s what you are entitled to under the GDPR.
edit: check out https://yourdigitalrights.org/ https://yourdigitalrights.org/ which might give you some templates and check whether you’re covered by other privacy regulations in case the GDPR does not apply.
- Dayshine 4y agoThe argument they make is that it's OK because they got your details from a "public" data source, plus guesswork. E.g. LinkedIn plus your company domain. They're still supposed to notify you when your info was transferred to them though. The problem is that this is in breach of LinkedIn terms and conditions, which means I immediately write off the company: if they can't lawfully find marketing leads, which should I trust them to lawfully process my business data.
- gingerlime 4y agoIANAL and could be wrong here, but I don’t think it matters. Personal data is personal. Even if it’s posted publicly it’s still personal data. Email is personal data. Your name is personal data. Plus spam laws are a thing. In any case, at the very least GDPR gives you a chance to delete your data. Hopefully so it doesn’t reappear either.
- hnbad 4y agoWhether PII is publicly available or not doesn't matter, they are still processing and storing it without consent. This works differently from "expectation of privacy" in the US, for example, where often anything is fair game as long as you can trace it back to a public space. You could literally staple your business card to your building's front door and they can't use it without explicit consent. Heck, the other day I called my legal insurance and the lawyer they referred me to initiated the conversation with reading out a GDPR disclosure because he needed my insurance number and needed to sync it with the insurance company (a third party), which meant transferring PII.