3 ms·
Can you define "private informations" and "need" in unambiguous ways, please? In my experience it's shockingly hard to do so once you get beyond the basics. Ev
by Kalium 4y ago
Can you define "private informations" and "need" in unambiguous ways, please? In my experience it's shockingly hard to do so once you get beyond the basics.
Even when you have clear legal obligations to collect a bunch of private data, you still have to figure what reasonable measures to protect it are. What's a reasonable measure when you're obligated to keep seven years of financial records about your customers in a way that lets you produce ready reports for regulators? Complete with mandatory personal identifiers for tax purposes?
- robin_reala 4y agoI’m not sure what you mean with your second point. A legal need to collect and process personal data is a valid GDPR basis. You don’t need to get consent there.
- Kalium 4y agoYou don't, but obligations under GDPR include taking "reasonable measures" to protect the private information you're obligated to collect. The point I was making is that this underscores is how difficult it is to define "reasonable measures" because not collecting private information is not always an option. GDPR is not just about being obligated to ask for consent. Its requirements go a great deal further. Probably. Maybe. Depending on what someone unknown with an unknown background considers reasonable based on unknown factors. I'm sure that will be easy to write requirements around. Right?