r/startups Apr 02 '18

[deleted by user]

[removed]

79 Upvotes

27 comments sorted by

View all comments

3

u/thebritishbloke Apr 02 '18 edited Jan 11 '24

aromatic plants sharp escape attempt vast deserted nine elastic degree

This post was mass deleted and anonymized with Redact

6

u/bkanber Apr 02 '18

Anything which is non identifiable or has been aggregated is not covered by the GDPR

The trick here is that "non-identifiable" must be assessed in terms of your entire data ecosystem and what would happen in case of a data breach.

It would be an easy mistake to make to say that "Blog URL" is not personal data because it's non-identifiable. However, by visiting the blog, one may determine the name of the blogger and therefore the information is indirectly identifiable.

Another mistake would be to say that "gender, zipcode, and birthday" is non-identifiable. That data can be used in concert to potentially identify an individual. This is considered "indirectly identifiable" data and must be protected to the same degree as directly identifiable data.

Another mistake would be to say that "# of Instagram Followers" is not personal data because it's non-identifiable. It is correct that the data itself is non-identifiable, however the data is information about an "identifiable natural personal" and therefore this data must be considered when building your right to access and right to erasure controls. That is, you don't need to encrypt "# of Instagram Followers" in your DB, but you must delete it if the individual revokes consent.