| ▲ | andai 2 days ago | |||||||
So I've seen some companies do it in a way that's not a pain in the ass. I'm wondering if that's legal. Because if it is, I also want to do it that way. | ||||||||
| ▲ | IanCal 2 days ago | parent | next [-] | |||||||
It is. It’s also often not necessary at all. You can’t do things with people’s data without either getting consent or basically having a good reason to. I like the ICO pages (uk regulator) for explaining a lot of things like this. If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine. Keep only what you need, for the time you need to keep it, in an appropriately secure way. | ||||||||
| ||||||||
| ▲ | latexr a day ago | parent | prev [-] | |||||||
Not only is it legal, it’s expected by the law. It specifically mentions that rejecting consent must be at least as easy as giving it. Websites just choose to make it hard to reject, going against the law. You may have noticed many websites have begun to be better behaved in that regard, for which you can thank organisations like noyb (https://en.wikipedia.org/wiki/NOYB). | ||||||||