Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GDPR is very specific. You must have written policies describing what you do with data, what you do if there’s a breach, how people can find out what data you hold, how people can have their data deleted. And you must have consent to contact someone unsolicited. If you don’t have consent you must have legitimate interest. Legitimate interest includes the words “reasonably expect” but that’s pretty standard for laws.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: