dwyl / learn-security

:closed_lock_with_key: For most technology projects Security is an "after thought", it does not have to be that way; let's be proactive!
67 stars 10 forks source link

Update with practical usage of GDPR #33

Open iteles opened 6 years ago

iteles commented 6 years ago

Following on from https://github.com/dwyl/hq/issues/404, we need to create a checklist of features/requirements driven by GDPR that we can go through with our clients and on our own applications to ensure compliance before the 25th May 2018.

iteles commented 6 years ago

If you infer data from the data provided to you, is that covered by GDPR? Grey area: "If you obtain personal data from other sources, you must provide individuals with privacy information within a reasonable period of obtaining the data and no later than one month." https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-be-informed/