Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm pretty sure GDPR states that it must be opt-in in a non deceiving manner.


Exactly; that's the point. An opt in that is coercive is not a valid grounds for holding personal data, ergo, that data is held illegally and subject to enforcement by a data-protection authority. Doesn't matter if everyone clicked yes.

A coercive opt-in isn't so much illegal; it's simply void. Having a coercive opt-in would be fine yet weird (as I understand it) if you then proceeded to only retain and process personal information to the extent you would be permitted without the opt-in. (IANAL, and only as far as the GDPR is concerned, perhaps if it's misleading enough that violates some fraud statutes somewhere, but that's a different issue).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: