Hacker News new | ask | show | jobs
by mclarke 3120 days ago
GDPR has an exemption related to the legal requirement to process data that might cover this (and related) scenarios.

> ...(unless) processing is necessary for compliance with a legal obligation to which the controller is subject;

1 comments

Does this mean that someone can game 1-time special offers by repeatedly signing up and then demanding to be forgotten?

There's probably no legal obligation to enforce once-only cashback sign-up offers, so the right to be forgotten would presumably have to be followed.

There is an exception category for “legitimate business interest” so we’ll probably have to wait and see what the courts have to say.