Hacker News new | ask | show | jobs
by xxs 3062 days ago
You don't need any personal data to conduct most of the business.

I work in a place that would be beyond heavily affected by GDPR and I find the legislation a good change as companies should not hoard data they don't need - just in case... or just to sell.

1 comments

Wouldn't you need personal data to accept payments? Or maybe a broker (like Stripe) would store these and the end business just a reference to payment.
You can get external ref to payment providers. Depending on the business you might need KYC and anti laundering procedures and then it's harder.

However if you have some direct business and do accept payments - by all means make it secure and transparent to your customers.

In lawyers terms: a payment apparently is just a contract. So you can store the data needed for the payment under that legal basis.

IANAL