|
|
|
|
|
by mziel
3031 days ago
|
|
You're supposed to enumerate all uses of the data (and they need to be sufficiently detailed and specific). The user has a choice to opt-in/out of each of them separately. There is currently no detailed description as to what the definition of "sufficiently" is. For example: - can I use your data to build a targeting machine learning model? - can I use it to target you? - do I need specific opt-in for every model? Most things in GDPR are not specified in order to both give flexibility to the sites and to reduce the number of loopholes (which are technically legal but against the spirit of the law). You need to decide on the implementation and be ready to defend it in case of an audit. |
|