Hacker News new | ask | show | jobs
by siimtalvik 2968 days ago
well article 6 is as concrete as it gets:

https://gdpr-info.eu/art-6-gdpr/

(and maybe article 9) https://gdpr-info.eu/art-9-gdpr/

1 comments

To be even more precise, you can refer to Article 6, section f) about Legitimate interests.

If you conduct business with an individual, most of time, your legal basis will be the Legitimate interests of both parties, you should only rely on consent for non-necessary part/service (like subscribing to a newsletter, or sharing information for improving the service).

For a good summary of that, I would recommand this ICO document: https://ico.org.uk/media/about-the-ico/consultations/2013551...