|
|
|
|
|
by hvidgaard
2951 days ago
|
|
Maybe, but they have a good reason to keep that data, and they even go out of their way to "hide it" the best they can using a one-way function. To save the information that a certain email address has explicitly withdrawn consent, they need to store it. The alternative is to send out a new email the next time someone adds then. I think the interpretation of GDPR this particular instance of information storing is still open, but they have done everything possible to keep it safe. Should the list of hashes be leaked, the best an adversary can realistically do is check known emails against the list of hashes. |
|