Hacker News new | ask | show | jobs
by danShumway 2822 days ago
So this is an interesting scenario that I've seen people bring up before, but I've never been completely clear on the answer. Let's say I'm using an online virtual assistant with auto-replies and stuff like that, and I upload your contact information and phone number so it can help me manage my schedule/emails/etc...

Under GDPR, the company I just gave that information to doesn't have your permission. So, let's say that later on, you go to the company and say, "hey, delete any information about me." For them to comply, they can't keep on syncing your contact information in my address book, right?

I guess, how does GDPR handle a situation where a separate customer is going to Facebook and saying, "hey, let me put in that I'm X's cousin"? Should Facebook block that person from specifying the relationship in the UI? Or would that just fall under "essential for business"?