| So you are saying: * A company is holding PII in a system they don't have the resources to manage . * The software is insufficiently secure to hold that data. * The company appears to be even be holding data on people that didn't even do business with the company. * This is in-part caused by the (sub)hiring of companies that also were not scrupulous with PII in the past. You say that this hurts said company, and they are going to stop doing that. I'd say this is the exact intended effect of the law. Not so stupid after all! Meanwhile, for people who scrupulously and ethically avoided collecting extraneous PII in the first place; I think the GDPR provides no great additional burden. |