Hacker News new | ask | show | jobs
by FourthProtocol 1411 days ago
These are technical controls - are you sure they're the right ones for your organisation - - or even needed? Organisations that comply with the GDPR typically employ a data protection officer - the person responsible for creating or overseeing the creation and ongoing maintenance of a privacy impact assessment. That feeds into requirements long before any code is written, let alone implementing other procedural or technical controls.
1 comments

In theory I agree, in practice GDPR compliance is lots of poorly bolted on band-aid solutions to legacy systems.