Hacker News new | ask | show | jobs
by ender341341 1306 days ago
Is it actually prescriptive, or does it say (in more legalese form) "use industry best practices to protect user data". Six characters is laughably bad and would fail pretty much any password requirements I've seen in the last decade (except for my credit union who only updated like 5 years ago after finally migrating to a better back end).
1 comments

The GDPR is actually surprisingly understandable and 'plain English' (obviously, lawyers have their own interpretations of everything).

Key section is probably this one: https://gdpr-info.eu/art-32-gdpr/