Hacker News new | ask | show | jobs
by eastbound 1295 days ago
That’s a good point: The use of general-purpose tools like Excel is by essence non-GDPR compliant, since there is no way to mark a column as “person” and therefore attach it to that person’s rights.

Therefore, all corporate tools must be specific for one purpose when managing PII, and no tool should allow free-text fields. Excel, Access, notepads shouldn’t exist in companies.

2 comments

The point isn't about the tool, it's about where and by whom the tool is run.

Office 365 is cloud based, that's what makes it potentially non-compliant. Having Excel in your company, on your computer, and the data never leaves that computer is a totally different scenario.

How is that different from a sheet of paper?