Hacker News new | ask | show | jobs
by PH95VuimJjqBqy 925 days ago
what the person said was "we could access any data we want, we just don't".

There's no way they fall under one of those exemptions, especially if they don't need it to do their job. If anything, the statement "we just don't" is indicative that they wouldn't fall under those exemptions.

But really the point was that this stuff is heavily regulated. If a company isn't following those regulations that's going to bite them in the ass eventually.

Typically speaking, you can convince auditors of a lot of things but it only takes getting the wrong auditor for it to all go down hill.