Hacker News new | ask | show | jobs
by brookst 317 days ago
I work at a Fortune 10 and we routinely avoid collecting PII when there’s no reason to do so. Not out of any noble championship of privacy, just because 1) legal wants less liability, and 2) subpoenas are a PITA for everyone.
2 comments

That's nice, but "no reason" is often a high bar.

There's often a good reason to keep the data (marketing, product, etc), which when weighted against the potential liability, usually wins.

"often" and "usually" are doing a lot of work there.

In my experience, in my role, we often forego collection of this data because there usually isn't an obvious upside that makes it worth it. If nothing else it's a ton more privacy and security reviews.

Ditto.