> financial services company, is probably obligated to retain records. GDPR defers to these obligations. Gee - how long until the GDPR-o-crats demand a fine from a company (possibly the "right to be forgotten" thing),…
> no mechanism for [blocking access to company X for the whole EU] ..they'll ask all the EU ISPs in each of 28 member states to block company X - nicely. () "EU citizens" meaning potential customers of company X - the…
> Is your customer data on a server that automation can tamper with? If so, is a copy periodically written to a write-only destination? Wait, so now we should have customer data in more locations?! I'm not disagreeing…
Maybe someone should organize a campaign to flood the European GDPR Regulators with "our data might have been compromised already or maybe in the future, and might have contained data on EU residents, that might be…
> financial services company, is probably obligated to retain records. GDPR defers to these obligations. Gee - how long until the GDPR-o-crats demand a fine from a company (possibly the "right to be forgotten" thing),…
> no mechanism for [blocking access to company X for the whole EU] ..they'll ask all the EU ISPs in each of 28 member states to block company X - nicely. () "EU citizens" meaning potential customers of company X - the…
> Is your customer data on a server that automation can tamper with? If so, is a copy periodically written to a write-only destination? Wait, so now we should have customer data in more locations?! I'm not disagreeing…
Maybe someone should organize a campaign to flood the European GDPR Regulators with "our data might have been compromised already or maybe in the future, and might have contained data on EU residents, that might be…