Hacker News new | past | comments | ask | show | jobs | submit login

Nothing in the directive requires the access to personal data to be done "in band" through the normal login only. It's a valid interpretation of GDPR to only accept "give me all my data" requests by post, and require additional ID to confirm that you're giving it to the right person.

"The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means."

"Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request referred to in Articles 15 to 21, the controller may request the provision of additional information necessary to confirm the identity of the data subject."

(article 12)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: