GDPR is bringing a whole new set of legal requirements on data retention which seem to contradict many existing laws on data retention and the requirements to hold data for set periods of time.
Does anyone know how ISPs are planning to handle the user data retention issues?
And has anyone else come across situations where GDPR seems to contradict existing legal data retention requirements.
This is without going into contractual data retention requirements many of which include holding backups for up to a year.