Forum Moderators: IanTurner & engine

Message Too Old, No Replies

EU GDPR & ISP Data Retention

Legal contradictions?

         

IanTurner

12:03 pm on Apr 18, 2018 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



GDPR is bringing a whole new set of legal requirements on data retention which seem to contradict many existing laws on data retention and the requirements to hold data for set periods of time.

Does anyone know how ISPs are planning to handle the user data retention issues?

And has anyone else come across situations where GDPR seems to contradict existing legal data retention requirements.

This is without going into contractual data retention requirements many of which include holding backups for up to a year.

Travis

12:23 pm on Apr 18, 2018 (gmt 0)

5+ Year Member Top Contributors Of The Month



The EU GDPR doesn't forbid the collect, and storing of personal information. The GDPR says you must not collect and store more than you really need to provide a service. You must not keep the data beyond your needs, and you have to inform and obtain the consent from the users. So I guess that in the case of ISP, they might obtain the consent from their subscribers to collect and keep their "personal data".

Also, the GDPR keep the notion of legitimate interest. If this is to conform to a law, I think this is legitimate interest. But still, a business needs to inform clearly a user about what is done and why.

But in theory, you have the right to get your personal data deleted...

see also : [webmasterworld.com...]