• morgunkorn
    link
    fedilink
    arrow-up
    12
    ·
    5 months ago

    The compliance people didn’t read article 6 of the General Data Protection Regulation.

    • koper@feddit.nl
      link
      fedilink
      arrow-up
      21
      ·
      5 months ago

      It’s possible that they’re functional cookies in the sense of article 5(3) of the ePrivacy directive (so no consent necessary) but still personal data under the GDPR that’s processed on the basis of legitimate interest. In that case they would still need to inform users of the processing under article 13 of the GDPR. Though that can usually be done with a less intrusive link to the privacy statement in the footer.

      • morgunkorn
        link
        fedilink
        arrow-up
        6
        arrow-down
        1
        ·
        5 months ago

        Beautifully explained, you just made my little heart of Datenschutzbeauftragter beat a bit faster ❤️