Comment on Apparently Palantir can access the content of social media accounts that were deleted a decade ago.
SanguineBrah@lemmy.sdf.org 2 days agoThe GDPR applies to data pertaining to an identifiable person. Anonymised data is more or less equivalent to deleted data as far as the regulation is concerned. Source: I was a DPO for 5 years.
ranzispa@mander.xyz 2 days ago
Oh, I see. Indeed anonymised data should be fine under GDPR. However it is often very difficult to anonymise data. Some things are easy to anonymise, other are very complex.
For a small company who does not mainly work with data, the easiest solution to comply with GDPR is indeed just deleting the data altogether.
SanguineBrah@lemmy.sdf.org 2 days ago
Yes, there a concept of “pseudonymous” data in some of the guidance, which refers to anonymous data which, when taken together, could identify person - even if some of that data is not held by the data controller. Under those circumstances seemingly anonymous data can fall under the regulation although most companies are very unlikely to consider such nuance in their data policies.