Which is kind of what GDPR wants to do for personal data: if you want to collect it from me, there are a minimum set of standards that you need to adhere to because it’s my data.
Which is kind of what GDPR wants to do for personal data: if you want to collect it from me, there are a minimum set of standards that you need to adhere to because it’s my data.
In particular if you already went though PCI DSS, it’s only a few additional things here and there.
The pci DSS has nothing in it like the gdpr; I'm not even sure why you would compare them.and it makes me think you know nothing about either.
While doing these changes, there will usualy be a rethinking of how user data is handled at its core. For instance I worked in the past on dissociating user account with it’s profile and private info, so we could get rid of personal info and only keep behaviors.
With GDPR you get similar leeway for keeping most of your data as long as you get rid of identifying info in a reasonable manner. If I’m not mistaken backups are also safe up to a point, but I don’t have the details at hand.
My main point was that if someone had the occasion to think thoroughly about user data policy and cleaning unwanted traces at leadt once in the past, GDPR was a lot easier than one might think at first.