- dont collect data you do not absolutely need to service the user
- do not use third party libs or services, where you do not understand how they handle the data you submit to it
- dont collect data you do not absolutely need to service the user
- do not use third party libs or services, where you do not understand how they handle the data you submit to it
While the latter part is the prime responsibility of the developer team. You need a culture of skepticism towards 3rd party access to you (customers, users, company) data.
Am I missing something here?
This is of course a legal document and the implementation may do something else.
So the question to answer is how can we ensure an interoperable contract for data between systems/services - that requires an ontology for privacy that makes enforcement easy(er).
It is possible to make privacy definitions a declarative and low effort part of development for engineers - then code becomes the enforcing layer instead of legal agreements.