I dunno, maybe the utter lack of consent or legal basis for processing?
We (Sentry) absolutely uphold GDPR and all data privacy directives, even in the face of machine learning.
So what's your legal basis for processing that data? It ain't consent
We are solely processing data that is in scope of the GDPR on behalf of our customer in fulfillment of the contract. If you submit a GDPR deletion request, we also ensure that the data is delete within the given period.
Sure, but if you unilaterally change the terms of that contract and don't re-consent for the expanded use, the old lawful basis doesn't really apply, now does it? I mean, whatever, the ICO will explain it to you soon enough with big legal words. Good luck!
So if one of my error messages leaks sensitive data to Sentry, and therefore gets used for AI training, are you going to delete your entire AI model upon request?
You know that technically that would virtually be the only guaranteed way to comply with such requests, right?
The US-EU data exchange agreements turn out to not be GDPR compliant time and time again.
Not sure why you are getting downvoted, this is absolutely correct.
The very move of this is a GDPR violation and doesn't stand a chance in EU courts.
How? Which part is a violation?
You cannot just update the TOS including something which warrants a consent.