[0] https://openid.net/specs/openid-connect-federation-1_0.html
131 karma · joined April 10, 2013
[0] https://openid.net/specs/openid-connect-federation-1_0.html
As frereubu notes elsewhere in this thread, the UK regulator's GDPR guide is excellent, and is a much better starting point in my opinion: https://ico.org.uk/for-organisations/guide-to-data-protectio...
> If a company sells something online they only really need your address & name for delivery + credit card details.
That would likely be "necessary for the performance of a contract" which is also a legal basis to process personal data. [2]
> I know of multiple companies where they prior to GDPR asked for explicit concent during signup for being allowed to send newsletters, but who post-GDPR dropped the concent and use 'Legitimate intrests' to justify it. Basically leaving the individual worse off.
That could be a violation of the ePrivacy Directive which provides that email marketing requires consent. [3]
[1] https://ec.europa.eu/justice/article-29/documentation/opinio...
[2] See Article 6.1(b) GDPR at https://eur-lex.europa.eu/eli/reg/2016/679/oj
[3] For information about how this rule is implemented in the UK, see: https://ico.org.uk/for-organisations/guide-to-pecr/electroni...
[0] http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:020... [1] https://www.autoriteitpersoonsgegevens.nl/sites/default/file...