惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
S
Secure Thoughts
Attack and Defense Labs
Attack and Defense Labs
人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
W
WeLiveSecurity
O
OpenAI News
SecWiki News
SecWiki News
博客园 - Franky
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
T
Tor Project blog
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
Security Latest
Security Latest
H
Hacker News: Front Page
Google Online Security Blog
Google Online Security Blog
P
Privacy & Cybersecurity Law Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
Darknet – Hacking Tools, Hacker News & Cyber Security
月光博客
月光博客
李成银的技术随笔
Spread Privacy
Spread Privacy
F
Full Disclosure
F
Fortinet All Blogs
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
AWS News Blog
AWS News Blog
WordPress大学
WordPress大学
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
V
Visual Studio Blog
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
博客园 - 司徒正美
Engineering at Meta
Engineering at Meta
Last Week in AI
Last Week in AI
P
Palo Alto Networks Blog
宝玉的分享
宝玉的分享
T
True Tiger Recordings
N
News and Events Feed by Topic
酷 壳 – CoolShell
酷 壳 – CoolShell
Cisco Talos Blog
Cisco Talos Blog
N
News | PayPal Newsroom
S
SegmentFault 最新的问题
Jina AI
Jina AI

LWN.net comments

It's a shame [LWN.net] Is your age restriction really necessary? [LWN.net] PQC signing for distros relying on OpenPGP? [LWN.net] Our editor-in-chief's inimitable dry humor [LWN.net] PQC signing for distros relying on OpenPGP? [LWN.net] schism status [LWN.net] Does using per-CPU variables in preemptable code make sense? [LWN.net] One option for dirty frag via selinux, dependent on user cases where ipsec is needed [LWN.net] Better off keeping it vague [LWN.net] Cost of LLMs in the cloud [LWN.net] Cost of LLMs in the cloud [LWN.net] everyone wins here [LWN.net] Thoughts from a younger generation.. [LWN.net] a bit of fishes vs bicycles comparison [LWN.net] Better off keeping it vague [LWN.net] Better off keeping it vague [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Better off keeping it vague [LWN.net] Better off keeping it vague [LWN.net] Better off keeping it vague [LWN.net] Some performance numbers? [LWN.net] workaround is okay [LWN.net] Better off keeping it vague [LWN.net] Thoughts from a younger generation.. [LWN.net] OpenWrt One still available for sale! [LWN.net] Does using per-CPU variables in preemptable code make sense? [LWN.net] Excellent communication [LWN.net] It's a shame [LWN.net] Fade out [LWN.net] Fade out [LWN.net] Which cards? [LWN.net] Which cards? [LWN.net] Better off keeping it vague [LWN.net] Hype isn't going anywhere at this rate [LWN.net] Per-CPU PGDs... [LWN.net] It's a shame [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] __set_flex_counter() and __flex_counter() [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] If you only want to work, why live? [LWN.net] Thoughts from a younger generation.. [LWN.net] If you only want to work, why live? [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] RISKS Archive [LWN.net] RISKS Archive [LWN.net] Origin of the quote. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] RISKS Archive [LWN.net] "Reproducible" sounds like a yes/no question but it's not [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Ownership [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Now to test the tests [LWN.net] Thoughts from a younger generation.. [LWN.net] Thoughts from a younger generation.. [LWN.net] Another of the great old ones passes [LWN.net] Thoughts from a younger generation.. [LWN.net] Ownership [LWN.net] off-by-ten? [LWN.net] Thoughts from a younger generation.. [LWN.net] Status of recent 0-days? [LWN.net] off-by-ten? [LWN.net] Status of recent 0-days? [LWN.net] Mark authencesn as BROKEN? [LWN.net] Fragnesia [LWN.net] Great product [LWN.net] Fragnesia mitigations [LWN.net] Fragnesia [LWN.net] BPF mm stability [LWN.net] Fragnesia [LWN.net] Mitigation [LWN.net] People should be paying attention to the role of splice in these bugs. [LWN.net] What are we gaining with chat? [LWN.net] Mitigation [LWN.net]
Better off keeping it vague [LWN.net]
Wol · 2026-05-21 · via LWN.net comments

> > Your comment and others talk about what is reasonable or necessary. And I agree, this seems like common sense. But it's a point of view, and not stated explicitly in the statute. I would not be surprised if a company's legal&compliance department decides that it's safer to just forbid storage of email addresses.

> It is in statute: this is classic GDPR Article 6.1(f) "legitimate interest" [1]. You need to be able to communicate with the users and email is the normal way to do that.

The thing is, there's nothing stopping you seeking to collect and store as much PII as you like, *as long as* you abide by the rules! I work as an analyst for an online retailer, I'm also a volunteer for a charity maintaining a (e- and snail- mail) mailing list. As such I'm subjected to a lot of compulsory training, including GDPR.

And as I see it, PII falls into two categories. If you can come up with a *good* answer to the question "Why do you *need* this info?", you can collect it no problem. That "are you 16?" question - you need to know the answer in order to comply with the law - you can collect it no problem. But if SUSE say wanted to know our home address - why? - they need to get *informed* consent to collect it unless they're mailing us a DVD or something. (Like SuSE did to me many moons ago :-)

The other thing about informed consent is it has to be voluntary - "we won't do business without it" can NOT be informed consent, but with informed consent you can collect anything you like. You can think up any excuse you like, and if the customer buys it, no problem (unless, of course, you fall foul of "but it wasn't informed consent, the detail was in a filing cabinet behind a locked door with a sign saying "beware of the leopard", on Alpha Centauri").

The corollary of collection, of course, is storage and processing. You are allowed to keep it for as long as you *need* it, or the subject's permission lasts. And you must keep it safe, and dispose of it as soon as whichever of those conditions ceases to apply. That "I am a minor" reply? You can process it, your web server responds "I'm sorry you're under age, go away", AND YOU DELETE ALL TRACE OF ANY PII.

Part of the trouble, I believe, is what has been pointed out before. American law says what you must do, American lawyers want to be able to tick off a list that says "we followed procedure" (past tense). European law is much more involved with results, we have a "do our procedures achieve the desired aim" (current tense) mindset.

The correct approach to the GDPR is (1) Are we asking for more information than we need? If so, (2) are we making sure we get permission? (3) EVERY time it is accessed, is it for necessary purposes, or within the subject's grant of consent? And (4) are we running cleanup processes regularly to get rid of stuff we no longer need? Everything there is present tense, anathema to an American lawyer. But really, it's not hard, and if you're up-front and honest about what you're doing you'll find it hard to go wrong. Secondly, the chances are the regulator will come around and have a quiet, off-the-record chat and give you a decent opportunity to put things right, but firstly the chances are your customers will put you on the straight and narrow pretty quickly! Just don't give the regulator the impression he's being played. Things can get nasty pretty quick. The law is intentionally vague to make it easy to catch "breaking the spirit of the law". But it plays the other way too - the regulator won't go for someone trying to play fair, because it's too easy for the Judge to let them off.

(And (2) includes implied permission - if they *choose* to interact with our services, I won't say that authorises *everything*, but it's hard for them to argue they didn't agree to the server showing their posts to all and sundry, for example - that's what servers do!)

(Just note how I worded (3) - that includes unauthorised access! So you just don't allow unauthorised access :-)

Cheers,
Wol