Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>- don't store data you don't need for your business' stated purpose

>- get active consent before you do so

These are mutually exclusive. The GDPR specifically warns against soliciting consent for collection and processing activities that are actually needed, as consent is not considered meaningful when the alternative is to avoid doing business. Consent is only valid if you can "degrade gracefully" in its absence. (I'm not a lawyer).



It makes more sense to ask for literally everything, and provide no feedback on whether the user should join or not until the next page. Literally everything. Even things they can't avoid sharing. Don't check it until the end - preferably several pages later. Then, if they didn't consent to a required thing instead of an optional thing (which should look identical), their entire setup process should be voided, with a great banner blaming European Regulation.


If you didn't check a required item, you're uncomfortable with a fundamental feature of the service, and shouldn't be using it at all. It seems like a feature, not a bug, that it's hard for you to override your values about privacy and use the service anyway. (But anyone designing for user engagement will be aware of this).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: