Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure, maybe it probably doesn't need to be but Article 29 guidance is clear that as a matter of good practice, you should look to document the balancing test you have undertaken to determine legitimate interests is appropriate.

Yes, quite right on the contract side. At the lowest level, a contract could be implied, or would arise from terms of use on a site. Absolutely, processing under the service provision ground should be limited solely to that which is necessary to provide a service.

I guess if you wanted to take things further I suppose on the authentication front, you could argue that authentication/login may not strictly be necessary to provide certain of the services as they could be provided in the absence of a login (creation of a to-do list for example). However my view would be you take things on a broad basis so that if a good proportion of the services required authentication (buying content on the basis of a to-do list) then you could put all service provision under service provision pursuant to a contract rather than splitting between legitimate interests and service provision grounds.



I agree with everything in your comment.

Regarding necessity I think it should not be interpreted too strictly. Rather, I believe it means something like this in EU law:

“Necessity implies the need for a combined, fact-based assessment of the effectiveness of the measure for the objective pursued and of whether it is less intrusive compared to other options for achieving the same goal.”

(Quote from: https://edps.europa.eu/sites/edp/files/publication/17-06-01_... )




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: