Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The operative word being "collect," the second being "store," what you do between those steps is not really relevant.

In other words: no, you probably will not be in the clear.

https://iapp.org/news/a/what-the-gdpr-will-mean-for-companie...



Operations before storage don't avoid any legal issues around the collection, but they certainly can obviate legal issues with storing the data. For example, if you 'hashed' them with an algorithm that always yield 0, you'd surely be in the clear as far as the storage goes. Probably you'd still be fine if the output of the hash was 1 bit. I don't know whether you'd still be in the clear for more common hash algorithms.


Storing the hash is not the same as storing the actual data.


The hash of PII is still PII.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: