Update and rename GDPR to GDPR.md

This commit is contained in:
Dennis Eichhorn 2018-09-27 14:25:38 +02:00 committed by GitHub
parent 4f9ea9708d
commit e68e45dd94
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 16 additions and 1 deletions

View File

@ -1 +0,0 @@
# GDPR

16
Legal/GDPR.md Normal file
View File

@ -0,0 +1,16 @@
# GDPR
* All personal data or data which can be used to identify a person
* Collection must be for specific use case(s)
* Needs to be accurate (updated)
* Data mustn't be stored longer than necessary OR for archiving, or statistical purposes.
* User must be allowed to request deletion (store datetime for interval analysis)
* Data must be optional unless absolutely required (e.g. HR data, customer info for invoice etc.). All other data requires approval by holder.
* Must be at least 16 years old
* Inform breach after 72 hours
## Processing
* Consent must be given by person (this consent needs to be able to demonstrate). Therefore it must be a activation checkbox and not a deactivation checkbox.
* Must be necessary for the contract (e.g. writing invoice etc.)
* User may request what data is stored