As data privacy and protection are now an integral part of technological development,…
To this end, it must be added that concerning the ‘by default’ requirement, reference…
Criterion 1: Minimum amount of personal data - The amount of personal data…
CNIL said Google had also not made it sufficiently clear to users where it is relying…
After taken into account the information Google provides to users in relation to…
Criterion 2: Minimum extent of the processing of personal data - The personal…
Criterion 3: Minimum period of the storage of the personal data - Clearly, the period of storage of personal data by the controller plays an important role. With respect to the purpose, the minimum time for storing the personal data has to be chosen. This could mean no storage at all, or an anonymization or erasure as soon as possible. Anonymization would not suffice since as discussed before in mobile ecosystems, it is very easy to combine data and identify an individual. However, erasure is a good way to comply with the criterion; Google recently announced a new feature, in fact, showing compliance with this criterion since it stated that it will no longer keep the location and activity data more than 18 months.(533)…
Criterion 4: Minimum accessibility of the personal data - Accessibility in Article 25(2) GDPR tackles possible access by any entity, examples of which can be people such as other users, organisations such as the data controller or government authorities, tools such as search engines or cloud servers. The accessibility depends on where the data are stored or processed, how the access is limited by assigned access rights,
The location of storage and processing is important to determine the accessibility,…
From another angle, it is worth mentioning that as ENISA emphasized it in its detailed…
