Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Share data" !=== "spy on the user"

Oauth, for example.

 help



If you need it in order to do what the user asked, you don't need the popup. The user asking to do a thing is consent to do what is obviously necessary to accomplish that thing, and may be consent to do what is less obviously necessary. The user's click on "sign in with google" is consent to share data with Google as needed to complete the sign-in, but no more - it's not consent to Google Analytics.

Legal bases for processing: https://gdpr-info.eu/art-6-gdpr/ Everyone knows part A because that's a catch-all. If the user requested something, it's better UX to use Part B. Parts C and F apply sometimes. You still have to follow the rest of the GDPR, like letting them delete it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: