Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You must provide a way to undo first party and third party data retention of personal data at the same level as the initial retention.

If such data exists in an app under control of the user, then uninstallation is fine.

If you persist that data in your own systems, you must provide a way to withdraw that consent. Same with data shared with third parties.

If you create an account in first party systems, you must provide a way to delete that account.

If the account is created outside the app (say via your website), thats fine, but you may get the same regulatory pressures directly (from GDPR, from California, etc) to support deletion in the same context.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: