opengdpr/OpenDSR

Supported identities and data minimisation

pdehaye opened this issue · 1 comments

https://github.com/opengdpr/opengdpr/blob/d3ccb34e78f2605b53c647ab11cdfd8d6ca7abd7/OpenGDPR_specification.txt#L183

I do not know the industry well enough, so this is a question.

Is there a risk of violating data minimisation principles here?

How can the n-th actor in the chain know that they should pass some subset of identities and only those to the (n+1)-th actor? Should this involve a conversation with that next processor? Will this depend on the particular n-th -- (n+1)th pair?

This ties in more with #1 than I had realized, so I will repost there.