Post #2103303
2026-04-27 06:51 UTC
@microblogc
Exactly. The code part can be done easily enough.
Now designing the data storage part and business processes so that it follows the GDPR principles of data minimisation by design it's a little bit more difficult.
It can be done (with some legal infrastructure), we are doing it for video ID (not age verification) for fraud prevention in our company, but it's nontrivial.
@leftylabourtech @danneau @zazzoo @pluralistic
Replies (1)
-
@zazzoo@mstdn.ca 2026-04-27 14:19
@yacc143 @microblogc @leftylabourtech @danneau @pluralistic And that's the issue, isn't it? I can't see these platforms suddenly shifting from "sell all the data and, oops, leave it in an open bucket" to PIPEDA/GDPR compliance. You think Twitter maintains chain of custody records from creation to destruction? 😂