Post #3134783
2025-09-26 21:27 UTC
@rlcw@ecoevo.social Doubtful. If they have a signed data processing agreement then the software vendor is likely in violation of this agreement, making them the guilty party under the GDPR. And if there is no data processing agreement because the clients aren’t aware of data processing taking place then the vendor is also liable. The clients are only liable if they were handling personal data and knew that the software would store it elsewhere, yet failed to acquire a data processing agreement.
Either way, I can answer your question: zero. GDPR enforcement is spotty to say the least. It doesn’t happen even in far more obvious cases.
@riley@toot.cat @RakowskiBartosz@hachyderm.io @thisismissem@hachyderm.io
Replies (0)
No replies.