Earlier quoted context omitted.
We do not have a Chief Privacy Officer or Chief Information Security Officer. The issue was raised by our head of product and I dismissed it. I saw it as a minor concern (I'm ashamed to say).
Next time: pass it by your lawyers for a quick review if you can't trust your own judgment on things like this. Ditto for all the dark patterns you are still using today on your website, clean up your act. Note that you are firmly in the crosshairs of the EU data privacy watchdogs and that the fines are nothing to sneeze at, if you expect to establish and maintain a foothold in this market realize two things: - trust…
In my opinion, in 2020, any company that releases software and has more than like 20 engineers should have at least one VP-level privacy approver who has the power to block releases.