>
So it makes sense to treat certain data as more sensitive.I cannot change my name so easily as far as the Dutch government is concerned as well as that of many other European countries. I need a reason of significance and a simple “I wish to be forgotten and start a new life.” is not accepted, as it is in many European countries.
If the E.U. cared so much about this, it would mandate that it's member states permit easier name changes.
Simply put, it is easier for me in the Netherlands to have plastic surgery and change my biometric data, than it is for me to change my name so I am holly unconvinced by this argument and it seems ad-hoc to justify what is purely an irrational distinction.
> At the same time, the GDPR doesn't want to go overboard with regulation. Name and address are data that lots of businesses need to process -- eg. every online store needs to collect customer name and address and pass it on to payment providers, shipping companies, etc. It would be really inconvenient if you'd need explicit permission for each use ("Do you consent that I can tell the post office where to deliver your package?").
There are already exceptions in place in the law where data may be collected if it be essential for operations.
As it stands, companies may ask for my name and address when they have no need for it to process anything, this information can surely be used to uniquely triangulate my identity with little effort, far more effort would be required to do so with a picture of my face, or a scan of my retina.
This seems highly arbitrary and ineffective to me. I remain very much unconvinced that this distinction is one that was given any serious thought.
> Sure, someone may find a way to abuse a list of names and addresses, but it's just not as sensitive as other data.
It is far, far more sensitive.
Would you rather that your name and address be placed on H.N., or that your fingerprints or retinal pattern end up here? Would you rather a stalker have the former or the latter?
To triangulate a man's identity from biometric data requires specialized equipment, to do so from name and address is a trivial endeavor a layman can undertake.
> I think the GDPR actually strikes a great balance between protecting people's privacy and not inconveniencing businesses. If you only collect and process data that's absolutely necessary for providing your service, the GDPR won't inconvenience you much.
I do not. I find the distinction made here to be completely arbitrary and undeniable that name and address are far more sensitive and open to abuse than biometric data, the latter requiring specialized equipment to make use of.
Again, would you rather a stalker have your name and address, or your retinal scan?