Are 1 million IPs in my logs 'large scale'?
I've got a call with a lawyer on Monday to clarify some bits of the GDPR. Number one Q for me is "how far can you take legitimate interests?".
Some lawyers are advising that marketing data and usage falls under legitimate interest, in a way that these higes drives for consent seem unnecessary.
If anyone else has any questions, I can ask and feedback. I'm sure I'll have those questions too.
Even ICO says legitimate interests might be okay for some marketing.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
"personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, [...] genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation"
1. you're a public authority (NHS practices are an example)
2. Large scale processing
3. Large scale processing of sensitive data
They don't specify what large scale means. They also haven't specified how sensitive data qualifies the third statement. One can assume the threshold is lower but the GDPR doesn't specify any thresholds with regards to this.
Not exactly an ironclad source, but better than nothing, hopefully.