How do client blacklists work with gdpr?
@robryk what kind of client blacklists?
@kuba
Examples (multiple because I expect the answer might differ):
a) "we don't serve these people" in a butcher shop
b) "these people cannot attend our performances" in a theatre,
c) "these people cannot buy anything from us" for an online retailer.
(Motivation for the question is https://www.nbcnewyork.com/investigations/face-recognition-tech-gets-girl-scout-mom-booted-from-rockettes-show-due-to-her-employer/4004677/)
@robryk tough question. I suspect there's no general answer. I guess it depends mostly on the purpose of such blocklist and it's proportionality to the importance of that purpose.
@kuba WDYM by purpose? Isn't purpose in all cases "nor serving a person we desire not to serve"?
@kuba I'm wondering about the case of processing someone's name or photo (that's shown to staff), because e.g. this fellow is too troublesome to serve. (Does gdpr make this qualitatively different from doing face recognition to do the same thing automatically?)