How can Santa keep his lists when GDPR is around?

Follow ➡

Santa’s data collection has always been compliant with GDPR, so he has no need to change his ways. The nature of his data collection is more transparent than most companies, and he is open to updating his records if you contact one of his representatives.

The legitimate business purpose of his data collection is to create a list of those who are naughty and nice this year:

He’s making a list And checking it twice;

Gonna find out Who’s naughty and nice

Santa Claus is coming to town


Santa is Christian priest (bishop as far as I remember). He is covered by exemption:

The new Regulation will maintain the existing exemption which allows churches and other bodies with a ‘religious… aim’ to process sensitive data:

  • ‘in the course of its legitimate activities…’;
  • ‘…with appropriate safeguards’;
  • ‘…on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes’; and
  • on condition that ‘the data are not disclosed outside that body without the consent of the data subject’.