Tweet · 28 Apr 2022, 15:13 UTC

Replying to @montezumachavez and @floorter, @JBAGerritsen, @PrivacyAcademyB, @MissIG_Geek, @PrivaCat, @peterhense

I don't believe that exists. For withdrawals and DSRs, there should be an obligation for additional controllers to provider identifiers to the first-party/subject-facing controller. Otherwise, these mostly can't be executed. It gives third-party controllers an edge (again).