Current granularity on personal data collection is on/off
As profile picture is defined in the scope of 'Identify user in service event' (according to a response from Paavo Huhtanen) I propose to add more granularity on the personal data collection so that each category can separately be switched on or off:
Account nae
Full user name
Profile picture
Or at least a toggle for the profile picture.
Rationale:
GDPR Recital (51): allowing the unique identification or authentication of a natural person (borderline case whether 'specific technical means' applies)
GDPR Article 9 Processing of special categories of personal data / 1.
In conjuction to the current Applixure implementation limitations of database encryption / underlying file system encryption