You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
GDPR: Removing Monal from the EU
61–70 of 957 posts
Re: GDPR: Removing Monal from the EU
#62>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…
Companies with less than 250 workers have fewer requirements, but the obligation of a DPO follows a different set of rules https://gdpr-info.eu/art-37-gdpr/ Edit: Art 30 "The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, th…
Re: GDPR: Removing Monal from the EU
#63Earlier quoted context omitted.
these assurances from internet forums are great and all, but hwy take such risk?
Please take the assurance from the 'horses mouth' instead. The ICO is the UK body responsible for policing this. Their site is simple and in plain English. https://ico.org.uk/for-organisations/guide-to-the-general-da...
Re: GDPR: Removing Monal from the EU
#64Earlier quoted context omitted.
Even if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...
I don't think he can. The DPO may not be assigned any tasks that would result in a conflict of interest between their role as a DPO and their other responsibilities. I suspect that means that the sole proprietor can't be the DPO. But, you know, not a lawyer, not even European, could be wrong. See article 38, paragraph 6, 2nd sentence.
Edit: DPO Network says this which I think is a pretty good summary (though it's not part of the explicit legal policy, it's someone's opinion)
> CAN WE ASSIGN ONE OF OUR EMPLOYEES AS OUR DPO?
> Yes. However, you must ensure that other professional duties of this employee must be compatible with his/her new duties as DPO and do not result in a conflict of interests.
Re: GDPR: Removing Monal from the EU
#65Earlier quoted context omitted.
Sure, feel free to "leave", really, no offense. We talked to a lawyer in Germany regarding this (we are a small software company with 5 people). His response was: If you don't do shady shit with customer data, you'll probably don't have to worry. Also, if you are in a "contractual agreement" (e.g. EULA), you can apparently justify most data collection without any change at all.
If he really said "probably", then he’s the one who doesn’t have to worry about the advice he gave you being incorrect.
However, this cases will be fought with the Googles & Facebooks, not with 5 person companies.
Re: GDPR: Removing Monal from the EU
#66I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.
Re: GDPR: Removing Monal from the EU
#67>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…
Companies with less than 250 workers have fewer requirements, but the obligation of a DPO follows a different set of rules https://gdpr-info.eu/art-37-gdpr/ Edit: Art 30 "The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, th…
Re: GDPR: Removing Monal from the EU
#68There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...
And then the next would be that it's inexpensive to "make your case" if you get reported.
Re: GDPR: Removing Monal from the EU
#69Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…
>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…
You are saying that's a bad thing?
Services that require you to sign up, should provide the possibility for users to look at, modify and delete their user data - that's all. Where's the problem?
Re: GDPR: Removing Monal from the EU
#70I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.