Earlier quoted context omitted.
Yup, I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases. But, yeah, I'm not a lawyer too. Edit: DPO Network says this which I think is a pretty good summary (though it's not part of the explicit legal policy, it's someone's opinion) > CAN WE ASSIGN ONE OF OUR EMPLOYEES AS OUR DPO? > Yes. However, you must ensure that other professional duties of this emp…
> I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases Being the sole owner and manager and being the DPO is clearly a conflict of interest.
GDPR: Removing Monal from the EU
811–820 of 957 posts
Re: GDPR: Removing Monal from the EU
#812Earlier quoted context omitted.
"you are required to comply with the laws of any country you do business with." Prove that. Because that's not how "the law" works. I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. No other country in the world can just make some "arbitrary" law that affects me. Unless my country agrees. And t…
> I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. If you decide to sell a couch to someone in America, you have to comply with American tax laws, American import and customs laws, American consumer laws, American patent laws, American copyright laws, American trademark laws, and any other law…
Re: GDPR: Removing Monal from the EU
#813Earlier quoted context omitted.
> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.
I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.
What? Because you just decided that it does?
It's people like you why we need GDPR-like laws. I'm curious, what's your stance on the Equifax data breach? They had data that belongs to them and they could do with and treat it as they pleased, right?
Re: GDPR: Removing Monal from the EU
#814Earlier quoted context omitted.
> And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary Views like this are exactly why we need the GDPR. I find it utterly ridiculous - disgusting even - that you really believe you have the right to do whatever you want with someone else's personal information. When you provide an email addr…
Why not? I have yet to see anyone arguing for data protection legislation actually give a reason that they think a users data belongs to the user.
Re: GDPR: Removing Monal from the EU
#815Earlier quoted context omitted.
I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…
And "large scale" means how many records in DB? How many users? Or records per day?
If
* core activities * require * large scale * regular * systematic
If you tick all those other boxes, but are concerned that your processing may be teetering on the boundary of 'large scale', I would be cautious and assume your liable.
Re: GDPR: Removing Monal from the EU
#816Earlier quoted context omitted.
Yeah, but the analogy is not good... * We've known about the GDPR for around 2 years. * The GDPR text, national regulators' comments, industry opinion, sample docs and a plethora of free resources have been readily accessible on the Internet for about the same length of time. Having worked on the GDPR docs for a medium-sized business that builds learning management systems for corporate customers (about 100 live syst…
Also, needing to have a DPO is not difficult since he already has one employee, himself. It's not ISO2700x, you don't need to fiddle around with rights in small businesses to make sure it fits the narrow perspective of a standardization and exclusiveness.
Re: GDPR: Removing Monal from the EU
#817Earlier quoted context omitted.
What are you talking about? There's a ton of information about what GDPR means, both from the EU and the national regulators (particularly the ICO). The best sign that the regulators aren't going to go crazy with this, is that they already have quite significant powers and they're not throwing their weight around now.
https://www.google.com/amp/s/www.xda-developers.com/facebook... Mind you Belgium us 1/30 the size of the US
Here's a statement from the CPP, connected to the 2015 lawsuit. They mention Facebook being in breach of Belgian privacy laws from 1992.
https://www.privacycommission.be/sites/privacycommission/fil...
[1] - none of the other reporting I found on the subject(Guardian, Bloomberg, etc) mentions the GDPR. They also don't show the court order, which is frustrating.
Re: GDPR: Removing Monal from the EU
#818Earlier quoted context omitted.
That's not exactly a new insight, Richelieu beat you to that one a couple of centuries ago. But that's just trying to stretch what we are discussing here: that it is possible to comply with the law in principle. That some overzealous prosecutor with a grudge could nail you might happen - in Russia, maybe even the USA. But frankly where I live I have not yet seen a case like that. We probably have them but not frequen…
Have you been running a socially controversial business? That's where the specifics of the law start to really matter. The butcher, baker and candlestick maker have little to fear from the most badly drafted of laws; it's the person running a skate park or gay bar in a small town who tends to be on the sharp end.
Or for that matter, someone running a social platform that allows socially "undesirable" speech, speech that is openly critical of government policy, or speech that exposes the wrongdoing of powerful people.
Re: GDPR: Removing Monal from the EU
#819Earlier quoted context omitted.
I think you're lumping together too many things. > I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. > All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. What if I didn't want you to visit my w…
If you didn't want visitors to your site you shouldn't have put it on the web. If you want visitors to your site without any strings attached you should serve the content without grabbing and storing anything about the clients. This is called the "technician's responsibility" where I come from. To only track/store/process what is absolutlely necessary, in order to not be liable for the consequences when someone you c…
I know the "logging by default" comes from a different age of the internet, and I'm absolutely for minimizing data collected - but I'm sticking to my opinion that as long as the default of every internet-facing package is logging IP addresses by default, it's not good that private owners have to face problems or a lot of work because of that.
Re: GDPR: Removing Monal from the EU
#820Earlier quoted context omitted.
Yeah, they are over-reacting. For example, IP addresses are considered personal information but what that means is you just can't blindly collect them. If the service you use relies on IP addresses as a basic point of operation then its fine. CDNs aren't going out of business for example.
> that means is you just can't blindly collect them Genuinely curious, what about all of the web servers that log every request which usually by default includes the client IP? Not doing anything special with the IP, they are just there in log files and archives.