Earlier quoted context omitted.
For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.
A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.
GDPR Hall of Shame
101–110 of 192 posts
Re: GDPR Hall of Shame
#102Earlier quoted context omitted.
I believe that they do lots of internal analytics but do not sell identifiable data on a per-person level; the laws regarding nondisclosure of banking data are old, well established and much stricter - for starters, intentional disclosure of confidential banking information outside of certain (though many) particular exceptions is an actual maybe-go-to-jail crime, not just a civil matter with some fines. Surveillance…
Does GDPR distinguish between "identifiable" data and "non-identifiable"? If so, how do you decide which is which? A list of credit card transactions is pretty easy to de-identify...
Re: GDPR Hall of Shame
#103Earlier quoted context omitted.
I think you've confused "if" with "if and only if"
The implication is clearly that you ought to pay for the products, so that you aren't the product. But if the incentives for paid and free products to monetize your data is the same, switching from one to the other doesn't help. You have to specifically seek out products where your privacy and data is taken seriously. This can happen for both free (open source?) and paid products.
Of course, that assumes competition is effective, which requires consumers to be informed that it's even a potential issue, to care, and to be able to assess which company is better or worse.
Re: GDPR Hall of Shame
#104Earlier quoted context omitted.
Hi Brian! Thanks for taking part in the discussion. But what part of GDPR was it that caused you to have to close off European Union users?
It's worth noting that GDPR applies to EU citizens regardless of where they happen to be in the world (or if they're using a proxy), so an IP ban does absolutely nothing to help comply with the law. You'd think a real company would have talked to a lawyer about this.
GDPR makes no mention of EU citizens or residents.
The 2 main groups it applies to are:
1. activities of an establishment of a controller or a processor in the Union (so if the company is in the EU, ALL processing has to be GDPR compliant regardless of where the user is)
2. processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union (if the company is not in the EU, processing of data of people in the EU - note they just have to be in the EU and not residents or citizens - so if you are from the US and on holiday in the EU and you order pizza delivery to your hotel, that personal data has to be handled in a GDPR compliant way, notwithstanding that the pizza company is probably in group 1 anyway but hopefully you get the point. And the converse of that, if you live in the EU and are on holiday in America and order pizza, that personal data does NOT need to be GDPR compliant as you are not IN the EU)
There are a few other scenarios included too.
Edit: It's worth pointing out that 1 seems to have been completed missed in almost all GDPR coverage I have seen, possibly because most of the coverage has been heavily US centric. If the company is established in the EU, it has to comply with GDPR for ALL users, not just people in the EU. This is why Facebook [1] and others changed their terms so that only EU users have a contract with Facebook Ireland, and everyone else now has a contract with Facebook Inc (US) - previously everyone had a contract with Facebook Ireland.
[1] https://www.reuters.com/article/us-facebook-privacy-eu-exclu...
Re: GDPR Hall of Shame
#105Re: GDPR Hall of Shame
#106Earlier quoted context omitted.
I believe that they do lots of internal analytics but do not sell identifiable data on a per-person level; the laws regarding nondisclosure of banking data are old, well established and much stricter - for starters, intentional disclosure of confidential banking information outside of certain (though many) particular exceptions is an actual maybe-go-to-jail crime, not just a civil matter with some fines. Surveillance…
Does GDPR distinguish between "identifiable" data and "non-identifiable"? If so, how do you decide which is which? A list of credit card transactions is pretty easy to de-identify...
2) "A list of credit card transactions" is the kind of data that I'd assume that Visa/MC aren't selling to anyone ever, I'd expect any data sales to be on the level of "real time subscription to how (and how much) different demographic groups are shopping in company X or in location Y", but not on the level of individual transactions or individual accounts. Group them by zip-code and hour and you're fine even for GDPR requirements; and you can provide "individual" granularity for the merchants (e.g. for stock traders who want to predict revenues) since merchants generally have no privacy protections.
Re: GDPR Hall of Shame
#107Hey! I made this, mostly just to poke fun at my inbox being here in Europe and experiencing it first hand. Feel free to fire me a reply with any good ones you've spotted; I'll be actively adding through tomorrow and beyond.
Re: GDPR Hall of Shame
#108shaming seems to be down currently.
Re: GDPR Hall of Shame
#109Earlier quoted context omitted.
A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.
What if EU citizens who are visiting US make purchases from your site?
Re: GDPR Hall of Shame
#110Earlier quoted context omitted.
I believe that they do lots of internal analytics but do not sell identifiable data on a per-person level; the laws regarding nondisclosure of banking data are old, well established and much stricter - for starters, intentional disclosure of confidential banking information outside of certain (though many) particular exceptions is an actual maybe-go-to-jail crime, not just a civil matter with some fines. Surveillance…
Does GDPR distinguish between "identifiable" data and "non-identifiable"? If so, how do you decide which is which? A list of credit card transactions is pretty easy to de-identify...
ico[1] is a useful resource for all GDPR related questions, but to answer your question: yes. Under GDPR, "personal data" is "any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier."[2]. You can also read the "Article 4 - definitions" section in the official regulation doc (pdf)[3].
For the most part, GDPR protections for "personal data" only apply to identifiable data, as would be expected.
1. https://ico.org.uk 2. https://ico.org.uk/for-organisations/guide-to-the-general-da... 3. http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...