I'm a little confused. Who is sending compliance requests? If it's not the ico, there's rely no problem. If it is the ico, ask what needs to change. No lawyers required.
The forum owner wasn't getting "compliance requests" he was receiving "subject data access requests". Those requests can be: - Please give me all my data - Please delete all my data - Please stop doing things (processing) my data Or some mix of all the above. A site owner (controller) has 30 days from receiving such a request to respond or the person making the request can report them to their Supervisory Authority (…
Shutting Down Forum (GDPR)
271–280 of 534 posts
Re: Shutting Down Forum (GDPR)
#272Earlier quoted context omitted.
Can you provide examples of websites shutting down due to GDPR ?
I only know about some US newspaper closing EU access and this guy's forum. I'm sure we'll get a separate thread for each site that's closing, to emphasize how the (advertising) world is ending, one just needs to wait.
Re: Shutting Down Forum (GDPR)
#273Can you send a GDPR letter to a public body, for example, the Office for National Statistics? Can you ask them to delete your data? Should they comply or are they waived from GDPR compliance?
I'm pretty sure you can.
> Can you send a GDPR letter to a public body
You can, for PII. One would hope they store their data anonymized.
> Should they comply or are they waived from GDPR compliance?
I think they'd need to make a pretty strong case for why they cannot anonymize your data for their work to get an exception.
Re: Shutting Down Forum (GDPR)
#274I just sent a GDPR letter to a company in the UK, which is still part of the EU. I have one of their Android phones, and it came with a non-removable app. It appeared to just be a bookmark. One day that app woke up and sent me a notification asking me to visit a web site, which led to a SurveyMonkey form. So I sent the company a letter asking what data they have on me. It's going to be interesting to see what happens…
It's going to be interesting to see what happens. My bet: Nothing.
Re: Shutting Down Forum (GDPR)
#275Earlier quoted context omitted.
The forum owner wasn't getting "compliance requests" he was receiving "subject data access requests". Those requests can be: - Please give me all my data - Please delete all my data - Please stop doing things (processing) my data Or some mix of all the above. A site owner (controller) has 30 days from receiving such a request to respond or the person making the request can report them to their Supervisory Authority (…
So it looks like having a script to delete all user's data can get you out of trouble with any of these letters.
For example, if you told the user why you collected the data, and you're still using it for that purpose, and you have a legitimate need to continue to do so then you don't need to delete the data. And there's an extra exemption for "exercising the right of freedom of expression and information".
Re: Shutting Down Forum (GDPR)
#276I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…
>If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. I can visit site A and B, not put any of my data intentionally on them but still my data get be funneled to 25 third parties that know what I visited. So your point is don't use internet or turn of javascript and open each link in private windows and maybe use some proxyes or Tor
Now everything loads in an instant, no more shenanigans that jump around the screen as I scroll, no Facebook/Twitter/Google buttons (that nobody even uses), no pop-up/in/out/over adverts, and even those asinine cookie warnings are gone by default!
I cannot recommend it well enough.
Re: Shutting Down Forum (GDPR)
#277Earlier quoted context omitted.
Despite all the bluster to the contrary, in the US we avoid accepting responsibility for our actions at all costs. To the point that business schools now effectively teach that the correct strategy is to put your fingers in your ears, and yell "la la la" until somebody actually smacks you.
The legal climate here is different. If you accept responsibility, you will be sued, by victims for possible monetary losses and/or by prosecutors for possible criminal liability. If you stonewall, you might get sued for (see previous) but you might not if it's too expensive. I don't know if it's a social thing or a legal thing or some combination or what, but apparently it's harder to sue in other parts of the world…
Re: Shutting Down Forum (GDPR)
#278Earlier quoted context omitted.
Do you believe that hobbyists must not follow laws & regulations when they interact with the public?
Do you believe that anyone who has a hobby website with a forum needs an official privacy document, presumably vetted by a lawyer.
Re: Shutting Down Forum (GDPR)
#279Earlier quoted context omitted.
There’s a big difference between ignoring somebody’s privacy and having an official lawyered document that spells them out. I’m sorry that this is a distinction you weren’t able to make.
It doesn't have to be lawyered.
Re: Shutting Down Forum (GDPR)
#280Earlier quoted context omitted.
Do you believe that anyone who has a hobby website with a forum needs an official privacy document, presumably vetted by a lawyer.
What if a forum owner receives a DMCA letter, or a letter from NSA? You do not really need to consult a lawyer to remove copyrighted material or something else that is illegal.
A letter from the NSA is a completely different story. You definitely need to hire a lawyer, probably an expensive one. One NSA letter could easily shut down a small startup.