Why they don't want to answer request? It's still would be a nice thing to do ever if not required by law.
An Eve Online corporation has been hit with a GDPR request from an ex-member
31–40 of 141 posts
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#32As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…
Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of view. You need to make sure that deletion requests also get honored when restoring from backup though, so ideally you want to store the requests in a third system and check them when you restore backups.
Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#33Earlier quoted context omitted.
Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.
If you run a website, is "not blocking users from the EU" considered as providing services in the EU? I am genuinely curious because in that case GDPR seems to impact many companies disregarding whether they actually do any business here.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#34Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#35As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#36The subtitle is "[d]isgruntled ex-guildie effectively invents new way to grief in EVE" but it sounds like the request in question was sent to a website outside of EVE. This could happen with other games or, you know, websites unrelated to games at all...
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#37How would this work if the data was stored on an immutable blockchain?
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#38Earlier quoted context omitted.
It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.
Your legal concept isn't valid. Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law. If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my…
However, isn't the idea of forfeiting the personal jurisdiction defense? I am not a lawyer, but from what I understand, once you start debating the merits of the case, you waive the ability to claim that the court doesn't have jurisdiction.
It seems like there's a bit of a chance of that here - once you admit the EU or Chinese legal system is the appropriate place to redress things, you've given up lack of jurisdiction as a defense.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#39As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…
I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#40As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…
Rolling backups, e.g daily and weekly, are fairly common. When the request comes in, just acknowledge there will be a time period before the deletion is fully purged from system backups - as is still legal post-GDPR. The user data will still be removed from production data, which is of primary concern.