For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…
That Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.
GDPR: Don't Panic
101–110 of 833 posts
Re: GDPR: Don't Panic
#102Earlier quoted context omitted.
FOI laws apply to governments, not corporations. And yes, civil servants did use those arguments to try and stop FOI. They lost because ultimately they pay themselves out of tax revenues, and when you force people to buy something the bar for denying them information about how that money is used is a lot higher. This doesn't apply in the case of companies and especially not job candidates.
Fair point about it being public bodies. But my point stands in terms of abuse of the system - the deluge didn't happen.
That said, I don't think it's really comparable to the GDPR. For one FOI compliance is a joke, organisations get out of it all the time on the thinnest of pretexts. There's no real incentive for a government to police itself in this regard. But GDPR enforcement is incentivised by large sums of money, for an organisation that is technically bankrupt.
Re: GDPR: Don't Panic
#103The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.
Such as?
> Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article.
It is, thanks.
Re: GDPR: Don't Panic
#104Earlier quoted context omitted.
The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.
But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…
EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth.
I understand WHY people have this belief. The EU is under constant attack at the moment from many sides, and people feel they need to defend it at all costs, even it they are wrong.
Re: GDPR: Don't Panic
#105This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…
If your company can not show the candidates why they were not hired, you are doing a very bad job.
Are you discriminating against protected classes?
Are you rude or offensive in your comments?
Then, stop doing it. That will be a very good side-effect of this situation. Public scrutiny works. If a company needs to make public their interview notes, that notes are going to improve quality and abide to law.
> how strong any company will experience their firehose of GDPR requests to be
If you are big enough to have a big influx of GDPR, you need to automate it.
> how easy it is for them to make requests
It needs to be easy. The goal is not to let your company shield behind "sorry it is too complicated to give you the information". You need to give people easy access to their own data.
> wildcard factors
How is this difference of a Denial of service attack on the technical side? On the legal part, there are lawsuits that are going to be more effective than GDPR that starts with recommendations for improvement.
> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. There are obvious ways to monetise a service like this, hence incentive for someone to do it.
You only get the data about YOUR own interview. You can not hoard data this way. It works the other way around. The data protection is protecting you from the company monetizing this information without your consent. Companies are the ones hoarding YOUR personal data and creating a business around it without YOUR consent.
Your concerns are the main reason GDPR was created.
Re: GDPR: Don't Panic
#106> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…
>there's a whole two hundred post debate around here whether ip are or aren't pii on their own. Largely pointless. EU courts have in the past ruled that IPs are personal data because they can be tracked back to a person. End of story. >there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). was largely already covered by the previ…
I know. I'm on that side. Can link you to dozens threads where the comment stating ip are pii are downvoted to hell asunder and false myths spread like wildfire.
> Courts largely agree that calendars for appointments are fine
yes, but for online calendars the provider is a processor and need to be listed as such. and when a customer exercise the right of being forgotten, you'll need to go back and delete the meetings. all new stuff I'm quite sure the majority forgot to consider.
> Yes I did. I informed myself
good for you, doesn't mean there are a lot of business that didn't, and considering the false myth spread around here, this board needs to hear as much as possible about these things.
Re: GDPR: Don't Panic
#107Re: GDPR: Don't Panic
#108Earlier quoted context omitted.
That Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.
Pardon me but, what does ICO site mean in this context?
Re: GDPR: Don't Panic
#109Earlier quoted context omitted.
Outsourcing your talent pools - literally the future of your company - would be an extreme step just to ensure GDPR compliance.
Talent pool as a Saas and the company needs to manage GDPR - you still have acces to your data. Still open how you monitor the company as required by GDPR, but at least you can redirect angry candidates.
Re: GDPR: Don't Panic
#110Earlier quoted context omitted.
That Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.
Pardon me but, what does ICO site mean in this context?