Earlier quoted context omitted.
It is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.
What targets? Where have you heard something about targets?
GDPR: Don't Panic
131–140 of 833 posts
Re: GDPR: Don't Panic
#132This is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?
Re: GDPR: Don't Panic
#133Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).
It is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.
There are no targets for bureaucrats.
Re: GDPR: Don't Panic
#134Earlier quoted context omitted.
This sounds like the arguments that organisations make against freedom of information laws. There is that risk, but what is the alternative? There doesn't seem to be a middle ground to me - either people can make subject access requests or they can't.
Not an alternative - but the only obvious defence is to do the right thing, and delete data as soon as you have completed processing. e.g. delete those interview notes the second you have declined the candidate.
I have. There's no way we will be deleting interview notes the moment a candidate is rejected. For one, we have to be able to prove later that we didn't reject based on grounds of discrimination (other regulations). But you also need the ability to review what your interviewers are doing to ensure consistency and quality of assessment. We also go back and re-read interview notes if someone doesn't make it through probation or gets fired, to see if we could have picked up on the issue earlier.
But hey GDPR defenders, here's a question to ponder. I have argued above that I legitimately need interview notes for the operation of my business. If you disagree, what makes you so sure your interpretation is correct and not mine? Don't you think it'd be good if we could resolve this disagreement in some clear way, like if the law itself spelled it out?
Re: GDPR: Don't Panic
#135> I don’t want to end up being arrested for GDPR violations when I go on a holiday in Europe (yes, I really saw that one) The US did it recently: https://www.theguardian.com/business/2017/dec/06/oliver-schm...
Re: GDPR: Don't Panic
#136Re: GDPR: Don't Panic
#137The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.
> The problem of multiple ambiguities in GDPR hasn't really been addressed here. Such as? > Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. It is, thanks.
- Scope outside of Europe – e.g. if a completely foreign entity that offers a Spanish or French translation of its service could potentially be covered by GDPR, even if they're not marketing to EU markets specifically. Too bad for Quebec I guess. Or what if you fly to speak at a conference in Europe – is that "marketing" to residents of EU? Depends on your slides? Or not? Who knows.
- Consent – does X fall under "legitimate interest"? Is it essential to providing the service? These are not easy to definitively answer for any non-trivial application. And it's not like you can just err on the side of caution – you are not allowed to ask for more consent than you need IIRC. And if the regulator (one of them) disagrees with you after you've spent a few years building a business relying on a certain interpretation, tough luck I guess, try again?
- How to deal with backups that contain personal information
Re: GDPR: Don't Panic
#138So it all depends.
Re: GDPR: Don't Panic
#139Earlier quoted context omitted.
But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…
> CNIL then immediately changed their mind and dished out a fine So, there's no opportunity for litigating using their previous statements? At least now I understand why you're on every GDPR thread.
Regulators can never be held to anything they say. When you ask questions, if they answer at all, it always comes with a disclaimer that it's merely "guidance" and not binding. If they later change their mind, it's always a "clarification" and not a change.
The sort of people who think vague regulations are a good idea are the sort of people who think regulators are staffed by people who are inherently good, so they're usually written to give regulators maximum power and minimum accountability. GDPR is a case in point. If you read the EU's documents on the matter closely, and I have, then you find that the EU refuses to even respond to questions at all. That's delegated to national regulators, but the EU is clear that those regulators don't have the power to issue binding declarations, only guidance. In other words, you can ask a regulator or a lawyer. Their opinion has no more or less weight than my own posts do. The only time binding decisions are made is during enforcement actions.
Re: GDPR: Don't Panic
#140Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.