But are you doing business abroad, just because you're on the internet?
Is it not the customer who is coming to you to to do their business abroad, while you do your business in the country you live in?
141–150 of 833 posts
But are you doing business abroad, just because you're on the internet?
Is it not the customer who is coming to you to to do their business abroad, while you do your business in the country you live in?
However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been routinely asked in recent months and there isn't always a clear, dependable answer:
- How will I be able to operate my small company website in the future in a legally compliant manner? Some companies even consider shutting down their websites completely and - of all things - only using a Facebook page in the future. Hence, ironically we might very will see GDPR actually benefitting companies like Facebook at the detriment of small companies that consequently won't have complete ownership of their content anymore.
- How exactly does a privacy policy have to be worded so I don't get sued on day 1?
- In which way will I still be able to store address data for contacting my existing customers?
- Will I still be able to use anti-spam and security plugins for my website? These tools might store users' IP addresses, which in some jurisdictions are considered personal data.
- Can I still load resources like Google Fonts from CDNs or do I now have to host those myself?
Earlier quoted context omitted.
I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.
It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)
Earlier quoted context omitted.
Talent pool as a Saas and the company needs to manage GDPR - you still have acces to your data. Still open how you monitor the company as required by GDPR, but at least you can redirect angry candidates.
In that scenario, you are the data controller and the GDPR obligations ride on you.
(simplified)
* You need to have a data processing agreement with the Saas company X.
* You need to tell candidates in your privacy information that you send data to X
* You need to make sure X is properly implementing the data processing agreement (currently not clear how you do this except using e.g. PwC to review X)
If you have the data, you need to tell the candidate what you do to protect it, backup it, restrict access to it etc.
(also if e.g. the talentpool feature is provided by LinkedIn based on LinkedIn data you're not responsible under the GDPR, only if you sent data to X or X collects data on your behalf e.g. in a web form)
Earlier quoted context omitted.
In an ideal world, yes. But that leads you down a Kafkaesque hole of bureaucracy - at some point you have to stop adding detail and leave things open to interpretation. There are plenty of laws out there with fines "up to €X" and, from my limited experience, I don't think the GDPR is especially ambiguous compared to others.
Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!
It's not a minimum.
Earlier quoted context omitted.
The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.
But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…
A new commission can always change their mind and propose new laws that get voted in, as can any government. There is few things an elected body can't do, and even when there is safeguards then those can be removed given enough effort.
And this is not exclusive to them. Common law and to a degree Civil law are changeable in this way where a court can retroactively decide that things previously allowed were actually illegal by providing a mere "clarification".
In eu this mean several layers that can modify what a law actually mean. The government, the national courts, the EU parliament, and the EU court. In the US you got federal law, state law, city law?, and courts all the way to the supreme court, each which can in 10 years make a decision that retroactively decide that things previously allowed were actually illegal. It seems like a risk that is inherently part of the legal system everywhere.
Earlier quoted context omitted.
In all of my research, talking to lawyers, and seminars on GDPR, it is about: 1. Ask permission for collecting data 2. Keep sensitive data safe 3. Restrict access to said data 4. Keep a log of what happens with the data 5. Delete it upon request 6. Have all of the above documented and adhere to the protocol. It's such a none issue unless you're relying on the very thing GDPR is designed to combat. If you not collecti…
Completely agree with everything you list, and would add that 6. you can't force a user to give up privacy in order to get some other benefit, e.g. you can't offer to unlock some feature in return for more tracking
Earlier quoted context omitted.
Law is by its nature open to interpretation and based on precedent. Otherwise there wouldn't be courts of appeal and supreme courts. What's so special about GDPR that makes you think it will be abused more than other laws?
What you're describing is the way common law works. Most European jurisdictions work under a civil law system.
wrong.
if everyone always followed the laws, earth would still be considered flat (at least until more recently).