GDPR: Don't Panic
181–190 of 833 posts
Re: GDPR: Don't Panic
#182For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…
The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.
Re: GDPR: Don't Panic
#183Earlier quoted context omitted.
It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)
If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.
Realistically, how hard is it to automatically grab some data from a database and export it as JSON, as well as remove data from your database pertaining to a user? With a relational database, this would be a cinch. I mention the right to access the erasure right, as I estimate these will be the most frequently called upon.
Re: GDPR: Don't Panic
#184Earlier quoted context omitted.
On what experiences with EU bureaucracy do you base your statement?
on what experience about gdpr case law is the linked article basing his statement? all those claims about warning shots and leniency and goodwill of the regulator are completely unfounded. the linked article makes the claim, the linked article should substantiate the claims, and we maintain a healthy right to remain skeptical of those claims until some meat is added to them.
In one a company was handling sensitive personal data (medical data). They're required to register with the ICO. They did not do so. The sceptics would claim they got huge fines. They didn't. THey got a letter asking them to register, with no further action taken. ICO released a statement.
Last para here: https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...
In another the Crown Prosecution Service lost data in the same way they had previously lost data: they sent unencrypted DVDs through the mail and those DVDs got lost. The DVDs contained victim interviews from children who had been sexually abused. It's hard to think of worse: very sensitive data, transmitted in a stupid easily fixed manner, and a repeat offence. Even this didn't attract the biggest fine. They got a £350,000 fine.
https://ico.org.uk/action-weve-taken/enforcement/crown-prose...
We have over 20 years experience of regulation. We're not making this up.
Re: GDPR: Don't Panic
#185For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…
I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…
Re: GDPR: Don't Panic
#186This is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?
How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit? The same way judges can throw out a case without going to trial. Checking if the complaint makes sense, if it represents an actual violation as described, etc. Anyone dealing with the public knows that a huge chunk of the complaints don't even pass that bar.
Re: GDPR: Don't Panic
#187This is how I understand the GDPR: You cannot store a users personal data like IP or cookie id unless you have consent from the user. I expect that nobody will comply with this. Smaller companies seem to think GDPR is something they can fix by changing the legalese in their impressum and privacy policy. "Yet another trip to the impressum generator". Bigger companies seem to pretend they misunderstand the GDPR. I got…
This isn't right. Consent is just one of six legal bases through which you can lawfully process data under GDPR.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Re: GDPR: Don't Panic
#188For instance, I run a small community website (~30 people). I receive no income, and I know everyone involved. Everyone is in the United States. Is it open to the world? Yes, technically. What happens when an EU resident signs up? Well, I'll continue to do exactly the way things are currently set up.
How does this situation play out long term? First, I'll tell whomever contacts me that I am in compliance with US law, and I'm a US citizen. I do not have to follow their laws because it's not within my jurisdiction. Second, they will order me to block EU citizens from my site, which I will not do because it's a mandate of work on me for no reason by a foreign country.
So what happens in this situation? The only recourse for the EU is the internet version of "sanctions", to block my website from the EU.
Now they've set a really interesting precedent. How do they now enforce these blocks? Technical issues aside, are they going to do a whitelist or a blacklist? Regardless, they are setting up the equivalent of the Great Firewall for the purposes of maintaining the GDPR.
So why does this matter? It's only an isolated incident that will likely never occur, right?
Wrong. One community website like mine with one EU citizen that decides to file a GDPR complaint means that somehow this situation occurs. It can even be an intentional, "sign up, file complaint" immediately to trigger this legal situation. Think there aren't any foreign governments that wouldn't flood a system like this to censor the EU citizens in various mild ways? Think some random anarchist activist will not decide to monkey with the system by finding and reporting all the small violators?
The end product is a curation of the internet for EU citizens by EU government. Hopefully your leaders are benevolent, and nothing crazy happens in the democratic process. I remember being told during the Bush and Obama administrations that my views against government surveillance due to potential for abuse were unjustified because we could never have a horrible president and that our presidents will always be benevolent, so the policy would never change toward the worse. How did that play out? How do people think democracy functions, honestly?
Again, I really don't care too much. They can self censor if they want, but it really seems like GDPR is a win for Russian and Chinese meddling.
Re: GDPR: Don't Panic
#189There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…
No-one can sue you now, that couldn't before. I'm baffled that so many people believe this. I could complain about you to my country's regulation body. Then they could decide to audit you, and for a first offense issue a warning.
If you need the address data for marketing only, and you didn't get an explicit (opt-in) yes to receive marketing, then sorry. Get that explicit opt-in yes in the next week, or delete the data.
If you need the address data for other reasons, for example fullfilling your contract with the customer, or tax records, then keep it. But _only use it for those real reasons_. No free marketing lists. Sorry.
Storing an IP for a limited time for security reasons is fine. Have rules in place for how this data is used and when it is deleted. Don't keep it longer than nessescary.
Google seems to think you can still use Fonts. They also seem to think like they will be the data controller, and not data processor, for any user data they scoop up [1]. This seems a bit weird to me. This is the only one of your questions that I'm really not sure about. If it was me, I would just host the font locally so I was sure.
1: https://github.com/google/fonts/issues/1495#issuecomment-382...
Re: GDPR: Don't Panic
#190Earlier quoted context omitted.
The DPA (Datatilsynet) in Denmark operates in the exact way stated in the article. I've fairly sure it's the same in Sweden, Germany, UK, and most of the EU. It is in stark contrast to the US. I'm not going to link cases, because they're in Danish. They are available from their webpage, and the most resent ones are linked on the frontpage. The last few cases large companies was not in compliance and the didn't get a…
That's supernice for you in supernice Denmark. Now what about all the other EU countries? What about in 5 years time if things become less supernice. 10 years time?
We have plenty of cases serving as prior judgements, and if a DPA suddenly act with a disproportional reaction, there is multiple levels of courts that can and will reverse the decision - nationally and EU level as well.