I have been through a number of GDPR resources and seminars and I am still of the opinion that there is nothing in it to worry people who are acting in good faith with their customers data. The organisations fined under existing laws seem to have been breathtakingly negligent or just deliberately callous.
Q: would I still be able to keep session logs of user journeys through my site without explicit consent? If not, this seems like huge issue for ecommerce analytics. If I need to obtain explicit consent, that the user isn't required to provide to continue accessing the site then I don't see how these technologies are not basically dead in the EU. Can you even legally do a customer churn analysis under the GDPR without…
Yes you can keep session logs, it is a 'legitimate interest'.
Are you just trying to see which deals interest people (zero issue, but you could annonymise this) or profiling the customer based on the logs and offering different prices (you are going to have to be more careful and transparent).
> Can you even legally do a customer churn analysis under the GDPR without explicit consent
There a lots of ways to look at churn with anonymised data. I do it with account ID's. If you are looking at churn rate of Asian people vs Afro-Caribbean then GDPR is going to be amongst your problems,
Many CS programs are accredited by ABET, but they're covered by the Computing Accreditation Commission which doesn't qualify graduates to sit for the FE exam. And many top CS programs, including CMU and Stanford, aren't ABET accredited at all. Nationwide, there's only 27 Software Engineering programs accredited by ABET. So graduates of those programs could sit for it but until graduates from top programs qualify, no…
> but they're covered by the Computing Accreditation Commission which doesn't qualify graduates to sit for the FE exam. Wait, are you sure about this? When I was in school, they pushed CS/CE students to take the FE Electrical and Computer exam. I never signed up, but why would the school nag students to do something they weren't allowed to do?
CE students are eligible. CS students are not. If your degree was a combination CS and CE, it might have been accredited by both commissions.
If wasting electricity becomes such a big problem for the society as misuse of personal data already is, sure, let's introduce regulations on that, too. In some European countries, there are regulations already on how to insulate new buildings to avoid energy waste.
> If wasting electricity becomes such a big problem for the society as misuse of personal data already is, sure, let's introduce regulations on that, too. Sure, what could go wrong there? Regulator, "We're going to need to look closer at that for-loop to see if it complies. And you do realize that n+1 queries are a violation of EU law?"
Your example is obviously unrealistic, but even when buying it, it rather supports my position. Imagine a regulator indeed pointing out where you can optimize your algorithms and thus save energy, money and achieve faster query processing. What is the problem with that?
Fire safety regulator: "we're going to need to look closer at that door seal glue component to see if it complies...". Nobody complains here about a regulator looking into details.
There is a fundamental truth that no one seems to accept.
But it is the truth, and the majority of the planet's ignorance of this fact makes it no less true.
(I am not arguing about what is legal or not, or proposing any illegal behavior, rather just observing that many things legal in the past were absurd/ wrong or still are in certain places on the planet - eg - women not being allowed to drive in certain countries. ie. I repeat, I am not arguing about what is legal or not, I am arguing about the disconnect between reality and the law).
The hard truth:
There is no such thing as privacy - it was just not so apparent until now. I can know whatever I want, you cannot stop me from knowing the color of your shirt, your bank pin, or seeing pictures of you naked if they exist. I am free to know whatever I want, and so is everyone else.
When everyone understands that this is in fact the case, then the world will be a better place.
There are lots of interesting topics and conversations that arise from this (sometimes people call them counter arguments, or try and tell me that what I am calling for is wrong). I am not calling for anything, and I understand the ramifications. But most importantly, I am not talking about how I want to world to operate. I am observing how the world DOES operate. Einstein did not invent relativity (I am not comparing my (probably far far lower) IQ to that of Eintein's like you will deflect to as I use this analogy to get my point across). Einstein merely observed what was there for anyone to observe, and his observation made the world's societies of people a better place (because humanity increased it's understanding of existence).
I repeat privacy is a fallacy. I can and will know whatever I want to know. So will others. Currently people in power have an unfair advantage because they can know anything about anyone and the rest of us go to jail if we also know it. The way to level the playing field is to realize this fact, remove the laws (in theory, that is my proposal, but I don't know how), realize everyone has a naked version, has been bad, can be taken out of context. In the end, the importance of context will return and the novelty of nudity (and all other things (location that abductors can find you, etc) and intimate knowledge will reduce. But we will all be better off because the difference between the person who knows your bank pin and the person who steals your money will be clearly understood.
Currently this is not the case.
My observation is correct. Although you will not agree, and be played as a sucker, continuing to fight for privacy, being ashamed of your past while making yourself more and more at the mercy of the bullies (I mean governments and information curators like wikipedia, fb, twit,goog - they are nothing more than storers of user generated content) that make laws and use them against you.
Another observation that you will dislike me for, but that I ask you to, at the least, just meditate on, repeating in your head a few times, before dismissing it:
Laws are a cheap substitute for understanding.
I think more there developers; it is operational burden for companies. GDPR discuss about the lifecycle of customer data and trying to draw boundaries who, how, when, where the user data is going to used.
Our product https://www.StegoSOC.com helps in automating cyber threat detection. That is also one of requirement for GDPR.
Could you elaborate on how this is a restriction on freedom of speech? How is an 'information site' affected? Take HN for example, when I signed up they didn't even ask my name. They probably log IP addresses and would be entitled to, for the purposes of analyzing malicious use.
It's all PII. People post personal details about their lives here, some use their real names as their username, the site asks for email addresses, how is it not PII? As for IPs. Any website could claim they need IP addresses for analyzing malicious use. So either it'll be a new cookie law in which they all use the vagueness of the new rules to loophole themselves out, or the EU will decide that this is only "reasonab…
> People post personal details about their lives here
Which they explicitly choose to do
> some use their real names as their username
Which is not required to use the site
> the site asks for email addresses
But you don't have to give one. If you do give one it is only used for password resets. Write that in your privacy policy and keep the email safe.
> Any website could claim they need IP addresses for analyzing malicious use
Yes they can, and the law allows it. Don't sell them to data aggregators and put it in your privacy policy why you are keeping it. If you don't want to then send the logs to /dev/null
> or the EU will decide
The courts will decide.
> The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
What do you want from the EU? A law that references the internet protocol explicitly, and every possible use of it? What happens when the protocol changes, or someone invents a new protocol, or a new way of exploiting it? Pass another law that says the same thing? Laws in the EU are generally principle based for exactly this reason, they age much better.
When stuff like this comes up it always seems so weird to me that with all the work that regulators put into this, why can't they at least scratch the surface of providing some specific examples? Of course there are legal documents, and maybe some "for dummies" versions written up about it. But would it be so crazy for these regulators to hire someone who knows something about commonly used open source software and b…
As others have noted: Laws with examples would be to specific to survive fast technological changes. Laws do mostly contain the 'spirit' of the idea and are applicable to many different situations and times. But the European Commission does gives examples: https://ec.europa.eu/info/law/law-topic/data-protection/refo... This is of course no nginx configuration. But the thing is.. there is no one size fits all example…
>Saving ip adresses in log files can be fully complaint IF you only use them for legal reasons (sue an attacker, ...), have severe access restrictions on the files, delete them as fast as possible and get consent from the user prior to saving the logs.
You do not need consent for saving the IP, user agent and URL (including GET values) in Apache logs because, as someone said above, you have a "legitimate interest to combat fraud and maintain information security".
Legitimate interest and consent are only 2 of the 6 legal bases under which you can collect and store (process) personal data. Art. 6 contains all 6 https://gdpr-info.eu/art-6-gdpr/ .
Standard server logs with IP addresses must be disclosed in a privacy policy but you do not have to seek consent for them because you collect them as part of a business critical need to prevent fraud. See Recital 47, which includes the language: "The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned." https://www…
The user can request I delete all of the data related to them without “undue delay”. Are you ready to purge all references to certain IP addresses in your logs? Don’t forget backups. GDPR blows up a lot of assumptions we make about writing software and managing servers. https://www.privacy-regulation.eu/en/article-17-right-to-era...
I wouldn’t worry about individuals requesting access or deletion of the Apache logs concerning a certain IP as I see no possible solution for the “reasonable measure to verify the identity of a data subject” against an IPv4 IP and, as per the GDPR, providing data to the wrong person could “affect the rights and freedoms of others” in which case you shouldn’t provide the data.
If only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe. GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulator…
You need to crawl through all your webserver logs (the zipped ones as well) and remove entries by IP. I seriously don't get what's the huge deal about this. Of course it sucks but it's not THAT hard to implement.
No you don't.
AS per the GDPR I see no possible solution for the “reasonable measure to verify the identity of a data subject” against an IPv4 IP and thus to reliably act on IPv4 related data subject access/deletion requests.
Also per the GDPR, providing data to the wrong person could “affect the rights and freedoms of others” in which case you shouldn’t provide the data.