Live data from Hacker News

GDPR and automated email marketing

gdprhq.io

81–82 of 82 posts

Re: GDPR and automated email marketing

#81
post #80

Earlier quoted context omitted.

I don't have any sympathy for business who were complying with the letter of the law while finding any excuse they could to subvert the spirit of the law. Neither do I. It's the organisations who were complying with the letter of the law, the spirit of the law, and generally accepted good practices at the time and still won't be compliant under GDPR that I'm worried about. As a concrete example, every single charity…

It's interesting that you mention charities, because as we know in the UK many of them were breaking the law and there has been considerable regulatory action to bring them back into compliance with the existing PECR and DPA. The fact that they're all contacting people saying "We need to re-gain permission under GDPR" just means that a bunch of organisations were, and still are, clueless about data protection. This,…

I had a different impression from the charity contacts I have, but let's assume you're right for this discussion. Doesn't that mean the only practical effect of the GDPR on these organisations is that instead of funding research to help people who had a stroke or providing water to villages in Africa or whatever other desirable work they would normally be supporting, they're spending time and money on legal technicalities that aren't going to make any meaningful difference to anyone? I still don't see how that's a good thing.

As someone supporting these charities and whose personal data is being used to send the updates on what they're doing, I (and others in a similar position) am the person who is supposedly being exploited undesirably and in need of protection here. And yet, as I wrote before, I was quite clear about what I was expecting to happen when I filled in each form, and none of the charities I deal with regularly has ever done anything I would consider abusive or beyond what I knowingly agreed to. I really would prefer it if they didn't have to waste their resources on this and instead spent them on whatever good work they would normally do, but since every single one of them has contacted me anyway, I have to assume that something about the GDPR-related changes is preventing that from happening.

Re: GDPR and automated email marketing

#82
post #78

Earlier quoted context omitted.

I fully agree with you, but there are many technical services/platforms that assume things that are not compatible with that thinking. Those will have to change, but they are still not up to speed. Let me preface my question with the statement that I mostly love the GDPR, and I think it greatly improves privacy and digital rights and I will exercise some of those rights come May 25:th against companies that I feel ha…

Sorry for late reply. For old data, the easyest way is to burn the tapes and make new backups. Now about new backups, here it becomes nasty as typically they aren't organized granulary enough (but you also need this for exporting the data on user request, so you just need to do it). Instead of backuping the whole databases, backup each users data separately, maybe database partitioning, table inheritance (postgres) o…

If You’re really destroying your logs each week you’re not meeting a lot of regulatory requirements, such as PCI if you accept credit cards.

Most security-oriented regulations, and indeed so-called “best practice”, requires keeping logs for security auditing purposes for at least a year if not longer. They’re often the only tool you have to detect when and how a breach began.

Post reply on HN