Earlier quoted context omitted.
Even if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...
I don't think he can. The DPO may not be assigned any tasks that would result in a conflict of interest between their role as a DPO and their other responsibilities. I suspect that means that the sole proprietor can't be the DPO. But, you know, not a lawyer, not even European, could be wrong. See article 38, paragraph 6, 2nd sentence.
GDPR: Removing Monal from the EU
861–870 of 957 posts
Re: GDPR: Removing Monal from the EU
#862Earlier quoted context omitted.
Maybe companies that are so flimsy didn't have long left anyway. You're required to have a fire safety officer at these companies too, but it's not a full-time position.
> You're required to have a fire safety officer at these companies too, but it's not a full-time position. AFAIK, most of the "safety committee" regulations usually have waivers for small companies.
Re: GDPR: Removing Monal from the EU
#863Earlier quoted context omitted.
Why not? I have yet to see anyone arguing for data protection legislation actually give a reason that they think a users data belongs to the user.
Equifax.
This is a bad solution to that problem. So many people's data was stolen that preventing future data from being stolen isn't the most important thing we should be doing. Last I heard it was 150 million people - that's enough that it no longer really matters to the average person if their data is leaked in the future because there's such a high change it already has.
The real solution is to change our systems so that data leaks aren't a big deal. If people didn't ask for a 9 digit number to identify me, as if that's a reasonable thing to keep secret, then it wouldn't matter if everyone in the world knew it. That's the problem with data breaches like this. That's what we should be fixing in response to it.
Re: GDPR: Removing Monal from the EU
#864Earlier quoted context omitted.
No. It is quite definitely not true that you must comply with the laws of countries you are not in. The EU is primarily leveraging the fact that most everyone wants to travel to the EU eventually. While you in your home country you have no need to comply with the GDPR unless a treaty between your home country and the EU exists to mandate it. The EU is also leveraging their trade agreements. What they don’t understand…
The U.S. has been doing this for decades, applying U.S. laws to global citizens who happen to travel to the U.S, and I'm not even talking about kidnapping foreign citizens and taking them to Cuba.
The US is quite opposed to extrajurisdictional law enforcement which is why they don’t sign onto things like the International Criminal Court.
Re: GDPR: Removing Monal from the EU
#865Earlier quoted context omitted.
You don’t need a lawyer to comply with the law is a weird statement to put out there. You should retract.
What? I don’t need a lawyer to tell me I can’t go out and steal someone’s wallet. It’s perfectly possible to comply with the law without one.
Having a data processing officer in the EU for some definition of significant business is not a natural law and requires careful parsing of the legal text.
Re: GDPR: Removing Monal from the EU
#866Earlier quoted context omitted.
Yes. You can sell alcohol to Saudi Arabians from Canada. You cannot ship to Saudi Arabia. The buyer may pick up in another location where alcohol is legal including in person in Canada. What they do with the alcohol once in their possession is their business.
Selling to Saudi Arabians and selling to Saudi Arabia are two entirely different things. In one you're doing conducting business in the Saudi Arabian market, and therefore under the umbrella of their government and in the other you're conducting business in whatever market the person you're selling your alcohol is located at, and under the umbrella of that market's laws.
Why would Saudi law apply in New York?
Re: GDPR: Removing Monal from the EU
#867Earlier quoted context omitted.
Legitimate interests is not defined. So good luck with that. Also you are responsible for downstream guarantees of legitimate interest. He is right that open P2P protocols like XMPP, such as NNTP, IRC, bitcoin, ethereum, etc are not handled clearly. It is a headache for him I can sympathize.
> Legitimate interests is not defined. So good luck with that. Are you expecting GDPR (or any law for that matter) to define an exhaustive list of every definition, that holds true now as well as for the future? Have a rethink about that statement...
Just as companies need to be specific about how they use data now the legal-judicial system needs to be specific about what it means and intends.
It is a double standard because the legislators are not interested in the commercial impact.
Re: GDPR: Removing Monal from the EU
#868Earlier quoted context omitted.
>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…
I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…
Re: GDPR: Removing Monal from the EU
#869Earlier quoted context omitted.
I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…
And "large scale" means how many records in DB? How many users? Or records per day?
Re: GDPR: Removing Monal from the EU
#870Earlier quoted context omitted.
That is not true. You do not need to comply with any country’s laws except the one you reside in, except for treaties by your home country that say otherwise or your desire to travel abroad. Just think of what China would do to the Internet if it could.
> You do not need to comply with any country’s laws except the one you reside in. Unless you want to business with another country, in which case you need to follow the laws of that country when you conduct that business. Which is what I've been saying the whole time. > Just think of what China would do to the Internet if it could. If you want to provide a service to China you need to follow Chinese laws or they will…
I am just saying that the EU will not be the only jurisdiction following this model. Be prepared.