Startups: It costs money to develop the systems to process personal data in the first place. I don't see any unreasonable restrictions in GDPR. If new startups plan for GDPR while developing the systems it should not add too much costs. It is basically about managing data responsibly and documenting how you utilise that data.
Established companies: I don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. This has happened to other industries as well, such as the tobacco industry who had to adjust to anti-smoking laws when the politicians could no longer ignore the negative effects.
Some commenters in these discussions write as if all businesses deserve the GDPR and all its attendant overheads as some sort of punishment for assumed past transgressions. And yet I work with small businesses, and so unsurprisingly I also know many other people who do, and not one of those businesses operates with any sort of data-hoarding, privacy-invading model, nor would any of us ever want to.
All that attitude teaches the next generation of startups is that they'll be penalised whether they try to act ethically and responsibly or not, so they might as well do the questionable things and make more money anyway. Surely that is exactly the opposite of what should be happening?
The only major requirement that can not be fixed by documentation or updating user consent, is the requirement to not store data more than necessary, which depends on your business. If you need to store data for a longer time period than absolutely required, you need to either anonymise it or delete. If you run a business and need to store purchase histories to meet other legal requirements, you have a valid reason to store it. If you use it to track which purchases a specific user has done to optimise targeted advertisement you will probably have to anonymise it.
This can of course be a complex task, but I don't think it is a good argument against GDPR. Why should I lose control of my personal information just because it costs money to process it responsibly? At some point a regulation has to be implemented and some companies will unfortunately be impacted even if their intentions were good.
Was it posted in their local planning department in Alpha Centauri as well? Because to most people running microbusinesses -- which is most businesses, remember -- it might as well have been.
If a business can't do that, it indicates that they don't have control of the information in the first place.
Not at all. It's quite possible that an organisation has been reasonable and responsible about handling personal data and its staff know exactly what it's doing and why, but that the formal documentation and automated processes referred to throughout today's discussion aren't in place because they have never been necessary before.
Why should I lose control of my personal information just because it costs money to process it responsibly?
The trouble is that different people will have different interpretations of "responsibly". For example, I'm not sure it's irresponsible to have been storing and processing data for legitimate purposes and entirely with the subject's informed consent for years, and also to be concerned about the cost of updating or replacing all of those systems because the subject is now being given a retrospective right to withdraw that consent that they didn't have before. While this might be considered desirable in terms of reining in data hoarders like Facebook or Google, it also imposes burdens on organisations with different models and lower risks to data subjects. Some sort of balance is needed between these competing priorities.
At some point a regulation has to be implemented and some companies will unfortunately be impacted even if their intentions were good.
Right, but this is exactly why both unambiguous rules and proportionality are important.
If personal info is worth what a lot of companies seem to think it’s worth, then governments have been downright negligent in their lack of regulation. Playing fast and lose with people’s identities should never have been acceptable, and complaining that the first wave of consumer protections is anti-business mostly tells you what kinds of businesses we’re dealing with.
Now that such requests are free, there is no deterrent and companies must introduce a scalable process for dealing with them (or risk being swamped and unable to meet the 30 day deadline).
This will actually be easier for companies like Google and Facebook to comply with, as they are digital natives.
Financial services is an industry struggling with a burden of legacy systems, and even paper-based processes still. This one GDPR provision alone is causing much expense and heartache.
That's a good thing. If it's causing much expense and heartache it means that our private data wasn't being handled with the necessary care and attention to value that it needed to be.
If they were putting my data at risk because they didn't have enough money, then this was required, right?
"Unfortunately we have to increase prices, because we now have be careful with your personal data"
Talk to better consultants. Consultants are not the regulator. The regulation itself is in plain language. What do you consider is not thought through?
* I (like most companies) have a variety of unstructured and/or immutable logs. I can't just DROP FROM table WHERE. Is it acceptable to delete this data by waiting a few days for a retention period to expire, or do I have to retrofit deletion functionality in?
* What if the retention period is a week, or a month? What if I've been advised to establish those longer retention periods for other reasons?
* If a bug is found in the data deletion workflow, is it an undue delay to say we'll tackle it next sprint? Do we need to drop everything and make it a priority now?
* Once we've resolved a personal data deletion bug, is it an undue delay to roll it out slowly over a week? Does it matter if this is our standard rollout process, or if there's a risky hotfix process we're deliberately choosing not to use?
In order to be allowed to store PII (even if it's in logs) you need a specific purpose. Why do you put PII in logs? What benefit does the user have?
> * What if the retention period is a week, or a month? What if I've been advised to establish those longer retention periods for other reasons?
If there is a legal requirement to keep PII (for example accounting) you can/must keep it as long as the legal requirement demands. If there is no legal requirement you have to delete PII, there is nothing that trumps that.
> * If a bug is found in the data deletion workflow, is it an undue delay to say we'll tackle it next sprint? Do we need to drop everything and make it a priority now?
If your next sprint starts 1 month down the road the regulator won't be happy. If it's next week and your GDPR doesn't have other gaping holes a reasonable regulator won't bat an eye.
> * Once we've resolved a personal data deletion bug, is it an undue delay to roll it out slowly over a week? Does it matter if this is our standard rollout process, or if there's a risky hotfix process we're deliberately choosing not to use?
Are you playing for time or doing responsible software development? If a regulator thinks you are bending the rules good luck, otherwise nobody will demand of you doing dangerous stuff.
I know, there are a lot of things open to interpretation. But as my lawyer told me: "There are people getting a speeding ticket for 5 above the limit and others who don't. Try to stick to the limit and make sure you are seen as one of the second category."
I probably would want to impose stricter rules on myself for the sake of avoiding regulators. But that's part of the problem. It doesn't seem possible to comply with GDPR as such without an army of consultants to guide you; what you have to do instead is invent a stricter regulation and follow that one instead.
> If a regulator thinks you are bending the rules good luck
That's the other part of the problem. A healthy regulatory system needs some way to say "well, you think I'm bending the rules, but I'm actually compliant in this complex way you hadn't considered". If a GDPR regulator just doesn't know much about software development, and thinks that any rollout-induced delay is undue, how do I argue against that?
Read my comment again, it does not say a user benefit is required. What it says is that you need a specific purpose for processing PII. A user can only give you consent for a specific purpose. What is the purpose that results in his PII ending up in an immutable log file? Asking for general consent without a specific purpose does not work with GDPR.
> That's the other part of the problem. A healthy regulatory system needs some way to say "well, you think I'm bending the rules, but I'm actually compliant in this complex way you hadn't considered". If a GDPR regulator just doesn't know much about software development, and thinks that any rollout-induced delay is undue, how do I argue against that?
If you feel you are being treated unfairly you will probably argue through your lawyer. As a technical person I would love it if the GDPR is black and white. It would allow me to know if I comply or not but real life is hardly black and white. So instead of being upset with things I can't change I will just do my best to comply.
PS: I don't understand the downvote.
I need a specific purpose for processing PII, but that doesn't mean that I need a specific purpose for each individual place that PII ends up going. If my web server or database end up incidentally capturing the data in transit, that's not a violation, any more than it's a violation if I copy the data onto more sheets of paper than are strictly necessary.
A lot of the "problems" of the GDPR goes away if you minimize the amount of personal data you process and retain, which incidentally generally will be good for your security as well.
Surely you see why this doesn't weaken the claim that it's hard for existing companies to understand what must be done to comply.
Doing so makes it super easy to comply with from the get-go and puts you ahead of incumbent players and their inertia and legacy systems.
You're going to have to do this at some point, may as well do it early and give yourself an advantage?