If so, the GDPR is similar to a broken protocol.
Maybe the people who designed it assume that it will never be misused. Anyone with experience designing protocols could tell them how dangerously naive that is.
If so, the GDPR is similar to a broken protocol.
Maybe the people who designed it assume that it will never be misused. Anyone with experience designing protocols could tell them how dangerously naive that is.
We keep being told that "data is the new oil". It is. Not for money making opportunities, but because you have to handle it responsibly and if it leaks it will cost millions to clean up.
For the few small companies I've worked for, this would have been a bit of work once (document the dataflows), and then a fairly easy set of queries to be repeated each time.
To add to a sibling comment, Google can afford a big enough legal department for estimated 0.00000x% of their turnover that deals exclusively with these.
For smaller organizations, this becomes more like 0.x% of turnover...
Not to mention the distraction and plain overhead when you're juggling so many other things.
By that logic don't you need a lawyer to handle all customer support interaction?
Couldn't you get sued to fraud if you fail to document purchases in a legal-safe way?
The part that's not clear about the GDPR is whether you're obligated to manually answer any data-related question a user has, or if you can just post a comprehensive FAQ + data export / account deletion tool, and auto-respond to GDPR requests with links to those.
It's unlikely that the number of requests of the type referenced in this article would be sufficiently large enough at that stage that it wouild "eliminate the value proposition."
Here is a listing of everything you have a right to know about our company and processes under GDPR:
<huge info dump>
Here is all of the personal data we have about you:
<very long CSV file>
Ideally, the most time-consuming part of responding, after the first such letter, will be verifying the user's identity.
It's very different. Here you're requested to answer fairly detailed and potentially tripping questions with potential legal implications on your business. This has little with how you secure things technically. It's all about jumping through some bureaucratic hoops, and wasting your time doing it. Answering those questions won't in any way, shape or form improve the security of your business. It's pure distraction.
My personal experience with the ICO has shown their quite lenient to mistakes, if you can show that you’re your honest best, and getting better.
No point crushing companies that are trying, better of getting the ones that just don’t care.
But it's not even just about getting to a point of getting fined or under some kind of investigation or audit. It can be all those clever customers who would use some automated service or a template, just to waste your time ... At least that's what the original post is about, but I hope it won't be too common.
Around here, regulators are prone to scoring easy points by going after the small, naive fish. All it takes is the wrong incentives: the department needs to show results, so it gives bonuses, or establishes quotas for successfully handled cases. Bam, your small business is now investigated because a government employee needs to meet a quota and correctly guesses you can’t afford competent legal defense.
Answering the questions is not intended to improve the security of your business, it's a form of serving your customers.
The difference is that you know offhand how to do one of these things but not the other.
People keep making this kind of argument, but it makes no sense.
Personal data isn't protected from leaks and privacy intrusions by documents or emails. It's protected by encryption, or only being processed by software with a clear purpose, or simply not being stored in the first place.
I suggest that it is not only possible but also quite likely that a reasonably diligent startup will be taking reasonable practical steps to secure personal data but will not have formal documentation or automated processes in place of the kind that would deal with a SAR like this.
We expect programmers to write working code out of general competence (and we even make sure they know how to write working code in the interview process), but we still write tests and insist that they pass. We expect finance folks to handle money correctly out of general competence, but we still have written policies about how money should be handled. The reason we do these is that good, well-intended people occasionally make mistakes, and in both of these cases, the mistakes have real consequences.
A written policy about how you handle data isn't going to save you if you're messing up in general. But it should be easy to write, and it will save you from "Wait, why did one of our interns add a library that sends stack traces and local variables to a third party? How did this code review even get approved?"
The documents don't protect your users' data. Your general technical practices protect your users' data. The documents protect your general technical practices.
So I think I would still argue that the security benefits of this law in terms of any documentation and processes it requires are at best unproven, and that a startup could be doing the practically useful things needed to protect personal data regardless of how compliant or otherwise they might be with any documentation requirements.
I wanted to tell you how impressed I am with how patiently and clearly you've responded throughout this comment section.
I likewise think the intent of the law is admirable: prevent future Equifax-es, give people control over their data, and centralize the requirements so that companies need to comply with a single EU standard, instead of 28 country-specific ones. But the amount of discretion left to regulators and the lack of any sort of proportionality built into the law make this all very scary. We are expecting a fifteen person small business to have a totally impractical degree of _documentation_ and _formal_ processes, which are 1) very expensive to produce, 2) totally unnecessary for an otherwise reasonable and well-intentioned group of people, and 3) crucially, basically orthogonal to actual data privacy and security best practices.
And even if you comply with the letter of the law, just reading and understanding an email like the one in this post will require hundreds of dollars of company time – beyond reading it, it will need to be escalated, someone will need to loop in a few other people to help with any new technical details, and so forth. If the fully-loaded cost of a white collar employee is $75/hr, this all gets expensive very quickly, and that cost can be levied on a company by an email that can be sent in one minute. Nobody is going to bring down Google with GDPR-spam but it would not be hard to do serious damage to a company of ten people.
There are a lot of well-meaning thoughts in this thread from people who are frustrated at the status quo but unfortunately don't understand how little this law will do to change it and how huge its costs will be.
When you try to deliver a novel product and build a business around it, you are forced to develop a strong sense of practicality and an understanding of the machinery of a business. Most people have never done this. Despite being very intelligent, a lot of these people haven't experienced the realities of creating a business, and as a consequence they don't really understand just how harmful this kind of law can be.
I admire how patient and articulate you are. (And I think your thoughts are clear and your point of view is correct and badly needed.) Would love to buy you a beer sometime.
Since Silhouette (and gdpr_throwaway) want to keep their anonymity, I opted for virtual beers by upvoting :) But happy to convert those karma points to real food or drink -- and hopefully an insightful conversation -- if you feel like getting in touch (my details aren't so private).
Then limit what you record. What do you need to store that isn't visible from peoples user profile when logged in?
Basically, you can request any non-sensitive information from any government agency and they have to provide it within a reasonable term or pay a fine to the requester.
This caused people to request all calibration reports of a speed camera if they got a ticket, because for quite some time the government would waive the ticket if you stopped the request.
When it got abused too widely they automated the process and now it's not a problem. This is also how large coorporations should handle this problem.
If you phrase it as "large companies," then it sounds bad - but it forbids incompetent large companies too. It enforces that only companies that are competent enough to answer questions about data protection can be in the personal data space. If a small company is inherently incapable of answering those questions or handling the data properly, it shouldn't be allowed in that space.
It's like saying that there's a "government enforced monopoly" keeping newcomers out of the food business by not letting them just make things in their apartment and hand them to Uber Eats. It is a technically accurate description, but most people who believe that government has any legitimate functions at all see health inspections as a good thing.
Can't feel too sorry for them
There will always be a few people out to cause trouble with excessive requests, but I don't think we should let that block access to non-sensitive information for things we as the tax payer have paid for.
See:
https://ico.org.uk/for-organisations/guide-to-the-general-da...
https://ico.org.uk/for-the-public/personal-information/
You can wait 3 months (not one).
You can charge £10 if the request is complicated.
A $1000 fee would seem a little bit more fair.
The law needs to be applicable to everyone, and imposing high costs is generally considered to do the opposite: http://www.bbc.co.uk/news/uk-40727400
It is utterly unfair to compare subsidized access to an employment tribunal (potential harm: months of undeserved unemployment, loss of home and possessions; cost of investigation: spread across the entire nation's taxpayers) to almost-free access to your GDPR privacy report (potential harm: a little bit of mental discomfort; cost of investigation: borne by one organization, potentially ruinous for a small business or solo project).
Companies storing and losing PII have a huge negative impact on the affected users, like e.g. credit card fraud or tax refund scams. This bears a huge actual cost to the victims, either because they never get back the stolen money, or because they need to invest significant time and expenses to fight for it.
A company trying to make money of my PII should better be prepared to handle it securely and to delete it upon request. Handling of GDPR requests must be calculated by them as part of the data handling expenses.
In both of these cases if the information is misused it has consequences for the individual, and (relatively) higher cost for the individual on minimum wage.
In the former, this can affect your future ability to find housing. This potentially leads to extraordinary stress.
In the latter the consequences again affect both wealthy and poor, but the person living hand to mouth faces much more serious consequences if their wages are adminstratively docked to pay for costs fraudulently registered in their name. Further, they're unlikely to be able to pay an expert to resolve this or take time out of work to do this themselves.
Which items do you feel are an impossible burden?
From what I see most of the items pertain to one of two possibilities:
1 - General procedures or information about the company (keep this updated and it's the same for all requests)
2 - Information about the subject (export their data in an automated fashion)
The thing about 'decisions based on their data' might be tricky, but I guess you can share what you concluded from it and the overall rationale (for example, Facebook's "Why am I seeing this" over an ad)
There are law firms whose sole business model is targeting small companies for not complying with certain regulations like legal notice requirements or disclaimers on websites.
Only time will tell if this will be the case with GDPR but there definitely is a risk that this new regulation will be abused by dubious players.
Impossible? Why is it not possible?