That is the fundamental issue and it has nothing to do with monopoly.
Just like you need progressive taxation to not choke out the poor, you need progressive regulation to not choke out the small business.
That is the fundamental issue and it has nothing to do with monopoly.
Just like you need progressive taxation to not choke out the poor, you need progressive regulation to not choke out the small business.
> The 1-5 man bootstrapped start up does not.
In my current company we are only two developers and we will comply with GDPR, it's going to take us a week or two worth of technical work, it's really not a big deal.
I wish it was easy as just manually looking for user data after an email, deleting it, and keeping that email request as part of the 'audit log'. And getting affirmative consent during signup.
Most small businesses would be fine with something that casual.
EDIT: If you guys winged it by actually just reading the regulations and winging it, you probably did something wrong.
In the long run, it's good for all of us if those business models are discouraged.
I think the best thing to take away from GDPR compliance is 'it's not as easy as you think it is', 'it's not as obvious as you think it is', and small businesses who totally respect privacy will probably still be breaking GDPR.
The abuses are happening from these big companies, not the thousands of tiny startups that live and die within months that have a few hundred thousand users.
For example, how do the decentralized social platforms (mastadon, diaspora), exist under GDPR?
The networks will not be able to process the data in other ways than making it available.
If you break someone's privacy laws you will be liable directly.
Probably also a note that data on this network cannot be completely deleted for specific technical reasons.
And startups that exploit users don't really provide much of anything anyway.
They can make it all opt-in fairly easily as a requirement for using certain features. People will blindly click and continue like normal.
GDPR or not, that could already be judged as some form of stalking by the already existing national laws.
Edit, people don't seem to like that, but the fact is that just having saved the contact info of people who did not want it has already been used as sufficient proof in harassment (I think? "harcèlement") cases in France. I would be surprised if it was not already the case elsewhere as well.
Most of the work in my company for GDPR is around user profiles, we store very few data about the users so we don't have that much to take care of. I guess if your business is to gather customer data, it's a completely different story.
If I use your service to store a photo of my mom, you now have a legal obligation to her even though you don't even know she exists. Any text that you store, you are required to know who is mentioned in it and give them tools for download, right to be forgotten, etc.
We have zero data on non-users so this part is not relevant to us, like I said it's not a data-gathering company. For the tools to download, remove data, consent... That's what I meant with that one or two weeks worth of work.
If I, party A, send a message to party B that happens to contain information about party C, party C does not get to see the messages between parties A and B just because it concerns them or has personally identifying information about them.
https://enterprise.microsoft.com/en-gb/articles/roles/discov...
GDPR does not cover only data you collect through your primary business model but ALL DATA defined as Personal Information under the GDPR.
What toy have to doo is to provide a way to scrub accidental data leaks.
I'm thinking cases like "someone posted a picture of their friend with a cat on your site". Not explicitly labelled "send in a photo of yourself".
Or if someone posted another's address. You should respond to it at least in request, preferably earlier.
The discovery service is mostly to help people transition by checking their third party operators if they do not know who that is.
If I take a photo of a crowd of people and upload it to a cloud service, that does not create an obligation on either me or the cloud service to identify all those people and give them to opportunity to opt out (or in).
I own the copyright of photos I take. I don't need permission from people to take their photo in a public space. They have no right to ask me to delete the photo or remove their face from any photo that includes them. Even if I store it on a computer.
If I provide a service that identifies all the people in a photo, then I am storing personally-identifiable information and I need to give the person I have identified the opportunity to remove their data from my system.
That doesn't mean removing their face from the photo, but does mean removing the data that allowed me to identify them in the photo. There's a difference.
Accidental uploads of private data by the user are perfectly fine in terms of GDPR but you must allow for these to be removed on request.
If you automatically scrub them it is good, but you do not really have to do that. Telling the user how any pictures will be used and how to get rid of them is enough.
That's like screening all your binary executables for accidental inclusion of someone's name in ASCII amongst the bytes.
It's a lawyer's job to worry about everything that could go wrong, and assume a worst-case scenario, but surely in many cases GDPR will be about the spirit of the law rather than the letter?
For example, while I personally think the backing-up-now-deleted-user-data issue is not insurmountable, assuming it's not, I cannot imagine that these 'small companies' will be fined left and right for failing to remove a user's data from every backup. And that's even assuming that there's a high likelihood that said backups will be investigated.
To make an analogy: there are quite a number of regulations in effect concerning invoicing that are flagrantly violated by almost every single small-business owner that I know. Some of them have won the 'audit-lottery' and did not suffer any significant consequences, because their transgression was relatively minor (stuff like correcting an invoice and sending it without properly sending a credit-invoice first to nullify the initial invoice).
Again, I'm way out of my depth here so by all means yell at me for being irresponsible about this :).
-How big is "probably? 5% chance? 0.01% Chance? -Maybe they will be lax on cookie policy slipups but not on purging delete requests from backups, how are we to know on May 26? -Maybe they will only investigate the big public giants, or maybe they will respect maliciously-intented complaints from competitors?
This is why, for example, Delaware is the chosen state for corporations -- case law is settled and has a very predictable legal frame work. In the absence of data, its hard to know WHERE people will get the hammer.
I did not see anything in GDPR which does not make sense to me, it looks like common sense applied to data management
versus
I get a feeling you haven't tried to actually properly implement the GDPR regs, talking to lawyers and everything
Which can be further shortened to:
common sense versus talking to lawyers
While interpretation of laws by necessity is at best difficult and at worst fraught with peril - reality in all its complexities is hard to catch in a few written pages - the legal profession has turned themselves into virtual toll collectors for anything related to law. Ask a lawyer about the legal implications of preparing a peanut butter sandwich and you'll be first presented with a legal disclaimer - pay me if you want advice - and then treated to a tale worthy of Lewis Carroll. GDPR is a $deity-send in this respect, good for many a year of steady income, especially given the stiff fines which threaten.
...which does not mean the person who used common sense to interpret the law is wrong. He is very much likely to be right and, having spent two weeks of technical work to prepare their infrastructure they're probably set to fulfil the obligations the law puts on them. It might need some fine-tuning here and there but that can mostly likely be handled as well without incurring the wrath of the courts.
In short, talking to a lawyer about being able to do something like this by yourself is more or less guaranteed to give the same reply as e.g. talking to someone who does data rescue whether you could replace the head stack on a hard drive by yourself. In both cases it is possible as long as you're careful and use the right tools, in both cases the answer will be 'you could do this at your own peril, disaster is waiting to strike, you take up enormous risks, let the professionals handle it'. Which is true to a certain level, there are risks just like there are risks in any venture.
Doesn’t seem to make a whole lot of sense.
Guys debating with you is a blast but if you keep downvoting all correct information because it doesn’t match your gut feelings you’ll just become even more of a circlejerk of what you already have here.
You are being downvoted because you are factually incorrect. IP addresses are only personal data if you can identify a natural person from them. You can't do so unless you've linked them to other information. Thus, by themselves IP addresses are not personal information.
Article 4: http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
> 1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Keyword indirectly. There’s plenty literature regarding ip and gdpr.
“The conclusion is that the GDPR does consider it as such. The logic behind this decision is relatively simple. The internet service provider (ISP) has a record of the temporary dynamic IP address and knows to whom it has been assigned. A website provider has a record of the web pages accessed by a dynamic IP address (but no other data that would lead to the identification of the person). If the two pieces information would be combined, the website provider could find the identity of the person behind a certain dynamic IP address.”
https://eugdprcompliant.com/personal-data/
And many others up and including the gdpr preamble
Please stop confusing the readers on the matter.
https://www.jdsupra.com/legalnews/ecj-confirms-dynamic-ip-ad...
In particular, if the website operator cannot legally access third party information that could be used to identify an IP address owner, or if access to such third party information is “practically impossible”, then the IP address is not personal data from that operator’s perspective.
There ya go. You sucker can keep downvoting facts as you wish, reality won’t care.
it's not like down voting these post changes the GDPR wording and definitions guys.
Here is another piece of GDPR PII:
9-5 Allée des 4 Vents 69160 Tassin-la-Demi-Lune, France
Random address I pulled from google maps of someone's house.
Who is 147.67.135.33?
Article 4:
http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
> 1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
https://privacylawblog.fieldfisher.com/2016/can-a-dynamic-ip...
https://www.jdsupra.com/legalnews/ecj-confirms-dynamic-ip-ad...
Etc. That’s what the european justice court said last time it was called to determine whether ip were personal information or not. What you gonna do now, downvote the proceedings?
> an internet service provider ("ISP") has a record of the temporary "dynamic IP address" assigned to a particular user's device (potentially identifiable data); and
Here they're not talking about "IP addresses", they're talking about "IP addresses assigned to particular users".
> In answering the BGH’s first question, the ECJ confirmed that dynamic IP addresses are considered personal data within the meaning of the Directive in circumstances where the data collector (e.g., a website operator) is likely or reasonably able to obtain information from a third party that would allow it to identify the user.
This clearly says that an IP address by itself is not personal information. It only becomes personal information when you can identify a natural person - when you link it with other data.
> reasonably able
it clearly states 'legal means' to identify the user. a subpoena is a perfectly reasonable and legal way to disclose an identity from an ip and doesn't require access to any other personal data, merely that such a link from ip to identity exists. the link is the "third party information to identify the user". it's not that you correlate an ip with a cookie or other technical means. you have to get out of the engineering mindset.
I think it’s good that EU tries to eradicate “let me steal and sell your secrets” business model that most SV startups are built on
Everybody in the business knows that big companies become targets.
Therefore for startups it's a land grab, aka break as many social rules as you can before getting big enough to get noticed.
Just to give an example — Google's AdX platform has been anonymizing IPs given to participating advertisers at least since 2013 when I interacted with them. They also tightly controlled what kind of content and JavaScript you could serve on participating websites. For example we were not allowed to set our own cookies and even loading ad content dynamically (via JS) was a problem. The smaller ad exchanges, like MoPub and below? They didn't give a fuck.
The most immoral companies around are the startups. The difference being that they don't have the resources or the reach of big companies. But that's no excuse.
---
On progressive taxation, that's simply a tax on productivity, plain and simple. The majority being made of people that earn minimal to medium wage and of socially assisted folks, it's simply a way to increase taxes without pissing off the electorate. And it's choking the middle class and the small businesses.
And that's because the big companies and the big earners have good lawyers and accountants that can come up with legal tax evasion schemes. The EU can't wait to fine the likes of Google and Facebook, as they've been evading a lot of taxes ;-)
NO THEY WON'T. This is just untrue. We've had decades of regulation - the regulators are not new - and so you can see how they work. They do not pursue everyone looking for easy cases. They go after the worst offenders, and they write letters asking them to come back into compliance.
There are also some relaxed rules in GDPR for SMEs also.