GDPR is a great example of the kinds of disasters that happen when nations try to force the entire planet to follow their unilateral actions.
GDPR is a great example of the kinds of disasters that happen when nations try to force the entire planet to follow their unilateral actions.
If a tribunal gets asked to delete the personal data of the accused, they will keep the data.
There is a principle of public interest and public obligations to keep data.
What part do you think that is a disaster?
uh... this post is about a guy losing his business because of the GDPR. What part of that isn't a disaster?
>If you are a bank and a client asks you to delete their data. The bank will still keep it for the tax agencies.
> If a tribunal gets asked to delete the personal data of the accused, they will keep the data.
> There is a principle of public interest and public obligations to keep data.
In other words, GDPR has no teeth outside of Europe.
Your example "my employer will have to delete records of firing me!" is exactly how the GDPR works.
There are exceptions -e .g. if the firing is now leading to a court case, but they are less than you think.
In an ironic twist, after deleting the data subject's personal information, you must be left with nothing that identifies them, so you don't even know that they have requested this in the past - only that someone exercised their right to erasure (not who).
The right to erasure does not apply if processing is necessary for one of the following reasons:
to exercise the right of freedom of expression and information;
to comply with a legal obligation;
for the performance of a task carried out in the public interest or in the exercise of official authority;
for archiving purposes in the public interest, scientific research historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing;
or for the establishment, exercise or defence of legal claims.
Article 17.1 The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; https://gdpr-info.eu/art-17-gdpr/
If you read further down the page, you come to the section you are quoting, 17.3, which says that the above right from 17.1 does not apply even if one of the conditions in 17.1 is met. However the scenario we are talking about is one where none of those conditions were met in the first place, so we never had to look at 17.3.
You can argue that 17.1.b/c would require an employer to remove any demographic/political data it had stored on you, but absolutely not that it requires the employer to remove the record of your existence at the company.
17.1.b appears to be the trump card held by the data subject. They can withdraw consent at any time and request erasure.
Once they do, the data controller can then use any of the exceptions in 17.3 to deny them. However none of these is "because I want to keep records of all firings".
My further understanding is that you certainly could keep a record that someone was fired, just not a record that included any personal information that could identify who that was.
i.e. pseudonymization..
(edit - and I think you could keep the information about their race/etc if it was properly pseudonymized, but I haven't tried working that out so I'm not sure).
In other words, GDPR has no teeth outside of Europe.
The GDPR applies to trying to do business in europe. Seems simple enough.
meaning you can be doing business with EU residents as a US only company.
I'm not quite sure how they intend to enforce the GDPR on foriegn companies, but they are making that claim.
This doesn't sound crazy to me.
If I'm in europe and I sell to an american, I have to adhere to certain US laws just the same. I have to fill in a W8-BEN form or whatnot.
I can elect not to, but next time I'm in the US, things might get awkward at customs. Also, my customers might be fined or more or less 'ordered' not to do business with me. That's within the US's right.
That's just how it works. Everywhere. For all countries.
GDPR (EU Law) requires companies to delete private data upon request.
SOX (US Law) requires companies do not delete private data, in case the government wants to investigate those companies later on.
SOX has existed since 2002. Did the EU lawmakers even consider this when crafting GDPR? I'm betting not, considering the damage they've done to the WHOIS system as well.
This kind of fallout is the result of poor planning and pushing incomplete legislation for political purposes and I think all of us realize that, so let's not pretend otherwise.
That is literally a disaster. I wonder if this kind of thing is why the EU is crumbling.
(Shrug) It's a public response to abuses by private actors. It's a great example of the kinds of disasters that happen when the user is the product and not the customer.
I disagree, I think it's a political move and won't have the kind of positive impact that we want it to.
GDPR, as it is written, should put Facebook and Google out of business. Invading people's privacy is a huge part of their revenue stream. I'm all in favor of protecting privacy of individuals but I'm cynical that we'll see any real progress as a result of this and the negative consequences are real, and possibly more significant than any positive effects. Time will tell.