If what you're doing could cause a problem I'm pretty sure I'd rather you didn't without the ability to deal with it.
If what you're doing could cause a problem I'm pretty sure I'd rather you didn't without the ability to deal with it.
Essentially, all you have to do is tell your users what data you are collecting and how you will use it.
Also, if a user asks for their data, you give it to them, and if a user asks for their data to be deleted, you delete it. I imagine if either of these things were to happen today, you would do as they wished GDPR or not.
It's not even remotely okay to use random people's blog posts as a compliance strategy.
> It's not even remotely okay to use random people's blog posts as a compliance strategy.
Then use the simple, human friendly guide from the body who will be enforcing it in the UK. I did. I thought it was simple.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
It takes 30 seconds to find out whether your identifier violates a trademark. Your content is trivially not a copyright violation if you created it yourself. Hobby projects are not debating the finer points of fair use and whether the conflicting name is for a sufficiently different kind of business to avoid confusion. But every HTTP server handles personal data, and a web-based tool with a database backend especially so, so all the subtlety of GDPR is in play.
But not all of them have a good reason to log it. /dev/null
How about asking and recording a persons birthday when really all you need to know is if they are the age of majority? A birthday is more information than needed which seems like a violation GDPR when interpreted strictly with my cursory knowledge. Seems unlikely though that any regulator would enforce such a distinction though.
> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:
there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual. [1]
So once the account info is deleted, that link is broken. This another piece of DP legislation that has been subject to a great deal of FUD since most of the headlines just went with ‘court confirms IP address are PII’ and omitted ‘in some cases’. TBH, this was already pretty explicitly obvious from the legislation defining Personally Identifiable Information (hint: clue’s in the name).
[1] https://www.whitecase.com/publications/alert/court-confirms-...
Makes sense.
Given the above still seems like a potential issue to not delete the ip logs.
1) Bob signs up for a service and is logged
2) Bob than asks for his account to be deleted. Account details are deleted, but the ip logs are retained.
3) Bob signs back up for a new account allowing the data processor to make the link from his new account to his ip old logs with the first account.
Weather the data processor can relink the two records with reasonable probability in step 3 depends on the particulars of the circumstance.
I assume cases like the above will be judged, at least in part, based on the data processor following best practices, and operating in good faith(not actively trying to unmask individuals and actively try to prevent unmasking).
Currently I would not let the GDPR stop me from going forward with any web services plans, however my casual reading of GDPR articles on HN and beyond have not made it obvious how cases like the above will be handled.
Nothing. Anything. This regulation assigns huge amounts of legal and financial risk to any hobbyist and will likely be selectively applied.