At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...
At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...
Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.
What this gives the EU is the hammer to hit persistent abusers of user data. They want you to be careful with user data and not treat it like you own it; you do not. It is not yours to sell or share or publicize.
Edit; note as well that every country has a compliance office; if they know you are in complaince as in you are ‘good people’ (best effort, no giant holes etc; just best practice in our field which you should do anyway) they will not bother you with every (or any) user complaint after that. I have good experiences with this with far grave (and potentially criminally punishable) matters in a few EU countries.
No its not as they now have regulations in place to prevent that, before GDPR you could. You can only be sued to the poor house from it if you do something like leave your patients health information on the bus.
The regulator is the effective judicial remedy.
In the UK there's also a First Tier Tribunal and probably an upper tribunal. These are when the regulator has made an error in law.
https://gdpr-info.eu/art-12-gdpr/
"The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests."
Regulators. "Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation".
So, 28 countries, each with 1+ organizations. So you could find yourself having to deal with multiple parties in different languages.
It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.
It's especially funny when small to medium German companies suddenly panic because of the GDPR and when you look at their situation all you can say is "yeah, you should have implemented that 15 years ago, it's already been German law that long".
In Germany not much will change, but at least companies like Facebook can no longer just move to another country with worse privacy laws (like Ireland) and call it a day. For us the GDPR means that protecting user data will no longer be a competitve disadvantage. But if you're a small company and handling data reasonably, the GDPR won't hurt you anyway.
Can you hint me to one of those German laws which do require one of the above?
It literally translates to "federal data protection law" and has been German law since 1978. In certain conditions it has also mandated a DPO (https://de.wikipedia.org/wiki/Datenschutzbeauftragter) since then, but in fact the first DPO position in Germany was created in 1971.
The right to be forgotten is mandated by article 35 BDSG (https://www.gesetze-im-internet.de/bdsg_1990/__35.html).
The right to a data export is mandated by article 34 BDSG (https://www.gesetze-im-internet.de/bdsg_1990/__34.html). It has always been common use this law to get a free copy of the data which our credit reporting agencies have about you, I've done that multiple times.
However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that.
How does that work for people who never had a Schufa history? If for instance I decided to move today from Brazil to Germany, would I be unable to do all these things there, since they would have "no data available" on me?
Any business that is shut down by GDPR is, to me, a good business to shut down.
Compliance. It doesn't matter if you delete your logs, if you had them in the first place you're subject to compliance.
Like the example in the article. Not sure why people are still thinking this doesn't happen, this is exactly what is happening in the article.
You're required to have a fire safety officer at these companies too, but it's not a full-time position.
AFAIK, most of the "safety committee" regulations usually have waivers for small companies.
I’m fairly left leaning for a US citizen & find the idea that the default should be big companies abhorrent.
But I recognize my bias & am not st all convinced it’s in any way objectively correct.
I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.
Nonsense. I look at another high tech data driven start-up every week and not a single one has stated that the GDPR costs are 'prohibitively high'. Sure, there are some that need to do more work than others (medical, ad tech). But on the whole companies that were already doing their best to not fuck up with their customers data have very little to do in order to get to where they should be and the remainder has a bit more work but will mostly likely be more-or-less compliant by the 25th and what work remains will be done long before the eye of Sauron will turn their way by virtue of their size.
The cost is strongly related to the size of the organization and the amount of sensitive data you hold as well as whether or not you were a bad steward of the data in the past.
There is a correlation between the number of GB you store and eg. how many DPOs you require?
A small business or a startup should have a relatively limited amount of data capture, and that data should be stored in a relatively limited number of places. In most cases, it should be straightforward to make sure that this is documented and appropriate controls are in place.
On the other hand, large companies have vast quantities of uncontrolled data gathering that nobody is responsible for.
If I want to put an open source app in the App Store, that’s not a business model for me. It’s more just personal expression.
Try convincing a regulator of that.
But it doesn't matter, you're still logging PII. GDPR doesn't make any distinction of profit vs. non-profit vs. personal ownership. You're as liable as an individual as an organization.
And then the next would be that it's inexpensive to "make your case" if you get reported.
Please, don't take my words as granted but talk to an actual lawyer. You'll probably even find a free session for startups somewhere in your city, at least in Europe.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
https://ico.org.uk/global/contact-us/advice-service-for-smal...
What hav the Danish & Belgian regulators been doing lately?
The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.
http://blog.quantum.com/backup-administrators-the-1-advice-t...
"The GDPR is open to interpretation, so we asked an EU Member State supervisory authority (CNIL in France) for clarification. CNIL confirmed that you’ll have one month to answer to a removal request, and that you don’t need to delete a backup set in order to remove an individual from it. Organizations will have to clearly explain to the data subject (using clear and plain language) that his or her personal data has been removed from production systems, but a backup copy may remain, but will expire after a certain amount of time (indicate the retention time in your communication with the data subject). Backups should only be used for restoring a technical environment, and data subject personal data should not be processed again after restore (and deleted again)."
Other opinions have concluded that you must keep an index of requested deletes in the face of backups, for instance.
Article 63 of the GDPR specifically covers consistency of enforcement across the regulatory agencies.
You keep daily backups for 1 week, and after one week the users data is gone from all backups.
The only possible window for restoring deleted user data is the time window from deletion to backup. To "solve" this you need to make more backups, ideally live backup and replication with really frequent snapshotting. And this is something you would want even without the new law, because you don't want to lose user data in case of a server failure. Why would you restore from an old backup? (And if you really need to restore from an old backup you most likely want to merge this backup with the newest one to reduce data loss. In this case you can reapply all deletes.)
The new laws don't change anything. For me at least. Also my lawyer is totally fine with "only" minimizing the problematic time window. We both know that it will never be zero.
You just can not keep backups of everything for the purpose of everything.
My example can not include all cases and was written in the spirit of "we are a bunch of devs with a small project". As is monal.im .
You can still log accesses and aggregate them into statistics, just don't keep the IP addresses. You can still log IP addresses to detect DOS attacks or whatever, just delete the log when you don't need it anymore, after a day or so. There's no need to get backups from glacier, because you know there is no personal data in them.
You do need to have a documented and implemented backup retention policy and communicate this if you receive a request to delete a user's data.
Invoices for VAT MOSS have to be archived for ten years. And until today nobody really knows (it is another EU law disaster) which information you have to keep to prove the origin of your customer.
Do you invoice for a different country than the recipients country? Why?
> the information used to determine the place where the customer is established or has their permanent address or usually resides.
Sadly this regulation doesn't specify which kind of information this could be.
Your customer could try to get a better price by pretending to be from a country without VAT. Therefore the address given by the customer is more or less worthless in this regards. One more realistic information is the IP address. But as this also is pretty easy to spoof it might be reasonable to also keep information about the country were the cc card was issued, if possible.
Database backups are only a problem if you save them forever, though it sounds like you are. GDPR generally requires that you regularly archive, rotate out, and clean up old data.
> Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address.
Emphasis mine.
I said:
> IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.
- the ip addresses never uniquely identify someone or
- you have a legitimate interest to collecting this data.
Neither provides carte blanche for collecting IP address.
If you have "other ways to identify somebody based on an IP address" then that wouldn't meet the criteria laid out by the lawyers.
You might be thinking of this pseudonymization stuff. My advice is not to play with it. Just delete your logs after a month unless you have a demonstrable and immediate security need for them.
That came from the legal departments from our German, UK, and French entities.
> Purpose of security doesn't change if its PII or not.
Security is the legitimate interest, an important part of collection under GDPR.
If you're too worried about this, remove the last octet from the IP or and/or it with a mask. And especially don't associate the IP with the user (by default you can't find out who's the user only by IP).
https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...
If owned or controlled by big-co in an non arms length manner, then it wont be considered a 'small company' in terms of the GDPR.
Edit: These corporate control laws have teeth, otherwise every small & large business owner would do something similar by making all of their corps 'offshore' in some zero tax jurisdiction and pay 0 tax locally except for business done actually in the territory itself.
Or the could be completely legitimate small businesses doing this device for anyone.
It's not 0, but large corps already do this. https://en.m.wikipedia.org/wiki/Double_Irish_arrangement
Can my small company be trivially bankrupted by any sociopathic gamer skid with an EU address and a grudge when DDOS attacks fail?
"You can beat the rap but you can't beat the ride."
Your dude with a grudge can only lodge a complaint with the relevant regulatory entity, they're the ones who will verify whether you complied or not with his GDRP requests and if they deem that you are in violation fine you after negotiation fails.
This isn't the US: you can't be sued by random people for anything.
(1)A random person complain to his regulator that you are not complying with GDPR. If he asked for his personal data, jump to (3)
(2) His regulator contact you, tells you that wht you're doing is bad: you have some stuff in opt-out, not clicking "opt-in" cause a degradation of service, or you are sending him 3rd party cookies he did not accept.
(3) Depending on the complexity and your ressources, you have X months to comply.
(4) You got caught again, you are fined.
Assuming you are American, the only court you need to worry about is American court. Your company is American? Your bank is American?
What's the actual liability here? Worst case?
There is no misconception on GDPR: the idea is good, the implementation is horrible and retarded and it is lead by people who do not understand a single thing about technology.
1. Enforcement is not arbitrary, but like all regulation the goal is compliance rather than punishment.
2. The idea is good, and the implementation is widely regarded as good by anybody familiar with data protection regulation.
3. Most of the panic seems to be from woefully misinformed US tech companies.
Also, i think the DPAs can fine any company in the EU, not just the companies of the country the DPA is in.
It would be entirely possible for someone to not be compliant with a side project and get fined 20M because there is nothing that explicitly forbids this it is entirely up to interpretation.
Given that US companies have already been targeted in the EU, unfairly [1], I find that law terrifying because I have to trust regulators that don’t have my best interests in mind with possible penalties that are very high.
[1] https://www.treasury.gov/resource-center/tax-policy/treaties...
Anyway, how should the ICO be able to be more concrete then the GDPR?
Article 83 states that any penalties must be proportionate to the nature, gravity and duration of the infringement, the intentional or negligent character of the infringement, action taken to prevent or mitigate an infringement and the degree of cooperation with the supervisory authority.
However, this cases will be fought with the Googles & Facebooks, not with 5 person companies.
Why haven‘t all those doomsayers closed down their businesses long before the GDPR?
There are varying degrees to which people see laws as affecting them. Small business tech owners, when a law says they have work to do, are going to feel affected. If there was a securities or accounting law that felt similarly overreaching one could expect a similar reaction. This is especially true if there is an alternative (locking out markets) that is easier. It's not helpful to try and compare the situations. It's also not fair to consider people weighing the costs of these laws as doomsayers. They aren't closing down their business, they're just restricting it to more business-friendly environments in their view.
People in other parts of the world have gotten used to that. As a current example, see US threats re: European business with Iran.
Even if the GDPR were overreaching (and I vigorously dispute that notion), it would simply be a taste of America‘s own medicine.
I was just pointing out, that when a lawyer says "probably", he usually has a good reason to do so. And it's my strong belief that the reference cases in court will not be fought by small companies, because they rarely are.. There is just not enough money to make fit the effort you need to put in winning the first case. Before there is not one single case, I don't think it's necessary to panic and shut everyone out.
You don't need to believe me or agree with me, but reducing this to "my personal appetite for risk" is really weird.
Maybe you have huge assumptions that people reading what you say will add all kinds of limitations to what you say? I don't. It leads to terrible discussions, like this one.
Regarding the personal risk comment, I could've been more clear: From what I got, no lawyer can give you a guarantee at the moment, that what he says is actually what will happen. So in the end you'll have to take action based on recommendations, and take a risk - or, as the op, shut out all European users completely. My personal risk is continuing to do business in the EU, even with this uncertainty. You couldn't have guessed all that from my earlier comment, so I agree it was bad..
I'll try to do better.
That rather makes the anti GDPR arguement sound like "yes I know that is the law, but I was breaking it over the internet so that doesn't count"
You could be breaking the law in any number of countries. What steps are you taking to comply with the laws of Saudi Arabia or North Korea?
Not the courts, but "Brexit"
The EU on the other hand...
Also almost all laws stay in one jurisdiction, they don't go beyond their own country.
What if you don't want to deal with any of that. You can no longer just create some useful, free service and make it public.Heck, I don't even like having to be familiar with software licensing just to add something in Github.
What if you don't want to deal with the rules of the road?
"protecting people's rights is expensive, therefore we shouldn't do it".
That's your argument? Really?
Then the law should say that. For instance when India implemented uniform goods and services tax processes, it explicitly excluded businesses below a certain revenue threshold and gave them a simple % of gross alternative to all the processes. GDPR doesn't make any such distinction, so such decisions to drop EU support are to be expected.
Sure, but that's not actually written anywhere.
Well that's a disappointment.
So you can profile without consent IFF you can convincingly justify said profiling via one of the other lawful bases. But those won't really let you do blanket profiling willy-nilly either and come with other strings attached.
One really can. It took me all of a few seconds to shrug of the GDPR when I first heard of it. Then, with all the scare mongering (webserver logs will be illegal!), I spent a few minutes reading up on it. It's all more than reasonable: if you're not doing anything shady, or are being negligent bordering on incompetent, you can just shrug it off and sleep soundly.
The monetary and time cost is minimal, but the mental benefit is pretty damn good.
Frankly this post has prompted me to reevaluate your other legal advice in this thread.
He did this several times before the corporate veil was pierced and they took him for all he had.
The other case was one that is probably best described as mismanagement ('onbehoorlijk bestuur') where the CEO/sole shareholder of a company started using the corporate account as though it was his personal account. When the company was unable to meet payroll taxes the taxman seized his private assets after piercing the veil.