Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
It doesn't matter if European law has a history of being "principle based", if it can fuck you then someday it just might. Europeans might be fine with this, but I think most Americans would not be. If I was in OP's position I would do the same thing, by simply blocking an IP range all possibility of being made an example of by some people from another continent is flushed down the drain. I'm absolutely baffled why people think this is absurd, if you're not even making any income off of it, why would you ever open yourself up to such expensive potential liability?
I will leave the reader to make their own jokes.
"(...) including for the processing of special categories of personal data (‘sensitive data’)", special categories are mentioned on Article 9. "(...) personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation"
Do you store or transfer or process any of that data on a large scale? Is it personally identifiable? "Processing" is defined on Article 4.
I believe the original legal text, though not the easiest to read, gives you a fairly clear idea on where your organization or project should stand with respect to GDPR.
(1) What data do you process? (2) How is it connected to your economic activity? (3) How do users consent this use of the data? (4) Is your data "sensitive data"?
If you're some random guy online doing large scale processing of "sensitive data" you better hire a law firm with GDPR expertise to understand and comply with the law, I mean, that's the whole point.
(1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or ....
Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, ...
I would say that messages send via IM are personal data like described in Article 9. I also would check the "large scale" checkbox. So in my interpretation he will need a DPO.
He has no data of the kind described in Article 9.
That seems a very pejorative way to describe it. You can say the same thing in terms of "you could probably keep operating if you put a lot of effort into understanding the details of the law" which kind of proves the author's point: this creates work for people and why should someone do that work for no return? Where does the presumption that people owe EU citizens these services at a higher standard than the rest of the world is content (legally) to accept?