GDPR Hysteria Part II, Nuts and Bolts, Actionable Advice
jacquesmattheij.com
jacquesmattheij.com
Google has made some big changes in how they deal with third parties in the advertising chain.[1][2] Third party trackers are being cut off, and advertisers are being encouraged to dump them and switch to Google Ads DataHub.
Google is frantically trying to get user consent for tracking, popping up a deceptive message on every Google search result page. That popup asks you to "log in" to Google. They just assume everyone has a Google account. Without that permission, Google can only serve you "non-personalized ads".
[1] http://www.thedrum.com/news/2018/05/01/publishers-hit-out-go... [2] https://adexchanger.com/platforms/google-sharply-limits-doub...
I think it is also an opportunity though, we might be able to roll back some of the more annoying ad-tech and get users to selectively switch off ad blockers again.
Another option is that more parties will switch to advertising space sold directly to media buyers without all those intermediaries (much like it used to be until we started to track everything and anything).
Once you are logged in to Google you can turn off the targeting of the ads through this link:
https://adssettings.google.com/authenticated
Slide the slider at the top right of the page to the left and confirm the change, targeted ads gone. This takes about 10 seconds or so if you are already logged in to Google.
We remember the internet before targeted ads came. 100 flashy and gif banners on the page. Websites still need to make money, they'll just increase the ad spots if the ads are not profitable enough.
That's why there is such an explosion of ad-tech firms, anything to get back to where they were last year in terms of CTR and engagement. Then the users become de-sentisized and then the whole cycle restarts.
I also think you will see some acquisitions of crappy publishers with lots of pageviews so that advertisers can get an end-user touch point.
If you aren't selling user's data, you keep it reasonably secure, and they can delete their account, you are probably good. Most of the services you use will already be GDPR (and Privacy Shield) compliant, and it is easy to list your cloud and payment providers and link to their statements of compliance.
And almost everything a user could ask for, if you don't have an automated solution to, you can generally comply with by checking your email and responding accordingly, so for small userbases, this is hardly really even an issue.
Furthermore, as far as actual enforcement goes, the EU is not going to shut you down or put you out of business on a technicality. They are going to take you out if you show flagrant disregard for your users. This is going to hit the Unroll.me's of the world, not your average web forum.
Even if your business is nothing like selling user data -- say you're Dropbox, or Box, or Microsoft, or similar -- your sales and marketing org is going to get walloped by the GDPR. How do you run a compliant cold outbound process? The EU has largely declined to tell people.
Perhaps that question itself illustrates the moral ambiguity of cold-calling?
If you rely on a marketing service that depends on buying personal information without the subject's knowledge, in order to catch people by surprise, then perhaps GDPR is doing its job by making that difficult.
Analogy: tax laws take money from me but the EU doesn't give me any hints on tax avoidance schemes
A dutch proverb says 'high trees catch a lot of wind', if you're a high tree you ensure the wind is not aimed at you unless you explicitly want it that way. At their level there are precious few excuses about lack of resources.
I am curious when people mention this: Who literally sells user's data ?
- Level 1: Monetizing aggregates. Aggregating lots and lots of data, running statistics on all of it, and selling the outcome. Example: An online streaming site that sells TV analytics to TV channels.
- Level 2: Selling proxied access. That's the Twitter/Facebook/Google ads model: Allow interested parties (advertisers) access to an audience, but they never are directly told "Mary Jane is a 33 year old woman with 2 children and an income of $80000/year."
- Level 3: Selling personal data. This is what people think is happening in level 2, but is much rarer than it sounds. For example, let's say you have influencers on your site, you'll sell to potential sponsors data about that influencer. Or sites with personal statistics and insights that will sell access to it to their users' competitions (a known practice in sports services).
- Level 4: Selling confidential data. That's where we're talking the really shady/illegal stuff. Gathering emails/credit cards and selling them to spammers and fraudsters, that sort of stuff.
https://www.iab.com/guidelines/real-time-bidding-rtb-project...
Other avenues of interest: location based advertising and programmatic adaptive advertising.
Some even claim to be GDPR compliant. It will be very interesting to see how that turns out. Personally I wouldn't mind if the whole business segment was burnt down by the regulators.
Isn't the uncertainty part of the problem?
> What’s important with any law is - besides the letter of the law - what the spirit of the law is, the laws intent.
This very conveniently forget the GDPR will not be interpreted by a single authority in Brussels but rather by the relevant authority in every single EU country. Whatever the lawmakers intended, who gives a hoot? I can pretty much guarantee the Hungarian NAIH will see this as a fantastic cash grab opportunity. (I am a dual Canadian-Hungarian citizen, I know my birth country all too well.)
Despite all this "pah-pah, it'll all be fine" there is not even a guidance much less any law describing who shall be fined for how much. Spirit of the law protecting you from Hungarian bureaucracy , good luck Chuck. The courts will eventually curb this madness and set some best practices but meanwhile those who got fined excessively will stay bankrupt. Don't be the patsy. At this time, unless you are a big enough company to have a sizable legal department do not do business with the EU. This is not hysteria, this is just good business sense.
If you don't believe that's how it will work that's entirely fine with me but about 30 years of data confirm my point of view.
The entire spirit of these articles are completely misguided because the adverse reaction to GDPR is not hysteria. Here's the unique nature of this which makes it a recipe for disaster:
1. Every business interacting practically any way with European citizens is affected
2. The potential fees for breaching a very complex regulation are unprecedentedly high.
3. Determining the actual fees for each breach is in the hand of every EU country, including some which today wouldn't be admitted into the EU.
People were genuinely surprised when the world didn't end. This is going to be just like that. May 25th the world will continue to turn and none of these bogeyman stories will come to pass with anything approaching fidelity.
Regulators will target the worst excesses to show they mean business and are severely limited in manpower anyway so the vast majority of interaction that has to do with the GDPR will amount to a change in mindset and some best practices. In edge cases things will get a bit more interesting (someone mentioned federated services and that's a really good question).
FWIW I've been looking at companies from the GDPR angle for about a year and a half now, we slowly ratcheted up the push for compliance and it is interesting to see how (EU based) start-ups have adapted to the new legislation. We have also found some companies that were ill prepared but that's to be expected.
The worst position to be in is a small (10...20FTE) company operating in the US running a SaaS that stores critical information. That's an expensive affair. For most other companies - including the really large ones - the impact will be mostly a one-time investment in software and inventory of data and processes. After that they will be in much better shape and that's a good thing.
Companies that make a business of selling data are expected to be hit hard, and rightly so.
Your confidence scares me. What about this, I have the same amount of evidence you have: Some regulators will target the weakest. It's really easy to slap a few tens of thousand of euros fine on a small business. Sure, fining a big company for many tens, hundreds of millions makes news but a few ten thousands is a good income.
Do you have any evidence for this?
I have plenty of evidence for the opposite, if you want I will collect it.
Here is one sample dataset, NL:
https://www.computable.nl/artikel/nieuws/overheid/6345059/25...
No fines in all of 2017, in spite of 10,009 data leaks that were reported.
In one case there was a settlement of 48K, but it is not quite clear what the circumstances were, probably to protect the guilty.
"De AP stelt in een samenvatting van het jaarverslag 2017 dat het niet altijd direct een onderzoek start. Het gaat eerst in gesprek met partijen die een overtreding begaan en in veel gevallen leiden die zogenoemde alternatieve interventies niet tot een officieel onderzoek."
Rough translation:
"The Authority says in the summary of their annual report for 2017 that it does not always immediately starts an investigation. It first tries to talk to the parties that have violated the law and in many cases these so called alternative interventions do not lead to an official inquiry."
I don't really understand your tax authority example though, doesn't that mean the payments are late and that the tax authority is fully with in their right to take what's theirs?
Did they take more than was their due?
Let's hope that kind of behavior won't be the norm. But I wish the Hungarian Data Protection Authority much good luck trying such tactics against other EU companies, it will most likely not play out how they think it will.
I recall a case of the Irish tax authority trying to fine EU companies for failure to pay VAT, that blew up pretty badly for them, and in the end it turned out they themselves had fucked up. Since then they've been well behaved.
I've tried to find a citation for that particular case but can't find it. I own one of the companies that got fined.
All the ideals of user control and data portability are there and central to the Diaspora project; but technically, the underlying protocol involves passing users' posts and comments from one server to another. This seems like it would fall afoul of guidelines against passing data to third parties, and the same technical constraint seems to be fundamental to other federated services like Friendica[3] and Mastodon[4]. I'm really curious how the GDPR would affect services like this, especially as someone who's quit Facebook and is looking at decentralized networks as an alternative.
[1] https://diasporafoundation.org [2] https://diaspora.github.io/diaspora_federation/ [3] https://friendi.ca [4] https://joinmastodon.org
From the top of my head it would require the software to implement the various GDPR principles, and it would be wise for operators of servers to verify that they are not exposed. Better yet if EU residents connect to EU servers and let the federation take care of the connections across legal boundaries. That's smart for a variety of non-GDPR related reasons too.
Anyone know what counts as "occasional"?
Also, the regulation says the representative must be in one of the member states where the data subjects are located. I know of some non-EU businesses that have just a handful of customers in the EU, scattered among a few member states. They slowly get new customers, and slowly lose old customers. Whatever member state they put their representative in, there is a decent chance that in a year or two all the customers in that member state will be gone. Do they have to keep changing representatives?
As for the whole designated representative thing I'm looking at solving that in a somewhat creative way, but this will take some time and preparation.
On the other hand, I look at Article 3, and I'm not sure posting content on a personal blog counts as offering goods and services. Or do blog comments count as a service?
https://gdpr-info.eu/recitals/no-18/
> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
Under the GDPR that would be PII and so the removal requests would arrive, whether or not the legal bar was met. I'd rather not have to argue in court whether or not my blog was purely personal even though I run it under my own name.
So even for a blog if you allow people to comment calculate in that they will ask for some of those comments to be removed. It's a relatively small burden because it won't happen often (with all the millions of Geocities sites it only happened a few thousand times over a decade), and it will stop people from complaining to the regulators. Better yet: monitor your comments and approve them selectively, if you drop the obvious dumb ones there is a fair chance that you'll never have a removal request.
That leaves people like me (and you, apparently), I solve the problem in the simplest way: no logs, no analytics, no comments on my site.
I'll be curious to see whether GDPR results in a web with fewer features, or maybe features that don't work as well. I tried DuckDuckGo, for example, but I dropped it quickly because Google's results are so much better. I actually like that it takes my previous searches into consideration.
Convenience and privacy will always be at odds. If the largest excesses are taken care of then this will already have been worth it.
”Whereas the mere accessibility of [your] website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that [you] envisages offering goods or services to data subjects in the Union.”
In English:
Do not translate your site to EU-only languages (Italian, German, etc.), use an EU based domain extension, or create content or services that would be especially appealing to EU users, and GDPR will not apply to you.
People's opinions on this regulation differ so dramatically that even when I read something in it that sounds pretty clear, I second-guess myself and worry that the courts will side with the worst-case interpretations.
No.
> I've been debating with myself whether I need to move my content somewhere like wordpress.com to avoid that requirement.
The biggest issue would be your log files, I've covered that in comments here, and in the articles as well. Another issue could be if you run analytics tags or advertising, which may impact you in a negative way financially in the case of advertising. My own blog is analytics and advertising free, I don't see it as a source of income so I don't care but obviously that will not hold for everybody.
The critical part is when you start to ask users to enter data into your system, as long as you don't do that you will be able to solve this in a straightforward way.
> The personal information I process comes from comments and web server logs, and I'm not sure that counts as occasional.
You are right that it isn't occasional. So, logs: analyze them, then delete them within 30 days or so. That should be enough to do most security related work with the logs as well as any analysis you care for.
Comments on your blog you will simply have to delete when the commenter asks for it. Even when I ran reocities.com this was the most requested support item, and it is pretty easy to do in an automatic fashion if you still have the original relationship between an account and the comments, this could be entirely self-service. I expect the typical blog engine plug ins to become GDPR compliant in the near future because lots of people will be asking for this.
> Or do blog comments count as a service?
Yes, it is a service. You operate a server which takes in data and records it. That it isn't commercial is not important in this case, data subjects will create accounts and there will be PII associated with those accounts, either directly or in the comments.
Now for some arguably bad advice (from a legal perspective, but it is very practical): I'd take 30 days to see how this all shakes out past may 25 before taking action on something as insignificant as a blog. That way you will have a lot more information to base your decision on. Obviously that has a risk: you will probably not be in compliance but I'm going on the assumption that regulators will have a lot more on their plate than your blog for the foreseeable future.
WordPress does have some plugins for complying with GDPR, so I'm going to try one of those to see what else needs to change, in those developers' opinion. If only there were such a thing as certification so I could trust anyone was doing more than guessing!
Anyway, thanks for your feedback. I appreciated your article.
There may be an alternative though, working on that :)
It's the armchair lawyers doing sneaky stuff that they will try to continue to do that should be worried here.
I think it's important to cite precise examples.
If we're asking developers of small websites to give up a significant amount of their time to be compliant, we have to be rock solid into the why it is a good regulation. For example, most of the recent privacy violations in the news - FB leaks, Snowden leaks, etc. - seems untouched by GDPR.
GDPR feels like the opposite of Y2K. Unheard of by most until very shortly before the deadline, underplayed by those who haven't researched it, and overplayed by many of those who have.
Now, though I'm wondering about the discussion e-mail lists we have and if we need to auto-prune archives. They have folks' real names and such in them, after all, from participating in discussion.
(I also wonder how this affects big email lists, e.g. linux-kernel)
As far as deleting old member records and public archives, it depends on what consent members have given before. Membership information, especially receipts for subscription must be kept usually for 10 years for bookkeeping purposes. As for public posts, unless the members withdraw their consent (Excercise Right to be Forgotton) i don't see why. They knew then that the posts are public?
edit: you must formalize this with a privacy policy though, what data you keep, what type of consent (article 6) and for what reason you need it, if you haven't done so yet. Then ask every member for approval of the policy.
The lists are not public, but only visible within the organization. I think part of my concern is not knowing how easy it would be to rip a given set of messages out of the archive in Mailman. I don't expect it is likely Right to be Forgotten will be exercised, but it sounds to be a bear if it does get exercised.
If that’s true, then the recommendation about backup in the article doesn’t work (you can’t store PII on offline backup media in the basement and not comply with erasing the data there too on request).
It also means that deletion requests can’t easily be automated. Chasing down records on archive media is likely going to involve physical labor. It’s even the case that for write-only media it’s impossible to delete, you’d have to re-write a backup without the offending data.
All this of course suggests this isn’t the case, that offline data must be out of scope. But why isn’t this clearer?
As for backups, I am going on the assumption that they are properly encrypted, I will update the article to that effect.
> The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
> the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
> the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
> the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
> the personal data have been unlawfully processed;
> the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
> the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).
I think this means your backups are ok, unless the data was for a child under the age of 16. But I also think that if you have encrypted your backups, and you make robust attempts to remove the <16 year old's data when you restore the backup, that the regulators are going to be satisfied.
For example in this article it is assumed that everyone needs a data protection officer - the only question is whether you want someone full-time, or you want to share one with several other companies. However when I read https://gdpr-info.eu/art-37-gdpr/ it seems that most companies don't fall under 1.a or 1.c.
The question mark is 1.b, the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale. If you're just recording transactions, clearly you are not monitoring them. If you're running a data broker, clearly you are monitoring them. If you're running queries against your transactional data to decide who to send a marketing email to..is that monitoring? "Find all people who put something into a cart yesterday and then didn't complete the transaction." I don't think of that query as monitoring, but I can see how someone else might.
Multiply that by the number of EU countries.
A lot of the fear in this thread seems to be from people reading EU law through US filters.
No, my fear is from reading the EU law with an experience based Hungarian filter.
Can you explain why you think that it does? With reference to where in the legislation it says it, and why you concluded that?
The designated representative however is another matter.
The specific part in the law that triggers this requirement is that almost every e-commerce site qualifies size wise ('the numbers of data subjects involved') and technology wise (analytics, A/B testing, funnels and recommendation systems).
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Would be a good document to review.
If the numbers are low (100's), there is no tracking, no recommendation systems and no analytics then you are right, in that case you do not need a DPO, but even then I would still assign the role since it is free.
Also I do not believe that the DPO is actually a free position to fill. If you read https://gdpr-info.eu/art-38-gdpr/ in section 6 there is the requirement that the DPO should not have a conflict of interest. If you're both the DPO and the person who is being asked to sell data, that's a conflict of interest. Even if you're the sole proprietor.
If I thought I needed one, I would hire one. Even as a part time contractor. It is safer.
I agree that the law is quite explicit that such conflicts of interest are to be avoided. But there is a lot of precedent for this situation with respect to compliance officers. A very small company that is audited for compliance with some standard will be looked at with a different level of strictness when it comes to separation of duties. This is simply a fact of life, when a company is small some conflicts of interest and some overlap between roles is unavoidable.
Given that this situation is a common one and given that regulators are not going to put a substantial chunk of Europe's SME's out of business (because that is not in their interest) I expect this to be dealt with in a reasonable way.
Something similar happened with VAT regulation: The EU decided to go after service companies selling into the EU and 'shopping' for the best VAT deal causing loss of income for the various governments (VAT is not harmonized in the EU). Initially this was a huge burden for small companies because they had to - on paper - file VAT in every EU country where they had customers and they could be audited by all of those entities. That was unworkable for small companies. So they came up with VAT-MOSS and it works very well (I've used it for a year or two).
Really? I haven't heard of people who have vastly different opinions in what specific pieces of GDPR means. Do you have any links?
> For example in this article it is assumed that everyone needs a data protection officer
What? Where is that assumed? The first thing it talks about are the reasons you may need one and nothing about assuming everyone needs one.
You will see that the only two options that he discusses are having a dedicated Data Protection Officer versus a designated Data Protection Officer. With the difference being whether they are your full time employee doing nothing else, versus a part time responsibility.
Neither in the article nor in his comments here does he admit the possibility that it might be a role that you don't actually need filled.
I replied to your other comment in this thread, and I will update the article.
check reddit.com/r/gdpr. Every other question has been answered with both a yes and a no.
I run a Pi-Hole [0] to redirect all advertising-related queries to a black hole. When tracking the most-blocked domains, Microsoft is at the very top [1].
For instance, when I enter "Office" into the start menu, Microsoft immediately sends a ping to bing.com and Microsoft's telemetry servers. That is, Microsoft is sending all of the data entered into the start menu to Microsoft's servers, even when using the 'Pro' version and with 'full' telemtry off.
When it was first detected that Microsoft was adding telemetry calls to all compiled programs in Windows [2], Microsoft said it was mostly for event debugging for programmers. Now I'm not so sure -- look at your Microsoft account privacy settings to see that Microsoft tracks when you open applications. (They say on the page that not all data is shown there).
Unforutnately, there is no way to opt out of this. You can "disable" full telemetry, but you still have to opt into "Basic" telemetry, which still sends your advertiser ID, the programs you run, and the queries you put into the start menu. I'm concerned that Microsoft is not going to stop here. They have a real incentive to capture as much data about you as they can -- they currently earn about $1 billion in advertising through Bing.com search queries. Unlike Google or especially Facebook, however, it's much more difficult to opt out of Microsoft's tracking -- so many people depend on Microsoft Office or other Windows programs that I can't fully switch to Linux.
I don't know how this is acceptable through GDPR. There are so many problems with what Microsoft is doing:
1. There is no way to opt out of telemetry
2. There is no way to see all of the data that Microsoft has collected
3. Microsoft has severe lock-in because so much software is written for Windows-only
4. Microsoft has an incentive to increase their telemetry, not decrease it.
[1] https://imgur.com/a/MbjtYJe
[2] https://old.reddit.com/r/cpp/comments/4ibauu/visual_studio_a...
I've long suspected this but couldn't prove it. Aside from the privacy implications I've found it makes windows unsable. Basic operations can take several seconds and if you're on an intermittent connection (which developers never test on) the menu can be frozen for over a minute.
> however, it's much more difficult to opt out of Microsoft's tracking -- so many people depend on Microsoft Office or other Windows programs that I can't fully switch to Linux.
This comes up a lot but I think we need to change how we think about it. Yes there will be pain and yes there will be things you could do before but can no longer do, but we need to treat it like ripping off a bandaid and embrace the pain rather than hope to mitigate it.
PECR is the implementation of http://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:320... which is European law.
There are a number of regulatory actions available to eg ICO if companies are violating PECR.
https://ico.org.uk/about-the-ico/what-we-do/taking-action-pr...
> There are a number of tools available to the Information Commissioner’s Office for taking action to change the behaviour of anyone who breaches the Privacy and Electronic Communications Regulations (PECR). They include criminal prosecution, non-criminal enforcement and audit. The Information Commissioner also has the power to serve a monetary penalty notice imposing a fine of up to £500,000.
> These powers are not mutually exclusive. We will use them in combination where justified by the circumstances.
I'd agree that the lack of enforcement of PECR certainly makes it feel like just a suggestion.
If it's not enforced, then what was its point?
I think it's best to think of the GDPR as its replacement, rather than thinking of them side by side, to be honest.
Wired getting something wrong is... believable.
As an EU citizen, I'd like to know what or whom I should direct my ire towards.
There are some instances where it may make sense to have a very long log history but I'd be careful to properly document the need for that unless that need is an obvious one and easily explained. Anything longer than a year would be outright wrong and anything shorter than 30 days will definitely be ok.
I wonder if that make the ETH and BTC blockchains illegal to have nodes in Europe from now on. Like if I post a series of transactions that are linked to me, can I ask all the EU nodes to remove this information?
EDIT: take a look at that slide, google invested 40 human years for assessment alone https://twitter.com/winfriedveil/status/995951301132537857?s...
As an end-user/customer, I’ll have the regulated version every single time, thank you.
You can reframe this either way you like, but what it will come down to is that IT has so far been one of the few completely unregulated industries, with only its own merits to show for why such regulation shouldn’t be needed. So far it’s not doing a very good case for itself.
People like Alan Kay has warned about this. If we don’t start taking our profession seriously (like doctors take not killing their patients seriously), someone else will. And then the future of programming will be legislated.
If that’s how it all will turn out, that’s because we as a industry has deserved it.
The GDPR is merely about basic decency and should only be considered a taste of what the future holds. Unless we ourselves show that we can act responsibly without further regulation.
Edit: Ofcourse if you are the world’s biggest privacy-violater with 100s of thousands of employees worldwide working every day to mine and AI even more shit out of you, ofcourse trying to get GDPR-compliant will take some effort. That’s the whole fucking point.
Smaller businesses treating user-data decently and with respect won’t have any such issues or conflicts of interests.
"Oops, did that airport take three times the money compared to expectations to build? Time to pony up more or end up with a half built airport".
I'm obviously biased because I work for a company providing CRM software. That said, that gives me a decent amount of expertise in the matters too.
Basically we need to get all our own customer-data and systems GDPR-compliant. Which I won't deny has been a reasonably big effort on our part.
But instead of only doing this for ourselves, we've put all this effort into getting our own CRM-software GDPR-compliant instead, meaning in the process all our customers get to benefit from this at near zero cost.
Basically: By using a modern, maintained and competent CRM-solution, you should get GDPR-compliance in your core-databases almost "for free". I won't push my own company here, but it should be trivial to find should you be curious.
If your CRM-solution does not help you provide GDPR-compliance, you should consider how serious they are in these matters and if you want to continue using them.
And if you don't have a CRM-solution at all (really?) it's definitely time to consider getting one, because that's going to be the absolutely best tool you will get w.r.t. ensuring compliance.
> Oh, and did you know that GDPR also affects the work of teachers, solo entrepreneurs, doctors and the like?
It affects stored and processed privacy-sensitive information. Why should certain professions or business-categories be excluded?
You say that like it's a bad thing.
Take a business about as far away from data as you can imagine. For instance, a business that makes replacement knobs for antique radio restorations. They have a website with an online catalog and a shopping cart where you can order replacement knobs, pay online, and they ship the knobs to you.
They collect your name and address for shipping, your email address to contact you if there are any questions or issues with the order and to give you order processing updates, and payment information.
If this business is offering their goods to people in the Union, that data collection falls under GDPR, and they have to have a designated representative in the Union.
I've not been able to find anything so far on (1) how some random small business in the US goes about finding someone to be their designated representative in the EU, and (2) what they will have to pay that person to take do so.
Can you point to which bit of GDPR says this please?
Article 3(2) is the one that says GDRP applies to the processing of personal data of data subjects in the Union by controllers or processors not in the Union if the processing activities are related to the offering of goods or services in the Union.
> The obligation laid down in paragraph 1 of this Article shall not apply to:
> processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
I think the processing is "occasional".
If you are smaller than that and you outsource processing of the personal data of your customers, then all you have to do is make sure the customers consent to this, and you are good to go with GDPR. It's practically effortless, unless your business model relies on monetizing innocent victimes without their consent.
The Article 27 representative must be in the Union, which is why it can be problematical for a company whose office and employees are all outside the Union.
To be excluded, the processing has to satisfy three requirements:
• "is occasional"
• "does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10"
• "is unlikely to result in a risk to the rights and freedoms of natural persons"
Most businesses probably won't process any of the Article 9(1) special categories or the Article 10 criminal stuff, so that shouldn't my much of a hurdle for most.
All kinds of data pose a risk to the rights and freedoms of natural persons. See Recital 75 for examples. Of particular note, if it can lead to identity theft, fraud, or financial loss it poses such a risk. This is going to snag a lot of businesses.
Then there is that "is occasional" requirement for being excluded. I have no idea how that is going to be interpreted.
And if they do run their own shopping infrastructure they obviously will have to deal with all the ins and outs of that, including operations, keeping the whole thing up-to-date and secured as well as compliance with the law.
Won't that mean they are still under GDPR and still need to have a designated representative?
This is quite funny considering you are writing this on the WWW, which runs on top of the TCP/IP stack. The WWW came out of CERN, the TCP/IP stack came out of DARPA. The web is at its roots a pretty global affair.
This is not about 'stifling competition', this is about privacy.
Until EU reaches mass debt and mass unemployment, and wonders why every tech startups are in the US, or in Asia.
also, being GDPR compliant gives companies a competitive edge.
I'm utterly shocked at the HN bubble about what constitutes a proper bussiness model.
Following my advice will substantially reduce the chances of people having to pay fines. That's a public service. If you want me to assume liability for that then you are clearly asking for more than I can give you.
But rather than trying to play word games with you I'd like to point to the track record of the various EU data protection entities and you'll see that on the whole they are doing a very good job.
Finally, as for paying people's fines, if you break the law you are liable for the fine, long before you will be fined (unless you are really making a mess of things) you will be warned so that you are able to come into compliance. If you ignore that and then you are fined you really have only yourself to blame.
This is an obvious slippery slope, and it's probably going to be challenged by the U.S. 1st amendment. It's already an issue with the previous "right to be forgotten" law which was way more limited in scope. [1][2][3]
[1] http://www.dailymail.co.uk/news/article-3156779/More-280-000...
[2] https://www.telegraph.co.uk/technology/google/10833894/Polit...
[3] https://www.wired.com/2014/07/google-right-to-be-forgotten-c...
I've read the law end-to-end several times, I do not think it is evil.
> Many small projects will get killed while privacy abusers will just find a way to avoid the law.
This is Europe, not the United States.
> You still have to point to one example where this law will make someone['s] life better.
It's already making my life better.
For instance, this email I just received:
--
Let's stay in touch!
As many of you know, the new General Data Protection Regulation ("GDPR") requirements go into effect on 25 May 2018. Your privacy is very important to us, so please consent by clicking the button below if you would like to continue receiving updates from YouPic on announcements, insights and potential opportunities. Yes, let's stay in touch!
Sent with from YouPic Viktor Rydbergsgatam 14, Gothenburg, Sweden
--
From a company that I've never done business with, that has absolutely no right to spam me and that I've tried many times to get them to stop spamming me with zero result.
So no, let's not stay in touch, fuck off with the spam, the targeted advertising, the profiles, the retargeting, the selling of profiles, the stealing of contact lists and so on.
I do agree with all of that, but I think the solution is more technical than regulatory.
Ublock Origin, uMatrix, and Ad Nauseum are doing an infinite better job to protect user privacy than any legislation we can make up.
At the end of the day, users are responsible for their own security and privacy as the web is global, and you can't expect all juridictions to comply with EU laws.
What would have worked is self regulation but the industry has clearly shown that it is utterly incapable of doing so.
> At the end of the day, users are responsible for their own security and privacy as the web is global, and you can't expect all juridictions to comply with EU laws.
That's the beauty of it: now we can. I'm really curious how the EU will go after foreign parties that decide to flaunt the law because they have no residence in the EU (and because they decided they did not want to play the representative game). That will be the real test. If that fails then the law will fall apart.
Time will tell.
Copyrights are very different as they are already everywhere. We don’t want reprocity for laws concerning content. Picture if China or Russia demands enforcement of their Internet laws globally.
Somehow our ancestors did not have the brilliant idea to just put a fine to any hospital that breaches medical protocols and send patients to death.
The first web browser was released in 1993. Any computer science professional born before 1970 had not seen a web browser as a student (because it did not exist).
25 years after 1993 the EU decided that a law that regulates the profession with fines (GDPR) is enough.
Good luck EU!
"It looks like you're accessing this site from the EU. This site is not compliant with EU law and cannot be accessed from within the EU. If this is an error and you do not reside within the EU, please read the following:
... very long legalese about claiming that you are definitely not an EU citizen and the EU-seeming IP address is in fact a VPN or proxy, so you are definitely not subject to EU law. In case this agreement is signed fraudulently, damages will be ascertained by $US_STATE court (wherever company HQ is) ...
[ ] I agree, under penalty of perjury, that the above applies to me. In the case that this agreement is signed fraudulently, I agree to pay the damages awarded by $US_STATE court and waive my right to sue within the US."
Can this company continue doing business as usual, given that any EU user who tries to invoke GDPR will subsequently be fined and potentially deported to the US for hearing?
So, no.