On the other hand, I look at Article 3, and I'm not sure posting content on a personal blog counts as offering goods and services. Or do blog comments count as a service?
On the other hand, I look at Article 3, and I'm not sure posting content on a personal blog counts as offering goods and services. Or do blog comments count as a service?
https://gdpr-info.eu/recitals/no-18/
> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
Under the GDPR that would be PII and so the removal requests would arrive, whether or not the legal bar was met. I'd rather not have to argue in court whether or not my blog was purely personal even though I run it under my own name.
So even for a blog if you allow people to comment calculate in that they will ask for some of those comments to be removed. It's a relatively small burden because it won't happen often (with all the millions of Geocities sites it only happened a few thousand times over a decade), and it will stop people from complaining to the regulators. Better yet: monitor your comments and approve them selectively, if you drop the obvious dumb ones there is a fair chance that you'll never have a removal request.
That leaves people like me (and you, apparently), I solve the problem in the simplest way: no logs, no analytics, no comments on my site.
I'll be curious to see whether GDPR results in a web with fewer features, or maybe features that don't work as well. I tried DuckDuckGo, for example, but I dropped it quickly because Google's results are so much better. I actually like that it takes my previous searches into consideration.
Convenience and privacy will always be at odds. If the largest excesses are taken care of then this will already have been worth it.
”Whereas the mere accessibility of [your] website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that [you] envisages offering goods or services to data subjects in the Union.”
In English:
Do not translate your site to EU-only languages (Italian, German, etc.), use an EU based domain extension, or create content or services that would be especially appealing to EU users, and GDPR will not apply to you.
People's opinions on this regulation differ so dramatically that even when I read something in it that sounds pretty clear, I second-guess myself and worry that the courts will side with the worst-case interpretations.
No.
> I've been debating with myself whether I need to move my content somewhere like wordpress.com to avoid that requirement.
The biggest issue would be your log files, I've covered that in comments here, and in the articles as well. Another issue could be if you run analytics tags or advertising, which may impact you in a negative way financially in the case of advertising. My own blog is analytics and advertising free, I don't see it as a source of income so I don't care but obviously that will not hold for everybody.
The critical part is when you start to ask users to enter data into your system, as long as you don't do that you will be able to solve this in a straightforward way.
> The personal information I process comes from comments and web server logs, and I'm not sure that counts as occasional.
You are right that it isn't occasional. So, logs: analyze them, then delete them within 30 days or so. That should be enough to do most security related work with the logs as well as any analysis you care for.
Comments on your blog you will simply have to delete when the commenter asks for it. Even when I ran reocities.com this was the most requested support item, and it is pretty easy to do in an automatic fashion if you still have the original relationship between an account and the comments, this could be entirely self-service. I expect the typical blog engine plug ins to become GDPR compliant in the near future because lots of people will be asking for this.
> Or do blog comments count as a service?
Yes, it is a service. You operate a server which takes in data and records it. That it isn't commercial is not important in this case, data subjects will create accounts and there will be PII associated with those accounts, either directly or in the comments.
Now for some arguably bad advice (from a legal perspective, but it is very practical): I'd take 30 days to see how this all shakes out past may 25 before taking action on something as insignificant as a blog. That way you will have a lot more information to base your decision on. Obviously that has a risk: you will probably not be in compliance but I'm going on the assumption that regulators will have a lot more on their plate than your blog for the foreseeable future.
WordPress does have some plugins for complying with GDPR, so I'm going to try one of those to see what else needs to change, in those developers' opinion. If only there were such a thing as certification so I could trust anyone was doing more than guessing!
Anyway, thanks for your feedback. I appreciated your article.
There may be an alternative though, working on that :)
It's the armchair lawyers doing sneaky stuff that they will try to continue to do that should be worried here.