Let me know if you have any questions...
Let me know if you have any questions...
From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate that’s what’s happening. In other words, good faith and best practice will get you far.
Your current reaction seems like a huge and unnecessary over reaction that is just harming your users, and unlikely to have any material impact to your legal risk.
I highly doubt this decision was made lightly and was probably informed by actual legal professionals with knowledge of the regulators in question and not the 3rd party opinion of some guy on the internet who "feels like its not that big of a deal."
Now would be a good time to do just that, and if the actual legal professionals thought it was a good idea to ban EU citizens but keep their data then maybe they should get better lawyers because that certainly won't work.
If I had an instapaper account it would be interesting to submit a GDPR request tomorrow, and see what kind of reply I got. Now I don't, but I'm sure there are plenty of other interested people around.
For most small business and startups this is no big deal as 1 or 2 reports to the regulator isn't going to trigger anything. For those companies of a certain size, the regulator might take note of 1,000 reports in the first week. I imagine some of those will have the regulator check if they have had a self-report from the company for non-compliance. Maybe then an email to colleagues at other ICOs across Europe.
In other words, the first to think they were GDPR compliant might have had to redo a ton of work to adjust to more recent interpretations.
And let's not forget, for large orgs with complex infrastructure, this is a behemoth of an effort. There's been year long projects in the two large tech companies I've had insight to since.
And while I'm at it, let me comment on the frequently expressed notion of "if you've respected your users in the past, you'll be fine!". Just to pick one counter argument: the right to be forgotten. That can only be implemented thoroughly and in the way the users expect it to work (ie. delete everything but what you're legally required to retain) by finding a way to connect all user data so you know what to drop if need be. That is exactly the kind of action that's caused public outrage at big tech to begin with and it's not only potentially a huge effort, it also increases risk of abuse.
This all being said, I still think GDPR is a good idea at least in principle. And believe it or not, while everyone around me is really of compliance work, GDPR seems widely considered a good idea in principle across engineering in big tech.
There we have to disagree. It's not like this is something new and untried.
GDPR is a development from long-standing, and now very well understood, Data Protection. The legislation seems mainly intended to modernise some of the definitions and scope (eg adding biometrics to PII), catch some newer practices, and make very plain and explicit that it doesn't just apply to EU companies.
In 1996 and 97 in the run up to the 1998 Data Protection Directive I recall a couple of common confusions and misunderstandings. Nothing like the ridiculously poor and simply incorrect reporting we have for this.
Any large org should have been fully compliant with DPA for years. They have to add extra mechanisms for explicit opt-in or deletion and get a little less time to retrieve full data and can't charge. That doesn't seem to need a "behemoth of effort", but not to say it's necessarily entirely trivial.
In other words they survived DPA with no apparent effect, yet it's >80% of GDPR with the same definitions. No one should be iteratively fumbling toward an unclear target at all. Even reading the UK ICO's old guide to 1998 Data Protection from a few years ago gets you most of the way there including understanding personal data.
There are companies, OP being one (a subsidiary of Pinterest) that have presence in the EU and are essentially playing chicken with the regulators. Blocking users but keeping their data is not compliance, nor are dialogs telling users you plan to carry on as normal. Companies do not do this with the IRS because they would be afraid of the consequences.
And that's only GDPR. We've had PECR (in UK) since 2002 and DPA since 1995.
Do they share reading habits with multiple third parties perhaps?
So, unless you’re saying that “Pinterest’s site reliability team can’t answer question 192 about how user data is deleted from the incident management system logs when an event is traced” is a “huge red flag” then you are exaggerating the issue.
https://jacquesmattheij.com/gdpr-hysteria
EU agencies would prefer compliance over fines and would work with businesses to help them. As the article suggests, prosecution/fines will come when all other avenues are exhausted not the starting point.
Let's be a little self-conscious here, shall we?
Of all the articles on HN that discuss the GDPR that I've read, I've found one that you didn't contribute to and your contributions never show an "understanding of laws based on the text of the law". For instance, you have consistently claimed that there will be 28 (btw, not 27) different interpretations of the law, completely disregarding entire articles devoted to the consistent application of the Regulation- which, as a regulation, does not need to be made into local law and is applicable across the bloc.
You are clearly on a warpath against the GDPR, which is perfectly fine of course; yet at the same time you accuse jacquesm of being a "tremendous fan of the GDPR". If you can express your opinion despite having an agenda, so can he - and he seems to be much better informed of the law than you are.
Edit: Just to clarify, I don't have some axe to grind against you. You're one of the few users whose handle I recognise because your comments in GDPR threads stand out so much in their fervour and because there are so many of them.
With regard to your claim that it will not be subject to unique interpretations in each country within the EU, that simply isn’t true. Each country will have its own enforcement agencies. They’ll enforce it in different ways, and to different degrees. Since this regulation is so vague, it simply isn’t possible that they will all interpret and enforce it in the same way.
You seem to be in Jacque’s corner, claiming that our new self-appointed privacy overlords will be perfectly coordinated and “good natured”. As someone with quite a bit of experience dealing with government agencies, I can tell you that few of those that seek out relatively low-paying government jobs where the primary perk is having power over other people are “good natured”. There will be abuses.
The good news is that D-Day is here, and now we can all stop arguing and watch to see whose predictions come true.
Your argument seems to be that a police state where the authorities have a lighter touch is preferable. That's obviously true compared to a draconian police state, but it's a police state either way.
Article 58 says that fines can be issued along with, or in place of, other enforcement action. That isn't "no warnings". Plus if you read the text of the law you would note that it is very clear that the size of the fine is dependent on 11 factors, many of which revolve around future compliance and efforts made by the business to resolve the breach and showing willingness to conply.
I realise that Pinterest is large and I'm sure they have sought legal advice, but that doesn't stop this coming across as an overreaction, if one assumes that they _aren't_ using the data in ways that explicitly violate the rights granted by the GDPR.
Now if they are explicitly violating those rights, that's another story! I'd rather attribute it to ignorance than malice though.
Shouldn't law apply equally to everyone? One could have thought that setting an example "to show them!" wouldn't have occurred in a civilised country.
Taxation (I would hope) is not minimally enforced.
Because it's the EU and not some other Union.
It's just silly to expect any enforcement body to go after everyone equally. It doesn't even make sense; company A has data on 1.5B people, company B has data on 27 people and the owner's mother. Why would you go after B before A?
a) they have said they don't want to punish companies for the sake of it, they want to use it as an incentive to fundamentally change the approach to the handling of user data. This means not suing tiny companies for more money than they are worth.
b) they have said that the standards will roughly increase with the size of the company and resources it has. A company with 27 users (and few employees) would not be expected to have a data protection officer, or many of the control processes that a company with data on 1.5B people.
Which effectively kills that company even if court finds their violation was minimal.
Setting an example is how the US regulators work, not so much the EU.
Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data”.
GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive liabilities that most companies outside the EU won’t be willing to take on. While Instapaper likely will eventually relaunch in the EU because of its footprint there, the reality is that EU residents are going to be blocked from a large percentage of the world’s websites. The liability is just too great and the rewards too small for most companies outside the EU. You guys chose to make your traffic radioactive. These are the consequences.
This sentiment and the hilariously large fines (regardless of company size, even) on relatively-ill-defined requirements make the whole GDPR process feel like it was designed to bully businesses into compliance.
Some pieces of GDPR are definitely for the benefit of the end-user (at the expense of companies, who happen to be providing those users other benefits). It all feels really heavy-handed, though.
Not to mention a little reminiscent of the problems that occur with other "bans" (which, this effectively is). When you put heavy legal restrictions on doing X (where, in this case, X is storing and processing data that you assumedly use to provide a service for users), you're effectively hurting the legitimate businesses most (_especially_ small ones) while the real "bad guys" that are actually doing bad things with our data are going to continue ignoring the law. There might be some value in-between, but I doubt there's much.
>Some pieces of GDPR are definitely for the benefit of the end-user (at the expense of companies, who happen to be providing those users other benefits). It all feels really heavy-handed, though.
The GDPR isn't vastly different to the old Data Protection Directive, which has been in force since 1997. The panic over GDPR suggests that a lot of companies had simply been ignoring the DPD. If a bit of bullying is required to get businesses to obey the law, then so be it.
I am not sure I understand this sentence. That’s what laws do. “Bully” you into compliance. I think you might have meant something else?
This is already happening without the GDPR (carders, dumps, etc), so I don't buy it. The black-market analogy (e.g. illegal drugs) also doesn't hold when applied to companies.
> the hilariously large fines (regardless of company size, even)
Oh no, proportional fines! How socialist!
The whole point is to make it somewhat independent of the company size, so bigger companies won't just swallow the fines. This is typically what Google et al do, they just factor it in to the cost of business. The GDPR wasn't written in a vacuum.
Ironically, it's the bigger companies that can still just swallow the fines and the little companies that just effectively vanish into bankruptcy.
Er. I vote in an EU country, but I don't feel like I "chose" anything. GDPR was mostly developed by institutions (Council of Europe, European Commission) formed of people that were not directly elected by European voters. In any case, given that personal data management issues are not a prominent part of the political discourse (even in the EU), I'd be surprised if any of the people in charge were elected because of their position on data protection.
It so happens that European institutions have come up with GDPR, but I don't think it is fair to see it as a conscious choice from EU voters.
> the reality is that EU residents are going to be blocked from a large percentage of the world’s websites
I'd be interested in seeing supporting evidence for this rather surprising claim. I'd conjecture that the "vast majority" is the long tail of small websites who haven't heard about GDPR or don't care about it; so I'm not too worried.
Says who? If they weren't doing shady stuff, they wouldn't be pulling out of the EU. The excuses of being complex are just that, excuses.
Says anyone with common sense. What percentage of sites do you think employ data scientists or would even know where to go to sell your data? Most sites do nothing more than throw GA on their website, and maybe some Adsense. You people decided to paint that as something evil.
That’s your decision to make, but just understand that most of the rest of the world wants no part of $20M potential fines and will simply take their ball and go home. This law will have the net effect of creating two Internets - one for the EU and one for the rest of us.
That actually is a problem. GA is a clear violation of everyone privacy.
Where "common sense" means "agrees with downandout, not the more traditional definition of "common sense".
But then, if you are using data for other purposes, it's a bit complicated because you'll have to refrain from doing so until you are compliant. It doesn't necessarily have to be shady stuff. Even if you aren't sure if what you are doing is contract basis or not, it can be a pain. It's not necessarily massively difficult, but if you woke up yesterday and thought "OMG! We haven't done GDPR! What are we going to do?", then I can see this.
I've written earlier about how the company I'm working for now has changed what it is doing with data, even though I don't think they were doing anything shady previously. But it's more like, "Do we really want to list a lot of things and piss off the customer?" So now there are heated discussions of what 3 (or whatever other small number) of things we might collect data for because we believe that's the kind of limit that the customer will tolerate.
All of these discussions take time -- especially in a large organisation. And you can see in discussions on HN, there is going to be a large backlash of "Why do we have to do this anyway? Can't we just ignore it?" which wastes a lot more time.
Sounds like they want to be compliant, but are just not ready yet. A miss on their part, but hopefully they will get things in order quickly.
It's most likely action based on what their suits (Lawyers) recommended, and not a reaction.
Using that line of reasoning, Pinterest is making a very prudent decision.
> because it’s not entirely clear right now what information residents will request, what format that information needs to be in, how to locate it and package it, and whether new infrastructure needs to be created to manage this request pipeline.
So in the meantime they can at least stop the flow of new data from the EU into their system until they are 'compliant' and have systems in place to deal with the existing large amount of EU users/data they already have.
It makes sense to me to be cautious here, plus it has the dual benefit of drawing attention to the real costs/risks the bill has on smaller firms without teams of lawyers and internal human resources (developers, CSRs) to deal with the new obligations imposed on them.
The safest option was actually to comply with the GDPR during the two years it has been in force now. I refuse to believe that the changes required were impossible to perform in two years.
I'd love to know when exactly did Instapaper start looking into the GDPR.
Plus there are still tons of unknown variables at play with GDPR... even among companies who did spend sufficient time beforehand, as I quoted from the article above. So additionally, the non-obvious requirements further makes the underestimation make sense.
The requirements are clear enough to figure out a solution in the last couple of years. What takes time is if you're trying to skate as close as you possibly can to the legal line and not go over it.
Source?
Pinterest which owns Instapaper (2 years ago mind you!) has raised $1.47B to date. There's no legitimate excuse here.
But that is one part which is confusing to me, from the UK ICO:
The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU.
Additionally, the GDPR does not apply to actions taken before and during the transition period (which ends now).
In this case, Instapaper does not offer goods or services to individuals in the EU. It actively blocks any user inside the EU.
Does that mean that Instapaper is no longer subject in any way to the GDPR?
In other words, if you had a company that had operations in the EU, but left the continent 2 years ago, and no longer has any activities with any EU individuals, does the GDPR suddenly apply to you?
If the GDPR applies to you, you need to hire a DPO based in Europe, as well as having a EU contact that will be responsible for any fees that you incur.
If you did business in the EU but no longer does, do you now have to hire a DPO in the EU and have a local contact responsible for any liabilities?
Managing the data is the easy part.
Which parts of GDPR do you think you're in violation of?
Why do you think removing access for users currently in the EU puts you in the clear legally?
What are you doing with European users data currently, have you deleted it all?
A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy, just by tightening up how they hold data, and making sure they are clear on permissions with users.
Are you sure you have good legal advice on this?
Answering those questions in a public forum would be extremely foolish. ("Do you know why I pulled you over?")
A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy
And how many of them are actually in compliance?
Perhaps asking for questions was foolish?
And how many of them are actually in compliance?
If you're not in the business of selling customer data to third parties, it's not very hard to comply, just requires some discipline on how data is stored and who it is shared with, and a point of contact for enquiries about data.
> US tourists on a trip to Paris are protected by the GDPR
That’s not entirely correct. They’d fall under GDPR if they do business with a company doing business in the EU (eg by buying something off of amazon and sending it to their Paris hotel address. They would however not benefit from GDPR if they were to order something from amazon but sending it to their US address instead.
"If the Data Subject, moves out of the EU border [...], or goes on holiday then their personal data processed under these circumstances is not covered by the GDPR and they are no longer a Data Subject in the context of the GDPR, unless the organisation is “established” in the EU"
Is geoblocking sufficient on its own to show that the Controller/Processor is not doing business in the EU? Even when the Controller/Processor still provides localization to EU languages?
- You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today.
- I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc.
The law is confusing "privacy" with "invisibility".
IPs combined with other user data could be PII.
"- You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically, advertising is optional in EU sites as of today."
Wrong. You need opt-in consent for non personalized ads, but this can be the "soft consent" type where you only present the "Accept" button. Advertising is no more optional tomorrow than it was today.
"- I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc."
Knowing what you have on me is not superfluous; it's my data.
Seriously, the FUD around this law is getting tiresome.
1) Bob signs up for a service and is logged
2) Bob than asks for his account to be deleted. Account details are deleted, but the ip logs are retained.
3) Bob signs back up for a new account allowing the data processor to make the link from his new account to his ip old logs with the first account.
This seems like a likely violation, if so you would have to treat ip address like personal information.
So if Bob asks for his personal information to be cleared and the system leaves Bob-IP tuples behind, it clearly didn't do what he told it to do.
It depends on Bob using DHCP, that his DHCP switches often enough, and there are enough people on the same network that the link can not be made.
The above is not always true, other mitigating factors are not always true. Which seems to make some of IP logs personal information. Or at least you are safest if you treat it that way.
I am basing some of my reasoning off an article that I was pointed to earlier: https://www.whitecase.com/publications/alert/court-confirms-...
Where, to my understanding, IP address are considered personal information only if you can link it to some other identifying info.
I think a regulator is unlikely to go after a company for not deleting IP logs in the current climate. As far as I can tell GDPR gives them the power to however.
Until there is some case/enforcement history it is understandable if people are cautious.
- ah, well google suggests you ask consent even for content-based ads
- 99% of the sites show you what they have on you when you use them. The provision could be to have a separate download page when that is not the case. If every business must have an unauthenticated download page, it becomes easier to get other people's data via phishing.
its not fud. this is the internet. lets talk again in a few months.
Unless you mean user-tracking advertising.
"I've a motor impairment do your hotel have accessible rooms?"
say you have your hosted email system, now you're in a huge mess.
people downvoting this should really hear a lawyer about gdpr.
It sounds as if you're unwilling to talk about the issues that you're facing. So what can you say? The only reason I can think of that you can't say is that are trying to get some infrastructure suppliers to be compliant and those talks are confidential. Correct?
Additionally, I can say that our privacy policy is concise, clear, and accurate with respect to the types of information we collect and how the data is used: https://www.instapaper.com/privacy
If you have other specific questions, I will do my best to answer them.
I'm naturally curious as to what's holding up Instapaper.
As you say, your Privacy Policy is very good, other than the disclaimer that says 'we may pass your personal data to others - who knows what they do with it eh?'. I imagine that this is the issue which is holding you up.
We are working very hard to minimize the service interruption.
The agencies that can enforce the GPDR want you to be compliant, not to fine you... If you're actually working towards compliance past evidence shows they won't fine you.
>2When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
> any action taken by the controller or processor to mitigate the damage suffered by data subjects;
>the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
>the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
>where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
>any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
So, a whole bunch of very explicit things that are to be used when deciding if whether to impose a fine (at all).
Says who? The only perfectly clear parts of the GDPR revolve around the massive fines.
https://www.theguardian.com/business/2017/jun/27/google-brac...
Shocking stuff.
Except the Commission actually gave Google quite detailed advice over 5 years earlier about what it needed to do to be compliant.
https://www.ft.com/content/564a284a-a334-11e1-8f34-00144feab...
I'd bet Pinterest is very risk averse given how little money they make from Instapaper.
Not complaining, I prefer it this way. Hope you will sort the issues quickly.
Interesting times these are.
As I refer to my first comment: interesting times.
(1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit.
(2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually.
(3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating the impact of the law or you do not know what you have or you changed strategies internally recently and now you're not going to be ready in time because you started way too late.
So in all, all you've managed to achieve with this action is to get the spotlight on you, and it is a 100% certainty that at least Instapaper will be solidly violating the GDPR come tomorrow.
If I were in your shoes I would use my designated representative to contact the authorities for guidance after explaining in detail what the problem is before I would let my end users pay the price for my own incompetence.
Some smaller companies and lower-profile groups within big companies are going to need more time to sort this out, and some may decide it's not worth the risk of the massive fines no matter how compliant they think they are and will block European users. Nobody knows how aggressive regulators will be in enforcing this so far, nor is their any precedent for how the law will be interpreted by actual courts. Calling people incompetent isn't going to change that.
This is one of the negative consequences of enacting complex regulation targeted mostly at giants like Facebook and Google and then applying it to every side project and business in the entire world no matter how big or small. Sorry.
Lower profile groups within big companies are probably most likely to shut off their services to European users because they have the cautious legal departments of the large company without the important profit center designation which would make compliance a priority.
Who cares? That's not a factor in whether or not you should comply with the law.
> Lower profile groups within big companies are probably most likely to shut off their services to European users because they have the cautious legal departments of the large company without the important profit center designation which would make compliance a priority.
Well, that may be their strategy but it won't work because it is the company that is violating the law, not the lower profile group.
speaking generally here, you know laws aren't always right? we had plenty bad laws to draw from to challenge this particular point, from racial to abortion laws.
gdpr isn't as draconian as these but still has plenty trash in it between the vague wording, the moving target 'state of the art' represents and the weird requirements and absurd implications of the 'right to be forgotten'.
It's the law, it was created by a democratically elected body. Racial and abortion laws are on a different plane altogether, and are not typically the playground of globally acting corporations.
I work in a company that was acquired and we're still our own legal entity. Would our owner be affected if we violate GDPR?
Unlikely. "Instapaper Holdings, Inc." is right in their footer.
Make up your mind.
And this is exactly why this is such a shitshow. Stop attacking people who haven't complied because small developers have other things rather than trying to figure out whether they have to redo their logs if a user asks their data to be deleted. This is almost bullying behavior.
Yep.
> And now you are advocating that they should have already complied with GDPR given its impact!
Obviously yes, because today the law becomes enforceable. Not having done the required work is just plain dumb.
> Make up your mind.
I made up my mind well over a year ago, spent the time required to be compliant (a couple of days) and that was that. Instapaper being as small as it is would not have had to spend more time than that unless they are doing something they shouldn't be doing, are unable to plan or changed tactics in the last 2 days. After all, if they weren't going to make the deadline they had a very long time to announce that, instead they announce it the day before the law becomes enforceable. That's just not ok. At a minimum they should have had their export facility up and running.
> Stop attacking people who haven't complied because small developers have other things rather than trying to figure out whether they have to redo their logs if a user asks their data to be deleted.
I suspect you are in the same boat?
> This is almost bullying behavior.
Right. Well, sorry, it really isn't, it's the perspective of someone who has been in business for a very long time and who feels that the GDPR addresses some fairly urgent matters. Companies have been running roughshod over users' privacy rights for decades and it is one of the worst things to come out of the internet. The level of tracking and data brokering that is going on is utterly disgusting.
If you weren't doing anything you shouldn't be doing the GDPR is going to be a pretty simple affair if you're a small company. Larger companies will have some more work but have more resources.
It surprises me how much this community tolerates such combative cluelessness.
Did you start working on compliance in a timely manner or did you become aware of this a few weeks ago?
Does your company have a clue about what it is doing in general?
Do you take a user centric approach to data ownership?
If those are all 'yes' then compliance is easy. If you don't care, do illegal stuff, are clueless or don't care about your users then compliance is going to be hard, that's what the law intends because those companies should change their ways.
For some reason he is such a fan of this legislation that he is willing to overlook its glaring problems. No objectivity there, I am afraid.
Oh my. Terribly sorry for putting up a political manifesto.
> Either self-interest or useful-idiot.
Take your pick. No third options? Such as a genuine desire to take some of the heat off for SMEs, of which I own several and participate in several others?
> For some reason he is such a fan of this legislation that he is willing to overlook its glaring problems.
Yes, I'm a fan of this legislation. I also was a fan of its predecessor and it's a joy to see companies that don't have their house in order make all kinds of panicked moves. I have a pretty good behind the scenes view of what goes on with respect to privacy abuse by corporations due to the nature of my work. Those companies that do illegal stuff, don't give a damn about their users and that in general are clueless (and which in turn increases the chances of their online properties being compromised) will be the ones that run into the 'glaring problems' The only thing that I see as troublesome with the law is the lack of reciprocity and enforcement across borders. The EU picked a complex and for really small companies expensive way to resolve that and that's something that I see as a real issue.
> No objectivity there, I am afraid.
I think you mean to say you don't agree with me.
There is nothing retroactive here.
I don't really see where the age of the data you store comes into play.
In fact that attitude goes exactly against what the law is trying to achieve in the first place.
I think this is an important realization for any regulator.
So you are not correct on #1.
"It was adopted on 14 April 2016, and after a two-year transition period, becomes enforceable on 25 May 2018."
Source: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
>And before that one there was another one.
Yes, but that was a different law. It required different things.
> Yes, but that was a different law. It required different things.
It actually required a lot of the same things, but because companies decided to ignore it it was revised.
how do you know that? i mean technically he says they re violating it today, just like we all did the past 2 years because it wasnt enforceable. what changes with their ban tomorrow?
Erase everything.
When you're told the highway near your house has a new speedlimit you can either obey the speed limit, use a detour (which will still be slower on account of it being longer) or you can take your car off the road in huff.
The first one is the only solution that makes sense.
I mean , knowing GDPR , i would guess at best the provision would be something like "a reasonably long amount of time but not long enough to be unreasonable based on appropriate considerations of data subject's patience"
I can imagine something to the effect of stopping further gathering of data (to stop digging the hole deeper), to give your users the option to request what is their right through some kind of form and to park those requests until you're done with the implementation and in the meantime give them continued access.
After all, the law already has a provision in it that you have 30 days to respond, and another 2 months after that if you are for some reason technically incapable and need an extension.