And now, they still have their name and email in one entry in our system, but it's the record that we deleted the first entry at their request. Thanks for wasting half an hour of my day checking our systems, jerk.
wow, and people claim this won't just destroy totally innocent startups.
What I meant by the 'four years' comment was not that it takes that long to train, but that GDPR has been included in the training for that long. A four year run-up is plenty long enough for even start-ups to get themselves up to speed and design their systems for privacy by design.
> "What were the lawyers doing all that time before then?"
what lawyers? do you realize that compliance, proving compliance, and implementing mandated features are completely separate tasks with cumulative costs? even if you aren't doing anything with the data?
> Any business trading internationally has to have a care over the regulatory environment of the target country. Why is internet trading any different?
bad, stifling, preemptive regulation is bad regulation in any industry. why is internet trading any different?
Don't you think that size of company would have a lawyer somewhere?
Also, you're going to either need to suck up the admin time, script it, or block the EU. Take your pick, there's not much point slinging names around. Chances are it's going to happen again and you may as well be ready.
Because then we have no record of complying with their request, which is something we need to show records of if we're ever audited.
> Also, you're going to either need to suck up the admin time, script it, or block the EU.
Yes? Does doing that preclude criticizing the clumsy legislation that caused this?
1. Someone requested you delete their data from your system.
2. You did this and logged their request.
That seems legit and pretty much un-jerk like. How did the user know what data you held on them? If they didn't know then the fact that you only held an email address then asking you to delete seems reasonable.
Also, did you really only have their name and email? Unless you have a table called "names_and_emails" that isn't linked anywhere else I assume that you've got the user linked to some sort of subscription or something? That's information too.
The other possible meaning of what you wrote (and my first understanding) was that the same user sent two deletion requests.
That does seem excessive, but then if you complied with the first then the second just becomes a formality at that point surely?
> Does doing that preclude criticizing the clumsy legislation that caused this?
Wether you think this law is clumsy or not (I don't, I think it's a hell of an improvement on the status quo) it stands a good chance of protecting people's privacy, and as a father that is especially important to me with kids growing up even more intertwined in digital age than I was.
As someone who runs a few sites it means some more work for me, but it's worth it. I'm still a person in the world with the need for privacy.
https://ec.europa.eu/commission/sites/beta-political/files/d...
But I'm gonna take your advice anyways. There is plenty of information already for anyone concerned.
[1] https://ico.org.uk/media/for-organisations/documents/2014223....
Why is this silly? Does the law explicitly forbid people from asking stuff like this?
No. The expectation is each of the EU’s twenty-eight national data regulators will be nice and reasonable into perpetuity.
The safe guards question would be valid in that context as well but not right of the bat in a first exchange, but if a previous answer left something specific unsaid.
The location of the servers is a valid request depending on the context, for instance when the data is sufficiently critical to be legally mandated that it stays within the EU (yes, there is such data).
Agreed on the automated response, that's the best way to handle this.
Again, this is a troll letter, but even so it still requires a response otherwise you give the claimant grounds for forwarding their complaint to the regulators (who likely will ignore it but I'd play it safe).
How does that make the letter irrelevant? Responding to the letter rather seems to be the first countermeasure against the authorities' involvement...
ironically, this very blogger made all the same arguments here:
https://jacquesmattheij.com/gdpr-hysteria
his response to his current concern is: "then automate it" as if this is trivial. and "my blog is compliant" as if this means anything for even the most basic business model.
I think the cost of not having this law is much higher.
Also, lots companies had few problems automating the dissemination of users personal information to dozens of interested parties, building completely automated markets for this information with derivatives trading etc, all without users (and regulators) knowing or understanding anything about these practices. It is long overdue to put a stop to the excesses, and as a EU citizen I am extremely happy with GDPR.
There will be new opportunities for startups, hopefully GDPR can help make sure these opportunities are less detrimental to society than before.
There is no way you could know this and every indication to the contrary. Many EU countries are struggling with jobs and claiming to want a tech sector. This just made it much less likely.
> There will be new opportunities for startups,
The barrier to entry was raised. That means that startups which cannot afford proof of compliance will not exist - whether or not they meet your subjective definition of "detrimental to society."
> Why are we down-voting this post?
Responding to that will certainly not lead to new insights or good discussion. I did respond to the other point.
In other words, your assumptions don't factor in the link between the myriad of web services now available, and the freedom people have had to provide services on the web.
The government has a constructive role to play in the market, in provisioning tools and information to empower people to maintain their privacy, which market players are not economically incentivized to provide in sufficient quantities.
That would take the form of public funding for development of anonymity technologies, public directories comparing services and their abidance to voluntary data protection standards, and possibly public service announcements educating people about what data they disclose while browsing non-anonymously, or browsing particular types of websites, and how that data can be shared and used by private data collectors.
What the government should not be doing is imposing Big Brother laws that violate the privacy rights of companies in relation to the data they store, which properly understood, belongs to them, regardless of who that information is pertaining to, and violate private property rights by regimenting how web service companies will operate.
Centrally planning the web economy in the manner of imposing regulations like the GDPR is so ridiculously misguided. It is going to destroy innovation, and particularly, business creation.
I think not: incumbents will have more changes to make than startups, who can think it through and get it right from the start (for everyone, ideally). Also the data-portability rule directly lowers the barrier to entry and creates huge opportunities for competition.
Ad-tech startups who built their tech in the previous years may feel screwed by GDPR, but I won't shed any tears for them. They may carry on in the US, if that makes you happy.
The solution severely confines the space of operation, by straightjacketing web service provisioning to a narrowly defined set of procedures, and thus I think it's unlikely to be less costly than the problem it seeks to solve.
Creativity does not flow from this kind of central planning. I believe the blind spot that GDPR advocates have is that they don't fully grasp the scope of what they don't know and what has not yet been discovered, and thus they don't fully account for the cost of laws that inhibit the innovative processes that lead to discovering new ways of providing goods/services.
The responsible way of addressing privacy concerns, that would have been far less likely to undermine liberty and have other negative unintended consequences, would have been to develop user friendly anonymous browsing technology, like Tor-enabled browsers.
After you reach anonymously a service (e.g. Facebook) and login you won't get any help from Tor or similar technologies. You need a law to tell the other party to not mess with your privacy
The rest is an issue of contract law. No one is forcing you to use Facebook, thus it is not violating your privacy when you choose to give it your data. Perhaps public education, on how the personal data you disclose to web services can be used, and information on anonymous alternatives, would help in this situation.
Whatever the solution, it should not impose arbitrary restrictions on how websites can use the data others disclose to them, or obligate a web provider to respond to letters they receive. These are Big Brother laws that will limit the availability of services by severely constraining the space of operation.
I want to be able to use the web without other people's overbearing laws severely limiting the range of websites and services available.
I'm in this camp, and to respond to your counterargument:
No one is forcing anyone to use anything... except healthcare, health insurance, car insurance, etc. And in many cases, while you may not be forced to use a tool, not using it puts you at an extreme competitive disadvantage. People shouldn't have to choose between being able to compete and valuing their privacy.
I'm fully on board with acknowledging that complying with GDPR has a pretty high cost, but the flipside of that is that if companies had done the right thing to begin with, a) the cost wouldn't be so high, and b) we wouldn't need this law.
Moving targets are no fun at all when running a business.
Answering a request - even one engineered to be annoying - like this should not be a huge burden for any company that is not doing anything shady and that has been preparing for just such an event.
In some cases you can, but most GDPR DSARs are going to be free of charge.
No, it's not: it's the government's fault for passing an over-large law.
Up to 4% or 20Mill. A small startup won't get slapped with that size of a fine. If you are worried about those numbers, you should be able to hire a lawyer and ensure you are in compliance.
So the fine is in range(0 ... max(4% gt, 20M))
Ok?
The absolute maximum available is 4% or €20m, whichever is higher, but the actual fine imposed is always going to be less than this. We know this because after 20 years of existing data protection law the maximum fines have never been imposed.
If you are worried about being subject to a twenty million dollar fine, then you can probably afford to hire a lawyer to respond to the multiple warnings you will get before any fine is levied.
The environment affect EVERYONE, it's important to protect it because of that. It's a single entity that affect everyone. It's funny because it's exactly the opposite of GPDR, which is a single entity (the one that gave the information to the company) that affect everyone (every potential customer of a company).
GDPR just shift the blame over corporation instead of the one that gave the information in the first place. It shift the fear toward them instead of the one actually responsible for sharing it in the first place.
I'm happy that GDPR will push company to keep less information, there so many website I avoided because they asked for information I didn't want to give, but that's an issue that many website already solved (because that friction was making less user too). What it did bad is add confusion.
I mean, it's not like businesses worry too much about people's livelihoods when they lay them off. It's just a business decision and the laid off person needs to deal with the realities of the situation. Now, business owners need to do the same when it comes to the GDPR decision.
If you tally the score today, I think it's a win. A few companies may have folded, but a billion or two users have gained a little more insight and control over how data about them is used. But like I said, it's too early to be very confident about this.
You're right, it's the EU's.