And now, they still have their name and email in one entry in our system, but it's the record that we deleted the first entry at their request. Thanks for wasting half an hour of my day checking our systems, jerk.
And now, they still have their name and email in one entry in our system, but it's the record that we deleted the first entry at their request. Thanks for wasting half an hour of my day checking our systems, jerk.
Also, you're going to either need to suck up the admin time, script it, or block the EU. Take your pick, there's not much point slinging names around. Chances are it's going to happen again and you may as well be ready.
Because then we have no record of complying with their request, which is something we need to show records of if we're ever audited.
> Also, you're going to either need to suck up the admin time, script it, or block the EU.
Yes? Does doing that preclude criticizing the clumsy legislation that caused this?
1. Someone requested you delete their data from your system.
2. You did this and logged their request.
That seems legit and pretty much un-jerk like. How did the user know what data you held on them? If they didn't know then the fact that you only held an email address then asking you to delete seems reasonable.
Also, did you really only have their name and email? Unless you have a table called "names_and_emails" that isn't linked anywhere else I assume that you've got the user linked to some sort of subscription or something? That's information too.
The other possible meaning of what you wrote (and my first understanding) was that the same user sent two deletion requests.
That does seem excessive, but then if you complied with the first then the second just becomes a formality at that point surely?
> Does doing that preclude criticizing the clumsy legislation that caused this?
Wether you think this law is clumsy or not (I don't, I think it's a hell of an improvement on the status quo) it stands a good chance of protecting people's privacy, and as a father that is especially important to me with kids growing up even more intertwined in digital age than I was.
As someone who runs a few sites it means some more work for me, but it's worth it. I'm still a person in the world with the need for privacy.
wow, and people claim this won't just destroy totally innocent startups.
What I meant by the 'four years' comment was not that it takes that long to train, but that GDPR has been included in the training for that long. A four year run-up is plenty long enough for even start-ups to get themselves up to speed and design their systems for privacy by design.
> "What were the lawyers doing all that time before then?"
what lawyers? do you realize that compliance, proving compliance, and implementing mandated features are completely separate tasks with cumulative costs? even if you aren't doing anything with the data?
> Any business trading internationally has to have a care over the regulatory environment of the target country. Why is internet trading any different?
bad, stifling, preemptive regulation is bad regulation in any industry. why is internet trading any different?
Don't you think that size of company would have a lawyer somewhere?