But also:
> Seems like Europe has decided that privacy and control of data personal data is something they want.
The problem here is that governments allow people to claim rights without bearing the cost of that claim (or at least hiding the cost).
But also:
> Seems like Europe has decided that privacy and control of data personal data is something they want.
The problem here is that governments allow people to claim rights without bearing the cost of that claim (or at least hiding the cost).
It is not difficult to avoid storing data you don't need.
You don't need a user phone number? Easy, don't ask for it.
Of course you argument is that it is difficult to change existing systems to follow this principle. Except that your starting position was that this regulation was about stifling competition, which is thus in direct contradition with this argument.
Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry.
Access logs for one thing are pretty unreasonable to force people to avoid storing.
>Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry.
Can you point out a specific example of somebody suffering actual damages from this "abuse?"
Store them for a limited time, it's not hard.
Sometimes it's important to update regulations, despite the inertia of existing implementations.
As the first offense only seems to result in a warning, they have a chance to figure things out. Then is asking their webdev to schedule a cron job to delete logs really such a burden?
I think it is certainly possible to find cases of identity theft resulting from PII that were leaked in security breaches, made easier by overreaching data collection.
“This Regulation does not apply to the processing of personal data: (...) by a natural person in the course of a purely personal or household activity;"
So, it really only applies to companies, or if you’re processing a large amount of user data for a hobby project.
That being the case, it doesn’t feel like the bar to being able to respect the law is so very high. But I’d be interested in counter examples.
Why do you think this is required by GDPR?
Here's the actual bit of law. Note how many exceptions there are. https://gdpr-info.eu/art-17-gdpr/
It's not surprising you fear it so much if you think it forces you to do all the stuff you've said. What is surprising is that almost everything you've said isn't in GDPR or has been exagerated beyond recognition.