"I am a customer of yours."
Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.
"I am a customer of yours."
Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.
If you collect data from me when I visit your website, even without me buying anything, you have now collected data and you need to comply.
The use of the word "customer" in this context is incorrect.
It's ok if the privacy law only gone against stuff like analytics or horrible facebook buttons that even collected stuffs from people who clearly weren't users. i.e. tracking especially tracking outside their "domain"
however GDPR goes against all and anything. I mean if I go to a supermarkt I can't just tell the supermarkt owner to shut down all his cameras until I leave the store, he would basically just kick me off his market (which actually is his right in the EU). However the EU somehow made a solution that actually even goes against their own market principles just to have extreme amount of Privacy in the internet (only in the internet, their own institutions can still collect data, i.e. in germany the ard has tons of data about everybody) and this is my problem with the GDPR, it's a law from people who actually just want to hurt the big us internet companies. The law also was made by a lot of people without any clear technical background (there were some, but they were a minority)
https://gdpr-info.eu/art-2-gdpr/
> This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
Your name, address, move-in date, and whether you paid them. Additionally – if you don't to pay twice – who you live with. Am I missing anything? In any case, they are still bound by the same GDPR as we all are.
(A small nitpick: The ARD does not hold any data but their members do.)
Your example is deeply misrepresenting the GDPR, seems like FUD to me. GDPR applies outside the internet, GDPR is very limited in scope as it kept the "legitimate interests" exemption from the 1995 directive.
Can you substantiate your claim that GDPR was made by people who do not understand what they do ?
In any case it's the wrong way to address the problem, and its ill effects are seen in cases like this. It's actually easier for "free services like Facebook" to comply because they can hire full-time compliance staff. The worst effects fall on smaller sites and individuals, making them less able to compete - individually or collectively - with the entrenched big sites. Some have even painted it as a form of regulatory capture, though I think that's a bit of a stretch.
No, it really doesn't.
In Europe action for civil torts is limited to what you've actually lost. There are no punitive civil claims. Courts are a method to get back to how you were, they're not a route to betterment.
And GDPR is not enforced by each victim of a breach taking civil action through the courts, but by victims reporting to the regulator and allowing the regulator to take action.
The reason people in Europe seem so blasé about this is because we've had decades of experience with regulation, and we know that they don't have many teeth, and tend not to use the teeth they do have.
GDPR isn't changing this.
https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
thing is if you require people to register to be able to buy from you they can be customer before actually paying anything.