It seems like he has no time only for legislation from EU.
It seems like he has no time only for legislation from EU.
I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer sufficient protection for the forum operator.
And more generally, prior to GDPR, a person could casually put up a forum on a website and not have a meaningful legal compliance workload. GDPR changes that.
There is no right to delete stuff that is not PII.
And forums already had to protect against eg people under 13 registering, or people under 18 sharing nudes. Both of those pose significant risk to online services, but people cope.
GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.
The ICO has produced a font of useful free guidance for getting compliant with the GDPR:
https://ico.org.uk/for-organisations/
That's what people should be reading.
The only reasonable assumption is that those new teeth will be tried out, and whoever they will be tried out on first will have a bad time. Do not assume that the first cases will be Google and Facebook, the regulators aren't stupid enough to try their luck first on the two organisations that has spend the most on being technically compliant, and has bottomless warchests to fight it.
You're right though, that it is always a relatively pure cost/benefit calculation for the company.
The EU has had data protection law for twenty years. The EU has enshrined proportionality of penalty in all EU law as a fundamental right. There is plenty of case law at the CJEU defining this.
All you need do is read the FAQs that EU ICO's have been putting up. The UK has never, in 20 years, applied the full penalty of the previous DPD, and under 0.1% of all reports got any fine at all.
A "typical" penalty will be help to comply. Perhaps a strongly worded letter.
Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA.
Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single piece of forum software
Work required for complying with a data access request: Search every single service you potentially could have stored user data in and provide it to the user. A non basic feature that requires custom development.
Additionally any malevolent user (as is shown in this case) is incentivized to send a GDPR data access request while this is not true for DMCA.
I agree however that they are both horrible laws. So if your argument was to show that GDPR is just as bad as the DMCA I agree. GDPR is a horrible law and it is not obvious to me that the law wasn't created specifically to target non European business.
The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction.
I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual legal threats and action. This just allows requests.
The DMCA helps big business at the expense of the general public. This does the reverse. It's no wonder there's been so much noise and scaremongering.
Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented.
>The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction.
Did I ever bring up litigation? What is your point here?
What is your point here? What is your point when you say that the EU is not litigious? Are you saying that I shouldn't expect to receive a fine for violating GDPR? Are you saying that I should just ignore GDPR data access requests if I am operating in a supposedly ethical manner and I am not selling user information?
a) They are doing the thing we have collectively decided is bad for society (misusing personal data)
b) Do nothing about this when somebody invokes one of their new legal rights, whether that be to retrieve the data you have on them or remove the data you no longer have a grounds under any of the six legal basises to store (which includes 'consent', which can be revoked, as well as five other bases which cannot be revoked but have more limited scope with what you can do with the data)
c) Be reported for this
d) Refuse to work with the compliance group
At this point, judging by how the EU has historically used fines as an enforcement mechanism, you're looking at a small fine designed as a wakeup call. The 20 million EUR figure (or % of revenue) is a _cap_, not a floor, and the EU has never gone for maximum fines except when it is obviously required to enforce compliance.
Since that's all this account has done and we don't allow single-purpose accounts here, I've banned it. Please don't create accounts to do this with.
"Can I have all my data?" is not new to GDPR. It has existed in previous data protection law. How did people cope before?
Getting sued in Europe is a huge deal, getting sued in the US is part of doing business.
The ICO is extremely reasonable and personable in my experience.
[1]: http://researchbriefings.files.parliament.uk/documents/CBP-7...
[2]: https://www.ft.com/content/afff45a0-1597-3f1c-a6da-79c3f61e6...
People send fake DCMA takedowns all the time.
If someone sends you a GDPR data request, you can ask for administrative costs. You can even ask it to be mailed to you via post. If someone sends you a bogus and unreasonable GDPR data request, you can ask them to pay you a further reasonable fee.
This can almost be an auto-response. Trolls will get bored.
> Work required for complying with a data access request: Search every single service you potentially could have stored user data in and provide it to the user. A non basic feature that requires custom development.
This is not true. Recital 62[1] says you don't have to give them any data they already have, and Recital 57[2] says you aren't obliged to determine which of your data identifies them if you aren't going to do it anyway.
[1]: http://www.privacy-regulation.eu/en/recital-62-GDPR.htm
[2]: http://www.privacy-regulation.eu/en/recital-57-GDPR.htm
> I agree however that they are both horrible laws.
I like the GDPR a great deal, and I think it'll be good for companies big and small in the long run. Disclaimer though: I'm doing some GDPR consulting, so you might prefer to think I'm getting paid to like the GDPR.
The scary bit seems to be for companies that approach compliance from the point-of-view of centralising understanding, and minimising the impact and costs of that compliance. They're looking for someone to tell them "this is enough effort", but the point is that Europeans don't want people playing chicken with their data[3].
As soon as companies realise that embracing the spirit of the GDPR is cheaper, it starts becoming a real opportunity for them.
[3]: https://www.sec.gov/Archives/edgar/data/33185/00011931251815...
"1 - The controller shall provide a copy of the personal data undergoing processing. 2- For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs."
Since you're allowed to respond to the first request with a list of the types of information you control, you should be able to do this without a search (and without undue costs).
Didn't a data subject sue Google and Facebook for billions on day one of enforcement?
"Three complaints worth €3.9 billion were filed in the early hours of Friday morning against Facebook and two subsidiaries, WhatsApp and Instagram via data regulators in Austria, Belgium and Hamburg. Another complaint worth €3.7 billion was filed with French data protection authority France CNIL in the case of Google’s Android operating system for smartphones." https://www.irishtimes.com/business/technology/max-schrems-f...
edit: To me, the difference between 'suing' and 'complaints' seems unimportant if the potentials fines from a 'complaint' could be so high.
GDPR however requires that you actively set up data auditing and security policies and practices which may break or otherwise require re-architecture of parts of your company. In fact that is it's purpose. If the company or organization is small enough, then it might be easier to abandon the project instead of being compliant.
In this guy's case he had an easy offramp to reddit, so he took it. Simple. However it does offer now at least one data point to show that GDPR has decreased diversity in data ownership and risk. The question is, are drone.io users better off now that they will be utilizing reddit?
Court orders take a comparative mountain of effort before they land on someone’s doorstep. They require someone to determine that there is a legitimate cause of action against the site, consult their attorneys/legal department as to the best course of action, research the case and produce enough evidence of their claims to hopefully convince a judge to give them the order they seek, then prepare and file the legal paperwork. In most cases, by the time such an order is issued, several people have invested dozens or hundreds of hours in the effort.
By contrast, sending a “nightmare letter” is a matter of copying and pasting, which can be done by anyone in just a few seconds. Even a small site like the one at issue here could easily receive hundreds or thousands of such requests per year that the owner is obligated to produce detailed responses to, under the threat of enormous fines.
This regulation was written in a way that made it ripe for abuse. We are seeing real-world abuse now, and we are barely a week into it. Shutting down and/or at least blocking EU traffic is entirely reasonable in light of the situation that GDPR has created.
Yes, that is the entirely correct mindset to have for someone who does not live in the EU.