An Eve Online corporation has been hit with a GDPR request from an ex-member
massivelyop.com
massivelyop.com
Perhaps some people will say "good, if you cannot run a site conforming to all laws of the land then you should shutdown". If you think that, consider this: as these laws pile up it will get more and more difficult to operate, leaving only the very tech/law savvy, and big business.
This is not the democratization of information that the web promised oh so many years ago.
On a semi-related note: if you are a small SASS operator wanting to comply with such requests, what are you meant to do about your DB backups that contain data that is meant to be forgotten?
[edits: punctuation/grammar]
Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of view. You need to make sure that deletion requests also get honored when restoring from backup though, so ideally you want to store the requests in a third system and check them when you restore backups.
Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO.
You might as well tell them that compilers can provide the functions necessary to comply.
If you are using software to process my personal data, and you don't know how to do that while protecting my personal data, then I'd like you to stop using that software right away.
This is where the GDPR has really helped me. I posted a comment on a blog critical of a government data sharing initiative. Nothing illegal, or questionable - it was a simple two sentence opinion comment which I posted under my real name. I didn't stop to think for a minute that it would cause me any problems.
It did. I discovered that I couldn't get to work on any government projects because when a background check was carried out on me, the above comment was found and according to Revenue (the gov agency responsible for such checks) it indicated that I was hostile to the governments IT plans.
I asked the blog owner (same country as me) to please remove the comment, they refused. So I submitted a right to be forgotten request to Google to stop the blog post appearing in searches for my name.
I'm not sure if the contract for Revenue is exactly the same as the civil service, but I would presume on this front it is very similar.
There have been three occasions where the IT contracting firm I was working for sent me to work on government IT projects as a contractor. None of them were for Revenue, but it is Revenue who do these checks for all other departments. On one occasion my employer managed to pull a few strings to get me on the project (DSP), on the other two I was told no government work for me (HSE and DoT).
On one of the three three occasions I was forwarded an email from Revenue that said "he expresses a desire for personal privacy that indicates he would be unwilling to fully embrace the governments data sharing strategy".
I did write to a few news outlets about this, none were interested. Even the ICCL wasn't interested, which really surprised me.
Well, that's kind of Orwellian.
- store as little data as needed - protect the data in state of the art ways - make transparent what you store and process and why - establish a process to delete data once it's not needed anymore
It is only complicated if you want to build a company around the abuse of data, as common in the ad world.
How about the duty to export user data on request?
How about player consent management? Consent updates, etc.
Those are not simple thing neither to implement nor to manage, especially if someone will accuse you and you need to prove that you are compliant.
Rolling backups, e.g daily and weekly, are fairly common. When the request comes in, just acknowledge there will be a time period before the deletion is fully purged from system backups - as is still legal post-GDPR. The user data will still be removed from production data, which is of primary concern.
But backups has to be stored securely, and the data within can't naturally be used if restored beyond exceptions.
If it's only due to technical skills then this problem can be solved technically.
The forum software needs to enable people to be GDPR compliant.
> On a semi-related note: if you are a small SASS operator wanting to comply with such requests, what are you meant to do about your DB backups that contain data that is meant to be forgotten?
This hasn't been tested in court, yet. But there are several possible approaches. Like delete on restoration or backing up in slices, so that the personal data becomes anonymous unless you have all the parts.
Don't forget that the "right to be forgotten" is not an absolute right. It doesn't trump everything else. Nobody would expect somebody to sue ESA for their "right to be forgotten" for a public message that they could send to ESA to put on a CD on a probe they sent into space and win.
First of all, it forces everybody involved with personal data to think about how they handle personal data and inform the users about that.
If you state "due to technical limitations, your personal data in backups can't be erased at the time of the request but will be deleted on restoration" up front during the signup of the user, this is already an improvement over the past where nobody knew what happened with their data.
Or just block EU traffic and ensure no seizable assets rest in the bloc.
For example, in the UK both of the above are law since 1998. And that only implements an EU Directive from 1995.
Sometimes I feel that the main effect of the publicity around the GDPR has been for many people to discover existing laws...
You record that these people need to be scrubbed if you restore backups, and you delete old backups.
The ICO has excellent guidance on this and other subjects:
https://ico.org.uk/for-organisations/guide-to-data-protectio...
> This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests
I can't understand what your question is.
There's absolutely no reason someone can delete spam from their public forum, but can't delete people's phone numbers from items that are pointed out to them.
If they have no search capabilities, and don't use a search capability, they're not required to create one.
The GDPR is extremely easy to comply with- European companies have been doing it for a long time (before it gained the force it has now) because it's largely a unification of existing data protection laws.
It’s really just a slight mental shift. Instead of seeing data as an asset see it as a liability. Once you do that everything comes naturally.
Some things are too dangerous to the public to allow part-time hobbyists to do. We don't allow part-time hobby doctors, or lawyers, or banks, or toxic waste disposal services, and most of us think that's the correct tradeoff. GDPR puts processing people's personal data in the same category; given how much damage a careless processor of personal data can cause, that seems appropriate.
Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. In practice this isn't a problem in most countries because there isn't enforcement against tiny operators either, but the fear and confusion it creates is very real.
(On the other hand, without this kind of thing you get phone companies selling your real-time location to criminals. If only there were such a thing as a sense of proportion)
I'd put it as: the decentralised social web cannot be allowed to exist unless and until a way to do robust privacy enforcement on it can be found.
> and heading in the direction of "the public cannot be allowed general purpose computers"
Slippery slope fallacy. GDPR exists not out of some abstract desire to regulate but as a response to the massive privacy breaches that have directly affected the general public. If and when general purpose computers are shown to have a similar negative effect on society, we can have a conversation about whether regulating them is appropriate given the costs and benefits of doing so.
Proportionality in the GDPR is based on the scale and sensitivity of your data activities. The size of your organisation or your technical capability is irrelevant; if you're not competent to safeguard the data you handle in accordance with the law, the EU doesn't want you to handle it. It's exactly the same principle we'd apply to toxic waste - you're not allowed to dump it in the woods just because you're a small business or a hobbyist.
Some examples of why there is no de minimis exemption:
A small charity accidentally sent a newsletter using "to" rather than "bcc". In doing so, it accidentally revealed the identities of 56 people who are HIV positive. It was fined £250 by the Information Commissioner's Office, because of the small size of the organisation and because the ICO was satisfied with steps taken to prevent further breaches.
https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...
A non-profit trade organisation with a single employee worked to facilitate information sharing between construction companies. That information consisted of files on trade unionists, political activists and advocates for health and safety, constituting an effective blacklist of "known troublemakers". The organisation's files were seized by the Information Commissioner's Office, leading to enforcement notices against 14 construction businesses; settlements under the Data Protection Act totalled over £50m.
The To/BCC one is both very important given the sensitivity of such data and a horrifyingly easy mistake for most organizations to make.
I understand that there's forums/websites run by people who have no idea what they're doing. And regulations like GDPR make sure that services they are using have baseline encryption and guarantees. Like, it should encrypt passwords and private data, don't store it if not necessary and have functionality to delete users.
It is not about people running the websites/forums, it is about software they are choosing to use. Baseline should not be "it works", but it should be "it works and provide reasonable level of security". I know it is some work on part of people who have no idea what they're doing, but ultimately it is up to developers to set up CMS and forum engines to comply.
It's probably the same reason why Hacker News does nothing to comply with the GDPR.
AggregateIQ could have ignored the GDPR-request, ignored any rulings and keep chugging along as long as they stuck to Canada (assuming Canada was not going to side with the EU).
In short, if you're not in the EU, do not care about EU and never will, you can largely ignore the GDPR. Same as if some banana republic dictator declares you persona non grata - if you never intend to visit and otherwise have no business in that country, who cares?
The difference is that the EU is not a banana republic (opinions may vary), and so many choose to respect and accept this their judgement in cases like this to stay on good terms.
That's not entirely true. You can go to a Canadian court to enforce an EU judgement against assets in Canada. So for example, if you cause a car accident in Germany, the plaintiff can sue you in Germany to get a judgement and then sue you in Canada to enforce that judgement. How Canadian (or US or otherwise) courts will treat a GDPR judgement remains to be seen, but it's not a guarantee that it won't be enforced.
Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law.
If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my company and granting the EU new global powers (such that I can provide the EU jurisdictional reach into the US so that it overrules or competes with US law). That isn't my decision to make if I operate inside the US jurisdiction. The US solely decides jurisdiction within its zone of political control. That is, the US has the final say legally in all regards in that case. I could choose to voluntarily comply with GDPR, however the EU has zero power to force me to. I can flip flop back and forth a thousand times, or not, it makes no difference.
If you ever find yourself wondering about these concepts, change the scenario to China. Under what scenario does the EU or US have power to dictate laws within China? None. It provides a perfect clarification every time. Nobody could possibly be confused about who is in charge of law within China.
However, isn't the idea of forfeiting the personal jurisdiction defense? I am not a lawyer, but from what I understand, once you start debating the merits of the case, you waive the ability to claim that the court doesn't have jurisdiction.
It seems like there's a bit of a chance of that here - once you admit the EU or Chinese legal system is the appropriate place to redress things, you've given up lack of jurisdiction as a defense.
If someone follows that request and if the EU has jurisdiction are orthogonal issues; plenty of services offered deletion before the GDPR.
The question of jurisdiction will come up if you ignore requests or otherwise violate the GDPR and a national agency that is responsible for handling violations contacts you.
In which case you can still choose to ignore them, if you're not on EU soil, then it's up to the extradition or similar laws on what happens; the agency will likely file a court case (or you file), then the court will handle out the details with your national legal system; in most cases this means nationalizing any punishment. Ie, the court case will be handled and if you don't show up after being invited, will be ruled upon in your absence. Then the fine will be forwarded to your country where the courts in your country with your countries jursdiction will then collect it, probably take a fee and then forward the remainder back to the EU. An alternative outcome would be that the entire court case is moved into your country.
Either way, complying to GDPR-related requests doesn't mean admitting jurisdiction of the EU; disagreeing the responsible government agencies involved is a good way to test if those have jurisdiction.
(FWIW yes I do have a law degree)
https://news.sky.com/story/huawei-cfo-meng-wanzhou-facing-ex...
> The global chief financial officer of Chinese phone firm Huawei is facing extradition to the US after being arrested in Canada.
> Meng Wanzhou, who is the daughter of company founder Ren Zhengfei, has been detained in Vancouver in relation to suspected violations by Huawei of US sanctions placed on Iran.
So not only do people have to avoid the U.S. to avoid being subject to U.S. laws, they have to avoid U.S. friendly countries too.
And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?
If I, as the prince of Princeton, was to pass a law that each time one of my subjects visits your website, you must pay me $1, you'd think that's mad. And you'd be right - since you're not bound by Princeton laws.
The EU is claiming that sites in other countries are bound by EU laws - and that's just as wrong as if Princeton passed the laws.
For isntance: Germany has laws around limiting usage of Nazi symbolism. If you create a web page glorifying Nazis and their symbols this is illegal under German law. If you run such a site targeting Americans no German state attorney or Court will take the case (exceptions exist for stupidity or ego or power play reasons) however if you host a page in the U.S. aiming at German Nazis that way (for example by commenting on German politics and German language) they will try to go after you. (Which might not lead far, as the site is probably protected by US freedom of speech, thus US authorities won't assist, but you might want to avoid travelling to Germany and countries which might cooperate with Germany)
P.S. I don't want to imply that you have any such plans for such a site, but it's a specific example working fully virtual
This idea is not new and certainly is not seen as unequivocally wrong in law.
If you produce libel against someone from another country, that person may sue you in their home country. That you performed the libel in another country is not generally seen as problematic to the libel laws of most countries. The US may refuse to recognize the judgment and you are fine as long as you do not travel to said country or a country with extradition agreements.
The GDPR is exactly the same. EU says that you have to comply with the GDPR if you process EU-citizen data. So company have the same choice: Comply with the EU GDPR or don't do business with the EU. I don't think it happen yet, and I think that the framework for this is not even ready yet, but nothing would prevent EU from banning your service in the EU if you don't want to comply with the EU GDPR.
I honestly don't understand why there is such an outcry about it. It always worked like this: you want to do business with a country, you apply the law of the country. Internet is not a magical international space with no regulation.
You can argue that this kind of laws, that is a form of protectionism in a way, is bad. But it has been this way for a very long time and GDPR is absolutely not the first time such a law was put in place.
Just another example, if you are a US citizen creating a bank account in the EU, the bank (even if it is a EU bank), will have to declare it to US authorities (apparently due to your tax system that also apply if you are resident abroad).
[1] https://en.wikipedia.org/wiki/United_States_sanctions_agains...
Re: GDPR, if a US or Canada based company does business in Europe, or has data for European users, they have to comply to European laws. Just like European online services have to comply with e.g. DMCA takedown requests if they want to do business in the US, or online services have to comply with Chinese censorship laws if they want to do business in China.
If you offer your services in the EU, you have to respect EU law.
Or do you plan to make all of your web services "respect" the laws of 200+ countries in the world, and for that matter all the sub-jurisdictions of those countries (such as states or provinces or cities) that have their own laws? The EU is not special in that regard, they're just one more jurisdiction that the service isn't hosted in.
As to jurisdiction, you can always sit in your home country and ignore any rulings against you from other countries so long as you are sure that your own country will not extradite you for such a thing (I am confident that Canada would not extradite a Canadian residence for such a thing). Just don't ever try to cross the border into a European country.
It set the precedent for arresting foreign national for breaching US laws while on foreign territory considerably before Sklyarov's arrest in 2001; some notable prior examples include Humberto Alvarez Machain (1985) and Manuel Noriega (1989), though they weren't the earliest, either.
Insofar as Sklyarov's case was notable, it was more because the charged offenses were completely legal where they occurred, not because they were allegedly committed by a foreign national outside of the US.
I am genuinely curious because in that case GDPR seems to impact many companies disregarding whether they actually do any business here.
If you offer a French or Spanish translation: maybe
If you run ads in Germany: certainly
If you advertise accepting Euro: most likely
If you embedded ads from an ad network which sends localised ads to Europeans: most likely
When having a site reporting news on local events in an African municipality most likely not.
There is no clear line, as writing that down is impossible and always requires judgement. Also the question is whether EU can enforce it. If you have no European subsidiary and live abroad there is little they can do.
I don’t outright disagree, I don’t think it’s settled or even established yet.
Mail is probably going to be a big precedent. Everything from play by mail chess to ordering from Sears will have to be considered.
If I was them I would just send the person their login profile and delete that from the site. Everything else is excepted, including backups which are kept for security.
A good community example to look at is Wikipedia. I will star to worry if and when I see them start deleting profiles and articles. Until then I see this kind of articles like a bit of scared interpretation of how nations might implement and apply GDPR.
Person B describes person A without mentioning a name, eg by describing person A in a way which is recognizable. (eg the pilot that shot down the death star.)
The first is at least searchable...
- https://gdpr-info.eu/art-89-gdpr/
- https://gdpr-info.eu/art-85-gdpr/
Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.
Devil meet details
In particular the NYTimes reports on Joe Baddy doing something bad. That article arguably belongs to the NYTimes. Google indexes that article with permission from NYTimes. Right to be forgotten requires Google remove the link to NYTimes even though neither Google's index nor the article at NYTimes belong to user.
I've tried playing Eve quite a few times, and it just isn't my thing. Reading about Eve, however, has always been an absolute joy.
Even comments like this (which makes complete sense in hindsight) shows me how much (for better or worse) people put into a "sandbox" or game like Eve.
I swear some of the stories are much better than the stuff they toss in theatres.
They can require you to prove this before processing your application, under GDPR.
Honestly, it sounds like it should be legal. Like the way ADA or CEQA trolling is. After all, that provides a valuable function.
The GDPR is actually quite simple to comply with for most people: European businesses have been doing it for years since the GDPR is largely the unification of various data protection regulations.
I suspect as more people learn that, that trolling business will fall by the wayside...
GDPR Deletion Requests only cover data for which's processing you either used consent, used the legitimate interest clause or is part of a protected category (sexuality, religion, etc.). Some parts of "legitimate interest" that continue to be legitimate interest (like for example, billing information for tax and fraud prevention) you may continue to keep it around as well.
There's no way to identify that the person making the request is who he/she says he/she is. The irony is that for services like Facebook, Facebook could ask for a scan of your id/passport to confirm it's you, (and would it also have to keep that scan saved somewhere in case it later needs to prove that it "authenticated" the gdpr request correctly?)
But in this case, how to determine it's really the user? Should "Bob" identifies himself by disclosing his password, and have the admin test of the login works?!
And yes, there is a need to verify IDs. Most companies don't have online forms for this so the way has always been to send an email and enquire, or to write on paper with a copy of a valid ID.
This is not new.
The question is whether data submitted under a pseudonym (e.g. forum activity) are actually personal information by law since the individual cannot be identified.
That's one way to do it.
Another way would be to ask them to log in and set some preference (change their info field or name to "DELETE ME") or something like that.
It really should be automated anyway. PII for billing and contractual reasons isn't covered by the right to be forgotten (as I read the regulations) because they're required for other legal reasons.
To wit, Article 25 of the GDPR ("Data protection by design and by default"):
> 1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
> 2. The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
If you suffer a data breach you have to disclose this, and you are potentially liable for it if you could've protected users from that breach by technological means (applying patches, salting passwords, encryption, and so on). If your breach includes too much personal data() this could be serious.
If you think you want to keep data forever, then your liabilities for that data extend forever. You should consider if this is really what you want, or if you might want to simply delete old backups and scrub identifying information after some time.
() The regulator will evaluate this by considering how the people that personal data is about will be affected. This is a difficult question to ask -- a chan user might at worst suffer potential embarrassment being linked to posts, so I suspect the regulator will view loss lightly, unless it could easily and reasonably be prevented.
The ICO has really good guidance about this on their website:
Embarassment? People lose their jobs in America for espousing commonly-held conservative views. They can be arrested in Europe for the same thing.
That being said, if your "chan" provides a safe haven for illegal behaviour, you might have other non-GDPR problems as well.
>‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
An IP address or tracking cookie is an identifier. It is not, in isolation, personal data. The other stuff you store like posts and access logs become personal data if those identifiers allow you to associate that stuff with a natural person. If you strip the data of identifiers to the extent that it can no longer be connected to anyone, then it ceases to be personal data within the scope of the GDPR.
“blindsided” bullcrap again
We have very little user data, just an email address and a name, and no tracking. Of course we have much more information about staff.
That's going to be a common situation, especially for non-tech or offline businesses.