Using GDPR to obtain one’s data as JSON
mazzo.li
mazzo.li
"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."
Which means that if e.g. a bank declines your mortgage application based on a decision from a fully automated system you have a right to have a human being review it.
Interestingly this made banks reluctant to use AI and helped with efforts in development of so-called "explainable AI".
If you make a machine learning model explain itself to humans, you open the possibility to challenge the model's conclusion. It's not just the question of whether the model does its math right - it also means we, as society, can say, "I see your math and it works out, but because $POLICY, you're not allowed to take these inputs into account". It means adding control points to a previously opaque process.
what i am wondering is though if this can't be used to everyones benefit.
apart from neding a human to verify a decision, how about, if the human and machine learning decision disagree, then the consumer gets the right to appeal for a second human review?
Of course I document my export format too so others can do the same with data from my app: https://github.com/TheLastProject/Catima/wiki/Export-format :)
The sad part is the allowed 30 days timeframe. Stocard really abuses this to make you wait as long for your data as they legally can make you wait: https://twitter.com/SylvieLorxu/status/1389343401435439112
List of local DPAs: https://edpb.europa.eu/about-edpb/about-edpb/members_en
That said, where does the GDPR stand when there is an API already in place that allows for data extraction?
GDPR doesn't require me to become a user to get my data.
1. There would be entitled to ask for a form of ID in order to verify your identity.
2. Even if they are confident that you are really John Doe, how do they know that a mention of "John Doe" in all the data they have really means you, and not someone else?
At some point it becomes too difficult and time-consuming so the easiest is to decline the request on the grounds of an exemption.
Hmm, wouldn't that you in trouble rather than github?
If i write a biography about you, can you GDPR your way to a copy of the book from amazon?
It is reasonable to assume that FOSS licenses also cover the commit.
IMHO at this point the transaction is more comparable to you selling your personal diary on ebay, you have no right to force the buyer to destroy it under the GDPR
https://todoist.com/help/articles/backups
I use the free plan, don’t reside in Europe, and recently wanted a backup. If you’re in the same boat, I recommend the following project — it has good documentation and immediately worked.
I've been delaying allowing whatsapp from sharing my data with facebook for a while now, but last news is that unless I give in to the extortion, I won't be allowed to send and receive messages to my contacts.
I'm going to request all my data to Whatsapp using GDPR before switching all my conversations to Telegram, I guess.
I had to use some unofficial software ( https://www.wazzapmigrator.com/ ) to extract and store the messages from an unencrypted iPhone backup. Then you have everything in an sqlite file.
I was just looking through my google drive and there's no trace of my whatsapp chat backups. Even after running another backup. And pages online confirm what you're saying.
I guess I'll have to use my GDPR rights.
Interestingly enough, there only is the possibility of exporting account information info, but the information page about that procedure explicitly says that messages are not included.
That's relevant because since there's no other procedure to export data, this means that Whatsapp is already not okay with GDPR procedures.
edit (2): I just sent an email to Whatsapp via their contact page (https://www.whatsapp.com/contact/?subject=messenger) asking for my data in accordance with GDPR. Let's see what happens.
No, you have your messages on your phone. You just don't have your messages in a way you want.
Personally I would like a global export option too, but I am not going to die on that hill.
No it doesn't, the data is local to your phone and not in their systems or servers. So you already have your data on a device you control. GDPR is not about local data inter-op.
If e.g: MSN messenger had the same strategy, you would one day find yourself without the ability to backup your messages.
not everybody values past conversations the same way - but i have a few that have emotional value to me and don't want to lose them if e.g: my phone gets stolen or whatsapp loses popularity and shuts down one day.
edit to add: the automatic backups IIRC are unencrypted. I don't appreciate google having that. Why can't i choose my own backup target if the functionality exists?
The annoying thing thoug, absolutely on whatsapp side, is that I have to export chats one by one.
Shouldn't I be enabled to extract my own backups, on my own gdrive, to read my own chats ?
Spent way too long diving into that rabbit hole one time when I switched phones, activated WhatsApp without thinking about it on the new phone (and didn't restore, or switched back and forth, or something) and refused to go on with a history split between two devices. Eventually managed to merge the databases, put it on the new phone, and reinstall (since you can only restore during first-time startup...). Absolutely not worth the time it took, but I was stubborn.
I'm not saying that isn't shit, or that WA expects you to do that, just that if you want to, it can be done.
this is news to me - i will definitely be using/chasing this lead to get my data, thank you!
However, a positive aspect I don’t hear talked about enough is how it has had a chilling effect (in the most positive pro consumer way possible) I’ve noticed in my industry people are just much more careful about user data now, compared to it hardly being talked about before GDPR. Just the threat of those fines has scared C levels enough to put at least some engineering resources on privacy and security where there was much less before from my experience.
Only necessary ones don't need consent, but the bar for "necessary" is high: the software wouldn't be able to function without it and there's no way to implement the software without it. Think: "address" is necessary for "delivery".
Even then you still need consent to store the cookie under most versions of the "Cookie law", which is a complementary but different thing to GDPR.
I don't think the cookie law is different from GDPR in that respect. IANAL, but from the EU directive itself [1]:
> Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information [...] and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
I read that as having the equivalent "no consent required for strictly necessary data" get-out clause to the GDPR. Yes, strictly necessary is a high bar, but for cookies that clear that bar I think both GDPR & the cookie law let you off the hook.
[1]: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
Yup. That's literally the point. Phrased in an equivalent form: cookies that require consent are ones you don't actually need.
It's thus not GDPR's fault that a site opts to spam their users with a consent popup - it's their choice to include cookies that aren't required to provide the service.
Same with blocking a script that sets such a cookie. Most cookies are not needed for providing a service.
edit: see the article 29 data protection working party guidelines here: https://ec.europa.eu/justice/article-29/documentation/opinio...
The top comment in this thread demonstrates that as well as the Data Protection Directive of 1995 had a functionally identical requirement allowing users to opt out of completely automated decisions for credit purposes.
I would claim the only way to make a webapp with login securely function in a usable manner is to use a session cookie with secure transport policy. Do you really need more than that?
See 3.2 in data protection working party recommendations: https://ec.europa.eu/justice/article-29/documentation/opinio...
Myself, I wish another GDPR iteration would instead mandate the shape and form of the initial consent popup, requiring it to fit to the following template (or something similar/equivalent):
+------------------------------------------------+
| Allow additional data collection? [X] |
| |
| This site would like to use technical means |
| such as cookies and local storage to collect |
| data about you and your computer. This data is |
| not necessary for the correct functioning of |
| this site, and does not impact the service |
| it provides. |
| |
| Do you consent to this opt-in data collection? |
| |
| GDPR requires this message to be shown because |
| the data collection requested is not necessary |
| and may carry data privacy risks. Necessary |
| data collection does not require consent form. |
| |
| [Learn purposes and] [>I do not consent<] |
| [configure consent ] |
+------------------------------------------------+
With an explicit [>I do not consent<] button, pre-selected, in the "call to action" color, doing the same thing as [X] does, which is declining data collection described. Displayed in the same language website content is, and with specific regulations guarding against the common "dark pattern" bullshit. I'm sure Brussels has some webdevs that would be happy to provide standard templates and React components and whatnot, so that site authors could just plug in a stylesheet and a JSON blob to configure the [Learn purposes...] section.The ultimate solution would be for member states' DPAs to get off their collective butts and start issuing fines for the current crop of blatantly illegal consent popups, but in the interim, it would be helpful to regulate the popups, so that they clearly communicate that a) they're requesting strictly unnecessary tracking that can be safely ignored, b) showing an annoying popup is a choice by the website owners, who decided to request consent for additional tracking.
This is kind of what I was getting at.
I think there would he subtleties to the user interactions though - I might say yes to marketing cookies if I knew not accepting it would lead to a degradation of service on some sites, but not for every site.
Driving a standard that can manage that kind of thing might be something regulators simply aren't up to.
Other sites might, for example, use your current location to display the local weather, which isn't required (you can type in your city in the search bar) but would be prefered by many.
A better solution would be to have the browser ask once, globally, on first install and then send the DNT after that. Any attempt to circumvent anything would be an instant fine.
To do this you would need to provide the legalese for that in some standardized way so the browser can pop up some UI that allows users to review that and approve/reject that. It should simply refuse any kind of cookie until the user has approved. That approval should be removable as well. Part of that should also cover having a sane API around that so sites can decide if they need to fall back to displaying their popups for this. Browsers that support this could even start defaulting to block all forms of cookies until explicit permission is in place for a website, regardless of existing UI. Many users have extensions that do this.
Wouldn't be the worst idea. Of course the flip side is that it also makes it easier for users to say "no" a lot (I would). And there is the notion that this may be a grey area under the current legal text. And of course some browser vendors have vested interest in the whole cookie & tracking business (Google).
My company and all the sites that I use didn't decrease data collection by a bit. They just added consent form in place of T and C. I would like to hear any counterexamples though, that some company actually stopped collecting data that they were collecting before GDPR.
What's the best strategy for exporting _all_ whatsapp messages on a device to a format that is readiable without whatsapp? - the export functionalities i've tried work with a message cap or other limitations.
Otherwise, they involve emailing yourself conversations one at a time.
I _think_ this is region dependent, but would like to hear from others.
It's readable without WA, though obviously proprietary in the sense of the structure of it, but it is just sqlite, you can then dump it out however you want.
I still managed to get all the 8 years of comments.
Any other information, anything else, like Year of movie would have helped. Instead I spent literal hours adjusting my data in Letterboxd’s fantastic import tool.
Do note that nobody actually knows* if what I'm saying is true, but that's just another problem of GDPR
But I guess it's good this guy found yet another way to recover lost data?
Is it? I'm the marketing manager of a European app publishers with around 5 millions active monthly users (and many times more if we account for the SDK that we license to other developers). We operates cloud services as part of our offering too. We find it very easy to comply with GDPR.
As for me, I'm very glad as the end users to be protected by GDPR. I've had my data deleted or unpublished about a dozen times since the law has been enacted. And all the people around me are far more careful with how they share their data (and mine! e.g switching to Signal vs Facebook Messenger, or ProtonMail vs Gmail...).
I keep making the same settings over and over again with different websites. That should not be necessary.
He wanted a backup he could control in case he loses his account, he gets banned or the company dies.
Sometimes a data loss can be quite liberating.
Also the service provided the active tasks as an export so same workflow could be copy-pasted and you update the SQL to include completed tasks too. The issue probably is that the priorities are different and implementing this would mean managers, designers and other "experts" would need to agree first.
IANAL, but this sounds to me like you are entitled to receive only the personal data of yours in a machine-readable format, not _everything_ you entered.
puts this in context. Personal data is everything that is connected to the person requesting it.
When companies like github.com do not follow the GDPR and do that notoriously I am sure the fines can be raised by the administrators without changing any laws. As you can see here https://www.enforcementtracker.com/ there are actually some juicy fines already. I mean 50.000.000 EUR is not much for Google but still better than nothing considering "Insufficient legal basis for data processing" was not even a real issue before GDPR.
BTW this is also a nice GDPR fine reason: "Insufficient technical and organisational measures to ensure information security" (e.g. British Airways was fined with 22 million).
I never did that, but did file a complaint at your national Data Protection Authority? https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Yea, it got forwarded to the Dutch authority because they're based in Holland. It took almost 2 years for the entire process. Basically the dutch couldn't really care and didn't understand the techincal facts of the matter and just believe Github's legal team when they said code is not personal data without knowing each commit has my name and email. The account has my photo and name. And that I was doing a personal data request and export request. Because my national agency had to forward it I couldn't file an appeal because my national agency just forwarded it and didn't actually do anything or make any decision they just relayed the decision.
For me, the key take away was I asked for all information they had that was relating to me. They said no and the dutch authories thought that was a-ok.
> take legal action against the DPA - If you believe that the DPA has not handled your complaint correctly or if you aren’t satisfied with its reply or if it doesn’t inform you with regard to the progress or outcome within 3 months from the day you lodged your complaint, you can bring an action directly before a court against the DPA.
There are debates as to what "relates to" (wording of GDPR) means, and that seems to be open to interpretation depending on context and data. Unless there is a definitive decision on this, I think it is reasonable to claim that source code is not personal data.
This brings to mind a few questions.
1. If a site stores multiple copies of a particular piece of personal data, let's say an email address, do they have to give you every instance when you ask for your data, or just tell you that they have your email address?
For example, if I use email address as an account identifier, so it is used as the primary key in the Users table in my database, and as a foreign key in my Purchased table, do I have to say send something that says your email address is in 1 row of one table and 13 rows of another table?
2. If I have to give back copies of your personal data that is in content you uploaded, what if that content contains personal information of other people, too?
If you had let others commit to your private GitHub repo, for example, their personal data would be in there. If GitHub has to give your commits to that repo in response to your GDPR request, do they have to filter them so that they only return the commits you committed?
What if I submitted an issue, you committed a fix, and in the commit message you thank me by email address for diagnosing the issue? Does GitHub have to remove my email address from the copy of the commit message when they respond to your GDPR request?
3. What about services that provide storage but don't process the content of that storage except to keep redundant copies or backups to protect you from hardware failure, such as Dropbox or Amazon S3? If I ask Amazon for personal information on me, do they have to figure out that you uploaded your contact list to S3 and my name, email, and phone number are there and tell me about it?
1. How the data is stored is irrelevant. Again personal data refers to data connected to your account. So if they store a history when and where you logged in, they have to provide it. When you upload stuff, they have to provide it. When you star a repo, they have to provide it.
2. They have to filter data out that is not ought to be seen by you. A Repository is a special case since it is not simply personal data. Think about giving a contractor temporary access to your repo etc. GDPR tries to enforce reasonable data compatibility between platforms ("Right to data portability"). This is orthogonal to personal data collection.
3. No. It's the responsibility of the services that use S3 to manage this. The operators are the controllers in this case. They also have to ensure that Amazon does not process the data they store on AWS S3. Eventually they have to make this agreement even part of the contract with the persons who they provide the service for.
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
AFAIK a personal to-do list would be "relating to an identifiable natural person" as the database will have a relation from this data to the account, which will likely have a name, email address or other PII (directly or indirectly).
IANAL
I think this is not correct.
AFAIK it's not transitive, but you can request any company directly. I think there are even people trying this randomly.
As long as it's data about you, you are allowed to request it. When you sign an agreement that your data may be transferred to another controller (and there is no other way this data may be transferred), you are totally entitled to ask this controller for your data.
For subprocessors it's different - they should send you back to the top-level controller for the data request. The subcontroller might not even know which data they have is actually connected to you, eg AWS is not going to figure out the schema of an RDS instance. But the controller is required to have an agreement with the subcontroller to be able to get them to cooperate to processing your requests.
(that's partly what all those data processing agreements that subprocessors and controllers have to sign are about)
You'll find nearly every time they use that.
I would claim this paragraph will side with the employee in dubious cases (see the article): "To use the legitimate interest allowance, employers must perform a privacy impact assessment balancing their legitimate interest against the employees’ privacy interests. The hard part, this must be documented to demonstrate that the employer’s legitimate interest does outweigh the employees’ rights. The next step that employers cannot overlook is that, even if the employer has a basis to process employee data, the employer must then provide notice to the employee that spells out exactly what data the employer is going to collect and what the employer is going to do with it."
Making a request like this is a borderline unethical waste of someone’s time.
The mindset change that needs to happen in our industry is that companies should build this into their products by default. "Download my data" should be a feature that is simply planned and built. Just like "permanently delete my data" is not optional either. It's not even that hard to build mostly. It's only hard if it catches you by surprise, which these days is poor planning more than anything else.
In Europe, and Germany especially, you can just expect people to do GDPR requests just because they can. We've had that happen right after GDPR became a thing. And you are legally required to be ready for that and respond in a timely fashion. If you want to do that manually, that's your problem. Small startups get a way with that. At some point it becomes annoying and you just fix it properly. Up to you when you do that.
These regulations just further enable monopolies and make it more difficult for diverse entrepreneurs to get into the game.
I’m just saying to be mindful that you might be costing a small business an enormous amount by making these types of requests.