IANAL, but this sounds to me like you are entitled to receive only the personal data of yours in a machine-readable format, not _everything_ you entered.
IANAL, but this sounds to me like you are entitled to receive only the personal data of yours in a machine-readable format, not _everything_ you entered.
puts this in context. Personal data is everything that is connected to the person requesting it.
When companies like github.com do not follow the GDPR and do that notoriously I am sure the fines can be raised by the administrators without changing any laws. As you can see here https://www.enforcementtracker.com/ there are actually some juicy fines already. I mean 50.000.000 EUR is not much for Google but still better than nothing considering "Insufficient legal basis for data processing" was not even a real issue before GDPR.
BTW this is also a nice GDPR fine reason: "Insufficient technical and organisational measures to ensure information security" (e.g. British Airways was fined with 22 million).
I never did that, but did file a complaint at your national Data Protection Authority? https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Yea, it got forwarded to the Dutch authority because they're based in Holland. It took almost 2 years for the entire process. Basically the dutch couldn't really care and didn't understand the techincal facts of the matter and just believe Github's legal team when they said code is not personal data without knowing each commit has my name and email. The account has my photo and name. And that I was doing a personal data request and export request. Because my national agency had to forward it I couldn't file an appeal because my national agency just forwarded it and didn't actually do anything or make any decision they just relayed the decision.
For me, the key take away was I asked for all information they had that was relating to me. They said no and the dutch authories thought that was a-ok.
> take legal action against the DPA - If you believe that the DPA has not handled your complaint correctly or if you aren’t satisfied with its reply or if it doesn’t inform you with regard to the progress or outcome within 3 months from the day you lodged your complaint, you can bring an action directly before a court against the DPA.
There are debates as to what "relates to" (wording of GDPR) means, and that seems to be open to interpretation depending on context and data. Unless there is a definitive decision on this, I think it is reasonable to claim that source code is not personal data.
This brings to mind a few questions.
1. If a site stores multiple copies of a particular piece of personal data, let's say an email address, do they have to give you every instance when you ask for your data, or just tell you that they have your email address?
For example, if I use email address as an account identifier, so it is used as the primary key in the Users table in my database, and as a foreign key in my Purchased table, do I have to say send something that says your email address is in 1 row of one table and 13 rows of another table?
2. If I have to give back copies of your personal data that is in content you uploaded, what if that content contains personal information of other people, too?
If you had let others commit to your private GitHub repo, for example, their personal data would be in there. If GitHub has to give your commits to that repo in response to your GDPR request, do they have to filter them so that they only return the commits you committed?
What if I submitted an issue, you committed a fix, and in the commit message you thank me by email address for diagnosing the issue? Does GitHub have to remove my email address from the copy of the commit message when they respond to your GDPR request?
3. What about services that provide storage but don't process the content of that storage except to keep redundant copies or backups to protect you from hardware failure, such as Dropbox or Amazon S3? If I ask Amazon for personal information on me, do they have to figure out that you uploaded your contact list to S3 and my name, email, and phone number are there and tell me about it?
1. How the data is stored is irrelevant. Again personal data refers to data connected to your account. So if they store a history when and where you logged in, they have to provide it. When you upload stuff, they have to provide it. When you star a repo, they have to provide it.
2. They have to filter data out that is not ought to be seen by you. A Repository is a special case since it is not simply personal data. Think about giving a contractor temporary access to your repo etc. GDPR tries to enforce reasonable data compatibility between platforms ("Right to data portability"). This is orthogonal to personal data collection.
3. No. It's the responsibility of the services that use S3 to manage this. The operators are the controllers in this case. They also have to ensure that Amazon does not process the data they store on AWS S3. Eventually they have to make this agreement even part of the contract with the persons who they provide the service for.
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
AFAIK a personal to-do list would be "relating to an identifiable natural person" as the database will have a relation from this data to the account, which will likely have a name, email address or other PII (directly or indirectly).
IANAL
I think this is not correct.
AFAIK it's not transitive, but you can request any company directly. I think there are even people trying this randomly.
As long as it's data about you, you are allowed to request it. When you sign an agreement that your data may be transferred to another controller (and there is no other way this data may be transferred), you are totally entitled to ask this controller for your data.
You'll find nearly every time they use that.
I would claim this paragraph will side with the employee in dubious cases (see the article): "To use the legitimate interest allowance, employers must perform a privacy impact assessment balancing their legitimate interest against the employees’ privacy interests. The hard part, this must be documented to demonstrate that the employer’s legitimate interest does outweigh the employees’ rights. The next step that employers cannot overlook is that, even if the employer has a basis to process employee data, the employer must then provide notice to the employee that spells out exactly what data the employer is going to collect and what the employer is going to do with it."
For subprocessors it's different - they should send you back to the top-level controller for the data request. The subcontroller might not even know which data they have is actually connected to you, eg AWS is not going to figure out the schema of an RDS instance. But the controller is required to have an agreement with the subcontroller to be able to get them to cooperate to processing your requests.
(that's partly what all those data processing agreements that subprocessors and controllers have to sign are about)