Social is a great discovery tool, but you want to offboard these folks to contact and publishing systems you control (mailing lists, sms lists, Wordpress, etc) for the day that your page or other social page gets nuked.
Social is a great discovery tool, but you want to offboard these folks to contact and publishing systems you control (mailing lists, sms lists, Wordpress, etc) for the day that your page or other social page gets nuked.
It's not hard, or expensive. Simply get consent. (Of course, you won't get much personal information on people that way, but that's how it be sometimes.)
Here's an example of how you could do it:
> Hello! I'm setting up a mailing list. If you're interested in receiving occasional updates about what's happening in this part of the community, please put your email address in this form: https://thecommunity.example.eu.org./subscribe
> I'll send you a verification email so nobody else can sign you up. There's also a link there to remove yourself from the list, and you can email unsubscribe@thecommunity.example.eu.org. any time to remove yourself from the list. (I'll send you a confirmation email to let you know you've been removed from the list.)
> If you want to unsubscribe, please just unsubscribe. If you mark the emails as spam, it might send other people's copies to their spam, too, and it might be months before anybody notices. And if you have any feedback, do let me know.
" Example: An online magazine using a mailing list to send a generic daily digest to its subscribers.
Possible Relevant criteria: Data processed on a large scale.
DPIA likely to be required?: No "
GDPR is also harming European scientific research:
https://sciencebusiness.net/news/data-protections-rules-harm...
If central planning worked at making society function better, the Soviet Bloc would have flourished and leapfrogged the West. It doesn't.
Only because the laws grew up around giants like Facebook. Prior to social media, it wouldn't have been a problem at all. You'd have no trouble setting up a small forum, blog, or mailing list.
We're in the predicament we're in precisely because of Facebook.
There might still be a cheap way to accomplish GDPR compliance as a small band, artist, company, etc. It doesn't seem hard to manually implement right to forget / data portability on the small scale. It's bolting onto big, existing businesses with lots of processes already in place that is expensive.
- ask for permission
- do not collect more than you have
- store securely
- allow users to change or remove their data
- have a dedicated officer if you collect a lot
Is that really THAT hard? (If yes, then really you shouldn't be collecting any data.)
If it requires employing someone you wouldn't be otherwise, then, yes, I do think it is unreasonable to require that I hire someone if I am letting people give me an email address for the purpose of sending them an email in the event that <x> (assuming that I am verifying at the time they give me the email address that they have control of the email address in question), no matter how many people request to be added to the list of people to send an email in the event that <x> .
And I think that if you manage a mailing list of million of people then having someone who understand security implications of it and how much they can lose (even to a simple phishing at this scale) if you get that list accessed by scammers is necessary.
A few hours of training is reasonable enough, I suppose?
Seems like it might be simpler to just have whoever is responsible be liable for any problems that could arise from not keeping the list secure? I guess maybe an issue issue with that is that it would be hard to track down all the harms that actually occurred as a result of letting the list fall into the wrong hands, and also hard to even get a good estimate.
Now you have to coordinate ALL of it to support right to forget and data export.
You need an expert in each system to drop what they're doing for one to two quarters to figure out how not to break everything and support this new use case.
You need to synchronize the plan of action throughout all of the various orgs. Some party receives GDPR requests, and that now needs to trickle down to every service to handle and report back.
This is hugely expensive.
Millions of dollars.
You vastly underestimate the toll on existing legacy businesses.
You could simply put up a web page with a RSS feed.