I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated.
Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.
I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated.
Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.
This is made even more frustrating by that at least I find GDPR to be not very precise. There are lots of corner cases where it's not clear if some data is covered or not. The strictest interpretations would easily obsolete / criminalize vast majority of ALL software that people today absolutely depend on for their daily lives - like various financial backbone systems - and which largely predate the GDPR.
It's hard to not find the regulation a joke - sadly. While GDPR is not precise, I won't even go into the details about the ridiculous cookie law and the braindead portions of the new 2019 digital copyright directive (that French publishers lobbied in to hurt Google News). If GDPR left you in doubt, that idiocy really showed that these EU bureaucrats are completely out of touch with the reality in the field of technology they want to control.
In order to get a fine you have to act evidently in bad faith or to lose your users’ PII or credit card information.
People don’t get fined billions because a legacy system saves an email address in the wrong table.
- GDPR-like legislation existed in most EU countries waaaaaay before GDPR.
- It was known for years that GDPR is coming.
- GDPR specifically gave companies two years after going in effect to get their act in order.
- We are now 4 years after GDPR went in effect.
If you're still complaining that it's "a drakonian law that doesn't let your company do haphazard PII processing aka collecting PII wholesale with no consent", then you company deserves to be sued and fined out of existence.
I think this is an extremely poor excuse. You're basically saying they don't understand their systems well enough. It is like a chemical company blaming environmental legislation when they've left barrels of polluting chemicals all over the place and not kept track of them.
Yes, this makes many, sometimes ideotic things, illegal. But not I also cross a red light on foot from time to time and I do not think it should be made legal. Regulations that leave a freedom what to prosecute are not bad by design.
> But not I also cross a red light on foot from time to time and I do not think it should be made legal. Regulations that leave a freedom what to prosecute are not bad by design.
This is not comparable as private citizens are able to petition and sue under GDPR. Hence, there is no similar discretion of what actually gets prosecuted as for jaywalking. It would be comparable if I, as a driver of a vehicle, was able to take any jaywalker to court. Which would be indeed complete madness.
That’s actually very clear and a simple example that anybody with passing familiarity can answer - and specifically you do nothing, since there is no right to erasure in this case. The “right to be forgotten” only applies in specific circumstances, under article 17: https://gdpr-info.eu/art-17-gdpr/
You have a legitimate interest in keeping server logs, so your responsibility is basically to have a clear and justifiable policy for why you are storing it, store it securely and for a reasonable time, and to make subjects aware of all this.
It’s way less complicated than you’re making out.
This is an inversion of the rule for legitimate interest processing, where the processing is legal unless there is an overriding interests, rights, and freedoms by the data subject. Basically, in the middle ground where neither set of rights and interests clearly override the other, the controller can legally process, but can also be forced to delete via the objection mechanism.
The fact that there is little clear guidance as to in what circumstances one set of interests, rights, or freedoms should override legitimate interests or vice versa, it does make this area of the law basically come down to somewhat arbitrary decisions of the relevant DPAs.
Recital 47 seems to suggest that for the normal direction of overriding interests, most situations where the average person would not be surprised/annoyed if informed about this processing in the specific circumstances is likely to be be permissible. But with Art 21(1)'s reversed burden, the guidance is simply "It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject." No guidance at all about how much or low little this differs from the what is permissible via Art 6(1)(f). Clearly some difference is intended since the wording is clearly reversed from Art 6(1)(f).
It leaves legitimate interests processing (which is by far the one of the most common processing reasons, and probably is common than all the other lawful reasons combined) as basically a giant minefield until the DPAs have established enough "case law" (for lack of a better term) to make sufficiently clear how they balance these competing interests and rights and freedoms.
In which case is the IP address in the access log helpful?
And that's just one small aspect of becoming fully compliant, there are millions of other types of surprising data that can be PII, and hence a liability, under GDPR. Email and IM apps, like Slack, are another interesting conundrum. Under GDPR, a customer should be able to request that all emails and Slack messages that contain/discuss his/her personal information must be a) discoverable and b) erasable. How do you even begin to solve that is beyond me..
For GDPR and any other law that enforce something on you, that it has to be reasonable for you to comply. So in my personal interpretation any data you provide and identifies should be auto deletable (a post linked to your account). If I post your PII and you request HN to delete it - they are required to delete it.
I don't think GDPR is too crazy .. but some people try to scare others because they scare to change because of making less money, ..
You don't, nor would you be required to, assuming those logs are being collected for a legitimate non-profiling interest, like detecting abuse, and are only kept for as long as reasonably necessary.
Lets take a look at the cases in which right to be forgotten even applies:
> the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
This would be fair enough if you are keeping the data for longer than necessary, but if you are doing so in such a scenario, you are almost certainly in violation in other ways.
>the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
Not consent based processing, so inapplicable.
> the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
22(2) is direct marketing related so inapplicable. 21(1) is interesting. It allows for subjects to object to legitimate interest processing. The controller must cease processing (including storage based "processing") the data upon such objection "unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims".
But it would not be hard to show that log data important for abuse prevention overrides the interests, rights, and freedoms of the subject here. We are talking about data that is almost certainly not particularly revealing or sensitive to the subject, with a relatively weak personal identifier (IP address), that is not publicly visible, that will automatically be deleted once it is too old to be relevant for such purposes. (probably after only one or two months). We are not talking about say a publicly available archived news article that mentions the street on which the subject lives or anything like that.
>the personal data have been unlawfully processed; >the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
Neither of these would be applicable.
>the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).
Ok, if you are running a social network, or youtube or something, and the data subject is a child, but they are either over the age of 16, and under it, but had parents consent on their behalf, then technically these logs would fall under this bullet point, and would need to be deleted. Art 8(1) only applies to procesing by consent, but if such consent were given these logs would obviously be related to the offer of such services. This scenario is not really what was intended though, and is poor wording in the law. (The law has a lot of poor wording!).
The idea here looks like it was supposed to be that Children's data processed by consent must be deleted if consent revoked, even if you still retain other legal grounds for that processing. Normally those other grounds would let you refuse to delete the data, but because ramifications of providing data under consent may be unclear to children, they get to revoke it more strongly than adults.
One question I've always had with this is whether it counts as personal data if it can only be de-anonymized by combining it with other data. So Company A manages some subset of a person's data.Company B manages a different subset (different app or whatever). Individually it is completely anonymous but if you combine them, it's trivial to de-anonymize.
Is this covered by GDPR? Both companies? What if one company dissolves and that data set is deleted?
Obviously a contrived example but an interesting thought experiment, I think.
Honestly, the main thing it revealed is how little value a particular segment of the technology community places on protection of individuals' data. It's actually hard for me to think of any better example of regulation that is designed and written to be in-tune with the technology involved.
Wasn't this called out repeatedly over the years and obvious from the start? That a double forum shopping model will produce paperwork and voluntary compliance, in cases where the offender literally didn't know they were misbehaving, but little real action?
[1] https://www.heise.de/news/Kein-Bussgeld-fuer-die-Datenpanne-...
This is the problem of German regulators being too cozy with incumbents. (Also see: Wirecard.) It's related, in that if you're one of the incumbents a regulator is cozy with, you're going to fight to switch forum to Germany. But it's a different problem with different solutions.
https://techcrunch.com/2021/12/20/facebook-transfers-impact-...
https://noyb.eu/en/irish-dpc-burns-taxpayer-money-over-delay...
(DPC = the official Irish body who should be responsible for enforcing GDPR… in bed with Facebook instead. Somewhere between shameful and criminal.)
Speaking as an Irish person, it's probably more accurate to say that the DPC is woefully under-resourced, and FB are super litigious so its more the government haven't given the DPC enough resources to do their job.