Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.
Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.
Yes we should. But there are a few too many systems, and we add and drop systems with such regularity that it would still be a non-stop engineering challenge.
>stop collecting
For the few records we do return as part of GDPR requests, they are usually associated to customer and billing data. I don't know how you run a business without that.
> eu citizens wont have such a fee.
They do and it's collected in the cost of higher product costs.
A majority of requests are actually this way - people use online services that submit blanket removal requests.
$100 for an occasional person? No biggie.
Potentially infinite? That's a bit more than normal overhead.
While we haven't seen this sort of DDoS attack through our GDPR process yet, the potential is already there if bad actors or competitors wanted to exploit it.
https://www.techrepublic.com/article/how-to-request-your-per...
>Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.”
Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.
Almost always to the dismay of one party, and sometimes to the dismay of the general public.
Courts rule on the evidence provided. If a user challenges the fee, the company can easily document where every penny went, and therefore claim it is a reasonable charge. The user's only real recourse would be to prove that company is over-billing, but that would require evidence.
Pegging the cost to a set number of labor hours by law signals to companies that part of the cost of collecting this data is they must develop their internal systems in a way that they can quickly and easily comply with requests.
But in general, EU/EC law is full of policy that gets interpreted as human judgement calls, and US law is full of details that are interpreted as badly-written code with a choice of parsers. The two styles are not compatible.
If cloudflare required people to pay to bypass their denial of service protections... well, I guess I dont know what would happen, other then that I would hate them even more then I already do for all the terrible things they do for my experience as a default tor browser user.
How would this even happen? I genuinely don't understand what you mean.
https://www.hhs.gov/foia/faqs/what-is-the-cost-for-getting-r...
I mean, what year is this? We've been hearing "automate it, automate it, etc" for years and years now. But to get your personal data, these companies just throw up their hands and say that it's too hard?
It's our data, dammit!
Completely disingenuous argument. Literally nobody claimed that.
By the same token of strawmanning, you're claiming that businesses should do nothing than hire people to send your data back to you. Why even have businesses if that's the only thing you think they should do?
If you're so invested in "your data, damnit", then don't give it to them in the first place.
Even ignoring implementation cost, there was a significant computational cost that's pretty hard to avoid.
4/5 times there aren't any - people doing the requests often use services that submit blanket requests.
These companies are happy to harvest up all your data, run all this crazy automation, spend millions analyzing algorithms, setting up machine learning, NFTs, run datacenters, networks, etc etc, but they can't figure out how to automate GDPR requests? FUCKING BULLSHIT.
There is literally zero reason why a data request should add any burden to a tech company.