You even admit this - nobody feels this way, except for the people who very strongly feel that way but their feelings are "FUD" so don't count?
You even admit this - nobody feels this way, except for the people who very strongly feel that way but their feelings are "FUD" so don't count?
GDPR often gets blown out of all proportion by people who seem to have a vested interest in having the regulation scrapped.
This played out the same with the EU cookie directive which was intended to give people consent on how they were tracked- with massive carve outs for legitimate use, the intention was that people would cut down on that tracking to avoid needing a popup; but ended up in some form of malicious compliance where everyone just put up pop-ups instead and tried to hide the opt-out with dark patterns.. massively overblowing what the regulation even entailed in the first place by claiming that the pop-up was necessary.
- The penalties are massive: fear
- The wording is vague: uncertainty
- What to do is unclear: doubt
That's entirely on the EU. I have no vested interest in GDPR one way or another at the moment and yet having been involved in assessment projects in the past, it is a crap law that makes the EU look incompetent and stupid. Nobody can figure out what the hell it means in all kinds of common scenarios. HN is full of people saying it's simple; I have yet to encounter any of these people inside actual enterprises, doing actual implementations of it. People who think it's easy are invariably eurofans engaging in wishful thinking.
> the intention was that people would cut down on that tracking to avoid needing a popup; but ended up in some form of malicious compliance
That's not how it was. The EU passed an incompetent law with unclear goals that kills the ability to do business of anyone who doesn't implement the banners. Cookies are in fact necessary, not optional, not nice to have. They are required. Thus everyone implements the banners, the internet got worse, the EU now looks foolish in front of the world and yet can't accept it.
If you read it, it's really clear: if you're not sending information to third parties then it's exceptionally easy to be compliant. A lot of things are "to best effort" which puts the burden of proof on the prosecution that you were grossly negligent.
There is a dedicated website to explaining the regulation for dummies; https://gdpr.eu -- the entire thing is 11 chapters, half of that is for governments to harmonise their national regulations to be GDPR compliant without people needing to invoke "GDPR", the remainder is a mix of common sense and ensuring digital privacy and consent. It's really clear for a legal document.
I should know, it's my part of job to read them and to ensure my company is compliant. It's not hard. The most loud people about this are lawyers who have a financial incentive to make it as hard as possible.
Even basic things like backups are made unclear by GDPR! Truly, a more incompetent piece of legislation is hard to find. The only people who disagree on this are people who have hopelessly naive views of what regulators are like, and assume they'll always be friends. Nope. You have to read these rules as if the people who are enforcing them are completely unreasonable sadists. The lawyers understand that, you don't, so I hope you aren't in a position where you may lose your job in case of GDPR violations.
The principles for satisfying “best efforts” standard have been enumerated as follows:
* "Best efforts" imposes a higher obligation than a legal "reasonable effort".
* "Best efforts" means taking, in good faith, all reasonable steps to achieve the objective, carrying the process to its logical conclusion and leaving no stone unturned. However, it does not require a party to sacrifice itself totally to the economic interests of the party to whom the duty is owed, although the interests of the other party must predominate.
* "Best efforts" includes doing everything known to be usual, necessary and proper for ensuring the success of the endeavour.
* The meaning of "best efforts" is, however, not boundless. It must be approached in the light of the particular contract, the parties to it and the contract's overall purpose as reflected in its language.
* While "best efforts" of the defendant must be subject to such overriding obligations as honesty and fair dealing, it is not necessary for the plaintiff to prove that the defendant acted in bad faith.
* Evidence of "inevitable failure" is relevant to the issue of causation of damage but not to the issue of liability. The onus to show that failure was inevitable regardless of whether the defendant made "best efforts" rests on the defendant.
* Evidence that the defendant, had it acted diligently, could have satisfied the "best efforts" test, is relevant evidence that the defendant did not use its best efforts.
Mere reasonable efforts will not suffice to meet the “best efforts” standard. Neither will occasional efforts made from time to time suffice. A higher level of effort is required.
Examples of situations where the standard was not met include:
* Contract for the purchase and sale of a house required the purchaser to obtain financing. Court found that the purchaser failed to do so because he applied for a loan for an inflated sum (by 60%), delayed the loan application, and that true reason for these actions was that the purchaser simply did not want to buy the property because he received a negative appraisal of it.
* Contract for the purchase and sale of land. The contract required the vendor use best efforts to obtain subdivision approvals. Obtaining approvals was also a condition precedent in the agreement, meaning that the parties could walk away from the transaction if the approvals were not obtained. The vendor hired an agent to obtain approvals, but the agent failed to advance the process. As time went on, the price of the land went up and the vendor notified the purchaser that it ought to be discharged from the obligation to close the transaction due to not receiving approvals. The Court found that the Vendors did not use best efforts. The court commented that to satisfy the standard, one must show progress, as well as reasonable and sensible response to roadblocks.
Examples of where the standard was met:
* An agreement to lease required tenants to obtain a business license to operate a car dealership on best-efforts basis. The tenants submitted an application within 3 days of signing the lease, did so accurately, but were told that the process would take significantly longer than anticipated. Best efforts standard was met.
Generally, there are more decisions where this standard is found to not have been not met than where it was met. Shy of impossibility, the best efforts standard imposes onerous obligations on the party that agrees to be bound by such a clause.
-----
The right to be forgotten does not apply to data that is not being processed, so your backup situation is clear too and if you ask then you get pretty clear answers. Obviously if you restore the backup you would be expected to re-process right to be forgotten requests, which can be stored for the duration of your backup.
Your lawyer has well and truly convinced you that it's difficult, it's not, and if you have a serious question; you can send it to your countries DPO office: https://edps.europa.eu/data-protection/data-protection/refer...
The backup question, for example, was clearly (publicly) answered by France's DPO.
To be clear here: I don't think you've actually interacted at all with the apparatus surrounding GDPR. It's not my lawyers who are loud, it's lawyer consultants- it's lawyers of companies who's business model is not compliant (trading personal data). It's people in the US and UK who are trying to spread as much uncertainty as possible to either make the EU look incompetent or non-competitive and/or weaken the bloc.
It's absurdly easy to be compliant. For all the whinging, if you're taking the necessary steps to secure data that you should have always been taking, and you don't sell peoples data, then the only thing you need to bake in is a "delete account" function- even things like legal records are exempt so transaction logs are not subject to GDPR. Just read the text.
I guess the reason people are scared is that GDPR is the first legal text they ever came into contact with. These are really common legal terms which have huge numbers precedence attached.