I detailed my personal experience here: https://reddragdiva.dreamwidth.org/606812.html
tl;dr no it isn't, unless your business model is to abuse customer data.
Personally: No one actually cares about data protection. As I said: You sign documents. And three seconds later no one cares anymore. It's just to comply on paper - it didn't actually improve things.
I just hope negative effects of (in my opinion) overregulation wont hurt the EUs economy too badly, but that wont be visible for another couple of decades
Cookie walls exist because companies insist on handing over their visitor data to external ad networks.
Data portability?
The users right to delete data?
Data processing agreements?
Data security?
Article 30?
They are all fairly trivial unless you do shady stuff really. Step one if is really looking at what you process as stipulated by article 30, a lot of the other stuff is much easier after that.
One of my roles is as a DPO in a bank in Europe, and it's far from impossible to comply.
you will never get specifics out of these guys. They will lead you down a circuitous thread of unspecified fears until it's clear that their business model is to abuse customer data even as they'll avoid actually saying so.
In practice that becomes the "right to rewrite history". Which should never be a good thing, for obvious reasons.
What exactly do you envision being the bad outcome here where you are asked to remove personal information and don't have a legitimate interest to keep it for?
Hacker news, please, think about being GDPR compliant! You're breaking the law, hacker news!
I am not an expert on the field, I tried a couple of times to get into the topic but found it difficult to navigate and left me with more questions than answers personally. What exactly does deleting user data mean? Do I have to search the weblogs for the users IP? Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate? Am I in breach if an ISP decides to route internet packets through the US? If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach? What if my mail provider decides to replicate their servers to another country?
If you have resources to read up on this and how to handle all of it, I would really appreciate it! Happy to be convinced that it actually is trivial
> Do I have to search the weblogs for the users IP?
No, because you don't keep web logs with any PII in them longer then you have to, right? The time you need to keep them for is a legitimate interest that you need to be able to justify.
Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate?
Write an Email Retention Policy, there are templates. Follow that.
Am I in breach if an ISP decides to route internet packets through the US?
Isn't it encrypted?
If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach?
You said it yourself: it's a data leak, so yes, it is (assuming this is some bulk email list). Depending on the sensitivity of the list, you may need to disclose the leak to the affected parties.
If you want to profit from being a data controller you really should already have done this homework, even before the GDPR and friends required it by law. A responsible company would already be taking care of it's customers' (and employee) data and at most just needs make sure the existing processes are documented. Demonstrably, companies don't do this, through laziness, incompetence or malice, and that's how we end up with these regulations. Just like how companies injuring people in unsafe workplaces is how you get H&S regulation.
And really all you have to do is just actually make a decent effort. If you find that extremely onerous it's usually because you actually want to use the data for something that you know deep down is not something the information owner would want you to use it for.
Not all those laws applied to all EU countries before, but, basically, if you were doing business across the entire EU all the laws that you had to conform to together looked a lot like the GDPR.
If you have a direct or indirect contractual relationship with the person whose PII you are storing, there is nothing more to do. If you don't, ask for permission and store the timestamp of the authorization.
That's all. Really it's that simple.
> document what PII you store
that part seems doable, the hardest part here are probably figuring out what PII is, and then take care of numerous services logging IP addresses. That's PII, isnt it? What about IPs of phone calls over IP? Or phone numbers stored in phones of numerous employees? Do companies delete those, or is it not necessary?
> who has access to it
I personally try to self-host as much as possible with as little third-parties involved as possible. But I think here are edge cases too, a lot of people might not think about, such as time tracking tools, calendaring, accounting software etc. What happens if employees just use online tools the employer doesn't know about? I am sure it's defined, but it's not entirely clear to me
> what you do with it
that's probably the easiest part, if you do something with it you probably know it
> Also have an internal procedure to scramble someone's PII on request.
I think that sounds good. It's just not entirely clear to me what that procedure should look like? How deep do we go with that? I could be nitpicking and say that physically information can not be destroyed. What if a SQL Server uses MVCC and doesn't delete data but just marks it as such? What about event sourcing architectures with kafka that rely on keeping the data? Or how about backups? Probably no deletion needed, but how to handle cases where backups are restored and previously deleted data reappears? I just think a clear set of rules would be great here, and a lot of people like to oversimplify things (or me, overcomplicating things here, probably)
The main technical thing is that all data stores containing Personal Data must be redactable.
For years I've read bizarre GDPR fanfic from panicked Americans claiming that the world will end if they have to pay the slightest attention to data protection. I assure you literally from personal experience that this is not the case.
I wrote this up several years ago: https://reddragdiva.dreamwidth.org/606812.html
If a business can only survive by extracting and processing against the wishes of the owner, or by storing it unsafely, maybe that's not actually a desirable business.