Since my server doesn’t do business in EU, I couldn’t care less about GDPR or other local laws, even the ones I think are good ideas.
American law doesn’t apply to someone running a server in Brussels. The converse is also true.
Since my server doesn’t do business in EU, I couldn’t care less about GDPR or other local laws, even the ones I think are good ideas.
American law doesn’t apply to someone running a server in Brussels. The converse is also true.
Except when the one running and renting out the server is Microsoft, Amazon, or some other US entity and the Patriot Act exists.
I’d have a different opinion about my service if I were hosting my server on Hetzner in Helsinki. Since I’m not, I don’t.
I'd say that is rather very relevant.
The Patriot Act is the foremost frontier in the ongoing dispute about the so-called Privacy Shield.
The GDPR explicitly permits "processing [as] necessary for compliance with a legal obligation to which the controller is subject" in Article 6.
Right to be forgotten still applies, there is just some limited data that will still be kept.
But it does require you to document that requirement and make sure that the data isn't shared beyond that requirement without consent.
HIPAA and GDPR aren't conflicting, they're orthogonal and cover different things.
Record retention laws win, as explicitly stated in the GDPR.
Same reason a murderer can't (successfully) issue a right-to-be-forgotten request to the cops investigating them.
(There's also "processing is necessary for the purposes of the legitimate interests pursued by the controller" as another exception, which allows, for example, your bank to retain the fact that you owe them $100k on your house still, even if you don't want them to.)
This is a fundamental aspect of GDPR and part of the central message in the regulation. Companies and organizations are only allowed to keep personal information if they have a legal allowed reason to do so, and must honor requests for deletions unless they have a legal reason not to do so.
What is and what isn't a legit reason depend on circumstance. What companies generally object with GDPR is that generate revenue through personal advertisement is not an legit reason to keep personal data.
Out of curiosity, could you give a few examples of incompatibilities?