257 karma · joined March 3, 2023
This is used by compcert: https://compcert.org/
https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_DI-2021-43...
> Sending an e-mail containing sensitive data with enforced TLS-encryption instead of end-to-end encryption was deemed insufficient secured under Article 32(1) GDPR.
They are AFAIK, but can be exempt of articles 12 to 22 under national law. What did I miss?
GDPR doesn't apply to EU activities related to foreign policy or law enforcement, but EUCFR articles 7 and 8 still apply, as does regulation 2018/1725 for the former, and directive 2016/680 for the latter–so in theory, some activities are indeed exempted from GDPR, in practice, they're still subject to data protection laws that require essentially the same measures as GDPR.
Source: GDPR article 2 and 6. On a more personal note, I've already requested my data under GDPR, cited WP29/EDPB guidelines, and filed complaints against various govt agencies.
I'm actually surprised the ICO can fine the UK government. This can't happen in France, for instance.
https://ec.europa.eu/justice/article-29/documentation/opinio...
This says that cookies for a shopping cart or user preferences are exempted from consent. The ICO and the CNIL say the same, as expected.
Now, I don't want to be too harsh on him. AF set him up to fail (acknowledged by the BEA report), then threw him under the bus. I can understand why he chose the support of the SNPL, even if it meant going at war against the plane.
For Airbus Industrie 129, it seems that the FCS was not the root cause of the issue, but I don't know a lot about this flight.
GDPR, article 17(3)a: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
> 3. [Right to erasure] shall not apply to the extent that processing is necessary:
> (a) for exercising the right of freedom of expression and information;
More precise information from WP29. See the criteria list, beginning in page 13: https://ec.europa.eu/justice/article-29/documentation/opinio... This was from the DPD era, but still applies to GDPR.
How Google handles removal requests: https://support.google.com/legal/answer/10769224?hl=en&sjid=...
>The deployment of that js file itself requires consent
is an “interesting” interpretation of ePrivacy.
This:
>the running of the javascript within the browser to ascertain how the browser is behaving also requires consent
is true in some cases, eg. browser fingerprinting for tracking purposes.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
>3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
The directive:
(1) does not target cookies, but methods to store information, or gain access to information stored;
(2) allows strictly necessary purposes without consent or popups;
(3) requires consent for other purposes.
The directive talks about cookies in recital 25, but only as an example.
The GDPR replaces the Data Protection Directive (Directive 95/46/EC), and along that, references made to it in ePrivacy. But it does not bring anything new about cookies.
Though, I agree with you: the GDPR is well made–apart from the litigation part, but that's going to change with the GDPR Procedural Regulation. ePrivacy is good too, but 5(3) aged poorly, unfortunately.
Side note: I know someone who requested their data to their DPA, and part of the response contained emails mentioning them and their complaints in the _content_ of the message (they were not in the From:, To:, Cc:, or Cci: fields). All names and emails address were censored, though, in accordance with 15(4).