Unfortunately, the commission doesn’t care about passing illegal legislation (DRD, the 3 EU-US transfer agreements, etc.), and the CJUE is not fast.
257 karma · joined March 3, 2023
Unfortunately, the commission doesn’t care about passing illegal legislation (DRD, the 3 EU-US transfer agreements, etc.), and the CJUE is not fast.
(Also, this law was ruled unconstitutional but shenanigans ensued.)
No. All I did was opening enforcement tracker, click on France, and look for familiar names. It was faster than writing my previous comment. I knew about one of the Carrefour cases, and the Criteo case though.
>The authoritarianism and the insanity of the laws in the first place is/are a far bigger problem
What is authoritarian or insane in GDPR? Or its previous iteration, the DPD (from 1995)? Oh no, we expect companies to handle personal data with care, the horror.
“Implicit permission” does not sound like “free, informed, specific and unambiguous consent”. Furthermore, the directive (ePrivacy, article 5(3)) states that consent is valid only if the user was provided with clear information about the purposes of the processing beforehand.
> does that include the app reading its own resource/assets data from its installed app-package/directory?
An app reading its own data will fall under the “strictly necessary” exception of the directive (cf. ePrivacy 5(3)). Reading other databases will depend on the purpose.
But you are right that this is illegal, because just sitting in a car is not a “specific, informed and unambiguous indication of the data subject's wishes”, which mandatory for consent (GDPR article 4(11)). Neither it is “transparent” (GDPR article 6(1)a).
>‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
An IP address, or an email address is personal data. Even a pseudonym or a session ID is personal data. Yes, having a log for security purposes (GDPR recital 49) captures personal data (even just access dates and requested URLs may be considered to be personal data). Yes, a comment section on a blog may capture personal data.
Once again, I'm fine with all of this. But ignoring GDPR by not capturing personal data is more complex that it might seem.
You can find guidance or good advice online for all of your questions.
> No cookies... so no language preferences. That is a profile cookie.
This is one of the examples of “strictly necessary” cookies, which do not require consent. See section 3.6 here: https://ec.europa.eu/justice/article-29/documentation/opinio...
> Right to erasure. What about invoices and orders? When can it be anonymous and when is it old enough to anonymize.
Invoices should typically fall under the “legal obligation” legal basis (article 6(1)c). See for how long the law requires you to keep them. In my country, it's 10 years.
>Do I get away with replacing personal data random data?
Yes, see WP216.
>Do I replace references to real people with 'anonymous person'? Will my sql constraints still work?
How do you do when someone deletes their account?
>When I restore data from backup and someone has been anonymized in the meantime, what mechanism will be used to anonymize the user after restore?
It's up to you to decide.
>Right to data portability. How much of the database and in what format?
The same as for a DSAR. As for the format, it's up to you to decide, provided it is a commonly used format.
You must list all kinds of data processing you perform, find the appropriate legal basis (and data retention duration, etc.), make sure you only gather data you need (data minimization), know to who you transfer data, make your services secure by default, monitor for unauthorized access, and tell affected people when there is a breach. Perhaps make a risk assessment, but it depends on the processing you do.
Yes, it's work. But quite frankly, I'm cool with a law that expects anyone who processes personal data to secure their service, to properly inform people, and holds them accountable.
The issue of Google's reCaptcha, according to the CNIL at least, is that they use data collected through the service for their own purposes. See https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000047346903, point 86. Deepl translation below:
> If a data controller can claim exemption from the requirement to provide information and obtain consent when the only purpose of read/write operations carried out on a user's terminal is to secure an authentication mechanism for the benefit of users (see CNIL, FR, September 27, 2021, Sanction, no. SAN-2021-013, published), the situation is different when these operations also pursue other purposes that are not strictly necessary for the provision of a service. The Google reCaptcha mechanism is not intended solely to secure the authentication mechanism for the benefit of users, but also enables Google to carry out analysis operations, as Google itself specifies in its general terms of use.
>Almost nothing is strictly necessary to just serve content when a URL is accessed
That's not what the law says.
> 3. Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
Emphasis mine. It's not to just serve content, but to provide a service requested by the user. This should clear up the confusion.
Full text here: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
Anyway, I provided a link from the ICO that explicitly says it's OK for user IDs, user preferences, etc.
The CNIL agrees: https://www.cnil.fr/sites/cnil/files/atoms/files/lignes_dire... See point 49.
The EDPB agrees: https://ec.europa.eu/justice/article-29/documentation/opinio...
About cookies, the relevant law is ePrivacy 2002/58/CE, article 5(3), which says you don't need to ask for consent for “strictly necessary” cookies. In practice, this means session ID cookies, user preferences, etc. This also applies to local storage or any other way to store and retrieve data on a user's device.
The issue is not that the law is unclear, it's people that can't help but speculate on its content even though they never read it. Google is full of links to this, and HN is bad in this regard. And to be honest, this is not exclusive to GDPR.
I've found Stackexchange law and /r/gdpr to be okay-ish. Otherwise, there is a guide on the commission's website, there is gdpr.eu, there is the commented version of GDPR on gdprhub.eu:
https://commission.europa.eu/law/law-topic/data-protection/r... https://gdpr.eu/ https://gdprhub.eu/index.php?title=Article_1_GDPR
You can find a lot of advice on various DPAs website (ICO, and even the CNIL publishes stuff in english sometimes).
https://ico.org.uk/for-organisations/direct-marketing-and-pr...
Cookies don't violate GDPR, but are subject to ePrivacy 2002/58/CE, article 5(3). “Strictly necessary” cookies (eg. session ID cookies) are exempt from consent.
Not illegal then.
And European companies are also sued for breaking GDPR. Recently, the CNIL fined Criteo, a French adtech company, for 40M€. Multiple other fines in the 1M+€ range (Carrefour, Total, AG2R…) for French companies.
You can go on Enforcement Tracker, you will find a lot of small fines against EU entities, and few but heavy fines against US entities. I don't think this is protectionism, but rather that EU companies fare better than US companies in environments with historically strong privacy laws, precisely because they are subject to these regulations from day 1.
> They are using the data in compliance with their ToS, which is decided post-facto to be in violation of the GDPR.
A ToS is a contract, and contracts can violate the law. Nothing surprising here.
In Germany too, if I remember correctly.
But if you are so sure about this, please sue so we can get rid of these cookie walls!