5 ms·
"Under the General Data Protection Regulation (GDPR), the requirements for valid consent have been made much stricter. Consent must be freely-given, specific,
by marsRoverDev 9y ago
"Under the General Data Protection Regulation (GDPR), the requirements for valid consent have been made much stricter. Consent must be freely-given, specific, informed and revocable. The GDPR expressly states that, where there is an imbalance of power between the party giving consent and the party receiving it, consent will not be valid. In the employment context, it has long been acknowledged that there is such an imbalance between employer and employee. This means that it will be very difficult indeed for employers to rely on consent to process employees’ personal data under the GDPR."
So no, this is not legal from 2018.
- secfirstmd 9y agoNot really. It all depends under what reason you have decided you are collecting the data in the first place in your Data Protection Impact Assessment (e.g your lawful basis). Consent is only one of them. Consent is problematic because it can be withdrawn.
- TazeTSchnitzel 9y agoMind you that the GDPR is EU law, whereas the judgement here is an ECHR ruling, and these are separate institutions. All EU countries are in the ECHR, but not vice-versa.
- magamind 9y agoGDPR applies globally to any company - there are no safe havens. If you keep data on an EU citizen then you must comply.
- closeparen 9y agoThis probably means the end of Europeans commenting on web forums, then. Can't imagine Hacker News, open source mailing lists, or any random guy with a phpBB/VBulletin interest group forum is going to appoint a compliance officer and fork over millions of dollars for consulting and legal services to become compliant.
- Gaelan 9y agoMost random guys with vBulletins probably aren’t compliant with some internet law or another anyway. Quite simply, there is no reason for the EU to care.
- closeparen 9y agoSome random internet law like what? I claim that it's a new situation that collecting values submitted through HTML forms is illegal by default.
- catdog 9y agoOne must also keep in mind that the treaty about the European Convention on Human Rights in itself is very weak so ECtHR rulings can easily be ignored in practice. The EU with its very similar fundamental rights framework strong arms it in some way so EU members have a very hard time to ignore such rulings. So while the ECtHR is not an EU institution and has broader coverage it's rulings mostly come to full effect inside the EU and maybe countries closely tied the the EU.
- TazeTSchnitzel 9y agoThis is true, although it does vary from country to country, as beyond being EU members, some have entrenched it in their legal systems. The UK, for example, requires its judges to, so far as possible, interpret laws so as to be compliant with the ECHR, though they can't directly strike them down. The UK also allows human rights claims to be taken to UK courts first, rather than having to go to Strasbourg straight away.
- candiodari 9y agoExactly. Actually suing someone for a human rights violation is very, very hard. It's expensive and the court can (and often does) just refuse to take cases.
- Godel_unicode 9y ago> where there is an imbalance of power between the party giving consent and the party receiving it, consent will not be valid. If that's the case, EU firms are going to get spear phished so much in the coming years! Operating an effective corporate SOC will be... challenging.