4 ms·
Honestly i think the GDPR is a great idea, unfortunately after going through 3 different firms who are supposed experts on the GDPR. We are still struggling. Wh
by Azeralthefallen 9y ago
Honestly i think the GDPR is a great idea, unfortunately after going through 3 different firms who are supposed experts on the GDPR. We are still struggling. When you ask them about a possible situation, and the response you get is "that is kind of a gray area", to "that is open to interpretation".
For example nobody has been able to give me a clear definition of what counts as identifying information. I have heard IP addresses count, so what about our cloudfront logs? They have the client ip address. If i pipe them straight to a logging SaaS, is it on the logging service to handle it? Or is it on me?
Furthermore for the right to be forgotten, how do i handle that with backups that are not under our control? E.g. AWS RDS backups? Amazon says there is no way to modify those backups, and our TAM has suggested managing our backups our selves.
What about data that our customers pipe to our service, how is that handled by the GDPR, it is all encrypted. But apparently we need to handle cases, but we don't have the decryption keys. Is it on the customer who uses our SaaS or is it on us? How do these scenarios work?
While i feel more and more we are ready for the GDPR at the same time i am terrified. I feel many of the laws can be interpreted far too many different ways which makes me uncomfortable.
- geocar 9y agoAllowing the court to decide makes it possible to interpret degrees of wrongness and malice of intent. IP addresses may be personal data if you have a database containing personal data (like a web form) and the IP address. Don’t have that database, or only make it accessible to your firm and processors to verify data integrity/protect against fraud: no problem. Dropping the IP column from that table after a month is probably easy enough and good enough. The GDPR also doesn’t mandate encryption. It says you’re responsible if you get hacked and could’ve prevented it. Applying an IT security standard (eg ISO) is just one (probably easily) defensible way to do it. Not getting hacked is another. Your consultants should fully understand your business and data flows: individual things taken in isolation are a “grey area” but looked through the lens of your whole company, actions and intent, versus value to the subject themselves (instead of just your customers) is what the European courts will do if they decide to give your company attention; they will not nit.
- jcranmer 9y agoThe GDPR strikes me as an urexample of regulations gone wrong. If you read some of the later posts in this series, one thing they say is that "the regulation can't be that onerous because this is all best practices anyways." But the reason the regulations are onerous are because what qualifies as falling under the purview is indefinite, and the regulators don't want to clarify so they can use the ambiguities to punch the punching bags when the opportunity arises. So the risk-averse have to assume that the requirements stretch to the truly insane (e.g., requiring an email for anti-spam blog commenting purposes triggering these provisions) with the only guidance really being "we're not really targeting you; we just care about the punching bags."
- the_mitsuhiko 9y ago> If i pipe them straight to a logging SaaS, is it on the logging service to handle it? Or is it on me? That’s not gray at all. That’s very clear cut. The SaaS acts as a data processor if it gets IP adresses or other PII. > Furthermore for the right to be forgotten, how do i handle that with backups that are not under our control? You need to ensure PII in your database is encrypted already with a per customer key and have these keys be backed up separately where the retention is low.
- geocar 9y agoThe GDPR doesn’t say anything about encryption or IP addresses. The ICO has said that if you have a breech that encryption would protect against them that could be a violation: https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- the_mitsuhiko 9y agoThe gdpr does mention encryption and pseudonymisation. It does not mention ip adresses because the law is very clear about anything being in scope that can be used to identify individuals.
- geocar 9y agoYou’re right. I should have said the GDPR doesn’t require encryption. I blame wee hours commenting. And an IP address cannot always be used to identify individuals.
- the_mitsuhiko 9y agoThat’s why ips are not directly listed in the law.
- tpetry 9y agoWe had very long discussions with our lawyers to make our email analytics solution [1] compliant to the very strict german privacy laws and GDPR. Ip addresses are personally identifiable information because someone is able to find the real person an ip address belongs to - your ISP. That you have no possibility to get them to hand you over this information and it wouldn‘t be legal makes no difference. It‘s a big joke. The solution is to anonymize the last ip adresses octet. You can (within some boundaries) work with the full ip address. In your case technically you would be violationg these rules because you are saving person identifiable information without your customer aknowledging this before. And you even transmit these information to other services. The joke is, this is how the internet works and this rule is practically not enforcable for everyone (we solved it for our solution). The least you could do to be a little bit compliant is to state in your rules that you are logging the customer‘s ip address and tell them every service you transmit this information to for transparency reasons. For the backup case with AWS RDS it‘s again not practical. The law has not been made by texhnicans. The simple answer is everyone is violating the law. In my opinion it will take 2-3 years and all these very openly stated rules will be clarified and in the end will be more logical. Until this day you could store an information which information should be deleted in another database and if AWS needs to restore your main database you use the seconds database information to delete the information again. You can then state its technically not feasible to delete some information from backups that you did your best. But then you should not store backups for 10 years, they should have much smaller timespans. [1] https://mailspice.com/ https://mailspice.com/
- bitwize 9y ago> Honestly i think the GDPR is a great idea, unfortunately after going through 3 different firms who are supposed experts on the GDPR. We are still struggling. When you ask them about a possible situation, and the response you get is "that is kind of a gray area", to "that is open to interpretation". In the USA, this would be an opportunity for entryism by opportunistic outside consultants who would propose all manner of insane policies, and hang the threat of noncompliance over management's head like a Sword of Damocles if they are not followed. See Sarbanes-Oxley compliance for a relevant comparison and note that SOX is probably one reason why we've seen a precipitous drop in IPO rate in recent decades. But the US regulatory infrastructure is, compared to civilized countries, from fucking Mars, so I have no idea if it will hold for GDPR.
- Silhouette 9y agoUnfortunately, the standard MO for the EU is to hang the Sword of Damocles over the head of small organisations itself by passing regulations obviously aimed at problems that normally come with much larger organisations. It does it with VAT. It does it with the consumer protection rules. Now it's doing it with the privacy and data protection rules. The moderating effect is that organisations too small to have dedicated in-house staff to deal with these kinds of issues are probably too small for resource-constrained regulators to bother with. If you're responsible for one of those small organisations, your choices are typically to try to stay on the right side of the law but in doing so accept disproportionate overheads for something that probably won't ever matter, or not to try, not to incur the overheads, and to hope that you don't get caught and penalised, which realistically you probably won't unless something happens that is so catastrophic that your organisation has already ceased to exist anyway. As far as smaller businesses are concerned, these kinds of rules hand a big competitive advantage to those who don't make a good faith attempt to follow them, at the expense of those who try to do the right thing legally speaking. As someone who is generally a strong believer in doing the right thing in business, and in fair consumer protections and strong privacy rights from a personal point of view, I find this outcome infuriating.