24 ms·
The Nightmare Letter: A Subject Access Request Under GDPR
- janemanos 9y agoIt will cost companies so much money and time to be compliant with GDPR. Maybe even become a neck-breaker for some young startups
- edent 9y agoGood. Perhaps there will be fewer reckless start-ups who sell on my personal details without permission.
- jl6 9y agoYour insurance will cost more because implementing GDPR is costing insurance companies a lot of money.
- geocar 9y agoI hope so. If they were putting my data at risk because they didn't have enough money, then this was required, right?
- jenscow 9y agoYes, exactly. "Unfortunately we have to increase prices, because we now have be careful with your personal data"
- peteretep 9y agoI am comfortable with this.
- janemanos 9y agoWell, the cost for GDPR won't be that high, if the EU would have thought this through. Talked to a few of the GDPR "Consultants" and as soon as people have some more in-depth questions how A or B can be handled, you just get a surprised look. I'm all for better protecting my information but if you introduce these regulations you, as the regulator, also have to have answers to basic questions.
- jimnotgym 9y ago> Talked to a few of the GDPR "Consultants" and as soon as people have some more in-depth questions how A or B can be handled, you just get a surprised look. I'm all for better protecting my information but if you introduce these regulations you, as the regulator, also have to have answers to basic questions. Talk to better consultants. Consultants are not the regulator. The regulation itself is in plain language. What do you consider is not thought through?
- amarkov 9y agoI must delete personal data "without undue delay". This opens up a few questions, which as far as I can tell the text of the regulation provides no guidance for. * I (like most companies) have a variety of unstructured and/or immutable logs. I can't just DROP FROM table WHERE. Is it acceptable to delete this data by waiting a few days for a retention period to expire, or do I have to retrofit deletion functionality in? * What if the retention period is a week, or a month? What if I've been advised to establish those longer retention periods for other reasons? * If a bug is found in the data deletion workflow, is it an undue delay to say we'll tackle it next sprint? Do we need to drop everything and make it a priority now? * Once we've resolved a personal data deletion bug, is it an undue delay to roll it out slowly over a week? Does it matter if this is our standard rollout process, or if there's a risky hotfix process we're deliberately choosing not to use?
- vidarh 9y agoFor logs, I'll suggest you aim to avoid personal data in the logs, and if necessary only log an anonymous id and separately keep a mapping to a user for the bare minimum amount of time needed, and in a way that let you explicitly delete it easily. A lot of the "problems" of the GDPR goes away if you minimize the amount of personal data you process and retain, which incidentally generally will be good for your security as well.
- analog31 9y agoDid my insurance costs go down when companies started gathering and storing my personal information? I figure, if this stuff starts costing them more than a token amount, they can direct their IT manager to systematically erase the personal information that isn't utterly vital to their immediate business needs.
- jl6 9y agoOne example of the increased costs due to GDPR are that data subject access requests are now free to make. In the UK they used to cost £10. A small amount which never really covered the cost of fulfilling the request, but enough to deter frivolous mass use. Now that such requests are free, there is no deterrent and companies must introduce a scalable process for dealing with them (or risk being swamped and unable to meet the 30 day deadline). This will actually be easier for companies like Google and Facebook to comply with, as they are digital natives. Financial services is an industry struggling with a burden of legacy systems, and even paper-based processes still. This one GDPR provision alone is causing much expense and heartache.
- lagadu 9y ago> Financial services is an industry struggling with a burden of legacy systems, and even paper-based processes still. This one GDPR provision alone is causing much expense and heartache. That's a good thing. If it's causing much expense and heartache it means that our private data wasn't being handled with the necessary care and attention to value that it needed to be.
- qw 9y agoThe final law was finalised in 2016 and was expected since at least 3-4 years ago when the agreement was made in the EU parliament. Startups: It costs money to develop the systems to process personal data in the first place. I don't see any unreasonable restrictions in GDPR. If new startups plan for GDPR while developing the systems it should not add too much costs. It is basically about managing data responsibly and documenting how you utilise that data. Established companies: I don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. This has happened to other industries as well, such as the tobacco industry who had to adjust to anti-smoking laws when the politicians could no longer ignore the negative effects.
- Erlangolem 9y agoWhen you move fast and break things, sometimes what ends up broken is you. That’s probably a lesson which needs to be painfully re-learned by some. As you said, too many have been outrunning real consequences for a while, but that’s not some inherent right, it’s a con. If personal info is worth what a lot of companies seem to think it’s worth, then governments have been downright negligent in their lack of regulation. Playing fast and lose with people’s identities should never have been acceptable, and complaining that the first wave of consumer protections is anti-business mostly tells you what kinds of businesses we’re dealing with.
- Silhouette 9y agoI don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. Some commenters in these discussions write as if all businesses deserve the GDPR and all its attendant overheads as some sort of punishment for assumed past transgressions. And yet I work with small businesses, and so unsurprisingly I also know many other people who do, and not one of those businesses operates with any sort of data-hoarding, privacy-invading model, nor would any of us ever want to. All that attitude teaches the next generation of startups is that they'll be penalised whether they try to act ethically and responsibly or not, so they might as well do the questionable things and make more money anyway. Surely that is exactly the opposite of what should be happening?
- FridgeSeal 9y agoI think you're viewing this as a blocker not an opportunity: if.youre a startup now, why wouldn't you be building your tech with GDPR in mind? Doing so makes it super easy to comply with from the get-go and puts you ahead of incumbent players and their inertia and legacy systems. You're going to have to do this at some point, may as well do it early and give yourself an advantage?
- montrose 9y agoIt seems to me that this letter is similar to a denial of service attack in the way that, although a valid request, it places an impossible burden on the recipient. If so, the GDPR is similar to a broken protocol. Maybe the people who designed it assume that it will never be misused. Anyone with experience designing protocols could tell them how dangerously naive that is.
- edent 9y agoIf you can't answer those questions in a few button clicks, then you probably can't be trusted with my personal data. We keep being told that "data is the new oil". It is. Not for money making opportunities, but because you have to handle it responsibly and if it leaks it will cost millions to clean up.
- Erlangolem 9y ago(Deleted)
- mattzito 9y agoYou know that the GDPR violation fines start at 10m or 2% of worldwide revenue, whichever is higher, right?
- detaro 9y agoThese are up to limits, not start at. The second class is 20 million/4%, but still up to. And given the long list of factors to consider for the fining authority, they can't just slap close-to-max amounts around without supporting evidence for why that's appropriate.
- montrose 9y agoOr you are an early-stage startup with just a couple founders trying to do everything.
- 9y ago
- donttrack 9y agoHow does the GDPR apply to governments storing data? Could I send a letter to the tax authorities and ask them to delete my data?
- occamrazor 9y agoNo, and you cannot either ask a company to delete data which must be retained according to the law. However you can ask for a copy of all their data about you, with very limited exceptions (national security, active investigations, etc.)
- kenbaylor 9y agoYou can ask, but the recipient company does not have to comply. The tax authorities have a legal obligation to keep the data, and they will. Reference: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- ferongr 9y agoObviously the state is exempt from such nonsense.
- detaro 9y agoThere are exceptions for some purposes, and I won't be surprised if governments try to stretch those as far as they can, but in general GDPR applies to governments as well.
- dominotw 9y agoWhat about NSA can I ask them what data they have on me?
- number6 9y agoThey will tell you, that they are not subject to EU Law. If you ask an EU equivalent they will just tell you that they don't have any data. Or that they might have but can't disclose it because of security concerns.
- cycop 9y agoThis is basic cyber security stuff and I get these questions from customers almost daily. If you are going to be in the business of using peoples personal information then you need to be prepared to answer these questions.
- kodablah 9y agoEven if you're not in that business you need to be prepared to answer these questions.
- emilfihlman 9y agoI wonder what would happen if we send this to Brussels en masse.
- number6 9y agoWhy not - just send this letters out en masse. There should be a webservice for this.
- speedupmate 9y agoFor every action, there is an equal and opposite reaction. If a customer can ask anything then a company asked can ask anything in return and if you send those out "en masse" you just become a subject to GDPR yourself.
- geocar 9y agoIf you get a letter like this, reply in plain language: Given that the "requests are complex or numerous", I will be responding within three months as recommended by the ICO[1]. Have a nice day. You now have plenty of time to deal with it properly. If you have a lot of data on someone, you can enumerate the categories (1) and then request they break it down (specifically request 1c; see Recital 63[2] of the GDPR for the exact language). Almost everything else should be in your privacy policy anyway. If you do not have a lot of data on someone, then three months should certainly be enough time to properly respond to this. Most businesses do not have any personal data on anyone beyond what you need for an invoice. If you have a dedicated CRM that contains leads of potential customers, or you use an online service like SalesForce, you can probably get their support in complying. [1]: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/ https://ico.org.uk/for-organisations/guide-to-the-general-da... [2]: http://www.privacy-regulation.eu/en/recital-63-GDPR.htm http://www.privacy-regulation.eu/en/recital-63-GDPR.htm
- nopriorarrests 9y agoSorry, but ICO stands for "Information Commissioner Office", and they seem to be UK organization, having .uk domain and all that. How can they recommend anything with regard to EU-wide law? Or, stating differently, how their recommendation hold any value at all?
- Silhouette 9y agoThe ICO is the government regulator responsible for data protection in the UK, and as such the people who are going to be enforcing the GDPR here.
- sharkdaysunrise 9y ago"The EU" doesn't enforce the GDPR, the Supervisory Authorities in each member state (like the ICO) enforce the GDPR. The member states have agreed to abide by the GDPR, but their own specific data protection laws are allowed have slight variations, e.g. the specific age limit defining minor vs. adult.
- 9y ago
- y0ghur7_xxx 9y agoSorry, this is off topic, but I would really like to read the article but it asks me to create a linkedIn account to read it and I am not comfortable with that. Is that the only way to read it?
- robin_reala 9y agoI don’t have a LinkedIn account (and my email address is in their blacklist) yet I was able to read it OK?
- y0ghur7_xxx 9y agoI don't know. It redirects me to https://www.linkedin.com/authwall?trk=bf&trkInfo=AQH_V0VMQlsQWwAAAWI0GwnQkikFevm0oWV5fgjniYjdZzKfOCSiBIdHwbtz5jaAJnIGDBU2bhmgDrOoDip-nXu1s0ZX4Pigd_qIkcBIqxXcIOlkxNAMBODg3WBtguOQhk_ghJ4=&originalReferer=https://news.ycombinator.com/&sessionRedirect=https%3A%2F%2Fwww.linkedin.com%2Fpulse%2Fnightmare-letter-subject-access-request-under-gdpr-karbaliotis%2F https://www.linkedin.com/authwall?trk=bf&trkInfo=AQH_V0VMQls...
- drewmol 9y agoI was gonna ask the same, Linkedin's authwall seems more difficult to circumvent than the news paywalls I encounter. It would be unfortunate to have to create a dummy account. If I do, I'll send them a copy of this letter ;-)
- xab9 9y agoLinkedin allows you to watch "some" content, but will show a loginwall later on. It's not cookie based afaik, I couldn't catch a sensible logic there. I'm on a job hunt cycle so I had to log in and use it in the past month many times and to me it's just as offensive and aggressive as facebook nowdays. I avoid it like the plague if possible.
- gls2ro 9y agoHere is a direct link to a website with this letter: https://constantk.wordpress.com/2017/06/30/the-nightmare-letter-a-subject-access-request-under-gdpr/ https://constantk.wordpress.com/2017/06/30/the-nightmare-let...
- Skye 9y ago...and how is wanting to know what a company has about you a bad thing? I'd be worried if a company cannot answer this, because that means they haven't got a handle on what data they store, which means that when they get hacked, they wouldn't know what got taken! EDIT: grammar (got -> get)
- 5h 9y agoReading this actually makes me feel pretty good, my team & I have been working on GDPR tooling for our app for the past couple of months & combined with the fact-sheets we've prepared answering such a letter while complying with the individuals rights would be pretty straightforward.
- redleggedfrog 9y agoI was thinking the same thing. Wouldn't be too hard to give that to a support person and get good answers. After the first one, a lot of it is reusable. And then a lot of it is already in the marketing materials we use for selling our services!
- robin_reala 9y agoThis is all good, and consistent with GDPR’s attempt to reframe data as a liability rather than an asset. The first months and years are going to be painful, but eventually companies will adapt to the new normal.
- jimnotgym 9y agoAs a PCI compliant company I already treat data as a liability. So much data collection is unnecessary, or the the result of defaults, like logs left on that nobody ever looks at.
- harshreality 9y agoIf this kind of request is a "nightmare" or too much of a burden, they should automate it. "We put lots of engineering effort into mining your personal data and selling bits to other people, but we can't be bothered to put any engineering effort into disclosing on your profile or account-settings page what we're doing with your data." A lot of the questions are answerable generically (no differences between users). You can't tell me that writing a data privacy FAQ with those answers in clear, simple language, once, with a link on every page and on users' profiles, is an excessive burden. These companies just don't want to have even that minimal burden and process to ensure that changes in usage of personal data get documented and updated on such a faq.
- Silhouette 9y agoThe GDPR applies as much to a startup or side business as it does to Facebook and Google. A letter like this would be a hugely disproportionate burden to a small business like that. It would take many hours, if not days, to reply properly to all of those points, even for a business that is doing nothing shady or unusual. You can't just write "automate it" as if that has no cost.
- harshreality 9y agoWhat's an example of a start-up collecting personal information, using it in a complex way that can't be summarized in a few paragraphs, but being unfairly burdened by this? If a start-up is doing things with personal data so that answering those questions takes more than a few paragraphs, isn't the start-up pretty much a personal-information-processing business, and doesn't it deserve to have the burden? Doubly so because start-ups often leave security considerations for later; any personal information they collect or share may not even meet the minimal industry standards and expectations of larger companies (not that such informal standards are adequate—those larger companies are often incompetent themselves).
- Silhouette 9y agoWhat's an example of a start-up collecting personal information, using it in a complex way that can't be summarized in a few paragraphs, but being unfairly burdened by this? It doesn't have to be doing any of that. Just the time and money to have a lawyer review this letter and identify the actual obligations is already a significant burden. For example, notice that just replying with everything requested here would in itself potentially breach data protection law.
- kenbaylor 9y agoThe reason why this is such a great letter is because it questions the competence of the recipient DPO. The data subject has a right to some of the information, but by no means all of it. If the DPO complies with all of it, they will breach the GDPR (e.g. Request 9b). Of course a data subject also has no right to know what security controls (request 8) you have in place, other than they are 'commercially reasonable'. A regulator can require this information, but not a consumer (data subject). This could be the basis of a great interview test for selecting your DPO.
- number6 9y agoThe request themselfs are legit. E.g request 8 is aiming at the ISO 27001 which state that the information policy is to made public to stakeholders. Request 9b is a bit tricky since the regulator have to be informed but not per se the data subject. Only if there is a risk for the data subject they have to be informed. The letter is carefully worded itself. The parts the data subject does not have a direct right to know are friendly request (eg 4 vs 8b). You can answer 8b just with one word: Yes. (Well or No) The takeaway here: If you give this letter to you technical personal you will get a detailed overview of the infrastructure they use. If you give the same letter to your lawyer you would get a very polite letter with the bare minimum of information. Example for 8b would be this: "We have technology in place which allows us with reasonable certainty to know whether or not you personal data has been disclosed"
- mjw1007 9y agoI found this part interesting: «Please also provide insight in the legal grounds for transferring my personal data to these jurisdictions.» Do you know if there's really a requirement to provide requestors with your beliefs about the law, or with legal advice you've received?
- sharkdaysunrise 9y agoThis language refers to the specific grounds established by chapter 5 of the GDPR under which transfer is allowed. The data subject is expecting you to point at the specific clause that provides legal grounds in your case.
- llao 9y agoThat looks excellent. Handling personal data is something that services should prefer not to do and if requests like this are a "nightmare" then hopefully the web will become a better place again.
- retrac98 9y agoTechnical types seem naively optimistic about how GDPR is going to work out. Businesses will do enough to pass the sniff test of proper compliance with GDPR, and no more. I've worked with enough to know most mid sized orgs are far too reactive, too technically incompetent, and far too busy making money to do a proper job on adhering. Most flout existing laws already, I don't think they'll be scared of disregarding elements of this too.
- cycop 9y agoYou right businesses will do enough to pass the sniff test, the sad thing is that is more than what they have been doing.
- donohoe 9y agoMaybe. Maybe not. I know that there is a HUGE concern about the fines that can be used to backup GDPR. I know of US companies that have a EU presence legally (but with little income from EU) that are considering just blocking EU traffic as a way to stay safe and smallest over-head.
- foobarbazetc 9y agoOr you could just run a semi-competent data operation...
- jimktrains2 9y agoThat really isn't the only reason the gdpr can cause headaches you'd rather avoid.
- guitarbill 9y agoThat's fine, businesses have that choice. Hopefully, GDPR gives people a choice w.r.t what happens with their data. Many countries in the EU have a great standard of living by focussing on individual's rights vs companies. Well, I say focussing. From our perspective, it's just normal and a good balance. But if you live in a country where companies can screw you over in a million ways ("at will" employment, arbitration, NDAs, etc.), maybe such rights might seem a bit alien.
- Radim 9y agoThese type of SAR requests (even milder ones) are of course impossible to handle manually. Self-assessment, the way most companies decided to handle GDPR, isn't much help here. How do you automate personal data discovery, especially for already existing data? Funnily, the biggest fear companies have regarding GDPR and SAR does not originate from "Mr. I. Rate the customer", like in this article. It comes from disgruntled employees ratting on the company. Employees know best where personal data is stored (and often no one else in the company does), so they can really do some surgical damage. GDPR introduces a whole new dynamic. This may be a good place to shamelessly plug a tech we developed (Show HN!) for automatically locating personal data across corporate resources: https://pii-tools.com https://pii-tools.com Personal data discovery is but a small piece in the compliance puzzle, but a piece that is critical to understanding what sensitive data is even out there: CVs with photos in backups? Scanned passports in attachments of email archives? Names and addresses in database tables? How about S3, Azure, GDrive? Let me also add that there's no shame in not having a comprehensive view of all the corporate personal inventory. Larger companies grow their resources organically, through acquiring other companies and separate business units doing their own thing. It is a complex problem, but one where technology can help.
- discoursism 9y ago> How do you automate personal data discovery, especially for already existing data? You attach an owner id to every record, and make sure all your systems can dump all information they store according to owner id. To the extent existing systems don't, you fix them.
- Radim 9y agoCharming response :-) Entire industry dismissed in a single HN comment. Poof! I'm not sure we understand "data discovery" to mean the same thing, but you reminded me of "How To Draw An Owl": http://sethgodin.typepad.com/seths_blog/2014/01/how-to-draw-an-owl.html http://sethgodin.typepad.com/seths_blog/2014/01/how-to-draw-...
- discoursism 9y ago
- unicornporn 9y agoMost of this information could be made accessible to the end user via a personal dashboard and knowledge base. GDPR will have broad implications. If you're not designing your services to be compliant there will be consequences.
- unicornporn 9y agoMost of this information could be made accessible to the end user via a dashboard and knowledge base. GDPR will have broad implications. If you are not designing your services to be compliant right now, there will be consequences.
- cycop 9y agoThe comments are an eye opening experience, amazed to see how so many people think they don't have a huge responsibility to the owner of personal information. More of a reason why GDPR is needed.
- fogzen 9y agoI’m amazed people think they own personal information at all. As if writing their name on something makes it their property.
- rdiddly 9y agoThe name itself is what is owned. You agree, since you just said "their name," i.e. "the name owned by them."
- PeterisP 9y agoWhile you may be amazed, this is literally now the truth in EU. The right to control such information is established as a right of the individual; and if you have possession of some information about me, then yes, I have more rights to control what you are allowed to do with this information in your hands than you, and that information can never in any way fully become "your property". As if possessing something makes it your property - property is a legal notion and (in democratic countries) means just what people want it to be.
- bo1024 9y agoDevils advocate -- if I write a poem for instance, and post it online, then copyright law still gives me control over uses of that information. People don't have the right to do whatever they want with that info. Is this so different? Similarly, companies often include EULA and shrinkwrap contracts governing what users are allowed to do with information accessed on their webpages. So why can't users collectively write a similar contract pointing the other way?
- ithkuil 9y ago> please provide me a copy of my data ... How should I send the personal data?
- geocar 9y agoRecital 63 gives some guidance here: http://www.privacy-regulation.eu/en/recital-63-GDPR.htm http://www.privacy-regulation.eu/en/recital-63-GDPR.htm It depends on what kind of data you have, how you keep it, how you know it is their personal data, how long you keep it, and so on.
- ThePhysicist 9y agoProviding a download link to a TLS-encrypted site that's only accessible to a logged in user would probably be the easiest way to do that.
- roel_v 9y agoA German student sued Facebook a few years ago over this and got send reams and reams of printed pages.
- thinkingemote 9y agoHow do you think Hacker News (this site) would react to such a letter, and what do you imagine a likely response would be? Would all a users comments be classed as personal data? Would just pointing at the website be enough to satisfy the request for a copy?
- geocar 9y ago> How do you think Hacker News (this site) would react to such a letter, and what do you imagine a likely response would be? I suspect Hacker News would simply delete the user's information from the site and explain that they control no data on the subject. If they are clever they would include an invoice for £10 with that response. > Would all a users comments be classed as personal data? Probably not. A user name is probably not personal data. The name "John Smith" might not even be personal data. The ICO explains: By itself the name John Smith may not always be personal data because there are many individuals with that name. https://ico.org.uk/media/for-organisations/documents/1554/determining-what-is-personal-data.pdf https://ico.org.uk/media/for-organisations/documents/1554/de... Even if the user posts a comment containing what is undeniably personal data, you still might not have to consider it personal data simply because Hacker News search sucks; Recital 26 says: To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. > Would just pointing at the website be enough to satisfy the request for a copy? Yes, in fact recital 63 recommends "remote access" as a method: http://www.privacy-regulation.eu/en/recital-63-GDPR.htm http://www.privacy-regulation.eu/en/recital-63-GDPR.htm
- e12e 9y agoMost of this seems wildly wrong and naive. What hn probably should do is offer a "takeout" option and a "delete me" option on the account page. The former would export every comment and submission along with vote counts, links to upvoted comments/stories profile data etc. All in machine readable form (eg: s-expressions). The latter would delete profile along with data. Or, possibly, simply anonymize the posts. I'm not entirely clear on the GDPR vs publishing - i don't think it's meant as a tool for "book burning" - and I've yet to see an interpretation vis-a-vis public discourse. There certainly are laws governing public archives that override parts of the GDPR in certain contexts. So while hn would probably have an obligation to export all comments, I'm less clear if they'd have an obligation to delete, under the GDPR. If the ip is logged along with actions, that'd also be considered personal data, and fall under the GDPR.
- bogomipz 9y agoThere's a different "nightmare letter" in the US, one that ordinary citizens receive. It comes from a credit agency or a company that uses a credit agency. The letter informs folks that they have been the victim of a data breach and that their personal data "may have been accessed." The nightmare letter provides little meaningful detail beyond that. The letter is sent via regular snail mail and arrives months after the actual data breach occurred. The letter is largely devoid of any meaningful recourse for the victim. It does however offer "free credit monitoring" for up to 1 year by the same agency that displayed complete disregard for security. If compliance and accountability with people's data especially when they are not permitted to opt out of such a system constitutes a "nightmare" then perhaps those companies should rethink parts of their business model.
- PaulKeeble 9y agoConsidering the normal situation is they receive no actual notice at all from most breaches and find out through the news if they are lucky I would say the very absence of disclosure is the true nightmare. You usually find out a year later when the data appears on the dark web and is then pulled into something like haveIbeenpwned.com.
- bogomipz 9y agoYes agreed and of course Experian has now starting using the existence of people's data on the dark web as another revenue stream See: http://securityaffairs.co/wordpress/64043/deep-web/experian-dark-web-tracking-service.html http://securityaffairs.co/wordpress/64043/deep-web/experian-... From the article: >"By using the “Free Dark Web Email Scan” a user will receive advertisements for Experian products at the e-mail address that is being scanned. The user agreement includes a clause which states that not only will Experian send you advertisements, but “offers for available credit cards, loan options, financial products or services, or credit-related products or services and other offers to customers.” It's like a vertically integrated criminal syndicate.
- eadmund 9y agoThat those practices are bad does not mean that something as simple & proper as storing IP addresses in your logs justifies receiving a nightmare letter. The GDPR is trying to do a good thing, but it goes too far.
- MarkMc 9y agoI would be willing to pay $10 to see the advice of a lawyer about how to respond to each question in the letter. Is this something that could be crowd-funded? Edit: Why are people downvoting this?
- trothamel 9y agoI wonder if the the end result of all of this is going to be an increase in the construction of data centers close enough to the EU to serve it properly, but outside its jurisdiction entirely. In Africa, for example, or perhaps a post-Brexit UK. It seems that being close to Europeans without being subject to EU law is going to be a big advantage going forwards.
- kuschku 9y agoThe GDPR specifically has a clause for those cases, it applies also extraterritorially, and will be inforced, if necessary, by seizing your funds via the SWIFT interbanking system. That's a very bad idea
- jimnotgym 9y agoThe UK has adopted GDPR and will sign it into UK law in April. The UK is bound by it even after Brexit. If they chose to repeal it then it could put it's firms at a competitive disadvantage with European customers
- e12e 9y agoIt might get tricky if you're planning on making money; at some point it seems likely credit card companies would be asked to stop funnelling money to "offshore criminal enterprises".
- oliwarner 9y agoJust remember there is a "go away†, this request is too onerous" get-out clause for GDPR requests. Just as there is a billable option for excessive queries. Both options have to be reasoned —and the person making the request and squeal off to the ICO at any point— but in a letter like the linked one, I would find it hard to justify forensically picking through years of historical access data and not charge a fee for doing so. Compliance regarding breach notification is forward-looking too, so all this nonsense about "has this ever happened" is outside the GDPR, as far as I can see, anyway. † The GDPR contains no rules about being polite. If somebody made demands like this at me, I would be considerably less polite than my example there.
- mindslight 9y ago> hard to justify forensically picking through years of historical access data If querying is so onerous, then why the fuck are years of historical access data even being stored ? This desire to keep reams of nebulously categorized surveillance data "just in case" seems to be one of the issues at the heart of this legislation. If it has business value and a legitimate purpose, then formalize it. Otherwise, delete it.
- oliwarner 9y agoObviously, most people might not but some will. In some countries and sectors it's a legal or contractual requirement that you keep audit trails for x years. I've worked on accounting systems where the insurers and banks have both had separare requirements here. Not that this is relevant here. My point was that if people demand retroactive notice of a breach —and you're not otherwise required to notify them— even if you have that data, you can tell them to bugger off.
- moduspol 9y agoWhat about backups? And isn't it good practice for them to be immutable? Or is that outside of scope?
- MarkMc 9y agoMy business takes credit card payment information from users. But it doesn't store that information - it just forwards it to Stripe. So if a user asks me for details of all her personal information, do I have to go to Stripe and say, "Please give me the credit card information you have on Jenny Smith"? Or do I say to the user, "Please contact Stripe directly - your Stripe customer ID is cus_34534985798243"?
- Silhouette 9y agoThis is the sort of area where interpretation comes into play. Who is controlling and who is processing the different personal data involved there? Logically, your business controls the personal information about the identity of your customer, and a Stripe token associated with their card or the equivalent. You're also presumably processing that information at least for accounting purposes. It doesn't make much sense for your business to be considered the controller of the card data that never touches your network, so Stripe ought to be considered the controller in that case, and presumably they are also processing it and potentially passing it on to further parties within the relevant card network infrastructure in order to collect payments for you. Hopefully a regulator would agree that this is a sensible interpretation of the responsibilities. However, given the mechanics involved, where your customer might not be aware at all that they are even dealing with Stripe when they provide their payment details on your business's web site, this is the kind of area where some official confirmation would be reassuring.
- creature 9y agoNeither, in this case. Under the GDPR, you'd be expected to reply something like "As described in our privacy policy we use Stripe for processing payments. The data you enter on our checkout is transferred directly to Stripe, and is not stored by us." You're expected to make sure that third parties your company works with are GDPR compliant, but that's just a case of "ensure Stripe's privacy policy reads as GDPR compliant".
- guitarbill 9y agoIt's also doesn't seem like a huge stretch for a GDPR-compliant 3rd party who's API you consume to add some GDPR-related API calls. (Payment processors are probably a bad example, as they already have boatloads of legal and contractual requirements to deal with. IF they're at all reputable, the GDPR will impact them minimally. The flip side of this is ad tech, who's scummy business model is almost painfully incompatible with GDPR - at the moment.)
- jimnotgym 9y agoAll those people who complied with the 1995 regulation and in the UK the subsequent 1998 Data Protection Act that passed it into law must be feeling a bit smug about this, as they will have this process in place already. The new General Data Protection Regulation is a welcome incremental update, which brings in much better methods of enforcement against the cross-border nature of large data processors. Facebook of course were not around in 1995. I also welcome the need for explicit plain language privacy terms. Any law that pushes out legalese must be welcome.
- mmaunder 9y agoThis is a useful exercise and not as scary as I expected. I'll bet this will be used as a template for requestors. Which makes me wonder about these requests en masse as a form of activism.
- rstephenson2 9y agoOne interesting part about this is that it's a letter, and the author never explicitly mentions that it was sent in an email. Assuming this letter arrives in the post one day, what do you do? Ask them to email you for verification? Send you one of their 2FA codes? What if your site doesn't have a login? Can they send you a screenshot of their IP address as verification? I get why the EU didn't want to overly specify the method, but it creates a lot of uncertainty about what processes are allowed/required. And with the pressure of gigantic fines on the line, it seems like GDPR opens up a significant vector for stealing other people's information via GDPR requests.
- matte_black 9y agoIs it possible to conduct some kind of denial of service legal attack against an unprepared business through the use of GDPR letters?
- s17tnet 9y agoProbably yes but IMNAL.
- IAmEveryone 9y agoNo. Long answer: people actually tried to do it to Facebook, Google, etc. As a response, they each started offering self-service tools to download your data.
- xab9 9y agoFirst you have to implement a download data function. I might be pessimistic, but with many sites requiring a login still on http and with the wonderous amount of bugs in web apps this may not be as easy as it sounds. But then: let them burn.
- Sylos 9y agoThe GDPR does have provisions against this in place. Something along the lines of you first of all being allowed to take more time to respond, if the requests are complex and numerous, to ask for a small fee then as well and in extreme cases, you can also report such abuse to authorities. And at the end of the day, you'll have to get sued for taking too long to respond, at which point a judge will investigate and can then tell that those requests were not legitimate.
- fogzen 9y agoI’m surprised nobody has mentioned that being forced to provide personal data on request does not in any way reduce the risk of personal data being misused. What’s the damage consumers are being protected from, exactly?
- wsxcde 9y agoBeing forced to comply with GPDR forces companies to keep track of data, limit usage, add data expiration policies -- all of this makes compliance easier and definitely improves security. A well-known researcher once joked to me that programmers are associated with a company for a few few years, programs live only for a few more years, but data lives forever.
- fogzen 9y ago> and definitely improves security. How? What procedure improves security? Right now, people I don't know at various companies have access to databases with my personal information. Those same people will still have the same access and opportunity to misuse my personal information, but under GDPR I can know what personal information is stored. I could also demand it be deleted, but that doesn't apply to data that's already been shared or under control of other parties.
- lagadu 9y agoGDPR is far wider than that; you're just looking at it from the end user perspective because GDPR isn't just allowing the user to enquire about their data. For a company to be GDPR compliant they also have to satisfy the regulators and that includes limiting access to data to only those that need it, knowing who those people are and putting measures in place in case of a breach.
- kbenson 9y agoAccurate knowledge of risk exposure allows consumers to adjust practices and plan accordingly. It may also incentive companies to play more carefully with the data, since they have to explain what that have done with it.
- vasco 9y agoWhat provisions are there in place for a company receiving this type of request to confirm the identity of the requesting party? Are companies expected to be able to properly identify a citizen, in order to not disclose possibly very sensitive information to someone else impersonating them? In a lot of cases the company might not even have enough information stored in order to know who the owner of a given account is. How do you prove "abc123@example.com" is Mr. Smith, if your service doesn't ask them for names? Or if it does, which Mr. Smith do you have on record? Email original senders can be spoofed. The first thing I'd do if I was a black hat type attacker would be to submit GDPR information requests to all internet companies I could think of in behalf of all my targets.
- wickedlogic 9y agoI haven't seen this reasonably addressed in any of the discussions, or org-based-presentations thus far. GDPR compliance itself basically ensures you cannot collect enough information to even defend against this type of attack vector.
- smu 9y agoThis is mentioned in the recitals: you can request additional identification, in fact you should if you can't identify the subject [1] and if you can demonstrate that you can't identify the data subject (with reasonable effort), you don't have to comply to the request. [2] [1] https://gdpr-info.eu/recitals/no-57/ https://gdpr-info.eu/recitals/no-57/ [2] https://gdpr-info.eu/art-12-gdpr/ https://gdpr-info.eu/art-12-gdpr/ (point 2)
- davidjgraph 9y agoWhere's the problem? To me it shows what an excellent job the creation of the GDPR was. It makes companies think in depth about the data they hold on me and how they process it. It also provides clear ways to question and challenge it. I've seen a number of articles trying to frame the GDPR as some kind of shambles. The shambles is the way too many companies have abused and mis-processed the data for too many years and somehow the EU lawmakers are bureaucratic imbeciles. Yet, everyone I know is fully in favour of this as consumers. And, for context, I am the person who will have to deal with these at our company. Our customers are absolutely entitled to expect us to process their personal information is a responsible manner and I hope a number of these letters are sent to every company, it's about time there was a power shift in this area.
- jcriddle4 9y agoAbout 50% of small business survive their 5th year and roughly 30% survive to their 10th year. The concern is the drip/drip effect of more and more regulation making those numbers even worse. In addition you may be saying to a poor or middle class person that the money costs of starting certain types business are not longer in reach due to much higher costs. A large well established business is in a much better position to weather these costs so the wealthy get wealthier. What are the costs compared to the benefits?
- EnFinlay 9y agoEverything there might be true. Everything might also be false. It might be cheaper to start a business because PPI information will be handled properly from the start and not be a cost centre. This might increase new business viability. Maybe there are no "costs". Just benefits and benefits?
- dsjoerg 9y agoIn general I strongly agree that regulations can be one of the slow drip/drips that crush a society over time. However there are two forms of complexity at war here; complexity for business (regulation) and complexity for ordinary people (having data about you everywhere, about everything, forever). So we have to decide which kind of complexity is worse, or how to strike the right balance.
- filoleg 9y agoSimple question: if I just want to not make my business available to subjects that fall under GDPR regulation (so that I don't have to worry about it at all), would putting up a disclaimer that you have to accept before entering the website be enough? I was thinking about something similar to how many sites that deal with alcohol content, for example, make you confirm that you are 21 or older by clicking on a button before you get access to the website. Please, refrain from sidetracking to things like "well, you wouldn't worry about it if you built everything with GDPR in mind in the first place". That's not what I was asking.
- deleted 9y ago[deleted]
- isostatic 9y agoAny company can be asked about gdpr, you can ignore it, and on the whole jurisdiction isn't going to cross boundaries (the u.s does believe it's federal laws apply globally, but it's rare they enforce it) However should you ever do business or go to an eu country you may struggle. Just like if you insult the Thai King, then go to Bangkok on holiday, you may well get arrested. Or if your company is accused of breaking the dmca and then go to the u.s on holiday you get arrested.
- filoleg 9y agoI understand your point, and I agree that this is what would probably happen if I just ignored it, but how would my service be breaking the rules, if it explicitly would state that it is not designed for citizens of EU and that if you click "yes", then you confirm that you are not a EU citizen? Wouldn't that be on the user for lying, in the same way it would be if an underage person visits an adult website and clicks a button that says "Confirm that I am 21+"?
- isostatic 9y agoI would suspect the EU would find such a box irellevent and would deal with you like the US dealt with David Carruthers or Peter Dicks
- adamwathan 9y agoWhat frustrates me the most about the GDPR is that a single person building a mailing list for a $19 ebook launch is just as affected and burdened as any other company. A side-business that might make you $30,000/yr is now no longer worth pursuing because of the costs of working with a lawyer to make sure you are GDPR compliant and have all of the right policies in place. It raises the barrier to entry for small one person businesses even more, forcing out anyone who can't justify the costs of compliance.
- simooooo 9y agoThere is a clause in the GDPR relating to the reasonable cost of providing the data. So there is potentially an escape route
- rikkus 9y agoPerhaps services that help build mailing lists will offer a feature of handling GDPR requests on your behalf.
- jopsen 9y agoIf you're building a mailing list for your ebook, won't you just need: 1) Allow people to login and view their personal information: name, email. 2) Allow people to delete the profile. And don't retain any data other than (1) or (2). If you want to track users to see if they clicked links and what countries they are browsing from then: (A) anonymize it or (B) make it visible in the profile information (1). If all you record is name and email, you won't need a lot of infrastructure. Your policy might say you transfer email addresses to AWS when sending emails.
- a3n 9y agoCompanies make millions and billions off data naively or knowingly given up for free. So, I weep. /s And if this becomes more than the odd request, build it into your processes. If you can identify me "as me" to your advertisers and other data customers, you can certainly do that for me. Or just do what other businesses do: pay off a few legislators to change the law, or a lobbying firm or association. If you have the money, pay to make this a patriotic move. That's how democracy works. /s
- cromwellian 9y agoIt's not baking security/privacy in from the start that's the problem, it's the need to have a "compliance officer" and have to handle these requests. Small companies don't have time or resources for this. Look at the American Disabilities Act, an act that has done enormous good in many ways, but that has also lead to an entire industry of lawyers hassling tiny businesses over insignificant infractions. (e.g. https://www.mercurynews.com/2016/04/10/serial-ada-lawsuit-filer-striking-bay-area/ https://www.mercurynews.com/2016/04/10/serial-ada-lawsuit-fi...) Startups in the US won't have this hassle. You don't have to serve EU customers to reach mid size/product market fit, you can concentrate on iterating on your core product. When it's time to scale, then you can look at GDPR. So limited resources stretch further. But if the lawyers in Europe start becoming a nuisance to startups there, it's just going to force more and more services to be located overseas, and more and more government complaining about the dominance of overseas tech, a problem they're probably going to make worse.
- guitarbill 9y ago> Startups in the US won't have this hassle. Startups in the US are what got us into this privacy nightmare in the first place. Of course, they are no longer startups, but they still didn't fix shit once they got bigger, so I don't see how this argument holds. I like to think of privacy like internationalisation or security. When I started programming, Unicode/UTF-8 was niche and not well supported at all. Now, for new languages, it's a given. The same with decent crypto libraries. Databases now offer pretty great unicode support (except for the old ones where it had to be bolted on, coughMySQLcough). It isn't inconceivable that privacy tools become standard in databases and data processing frameworks. Personally, I see this as a brilliant opportunity for people/companies who want to do the right thing for their customers (whether that's consumers directly, or a company using them). My prediction is you'll see this with cloud providers strongest. Some are putting a lot of effort into GDPR, and a properly compliant provider will become a huge value-add, and not a liability.
- briandear 9y agoYou don’t think BNP bank or AXA insurance play loose with sharing personal data? I had my Peugeot dealer share my purchase information with a third party “extended warranty” vendor without my permission. The vendor called me and sent letters. I never told Peugeot that they could sell my data. I have never given any business permission to call me — yet they do. Blaming US tech is naïve. European companies have been engaged in non-digital forms of privacy invasion long before Google even existed.
- amelius 9y agoHow do you reply safely to such a data request? I mean, this could have been written by an impersonator. And even if you can verify the identity, you still need to send sensitive information somehow.
- amelius 9y agoWouldn't it be fair if the GDPR allowed for a small administration fee, for such requests?
- mirimir 9y ago> 3. Please provide a list of all third parties with whom you have (or may have) shared my personal data. I wonder whether this includes police and TLAs.
- av501 9y agoJust because you are small does not mean not doing the right thing is something you should get away with. I see lot of comments of how doing the right thing can be a burden. However, I see it the other way. Not doing the right thing is a burden you have to carry with you everyday. GDPR is helping you with guidelines on how to shed that burden. I do not know how and won't imagine it is easy, but I wish something in our existing socio-economic systems would slowly edge towards making 'doing the right thing' a significant variable that everyone has to care about for their own wellbeing and prosperity.
- chasb 9y agoBe aware, this article is not a list of GDPR requirements. It is, however, a good list of questions that every business processing data in the cloud should be aware of. You need to be able to answer these questions.
- jakeogh 9y agoI just had an awesome idea. Lets make keeping records of past information and actors encountered illegal if they don't want you to remember, while at the same time make it trivial for the same people to waste your time by demanding free consulting.
- aazar 9y agoHi Everyone, I am the Co-Founder of ECOMPLY.io. I thought about jumping in and helping you all out. First of all, you need to understand, do you have customers in Europe. If yes, is data your everyday thing? If yes, then you need to comply with Article 30 first. Article 30 asks, how many processes of you have, how many of them have personal data involved, and then tell you to answer purpose, legal basis, category of personal data and deletion request. I took an interview from Mailjet how they did it: https://ecomply.io/how-to-become-gdpr-compliant-insights-from-mailjets/ https://ecomply.io/how-to-become-gdpr-compliant-insights-fro... Now, how to answer Subject Access Request, once you're done with article 30 i.e. records of processing activities, you'll know what, where and how you obtained that data with the purpose and legal basis. This request will be difficult to answer then: Here are the 10 steps you need to do: https://ecomply.io/10-critical-steps-to-general-data-protection-regulation-gdpr-for-smes/ https://ecomply.io/10-critical-steps-to-general-data-protect... It's a piece of cake then. Plus, you need to change your way of doing sales & marketing in Europe: https://ecomply.io/pimping-up-your-sales-in-a-post-gdpr-world/ https://ecomply.io/pimping-up-your-sales-in-a-post-gdpr-worl...
- red_admiral 9y agoHave I Been Pwned is going to hit 5 billion breached accounts any day now. If the GDPR pushes back against this kind of thing, all the better. If the GDPR makes it harder to found a startup for the sole purpose of collating and monetizing people's personal data, I'm not too upset either. If a company suffers a data breach and can not answer to all of point 7. in the linked page, I'll leave it to the lawyers whether this is negligence but I'm inclined towards "yes" myself. The moment you want to process any credit card data, you're already bound by regulations with teeth: the PCI-DSS. That's why in several recent data breaches one of the first things you read on the breach notification was "no payment card data was affected", suggesting that it's less important to the company if they lost "only" personal data. Bring on the GDPR.
- Zigurd 9y agoThis looks like the mirror image for the requirements document for protecting PII. You may not need to be able to respond directly to every demand in the letter, but you should be able to have a watertight explanation of why not. "Burdensome" won't cut it.