7 ms·
All you’re telling me is that your Agile Startup doesnt have: 1) an updated Asset Inventory 2) a Data Classification Scheme 3) Data Labeling Policy & Procedu
by akshatpradhan 9y ago
All you’re telling me is that your Agile Startup doesnt have:
1) an updated Asset Inventory
2) a Data Classification Scheme
3) Data Labeling Policy & Procedure
Those are basic components of an InfoSec 101 course taught by Community Colleges and the top basic items GDPR is wanting.
- Silhouette 9y agoThe GDPR is an EU regulation, but you appear to be adopting some US(?) based conventions and terminology, and then posting a string of buzzwords that have little if any connection to the subject at hand. Also, are you seriously suggesting that in response to a formal legal communication it's a good idea to reply without having input from a lawyer?
- discoursism 9y agoYou probably need a lawyer to help you write the document the first time, and to update it when you make new partnerships or develop major new pipelines for data. You probably don't need a lawyer every time you receive such a letter.
- Silhouette 9y agoYou probably don't need a lawyer every time you receive such a letter. For routine enquiries, maybe not. For a letter like this, from someone who is clearly intending to trip you up and cause trouble, our lawyer is the first call I'm making, every time. And that initial conversation is already going to cost me hundreds of pounds and a half-day of work, even if I already have reasonable answers to anything we are actually required to respond with under the GDPR here.
- discoursism 9y ago> For a letter like this . . . our lawyer is the first call I'm making /shrug It's your money. You could do that, or you could even light it on fire if you wish. It's no skin off my back. If your company is profitable enough to eat this self-imposed overhead, then its owners will just make less money. If it's not, then leaner competitors will replace it. I'm fine with either outcome.
- Silhouette 9y agoIn this area, we have no idea which overheads are actually going to prove justified and which are just throwing money away. That's one of my main points here. As I've argued several times on HN recently, a big part of the problem is that if you're running a small business that isn't handling large amounts of personal data but obviously is going to be subject to the GDPR like everyone else, there is no clear indication of what you have to do to be considered reasonably compliant. The GDPR itself is very heavy and has little in the way of moderation for small-scale data controllers/processors, so in practice it's going to come down to interpretation by regulators (and potentially anyone who has rights under the GDPR and wants to make trouble, as in the example we're discussing). If you don't do enough, you potentially face even greater overheads due to formal audits, financial penalties, etc. If you do too much, then as you rightly point out, you leave yourself at a disadvantage compared to competition who don't do as much (and this remains the case even if that competition is knowingly breaking the law as a result, and that in turn doesn't matter if they face no meaningful penalties for it).
- discoursism 9y ago> we have no idea which overheads are actually going to prove justified and which are just throwing money away Life is risk. I contend that if you make a good faith effort to comply with this law (i.e. consult with a lawyer, once, to develop those eight documents you mentioned in another part of this thread) and generally practice good private information hygiene (wipe out old data, don't log private info, don't retain logs or emails too long, etc.), you're probably going to be fine. This is probably not going to be in the "inner loop" of risks your small business faces. In every regulation, there are winners and losers. Some of the losers didn't do anything wrong, but are just losing because that's the nature of designing laws that factor in disparate interests. At this point, it's the law, and your only choice is how you're going to handle it. And my contention is that, if your small business is receiving letters like this with any regularity, calling a lawyer and spending half a day on it each time is not among the reasonable spectrum of risk-mitigating responses.
- DanBC 9y ago> there is no clear indication of what you have to do to be considered reasonably compliant. This is just untrue. THere are fucking reams of advice to small businesses. https://ico.org.uk/for-organisations/resources-and-support/getting-ready-for-the-gdpr-resources/ https://ico.org.uk/for-organisations/resources-and-support/g...
- akshatpradhan 9y ago>Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases. Data Classification >a. In particular, please tell me what you know about me in your information systems, whether or not contained in databases, and including e-mail, documents on your networks, or voice or other media that you may store. Data Classification >b. Additionally, please advise me in which countries my personal data is stored, or accessible from. In case you make use of cloud services to store or process my data, please include the countries in which the servers are located where my data are or were (in the past 12 months) stored. Asset Inventory >2. Please provide me with a detailed accounting of the specific uses that you have made, are making, or will be making of my personal data. Privacy Impact Assessment >3. Please provide a list of all third parties with whom you have (or may have) shared my personal data. Privacy Impact Assessment >a. If you cannot identify with certainty the specific third parties to whom you have disclosed my personal data, please provide a list of third parties to whom you may have disclosed my personal data. Privacy Impact Assessment >b. Please also identify which jurisdictions that you have identified in 1(b) above that these third parties with whom you have or may have shared my personal data, from which these third parties have stored or can access my personal data. Please also provide insight in the legal grounds for transferring my personal data to these jurisdictions. Where you have done so, or are doing so, on the basis of appropriate safeguards, please provide a copy. Asset Inventory >c. Additionally, I would like to know what safeguards have been put in place in relation to these third parties that you have identified in relation to the transfer of my personal data. Access Control >4. Please advise how long you store my personal data, and if retention is based upon the category of personal data, please identify how long each category is retained. Data Retention >5. If you are additionally collecting personal data about me from any source other than me, please provide me with all information about their source, as referred to in Article 14 of the GDPR. Data Collection >6. If you are making automated decisions about me, including profiling, whether or not on the basis of Article 22 of the GDPR, please provide me with information concerning the basis for the logic in making such automated decisions, and the significance and consequences of such processing. >7. I would like to know whether or not my personal data has been disclosed inadvertently by your company in the past, or as a result of a security or privacy breach. Breach Escalation >a. Please inform me whether you have backed up my personal data to tape, disk or other media, and where it is stored and how it is secured, including what steps you have taken to protect my personal data from loss or theft, and whether this includes encryption. Backup >a. What technologies or business procedures do you have to ensure that individuals within your organization will be monitored to ensure that they do not deliberately or inadvertently disclose personal data outside your company, through e-mail, web-mail or instant messaging, or otherwise. Log Review >c. Please advise as to what training and awareness measures you have taken in order to ensure that employees and contractors are accessing and processing my personal data in conformity with the General Data Protection Regulation. Security Awareness Training >8. I would like to know your information policies and standards that you follow in relation to the safeguarding of my personal data, such as whether you adhere to ISO27001 for information security. Get an ISO audit.
- jimnotgym 9y agoThe answer every single time is: A) You are using personal data in good faith as part of and don't need a lawyer. Just reply. I work for an organisation at the larger end of the SME scale and wont be using a lawyer. Like I don't use a lawyer for routine contractual disputes like debt collection until the debtor refuses to pay. B) You are walking a fine line and relying on the exact wording rather than the spirit of the law. You are not acting in good faith and trying to make money out of customer data. You need a consultancy firm and lawyers and you wont get any sympathy from me. I'm not sure whether you are serious or this continues your repeated anti-EU comments on HN, Silhouette. I find it OT and I hope the moderators do to.
- Silhouette 9y agoI'm not sure whether you are serious or this continues your repeated anti-EU comments on HN, Silhouette. To the extent that I am anti-EU in some respects, particularly around the areas of small businesses and excessive regulation, that is born of experience. As I have mentioned in previous comments, which apparently you might have seen, I have been on the wrong side of EU rules being over-zealously applied before, and I have been on the wrong side of a government regulator that is for most practical purposes above the law making a mistake before. Some things that some commenters tend to dismiss as hypothetical, I know from direct personal experience to be real threats, and I will challenge bad laws that allow scope for such threats to exist. I find it OT and I hope the moderators do to. I'm sorry that you feel censorship is a useful response to someone with different experience and views to your own. I like to think that HN is a forum where people can discuss such differences of opinion openly and intelligently.
- akshatpradhan 9y ago>I know from direct personal experience to be real threats Access Controls, Data Classifications, and Privacy Impact Assessments requested by GDPR are not a threat. That’s just security 101 basics.
- TomMarius 9y ago
- DanBC 9y ago> Also, are you seriously suggesting that in response to a formal legal communication it's a good idea to reply without having input from a lawyer? You don't need a lawyer to reply to GDPR letters. You do need to comply with the law when you collect personal data. What you're saying is "I should be free to ignore the law until someone writes to ask about my compliance, and when they do it's burdensome for me to get legal advice to respond to that letter".
- Silhouette 9y agoI'm saying no such thing, and it's neither courteous nor constructive to twist words like that. You keep asserting that it's not necessarily to have a lawyer review a letter, despite the letter being legal in nature and in this case clearly coming from someone who is looking to cause trouble. Clearly you and I have very different attitudes to risk in this respect. In any case, an obligation to comply with the law is self-evident. My objection is that the law itself is poorly implemented and that what is necessary to comply is ambiguous.
- DanBC 9y agoEverything you do with customers is legal in nature - what do you think governs your relationship if it's not legislation? Your repeated scare mongering around GDPR is fucking tedious, especially since almost everything you've said about it is false.
- tonfa 9y agoAren't those letters already pretty standard anyway? I was sending those to various places > 10 years ago using the existing privacy/data protection laws in the country I was a resident in. (you get fun stuff back, I got all the logs from my public transit card that way)
- Silhouette 9y agoEverything you do with customers is legal in nature But most interactions with my customers do not begin with a multi-page letter that literally opens with a direct threat and then proceeds to demand a response on 40 different points. Your repeated scare mongering around GDPR is fucking tedious I run small businesses, and we have been dealing with GDPR issues. The ambiguity and overheads I have been talking about in this discussion are costing us time and money right now. Dealing with a letter like they one we're discussing would cost us more time and money. Apparently we aren't alone in these respects. Some of the GDPR's supporters have argued that the lack of proportionality in the actual regulations is not a problem because the regulators will enforce it pragmatically. I have personally heard such arguments made about onerous EU rules before, and through my own businesses I have been on the receiving end of government mistakes and their rather unpleasant consequences. And again, that wasn't some freak unlucky event: thousands of other businesses are known to have been subject to similar problems, in more than one incident, involving more than one government authority. A few people have suggested that involving lawyers in response to a letter like this is unnecessary. Clearly it's going to be a matter of risk assessment, but I don't think it's unreasonable. Once again, I have personally seen (at a former employer in this case) how much time can be wasted if a company gets caught up in formal legal proceedings even having done nothing wrong. In short, there are people out there dealing with the issues you call "scare mongering" every day. These are not just hypothetical problems. Maybe you've never been caught up in them yourself, but sadly not everyone is that lucky. especially since almost everything you've said about it is false. If you're going to call me a liar, please at least tell me what I've written anywhere in this discussion that was false so I can set the record straight.
- eximius 9y agoYes, I can just imagine this is the first thing I'd do when starting a business. /s
- ncallaway 9y agoOkay, that's fair. Don't do those things when you start a business. But, then, don't have your business collect and process data on individuals.
- delecti 9y ago> Don't do those things when you start a business. > But, then, don't have your business collect and process data on individuals. Aren't those two statements together effectively equivalent to "don't ever start certain kinds of businesses"?
- toomuchtodo 9y agoThat’s the goal. My data is my data, not the fundemental requirement of some businesses.
- delecti 9y agoI certainly respect your desire for no businesses to have certain pieces of of your personal data, but there's a difference between "I don't want to be a customer of certain kinds of businesses" and "such businesses shouldn't exist at all". And beside that, regulations that effectively result in prohibiting certain kinds of businesses even though they don't explicitly do so are bad regulations IMO.
- toomuchtodo 9y agoI understand your sentiment, but we’ve swung so far towards the unrelenting abuse of consumer data, I’m supportive of regulation through any means necessary. To your point, if a business is not explicitly banned, but banned because of regulation about what that business can do, that’s exactly the sort of regulation we want. We don’t dictate your business specifically, just what you can and can’t do with the data. If you can operate within those regulations, congrats!