6 ms·
This post was inspired by "The Nightmare Letter: A Subject Access Request under GDPR" [0]. Which shows the potential scary consequences of subject access reques
by twakefield 9y ago
This post was inspired by "The Nightmare Letter: A Subject Access Request under GDPR" [0]. Which shows the potential scary consequences of subject access requests.
There's a lot of FUD around this topic. I've seen posts opinions ranging from "no big deal" to "this is actually good for U.S. SaaS" to "This is going to kill SaaS". It will be interesting to see how enforcement of the GDPR plays out.
At the moment, with Facebook transgressions in the news, the pendulum seems to be swinging towards privacy. We'll see how far it swings.
[0] https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/ https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
- louthy 9y agoAs a CTO at a European SaaS company I don't particularly find 'The Nightmare Letter' nightmarish at all. If you're doing your job properly then this stuff isn't hard. It's had very little effect on our day-to-day - yeah, it's cost us real cash money in lawyers, and additional training for GDPR, but most of what is going to be legislation we were already doing. As an individual I welcome this legislation - it should really help to stop the shoddy practises that clearly go on (based on the amount outrage I've seen on this issue). GDPR seems, to me, to be proportionate and reasonable. I don't see this helping US SaaS companies, because once GDPR is in-place then I'd consider EU SaaS providers to be more attractive. It's a real selling point that your data isn't leaking or being mismanaged. If anything I see this as a potential boon for the SaaS companies doing their job properly, because the companies that have in-house systems (or have their own bespoke solutions) are going to have to prove those systems themselves - and have all the answers to The Letter. Whereas a good SaaS company can take those problems off their hands.
- ryandrake 9y agoNothing in that nightmare letter seems unreasonable for an end user to want to know, and I'd be hesitant to do business with a company that can't answer those questions about their own business. If those "nightmare" questions are the bar, it's a pretty low bar.
- amarkov 9y agoThe issue isn't whether the company has the answers to the questions, but what it costs to assemble those answers in the requested form. You can't respond to detailed legal inquiries by just having customer support copy-paste from documentation; they don't have the expertise required to guarantee a complete and correct answer.
- qw 9y agoWhy do they have to copy and paste? Why couldn’t they make a self service tool where they login and get all documentation that is required by law? The law says that you have the right to information, but does it say you have the right to a human responding with only the requested information?
- heavenlyblue 9y agoJust the same way a bank clerk is given a set of security questions so that he could prove your identity and the legal/security departments make sure those questions are relevant and to be trusted. Most of the time you're not speaking to the bank's lawyers when trying to open an account.
- adventured 9y ago> I don't see this helping US SaaS companies, because once GDPR is in-place then I'd consider EU SaaS providers to be more attractive. It's a real selling point that your data isn't leaking or being mismanaged. That doesn't make any sense. If GDPR is in place, then US SaaS firms won't be leaking & mismanaging your data, the whole point is they'll have to start complying or else. US SaaS firms will still have a vast advantage because: they're radically larger with far greater financial resources, have a drastically larger VC environment of initial funding, and still have the world's largest homogeneous economy as the base hub to initialize out of and get to huge scale to easily afford to spend anything they need to on compliance. What the EU just did is make the compliance picture far more difficult and complex for small European competitors as a whole. With Brexit, the EU lost 15% of its economic mass, further aggrevating this concept of regulatory & compliance splintering across Europe. The European splintering will only get worse as individual European non-EU nations come up with their own rules on this type of stuff. Salesforce or Workday can more easily comply with a dozen compliance approaches across the whole of Europe, than a given start-up in Portugal or Greece can.
- heavenlyblue 9y agoYou're making an argument about the good parts of GDPR into an argument about whether the political system should take sides in terms of business opportunities it gives. Is GDPR good for personal data safety? I think it is. Is GDPR easier for small businesses than for larger ones? No.
- moduspol 9y ago> I don't see this helping US SaaS companies, because once GDPR is in-place then I'd consider EU SaaS providers to be more attractive. It's a real selling point that your data isn't leaking or being mismanaged. Does GDPR prevent data from being leaked or mismanaged?
- heavenlyblue 9y agoBut it gives a clear way of penalising the company if they are caught doing so (and a clear definition of what "doing so" means).
- louthy 9y agoNo - but it penalises you if you fail to follow best practice (like not encrypting data at rest for example). So, the incentive to do the right thing is greater seeing as you can be fined a percentage of your turnover.
- moduspol 9y agoIndeed. Just pointing out the clear difference between that and what was stated.
- louthy 9y agoThanks for clearing that up. I’m sure nobody knew what I meant until I made the clarifying post above. As an individual I am much more likely to trust an organisation that follows GDPR regulations over one that doesn’t. That obviously doesn’t mean they’re never going to have a data breach- but by law they will have to announce it within 3 days, and will face massive fines if negligent - that, to me, is a company I would prefer to give my business to - and was my point. Pedantry doesn’t help.
- moduspol 9y agoGDPR is very popular here on HN, but I think it's important to keep a level head about what it actually does and what its real-world effects will be. That is the entire point of this thread, after all. The difference between "not having a breach" and "a legal obligation to announce it within three days" is not semantic. It is absolutely material to the real-world value of GDPR, and claims about it should reflect that.
- hectormalot 9y agoI suspect that the 'nightmare GDPR letter' pushes the boundaries on what the GDPR would probably intent as a reasonable request, and I wonder if it would hold up in court if challenged by one of the companies. I think most of the provisions make a lot of sense if you look at them in a simple way. It's not unreasonable to ask a company: * what information on me do you keep? * what are you using it for? * can you provide me with a copy of my data? (with interesting situations where the data itself might be privacy or competitively sensitive, e.g. can I expect a company to share derived insurance scores with me? what if the data also includes other people's data?) * can you erase my data? As for impact on small SaaS businesses, I think it is relatively limited. .e.g For my SaaS side business I could probably answer the nightmare request within a day, if I would get 1+ request per week we could probably automate the response, with the exception of manual ID validation. Information deletion is something that the app wouldn't handle well at the moment and would be a bit more work. Thinking of it in this way, this is probably only a problem for a) large user bases (in which case I hope companies have the capacity to automate these requests efficiently), and b) data hoarding / ad companies (for which I don't really feel sorry)
- kenbaylor 9y agoFor any company that is compliant with GDPR (after 25th May 2018), the answers your 4 questions (2 on data collection, other 2 on data subject rights) must already be in their privacy notice on their website, with instructions for how to contact their data protection officer.
- wukerplank 9y agoThe privacy laws in my country were nearly as restrictive as GDPR and now they get a bit stricter. No big deal. GDPR is only stating the obvious and actually it is sad that the protection of most private information is not common sense but needs to be enforced with rigorous punishment.
- Spearchucker 9y agoI've had that letter bookmarked for months now, and the thing that worries me most is that for example, as a subject that hasn't ever owned an Android phone, doesn't use Google, Gmail or have a YouTube account - if I send that letter to Google, what stops Google from just straight-out lying to me? How do they prove their honesty to me if they say "we got nothing on you"?
- kenbaylor 9y agoThis is a key reason why there are data protection officers under GDPR. They report to the highest level of management (mostly the board) and are independent. They are also called mini-regulators. They ensure the company is compliant. If they are not doing their job, (and you are not content with their reply), you then appeal to the Data Protection Authority (DPA, Privacy Regulator in the country). The DPA has full powers of subpoena (and a whole lot more), and are not to be trifled with.
- chopin 9y agoThat doesn't help. I'm in a similar position, but I'd like to know which data has eg. Facebook on me. If they write back "you have no account, we have no data on you" how I am to know that this is true (and it is almost certainly not)? With nothing on hand it doesn't make sense to go to a regulator.
- kenbaylor 9y agoThere is a process to be followed. If you have the response from the DPO and a reasonable suspicion based on evidence, you can absolutely to to the DPA. If your evidence is strong, that may proceed on that. If not but there are many other similar complaints, they can formally ask the company to 'clarify' issues....which is a very dangerous thing if you are a company that is evasive.
- heavenlyblue 9y agoYou have an entity that regularly creates accounts on Facebook, then sends the letters requesting the data Facebook holds for them. For any requests replying those accounts do not exist that entity brings Facebook to court.