3 ms·
Not true; GDPR explicitly grants a large number of rights to the data subject. [1] These rights include: * the right to be informed about what data is process
by molf 9y ago
Not true; GDPR explicitly grants a large number of rights to the data subject. [1]
These rights include:
* the right to be informed about what data is processed
* the right to access all data gathered about them
* the right to rectification of incorrect data
* the right to receive an export of the data in a common format
* the right to object, to have all data removed, and to restrict processing until further notice
GDPR also requires a data controller to respond within a month, and not charge any fee for this unless the requests are excessive (because they are repetitive). [2]
[1] https://gdpr-info.eu/chapter-3/ https://gdpr-info.eu/chapter-3/
[2] https://gdpr-info.eu/art-12-gdpr/ https://gdpr-info.eu/art-12-gdpr/
- kasey_junk 9y agoThe letter is a nice mix of asks that are specifically covered, rights that might be covered & things that are not covered at all. In that sense it’s a great way to rattle someone without specific GDPR guidance. But all things being equal, the large orgs that are capable of systematic data collection, are not at all troubled by it & certainly won’t be answering it with direct point by point answers.
- molf 9y agoWhich things that are mentioned do you believe are not covered?
- kasey_junk 9y agoI’m not a GDPR lawyer or auditer, do nothing in this reply should be seen as advice. My general feel is that if he didn’t cite a specific article it was on purpose. He took implications or broad interpretations for anything not explicitly cited. A couple that jump out immediately are the requests for server locality information, retention periods & specifics about security policies are the ones that are likely to get a very polite “we conform to industry best practices piss off” replies.
- molf 9y agoThat's all neatly laid out in article 13. [1] I'm not a lawyer but having extensively studied all of GDPR recently I'm afraid the letter seems legit. If there's any error it will be a minor one. [1] https://gdpr-info.eu/art-13-gdpr/ https://gdpr-info.eu/art-13-gdpr/
- kasey_junk 9y agoArticle 13, to my reading, provides no basis for requiring locality information or security policies. The retention declarations I’ve seen have been legal niceties that don’t answer the question in a way that makes it clear what the retention policy is. I’m not suggesting that the letter won’t get a response. I’m suggesting there isn’t anything in it that would cause a large organization to send any different a response than if they got a letter written in crayon that said “gives us the GDPR data”. In that way it’s not a “nightmare” letter. It’s the default thing you pay lawyers for.