4 ms·
For most smaller businesses there is no real reason to do all that much as long as you can answer such questions on an ad-hoc basis. Although of course we still
by molf 9y ago
For most smaller businesses there is no real reason to do all that much as long as you can answer such questions on an ad-hoc basis. Although of course we still have to see how widespread it will become in practice.
Basically you need to make sure you 100% know what data you collect (including any third parties) and make sure you have a good reason to collect it.
Honestly most of GDPR should be considered "common sense". It's just that many corporations actively act against the interest of individuals they collect data on, and it's precisely these practices that GDPR tries to correct.
- Silhouette 9y agoUnfortunately even if you're already handling personal data responsibly, the GDPR still also requires that you be able to provide various documented policies to your regulator on demand, still contains lots of ambiguity about how far subject rights can go in practice, still imposes obligations to include lots of extra detail in privacy policies or otherwise provide lots of information and active warnings to data subjects, etc.
- ryandrake 9y agoHow about, “Our documented policy is to not collect personal information from users at all.” Assuming it’s true, wouldn’t that be compliant?
- kasey_junk 9y agoGDPR also expands what is personal data to include things that are collected as a matter of course such as IP address. You likely have a reason to log that data but GDPR requires that you document it. Further it reaches into your business even if you aren’t trying to do business in the EU, as EU citizens can come to your site without your control. There is a lot to like with GDPR but it absolutely is expansive & easy to have many interpretations.
- ryandrake 9y agoMaybe these things shouldn’t be collected as a matter of course. Should web servers log client IP addresses by default? Why? Does my mail server need to log email addresses of incoming mail by default? “Logging all the things” as default behavior really needs to be a thing of the past. If anyone wants to get their feet wet in open source, there are thousands of high profile projects out there that could use a patch to scrub PII from their logging, and these are probably simple diffs.
- merinowool 9y agoWhat if you have a forum and users of that forum commit a crime, police asks you to give up their data and you say you don't have any data?
- wadkar 9y ago> you say you don’t have any data? And what’s wrong in telling the truth to the police? Sounds great to me. Also, see how signal responds to such requests.
- Silhouette 9y ago“Logging all the things” as default behavior really needs to be a thing of the past. Maybe, but logging useful things is reasonable. We investigate problems with our systems using server logs. We diagnose various security threats, fraud risks and ToS violations using server logs. We're generally respectful of users' privacy, but we also have a legitimate interest in knowing how our systems are being used and preventing people from doing bad things with them. Those legitimate interests may take precedence over a visitor's right to privacy in some cases, in the same way that you can't tell a government to forget your criminal record or a bank to forget that you owe them money.
- Silhouette 9y agoPresumably it would, but since approximately 0% of businesses that actually do anything could make such a statement truthfully, that doesn't help very much.