5 ms·
In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.
by philipps 8y ago
In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.
- morgante 8y agoThe law could have easily been tailored to target large social media companies. Instead it applies to everyone, including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.
- vincnetas 8y agoAnd then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...
- dannyw 8y agoThere are plenty of laws and legal instruments / concepts (controlling stake, anti-avoidance laws, etc) that stop large companies from doing this.
- morgante 8y agoAnd that is just as "possible" under the current structure of GDPR.
- pilsetnieks 8y agoNot really. For example, if Facebook Inc. establishes a "Totally not FB LLC" for the purpose of skirting GDPR, Facebook Inc. is still the data controller according to the law, as it is directing the data collection and purpose, even if "Totally not FB LLC" does all of the handling as a data processor. Except now the fine is levied on the total turnover of both companies, not just one.
- morgante 8y agoRight, I meant it's just as "possible" in the sense of it not really being practically possible.
- pbhjpbhj 8y agoWhat PII are you gathering? Can't you just remove those fields, add a consent field, drop old PII from your DBs? I imagine most CMS will have the option to do that at update?
- grabeh 8y agoIt would be a shame to take down your old blogs as I'm sure people get value from them. My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely am I to be subject to a targeted attack where people try to remove information from my server? How likely am I to be the subject to enforcement action if my server is hacked and data is leaked? On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event. If you're outside the EU, GDPR will only apply if you are actually offering goods/services to those in the Union, or are monitoring them. I take the point about analytics in the second place, but in the absence of analytics, I don't see that making available a blog constitutes the offering of goods/services?
- morgante 8y ago> My approach is one very much based on risk Mine too. The risk is massive fines, while I currently derive virtually no benefit from my online presence. > On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event. I also own a business and previously several of my clients have come through my blog postings.
- pilsetnieks 8y agoDo you habitually post personally identifiable information of other people in your blog without their consent?
- grabeh 8y agoJust to be clear, there is little to no risk of someone running a simple blog getting fined by a data protection regulator. In the UK for example the ICO who regulate data protection matters concluded 17,300 cases, in which only 16 of them resulted in fines. I’m just intrigued as to how you have developed this perception of GDPR and data protection law looking to regulate small one man blogs out of existence? /edit oh and my other point still remains - even if you’ve got some customers through a blog, you don’t appear to be within scope of GDPR on the assumption you’re not directly looking to do business with EU based customers (for example through offering payment options in European currencies).