5 ms·
What happens when GDPR conflicts with SOX, which prohibits the destruction of data? GDPR is a great example of the kinds of disasters that happen when nations
by originalsimba 8y ago
What happens when GDPR conflicts with SOX, which prohibits the destruction of data?
GDPR is a great example of the kinds of disasters that happen when nations try to force the entire planet to follow their unilateral actions.
- kartan 8y agoIf you are a bank and a client asks you to delete their data. The bank will still keep it for the tax agencies. If a tribunal gets asked to delete the personal data of the accused, they will keep the data. There is a principle of public interest and public obligations to keep data. What part do you think that is a disaster?
- originalsimba 8y ago> What part do you think that is a disaster? uh... this post is about a guy losing his business because of the GDPR. What part of that isn't a disaster? >If you are a bank and a client asks you to delete their data. The bank will still keep it for the tax agencies. > If a tribunal gets asked to delete the personal data of the accused, they will keep the data. > There is a principle of public interest and public obligations to keep data. In other words, GDPR has no teeth outside of Europe.
- lazyasciiart 8y agoGPDR explicitly lets organizations keep data if they need to. Do you think it just turned into a magical get-out-of-your-past switch that means "my employer will have to delete records of firing me!"?
- originalsimba 8y ago> In other words, GDPR has no teeth outside of Europe. In other words, GDPR has no teeth outside of Europe.
- abraae 8y agoI don't think you've read the legislation. Your example "my employer will have to delete records of firing me!" is exactly how the GDPR works. There are exceptions -e .g. if the firing is now leading to a court case, but they are less than you think. In an ironic twist, after deleting the data subject's personal information, you must be left with nothing that identifies them, so you don't even know that they have requested this in the past - only that someone exercised their right to erasure (not who).
- lazyasciiart 8y agoYes, I have read it, although I am not a lawyer. Have you? Because the exceptions include "necessary in relation to the purposes for which they are collected or otherwise processed", and avoiding re-hire of a bad employee seems pretty related to the purpose of identifying employees in the first place. If you have professional legal advice to the contrary I would definitely be interested in knowing more.
- abraae 8y agoI'm not a lawyer but I've read it fairly thoroughly. From the ico, the exceptions to the right to erasure are below (none of them cover your example): The right to erasure does not apply if processing is necessary for one of the following reasons: to exercise the right of freedom of expression and information; to comply with a legal obligation; for the performance of a task carried out in the public interest or in the exercise of official authority; for archiving purposes in the public interest, scientific research historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing; or for the establishment, exercise or defence of legal claims.
- lazyasciiart 8y agoOk, well here's the text of the legislation. Article 17.1 The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; https://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/ If you read further down the page, you come to the section you are quoting, 17.3, which says that the above right from 17.1 does not apply even if one of the conditions in 17.1 is met. However the scenario we are talking about is one where none of those conditions were met in the first place, so we never had to look at 17.3. You can argue that 17.1.b/c would require an employer to remove any demographic/political data it had stored on you, but absolutely not that it requires the employer to remove the record of your existence at the company.
- salvar 8y agoWho lost his business because of GDPR? I see a man who decided not to bother with informing himself about how to treat user data properly, and instead shut down his app.
- rzwitserloot 8y agoCan you name a conflict? The GDPR applies to trying to do business in europe. Seems simple enough.
- keithnz 8y agothat's not quite correct.... "The GDPR not only applies to organisations located within the EU but it will also apply to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location." meaning you can be doing business with EU residents as a US only company. I'm not quite sure how they intend to enforce the GDPR on foriegn companies, but they are making that claim.
- rzwitserloot 8y agoWell, the EU basically says that if you store data on people who fall under EU law, you're doing business in the EU. This doesn't sound crazy to me. If I'm in europe and I sell to an american, I have to adhere to certain US laws just the same. I have to fill in a W8-BEN form or whatnot. I can elect not to, but next time I'm in the US, things might get awkward at customs. Also, my customers might be fined or more or less 'ordered' not to do business with me. That's within the US's right. That's just how it works. Everywhere. For all countries.
- originalsimba 8y ago> Can you name a conflict? GDPR (EU Law) requires companies to delete private data upon request. SOX (US Law) requires companies do not delete private data, in case the government wants to investigate those companies later on. SOX has existed since 2002. Did the EU lawmakers even consider this when crafting GDPR? I'm betting not, considering the damage they've done to the WHOIS system as well. This kind of fallout is the result of poor planning and pushing incomplete legislation for political purposes and I think all of us realize that, so let's not pretend otherwise.
- matthewmacleod 8y agoPlease read and understand the requirements of the GDPR before promoting incorrect ideas like this.
- CamperBob2 8y agoGDPR is a great example of the kinds of disasters that happen when nations try to force the entire planet to follow their unilateral actions. (Shrug) It's a public response to abuses by private actors. It's a great example of the kinds of disasters that happen when the user is the product and not the customer.
- originalsimba 8y ago> (Shrug) It's a public response to abuses by private actors. I disagree, I think it's a political move and won't have the kind of positive impact that we want it to. GDPR, as it is written, should put Facebook and Google out of business. Invading people's privacy is a huge part of their revenue stream. I'm all in favor of protecting privacy of individuals but I'm cynical that we'll see any real progress as a result of this and the negative consequences are real, and possibly more significant than any positive effects. Time will tell.
- woolvalley 8y agoIt will make them more money from less competition.