5 ms·
I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashm
by AnabeeKnox 8y ago
I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.
- Marazan 8y agoIf it is difficult and time consuming for you to answer a GDPR request then your data handling practices are bad and you should feel bad.
- cbg0 8y agoIt is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)
- AnabeeKnox 8y agoIf 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.
- AstralStorm 8y agoYou mean request to be forgotten? Are you seriously lacking an automated removal process if you have more than a thousand users and also can't keep it in a three month deadline? Oor is it collecting so much data that you cannot just send it all to the requestee? If it would take a decade, then it is a broken business that should cease to exist as it is doing something illegal with the collected data. What kind of business is it?
- cbg0 8y agoIf this is such a serious concern, you should automate this process as much as possible. You don't necessarily need to respond manually to these requests if you put in place the required features on your website which will allow your EU data subjects to benefit from their rights. Realistically, how hard is it to automatically grab some data from a database and export it as JSON, as well as remove data from your database pertaining to a user? With a relational database, this would be a cinch. I mention the right to access the erasure right, as I estimate these will be the most frequently called upon.
- desas 8y agoDepends on your system. We have an automated process that produces a PDF, which a human will then go through and redact so we're not leaking through the non-relevent PII of other people if one of our users isnt using the system quite properly.
- acqq 8y agoIf you have a lot of “members” you obviously provide the services by the automated process. Obviously the request processing could also be mostly automatic.
- krageon 8y agoThen automate it. If you can't automate it within one month plus two months extension, you have bigger problems than GDPR requests.
- salvar 8y agoWhat does it mean to "request a GDPR"?
- Sangermaine 8y agoAs said below, this can be automated. If you can't or won't comply, then your website shouldn't exist.
- apple4ever 8y agoOr we just avoid the EU altogether. It shouldn’t even be possible to request anyway.
- bkor 8y agoEnabling people to force a company into bankruptcy using the GDPR is not the intention. From https://gdpr-info.eu/art-12-gdpr/ https://gdpr-info.eu/art-12-gdpr/: "Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either: " The quoted bit is about one person, not multiple so not directly applicable. I assume if someone organizes a coordinated flood of requests from multiple persons you can still argue that it is excessive. I agree that the amount of requests is very uncertain. Within my company I'm planning to make one request (data regarding me as an employee). This to see if they're prepared.
- pheleven 8y agoI was thinking a solid new business plan is to register gdpr.me (or whatever) and offer a service. $40, fill out a form, and I will send a GDPR request to every company in the world on your behalf. The data coming back is then offered back to you with the ability to create further requests (deletion for example) selectively or in full. This seem explicitly allowed for in the law.
- jacquesm 8y ago(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests. (2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject. I see such a service as acting in bad faith and would file a complaint against you and your service if such a frivolous request would land in my inbox. Better hold on to the $40, you might need to spend them on a lawyer. But kudos for trying to see the GDPR as an opportunity, now try to do so in a more constructive way. And - funny - you would be mailing yourself since you would be sure to hold PII on the party making the request in order to be able to authenticate the request as being a genuine one, which in turn would make you required to be in compliance.
- shabble 8y agoYou could maybe provide your users with a pre-filled request form for various companies they indicate they're a customer of, and have them send them directly. IIRC there are services along those lines for various 'contact your $REPRESENTATIVE' political and activism lines. I vaguely recall something about how the US has specific laws allowing certain requests to be ignored (or maybe even criminalising the sending of) generated or form-letters, due apparently to this sort of abuse. Can't remember what the exact context was that I saw it, but it might have been FOI or something data- related
- jacquesm 8y agoThat sounds like a much better idea. > I vaguely recall something about how the US has specific laws allowing certain requests to be ignored (or maybe even criminalising the sending of) generated or form-letters, due apparently to this sort of abuse. Exactly, and it is abuse. There are so called 'mass letter writers' here in NL that keep on sending FOI requests and other letters to local government effectively DDOSing the services and they too can be - and have been - slapped down.