4 ms·
Would you say a personal blogger in the US needs an EU representative if they're running a WordPress installation on a shared web host? I've been debating with
by thinkulum 8y ago
Would you say a personal blogger in the US needs an EU representative if they're running a WordPress installation on a shared web host? I've been debating with myself whether I need to move my content somewhere like wordpress.com to avoid that requirement. The personal information I process comes from comments and web server logs, and I'm not sure that counts as occasional.
On the other hand, I look at Article 3, and I'm not sure posting content on a personal blog counts as offering goods and services. Or do blog comments count as a service?
- downandout 8y agoSee recital 23 of the GDPR [1]. You do not need to comply with GDPR unless ”it is apparent that [you] envisage offering services to data subjects in one or more Member States in the Union”. The test for this is: ”Whereas the mere accessibility of [your] website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that [you] envisages offering goods or services to data subjects in the Union.” In English: Do not translate your site to EU-only languages (Italian, German, etc.), use an EU based domain extension, or create content or services that would be especially appealing to EU users, and GDPR will not apply to you. [1] https://gdpr-info.eu/recitals/no-23/ https://gdpr-info.eu/recitals/no-23/
- thinkulum 8y agoThat's sort of what I was thinking, though I don't know how well I'll resist griping about GDPR there. :D People's opinions on this regulation differ so dramatically that even when I read something in it that sounds pretty clear, I second-guess myself and worry that the courts will side with the worst-case interpretations.
- jacquesm 8y ago> Would you say a personal blogger in the US needs an EU representative if they're running a WordPress installation on a shared web host? No. > I've been debating with myself whether I need to move my content somewhere like wordpress.com to avoid that requirement. The biggest issue would be your log files, I've covered that in comments here, and in the articles as well. Another issue could be if you run analytics tags or advertising, which may impact you in a negative way financially in the case of advertising. My own blog is analytics and advertising free, I don't see it as a source of income so I don't care but obviously that will not hold for everybody. The critical part is when you start to ask users to enter data into your system, as long as you don't do that you will be able to solve this in a straightforward way. > The personal information I process comes from comments and web server logs, and I'm not sure that counts as occasional. You are right that it isn't occasional. So, logs: analyze them, then delete them within 30 days or so. That should be enough to do most security related work with the logs as well as any analysis you care for. Comments on your blog you will simply have to delete when the commenter asks for it. Even when I ran reocities.com this was the most requested support item, and it is pretty easy to do in an automatic fashion if you still have the original relationship between an account and the comments, this could be entirely self-service. I expect the typical blog engine plug ins to become GDPR compliant in the near future because lots of people will be asking for this. > Or do blog comments count as a service? Yes, it is a service. You operate a server which takes in data and records it. That it isn't commercial is not important in this case, data subjects will create accounts and there will be PII associated with those accounts, either directly or in the comments. Now for some arguably bad advice (from a legal perspective, but it is very practical): I'd take 30 days to see how this all shakes out past may 25 before taking action on something as insignificant as a blog. That way you will have a lot more information to base your decision on. Obviously that has a risk: you will probably not be in compliance but I'm going on the assumption that regulators will have a lot more on their plate than your blog for the foreseeable future.
- olskool 8y agoI don't find anything in your postings to be reassuring. To say that the regulators will be too busy to mess with my blog won't be of use to me the day they do choose to mess with my blog.
- DanBC 8y agoI'm not sure a personal blog counts. I think the people who created the blogging and comment software need to do something, but not you as the blogger. https://gdpr-info.eu/recitals/no-18/ https://gdpr-info.eu/recitals/no-18/ > This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
- jacquesm 8y agoI'll give you an example from real life: The Geocities archive that I re-hosted contained numerous so called geobooks, guestbooks filled out by the visitors of the geocities sites. These comments were usually pretty harmless but some people did really dumb stuff and under their own name. Under the GDPR that would be PII and so the removal requests would arrive, whether or not the legal bar was met. I'd rather not have to argue in court whether or not my blog was purely personal even though I run it under my own name. So even for a blog if you allow people to comment calculate in that they will ask for some of those comments to be removed. It's a relatively small burden because it won't happen often (with all the millions of Geocities sites it only happened a few thousand times over a decade), and it will stop people from complaining to the regulators. Better yet: monitor your comments and approve them selectively, if you drop the obvious dumb ones there is a fair chance that you'll never have a removal request.
- thinkulum 8y agoThe only thing is that I'm running the site myself. That's why I was thinking of moving the content to a blog host that would manage the back end for me. But maybe even moderating the comments myself would make me the processor or controller. If every blogger on Tumblr or wherever is subject to GDPR that way, wow is the web in trouble.
- 8y ago