5 ms·
Disclaimers, although I was responsible for implementing GDPR for a subsection of a bigCo, I am not a lawyer, do not speak for my company, etc. I've just been
by existencebox 8y ago
Disclaimers, although I was responsible for implementing GDPR for a subsection of a bigCo, I am not a lawyer, do not speak for my company, etc. I've just been getting increasingly annoyed by the amount if misinformation on both sides of the GDPR debate, (that it's both a straight good or a straight bad) even in sister comments to this, that I figured I'd try and give a Real Answer to your question.
They would need to provide functionality such that an EU resident could request timely export and deletion of any records belonging to them in that guestbook.
If your guestbook is physical and substantial, this may be limiting without additional systems, but GDPR also is rather vague in the pushback you're allowed to give if you're completing the export with best intentions, so this will likely not be settled until precedent occurs; this will be even more grey-area due to considerations of "ease of access" of the information in question, and other "softer" considerations.
So to answer your question more bluntly: Without the bare minimum of a business process for someone to call up and say "I want to export/delete my entry in your guestbook" I'd say the experts who guided my team would probably agree that the business owner should err on the side of assuming non-compliance, so long as you don't reasonably preclude EU visitors.
- 0xffff2 8y agoCan you clarify how your entire response is substantially different in any way from the single word "maybe"?
- existencebox 8y ago"maybe" doesn't detail the steps you could take to bring yourself into compliance, doesn't describe the specific decision points that put you at risk, and doesn't describe how the "maybe" ever resolves to a hard "yes or no" I've given you the benefit of the doubt in answering this honestly but I don't think you read my initial response charitably.
- donogh 8y agoI would say that you could provide a notice specifying that signing the guestbook also constitutes consent to the public display of the person's name. If you want to take it further, you could ask them to submit a small form confirming their consent. Worst case, you redact their name -- use a marker! -- and document that process as part of your data review. Either way, it's complete overkill. It's not about following the letter of the law; it's about the spirit of the law. No one is going to get sued or fined for providing a public guest book.
- existencebox 8y agoTwo notes here: First, pedantically, (But in the interest of maintaining my "trying to reiterate the letter of the law as I understand it") I'm pretty sure interactive/implied consent isn't considered sufficient; (Interactive consent being what was allowed for EU cookie compliance) and that one cannot "Sign away" GDPR protection. Second, while I agree that it's overkill, I'm operating from the "This is the rigorous interpretation that people far more legally versed than myself have established". This may not be the right decision for a smaller corp or business entity, as it is in my case for a notable multinational. While I might agree that I'd have an absolute spit-take if such a small entity were made an example of, I can also understand the paranoia on the other side, especially given the context of US jurisprudence and how it differs from the "tone" of EU-style enforcement.
- donogh 8y agoNo argument on either point. We have to be practical, though, and the law is usually forgiving of such practicalities. You're right, though: strictly speaking, it's not compliant.
- test525 8y ago>If your guestbook is physical and substantial, this may be limiting without additional systems, but GDPR also is rather vague in the pushback you're allowed to give if you're completing the export with best intentions, so this will likely not be settled until precedent occurs; And then you are fined 4% of revenue when you are the scapegoat setting a precedent for a vaguely defined law...
- kazen44 8y agosigh.. the 4% is the maximun fine allowed.. its not a minimum.. this FUD is getting idiotic.
- curun1r 8y agoActually, the maximum fine is 4% of revenue or €20m, whichever is more. For a small business or organization, the 4% number isn't the scary one. You can say that in practice this would never happen, but calling it FUD also doesn't seem right since the regulation is super vague and only mentions maximum fines, not likely actual fines.
- test525 8y ago>the 4% is the maximun fine allowed.. its not a minimum.. I think it's always safe to assume the worst from bureaucrats. Especially when no sentencing guidelines exist.
- jdietrich 8y ago>I think it's always safe to assume the worst from bureaucrats. No it isn't. As a law-abiding web developer, I have had frequent contact with European data protection authorities for many years. Without exception, they have been thoughtful, reasonable and gone out of their way to help me comply with the regulations. The regulatory authorities exist to ensure compliance, nothing more. They are not a revenue-generating scheme or a Kafkaesque bureaucracy. The GDPR explicitly states that penalties must be proportionate and sets out no fewer than eleven factors that must be considered before any penalty is issued. It also explicitly establishes a mechanism for ensuring that enforcement is consistent across all member states, by means of the European Data Protection Board. The regulations simply do not allow a member state to "go rogue" and start handing out €20m fines for trivial infractions. https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/chapter-7/ https://gdpr-info.eu/chapter-7/
- s73v3r_ 8y agoSuppose they wanted their data removed from the guestbook. Would simply taking some white-out to where they signed it be enough?