5 ms·
Except its not ‘in practice’ because gdpr does not require such thing. In spirit, maybe [i.e. practically they wouldn't be fined for this]
by zerostar07 8y ago
Except its not ‘in practice’ because gdpr does not require such thing. In spirit, maybe
[i.e. practically they wouldn't be fined for this]
- notafraudster 8y agoIt might be reasonable to conclude that, in practice, GDPR has caused a number of companies to their re-assess data collection and retention hygiene (even beyond the minimum bounds of the law). In particular, this change seems to be a very charitable or expansive reading of the requirement under the GDPR for companies not to collect more than is necessary -- as the post ends by noting.
- merinowool 8y agoI think hygiene was mostly in place, but there was no PR points to score. Before GDPR an information that company stores something for 3 months would be a non-news. GDPR doesn't in any way protect people from data leaks.
- matt4077 8y ago> GDPR doesn't in any way protect people from data leaks. If GDPR provides PR reasons for better data hygiene the result is the same: less data retained, less data at risk of being leaked.
- jdietrich 8y ago>GDPR doesn't in any way protect people from data leaks. Article 32: Security of processing Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. Recital 83: In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage. GDPR also mitigates the impact of leaks. Art. 5 requires that data is stored for no longer than necessary for the purposes for which it was collected. Art. 33 requires that the supervisory authority must be notified of any data breach within 72 hours. Art. 34 requires that data subjects be notified of any breach without undue delay. All of this is enforceable with heavy fines. https://gdpr-info.eu/art-32-gdpr/ https://gdpr-info.eu/art-32-gdpr/ https://gdpr-info.eu/recitals/no-83/ https://gdpr-info.eu/recitals/no-83/
- merinowool 8y agoI can't see how this protects people. You can evaluate risks all the time you want, but unless you have exceptional security team, you won't get your situation improved beyond what's already been established in the industry. Unless you think about companies leaving their databases facing the public without password - but then I still can't see how GDPR would help there. Requirements for post mortem actions are quite sensible though, but given arbitrary rules that is likely only going to be a cash cow for the governments, as even a second of the delay is undue.
- namibj 8y agoThe criteria for when such a delay is undue in Germany ("ohne schuldhafte Verzoegerung"), is if it would have been within your power and not incurring gross risks/costs (unless it's your fault for creating a situation where there are gross risks/costs) to have done the required action at an earlier time. It is not undue delay if you needed to sleep, or if your ISP just cut you off and you need to go into the city and get some other ISP to get you a connection, but it is your fault if you then sit around for a month, waiting for the ISP to get it ready, without the ISP getting the connection up soon enough. They would require you to go to the city and get a permit to string fiber across from the next hub to your building, if there was no other way to get it done sooner, due to e.g. there not being anyone with free time to dig up the street and fix the cable, or whatever.
- d357r0y3r 8y agoIt's literally "in practice" if companies are doing this because of GDPR. The fact that they are misinterpreting the guidelines doesn't change the fact that they are making decisions on what they believe are the guidelines.
- dvfjsdhgfv 8y agoWell, it's like calling a common pointer error "C in practice". You're not wrong, it's just viewing it at a particular angle.
- d2wa 8y agoWhat they’ve done is much cheaper to develop and maintain than implement more granular data deletion tools. Especially when they really don’t need to store the data any longer than one billing period.
- d2wa 8y agoBut it does. > “The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. […]” ― GDPR: Article 25 Data protection by design and by default: Paragraph 2 > “The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay [when] the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;” ― GDPR: Article 17 Right to erasure: Paragraph 1: Point A
- jdietrich 8y agoArt. 5: Personal data shall be: kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed Recital 39: The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum. The GDPR is very explicit on this point. You must delete or thoroughly anonymise personal data as soon as is practically possible. https://gdpr-info.eu/art-5-gdpr/ https://gdpr-info.eu/art-5-gdpr/ https://gdpr-info.eu/recitals/no-39/ https://gdpr-info.eu/recitals/no-39/
- zerostar07 8y agoYes it's quoted in the article too, however "necessary for the purposes" is subject to interpretation, and there is a huge leeway here. In practice it is always possible to claim that some procedure would require retention for longer, and it would be impossible to have them prosecuted for that.
- ocdtrekkie 8y agoIf they divvy up a monthly fee to the sites you visit, they're going to have a hard time explaining the need to keep your browsing data more than a single month: Enough time to pay out to the websites. Then you can maybe add a couple months to account for backups and the like. It sounds like trimming the data retention here was well-warranted, particularly given the high sensitivity of browsing data.