5 ms·
> GDPR.EU is a website operated by Proton Technologies AG, which is co-funded by Project REP-791727-1 of the Horizon 2020 Framework Programme of the European Un
by _rpd 8y ago
> GDPR.EU is a website operated by Proton Technologies AG, which is co-funded by Project REP-791727-1 of the Horizon 2020 Framework Programme of the European Union. This is not an official EU Commission or Government resource. The europa.eu webpage concerning GDPR can be found here. Nothing found in this portal constitutes legal advice.
- dpwm 8y agoI'm not sure why you're pointing this out – it could be because it's interesting or it could be as a warning. If as a warning, nothing here seems particularly unreasonable. > GDPR.EU is a website operated by Proton Technologies AG, which is co-funded by Project REP-791727-1 of the Horizon 2020 Framework Programme of the European Union. This is probably a requirement of the funding. > This is not an official EU Commission or Government resource. The europa.eu webpage concerning GDPR can be found here. This seems reasonable. Funded by does not mean endorsed by. Here's the official page. > Nothing found in this portal constitutes legal advice. Realistically it can't be legal advice, even though it's dealing with an area that could get you into legal trouble. It's referring to a directive which has been implemented by member states. Each member state has its own enforcing body, and some will take a more firm approach than others. As for legal advice, in at least some jurisdictions even paid advice is treated as just that – advice – and if you get bad advice, there is little to no realistic prospect of redress. This appears at first glance to be one of the better resources on the GDPR I have seen.
- _rpd 8y agoIt's a warning. The site is authored by a private entity whose only qualification may be that they registered the gdpr.eu domain most quickly. It claims to be a "complete guide to GDPR compliance" but is nothing of the sort. Most pages end with the disclaimer that "nothing found in this portal constitutes legal advice" and to consult a lawyer. Legally, it's quite dangerous since it might give you the feeling of being compliant while still being at risk. "But Proton Technologies AG said ..." isn't going to hold up in court.
- dpwm 8y ago> Legally, it's quite dangerous since it might give you the feeling of being compliant while still being at risk. If you're soliciting free advice online – even from a law firm – it may as well contain such a disclaimer. Nearly always the terms of service do contain such a term. > "But Proton Technologies AG said ..." isn't going to hold up in court. "But our law firm said…" seems to be the alternative here. I'm not sure how well that would hold up in court. I'm all for getting legal advice from professionals. That said, there's a lot of law firms that will give you advice on the GDPR without really knowing what they're talking about. Their risk is pretty minimal – as a business client you're unlikely to be entitled to the same redress as consumers. The bar is very high for demonstrating negligence.
- IanCal 8y agoI think the point here may be that it could be different if this was an official EU page. I think the justification of "But we followed your guidance" is a pretty reasonable one in a court (I'm not a lawyer though).
- xg15 8y agoI think it's not paid vs unpaid but official vs private. I found the warning very useful, as I assumed this was a publication from an EU institution as well. If this had been the case, you could have assumed that the page had been produced with the primary goal of informing the public and clearing up confusion - and that the page were likely to have input from people close to who actually drafted the regulation. All that would put my trust in the accuracy of the information way higher than that in a random law firm, no matter how much legal weight that would have in either case. Additionally, it would be some news if an EU body published an "official" guide how to implement the GDPR, whereas there are likely many such guides by private advisors.
- dpwm 8y agoOn deeper inspection it seems the whole thing is a bit of a plug for Proton Mail. For some reason my disengaged brain hadn't linked Proton Technologies AG with ProtonMail, which was plugged frequently enough for me to notice on first glance but not quite enough to make me suspicious.
- abtinf 8y agoIt is an important warning for people in the US, where websites published under .gov are run by the federal government. When I saw the short domain followed by .eu, I assumed this would be an official government site providing GDPR compliance guidance.
- angott 8y agoAnybody can register a .eu domain. There are many companies that operate across EU borders in different countries, and use .eu domains to advertise their pan-European targeting.
- robin_reala 8y agoAny EU citizen. There was the fracas recently when it turned out that .eu domains registered by British people would be decomissioned post-Brexit: https://ec.europa.eu/info/sites/info/files/notice_to_stakeholders_brexit_eu_domain_names.pdf https://ec.europa.eu/info/sites/info/files/notice_to_stakeho...
- M2Ys4U 8y ago>It's referring to a directive which has been implemented by member states. Each member state has its own enforcing body, and some will take a more firm approach than others. That's not true. The GDPR is a regulation (hence the R in GDPR!) which does not need to be implemented by member states. Regulations have direct effect, meaning the same legal text applies in every EU member state directly.
- pmontra 8y agoHowever the header states "This project is co-funded by the Horizon 2020 Framework Programme of the European Union", so maybe they had to pass some review. What all these checklists lack is some real advice for software architects/developers, something along the lines of "I'm a Java developer, should I do something different now?" Reading the real GDPR [1] is more useful and not more complex than any technical document we are used to study. It contains several hints here and there both in Recitals and in Articles (Recitals are the claims between "Whereas" and the Articles.) For example Recital 29, which is more cryptic than most of the others, hints about a best practice of separating personal data from all the other ones and from the information required for reconciliation. Maybe different databases on different machines. This is not the naive soup of fields in a users table. Thinking about a classical MVC web app, it could be that the code in the controllers should have zero knowledge about personal data, with the exception of the part of the application that for example deals with user profiles. That could be a separate application with its own database and admins. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
- athenot 8y agoOf course the only way to have legal advice is to pay for legal advice. Free is subtantially cheaper. The way to use such sites is to rely on them at first, to help you navigate the waters. They should help you become MOSTLY compliant. Once you're done, THEN hire some legal experts to finish off the last few ommissions or mis-interpretations. It's a lot cheaper than starting with a law firm from the beginning. Know that there's always a risk that the informative site lead you down a wrong path so if you're about to make a decision that's hard to undo, you can engage the legal advice sooner.
- fxfan 8y agoAnyone else not a fan of private entities squatting on domains in a subversive way? I like protonmail like I like sourcegraph but they are disingenuous in the squatting of gdpr.eu and langserver.org. The latter is even more egregious