3 ms·
So the GDPR is only about personal data? What are my responsibilities if I run a chan, i.e., I store no personal data about my posts other than the IP address w
by tql 8y ago
So the GDPR is only about personal data? What are my responsibilities if I run a chan, i.e., I store no personal data about my posts other than the IP address where they originated? What if I use some tracking technology such as a cookie or localStorage to identify unique browsers regardless of their IP address?
- geocar 8y agoYou have to make it clear to people that you're using these technologies and how long you keep their data. You should also explain how you keep this data safe. If you suffer a data breach you have to disclose this, and you are potentially liable for it if you could've protected users from that breach by technological means (applying patches, salting passwords, encryption, and so on). If your breach includes too much personal data() this could be serious. If you think you want to keep data forever, then your liabilities for that data extend forever. You should consider if this is really what you want, or if you might want to simply delete old backups and scrub identifying information after some time. () The regulator will evaluate this by considering how the people that personal data is about will be affected. This is a difficult question to ask -- a chan user might at worst suffer potential embarrassment being linked to posts, so I suspect the regulator will view loss lightly, unless it could easily and reasonably be prevented. The ICO has really good guidance about this on their website: https://ico.org.uk/for-organisations/business/ https://ico.org.uk/for-organisations/business/
- bumbledraven 8y ago> a chan user might at worst suffer potential embarrassment being linked to posts Embarassment? People lose their jobs in America for espousing commonly-held conservative views. They can be arrested in Europe for the same thing.
- geocar 8y agoI understand your point, but this isn't a special risk introduced by the GDPR, and from the perspective of a regulator, I don't think they are going to consider the linking someone to illegal behaviour to be additional liabilities for the company suffering the breach. That being said, if your "chan" provides a safe haven for illegal behaviour, you might have other non-GDPR problems as well.
- bumbledraven 8y agoI see what you mean. As an explanation of how a GPDR regulator would view things, what you say makes sense.
- Cthulhu_ 8y agoThen you couldn't comply with takedown requests (and thus can safely disregard them) because you don't know what content belongs to what user, and you can't even be sure that the person making the request is actually the one that posted the information on your chan.
- jdietrich 8y ago"Personal data" is defined differently in the GDPR than in most US legislation. >‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person An IP address or tracking cookie is an identifier. It is not, in isolation, personal data. The other stuff you store like posts and access logs become personal data if those identifiers allow you to associate that stuff with a natural person. If you strip the data of identifiers to the extent that it can no longer be connected to anyone, then it ceases to be personal data within the scope of the GDPR. https://gdpr-info.eu/art-4-gdpr/ https://gdpr-info.eu/art-4-gdpr/