5 ms·
Yet another sensitive database with probably no way to know if you're in it - GDPR sounds like a pain but I'm coming around to believing it's a necessary evil t
by GFischer 8y ago
Yet another sensitive database with probably no way to know if you're in it - GDPR sounds like a pain but I'm coming around to believing it's a necessary evil to stop this nonsense.
OTOH I guess this is relevant information and so they should be allowed to have it under GDPR rules? I'm obviously not a lawyer although my work, like most programmers' is affected by GDPR, PCI and whatnot.
- dariusj18 8y agoAccording to the article, the data was all pull together from public sources.
- GFischer 8y agoFrom what I understand (as mentioned, IANAL) having the database itself is lawful, as they're compiling it to comply with a legal requirement, but under GDPR, that still wouldn't stop from having to comply with GDPR and the rights (including knowing if a subject is in the database): http://lexindicium.com/2018/03/19/data-mining-and-gdpr-compliance/ http://lexindicium.com/2018/03/19/data-mining-and-gdpr-compl... https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens/my-rights/what-are-my-rights_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... Right to: information about the processing of your personal data; obtain access to the personal data held about you; ask for incorrect, inaccurate or incomplete personal data to be corrected; request that personal data be erased when it’s no longer needed or if processing it is unlawful; object to the processing of your personal data for marketing purposes or on grounds relating to your particular situation; request the restriction of the processing of your personal data in specific cases; receive your personal data in a machine-readable format and send it to another controller (‘data portability’); request that decisions based on automated processing concerning you or significantly affecting you and based on your personal data are made by natural persons, not only by computers. You also have the right in this case to express your point of view and to contest the decision. In particular, the clauses about access to personal data and to have decisions being made by a natural person seem relevant here.
- AJ007 8y agoThere is a very interesting clash here where the anti-money laundering and know your customer laws require pretty substantial investigation in to customers and EU laws (GDPR, right to be forgotten) which require this sort of data to be purged or publicized.
- occamrazor 8y agoGDPR explicitly addresses the right of holding and processing data for legal and regulatory compliance.
- dmix 8y agoShouldn't we see if GDPR actually starts preventing these leaks before declaring it a success? I'd imagine it being a 'success' is a predicate on it being useful right? Not just punishing the small percentage who get 'caught' while doing nothing to actually help the problem - ala the drug war. And for everyone who thinks it's just big evil companies who get punished, one of the first GDPR fines was $4k against an Austrian small business owner whose video surveillance around his building was deemed too broad it violated peoples privacy. I'm not declaring GDPR a failure by any means but all policy must be judged on a long-term full-picture basis. Not simply on "good intentions" of the bill + a few high visibility wins early on, then moving on as if the world is a better place.
- dsr_ 8y agoGDPR doesn't prevent leaks any more than anti-speeding laws prevent speeding. GDPR tells you what you can't do and what the penalty is for being caught in violation, just like a speeding law tells you what speed you can't exceed and what the penalty is for being caught.
- chr_o_mium 8y agoStill too early. We can't say if GDPR is a good thing or not for at least 10 years IMHO. And unfortunately, I'm sure hackers & leakers will find other, perhaps more harmful practises.
- Miredly 8y agoOr we could just start punishing companies for massive and widely damaging data leaks. AFAIK about GDPR, it wouldn't prevent this. These things keep happening because nothing bad happens to companies that let it happen.
- pavlov 8y agoGDPR specifies fines up to 4% of annual global turnover or 20 million euros, whichever is greater. That seems like plenty enough bite, if it were enforced.
- Scoundreller 8y agoWhy does an unprofitable 1person tiny business get a bankrupting (identical) fine as a profitable 1000 employee firm with $500m in turnover?
- northwest65 8y ago>up to I think that is the catch?
- munchbunny 8y agoIt doesn't. Those numbers are upper limits. Just like with traffic tickets and other fines, the actual amount is left to judgement.
- Mirioron 8y agoIf this were true then why have upper limits at all? The only reason I can think of is to protect large corporations.
- munchbunny 8y agoFor two reasons: 1. To prevent cruel and unusual punishment. 2. To set expectations about the seriousness of the infraction in the eyes of the law. I am not a lawyer or a legal scholar, so I'm sure there are more reasons.
- astura 8y ago... it's a compilation of public records... Hard to get too excited about public information being made public. >The data is all collected from public sources, such as news articles and government filings.
- adolph 8y agoIsn't that a bit like saying Facebook is just a collection of forwards from Granny? The compilation of raw materials into a coherent whole has a larger value than the existence of the raw materials.
- astura 8y agoSo? It's exactly the same as Wikipedia; yet nobody calls Wikipedia a "sensitive database." I mean "So?" from a privacy standpoint, from a business standpoint it's an issue for Dow Jones.
- machinecoffee 8y agoIt's not where the data came from that's interesting, it's the the fact the list exists, who's on it and that it's being used to identify people that you may not want to start a business relationship with.
- anigbrowl 8y agoYes, I'd quite like to know if I show up in it or not.