4 ms·
If you are a company, GDPR does apply to data on physical letters and local emails. A large part of the preparation for the introduction of GDPR enforcement was
by donaltroddyn 7y ago
If you are a company, GDPR does apply to data on physical letters and local emails. A large part of the preparation for the introduction of GDPR enforcement was companies getting a handle on what they had stored in various media.
- merb 7y agoactually email and letters are something which the gdpr falls short in some countries. especially germany. since basically the constitution is above the gdpr and depending on the letter/email the content of the letter does not need to be acknowledged or showed (gdpr also means you can access your data) to the person who want his data deleted/showed/whatever.
- big_chungus 7y agoAll true, but costs of hosting and serving aside, there is a non-zero legal cost with hosting and serving the content. Blame bureaucrats, parasite lawyers, and our litigious society.
- dredmorbius 7y agoThose costs reflect the actual social costs of that hosting. Prior to GDPR and similar legislation, those risks were externalised onto users and society at large. They're now being shifted, properly, to where they should have been borne in the first place, on the service providers themselves. Blame risk-externalising business practices and willful ignorance.
- big_chungus 7y agoWhat social coast is there to distributing content contributed by people who agreed to terms according to those terms? Users transmitted data about themselves to a party after reading that party's terms of service and agreeing to the things it promised to do with the data. To paraphrase a popular talking point, two consenting IP addresses should be able to send whatever data they want between each other.
- dredmorbius 7y ago1. Terms of use can change at any time. 2. Technical capabilities have expanded massively. When Yahoo Groups launched, enterprise storage of more than a few hundred GB was highly unusual. I worked for a Very Impressive Service Agency which was lucky to claim two Sun Starfire servers, only one of which was Large File (> 2 GB) at about the time, for analytic use. By the late 2000s, AOL were deploying massive-RAM based systems to be able to perform whole-dataset operations in memory. For the past ~5-8 years, large-scale SSD drives have been A Thing, now available in the terabyte range, for a price. Again, the level of analysis and expolration possible have made tremendous leaps. 3. There is the concept of manifest vs. latent functions, and awareness. The full realm of possibilities of technical systems are rarely apparent to their creators, let alone nontechnical users. See (very generally): https://en.wikipedia.org/wiki/Manifest_and_latent_functions_and_dysfunctions https://en.wikipedia.org/wiki/Manifest_and_latent_functions_... The marketing and disclosures of such services rarely include such disclaimers as "use of this system may subject you to a lifetime of personal and social profiling, grammar-based context analysis, GD ML AI based image content analysis, and imperil the global liberal social democratic experiment." Hiding behind the figleaf of "you should have considered all possible future implications of your present actions and will have no future recourse" is grossly flawed, and quite frankly, professional malfeasance and malice aforethought given current understanding. The awareness of risks has changed, and is unambiguous. Providers should foot the costs, or mitigate them accordingly. (I suspect that at least in part, the actions of Yahoo, Google, and others, reflects this changed awareness, though I'm not aware any providers have explicitly stated this.) Again: the risks always existed. The previous state was made possible only by pretending they did not. They do. Practices must change.
- big_chungus 7y agoSocial cost would be at best very difficult to quantify, though, making it quite hard to handle. "Increased partisan tensions" due to social media, for instance, is not the sort of thing the cost of which one can quantify and mitigate. Your point that the things which can be done with information collected are constantly in flux, and I agree the ability to retroactively change terms of service to cover previously-collected data is ridiculous and implies an illusory contract which is not legally valid. No one should be able to run through a neural net data collected in the nineties. However, it's also not reasonable to demand that old data be removed, as it's produced at least as much by the server as by the client (e.g. access logs are typically produced by server-side monitoring of server-side software). The most sensible option is for companies to require explicit agreement to TOS changes to continue using the service, and use new data only under that policy while using the old data under the old policy. It's additional compliance overhead, certainly, but it's no different from how a client contract would be treated. > professional malfeasance and malice aforethought You are not the arbiter of such things, but thank you for your opinion. There's also a site guideline about assuming good faith, so you're in violation of that.