13 ms·
I think the "Prepare for the exercise of people’s rights" part is critical. If you are a software architect, you need to ask yourself: can I delete a single us
by BeniBoy 6y ago
I think the "Prepare for the exercise of people’s rights" part is critical.
If you are a software architect, you need to ask yourself: can I delete a single user data across all my infra easily? If not, you might be in trouble a couple a year later when you are hit with thousands of deletion request and technically can't honor them.
Another side of tech debt I guess!
- moksly 6y agoYou can answer no to that and still be GDPR compliant. You’re allowed to save personal information that is critical to your business. People can’t buy stuff from you and demand you have their payment data deleted before you charge them, or right after they do a charge back of money paid to you for instance. It’s probably healthy to design systems that are build to let people manage their own data though. I think people will slowly start to expect that of you in the future as more and more solutions start to offer it. In the public sector of Denmark we give people access to all their health data. When I have blood drawn for analysis (not English and I don’t know what it’s called sorry) I can log in and see the results exactly like the doctor sees them. When I’ve been to a doctors consultant and she’s written stuff in my journal I can log in and read it. People are going to want that stuff once they get used to it.
- BeniBoy 6y agoYou are right. The rights of the user depend on the legal basis you choose. This is covered here[1] Basically: * The right to object is not applicable if your processing is based on contract, legal obligation or protection of vital interest * The right to erasure is not applicable in case of a legal obligation or public interest [1]https://github.com/LINCnil/GDPR-Developer-Guide/blob/master/15-Take%20into%20account%20the%20legal%20basis%20in%20the%20technical%20implementation.md#rights-exercises-and-modalities-of-information-to-be-provided-according-to-legal-basis https://github.com/LINCnil/GDPR-Developer-Guide/blob/master/...
- ArnoVW 6y ago.. and since one is obliged to keep 10 years of history for tax auditing reaons, the whole point becomes moot. Yes, you can ask that your avatar image be removed. But they can easily claim that your name, address, bank account number are needed for tax auditing and Know Your Customer purposes. https://en.wikipedia.org/wiki/Know_your_customer https://en.wikipedia.org/wiki/Know_your_customer
- vertex-four 6y agoSure, but only if you you then never process that data for reasons not covered by your legal basis and privacy policy. It's not only the collection of data that is covered by the GDPR - it's any processing as well. Easiest way to do this is probably to duplicate data into another table for tax audit purposes, that your "normal" applications have no permission to read. Then you can delete everything your application can access and still keep legal records.
- njb311 6y agoI wouldn’t say the _whole point_ becomes moot. As you have to have a legal basis for each type of data that you are storing or processing, relying on different legal bases can add complexity to the problem of a deletion request. Just because you have to retain some information does not give a free pass to retain everything. Also, remember that data subjects have a right to limit the purposes for which their data is used – systems need to be able to cope with that. This is where a well thought-out and documented approach to personal information makes everything easier, for internal users of that data too. For legacy systems it can be a nightmare because nobody seemed to care, but with a clean sheet, _why wouldn’t you_ address data protection and privacy from the outset?
- outadoc 6y agoYou can answer no to that if you only store information that you legally have to keep. Chances are, that's not the case.
- remus 6y agoThere's actually 6 lawful bases for processing data https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/#what https://ico.org.uk/for-organisations/guide-to-data-protectio... though deciding which is applicable in a given situation is not straightforward. The legal basis is actually quite broad. For example, most companies need to keep records for accounting purposes for several years which would count as a lawful basis. Another example would be keeping client data in case you need to protect yourself against potential future litigation e.g. a gym may need to protect themselves against personal injury claims (otherwise you could injure yourself, ask them to delete the records and then sue them).
- closeparen 6y agoAs the chart explains, only public interest and legal requirement trump the right to erasure. Legitimate interest does not. A legal requirement is "you shall retain these data for N years or face prison time" not "this might be helpful in a lawsuit"
- user5994461 6y agoCompanies legally have to keep a ton of information as soon as they process any payment. High chances are your company gets money from its customers so it can keep all kind of information almost indefinitely. The only notable exception is ad business because "users" are not customers and do not enter any transactions.
- abraae 6y agoOne thing about GDPR that I've never heard answered convincingly - when a user requests deletion of all of their personal data, does that include also any history of the deletion request itself?
- BeniBoy 6y agoIt's a good question and I don't thing any DPA has said anything specifically on this issue. But if your logs contains personnal data related to the user which made the deletion request, you might be in trouble. And personnal data has a very broad definition. But honestly this is a very minor point, if that's what is keeping you up at night, you are amongst the most compliant ones !
- motdiem 6y agoMy understanding is keeping the deletion requests fullfills a legitimate business interest, so no -I would not delete the request. What we do is we keep those in a separate system, since the user records themselves (in my app, crm, etc) would be removed. That system is also how we "prove" that we executed the deletion requests in a timely manner
- jayelbe 6y agoThis all depends on what the legal basis for you processing personal data is in the first place. There are several possible legal bases for processing personal data and legitimate interests is one; if legitimate interests wasn't your reason for processing personal data in the first place, then you couldn't rely on it later. If legitimate interests were the basis for your processing, and a person requested their data be deleted, you have to be able to demonstrate that your legitimate interest overrides their rights. You should probably also demonstrate there aren't other steps you could reasonably take, eg partially deleting or anonymising the data.
- keerthiko 6y agoThe focus of the spirit of GDPR is PII at its core. Communications with the user such as email exchanges, transaction records, etc are fine to preserve as long as all PII have been scrubbed and are dissociated from the user.