5 ms·
> The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller IANAL, but this sounds
by methyl 5y ago
> The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller
IANAL, but this sounds to me like you are entitled to receive only the personal data of yours in a machine-readable format, not _everything_ you entered.
- malka 5y agoIf it is a free text form, it's safer to assume that the data is personal.
- kapep 5y agoEven timestamps can count as personal data. For example when they can be used to track working hours.
- chromanoid 5y ago> " and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided " puts this in context. Personal data is everything that is connected to the person requesting it.
- that_guy_iain 5y agoI had GitHub claim my private git repos were not personal data. Because it was code, forgetting that my name and email are attached to every commit. Until there are massive fines for not following GDPR, it's pointless. GDPR was meant to be a serious threat and it is in some regards but it is ignored so many times with stuff like this and the fines honestly, aren't that much. I've seen GDPR violations result in no fine even after they admitted the violation in court.
- chromanoid 5y agoAs others stated, as long as data is associated with your account (regardless of what content) it is personal data. When companies like github.com do not follow the GDPR and do that notoriously I am sure the fines can be raised by the administrators without changing any laws. As you can see here https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ there are actually some juicy fines already. I mean 50.000.000 EUR is not much for Google but still better than nothing considering "Insufficient legal basis for data processing" was not even a real issue before GDPR. BTW this is also a nice GDPR fine reason: "Insufficient technical and organisational measures to ensure information security" (e.g. British Airways was fined with 22 million). I never did that, but did file a complaint at your national Data Protection Authority? https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens/redress/what-should-i-do-if-i-think-my-personal-data-protection-rights-havent-been-respected_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- that_guy_iain 5y ago> I never did that, but did file a complaint at your national Data Protection Authority? https://ec.europa.eu/info/law/law-topic/data-protection/refo https://ec.europa.eu/info/law/law-topic/data-protection/refo... Yea, it got forwarded to the Dutch authority because they're based in Holland. It took almost 2 years for the entire process. Basically the dutch couldn't really care and didn't understand the techincal facts of the matter and just believe Github's legal team when they said code is not personal data without knowing each commit has my name and email. The account has my photo and name. And that I was doing a personal data request and export request. Because my national agency had to forward it I couldn't file an appeal because my national agency just forwarded it and didn't actually do anything or make any decision they just relayed the decision. For me, the key take away was I asked for all information they had that was relating to me. They said no and the dutch authories thought that was a-ok.
- chromanoid 5y agoMmh in this case the third bullet point from https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens/redress/what-should-i-do-if-i-think-my-personal-data-protection-rights-havent-been-respected_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... is relevant ... :/ > take legal action against the DPA - If you believe that the DPA has not handled your complaint correctly or if you aren’t satisfied with its reply or if it doesn’t inform you with regard to the progress or outcome within 3 months from the day you lodged your complaint, you can bring an action directly before a court against the DPA.
- mytailorisrich 5y agoIt's not that clear-cut. There are debates as to what "relates to" (wording of GDPR) means, and that seems to be open to interpretation depending on context and data. Unless there is a definitive decision on this, I think it is reasonable to claim that source code is not personal data.
- tzs 5y ago> I had GitHub claim my private git repos were not personal data. Because it was code, forgetting that my name and email are attached to every commit. This brings to mind a few questions. 1. If a site stores multiple copies of a particular piece of personal data, let's say an email address, do they have to give you every instance when you ask for your data, or just tell you that they have your email address? For example, if I use email address as an account identifier, so it is used as the primary key in the Users table in my database, and as a foreign key in my Purchased table, do I have to say send something that says your email address is in 1 row of one table and 13 rows of another table? 2. If I have to give back copies of your personal data that is in content you uploaded, what if that content contains personal information of other people, too? If you had let others commit to your private GitHub repo, for example, their personal data would be in there. If GitHub has to give your commits to that repo in response to your GDPR request, do they have to filter them so that they only return the commits you committed? What if I submitted an issue, you committed a fix, and in the commit message you thank me by email address for diagnosing the issue? Does GitHub have to remove my email address from the copy of the commit message when they respond to your GDPR request? 3. What about services that provide storage but don't process the content of that storage except to keep redundant copies or backups to protect you from hardware failure, such as Dropbox or Amazon S3? If I ask Amazon for personal information on me, do they have to figure out that you uploaded your contact list to S3 and my name, email, and phone number are there and tell me about it?
- chromanoid 5y agoIANAL 1. How the data is stored is irrelevant. Again personal data refers to data connected to your account. So if they store a history when and where you logged in, they have to provide it. When you upload stuff, they have to provide it. When you star a repo, they have to provide it. 2. They have to filter data out that is not ought to be seen by you. A Repository is a special case since it is not simply personal data. Think about giving a contractor temporary access to your repo etc. GDPR tries to enforce reasonable data compatibility between platforms ("Right to data portability"). This is orthogonal to personal data collection. 3. No. It's the responsibility of the services that use S3 to manage this. The operators are the controllers in this case. They also have to ensure that Amazon does not process the data they store on AWS S3. Eventually they have to make this agreement even part of the contract with the persons who they provide the service for.
- pawelkomarnicki 5y agoIt depends on how data is stored — many companies use user identifiers with attachable profile objects so when you delete your account your account is done random id. Hard to say if that’s a personal information anymore.
- tebbers 5y agoYeah I think this is a massive loophole. In a B2B setting, there is no GDPR obligation of another company to export all the data that a customer (e.g. a doctor) has uploaded (e.g. data on their patients). We've had some companies quoting hundreds of pounds to do this and have had to get the competition authorities involved.
- chromanoid 5y ago> In a B2B setting, there is no GDPR obligation I think this is not correct. AFAIK it's not transitive, but you can request any company directly. I think there are even people trying this randomly. As long as it's data about you, you are allowed to request it. When you sign an agreement that your data may be transferred to another controller (and there is no other way this data may be transferred), you are totally entitled to ask this controller for your data.
- that_guy_iain 5y agoThere are some aspects of B2B AFAIK that are excluded. For example, b2b doesn't need the employees permission for the data processing. But for clients of the b2b they do.
- chromanoid 5y agoOf course they need the employees permission if it is personal data (see also https://www.dickinson-wright.com/news-alerts/the-gdpr-covers-employee-hr-data-and-tricky https://www.dickinson-wright.com/news-alerts/the-gdpr-covers...). At least under German law if the times when I work are logged and processed I have to agree to this as employee. This is usually part of the employment contract. Also companies have to rightfully store legally relevant data usually 10 years so there are of course exceptions. For the storage clause there is even the right for data access blocking (when deletion is not possible because of a retention period).
- that_guy_iain 5y ago> Without consent, there are only a number of other ways an employer can process data, and those are identified in the GDPR as “legitimate basis”, which include, in relevant part: (1) to perform an employment contract; (2) to comply with legal obligations; and (3) to further a legitimate interest of the employer. You'll find nearly every time they use that.
- swongel 5y agoFrom article 4. of the GDPR: ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; AFAIK a personal to-do list would be "relating to an identifiable natural person" as the database will have a relation from this data to the account, which will likely have a name, email address or other PII (directly or indirectly). IANAL