3 ms·
There's a lot of uncharitable talk in this thread, where comments like yours assume bad intent on behalf of businesses who find GDPR compliance challenging. It
by sterwill 5y ago
There's a lot of uncharitable talk in this thread, where comments like yours assume bad intent on behalf of businesses who find GDPR compliance challenging. It's a giant body of regulatory law, of course it's complicated! The GDPR probably _isn't_ hard to deal with if you don't actually care about privacy; it's easy to just not follow the law and hope you don't get caught. But if your company respects individual privacy, and collects personal data only with a lawful basis, and needs to make assurances to its customers that all the regulations are being followed, there's a lot of work you have to do to demonstrate compliance, and many specifics (for example, with regards to personal data erasure in backups and archives) are completely unspecified. How uncomplicated is that issue?
- denton-scratch 5y agoThe more collecting and processing you want to do, the more complying you're going to have to do, I can see that. With respect to the archives: don't you think that's best left to the company and their legal department? - As far as I'm concerned, an archive is by definition immutable. And if a company caan't protect its own archives, it's got worse problems than GDPR.
- jstummbillig 5y ago> The more collecting and processing you want to do, the more complying you're going to have to do, I can see that. I am sorry, but this is too hand-wavy considering the insane complexity we are touching here. To illustrate, a super simple example: Someone writes you (a business entity, it's harder when it's in health) a mail with a random business related request. If you think, it should be fair enough to a) receive/store, b) read and/or c) answer to this very much unsolicited mail you are mistaken. If you think, that there is a clear/sane/minimal way to handle any of these scenarios, you are wrong again. Depending on your exact situation and request you might first have to respond by asking the party to waive their right to encrypted communication (which they, of course, couldn't even execute, since pgp is obviously not a thing with real people in the real world), and/or their physical address, to SEND THEM YOUR ANSWER VIA POSTAL OR FUCKING FAX, because that is deemed a sane way to get around problems with email storage/encryption, even in big companies and governmental agencies. You definitely also have to delete the email after some amount of time. All of a sudden you (as in some random person who just wants to do business in the modern times) has to figure out retention policy and implementation (or pay some consultant, who will be happy to be paid to figure out how to use email for your business without getting sued in 2021) In case you don't run your own email server on your own fucking physical server, you also better get a contract with every relevant so called Processor (Art. 28 GDPR) in the chain. This however might not suffice if if you want to use gmail/google workspace (or in any other non-eu hosted provider). Depending on the industry it might simply be illegal for you to use theses services. I say might, because, honest to god, there is no clear fucking answer on this. Trust me, I looked. But you know what, this is not my biggest gripe with GDPR. It's not the burden that it puts on seemingly simple processes, no matter how well intentioned you might just want to get your actual job done. The biggest gripe is that it's full of vague wordings like "meet requirements to ensure protection" without specifying the exact fucking requirements, or "careful handling of sensitive data", as if that explained anything. What the fuck? If you are actually serious about creating a law to protect privacy you have to at least provide very serious specs – and, I would argue, to be not completely fuck all the normies trying to run a business, also easy and cheap implementation. After having done a very thorough trip through the entire thing, I am 99% certain that 99.9% of businesses are knowingly and/or unknowingly in violation of GDPR.
- denton-scratch 5y agoThat stuff about mandatory email encryption is nonsense. Nothing in GDPR impacts on the way a normal mailserver operates. And if you're running a mailserver, then you've got a retention policy. Either it's your policy, or it owns you.