4 ms·
Considering that the P in GDPR stands for Protection, not Privacy, the scope of the legislation is significantly broader. If we look at the ISO standard for inf
by utucuro 5y ago
Considering that the P in GDPR stands for Protection, not Privacy, the scope of the legislation is significantly broader. If we look at the ISO standard for information security, ISO 27001, apart from the confidentiality and accessibility of data, it considers integrity as one of the three things to consider when classifying data and similarly, the GDPR expect PID to be handled in a manner that assures correctness at the very least.
In the specific case of this bank, like everyone else, they were expected to update systems unable to comply with the legislation within the grace period and yet it seems that they were unwilling or unable to update or replace a system that is incapable of achieving data integrity in a matter as basic as the name of a customer.
- SpicyLemonZest 5y agoBut it's just not true that everyone else was expected to do this. Credit card names are still running on ASCII! (I'm also, to be frank, highly skeptical that the court would have taken such a hard line if the customer had been complaining that Chinese characters aren't supported or that his Arabic name should be written right to left.)
- Daneel_ 5y agoThat's not quite the issue at hand though. In that situation, the bank should be opening an account with the correct name then issuing a credit card with an ASCII-converted name. This would be acceptable because the personal information is stored correctly, it's just represented in simplified form on the card. The issue in the article is that the bank couldn't even open an account with the correct name. I suspect this will be fixed by storing the correct name in an external system and using an ID number or similar to refer to the customer on EBCDIC systems.
- SpicyLemonZest 5y agoThat all sounds reasonable to me as a matter of customer-friendly system design, but it's not obvious to me why it would satisfy the court here. If using a customer's properly formatted name is a GDPR requirement, it seems like it'd be required in all cases; GDPR doesn't have any sort of "nbd if it's too hard to comply" clause.