3 ms·
Not sure what you are answering. If you for instance expose an endpoint by accident and then can't show logs for the access to it, you are going to have a probl
by AtNightWeCode 5y ago
Not sure what you are answering. If you for instance expose an endpoint by accident and then can't show logs for the access to it, you are going to have a problem in one of those GDPR hearings. The irony of GDPR is that you may end up with more logging of user data, not less.
- jacquesm 5y agoExplain 'one of those GDPR hearings'. I'm pretty familiar with the GDPR and everything that comes with it, I've never even heard of the term 'GDPR hearing'.
- AtNightWeCode 5y agoMaybe it is not handled the same way depending on where you operate from but where I live you are supposed to report any potential data leak of GDPR sensitive data to the local authorities. I do not know what the criteria is that makes you end up being questioned about it though. I been at such meetings over silly things.
- jacquesm 5y agoThe reporting requirements are the same all over Europe, it's a 'better safe than sorry' mechanism put in place after companies routinely wiped their data breaches under the rug in the hope that nobody would notice. Once you get to that stage there can be a follow up to gather more information, and that follow up then usually results in some advice or no further action. In rare cases - typically the ones where gross negligence or willful transgression of the rules was established - there will be a fine and if it is a repeat occurrence that fine can be quite substantial. Also you don't have to report 'potential leaks', only actual leaks. So I think that in the case of your hypothetical end-point the logging isn't a GDPR requirement, but if your endpoint ends up leaking data then the log can help you to establish if and if so how much data was exfiltrated. But that does not mean that the GDPR requires you to have logs, though, having access logs for your endpoints is a fairly standard thing and not having them is going to raise a few eyebrows, especially if you are also reporting a breach. Where there are logging requirements: data retention laws, SOX, fintech, tax regulation, AML.
- AtNightWeCode 5y agoAt companies I worked with repute is key. Companies with employee count in the range of 10 to 50k. The legal departments will report any potential breach. As a developer you can decide what is logged but not much about anything else in the business. You as a developer or tech lead will most likely be held accountable.