13 ms·
The thing about GDPR is that they can’t prove one way or another whether you are or are not a European citizen, so they are legally obligated to fill the reques
by witheld 5y ago
The thing about GDPR is that they can’t prove one way or another whether you are or are not a European citizen, so they are legally obligated to fill the request regardless.
- dekhn 5y agoWouldn't making such a request be fraudulent, then? I'd love to see my interview feedback but abusing GDPR or CCPA to obtain it seems abusive.
- multjoy 5y agoIt's data about you, GDPR gives you the right to access it. It is hardly abuse.
- dekhn 5y agoHmm, I'm going to have to think about this. A job applicant is a data subject of the company they apply to. The company produces data (interview evaluations) based on the expectation that their internal data is kept proprietary. However, GDPR permits the job applicant to act as a data subject and request the company's proprietary information (produced by employees who expected to remain semi-anonymous to provide candid feedback). If that's the case, I think I have another in a long list of items to add to my list of "why GDPR is a crazy law and the implications weren't completely thought-through"
- detaro 5y ago> The company produces data (interview evaluations) based on the expectation that their internal data is kept proprietary. To phrase it bluntly, a company needs to consider what laws apply to it before it forms such expectations. I'm sure some company also compiled databases of addresses for advertising purposes to based on the expectation that their internal data is kept proprietary, also doesn't work like that. Also note that an obvious solution to having to disclose data is not having it. Plenty places will have you re-interview if you re-apply anyways, so justifying why they keep detailed interview notes around is an interesting question, assuming this request comes after the process has ended. > (produced by employees who expected to remain semi-anonymous to provide candid feedback). Employees don't just expect that, they have a legal right to it. "my personal data" does not include "who did interview me", and the company has to protect the personal details of its employees. (presumably why the reddit OP mentioned data being redacted)
- dekhn 5y agoI'm not aware of any law before GDPR that permitted this. Normally, you'd have to have a court case and do discovery. So I do think that companies shouldn't really have anticipated this when they formed their expecftations, unless they were formed after GDPR was approved. Just being able to read interview feedback is enough to recognize who wrote it.
- detaro 5y agoBut that applies to pretty much any new law: you need to consider what it means for your existing process. I can't ignore tax law with "but that was different last year!" either. Even keeping records about applicants for a long time without explicit permission is a problem, so if you still have pre-GDPR records around... GDPR was published 2016 and became active in 2018. Even if you only started to think about it at the second date you've had almost 4 years.
- handoflixue 5y ago> Just being able to read interview feedback is enough to recognize who wrote it. While that might be true internally, I think it's pretty unlikely that a candidate had enough of a sense of each person's writing style (especially if the interview was conducted via voice, as is typical) > So I do think that companies shouldn't really have anticipated this when they formed their expecftations, unless they were formed after GDPR was approved. The GDPR was passed in 2016. I feel like 5+ years is plenty of time to re-adjust expectations.
- dekhn 5y agoAt this time, I believe that the law (either GDPR or CCPA) itself does not require companies to disclose confidential interview notes. Certainly when I worked at Google during GDPR they reorganized massive amounts of data storage to comply with that, but I don't recall anybody doing hiring saying GDPR applied. From I can tell a random throwaway made this post on reddit, it may have happened, but it doesn't mean that companies are required to do this. I would like to see more supporting data.
- PeterisP 5y agoThe basic legal principle (GDPR article 6) is that processing data about people is allowed only if a specific legal basis applies, and only to the extent that this legal basis allows it. So before we're even talking about expectations of the availability of this data - e.g. detailed interview notes in some company HR system (personal notes of specific interviewing employees would not count if these notes are not used in the company processes) - the company must consider why do they think they are allowed to record and store that data in the first place, since the "default expectation" is that they are not. And if they have a valid reason, they are required to have their Data Protection Officer to know that they are processing this data and it's the duty of the DPO to inform these people about what exactly they are permitted and required to do with this data - so if the people recording this data have a misleading expectation, that's fully the fault of the company. Before "the company produces data (interview evaluations) based on the expectation that their internal data is kept proprietary" it's the duty of the company to ensure that this processing of private data is reviewed, verified whether that processing is lawful in the first place and ensure that the people recording this information are informed about what they can/can't/must do with it, as the law requires the company to either ensure "appropriate organizational measures" for that, or not process this data at all. If the company has their employees "simply" producing data that includes personal data of others without considering the GDPR impact, that by itself is a breach of their legal duty of Article 24 of GDPR. In situations like these, most companies would assert that they have a specific legitimate interest (article 6.1.f) in processing the data for conducting the interview and application decision process, which is a perfectly valid justification - however, that would not necessarily grant them the right to process the data after the interview process ended with a rejection; there's no inherent right for the company to just continue storing the detailed interview notes just because, so it would be interesting to see what legal basis they assert for having that data in the first place, and IMHO in most EU companies the standard HR process now would require to discard the details after the interviews.
- detaro 5y agoAt least in Germany it seems storing records for up to 6 months is common, since that's when the deadlines for suing under discrimination law expire and an employer has a legitimate interest in being able to produce detailed documentation about their decision process to defend against such lawsuits. But that's again a very specific thing that justifies it.
- M2Ys4U 5y agoThis has been the case since long before the GDPR. The ability to make subject access requests was in the Data Protection Directive which was passed in 1995.
- icedchai 5y agoI would just say it has been deleted, so no data is available. Why waste your time with a response?
- atoav 5y agoBecause sometimes people who send you such a request might actually already know parts of the data you have on them. Telling them there is _no_ data shows them that you are either untrustworthy or utterly incompetent. If they are the wrong type of person they might come with a lawyer next.
- icedchai 5y agoI’m saying I had no data ever, I’m saying I have none now. Unless you have big bucks GDPR is toothless for stuff like this. I firmly believe data about interviews is private, to the company.
- atoav 5y agoAre you sure you have none now? This could be very expensive : )
- icedchai 5y agoHow is someone going to figure out if I actually do, if none of the data is externally accessible?
- multjoy 5y agoWhy do you need big bucks? You make a complaint to the regulator and then they do the heavy lifting on your behalf.
- icedchai 5y agoI'm sure it's that simple. You'll need big bucks to get a lawyer and prepare a compliant. The regulator will have bigger fish to fry. One or two people whining about "their" interview data is laughable. Your little complaint will land on the bottom of the stack, where it will stay, forever.
- Arnavion 5y agoI tried to use the GDPR angle to close a bunch of old accounts I'd gathered over the last decade. One of them, an MMO, wanted me to provide proof of my EU citizenship by scanning and sending them my passport / national ID in order to proceed.
- detaro 5y agoGDPR applies to non-citizens too, so that requirement was bogus.
- foepys 5y agoGDPR also applies to EU residents, so asking for a passport or national ID is not enough to avoid answering a request.
- detaro 5y agoit also applies to people that just physically are in the EU, no residency needed.
- junon 5y agoThis is a common cop-out and is not specified in the laws whatsoever. If they are slimy enough to require proof (instead of just being good data processors and honoring the request anyway) tell them they should check your IP's location if they really want proof, and that if they do not comply you'll open a complaints case against them with the relevant authority for the country in which you reside.
- detaro 5y agoCitizenship is irrelevant to GDPR. A non-EU company could probably request at least some proof that you're in scope if they have reasonable doubts about if you are, but I suspect in practice many find it easier to just oblige a reasonable request they have a process for than getting into the weeds of scope and risk getting it wrong. (i.e. I suspect there's some fun legal nuance in scenarios like "I'm a US citizen living in the US that applied and got rejected 3 months ago, now I'm on holiday in Copenhagen and writing an access request" - I could see ways of arguing that either way depending on the circumstances, but also am not a lawyer). Although a request for interview information like this might be enough hassle to be restrictive.
- remus 5y agoIt's not actually that unfeasible. A pretty standard first step in complying with a Subject Access Request is to verify the identity of the person you're talking to (wouldn't want to hand over a load of personal data to some random after all), so checking their nationality at the same time isn't miles off.
- detaro 5y agoagain: citizenship/nationality/residency doesn't matter.
- x0x0 5y agoA non-EU company, or a company that believed a data subject was not subject to GDPR, would definitely demand some proof the company was GDPR obligated before handing over job applicant or employee data, since that is likely being used to prep for a lawsuit. You can't fly to Copenhagen and submit a request if the employer and application took place in eg the US. That's all part of the territorial applicability -- you don't necessarily need a presence in the EU, but you do need an establishment through eg stable arrangements. See Guidelines 3/2018 on the territorial scope of the GDPR (Article 3).
- detaro 5y agoI was thinking more multinational corp, where there could be interesting questions if the US could in edge-cases still count as touching the context of the (clearly existing) EU establishment. E.g. if an employee in an EU office happened to do one interview stage or was otherwise involved, they'd have done "data processing" in the EU. Or if the same hiring process and organization also runs the equivalent for EU offices, does that pull it in through same way. Etc. Very possible that not, just not something I'd be confident on for all cases. Of course a large multinational is also likely to have had people look at these questions and design their process around them where needed. Good point on the lawsuit risk being a reason to be strict though.
- PeterisP 5y agoOne aspect is that for companies within EU it applies for everyone - i.e. if you're an EU company which serves 100% only Chinese and Brazilian individuals and noone within EU, GDPR still applies to you and how you must handle the data of individuals so they all get GDPR rights. Citizenship and residence matters only for foreign companies doing business in EU.
- colejohnson66 5y agoSo, if I’m an American who has never been to the EU, could I file a GDPR request against Google Europe or whoever?
- 0xdeadb00f 5y agoYes
- PeterisP 5y agoYou could, however, IMHO the result would be that "Google Europe" (in my case, Google Ireland Limited) would notify that they and their subsidiaries have no data on you since they do not deal with your data in any way as you are the customer of "Google USA" and not their customer, unlike all the users Google thinks are in EU and switched their accounts/contracts/etc to the EU subsidiary. And if your data is processed by "Google USA", then GDPR applies to that processing only if you are "a data subject in the Union".
- junon 5y agoThis is not true. They are allowed to figure out where the request came from, even if it is from IP information. I had a pretty nasty back and forth with a Grammarly alternative about retention of my data, where he insisted he needed my passport and a whole bunch of other stuff to fulfill the request, to verify I was requesting from Europe. I kindly reminded him that his privacy policy states the site collects IP information. After about a month of legal threats, the GDPR request was fulfilled.