5 ms·
Collecting personal data like that in Europe is hard and expensive to do legally, which is one reason why page owners would rather use Facebook.
by jdkjs 5y ago
Collecting personal data like that in Europe is hard and expensive to do legally, which is one reason why page owners would rather use Facebook.
- deleted 5y ago[deleted]
- wizzwizz4 5y ago> Absolutely be collecting email addresses and general contact info (with their consent of course) of your fans or page participants It's not hard, or expensive. Simply get consent. (Of course, you won't get much personal information on people that way, but that's how it be sometimes.) Here's an example of how you could do it: > Hello! I'm setting up a mailing list. If you're interested in receiving occasional updates about what's happening in this part of the community, please put your email address in this form: https://thecommunity.example.eu.org./subscribe https://thecommunity.example.eu.org./subscribe > I'll send you a verification email so nobody else can sign you up. There's also a link there to remove yourself from the list, and you can email unsubscribe@thecommunity.example.eu.org. any time to remove yourself from the list. (I'll send you a confirmation email to let you know you've been removed from the list.) > If you want to unsubscribe, please just unsubscribe. If you mark the emails as spam, it might send other people's copies to their spam, too, and it might be months before anybody notices. And if you have any feedback, do let me know.
- erehweb 5y agoLarge-scale data processing is considered high risk and requires appointing a data processing officer, according to https://www.osano.com/articles/gdpr-compliance-regulations https://www.osano.com/articles/gdpr-compliance-regulations. How large is large scale? Depends on the country - according to this link, the Czech Republic says 10,000 is enough https://iapp.org/news/a/on-large-scale-data-processing-and-gdpr-compliance/ https://iapp.org/news/a/on-large-scale-data-processing-and-g...
- ThePowerOfFuet 5y agoThis hypothetical situation doesn't require the appointment of a DPO.
- philistine 5y agoThat sounds like a job for the drummer.
- wiml 5y agoOur last data protection officer spontaneously combusted...
- waterhouse 5y agoHitting the send button really really fast. The skills carry over.
- Zababa 5y agoOf course a company trying to sell you services to help compliance is going to say that this business is "high risk".
- erehweb 5y agoHigh-risk is a term used in the GDPR itself - see e.g. https://ec.europa.eu/newsroom/article29/items/611236 https://ec.europa.eu/newsroom/article29/items/611236 from the European Commission
- Graffur 5y agoYour source has this: " Example: An online magazine using a mailing list to send a generic daily digest to its subscribers. Possible Relevant criteria: Data processed on a large scale. DPIA likely to be required?: No "
- isbvhodnvemrwvn 5y ago
- striking 5y agoIf you collect the info for just this specific purpose (maybe something like "Facebook takes down pages all the time, please help me keep in touch with you by subscribing to this email newsletter! I promise to use it only in the case that Facebook takes this page down or it becomes otherwise unmanaged by me") then I don't see why it would be complicated, just as long as it's something they intentionally do and you're clear about how you'll use the data.
- CryptoPunk 5y agoAnd the GDPR advocates claimed it wouldn't have devastating unintended consequences. Using coercive state power to forcefully regiment voluntary interactions is always wrong and causes severe adverse effects. GDPR is also harming European scientific research: https://sciencebusiness.net/news/data-protections-rules-harming-eu-leadership-health-research-says-report https://sciencebusiness.net/news/data-protections-rules-harm... If central planning worked at making society function better, the Soviet Bloc would have flourished and leapfrogged the West. It doesn't.
- echelon 5y ago> Collecting personal data like that in Europe is hard and expensive to do legally Only because the laws grew up around giants like Facebook. Prior to social media, it wouldn't have been a problem at all. You'd have no trouble setting up a small forum, blog, or mailing list. We're in the predicament we're in precisely because of Facebook. There might still be a cheap way to accomplish GDPR compliance as a small band, artist, company, etc. It doesn't seem hard to manually implement right to forget / data portability on the small scale. It's bolting onto big, existing businesses with lots of processes already in place that is expensive.
- uuidgen 5y agoSo what are those problematic GDPR requirements? - ask for permission - do not collect more than you have - store securely - allow users to change or remove their data - have a dedicated officer if you collect a lot Is that really THAT hard? (If yes, then really you shouldn't be collecting any data.)
- drdeca 5y agoDepends on what "have a dedicated officer" entails? If it requires employing someone you wouldn't be otherwise, then, yes, I do think it is unreasonable to require that I hire someone if I am letting people give me an email address for the purpose of sending them an email in the event that <x> (assuming that I am verifying at the time they give me the email address that they have control of the email address in question), no matter how many people request to be added to the list of people to send an email in the event that <x> .
- uuidgen 5y agoIt means designating a person that understands GDPR in the scope it applies to the particular data set and handles requests/security incidents. It can be secretary after a few hours of training. And I think that if you manage a mailing list of million of people then having someone who understand security implications of it and how much they can lose (even to a simple phishing at this scale) if you get that list accessed by scammers is necessary.
- seany 5y agoJust host this portion of your operation in an area that doesn't give a shit about EU rules? Seems like kind of a non issue in the context of the OP.