4 ms·
What other rule do you find impossible? Data portability? The users right to delete data? Data processing agreements? Data security? Article 30? They are
by tyfon 2y ago
What other rule do you find impossible?
Data portability?
The users right to delete data?
Data processing agreements?
Data security?
Article 30?
They are all fairly trivial unless you do shady stuff really. Step one if is really looking at what you process as stipulated by article 30, a lot of the other stuff is much easier after that.
One of my roles is as a DPO in a bank in Europe, and it's far from impossible to comply.
- davidgerard 2y ago> What other rule do you find impossible? you will never get specifics out of these guys. They will lead you down a circuitous thread of unspecified fears until it's clear that their business model is to abuse customer data even as they'll avoid actually saying so.
- userbinator 2y agoThe users right to delete data? In practice that becomes the "right to rewrite history". Which should never be a good thing, for obvious reasons.
- gravescale 2y agoIt's not a universal rule that you have to delete personal data on request. If there's a "legitimate interest", you don't need to delete it even if asked to. But you will need to have that legitimate interest documented. What exactly do you envision being the bad outcome here where you are asked to remove personal information and don't have a legitimate interest to keep it for?
- GeoAtreides 2y ago> The users right to delete data? Hacker news, please, think about being GDPR compliant! You're breaking the law, hacker news!
- pheggs 2y agoI understand you are an expert on the field, and I am sure it's trivial for you. IMO the complexity arises from the many small things, imagine a smallish startup without having someone hired full time to deal with it. I am not an expert on the field, I tried a couple of times to get into the topic but found it difficult to navigate and left me with more questions than answers personally. What exactly does deleting user data mean? Do I have to search the weblogs for the users IP? Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate? Am I in breach if an ISP decides to route internet packets through the US? If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach? What if my mail provider decides to replicate their servers to another country? If you have resources to read up on this and how to handle all of it, I would really appreciate it! Happy to be convinced that it actually is trivial
- gravescale 2y agoThere is a ridiculous amount of material to read online and you can answer all those questions fully in about 30 minutes of searching and you could have relevant the policies written up by lunchtime. > Do I have to search the weblogs for the users IP? No, because you don't keep web logs with any PII in them longer then you have to, right? The time you need to keep them for is a legitimate interest that you need to be able to justify. Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate? Write an Email Retention Policy, there are templates. Follow that. Am I in breach if an ISP decides to route internet packets through the US? Isn't it encrypted? If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach? You said it yourself: it's a data leak, so yes, it is (assuming this is some bulk email list). Depending on the sensitivity of the list, you may need to disclose the leak to the affected parties. If you want to profit from being a data controller you really should already have done this homework, even before the GDPR and friends required it by law. A responsible company would already be taking care of it's customers' (and employee) data and at most just needs make sure the existing processes are documented. Demonstrably, companies don't do this, through laziness, incompetence or malice, and that's how we end up with these regulations. Just like how companies injuring people in unsafe workplaces is how you get H&S regulation. And really all you have to do is just actually make a decent effort. If you find that extremely onerous it's usually because you actually want to use the data for something that you know deep down is not something the information owner would want you to use it for.