Forum Moderators: webwork

Message Too Old, No Replies

EU GDPR is not only about Websites

         

Travis

12:12 pm on Apr 6, 2018 (gmt 0)

5+ Year Member Top Contributors Of The Month



Just wanted to point that the EU GDPR concerns all businesses as well as any kind of personal data. So for example, it also concerns your employees information, your clients, your mailing list, anything.

LifeinAsia

5:52 pm on Apr 6, 2018 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



So true! I work at a university and deal with a LOT of personal data in multiple locations across many divisions.

You also have to remember that the data is in backups and archived data, so scrubbing live data isn't sufficient.

Travis

5:55 pm on Apr 6, 2018 (gmt 0)

5+ Year Member Top Contributors Of The Month



You also have to remember that the data is in backups and archived data, so scrubbing live data isn't sufficient.

Without forgetting that the EU GDPR includes the right to have your personal data deleted, meaning that, at the request of a EU citizen, you have to be able to remove his/her data from your backups as well.

LifeinAsia

7:08 pm on Apr 6, 2018 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Right, like I said. :)

tangor

12:47 am on Apr 7, 2018 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



And then .... wait for it....

There will be challenges for such breaking law enforcement needs, accounting practices, and other oddities of "doing business".

One of the classic cake-and-eat-it-too conundrums of a tcch society.

How much, how far, how detailed, and who gets to manage it, and IF YOU CAN MAKE IT DISAPPEAR how,, in certain circumstances, can civil necessities be documented and accomplished?

We live in interesting times.

Shaddows

12:59 pm on Apr 11, 2018 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



GDPR expressly allows you to refuse to delete data where you may need to to discharge legal responsibilities. This covers taxes and accounting.

You may need to pseudonymise it, however. This essentially means that all the "operational" data (like what was ordered, where it shipped, how much it cost) can be tied to an identifier, then the identity held elsewhere (to be reassembled if required, while effectively anonymous if not).

I do think this disassemble/reassemble of sales data opens up whole new opportunities to launder money.

_____

Imagine a gigantic corporate, using tape backup at the end of their data-handling chain. If I ask them to to delete me, will they reasonably re-write that tape backup? I don't think so.

Travis

5:33 pm on Apr 11, 2018 (gmt 0)

5+ Year Member Top Contributors Of The Month



Also, the EU GDPR mentions that, you have to ensure that data collected before the enforcement are also compliant with the GDPR. For example, if you didn't recorded the explicit consent from a user to record such or such data, you have to obtain this consent now. Same, if you recorded data , and archived them. You 'll have to go through your archives to delete them.

Mark_A

11:48 am on Apr 13, 2018 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



It should not be forgotten consent is one of the legal basis for processing private information, there is also legitimate interest which in some circumstances is also ok as a legal basis.

Travis

1:12 pm on Apr 13, 2018 (gmt 0)

5+ Year Member Top Contributors Of The Month



...legitimate interest which in some circumstances is also ok as a legal basis...

In that case, Interested based ads tracking is also a legitimate interest, since this is to improve users' experience, by providing them with ads which are interesting, instead of bothering them with other ads.... there is a survey somewhere which said that xx % of people prefered to see ads targetted to their interest than random ads ...

Collecting private data and selling them to marketers is also a legitimate interest since like that it allows to offer a free service, in exchange, etc, etc...