Questions tagged [gdpr]

Questions about the European Union General Data Protection Regulation (GDPR)

https://www.eugdpr.org/

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) was adopted in 2016 and enters force starting 25 May 2018. It contains provisions for EU citizens and residents to control their personal data, which it explicit defines as:

Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer IP address.

The GDPR applies not only to EU organisations but also to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location.

Violators can be subject to fines.

998 questions
27
votes
2 answers

How to satisfy GDPR's consent requirement for IP logging?

Countless websites are served by webserver software (Apache, nginx, etc.) which logs the source IP address of every web page visit. The GDPR considers an IP address "personal data" that is subject to the GDPR. The GDPR requires consent of the…
Pistos
  • 373
  • 1
  • 3
  • 6
26
votes
2 answers

Can I request a copy of my personal data (GDPR) from email-scammers and sue them if they don't comply?

So, I've been receiving a lot of spammails recently and I'm pretty fed up with them. I've also been wondering, how they got access to my mail-address, so I sent a request of information so I can see, what data they store about me, where they got it…
Florian F.
  • 363
  • 3
  • 6
20
votes
2 answers

Are global user account systems now illegal following the EU's May 2023 fine of Meta?

The fine: https://www.theguardian.com/technology/2023/may/22/facebook-fined-mishandling-user-information-ireland-eu-meta Like any website, we have an account system where people log in to access their orders and activate their software. So we have…
Per
  • 303
  • 1
  • 4
17
votes
1 answer

Can Slack really claim not to be a data controller?

I'm an EU resident. I just sent in a GDPR removal request to Slack. Their response: Per our Terms of Service and Privacy Policy, your Workspace Primary Owner (Customer) controls Customer Data. Customer owns all of the submitted content, including…
the
  • 271
  • 2
  • 6
14
votes
1 answer

How can consent-banner as a service be GDPR compliant?

A couple of months ago I've read that hosting google fonts on your own server is a better but maybe slower solution as loading content from google servers is already something that the users must be informed about due to submitting your IP to…
Samuel
  • 243
  • 1
  • 5
12
votes
3 answers

Why does the GDPR matter to me, a US citizen with no property in Europe?

I run a Web site. I am a natural-born US citizen. I own no property outside the US. Why does my Web site have to be GDPR compliant? Even if a European court convicts me of a crime, does it really affect me?
Someone
  • 17,046
  • 10
  • 84
  • 177
11
votes
5 answers

GDPR: Can a city request deletion of all personal data that uses a certain domain for logins?

A city in Finland asked me to delete all data for everyone whose login uses a certain domain. The domain contains "edu" in it and "oppilas" (which translates to "student"), and my website doesn't have data that anyone is going to mind losing, so I…
cesoid
  • 211
  • 3
10
votes
2 answers

Can a company actually become GDPR compliant? Is there such a thing?

(This question could be expanded to other auditing procedures too) How do huge multinational companies that want to become GDPR compliant start off this? I mean, I guess one has to read the regulation, correct? But what if you misunderstood a point?…
4d4143
  • 103
  • 1
  • 5
10
votes
1 answer

What actions to take when a Data Processor doesn't respect GDPR?

We've recently exchanged emails with one of our Data Processors, because they don't grant the ability to permanently delete hosted documents (pdf, png, etc.) on their platform. Such documents might contain personal information. In the event where an…
Vadorequest
  • 201
  • 1
  • 5
10
votes
6 answers

GDPR and right to provide meter readings

My energy company have estimated the opening meter readings for my move in date for a property. I have the correct readings in photos taken on that date, but the energy company won't allow me to submit those readings since their terms and…
F Chopin
  • 315
  • 2
  • 9
10
votes
1 answer

GDPR Compliance - notification of data breach

In Art. 33, the GDPR specifies that a controller must notify a personal data breach to the supervisory authority after having become aware of it. Case 1: A database dump with personal data is hosted for a period of time on a server that is…
Simon
  • 201
  • 1
  • 5
9
votes
2 answers

GDPR & EPR regards maintaining email blacklist

Note a user call YIVI had previously stated that you could store a hash of the users email address to avoid the requirements of General Data Protection Regulation (GDRP) and ePrivacy Directive (EPD). This is false as hashed email addresses are still…
user32690
9
votes
1 answer

Does GDPR cover the collection of data by websites that crawl the web and resell user data

I have found that a lot of my personal info is now available on a bunch of websites that collect data and resell it. I'm talking about those 'find anything about anyone' websites. A lot of the data is also inaccurate. Since a lot of these companies…
Thomas
  • 523
  • 2
  • 6
9
votes
3 answers

Under GDPR, can I request to be forgotten and re-register for a trial?

Imagine an on-line service which offers 1 month of free trial for new users. Can I perpetually: register for the trial, use it for a month request my account deleted and my data forgotten repeat ?
9
votes
1 answer

Legal aspects of Firebase Crashlytics SDK

Let's say we have a mobile app, where every user is associated with app-generated unique user id (ex. 57d2ef8b391277001aad7784). Having the uuid itself that's not possible to identify a user. Having the uuid and access to the app backend…
1
2 3
18 19