{"id":5272,"date":"2018-06-05T20:05:00","date_gmt":"2018-06-05T20:05:00","guid":{"rendered":"https:\/\/really.zonky.org\/?p=5272"},"modified":"2018-06-05T20:05:00","modified_gmt":"2018-06-05T20:05:00","slug":"no-it-wasnt-a-gdpr-hissy-fit-but-a-hardware-fault","status":"publish","type":"post","link":"https:\/\/really.zonky.org\/?p=5272","title":{"rendered":"No It Wasn&#8217;t a GDPR Hissy Fit But A Hardware Fault"},"content":{"rendered":"<p>As the subject says, this blog has been offline for just over a week because of a hardware failure. Just when I wanted to moan about all the GDPR hissy fits that people are throwing.<\/p>\n<p>Noticed some websites are blocking you because of the GDPR?<\/p>\n<p>That&#8217;s the hissy fit. Seems that some international web site operators who previously assumed that GDPR didn&#8217;t apply to them, are suddenly realising that it does. Which is an indication that they have been impersonating an ostrich for a couple of years now.<\/p>\n<p>Smaller businesses get a free pass on that one, but any reasonably sized company should have been aware of GDPR by now. It was put in place and\u00a0<em>deliberately<\/em> put on hold for two years to allow people to get started with complying with GDPR. Anyone involved in the security business has been hearing &#8220;GDPR&#8221; for over two years now.<\/p>\n<p>So there are those who claim they&#8217;ve not heard of it, and are now panicking and trying to catch up, making a mountain out of a molehill, and claiming that it&#8217;s a dumb law. Technically it isn&#8217;t actually a law but an EU regulation that member states are required to make law.<\/p>\n<p>Anyway onto some of the biggest arguments against the GDPR &#8230;<\/p>\n<h2>The Whois Question<\/h2>\n<p>This is a great example of what happens when you ignore a situation and then panic.<\/p>\n<p>When you register a domain (such as\u00a0<em>zonky.org<\/em>) or a netblock (a set of IP addresses), you are expected to provide contact details for the individual(s) involved in the registration process &#8211; to allow for billing, and contact to be made in the event of operational issues.<\/p>\n<p>Storing that information is perfectly reasonable.<\/p>\n<p>Publishing that information is perfectly reasonable given informed consent.<\/p>\n<p>Ideally the domain registration would offer a choice to the registrant &#8211; public listing of personal details, public listing of role contact information, or public listing of indirect contacts (i.e. keeping the contact details private).<\/p>\n<p>There is a German court case decision saying that it isn&#8217;t necessary to have contact information for registering a domain; all I can say is that the German court obviously didn&#8217;t have the full facts.<\/p>\n<h2>GDPR&#8217;s &#8220;Right To Be Forgotten&#8221;<\/h2>\n<p>One of the misconceptions is that the &#8220;right to be forgotten&#8221; is an absolute human right; for a start it&#8217;s not a a human right, but a right under the law. And it is not absolute; the text of the GDPR includes numerous exceptions to the right to be forgotten, such as :-<\/p>\n<ul>\n<li>A legal or regulatory obligation to keep the personal information.<\/li>\n<li>An overriding public interest.<\/li>\n<li>Ongoing legitimate business processes still require that personal information.<\/li>\n<\/ul>\n<p>The key is that if you are an ethical business (in particular don&#8217;t plan to sell personal information and\/or keep spamming people) then the right to be forgotten isn&#8217;t anything to worry about.<\/p>\n<h2>GDPR: The Fines<\/h2>\n<p>The strange thing is that there is doubt over the level of fines that can be levied under the GDPR which is remarkable as the language is quite clear &#8211; the lower level of breach can be fine of up to either \u20ac10 million or 2% of annual turnover.<\/p>\n<p>Or to put it another way, for the lower level of breach, the\u00a0<em>maximum<\/em> fine is whichever is greater \u20ac10 million or 2% of annual turnover. The\u00a0<em>maximum<\/em>.<\/p>\n<p>Do you know how often the ICO has imposed the maximum level of fine under existing legislation? Never.<\/p>\n<h2>The Jurisdiction Issue<\/h2>\n<p>Now here there is some legitimate grounds for grievance; after all whenever the US starts imposing its laws outside of the US, people outside the US start jumping up and down. And yes, the EU\u00a0<em>does<\/em> expect non-EU companies to obey the GDPR regulation if they store data on EU citizens.<\/p>\n<p>In practice, the EU isn&#8217;t going to try going after small companies outside the EU; particularly not small companies that are just ordinary business and not engaged in Cambridge Analytica type business.<\/p>\n<p>The other way of looking at the global reach of the GDPR is whether it would be a good idea for there to be a world-wide law in relation to the protection of personal information. The Internet means that world-wide laws are necessary in this area, or those abusing personal information will merely move to the jurisdiction with the weakest protection of personal information.<\/p>\n<div id=\"attachment_5247\" style=\"width: 705px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-5247\" class=\"size-large wp-image-5247\" src=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2018-05-06-Rusty-Handrail.jpg?resize=695%2C463&#038;ssl=1\" alt=\"\" width=\"695\" height=\"463\" srcset=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2018-05-06-Rusty-Handrail.jpg?resize=1024%2C682&amp;ssl=1 1024w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2018-05-06-Rusty-Handrail.jpg?resize=300%2C200&amp;ssl=1 300w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2018-05-06-Rusty-Handrail.jpg?resize=768%2C512&amp;ssl=1 768w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2018-05-06-Rusty-Handrail.jpg?w=1280&amp;ssl=1 1280w\" sizes=\"auto, (max-width: 695px) 100vw, 695px\" \/><p id=\"caption-attachment-5247\" class=\"wp-caption-text\">Rusty Handrail<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>As the subject says, this blog has been offline for just over a week because of a hardware failure. Just when I wanted to moan about all the GDPR hissy fits that people are throwing. Noticed some websites are blocking you because of the GDPR? That&#8217;s the hissy fit. Seems that some international web site <a href='https:\/\/really.zonky.org\/?p=5272' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_share_on_mastodon":"0"},"categories":[4,489],"tags":[1726],"class_list":["post-5272","post","type-post","status-publish","format-standard","hentry","category-it","category-security","tag-gdpr","category-4-id","category-489-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"share_on_mastodon":{"url":"","error":""},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1f2KI-1n2","_links":{"self":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/5272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5272"}],"version-history":[{"count":2,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/5272\/revisions"}],"predecessor-version":[{"id":5274,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/5272\/revisions\/5274"}],"wp:attachment":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}