Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>If you ask for your data to be deleted does that include your address in my contacts?

I'm assuming that "my" in this sentence means a business, since individuals are not subject to GDPR, and that the thrust of your question revolves around, say, a customer support portal.

Yes, addresses have to go unless you have a legitimate business reason to keep them. For tax purposes or to prove something in an active court case are both examples of a reason you could keep the address at least temporarily.

>Does it include your messages to me?

No, they could be anonymised instead. If the messages contain PII you might need to sanitize them.

>Does it include your posts that appeared on my feed?

Same as the previous question.

>It's not clear to me how those are handled by the GDPR and at what point things sent digitally from you to me end being my property and no longer your property.

This is defined on, like, the second page of the GDPR document. Article 2 "material scope" point 1.

This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

GDPR kicks in when you start processing this stuff automatically. If you want to handle your entire businesses paperwork via a set of paper ledgers with humans in front of them, that'll make you GDPR immune.

Listen man, I read the GDPR document /once/ almost a year ago now, and I remember the answers to your questions off the top of my head. I'm not a lawyer either, I'm a software engineer.

If someone told you GDPR was complex, they lied to you. The legislation is dead simple and most of the document is actually not about what businesses need to do but about what the EU bureaucrats need to do. You only need to read about half of it, the rest is irrelevant to you.

If this matters to you, just go read the damn thing. Trust me, it's a fricking revelation to do so, you'll be staggered by the amount of bullshit people spout about it and the amount of needless fretting and hand-wringing they do once you know how simple it is. Don't get me wrong, the implementation may be hard for some businesses, but I'll also tell you straight up, there are lots of businesses voluntarily making their GDPR implementations harder and more expensive than necessary because they didn't bother actually reading the law and are instead going off third-hand chinese-whisper information, which is a crazy way to run a business.



> I'm assuming that "my" in this sentence means a business, since individuals are not subject to GDPR

No; tokyodude is asking what happens if you request that (for example) Google erases your data, and he has your email address in his Gmail contacts. Does Google, as the data controller who ultimately stores tokyodude's contact list for him, then have to purge your email address from tokyodude's address book?

> Listen man, I read the GDPR document /once/ almost a year ago now, and I remember the answers to your questions off the top of my head. I'm not a lawyer either, I'm a software engineer.

This condescension is obnoxious and unwarranted. Just take a look at the complexity of the conditions at https://gdpr-info.eu/art-17-gdpr/ dictating when the right to erasure applies. Point (b) seems to suggest that it applies by default if the basis for originally processing the data was the subject's consent... but that the controller can override that if they have another legal ground for processing. So can they just argue they have a "legitimate interest", under article 6(1) point (a), in preserving tokyodude's address book? I have no idea.

Meanwhile, point (f), linking to article 8 about children, is saying - I think - that a data controller must honour an erasure request if it's about data they collected from a child, even if they have another legal ground for processing that data. So even if the legitimate interests argument above would hold, if you're a 12-year-old, I think you absolutely can demand that your email address be purged from tokyodude's address book and he can't do anything about it?

How about your actual emails to him? Can you demand that Google deletes them from his inbox? As far as I can see, the answer logically ought to be "yes"; Art 17 (1) (f) applies and I don't see any exception that would let Google wriggle out of the obligation.

But I'm not sure if any of the above, because this stuff is vague and complicated. If you truly think it's simple, I invite you to walk us through the answers to the scenarios I've explored above, supporting your assertions with relevant references to the text of the law. I do not expect you to be able to do so.


>No; tokyodude is asking what happens if you request that (for example) Google erases your data, and he has your email address in his Gmail contacts.

Oh, well in that case this is explicitly handled in recital 18. https://gdpr-info.eu/recitals/no-18/

> Point (b) seems to suggest that it applies by default if the basis for originally processing the data was the subject's consent... but that the controller can override that if they have another legal ground for processing.

Yes.

>So even if the legitimate interests argument above would hold, if you're a 12-year-old, I think you absolutely can demand that your email address be purged from tokyodude's address book and he can't do anything about it?

Yes.

>How about your actual emails to him? Can you demand that Google deletes them from his inbox?

Covered in recital 18.

I totally agree with all your interpretations, well done. See what I mean about it not being that complex?

Not that you shouldn't run all this past your company lawyer to make sure they agree mind you. After all, companies keep lawyers around for input on exactly these kinds of issues, might as well get your moneys worth.

It's ok for you as a software developer to be unsure about some of these things, you're not a trained lawyer. What I'm being condescending about is software developers wailing "oh it's impossibly byzantine, oh it's impenetrable, oh woe, oh drat, oh heavy is the burden of being me in a GDPR-compliant era". Software developers regularly read documentation more complex than the GDPR legislation. Jesus, you'd think it was written in latin the way some people on hacker news cry about it.


I think part of the issue here is that a plain English reading of the GDPR implies such appalling totalitarian overreach that most people find it hard to believe that it can really be what's meant.

I mean, you've just agreed with my reading that the GDPR gives me the power to reach into your personal inbox and censor your records of communications with me. That sort of power for bad actors to carry out historical revisionism on what until now we'd've thought of as someone else's data is unprecedented and - at least to me - a pretty frightening threat to freedom of information and a culture of truth. And meanwhile we've got people running around Hacker News saying "GDPR is all wonderful, it's just common-sense privacy protections, and if your business isn't spying on users without their consent and selling their data you'll be fine".

You're clearly confident that the (to me, somewhat dystopian) interpretations we discussed just above will hold up in court. I'm not, even though they worry me and seem to me to be the most straightforward plain English reading of the bill. That doubt - and associated anger at the failure of the EU to bring greater clarity to these sorts of points before now - seem to me to be reasonable, and not a worthy target for condescension.


>I mean, you've just agreed with my reading that the GDPR gives me the power to reach into your personal inbox and censor your records of communications with me.

That's quite literally the opposite of what recital 18 explicitly says?


recital 18 clearified absolutly nothing for me. My plain reading of recital 18 is that it has to do with personal records stored on paper or my own computers. it in no way covered emails I received from you via Gmail and whether or not you can demand Google delete emails you sent to me from my Gmail account.


That's the opposite of totalitarian, btw, if we're interested in words.


In what way is government-mandated censorship and falsification of history "the opposite of totalitarian"?


In that the government isn’t using people as tools. People are using the government as a tool.

(Edit: without addressing your questionable definition of what it means to control one’s data.)


> I think part of the issue here is that a plain English reading of the GDPR implies such appalling totalitarian overreach that most people find it hard to believe that it can really be what's meant.

Do you think this level of hyperbole is necessary?


In what sense do you think I'm being hyperbolic? I'm pretty sure I mean every word of what I wrote literally.

(Though perhaps "authoritarian" would be a better choice of word than "totalitarian"; I mean it only in the broader sense of "infringing unjustly on individual freedom" and not in the stricter sense of "mandating total subservience to the state" that a Google 'define:' search yields as the first result. I thought it was correct to use "totalitarian" in the former sense, but don't have time to confirm; if I'm wrong, and that word choice is what you take issue with, then I'll concede that it was an erroneous word choice and I should've written "authoritarian" instead.)


> Oh, well in that case this is explicitly handled in recital 18. https://gdpr-info.eu/recitals/no-18/

I disagree. One's GMail contacts is a clear (ha) example of a fuzzy scenario that I think is ... questionably handled by the language at the link you reference. It's difficult especially because it's a weird hybrid of a very personal or household activity that runs inside a commercial activity.

From the text:

> 1 This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity

Ok!

> and thus with no connection to a professional or commercial activity.

...wait, GMail is clearly a professional or commercial product. An online addressbook in GMail... does that count as having a "connection" or not? My purpose of the addresses is personal. But it's clearly connected (at least by tcp, haha) to a commercial activity.

> 2 Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities.

Ok ... wait, social networking clearly involves commercial entities (e.g. twitter). So my personal actions for personal non-business uses of twitter are not regulated. Fine. But twitter itself is?

> 3 However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.

Ok so the regulation applies to the controllers/processors (e.g. GMail, twitter).

So: the regulation does not "apply" to me for my personal use, but my (personally defined for personal use) GMail contacts could get deleted by the other person?

I am definitely not a lawyer, but this does seem at least somewhat contradictory, or at least would benefit greatly from a few more clarifying sentences.

Comparison to complex documentation is not apt to your pro-condescension argument. Complex and vague can be very different.

Documentation can be complex, but if it's rigorous and not vague, I am totally fine with that. Software can be very complex. When it is complex, I would hope the documentation has sufficient detail to cover their intricacies. I'm glad that the postgres documentation is huge and complex -- it has to be.

I do however complain pretty often about vague documentation haha. I feel like it's pretty common for people to complain about an under-documented quirk shooting them in the foot (e.g. mongodb and durability back in the day).

One last thing: If your interpretation is right (and it seems plausible, maybe even likely), then I really need to locally archive my emails and contacts more often haha.


I think your interpretation is correct. In particular, I think that your first two quotes from the text are saying that the "personal or household" user themselves has no obligations under the GDPR. It's coherent to include social networking in here; without that clause, a child writing on Facebook about how another child smells bad would presumably themselves be a data controller and subject to an erasure request, whereas with the clause, Facebook can be compelled by a regulator to remove the post but the child who posted it cannot.

Or at least that's my interpretation. Like you, I remain uncertain and troubled.


>One last thing: If your interpretation is right (and it seems plausible, maybe even likely), then I really need to locally archive my emails and contacts more often haha.

I mean, yeah, you probably should if you care about it. Most office exchange servers are configured to allow some users to "unsend" emails. Outlook dutifully deletes the email from my co-workers inboxes, but my thunderbird client simply tells me that someone sent a recall request and lets me choose what to do with it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: