• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

GDPR - is it good or bad?

Status
Not open for further replies.

AM9

Veteran Member
Joined
13 May 2014
Messages
16,026
Location
St Albans
OK, so GDPR (General Data Protection Regulation) is now implemented. It was passed over 2 years ago and here in the UK, everbody has been increasingly made aware of it for about a year.
Out of all the people that I personally know, I've not heard any of them criticise either its intentions nor the way that the law is likely to impact on them as members of the general public. Yet every day for about a month the media has managed to find commentators that say that it will be bad for business/social media/public services/etc., and shouldn't have been made law.
We here as subscribers to RUK must have received many seemingly desperate e-mails from suppliers begging us to stay in touch.
How do other members of the forum view GDPR.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

nlogax

Established Member
Joined
29 May 2011
Messages
6,012
Location
Mostly Glasgow-ish. Mostly.
Implementation and communication is a bit of a patchwork mess tbh. Some companies get it, others don't, others haven't even bothered to look at it. The email deluge was to be expected but the bonus is being unsubscribed from a ton of stuff I don't want or need without me having to do anything proactive. Can't complain about that.
 

AM9

Veteran Member
Joined
13 May 2014
Messages
16,026
Location
St Albans
Implementation and communication is a bit of a patchwork mess tbh. Some companies get it, others don't, others haven't even bothered to look at it. The email deluge was to be expected but the bonus is being unsubscribed from a ton of stuff I don't want or need without me having to do anything proactive. Can't complain about that.
I note in today's press that some of the major US tech. companies are threatening to remove access to products/deactivating accounts etc. if the users don't accept new (non GDPR-compliant) privacy policies. In the case of Google's own Nest home energy and security product, unless European customers agree to an updated privacy policy, the user will be unable to adjust the thermostats in their homes.
A group of digital privacy campaigners have filed law suits claiming that they are being forced to accept new policies for fear of losing access/use of services. It looks like the GDPR will bring the misuse of private data to the courts' attention.
Could get very interesting.
 

Lucan

Established Member
Joined
21 Feb 2018
Messages
1,251
Location
Wales
What will happen is the same as has happened in similar circumstances before (eg when use of cookies became notifiable). Some website will continue with what they are doing already but will ask you to agree to it - if you don't you just won't be able to log in anymore.
In fact another forum I use presented me earlier today with a tick-box questionaire (super-imposed over their home page) about sharing my data etc, in which I was invited to "review my preferences". But after trying several combinations of ticks I cam to the conclusion that if I did not tick every permission the questionaire was not going to go away - it just kept bouncing back. Now this is the point - I had already completed a similar questionaire when I first registered with that site some years ago in which I had successfully chosen the minimal data sharing; in other words the site was using this GDPR occasion to force an increased amout of data sharing on me. Too bad, I won't go there again. The info I had given about myself before was all false anyway :lol:
 

AM9

Veteran Member
Joined
13 May 2014
Messages
16,026
Location
St Albans
What will happen is the same as has happened in similar circumstances before (eg when use of cookies became notifiable). Some website will continue with what they are doing already but will ask you to agree to it - if you don't you just won't be able to log in anymore.
In fact another forum I use presented me earlier today with a tick-box questionaire (super-imposed over their home page) about sharing my data etc, in which I was invited to "review my preferences". But after trying several combinations of ticks I cam to the conclusion that if I did not tick every permission the questionaire was not going to go away - it just kept bouncing back. Now this is the point - I had already completed a similar questionaire when I first registered with that site some years ago in which I had successfully chosen the minimal data sharing; in other words the site was using this GDPR occasion to force an increased amout of data sharing on me. Too bad, I won't go there again. The info I had given about myself before was all false anyway :lol:
There a slight difference when you have purchased a product (I gave the example of Nest) where the manufacturer's refusal to offer GDPR compliant privacy will render the product not fit for purpose. That would be the same across all EU countries, so they would be:
a) open to legal action from the EU
b) be cutting themselves off from the largest trading block in the world (the EU)*​
* in the case of large data-trading operations like Google or Facebook, unless they were prepared for considerable (and continuous) fines, they would see the whole of their operations prohibited in the EU and probably the EEA.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,604
Location
Scotland
How do other members of the forum view GDPR.
Professionally, it's a nightmare: my employer is a supplier to service providers, so we have a LOT of data covered by GDPR and a large percentage of our customers only seem to have heard about GDPR last week based on the number of panicked questions we got.

Personally: I welcome the increased fines for getting things wrong. The levels under the previous legislation weren't a real deterrent.
 

AM9

Veteran Member
Joined
13 May 2014
Messages
16,026
Location
St Albans
Professionally, it's a nightmare: my employer is a supplier to service providers, so we have a LOT of data covered by GDPR and a large percentage of our customers only seem to have heard about GDPR last week based on the number of panicked questions we got.

Personally: I welcome the increased fines for getting things wrong. The levels under the previous legislation weren't a real deterrent.
I'm amused by a couple of small trader interviews recently where the attitude was that because of the need to verify an interest in receiving continued marketing informatio, they would lose a lot of their client database. My view was that if those potential/ex customers were interested enough to accept marketing mail in the future, they would say so. If they weren't, then the supplier had no reson to keep them on that database, (unless they were 'trading' in their personal data which fortunately is now illegal without express permission).
 

PeterC

Established Member
Joined
29 Sep 2014
Messages
4,769
It is a pain for the voluntary sector as this is an overhead both in volunteer time and in the additional audit information that is, at least in theory, needed.

A lot of people have over reacted as well. For example you don't need a new permission to hold the delivery address for a magazine subscription (I really did get that request) as that is covered by contract.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,604
Location
Scotland
A lot of people have over reacted as well.
For some it was overreaction, for many it was an opportunity to hoodwink senior management into *finally* allowing that data cleanup that they've been putting off for ages as 'unnecesary' or 'too time-consuming'.
 

northwichcat

Veteran Member
Joined
23 Jan 2009
Messages
32,692
Location
Northwich
Implementation and communication is a bit of a patchwork mess tbh. Some companies get it, others don't, others haven't even bothered to look at it. The email deluge was to be expected but the bonus is being unsubscribed from a ton of stuff I don't want or need without me having to do anything proactive. Can't complain about that.

I found the opposite in one case (Barratts shoes.) I've not ordered from them for a long time and unsubscribed from their marketing emails. However, I noticed an email from them with GDPR in the subject line. I ignored it and a couple of days later I found they'd opted me back in to their mailing list - I clicked the spam button in my browser, hopefully others do the same and they find they can't send to certain domains because of too many CFLs.
 

radamfi

Established Member
Joined
29 Oct 2009
Messages
9,267
Given that it comes from the EU, it must automatically be bad.
 

Hornet

Member
Joined
16 Jul 2013
Messages
748
Don't really need GDPR if you use your common sense with regard to your info. If people want to plaster their all and sundry about their lives over social media, then they should not be surprised that others might use their details. Don't reply to unsolicited e-mails, tell phone cold callers to f*** off and be wary what you post on social media. Simple really.
 

Geezertronic

Established Member
Joined
14 Apr 2009
Messages
4,124
Location
Birmingham
For IT Consultants like me that have to check, implement, and mitigate to become and stay GDPR compliant, it is just another set of compliance rules to adhere to.
 

krus_aragon

Established Member
Joined
10 Jun 2009
Messages
6,105
Location
North Wales
For IT Consultants like me that have to check, implement, and mitigate to become and stay GDPR compliant, it is just another set of compliance rules to adhere to.

Is it a significantly greater workload in your eyes? As a (slightly interested) bystander, much of what the GDPR covers seems to have been already covered by the Data Protection Act, with new bits 'bolted' on.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,604
Location
Scotland
Is it a significantly greater workload in your eyes? As a (slightly interested) bystander, much of what the GDPR covers seems to have been already covered by the Data Protection Act, with new bits 'bolted' on.
For most businesses there won't be a day-to-day operational impact, however many smaller businesses aren't in the habit of having to demonstrate compliance. So there's been a lot of work involved getting themselves to the point where they can prove that they are compliant.
 

NSEFAN

Established Member
Joined
17 Jun 2007
Messages
3,518
Location
Southampton
For most businesses there won't be a day-to-day operational impact, however many smaller businesses aren't in the habit of having to demonstrate compliance. So there's been a lot of work involved getting themselves to the point where they can prove that they are compliant.
I think it's for the best to get smaller firms to take security of customer data more seriously, as if anything a historic lack of compliance can create complacency. I recall the story of an observant returning customer for a small firm ordering something over the phone, and was not asked for any card or payment details. Upon further investigation, the firm was keeping paper copies of all transactions, including full card details, in boxes on the shelf that anyone could access.
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,810
Location
Epsom
It will be especially hairy for businesses which sub-contract processes to third party companies. Legally, a business is liable for the conduct of anyone they contract work out to. Which would be frightening in a case like this one from last year:

https://www.csoonline.com/article/3...ta-breach-exposes-20000-customer-records.html

"On April 2, Genpact, a third-party vendor, confirmed that it had uploaded a data set to one of its cloud servers that did not have all security protocols in place. As a result, the data was not fully secured for a period of time. The file contained commercial loan application information of a small B2B unit within Scottrade Bank, including non-public information of as many as 20,000 individuals and businesses. Upon being alerted to the issue, Genpact immediately secured that information, and traced the issue to a configuration error on their part while uploading the file," the Scottrade statement explained.

Scottrade added that Genpact, a professional services firm headquartered in New York, works exclusively with the B2B banking unit and had no access to any other information.

"This appears to be a case of isolated human error by the vendor in handling the data set. It is important to note that we hold all of our third-party vendors to rigorous information security standards. The vendor has acknowledged responsibility for this incident," Scottrade said.
 

whhistle

Established Member
Joined
30 Dec 2010
Messages
2,636
I started receiving emails asking me to confirm I was happy for the company to keep my details.
However, these switftly turned into "we've upgraded our privacy policy... view it here".

It was a missed opportunity to force companies to email and ask if people still want to be contacted. I don't want to be contacted by many companies that emailled me, but had no opportunity to "unscubscribe" without a fair amount of effort from me. Yet others had a simple button.

Shame they don't require this confirmation every 5 years or whatever.
 

AM9

Veteran Member
Joined
13 May 2014
Messages
16,026
Location
St Albans
I started receiving emails asking me to confirm I was happy for the company to keep my details.
However, these switftly turned into "we've upgraded our privacy policy... view it here".

It was a missed opportunity to force companies to email and ask if people still want to be contacted. I don't want to be contacted by many companies that emailled me, but had no opportunity to "unscubscribe" without a fair amount of effort from me. Yet others had a simple button. ...
Behaviour like that is expressly outlawed in the regulations and the view is that it will be called out and appropriate action against offenders taken. Requests for consent must be given in an intelligible and easily accessible form, with the purpose for data processing attached to that consent - meaning it must be unambiguous.
Consent must be clear and distinguishable from other matters and provided in an intelligible and easily accessible form, using clear and plain language. Notification of consent will have to be explicit in the case of sensitive data and unambiguous consent for non-sensitive data.
Apart from some of the less scrupulous 'datamongers' (mainly US based) who will pretend that the law doesn't apply to them until they have been threatened with penalties by EU ICOs, most global companies will adjust their business practices to achieve full compliance. Indeed, in some cases follow the lead of Microsoft which has decided to adopt the rules globally and not just where the EU can enforce it. This follows the line taken by other responsible global corporations with other major EU regulations such as EMC, electrical safety etc.. So when Trump decides to put America first by snubbing non-US initiatives with his 'not invented here' attitude, he may find that any worthwhile US corporation has just ignored him and left all that gameplay behind.
 

northwichcat

Veteran Member
Joined
23 Jan 2009
Messages
32,692
Location
Northwich
I started receiving emails asking me to confirm I was happy for the company to keep my details.
However, these switftly turned into "we've upgraded our privacy policy... view it here".

It was a missed opportunity to force companies to email and ask if people still want to be contacted. I don't want to be contacted by many companies that emailled me, but had no opportunity to "unscubscribe" without a fair amount of effort from me. Yet others had a simple button.

Shame they don't require this confirmation every 5 years or whatever.

A marketing email must by law contain an unsubscribe link or unsubscribe instructions e.g. email an address with unsubscribe in the subject line or unsubscribe in your account section on our site. However, informing you of updated terms and conditions is an information email (like those confirming your order from a site) and don't need an unsubscribe link.

I'm not 100% sure on the new terms but under the old ones they were allowed to try and persuade you to change your mind about opting out before confirming you've opted out e.g. by saying you'll miss out on x, y or z if you unsubscribe. I worked on campaigns for a Canadian company and under their previous law change they didn't allow that and had very politely opt-out wording in comparison to what British companies send out.
 

underbank

Established Member
Joined
26 Jan 2013
Messages
1,486
Location
North West England
I recall the story of an observant returning customer for a small firm ordering something over the phone, and was not asked for any card or payment details. Upon further investigation, the firm was keeping paper copies of all transactions, including full card details, in boxes on the shelf that anyone could access.

Pretty sure that kind of sloppiness was already outlawed by a previous credit card processing law, and would certainly have been outlawed by the credit card company's merchant contract terms. If a company isn't complying with existing laws/rules, I'm not sure a new law will make much difference. Especially since most recent laws seem to be policed on a voluntary basis anyway, i.e. no actual checking/policing until complaints are made, i.e. shutting the stable door after the horse has bolted.
 

Geezertronic

Established Member
Joined
14 Apr 2009
Messages
4,124
Location
Birmingham
Is it a significantly greater workload in your eyes? As a (slightly interested) bystander, much of what the GDPR covers seems to have been already covered by the Data Protection Act, with new bits 'bolted' on.

From a technical point of view, if you are a big business and PCI compliant then there is just another set of "rules" to be interpreted.

I believe that small businesses will be hit the hardest as they won't have the time or finances to worry about compliance to the extent of GDPR
 

NSEFAN

Established Member
Joined
17 Jun 2007
Messages
3,518
Location
Southampton
Pretty sure that kind of sloppiness was already outlawed by a previous credit card processing law, and would certainly have been outlawed by the credit card company's merchant contract terms. If a company isn't complying with existing laws/rules, I'm not sure a new law will make much difference. Especially since most recent laws seem to be policed on a voluntary basis anyway, i.e. no actual checking/policing until complaints are made, i.e. shutting the stable door after the horse has bolted.
Oh it was definitely not allowed even at the time. I'm just hoping that the sheer amount of publicity about the GDPR will rattle some of these kind of businesses into taking data security more seriously, even if little to no action is actually taken against them.
 

ASharpe

Member
Joined
4 Feb 2013
Messages
1,021
Location
West Yorkshire
For me it's been a bit of a pain at work. I work with lots of data (AKA big data if looking for a new job) and I've had to review what data is kept for me to see if we can keep less of it.

The answers aren't obvious because I need more historic data for smaller stores than bigger stores to be able to accurately forecast the future but we can't easily define and implement different cut offs

And What might be a cutoff for me might be a different cutoff for someone else whose data I try to join and then get strange results.

It's not straightforward at all even for a large company as every individual in the company has different needs.
 

Crossover

Established Member
Joined
4 Jun 2009
Messages
9,493
Location
Yorkshire
I think the underlying idea isn't necessarily a bad one, but there has been a lot of scaremongers (Y2K Take 2) and it has been an opportunity for a number of companies to sell unnecessary solutions to "be GDPR compliant"

I too have been hit with the "updated privacy policy" emails - they may actually be above the law as there is something called a "soft opt-in"

I have been to various talks over the last 12 months where GDPR has been a hot topic - one of the most recent was one of the most interesting. The Regulation is said to be over 90,000 words (the first Harry Potter novel was under 80,000 words, for comparison) and has been written in various languages, all of which are "live" (I forget the word used at the moment, but basically all of them are binding in any country)
The ICO also employs less than 500 people (hence some shockingly long waiting times to get questions answered by them in the past few weeks) and this is only due to increase to 600, and with a limited budget, so they have to pick their fights. It has also been alluded that they may shy away from the bigger companies, as they have the resources to fight it and the ICO have been burnt by it before. I did see some figures of reported breaches under DPA and expected reports under GDPR and they were pretty large!
 

GusB

Established Member
Joined
9 Jul 2016
Messages
8,122
Location
Elginshire
Most of the emails I've received regarding GDPR have been along the lines of "we've changed our privacy policies, visit [xxx].com to view". A few companies have provided me with the relevant links that allow me to view the data I've provided. Some told me that unless I do log in and review my data, it will be deleted within a given period of time. In all honesty, the organisations which have asked me to review and re-consent are the ones which I'm most likely to remain with. What was quite disturbing was receiving an email from ticketmaster.ie - I've never dealt with Ticketmaster, ever.
 

The Ham

Veteran Member
Joined
6 Jul 2012
Messages
12,036
One of the best emails I got gave me an overview of their policy in about 200 words over about 6 sections, but with a link to the full policy if I wished to read it.
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,317
Location
LBK
The best one I got was from Avis:

A farewell from Avis

We’ve noticed that you haven’t opened any of our emails for a while and, as such, we think you would probably rather not hear from us anymore. So we’re going to stop sending you marketing emails. If we’ve got it wrong and you want to continue to hear about sales, offers and new services, simply click here and we will continue to stay in touch.

You can change your mind at any point in the future.
 

WelshBluebird

Established Member
Joined
14 Jan 2010
Messages
5,580
If a company isn't complying with existing laws/rules, I'm not sure a new law will make much difference.

I think the additional fines that GDPR brings in may well have an impact. Because really, a lot of the behaviours GDPR is aimed at are already either illegal or operate in a legal grey area anyway, its just the punishments have never been enough of a deterrent.
 
Status
Not open for further replies.

Top