7 ms·
On the other side of this, depending on the breadth of your data, it can be non trivial to run pipelines to redact someones information. It takes man hours to v
by mosseater 5y ago
On the other side of this, depending on the breadth of your data, it can be non trivial to run pipelines to redact someones information. It takes man hours to verify, and processing time ($$). Plus, what if they don't have that process in place? They will need to do it manually, and take up more time from someone. Plus you need to communicate with the requestee and verify their identity as well as give them updates when they ask.
This is fine if not abused. But if a mountain of redactions came in, I could see a company just deciding it wasn't worth it to serve the EU. Not to mention the fact that there are a non-zero amount of people that will make GDPR redaction requests and hound the company down in hopes of suing them if they don't follow the law to the letter and/or can't process the redaction in time. If a company doesn't already have that process in place, it could be a momentous task to initially process.
I'm 100% for user privacy. But it can be tricky with the way the GDPR law works, so I understand why companies outside of the EU don't bother with it.
- mindslight 5y agoThere are two easy answers for this: 1. Don't create surveillance files on people in the first place. It's not like the lack of privacy legislation means there are legitimate reasons to be performing surveillance. It's just that the illegitimate ones have not yet been made illegal. 2. US states should start adopting the GDPR verbatim (with no corpocratic handouts), so there is only one law to follow.
- dinvlad 5y agoI think in CVS's case likely yes, they probably hired underpaid folks to implement their site, and now those folks are probably long gone so no one would even know how to remove all those advertising domains without which the site doesn't work.