• Please take a moment to look over the Suggestions & Feedback rules before making a post: READ RULES HERE

BlackHatWorld and UK Data Protection Act 2018

Status
Not open for further replies.

NX_NULL

Banned - Multiple Rules Violations
Joined
Dec 31, 2008
Messages
717
Reaction score
931
Since BHW is doing business in UK, Shouldnt it follow Data Protection Act ?
There is something called "The right to be forgotten"

I have seen several times that mods refuse to delete threads and posts when we self report it. Isnt it against law?
 
There should be an option to at least delete threads without any replies. They live in database like ghosts.
 
Yes but it appears bhw takes a different interpretation...

Have you got the time or money to take bhw to court? The ICO are pretty useless.

Considering BHW suffered a total data breach in June 2014. Any post made before 2014 could be argued to be identifiable personal information.
 
We only legally need to delete posts with personal information and this is done as and when requested. If you have a specific situation, you can contact us via support and we'll look into it. Usually, if you request your own posts, we'll delete them but if not, we'd explain why.

If you'd like your actual account deleted, contact us https://support.blackhatworld.com/support/home or via [email protected] - we'll delete all held informaiton on you and is irreversable. This will be/is in accordance with https://iapp.org/media/pdf/resource_center/CCPA_GDPR_Chart_PracticalLaw_2019.pdf.

We don't do a mass delete of all your posts when this happens, but you won't be able to be linked/identified with the content posted.
 
As the bhw data breach in June 2014 consisted of DoB, email address, IP addresses, passwords, usernames and website activity (including the content of private messages)

It could be argued that in order to comply all posts before June 2014 would need to be deleted aswell.
 
https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/what-is-personal-data/
This is useful for anyone wanting to look into it.

I'd argue that A forum post from an individual is always identifiable.

Personal data is information that relates to an identified or identifiable individual.

But also the way that BHW handles deleted accounts goes against UK GDPR.

Information which has had identifiers removed or replaced in order to pseudonymise the data is still personal data for the purposes of UK GDPR.

But in any case posts prior to June 2014 would still be covered as personal information as the database dump is widely available and thus.

If you cannot directly identify an individual from that information, then you need to consider whether the individual is still identifiable. You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual.
 
As the bhw data breach in June 2014 consisted of DoB, email address, IP addresses, passwords, usernames and website activity (including the content of private messages)

It could be argued that in order to comply all posts before June 2014 would need to be deleted aswell.
How come you know so much about bhw in just over a month. I didn't even know about the data breach of 2014. (Just thinking aloud ).
 
If the owner is in theory British he seems to be then someone could argue you are right OP but if the business founded or say operate in America for office or business location I don't think the UK government could do much over it .
 
We are a UK business and remain confident that we comply with all current laws relating to GDPR. We remain ICO compliant after a long external review at the time this law was implemented and a number of follow-ups since then.

Under the GDPR laws you indeed have the right to be forgotten and the actions mentioned above in the thread from @BHWMPS will result in us actioning your request within the allocated timescale. we action this by systematically removing all personal data, including your account, from our system which is what GDPR was designed for and we're fully supportive of. GDPR was not designed for rep management.

If you'd like to action your right to be forgotten then please follow the directions as outlined in the previous post.

Asked - Answered - Closed.
 
Status
Not open for further replies.
Back
Top