• Please take a moment to look over the Suggestions & Feedback rules before making a post: READ RULES HERE

GDPR Changes to BHW

  • Thread starter Thread starter Deleted member 969102
  • Start date Start date
D

Deleted member 969102

Guest
Quick question: Does the new GDPR law mean that members can now request that their account (& content) is deleted?

I've received a lot of emails over the last few days and weeks from other services with changes to their terms making it easier to delete my account and content on their platform - just wondering if this will be the case with BHW and, if not, what changes are being made in regards to the data that is stored about us.
 
GDPR applies to consumers in the EU only, not to anyone using the site as a business.

Consumers don't have the automatic right to have data deleted - the forum must have no good reason to keep it.

I forget, but I think we all agreed to the T&C on the BHW site when we became members (I'd be surprised if we didn't), so the basis for processing personal data is probably contractual. We have a contract through the T&C for BHW to publish what we write, therefore, wih a few exceptions, it is under no obligation to delete anything.

My work covers GDPR at the moment, so if you want to PM me, I can answer in more detail if you want specific advice on any particular site or business.
 
GDPR applies to consumers in the EU only, not to anyone using the site as a business.

Consumers don't have the automatic right to have data deleted - the forum must have no good reason to keep it.

I forget, but I think we all agreed to the T&C on the BHW site when we became members (I'd be surprised if we didn't), so the basis for processing personal data is probably contractual. We have a contract through the T&C for BHW to publish what we write, therefore, wih a few exceptions, it is under no obligation to delete anything.

My work covers GDPR at the moment, so if you want to PM me, I can answer in more detail if you want specific advice on any particular site or business.
I know it's not an entitlement, I was just wondering if BHW was introducing anything like this voluntarily - as some other services are.

I've already had the conversation about T&Cs before.

For someone who posts so much shit, it's surprising how hard it is to get it all wiped.
 
Interesting, I organised a webinar for our staff about GDPR today, as accountants, it affects us a lot.

As far as my understanding goes (I'm no expert) - No, we wouldn't be able to request our posts/content be deleted. GDPR is a bit like a refreshed data protection act. It only effects PII (Personal identifiable information). Comments on an internet forum would not be considered PII.

You would be able to ask BHW what information they have on you.

You also have the right to be forgotten.

That applies to any information they have on file, that relates to you as an actual person, rather than your username. For example, you would be able to request that BHW forget all of your card details, paypal details, name, address - those kinds of things.

Your posts are also in the public domain, another reason they would not fall under the GDPR regulation.
 
I organised a webinar for our staff about GDPR today, as accountants, it affects us a lot.
While we're on the topic, would you mind answering a quick question?

We store all of our client's information in salesforce and mailchimp. Does the burden of GDPR fall on us, the 3rd party, or both? Same goes for FB etc.
 
Your posts are also in the public domain, another reason they would not fall under the GDPR regulation.

Is that right?

My understanding is that if an business processes any data that can be used to identify a person, they have the right to be forgotten.

The big question on here would be what information could be used to identify a person? Unless someone posts their actual name, a picture of themselves, or other information like their address, I don't believe BHW would be under any obligation to remove all their content.

If someone does ask to be forgotten, then I think BHW could just ban the account. As long as there are no posts containing personally identifiable information, then there would be no grounds for your content to be removed from here.
 
We store all of our client's information in salesforce and mailchimp. Does the burden of GDPR fall on us, the 3rd party, or both? Same goes for FB etc.

EDIT: All of this ONLY applies to PERSONAL DATA. Business data DOES NOT fall under GDPR.

EDIT #2: There is a myth going around that companies need not worry about GDPR if they have less than 250 employees or they are below a certain Turnover threshold. There is no truth to this whatsoever.

Again, I'm no expert and these regulations are incredibly complex.

Please excuse me breaking this down to basics - if I didn't, I wouldn't understand it enough to explain it to you in the first place.

Let's say you have my phone number stored on Mailchimp (CRM) AND I am an ACTIVE customer of yours.

> 07XXX XXX XXX

That's all fine and dandy I would have had to sign some sort of T&C's that allowed you to take my phone number and use it to contact me.

> Can I have your phone number? I'll use it to tell you important stuff about our product lines.
> Yes of course, here you go. 07XXX XXX XXX

You then take that phone number and put it straight on to your CRM.

Wait a second.... HUGE PROBLEM.

If you didn't stipulate in the T&C's I signed, that you would store my personal data on a server belonging to a third party - You've probably breached the regulation.

The reason I highlighted ACTIVE, is because if I was a potential client - you need a reason to keep my phone number. You couldn't keep it for ten years in the hopes that one day I might possibly become a client (even if I never requested to be forgotten).

With regard to your question on who's responsible, anyone who holds the data OR anyone who controls the data is responsible.

For example, if you took a bunch of personal data from your work computer and put it on a pen-drive. Then you got on a train and lost it - You would have to report that to the ICO, depending on the type of data, you may have to inform the individuals who's data was breached as well (unless it was encrypted).

If MailChimp suffered a massive breach, they would have to report it to the ICO.

If your MailChimp account was hacked both you and MailChimp would have to report it.

Is that right?

My understanding is that if an business processes any data that can be used to identify a person, they have the right to be forgotten.

The big question on here would be what information could be used to identify a person? Unless someone posts their actual name, a picture of themselves, or other information like their address, I don't believe BHW would be under any obligation to remove all their content.

If someone does ask to be forgotten, then I think BHW could just ban the account. As long as there are no posts containing personally identifiable information, then there would be no grounds for your content to be removed from here.

Hi @Sephrata - I think I explained myself poorly (It's getting late here).

What I'm saying is that if I decided one day to post my bank details, passport number and all the rest. Even though I was posting on a site owned by BHW, it would not be their responsibility to look after that data - as the information would then be public.

With regards to just banning the account, if BHW log IP's (which I think they do) - they would constitute information that could identify a person and would need to be deleted. Also, email addresses would need to be deleted of the system.

I forgot to mention - I know that a lot of the forum members are from countries outside of the UK, the regulations were originally set up to harmonise legislation across the EU (before Brexit was a thing).

It wouldn't matter what far off land you reside in, if you ask for your data, you have the right to it (it belongs to you) as BHW have to comply with UK law.

UK companies need to be compliant by the 25th of May. There are HUGE fines, up to the higher of £17m or 4% of global income.

I hope that answers everyone's questions, if not ask away and I'll get to them tomorrow (although, I'm close to the extent of my knowledge as it is)

I'm sure BHW are on top of it, but just in case: @Apricot @BassTrackerBoats @Diamond Damien
 
Last edited:
I forgot to mention - I know that a lot of the forum members are from countries outside of the UK, the regulations were originally set up to harmonise legislation across the EU (before Brexit was a thing).

It wouldn't matter what far off land you reside in, if you ask for your data, you have the right to it (it belongs to you) as BHW have to comply with UK law.

GDPR only applies to the personal data of UK citizens and residents. It doesn't apply to any data subject in, say India, even if the controller or processor is in the UK (or anywhere else in the EU).

Brexit will not make any difference to the GDPR. The GDPR is a directive, and therefore applies automatically in all EU countries without the parliaments of those countries ratifying it. However, the UK has decided also to introduce statutory law (called the Data Protection Bill) that goes further than the GDPR. So even when we are out of the EU, we will comply with the GDPR and to an even greater extent, "protect" the privacy of personal users.

In my opinion, the ICO is unlikely to issue any fines immediately. It is more likely to warn businesses, then expect them to comply. It doesn't have the resources to police the GDPR fully. Also, requirements of the GDPR can be subjective and hidden from public view. So unless there is a serious data breach, the ICO are unlikely to investigate.

If you have a good GDPR compliant privacy policy on your site, and your T&C are good, then you're likely to be able to show willingness to comply and therefore escape any immediate fines.

MailChimp is a US company. It may have a headquarters in the EU. The EU still expects it as a US company to comply with EU law, but there is no way of enforcing that.

The obligations of GDPR in theory fall on MailChimp and the businesses that use MailChimp. In practice, they are more likely to be enforced against the EU business that uses MailChimp as it is more likely to be easier to pursue such a case in court.

If you think about all the SAAS businesses operated out of countries other than those in the EU that we use (all those Wordpress add-ons for example), it will be very difficult for any EU business to ensure that it is fully compliant continuously unless it uses EU produced software only.

Also, the right to be forgotten doesn't apply in certain circumstances. A business can refuse, for example, if it wants to exercise the right of freedom of expression (whatever that is), or keep it to support future legal claims.
 
Last edited:
GDPR only applies to the personal data of UK citizens and residents.

GDPR applies to anyone who is a data subject within the borders of the EU, who's personal data is processed.

MailChimp is a US company. It may have a headquarters in the EU. The EU still expects it as a US company to comply with EU law, but there is no way of enforcing that.

Although they have no way of enforcing the law against overseas companies, the ability to fine their worldwide income is more than a deterrent in most cases.

It's most likely that the non-compliant businesses will be small, overseas businesses with little or no presence in the EU. In these cases, it will be very hard for anyone to enforce anything against them.

What I'm saying is that if I decided one day to post my bank details, passport number and all the rest. Even though I was posting on a site owned by BHW, it would not be their responsibility to look after that data - as the information would then be public.

But if you were to post some personal information, surely you still retain the right to ask to have it removed? I would be very surprised if you did not have this right - say for example you open a Shit List on here and accidentally post a screenshot of your bank details. BHW would be the controller of this information and wherever their hosting is based, would be the processor?

With regards to just banning the account, if BHW log IP's (which I think they do) - they would constitute information that could identify a person and would need to be deleted. Also, email addresses would need to be deleted of the system.

IPs are going to be an interesting one because an IP alone is very unlikely to amount to personal data unless it can somehow be used to identify an individual.

The other issue with IPs is how does the data controller know that it belongs to you? Say you sent a company a request for personal information based solely on IPs - how can that company possibly know the IP belongs to you?

I forgot to mention - I know that a lot of the forum members are from countries outside of the UK, the regulations were originally set up to harmonise legislation across the EU (before Brexit was a thing).

I think overall in the UK there isn't really much to get too concerned about because we have lived with the DPA for many years and it's been a good piece of legislation that has been relatively well enforced.

The issue will be countries in the EU where the has been no data protection or enforcement (despite the EU Data Protection Directive). I've had first hand experience where a company refused to comply with a subject access request and the information commissioner said there was nothing they could do.
 
GDPR applies to anyone who is a data subject within the borders of the EU, who's personal data is processed.

Although they have no way of enforcing the law against overseas companies, the ability to fine their worldwide income is more than a deterrent in most cases.

It's most likely that the non-compliant businesses will be small, overseas businesses with little or no presence in the EU. In these cases, it will be very hard for anyone to enforce anything against them.

But if you were to post some personal information, surely you still retain the right to ask to have it removed? I would be very surprised if you did not have this right - say for example you open a Shit List on here and accidentally post a screenshot of your bank details. BHW would be the controller of this information and wherever their hosting is based, would be the processor?

IPs are going to be an interesting one because an IP alone is very unlikely to amount to personal data unless it can somehow be used to identify an individual.

The other issue with IPs is how does the data controller know that it belongs to you? Say you sent a company a request for personal information based solely on IPs - how can that company possibly know the IP belongs to you?

I think overall in the UK there isn't really much to get too concerned about because we have lived with the DPA for many years and it's been a good piece of legislation that has been relatively well enforced.

The issue will be countries in the EU where the has been no data protection or enforcement (despite the EU Data Protection Directive). I've had first hand experience where a company refused to comply with a subject access request and the information commissioner said there was nothing they could do.

Sorry. I meant EU citizens and residents, not just UK.

The supervisory bodies can try to fine on worldwide income, but they will find it difficult in law to do so if the country in which the business is resident is not in the EU. The GDPR is an EU-wide law, not a worldwide law. A UK court won't be able to enforce a fine on a company based in Australia with no operations in the EU (but which sells into the EU) because EU law doesn't apply in Australia (Australian law does). It would be able to fine a US-based company (such as Alphabet) that has EU-based subsidiaries.

You could ask someone to remove data about you, but you have no right to have it removed. If there is a good reason to keep it, it can be kept.

GDPR will give UK businesses more to comply with over the DPA. For example, businesses will have to put processes in place to identify what data is held about someone, in case someone does request it. The right to portability will also require some businesses (e.g. banks) to design new systems.

There are plenty of businesses that don't comply with the law at the moment and that get away with it. I don't think a change in the rules will change whether or not the rules are enforced. The ICO and other supervisory bodies just don't have the resources to police privacy to the depth the GDPR requires.
 
Back
Top