| ▲ | scott_w 2 days ago | |||||||
As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated. | ||||||||
| ▲ | tzs 21 hours ago | parent [-] | |||||||
How about if someone asks for copies of all their data? I thought that was not complicated, but then there was that post here a while back where someone asked McDonald's for their data. It included a vast amount of things that the company had inferred from the data. I hadn't realized that would be in scope, and did some Googling on just what has to be included. According to a few sites I found, and Google's LLM concurred, it is basically everything I have about them, regardless of if I got it from them, a third party, or produced it internally. Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them? That should be in the GDPR response (I can redact the names of the rep and supervisor). I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists. That's supposed to be in the GDPR data, if the sites I found are to be believed. Heck...if some customer calls to update their credit card and calls the wrong number, and leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data. (If they call customer support and leave such a message it would go to a number handled by the expensive outsourced customer service system, which has voice transcription software that looks for things like that and deals with it, but the internal phone system used by other departments doesn't so if the wrong number went to some random person in some other department it won't have that automated handling of this). If that's right than handling a GDPR data request 100% according to the rules would require having some way to search nearly every computer we've got looking for anything concerning any particular customer. I'm hoping the sites I found and the LLM were wrong and it is not this bad. | ||||||||
| ||||||||