Resend my activation email : Register : Log in 
BCF: Bike Chat Forums


GDPR Compliance

Reply to topic
Bike Chat Forums Index -> The Geek Zone
View previous topic : View next topic  
Author Message

Easy-X
Super Spammer



Joined: 08 Mar 2019
Karma :

PostPosted: 12:33 - 27 Jul 2021    Post subject: GDPR Compliance Reply with quote

I'm sure we have some clever computer bods on here and I'm wondering if you could help me wrap my head around GDPR Praying

I'm writing a POS integration for [unnamed slave drivers] and (as is usual) a long API contract awaits. Embedded in there is a "...we send you PII..." hence the mention of GDPR. Thing is we don't even need any of this personal information, we just want the sale items and the special code for the slave delivery rider.

I could quite easily ignore this personal information at the Cloud side but technically we're still being sent it. Is this enough to not worry about GDPR or am I going to need to write up some compliance spec on how we don't actually process anything?

There's no need for [unnamed slave drivers] to send us this info but technically the target site could do their own fulfilment, not that anyone does. If they did they'd probably have their own website or use Just Eat. Anyhoo, seems like the data centre hobgoblins are all "send them it anyway whether they need it or not!" which I thought GDPR was meant to put a stop to Sad
____________________
Husqvarna Vitpilen 401, Yamaha XSR700, Honda Rebel, Yamaha DT175, Suzuki SV650 (loan) Fazer 600, Keeway Superlight 125, 50cc turd scooter
 Back to top
View user's profile Send private message You must be logged in to rate posts

Zen Dog
World Chat Champion



Joined: 11 Aug 2004
Karma :

PostPosted: 15:42 - 27 Jul 2021    Post subject: Reply with quote

It seems like you need the advice of a compliance specialist more than a computer one. I've got some GDPR experience but I'm not an expert (in this...or anything else to be honest).

But it seems to me that your issue comes down to - If you are being sent personal data, but you don't access it or store it, are you still a data processor in the GDPR sense?

If you're not, yay. If you are, well it's time to open the GDPR can of worms. I suspect the answer will be that you are a data processor, but it's definitely worth finding out for sure, because if you're not you're going to save a lot of effort.

This may or may not be helpful - https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/controllers-and-processors/how-do-you-determine-whether-you-are-a-controller-or-processor/
____________________
Current - '94 VFR750FR, '00 VFR800FI Previous - '10 Street Triple R, '92 MZ ETZ301, '05 TTR250, NSR125R, KMX125, "Honda" Win (chinese copy of an old Honda design with a C90 engine)
My bike trip around S.E. Asia 2010/2011
 Back to top
View user's profile Send private message You must be logged in to rate posts

Easy-X
Super Spammer



Joined: 08 Mar 2019
Karma :

PostPosted: 11:49 - 28 Jul 2021    Post subject: Reply with quote

Thanks, there seems to be loads of info on what to do if you are a controller or processor to the point where it drowns out any meaningful discussion on edge-cases. Maybe this is the intent to keep compliance officers in a job Laughing
____________________
Husqvarna Vitpilen 401, Yamaha XSR700, Honda Rebel, Yamaha DT175, Suzuki SV650 (loan) Fazer 600, Keeway Superlight 125, 50cc turd scooter
 Back to top
View user's profile Send private message You must be logged in to rate posts

Islander
World Chat Champion



Joined: 05 Aug 2012
Karma :

PostPosted: 12:02 - 28 Jul 2021    Post subject: Reply with quote

That's an interesting one.

If they're sending you personal or special category information as a part of a system development (presumable for testing purposes?) when they don't need to then they're in breach. If it IS for testing purposes then they're really in breach as all development/testing data should either be dummy data or anonymised to the extent that it's impossible to identify an individual from that data. If you accept that data then your head is on the block too.

If it's all legit then you have Data Protection (not just GDPR) responsibilities.

Speak to a Data Protection specialist.
 Back to top
View user's profile Send private message You must be logged in to rate posts

Easy-X
Super Spammer



Joined: 08 Mar 2019
Karma :

PostPosted: 13:56 - 28 Jul 2021    Post subject: Reply with quote

Just had a deep dive into the API specs and regardless of fulfilment type we will apparently be getting First Name , Last Name and an "anonymised" phone number. (I assume this number runs through some sort of proxy dialler that forwards the call on.) Only restaurant fulfilment hands out the punter's address, phew!

Is First Name , Last Name enough to trigger the need for all this GDPR & Data Protection stuff?

<edit> just been informed we don't get the last name, even better! I think I panicked a bit too much, sorry guys Doh!
____________________
Husqvarna Vitpilen 401, Yamaha XSR700, Honda Rebel, Yamaha DT175, Suzuki SV650 (loan) Fazer 600, Keeway Superlight 125, 50cc turd scooter
 Back to top
View user's profile Send private message You must be logged in to rate posts

Islander
World Chat Champion



Joined: 05 Aug 2012
Karma :

PostPosted: 21:21 - 29 Jul 2021    Post subject: Reply with quote

Easy-X wrote:
Just had a deep dive into the API specs and regardless of fulfilment type we will apparently be getting First Name , Last Name and an "anonymised" phone number. (I assume this number runs through some sort of proxy dialler that forwards the call on.) Only restaurant fulfilment hands out the punter's address, phew!

Is First Name , Last Name enough to trigger the need for all this GDPR & Data Protection stuff?

<edit> just been informed we don't get the last name, even better! I think I panicked a bit too much, sorry guys Doh!


The definition is any piece of information that on its own or with one or more additional pieces of information can be used to identify a living individual.

If it were first name + last name then you've got a living individual right there. If it's a first name and the rest anonymised (properly anonymised!) then you're probably alright. Thumbs Up

Development really should use entirely dummy data though.
 Back to top
View user's profile Send private message You must be logged in to rate posts
Old Thread Alert!

The last post was made 2 years, 261 days ago. Instead of replying here, would creating a new thread be more useful?
  Display posts from previous:   
This page may contain affiliate links, which means we may earn a small commission if a visitor clicks through and makes a purchase. By clicking on an affiliate link, you accept that third-party cookies will be set.

Post new topic   Reply to topic    Bike Chat Forums Index -> The Geek Zone All times are GMT + 1 Hour
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Read the Terms of Use! - Powered by phpBB © phpBB Group
 

Debug Mode: ON - Server: birks (www) - Page Generation Time: 0.08 Sec - Server Load: 0.3 - MySQL Queries: 17 - Page Size: 53.02 Kb