Gdpr

AmericanThunder

Super Moderator
I have been aware for some time that the old Data Protection Act is being replaced by the General Data Protection Regulation, (GDPR).
The GDPR is an EU directive to better protect individuals data.
I have been involved in a project at work since I started back in November. The implications are huge, but I will try and summarise:

1. GDPR means that companies are responsible for the data they process on individuals.
2. You have to opt-in to marketing (of all types). The old opt-out will be a thing of the past.
3. It applies to any company that processes data relating to EU individuals
4. Brexit will have no impact on it.
5. Individuals have the right to be forgotten
6. Individuals have the right to view data held on them.
7. Individuals have the right to transport data held on them.
8. Individuals have the right to rectify data held on them.
9. It comes into force on May 23 2018

I'm happy to clarify any points to the best of my knowledge for anyone interested, but remember that this directive is as yet untested so there is no case law to test any of this out.

So why have I started this thread?

Well, US based companies that only supply goods and services to the US are exempt from GDPR. They will have to comply with a variation of it but its less stringent. My concern is that when we try and buy goods from our favourite suppliers after May next year we may find it more difficult. Why?
Well:
1. If a US based company supplies you your spare parts they are processing data on an EU resident. This means GDPR applies and they will have to be setup to deal with it which includes the company having to employ the services of a data protection officer.
2. Many of the processes required to achieve GDPR compliance are similar to existing standards such as ISO27001 and indeed many companies will adopt ISO27001 as a huge stepping stone in achieving GDPR compliance.
3. Adopting either ISO27001 or GDPR will cost money.
4. Data protection officers are in very short supply and as a consequence will command big money regardless of whether they are employed directly by a company or contracted to them and others.

My fear is that many of our usual suppliers will simply either not bother which means they will not be able to supply us our goods and parts or the additional cost incurred will be passed on to their customers and those outside the US in particular.

Its also possible that we will see the emergence of more dedicated shippers based in the US that are GDPR compliant. You will place your order with them and they will deal with compliance issues and ship your goods to you. Of course, this will also incur the costs that ultimately we will end paying for.

Even current suppliers like RockAuto, Ultimate Spares of America and US Automotive are also likely to pass these costs on.

I suspect our hobby will become even more expensive from next year. Hopefully I'm wrong!
 
Raised some good points there

Watch this space as they say,

word of advice for them KIS KEEP IT SIMPLE SO MUCH EASIER
 
Yeah could make it more difficuly/costly to get stuff from the States, but on the other hand should reduce the Chinese crap that comes to our shores only to be in landfill in a few months.

I would hope that the USA don't need to adjust much to deal with UK customers as USA a country that tends to sue anyone, so they must have soo much protection in-place for that.
 
Raised some good points there

Watch this space as they say,



word of advice for them KIS KEEP IT SIMPLE SO MUCH EASIER

This is far from simple. But then i suppose maintaining better control of your data and preventing repeats of the breaches we have seen in the past is not going to be easy. They are serious though with fines for the worst offenders set at either £20million or 4% of turn-over, which ever is higher!
 
And as predicted US companies are now not shipping to the U.K./EU anymore as then GDPR doesn’t affect them.
A friend has tried 3 companies to purchase an SLP fan switch and none will ship, including Dans favorite, WS6Store!
 
Oh no. :( I guess my next batch of parts I'll tie it in with a business trip again and collect them. :)
 
Oh no. :( I guess my next batch of parts I'll tie it in with a business trip again and collect them. :)

Won’t help if you are paying with funds transferred from a U.K./eu bank or using a card from a U.K./eu bank.
You are the resident of a country where GDPR is/will be in effect. You will need a bank account in the US to pay then you can ship it anywhere.
 
As predicted....

B4A1814F-62B6-45CA-A1F7-EF7F34AC6362.jpg
 
I have seen a couple of websites now which have closed when accessed from this country. Going in via a proxy works but slow. Whole world gone loopy, surly the internet is for everyone to be able to access. What caused it all? was it places farming email addresses to sell on to used as spam?
 
Using a proxy doesn’t help if you actually want t make a purchase. You need a bank account and shipping address outside the EU.
The legislation was needed to prevent companies maintaining information that they did not securely manage. Inappropriate security controls has led to breaches that result in identity theft or huge amounts of unwanted and sometimes inappropriate marketing.
The irony is that everyone still uses Facebook and searches with Google, and both those companies are making far more revenue marketing you than the fines cost so why would they change?
 
Back
Top