this post was submitted on 18 Sep 2023
52 points (98.1% liked)
Explain Like I'm Five
14230 readers
84 users here now
Simplifying Complexity, One Answer at a Time!
Rules
- Be respectful and inclusive.
- No harassment, hate speech, or trolling.
- Engage in constructive discussions.
- Share relevant content.
- Follow guidelines and moderators' instructions.
- Use appropriate language and tone.
- Report violations.
- Foster a continuous learning environment.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yeah, it absolutely is vague. I had reason to read some GDPR stuff a while back - that phrasing is just lifted from there. Article 6 is about what reasons you could have to store private info. 1f is, apparently... yeah, you're just "legitimately" interested. Wonder what that means? So do I.
OK, so all the explanations I saw were vague because the law itself was vague. That looks quite like a loophole to have passed!
The rule itself is not a loophole.
To use legitimate interest as a reason to process data you need you be able to argue that you do actually have a good reason to do so and that the user would expect you to process it.
For example, I think that websites have a legitimate interest in anonymously tracking your browser behaviour to analyse performance data and errors so that they can improve their app.
The loophole is that advertisers use it to process way too much data (when they are pretty much the reason for the bloody law in the first place) and that nothing is done about it.
I know right? Now, I'm not a lawyer, but it seems interesting because of what it isn't. 1a through e are consent, needed for business, legal obligation, (your) vital interests or another being, or public interest/authority.
So after all that, you have to figure... what legitimacy's left?
GDPR is pretty airtight in general, so I'm guessing we're missing something.
Edit: Hmm, it looks like the definition is left up to the courts of individual countries. That's not great.
Just a reminder that there's never such a thing as "a loophole". What there is is a carefully-worded, innocuous-sounding phrase that some corporation "helpfully" got added to a law or regulation (usually "for clarity"), and which the corporation already plans to mis-use in a given way should the appropriate circumstances arise (and in contradiction of all "we should never do that!" protestations they might make prior to the law or regulation taking effect).
Again, there is no such thing as "a loophole".