Jump to content

Recommended Posts

Posted
Isn't the onus on the person claiming the consent was fraudulent to prove it was fraudulent? Burden of proof and all?

In the situation we are talking about, the onus would be on the data processor to prove they have the proper consent and the right to process the data. That is rather difficult to do if the actual, real person is standing up in court and saying "No, I do not consent to you processing my data".

Posted

Whilst I can appreciate that, the argument isn't about an ongoing right to process data. The right to process the data has already been given, and it has been given without restriction or limit, that is to say, it hasn't been given "until I say otherwise", "until $DateTime" or until anything at all. It is given. It does not expire.

 

The person standing in front of you saying "I do not consent to you processing my data.", is this not anything more than an "Er, I changed my mind." I'd suspect the response would be "Doesn't matter. You already gave us the right to process the data you gave us. Then you gave us the data itself. We're allowed to process it. No backsies."

 

If the user then says "Well I wasn't given consent to sign up by my parents." then one of two things must happen. The data processor must fight that claim ("Well you said you did. Can you prove that you didn't?") or they must remove the data ("Then you have signed up to our service fraudulently and your account will be removed."). The first sounds like the option they'll pick as the second incurs financial penalties for them for A) A user illegally using their services, B) The cost of removing the data and C) The cost of refunding people they sold fraudulent/falsified data to.

 

I know it probably sounds like I'm just arguing but I'm legitimately trying to get my head around it. I cannot see how this would help a 13/14/15 year old remove data they no longer want because I just can't see the conversation going down that way.

Posted
Whilst I can appreciate that, the argument isn't about an ongoing right to process data. The right to process the data has already been given, and it has been given without restriction or limit, that is to say, it hasn't been given "until I say otherwise", "until $DateTime" or until anything at all. It is given. It does not expire.

I think we may be misunderstanding each other. It is not possible to consent fraudulently.

The person standing in front of you saying "I do not consent to you processing my data.", is this not anything more than an "Er, I changed my mind." I'd suspect the response would be "Doesn't matter. You already gave us the right to process the data you gave us. Then you gave us the data itself. We're allowed to process it. No backsies."

 

If the user then says "Well I wasn't given consent to sign up by my parents." then one of two things must happen. The data processor must fight that claim ("Well you said you did.

Who would have said they did? The person who has admitted they are considered a minor in respect of your right to process their data? I think if you need their parents permission then you need more than that minor declaring via a checkbox : "sure they give me permission- lol".

Can you prove that you didn't?") or they must remove the data ("Then you have signed up to our service fraudulently and your account will be removed."). The first sounds like the option they'll pick as the second incurs financial penalties for them for A) A user illegally using their services, B) The cost of removing the data and C) The cost of refunding people they sold fraudulent/falsified data to.

 

I know it probably sounds like I'm just arguing but I'm legitimately trying to get my head around it. I cannot see how this would help a 13/14/15 year old remove data they no longer want because I just can't see the conversation going down that way.

Sure. I have some doubts that it could be achieved in practice (~80/20 ish), my point is really to try and illustrate how the change might viewed as strengthening someone's rights to protect their data from companies that exploit that data for their own interests (which may or may not coincide with the interests of the data subject/s). That is a good thing - IMO.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...