Re: (Lack of) GDPR compliance in Debian

2022-03-13 Thread Free unofficial Italian translation - FUIT
If Debian has not been publicly registered in Europe, Debian is a de facto entity in Europe. However, the text also addresses the issue of exporting personal data outside the EU and obliges all data controllers (including with registered offices outside the EU) who process data of EU residents

Re: (Lack of) GDPR compliance in Debian

2022-03-12 Thread David Bremner
Russ Allbery writes: > (If you do open source work outside of the auspices of an organization > that carries insurance and you have assets to protect, it's worth > considering a personal umbrella policy.) Obviously it's not Russ's fault, but... I hate that we live in such a world. d

Re: (Lack of) GDPR compliance in Debian

2022-03-12 Thread Russ Allbery
Jonathan Carter writes: > It's not 100% clear to me, but from what I understand having had some > informal conversations with experts in this field (we should ideally > speak get some more information from legal experts on this topic), it > would fall on individual members, unless a TO has en exp

Re: (Lack of) GDPR compliance in Debian

2022-03-12 Thread Jonathan Carter
Hi Adrian On 2022/03/12 17:23, Adrian Bunk wrote: Is it SPI that is liable for penalies of up to 20 Million Euro and compensation claims, or is it individual team members who are personally liable for penalies of up to 20 Million Euro and compensation claims? If this is unclear, the easiest way

Re: (Lack of) GDPR compliance in Debian

2022-03-12 Thread Adrian Bunk
On Sat, Mar 12, 2022 at 02:46:02PM +0100, Bastian Blank wrote: > Hi Adrian Hi Bastian, > On Sat, Mar 12, 2022 at 01:27:03AM +0200, Adrian Bunk wrote: >... > > Does this also apply to highly sensitive data revealing for example > > sexual orientation or political opinions? > > We don't process t

Re: (Lack of) GDPR compliance in Debian

2022-03-12 Thread Bastian Blank
Hi Adrian On Sat, Mar 12, 2022 at 01:27:03AM +0200, Adrian Bunk wrote: > Out of curiousity I started looking at various aspects of GDPR > compliance in Debian, and what I saw in the Privacy Policy[2] made me > worry that the lawyer has not yet been involved enough in ensuring that > privacy in

(Lack of) GDPR compliance in Debian

2022-03-11 Thread Adrian Bunk
This email is about the EU GDPR (General Data Protection Regulation), and any use of "data" below refers to personal data of people covered by the GDPR. Two years ago the outgoing DPL announced that our Data Protection Team has a relationship with a GDPR lawyer.[1] Out of curiousity I started l