[HN Gopher] PSA: If you want to know why a company rejected you,...
___________________________________________________________________
PSA: If you want to know why a company rejected you, send them a
GDPR request
Author : mudro_zboris
Score : 35 points
Date : 2022-01-05 20:56 UTC (2 hours ago)
(HTM) web link (old.reddit.com)
(TXT) w3m dump (old.reddit.com)
| schappim wrote:
| GDPR is a regulation in EU law on data protection and privacy in
| the European Union and the European Economic Area (so all EU
| countries + Iceland, Liechtenstein and Norway, but not
| Switzerland). GDPR comes with a "Right of access by the data
| subject" to one's own personal information. This is what I
| believe the OP is using.
|
| A "GDPR request" can be as simple as[1]: >
| Dear... > > I wish to make an access request under
| Article 15 of the General Data Protection Regulation (GDPR) for a
| copy of any information you keep about me, on computer or in
| manual form in relation to...
|
| GDPR does not apply to US citizens living in the US, but some
| federal and state-level (eg. CalOPPA or CCPA) privacy regulations
| _might_ offer some similar rights (IANAL).
|
| [1] https://www.dataprotection.ie/en/individuals/know-your-
| right...
| witheld wrote:
| The thing about GDPR is that they can't prove one way or
| another whether you are or are not a European citizen, so they
| are legally obligated to fill the request regardless.
| PeterisP wrote:
| One aspect is that for companies within EU it applies for
| everyone - i.e. if you're an EU company which serves 100%
| only Chinese and Brazilian individuals and noone within EU,
| GDPR still applies to you and how you must handle the data of
| individuals so they all get GDPR rights. Citizenship and
| residence matters only for foreign companies doing business
| in EU.
| detaro wrote:
| Citizenship is irrelevant to GDPR.
|
| A non-EU company could probably request at least some proof
| that you're in scope if they have reasonable doubts about if
| you are, but I suspect in practice many find it easier to
| just oblige a reasonable request they have a process for than
| getting into the weeds of scope and risk getting it wrong.
| (i.e. I suspect there's some fun legal nuance in scenarios
| like "I'm a US citizen living in the US that applied and got
| rejected 3 months ago, now I'm on holiday in Copenhagen and
| writing an access request" - I could see ways of arguing that
| either way depending on the circumstances, but also am not a
| lawyer). Although a request for interview information like
| this might be enough hassle to be restrictive.
| remus wrote:
| It's not actually that unfeasible. A pretty standard first
| step in complying with a Subject Access Request is to
| verify the identity of the person you're talking to
| (wouldn't want to hand over a load of personal data to some
| random after all), so checking their nationality at the
| same time isn't miles off.
| detaro wrote:
| again: citizenship/nationality/residency doesn't matter.
| dekhn wrote:
| Wouldn't making such a request be fraudulent, then?
|
| I'd love to see my interview feedback but abusing GDPR or
| CCPA to obtain it seems abusive.
| multjoy wrote:
| It's data about you, GDPR gives you the right to access it.
| It is hardly abuse.
| Arnavion wrote:
| I tried to use the GDPR angle to close a bunch of old
| accounts I'd gathered over the last decade. One of them, an
| MMO, wanted me to provide proof of my EU citizenship by
| scanning and sending them my passport / national ID in order
| to proceed.
| foepys wrote:
| GDPR also applies to EU residents, so asking for a passport
| or national ID is not enough to avoid answering a request.
| detaro wrote:
| it also applies to people that just physically are in the
| EU, no residency needed.
| detaro wrote:
| GDPR applies to non-citizens too, so that requirement was
| bogus.
___________________________________________________________________
(page generated 2022-01-05 23:01 UTC)