[HN Gopher] PSA: If you want to know why a company rejected you,...
       ___________________________________________________________________
        
       PSA: If you want to know why a company rejected you, send them a
       GDPR request
        
       Author : mudro_zboris
       Score  : 35 points
       Date   : 2022-01-05 20:56 UTC (2 hours ago)
        
 (HTM) web link (old.reddit.com)
 (TXT) w3m dump (old.reddit.com)
        
       | schappim wrote:
       | GDPR is a regulation in EU law on data protection and privacy in
       | the European Union and the European Economic Area (so all EU
       | countries + Iceland, Liechtenstein and Norway, but not
       | Switzerland). GDPR comes with a "Right of access by the data
       | subject" to one's own personal information. This is what I
       | believe the OP is using.
       | 
       | A "GDPR request" can be as simple as[1]:                 >
       | Dear...       >        > I wish to make an access request under
       | Article 15 of the General Data Protection Regulation (GDPR) for a
       | copy of any information you keep about me, on computer or in
       | manual form in relation to...
       | 
       | GDPR does not apply to US citizens living in the US, but some
       | federal and state-level (eg. CalOPPA or CCPA) privacy regulations
       | _might_ offer some similar rights (IANAL).
       | 
       | [1] https://www.dataprotection.ie/en/individuals/know-your-
       | right...
        
         | witheld wrote:
         | The thing about GDPR is that they can't prove one way or
         | another whether you are or are not a European citizen, so they
         | are legally obligated to fill the request regardless.
        
           | PeterisP wrote:
           | One aspect is that for companies within EU it applies for
           | everyone - i.e. if you're an EU company which serves 100%
           | only Chinese and Brazilian individuals and noone within EU,
           | GDPR still applies to you and how you must handle the data of
           | individuals so they all get GDPR rights. Citizenship and
           | residence matters only for foreign companies doing business
           | in EU.
        
           | detaro wrote:
           | Citizenship is irrelevant to GDPR.
           | 
           | A non-EU company could probably request at least some proof
           | that you're in scope if they have reasonable doubts about if
           | you are, but I suspect in practice many find it easier to
           | just oblige a reasonable request they have a process for than
           | getting into the weeds of scope and risk getting it wrong.
           | (i.e. I suspect there's some fun legal nuance in scenarios
           | like "I'm a US citizen living in the US that applied and got
           | rejected 3 months ago, now I'm on holiday in Copenhagen and
           | writing an access request" - I could see ways of arguing that
           | either way depending on the circumstances, but also am not a
           | lawyer). Although a request for interview information like
           | this might be enough hassle to be restrictive.
        
             | remus wrote:
             | It's not actually that unfeasible. A pretty standard first
             | step in complying with a Subject Access Request is to
             | verify the identity of the person you're talking to
             | (wouldn't want to hand over a load of personal data to some
             | random after all), so checking their nationality at the
             | same time isn't miles off.
        
               | detaro wrote:
               | again: citizenship/nationality/residency doesn't matter.
        
           | dekhn wrote:
           | Wouldn't making such a request be fraudulent, then?
           | 
           | I'd love to see my interview feedback but abusing GDPR or
           | CCPA to obtain it seems abusive.
        
             | multjoy wrote:
             | It's data about you, GDPR gives you the right to access it.
             | It is hardly abuse.
        
           | Arnavion wrote:
           | I tried to use the GDPR angle to close a bunch of old
           | accounts I'd gathered over the last decade. One of them, an
           | MMO, wanted me to provide proof of my EU citizenship by
           | scanning and sending them my passport / national ID in order
           | to proceed.
        
             | foepys wrote:
             | GDPR also applies to EU residents, so asking for a passport
             | or national ID is not enough to avoid answering a request.
        
               | detaro wrote:
               | it also applies to people that just physically are in the
               | EU, no residency needed.
        
             | detaro wrote:
             | GDPR applies to non-citizens too, so that requirement was
             | bogus.
        
       ___________________________________________________________________
       (page generated 2022-01-05 23:01 UTC)