GDPR surely doesn't mean this?
GDPR surely doesn't mean this?
Author
Discussion

davek_964

Original Poster:

11,299 posts

205 months

Monday 10th September 2018
quotequote all
I went to a Samsung repair center on Saturday to have a new screen fitted - the one they fitted just under a year ago had suffered terrible screen burn. They were happy to replace it under warranty, and then said :

But we need to wipe your device.

I said : You didn't when you replaced the screen last year.

The reply was : Because of GDPR we have to wipe all your data.

I replied saying that I didn't think that's quite what GDPR meant. It's my data on my device - it makes no sense that they have to wipe it. GDPR is about data they hold about me.

It was pointless arguing any further, since this is clearly what the guys in the store have been told they have to do. But surely that's not the correct interpretation is it?

anonymous-user

84 months

Monday 10th September 2018
quotequote all
Nope it's bks.

Doesn't help you though. Take it somewhere else

anonymous-user

84 months

Monday 10th September 2018
quotequote all
I have no specific knowledge, however I can imagine a scenario where Samsung would be concerned that a rogue employee could take data from your device and use it maliciously, or that the device could itself fall i to the wrong hands and the and happen. To counter this, it issues instructions that all devices are wiped before any work undertaken.

It might be overkill, however when the potential penalty is 4% of global turnover, it can be a significant sun at risk, hence some companies going very belt and braces.

Of course, the OPs scenario could be a staff misunderstanding or over zealousness, however it's not always the GDPR at fault, rather the organisations policies around it.

Roger Irrelevant

3,391 posts

143 months

Monday 10th September 2018
quotequote all
GDPR seems to be becoming the 'elf n' safety' of the digital world - a vague universal excuse to justify any old policy that an organisation wants to implement. There have even been people posting on here that they won't post Google Earth pictures of where they had/saw an accident due to GDPR concerns. I've gained a half-decent working knowledge of GDPR over the last couple of years and can see no reason why it would necessitate a device being wiped when its screen is replaced, as per the previous poster that's a load of bks.

creampuff

6,511 posts

173 months

Monday 10th September 2018
quotequote all
Someone, perhaps several, people in the Samsung hierarchy are thick as fk is your answer.

Unless they are planning on replacing your phone with a white box phone and forgot to mention that. I’m going with thick as fk though.

IanCress

4,409 posts

196 months

Monday 10th September 2018
quotequote all
GDPR covers how your data is stored and used. Since they're not actually accessing any of your data, I can't see that GDPR has any effect on what you're asking them to do.

As stated above, it may be due to them trying to protect you from a rogue employee accessing your data. That's not GDPR though, it's just an internal policy.

anonymous-user

84 months

Monday 10th September 2018
quotequote all
IanCress said:
As stated above, it may be due to them trying to protect you from a rogue employee accessing your data. That's not GDPR though, it's just an internal policy.
Many of these things are influenced by GDPR, the reason being be exceptionally high penalties available. Do not underestimate the power of the threat that 4% of your global T/O could be taken from you.

Corporate governance dictates you have to take that kind of threat very seriously indeed.

Until such time some contested cases have run through the courts and therefore precedents available, expect to see all kinds of over the top policies.



CrutyRammers

13,735 posts

228 months

Monday 10th September 2018
quotequote all
I'll join the chorus of "utter bks". Doesn't apply here. They're probably worried about staff seeing your personal data during the repair; but all they'd have to do is ask for your consent anyway.

Ninja59

3,691 posts

142 months

Monday 10th September 2018
quotequote all
CrutyRammers said:
I'll join the chorus of "utter bks". Doesn't apply here. They're probably worried about staff seeing your personal data during the repair; but all they'd have to do is ask for your consent anyway.
Asking for consent in itself is not a problem, but keeping track of and ensuring that the records can be found quickly and easily is a different kettle of fish.

Equally it is not just down to GDPR, wiping phones as part of repairs is regularly done in case there is something interfering with how the phone was originally intended to operate.

Honestly, these days though it is so easy to move phones (or restore data to original ones) and the data with them, android simply back them up with the Google facility and ensure automatic restore is on on your old phone. Make sure that the phone recently backed up (it will display when it last done).

Turn on new phone, login into email account then select backup and restore from the old backup. Apps, contacts and a decent percentage of all my other content transferred with no involvement from me - heck it even imported my background from my old phone! All said and done it was up and running in a few hours with minimal involvement from me, had to tweak a few bits in the following days but I was impressed how quickly all the main essentials had just appeared on the new phone with no involvement.

sidekickdmr

5,210 posts

236 months

Monday 10th September 2018
quotequote all
As said above, nothing really to do with GDPR, however remember a few months ago there was a story in the paper of a apple store, or phone shop repairer stealing nudes from someones phone, thats why they are doing it, damage limitation/covering themselves.

BertBert

21,270 posts

241 months

Monday 10th September 2018
quotequote all
They do have a GDPR responsibility obviously. They have to have a procedure to safeguard the personal data that comes to them. Signing a disclaimer is of no help unless it said "I agree that you have my personal data and I'm not bothered if you don't take any care of it and lose it". And then it wouldn't stand up.

So wiping the device as soon as possible seems a sensible strategy to me and very much in line with a risk averse approach to GDPR.

Bert

Gavia

7,627 posts

121 months

Monday 10th September 2018
quotequote all
Roger Irrelevant said:
GDPR seems to be becoming the 'elf n' safety' of the digital world - a vague universal excuse to justify any old policy that an organisation wants to implement. There have even been people posting on here that they won't post Google Earth pictures of where they had/saw an accident due to GDPR concerns. I've gained a half-decent working knowledge of GDPR over the last couple of years and can see no reason why it would necessitate a device being wiped when its screen is replaced, as per the previous poster that's a load of bks.
^^^^^^ this. Not forgetting the other view on here that means that no company can hold any information at all about anyone ever and if anyone does know anything at all then they are immediately in breach of GDPR.

CrutyRammers

13,735 posts

228 months

Monday 10th September 2018
quotequote all
Ninja59 said:
Asking for consent in itself is not a problem, but keeping track of and ensuring that the records can be found quickly and easily is a different kettle of fish.
But they're not going to store the data. They might see it, but they're not going to keep it, so it doesn't apply. Consent to view would cover it, I think. None of it will stop a rogue employee looking for nudes anyway.

Haws

58 posts

122 months

Monday 10th September 2018
quotequote all
No-one seems to have mentioned the part where if they say that about GDPR, nobody wants their phone wiping so the warranty repair goes away and they no longer have to do it

lyonspride

2,978 posts

185 months

Monday 10th September 2018
quotequote all
Roger Irrelevant said:
GDPR seems to be becoming the 'elf n' safety' of the digital world - a vague universal excuse to justify any old policy that an organisation wants to implement.
Indeed, it's not unlike that thing a few years back regarding cyber security (wish I could remember what it was called), that got misused like crazy, a company I worked for used it to ban phones, implement employee monitoring, company phone tapping, searching of personal possessions at a whim, and as an excuse to sack people for any infringement they could make up to fit, relying on their limited knowledge being greater than the employees limited knowledge.

These things are meant to keep us safe, but they're mostly used to cause us harm.


davek_964

Original Poster:

11,299 posts

205 months

Monday 10th September 2018
quotequote all
Haws said:
No-one seems to have mentioned the part where if they say that about GDPR, nobody wants their phone wiping so the warranty repair goes away and they no longer have to do it
I don't think that's generally happening. I still had my repair done - it just meant a quick backup, and then a few hours in the afternoon getting everything back to normal. And I didn't see anybody else there who declined the repair.

It was a little inconvenient - but I only had one day remaining on the warranty for a screen which cost me something like £280, so I had limited options.

BertBert

21,270 posts

241 months

Monday 10th September 2018
quotequote all
CrutyRammers said:
But they're not going to store the data. They might see it, but they're not going to keep it, so it doesn't apply. Consent to view would cover it, I think. None of it will stop a rogue employee looking for nudes anyway.
The consent thing is an irrelevance, they are not worried about customer consent because as you say that's inherent and built in to the piece of paper you sign to get the phone fixed I imagine.

They are worried about how to keep the data safe once they have the phone and from any accusations that they somehow let the data out (lost it, had it stolen, copied, lost the phone etc). So failsafe, wipe the data. Then the additional benefit is that if the fix buggers the phone and they replace it, there's no problem with loss/deletion of data (which again may be a GDPR problem).

Bert

BertBert

21,270 posts

241 months

Monday 10th September 2018
quotequote all
And for a laugh, albeit pre-GDPR, the local hospital told me they couldn't tell me or send me some info on me from a recent exam due to data protection!
Bert

Mike335i

6,054 posts

132 months

Monday 10th September 2018
quotequote all
Could you not complain that they mishandled your data by, against your will, destroying it?

richard sails

813 posts

289 months

Monday 10th September 2018
quotequote all
My dentist won't let my wife book my appointment due to GDPR rules!, she just smiles and says ok I will let you keep trying to ring him while he is at work with his phone switched off.