datenanfragen / data

The data behind the Datenanfragen.de project. This contains a directory of contact information and privacy-related data on companies under the scope of the EU GDPR, a directory of supervisory authorities for privacy concerns, a collection of templates for GDPR requests and a list of suggested companies to send access requests to.
https://www.datarequests.org/company
Creative Commons Zero v1.0 Universal
106 stars 90 forks source link

Dealing with defunct companies/services #1157

Open baltpeter opened 3 years ago

baltpeter commented 3 years ago

How do we want to deal with companies and services in our database that have since been closed?

I'm mostly opening this issue to remind us that we should adopt a policy for that. If anyone has any thoughts, I'd be glad to hear them!

fm commented 3 years ago

We can either purge them or keep them and create a flag that we could set on the record that would let the user know the company no longer exists/operates?

mal-tee commented 3 years ago

Both options are fine for me. I think it boils down to the question: Who is responsible for the data a company processed/collected after its shutdown?

I suppose most companies would delete their records, but what about those that don't? If there is still some data, we have a right to access it/correct/... it. But thats only really useful, if we can contact somebody responsible. From our point of view, we only have the contact information we already stored. That means a flag would make the most sense in these cases?

baltpeter commented 3 years ago

I think we agree that if there is still an entity that is responsible for some data, we should keep them in the database, regardless of whether they are still carrying out business under that brand or not. That's also pretty much what we're doing already by adding (formerly) to the respective runs entry.
But I think it's good to formalize this as an official policy here.

The next question then is when we consider a company to be closed. There's often cases where for example the website goes offline but the company still exists. As a measure to decide that, I'd propose to look at the official company registers and check whether the company is still listed as active.
That of course only works if the company is in fact listed in an official register. Not sure what to do otherwise.

Now, with regards to companies that we have determined to be actually closed, I don't know whether keeping them in the database (with a flag) would really serve any purpose. If the company is really closed, it's unlikely that you would still reach anyone through the old contact details. In some cases, there may be an insolvency administrator/liquidator or something like that, that now becomes the controller (and in that case, we should list them) but that is not always the case.

I suppose most companies would delete their records, but what about those that don't? If there is still some data, we have a right to access it/correct/... it. But thats only really useful, if we can contact somebody responsible.

Definitely. But unfortunately, I really don't see a way for us to determine who the responsible entity is unless one of us is affected and wants to put major work into finding that out. And in many cases, it's probably going to be a natural person rather than a company, which makes this even more difficult. :/

baltpeter commented 3 years ago

A few example of companies that I am not quite sure what to do with:

baltpeter commented 3 years ago

Another thing to consider: By deleting a company, we invalidate the links to it, including the ones in My requests. I'm really not a fan of that*.

Considering that, I might lean more on the side of keeping the records with a flag but not showing them in the search and lists.


Side note: In #1168, I am deleting a few defunct companies. As we haven't decided on anything else yet, I'll keep doing that for now. Should we decide to keep the records after all, it's easy enough to restore them.

baltpeter commented 3 years ago

Considering that, I might lean more on the side of keeping the records with a flag but not showing them in the search and lists.

I think it would also be a good idea to provide a way to redirect defunct records to other ones. Not sure what a nice way to implement that would be yet but I have seen quite a few companies that have been merged with or bought by others. For those, I have listed the old company as (formerly) on the other one but it would also be nice to redirect the existing record there.

zner0L commented 1 year ago

We decided that:

mal-tee commented 12 months ago

(formerly)

Do we translate that?