Zephiel API
Compliance11 July 20179 min read

We read the GDPR so you do not have to

Enforcement starts in May 2018. Here is what it actually requires of an API platform, and the four things we are changing now.

The General Data Protection Regulation was adopted last year and becomes enforceable on 25 May 2018. There is a lot of consultancy noise about it and comparatively little plain description, so here is ours.

What it actually is

It is a regulation about personal data — anything that identifies a living person, directly or with a bit of joining. It applies to us because we process data belonging to people in the EU, regardless of where our servers are.

The parts that matter for a platform like ours are the lawful basis for processing, the rights individuals have over their data, the obligation to report breaches within seventy-two hours, and the requirement that processors are bound by contract to the same standards as controllers.

Controller and processor

This distinction does most of the work and is worth getting right. When you use an API through us, you are generally the controller — you decide why the data is being processed. We are a processor acting on your instructions, and the provider behind the API is usually a sub-processor.

That means you need a data processing agreement with us, we need one with each provider, and you are entitled to know who the sub-processors are. We are publishing that list rather than making people ask.

The four things we are changing

Data export, so any account can retrieve everything we hold about it without opening a ticket. Data deletion that actually deletes, including from backups within the retention window, rather than setting a flag. Retention limits on request logs, which we have been keeping indefinitely for no better reason than that storage was cheap. And a documented breach process with names against it, because seventy-two hours is not long enough to work out who is responsible.

What we are not doing

We are not going to email you a consent banner. Consent is one lawful basis among six and it is the wrong one for a B2B contract; the correct basis for most of what we do is performance of a contract or legitimate interest. Vendors telling you that everything needs consent are selling something.

Ten months is more time than it sounds like. We are starting now.

Keep reading